Signature management device and signature system

The signature management device and system securely manage private keys by automating digital certificate issuance for public keys, addressing user-dependent management risks and ensuring legitimate digital signature verification.

JP2025115173APending Publication Date: 2025-08-06KK TOSHIBA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024009556
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-25
Publication Date
2025-08-06

AI Technical Summary

Technical Problem

Existing signature management systems rely on users to securely manage private keys, which poses a risk of unauthorized access and management challenges.

Method used

A signature management device and system that includes a first communication unit, a second communication unit, an interface, and a processor, which communicates with a user device and a certification authority to manage and generate digital certificates for public keys stored in a secure device, allowing secure management of private keys without user intervention.

Benefits of technology

Ensures secure management of private keys by automating the issuance of digital certificates for public keys, preventing unauthorized access and ensuring the legitimacy of digital signatures through trusted certification authority verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025115173000001_ABST
    Figure 2025115173000001_ABST
Patent Text Reader

Abstract

To provide a signature management device and a signature system by which keys can be safely managed without depending on a user.SOLUTION: According to an embodiment, a signature management device includes a first communication unit, a second communication unit, an interface, and a processor. The first communication unit communicates with a user device operated by a user. The second communication unit communicates with a certification authority that issues electronic certificates. The interface connects to a secure device that stores a private key used to generate an electronic signature to be added to electronic data from the user. The processor requests the certification authority to issue an electronic certificate for a public key corresponding to the private key stored in the secure device, and after the certification authority issues the electronic certificate for the public key, adds an electronic signature to the electronic data from the user using the private key stored in the secure device.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] FIELD Embodiments of the present invention relate to a signature management device and a signature system. [Background technology]

[0002] In recent years, there have been increasing opportunities to apply electronic signatures to electronic documents, such as electronic contracts. To prevent unauthorized generation of electronic signatures, it is necessary to securely manage the private key of the public key cryptography used to generate the electronic signature. Conventionally, some computer-based software for editing documents and images has the function of adding electronic signatures to electronic data such as documents and images, but the storage and management of the private key for the electronic signature is left to the user. Another method for managing the private key is to store the private key in a secure device such as an IC card. However, this method has the problem that the secure device itself storing the private key must be securely managed by the user. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent Publication No. 2021-40278 Summary of the Invention [Problem to be solved by the invention]

[0004] In order to solve the above problems, an object of the present invention is to provide a signature management device and a signature system that can safely manage keys without relying on users. [Means for solving the problem]

[0005] According to an embodiment, a signature management device has a first communication unit, a second communication unit, an interface, and a processor. The first communication unit communicates with a user device operated by a user. The second communication unit communicates with a certification authority that issues digital certificates. The interface connects to a secure device that stores a private key used to generate a digital signature to be added to digital data from the user. The processor requests the certification authority to issue a digital certificate for a public key corresponding to the private key stored in the secure device, and after the certification authority issues the digital certificate for the public key, adds a digital signature to the digital data from the user using the private key stored in the secure device. [Brief explanation of the drawings]

[0006] [Figure 1] FIG. 1 is a diagram schematically illustrating a first configuration example of a signature system according to an embodiment. [Figure 2] FIG. 2 is a diagram schematically illustrating a second configuration example of the signature system according to the embodiment. [Figure 3] FIG. 3 is a block diagram showing an example of the configuration of a signature management server of a signature management system in the signature system according to the embodiment. [Figure 4] FIG. 4 is a block diagram showing an example of the configuration of a CA server of a CA system in a signature system according to an embodiment. [Figure 5] FIG. 5 is a sequence diagram illustrating a first operation example of data processing including a digital signature in the signature system according to the embodiment. [Figure 6] FIG. 6 is a sequence diagram illustrating a second operation example of data processing including a digital signature in the signature system according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0007] Hereinafter, embodiments will be described with reference to the drawings. First, the configuration of a signature system 1 according to an embodiment will be described. 1 and 2 are diagrams showing an example of the configuration of a signature system according to an embodiment. A signature system 1 shown in Fig. 1 shows a first example of the configuration of a signature system according to an embodiment. A signature system 1' shown in Fig. 2 shows a second example of the configuration of a signature system according to an embodiment.

[0008] In the configuration examples shown in FIGS. 1 and 2, the signature system 1 (1') includes a signature management system 2 and a CA (Certificate Authority) system 3. The signature management system 2 (2') is a system that assigns electronic signatures to electronic documents such as contracts, and electronic data such as images or programs. The signature management system 2 generates key information for each user. The signature management system 2 manages the key information for each user as key information to be used for electronic signatures requested by the user.

[0009] For example, the signature management system 2 generates and manages key information including a key pair of a public key and a private key for each user. In response to a request from a user, the signature management system 2 affixes an electronic signature to electronic data using the private key included in the key information for each user. The signature management system 2 requests the CA system 3 to issue an electronic certificate for the public key corresponding to the private key used for the electronic signature, and provides the electronic data affixed with the electronic signature to the user.

[0010] The CA system 3 (3') is a system for generating digital certificates. The CA system 3 manages CA key information and issues digital certificates using the CA key information. The CA system 3 also publishes CA certificates for verifying the issued digital certificates. For example, in response to a request from the signature management system 2 for the issuance of a digital certificate for a user's public key, the CA system 3 issues a digital certificate for the public key (hereinafter also referred to as a public key certificate).

[0011] In this embodiment, the digital certificate of a user's public key issued by the CA system 3 may be transmitted to the user via the signature management system 2. The digital certificate of a public key issued by the CA system 3 may also be stored and made public by the CA system 3. When making public the digital certificate of each user's public key, the CA system 3 may provide the digital certificate of the public key identified by a search in response to a search request (inquiry) from a verifier.

[0012] In the first configuration example of the signature system 1 shown in Figure 1, the signature management system 2 includes a signature management server (signature management device) 21 and an HSM (Hardware Security Module) 22, and the CA system 3 includes a CA server (certification authority device) 31 and an HSM 32.

[0013] 2, a signature system 1′ of a second configuration example shown in FIG. 2 includes a signature management system 2′ that includes a signature management server (signature management device) 21, and a CA system 3′ that includes a CA server (certification authority device) 31. Furthermore, in the second configuration example shown in FIG. 2, the signature management server 21 and the CA server 31 are connected to an HSM 11.

[0014] For example, the signature system 1 of the first configuration example shown in Fig. 1 is assumed to be configured in a case where the signature management server 21 and the CA server 31 are installed in physically separate locations. In contrast, the signature system 1' of the second configuration example shown in Fig. 2 is assumed to be configured in a case where the signature management server 21 and the CA server 31 are installed in physically close locations (for example, in the same server room).

[0015] The HSM 11 shown in Fig. 2 has the functions of both the HSM 22 shown in Fig. 1 and the HSM 32 shown in Fig. 1, and the signature management server 21 and CA server 31 shown in Fig. 2 use the HSM 11 to achieve functions similar to those of the signature management server 21 and CA server 31 shown in Fig. 1. That is, the signature system 1' shown in Fig. 2 can be achieved by replacing the HSM 22 and HSM 32 in the signature system 1 shown in Fig. 1 with the HSM 11. For this reason, in the following explanation, the operation and configuration of the signature system 1 shown in Fig. 1 will be explained, and a detailed explanation of the signature system 1' shown in Fig. 2 will be omitted.

[0016] The signature management server 21 in the signature management system 2 communicates with the user PC 4 and the CA server 31 in the CA system 3. The user PC 4 is a user device operated by a user. The user PC 4 is configured as an information processing device including a computer such as a personal computer, a smartphone, or a tablet terminal. The user PC 4 has a communication function for communicating data with devices such as the signature management server 21 and the verifier PC 5.

[0017] The user PC 4 creates electronic data to which an electronic signature is to be attached. The electronic data to which an electronic signature is to be attached is, for example, a document (electronic document) such as a contract to be presented (sent) to another person (verifier), or electronic data such as an image or program. The user PC 4 requests the signature management server 21 to issue an electronic signature for the electronic data. The user PC 4 obtains the electronic data to which the electronic signature has been attached from the signature management server 21, which is the request destination for the electronic signature. The user PC 4 may also request the signature management server 21 to issue an electronic signature via any server, such as a registration authority that accepts certificate issuance procedures.

[0018] The user PC4 transmits the electronic data to which the digital signature has been affixed to the verifier PC5, which is operated by another party (the verifier) to whom the electronic data will be provided. Here, the user PC4 also transmits information to the verifier PC5 for verifying the digital signature affixed to the electronic data (the legitimacy of the electronic data). For example, the user PC4 may transmit to the verifier PC5, together with the digitally signed electronic data, a public key certificate issued by the CA system 3 for verifying the digital signature. Furthermore, the user PC4 may transmit to the verifier PC5, to which the digitally signed electronic data will be sent, information including information (search information) for obtaining from the CA system 3 a public key certificate for verifying the digital signature.

[0019] The verifier PC 5 is an information processing device such as a computer. The verifier PC 5 has a communication function for communicating data with devices such as the user PC 4 and the CA server 31. The verifier PC 5 acquires electronic data to which an electronic signature has been attached from the user PC 4. For example, the verifier PC 5 verifies the electronic signature attached to the electronic data from the user PC 4 using a public key indicated in the public key certificate of the signatory user. The verifier PC 5 may acquire the public key certificate for verifying the electronic signature from the user PC 4 or from the CA server 31.

[0020] In the signature system according to the embodiment, mutual authentication is performed between the signature management server 21 and the CA server 31, and secure data communication is performed between the signature management system 2 and the CA system 3. As in the second configuration example, the signature management system 2 and the CA system 3 may be operated in the same server room, or the signature management server 21 and the CA server 31 may be configured as a single server device, thereby preventing a third party from impersonating the signature management system 2.

[0021] Next, the functions of the signature management server 21 of the signature management system 2 in the signature system 1 will be described. The signature management server 21 in the signature management system 2 has, as its main functions, a key generation function, a key management function, a signature generation function, a user management function, a log management function, and a notification function. In this embodiment, the signature management server 21 in the signature management system 2 realizes the key generation function, the key management function, the signature generation function, etc. by working in cooperation with the HSM 22.

[0022] The signature management server 21 connects to the HSM 22 via an interface. The HSM 22 is a tamper-resistant hardware device (security device) that securely generates key information and stores the generated key information. The HSM 22 is also an example of a storage device. The signature management server 21 causes the HSM 22 to generate a key pair of a public key and a private key to serve as user key information. The HSM 22 securely stores the private key of the generated user key information and outputs the public key of the user key information to the signature management server 21.

[0023] For example, when the signature management server 21 receives a request from the user PC4 to issue an electronic certificate, it causes the HSM 22 to generate user key information including a key pair of a public key and a private key. The signature management server 21 then requests the CA server 31 of the CA system 3 to issue an electronic certificate (public key certificate) for the public key of the user's key information generated by the HSM 22. The signature management server 21 does not provide the public key itself, but rather provides the public key certificate issued by the CA server 31. The public key certificate issued by the CA system 3 in response to the issuance request from the signature management server 21 may be transmitted to the user PC4 via the signature management server 21, or may be made public by the CA system 3.

[0024] Furthermore, the signature management server 21 has a user authentication function (login function) as one of its user management functions. For example, as the user authentication function, the signature management server 21 holds user information including identification information such as an ID and authentication information such as a password for each user. The signature management server 21 performs user authentication (login) by combining the identification information and authentication information specified by the user on the user PC 4.

[0025] The signature management server 21 also manages key information for each user authenticated by the user authentication function. In response to a request for generating an electronic signature from a user identified by the user authentication function, the signature management server 21 generates an electronic signature using the private key of the user. For example, the signature management server 21 accepts a request for generating an electronic signature from a specific user who logs in from the user PC4. In response to the request for generating an electronic signature from the specific user, the signature management server 21 generates an electronic signature using the private key of the specific user using the HSM 22.

[0026] The signature management server 21 also has user management functions such as a user authority function, a user information management function, a group management function, and an access management function. The signature management server 21 manages the authority of each individual user through a user authority function. For example, the user authority function grants or revokes the authority to execute various functions for each individual user. The signature management server 21 also manages the user information of each user through a user information management function. For example, the user information management function registers, modifies, and deletes user information about each individual user.

[0027] The signature management server 21 also manages each user by group using a group management function. For example, the group management function registers, modifies, and deletes group information for each group. The signature management server 21 also manages access for each user or group using an access management function. For example, the access management function restricts various processes using the managed key information for each user or group.

[0028] Furthermore, the signature management server 21 stores log data indicating the details of processing as a log management function. For example, the signature management server 21 may realize the log management function by working in cooperation with the HSM 22. Specifically, the signature management server 21 generates log data indicating the details of processing when processing such as digital signature using a private key stored in the HSM 22 is executed, and stores data (signed log data) on which the HSM 22 digitally signs the generated log data in a storage device. Furthermore, the signature management server 21 provides a notification function, for example, by sending various notifications to the user or a pre-set notification destination by email or the like when various functions are used.

[0029] Next, the functions of the CA server 31 of the CA system 3 in the signature system 1 will be described. The CA server 31 issues (generates) an electronic certificate for a public key corresponding to a private key used for an electronic signature. The CA system 3 according to the embodiment accepts a request for issuance of an electronic certificate from the signature management server 21, and issues (generates) the specified electronic certificate using the CA's key information. The CA server 31 publishes a CA certificate indicating the CA's public key for verifying the validity of the issued electronic certificate. As a result, the validity of the electronic certificate issued by the CA server 31 is verified using the CA certificate indicating the CA's public key.

[0030] For example, when the CA server 31 receives a request from the signature management server 21 to issue a digital certificate for a public key, it uses the CA key information to issue a digital certificate (public key certificate) for the specified public key. The CA server 31 supplies the public key certificate issued in response to the request to the signature management server 21 that made the request. The CA server 31 may also store the public key certificate issued in response to the request and make the stored public key certificate public. In this case, the CA server 31 supplies the public key certificate identified in response to a search request from a device such as the verifier PC 5 to the device that made the search request.

[0031] Next, the configuration of the signature management server 21 of the signature management system 2 in the signature system 1 according to the embodiment will be described. FIG. 3 is a block diagram showing an example of the configuration of the signature management server 21 of the signature management system 2 in the signature system 1 according to the embodiment. As shown in FIG. 3, the signature management server 21 includes a processor 51, a ROM 52, a RAM 53, a data memory 54, an interface 55, a communication interface 56, and a communication interface 57.

[0032] The processor 51 executes various processes by executing programs. The processor 51 is, for example, a CPU (Central Processing Unit). The processor 51 is connected to each part in the server 21 via a system bus, and transmits and receives data to and from each part. The processor 51 cooperates with the ROM 52 and RAM 53 to execute operations such as control and data processing in the signature management server 21.

[0033] The ROM (Read Only Memory) 52 is a non-volatile memory that stores programs and control data for implementing the basic operations of the signature management server 21. The RAM (Random Access Memory) 53 is a volatile memory that temporarily stores data and functions as a working memory when the processor 51 executes a program.

[0034] The data memory 54 is a storage device that stores various types of data. The data memory 54 is configured as a non-volatile memory that allows data to be rewritten. For example, the data memory 54 stores an OS program, an application program, operation setting information, etc. The data memory 54 may also store user information, etc. The data memory 54 may also store log data that indicates the processing content.

[0035] The interface 55 is an interface for accessing the HSM 22 (or HSM 32). The interface 55 may be any interface that complies with the interface standard of the HSM 22. The communication interface 56 is a communication interface for communicating with the user PC 4. For example, the communication interface 56 may be configured as a network interface for communicating with the user PC and the verifier PC 5 via a wide area network such as the Internet.

[0036] The communication interface 57 is a communication interface for communicating with the CA server 31. For example, the communication interface 57 may be configured as a local area network (LAN) interface for communicating with the CA server 31 via a LAN. The communication interface 56 and the communication interface 57 may be a single communication interface. The communication interface 56 and the communication interface 57 may be interfaces that perform wireless communication or interfaces that perform wired communication.

[0037] Next, the configuration of the CA server 31 of the CA system 3 in the signature system 1 according to the embodiment will be described. FIG. 4 is a block diagram showing an example of the configuration of the CA server 31 in the CA system 3 in the signature system 1 according to the embodiment. As shown in FIG. 4, the CA server 31 includes a processor 61, a ROM 62, a RAM 63, a data memory 64, an interface 65, a communication interface 66, and a communication interface 67.

[0038] The processor 61 executes various processes by running programs. The processor 61 is, for example, a CPU. The processor 61 is connected to each unit in the CA server 31 via a system bus, and transmits and receives data to and from each unit. The processor 61 cooperates with the ROM 62 and RAM 63 to execute operations such as control and data processing in the CA server 31.

[0039] The ROM 62 is a non-volatile memory that stores programs and control data for implementing the basic operations of the CA server 31. The RAM 63 is a volatile memory that temporarily stores data and functions as a working memory when the processor 61 executes a program.

[0040] The data memory 64 is a storage device that stores various types of data. The data memory 64 is configured as a non-volatile memory that allows data to be rewritten. For example, the data memory 64 stores an OS program, an application program, operation setting information, etc. The data memory 64 may also store user information, etc. The data memory 64 may also store log data that indicates the processing content.

[0041] The interface 65 is an interface for accessing the HSM 32 (or HSM 11). The interface 65 may be any interface that complies with the interface standard of the HSM 32.

[0042] The communication interface 66 is a communication interface for communicating with the verifier PC 5. For example, the communication interface 66 may be configured as a network interface for communicating with the user PC and the verifier PC 5 via a wide area network such as the Internet.

[0043] The communication interface 67 is a communication interface for communicating with the signature management server 21. For example, the communication interface 67 may be configured as a local area network (LAN) interface for communicating with the signature management server 21 via a LAN.

[0044] The communication interface 66 and the communication interface 67 may be a single communication interface. The communication interface 66 and the communication interface 67 may be interfaces that perform wireless communication, or may be interfaces that perform wired communication.

[0045] Next, an example of the operation of data processing including a digital signature by the signature management server 21 in the signature system 1 according to this embodiment will be described. FIG. 5 is a sequence diagram for explaining a first operation example of data processing including a digital signature by the signature management server 21 in the signature system 1 according to this embodiment. First, a user who uses the signature system 1 performs an operation to log in to the signature management server 21 using the user PC 4. For example, the user operates the user PC 4 to register user information including authentication information used for user authentication in the signature management server 21. The signature management server 21 stores user information including authentication information such as an ID and password for each user, and accepts a login request from each user.

[0046] The user PC 4 and the signature management server 21 of the signature management system 2 execute a login process (user authentication) for the user to log in to the signature system 1 from the user PC 4 (ST11). For example, the user PC 4 establishes a communication connection with the signature management server 21 in response to a user operation, and transmits a user authentication (login) request along with authentication information (e.g., ID and password) entered by the user to the signature management server 21. The signature management server 21 receives the login request from the user PC 4 via the communication interface 56. The processor 51 of the signature management server 21 executes user authentication based on the authentication information received from the user PC 4 and user information stored in the data memory 54 or the like.

[0047] If the user authentication is successful (if the user is confirmed to be a valid user), the processor 51 of the signature management server 21 places the user in a logged-in state. The processor 51 of the signature management server 21 accepts a processing request (a request) from the user PC 4 based on the authority set for the user in the logged-in state.

[0048] When the user PC 4 successfully logs in to the signature management server 21, the user PC 4 requests the signature management server 21 to issue an electronic certificate in response to an operation by the user (ST12). The signature management server 21 receives a request for issuance of an electronic certificate from the user PC 4 via the communication interface 56. Here, the processor 51 of the signature management server 21 may be configured to confirm that the currently logged-in user has the authority to request the issuance of an electronic certificate. In this case, the processor 51 may be configured to accept the request for issuance of an electronic certificate from the currently logged-in user if the currently logged-in user has the authority to request key generation.

[0049] When the processor 51 of the signature management server 21 receives a request to issue a digital certificate, it requests the HSM 22 connected to the interface 55 to generate and store key information (ST13). The HSM 22 generates the user's key information in response to the request from the processor 51. After generating the user's key information in response to the request from the signature management server 21, the HSM 22 stores the generated key information in a secure memory within the HSM 22.

[0050] For example, the HSM 22 generates a private key and a public key paired with the private key as key information of the user. After generating a key pair of the public key and the private key, the HSM 22 stores the generated key pair in a secure memory within the HSM 22 in association with a user ID (or a key ID associated with the user ID). This allows the HSM 22 to securely store the user's key information, and makes it possible to perform arithmetic processing such as digital signatures using the private key within the HSM 22 without outputting the private key included in the key information to an external device.

[0051] In the signature management system 2, the HSM 22 stores the generated user key information and then outputs the public key from the stored (generated) key information to the signature management server 21. When the processor 51 of the signature management server 21 acquires the public key from the key information generated by the HSM 22, it requests the CA server 31 of the CA system 3 to issue an electronic certificate for the public key (ST14). The processor 51 of the signature management server 21 connects to the CA server 31 via the communication interface 57 and transmits a request to the CA server 31 to issue an electronic certificate for the public key.

[0052] The CA server 31 receives a request for issuing a digital certificate for the public key from the signature management server 21 via the communication interface 67. When the processor 61 of the CA server 31 accepts the request for issuing a digital certificate, it performs processing to issue a digital certificate for the public key for which the issuance request has been received (ST15).

[0053] For example, the processor 61 of the CA server 31 requests the HSM 32 connected to the interface 65 to issue a digital certificate for the public key using the CA's key information. In response to the request from the processor 61, the HSM 32 generates a digital certificate (public key certificate) for the public key acquired from the signature management server 21 using the CA's own key information. When the HSM 32 generates the public key certificate, the CA server 31 transmits the public key certificate generated by the HSM 32 to the signature management server 21 (ST16).

[0054] The signature management server 21 receives the digital certificate for the public key issued (generated) from the CA server 31 via the communication interface 57. The processor 51 of the signature management server 21 transmits the digital certificate for the public key issued by the CA server 31, obtained from the CA server 31, to the user PC4 (ST17). In response to a request for issuance of a digital certificate from the user PC4, the signature management server 21 can thereby have the CA server 31 issue a digital certificate for the public key corresponding to the user's private key stored in the HSM 22, and provide it to the user PC4.

[0055] After requesting the issuance of an electronic certificate, the user PC4 receives the electronic certificate for the public key issued by the CA server 31 from the signature management server 21. The user PC4 stores the electronic certificate for the public key obtained from the signature management server 21 in memory (ST18). When the user PC4 receives the electronic certificate for the public key from the signature management server 21, it becomes able to receive an electronic signature from the signature management server 21.

[0056] After the user PC 4 saves the public key certificate (after the certificate is ready to receive a digital signature), the user PC 4 designates the digital data to be signed with the digital signature (ST21). For example, the user creates a document such as a contract on the user PC 4, and designates the document data or image data of the created document as the digital data to be signed with the digital signature.

[0057] When the electronic data to be signed is designated, the user PC4 requests the signature management server 21 to generate an electronic signature for the electronic data to be signed (ST22). Here, it is assumed that the user operating the user PC4 is logged in to the signature management server 21. If the user to be the signer is not logged in to the signature management server 21, it is assumed that the electronic signature is requested when the user operating the user PC4 is logged in by executing the login process as described in ST11.

[0058] The signature management server 21 receives a request for generation of an electronic signature from the currently logged-in user from the user PC 4 via the communication interface 56. Here, the processor 51 of the signature management server 21 may be configured to confirm that the currently logged-in user has the authority to request an electronic signature. In this case, the processor 51 accepts the request for an electronic signature from the currently logged-in user if the currently logged-in user has the authority to request an electronic signature.

[0059] When the processor 51 of the signature management server 21 accepts a signature request from the currently logged-in user, it requests the HSM 22 connected to the interface 55 to generate an electronic signature (ST23). In response to the request from the processor 51, the HSM 22 generates an electronic signature for the electronic data to be signed using the private key of the currently logged-in user. The HSM 22 returns the electronic data to which the electronic signature has been added using the private key of the currently logged-in user to the signature management server 21.

[0060] When the processor 51 of the signature management server 21 acquires the electronic signature generated by the HSM 22, it transmits the electronic data to which the electronic signature generated by the HSM 22 has been attached to the user PC 4 (ST24). Here, the processor 51 of the signature management server 21 may store log data indicating that the electronic signature has been executed or may notify a preset notification destination.

[0061] Note that the user PC 4 may receive a notification from the signature management server 21 indicating that the key pair generation has been completed based on the request for issuance of the digital certificate, and may transmit a signature generation to the signature management server 21. In this case, the signature management server 21 transmits the data to which the digital signature has been attached and the digital certificate received from the CA server 31 together to the user PC 4. In other words, the digital certificate issued by the CA server 31 only needs to be issued by the time the verifier verifies the digital certificate.

[0062] For example, when the processor 51 of the signature management server 21 affixes a digital signature to electronic data in response to a signature request from a user, the processor 51 generates log data indicating the processing details. The processor 51 of the signature management server 21 requests the HSM 22 to affix a digital signature to the log data (a digital signature using the user's private key), and stores the signed log data generated by the HSM 22 in a storage device such as the data memory 64. This allows the signature management server 21 to store the signed log data indicating the processing details.

[0063] Furthermore, when an electronic signature is issued, the processor 51 of the signature management server 21 may notify a pre-set destination of the details of the processing. For example, the processor 51 sends an email indicating the details of the processing to an email address set in the user information of the user who requested the electronic signature. This allows the destination set in the user information to understand the details of the processing performed using the signature system 1.

[0064] After requesting a digital signature, the user PC 4 obtains the digitally signed electronic data from the signature management server 21. Here, the user designates the verifier PC 5 as the destination of the digitally signed electronic data in the user PC 4. The user PC 4 transmits the digitally signed electronic data and the digital certificate of the public key used to verify the digital signature to the verifier PC 5 designated by the user as the destination (ST25).

[0065] The verifier PC 5 receives electronic data with an electronic signature and an electronic certificate of the public key from the user PC 5. Here, when using the signature system 1, the verifier PC 5 is assumed to trust the CA system 3. When verifying an electronic signature generated by the signature management system 2, the verifier PC 5 obtains a CA certificate published by the CA server 31 (ST30). The verifier PC installs the CA certificate obtained from the CA server 31 in memory (ST31), and is set in a state where it can verify the electronic certificate using the CA certificate.

[0066] When the verifier PC5 receives from the user PC4 a digital certificate of the public key issued by the CA server 31, it verifies the digital certificate of the public key using the CA certificate installed in advance (ST32). The verifier PC5 verifies the digital certificate of the public key received from the user PC4 using the CA certificate, thereby confirming the legitimacy of the public key. That is, the verifier PC5 obtains a public key whose legitimacy has been confirmed by verifying the digital certificate. Upon obtaining the public key whose legitimacy has been confirmed by verifying the digital certificate, the verifier PC5 uses the public key whose legitimacy has been confirmed to be valid to verify the digital signature attached to the electronic data (ST33). This allows the verifier operating the verifier PC5 to confirm whether the electronic data received from the user PC4 is electronic data signed by the user.

[0067] As described above, according to the first operation example, the signature management server generates and stores a key pair of a private key and a public key as key information for each user. When the signature management server generates key information, it requests a CA (certificate authority) server to issue a digital certificate for the public key of the generated key information. The signature management server provides the user with the digital certificate for the public key issued by the CA server and accepts a digital signature from the user. In response to a signature generation request from the user, the signature management server generates a digital signature using the private key as key information stored for each user, and provides electronic data with the digital signature attached.

[0068] This allows the signature management server to not only securely store the private key used for the digital signature, but also seamlessly (without user operation) have the CA issue a digital certificate for the public key corresponding to the private key. As a result, users can affix digital signatures to digital data without having to manage the private key themselves, and can also present a digital certificate for the public key that proves the legitimacy of the digital signature to a verifier who presents the digital data to which the digital signature has been affixed.

[0069] For example, when a user (signer) of a user PC and a verifier of a verifier PC exchange a contract, which is an electronic document (electronic data), the validity of the electronic signature affixed to the contract can be mutually verified using a digital certificate issued by a certification authority (CA), even if the signer and verifier belong to different companies. In other words, the verifier can verify the digital certificate issued by a trusted certification authority and can verify the digital signature received from the signer using the public key whose authenticity has been confirmed by verifying the digital certificate.

[0070] Furthermore, if a malicious third party posing as a legitimate user generates a fake key pair and sends a fake contract with a digital signature attached using the fake private key and a fake public key to a verifier, the verifier may believe the fake contract in order to verify the digital signature using the fake public key. Even in such a case, the signature system according to this embodiment can present the verifier with a digital certificate of the true user's public key issued by a certification authority, rather than the public key itself. In other words, the signature system allows the verifier to verify the validity of the public key using the digital certificate issued by the certification authority, assuming that the certification authority is trustworthy, and prevents the verifier from verifying the digital signature using a fake public key.

[0071] Next, a second operation example of data processing including a digital signature by the signature management server 21 in the signature system 1 according to this embodiment will be described. FIG. 6 is a sequence diagram illustrating a second operation example of data processing including a digital signature by the signature management server 21 in the signature system 1 according to this embodiment. In the second operation example, the user PC 4 and the signature management server 21 of the signature management system 2 perform a login process (user authentication) for the user to log in to the signature system 1 from the user PC 4 (ST51), similar to the first operation example described above.

[0072] If the user authentication is successful, the processor 51 of the signature management server 21 accepts a processing request (request) from the user PC 4. When the user PC4 successfully logs in to the signature management server 21, the user PC4 requests the signature management server 21 to issue an electronic certificate (generate a key pair) for implementing an electronic signature (ST52).

[0073] The signature management server 21 receives a request for issuing an electronic certificate from the user PC 4 via the communication interface 56. Upon receiving the request for issuing an electronic certificate, the processor 51 of the signature management server 21 generates and stores key information for the user (ST53). The processor 51 of the signature management server 21 causes the HSM 22 to generate and store the key information, similar to ST13 described above.

[0074] When the processor 51 of the signature management server 21 acquires the public key from the key information generated by the HSM 22, it requests the CA server 31 of the CA system 3 to issue a digital certificate for the public key (ST54).

[0075] The CA server 31 receives the request for issuing a digital certificate for the public key from the signature management server 21 via the communication interface 67. Upon receiving the request for issuing a digital certificate, the processor 61 of the CA server 31 issues (generates) and stores the digital certificate for the public key (ST55).

[0076] For example, the processor 61 of the CA server 31 requests the HSM 32 to issue a digital certificate for the public key obtained from the signature management server 21. In response to the request from the processor 61, the HSM 32 generates a digital certificate for the public key (public key certificate) using the CA's own key information. The processor 61 of the CA server 31 stores the digital certificate for the public key generated by the HSM 32 in the data memory 64. The processor 61 of the CA server 31 makes public the digital certificate for the issued public key stored in the data memory 64.

[0077] Furthermore, after storing the digital certificate in the data memory 64, the processor 61 of the CA server 31 notifies the signature management server 21 of information indicating that the digital certificate has been issued, without transmitting the issued digital certificate itself (ST56). Here, the processor 61 of the CA server 31 may notify the signature management server 21 of information for identifying the issued digital certificate (for example, a serial number specified in the digital certificate) together with the notification of completion of issuance of the digital certificate.

[0078] When the processor 51 of the signature management server 21 receives notification from the CA server 31 that a public key digital certificate has been issued, the processor 51 notifies the user PC4 that the public key digital certificate has been issued (or that the public key digital certificate has been made public by the CA server 31) (ST57). This enables the signature management server 21 to notify the user PC4 that the CA server 31 has issued the digital certificate requested by the user PC4.

[0079] When the user PC 4 receives the digital certificate for the public key from the signature management server 21, the user PC 4 is ready to receive a digital signature from the signature management server 21. After the user PC 4 receives the notification of issuance of the digital certificate for the public key (after the user PC 4 is ready to receive a digital signature), the user PC 4 specifies the digital data (document) to be signed with the digital signature (ST61). For example, the user creates a document such as a contract on the user PC 4, and specifies the document data or image data of the created document as the digital data to be signed with the digital signature.

[0080] When the user designates the electronic data to be signed, the user PC 4 requests the signature management server 21 to generate an electronic signature for the electronic data to be signed (ST62). Here, it is assumed that the user operating the user PC 4 is logged in to the signature management server 21.

[0081] When the processor 51 of the signature management server 21 accepts a signature request from the currently logged-in user, it executes a process of attaching a digital signature to the electronic data to be signed from the user PC 4 (ST63). For example, the processor 51 of the signature management server 21 requests the HSM 22 connected to the interface 55 to generate a digital signature. In response to the request from the processor 51, the HSM 22 attaches a digital signature to the electronic data to be signed using the private key of the currently logged-in user, and returns the digital data with the attached digital signature to the signature management server 21.

[0082] When the processor 51 of the signature management server 21 acquires the digital signature generated by the HSM 22, it transmits the digital data to which the digital signature generated by the HSM 22 has been attached to the user PC 4 (ST64). Here, the processor 51 of the signature management server 21 may store log data indicating that the digital signature has been executed or may notify a preset notification destination, as in the first operation example.

[0083] When the user PC 4 acquires the electronic data to which the electronic signature has been added from the signature management server 21, it transmits the electronic data to which the electronic signature has been added to the verifier PC 5 (ST65). Here, the user PC 4 may transmit to the verifier PC 5, together with the electronic data to which the electronic signature has been added, information that uniquely identifies the electronic certificate of the public key for verifying the electronic signature (for example, the serial number of the electronic certificate).

[0084] The verifier PC 5 receives the electronic data with the digital signature from the user PC 5. Here, as in the first operation example described above, the verifier PC 5 acquires the CA certificate published by the CA server 31 (ST70) and installs the acquired CA certificate in memory (ST71).

[0085] When the verifier PC5 receives electronic data with a digital signature from the user PC4, it executes a process to obtain a digital certificate of the public key of the user who signed the digital signature from the CA server 31. Here, it is assumed that the CA server 31 has published issued digital certificates including a digital certificate of the public key of the user who signed the digital signature.

[0086] The verifier PC 5 sets search information for identifying the digital certificate of the public key of the user who is the signer from among the issued digital certificates stored (published) by the CA server 31. A first example of search information for identifying the digital certificate of the signatory user's public key is to set the serial number (identification information) specified in the digital certificate. The digital certificate serial number is an example of information that can uniquely identify a digital certificate from among issued digital certificates.

[0087] However, when the serial number of the electronic certificate is set as search information, the serial number of the electronic certificate for the user's public key issued by the CA server 31 must be transmitted from the user PC 4 to the verifier PC 5. For example, the user PC 4 can obtain and store the serial number of the electronic certificate for the user's public key issued by the CA server 31 via the signature management server 21, and transmit the serial number of the electronic certificate to the verifier PC 5 together with the electronic data to which the electronic signature has been attached.

[0088] As a second example of search information for identifying the digital certificate of the public key of the user who is the signer, information contained in the CommonName information of the digital certificate may be set as the search information. The CommonName information of the digital certificate generally stores information (user identification information) that identifies the user as the signer, such as the user name, company name, or group name. Since user identification information such as the user name is clearly information about the sender of the digital signature, it does not need to be separately transmitted from the user PC 4 to the verifier PC 5, and it becomes possible to search for the digital certificate of the public key of the user who is the signer from the digital certificates published by the CA server 31.

[0089] However, user identification information such as a user name or company name may not be enough to uniquely identify an electronic certificate, resulting in the search for multiple electronic certificates. In such cases, the verifier PC5 may need to select an electronic certificate of a public key to be used to verify the electronic signature from the multiple searched electronic certificates. Furthermore, to prevent the provision of a false electronic certificate with a false CommonName, the signature management server 21 must perform user authentication with high accuracy, and information transmission between the signature management server 21 and the CA server 31 must be secure, so that user information can be accurately transmitted from the signature management server 21 to the CA server 31.

[0090] After setting the search information for identifying the public key digital certificate, the verifier PC sends a search request for the digital certificate using the search information to the CA server 31 (ST72). The processor 61 of the CA server 31 receives the search request from the verifier PC 5 and searches for issued digital certificates using the search information specified in the search request. The processor 61 provides the digital certificate identified by the search information to the verifier PC that sent the search request (ST73).

[0091] When the verifier PC5 receives the digital certificate of the public key from the CA server 31, it verifies the digital certificate of the public key using the CA certificate that was previously installed (ST74). The verifier PC5 confirms the legitimacy of the public key of the signer user by verifying the digital certificate of the public key received from the CA server 31 with the CA certificate. As a result, the verifier PC5 obtains the public key of the signer user whose legitimacy has been confirmed.

[0092] When the verifier PC5 obtains the public key of the signer whose legitimacy has been confirmed by verifying the digital certificate, it verifies the digital signature attached to the digital data using the public key whose legitimacy has been confirmed (ST75). This allows the verifier operating the verifier PC5 to confirm whether the digital signature attached to the digital data received from the user PC4 is the legitimate signature of the user.

[0093] As described above, according to the second operation example, the signature management server generates and stores a key pair of a private key and a public key as key information for each user. When the signature management server generates key information, it requests a CA (certificate authority) server to issue and store an electronic certificate for the public key of the generated key information. The CA server stores and publishes the electronic certificate for the issued user's public key. When the CA server issues an electronic certificate for the user's public key, the signature management server accepts an electronic signature from that user. In response to a signature generation request from a user, the signature management server generates an electronic signature using the private key as key information stored for that user, and provides electronic data with the electronic signature attached.

[0094] This allows the signature management server to securely store the private key used for the electronic signature, and allows the CA to issue and store the digital certificate of the public key corresponding to the private key. Furthermore, the user does not need to transmit the digital certificate for verifying the electronic signature to the verifier, and the verifier can obtain the digital certificate as needed. As a result, the user can present the verifier with electronic data affixed with a digital signature whose authenticity can be verified using the digital certificate published by the CA, without the user having to manage the private key themselves.

[0095] The functions described in the above embodiments can be realized not only by hardware but also by software by loading a program describing each function into a computer. Furthermore, each function may be realized by selecting either software or hardware as appropriate.

[0096] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, and are also included in the scope of the invention and its equivalents as defined in the claims. [Explanation of symbols]

[0097] 1...signature system, 2...signature management system, 3...CA (certification authority) system, 11...HSM, 21...signature management server (signature management device), 22...HSM, 31...CA server (certification authority device), 32...HSM, 51...processor (first processor), 54...data memory, 55...interface, 56...communication interface (first communication unit), 57...communication interface (second communication unit), 61...processor (second processor), 64...data memory (memory), 65...interface, 66...communication interface (third communication unit), 67...communication interface (fourth communication unit).

Claims

1. a first communication unit that communicates with a user device operated by a user; a second communication unit that communicates with a certification authority that issues a digital certificate; an interface for connecting to a secure device that stores a private key used to generate an electronic signature to be attached to electronic data from the user; a processor that requests the certificate authority to issue a digital certificate for a public key corresponding to the private key stored in the secure device, and that affixes a digital signature to the digital data from the user using the private key stored in the secure device; A signature management device having:

2. the processor affixes a digital signature to the electronic data from the user using a private key stored in the secure device after the certificate authority issues a digital certificate for the public key; The signature management device according to claim 1 .

3. the secure device is an HSM that generates the public key and the private key and securely stores the private key; The signature management device according to claim 1 or 2.

4. The processor: When a request for issuing a digital certificate is received from the user device, the HSM generates the public key and the private key, and transmits a digital certificate for the public key issued by the certification authority to the user device; When the HSM receives the electronic data to which a digital signature is to be added from the user device, the HSM adds a digital signature generated by using the private key to the electronic data and transmits the digital data to the user device. The signature management device according to claim 3 .

5. The processor: When a request for issuance of a digital certificate is received from the user device, the HSM generates the public key and the private key, and requests the certification authority to issue a digital certificate for the public key that is to be made public to the certification authority; When the HSM receives the electronic data to which a digital signature is to be added from the user device, the HSM adds a digital signature generated by using the private key to the electronic data and transmits the digital data to the user device. The signature management device according to claim 3 .

6. In a signature system including a signature management device and a certificate authority device, The signature management device a first communication unit that communicates with a user device operated by a user; a second communication unit that communicates with the certificate authority device; an interface for connecting to a secure device that stores a private key used to generate an electronic signature to be attached to electronic data from the user; a first processor that requests the certificate authority device to issue a digital certificate for a public key corresponding to the private key stored in the secure device, and that affixes a digital signature to electronic data from the user using the private key stored in the secure device; The certificate authority device a third communication unit that communicates with an information processing device operated by a verifier who verifies the digital certificate; a fourth communication unit that communicates with the signature management device; a second processor that issues a digital certificate for the public key in response to a request from the signature management device; Signature system.

7. the secure device of the signature management device is an HSM that generates the public key and the private key and securely stores the private key; The signature system of claim 6.

8. The first processor of the signature management device When a request for issuing a digital certificate is received from the user device, the HSM generates the public key and the private key, and transmits the digital certificate for the public key issued by the certification authority device to the user device; When the HSM receives the electronic data to which a digital signature is to be added from the user device, the HSM adds a digital signature generated by using the private key to the electronic data and transmits the digital data to the user device. The signature system of claim 7.

9. The first processor of the signature management device When a request for issuance of a digital certificate is received from the user device, the HSM generates the public key and the private key, and requests the certificate authority device to issue a digital certificate for the public key that is to be made public to the certificate authority device; When the HSM receives the electronic data to which a digital signature is to be added from the user device, the HSM adds a digital signature generated by using the private key to the electronic data and transmits the digital data to the user device. The certificate authority device a memory for storing the issued digital certificate; the second processor of the signature management device stores the electronic certificate issued in response to a request from the signature management device in the memory, identifies an electronic certificate designated by the information processing device from among the electronic certificates stored in the memory based on search information designated by the information processing device communicating via the third communication unit, and provides the identified electronic certificate to the information processing device. The signature system of claim 7.

Citation Information

Patent Citations

  • Key management system, signing device, method for managing key, and program

    JP2021040278A