Qualification signature device and qualification signature program

The qualifications signature device verifies and records the qualifications of contracting parties in electronic signatures, addressing the inability of existing systems to confirm qualifications, thereby ensuring qualified signatures.

JP2025162510AActive Publication Date: 2025-10-27SEIKO SOLUTIONS
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2025005479
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-15
Filing Date
2025-01-15
Publication Date
2025-10-27
Estimated Expiration
2045-01-15

AI Technical Summary

Technical Problem

Existing electronic signature systems fail to verify the qualifications of contracting parties in witness-type electronic signatures, making it impossible to confirm if the signature is made by a qualified person.

Method used

A qualifications signature device that includes an electronic contract acquisition means, a qualification determination means, and an electronic signature means using a qualifications signature key and certificate to verify and record the qualifications of the contracting party.

Benefits of technology

Enables confirmation of the qualifications held by the contracting party in the electronically signed electronic contract, ensuring that the signature is made by a qualified person.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025162510000001_ABST
    Figure 2025162510000001_ABST
Patent Text Reader

Abstract

To make it possible to verify the qualifications held by contracting parties from an electronically signed electronic contract.SOLUTION: For an electronic contract, a qualification signature device 1 performs a witness-type electronic signature (qualification signature) on the electronic contract not using a private key of a contracting party or the like, but instead using a qualification signature key and an electronic certificate issued for each qualification to the qualification signature device 1. The electronic certificate corresponding to each qualification signature key includes description of qualification information (for example, the name of the qualification) indicating that the contracting party is a holder of the qualification corresponding to the qualification signature key. When performing the electronic signature, qualification information that enables verification of the contractor's qualification is also included in attribute information. Thus, the contracting party or a third party can verify, through the electronic certificate or the attribute information of the qualification signature key, that the electronic contract subjected to qualification signature processing by the qualification signature device 1 is a contract made by at least one qualified person.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an apparatus and a program for digitally signing an electronic contract. [Background technology]

[0002] Electronic contracts are now being used to electronically sign electronic contracts (including electronic consent forms) that electronically record the contractual content between the parties, and depending on the content of the contract, electronic contracts are signed by the parties themselves or by businesses (witnesses). An electronic contract with an electronic signature is guaranteed to be signed by the contracting party himself / herself and that the contents have not been tampered with. In a party-based electronic signature system, a private key and electronic certificate (hereinafter referred to as the private key, etc.) owned exclusively by the contracting parties are used to digitally sign an electronic contract. On the other hand, in witness-type electronic signatures, as described in Patent Document 1, a private key or the like of an electronic signature business operator who acts as a witness is used to digitally sign an electronic contract. In such witness-type electronic signatures, the private key of the witness is generally used, rather than the private key of the contracting party itself. Therefore, the service provider must undergo strict identity verification (for example, verification of ID (identification number) and PW (password)), and the attribute information that identifies the contracting party, such as an email address, is included in the electronic signature.

[0003] By the way, electronic contracts not only have a wide variety of content, but also have a variety of parties to the contracts. For example, qualified persons such as doctors and architects may enter into electronic contracts in their respective qualifications. In such cases, it is preferable that a third party, including the contracting party, can verify that the electronically signed electronic contract has been signed by a person with the required qualifications. However, in the case of witness-type electronic signatures, it was not possible to determine the qualifications of the electronic contract holder from the electronically signed electronic contract. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2013-114641 Summary of the Invention [Problem to be solved by the invention]

[0005] The present invention aims to make it possible to confirm the qualifications held by contracting parties in a digitally signed electronic contract. [Means for solving the problem]

[0006] The present invention provides a qualifications signature device that allows a contracting party to sign an electronic contract in a witness-type electronic signature, characterized in that it comprises: an electronic contract acquisition means for acquiring an electronic contract that is the subject of an electronic contract by the contracting party; a qualification determination means for determining whether the contracting party is a qualified person who has specified qualifications; and, if the contracting party is a qualified person, an electronic signature means for signing the electronic contract using a qualifications signature key, which is a private key created corresponding to the qualifications of the qualified person, and an electronic certificate in which specific information of the qualifications is recorded. [Effects of the Invention]

[0007] In this invention, when a contracting party is a qualified person, an electronic signature is made to the electronic contract using a qualifications signing key, which is a private key created corresponding to the qualifications of the qualified person, and an electronic certificate that records specific information about the qualifications, so that the qualifications held by the contracting party can be confirmed in the electronically signed electronic contract. [Brief explanation of the drawings]

[0008] [Figure 1] 1 is an explanatory diagram showing the configuration of a qualification signature system including a qualification signature device; [Figure 2] FIG. 1 is an explanatory diagram showing the configuration of a qualification signing device. [Figure 3]1 is an explanatory diagram conceptually showing the contents of an account DB stored in a storage device of a qualification signing device. [Figure 4] 1 is an explanatory diagram conceptually showing the contents of a qualification DB stored in a storage device of a qualification signing device. [Figure 5] 10 is a flowchart showing the flow of an account registration process by the entitlement signature system. [Figure 6] 10 is a flowchart showing a part of the flow of a qualification signature process by the qualification signature system. [Figure 7] 10 is a flowchart showing the continuation of the flow of the entitlement signature process by the entitlement signature system. [Figure 8] FIG. 10 is an explanatory diagram showing a display screen of an electronic contract (surgery consent form) file displayed on a user terminal. [Figure 9] FIG. 10 is an explanatory diagram illustrating an electronic signature selection screen displayed on a user terminal. [Figure 10] 1 is an explanatory diagram conceptually showing the structure of a qualifications-signed electronic contract signed by a qualifications signing system. [Figure 11] 10 is a flowchart showing the flow of a verification process for a qualifications-signed electronic contract that has been qualified. [Figure 12] FIG. 10 is an explanatory diagram conceptually showing the structure of a qualification signature electronic contract according to a modified example. [Figure 13] FIG. 2 is an explanatory diagram showing the configuration of a qualification signature system corresponding to FIG. 1 in a modified example. [Figure 14] FIG. 5 is an explanatory diagram conceptually showing the contents of a qualification DB corresponding to FIG. 4 in a modified example. [Figure 15] 6 is a flowchart showing the flow of an account registration process corresponding to FIG. 5 in a modified example. DETAILED DESCRIPTION OF THE INVENTION

[0009] Preferred embodiments and modifications of the qualification signature device 1 of the present invention will be described in detail below with reference to FIGS. (1) Overview of the embodiment When at least one of the contracting parties (users) is a person with a predetermined qualification (qualified person), the qualifications signature device 1 issues a witness-type electronic signature to the electronic contract in a manner that allows the contracting parties or a third party to later confirm the qualification of the qualified person who requested the electronic contract to be electronically signed. The qualifications that can be verified include various qualifications established by the state or private sector, qualifications based on enrollment in social insurance or national health insurance, and various qualifications such as Japanese nationality and residence status. However, whether or not the contractor (user) signs a qualification based on their own qualification is a separate matter, and the qualification signature process will be carried out if the contractor wishes and specifies their own qualification.

[0010] Specifically, the entitlement signature device 1 performs a so-called witness-type electronic signature (entitlement signature) on an electronic contract (hereinafter referred to as an electronic contract) including an electronic consent form, using a entitlement signature key (private key) and electronic certificate issued to the entitlement signature device 1 for each entitlement, rather than the private key of the contracting party or consenting party (hereinafter referred to as the contracting parties). The digital certificate for each entitlement signing key contains, by subject, subject alternative name, or policy OID (Object Identifier), entitlement information (e.g., entitlement name, entitlement code, etc.) that indicates that the requester of the digital signature (contracting party) is the holder of the entitlement corresponding to the entitlement signing key.

[0011] Furthermore, when issuing an electronic signature, the qualification signature device 1 includes qualification information that can verify the contract holder's qualifications in the attribute information (reason for electronic signature), calculates a hash value together with the electronic contract, and issues an electronic signature using a qualification signature key, etc. (qualification signature key and electronic certificate) corresponding to the contract holder's qualifications. The attribute information (reason for electronic signature) is one part of the format for the qualification signature process, and is an area in which any text information included in the scope of encryption can be entered. This allows the contracting parties and third parties to verify, through the digital certificate and attribute information of the qualifications signing key, that the electronic contract that has undergone qualifications signing processing by the qualifications signing device 1 is a contract made by at least one qualified person.

[0012] In the qualification signature process of this embodiment, electronic signatures are issued for multiple contracting parties each time a signature request is received from each party. If the party requesting the signature is qualified, a qualification signature is issued using a private key or the like corresponding to the qualification of the qualified party, and if the party is not qualified, an electronic signature (general signature) is issued using a common signature key (a private key used in common by all non-qualified parties) that does not correspond to the qualification. In addition, the identity and qualification verification of the contracting parties (qualified and unqualified persons) may be performed by the qualification signing device 1, or the qualification signing device 1 may request the verification to be performed by an external device, such as an identity verification agency 75 (functioning as a third-party agency), such as My Number Portal or an identity verification service provider.

[0013] (2) Details of the embodiment FIG. 1 is a diagram showing the system configuration of a qualification signature system for witness-type electronic signatures for electronic contracts, including a qualification signature device 1 according to this embodiment. As shown in FIG. 1, a credentials signing device 1 forms a credentials signing system together with user terminals 91, 92, 93, . . . used by users who are contracting parties or verifiers, a list publishing server 6, a certification authority 7, and a timestamp server 8. The entitlement signing device 1 is connected to user terminals 91, 92, 93 and a list publication server 6 via the Internet, telephone lines, or the like, and is connected to a timestamp server 8 and a certification authority 7 via a VPN (Virtual Private Network) or the like.

[0014] The list publishing server 6 publishes the qualification comparison table 61 via the Internet or the like. This entitlement comparison table 61 is used to confirm the validity of the entitlements of the contracting parties for an entitlement-signed electronic contract (entitlement-signed electronic contract (TS)), and is configured to be able to display a list of the entitlement code, entitlement name, and entitlement holder identity verification method for each entitlement. The entitlement comparison table 61 is generated from the entitlement DB 56 of the entitlement signature device 1, which will be described later. The URI of this qualification comparison table 61 is stored in a qualification DB (to be described later) of the qualification signature device 1, and is also recorded in the attribute information when the qualification is signed. The qualification comparison table 61 published on the list publication server 6 is used to confirm the validity of the qualifications of the contracting parties, and by using the qualification comparison table 61, other electronic signature businesses can adopt the same standards as the qualification signature device 1. The list publishing server 6 is operated by an organization external to the qualifications signing device 1, but may be operated by the same operating body as the qualifications signing device 1.

[0015] A Certification Authority (CA) 7 is an organization that verifies the identity of those who issue electronic signatures. It verifies the identity of users based on their applications and various certificates, generates private and public keys for users, and issues digital certificates that link the public keys with the owners (users) of the corresponding private keys. In this embodiment, the qualification signature device 1, as a user of the certification authority 7, is issued a qualification signature key (private key), a public key, and an electronic certificate (hereinafter referred to as a qualification signature key, etc.) for each of the multiple qualifications, and stores them in the signature key DB. The qualification signature device 1 also stores in advance in the signature key DB a common signature key, a public key, and an electronic certificate (hereinafter referred to as a common signature key, etc.) to be commonly used for electronic signatures for non-qualified users.

[0016] Based on a request from the entitlement signing device 1, the timestamp server 8 assigns a timestamp to the entitlement signed electronic contract after the entitlement signing process has been performed.

[0017] The user terminals 91, 92, 93, . . . are terminals used by contracting parties who make an electronic contract using a witness-type electronic signature by the qualification signature device 1, or by persons who verify the qualification-signed electronic contract. In the following description, the user terminals 91, 92, and 93 will be collectively referred to as the user terminal 9. The user terminal 9 is a computer that can be connected to a communication network wirelessly or by wire, and is configured, for example, by a personal computer, a smartphone, a mobile phone, or a game device. The user terminal 9 is equipped with a browser and a display device for displaying electronic contracts and the like provided by the qualification signature device 1, and is configured to be able to use short mail service (SMS) and / or e-mail using a telephone number. The user terminal 9 also has a touch panel and keyboard for performing various input operations in the qualification signature process.

[0018] In Figure 1, the user terminals 9 are shown as user terminal (qualified person) 91, user terminal (unqualified person) 92, and user terminal (verifier) ​​93, but in reality there are multiple terminals, such as user terminal (administrator / qualified identity verifier) ​​94 shown in Figure 5, depending on the number of contracting parties who have accounts for electronic contracts with the qualification signing device 1. However, provided that at least one of the users (contracting parties) has completed the account registration of a qualified person, it is possible to carry out qualified signature processing for electronic contracts in which a non-registered person who does not have an account is a contracting party.

[0019] The entitlement signature device 1 comprises a entitlement signature processing unit 2, a signature verification unit 3, and an account registration unit 4 as function realization units, and a storage device 5. The storage device 5 stores a template DB 54, an account DB 55, etc. as various programs and data for realizing the functions of each of the function realization units 2 to 4 (details will be described later). The account registration unit 4 newly registers or updates accounts of users (qualified and unqualified contracting parties, verifiers, qualified administrators, etc.) in the account DB 55 based on various registration information transmitted from the user terminals 91-. The qualification signature processing unit 2 performs witness-type qualification signature processing for the target electronic contract, for example, based on a signature request from a user (qualified person) of the user terminal 91 and a user (unqualified person) of the user terminal 92. The signature verification unit 3 receives a verification request for an electronic contract that has undergone qualification signature processing (hereinafter referred to as a qualification-signed electronic contract) from, for example, a user terminal (verifier) ​​93 or a user terminal of a contracting party, and verifies that the qualification-signed electronic contract has not been tampered with and verifies the expiration date of the qualifications of the contracting party, etc. Each device in FIG. 1 that forms the entitlement signature system is capable of communicating in a state encrypted with SSL or TLS via a communication network such as the Internet.

[0020] FIG. 2 shows a hardware configuration for realizing each function of the entitlement signature device 1 described in FIG. As shown in FIG. 2, the qualification signature device 1 includes a CPU 11, a ROM 12, a RAM 13, a storage device 5, a communication control unit 14, and other devices connected via a bus line. The CPU 11 is a central processing unit that operates according to various programs stored in the storage device 5, and performs communication processing with external devices such as the list publication server 6, the certification authority 7, the timestamp server 8, and the user terminal 9. In addition, the CPU 11 functions as the qualification signature processing unit 2 shown in Figure 1 by executing the qualification signature processing PG (program) 50, functions as the signature verification unit 3 by executing the signature verification PG 51, and functions as the account registration unit 4 by executing the account registration PG 52.

[0021] The ROM 12 is a read-only memory that stores basic programs and parameters for the CPU 11 to operate. The RAM 13 is a readable and writable memory, and serves as a working memory when the CPU 11 performs the electronic contract processing in this embodiment. For example, in the qualifications signing process, the RAM 13 stores the login IDs of the qualified individuals who are the contracting parties, the electronic contracts at each processing stage until the qualifications signing process is completed, and the like. The communication control unit 14 performs communication processing with external devices such as the user terminal 9.

[0022] The storage device 5 is configured using one or more large-capacity storage media such as hard disks, and stores various programs such as qualification signature processing PG50, signature verification PG51, account registration PG52, etc., which enable the CPU 11 to perform the functions of this embodiment, as well as various data such as a template DB (database) 54, account DB 55, qualification DB 56, and signature key DB 57. As described above, the qualification signature processing PG50, signature verification PG51, and account registration PG52 are programs for functioning as the qualification signature processing unit 2, signature verification unit 3, and account registration unit 4, and the details of each process will be described later.

[0023] The template DB 54 stores templates of various contracts (including consent forms, oaths, pledges, etc.) that are used in electronic contracts for witnessing dolls and are subject to the qualification signature processing of this embodiment. The templates stored in the template DB54 include original electronic contract templates that can be used in a variety of situations, including medical, construction and civil engineering, public institutions, the legal system, finance, and more. In the template DB 54 of this embodiment, templates of various electronic contracts are stored, classified by predetermined industry type, but it is also possible to store them according to other classifications, such as the Japan Standard Industrial Classification. The templates of electronic contracts are created, collected and stored by the operator of the qualification signature device 1, as well as those created and uploaded by users or administrators who have registered accounts.

[0024] The various templates stored in the template DB 54 can be downloaded from the user terminal 91 of a user who has logged in to the qualification signature device 1 and has registered an account. A user who has registered an account can use an electronic contract stored in the template DB 54, as well as an electronic contract stored in an external device other than the qualifications signing device 1 or in the user's own device, to undergo qualifications signing processing by the qualifications signing device 1. In this case, the electronic contract to be used is uploaded from the user terminal 9 to the qualifications signing device 1, and the qualifications signing device 1 performs qualifications signing processing for this, and can also store the electronic contract before electronic signature in the template DB 54 as necessary.

[0025] The signature key DB 57 stores the qualification signature keys etc. corresponding to various qualifications issued by the certification authority 7, as well as the common signature keys etc. Multiple qualification signature keys etc. (qualification signature keys and digital certificates) and the common signature keys etc. are managed using predetermined signature key numbers. The digital certificate for each qualification signing key records a subject, subject alternative name, or policy OID. This allows the digital certifier to verify that the user (contractor) entering into the digital contract of the witness doll is a licensed doctor, architect, etc., and that the digital signature is based on that license.

[0026] The account DB 55 stores various information about users and the like through account registration processing. Account registration is required for users such as contracting parties and verifiers to have the authority to use the qualification signature service provided by the qualification signature device 1. FIG. 3 conceptually shows the contents stored in the account DB 55. As shown in FIG. 3, the account DB 55 stores an account table 551, a qualification / identification information table 552, and a file table 553 for each user, and is managed by an ID assigned to each user.

[0027] The account table 551 stores basic information necessary to distinguish between the accounts of users who have specified qualifications (who register their qualifications) and users who do not have qualifications (who do not register), such as an ID that identifies the user, a password (PW) required along with the ID when logging in to the qualification signature device 1, the user's name, the name of the organization to which the user belongs (an optional field required if present), an email address, and a telephone number to be used for short message service (SMS).

[0028] The qualification and personal identification information table 552 stores personal identification information 5521, personal identification document data 5522, qualification verification information 5523, qualification verification document data 5524, and qualification code 5525. Personal identification information 5521 and personal identification document data 5522 are data that indicates (specifies) the user and data about the document used for personal identification. The qualification verification information 5523 and the qualification verification document data 5524 are data indicating (identifying) the qualification if the user himself / herself is a qualified person (only if the user wishes to register the qualification (including not only at the time of registration but also at the time of electronic signature)), and data regarding the document used for qualification verification.

[0029] The identity verification information 5521 is information for identifying (confirming) the user who has registered an account, and stores the address, name, sex, date of birth, registered domicile, age, telephone number, identity verification person ID, and identity verification method. Note that the identity verification information 5521 can also include other information such as the user's email address and data in an IC chip that certifies the user's identity. The ID of the person who verified the identity of the user according to the identity verification document data 5522 is the identity verifier ID, and the identity verification method indicates how the identity verification was performed. This identity verifier ID functions as identifying information of the person who verified the identity. The person who verified the identity (identifier) ​​may be the operator of the qualification signature device 1, the organization to which the person belongs (for example, the corporation to which the person belongs), a third-party auditing organization, etc., and the identifying information may be the ID or name of the qualification verifier.

[0030] The personal identification document data 5522 is data relating to the document used (requested to be submitted) when the personal identification person performed the user's identity verification. Examples of identity verification documents include a resident card, driver's license, and My Number card. The personal identification document data 5522 stores the document name, scanned image, classification, identification number, expiration date (next scheduled verification date), etc. of the personal identification document. The expiration date is the one specified (written) on the identity verification document. If an expiration date is not specified, an expiration date (next scheduled verification date) calculated from the date and time of this action can be set as necessary.

[0031] The qualification verification information 5523 is information used to verify that a user who has registered an account has valid qualifications if the user is a qualified person, and stores the address, name, gender, date of birth, registered domicile, age, telephone number, qualification verification person ID, and qualification verification method as a qualified person. The qualification verifier ID is an identification number of the person who confirmed that the user has valid qualifications in accordance with the qualification confirmation document data 5524. This qualification verifier ID functions as identifying information of the person who confirmed the qualifications of the qualified person. The person who confirmed the qualifications (qualification verifier) ​​corresponds to the operator of the qualification signature device 1, the organization to which the qualified person belongs (for example, the hospital to which the qualified doctor belongs), a third-party auditing organization, etc., and the identifying information corresponds to the ID and name of the qualification verifier. The qualification verification method indicates the method used by the qualification verifier to verify the qualification. The specific method of qualification verification is performed in accordance with the provisions for each qualification that are predefined in the qualified person identity verification method in the qualification DB 56 in Fig. 4, which will be described later, or in accordance with the provisions in laws, regulations, or guidelines, if any. The qualifications to be checked include qualifications set by the state or private sector, membership in social insurance or national health insurance, or nationality or residence status, and the qualifications that can be registered are specified in the qualification DB 56 shown in FIG. 4.

[0032] The qualification verification document data 5524 is data relating to the document used (requested to be submitted) when the qualification verifier verified the qualification of the user. Examples of qualification verification documents include qualification certificates such as a doctor's license (copy) or a nurse's license (copy), a driver's license, an IC chip on which qualifications are recorded such as a My Number card, etc.

[0033] Although each qualified person can submit the qualification confirmation documents individually, it also includes a qualification confirmation list (which must include the signature and seal of the relevant person, as well as the date of confirmation, etc.) created after a representative of multiple qualified persons, such as a hospital director or other manager, is appointed as the qualified identity verifier and confirms the qualifications of the qualified persons (doctors, nurses, etc.) affiliated with the hospital. It also includes a qualification confirmation list that compiles multiple different qualifications, such as the attorneys, patent attorneys, administrative scriveners, etc., that are affiliated with a designated general office. In this case, the qualification confirmation list should be submitted in writing as a general rule, but it can also be submitted as electronic data with the administrator's electronic signature instead of a name and seal.

[0034] The qualification confirmation document data 5524 stores the document name, scanned image, classification, identification number, expiration date (next scheduled confirmation date), etc. of the qualification confirmation document. The expiration date is the one specified (written) on the qualification confirmation document, and if no expiration date is specified, an expiration date (next scheduled confirmation date) can be set based on the date and time of the implementation of this action, if necessary.

[0035] The qualification code 5525 stores a qualification code corresponding to the qualification name of the qualified person who has registered the account, and is read from the qualification DB 56 (described later in FIG. 4) and stored. If a user has multiple qualifications, multiple qualification codes are stored.

[0036] The file table 553 stores files to be electronically signed and files that have already been electronically signed, in association with the ID of each account. An electronic signature target file is a file for which a qualification signature, etc., is to be applied. For the electronic signature target file stored here, it is possible to grant each of the permissions for operation, viewing, and access use for each ID within the same organization (for example, various organizations such as a hospital, company, or workplace to which the user of the ID belongs). The digitally signed file is a file of the electronic contract (entitlement-signed electronic contract) after the entitlement signature process (and the addition of a timestamp) according to this embodiment has been performed. In other words, when the entitlement signature process according to this embodiment has been performed between User A and User B, the entitlement-signed electronic contract is stored in the digitally signed file associated with User A's ID, and also in the digitally signed file associated with User B's ID. The electronic contracts after the qualification signature process that are saved in the electronically signed file include not only electronic contracts read from the template DB 54, but also electronic contracts read by the contracting parties from other devices.

[0037] Of the specific information that identifies the user and the user's qualifications stored in the account table 551 and the qualification / identification information table 552, the following data (a) to (g) are recorded as attribute information to be hashed in the qualification signature process. (a) ID, email address, and phone number (SMS) in account table 551 (b) Identity verification information 5521: Identity verification person ID, identity verification method (c) Document name, classification, identification number, and expiration date of identity verification document data 5522 (d) Eligibility verification information 5523 Eligibility verification person ID, eligibility verification method, (e) Document name, classification, identification number, and expiration date of qualification verification document data 5524 (f) Qualification Code 5525 (g) The name of the qualification, the location of the qualification table, and the method of verifying the identity of the qualified person stored in the qualification DB56 corresponding to the qualification code. However, among these pieces of specific information, (a) other than the ID, email address, and telephone number (SMS) in the account table 551, as for the qualification information that can confirm the qualification of the user (qualified person), it is not necessary to record all of them in the attribute information (reason for electronic signature); at least one of them may be recorded. For example, in the case of one, it may be the qualification code of the qualification code 5525 or the qualification name. This enables the contracting parties and third parties to verify, using the attribute information, that the electronic contract that has undergone the qualifications signature process by the qualifications signature device 1 is a contract made by at least one qualified person. In addition, the attribute information for the qualification signature may store either the identity verifier ID or the identity verification method in (b), or either the identity verifier ID or the qualification verification method in (d).

[0038] For electronic signatures corresponding to users who do not have qualifications (non-qualified persons) or users who have qualifications but do not wish to issue a qualified signature using their qualifications, (a) the ID, email address, and telephone number (SMS) in account table 551 are recorded in the attribute information (reason for electronic signature).

[0039] Returning to FIG. 2, the qualification DB 56 is a database of qualifications defined as targets of qualification signature processing according to this embodiment. FIG. 4 conceptually shows the contents stored in the qualification DB 56. As shown in FIG. 4, the qualification DB 56 stores the qualification name, qualification code, method of verifying the identity of the qualified person, location of the qualification comparison table, location of the qualification signature key, etc. The qualification name is a name that indicates the qualification, and examples include doctor, financial planner, Japanese nationality, and the like. The qualification code is a regular set of letters, numbers, symbols, and symbols that are uniquely assigned to each qualification, and is the object of storage of the qualification code 5525.

[0040] The method of verifying the identity of a qualified person is specified for each qualification code. Examples of specific methods prescribed in the Qualified Person Identification Act include the following (i) to (iv) and various other methods. For these verification methods for qualified person identity verification, one or more methods are specified for each qualification, and the method used to actually verify the qualified person's identity is saved as the qualification verification method in qualification verification information 5523 in qualification / identification information table 552. (i) In person, you will be asked to submit the required documents (copy of license (medical license in the case of a doctor), copy of resident registration, email address, telephone number / license certificate, photo ID). (b) Public personal authentication will be carried out non-face-to-face using eKYC (electronic Know Your Customer). (c) The representative of the organization (e.g., the hospital director) will verify the qualifications and identities of the qualified personnel affiliated with the organization and submit a list of the qualified personnel's identity and qualification information (name, address, gender, date of birth, qualification name, qualification code, etc.) and a paper copy of the qualification certificate. (d) The operator (verification officer) of the qualification signature device 1 verifies the notification documents (copy of qualification certificate, copy of ID) of the qualified person. During verification, the "qualification verification information" is read from the ID etc. and is entered into an external database to confirm that the qualified person actually exists.

[0041] The location of the qualification comparison table is the URI (Uniform Resource Identifier) ​​of the qualification comparison table 61 that the list publication server 6 has published on the Internet or the like. The location of the qualification signature key, etc. is the address where the qualification signature key for the electronic signature used in correspondence with each qualification code and its electronic certificate are stored, and the address where the common signature key and its electronic certificate are stored. In the list disclosure server 6 of this embodiment, the qualification comparison table 61 is classified by predetermined qualification (for example, medical, law, architecture, etc.), and the qualification comparison table 61 for each classification is made public. For this reason, a different URI is defined for each classification for the location of the qualification comparison table in the qualification DB 56. However, it is also possible to use a single qualification comparison table 61 that compiles all qualifications, and correspondingly define the same URI for the location of the qualification comparison table in the qualification DB 56.

[0042] Next, various processing operations performed by a qualification signature system using the qualification signature device 1 will be described. FIG. 5 is a flowchart showing the flow of account registration processing by the entitlement signature system. This account registration process is a process for registering an account for each user as a prerequisite for the qualification signature process according to this embodiment, and is performed in the qualification signature device 1 by the CPU 11 executing the account registration PG52 of the storage device 5. In the following explanation, the process performed by the CPU 11 executing various programs will be explained as the operation of the qualification signature device 1 (the same applies to the user terminal 9). 5, a hospital-related account registration process will be described as an example of account registration. That is, the account registration process will be described from a user terminal 91 of a doctor (qualified person) who is a user belonging to a predetermined hospital, a user terminal 94 of an administrator (qualified person) of the hospital, and a user terminal 92 of a patient (unqualified person).

[0043] As shown in Figure 5, when an unqualified patient registers an account, the patient's user terminal 92 submits the user's (patient's) identification, such as a resident registration card, My Number card, or driver's license, to the qualification signature device 1 as registration information (step 921).

[0044] On the other hand, when a qualified doctor registers an account, the doctor submits his / her medical qualification certificate as a document verifying his / her qualifications, and personal identification such as a resident registration card, My Number card, or driver's license as registration information to the qualification signature device 1 or the administrator (step 911). In addition, when the registration information is submitted to the administrator rather than the qualification signature device 1, the doctor's account is submitted to the qualification signature device 1 from the user terminal 94 together with other qualified persons using an identity confirmation list created by the administrator, rather than from the doctor's own user terminal 91.

[0045] That is, the administrator receives the qualifications and identification cards of doctors, nurses, physical therapists, occupational therapists, etc. who belong to the organization (here, a hospital) that the administrator manages, and verifies their qualifications and identities (step 941). Then, the administrator's user terminal 94 compiles the submitted qualifications and personal identification cards to create a qualification and personal identification information list, and stores it in the user terminal 94 or the database of the hospital to which the user belongs (step 942). The qualification and identity verification information list created here is a list of the contents of the account table 551 and qualification and identity verification information table 552, excluding the ID.

[0046] The administrator then records the administrator's name and seal, the confirmation date, etc. on the created qualification and identity verification information list, and submits it to the qualification signature device 1 (step 943). The submission method can be various methods, including sending the PDF data of the qualification and identity verification information list as an email attachment, and details will be explained in the processing on the user terminal 92 side.

[0047] When registration information is submitted by the user terminal 9 or the user, the entitlement signature device 1 acquires it (step 101). There are various patterns for submitting registration information and obtaining registration information, as follows: (a) When an unqualified person, a qualified person, or an administrator submits a physical medium (copy, printout) or data of the registration information (by mail, email attachment, upload, etc.) and the qualification signature device 1 receives it. (b) When the user accesses the account registration screen of the qualification signature device 1 from the user terminal 9 and inputs each item of registration information

[0048] If the acquired registration information includes a qualification such as a qualification name, the qualification signature device 1 refers to the qualification comparison table 61 of the list publication server 6 and acquires a qualification code corresponding to the qualification (step 102). The qualification signature device 1 then determines whether or not there is a qualification code corresponding to the qualification included in the registration information (step 103), and if there is no qualification code (step 103; N), it sends a registration information error to the corresponding user terminal 9 (step 104. Note that if the registration information is not submitted from the user terminal 9 but by mail, etc., the sender user is notified of the mail error.

[0049] In the case of registration information of an unqualified person, or if there is a qualification code corresponding to the qualification contained in the registration information (step 103; Y), the qualification signature device 1 confirms the contents of the registration information (including personal identification) and stores it in the account DB 55 with an ID for each account (step 105). That is, if the registration information is of an unqualified person, the operator of the qualifications signature apparatus 1 checks the contents of the acquired registration information and stores it in the account table 551 . On the other hand, if the registration information is from an individual qualified person, the operator of the qualification signature device 1 checks the contents of the registration information (including identity verification and qualification verification) and stores it in the account table 551 and qualification / identity verification information table 552. Also, if the registration information is from an administrator (qualification and identity verification information list), the details of each listed qualified person are checked, and an ID for each qualified person is attached and stored in the account table 551 and the qualification and identity verification information table 552. As for the qualification code 5525 in the qualification / personal verification information table 552, the qualification code acquired in step 102 is saved.

[0050] Registration information can be confirmed and saved using the following methods. That is, the operator of the entitlement signature device 1 checks the contents of the submitted physical medium, inputs them, and saves them. In addition, there are cases where a user inputs information into an input form for account registration provided by the qualification signature device 1 from the user terminal 9, and the contents are confirmed and saved by the administrator. In this case, it is possible to automatically register an account by simply completing online identity verification (eKYC).

[0051] The above has been a description of the registration of an account in the qualification signature device 1, but the same applies to updating (modifying, adding) an already registered account. However, when updating, since an account already exists, the user submits registration information including the account and any information to be corrected or added. If an account exists in the acquired registration information, the qualification signature unit 1 determines that the request is an update request and updates the contents of the account.

[0052] When the registration / update of the account is completed, the credential signature device 1 notifies the user of the account of the registration / update (step 106), and ends the process.

[0053] Next, the process of signing an electronic contract by a user who has registered an account will be described. FIG. 6 is a flowchart showing part of the flow of the entitlement signature process by the entitlement signature system, and FIG. 7 is a flowchart showing the rest of the process. 6 and 7, an example will be explained in which a witnessed electronic contract between a qualified person (doctor) and an unqualified person (patient) is performed using user terminals 91 and 92 and a qualification signature device 1 to process the qualification signature for the consent form (electronic contract). It is assumed that both the doctor and the patient have completed account registration.

[0054] As shown in FIG. 6, the doctor logs in to the electronic signature service provided by the qualification signature device 1 from the user terminal 91 (step 912). That is, the doctor opens the login screen of the electronic signature service on the user terminal 91 , enters the ID and password (PW) of his / her account, and transmits them to the qualification signature device 1 .

[0055] When the qualification signature device 1 receives the ID and PW transmitted from the user terminal (doctor) 91, it checks whether or not they have been registered in the account DB 55 and performs login authentication (step 110). When the login authentication is completed, the qualification signature apparatus 1 notifies the user terminal (doctor) 91 of the completion of the login authentication, and temporarily stores the ID of the logged-in doctor in the RAM 13. On the other hand, if at least one of the ID and PW is not registered, a login error is returned to the user terminal (doctor) 91.

[0056] When the login to the electronic signature service is completed, the user terminal (doctor) 91 uploads or calls up the consent form (electronic contract) that is the subject of the electronic contract, and displays it on the screen (step 913). That is, the user terminal (doctor) 91 reads out the consent form stored in its own device or in a predetermined storage device managed by the hospital, and uploads it to the qualification signature device 1 as the consent form to be subjected to the current qualification signature process. The user terminal (doctor) 91 accesses the template DB 54 stored in the storage device 5 of the qualification signature device 1 and calls up the desired consent form.

[0057] When a consent form is uploaded from the user terminal (doctor) 91, the qualification signature device 1 stores the consent form in an electronic signature target file in the file table 553 corresponding to the doctor's ID. Note that the consent form may be stored in the template DB 54 with the doctor's consent. On the other hand, when the consent form is called, the qualification signature device 1 reads out the corresponding consent form template (electronic contract) from the template DB 54 and provides it to the user terminal (doctor) 91 (step 111).

[0058] FIG. 8 shows a display screen of the surgery consent file displayed on the user terminal (doctor) 91. The surgery consent form file shown in FIG. 8 is not one that has been called from the template DB 54 of the qualification signature device 1, but is a surgery consent form file that has been created and saved in advance in the hospital to which the doctor belongs. As shown in FIG. 8, the display screen for the surgery consent form file displays a form field 801, a thumbnail field 802, an in-house management field 803, a delivery address field 804, a signature selection button 809, and the like. In the form field 801, the file name "Surgery Consent Form 11.pdf" is recorded, along with the expiration date, transmission date and time, sender, etc. In the example of Figure 8, the sender field records that the document was created by "Takumi Fuko," an office worker at Memorial Hospital. The thumbnail field 802 displays thumbnail images linked to the "surgery consent form" that is the subject of the qualification signature process. The doctor and patient, who are the contracting parties, can click on this thumbnail image to confirm the contents of the displayed surgery consent form and agree to the electronic signature by the qualification signature device 1.

[0059] The in-house management column 803 is a column where the created information for management within the hospital is entered. The destination column 804 records the names of the contracting parties to this surgery consent form (Doctor Iida Taro and outpatient Masao) and the destination of the surgery consent form for each of them. The signature selection button 809 is a button that displays a selection screen for the type of electronic signature (general, qualified, etc.) for the surgical consent form. This signature selection button 809 can only be selected after the user has selected the thumbnail field 802 and displayed and confirmed the surgical consent form at the linked destination.

[0060] FIG. 9 shows an electronic signature selection screen that is displayed when the signature selection button 809 is selected. As shown in FIG. 9, the electronic signature selection screen displays a signature qualification selection field 901, a qualification signature request button 909, and the like. The signature qualification selection field 901 specifies the types of electronic signatures that can be selected in relation to the contract (surgery consent form), including a general signature without a qualification, a qualification signature (Japanese nationality), a qualification signature (physician), a qualification signature (dentist), etc. The qualification signature request button 909 is a button for requesting the qualification signature apparatus 1 to issue an electronic signature corresponding to any one of the selected signature forms.

[0061] Returning to FIG. 6, the user terminal (doctor) 91 designates users (patients) other than the doctor for the surgery consent form (step 914). That is, the doctor inputs his / her name, destination, and the patient's name and destination in the destination column 804 . However, this step 914 can be omitted if the information has already been entered by the creator of the file, as in the surgery consent file shown in FIG.

[0062] Next, on the user terminal (doctor) 91, the thumbnail image in the thumbnail column 802 is clicked to display the "Surgery Consent Form," and the doctor checks the displayed contents and enters the doctor's name in the signature column of the surgery consent form (or checks the name if it has already been entered by the creator). Thereafter, the doctor selects the signature selection button 809 displayed on the screen to display the electronic signature selection screen, and selects the type of qualification signature to be requested from the qualification signature apparatus 1 (in this case, qualification signature (doctor)). As a result, the user terminal (doctor) 91 transmits to the qualification signature device 1 that "qualification signature (doctor)" has been selected (step 915).

[0063] When the "license signature (doctor)" is notified from the user terminal (doctor) 91, the license signature device 1 checks the license code associated with the ID (step 112). That is, the qualification signature device 1 reads the ID stored in RAM 13 in step 110, determines whether the qualification identified by the qualification code 5525 (see Figure 3) associated with this ID matches the qualification in the notified signature form (in this case, a doctor), and returns confirmation information to the user terminal (doctor) 91 if they match, or mismatch information if they do not match. When confirmation information is returned, the user terminal (doctor) 91 makes the qualification signature request button 909 shown in Figure 9 selectable, and when discrepancy information is returned, a message to that effect is displayed on the screen, and the user must change to a different qualification signature format.

[0064] When the doctor selects the qualification signature request button 909, which has become selectable, the user terminal (doctor) 91 transmits a request (request) for an electronic signature based on the qualification to the qualification signature device 1 (step 916), and the qualification signature device 1 receives the request for an electronic signature (step 113).

[0065] Then, the license signature device 1 checks the expiration date of the license corresponding to the doctor's ID stored in the RAM 13 (step 114). That is, the qualifications signature apparatus 1 determines that the ID is within the validity period if the validity period stored in the qualifications verification document data 5524 corresponding to the ID is later than the current time (current date). It is also possible to determine that the expiration date is within the expiration date if the expiration date is a predetermined period T or more from the current date. In this case, the predetermined period T is arbitrary, but a default period is set to, for example, one month. If the license expiration date has passed (step 114; N), the license signature device 1 sends an error screen (expiration date exceeded) to the user terminal (doctor) 91 (step 115), and the user terminal (doctor) 91 displays the error screen to notify the doctor that the expiration date has passed.

[0066] On the other hand, if the license is within the validity period (step 114; Y), license signature device 1 creates attribute information to be attached to the surgery consent form (step 116). That is, the qualification signature device 1 refers to the account DB 55 corresponding to the ID of the doctor who has been requested to sign, reads out each of the above-mentioned data (a) to (g) from the account table 551 and the qualification / identification information table 552, and creates attribute information to be attached to the surgery consent form.

[0067] Thereafter, the entitlement signing device 1 executes the entitlement signing to create a "primary signed electronic contract" (step 117). That is, the qualification signature device 1 checks the location of the qualification signature key, etc. from the qualification code 5525 of the qualification (doctor) corresponding to the signature form notified by the user terminal (doctor) 91 in step 915, reads the qualification signature key, etc. (qualification signature key and electronic certificate) for the qualification (doctor) from the signature key DB 57, temporarily stores it in RAM 13, and executes the qualification signature using the qualification signature key, etc.

[0068] Figure 10 is an explanatory diagram conceptually showing the structure of a qualified signature electronic contract after a qualified signature has been made. Note that Figure 10 does not show a specific surgery consent form, but rather a more generalized structure after parties A and B have executed a qualified signature, etc., on an electronic contract (including a surgery consent form). The execution of the entitlement signature using the entitlement signature key and the like in step 117 will be described below with reference to FIG. The qualification signing device 1 attaches the attribute information 122 of contract holder A (doctor) created in step 116 to the ``electronic contract (original) 120'' (surgery consent form), creates a ``first electronic contract'' 123, and calculates a hash value 124 of this first electronic contract.

[0069] Furthermore, the qualification signature device 1 calculates the signature value 125 by encrypting the calculated hash value 124 using the qualification signature key (private key) corresponding to the signature type (qualification signature (doctor)) notified by the user terminal (doctor) 91 in step 915. The qualification signature device 1 creates a "primary signature electronic contract" 127 based on Party A's request (qualification signature (doctor)) by embedding the calculated signature value 125 and the "electronic certificate" 126 corresponding to the used qualification signature key into the "first electronic contract" 123. Although the digital certificate is embedded in the "primary signed digital contract" 127, both the digital certificate and revocation information may be embedded. If revocation information is not embedded, it is necessary to check whether the digital certificate has been revoked based on the revocation information of the certification authority 7 that issued the digital certificate.

[0070] Returning to FIG. 6, after the qualification signature based on the request of the user (doctor) (step 117) is completed, the qualification signature device 1 transmits a qualification signature completion screen to the user terminal (doctor) 91 that requested the qualification signature (step 118). On the other hand, the user terminal (doctor) 91 displays the received qualification signature completion screen to notify the user (doctor) (step 917).

[0071] Next, as shown in Figure 7, the qualification signature device 1 presents the "primary signed electronic contract" 127 to the user terminal (patient) 92 of the user (patient) who is an unsigned contracting party (step 119), and displays it on the screen of the user terminal 92 (step 922). That is, the qualification signature device 1 sends the URL where the "primary signature electronic contract" 127 is saved to the telephone number of the user (patient) by SMS, and prompts the user to confirm and request an electronic signature. Here, the telephone number of the outpatient Masao, who is the user (patient) specified in the delivery address field 804 of Figure 8, is used as the telephone number for the SMS. If the delivery address field 804 is not specified, the telephone number of the user, etc. specified from the user terminal (doctor) 91 in step 914 is used.

[0072] The user (patient) who receives the request for electronic signature via SMS accesses the specified URL from the user terminal (patient) 92 and displays the "primary signature electronic contract" 127 on the screen (step 922). The user (patient), like the user (doctor), clicks on the thumbnail image in the thumbnail field 802 (Figure 8) of the "First Signature Electronic Contract" 127 displayed on the screen to display the "Surgery Consent Form," confirm its contents, and enters the patient's name in the signature field of the surgery consent form (or confirms the name if it has already been entered by the creator). Furthermore, the patient selects the signature selection button 809 to display the electronic signature selection screen (Fig. 9) and selects the type of qualification signature (here, general signature) (step 923). If this general signature is selected, the qualification code confirmation by the qualification signature device 1 (step 112) is not required, so the qualification signature request button 909 becomes selectable. When the user (patient) selects the qualification signature request button 909, the user terminal (patient) 92 requests a general signature from the qualification signature device 1 (step 924).

[0073] When the qualification signature device 1 receives an electronic signature request from the user terminal (patient) 92, it creates attribute information to be attached to a "primary signature electronic contract" 127 including the surgery consent form (step 120). That is, since the request for an electronic signature is a general signature, the qualification signature device 1 refers to the account DB 55 corresponding to the ID of the user (patient), reads the ID, email address, and telephone number (SMS) from the account table 551, and creates attribute information.

[0074] Then, the entitlement signature unit 1 reads out the common signature key from the common key DB 58 and executes the general signature (step 121). That is, as shown in Figure 10, the entitlement signature device 1 attaches the created attribute information (attribute information of Contractor B) to the "primary signed electronic contract" 127 to create a "secondary electronic contract" 132, calculates a hash value 133 of this "secondary electronic contract" 132, encrypts it with a common signature key, and calculates a signature value 134. The entitlement signature device 1 embeds the calculated signature value 134 and the "digital certificate" 135 corresponding to the common signature key into the "second digital contract" 132, thereby creating a "entitlement signature digital contract" 136 based on the request of the doctor (party A) and the patient (party B). Note that revocation information can also be embedded together with the digital certificate 135, as in the case of the entitlement signature.

[0075] At this stage, the qualification signature device 1 transmits a general signature completion screen indicating that the general signature based on the request from the patient has been completed to the user terminal (patient) 92 (step 122), and the user terminal (patient) 92 displays the received general signature completion screen to notify the user (patient) (step 925).

[0076] The entitlement signature device 1 further requests the timestamp server 8 to assign a timestamp to the "entitlement signature electronic contract" 136, and creates a "entitlement signature electronic contract (TS)" 138 (step 123). Then, the "Qualification Signature Electronic Contract (TS)" 138 is stored in the electronically signed file in the file table 553 of the two parties in the account DB 55 associated with the ID of the user (doctor) who signed the qualification and the ID of the user (patient) with a predetermined signature management number, and is also sent to the user terminal (doctor) 91 and the user terminal (patient) 92 (step 124), thereby completing the qualification signature process. Meanwhile, the user terminal (doctor) 91 and the user terminal (patient) 92 display the received "Qualification Signature Electronic Contract (TS)" 138 on their screens, and after the doctor and patient have confirmed it, they save it in a designated storage device in accordance with the save processing operation (steps 918 and 926), thereby completing the process.

[0077] Next, the verification process of the entitlement signature electronic contract (TS) will be explained. FIG. 11 is a flowchart showing the flow of verification processing for a qualification-signed digital contract (TS) that has been qualified. Note that the verification of the qualified signature electronic contract (TS) is performed not only by the parties to the contract, but also by qualified administrators and other verifiers, and therefore is shown as a user terminal 95 used by these persons. As shown in FIG. 11, the user terminal (verifier) ​​95 displays on its screen the entitlement signature electronic contract (TS) designated based on the verifier's operation (step 951). When the verifier selects the verification button, the signature management number attached to the qualifications signature electronic contract (TS) is transmitted to the qualifications signature device 1 to request verification (step 952).

[0078] The entitlement signing device 1 reads out the entitlement signing electronic contract (TS) with the specified signature management number, and checks whether it has been tampered with and whether it has expired (step 131). That is, the entitlement signing device 1 obtains a hash value 133 of the second electronic contract 132 by decrypting the signature value 134 using the public key described in the digital certificate 135 embedded in the entitlement signing digital contract (TS). This hash value 133 is a value calculated in the entitlement signing process. Furthermore, the entitlement signing device 1 obtains a new hash value for verification from the second electronic contract 132 (see FIG. 10) and verifies that this matches the hash value 133.

[0079] In addition, the entitlement signature device 1 obtains a hash value 124 of the first electronic contract 123 by decrypting the signature value 125 using the public key described in the electronic certificate 126, and verifies that it matches the hash value of the first electronic contract 123 calculated for verification purposes. If the hash values ​​133 and 124 match, the entitlement signing device 1 verifies that the electronic contract (original) is not tampered with.

[0080] Furthermore, the qualification signature device 1 checks the expiration date by verifying that the expiration date recorded based on the qualification confirmation document data 5524 is later than the qualification signature date and time of the qualification signature electronic contract (TS) being verified. This verification proves that the electronic contract was made by a qualified person holding valid credentials. It is also possible to use the acquisition date and time of a timestamp instead of the date and time of signing the credentials. In this case, the credentials signing device 1 verifies that the expiration date of the credentials is later than the acquisition date and time of the timestamp.

[0081] In this way, not only can it be verified that the qualified signature electronic contract (TS) has not been tampered with, but by including the expiration date of the qualification in the attribute information that is the subject of the signature (the subject of hashing), it can also be verified that the electronic contract has been qualified and signed at the request of a qualified person who holds a valid qualification.

[0082] After checking for tampering and expiration date, the certificate signing device 1 presents the verification result to the user terminal (verifier) ​​95 (step 132), and the user terminal (verifier) ​​95 displays the verification result on the screen (step 953). The user (verifier) ​​can confirm from the verification results displayed on the screen that the entitlement signature electronic contract (TS) has not been tampered with and that the entitlement signature device 1 has verified that the entitlement signature was made within the validity period of the entitlement.

[0083] Furthermore, based on the operation of the verifier who specifically wishes to have the qualifications verified, the user terminal (verifier) ​​95 displays a qualification comparison table on the screen (step 954). That is, the user terminal (verifier) ​​95 reads the location (URI) of the qualification comparison table recorded in the attribute information 122 of contractor A (qualified person) in the qualification signature electronic contract (TS) 138, accesses the list publication server 6 to read the qualification comparison table 61, and displays it on the screen. The user terminal (verifier) ​​95 further displays the qualification comparison table, as well as attribute information and the contents of the electronic certificate in accordance with the verifier's operations.

[0084] The verifier can confirm the following (A) to (E) by referring to and comparing the entitlement comparison table displayed on the user terminal (verifier) ​​95 with the contents of the entitlement signature (attribute information 122, 131, electronic certificate 126, 135, etc.) (step 955). (A) It can be confirmed that the name of the qualification that the qualification signing device 1 has determined the contractor has is written in the attribute information 122 of the qualification signing electronic contract (TS) 138. Alternatively, the common name of the digital certificate used in the qualification signature can be confirmed. (B) You can refer to the qualification comparison table 61 to check the qualification code corresponding to the qualification name. Or, it can be confirmed that the common name of the digital certificate in (A) above corresponds to the name of the qualification.

[0085] (C) It can be confirmed whether the qualification name recorded in the attribute information 122 of the qualification signature electronic contract (TS) 138 matches the qualification comparison table 61. This allows verification that the credential signing was performed by the appropriate entity. (D) It can be confirmed that the expiration date written in the attribute information 122 is later than the date and time of the qualification signature recorded in the qualification signature electronic contract (TS) 138. This allows us to confirm that the user's (qualified person's) account has been registered and provided after proper qualification verification has been carried out. (E) By referring to the "Identity Verification Method" and "Qualification Verification Method" in the Qualification Comparison Table 61, it is possible to confirm whether the qualification verification and identity verification of the qualified person have been carried out appropriately. Furthermore, a third party can also check the policies of the "identity verification method" and "qualification verification method" determined by the qualification signature device 1 or the organization (company, hospital, etc.) to which the qualified person belongs.

[0086] As explained above, in the case of an electronic contract using a witness-type electronic signature, if the contracting parties are qualified persons with specified qualifications such as doctors or architects, the qualification signature device 1 performs a preliminary qualification check and party check before registering an account. Then, an electronic signature (qualification signature) is applied to electronic contracts such as surgical consent forms using a qualification signature key that differs for each qualification and an electronic certificate that contains qualification information indicating that the person is the holder of the qualification corresponding to the qualification signature key, so that the qualifications held by the contracting parties can be confirmed from the electronic contract with the qualification signature (qualification signature electronic contract 136 or qualification signature electronic contract (TS) 138) (this is called the first qualification confirmation configuration). In addition, when signing a qualification signature, at least one piece of qualification confirmation information is recorded in the attribute information 122 of the qualified person (contractor A), who is the subject of the hash value calculation, so the qualification information of the contracting parties can also be confirmed from the attribute information 122 of the electronic contract to which the qualification signature has been applied (this is called the second qualification confirmation configuration). Furthermore, the account of each qualified person records the person who confirmed the qualification and the expiration date, and these are recorded in the attribute information, so it is possible to verify that the electronic contract was made by a qualified person with valid qualifications.

[0087] Although the embodiment of the entitlement signature device 1 has been described, the following modifications are possible. For example, in the described embodiments and variants, the qualification signature device 1 acquires personal identification information and registration information including the qualification confirmation information, and performs personal identification (confirms the existence of a qualified person) and qualification confirmation (confirms that the qualified person owns the qualification and that the qualification is valid) based on the acquired registration information, and if both confirmations are successful, the qualification signature device 1 registers the information in the account DB 55. In contrast, in this modified example, the identity and qualification verification of the qualified person based on the registration information is requested from a third-party identity verification agency outside the qualification signature device 1 (for example, My Number Portal or an identity verification service provider), and if the identity and qualification verification is successful based on the verification results received from the identity verification agency, the received registration information and token, etc. are stored in the qualification / identity verification information table 552 of the account DB 55. Below, a case will be described in which the identity verification agency performs both identity verification and qualification verification, but it is also possible for identity verification and qualification verification to be performed by separate third-party agencies.

[0088] The following describes the qualification signature device 1 in this modified example, focusing on the differences from the embodiment described above. FIG. 13 shows the configuration of a qualification signature system in a modified example, and corresponds to FIG. 1 in the embodiment. The identity verification organization 75 is an external organization that verifies the identity of unqualified and qualified individuals, and verifies the qualifications of qualified individuals, and functions as a third-party organization. For example, My Number Portal and identity verification service providers are examples of such organizations. As shown in FIG. 13, the qualification signature apparatus 1 of this modified example is further connected to an identity verification organization 75 via the Internet, VPN, or the like.

[0089] The identity verification organization 75 includes an organization DB 76. The organization DB 76 stores registration information (identity verification information, qualification verification information) submitted by unqualified individuals, qualified individuals, administrators, and qualified identity verifying individuals. Based on the registration information sent from the qualifications signing device 1 and the confirmation request, the identity verification authority 75 verifies the identity and qualifications by querying the authority DB 76, and transmits a token that has confirmed that the person is the person in question and the holder of the qualification as the confirmation result (identity verification result, qualification verification result) to the qualifications signing device 1. Here, the token sent by the identity verification authority 75 is a unique code that indicates that a verification query has been made. In addition, the identity and qualification verification of the contracting parties (qualified and unqualified persons) may be performed by the qualification signing device 1, or the qualification signing device 1 may request the verification to be performed by an external device, such as an identity verification agency 75 (functioning as a third-party agency), such as My Number Portal or an identity verification service provider.

[0090] In the embodiment shown in Figure 3, the identity verification information 5521 of the account DB 55 stores the "identity verification person ID" and "identity verification method" (see Figure 3), whereas in this modified example, the identity verification information 5521 stores the "token from the institution DB 76" and "query to the institution DB 76" (indicating that a query to the institution DB 76 was made as the qualification verification method). In this modified example, the "token of the authority DB76" is a token as a confirmation result (identity verification result, qualification verification result) received from the identity verification authority 75 in response to an inquiry requested by the qualification signature device 1 sending registration information to the authority DB76 of the identity verification authority 75. The contents of the personal identification document data 5522 and the qualification verification document data 5524 stored in the account DB 55 are the same as those in the embodiment shown in Figure 3, but if there are items that overlap with the contents stored in the institution DB 76, they can be excluded from being stored in the account DB 55.

[0091] The token resulting from the verification, together with the URL of the identity verification agency 75, which is the authentication site, is included in the attribute information 122 attached to the electronic contract (original) when the qualified person's qualifications are signed by the qualifications signature device 1, or in the form portion to be hashed, and is used as the object for calculating the hash value. This makes it possible for the contracting parties or verifiers to verify the qualifications of the qualified person in the verification process of the qualified person's electronic contract at a later date. This makes it possible to verify the credentials by accessing the identity verification agency 75, which is an authentication site, and entering the token.

[0092] Note that the authority DB 76 may not have a mechanism for returning a token, and may, for example, return only the registration information, or may only display the results on a web screen. In such cases, the response to the web request or a web screen screenshot obtained from the authority DB76 may be saved in the identity verification document data 5522, and a hash value may be calculated from this identity verification document data 5522 data and used in place of the token from the authority DB76. In this way, the responses to web requests and web screen screenshots obtained from the institution DB 76 are used to calculate hash values, so that it is possible to verify the qualifications of qualified individuals by checking whether the hash value matches the hash value recalculated from the identity verification document data 5522, rather than accessing the authentication site, which is the identity verification institution 75, and entering the token. In practice, it is defined as a qualified identity verification method depending on the configuration of each identity verification organization 75.

[0093] FIG. 14 conceptually shows the contents of the qualification DB 56 in the modified example, and corresponds to FIG. 4 in the embodiment. In the qualification DB 56 in the embodiment, (i) to (iv) have been described as the "qualified person identification method" (see FIG. 4) for identifying the qualified person, which is predetermined for each qualification code. In contrast to this, in this modified example, a further provision (e) of the qualified person identity verification method is added, which states that "the identity verification agency 75 returns a token as the verification result upon querying the agency DB 76." As a result, as shown in FIG. 14, the "Qualified Person Identity Verification Method" column for the qualification names such as doctor, dentist, pharmacist, etc. is (A) to (E).

[0094] FIG. 15 is a flowchart showing the flow of the account registration process in the modified example, and corresponds to FIG. 5 in the embodiment. In the account registration process in this modification, the identity verification and qualification verification are performed by the identity verification organization 75, so the process by the user terminal 94 in the embodiment is not required. As a prerequisite for the account registration process in this modified example, it is assumed that documents and data (registration information) necessary for identity verification and qualification verification are submitted to the identity verification agency 75 by unqualified persons, qualified persons, managers of qualified persons, qualified identity verifyers, etc., and registered in the agency DB 76.

[0095] As shown in Figure 15, the user sends registration information (identity verification information, qualification verification information) including, for example, a qualification certificate and a resident card, requested by the institution DB 76 of the identity verification agency 75 from the user terminal 91 to the qualification signature device 1, and requests account registration (step 911). When the qualification signature device 1 acquires the registration information from the user terminal 91, it temporarily stores it in RAM 13 (step 101), and sends the registration information received as information regarding identity verification and qualification verification requested by the institution DB 76 of the identity verification agency 75, requesting a confirmation inquiry (step 1011).

[0096] When the identity verification agency 75 receives a confirmation query from the agency DB 76, it performs identity verification and qualification verification, and sends a token that confirms the identity of the person and that the person is the holder of the qualification to the qualification signing device 1 as the verification result (identity verification result, qualification verification result). As a result, the entitlement signature device 1 obtains a token from the identity verification authority 75 as the inquiry result (identity verification result, entitlement verification result) in response to the verification inquiry. The qualification signature device 1 completes identity verification and qualification verification by receiving the token in response to the verification inquiry, and then creates an account for the qualified person based on the contents of the registration information temporarily stored in RAM 13 and the token, etc., and saves it in the qualification / identity verification information table 552 of the account DB 55 (step 1012).

[0097] Next, the qualification signature device 1 refers to the qualification comparison table 61 of the list publication server 6 for the qualification of the qualified person of the user terminal 91, and acquires a qualification code corresponding to the qualification (step 102). The following processing (from step 103) is the same as in the embodiment.

[0098] As another modification, for example, in the embodiment described above, a case where entitlement signatures are made using both the first entitlement verification configuration and the second entitlement verification configuration has been described. Alternatively, the entitlement signature may be performed using only one of the first entitlement verification configuration and the second entitlement verification configuration. The structure of the qualification signature electronic contract 136 (138) in these cases will be described with reference to FIG.

[0099] When only the first credential verification configuration is used, the credential signing device 1 enters the above-mentioned information (a) in the attribute information 122 of contractor A (qualified person), similar to the attribute information 131 of contractor B (unqualified person), but does not enter the information (b) to (g). Then, as in the embodiment, the credential signing device 1 issues an electronic signature (credentials signature) using a credential signing key corresponding to the credential and an electronic certificate describing credential information indicating that the person is the holder of the credential corresponding to the credential signing key.

[0100] When only the second qualification verification configuration is used, the qualification signature device 1 enters information (a) to (g) in the attribute information 122 of contractor A (qualified person) as in the embodiment, and performs an electronic signature (general signature) on the hash value 124 using a common signature key and an electronic certificate. When only the second qualification confirmation configuration is used, the qualification signature device 1 may attach the attribute information of all contracting parties (qualified parties enter (a) to (g) and unqualified parties enter (a)) together to the first electronic contract 123, as shown in Figure 12, and perform a general signature using a common signature key and electronic certificate. In this case, the attribute information for qualified parties will be (a) to (g), and the attribute information for unqualified parties will be (a).

[0101] In addition, in the described embodiments and variants, the case where the qualification signature device 1 performs the qualification signature process based on confirmation and signature requests for the surgical consent form from two parties, a doctor from the user terminal (doctor) 91 and a patient from the user terminal (patient) 92, has been described. On the other hand, it is also possible to perform qualification signature processing for signature requests from three or more contracting parties, for example, a qualified doctor, a patient, and the patient's guarantor, using the qualification signature device 1. In this case, the qualification signature device 1 performs qualification signature processing using a qualification signature key or the like for the signature request from the qualified doctor, issues a general signature using a common key or the like for the signature request from the patient, and issues a general signature using a common key or the like for the signature request from the guarantor.

[0102] In the embodiment and modified examples described above, a case has been described in which a qualified person (doctor) signs a certificate and then a general signature is issued in response to a general signature request from a non-qualified person (patient). In contrast, the signature request can come first from either the qualified or unqualified party. When the request from the unqualified party comes first, the first electronic contract (corresponding to first electronic contract 123 in Figure 10) is signed by adding the ID, email address, and telephone number (SMS) to the attribute information of contractor B (unqualified party) and signing with a general signature, and then adding the qualification information (a) to (g) to the attribute information of contractor A (qualified party) and signing with a qualification signature.

[0103] In addition, two or more of the multiple contractors may be qualified, and in this case the qualifications may be the same or different. For example, in the case of a construction contract for a hospital, a construction contract between a qualified person (doctor) and a qualified person (architect) will be signed with a qualification signature using a qualification signature key corresponding to the doctor, and a qualification signature using a qualification signature key corresponding to the architect.

[0104] Furthermore, when there are multiple qualified and unqualified parties to a contract, for example, in the case of N contracting parties, instead of making a total of seven qualified signatures or general signatures, it is also possible to have all qualified and unqualified parties with the same qualification make a qualified signature or unqualified signature together. For example, in the case of an electronic contract between seven people, namely, qualified persons a1 to a3 with qualification A, qualified persons b1 and b2 with qualification B, and unqualified persons x1 and x2, the attribute information (including qualification information) of each of the qualified persons a1 to a3 is attached together and a qualified signature is made using a signing key or the like for qualification A, the attribute information (including qualification information) of each of the qualified persons b1 and b2 is attached together and a qualified signature is made using a signing key or the like for qualification B, and the attribute information (excluding qualification information) of each of the unqualified persons x1 and x2 is attached together and a general signature is made using a common signing key or the like. This allows the qualification signature to be completed with the number of electronic signatures corresponding to the number of qualified and unqualified parties (three times), rather than the number of electronic signatures corresponding to the total number of contract holders N (seven times).

[0105] In the embodiment and modified examples described above, the qualification signature device or the like when the contract form is an electronic contract using a witness-type electronic signature can be configured as follows. (Configuration 11) A qualified signature device for executing a witness-type electronic signature on an electronic contract by a contracting party, an electronic contract acquisition means for acquiring an electronic contract that is the subject of the electronic contract between the contracting parties; a qualification determination means for determining whether the contracting party is a qualified person having a predetermined qualification; an electronic signature means for, when the contracting party is a qualified person, signing the electronic contract using a qualification signature key, which is a private key created in accordance with the qualification of the qualified person, and an electronic certificate in which specific information of the qualification is recorded; A qualification signing device comprising: (Configuration 12) The electronic signature means issues an electronic signature using the qualification signature key and the electronic certificate when requested to do so by the qualified person. 12. The entitlement signing device according to claim 11. (Configuration 13) The electronic signature means In response to a signature request from the contracting party who is a qualified person, a qualified signature is made using the qualified signature key and the electronic certificate; In response to a signature request from a non-qualified contracting party, a general signature is made using a common signature key, which is a private key that does not correspond to the qualification, and an electronic certificate that does not record any specific information about the qualification. 13. The entitlement signing device according to claim 11 or 12. (Configuration 14) An account DB is provided in which identity verification information and qualification verification information are stored in the account of the qualified person, and identity verification information is stored in the account of the unqualified person who does not have the qualification, The qualification determination means determines whether the contracting party is a qualified person based on the account DB. 14. The entitlement signing device according to claim 11, 12, or 13. (Configuration 15) The account DB stores a login identification number and password for each qualified person and unqualified person, The qualification determination means determines whether the contracting party is qualified or unqualified based on the identification number used when the contracting party logs in. 15. The entitlement signing device of claim 14. (Configuration 16) A registration information acquisition means for acquiring registration information including identity verification information and qualification verification information from the qualified person; a verification means for verifying the identity of the qualified person based on the acquired registration information and for verifying that the qualification held by the qualified person is valid; a registration means for registering the acquired registration information in the account of the qualified person in the account DB when the identity verification and the qualification verification are successful; 15. The entitlement signing device according to claim 14, comprising: (Configuration 17) The qualification signature device described in Configuration 16 is characterized in that the verification means requests the same or different third-party organizations to verify the identity based on the acquired identity verification information and to verify the qualifications based on the acquired qualification verification information, and obtains an identity verification result that the qualified person exists and a qualification verification result that the qualifications held by the qualified person are valid. (Configuration 18) If the contracting party is a qualified person, the electronic signature means attaches attribute information recording qualification information identifying the qualification of the qualified person to the electronic contract, and performs an electronic signature using the qualification signature key and electronic certificate. 18. The entitlement signing device of any one of configurations 11 to 17. (Configuration 19) A qualified signature program that causes a computer to function as a qualified signature device that executes a witness-type electronic signature on an electronic contract by a contracting party, an electronic contract acquisition function for acquiring an electronic contract that is the subject of the electronic contract between the contracting parties; a qualification determination function for determining whether the contracting party is a qualified person having a predetermined qualification; an electronic signature function that, when the contracting party is a qualified person, electronically signs the electronic contract using a qualification signature key, which is a private key created in accordance with the qualification of the qualified person, and an electronic certificate in which specific information of the qualification is recorded; A qualification signing program characterized by causing a computer to realize the above.

[0106] It is also possible to configure it as follows. (Configuration 21) A qualified signature device for executing a witness-type electronic signature on an electronic contract by a contracting party, an electronic contract acquisition means for acquiring an electronic contract that is the subject of the electronic contract between the contracting parties; a qualification determination means for determining whether the contracting party is a qualified person having a predetermined qualification; If the contracting party is a qualified person, an electronic signature means attaches personal information identifying the qualified person and attribute information recording qualification information identifying the qualification to the electronic contract and executes an electronic signature; A qualification signing device comprising: (Configuration 22) When requested to do so by the qualified person, the electronic signature means attaches attribute information recording the personal information and the qualification information to the electronic contract and signs it. 22. The entitlement signing device according to claim 21. (Configuration 23) When the contracting party is an unqualified person, the electronic signature means attaches attribute information recording personal information identifying the unqualified person to the electronic contract and signs the electronic contract. 23. The entitlement signing device according to claim 21 or 22. (Configuration 24) An account DB is provided in which identity verification information including identity information and qualification verification information including qualification information are stored in the account of the qualified person, and identity verification information including identity information is stored in the account of the unqualified person who does not have qualification, The qualification determination means determines whether the contracting party is a qualified person based on the account DB. 24. The entitlement signing device according to claim 21, 22, or 23. (Configuration 25) The account DB stores a login identification number and password for each qualified and unqualified person, The qualification determination means determines whether the contracting party is qualified or unqualified based on the identification number used when the contracting party logs in. 25. The entitlement signing device of claim 24. (Configuration 26) A registration information acquisition means for acquiring registration information including identity verification information and qualification verification information from the qualified person; a verification means for verifying the identity of the qualified person based on the acquired registration information and for verifying that the qualification held by the qualified person is valid; a registration means for registering the acquired registration information in the account of the qualified person in the account DB when the identity verification and the qualification verification are successful; 25. The entitlement signing device according to claim 24, comprising: (Configuration 27) The qualification signature device described in Configuration 26 is characterized in that the verification means requests the same or different third-party organizations to verify the identity based on the acquired identity verification information and to verify the qualifications based on the acquired qualification verification information, and obtains an identity verification result that the qualified person exists and a qualification verification result that the qualifications held by the qualified person are valid. (Configuration 28) When the contracting party is a qualified person, the electronic signature means attaches attribute information to the electronic contract, which further records at least one of the identification information of the person who confirmed the qualification of the qualified person and the method of confirming the qualification, to the attribute information of the qualified person. 28. The entitlement signing device of claim 2 of any one of claims 21 to 27. (Configuration 29) A qualified signature program that causes a computer to function as a qualified signature device that executes a witness-type electronic signature on an electronic contract by a contracting party, an electronic contract acquisition function for acquiring an electronic contract that is the subject of the electronic contract between the contracting parties; a qualification determination function for determining whether the contracting party is a qualified person having a predetermined qualification; an electronic signature function that, if the contracting party is a qualified person, attaches personal information identifying the qualified person and attribute information recording the qualification information identifying the qualification to the electronic contract and executes an electronic signature; A qualification signing program characterized by causing a computer to realize the above. [Explanation of symbols]

[0107] 1. Credential signing device 2. Credential Signature Processing Unit 3 Signature Verification Unit 4. Account Registration Section 5 Storage device 6 List publishing server 7 Certificate Authorities 8. Timestamp Server 9, 91-95 User terminals 11 CPU 12 ROM 13 RAM 14 Communication control section 50 Qualification Signature Processing PG 51 Signature Verification PG 52 Account Registration PG 54 Template DB 55 Account DB 56 Qualification DB 57 Signing key DB 61 Qualification Comparison Table 75 Identity Verification Agency 76 Institutional DB 122 Attribute information 123 Electronic Contracts 124, 133 hash value 125 Signature Value 126 Digital Certificates 131 Attribute information 132 Electronic Contracts 134 Signature Value 135 Digital Certificates 136 Qualified Signature Electronic Contract 551 Account Table 552 Eligibility and Identity Verification Information Table 5521 Personal Identification Information 5522 Personal Identification Document Data 5523 Credential Verification Information 5524 Qualification Verification Document Data 5525 Qualification Code 553 File Table 801 Form column 802 Thumbnail column 803 Internal Management Column 804 Delivery address field 809 Signature Selection Button 901 Signature qualification selection field 909 Qualification Signature Request Button

Claims

1. A qualified signature device for executing a witness-type electronic signature on an electronic contract by a contracting party, an electronic contract acquisition means for acquiring an electronic contract that is the subject of the electronic contract between the contracting parties; a qualification determination means for determining whether the contracting party is a qualified person having a predetermined qualification; an electronic signature means for, when the contracting party is a qualified person, signing the electronic contract using a qualification signature key, which is a private key created in accordance with the qualification of the qualified person, and an electronic certificate in which specific information of the qualification is recorded; A qualification signing device comprising:

2. the electronic signature means, when requested to do so by the qualified person, issues an electronic signature using the qualified signature key and the electronic certificate; 2. The entitlement signing device of claim 1.

3. The electronic signature means In response to a signature request from the contracting party who is a qualified person, a qualified signature is made using the qualified signature key and the electronic certificate; In response to a signature request from a non-qualified contracting party, a general signature is made using a common signature key, which is a private key that does not correspond to the qualification, and an electronic certificate that does not record any specific information about the qualification.

3. The entitlement signing device according to claim 1 or claim 2.

4. An account DB is provided in which identity verification information and qualification verification information are stored in the account of the qualified person, and identity verification information is stored in the account of the unqualified person who does not have qualification, The qualification determination means determines whether the contracting party is a qualified person based on the account DB.

3. The entitlement signing device according to claim 1 or claim 2.

5. The account DB stores login identification numbers and passwords for each qualified and unqualified person, The qualification determination means determines whether the contracting party is qualified or unqualified based on the identification number used when the contracting party logs in.

5. The entitlement signing device of claim 4.

6. a registration information acquisition means for acquiring registration information including identity verification information and qualification verification information from the qualified person; a verification means for verifying the identity of the qualified person based on the acquired registration information and for verifying that the qualification held by the qualified person is valid; a registration means for registering the acquired registration information in the account of the qualified person in the account DB when the identity verification and the qualification verification are successful; 5. The entitlement signing device of claim 4, further comprising:

7. The qualification signature device described in claim 6, characterized in that the verification means requests the same or different third-party organizations to verify the identity of the person based on the acquired identity verification information and to verify the qualifications based on the acquired qualification verification information, and obtains an identity verification result that the qualified person exists and a qualification verification result that the qualification held by the qualified person is valid.

8. If the contracting party is a qualified person, the electronic signature means attaches attribute information recording qualification information identifying the qualification of the qualified person to the electronic contract and executes an electronic signature using the qualification signature key and electronic certificate.

3. The entitlement signing device according to claim 1 or claim 2.

9. A qualified signature program that causes a computer to function as a qualified signature device for executing a witness-type electronic signature on an electronic contract by a contracting party, an electronic contract acquisition function for acquiring an electronic contract that is the subject of the electronic contract between the contracting parties; a qualification determination function for determining whether the contracting party is a qualified person having a predetermined qualification; an electronic signature function that, when the contracting party is a qualified person, electronically signs the electronic contract using a qualification signature key, which is a private key created in accordance with the qualification of the qualified person, and an electronic certificate in which specific information of the qualification is recorded; A qualification signing program characterized by causing a computer to realize the above.

Citation Information

Patent Citations

  • System, method and program for electronic signature, and recording medium having the program recorded thereon

    JP2003281333A

  • Electronic signature system and its program

    JP2004248045A

  • Electronic financing contract system and method

    JP2005222268A

  • Electronic contract system and electronic contract method using the same

    JP2013114641A

  • Profile determination apparatus and profile determination method

    JP2013162235A