Qualification signature device, and qualification signature program

The qualification signature device enforces signature restrictions based on predefined qualifications, ensuring that only qualified individuals can sign electronic contracts, thereby preventing unauthorized signatures and enhancing the integrity of electronic contracts.

JP2025162508AActive Publication Date: 2025-10-27SEIKO SOLUTIONS
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
JP2025005477
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-15
Filing Date
2025-01-15
Publication Date
2025-10-27
Estimated Expiration
2045-01-15

Smart Images

  • Figure 2025162508000001_ABST
    Figure 2025162508000001_ABST
Patent Text Reader

Abstract

To more surely perform an electronic signature based on an appropriate qualification.SOLUTION: If at least one person of contractors performing a witness type electronic signature is a qualified person having a predetermined qualification, only persons having a qualification requested in a signature column perform a signature restriction that enables an electronic signature to each signature column of an electronic contract. An electronic signature by a person other than the qualified person subjected to the signature restriction is excluded, for example, by linking a request qualification called "a doctor" ... to a signer 1 in various electronic contracts or providing a request qualification signature form with a request qualification embedded in each signature column of the electronic contracts. Then, if a qualification of a contractor matches the qualification requested by the electronic contracts, a qualification signature is performed as a qualification signature key being a secret key created corresponding to the qualification of the qualified person and an electronic signature using an electronic certificate with specific information of the qualification recorded.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an apparatus and a program for digitally signing an electronic contract. [Background technology]

[0002] Electronic contracts are now being used to electronically sign electronic contracts (including electronic consent forms) that electronically record the contractual content between the parties, and depending on the content of the contract, electronic contracts are signed by the parties themselves or by businesses (witnesses). An electronic contract with an electronic signature is guaranteed to be signed by the contracting party himself / herself and that the contents have not been tampered with. In a party-based electronic signature system, a private key and electronic certificate (hereinafter referred to as the private key, etc.) owned exclusively by the contracting parties are used to digitally sign an electronic contract. On the other hand, in witness-type electronic signatures, as described in Patent Document 1, a private key or the like of an electronic signature business operator who acts as a witness is used to digitally sign an electronic contract. In such witness-type electronic signatures, the private key of the witness is generally used, rather than the private key of the contracting party itself. Therefore, the service provider must undergo strict identity verification (for example, verification of ID (identification number) and PW (password)), and the attribute information that identifies the contracting party, such as an email address, is included in the electronic signature.

[0003] By the way, electronic contracts not only have a wide variety of content, but also have a variety of parties to the contracts. For example, qualified persons such as doctors and architects may enter into electronic contracts in their respective qualifications. In such cases, it is preferable that a third party, including the contracting party, can verify that the electronically signed electronic contract has been signed by a person with the required qualifications. However, in the case of witness-type electronic signatures, it was not possible to determine the qualifications of the electronic contract holder from the electronically signed electronic contract.

[0004] Furthermore, some contracts, such as a doctor-patient agreement, impose qualification conditions on the person who can sign them (in this case, a medical license is required). However, conventional electronic contract services did not have a mechanism to prevent signatures from being made by people who did not meet the qualifications, and it was not possible to prevent signatures from being made by the wrong signer. It was also difficult to verify whether a signature had been made by the wrong signer. This meant that an unqualified person could intentionally or mistakenly sign as a qualified person, or a qualified person could mistakenly sign as someone with a different qualification (for example, a nurse signing as a doctor). [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2013-114641 Summary of the Invention [Problem to be solved by the invention]

[0006] The present invention aims to enable contracting parties to an electronic contract who sign a witness-type electronic signature to more reliably sign the electronic signature based on appropriate qualifications. [Means for solving the problem]

[0007] The present invention provides a qualification signature device that sequentially executes witness-type electronic signatures on electronic contracts based on requests from each contracting party, a presentation means for presenting an electronic contract in which signature restrictions are specified in each signature field so that only persons with the required qualifications can electronically sign, when at least one of the contracting parties is a qualified person with a predetermined qualification; a qualification determination means for determining, when the contracting party requesting an electronic signature is a qualified person, whether the qualification of the contracting party matches the qualification required in the signature field of the electronic contract; an electronic signature means for signing the electronic contract in a manner that can be verified as being the electronic signature of a person with the relevant qualifications if the qualifications match; The present invention provides a qualification signing device characterized by comprising: [Effects of the Invention]

[0008] In this invention, if the contracting party requesting an electronic signature is a qualified person, the electronic signature will be issued if the qualifications of the contracting party match the qualifications required in the signature section of the electronic contract, thereby making it possible to more reliably issue an electronic signature based on appropriate qualifications. [Brief explanation of the drawings]

[0009] [Figure 1] 1 is an explanatory diagram showing the configuration of a qualification signature system including a qualification signature device; [Figure 2] FIG. 1 is an explanatory diagram showing the configuration of a qualification signing device. [Figure 3] FIG. 10 is an explanatory diagram conceptually showing a request qualification signature list based on signature limitation A. [Figure 4A] This is an explanatory diagram showing an unrestricted template before adding a request qualification signature form to a surgical consent form. [Figure 4B] This is an explanatory diagram showing the display screen of a surgery consent form in which a request qualification signature form with signature restriction B is embedded in an unrestricted template. [Figure 4C] This is an explanatory diagram showing the display screen of a surgery consent form with signature limitation B after electronic signature and time stamp by the qualification signing device. [Figure 4D] This is an explanatory diagram showing the display screen of a surgical consent form with signature limitation B, which has been signed by a qualified person. [Figure 5] 1 is an explanatory diagram conceptually showing the contents of an account DB stored in a storage device of a qualification signing device. [Figure 6] 1 is an explanatory diagram conceptually showing the contents of a qualification DB stored in a storage device of a qualification signing device. [Figure 7]10 is a flowchart showing the flow of an account registration process by the entitlement signature system. [Figure 8] 10 is a flowchart showing a part of the flow of a qualification signature process by the qualification signature system. [Figure 9] 10 is a flowchart showing the continuation of the flow of the entitlement signature process by the entitlement signature system. [Figure 10] FIG. 10 is an explanatory diagram showing a display screen of an electronic contract (surgery consent form) file displayed on a user terminal. [Figure 11] FIG. 10 is an explanatory diagram illustrating an electronic signature selection screen displayed on a user terminal. [Figure 12] 1 is an explanatory diagram conceptually showing the structure of a qualifications-signed electronic contract signed by a qualifications signing system. [Figure 13] 10 is a flowchart showing the flow of a verification process for a qualifications-signed electronic contract that has been qualified. [Figure 14] FIG. 10 is an explanatory diagram conceptually showing the structure of a qualification signature electronic contract according to a modified example. DETAILED DESCRIPTION OF THE INVENTION

[0010] A preferred embodiment of the entitlement signature device 1 of the present invention will be described in detail below with reference to FIGS. (1) Overview of the embodiment When at least one of the contracting parties (users) who enter into a witness-type electronic signature is a person with predetermined qualifications (qualified person), the qualification signature device 1 applies signature limitation A or signature limitation B to each signature field of the electronic contract, which allows only persons with the qualifications required in that signature field to sign electronically. Signature Restriction A allows the required qualifications to be linked to various electronic contract templates, such as "doctor" for Signer 1, "nurse" for Signer 2, etc. When the required qualifications are linked, any signature request from anyone other than the relevant qualified person (doctor, nurse, etc.) will be flagged as an error, ensuring that the electronic signature is made by the requested qualified person. Regarding the linking of request qualifications to the template of the electronic contract, the request qualification signature number is linked in accordance with the request qualification signature list 58 (see Figs. 2 and 3) in which the request qualifications are specified. For example, by linking the required qualification signature number "01" of "Medical Consent Form 1," the required qualifications are linked as "Doctor" to Signer 1, "Nurse" to Signer 2, and so on. When a user uses a template associated with a requested qualification, the qualification signature device 1 controls to select a qualification signer based on the conditions in the requested qualification signature list 58.

[0011] In Signature Restriction B, a form field (hereinafter referred to as the Requested Qualification Signature Form) with the requested qualifications (qualification information) embedded is provided in each signature field of an electronic contract, thereby eliminating electronic signatures from persons other than those qualified as specified by the embedded requested qualifications. For example, in the requested qualification signature form, the input form name is embedded as "SYOMEI01@N001", which is the original form name "SYOMEI01" plus the qualification code "N001" of the requested qualification specified in this form. Here, "@" indicates that additional information for the requested qualification follows, and the qualification code to be added is added in accordance with the qualification DB 56 (see FIGS. 2 and 6) described later. Other signature restrictions include including required qualifications such as those of a doctor as input restrictions for an electronic contract that has an input restriction function, or including the required qualification conditions in the properties of the electronic contract.

[0012] In the electronic signature by the qualification signature device 1, a witness-type electronic signature is made on the electronic contract in a manner that allows the contracting parties and third parties to confirm, after the contract by electronic contract is completed, whether the electronic contract was electronically signed at the request of a qualified person with what qualifications, regardless of whether there is a signature limitation. The qualifications that can be verified include various qualifications established by the state or private sector, qualifications based on enrollment in social insurance or national health insurance, and various qualifications such as Japanese nationality and residence status. However, whether or not the contractor (user) signs a qualification based on their own qualification is a separate matter, and the qualification signature process will be carried out if the contractor wishes and specifies their own qualification.

[0013] Specifically, the entitlement signature device 1 performs a so-called witness-type electronic signature (entitlement signature) on an electronic contract (hereinafter referred to as an electronic contract) including an electronic consent form, using a entitlement signature key (private key) and electronic certificate issued to the entitlement signature device 1 for each entitlement, rather than the private key of the contracting party or consenting party (hereinafter referred to as the contracting parties). The digital certificate for each entitlement signing key contains, by subject, subject alternative name, or policy OID (Object Identifier), entitlement information (e.g., entitlement name, entitlement code, etc.) that indicates that the requester of the digital signature (contracting party) is the holder of the entitlement corresponding to the entitlement signing key.

[0014] Furthermore, when issuing an electronic signature, the qualification signature device 1 includes qualification information that can verify the contract holder's qualifications in the attribute information (reason for electronic signature), calculates a hash value together with the electronic contract, and issues an electronic signature using a qualification signature key, etc. (qualification signature key and electronic certificate) corresponding to the contract holder's qualifications. The attribute information (reason for electronic signature) is one part of the format for the qualification signature process, and is an area in which any text information included in the scope of encryption can be entered. This allows the contracting parties and third parties to verify, through the digital certificate and attribute information of the qualifications signing key, that the electronic contract that has undergone qualifications signing processing by the qualifications signing device 1 is a contract made by at least one qualified person.

[0015] In the qualification signature processing of this embodiment, an electronic signature is issued for each signature request from multiple contracting parties. If the qualifications of the contracting parties match the qualifications required in the electronic contract, a qualification signature is issued using a qualification signature key, which is a private key created corresponding to the qualifications of the qualified person, and an electronic certificate recording specific information about the qualifications. If the contracting party is not qualified, an electronic signature (general signature) is issued using a common signature key (a private key used in common by all non-qualified parties) that does not correspond to the qualifications.

[0016] (2) Details of the embodiment FIG. 1 is a diagram showing the system configuration of a qualification signature system for witness-type electronic signatures for electronic contracts, including a qualification signature device 1 according to this embodiment. As shown in FIG. 1, a credentials signing device 1 forms a credentials signing system together with user terminals 91, 92, 93, . . . used by users who are contracting parties or verifiers, a list publishing server 6, a certification authority 7, and a timestamp server 8. The entitlement signing device 1 is connected to user terminals 91, 92, 93 and a list publication server 6 via the Internet, telephone lines, or the like, and is connected to a timestamp server 8 and a certification authority 7 via a VPN (Virtual Private Network) or the like.

[0017] The list publishing server 6 publishes the qualification comparison table 61 via the Internet or the like. This entitlement comparison table 61 is used to confirm the validity of the entitlements of the contracting parties for an entitlement-signed electronic contract (entitlement-signed electronic contract (TS)), and is configured to be able to display a list of the entitlement code, entitlement name, and entitlement holder identity verification method for each entitlement. The entitlement comparison table 61 is generated from the entitlement DB 56 of the entitlement signature device 1, which will be described later. The URI of this qualification comparison table 61 is stored in a qualification DB (to be described later) of the qualification signature device 1, and is also recorded in the attribute information when the qualification is signed. The qualification comparison table 61 published on the list publication server 6 is used to confirm the validity of the qualifications of the contracting parties, and by using the qualification comparison table 61, other electronic signature businesses can adopt the same standards as the qualification signature device 1. The list publishing server 6 is operated by an organization external to the qualifications signing device 1, but may be operated by the same operating body as the qualifications signing device 1.

[0018] A Certification Authority (CA) 7 is an organization that verifies the identity of those who issue electronic signatures. It verifies the identity of users based on their applications and various certificates, generates private and public keys for users, and issues digital certificates that link the public keys with the owners (users) of the corresponding private keys. In this embodiment, the qualification signature device 1, as a user of the certification authority 7, is issued a qualification signature key (private key), a public key, and an electronic certificate (hereinafter referred to as a qualification signature key, etc.) for each of the multiple qualifications, and stores them in the signature key DB. The qualification signature device 1 also stores in advance in the signature key DB a common signature key, a public key, and an electronic certificate (hereinafter referred to as a common signature key, etc.) to be commonly used for electronic signatures for non-qualified users.

[0019] Based on a request from the entitlement signing device 1, the timestamp server 8 assigns a timestamp to the entitlement signed electronic contract after the entitlement signing process has been performed.

[0020] The user terminals 91, 92, 93, . . . are terminals used by contracting parties who make an electronic contract using a witness-type electronic signature by the qualification signature device 1, or by persons who verify the qualification-signed electronic contract. In the following description, the user terminals 91, 92, and 93 will be collectively referred to as the user terminal 9. The user terminal 9 is a computer that can be connected to a communication network wirelessly or by wire, and is configured, for example, by a personal computer, a smartphone, a mobile phone, or a game device. The user terminal 9 is equipped with a browser and a display device for displaying electronic contracts and the like provided by the qualification signature device 1, and is configured to be able to use short mail service (SMS) and / or e-mail using a telephone number. The user terminal 9 also has a touch panel and keyboard for performing various input operations in the qualification signature process.

[0021] In Figure 1, the user terminals 9 are shown as user terminal (qualified person) 91, user terminal (unqualified person) 92, and user terminal (verifier) ​​93, but in reality there are multiple devices, such as user terminal (administrator / qualified identity verifier) ​​94 shown in Figure 7, depending on the number of contracting parties who have an account for electronic contracts with the qualification signing device 1. However, provided that at least one of the users (contracting parties) has completed the account registration of a qualified person, it is possible to carry out qualified signature processing for electronic contracts in which a non-registered person who does not have an account is a contracting party.

[0022] The entitlement signature device 1 comprises a entitlement signature processing unit 2, a signature verification unit 3, and an account registration unit 4 as function realization units, and a storage device 5. The storage device 5 stores various programs and data for realizing the functions of each of these function realization units 2 to 4, such as a template DB 54 that stores templates for electronic contracts with signature limitations stipulated, in which requested entitlements are linked and requested entitlement signature forms are embedded in each signature field, and an account DB 55 (details will be described later). The account registration unit 4 newly registers or updates accounts of users (qualified and unqualified contracting parties, verifiers, qualified administrators, etc.) in the account DB 55 based on various registration information transmitted from the user terminals 91-. The qualification signature processing unit 2 performs witness-type qualification signature processing for the target electronic contract, for example, based on a signature request from a user (qualified person) of the user terminal 91 and a user (unqualified person) of the user terminal 92. The signature verification unit 3 receives a verification request for an electronic contract that has undergone qualification signature processing (hereinafter referred to as a qualification-signed electronic contract) from, for example, a user terminal (verifier) ​​93 or a user terminal of a contracting party, and verifies that the qualification-signed electronic contract has not been tampered with and verifies the expiration date of the qualifications of the contracting party, etc. Each device in FIG. 1 that forms the entitlement signature system is capable of communicating in a state encrypted with SSL or TLS via a communication network such as the Internet.

[0023] FIG. 2 shows a hardware configuration for realizing each function of the entitlement signature device 1 described in FIG. As shown in FIG. 2, the qualification signature device 1 includes a CPU 11, a ROM 12, a RAM 13, a storage device 5, a communication control unit 14, and other devices connected via a bus line. The CPU 11 is a central processing unit that operates according to various programs stored in the storage device 5, and performs communication processing with external devices such as the list publication server 6, the certification authority 7, the timestamp server 8, and the user terminal 9. In addition, the CPU 11 functions as the qualification signature processing unit 2 shown in Figure 1 by executing the qualification signature processing PG (program) 50, functions as the signature verification unit 3 by executing the signature verification PG 51, and functions as the account registration unit 4 by executing the account registration PG 52.

[0024] The ROM 12 is a read-only memory that stores basic programs and parameters for the CPU 11 to operate. The RAM 13 is a readable and writable memory, and serves as a working memory when the CPU 11 performs the electronic contract processing in this embodiment. For example, in the qualifications signing process, the RAM 13 stores the login IDs of the qualified individuals who are the contracting parties, the electronic contracts at each processing stage until the qualifications signing process is completed, and the like. The communication control unit 14 performs communication processing with external devices such as the user terminal 9.

[0025] The storage device 5 is configured using one or more large-capacity storage media such as hard disks, and stores various programs such as a qualification signature processing PG50, a signature verification PG51, and an account registration PG52 to enable the CPU 11 to perform the functions of this embodiment, as well as various data such as a template DB (database) 54, an account DB 55, a qualification DB 56, a signature key DB 57, and a requested qualification signature list 58. As described above, the qualification signature processing PG50, signature verification PG51, and account registration PG52 are programs for functioning as the qualification signature processing unit 2, signature verification unit 3, and account registration unit 4, and the details of each process will be described later.

[0026] The template DB 54 stores templates of various contracts (including consent forms, oaths, pledges, etc.) that are used in electronic contracts for witnessing dolls and are subject to the qualification signature processing of this embodiment. The templates stored in the template DB54 include original electronic contract templates that can be used in a variety of situations, including medical, construction and civil engineering, public institutions, the legal system, finance, and more. In the template DB 54 of this embodiment, templates of various electronic contracts are stored, classified by predetermined industry type, but it is also possible to store them according to other classifications, such as the Japan Standard Industrial Classification. The templates of electronic contracts are created, collected and stored by the operator of the qualification signature device 1, as well as those created and uploaded by users or administrators who have registered accounts.

[0027] The various templates stored in the template DB 54 can be downloaded from the user terminal 91 of a user who has logged in to the qualification signature device 1 and has registered an account. A user who has registered an account can use an electronic contract stored in the template DB 54, as well as an electronic contract stored in an external device other than the qualifications signing device 1 or in the user's own device, to undergo qualifications signing processing by the qualifications signing device 1. In this case, the electronic contract to be used is uploaded from the user terminal 9 to the qualifications signing device 1, and the qualifications signing device 1 performs qualifications signing processing for this, and can also store the electronic contract before electronic signature in the template DB 54 as necessary.

[0028] The templates for various contracts stored in the template DB54 include signature restriction A (electronic contracts linked to required qualifications), signature restriction B (electronic contracts using a "required qualification signature form" in which qualification information restricting the signer is embedded in the signature field), and templates for other electronic contracts for which signature restrictions are specified. The template DB 54 also stores templates for electronic contracts that do not specify signature restrictions. For example, there are electronic contracts where none of the parties are required to have a qualification. It also stores templates for electronic contracts before signature restrictions were specified (hereinafter referred to as "unrestricted templates"). The unrestricted template is a template for adding signature restrictions based on required qualifications, and the electronic contract with the specified signature restrictions is saved as a new template separately from the original unrestricted template.

[0029] Here, signature limitation A and signature limitation B, which limit electronic signatures to only predetermined qualified persons, will be described. FIG. 3 conceptually shows a request qualification signature list 58 for linking a template of an electronic contract with signature limitation A by request qualification. This request entitlement signature list 58 is stored in the storage device 5 of FIG. As shown in Figure 3, the required qualification signature list 58 is managed for each "request qualification signature number (No.)" and specifies the "electronic contract file name," which is the name of the target electronic signature, and the required qualification list that specifies the qualifications required for each signature field of the electronic contract (signature 1, signature 2, ...). The electronic contract file name serves as a heading when searching for the target electronic contract template.

[0030] In Signature Restriction A, a list of required qualifications is linked by linking a required qualification signature number to the template of the electronic contract, and each signature field in the electronic contract is limited to electronic signatures by persons who have the linked qualifications (required qualifications). For example, if the required qualification signature number "01" for "Medical Consent Form 1" is linked to an electronic contract template, then as specified in the required qualification list, the required qualifications of doctor will be linked to the "Signature 2" field of the electronic contract, and nurse will be linked to the "Signature 3" field, and only qualified individuals (doctors, nurses, etc.) who meet the required qualifications will be able to sign electronically, and signature requests from individuals other than the relevant qualified individuals will not be accepted. However, although it is possible to select a signature request from an individual other than a qualified individual, it is also possible to set it up so that an error will occur if selected. When a user uses a template associated with a requested qualification, the qualification signature device 1 controls to select a qualification signer based on the conditions in the requested qualification signature list 58.

[0031] Here, depending on the required qualification, there are qualifications that are in a higher or lower relationship. Therefore, when the requested qualification is a lower-level qualification, it is possible to specify the higher-level qualification as well. In such a case, in signature restriction A, when specifying a lower qualification as a required qualification in the "signature x" field, it is possible to specify a higher qualification as well. For example, there are qualifications such as first-class architect, second-class architect, and wooden architect, in descending order of rank. If the "Signature x" field requires "wooden architect," it is possible to specify the higher-ranking qualifications, such as first-class architect and second-class architect. Similarly, since doctors are ranked higher than nurses, if the required qualification is a nurse, it is possible to specify doctors in the "Signature x" field as well. On the other hand, in the case of signature limitation B described below, when requesting lower-level qualifications in the required qualification form embedded in each signature field of the electronic contract, it is also possible to specify higher-level qualifications as well.

[0032] On the other hand, the "Unqualified" in the "Signature 1" column for the required qualification signature number "01" indicates that no specific qualification is associated with the document. This allows a person with a qualification other than those specified in the other signature columns, such as a person without a specific qualification or a person with another qualification such as an architect, to sign. In this unqualified signature column 1, a general signature, as described below, is used.

[0033] The required qualifications list 58 illustrated in Figure 3 shows a case where required qualifications are specified for each signature column, but it is also possible to restrict signatures other than those of designated qualified persons and specify the number of designated qualified persons, for example, by specifying one or more doctors and one or more nurses for columns Signature 1 to Signature N. When the number of persons is specified in this way, the qualification signature device 1 completes the witness-type electronic signature for the electronic contract on the condition that the electronic signatures of the specified number of qualified persons are entered. The witness-type electronic signature remains in an incomplete state until the electronic signatures of the specified number of qualified persons are entered. When required qualification A is specified for multiple consecutive signature fields, such as signature fields 1 to N, a qualified person who has the required qualification A can use any of the signature fields to sign electronically. When multiple people have specified multiple requested qualifications (for example, requested qualification A, requested qualification B) for the signature 1 to signature N fields, it becomes possible for each person to sign an electronic signature using qualification A or qualification B for any signature field.

[0034] If the desired request entitlement list does not exist, a newly created request entitlement list and its electronic contract file name can be added and saved to the request entitlement signature list 58. Also, the contents of an existing request entitlement signature list can be changed and then saved as a new request entitlement list. When saving these additional requests, a new request entitlement signature number is assigned.

[0035] Regarding the timing of linking the requested qualifications, there are cases where linking is performed in advance when a template is created on the terminal of the user (qualified person or their administrator) or on the qualification signature device 1, and cases where an unlinked template is read from the template DB 54 of the qualification signature device 1 to the user terminal and linked later. In the case of later linking, the linked template is saved in the template DB 54 as a new template.

[0036] Next, signature limitation B will be explained. In Signature Restriction B, a request qualification signature form that specifies the request qualification (qualification information) is embedded in each signature field of the electronic contract, thereby eliminating electronic signatures from persons other than those who are qualified to fulfill the specified request qualification. The request qualification signature form is embedded in each signature field. The requested qualification signature form may be embedded in each signature field by the creator of the electronic contract (unrestricted template), or by a qualified person, the manager of the qualified person, or the operator of the qualification signature device 1, etc., who has read out the unrestricted template from the template DB 54. When an unrestricted template is read from the template DB 54 and a request qualification signature form is embedded, it is stored in the template DB 54 as a template for a new electronic contract. When an electronic contract in which a requested qualification signature form is embedded is acquired by the qualification signature device 1, for example, when it is uploaded by a user, or after it is embedded by the operator of the qualification signature device 1, an electronic signature using the private key of the qualification signature device 1 and a timestamp are attached to it, thereby preventing the requested qualifications from being altered by the embedded requested qualification signature form, guaranteeing that they are correct, and proving their existence. However, it is also possible to store the electronic contract in which the requested qualification signature form is embedded in the template DB 54 with only the electronic signature applied by the qualification signature device 1 or with only a timestamp attached.

[0037] Below, we will use a surgical consent form created in PDF as an example to explain the electronic contract (template) before and after setting up the required qualification signature form. FIG. 4A shows an open-ended template for a surgical consent form before adding a required qualification signature form. FIG. 4B shows a display screen of a surgical consent form in which a request qualification signature form with signature restriction B is embedded in an unrestricted template. FIG. 4C shows a display screen of the surgery consent form with signature limitation B after electronic signature and time stamp by qualification signature device 1.

[0038] As shown in FIG. 4A, the surgical consent form (unrestricted template) before the request qualification signature form is provided has signature fields 401 to 403 for each contracting party at the bottom right. If a witness-type electronic signature is applied to the surgical consent form shown in Figure 4A, it is possible to infer the required qualifications from the wording and format of the electronic contract, such as the names of each signature field (patient name, doctor, explaining nurse), and determine whether they match the signer's qualifications. However, in this case, discrepancies due to inference errors will occur, and a mechanical judgment cannot be made. Therefore, as shown in Figure 4B, a form field is provided for each signature section 401 to 403 of the surgical consent form (electronic contract), and a request qualification signature form specifying the relevant request qualification is embedded in this field, thereby displaying electronic signature symbols 411 to 413 indicating that this is an area where an electronic signature using signature limitation B should be made. For example, in the signature field 402, "SYOMEI01@N001" is embedded as a requested qualification signature form, which is the name of the form field "SYOMEI01" plus the qualification code "N001" (see FIG. 6) of the requested qualification.

[0039] In the signature fields 401 to 403 in which the request qualification signature form is embedded, digital signature symbols 411 to 413 are displayed. Details of the request qualification signature form corresponding to the digital signature symbols 411 to 413 can be confirmed in the latter of the signature field 420a and unsigned field 420b reserved in the signature details column 420 on the right side of the screen. For example, the details corresponding to the signature field 401 of the patient's name are displayed in the details field 421 of the unsigned field 420b, which displays "patient," meaning a patient, and the page on which the signature field 401 exists, "Page: 1." In addition, the details corresponding to the doctor's signature field 402 are written in the details field 422 of the unsigned field 420b, including "@" indicating the embedding of the requested qualification, the qualification code "N001" (see Figure 6) corresponding to the requested qualification, its qualification name "Doctor", and the page "Page: 1" on which the signature field 402 is located. In addition, the details corresponding to the signature field 403 of the explaining nurse are entered in the details field 423 of the unsigned field 420b, which includes "@" indicating the embedding of the requested qualification, the qualification code "N002" corresponding to the requested qualification, its qualification name "Nurse", and the page "Page: 1" on which the signature field 403 is located. Note that FIG. 4B shows an electronic contract in which the required qualification signature form has been embedded in each of the signature fields 401 to 403, and since no actual signature has been made, the signature field 420a is blank.

[0040] By embedding the requested qualification signature form in each signature field of the electronic contract using signature limitation B in this way, the qualification signature device 1 can mechanically and reliably determine whether the qualifications held by the signer match or mismatch the qualifications requested by the requested qualification signature form. In other words, when adding a witness-type electronic signature, the qualification signature device 1 confirms that the requested qualification "N001" is specified after "@" in the embedded requested qualification signature form, and automatically determines whether the account (signatory) has the corresponding qualification (in this case, a doctor) before allowing the electronic signature.

[0041] When an electronic contract with a requested qualification signature form embedded in each signature field 401 to 403 is uploaded to the qualification signature device 1, or when the operator of the qualification signature device 1 completes embedding of the requested qualification signature form, the qualification signature device 1 assigns an electronic signature and a timestamp using the private key of the qualification signature device 1, and stores it in the template DB 54 as a template for a new electronic contract. After this electronic signature and timestamp, in the electronic contract (surgery consent form) with signature limitation B, as shown in Figure 4C, a signature panel 450 is displayed at the top of the surgery consent form, stating that it has been electronically signed by the qualified signature device 1. In addition, by clicking on the signature panel 450, it is possible to check the details of the timestamp attached from the electronic signature panel (not shown) displayed on the left side of the screen. Furthermore, when the qualification signature device 1 issues an electronic signature or the like, the name and email address of the representative of the qualification signature device 1 are displayed in the signature field 420a of the signature details section 420. The electronic contract with the embedded requested qualification signature form after electronic signature and time stamp is stored in the template DB 54 as a template for a new electronic contract.

[0042] Figure 4D shows the screen in which, during a witness-type electronic contract using the qualification signing device 1, an electronic contract (surgery consent form) with signature limitation B is read from the template DB 54 and a qualified signature is made by a doctor who is the requested qualified person. As shown in Figure 4D, after the doctor has completed signing the qualifications corresponding to the requested qualifications in the requested qualification signature form embedded in the signature field 402, the signature field 402 displays the name of the doctor who signed, instead of the electronic signature symbol 412 that was displayed before signing. That is, the signature field 402 displays the signer's "Name", "@", "Qualification Code", and "Qualification Name", as well as the signing date and time. Furthermore, since the doctor has completed signing the qualifications, the details column 422 of the unsigned field 420b corresponding to the signature column 402 is deleted, and the doctor's signature content "Name + @ + qualification number + qualification name" is entered in the signature field 420a.

[0043] Returning to Figure 2, the signature key DB 57 stores the qualification signature keys etc. corresponding to various qualifications issued by the certification authority 7, as well as the common signature keys etc. Multiple qualification signature keys etc. (qualification signature keys and digital certificates) and the common signature keys etc. are managed using predetermined signature key numbers. The digital certificate for each entitlement signing key contains a subject, subject alternative name, or policy OID. This allows the digital certifier to verify that the user (contractor) entering into the digital contract of the witness doll is a licensed doctor, architect, etc., and that the digital signature is based on that license.

[0044] The account DB 55 stores various information about users and the like through account registration processing. Account registration is required for users such as contracting parties and verifiers to have the authority to use the qualification signature service provided by the qualification signature device 1. FIG. 5 conceptually shows the contents stored in the account DB 55. As shown in FIG. 5, the account DB 55 stores an account table 551, a qualification / identification information table 552, and a file table 553 for each user, and is managed by an ID assigned to each user.

[0045] The account table 551 stores basic information necessary to distinguish between the accounts of users who have specified qualifications (who register their qualifications) and users who do not have qualifications (who do not register), such as an ID that identifies the user, a password (PW) required along with the ID when logging in to the qualification signature device 1, the user's name, the name of the organization to which the user belongs (an optional field required if present), an email address, and a telephone number to be used for short message service (SMS).

[0046] The qualification and personal identification information table 552 stores personal identification information 5521, personal identification document data 5522, qualification verification information 5523, qualification verification document data 5524, and qualification code 5525. Personal identification information 5521 and personal identification document data 5522 are data that indicates (specifies) the user and data about the document used for personal identification. The qualification verification information 5523 and the qualification verification document data 5524 are data indicating (identifying) the qualification if the user himself / herself is a qualified person (only if the user wishes to register the qualification (including not only at the time of registration but also at the time of electronic signature)), and data regarding the document used for qualification verification.

[0047] The identity verification information 5521 is information for identifying (confirming) the user who has registered an account, and stores the address, name, sex, date of birth, registered domicile, age, telephone number, identity verification person ID, and identity verification method. Note that the identity verification information 5521 can also include other information such as the user's email address and data in an IC chip that certifies the user's identity. The ID of the person who verified the identity of the user according to the identity verification document data 5522 is the identity verifier ID, and the identity verification method indicates how the identity verification was performed. This identity verifier ID functions as identifying information of the person who verified the identity. The person who verified the identity (identifier) ​​may be the operator of the qualification signature device 1, the organization to which the person belongs (for example, the corporation to which the person belongs), a third-party auditing organization, etc., and the identifying information may be the ID or name of the qualification verifier.

[0048] The personal identification document data 5522 is data relating to the document used (requested to be submitted) when the personal identification person performed the user's identity verification. Examples of identity verification documents include a resident card, driver's license, and My Number card. The personal identification document data 5522 stores the document name, scanned image, classification, identification number, expiration date (next scheduled verification date), etc. of the personal identification document. The expiration date is the one specified (written) on the identity verification document. If an expiration date is not specified, an expiration date (next scheduled verification date) calculated from the date and time of this action can be set as necessary.

[0049] The qualification verification information 5523 is information used to verify that a user who has registered an account has valid qualifications if the user is a qualified person, and stores the address, name, gender, date of birth, registered domicile, age, telephone number, qualification verification person ID, and qualification verification method as a qualified person. The qualification verifier ID is an identification number of the person who confirmed that the user has valid qualifications in accordance with the qualification confirmation document data 5524. This qualification verifier ID functions as identifying information of the person who confirmed the qualifications of the qualified person. The person who confirmed the qualifications (qualification verifier) ​​corresponds to the operator of the qualification signature device 1, the organization to which the qualified person belongs (for example, the hospital to which the qualified doctor belongs), a third-party auditing organization, etc., and the identifying information corresponds to the ID and name of the qualification verifier. The qualification verification method indicates the method used by the qualification verifier to verify the qualification. The specific method of qualification verification is performed in accordance with the provisions for each qualification that are predefined in the qualified person identity verification method in the qualification DB 56 in Fig. 6, which will be described later, or in accordance with the provisions in laws, regulations, or guidelines, if any. The qualifications to be checked include qualifications set by the state or private sector, membership in social insurance or national health insurance, or nationality or residence status, and the qualifications that can be registered are specified in the qualification DB 56 shown in FIG. 6.

[0050] The qualification verification document data 5524 is data relating to the document used (requested to be submitted) when the qualification verifier verified the qualification of the user. Examples of qualification verification documents include qualification certificates such as a doctor's license (copy) or a nurse's license (copy), a driver's license, an IC chip on which qualifications are recorded such as a My Number card, etc.

[0051] Although each qualified person can submit the qualification confirmation documents individually, it also includes a qualification confirmation list (which must include the signature and seal of the relevant person, as well as the date of confirmation, etc.) created after a representative of multiple qualified persons, such as a hospital director or other manager, is appointed as the qualified identity verifier and confirms the qualifications of the qualified persons (doctors, nurses, etc.) affiliated with the hospital. It also includes a qualification confirmation list that compiles multiple different qualifications, such as the attorneys, patent attorneys, administrative scriveners, etc., that are affiliated with a designated general office. In this case, the qualification confirmation list should be submitted in writing as a general rule, but it can also be submitted as electronic data with the administrator's electronic signature instead of a name and seal.

[0052] The qualification confirmation document data 5524 stores the document name, scanned image, classification, identification number, expiration date (next scheduled confirmation date), etc. of the qualification confirmation document. The expiration date is the one specified (written) on the qualification confirmation document, and if no expiration date is specified, an expiration date (next scheduled confirmation date) can be set based on the date and time of the implementation of this action, if necessary.

[0053] The qualification code 5525 stores a qualification code corresponding to the qualification name of the qualified person who has registered the account, and is read from the qualification DB 56 (described later in FIG. 6) and stored. If a user has multiple qualifications, multiple qualification codes are stored.

[0054] The file table 553 stores files to be electronically signed and files that have already been electronically signed, in association with the ID of each account. An electronic signature target file is a file for which a qualification signature, etc., is to be applied. For the electronic signature target file stored here, it is possible to grant each of the permissions for operation, viewing, and access use for each ID within the same organization (for example, various organizations such as a hospital, company, or workplace to which the user of the ID belongs). The digitally signed file is a file of the electronic contract (entitlement-signed electronic contract) after the entitlement signature process (and the addition of a timestamp) according to this embodiment has been performed. In other words, when the entitlement signature process according to this embodiment has been performed between User A and User B, the entitlement-signed electronic contract is stored in the digitally signed file associated with User A's ID, and also in the digitally signed file associated with User B's ID. The electronic contracts after the qualification signature process that are saved in the electronically signed file include not only electronic contracts read from the template DB 54, but also electronic contracts read by the contracting parties from other devices.

[0055] Of the specific information that identifies the user and the user's qualifications stored in the account table 551 and the qualification / identification information table 552, the following data (a) to (g) are recorded as attribute information to be hashed in the qualification signature process. (a) ID, email address, and phone number (SMS) in account table 551 (b) Identity verification information 5521: Identity verification person ID, identity verification method (c) Document name, classification, identification number, and expiration date of identity verification document data 5522 (d) Eligibility verification information 5523 Eligibility verification person ID, eligibility verification method, (e) Document name, classification, identification number, and expiration date of qualification verification document data 5524 (f) Qualification Code 5525 (g) The name of the qualification, the location of the qualification table, and the method of verifying the identity of the qualified person stored in the qualification DB56 corresponding to the qualification code. However, among these pieces of specific information, (a) other than the ID, email address, and telephone number (SMS) in the account table 551, as for the qualification information that can confirm the qualification of the user (qualified person), it is not necessary to record all of them in the attribute information (reason for electronic signature); at least one of them may be recorded. For example, in the case of one, it may be the qualification code of the qualification code 5525 or the qualification name. This enables the contracting parties and third parties to verify, by the attribute information, that the electronic contract that has undergone the qualifications signature process by the qualifications signature device 1 is a contract made by at least one qualified person. In addition, the attribute information for the qualification signature may store either the identity verifier ID or the identity verification method in (b), or either the identity verifier ID or the qualification verification method in (d).

[0056] For electronic signatures corresponding to users who do not have qualifications (non-qualified persons) or users who have qualifications but do not wish to issue a qualified signature using their qualifications, the ID, email address, and telephone number (SMS) in (a) account table 551 are recorded in the attribute information (reason for electronic signature).

[0057] Returning to FIG. 2, the qualification DB 56 is a database of qualifications defined as targets of qualification signature processing according to this embodiment. FIG. 6 conceptually shows the contents stored in the qualification DB 56. As shown in FIG. 6, the qualification DB 56 stores the qualification name, qualification code, method of verifying the identity of the qualified person, location of the qualification comparison table, location of the qualification signature key, etc. The qualification name is a name that indicates the qualification, and examples include doctor, financial planner, Japanese nationality, and the like. The qualification code is a regular set of letters, numbers, symbols, and symbols that are uniquely assigned to each qualification, and is the object of storage of the qualification code 5525. For example, as shown in FIG. 6, a doctor's qualification code "N001", a nurse's qualification code "N002", and so on are defined and stored.

[0058] The method of verifying the identity of a qualified person is specified for each qualification code. Examples of specific methods prescribed in the Qualified Person Identification Act include the following (i) to (iv) and various other methods. For these verification methods for qualified person identity verification, one or more methods are specified for each qualification, and the method used to actually verify the qualified person's identity is saved as the qualification verification method in qualification verification information 5523 in qualification / identification information table 552. (i) In person, you will be asked to submit the required documents (copy of license (medical license in the case of a doctor), copy of resident registration, email address, telephone number / license certificate, photo ID). (b) Public personal authentication will be carried out non-face-to-face using eKYC (electronic Know Your Customer). (c) The representative of the organization (e.g., the hospital director) will verify the qualifications and identities of the qualified personnel affiliated with the organization and submit a list of the qualified personnel's identity and qualification information (name, address, gender, date of birth, qualification name, qualification code, etc.) and a paper copy of the qualification certificate. (d) The operator (verification officer) of the qualification signature device 1 verifies the notification documents (copy of qualification certificate, copy of ID) of the qualified person. During verification, the "qualification verification information" is read from the ID etc. and is entered into an external database to confirm that the qualified person actually exists.

[0059] The location of the qualification comparison table is the URI (Uniform Resource Identifier) ​​of the qualification comparison table 61 that the list publication server 6 has published on the Internet or the like. The location of the qualification signature key, etc. is the address where the qualification signature key for the electronic signature used in correspondence with each qualification code and its electronic certificate are stored, and the address where the common signature key and its electronic certificate are stored. In the list disclosure server 6 of this embodiment, the qualification comparison table 61 is classified by predetermined qualification (for example, medical, law, architecture, etc.), and the qualification comparison table 61 for each classification is made public. For this reason, a different URI is defined for each classification for the location of the qualification comparison table in the qualification DB 56. However, it is also possible to use a single qualification comparison table 61 that compiles all qualifications, and correspondingly define the same URI for the location of the qualification comparison table in the qualification DB 56.

[0060] Next, various processing operations performed by a qualification signature system using the qualification signature device 1 will be described. FIG. 7 is a flowchart showing the flow of account registration processing by the entitlement signature system. This account registration process is a process for registering an account for each user as a prerequisite for the qualification signature process according to this embodiment, and is performed in the qualification signature device 1 by the CPU 11 executing the account registration PG52 of the storage device 5. In the following explanation, the process performed by the CPU 11 executing various programs will be explained as the operation of the qualification signature device 1 (the same applies to the user terminal 9). 7, a hospital-related account registration process will be described as an example of account registration. That is, the account registration process will be described from a user terminal 91 of a doctor (qualified person) who is a user belonging to a predetermined hospital, a user terminal 94 of an administrator (qualified person) of the hospital, and a user terminal 92 of a patient (unqualified person).

[0061] As shown in Figure 7, when an unqualified patient registers an account, the patient's user terminal 92 submits the user's (patient's) identification card, such as a resident registration card, My Number card, or driver's license, to the qualification signature device 1 as registration information (step 921).

[0062] On the other hand, when a qualified doctor registers an account, the doctor submits his / her medical qualification certificate as a document verifying his / her qualifications, and personal identification such as a resident registration card, My Number card, or driver's license as registration information to the qualification signature device 1 or the administrator (step 911). In addition, when the registration information is submitted to the administrator rather than the qualification signature device 1, the doctor's account is submitted to the qualification signature device 1 from the user terminal 94 together with other qualified persons using an identity confirmation list created by the administrator, rather than from the doctor's own user terminal 91.

[0063] That is, the administrator receives the qualifications and identification cards of doctors, nurses, physical therapists, occupational therapists, etc. who belong to the organization (here, a hospital) that the administrator manages, and verifies their qualifications and identities (step 941). Then, the administrator's user terminal 94 compiles the submitted qualifications and personal identification cards to create a qualification and personal identification information list, and stores it in the user terminal 94 or the database of the hospital to which the user belongs (step 942). The qualification and identity verification information list created here is a list of the contents of the account table 551 and qualification and identity verification information table 552, excluding the ID.

[0064] The administrator then records the administrator's name and seal, the confirmation date, etc. on the created qualification and identity verification information list, and submits it to the qualification signature device 1 (step 943). The submission method can be various methods, including sending the PDF data of the qualification and identity verification information list as an email attachment, and details will be explained in the processing on the user terminal 92 side.

[0065] When registration information is submitted by the user terminal 9 or the user, the entitlement signature device 1 acquires it (step 101). Here, there are various patterns for submitting registration information and obtaining registration information, as follows: (a) When an unqualified person, a qualified person, or an administrator submits a physical medium (copy, printout) or data of the registration information (by mail, email attachment, upload, etc.) and the qualification signature device 1 receives it. (b) When the user accesses the account registration screen of the qualification signature device 1 from the user terminal 9 and inputs each item of registration information

[0066] If the acquired registration information includes a qualification such as a qualification name, the qualification signature device 1 refers to the qualification comparison table 61 of the list publication server 6 and acquires a qualification code corresponding to the qualification (step 102). The qualification signature device 1 then determines whether or not there is a qualification code corresponding to the qualification included in the registration information (step 103), and if there is no qualification code (step 103; N), it sends a registration information error to the corresponding user terminal 9 (step 104. Note that if the registration information is not submitted from the user terminal 9 but by mail, etc., the sender user is notified of the mail error.

[0067] In the case of registration information of an unqualified person, or if there is a qualification code corresponding to the qualification contained in the registration information (step 103; Y), the qualification signature device 1 confirms the contents of the registration information (including personal identification) and stores it in the account DB 55 with an ID for each account (step 105). That is, if the registration information is of an unqualified person, the operator of the qualifications signature apparatus 1 checks the contents of the acquired registration information and stores it in the account table 551 . On the other hand, if the registration information is from an individual qualified person, the operator of the qualification signature device 1 checks the contents of the registration information (including identity verification and qualification verification) and stores it in the account table 551 and qualification / identity verification information table 552. Also, if the registration information is from an administrator (qualification and identity verification information list), the details of each listed qualified person are checked, and an ID for each qualified person is attached and stored in the account table 551 and the qualification and identity verification information table 552. As for the qualification code 5525 in the qualification / personal verification information table 552, the qualification code acquired in step 102 is saved.

[0068] Registration information can be confirmed and saved using the following methods. That is, the operator of the entitlement signature device 1 checks the contents of the submitted physical medium, inputs them, and saves them. In addition, there are cases where a user inputs information into an input form for account registration provided by the qualification signature device 1 from the user terminal 9, and the contents are confirmed and saved by the administrator. In this case, it is possible to automatically register an account by simply completing online identity verification (eKYC).

[0069] The above has been a description of the registration of an account in the qualification signature device 1, but the same applies to updating (modifying, adding) an already registered account. However, when updating, since an account already exists, the user submits registration information including the account and any information to be corrected or added. If an account exists in the acquired registration information, the qualification signature unit 1 determines that the request is an update request and updates the contents of the account.

[0070] When the registration / update of the account is completed, the credential signature device 1 notifies the user of the account of the registration / update (step 106), and ends the process.

[0071] Next, the process of signing an electronic contract by a user who has registered an account will be described. FIG. 8 is a flowchart showing part of the flow of the entitlement signature process by the entitlement signature system, and FIG. 9 is a flowchart showing the rest of the process. 8 and 9, an example will be explained in which a qualified person (doctor) and an unqualified person (patient) make an electronic contract with witnesses, and the qualified signature process for a surgical consent form (electronic contract) is performed using user terminals 91, 92 and the qualified signature device 1 with signature limitation A or signature limitation B. It is assumed that both the doctor and the patient have completed account registration.

[0072] As shown in FIG. 8, the doctor logs in to the electronic signature service provided by the qualification signature device 1 from the user terminal 91 (step 912). That is, the doctor opens the login screen of the electronic signature service on the user terminal 91 , enters the ID and password (PW) of his / her account, and transmits them to the qualification signature device 1 .

[0073] When the qualification signature device 1 receives the ID and PW transmitted from the user terminal (doctor) 91, it checks whether or not they have been registered in the account DB 55 and performs login authentication (step 110). When the login authentication is completed, the qualification signature apparatus 1 notifies the user terminal (doctor) 91 of the completion of the login authentication, and temporarily stores the ID of the logged-in doctor in the RAM 13. On the other hand, if at least one of the ID and PW is not registered, a login error is returned to the user terminal (doctor) 91.

[0074] When the login to the electronic signature service is completed, the user terminal (doctor) 91 ULs (uploads) or calls up the electronic contract with signature restrictions that is the subject of the electronic contract, and displays it on the screen (step 913). Here, the surgical consent form with signature limitation A, in which the requested qualification signature number 01 (see Figure 3) is linked to the surgical consent form shown in Figure 4A, or the surgical consent form with signature limitation B shown in Figure 4C (after electronic signature by qualification signature device 1) is the target.

[0075] That is, the user terminal (doctor) 91 reads out a surgical consent form that has any signature restriction and is stored in its own device or in a designated storage device managed by the hospital, and uploads it to the qualification signature device 1 as the surgical consent form to be subject to this qualification signature process. On the other hand, if the user terminal (doctor) 91 does not use the surgery document stored in its own device or in a hospital-managed storage device, the user terminal (doctor) 91 accesses the template DB 54 stored in the storage device 5 of the qualification signature device 1 and calls up the desired surgery consent form.

[0076] When a consent form for surgery is uploaded from the user terminal (doctor) 91, the license signature device 1 affixes an electronic signature and a timestamp to the consent form using the private key of the license signature device 1, and then stores the electronic signature file in the file table 553 corresponding to the doctor's ID. Note that the file may be stored in the template DB 54 with the doctor's consent. On the other hand, if a surgery consent form is called up by access, the qualification signature device 1 reads out the corresponding surgery consent form template (electronic contract) from the template DB 54 and provides it to the user terminal (doctor) 91 (step 111).

[0077] FIG. 10 shows a display screen of the surgery consent file displayed on the user terminal (doctor) 91. The surgery consent file shown in FIG. 10 is a surgery consent file that is created and saved in advance, for example, in the hospital to which the doctor belongs. As shown in FIG. 10, the display screen for the surgery consent form file displays a form field 801, a thumbnail field 802, an in-house management field 803, a delivery address field 804, a signature selection button 809, and the like. In the form field 801, the file name "Surgery Consent Form 11.pdf" is recorded, along with the expiration date, transmission date and time, sender, etc. In the example of Figure 10, the sender field records that the document was created by "Takumi Fuko," an office worker at Memorial Hospital. The thumbnail field 802 displays thumbnail images linked to the "surgery consent form" that is the subject of the qualification signature process. The doctor and patient, who are the contracting parties, can click on this thumbnail image to confirm the contents of the displayed surgery consent form (see Figures 4A to 4C) and agree to the electronic signature by the qualification signature device 1.

[0078] The in-house management column 803 is a column where the created information for management within the hospital is entered. The destination column 804 records the names of the contracting parties to this surgery consent form (Doctor Iida Taro and outpatient Masao) and the destination of the surgery consent form for each of them. The signature selection button 809 is a button that displays a selection screen for the type of electronic signature (general, qualified, etc.) for the surgical consent form. This signature selection button 809 can only be selected after the user has selected the thumbnail field 802 and displayed and confirmed the surgical consent form at the linked destination.

[0079] FIG. 11 shows the electronic signature selection screen that is displayed when the signature selection button 809 is selected. The electronic signature selection screen functions as an electronic signature request form for the contracting parties to request a qualification signature from the qualification signature device 1. As shown in FIG. 11, the electronic signature selection screen displays a signature qualification selection field 901, a qualification signature request button 909, and the like. The signature qualification selection field 901 specifies the types of signatures that can be selected in relation to the contract (surgery consent form), including a general signature without a qualification, a qualification signature (Japanese nationality), a qualification signature (physician), a qualification signature (dentist), etc. The qualification signature request button 909 is a button for requesting the qualification signature apparatus 1 to issue an electronic signature corresponding to any one of the selected signature forms.

[0080] Here, the user terminal (doctor) 91 determines whether the qualifications (doctor) of the terminal user match any one of the required qualifications specified in the signature restrictions of the surgery consent form, i.e., whether the required qualification corresponding to the user's qualifications (doctor) is specified in the signature restrictions of the surgery consent form (hereinafter referred to as a match determination), and if they are not specified, outputs an error, and if they are specified (match), displays only the relevant signature field as selectable. In this case, the processing is being performed by a qualified person (physician), so as shown in Figure 11, only the qualification signature (physician) field is activated and selectable, and is displayed in a dark color, while the general signature field and other qualification signature fields are deactivated and cannot be selected, and are displayed in a light color.

[0081] In this embodiment, the user terminal (doctor) 91 determines whether the user qualifications match the qualifications required in the surgical consent form, and creates an electronic signature selection screen (see Figure 11) in which only the relevant qualification signature field or general signature field is activated (selectable), but these tasks may also be performed by the qualification signature device 1. In this case, the user terminal (doctor) 91 transmits to the qualification signature device 1 that the signature selection button 809 has been selected, and the qualification signature device 1 determines whether the ID of the currently logged-in doctor temporarily stored in RAM 13 matches the qualification restrictions on the surgery consent form.If there is a match, it creates the electronic signature selection screen shown in Figure 11 and transmits it to the user terminal (doctor) 91.

[0082] Returning to FIG. 8, the user terminal (doctor) 91 designates users other than the doctor (patient, nurse) for the surgery consent form (step 914). That is, the doctor inputs his / her name, destination, and the patient's name and destination in the destination column 804 . However, this step 914 can be omitted if the information has already been entered by the creator of the file, as in the surgery consent file shown in FIG.

[0083] Next, on the user terminal (doctor) 91, the thumbnail image in the thumbnail column 802 is clicked to display the "Surgery Consent Form." That is, by clicking the thumbnail image, the surgery consent form shown in Figure 4A is displayed in the case of signature limitation A, and the surgery consent form in Figure 4C is displayed in the case of signature limitation B. The user, who is a doctor, checks the contents of the surgical consent form displayed on the user terminal (doctor) 91 and enters his / her name in the signature field 402 (see Figures 4A and 4C) in the surgical consent form (or checks the name if it has already been entered by the creator).

[0084] In this embodiment, an example of a surgical consent form with signature restrictions A and B is used for explanation. However, if the conditions for required qualifications are described in a script in an electronic contract such as a surgical consent form, it is also possible to display a signature selection screen so that signatures can be selected only for the types of qualifications described.

[0085] Thereafter, the doctor selects the signature selection button 809 (see FIG. 10) displayed on the screen of the user terminal (doctor) 91 to display the electronic signature selection screen (see FIG. 11). Here, as described above, based on the signature limitation (signature limitation A or signature limitation B), only the qualification signature (physician) field is activated and selectable. The user (doctor) then checks the checkbox in the selectable Qualification Signature (Doctor) field to make a selection. As a result, user terminal (doctor) 91 transmits to qualification signature apparatus 1 that "qualification signature (doctor)" has been selected (step 915).

[0086] When the "license signature (doctor)" is notified from the user terminal (doctor) 91, the license signature device 1 checks the license code associated with the ID (step 112). That is, the qualification signature device 1 reads the ID stored in RAM 13 in step 110, compares the qualification identified by the qualification code 5525 (see Figure 5) associated with this ID with the qualification in the notified signature form (in this case, a doctor), mechanically determines whether the two match, and returns confirmation information to the user terminal (doctor) 91 if they match, or mismatch information if they do not match. When confirmation information is returned, the user terminal (doctor) 91 makes the qualification signature request button 909 shown in Figure 11 selectable, and when discrepancy information is returned, a message to that effect is displayed on the screen, and the user must change to a different qualification signature format.

[0087] When the doctor selects the qualification signature request button 909, which has become selectable, the user terminal (doctor) 91 transmits a request (request) for an electronic signature based on the qualification to the qualification signature device 1 (step 916), and the qualification signature device 1 receives the request for an electronic signature (step 113).

[0088] Then, the license signature device 1 checks the expiration date of the license corresponding to the doctor's ID stored in the RAM 13 (step 114). That is, the qualifications signature apparatus 1 determines that the ID is within the validity period if the validity period stored in the qualifications verification document data 5524 corresponding to the ID is later than the current time (current date). It is also possible to determine that the expiration date is within the expiration date if the expiration date is a predetermined period T or more from the current date. In this case, the predetermined period T is arbitrary, but a default period is set to, for example, one month. If the license expiration date has passed (step 114; N), the license signature device 1 sends an error screen (expiration date exceeded) to the user terminal (doctor) 91 (step 115), and the user terminal (doctor) 91 displays the error screen to notify the doctor that the expiration date has passed.

[0089] On the other hand, if the license is within the validity period (step 114; Y), license signature device 1 creates attribute information to be attached to the surgery consent form (step 116). That is, the qualification signature device 1 refers to the account DB 55 corresponding to the ID of the doctor who has been requested to sign, reads out each of the above-mentioned data (a) to (g) from the account table 551 and the qualification / identification information table 552, and creates attribute information to be attached to the surgery consent form.

[0090] Thereafter, the entitlement signing device 1 executes the entitlement signing to create a "primary signed electronic contract" (step 117). That is, the qualification signature device 1 checks the location of the qualification signature key, etc. from the qualification code 5525 of the qualification (doctor) corresponding to the signature form notified by the user terminal (doctor) 91 in step 915, reads the qualification signature key, etc. (qualification signature key and electronic certificate) for the qualification (doctor) from the signature key DB 57, temporarily stores it in RAM 13, and executes the qualification signature using the qualification signature key, etc.

[0091] Figure 12 is an explanatory diagram conceptually showing the structure of a qualified signature electronic contract after a qualified signature has been made. Note that Figure 12 does not show a specific surgery consent form, but rather a more generalized structure after parties A and B have executed a qualified signature, etc., on an electronic contract (including a surgery consent form). The execution of the entitlement signature using the entitlement signature key and the like in step 117 will be described below with reference to FIG. The qualification signing device 1 attaches the attribute information 122 of contract holder A (doctor) created in step 116 to the ``electronic contract (original) 120'' (surgery consent form), creates a ``first electronic contract'' 123, and calculates a hash value 124 of this first electronic contract.

[0092] Furthermore, the qualification signature device 1 calculates the signature value 125 by encrypting the calculated hash value 124 using the qualification signature key (private key) corresponding to the signature type (qualification signature (doctor)) notified by the user terminal (doctor) 91 in step 915. The qualification signature device 1 creates a "primary signature electronic contract" 127 based on Party A's request (qualification signature (doctor)) by embedding the calculated signature value 125 and the "electronic certificate" 126 corresponding to the used qualification signature key into the "first electronic contract" 123. Although the digital certificate is embedded in the "primary signed digital contract" 127, both the digital certificate and revocation information may be embedded. If revocation information is not embedded, it is necessary to check whether the digital certificate has been revoked based on the revocation information of the certification authority 7 that issued the digital certificate.

[0093] Returning to FIG. 8, after the qualification signature based on the request of the user (doctor) (step 117) is completed, the qualification signature device 1 transmits a qualification signature completion screen to the user terminal (doctor) 91 that requested the qualification signature (step 118). On the other hand, the user terminal (doctor) 91 displays the received qualification signature completion screen to notify the user (doctor) (step 917).

[0094] Next, a qualified signature (nurse) is made on the "Primary Signature Electronic Contract" 127 using the qualified signature key (private key) corresponding to Hanako Iida, a nurse, who is specified as the second signatory in the delivery address field 804 of Figure 10. The qualified signature process (nurse) for this "Primary Signature Electronic Contract" 127 is carried out in the same manner as the qualified signature process (doctor) for the "Electronic Contract (Original) 120" (Surgery Consent Form), so an overview of this process is provided below. That is, after the qualification signature process (doctor) is completed, the qualification signature device 1 sends the URL where the "primary signature electronic contract" 127 is saved to the email address of the nurse's user terminal (nurse) 91, and prompts the user to confirm it and request an electronic signature. Here, the email address of the user (nurse) is the email address of the user (nurse), Hanako Iida, specified in the delivery address field 804 in Figure 10. The user (nurse) who receives the request for electronic signature by email accesses the specified URL from the user terminal (nurse) 91 and displays the "primary signature electronic contract" 127 on the screen. At this time, the user (nurse) enters his / her own ID and password, and the qualification signature device 1 performs login authentication in the same way as in the case of a doctor (step 110). Thereafter, in the same manner as in the case of the doctor, steps 914 to 917 are processed at the nurse's user terminal (nurse) 91, and steps 112 to 118 are processed at the qualification signature device 1.

[0095] Next, the user (patient), who is specified as the third signatory in the delivery address field 804 in Figure 10, will sign the "Primary Signature Electronic Contract No. 2" using the common key (private key). In this embodiment, the electronic signature of the user (patient) is specified as the third, so the "primary signature electronic contract no. 2" is the subject of the signature. On the other hand, if another qualified person is specified as the required qualification, and the user (patient = non-qualified person) is specified as the fourth signatory, the "Primary Signature Electronic Contract No. 3" will be subject to a general signature by the user (patient). In addition, if the only person qualified to make the request is a doctor and the user (patient) is specified as the second signatory, the “Primary Signature Electronic Contract” 127 is subject to a general signature by the user (patient). Therefore, in the following explanation, we will explain the case where there is only one requesting party, the user (patient) is specified as the second signatory, and the ``Primary Signature Electronic Contract'' 127 is the subject of a general signature.

[0096] As shown in Figure 9, the qualification signature device 1 presents the "primary signed electronic contract" 127 to the user terminal (patient) 92 of the user (patient) who is an unsigned contracting party (step 119), and displays it on the screen of the user terminal 92 (step 922). That is, the qualification signature device 1 sends the URL where the "primary signature electronic contract" 127 is saved to the telephone number of the user (patient) by SMS, and prompts the user to confirm and request an electronic signature. Here, the telephone number of the outpatient Masao, who is the user (patient) specified in the delivery address field 804 of Figure 10, is used as the telephone number for the SMS. If the delivery address field 804 is not specified, the telephone number of the user, etc. specified from the user terminal (doctor) 91 in step 914 is used.

[0097] The user (patient) who receives the request for electronic signature via SMS accesses the specified URL from the user terminal (patient) 92, and after the user (patient) enters his / her ID and password and is authenticated, the "Primary Signature Electronic Contract" 127 is displayed on the screen (step 922). The user (patient), like the user (doctor), clicks on the thumbnail image in the thumbnail field 802 (Figure 10) of the "First Signature Electronic Contract" 127 displayed on the screen to display the "Surgery Consent Form," confirm its contents, and enters the patient's name in the signature field 401 (see Figures 4A and 4C) in the surgery consent form (or confirms the name if it has already been entered by the creator). Furthermore, the patient selects the signature selection button 809 to display the electronic signature selection screen. On this electronic signature selection screen, since the user (patient) is determined not to be a qualified person based on their ID, only the general signature field is active and selectable, unlike Figure 11, where only the qualified signature (physician) field is active. The user (patient) makes a selection by checking the checkbox in the general signature field that is available. If a general signature is selected, the qualifications signature device 1 does not need to verify the qualification code (step 112), and therefore the qualifications signature device 1 makes the qualifications signature request button 909 selectable. When the user (patient) selects the qualification signature request button 909, the user terminal (patient) 92 requests a general signature from the qualification signature device 1 (step 924).

[0098] When the qualification signature device 1 receives an electronic signature request from the user terminal (patient) 92, it creates attribute information to be attached to a "primary signature electronic contract" 127 including the surgery consent form (step 120). That is, since the request for an electronic signature is a general signature, the qualification signature device 1 refers to the account DB 55 corresponding to the ID of the user (patient), reads the ID, email address, and telephone number (SMS) from the account table 551, and creates attribute information.

[0099] Then, the entitlement signature unit 1 reads out the common signature key from the common key DB 58 and executes the general signature (step 121). That is, as shown in Figure 12, the entitlement signature device 1 attaches the created attribute information (attribute information of Contractor B) to the "primary signed electronic contract" 127 to create a "secondary electronic contract" 132, calculates a hash value 133 of this "secondary electronic contract" 132, encrypts it with a common signature key, and calculates a signature value 134. The entitlement signature device 1 embeds the calculated signature value 134 and the "digital certificate" 135 corresponding to the common signature key into the "second digital contract" 132, thereby creating a "entitlement signature digital contract" 136 based on the request of the doctor (party A) and the patient (party B). Note that revocation information can also be embedded together with the digital certificate 135, as in the case of the entitlement signature.

[0100] At this stage, the qualification signature device 1 transmits a general signature completion screen indicating that the general signature based on the request from the patient has been completed to the user terminal (patient) 92 (step 122), and the user terminal (patient) 92 displays the received general signature completion screen to notify the user (patient) (step 925).

[0101] The entitlement signature device 1 further requests the timestamp server 8 to assign a timestamp to the "entitlement signature electronic contract" 136, and creates a "entitlement signature electronic contract (TS)" 138 (step 123). Then, the "Qualification Signature Electronic Contract (TS)" 138 is stored in the electronically signed file in the file table 553 of the two parties in the account DB 55 associated with the ID of the user (doctor) who signed the qualification and the ID of the user (patient) with a predetermined signature management number, and is also sent to the user terminal (doctor) 91 and the user terminal (patient) 92 (step 124), thereby completing the qualification signature process. Meanwhile, the user terminal (doctor) 91 and the user terminal (patient) 92 display the received "Qualification Signature Electronic Contract (TS)" 138 on their screens, and after the doctor and patient have confirmed it, they save it in a designated storage device in accordance with the save processing operation (steps 918 and 926), thereby completing the process.

[0102] Next, the verification process of the entitlement signature electronic contract (TS) will be explained. FIG. 13 is a flowchart showing the flow of verification processing for a qualification-signed digital contract (TS) that has been qualified. Note that the verification of the qualified signature electronic contract (TS) is performed not only by the parties to the contract, but also by qualified administrators and other verifiers, and therefore is shown as a user terminal 95 used by these persons. As shown in FIG. 13, the user terminal (verifier) ​​95 displays on the screen the entitlement signature electronic contract (TS) designated based on the operation of the verifier (step 951). When the verifier selects the verification button, the signature management number attached to the qualifications signature electronic contract (TS) is transmitted to the qualifications signature device 1 to request verification (step 952).

[0103] The entitlement signing device 1 reads out the entitlement signing electronic contract (TS) with the specified signature management number, and checks whether it has been tampered with and whether it has expired (step 131). That is, the entitlement signing device 1 obtains a hash value 133 of the second electronic contract 132 by decrypting the signature value 134 using the public key described in the digital certificate 135 embedded in the entitlement signing digital contract (TS). This hash value 133 is a value calculated in the entitlement signing process. Furthermore, the entitlement signing device 1 obtains a new hash value for verification from the second electronic contract 132 (see FIG. 12) and verifies that this matches the hash value 133.

[0104] In addition, the entitlement signature device 1 obtains a hash value 124 of the first electronic contract 123 by decrypting the signature value 125 using the public key described in the electronic certificate 126, and verifies that it matches the hash value of the first electronic contract 123 calculated for verification purposes. If the hash values ​​133 and 124 match, the entitlement signing device 1 verifies that the electronic contract (original) is not tampered with.

[0105] Furthermore, the qualification signature device 1 checks the expiration date by verifying that the expiration date recorded based on the qualification confirmation document data 5524 is later than the qualification signature date and time of the qualification signature electronic contract (TS) being verified. This verification proves that the electronic contract was made by a qualified person holding valid credentials. It is also possible to use the acquisition date and time of a timestamp instead of the date and time of signing the credentials. In this case, the credentials signing device 1 verifies that the expiration date of the credentials is later than the acquisition date and time of the timestamp.

[0106] In this way, not only can it be verified that the qualified signature electronic contract (TS) has not been tampered with, but by including the expiration date of the qualification in the attribute information that is the subject of the signature (the subject of hashing), it can also be verified that the electronic contract has been qualified and signed at the request of a qualified person who holds a valid qualification.

[0107] After checking for tampering and expiration date, the certificate signing device 1 presents the verification result to the user terminal (verifier) ​​95 (step 132), and the user terminal (verifier) ​​95 displays the verification result on the screen (step 953). The user (verifier) ​​can confirm from the verification results displayed on the screen that the entitlement signature electronic contract (TS) has not been tampered with and that the entitlement signature device 1 has verified that the entitlement signature was made within the validity period of the entitlement.

[0108] Furthermore, based on the operation of the verifier who specifically wishes to have the qualifications verified, the user terminal (verifier) ​​95 displays a qualification comparison table on the screen (step 954). That is, the user terminal (verifier) ​​95 reads the location (URI) of the qualification comparison table recorded in the attribute information 122 of contractor A (qualified person) in the qualification signature electronic contract (TS) 138, accesses the list publication server 6 to read the qualification comparison table 61, and displays it on the screen. The user terminal (verifier) ​​95 further displays the qualification comparison table, as well as attribute information and the contents of the electronic certificate in accordance with the verifier's operations.

[0109] The verifier can confirm the following (A) to (E) by referring to and comparing the entitlement comparison table displayed on the user terminal (verifier) ​​95 with the contents of the entitlement signature (attribute information 122, 131, electronic certificate 126, 135, etc.) (step 955). (A) It can be confirmed that the name of the qualification that the qualification signing device 1 has determined the contractor has is written in the attribute information 122 of the qualification signing electronic contract (TS) 138. Alternatively, the common name of the digital certificate used in the qualification signature can be confirmed. (B) You can refer to the qualification comparison table 61 to check the qualification code corresponding to the qualification name. Or, it can be confirmed that the common name of the digital certificate in (A) above corresponds to the name of the qualification.

[0110] (C) It can be confirmed whether the qualification name recorded in the attribute information 122 of the qualification signature electronic contract (TS) 138 matches the qualification comparison table 61. This allows verification that the credential signing was performed by the appropriate entity. (D) It can be confirmed that the expiration date written in the attribute information 122 is later than the date and time of the qualification signature recorded in the qualification signature electronic contract (TS) 138. This allows us to confirm that the user's (qualified person's) account has been registered and provided after proper qualification verification has been carried out. (E) By referring to the "Identity Verification Method" and "Qualification Verification Method" in the Qualification Comparison Table 61, it is possible to confirm whether the qualification verification and identity verification of the qualified person have been carried out appropriately. It can also be confirmed that a third party also follows the policies of the "identity verification method" and "qualification verification method" established by the qualification signature device 1 or the organization (company, hospital, etc.) to which the qualified person belongs.

[0111] As explained above, in the case of an electronic contract using a witness-type electronic signature, if the contracting parties are qualified persons with specified qualifications such as doctors or architects, the qualification signature device 1 performs a preliminary qualification check and party check before registering an account. Then, an electronic signature (qualification signature) is applied to electronic contracts such as surgical consent forms using a qualification signature key that differs for each qualification and an electronic certificate that contains qualification information indicating that the person is the holder of the qualification corresponding to the qualification signature key, so that the qualifications held by the contracting parties can be confirmed from the electronic contract with the qualification signature (qualification signature electronic contract 136 or qualification signature electronic contract (TS) 138) (this is called the first qualification confirmation configuration). In addition, when signing a qualification signature, at least one piece of qualification confirmation information is recorded in the attribute information 122 of the qualified person (contractor A), who is the subject of the hash value calculation, so the qualification information of the contracting parties can also be confirmed from the attribute information 122 of the electronic contract to which the qualification signature has been applied (this is called the second qualification confirmation configuration). Furthermore, the account of each qualified person records the person who confirmed the qualification and the expiration date, and these are recorded in the attribute information, so it is possible to verify that the electronic contract was made by a qualified person with valid qualifications.

[0112] In the qualification signature device 1 of this embodiment, when at least one of the contracting parties in a witness-type electronic contract is a qualified person, signature restrictions are imposed on each signature field of the electronic contract such that only persons with the qualifications required in that signature field can sign (signature restriction A that links a list of required qualifications to the electronic contract, signature restriction B that embeds a required qualification signature form in each signature field, etc.), thereby making it possible to more reliably execute electronic signatures based on appropriate qualifications. The qualification signature device 1 limits the required qualifications for each signature field in an electronic contract, so it can mechanically and reliably determine whether the limited qualifications match or do not match the qualifications held by the signer.

[0113] In addition, in the qualification signature device 1 of this embodiment, electronic contracts with signature restrictions used in witness-type electronic contracts between contracting parties including qualified persons are used that are affixed with an electronic signature using the private key of the qualification signature device 1 and a timestamp at least before the electronic contract is made. This allows electronic contracts and requested entitlement information (requested entitlement lists, requested entitlement signature forms, scripts, etc.) to be circulated in a manner that allows the identity of the issuer (entitlement signature device 1) and the non-tampering and existence of the requested entitlements to be provably verified.

[0114] When an electronic signature using the private key of the entitlement signature device 1 is made without including attribute information of the contracting parties, it can be shown that the electronic contract is registered in the service of the entitlement signature device 1 or that it is an electronic contract. An example of this case would be a template for an electronic contract provided by the entitlement signature device 1. On the other hand, when adding a witness-type electronic signature containing the contracting party's attribute information to the electronic signature made by the Qualification Signature Device 1, the creator of the template for the electronic contract can be indicated. An example of this case is a template for medical consent supervised by a lawyer that specifies the required qualifications of the signer from the perspective of medical procedures, treatment contents, and informed consent. (For example, for outpatient surgery with low risk to life, only a doctor is required. For high-risk surgery, a nurse who will be present to explain the procedure may be added in addition to the doctor.)

[0115] Although the embodiment of the entitlement signature device 1 has been described, the following modifications are possible. For example, in the embodiment described above, the case where entitlement signatures are performed using both the first entitlement verification configuration and the second entitlement verification configuration has been described. Alternatively, the entitlement signature may be performed using only one of the first entitlement verification configuration and the second entitlement verification configuration. The structure of the qualification signature electronic contract 136 (138) in these cases will be described with reference to FIG.

[0116] When only the first credential verification configuration is used, the credential signing device 1 enters the above-mentioned information (a) in the attribute information 122 of contractor A (qualified person), similar to the attribute information 131 of contractor B (unqualified person), but does not enter the information (b) to (g). Then, as in the embodiment, the credential signing device 1 issues an electronic signature (credentials signature) using a credential signing key corresponding to the credential and an electronic certificate describing credential information indicating that the person is the holder of the credential corresponding to the credential signing key.

[0117] When only the second qualification verification configuration is used, the qualification signature device 1 enters information (a) to (g) in the attribute information 122 of contractor A (qualified person) as in the embodiment, and performs an electronic signature (general signature) on the hash value 124 using a common signature key and an electronic certificate. When only the second qualification confirmation configuration is used, the qualification signature device 1 may attach the attribute information of all contracting parties (qualified parties enter (a) to (g) and unqualified parties enter (a)) together to the first electronic contract 123, as shown in Figure 14, and perform a general signature using a common signature key and electronic certificate. In this case, the attribute information for qualified parties will be (a) to (g), and the attribute information for unqualified parties will be (a).

[0118] In addition, in the described embodiments and variants, the case where the qualification signature device 1 performs the qualification signature process based on confirmation and signature requests for the surgical consent form from two parties, a doctor from the user terminal (doctor) 91 and a patient from the user terminal (patient) 92, has been described. On the other hand, it is also possible to perform qualification signature processing for signature requests from three or more contracting parties, for example, a qualified doctor, a patient, and the patient's guarantor, using the qualification signature device 1. In this case, the qualification signature device 1 performs qualification signature processing using a qualification signature key or the like for the signature request from the qualified doctor, issues a general signature using a common key or the like for the signature request from the patient, and issues a general signature using a common key or the like for the signature request from the guarantor.

[0119] In the embodiment and modified examples described above, a case has been described in which a qualified person (doctor) signs a certificate and then a general signature is issued in response to a general signature request from a non-qualified person (patient). In contrast, the signature request can come first from either the qualified or unqualified party. When the request from the unqualified party comes first, the first electronic contract (corresponding to first electronic contract 123 in Figure 12) is signed by adding the ID, email address, and telephone number (SMS) to the attribute information of contractor B (unqualified party) and signing a general signature, and then adding the qualification information (a) to (g) to the attribute information of contractor A (qualified party) and signing a qualification signature.

[0120] In addition, two or more of the multiple contractors may be qualified, and in this case the qualifications may be the same or different. For example, in the case of a construction contract for a hospital, a construction contract between a qualified person (doctor) and a qualified person (architect) will be signed with a qualification signature using a qualification signature key corresponding to the doctor, and a qualification signature using a qualification signature key corresponding to the architect.

[0121] Furthermore, when there are multiple qualified and unqualified parties to a contract, for example, in the case of N contracting parties, instead of making a total of seven qualified signatures or general signatures, it is also possible to have all qualified and unqualified parties with the same qualification make a qualified signature or unqualified signature together. For example, in the case of an electronic contract between seven people, namely, qualified persons a1 to a3 with qualification A, qualified persons b1 and b2 with qualification B, and unqualified persons x1 and x2, the attribute information (including qualification information) of each of the qualified persons a1 to a3 is attached together and a qualified signature is made using a signing key or the like for qualification A, the attribute information (including qualification information) of each of the qualified persons b1 and b2 is attached together and a qualified signature is made using a signing key or the like for qualification B, and the attribute information (excluding qualification information) of each of the unqualified persons x1 and x2 is attached together and a general signature is made using a common signing key or the like. This allows the qualification signature to be completed with the number of electronic signatures corresponding to the number of qualified and unqualified parties (three times), rather than the number of electronic signatures corresponding to the total number of contract holders N (seven times).

[0122] In the embodiment and modified examples described above, the qualification signature device or the like when the contract form is an electronic contract using a witness-type electronic signature can be configured as follows. (Configuration 1) A qualified signature device that sequentially executes witness-type electronic signatures on electronic contracts based on requests from each contracting party, a presentation means for presenting an electronic contract in which each signature field is specified with a signature restriction that only a person having the required qualification can sign, when at least one of the contracting parties is a qualified person having a predetermined qualification; a qualification determination means for determining, when the contracting party requesting an electronic signature is a qualified person, whether the qualification of the contracting party matches the qualification required in the signature field of the electronic contract; an electronic signature means for signing the electronic contract in a manner that can be verified as being the electronic signature of a person with the relevant qualifications if the qualifications match; A qualification signing device comprising: (Configuration 2) The electronic signature means electronically signs the electronic contract using a qualified signature key, which is a private key created in accordance with the qualifications of the qualified person, and an electronic certificate in which specific information of the qualifications is recorded, as an electronic signature that can be verified as being made by a qualified person. 2. The entitlement signing device according to claim 1. (Configuration 3) The electronic signature means attaches to the electronic contract personal information identifying the qualified person and attribute information recording qualification information identifying the qualifications, so that the electronic signature can be verified as having been made by the qualified person. 3. The entitlement signing device according to claim 1 or 2, (Configuration 4) The electronic contract to be presented has a list of required qualifications linked to it, which specifies the required qualifications corresponding to each signature field. 4. The entitlement signing device according to claim 1, 2, or 3, (Configuration 5) A list storage means for storing a request qualification signature list in which a request qualification list of request qualifications required corresponding to each signature field is specified for each request qualification signature number, The electronic contract is linked to a request entitlement signature number in the request entitlement list. 5. The entitlement signing device according to configuration 4. (Configuration 6) The electronic contract to be presented has the required qualifications required of the contracting parties embedded in the form fields provided for each signature column. 6. The entitlement signing device of any one of configurations 1 to 5. (Configuration 7) A request form providing means is provided for providing each contracting party with a request form that allows only qualified persons, as specified in the signature restrictions of the signature field corresponding to that contracting party, to select an electronic signature request; The qualification determination means, when a request for an electronic signature is made using the request form, determines whether the qualification of the contracting party matches the qualification required in the signature field of the electronic contract. 7. The entitlement signing device of any one of configurations 1 to 6. (Configuration 8) In response to a signature request from a contracting party who is not qualified, the electronic signature means issues a general signature using a common signature key, which is a private key that does not correspond to the qualification, and an electronic certificate in which no specific information regarding the qualification is recorded. 8. The entitlement signing apparatus of any one of configurations 1 to 7. (Configuration 9) When the contracting party is an unqualified person, the electronic signature means attaches attribute information that records personal information that identifies the unqualified person to the electronic contract and then signs the general signature. 9. The entitlement signing apparatus of any one of configurations 1 to 8. (Configuration 10) A qualified signature program that causes a computer to function as a qualified signature device that sequentially executes witness-type electronic signatures on an electronic contract based on a request from each contracting party, A submission function that, when at least one of the contracting parties is a qualified person with a predetermined qualification, presents an electronic contract in which signature restrictions are specified for each signature field so that only persons with the required qualification can electronically sign; a qualification determination function that, if the contracting party requesting an electronic signature is a qualified person, determines whether the qualification of the contracting party matches the qualification required in the signature field of the electronic contract; If the qualifications match, an electronic signature function that verifies that the electronic signature on the electronic contract was made by the qualified person; A qualification signing program characterized by causing a computer to realize the above.

[0123] It is also possible to configure it as follows. (Configuration 11) A qualified signature device for executing a witness-type electronic signature on an electronic contract by a contracting party, an electronic contract acquisition means for acquiring an electronic contract that is the subject of the electronic contract between the contracting parties; a qualification determination means for determining whether the contracting party is a qualified person having a predetermined qualification; an electronic signature means for, when the contracting party is a qualified person, signing the electronic contract using a qualification signature key, which is a private key created in accordance with the qualification of the qualified person, and an electronic certificate in which specific information of the qualification is recorded; A qualification signing device comprising: (Configuration 12) The electronic signature means issues an electronic signature using the qualification signature key and the electronic certificate when requested to do so by the qualified person. 12. The entitlement signing device according to claim 11. (Configuration 13) The electronic signature means In response to a signature request from the contracting party who is a qualified person, a qualified signature is made using the qualified signature key and the electronic certificate; In response to a signature request from a non-qualified contracting party, a general signature is made using a common signature key, which is a private key that does not correspond to the qualification, and an electronic certificate that does not record any specific information about the qualification. 13. The entitlement signing device according to claim 11 or 12. (Configuration 14) An account DB is provided in which identity verification information and qualification verification information are stored in the account of the qualified person, and identity verification information is stored in the account of the unqualified person who does not have the qualification, The qualification determination means determines whether the contracting party is a qualified person based on the account DB. 14. The entitlement signing device according to claim 11, 12, or 13. (Configuration 15) The account DB stores a login identification number and password for each qualified person and unqualified person, The qualification determination means determines whether the contracting party is qualified or unqualified based on the identification number used when the contracting party logs in. 15. The entitlement signing device of claim 14. (Configuration 16) If the contracting party is a qualified person, the electronic signature means attaches attribute information recording qualification information identifying the qualification of the qualified person to the electronic contract, and performs an electronic signature using the qualification signature key and electronic certificate. 16. The entitlement signing device according to any one of configurations 11 to 15. (Configuration 17) A qualified signature program that causes a computer to function as a qualified signature device that executes a witness-type electronic signature on an electronic contract by a contracting party, an electronic contract acquisition function for acquiring an electronic contract that is the subject of the electronic contract between the contracting parties; a qualification determination function for determining whether the contracting party is a qualified person having a predetermined qualification; an electronic signature function that, when the contracting party is a qualified person, electronically signs the electronic contract using a qualification signature key, which is a private key created in accordance with the qualification of the qualified person, and an electronic certificate in which specific information of the qualification is recorded; A qualification signing program characterized by causing a computer to realize the above.

[0124] It is also possible to configure it as follows. (Configuration 21) A qualified signature device for executing a witness-type electronic signature on an electronic contract by a contracting party, an electronic contract acquisition means for acquiring an electronic contract that is the subject of the electronic contract between the contracting parties; a qualification determination means for determining whether the contracting party is a qualified person having a predetermined qualification; If the contracting party is a qualified person, an electronic signature means attaches personal information identifying the qualified person and attribute information recording qualification information identifying the qualification to the electronic contract and executes an electronic signature; A qualification signing device comprising: (Configuration 22) When requested to do so by the qualified person, the electronic signature means attaches attribute information recording the personal information and the qualification information to the electronic contract and signs it. 22. The entitlement signing device according to claim 21. (Configuration 23) When the contracting party is an unqualified person, the electronic signature means attaches attribute information recording personal information identifying the unqualified person to the electronic contract and signs the electronic contract. 23. The entitlement signing device according to claim 21 or 22. (Configuration 24) An account DB is provided in which identity verification information including identity information and qualification verification information including qualification information are stored in the account of the qualified person, and identity verification information including identity information is stored in the account of the unqualified person who does not have qualification, The qualification determination means determines whether the contracting party is a qualified person based on the account DB. 24. The entitlement signing device according to claim 21, 22, or 23. (Configuration 25) The account DB stores a login identification number and password for each qualified and unqualified person, The qualification determination means determines whether the contracting party is qualified or unqualified based on the identification number used when the contracting party logs in. 25. The entitlement signing device of claim 24. (Configuration 26) When the contracting party is a qualified person, the electronic signature means attaches attribute information to the electronic contract, which further records at least one of the identification information of the person who confirmed the qualification of the qualified person and the method of confirming the qualification, to the attribute information of the qualified person. 26. The entitlement signing device of any one of configurations 21 to 25, wherein: (Configuration 27) A qualified signature program that causes a computer to function as a qualified signature device that executes a witness-type electronic signature on an electronic contract by a contracting party, an electronic contract acquisition function for acquiring an electronic contract that is the subject of the electronic contract between the contracting parties; a qualification determination function for determining whether the contracting party is a qualified person having a predetermined qualification; an electronic signature function that, if the contracting party is a qualified person, attaches personal information identifying the qualified person and attribute information recording the qualification information identifying the qualification to the electronic contract and executes an electronic signature; A qualification signing program characterized by causing a computer to realize the above. [Explanation of symbols]

[0125] 1. Credential signing device 2. Credential Signature Processing Unit 3 Signature Verification Unit 4. Account Registration Section 5 Storage device 6 List publishing server 7 Certificate Authorities 8. Timestamp Server 9, 91-95 User terminals 11 CPU 12 ROM 13 RAM 14 Communication control section 50 Qualification Signature Processing PG 51 Signature Verification PG 52 Account Registration PG 54 Template DB 55 Account DB 56 Qualification DB 57 Signing key DB 58 Request Qualification Signature List 61 Qualification Comparison Table 122 Attribute information 123 Electronic Contracts 124, 133 hash value 125 Signature Value 126 Digital Certificates 131 Attribute information 132 Electronic Contracts 134 Signature Value 135 Digital Certificates 136 Qualified Signature Electronic Contract 401~403 Signatures 411~413 Electronic Signature Symbol 420 Signature Details 420a Signature Field 420b Unsigned Fields 421~423 Details column 450 Signature Panel 401~402 Each signature field 411~413 Request Eligibility Signature Form 411~413 Electronic Signature Symbol 411~413 Electronic signature activation 412 Electronic Signature Symbol 420 Signature Details 420a Signature Field 420b Unsigned Fields 421~423 Details column 450 Signature Panel 551 Account Table 552 Eligibility and Identity Verification Information Table 5521 Personal Identification Information 5522 Personal Identification Document Data 5523 Credential Verification Information 5524 Qualification Verification Document Data 5525 Qualification Code 553 File Table 801 Form column 802 Thumbnail column 803 Internal Management Column 804 Delivery address field 809 Signature Selection Button 901 Signature qualification selection field 909 Qualification Signature Request Button

Claims

1. A qualified signature device that sequentially executes witness-type electronic signatures on an electronic contract based on a request from each contracting party, a presentation means for presenting an electronic contract in which, when at least one of the contracting parties is a qualified person with a predetermined qualification, signature restrictions are specified for each signature field so that only persons with the required qualification can sign; a qualification determination means for determining, when the contracting party requesting an electronic signature is a qualified person, whether the qualification of the contracting party matches the qualification required in the signature field of the electronic contract; an electronic signature means for signing the electronic contract in a manner that can be verified as being the electronic signature of a person with the relevant qualifications if the qualifications match; A qualification signing device comprising:

2. The electronic signature means affixes an electronic signature to the electronic contract using a qualification signature key, which is a private key created in accordance with the qualification of the qualified person, and an electronic certificate in which specific information of the qualification is recorded, as an electronic signature that can be verified as being made by a qualified person.

2. The entitlement signing device of claim 1.

3. The electronic signature means attaches to the electronic contract personal information identifying the qualified person and attribute information recording qualification information identifying the qualifications, so that the electronic signature can be verified as having been made by the qualified person.

3. The entitlement signing device according to claim 1 or claim 2.

4. The electronic contract to be presented has a required qualification list linked to it, which specifies the required qualifications corresponding to each signature field.

2. The entitlement signing device of claim 1.

5. a list storage means for storing a request qualification signature list in which a request qualification list of request qualifications required corresponding to each signature field is specified for each request qualification signature number; The electronic contract is linked to a request entitlement signature number in the request entitlement list.

5. The entitlement signing device of claim 4.

6. The electronic contract to be presented has required qualifications required of the contracting parties embedded in form fields provided for each signature section.

2. The entitlement signing device of claim 1.

7. a request form providing means for providing each contracting party with a request form that allows only qualified persons, as specified in the signature restrictions of the signature field corresponding to the contracting party, to select an electronic signature request; The qualification determination means, when a request for an electronic signature is made using the request form, determines whether the qualification of the contracting party matches the qualification required in the signature field of the electronic contract.

2. The entitlement signing device of claim 1.

8. The electronic signature means issues a general signature to a contracting party who is not qualified and who has no qualifications, using a common signature key, which is a private key that does not correspond to the qualifications, and an electronic certificate in which no specific information regarding the qualifications is recorded.

2. The entitlement signing device of claim 1.

9. If the contracting party is an unqualified person, the electronic signature means attaches attribute information recording personal information identifying the unqualified person to the electronic contract and signs the general signature.

2. The entitlement signing device of claim 1.

10. A qualified signature program that causes a computer to function as a qualified signature device that sequentially executes witness-type electronic signatures on an electronic contract based on a request from each contracting party, a presentation function that, when at least one of the contracting parties is a qualified person with predetermined qualifications, presents an electronic contract in which signature restrictions are specified for each signature field so that only persons with the required qualifications can sign; a qualification determination function that, if the contracting party requesting an electronic signature is a qualified person, determines whether the qualification of the contracting party matches the qualification required in the signature field of the electronic contract; If the qualifications match, an electronic signature function that verifies that the electronic signature on the electronic contract was made by the qualified person; A qualification signing program characterized by causing a computer to realize the above.

Citation Information

Patent Citations

  • Method and system for exchanging electronic message, and storage medium for electronic message exchanging processing

    JP1997046335A

  • Decision system

    JP2002082836A

  • System, method and program for electronic signature, and recording medium having the program recorded thereon

    JP2003281333A

  • Electronic signature system and its program

    JP2004248045A

  • Electronic financing contract system and method

    JP2005222268A