Electronic signature system, electronic signature method, and program using public electronic certificates

The electronic signature system addresses security and permanence issues by using a public electronic certificate to generate and verify signatures independently of handling regulations, ensuring secure and unrestricted document management.

JP2025169170AActive Publication Date: 2025-11-12SKYCOM
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2025062116
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-30
Filing Date
2025-04-03
Publication Date
2025-11-12
Estimated Expiration
2045-04-03

AI Technical Summary

Technical Problem

Existing electronic signature systems using My Number cards face restrictions due to handling regulations, leading to inconsistent digital certificate security and permanence across different services, complicating the balance between security and convenience.

Method used

An electronic signature system utilizing a public electronic certificate that generates a document hash value, acquires and verifies an electronic certificate, creates verification information, and assigns it to the document without violating handling restrictions, ensuring permanence and security through a system server.

Benefits of technology

The system provides an electronic signature system that maintains security and permanence by using official certificates without storage or management restrictions, combining the advantages of official certificates with convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025169170000001_ABST
    Figure 2025169170000001_ABST
Patent Text Reader

Abstract

To provide an electronic signature system that uses a public electronic certificate such as a My Number card and is not subject to any restrictions imposed by enforcement regulations on the handling of electronic documents to which electronic signatures are attached.SOLUTION: According to the present invention, independently created verification information that is not restricted by the Enforcement Regulations is assigned to an electronic document on the basis of an electronic signature created using an official electronic document and validity information that is restricted by the Enforcement Regulations. This makes it possible to avoid restrictions on storage, management, etc., and provides an electronic signature system that combines the permanence and security of using an official electronic certificate with the convenience of not being restricted by the Enforcement Regulations when handling electronic documents to which a digital signature is assigned.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an electronic signature system, an electronic signature method, and a program that use a public electronic certificate. [Background technology]

[0002] In recent years, with the spread of paperless and remote work, electronic documents, which are documents that have been digitized, are becoming more common. The need for electronic signatures to ensure the legal validity of electronic documents is increasing. Using electronic signatures makes it possible to confirm that electronic documents have not been tampered with and to demonstrate the authenticity of the signer's intention.

[0003] When making a digital signature, a digital certificate is used. A digital certificate, also known as a public key certificate, is a document that proves that various information, including the public key, belongs to the person in question and has been certified by a third party (certification authority). Unlike certification using a user ID or password, the use of a digital certificate has the advantage of being highly secure and with a low risk of information being stolen.

[0004] The Public-Key Infrastructure (PKI) is a standard and specification related to the operation of digital signatures. PKI consists of users who sign digital signatures, certification authorities who issue digital certificates, and repositories, which are databases that store certificates. An example of a public digital certificate currently in use is the My Number Card, which is used in the Japanese Public Key Infrastructure (JPKI) public personal authentication service. In addition to personal identification information, the My Number Card stores a digital signature certificate and a private key used as a public key.

[0005] As prior art related to electronic signatures using My Number cards, Patent Document 1 provides: reading means for reading information including at least a user's personal information from an IC card that stores the personal information, a first electronic certificate including a first public key, and a first private key corresponding to the first public key; verification means for verifying the identity of the user from an electronic signature based on the first private key of the IC card; certificate acquisition means for acquiring second information including a second electronic certificate including a second public key and a second private key corresponding to the second public key from a certification authority server that issues an electronic certificate different from the issuer of the first electronic certificate, based on the personal information included in the information read by the reading means for the user whose identity has been verified by the verification means; and signing means for applying an electronic signature based on the second private key included in the second information acquired by the certificate acquisition means to a contract.

[0006] Furthermore, there is a service called GMO Sign, operated by GMO GlobalSign Holdings Inc., that provides electronic signatures using My Number cards (Non-Patent Document 2). [Prior art documents] [Patent documents]

[0007] [Patent Document 1] Japanese Patent Application Laid-Open No. 2018-78499 [Non-patent literature]

[0008] [Non-Patent Document 1] "My Number Official Seal | For electronic contracts, use the electronic seal GMO Sign" [online], March 14, 2024, GMO GlobalSign Holdings, Inc., Internet<URL:https: / / www.gmosign.com / function / mynumber / > Summary of the Invention [Problem to be solved by the invention]

[0009] However, because My Number cards are linked to important personal information, including My Numbers, there are restrictions on how they can be handled under the Enforcement Regulations. For example, if an electronic signature is made using the digital certificate included in the My Number card, the contracting parties and businesses cannot store the signature or download the document to which the signature is attached.

[0010] For this reason, as in Patent Document 1 and Non-Patent Document 2, it is common for the My Number Card to be used as identification like a driver's license, with each electronic signature service creating a separate electronic certificate. Specifically, for each My Number Card presented by a user, each electronic signature service verifies the validity of the My Number Card with the Local Authority Information Systems Agency through an electronic certification authority, then issues an electronic certificate and creates an electronic signature using the issued electronic certificate. By using such methods, each electronic signature service maintains the convenience of electronic signatures.

[0011] However, in such electronic signatures, the digital certificates linked to the actual digital signatures are created independently by each service or system and are different from public digital certificates. This makes it difficult to guarantee their permanence and security, as there is a possibility that each digital signature service may be terminated or that the service may be operated by a company that lacks social credibility.

[0012] Due to the above circumstances, there is a problem in balancing the permanence and security that can be achieved by using official digital certificates with the convenience that is limited by the restrictions imposed by the enforcement regulations.

[0013] Therefore, the present invention aims to provide an electronic signature system that uses a public electronic certificate such as a My Number card and that is not subject to any restrictions imposed by enforcement regulations on the handling of electronic documents to which electronic signatures are attached. [Means for solving the problem]

[0014] The present invention provides an electronic signature system using a public electronic certificate executed by a system server, comprising: document hash value generation means for generating a document hash value from a previously acquired electronic document; electronic certificate acquisition means for acquiring an electronic certificate from an information source including an electronic certificate including a public key held by a user and a private key corresponding to the public key; electronic signature assignment means for acquiring from a user terminal an electronic signature created by the user terminal using the information source for the document hash value and assigning it to the electronic document; validity confirmation means for inquiring about the validity of the electronic certificate from a certification authority server that issued the electronic certificate and acquiring confirmed validity information; verification information creation means for creating verification information for the electronic signature based on the validity information acquired by the validity confirmation means; and verification information assignment means for assigning the verification information to the electronic document to which the electronic signature has been assigned by the electronic signature assignment means.

[0015] It is preferable that the validity checking means in the present invention further stores the validity information and key information for identifying the validity information in the system server.

[0016] It is preferable that the digital signature assigning means in the present invention further assigns the validity information and the key information to the digital document.

[0017] Preferably, the system server in the present invention further comprises a verification means for verifying the verification information.

[0018] The verification means in the present invention preferably further collates the verification information attached to the electronic document with the validity information stored in the system server.

[0019] It is preferable that the validity information stored in the system server of the present invention can be individually verified as needed.

[0020] It is preferable that the system server in the present invention further comprises warning means for issuing a warning message when the validity checking means determines that the data is invalid.

[0021] Although the present invention is in the category of computer systems, it also exerts similar functions and effects according to other categories such as electronic signature methods and programs. [Effects of the Invention]

[0022] According to the present invention, by creating unique validation information using a validation information creation means, it is possible to avoid storing validity information of electronic certificates, which would otherwise be subject to restrictions on how they can be used. This makes it possible to provide an electronic signature system that combines the permanence and security of using official electronic certificates with the convenience of not being restricted by enforcement regulations on the handling of electronic documents to which electronic signatures are attached. [Brief explanation of the drawings]

[0023] [Figure 1] FIG. 1 is a schematic diagram of a general electronic signature system. [Figure 2] 1 is a schematic diagram of a system 1 according to the present invention. [Figure 3] 1 is a diagram showing the overall configuration of a system 1 according to the present invention. [Figure 4] FIG. 2 is a flowchart showing a process executed by the system 1 according to the first embodiment of the present invention. [Figure 5] FIG. 10 is a flowchart showing a process executed by a system 1 according to a second embodiment of the present invention. [Figure 6] FIG. 10 is a flowchart showing a process executed by a system 1 according to a third embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0024] The present invention will be specifically described using preferred embodiments. However, the following embodiments are merely examples of the present invention, and the effects of the present invention are not limited to those described in the embodiments of the present invention.

[0025] Before explaining the present invention, we will explain the mechanism of a general electronic signature based on Fig. 1. Fig. 1 is a schematic diagram of a general electronic signature system. Electronic signatures are broadly divided into a sender's phase and a receiver's phase. In this case, the signer is on the sender's side.

[0026] First, an electronic document containing the contractual details to which the electronic signature is to be attached is created. This document can be created by either the sender or the recipient. Next, the sender, who is the party signing, creates a hash value corresponding to the electronic document. A hash value is a random number that is uniquely generated from any given sentence. The calculated hash value is encrypted with the private key, and this encrypted hash value becomes the digital signature. The electronic document, electronic signature, and public key are sent as a set to the recipient.

[0027] The recipient calculates a hash value for the received electronic document. The digital signature is then decrypted using the received public key, and the decrypted hash value is compared with the hash value calculated by the recipient. If the two values ​​match, it is determined that the signature was from the sender.

[0028] In other words, the fact that the hash value has not changed guarantees that the electronic document has not been tampered with, and the fact that the public key for the electronic signature was successfully decrypted guarantees that the electronic signature was indeed encrypted with the sender's private key.

[0029] After comparing the hash values, the public key may be verified, which involves checking whether the public key is a certificate issued to the certifier by a legitimate certification authority, whether the certificate was within its validity period at the time of signing, and whether the certificate had not expired at the time of signing.

[0030] Furthermore, the validity period of a digital certificate is five years. This period was set in consideration of developments in digital signature encryption technology. Therefore, in order to create a digital signature that is valid for more than five years, it is possible to extend the validity period by creating an additional timestamp and adding another timestamp within the validity period of that timestamp (generally within 10 years). This is called a long-term signature method.

[0031] Next, an overview of the electronic signature system 1 according to the present invention will be described. System 1 is an electronic signature system that uses public electronic certificates and is not subject to any restrictions under the Enforcement Regulations on the handling of electronic documents affixed with electronic signatures, and is composed of a system server 2 including a computer and a user terminal 3. Note that system 1 may also include other terminals and devices in addition to the system server 2 and user terminal 3, and the number, type, and functions of these devices are not particularly limited and can be designed as appropriate. The processing performed by the system 1 will be outlined with reference to Fig. 2. Fig. 2 is a schematic diagram of the system 1 according to the present invention. First, the system server 2 generates an electronic document hash value from a previously acquired electronic document. Next, the user terminal 3 acquires the electronic document hash from the system server 2 and creates an electronic signature for the electronic document hash value using an information source such as an Individual Number Card. The system server 2 then acquires the electronic signature created by the user terminal 3 and attaches the electronic signature to the electronic document. The system server 2 also acquires an electronic certificate from the information source and further verifies the validity of the acquired electronic certificate from, for example, a public personal authentication service certification authority, to obtain validity information. The system server 2 saves the acquired validity information and also creates verification information based on the validity information and attaches it to the electronic document. At this time, the acquired validity information itself is not attached to the electronic document. This means that the handling of electronic documents is not subject to the Enforcement Regulations for Individual Number Cards, etc.

[0032] The system server 2 may be realized by a computer such as a desktop computer, a notebook computer, etc. The system server 2 may be realized by a single computer, or may be realized by multiple computers such as a cloud computer. In this specification, a cloud computer refers to a computer that uses any computer in a scalable manner to perform a specific function, or a computer that includes multiple functional modules to realize a system, has those functions, and is equipped with a device as a communication unit that enables communication with other terminals, devices, etc. In this case, the system 1 executes each process described below using the system server 2 and / or a combination of the other included terminals, devices, etc.

[0033] The user terminal 3 is, for example, a computer such as a desktop personal computer, a notebook computer, or a server, a mobile terminal such as a smartphone or a tablet terminal, or a wearable terminal such as a head-mounted display such as smart glasses or a smart watch. Alternatively, a different user terminal 3 may be used for each user.

[0034] Between the system server 2 and the user terminal 3, or between the system server 2, the user terminal 3 and other terminals, devices, etc., necessary data and information are transmitted and received via information communication lines such as 4G / LTE and WiFi, or public line networks, etc. (referred to as network 4 in the figure). This communication may be wired or wireless.

[0035] Next, the system configuration of the system 1 according to the first embodiment, which is a preferred embodiment of the present invention, will be described with reference to Fig. 3. Fig. 3 is a diagram showing the overall configuration of the system 1 according to the first embodiment of the present invention.

[0036] The system server 2 includes a central processing unit (CPU), a graphics processing unit (GPU), a random access memory (RAM), a read only memory (ROM), and the like as a control unit. The system server 2 also includes a storage unit such as a hard disk, a semiconductor memory, a recording medium, a memory card, etc. The data may be stored in a cloud service, a database, etc. The system server 2 also includes a communication unit, which is a device that enables communication with other terminals, devices, etc. The communication method may be wireless or wired. The system server 2 also has an input unit that is equipped with functions necessary to enable operation of the system server 2. Examples include an LCD display that realizes a touch panel function, a keyboard, a mouse, hardware buttons on the device, and a microphone for voice recognition. Furthermore, the system server 2 is assumed to have, as an output unit, functions necessary to enable operation of the system server 2. Examples include display and audio output such as on an LCD display, a PC display, or projection on a projector. The system server 2 also has a function as a reading unit that is necessary to read information stored in some kind of IC card, such as a card reader function or an external application.

[0037] The system server 2, by having the control unit load a predetermined program, works in cooperation with the communication unit to realize a document hash value generation module 20, an electronic certificate acquisition module 21, an electronic signature assignment module 22, a validity confirmation module 23, a verification information creation module 24, and a verification information assignment module 25. It is not necessary for the system server 2 to implement all modules at once, and the system 1 may be used with only specific modules implemented.

[0038] The control unit of the user terminal 3 reads a predetermined program, and thereby the control unit cooperates with the communication unit to realize the digital signature module 30. The user terminal 3 also realizes the function of transmitting and receiving any data to and from the system server 2, and storing the received data.

[0039] An outline of the processing executed by the system 1 will be described with reference to Fig. 4. Fig. 4 is a diagram showing a flowchart of the processing executed by the system 1 according to the first embodiment of the present invention. As shown in FIG. 4, the process performed by the system 1 of the first embodiment is made up of step S30 and steps S20 to S25. The user terminal 3 is equipped with an electronic signature creation means (step S30) that creates an electronic signature for the electronic document hash value obtained from the system server 2 using an electronic certificate including a public key held by the user and an information source including a private key corresponding to the public key. The system server 2 includes a document hash value generation means (step S20) that generates a document hash value from a previously acquired electronic document, an electronic certificate acquisition means (step S21) that acquires electronic certificate information from an information source, an electronic signature assignment means (step S22) that acquires an electronic signature created by an electronic signature creation means and assigns it to the electronic document acquired by the acquisition means, a validity confirmation means (step S23) that queries the certificate authority server that issued the electronic certificate about the validity of the electronic certificate and acquires confirmed validity information, a verification information creation means (step S24) that creates verification information for the electronic signature based on the validity information acquired by the validity confirmation means, and a verification information assignment means (step S25) that assigns the verification information to the electronic document to which the electronic signature has been assigned by the electronic signature assignment means. In this specification, each process may be executed as a function that the process content has, or may be executed via a predetermined application, or may be executed by loading a predetermined program that includes the process.

[0040] The document hash value generation module 20 generates an electronic document hash value from the electronic document acquired in advance (step S20). Specifically, a hash value is calculated from the contents of the electronic document using a one-way hash function. The type of one-way hash function used here is not particularly limited as long as it is collision-resistant. The electronic document may be created by another device or the like and then stored in the system server 2, or may be acquired by the system server 2 from another device or the like via a communication line, such as when a document is created by hand and then electronically scanned and imported into the system server 2. The file format of the electronic document is primarily assumed to be PDF (Portable Document Format), but other text file formats or image file formats may also be used.

[0041] The electronic signature module 30 provided in the user terminal 3 acquires the electronic document hash value obtained in step S20, and creates an electronic signature for the acquired document hash value using an IC card that stores the user's personal information, an electronic certificate including a public key, and a private key corresponding to the public key (step S30). Specifically, the digital signature is created by encrypting the hash value using a private key. There are no particular limitations on the means and method for this encryption. The communication method between the system server 2 and the user terminal 3 may be wired or wireless, and the electronic document hash value may be obtained using an external service or application such as email or cloud drive. Also, the system server 2 may create a two-dimensional barcode that can be accessed for the electronic document, and the user terminal 3 may read this to obtain the electronic document hash value.

[0042] The digital certificate acquisition module 21 acquires digital certificate information from an information source that includes a digital certificate containing a public key held by the user and a private key corresponding to the public key (step S21). As a specific example of the acquisition method, information on an IC card including the above information is read using a terminal such as a smartphone with an IC card reader function connected to the system server 2, whether wired or wirelessly, and transmitted to the system server 2. Furthermore, the IC card reader and the system server 2 do not need to be directly connected, and a terminal with another communication function may be used as an intermediary.

[0043] The information source targeted by the electronic certificate acquisition module 21 is one that stores at least the user's personal information, an electronic certificate containing a public key, and a private key corresponding to the public key. Examples include a My Number card or an IC card issued by a public personal authentication service that records an electronic certificate containing the user's facial photograph data. The information on the IC card may be read at any time before step S21.

[0044] The digital signature assignment module 22 acquires the digital signature generated in step S30 from the user terminal 3 and assigns it to the digital document (step S22).

[0045] The validity confirmation module 23 inquires about the validity of the digital certificate acquired in step S21 from the certificate authority server that issued the digital certificate, and acquires validity information (step S23). Specifically, a certificate authority server is contacted to check whether the digital certificate has been revoked, and a response is obtained from the certificate authority server. As an example, the certificate authority server is assumed to be a public personal authentication service operated by a local government. Here, the response from the certificate authority server refers to OCSP response data (Online Certificate Status Protocol). Therefore, the validity information referred to here is synonymous with OCSP response data. OCSP is a communications protocol for obtaining the validity of a digital certificate. The OCSP response data acquired in step S23 is stored and managed in the system server 2 together with key information for identifying the OCSP response data. This key information may be a hash value generated from the OCSP response data or an ID for identifying the electronic document. Additionally, the system server 2 may also store and manage information that can identify the electronic document in step S22 and the value of the electronic signature created in step S30.

[0046] The verification information generation module 24 generates verification information for the digital signature based on the validity information acquired in step S23 (step S24). Specifically, a hash value is created from the OCSP response data as unique verification information and encrypted. At the same time, the fact that the OCSP response data was valid is converted into unique validity information status data. In other words, the verification information created in step S24 includes the hash value created from the OCSP response data and the validity information status. It should be noted that step S24 is performed only if the electronic certificate confirmed in step S23 is valid, and this process is not performed if the electronic certificate is invalid.

[0047] The verification information assignment module 25 assigns the verification information created in step S24 and the key information of the OCSP response data to the electronic document to which the digital signature was assigned in step S30 (step S25), taking care to assign the information in a manner that does not deviate from the file standard of the target electronic document.

[0048] Furthermore, when the agreement of all the parties involved in the electronic document is obtained, the verification information assignment module 25 may assign a document timestamp at the same time as assigning an electronic signature. Specifically, by attaching a document timestamp that certifies the date and time when the existence and content of the electronic document were confirmed in accordance with the long-term signature format, the existence of the entire document is guaranteed until the expiration date of the electronic certificate. At this time, care must be taken to attach the timestamp in a manner that does not deviate from the file specifications of the electronic document in question. An example of a supported long-term signature format is PAdES (PDF Advanced Electronic Signature), which is compatible with PDF documents. This document timestamp may be updated as appropriate after the series of processes in the system 1 is completed, as long as it is within the validity period of the digital certificate.

[0049] Through the above process, independently created verification information that is not restricted by the Enforcement Regulations is assigned to the electronic document from the electronic signature created using the official electronic document and the validity information that is restricted by the Enforcement Regulations. This makes it possible to avoid restrictions on storage, management, etc., and provides an electronic signature system that combines the permanence and security of using an official electronic certificate with the convenience of not being restricted by the Enforcement Regulations when handling electronic documents that have been assigned an electronic signature.

[0050] Next, an overview of the processing executed by the electronic signature system 1 of a second embodiment, which is another embodiment of the present invention, will be described. This embodiment differs from the first embodiment in that it further includes means for verifying the verification information added in the first embodiment.

[0051] In the second embodiment, as in the first embodiment, the system server 2 has a control unit that reads a predetermined program, and in cooperation with the communication unit, realizes a document hash value generation module 20, an electronic certificate acquisition module 21, an electronic signature assignment module 22, a validity confirmation module 23, a verification information creation module 24, and a verification information assignment module 25. The system server 2 differs from the first embodiment in that it further implements a verification module 26 . It is not necessary for the system server 2 to implement all modules at once, and the system 1 may be used with only specific modules implemented.

[0052] The control unit of the user terminal 3 reads a predetermined program, and thereby the control unit cooperates with the communication unit to realize the digital signature module 30.

[0053] An overview of the processing executed by system 1 of a second embodiment, which is another embodiment of the present invention, will be described with reference to Fig. 5. Fig. 5 is a diagram showing a flowchart of the processing executed by system 1 of the second embodiment of the present invention. As shown in Fig. 5, the processing executed by system 1 of the second embodiment is composed of step S30, steps S20 to S25, and step S26, and further includes verification means (step S26) that verifies the verification information assigned by the verification information assignment means. Note that the same functions and configurations as those of the first embodiment are assigned the same reference numerals, and description thereof will be omitted.

[0054] In this embodiment, it is assumed that the digital document has been given a digital signature and verification information through the processing up to step S25. The verification module 26 verifies the verification information added in step S25 (step S26). The verification in step S26 may use only the information added to the electronic document, or may use the OCSP response data stored in the system server 2 in addition to the information added in step S26. Specifically, the fact that verification information is attached to an electronic document determines that the electronic signature is valid. This is because the verification information attached to an electronic document includes the status of validity information, and verification information is attached only when there is evidence that the electronic certificate is valid. Note that it may also be confirmed that this verification information was attached using system 1. In addition to this verification, even stronger verification can be performed by checking whether OCSP response data linked to the electronic document is stored in the system server 2 based on the key information assigned to the electronic document.

[0055] The OCSP response data stored in the system server 2 may be individually verified online as needed.

[0056] Next, an overview of the processing executed by the electronic signature system 1 of a third embodiment, which is another embodiment of the present invention, will be described. This embodiment differs from the first embodiment in that it further includes a warning means for issuing a warning message when the validity checking means executed in the first embodiment determines that the signature is invalid.

[0057] In the third embodiment, as in the first embodiment, the system server 2 has a control unit that reads a predetermined program, and in cooperation with the communication unit, realizes a document hash value generation module 20, an electronic certificate acquisition module 21, an electronic signature assignment module 22, and a validity confirmation module 23. The system server 2 differs from the first embodiment in that it further implements an invalid warning module 27 . It is not necessary for the system server 2 to implement all modules at once, and the system 1 may be used with only specific modules implemented.

[0058] An overview of the processing executed by system 1 of a third embodiment, which is another embodiment of the present invention, will be described with reference to Fig. 6. Fig. 6 is a diagram showing a flowchart of the processing executed by system 1 of the third embodiment of the present invention. As shown in Fig. 6, the processing executed by system 1 of the third embodiment is composed of step S30, steps S20 to S23, and step S27, and further includes warning means (step S27) that issues a warning message when the validity checking means determines that the data is invalid. Note that the same functions and configurations as those of the first embodiment are assigned the same reference numerals, and descriptions thereof will be omitted.

[0059] In this embodiment, it is assumed that the validity of the digital certificate has been inquired of to the certificate authority server that issued the digital certificate in step S23. The invalidity warning module 27 outputs a warning message if the requested digital certificate is determined to be invalid (step S27). The warning message may be displayed on an output unit such as a display, or may be emitted as sound from an output unit such as a speaker. The warning message may also be distributed to other terminals or devices via a communication unit.

[0060] The above-described means and functions are realized by a computer (including a CPU, an information processing device, various terminals, etc.) incorporating and executing a predetermined program. This program may be provided, for example, from the computer via a network or by a cloud service. The program may also be provided in a form recorded on a computer-readable recording medium. In this case, the computer reads the program from the recording medium, transfers it to an internal or external recording device, records it, and executes it. The program may also be pre-recorded on a recording device and provided to the computer from the recording device via a communication line.

[0061] Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Furthermore, the effects described in the embodiments of the present invention are merely a list of the most preferable effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments of the present invention. [Explanation of symbols]

[0062] 1: System 2: System Server 20: Document hash value generation module 21: Electronic certificate acquisition module 22: Electronic signature module 23: Validation module 24: Verification information creation module 25: Verification information assignment module 26: Verification module 27: Invalid warning module 3: User terminal 30: Electronic Signature Module 4: Network

Claims

1. An electronic signature system using a public electronic certificate executed by a system server, a document hash value generating means for generating a document hash value from a previously acquired electronic document; an electronic certificate acquisition means for acquiring an electronic certificate from an information source including a public key held by a user and a private key corresponding to the public key; an electronic signature assigning means for acquiring from a user terminal an electronic signature created by the user terminal using the information source for the document hash value, and assigning the electronic signature to the electronic document; a validity confirmation means for inquiring about the validity of the digital certificate from a certificate authority server that is the issuer of the digital certificate and obtaining confirmed validity information; a verification information generating means for generating verification information for the electronic signature based on the validity information acquired by the validity confirmation means; a verification information assigning means for assigning the verification information to the electronic document to which the electronic signature has been assigned by the electronic signature assigning means; An electronic signature system comprising:

2. 2. The electronic signature system according to claim 1, wherein said validity confirmation means further stores said validity information and key information for identifying said validity information in said system server.

3. 3. The electronic signature system according to claim 2, wherein said electronic signature assigning means further assigns said validity information and said key information to said electronic document.

4. 4. The electronic signature system according to claim 3, wherein the system server further comprises a verification unit for verifying the verification information.

5. 5. The electronic signature system according to claim 4, wherein said verification means further compares said verification information attached to said electronic document with said validity information stored in said system server.

6. 5. The electronic signature system according to claim 4, wherein the validity information stored in the system server can be individually verified as needed.

7. 2. The electronic signature system according to claim 1, wherein said system server further comprises warning means for issuing a warning message when said validity checking means determines that said signature is invalid.

8. An electronic signature method using a public electronic certificate executed by a system server, comprising: generating a document hash value from a previously acquired electronic document; obtaining a digital certificate from a source containing a public key held by a user and a private key corresponding to said public key; a step of acquiring from the user terminal a digital signature created by the user terminal using the information source for the document hash value, and assigning the digital signature to the digital document; inquiring about the validity of the digital certificate from a certificate authority server that is an issuer of the digital certificate, and obtaining confirmed validity information; generating verification information for the electronic signature based on the acquired validity information; adding the verification information to the electronic document to which the digital signature has been added; 1. An electronic signature method comprising:

9. On the computer, generating a document hash value from a previously acquired electronic document; obtaining a digital certificate from a source containing a digital certificate including a public key held by the user and a private key corresponding to the public key; a step of obtaining, from the user terminal, a digital signature created by the user terminal using the information source based on the document hash value, and assigning the digital signature to the digital document; a step of inquiring about the validity of the digital certificate from a certificate authority server that is an issuer of the digital certificate and obtaining confirmed validity information; generating verification information for the electronic signature based on the acquired validity information; adding the verification information to the electronic document to which the digital signature has been added; A computer-readable program for executing the program.

Citation Information

Patent Citations

  • Apparatus and method for lapse confirmation

    JP2003143137A

  • Signature data preparation system, signature data preparation terminal, signature verification terminal and certificate verification server

    JP2006165881A

  • System, management server, information processing method, and program

    JP2018078499A