Verification system, inventory management system, program, verification method, and inventory management method
The verification system uses public key cryptography to ensure the authenticity and integrity of product data, addressing the challenge of counterfeit detection and improving inventory management by verifying and managing only genuine products.
Patent Information
- Application Number
- JP2024052720
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-28
- Publication Date
- 2025-10-09
AI Technical Summary
Existing systems struggle to verify the authenticity of products and ensure that authenticity determination data has not been tampered with, especially in the context of e-commerce where distinguishing genuine products from counterfeits is crucial.
A verification system utilizing public key cryptography to verify authenticity determination data, including an encrypted data acquisition, decryption, and verification data generation process, ensuring the data is obtained using a predetermined method and has not been tampered with, and an inventory management system to manage only verified authentic products.
Enhances the reliability of authenticity determination data by verifying its integrity and reduces computational and human resources, allowing for secure and efficient inventory management of genuine products.
Smart Images

Figure 2025151345000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a verification system, an inventory management system, a program, a verification method, and an inventory management method. [Background technology]
[0002] Patent Document 1 describes the information processing method as follows: "An information processing device executes a product information acquisition step in which an information processing device acquires product identification information capable of identifying the product to be matched from a serial code attached to the product to be matched or image information of the product to be matched; an optical image acquisition step in which an optical image information relating to an optical image obtained from a fine line pattern attached to the product to be matched; and a matching step in which an information processing device generates a matching result by matching the acquired optical image information with correct answer information relating to a correct answer label of the optical image corresponding to the product identification information." [Prior art document] [Patent Documents] [Patent Document 1] International Publication No. 2022 / 054869 Summary of the Invention
[0003] In a first aspect of the present invention, a verification system is provided that includes an encrypted data acquisition unit that acquires encrypted data containing product authenticity determination data and encrypted using a private key; a decryption unit that generates first decrypted data by decrypting the encrypted data acquired by the encrypted data acquisition unit using a first public key that corresponds to the private key; an authenticity determination data output unit that outputs at least a portion of the authenticity determination data included in the first decrypted data; a verification data request receiving unit that receives a request for verification data from a user terminal used by a user of the authenticity determination data, the verification data indicating that the authenticity determination data is data obtained using a predetermined authenticity determination method; and a verification data output unit that outputs the verification data to the user terminal.
[0004] The verification data request receiving unit may acquire a second public key corresponding to the private key from the user terminal, and the decryption unit may generate second decrypted data by decrypting the encrypted data with the second public key.
[0005] Any of the above verification systems may further comprise a verification data generation unit configured to generate verification data, the verification data generation unit may generate the verification data based on the first decrypted data and the second decrypted data.
[0006] The verification data generation unit may compare the authenticity determination data contained in the first decrypted data with the authenticity determination data contained in the second decrypted data, and if the two match, generate verification data indicating that the authenticity determination data is data obtained by a predetermined authenticity determination method.
[0007] The encrypted data acquisition unit may acquire the encrypted data from an authenticity determination device that determines the authenticity of a product by reading an anti-counterfeit label attached to the product.
[0008] Any of the above verification systems may further comprise a private key output unit that outputs the private key to the authenticity determination device.
[0009] Any of the above verification systems may further comprise a public key output unit that outputs the second public key to the user terminal.
[0010] Any of the above verification systems may further comprise a key generation unit that generates at least one of a private key, a first public key, and a second public key.
[0011] The authenticity determination data may include at least one of the result of authenticating the product, the authenticity determination device that performed the authenticity determination, the owner of the authenticity determination device, the date and time the authenticity determination was performed, and information about the product.
[0012] User terminals may include terminals used by product sellers, product manufacturers, and / or product distributors.
[0013] In any of the above verification systems, at least one of the encrypted data, the first decrypted data, the second decrypted data, and the verification data may be recorded on a ledger on a blockchain network.
[0014] Any of the above verification systems may further include a recipient registration unit that registers a recipient of verified authenticity determination data that has been shown to be data obtained by a predetermined authenticity determination method, an anonymization unit that generates anonymized data by anonymizing the verified authenticity determination data, and an anonymized data output unit that outputs the anonymized data to a terminal used by the recipient.
[0015] In a second aspect of the present invention, an inventory management system is provided, which includes a verification data acquisition unit that acquires verification data output by any of the above-mentioned verification systems, an inventory permission data generation unit that generates inventory permission data for products whose authenticity determination data is indicated by the verification data to be data obtained by a predetermined authenticity determination method, and an inventory registration unit that registers the products for which inventory permission data has been generated as inventory.
[0016] In a third aspect, the present invention provides a program that, when executed by a computer, causes the computer to function as any one of the above verification systems.
[0017] In a fourth aspect of the present invention, there is provided a program that, when executed by a computer, causes the computer to function as the above-described inventory management system.
[0018] In a fifth aspect of the present invention, a verification method is provided in which any of the above verification systems executes an encrypted data acquisition step of acquiring encrypted data containing product authenticity determination data and encrypted with a private key; a decryption step of generating first decrypted data by decrypting the encrypted data acquired in the encrypted data acquisition step with a first public key corresponding to the private key; an authenticity determination data output step of outputting at least a portion of the authenticity determination data included in the first decrypted data; a verification data request acceptance step of accepting a request for verification data from a user terminal used by the user of the authenticity determination data, the verification data indicating that the authenticity determination data is data obtained by a predetermined authenticity determination method; and a verification data output step of outputting the verification data to the user terminal.
[0019] In a sixth aspect of the present invention, an inventory management method is provided in which the above-mentioned inventory management system executes a verification data acquisition stage in which it acquires verification data output by any of the above-mentioned verification systems, an inventory entry permission data generation stage in which it generates inventory entry permission data for products whose authenticity determination data is shown by the verification data to be data obtained by a predetermined authenticity determination method, and an inventory registration stage in which it registers the products for which inventory entry permission data has been generated as inventory.
[0020] The above summary of the invention does not list all of the features of the present invention, and subcombinations of these features may also be inventions. [Brief explanation of the drawings]
[0021] [Figure 1] 1 shows an example of an authenticity determination system 10 according to this embodiment. [Figure 2] 2 shows another example of the authenticity determination system 10 of this embodiment. [Figure 3] 1 shows an example of a processing flow of a method in the verification system 100 of this embodiment. [Figure 4] An example of the authenticity determination data 900 is shown. [Figure 5A]1 shows an example of comparison data 1000 between the authentication data included in the first decoded data and the authentication data included in the second decoded data. [Figure 5B] 11 shows an example of comparison data 1100 between the authentication data included in the first decoded data and the authentication data included in the second decoded data. [Figure 6] An example of verified authenticity determination data 1200 is shown below. [Figure 7] 10 shows a modified example of the processing flow of the method in the verification system 100 of this embodiment. [Figure 8] An example of anonymized data 1300 is shown. [Figure 9] 10 shows an example of a processing flow of a method in the inventory management system 800 of this embodiment. [Figure 10] 22 illustrates an example computer 2200 in which aspects of the present invention may be embodied, in whole or in part. DETAILED DESCRIPTION OF THE INVENTION
[0022] The present invention will be described below through embodiments of the invention, but the following embodiments do not limit the scope of the invention according to the claims. Furthermore, not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention.
[0023] 1 shows an example of an authenticity determination system 10 according to this embodiment. The authenticity determination system 10 includes a verification system 100, a user terminal 500 used by a user 400 (sometimes simply referred to as a "user") who uses authenticity determination data, and an authenticity determination device 700 used by a distributor or the like 600 (sometimes simply referred to as a "distributor or the like") who performs product authenticity determination.
[0024] The verification system 100 verifies that the product authenticity determination data is data acquired by a predetermined authenticity determination method, and outputs the verification result to the user.
[0025] In the verification system 100 of this embodiment, a product refers to an item manufactured for sale. The product may be, for example, a bag, a wallet, clothing, cosmetics, jewelry, ceramics, watches, food, etc. The product may be a high-priced product such as a brand-name product. In particular, this embodiment may target products that may be counterfeited (e.g., high-priced and / or highly recognized products by consumers). In this specification, the term "product" refers to a single and / or multiple items.
[0026] As the sale of products via e-commerce expands, there are cases where authenticity determination is performed to distinguish and remove unauthorized products from genuine products during the product distribution process. For example, highly reliable authenticity determination can be achieved by using an authenticity determination method that uses an authenticity determination label that is difficult to counterfeit.
[0027] On the other hand, even if the authenticity determination data was obtained using a highly reliable authenticity determination method, it is difficult to prove that the data itself has not been tampered with and that the authenticity determination data was obtained using that highly reliable authenticity determination method.
[0028] Therefore, the verification system 100 of this embodiment verifies the authenticity determination data using public key cryptography to verify that the authenticity determination data has not been tampered with and that the authenticity determination data was obtained using a predetermined authenticity determination method. Furthermore, the inventory management system 800 of this embodiment grants storage permission to only products that have been determined to be authentic using the verified authenticity determination data by the verification system 100, and manages them as inventory.
[0029] The verification system 100 of this embodiment includes an input unit 110 , a storage unit 120 , a display unit 130 , a communication unit 140 , and a calculation unit 200 .
[0030] The input unit 110 inputs necessary information and / or instructions to the calculation unit 200. The input unit 110 may be an input device such as a keyboard or a mouse connected to the calculation unit 200. The input unit 110 may input information and / or instructions via communication with an external terminal or the like, but is not limited to this.
[0031] The storage unit 120 stores information input by the input unit 110, information processed by the calculation unit 200, etc. The storage unit 120 may store encrypted data, first decrypted data, second decrypted data, verification data, etc. The storage unit 120 may be a storage device such as a memory or a hard disk. The storage unit 120 may be called by the calculation unit 200 and provide the stored data to the calculation unit 200 as needed.
[0032] The display unit 130 displays the processing results of the calculation unit 200. As an example, the display unit 130 may be an output device such as a monitor connected to the calculation unit 200, but is not limited to this.
[0033] The communication unit 140 is connected to a user terminal 500 used by a user 400 and an authenticity determination device 700 used by a distributor or the like 600 via a network 300 such as the Internet.
[0034] The user 400 is a person who uses the authenticity determination data for the product. The user 400 may be a person included in the supply chain of the product, such as a seller of the product, a manufacturer of the product, and / or a distributor of the product.
[0035] The user 400 may use the authenticity determination data to manage inventory, deliver, sell, etc. For example, the user 400 may use the authenticity determination data to distinguish and remove counterfeit products from genuine products during the product distribution process and inventory.
[0036] The distributors 600 may be, for example, distributors, manufacturers, sellers, etc. that perform product authenticity determination. The distributors 600 may perform authenticity determination at a product distribution center, or may perform authenticity determination on products before shipping to the distribution center. The distributors 600 may also perform authenticity determination on products managed as inventory. The distributors 600 may perform authenticity determination using an authenticity determination device 700.
[0037] The authenticity determination device 700 is a device that determines whether a product is genuine or counterfeit and generates authenticity determination data. The authenticity determination device 700 may be an authenticity determination device that performs product authenticity determination by reading an anti-counterfeiting label attached to the product. The authenticity determination device 700 may encrypt the authenticity determination data using a private key described below. The authenticity determination device 700 may also have a communication function and be directly connected to the network 300 to output the encrypted data to the verification system 100.
[0038] The anti-counterfeit label may be, for example, a high-definition pattern formed on a transparent film that has low visibility and is difficult to counterfeit. Information indicating that the product is genuine may be recorded in a predetermined manner on the high-definition pattern, and by reading the pattern and decoding the recorded information, it is possible to determine whether the product is genuine or a counterfeit. As an example, the anti-counterfeit label may be Akliteia (registered trademark) manufactured by Asahi Kasei.
[0039] The calculation unit 200 is connected to the input unit 110, the storage unit 120, the display unit 130, and the communication unit 140, and executes processes such as generating verification data based on information acquired via the input unit 110 and the communication unit 140. The calculation unit 200 is a computer. The calculation unit 200 may be provided in a single computer, or each function may be distributed across multiple computers.
[0040] The calculation unit 200 may include a key generation unit 205, a private key output unit 210, a public key output unit 215, an encrypted data acquisition unit 220, a decryption unit 225, an authenticity determination data output unit 230, a verification data request reception unit 235, a verification data generation unit 240, a verification data output unit 245, a provided person registration unit 250, an anonymization unit 255, and an anonymized data output unit 260.
[0041] The key generation unit 205 generates at least one of a private key, a first public key, and a second public key for the product authentication data. The private key and the first and second public keys are generated in pairs and are used to encrypt and decrypt the authentication data. Details of the private key, the first public key, and the second public key will be described later.
[0042] The private key output unit 210 outputs the private key generated by the key generation unit 205 to the authenticity determination device 700. The private key is used to encrypt product authenticity determination data in the authenticity determination device 700. By outputting the private key to the authenticity determination device 700 that performs the authenticity determination, the authenticity determination data can be encrypted in the authenticity determination device 700. This makes it possible to prevent tampering with the authenticity determination data.
[0043] The public key output unit 215 outputs the second public key to the user terminal 500. The second public key is used to decrypt the encrypted data obtained from the authenticity determination device 700 and generate second decrypted data.
[0044] The user terminal 500 is a terminal used by a user 400 of the product authenticity determination data. The user terminal 500 may be one or more of a terminal used by a product seller, a terminal used by a product manufacturer, and / or a terminal used by a product distributor in the product supply chain.
[0045] The encrypted data acquisition unit 220 acquires encrypted data that has been encrypted with a private key in the authenticity determination device 700. The encrypted data acquisition unit 220 may acquire the encrypted data from the authenticity determination device 700 via the network 300.
[0046] The decryption unit 225 decrypts the encrypted data acquired by the encrypted data acquisition unit 220 using the first public key corresponding to the private key to generate first decrypted data. Details of the first decrypted data will be described later.
[0047] The authenticity determination data output unit 230 outputs at least a part of the authenticity determination data included in the first decrypted data. The authenticity determination data output unit 230 may output at least a part of the authenticity determination data to the user terminal 500. From the authenticity determination data acquired by the user terminal 500, the user 400 can understand the occurrence status of counterfeit products related to their company.
[0048] The verification data request receiving unit 235 receives a request for verification data from the user terminal 500. The verification data is data indicating that the authenticity determination data is indeed authenticity determination data obtained by a predetermined authenticity determination method. The verification data is also data indicating that the authenticity determination data has not been tampered with. The user 400 may request verification data from the verification system 100 to obtain verification data for the authenticity determination data.
[0049] When receiving a request for verification data, the verification data request receiving unit 235 may obtain a second public key from the user terminal 500. The second public key is an encryption key made public to the user 400, and is used by the verification data generating unit 240 to generate verification data.
[0050] The verification data generation unit 240 generates verification data based on the first decrypted data and the second decrypted data. The verification data is data indicating that the authenticity determination data is data acquired by a predetermined authenticity determination method and has not been tampered with. The verification data generation unit may compare the authenticity determination data included in the first decrypted data with the authenticity determination data included in the second decrypted data, and generate verification data if the two match. Details of the verification data will be described later.
[0051] The verification data output unit 245 outputs the verification data to the user terminal 500. By acquiring the verification data, the user 400 can obtain verification data that indicates that the authenticity determination data is indeed the authenticity determination data acquired by a predetermined authenticity determination method and has not been tampered with.
[0052] The verification system 100 of this embodiment allows the user 400 of the authenticity determination data to obtain authenticity determination data that has been verified to be data obtained using a predetermined authenticity determination method and has not been tampered with, thereby increasing the reliability of the authenticity determination data obtained by the authenticity determination device 700. In addition, the verification system 100 of this embodiment can reduce the computational and human resources consumed in verifying the authenticity determination data.
[0053] The verification system 100 may further include a provided item registration unit 250, an anonymization unit 255, and an anonymized data output unit 260. When the user 400 and the distributor 600 share authenticity determination data with each other within the product industry, the provided item registration unit 250, the anonymization unit 255, and the anonymized data output unit 260 anonymize the authenticity determination data, thereby enabling the sharing of the occurrence status of counterfeit products within the product industry, etc., without disclosing information such as individual company names included in the authenticity determination data to other companies in the same industry.
[0054] The provided-person registration unit 250 registers a person who receives verified authenticity determination data that is shown to be data acquired by a predetermined authenticity determination method. A person who receives the authenticity determination data (sometimes simply referred to as a "recipient") may be a user 400 who has agreed to receive only anonymized information from among the information included in the authenticity determination data that may identify information about an individual company, and / or to provide to other provided persons only anonymized information from among the information included in the authenticity determination data acquired by the authenticity determination device 700 that may identify information about their own company.
[0055] The anonymization unit 255 generates anonymized data by anonymizing the verified authenticity determination data generated by the verification data generation unit 240. The information to be anonymized includes, from the information included in the authenticity determination data, information that identifies information about an individual company (for example, company name, product name from which the company can be identified, etc.).
[0056] The anonymized data output unit 260 outputs the anonymized data to the terminal used by the person receiving the data. The terminal used by the person receiving the data may be the user terminal 500 of the user 400 registered as the person receiving the data.
[0057] Since the verification system 100 of this embodiment further comprises a provided person registration unit 250, an anonymization unit 255, and an anonymized data output unit 260, the verification system 100 can share information about the occurrence of counterfeit goods within a product industry, such as within a supply chain, among multiple users 400 without disclosing information about the individual companies of the users 400.
[0058] Furthermore, this embodiment provides a program that is executed by a computer to cause the computer to function as the above-described verification system 100. The storage unit 120 may store the program.
[0059] 2 shows another example of the authenticity determination system 10 of this embodiment. The authenticity determination system 10 includes an inventory management system 800, a verification system 100, a user terminal 500, and an authenticity determination device 700.
[0060] The inventory management system 800 uses the verification data generated by the above-mentioned verification system 100 to grant inventory permission and register inventory for products whose authenticity determination data has been obtained using a predetermined authenticity determination method and verified to be tamper-free data.
[0061] The inventory management system 800 is a system that manages the incoming and outgoing status and inventory status of products. The inventory management system 800 may be provided in, for example, a product manufacturer, a seller, or a distributor, and in cases where the user 400 is a manufacturer, a seller, or a distributor, the inventory management system 800 may be provided in a user terminal 500.
[0062] The inventory management system 800 of this embodiment includes an input unit 810 , a storage unit 820 , a display unit 830 , a communication unit 840 , a verification data acquisition unit 850 , a warehousing permission data generation unit 860 , and an inventory registration unit 870 .
[0063] The input unit 810 inputs necessary information and / or instructions to the verification data acquisition unit 850, the warehousing permission data generation unit 860, and the inventory registration unit 870. The input unit 810 may be an input device such as a keyboard or a mouse connected to the inventory management system 800. The input unit 810 may input information and / or instructions via communication with an external terminal or the like, but is not limited to this.
[0064] The storage unit 820 stores information input by the input unit 810, information processed by the inventory management system 800, etc. The storage unit 820 may store verification data, warehousing permission data, and inventory registration data obtained from the verification system 100. The storage unit 820 may be a storage device such as a memory or a hard disk.
[0065] The display unit 830 displays the processing results of the inventory management system 800. As an example, the display unit 830 may be an output device such as a monitor, but is not limited to this.
[0066] The communication unit 840 is connected via the network 300 to the above-mentioned verification system 100, the user terminals 500 of other users 400, and the authenticity determination devices 700 used by other distributors 600, etc.
[0067] The verification data acquisition unit 850 acquires the verification data output by the verification system 100 .
[0068] The receiving permission data generating unit 860 generates receiving permission data for a product for which the verification data indicates that the authenticity determination data is data acquired by a predetermined authenticity determination method.
[0069] The inventory registration unit 870 registers the product for which receiving permission data has been generated as inventory. The verification data is data indicating that the authenticity determination data was obtained using a predetermined authenticity determination method. Therefore, the authenticity determination data for the product for which verification data has been generated has been obtained using a predetermined authenticity determination method (for example, an authenticity determination method using an anti-counterfeit label that is difficult to forge) and has been verified to have not been tampered with, so the authenticity determination data for that product is highly reliable. Therefore, by generating receiving permission data for that product using the inventory management system 800 of this embodiment, only genuine products can be registered as inventory.
[0070] Furthermore, in this embodiment, a program is provided that is executed by a computer to cause the computer to function as the above-described inventory management system 800. The program may be stored in the storage unit 820 of the inventory management system 800.
[0071] 3 shows an example of a processing flow of a method in the verification system 100 of this embodiment. By performing the processing flow from S1010 to S1190 in FIG. 3, the verification system 100 executes the following steps: an encrypted data acquisition step of acquiring encrypted data including product authentication data and encrypted with a private key; a decryption step of generating first decrypted data by decrypting the encrypted data acquired in the encrypted data acquisition step with a first public key corresponding to the private key; an authenticity determination data output step of outputting at least a part of the authenticity determination data included in the first decrypted data; a verification data request acceptance step of accepting, from a user terminal used by a user of the authenticity determination data, a request for verification data indicating that the authenticity determination data was acquired using a predetermined authenticity determination method; and a verification data output step of outputting the verification data to the user terminal.
[0072] For ease of explanation, the processes from S1010 to S1190 will be explained in order, but at least some of these processes may be executed in parallel, or the steps may be interchanged and executed as long as it does not deviate from the spirit of the present invention, or some steps may be omitted and executed as long as it does not deviate from the spirit of the present invention.
[0073] In the processing flow shown in FIG. 3, the verification system 100 executes a key generation step S1010, a private key output step S1020, a public key output step S1040, an encrypted data acquisition step S1100, a first decrypted data generation step S1110, a verification data request reception step S1150, a second decrypted data generation step S1160, a verification data generation step S1170, and a verification data output step S1180.
[0074] In the flow shown in Figure 3, first, in S1010, the key generation unit 205 generates a private key and a first public key and a second public key corresponding to the private key. The verification system 100 incorporates the private key into the authenticity determination device 700 and uses it to encrypt the authenticity determination data. The same private key may be generated for multiple models of authenticity determination devices 700, or a different private key may be generated for each model. Different private keys may also be generated between authenticity determination devices 700 of the same model.
[0075] The verification system 100 uses the first public key and the second public key to decrypt the encrypted data of the authenticity determination data in the decryption unit 225. The first public key and the second public key may be the same public key or different public keys. The first public key and the second public key may be different public keys for each user 400.
[0076] The key generation unit 205 may generate the private key, the first public key, and the second public key using a known method. For example, the key generation unit 205 may generate a pair of private and public keys using the RSA encryption method, the DSA encryption method, the ECDSA encryption method, or the like.
[0077] The private key, the first public key, and the second public key generated in S1010 may be stored in the storage unit 120. The verification system 100 may record at least one of the encrypted data, the first decrypted data, the second decrypted data, and the verification data on a ledger on the blockchain network.
[0078] After S1010, in S1020, the private key output unit 210 outputs the private key to the authenticity determination device 700. The private key output unit 210 may output the private key to the authenticity determination device 700 before handing over the authenticity determination device 700 to the distributor, etc. 600 that will perform the authenticity determination. In S1020, the private key output unit 210 may output the private key via the network 300 after handing over the authenticity determination device 700 to the distributor, etc. 600.
[0079] After S1020, in S1030, the authenticity determination device 700 acquires the private key. The distributor etc. 600 may receive the authenticity determination device 700 incorporating the private key in S1030 and use it for authenticity determination.
[0080] After S1010, in S1040, the public key output unit 215 outputs the second public key to the user terminal 500 used by the user 400.
[0081] After S1040, in S1050, the user terminal 500 acquires a second public key. The acquired second public key may be stored in a storage device of the user terminal 500 and used in S1140, which will be described later.
[0082] Following S1030 described above, in S1060, the authenticity determination device 700 performs an authenticity determination of the product. The authenticity determination device 700 performs the authenticity determination using a predetermined authenticity determination method. For example, the authenticity determination device 700 may perform the authenticity determination by reading an anti-counterfeiting label attached to the product.
[0083] If the distributor 600 is a distributor that collects and delivers products at a distribution center, the distributor may perform authenticity verification on the products delivered to the distribution center. If the distributor 600 is a product manufacturer or seller, the distributor may perform authenticity verification on the products to be shipped when the products are shipped.
[0084] Next, in S1070, the authenticity determination device 700 acquires authenticity determination data of the authenticity determination performed in S1060. The authenticity determination data may include, for each product for which an authenticity determination has been performed, at least one of the result of the authenticity determination of the product, the authenticity determination device 700 that performed the authenticity determination, the owner of the authenticity determination device 700, the date and time when the authenticity determination was performed, and information related to the product.
[0085] Next, in S1080, the authenticity determination device 700 encrypts the authenticity determination data to generate encrypted data. The authenticity determination device 700 may perform encryption on the authenticity determination data for each product, or may encrypt the authenticity determination data for multiple products collectively. The authenticity determination device 700 uses the private key obtained in S1030 for encryption. By the authenticity determination device 700 encrypting the authenticity determination data, it is possible to prevent tampering with the authenticity determination data.
[0086] Next, in S1090, the authenticity determination device 700 outputs the encrypted data to the verification system 100. The authenticity determination device 700 may output the encrypted data via the network 300.
[0087] Next, in S1100, the encrypted data acquisition unit 220 acquires the encrypted data output by the authenticity determination device 700 in S1090.
[0088] Next, in S1110, the decryption unit 225 decrypts the encrypted data acquired by the encrypted data acquisition unit 220 to generate first decrypted data. In S1110, the decryption unit 225 performs the decryption using a first public key corresponding to the private key. The first decrypted data may include, as authenticity determination data, at least one of the result of the authenticity determination of the product, the authenticity determination device that performed the authenticity determination, the owner of the authenticity determination device, the date and time when the authenticity determination was performed, and information related to the product.
[0089] The information about the authenticity determination device and the owner of the authenticity determination device included in the authenticity determination data is information indicating that the authenticity determination was obtained using a predetermined authenticity determination method.
[0090] Next, in S1120, the authenticity determination data output unit 230 outputs at least a part of the authenticity determination data included in the first decrypted data to the user terminal 500. The above description may be applied to the user terminal 500 as is.
[0091] Next, in S1130, the user terminal 500 acquires the authenticity determination data output by the authenticity determination data output unit 230 in S1120. The user terminal 500 may display the acquired authenticity determination data on an output device such as a monitor. This allows the user 400 to view the authenticity determination data performed by the distributor 600, etc.
[0092] If the user 400 requests the verification system 100 to verify that the authenticity determination data obtained in S1130 has not been tampered with by a third party or the like after being decrypted with the first public key in the verification system 100, and that the authenticity determination data has indeed been obtained through a predetermined authenticity determination, the user terminal 500 may proceed with the processing to S1140.
[0093] Next, in S1140, the user terminal 500 outputs a request for verification data indicating that the authenticity determination data is data obtained by a predetermined authenticity determination method to the verification system 100. At this time, the user terminal 500 outputs the second public key obtained in S1050 to the verification system 100.
[0094] Next, in S1150, the verification data request receiving unit 235 receives the request for verification data output by the user terminal 500 in S1140.
[0095] Fig. 4 shows an example of the authenticity determination data 900. The example in Fig. 4 shows the authenticity determination data acquired by the user terminal 500 in S1130. The authenticity determination data 900 includes an authenticity determination date and time 910, a product name 920 as information related to the product, a product ID 930 and product manufacturer 940, an authenticity determination device owner 950, an authenticity determination device ID 960, and an authenticity determination result 970.
[0096] In the authenticity determination data 900, the authenticity determination date and time 910 indicates the date and time when the authenticity determination device 700 performed an authenticity determination on the product. The product ID 930 may be an ID assigned to an individual product (individual item) and identifying the individual item. The authenticity determination device owner 950 is the person who owns the authenticity determination device 700 and / or performs product authenticity determination using the authenticity determination device 700. The authenticity determination result 970 indicates whether the product is genuine or a counterfeit. In the example of FIG. 4, in addition to the authenticity determination data 900, a verification data request button 980 is shown.
[0097] 4 shows information relating to the authentication method by which the authentication data was obtained, including an authentication device owner 950 and an authentication device ID 960. If the authenticity determination device owner 950 and the authenticity determination device ID 960 match the predetermined authenticity determination device owner and authenticity determination device IDs, respectively, it indicates that the authenticity determination data was obtained by the predetermined authenticity determination method.
[0098] When outputting the authenticity determination data to the user terminal 500, the user terminal 500 may display a verification data request button 980 for accepting a request for verification data from the verification system 100, as shown in Fig. 4, in order to accept the request for verification data in S1140. The user 400 can request verification data for the product authenticity determination data by pressing the verification data request button 980 displayed by the user terminal 500.
[0099] After S1150, in S1160, the decryption unit 225 decrypts the encrypted data acquired in S1100 to generate second decrypted data. In S1160, the decryption unit 225 performs the decryption using a second public key corresponding to the private key. The second decrypted data may include, as authentication data, at least one of the result of the authentication of the product, the authentication device that performed the authentication, the owner of the authentication device, the date and time when the authentication was performed, and information related to the product.
[0100] Next, in S1170, the verification data generation unit 240 generates verification data based on the first decrypted data and the second decrypted data. The verification data is data indicating that the authenticity determination data is data obtained by a predetermined authenticity determination method and has not been tampered with.
[0101] In S1170, the verification data generation unit 240 may compare the authenticity determination data contained in the first decrypted data with the authenticity determination data contained in the second decrypted data, and if the two match, generate verification data indicating that the authenticity determination data is data obtained by a predetermined authenticity determination method.
[0102] FIG. 5A shows an example of comparison data 1000 between the authentication data included in the first decoded data and the authentication data included in the second decoded data.
[0103] In the example of Figure 5A, the comparison data 1000 includes, for each of the first decrypted data decrypted with the first public key and the second decrypted data decrypted with the second public key, a public key type 1010, and, as authenticity determination data, an authenticity determination date and time 1020, a product name 1030 as information about the product, a product ID 1040 and product manufacturer 1050, an authenticity determination device owner 1060, an authenticity determination device ID 1070, and an authenticity determination result 1080.
[0104] 5A, in comparison data 1000, the first decoded data and the second decoded data completely match in items 1020 to 1080, which indicate the authentication data. In this case, verification system 100 may proceed to S1170 and generate verification data indicating that the authentication data is indeed authentication data obtained by a predetermined authentication method.
[0105] In the flow of the method of this embodiment, the second decrypted data is generated from the encrypted data at the time of comparing the first decrypted data with the second decrypted data in S1160, so the authentication determination data included in the second decrypted data is not subject to tampering by a third party. Therefore, even if the authentication determination data included in the first decrypted data has been tampered with, it is possible to detect the tampering made to the first decrypted data by comparing it with the second decrypted data.
[0106] FIG. 5B shows an example of comparison data 1100 between the authentication data included in the first decrypted data and the authentication data included in the second decrypted data.
[0107] In the example of Figure 5B, the comparison data 1100 includes, for each of the first decrypted data decrypted with the first public key and the second decrypted data decrypted with the second public key, a public key type 1110, and, as authenticity determination data, an authenticity determination date and time 1120, a product name 1130 as information about the product, a product ID 1140 and product manufacturer 1150, an authenticity determination device owner 1160, an authenticity determination device ID 1170, and an authenticity determination result 1180.
[0108] 5B, the authenticity determination results 1180 do not match between the first decrypted data and the second decrypted data for products represented by the same product name 1130, product ID 1140, and product manufacturer 1150. Because the second decrypted data is generated from encrypted data at the time of comparing the first decrypted data with the second decrypted data in S1160, the authenticity determination data included in the second decrypted data is not subject to tampering by a third party. Therefore, the authenticity determination data shown in the first decrypted data may have been tampered with after being decrypted with the first public key in the verification system 100.
[0109] As shown in the example of Figure 5B, in S1160, if a comparison of the authenticity determination data contained in the first decrypted data and the authenticity determination data contained in the second decrypted data reveals data that does not match, it is not verified that the authenticity determination data was obtained by a predetermined authenticity determination.
[0110] Next, in S1180, the verification data output unit 245 outputs the verification data to the user terminal 500. The verification data output unit 245 may output the authentication data and the verification data to the user terminal 500 as verified authentication data.
[0111] Fig. 6 shows an example of verified authentication data 1200. The example in Fig. 6 shows verification data 1290 generated by the verification data generation unit 240 in S1170 along with the authentication data. The authentication data includes an authentication date and time 1210, product name 1220 as information about the product, product ID 1230 and product manufacturer 1240, authenticity determination device owner 1250, authenticity determination device ID 1260, and authenticity determination result 1270. The example in Fig. 4 shows a verification data request history 1280 and verification data 1290 in addition to the authenticity determination data.
[0112] The explanations of 910 to 970 shown in Figure 4 may be applied as is to the authenticity determination date and time 1210, product name 1220, product ID 1230, product manufacturer 1240, authenticity determination device owner 1250, authenticity determination device ID 1260, and authenticity determination result 1270 contained in the authenticity determination data.
[0113] 6, the verification data request history 1280 indicates a history of requests for verification data. For example, when a request for verification data is made from the user terminal 500, a check mark may be displayed in the verification data request history 1280.
[0114] The verification data 1290 includes sentences, characters, symbols, etc. that indicate that the authenticity determination data is data obtained by a predetermined authenticity determination method. For example, as shown in Fig. 6, a sentence may indicate that the authenticity determination company (authenticity determination device owner 1250) and the authenticity determination device (authenticity determination device ID) have been verified as predetermined.
[0115] In the example shown in FIG. 5B, if the verification data 1290 includes data in which the first decrypted data and the second decrypted data do not match, the verification data 1290 may indicate that the authenticity determination data may have been tampered with.
[0116] Next, in S1190, the user terminal 500 acquires the verification data output in S1180. The user 400 can acquire the authentication data that has been verified, using the verification data acquired by the user terminal 500, to be data acquired by a predetermined authentication method and that has not been tampered with.
[0117] The method flow of this embodiment allows the user 400 of the authentication data to obtain authentication data that has been verified to be data obtained by a predetermined authentication method and has not been tampered with, thereby increasing the reliability of the authentication data obtained by the authentication device 700. In addition, the method flow of this embodiment makes it possible to reduce the computational and human resources consumed in verifying the authentication data.
[0118] Fig. 7 shows a modified example of the processing flow of the method in the verification system 100 of this embodiment. In the processing flow shown in Fig. 3, S1005' in Fig. 7 is added, and S1170 to S1190 in Fig. 3 are replaced with the processing flow of S1170' to S1190', thereby further executing the following steps in the processing flow described with reference to Fig. 3: a recipient registration step of registering a recipient of verified authenticity determination data that has been shown to be data acquired by a predetermined authenticity determination method, an anonymization step of generating anonymized data by anonymizing the verified authenticity determination data, and an anonymized data output step of outputting the anonymized data to a terminal used by the recipient.
[0119] For ease of explanation, the processes of S1005' and S1170' to S1190' will be explained in order, but at least some of these processes may be executed in parallel, or the steps may be interchanged as long as it does not deviate from the spirit of the present invention, or some steps may be omitted as long as it does not deviate from the spirit of the present invention.
[0120] In the processing flow shown in FIG. 7, the verification system 100 executes a provided person registration step S1005', an anonymization step S1170', and an anonymized data output step S1180'.
[0121] 7, first, in S1005', the provided person registration unit 250 registers a provided person (sometimes simply referred to as "provided person") who will receive anonymized data. The provided person is a person who has been registered in the verification system 100 as a provided person in order to receive verified authenticity determination data that has been shown to be data acquired by a predetermined authenticity determination method, and anonymized data in which information about individual companies has been anonymized from information included in the authenticity determination data.
[0122] After S1005', the verification system 100 advances the process to S1010 in Fig. 3. The description of Fig. 3 may be applied to the processes from S1010 to S1160.
[0123] 7, after S1160, in S1170′, the anonymization unit 255 generates anonymized data by anonymizing the verified authenticity determination data. The anonymization unit 255 may anonymize information included in the authenticity determination data that may cause the individual company name to be recognized by the person to whom the information is provided.
[0124] For example, if the authenticity determination data includes information about the owner of the authenticity determination device and / or information about the product, and this information includes information that may lead to the recognition of an individual company name (for example, the name of the owner of the authenticity determination device, the manufacturer of the product, etc.), the anonymization unit 255 may anonymize the information that may lead to the recognition of an individual company name. The anonymization unit 255 may perform the anonymization by deleting, masking, or symbolizing (for example, rewriting with a symbol such as "xxx") the information that may lead to the recognition of an individual company name.
[0125] Fig. 8 shows an example of anonymized data 1300. In the example of Fig. 8, the anonymized data 1300 includes, as authenticity determination data, an authenticity determination date and time 1310, product name 1320 as information related to the product, product ID 1330, product manufacturer 1340, authenticity determination device owner 1350, authenticity determination device ID 1360, and authenticity determination result 1370. In addition to the authenticity determination data, the anonymized data 1300 also includes a verification data request history 1380 and verification data 1390.
[0126] 4 may be applied as is to the authentication determination date and time 1310, product name 1320, product ID 1330, product manufacturer 1340, authentication determination device owner 1350, authentication determination device ID 1360, and authentication determination result 1370 included in the authentication data. The description of 910 to 970 in the example of FIG. 6 may be applied as is to the verification data 1390.
[0127] In an example of anonymized data 1300, information included in the authentication data and / or verification data that may identify information about an individual company may be anonymized. For example, the product manufacturer 1340, authentication device owner 1350, and / or authentication device owner included in the authentication data may be deleted or hidden so that information about an individual company is not included in the verification data 1390.
[0128] After S1170′, in S1180′, the anonymized data output unit 260 outputs the anonymized data to the terminal used by the person to whom the data is to be provided (for example, the user terminal 500).
[0129] Next, in S1190', the terminal used by the recipient acquires the anonymized verification data output in S1180'.
[0130] When multiple companies (e.g., related companies in a supply chain) collaborate and share authentication determination data with each other, they may want to understand the occurrence of counterfeit products within the industry without disclosing information about individual companies (e.g., company names, etc.) to other companies. In such cases, the anonymized data 1300 of this embodiment allows recipients to obtain mutually anonymized verification data, thereby making it possible to understand the occurrence of counterfeit products in multiple companies without disclosing information about individual companies to other companies.
[0131] Figure 9 shows an example of the processing flow of the method in the inventory management system 800 of this embodiment. By performing the processing flow from S2010 to S2030 in Figure 9, the inventory management system 800 executes a verification data acquisition stage of acquiring verification data output by the verification system 100, a warehousing permission data generation stage of generating warehousing permission data for products whose authenticity determination data has been shown by the verification data to be data obtained using a predetermined authenticity determination method, and an inventory registration stage of registering the products for which warehousing permission data has been generated as inventory.
[0132] For ease of explanation, the processes from S2010 to S2030 will be explained in order, but at least some of these processes may be executed in parallel, or the steps may be interchanged and executed as long as it does not deviate from the spirit of the present invention, or some steps may be omitted and executed as long as it does not deviate from the spirit of the present invention.
[0133] In the process flow shown in FIG. 9, the inventory management system 800 executes a verification data acquisition step S2010, a warehousing permission data generation step S2020, and an inventory registration step S2030.
[0134] 3 or S1190' in the processing flow of Fig. 7, in the flow shown in Fig. 9, the verification data acquisition unit 850 of the inventory management system 800 acquires the verification data output by the verification system 100. The explanation of the verification data may be the same as that of S1190 and S1190'.
[0135] Next, in S2020, the warehousing permission data generation unit 560 generates warehousing permission data for a product for which the verification data indicates that the authenticity determination data is data acquired by a predetermined authenticity determination method.
[0136] Next, in S2030, the inventory registration unit 570 registers the product for which the warehousing permission data has been generated as inventory.
[0137] For products whose verification data indicates that the authenticity data was obtained using a predetermined authenticity determination method, the authenticity data is highly reliable. Therefore, by generating inventory permission data for the product using the processing flow shown in Figure 9, only genuine products can be registered as inventory.
[0138] 10 illustrates an example of a computer 2200 in which aspects of the present invention may be embodied, in whole or in part. Programs installed on the computer 2200 may cause the computer 2200 to function as or perform operations associated with an apparatus or one or more sections of the apparatus according to embodiments of the present invention, and / or to perform a process or steps of a process according to embodiments of the present invention. Such programs may be executed by the CPU 2212 to cause the computer 2200 to perform specific operations associated with some or all of the blocks of the flowcharts and block diagrams described herein.
[0139] A computer 2200 according to this embodiment includes a CPU 2212, a RAM 2214, a graphics controller 2216, and a display device 2218, which are interconnected by a host controller 2210. The computer 2200 also includes input / output units such as a communication interface 2222, a hard disk drive 2224, a DVD-ROM drive 2226, and an IC card drive, which are connected to the host controller 2210 via an input / output controller 2220. The computer also includes legacy input / output units such as a ROM 2230 and a keyboard 2242, which are connected to the input / output controller 2220 via an input / output chip 2240.
[0140] The CPU 2212 operates according to programs stored in the ROM 2230 and RAM 2214, thereby controlling each unit. The graphics controller 2216 acquires image data generated by the CPU 2212 into a frame buffer or the like provided in the RAM 2214 or into the graphics controller 2216 itself, and causes the image data to be displayed on the display device 2218.
[0141] The communications interface 2222 communicates with other electronic devices via a network. The hard disk drive 2224 stores programs and data used by the CPU 2212 in the computer 2200. The DVD-ROM drive 2226 reads programs or data from the DVD-ROM 2201 and provides the programs or data to the hard disk drive 2224 via the RAM 2214. The IC card drive reads programs and data from an IC card and / or writes programs and data to an IC card.
[0142] The ROM 2230 stores therein a boot program or the like that is executed by the computer 2200 upon activation, and / or programs that depend on the hardware of the computer 2200. The input / output chip 2240 may also connect various input / output units to the input / output controller 2220 via a parallel port, a serial port, a keyboard port, a mouse port, etc.
[0143] The programs are provided by a computer-readable medium such as a DVD-ROM 2201 or an IC card. The programs are read from the computer-readable medium, installed in the hard disk drive 2224, RAM 2214, or ROM 2230, which are also examples of computer-readable media, and executed by the CPU 2212. Information processing described in these programs is read by the computer 2200, and brings about cooperation between the programs and the various types of hardware resources described above. An apparatus or method may be configured by realizing information manipulation or processing in accordance with the use of the computer 2200.
[0144] For example, when communication is performed between the computer 2200 and an external device, the CPU 2212 may execute a communication program loaded into the RAM 2214 and instruct the communication interface 2222 to perform communication processing based on the processing described in the communication program. Under the control of the CPU 2212, the communication interface 2222 reads transmission data stored in a transmission buffer processing area provided in the RAM 2214, the hard disk drive 2224, the DVD-ROM 2201, or a recording medium such as an IC card, and transmits the read transmission data to the network, or writes reception data received from the network to a reception buffer processing area or the like provided on the recording medium.
[0145] The CPU 2212 may also cause all or a necessary portion of a file or database stored on an external recording medium such as the hard disk drive 2224, the DVD-ROM drive 2226 (DVD-ROM 2201), an IC card, etc. to be read into the RAM 2214, and perform various types of processing on the data on the RAM 2214. The CPU 2212 then writes back the processed data to the external recording medium.
[0146] Various types of information, such as various types of programs, data, tables, and databases, may be stored on the recording medium and may undergo information processing. The CPU 2212 may perform various types of processing on data read from the RAM 2214, including various types of operations, information processing, conditional judgment, conditional branching, unconditional branching, information search / replacement, etc., as described throughout this disclosure and specified by the instruction sequences of the programs, and write the results back to the RAM 2214. The CPU 2212 may also search for information in a file, database, etc. on the recording medium. For example, if multiple entries each having an attribute value of a first attribute associated with an attribute value of a second attribute are stored on the recording medium, the CPU 2212 may search for an entry that matches a condition specified by the attribute value of the first attribute from among the multiple entries, read the attribute value of the second attribute stored in the entry, and thereby obtain the attribute value of the second attribute associated with the first attribute that satisfies a predetermined condition.
[0147] The above-described programs or software modules may be stored in a computer-readable medium on or near the computer 2200. A recording medium such as a hard disk or RAM provided in a server system connected to a dedicated communication network or the Internet can also be used as a computer-readable medium, thereby providing the programs to the computer 2200 via the network.
[0148] Although the present invention has been described above using embodiments, the technical scope of the present invention is not limited to the scope described in the above embodiments. It will be apparent to those skilled in the art that various modifications and improvements can be made to the above embodiments. It is clear from the claims that such modifications and improvements can also be included within the technical scope of the present invention.
[0149] It should be noted that the execution order of each process, such as operations, procedures, steps, and stages, in the devices, systems, programs, and methods shown in the claims, specifications, and drawings is not specifically stated as "before," "prior to," etc., and that the processes can be performed in any order unless the output of a previous process is used in a subsequent process. Even if the operational flow in the claims, specifications, and drawings is described using "first," "next," etc. for convenience, this does not mean that the processes must be performed in this order. [Explanation of symbols]
[0150] 10 Authentication System 100 Verification System 110 Input section 120 Storage section 130 Display section 140 Communications Department 200 Arithmetic section 205 Key generation section 210 Private key output unit 215 Public key output section 220 Encrypted Data Acquisition Unit 225 Decoding Unit 230 Authenticity determination data output unit 235 Verification data request reception unit 240 Verification Data Generation Unit 245 Verification data output unit 250 Recipient Registration Department 255 Anonymization Department 260 Anonymized Data Output Unit 300 Network 400 users 500 user terminals 600 Distributors, etc. 700 Authentication Device 800 Inventory Management System 810 Input section 820 Storage section 830 Display section 840 Communications Department 850 Verification Data Acquisition Unit 860 Storage permission data generation unit 870 Inventory Registration Department 900 Authenticity Determination Data 910, 1020, 1120, 1210, 1310 Authentication date and time 920, 1030, 1130, 1220, 1320 Product name 930, 1040, 1140, 1230, 1330 Product ID Manufacturer of 940, 1050, 1150, 1240, 1340 products 950, 1060, 1160, 1250, 1350 Authentication Device Owner 960, 1070, 1170, 1260, 1360 Authentication device ID 970, 1080, 1180, 1270, 1370 Authenticity test results 980 Verification Data Request Button 1000, 1100 comparison data 1010, 1110 Public key type 1200 verified authenticity data 1280, 1380 Validation Data Request History 1290, 1390 validation data 1300 anonymized data 2200 Computer 2201 DVD-ROM 2210 host controller 2212 CPU 2214 RAM 2216 Graphics Controller 2218 Display Device 2220 Input / Output Controller 2222 communication interface 2224 hard disk drive 2226 DVD-ROM drive 2230 ROM 2240 I / O chip 2242 keyboard
Claims
1. an encrypted data acquisition unit that acquires encrypted data that includes product authenticity determination data and is encrypted using a private key; a decryption unit that generates first decrypted data by decrypting the encrypted data acquired by the encrypted data acquisition unit with a first public key corresponding to the private key; an authenticity determination data output unit that outputs at least a part of the authenticity determination data included in the first decrypted data; a verification data request receiving unit that receives, from a user terminal used by a user of the authentication data, a request for verification data indicating that the authentication data is data obtained by a predetermined authentication method; a verification data output unit that outputs the verification data to the user terminal; A verification system comprising:
2. the verification data request receiving unit acquires a second public key corresponding to the private key from the user terminal; the decryption unit generates second decrypted data by decrypting the encrypted data with the second public key. The verification system of claim 1 .
3. a verification data generation unit that generates the verification data; the verification data generation unit generates the verification data based on the first decrypted data and the second decrypted data. The verification system of claim 2 .
4. the verification data generation unit compares the authenticity determination data included in the first decrypted data with the authenticity determination data included in the second decrypted data, and if the two match, generates verification data indicating that the authenticity determination data is data obtained by a predetermined authenticity determination method. The verification system of claim 3 .
5. the encrypted data acquisition unit acquires the encrypted data from an authenticity determination device that determines the authenticity of the product by reading an anti-counterfeit label attached to the product; The verification system of claim 1 .
6. The authentication device further includes a private key output unit that outputs the private key to the authentication device. The verification system of claim 5 .
7. further comprising a public key output unit that outputs the second public key to the user terminal; The verification system of claim 2 .
8. further comprising a key generation unit that generates at least one of the private key, the first public key, and the second public key; The verification system of claim 2 .
9. The authenticity determination data includes at least one of the result of authenticity determination of the product, the authenticity determination device that performed the authenticity determination, the owner of the authenticity determination device, the date and time when the authenticity determination was performed, and information about the product. The verification system of claim 1 .
10. The user terminal includes a terminal used by a seller of the product, a manufacturer of the product, and / or a distributor of the product; The verification system of claim 1 .
11. recording at least one of the encrypted data, the first decrypted data, the second decrypted data, and the verification data on a ledger on a blockchain network; The verification system of claim 2 .
12. a registration unit for registering a person to whom the verified authenticity determination data is to be provided, the person being shown to have been obtained by a predetermined authenticity determination method; an anonymization unit that generates anonymized data by anonymizing the verified authenticity determination data; an anonymized data output unit that outputs the anonymized data to a terminal used by the person to whom the data is to be provided; The verification system of claim 1 further comprising:
13. a verification data acquisition unit that acquires the verification data output by the verification system according to any one of claims 1 to 12; a storage permission data generation unit that generates storage permission data for a product for which the authentication data is shown to be data obtained by a predetermined authentication method based on the verification data; an inventory registration unit that registers the product for which the warehousing permission data is generated as inventory; An inventory management system comprising:
14. The method is executed by a computer, causing the computer to:
13. The verification system according to claim 1, program.
15. The method is executed by a computer, causing the computer to: The inventory management system according to claim 13 is operated as follows. program.
16. The verification system according to any one of claims 1 to 12, an encrypted data acquisition step of acquiring encrypted data including product authenticity determination data and encrypted with a private key; a decryption step of generating first decrypted data by decrypting the encrypted data acquired in the encrypted data acquisition step with a first public key corresponding to the private key; an authentication data output step of outputting at least a part of the authentication data included in the first decrypted data; a verification data request receiving step of receiving, from a user terminal used by a user of the authentication data, a request for verification data indicating that the authentication data is data obtained by a predetermined authentication method; a verification data output step of outputting the verification data to the user terminal; The validation method to perform.
17. The inventory management system according to claim 13, a verification data acquisition step of acquiring the verification data output by the verification system according to any one of claims 1 to 12; a receiving permission data generating step of generating receiving permission data for a product for which the authentication data is shown to be data obtained by a predetermined authentication method based on the verification data; an inventory registration step of registering the product for which the warehousing permission data is generated as inventory; Inventory management method to carry out.