Information processing method, information processing system, information processing program, and recording medium
The system addresses the challenge of verifying legitimate package openings and inspections by using an electronic tag to encrypt and decrypt information, ensuring secure and transparent management of storage device events through multi-signature verification.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-18
- Publication Date
- 2026-03-31
AI Technical Summary
Existing systems fail to verify the legitimacy of package openings and inspections, allowing unauthorized repackaging and bypassing of inspection results, particularly in luggage management systems.
An information processing method and system that uses an electronic tag with a secret key to encrypt and decrypt information, associating multisig unique information with a storage device to manage opening and closing events, ensuring legitimacy through multi-signature verification.
Facilitates easy management of storage device opening and closing information by authenticating legitimate inspections and repackaging events, providing secure and transparent record-keeping.
Smart Images

Figure 2026055709000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing method, an information processing system, an information processing program, and a recording medium.
Background Art
[0002] A system for managing the transportation or delivery of luggage such as a bag in which an article is stored has been developed. For example, there is a system including a mobile terminal and a server, wherein the mobile terminal includes communication means for performing data transmission and reception with the server, time acquisition means for acquiring the current time, position acquisition means for acquiring the current position, input means for inputting receipt confirmation information indicating that the recipient of the luggage has received the luggage, and control means for performing an electronic signature on electronic slip data including the receipt confirmation information input from the input means, the current time output from the time acquisition means, and the current position output from the position acquisition means when delivering the luggage, and transmitting the electronic slip data with the electronic signature to the server by the communication means; and the server includes communication means for performing data transmission and reception with the mobile terminal, and control means for verifying the authenticity of the electronic slip data with the electronic signature received from the mobile terminal by the communication means (see, for example, Patent Document 1).
[0003] Furthermore, at the boarding area where boarding procedures for an aircraft are carried out, an RFID tag capable of reading and writing information wirelessly is attached to the passenger's airline baggage, and at least sorting information for sorting and transporting the airline baggage to the baggage loading area corresponding to the aircraft to which the airline baggage is to be loaded is written as initial information to the RFID tag, and an inspection device placed at a predetermined position on the transport line for sorting and transporting the airline baggage with the RFID tag attached from the boarding area to one of the baggage loading areas is used to inspect the airline baggage transported on the transport line. There is an air baggage management method characterized by comprising: a second step of visually inspecting the contents of an item and writing the inspection result to the RFID tag of the air baggage, and transporting the air baggage that has passed the inspection to a baggage loading area corresponding to the aircraft on which the air baggage is to be loaded, based on the sorting information written on the RFID tag of the air baggage; and a third step of reading the inspection result written on the RFID tag of the air baggage that has been transported by the transport line at the baggage loading area, and separating the air baggage that has not passed the inspection so that it is not loaded onto the aircraft (see, for example, Patent Document 2). [Prior art documents] [Patent Documents]
[0004] [Patent Document 1] Japanese Patent Publication No. 2010-128535 [Patent Document 2] Japanese Patent Publication No. 2002-362730 [Overview of the project] [Problems that the invention aims to solve]
[0005] However, while the technology described in Patent Document 1 (hereinafter referred to as "Prior Art 1") is a technology that can verify the authenticity of electronic document data, it was difficult to verify the legitimacy of the inspection when opening a package. Furthermore, while the technology described in Patent Document 2 (hereinafter referred to as "Prior Art 2") is a technology that determines a package is free of problems on the condition that the pass information of the inspection result is stored in the RFID, it was extremely difficult to determine the legitimacy of the inspection when opening a package.
[0006] The object of the present invention is to provide an information processing method, an information processing system, an information processing program, and a recording medium that contribute to easily managing information related to the opening and closing of a storage device in a storage device by enabling an information processing device capable of encrypting information using a legitimate private key corresponding to a public key held in a storage device to receive opening and closing information of a storage device equipped with an electronic tag from the electronic tag and store the encrypted information in the storage device. [Means for solving the problem]
[0007] An information processing method according to one aspect of the present invention is an information processing method in an information processing system including an electronic tag that is openable and closable and built into or attached to a storage device for storing articles, and a plurality of information processing devices that can be connected to a storage device using one or more communication means, wherein when the first information processing device receives digital signature unique information from the electronic tag, which is encrypted using the information of a first secret key in the electronic tag, it encrypts the digital signature unique information using the information of a second secret key to generate multisig unique information, associates the unique information previously held in the storage device by the electronic tag, and holds the multisig unique information in the storage device, and the second information processing device receives the first encrypted information from the electronic tag When received from the device, the first encrypted information is decrypted using predetermined first public key information held in the storage device, and when the multisig unique information associated with the information decrypted using the first public key information is held in the storage device, the corresponding third public key information is encrypted using the third private key information held in the storage device and second encrypted information is transmitted to the electronic tag, and when the electronic tag receives first predetermined digital signature information, which is encrypted first predetermined information relating to permission to open in response to the decryption of the second encrypted information using the third public key in the electronic tag, multisig first predetermined information is generated by encrypting the first predetermined digital signature information using the third private key information and stored in the storage device.
[0008] An information processing system according to one aspect of the present invention is a system comprising an electronic tag that is openable and closable and built into or attached to a storage device for storing articles, and a plurality of information processing devices that can be connected to a storage device using one or more communication means, wherein when a first information processing device receives digital signature unique information from the electronic tag, which is encrypted using first secret key information in the electronic tag, it encrypts the digital signature unique information using second secret key information to generate multisig unique information, associates the multisig unique information with the unique information previously held in the storage device by the electronic tag, and holds the multisig unique information in the storage device, and the second information processing device receives first encrypted information from the electronic tag. In this case, the first encrypted information is decrypted using predetermined first public key information held in the storage device, and when the multisig unique information associated with the information decrypted using the first public key information is held in the storage device, the corresponding third public key information is encrypted using the third private key information held in the storage device and second encrypted information is transmitted to the electronic tag, and when the electronic tag receives first predetermined digital signature information, which is encrypted first predetermined information relating to permission to open in response to the decryption of the second encrypted information using the third public key in the electronic tag, multisig first predetermined information is generated by encrypting the first predetermined digital signature information using the third private key information and stored in the storage device.
[0009] An information processing program according to one aspect of the present invention is an information processing system including an electronic tag that is openable and closable and built into or attached to a storage device for storing articles, and a first information processing device and a second information processing device that can be connected to a storage device using one or more communication means, wherein when the electronic tag receives digital signature unique information encrypted using first secret key information for unique information relating to the storage, the computer in the first information processing device executes a control process to encrypt the digital signature unique information using second secret key information to generate multisig unique information, associate the multisig unique information with the unique information previously held in the storage device by the electronic tag, and hold the multisig unique information in the storage device, and when the first encrypted information is received from the electronic tag, the storage The system is configured to have a computer in the second information processing device perform the following control process: decrypt the first encrypted information using predetermined first public key information held in the device; when the multisig unique information associated with the information decrypted using the first public key information is held in the storage device, transmit the corresponding third public key information, encrypted using the third private key information held in the storage device, to the electronic tag; and when the electronic tag receives first predetermined digital signature information, which is encrypted with first predetermined information regarding permission to open in response to the decryption of the second encrypted information using the third public key in the electronic tag, generate multisig first predetermined information by encrypting the first predetermined digital signature information using the third private key information and hold it in the storage device.
[0010] A recording medium according to one aspect of the present invention is an information processing system including an electronic tag that is openable and closable and built into or attached to a storage device for storing articles, and a first information processing device and a second information processing device that can be connected to a storage device using one or more communication means, wherein when the electronic tag receives digital signature unique information encrypted using first secret key information for unique information relating to the storage, the computer in the first information processing device executes a control process to encrypt the digital signature unique information using second secret key information to generate multisig unique information, associate the multisig unique information with the unique information previously held in the storage device by the electronic tag, and hold the multisig unique information in the storage device, and when the first encrypted information is received from the electronic tag, it is held in the storage device. The system records an information processing program that causes a computer in the second information processing device to execute a control process that decrypts the first encrypted information using predetermined first public key information, transmits the corresponding third public key information, encrypted second encrypted information using the third private key information stored in the storage device, to the electronic tag when the electronic tag receives first predetermined digital signature information, which is encrypted with first predetermined information relating to permission to open the second encrypted information in response to the decryption of the second encrypted information using the third public key in the electronic tag, and generates multisig first predetermined information, which is encrypted with the third private key information, and stores it in the storage device. [Effects of the Invention]
[0011] According to the present invention, an information processing device capable of encrypting information using a legitimate private key corresponding to a public key held in a storage device can receive opening and closing information of a storage device equipped with an electronic tag from the electronic tag, encrypt the information, and store it in the storage device, thereby contributing to the easy management of information related to the opening and closing of a storage device in the storage device. [Brief explanation of the drawing]
[0012] [Figure 1] Block diagram showing an example of the functional configuration of an information processing system according to Embodiment 1, as well as an electronic tag, multiple information processing devices, an information processing device, and a storage device. [Figure 2] Block diagram showing another first example of the functional configuration of the information processing system according to Embodiment 1, as well as the electronic tag, multiple information processing devices, information processing device, and storage device. [Figure 3] Block diagram showing another second example of the functional configuration of the information processing system according to Embodiment 1, as well as the electronic tag, multiple information processing devices, information processing device, and storage device. [Figure 4] Block diagram showing a third example of the functional configuration of the information processing system according to Embodiment 1, as well as the electronic tag, multiple information processing devices, information processing device, and storage device. [Figure 5] Block diagram showing an example of the functional configuration of an electronic tag according to Embodiment 1. [Figure 6] Block diagram showing an example of the functional configuration of a storage device including an electronic tag according to Embodiment 1. [Figure 7] Block diagram showing two examples of the functional configuration of the information processing device according to Embodiment 1. [Figure 8] Block diagrams showing two examples of the functional configurations of the information processing device and information processing server according to Embodiment 1. [Figure 9] Sequence diagram showing an example of the procedure for sending and receiving information and processing information between an electronic tag and multiple information processing devices according to Embodiment 1 of the present invention. [Figure 10] Sequence diagram showing an example of the procedure for sending and receiving information and processing information between an electronic tag and a second information processing device according to Embodiment 1 of the present invention. [Figure 11] A flowchart showing an example of the operation flow of the first information processing device in the information processing method according to Embodiment 1. [Figure 12] A flowchart showing an example of the operation flow of the second information processing device in the information processing method according to Embodiment 1. [Figure 13]A diagram showing an example of the hardware configuration of a computer that realizes the functions of each part by a program
Embodiments for Carrying out the Invention
[0013] (The process of arriving at an invention of one aspect according to the present invention)
[0014] As described above, the prior art 1 is a technology that enables the authenticity of electronic slip data to be confirmed by attaching an electronic signature. However, when the package is opened after the goods are packed, no information remains as to whether the opening was made by the person with the rightful authority. Specifically, the inventor of the present invention has found the following problems in this regard.
[0015] For example, when the sender of the goods repackages them for reconfirmation or inspection after the goods are packed, the repackaging is a regular opening because it is an act by the person with the rightful authority and there is no problem. However, no information remains as to the fact that the goods have been repackaged. Also, for example, when inspection of goods such as bags at an airport is carried out and the inspector repackages the bag for re-inspection, the repackaging is a regular opening because it is an act by the person with the rightful authority and there is no problem. However, as described above, no information remains as to the fact that the goods have been repackaged.
[0016] Regarding the above points, the prior art 2 is a technology that determines that there is no problem with the goods on the condition that the pass information of the inspection result is stored in the RFID. However, like the prior art 1, it is not a technology that leaves information as to whether the opening of goods such as bags that can be opened and closed is regular. Furthermore, when the pass information of the inspection result is stored in the RFID, there arises a problem of bypassing the inspection using the information stored in the RFID.
[0017] Therefore, the inventors of the present invention have devised an information processing method, information processing system, information processing program, and recording medium that enable easy management of information regarding the opening and closing of a storage device in a storage device by having an information processing device capable of encrypting information using a legitimate private key corresponding to a public key held in a storage device, receive opening and closing information of a storage device equipped with an electronic tag from the electronic tag, encrypt the information, and store it in the storage device, thereby inventing one aspect of the present invention.
[0018] In this disclosure, the following terms are defined:
[0019] (This service) In this disclosure, the service provided using an information processing server is referred to as the Service. The basic content of the Service may be, for example, a service that allows users who possess a storage device equipped with an electronic tag and capable of opening and closing to easily manage or view information on the opening and closing of the storage device between the time the electronic tag communicates with a first information processing device and the time the electronic tag communicates with a second information processing device, using, for example, a distributed ledger contained in a storage device.
[0020] (user) In this disclosure, the user of the Service is referred to as "User." A User may be the owner or user of a storage device that can be opened and closed, and may also be the person who causes the storage device to store storage information, such as information about the contents of the storage device, in the memory of the electronic tag in this disclosure. A User may be a natural person or a legal person.
[0021] (Administrator) In this disclosure, the person who manages or operates the information processing servers used in the Service is referred to as the Administrator. The Administrator may be, for example, a natural person or legal entity that manages and operates the information processing servers in order to provide the Service to users. The Administrator may consist of one or more persons. The Administrator may also be referred to as the Controlling Administrator.
[0022] (User identification information) User identification information may be information that uniquely identifies each user of this service. Identification information may also be ID information assigned to the user by the administrator. Identification information may be information that can be set by the user in conjunction with the setting of personal information during registration for this service, or at a time separate from the setting of personal information. Identification information may include information that includes at least one piece of personal information, such as address information. Address information may include an email address, an ID for a specific application such as a social networking service or chat, or a telephone number. Identification information only needs to be information that can uniquely identify each user, and the scope of this disclosure is not limited by its specific content. The timing of the issuance of identification information may be arbitrarily set by the administrator.
[0023] The definitions of terms used in this disclosure have been explained above. If any of the defined terms have a special meaning, further definitions may be provided in the description of the embodiments.
[0024] Embodiments of the present invention will be described in detail below with reference to the drawings. In the embodiments, components having the same function are denoted by the same reference numerals, and redundant descriptions may be omitted. The embodiments described below represent specific examples of the present disclosure. The configurations, processes, or sequences of processes shown in the embodiments are examples and do not limit the scope of the present disclosure.
[0025] (Embodiment 1) The configuration of the information processing system 1 according to this embodiment will be described with reference to Figure 1 and other figures. Figure 1 is a block diagram showing an example of the functional configuration of the information processing system according to Embodiment 1, as well as an electronic tag, a plurality of information processing devices, an information processing device, and a storage device. Figures 2 to 4 are block diagrams showing other first to third examples of the functional configuration of the information processing system according to Embodiment 1, as well as an electronic tag, a plurality of information processing devices, an information processing device, and a storage device.
[0026] In Figure 1, the information processing system 1 may include an electronic tag 100 built into or attached to the storage device 10, a plurality of information processing devices 200, an information processing device 300, a storage device 400, and a communication network 500.
[0027] The storage device 10 may be openable and closable and may be a device for storing articles. The opening and closing of the storage device may be done by, for example, an electronic or physical lock, or by sealing using glue or the like. The storage device may be a storage device that can be used for packaging, packing, wrapping, storing, or other storage. Specifically, it may be a suitcase, bag, container, envelope, etc. The storage device 10 may have an electronic tag 100 built in or attached to it, as described later. The electronic tag 100 may be detachable from the storage device 10.
[0028] The communication network 500 may be a network composed of telecommunication lines. The communication network 500 may be a wired communication network or a wireless communication network. The communication network 500 may be, for example, the Internet, a dedicated line, a LAN (Local Area Network), etc.
[0029] In Figure 1, the information processing device 300 and the storage device 400 may be connected via the communication network 500. Also, as shown in Figure 1, the information processing device 200 does not need to have a communication function that connects directly to the communication network 500.
[0030] For example, the information processing device 200 may send and receive information to and from the communication network 500 via any communication terminal shown in Figure 1. The communication terminal may have the function of sending and receiving at least one of information and signals between it and the information processing device 200, as well as the function of connecting to the communication network. The exchange of information, etc., between the information processing device 200 and the information processing device 300 and the storage device 400 may be carried out via any communication terminal and the communication network 500. In such a case, the information processing device 200 may be a storage device such as a USB memory, as will be described later.
[0031] On the other hand, the information processing device 200 may have a communication function that connects directly to the communication network 500, as shown in Figure 2. In this case, the information processing device 200 may be a terminal device with communication functions, such as a smartphone, as will be described later.
[0032] In Figures 1 and 2, the electronic tag 100 does not necessarily have the function of directly connecting to the communication network 500. For example, the electronic tag 100 may send and receive information to and from the communication network 500 via the information processing device 200 in Figures 1 and 2. The exchange of information between the electronic tag 100 and the information processing device 200 may be carried out via, for example, a wired connection or a wireless connection such as short-range wireless communication. The exchange of information between the electronic tag 100 and the information processing device 300 and the storage device 400 may be carried out via the information processing device 200, or via the information processing device 200 and any communication terminal. In such cases, the information processing device may be, for example, an electronic tag, as will be described later.
[0033] On the other hand, the electronic tag 100 may have a communication function that connects directly to the communication network 500, as shown in Figures 3 and 4. In this case, the electronic tag 100 may be a terminal device with communication functions, such as a smartphone, as will be described later.
[0034] As explained with reference to Figures 1 to 4, in the information processing system 1 of this disclosure, the electronic tag 100, information processing device 200, information processing device 300, and storage device 400 only need to be able to exchange and receive at least one of information and signals with each other, and the connection configuration between the components of the information processing system 1 may be arbitrarily set by an administrator or the like, and the scope of this disclosure is not limited by the specific content of the connection configuration.
[0035] In this disclosure, "transmission" and "delivery" may be interchangeable, "reception" and "acceptance" may be interchangeable, and "sending and receiving" and "giving and receiving" may be interchangeable.
[0036] Figure 5 is a block diagram showing an example of the functional configuration of an information processing device according to Embodiment 1. In Figure 5, the electronic tag 100 may have a communication unit 101, a memory unit 102, and a control unit 103.
[0037] The communication unit 101 may have the function of being able to send and receive information between itself and multiple information processing devices 200 and storage devices 400 using one or more communication means. As shown in Figures 1 to 4, one or more communication means may be at least one of the following, or a combination thereof: a communication network 500, wired communication, wireless communication such as short-range wireless communication, LAN, etc. The scope of this disclosure is not limited by specific specifications such as the form and standards of the network connecting the communication unit 101 and the information processing devices 200 and storage devices 400.
[0038] The communication unit 101 may have the function of exchanging, for example, digital signature unique information in which unique information has been encrypted, predetermined encrypted information encrypted using a private key, etc., with the information processing device 200, as will be described later. The communication unit 101 may also have the function of exchanging, for example, unique information, information on one or more public keys, predetermined encrypted information, various application software, and various programs, as will be described later. The content of the above-mentioned information that the communication unit 101 exchanges with any communication terminal, information processing device 200, information processing device 300, and storage device 400 is an example, and the scope of this disclosure is not limited by its specific content.
[0039] The communication unit 101 may be, for example, a communication module including an antenna for wireless communication, or a communication module for wired communication. Furthermore, the communication unit 101 may be a connector for sending and receiving information, or a connection terminal.
[0040] The memory unit 102 may have the function of being able to store information received from the communication unit 101. The memory unit 102 may be able to store information received from the communication unit 101, as well as predetermined information that is stored in advance during the manufacturing stage of the electronic tag 100. For example, the memory unit 102 may store information for a secret key, which will be described later, in advance.
[0041] The memory unit 102 may have a function to temporarily hold various types of information, a function to non-temporarily hold various types of information unless an information deletion process is performed, or a combination of these functions. In other words, the memory unit 102 may be volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory.
[0042] The control unit 103 may have functions for performing various controls on the electronic tag 100. The control unit 103 may have, for example, a function for storing information received by the communication unit 101 in the memory unit 102. The control unit 103 may have, for example, functions for encrypting information, decrypting information, and executing predetermined calculation processes based on instructions from various applications or from the information processing device 300 or information processing device 200.
[0043] The control unit 103 may be, for example, a control circuitry that controls each part by electrical signals. Specifically, the control unit 103 may be composed of an integrated circuit such as an FPGA (Field Programmable Gate Array). The control unit 103 may be implemented by, for example, a CPU (Central Processing Unit) or an MPU (Micro Processing Unit).
[0044] In the above description, the electronic tag 100 was described as having a communication unit 101, a memory unit 102, and a control unit 103, but for example, it may also have an input unit and a display medium (not shown).
[0045] An input unit not shown may have the function of selecting display content on an unshown display medium, and the function of inputting or editing characters. An input unit not shown may also have the function of accepting user input. An input unit not shown may be at least one of the following: a keyboard, a mouse, hardware buttons, touch operation using a touch panel, a stylus pen using a touch panel, input based on user gaze detection, and voice input. The keyboard may be an externally connected physical keyboard or a software keyboard on a touch panel.
[0046] The display medium, which is not shown, may be, for example, a two-dimensional display, or a three-dimensional display in virtual reality, mixed reality, etc. The two-dimensional display may be a liquid crystal display, an organic EL display, etc. The type of display is not limited to the scope of this disclosure. In such a case, the control unit 103 may have a function to receive user input from an input unit (not shown) and display it on the display medium (not shown).
[0047] The control unit 103 may, using the above functions, encrypt the unique information relating to storage held in the memory unit 102 using the information of the first secret key, as will be described in detail later. The information of the first secret key may, for example, be held in the memory unit 102 in advance during manufacturing, or it may be received directly or indirectly from the information processing device 300 and held in the memory unit 102. Alternatively, as will be described later, the information of the first secret key may be extracted as information unique to the electronic tag 100. Furthermore, the control unit 103 may have a function to decrypt the second encrypted information received from the information processing device 200 using the information of the third public key held in the storage device 400 and generate predetermined information indicating permission to open the package, as will be described in detail later.
[0048] Figure 6 is a block diagram showing an example of the functional configuration of a storage device including an electronic tag according to Embodiment 1. In Figure 6, the storage device 10 may include an electronic tag 100, a storage area, an opening / closing mechanism, a locking mechanism 110, another opening / closing mechanism, and another storage area.
[0049] The storage area may be a three-dimensional spatial area for storing physical items. The opening and closing mechanism may be a mechanism that allows the storage device to be opened and closed in order to store physical items in the storage area. The locking mechanism 110 may be a mechanism that allows the opening and closing of the storage device to be locked electronically or physically. The structure for realizing the locking mechanism 110 is known technology, so a detailed explanation is omitted.
[0050] As will be described later, the locking mechanism 110 may also be capable of receiving information or signals from the communication unit 101 and unlocking based on the received signal. Furthermore, the locking mechanism 110 may be capable of sending and receiving information or signals to and from the communication unit 101. For example, when the locking mechanism 110 detects unlocking, it may send information or a signal to the communication unit 101 indicating that it has been detected.
[0051] Figure 7 is a block diagram showing two examples of the functional configuration of an information processing device according to Embodiment 1. In Figures 7(a) and 7(b), the information processing device 200 may include a communication unit 201, a memory unit 202, and a control unit 203.
[0052] In Figures 7(a) and 7(b), the communication unit 201 may have the function of being connectable to an electronic tag 100, which is openable and closable and built into or attached to a storage device for storing articles, and a storage device 400, using one or more communication means.
[0053] As described above, in the case shown in Figures 1 and 3, for example, the communication unit 201 may have the function of exchanging information or signals with the electronic tag 100 and any communication terminal using one or more communication means such as wired communication, short-range wireless communication, or wired or wireless LAN. The communication unit 201 may be, for example, a connector for exchanging information, or a connection terminal. In such a case, the information processing device 200 may be, for example, a storage device such as a USB memory.
[0054] On the other hand, in the case shown in Figures 2 and 4, for example, the communication unit 201 may have the function of exchanging information or signals with the electronic tag 100 and the storage device 400 using one or more communication means, such as wired communication, short-range wireless communication, wired or wireless LAN, and a communication network. The communication unit 201 may also be a communication module including an antenna for wireless communication, or a communication module for wired communication. In such a case, the information processing device 200 may be a device such as a smartphone, tablet terminal, notebook computer, desktop computer, wearable terminal, or dedicated terminal.
[0055] In this disclosure, the information processing device 200 may have the configuration shown in Figure 7(a) or the configuration shown in Figure 7(b). Furthermore, some of the multiple information processing devices 200 may have the configuration shown in Figure 7(a), while the others have the configuration shown in Figure 7(b).
[0056] In Figures 7(a) and 7(b), the memory 202 may, as will be described later, hold information about a unique private key assigned to or distributed to the information processing device 200. The memory 202 may also hold predetermined information received from the electronic tag 100 and public key information received from the storage device 400, as will be described later. Similar to the memory 102, the memory 202 may have the function of temporarily holding various information, the function of non-temporarily holding various information unless an information deletion process is performed, or a combination of these functions.
[0057] In Figures 7(a) and 7(b), the control unit 203 may have functions for performing various controls on the information processing device 200. The control unit 203 may have, for example, a function for storing information received by the communication unit 201 in the memory unit 202. The control unit 203 may have, for example, functions for encrypting information, decrypting information, and executing predetermined arithmetic processing based on instructions from various applications or the information processing server 30 or electronic tag 100.
[0058] Specifically, for example, the control unit 203 may have a first function in which, when it receives digital signature unique information from the electronic tag 100, which has been encrypted using the first secret key information in the electronic tag 100, it encrypts the digital signature unique information using the second secret key information to generate multisig unique information, associates it with unique information previously held in the storage device 400 by the electronic tag 100, and causes the storage device 400 to hold the multisig unique information.
[0059] Furthermore, the control unit 203 may have a second function in which, upon receiving first encrypted information from the electronic tag 100, it decrypts the first encrypted information using predetermined first public key information held in the storage device 400, and when multisig unique information associated with the information decrypted using the first public key information is held in the storage device 400, it transmits second encrypted information encrypted using third private key information held in the storage device 400, corresponding third public key information, to the electronic tag 100, and when it receives first predetermined digital signature information encrypted with first predetermined information relating to permission to open in response to the decryption of the second encrypted information using the third public key in the electronic tag 100, it generates multisig first predetermined information encrypted with third private key information, and stores it in the storage device 400. In this disclosure, the control unit 203 has at least one of the first function and the second function.
[0060] The control unit 203 may be, for example, a control circuit that controls each part by electrical signals. Specifically, the control unit 203 may be configured by an integrated circuit such as an FPGA. The control unit 203 may also be implemented by, for example, a CPU or MPU.
[0061] As shown in Figure 7(b), the information processing device 200 may further include an input unit 204 and a display medium 205. The input unit 204 may have a function for selecting display content on the display medium 205 and a function for inputting or editing characters. The input unit 204 may also have a function for receiving input from the user. The input unit 204 may be at least one of the following: a keyboard, a mouse, hardware buttons, touch operation using a touch panel, a stylus pen using a touch panel, input based on user gaze detection, and voice input. The keyboard may be an externally connected physical keyboard or a software keyboard on a touch panel.
[0062] The display medium 205 may be, for example, a two-dimensional display, or a three-dimensional display in virtual reality, mixed reality, etc. The two-dimensional display may be a liquid crystal display, an organic EL display, etc. The type of display is not limited to the scope of this disclosure. In such a case, the control unit 203 may have a function to receive user input from the input unit 204 and display it on the display medium 205.
[0063] Furthermore, each element included in the information processing device 200 may be connected via wired or wireless connection to some or all of the other elements, based on the design specifications. In addition, although the elements such as the display medium 205 provided by the information processing device 200 have been described as being built into the information processing device 200 in the above description, they may also be attached to the information processing device 200 as external components. Such components may be detachable.
[0064] Figure 8 is a block diagram showing two examples of the functional configurations of the information processing device 300 and the information processing server 30 according to Embodiment 1. In Figure 8(a), the information processing server 30 is described as not including at least a part of the storage device 400, but as shown in Figure 8(b), the information processing server 30 may be configured to include a part of the storage device 400. In this disclosure, the information processing server 30 is included in both the system configuration shown in Figure 8(a) and the system configuration shown in Figure 8(b). In other words, whether or not the information processing server 30 includes at least a part of the storage device 400 does not limit the scope of this disclosure.
[0065] In Figure 8, the information processing device 300 may have a communication unit 301 and a control unit 302. The communication unit 301 and the control unit 302 are connected to each other by wire or wireless connection. The information processing device 300 may be a computer or recording medium having the function of storing in the storage device 400 information information of a first public key corresponding to the information of a first secret key unique to the first information processing device 200a, and information of a second public key corresponding to the information of a second secret key unique to the second information processing device 200b. The information processing device 300 may also have the function of receiving information directly or indirectly from the electronic tag 100 and the information processing device 200, and storing the received information in the storage device 400.
[0066] Furthermore, at least one of the electronic tag 100 and the information processing device 200 may have the function of storing information in the storage device 400 without going through the information processing device 300. The information processing device 300 may be implemented, for example, by a combination of a general-purpose computer and software that performs the operations described in this embodiment.
[0067] The communication unit 301 may have the function of sending and receiving information to, for example, a communication network 500 in order to store information in the electronic tag 100, the information processing device 200, and the storage device 400, or to receive information. The communication unit 301 may be, for example, a communication module including an antenna for wireless communication, or a communication module for wired communication.
[0068] The control unit 302 may be a control circuit that controls each part by electrical signals. Specifically, the control unit 203 may be configured by an integrated circuit such as an FPGA. The control unit 103 may be implemented by a CPU or MPU, for example.
[0069] The storage device 400 may have the function of storing public key information corresponding to the secret key information held in the electronic tag 100 and the information processing device 200, predetermined information encrypted in the electronic tag 100 and the device, and information indicating anomalies detected in the storage device, as described later. In this disclosure, storage may be replaced with storage as appropriate.
[0070] The storage device 400 may also store various application software. This application software may, for example, allow the service to be run standalone on the electronic tag 100 or the information processing device 200. The application software may also be, for example, source code such as HTML, CSS, or JavaScript (registered trademark) that can be loaded and run in a web browser installed on a client PC.
[0071] The information held by the storage device 400 may be held, for example, by a database. The structure or model of the database in this disclosure may be arbitrarily configured by the administrator. The structure or model of one or more databases in this disclosure may be a relational database that manages data by predetermined tables, or it may be a non-relational database (NoSQL: Not only SQL). The information processing system 1 may include multiple storage devices 400, and at least one storage device 400a may be included in the information processing server 30. In such a case, the database may be a distributed ledger.
[0072] The configuration examples of the information processing system 1, electronic tag 100, information processing device 200, information processing device 300, and storage device 400 according to this embodiment have been described above with reference to Figures 1 to 8.
[0073] In the embodiments of the present invention, control by various programs provided from the information processing server 30 to the information processing device 200, and control by the information processing server 30, may be referred to as control by the information processing server 30, etc. Even when simply referred to as control by the information processing server 30, it may be interpreted as having the same meaning as control by the information processing server 30, etc.
[0074] In addition, there may be multiple electronic tags 100, information processing devices 200, and storage devices 400 in the information processing system 1. In such cases, multiple functions may be distributed across multiple servers and multiple devices.
[0075] The information processing system 1 according to this embodiment, as shown in the above configuration example, allows the information processing device 200, which can encrypt information using a legitimate private key corresponding to a public key held in the storage device 400, to receive opening and closing information of a storage device equipped with an electronic tag 100 from the electronic tag 100 and store the encrypted information in the storage device 400, thereby contributing to the easy management of information related to the opening and closing of a storage device in the storage device 400.
[0076] Specifically, in this disclosure, if a provider of the Service, such as an administrator, stores public key information corresponding to a private key unique to each of the electronic tag 100 and multiple information processing devices 200 in a storage device 400 using an information processing server 30, then the encrypted information that cannot be decrypted using the public key information stored in the storage device 400 is information encrypted using non-legitimate encryption key information due to reasons such as not being authorized by the administrator, not being distributed by the administrator, or not being associated with each device by the administrator. In this disclosure, the public key information stored in the storage device 400 may be managed or restricted by the administrator, and may be referred to as the private key corresponding to the public key stored in the storage device 400, or the legitimate private key.
[0077] Furthermore, in order to enable easy management of information regarding the opening and closing of the storage device 10 in the storage device 400, the information processing device 200, which can encrypt information using a legitimate private key corresponding to a public key held in the storage device 400, receives opening and closing information of the storage device 10 equipped with an electronic tag 100 from the electronic tag 100 and stores the encrypted information in the storage device 400, the information processing system 1 in this disclosure performs a first inspection and a second inspection.
[0078] The first inspection may involve the first inspector physically or electrically verifying the contents of the storage device 10 and affixing a digital signature to the unique storage information described later using the electronic tag 100 and the first information processing device 200a operated by the first inspector, in order to record the verification in the storage device 400. The second inspection may involve the second inspector using the second information processing device 200b to verify that the first inspection has been performed on the contents of the storage device 10 equipped with the electronic tag 100, and that the second information processing device 200b is a legitimate device associated with a legitimate private key and public key. The inspector operating the information processing device 200 associated with a legitimate private key may be referred to as a legitimate inspector.
[0079] In such cases, as evidence that the first inspection has been performed, multi-signature specific information, as described later, may be stored in the storage device 400 and made accessible to users, administrators, and third parties. As evidence that the second inspection has been performed, multi-signature first predetermined information, as described later, may be stored in the storage device 400 and made accessible to users, administrators, and third parties. The information processing method in this disclosure achieves the effects unique to the present invention by authenticating that the first and second inspections are performed by a legitimate electronic tag 100 and information processing device 200, and by storing evidence of their performance in the storage device 400.
[0080] Specifically, a legitimate first inspector who inspects the contents of the contents of the storage container 10, such as the items contained within, can record or manage multisig-specific information, which has been encrypted using legitimate secret key information, in the storage device 400 in response to the first inspection, thereby recording or managing multisig-specific information in the storage device 400 that indicates the contents were inspected by a legitimate first inspector. Then, after the first inspector confirms or inspects the contents of the storage container 10, a second inspector who operates a second information processing device 200b, to which legitimate secret key information is associated, can perform the above-described second inspection using the second information processing device 200b when opening the storage container 10 equipped with an electronic tag 100. In response to the second inspection, the second inspector can record or manage multisig-specific information, which has been encrypted using legitimate secret key information, in the storage device 400, thereby recording or managing multisig-specific information, which has been encrypted using legitimate secret key information, in response to the opening of the storage container 10, thereby recording or managing multisig-specific information, which indicates the contents were inspected by a legitimate second inspector. In particular, since the storage device 400 stores information indicating permission to open the storage device, which has been multi-signatured in response to the second inspection being performed, the user who possesses the storage device 10 can check the contents of the storage device and confirm that permission to open it has been granted by referring to the information stored in the storage device 400.
[0081] The above describes the basic services provided by the information processing method and information processing system described in this disclosure.
[0082] Figure 9 is a sequence diagram showing an example of the procedure for sending and receiving information and processing information between the electronic tag 100 according to Embodiment 1 of the present invention and a plurality of information processing devices 200. The basic operation procedure of the electronic tag 100 according to this embodiment will be described below with reference to Figure 9.
[0083] In Figure 9, the electronic tag 100 may receive storage information from a communication terminal (step S901).
[0084] The storage information may include at least one of the following: information about one or more items stored in the storage device 10, information about the time the storage device 10 was closed, and identification information unique to the user operating the third information processing device 200c. The user may, for example, operate a communication terminal such as a smartphone to display an unillustrated storage information setting page in this service on a display medium 205, and set the storage information on that storage information setting page. The communication terminal may be, for example, the third information processing device 200c. Hereinafter, the communication terminal will be described as the third information processing device 200c as an example.
[0085] The storage information setting page, which is not illustrated in this service, may be, for example, one of one or more pages on the website or application software related to this service. The user may use the input unit 204 to access the website on the information processing device 200c or to launch the application software and display the storage information setting page on the display medium 205. The user may set the storage information on the storage information setting page displayed on the display medium 205 and use the communication unit 201 to transmit the set storage information to the electronic tag 100.
[0086] The specified application software installed on the third information processing device 200c may be standalone application software that does not use a web browser. This application software may be installed on the information processing device 200c via a communication network from a specified application distribution system, and the collection information setting function related to this service may be performed when the application software is launched on the information processing device 200c. The application software may also be an information processing program.
[0087] The information of one or more items stored in the storage device 10 may be, for example, information about clothing, documents, etc. The information about the items may be text information that can be arbitrarily set using the input unit 204, or it may be information selected from checkboxes or pull-down menus.
[0088] The time information for when the storage device is closed may, for example, be set by the user on the storage information setting page. Alternatively, a predetermined program on the website or application software related to this service may detect the time information for which the storage information was set, and set that time information as the time information. In addition, the time information may be handled by, for example, an electronic tag 100 that receives the storage information, which detects the reception time, sets the detected time information as the time information, and adds that time information to the package information received from the information processing device 200c, etc., and treats it as storage information.
[0089] User-specific identification information, as defined above, is ID information that uniquely identifies each user of this service, and may, for example, be information assigned to each user by the administrator. Identification information may also be unique information that can be set by the user, for example, in conjunction with the setting of user information, or at a time separate from the setting of user information. Furthermore, identification information may be unique to each user, for example, including at least one piece of information set as personal information included in user information. In such cases, that at least one piece of information may be address information, for example. Identification information only needs to be unique information that can uniquely identify each user, and its specific content is not limited to the scope of this disclosure.
[0090] Furthermore, the contents of the storage information set on the storage information setting page and stored in the electronic tag 100 may be arbitrarily set by the administrator. For example, the contents of the storage information may be at least one of the following: user identification information, item information, and information on the time the storage device was closed, as described above. The electronic tag 100, which has received the storage information from the third information processing device 200c, may store the storage information in the memory unit 102.
[0091] Returning to Figure 9, the electronic tag 100 may encrypt its unique information using the information of the first secret key (step S902). The unique information encrypted using the information of the first secret key may be called digital signature unique information.
[0092] The unique information may be, for example, the storage information itself received from the third information processing device 200c. Alternatively, the unique information may be numerical information obtained by the control unit 103 of the electronic tag 100 by performing a predetermined calculation on the storage information. The predetermined calculation is an operation using a hash function, and the numerical information may be a hash value based on the storage information. In other words, the unique information may be information based on storage information that is at least one of the following: information about one or more articles stored in the storage device, information about the time the storage device was closed, and identification information unique to the user operating the communication terminal. Hereafter, the unique information will be described assuming that it is the hash value of the storage information.
[0093] The information of the first private key may be, for example, information of a private key distributed by the administrator to the electronic tag 100 via one or more means of communication. Alternatively, the information of the first private key may be stored in the memory section 102 of the electronic tag 100 at the time of manufacture. That is, the information of the first private key may be associated with the electronic tag 100 and be unique to the electronic tag 100. Furthermore, the information of the first private key may be information extracted by the electronic tag 100, as will be described later. The information of the public key corresponding to the first private key may be stored in the storage device 400 in advance by the administrator.
[0094] In this disclosure, the information of the public key corresponding to the unique private key associated with the electronic tag 100 and the information processing device 200 may be information held in the storage device 400 by the provider of this service, such as an administrator. In this disclosure, the information of the public key corresponding to the private key is information that can decrypt information encrypted using the said private key information. Each of the multiple pieces of public key information held in the storage device 400 may be information held in the storage device 400 only by the provider of this service. In this disclosure, the public key held in the storage device 400 by the provider of this service may be the official public key information for this service.
[0095] In other words, the electronic tag 100 and the information processing device 200, to which the information of the private key corresponding to the public key held in the storage device 400 is associated, are authorized devices or equipment certified by the service provider. Furthermore, the operator of the electronic tag 100 may be referred to as an authorized user, and the operator of the information processing device 200 may be referred to as an authorized inspector.
[0096] Furthermore, the electronic tag 100 may, at a predetermined timing prior to step S905 described later, have its unique information stored in the storage device 400 via one or more communication means.
[0097] For example, if the electronic tag 100 has a communication function, the electronic tag 100 itself may store unique information in the storage device 400. Alternatively, for example, the unique information stored in the memory unit 102 of the electronic tag 100 may be output to the communication network 500 via any communication terminal that can connect to the communication network 500, and the information processing server 30 may store the unique information in the storage device 400. Alternatively, for example, the information processing device 200a may output encrypted unique information to the communication network 500, and the information processing server 30 may store it in the storage device 400. The above methods for storing unique information generated in the electronic tag 100 in the storage device 400 are examples, and the scope of this disclosure is not limited by the specific details thereof.
[0098] Returning to Figure 9, the electronic tag 100 may transmit digital signature-specific information encrypted using the first secret key information to the first information processing device 200a (step S903). The first information processing device 200a is a device operated by the first inspector for the first inspection, and may be a terminal such as a smartphone or tablet, or a USB memory stick.
[0099] As described above, the first inspector, after confirming the contents of the storage container, may operate the first information processing device 200a to have the storage device 400 store multi-signature unique information to prove that the first inspection was properly conducted, and have the communication unit 201 receive the digital signature unique information from the electronic tag 100. In such a case, the electronic tag 100 may transmit the digital signature unique information to the first information processing device 200a as a trigger, for example, by receiving a predetermined signal from the first information processing device 200a requesting the transmission of the digital signature unique information, or by establishing a wired or wireless connection with the first information processing device 200a via the communication unit 101. In this disclosure, the triggers for the electronic tag 100 to transmit the digital signature unique information to the first information processing device 200a are not limited to those exemplified above.
[0100] The first information processing device 200a may also store digital signature unique information in the memory unit 202. For example, the first information processing device 200a may use the communication unit 201 to receive digital signature unique information, which has been encrypted, and store it in the non-volatile memory or volatile memory of the memory unit 202.
[0101] Returning to Figure 9, the first information processing device 200a may encrypt the digital signature unique information using the information of the second secret key (step S904). The information encrypted using the information of the second secret key may be referred to in this disclosure as multisig unique information. As described above, the first information processing device 200a may generate multisig unique information as information indicating that a legitimate first check has been performed, and store the multisig unique information in the storage device 400 (step S905).
[0102] In such a case, the first information processing device 200a may store multi-signature unique information in the storage device 400 by associating it with unique information previously stored in the storage device 400 by the electronic tag 100. This helps the second inspector determine whether the electronic tag 100 is genuine when authenticating the electronic tag 100 in the second inspection, as will be described later.
[0103] The multi-signature unique information is information that has been encrypted in the electronic tag 100, with the storage information set by the user, such as the owner of the storage device 10, and further encrypted using the information of the second secret key that was distributed by the administrator to the first information processing device 200a operated by the first inspector. Therefore, the fact that the multi-signature unique information is stored in the storage device 400 serves as evidence that a legitimate inspection has been performed.
[0104] If the unique information stored in the storage device 400 is storage information stored on the electronic tag 100 by the owner of the storage device or the user who shipped the storage device, or information generated based on said storage information, then it is impossible for a third party to generate the multi-signature unique information at the time it is confirmed by the first inspector. Therefore, the multi-signature unique information stored in the storage device 400 is unique information generated in response to operations by the user and the first inspector.
[0105] In such cases, the multisig-specific information may be recorded, for example, in a distributed ledger on the storage device 400. This allows the content and the fact that an inspection was performed to be confirmed by, for example, a user or other inspector decrypting the multisig-specific information recorded in the distributed ledger.
[0106] Furthermore, the information of the first secret key only needs to be used for encryption processing in the first information processing device 200a, and whether or not the information of the first secret key is stored in the memory unit 202 does not limit the scope of this disclosure. The information of the first secret key is not, for example, exchanged via the communication network 500, and the first information processing device 200a may receive the information of the first secret key held in any terminal device via the communication unit 201.
[0107] In this disclosure, the secret key information may be generated based on a Physical Unclonable Function (PUF). Specifically, for example, the secret key information associated with the electronic tag 100 and the information processing device 200 may be extracted or generated based on minute variations in the manufacturing of the devices, and Hardware Root of Trust (HRoT) may be implemented in the electronic tag 100 and the information processing device 200. In such a case, since encryption key information unique to the electronic tag 100 and other devices is generated in response to power being turned on in the electronic tag 100 and the information processing device 200, the secret key information does not need to be stored in memory units 102 and 202.
[0108] This prevents the leakage of encryption key information. More specifically, by managing or protecting encryption key information at the hardware level using HRoT, side-channel attacks such as power analysis attacks that infer secret information from power consumption patterns, electromagnetic analysis attacks that infer secret information from electromagnetic waves emitted by devices such as the information processing device 200 while they are operating, and time analysis attacks that infer internal operation from processing time can be prevented.
[0109] In the following explanation, for the sake of clarity, we will assume that the encryption key information is distributed by the administrator and stored in memory units 102 and 202. However, as mentioned above, the encryption key information may also be generated or extracted based on the PUF.
[0110] Returning to Figure 9, the electronic tag 100 may, for example, transmit the first encrypted information to the second information processing device 200b as information processing in the second inspection described above (step S906).
[0111] Specifically, for example, when the storage container 10 is delivered or transported after multi-signature unique information is stored in the storage device 400 following a first inspection of the contents of the storage container 10, and a second inspector performs a second inspection by operating the second information processing device 200b, the second information processing device 200b may transmit a signal or information to the electronic tag 100 requesting it to transmit the first encrypted information. The electronic tag 100 may then transmit the first encrypted information to the second information processing device 200b upon receiving the signal or information relating to the request. The electronic tag 100 may also transmit the first encrypted information in response to, for example, being connected to the second information processing device 200b by wire or wireless connection. In other words, the scope of this disclosure is not limited by the specific content of the trigger that causes the electronic tag 100 to transmit the first encrypted information to the second information processing device 200b.
[0112] Furthermore, the second inspection may be a mutual authentication process between the electronic tag 100 and the second information processing device 200b using a legitimate public key and private key, which is performed in advance to issue information that authorizes the electronic tag 100 to open the storage device 10 and to store it in the storage device 400, as described above.
[0113] The first encrypted information transmitted from the electronic tag 100 may be encrypted information obtained by encrypting predetermined information in the electronic tag 100 using the information of a legitimate first secret key whose corresponding public key information is pre-stored in the storage device 400. The predetermined information may be the aforementioned unique information generated in the electronic tag 100. In other words, the first encrypted information may be digital signature unique information.
[0114] The electronic tag 100 may simultaneously or separately transmit to the second information processing device 200b the digital signature unique information and predetermined key management information for directly or indirectly identifying the first public key corresponding to the first private key that encrypts the digital signature unique information. For example, key management information, which is a management number that identifies the first private key or first public key previously assigned by an administrator, may be attached to the digital signature unique information and transmitted to the second information processing device 200b. Alternatively, for example, the electronic tag 100 may generate key management information, which is predetermined information for identifying the first public key held in the storage device 400, and transmit it to the second information processing device 200b. The above content of the key management information transmitted from the electronic tag 100 to the second information processing device 200b is just an example.
[0115] When observed from the second information processing device 200b, it is not possible to determine that the first encrypted information transmitted from the electronic tag 100 is digital signature unique information until it is decrypted using the first public key information. Furthermore, as will be described later, it is only by confirming that the multisig unique information associated with the decrypted unique information is held in the storage device 400 that it can be determined that the electronic tag 100 that transmitted the first encrypted information is the device associated with the legitimate private key information.
[0116] Furthermore, in the mutual authentication between the electronic tag 100 and the second information processing device 200b in the second inspection, the use of the first cryptographic information, which is digital signature unique information, prevents attempts to circumvent the legitimate first inspection. Specifically, for example, if a malicious third party were to obtain the unique information held in the storage device 400 and attempt to use the obtained unique information to perform information processing in the second inspection, the malicious third party would not possess the legitimate encryption key, making it impossible to have the second information processing device 200b certify that the first inspection was performed. On the other hand, when digital signature unique information is used in the mutual authentication between the electronic tag 100 and the second information processing device 200b in the second inspection, the electronic tags that can encrypt information using the encryption key information corresponding to the public key held in the storage device 400 are limited to legitimate electronic tags. Therefore, it is possible to prevent a malicious third party from obtaining the unique information held in the storage device 400, storing it in an arbitrary device, and attempting to circumvent the legitimate first inspection.
[0117] Returning to Figure 9, if the second information processing device 200b receives the first encrypted information from the electronic tag 100, it may decrypt the first encrypted information using predetermined first public key information held in the storage device 400 (step S907). As described above, the predetermined first public key information is information received by the second information processing device 200b from the storage device 400 based on the key management information received from the electronic tag 100.
[0118] As described above, when the second information processing device 200b receives encrypted information from one of the multiple electronic tags included in the information processing system 1, it is extremely difficult to uniquely identify the public key information corresponding to the private key information used to encrypt the encrypted information from among the multiple public keys held in the storage device 400. Therefore, key management information is transmitted from the electronic tag 100 to the second information processing device 200b. Furthermore, at the stage when the second information processing device 200b receives the first encrypted information from the electronic tag, it is unclear whether the electronic tag is installed in a storage device owned by a legitimate user, or whether the electronic tag illegally obtains a third party's unique information held in the storage device 400 and stores information encrypted using unauthorized private key information. Therefore, by having the second information processing device 200b receive key management information from the electronic tag along with the encrypted information to identify the public key information corresponding to the private key information used for encryption, it is possible to easily determine whether the electronic tag is installed in a storage device owned by a legitimate user.
[0119] In other words, if the electronic tag that transmitted the first cryptographic information and key management information to the second information processing device 200b is the legitimate electronic tag 100, then consequently, the predetermined first public key information may be information held in the storage device 400, used to encrypt the aforementioned unique information, and corresponding to the first public key unique to the electronic tag 100.
[0120] As described above, if the electronic tag that transmitted the first encrypted information to the second information processing device 200b is legitimate, the second information processing device 200b may obtain unique information by decrypting the first encrypted information using the information of the first public key. On the other hand, if the electronic tag is invalid, the second information processing device 200b may determine that the electronic tag is invalid at step S908 because it cannot decrypt the first encrypted information using the information of the public key identified by the key management information.
[0121] Next, the second information processing device 200b may determine whether or not multisig unique information associated with the information decrypted using the first public key information is held in the storage device 400 (step S908). Specifically, the second information processing device 200b may use the acquired unique information to determine whether or not multisig unique information is held in the storage device 400 in association with the unique information. If multisig unique information is held in the storage device 400 in association with the unique information, it serves as evidence that the first inspection was performed using an information processing device 200 different from the second information processing device 200b. In this case, the existence of multisig unique information associated with the unique information serves as evidence that the storage device 10 equipped with the electronic tag 100 was delivered or transported after the contents of the storage device were confirmed by the first inspector. Therefore, the second inspector operating the second information processing device 200b can confirm that the delivery or transport of the storage device was carried out safely.
[0122] Next, the second information processing device 200b may transmit to the electronic tag 100 the second encrypted information encrypted using the third private key information stored in the storage device 400, which contains the corresponding third public key information (step S909). Specifically, after confirming the authenticity of the electronic tag 100, the second information processing device 200b may transmit to the electronic tag 100 the second encrypted information encrypted using the third private key information unique to the second information processing device 200b, in order to have the electronic tag 100 determine the authenticity of the second information processing device 200b. The third private key information is the information of a legitimate private key, which contains the third public key information corresponding to the third private key, stored in the storage device 400.
[0123] The second encrypted information may be, for example, a temporary access token, or it may be information that allows the electronic tag 100 to detect that the operator of the second information processing device 200b is a legitimate person. Specifically, as will be described later, if the electronic tag 100 can decrypt the second encrypted information using the public key information legitimately stored in the storage device 400, it indicates that the sender of the temporary access token was legitimately distributed the private key information by the administrator, and therefore the electronic tag 100 can determine that the operator of the second information processing device 200b is a legitimate person. As mentioned above, the second encrypted information, such as a temporary access token, may also be accompanied by key management information to identify the public key information corresponding to the second private key information used for encryption.
[0124] Returning to Figure 9, the electronic tag 100 may decrypt the second encrypted information using the information of the second public key received via the communication unit 101 (step S910). Specifically, as described above, the electronic tag 100 may receive the corresponding public key information from the storage device 400 based on the key management information attached to the temporary access token, and decrypt the second encrypted information using the said public key information.
[0125] The corresponding public key information may, for example, be stored in the memory unit 102 in advance. Specifically, for example, if, at the stage when the first inspector inspects the storage device 10, the second private key information stored in the second information processing device 200b operated by the second inspector is known in advance, the second public key information acquired by the first information processing device 200a may be passed to the electronic tag 100 and stored in the memory unit 102 in advance. In this disclosure, the second public key information only needs to be able to encrypt the second cryptographic information received from the second information processing device 200b, and the timing at which the second public key is stored in the memory unit 102 is not limited to the scope of this disclosure.
[0126] Returning to Figure 9, when the electronic tag 100 decrypts the second encrypted information, as described above, it can determine that the second information processing device 200b that transmitted the second encrypted information is a device operated by a legitimate inspector. Therefore, in response to the decryption of the second encrypted information, it may encrypt the first predetermined information relating to permission to open the document and generate the first predetermined digital signature information, which is the encrypted first predetermined information (step S911).
[0127] The first prescribed information regarding permission to open the package may, for example, be information indicating permission to open the package, which is generated in the electronic tag 100 in response to the completion of the second inspection by the second inspector. The specific name and content of the first prescribed information may be arbitrarily set by the administrator.
[0128] Although the first predetermined information has been described as information relating to permission to open the electronic tag 100, for example, the first predetermined information may be information obtained by decrypting the second encrypted information using the information of the third public key held in the storage device 400.
[0129] Returning to Figure 9, the electronic tag 100 may transmit to the second information processing device 200b a digital signature first predetermined information, which is encrypted first predetermined information relating to permission to open, in response to the decryption of the second encrypted information using the third public key in the electronic tag 100 (step S912).
[0130] Specifically, the electronic tag 100 may digitally sign the first predetermined information relating to permission to open the package and transmit the digital signature first predetermined information to the second information processing device 200b in order to store the multi-signature permission to open the package in the storage device 400 via the second information processing device 200b.
[0131] Furthermore, the first digital signature information may be transmitted from the electronic tag 100 to the second information processing device 200b when the information obtained by decrypting the second cryptographic information using the third public key information in the electronic tag 100 satisfies the predetermined conditions. The information used to determine whether or not the predetermined conditions are met may be all or part of the decrypted information.
[0132] Specifically, the predetermined condition may be, for example, that when the second encrypted information received from the second information processing device 200b is decrypted using the information of the third public key, the information contained in the decrypted information satisfies at least one of the following: for example, information indicating the legitimacy of the second inspector, and information indicating that it has been confirmed that the multi-signature unique information corresponding to the digital signature unique information received from the electronic tag 100 is held in the storage device 400. The specific content of the predetermined condition may be arbitrarily set by the provider of this service, such as the administrator, and the scope of this disclosure is not limited by the specific content.
[0133] On the other hand, the first digital signature information does not have to be transmitted from the electronic tag 100 to the second information processing device 200b if the decrypted information of the second encrypted information does not meet the predetermined conditions. This allows for the generation of information regarding permission to open the document, for example, in response to the second inspector confirming that the first inspection has been performed, thereby further facilitating the execution of a two-stage inspection including the first and second inspections.
[0134] Returning to Figure 9, when the second information processing device 200b receives the first digital signature predetermined information from the electronic tag 100, it may generate the first multi-signature predetermined information by encrypting the first digital signature predetermined information using the information of the third secret key (step S913). Specifically, when the second information processing device 200b receives the first digital signature predetermined information using the communication unit 201 in response to transmitting the second encrypted information to the electronic tag 100, it may digitally sign the information regarding permission to open the document and convert it into a multi-signature.
[0135] Furthermore, the second information processing device 200b may use one or more communication means to cause the storage device 400 to store the multi-signature first predetermined information in order to store information regarding permission to open the storage device with a digital signature in the storage device 400 (step S914). As a result, the user can open the storage device after the storage device 400 has recorded that the first and second inspections were performed when the storage device was delivered or transported.
[0136] In the above description, it was explained that in step S912, the second information processing device 200b receives the first predetermined digital signature information from the electronic tag 100. However, for example, the second predetermined digital signature information may be obtained by encrypting the first predetermined digital signature information and the second predetermined information regarding an opening abnormality of the storage device equipped with the electronic tag 100 using the first predetermined digital signature information.
[0137] The second predetermined information regarding the abnormal opening may be information generated by the electronic tag 100 when it detects that the storage device has been opened improperly. Improper opening of the storage device may, for example, mean that the storage device was opened before the electronic tag 100 received the second encrypted information from the second information processing device 200b. The electronic tag 100 may detect the opening of the storage device based on a predetermined signal received from a locking mechanism 110 provided in the storage device. The above-mentioned content of improper opening is merely an example, and the specific content of improper opening may be arbitrarily set by an administrator or the like, and the scope of this disclosure is not limited by the specific content.
[0138] In such a case, when the electronic tag 100 detects an unauthorized opening, it may generate the second predetermined information described above, encrypt it using the first secret key information, and store the encrypted digital signature second predetermined information in the memory unit 102. The electronic tag 100 may transmit the digital signature second predetermined information together with the digital signature first predetermined information to the second information processing device 200b. The second information processing device 200b then stores the multi-signature second predetermined information, which is the digital signature second predetermined information received from the electronic tag 100 and encrypted, together with the multi-signature first predetermined information in the storage device 400, and may record, for example, in a distributed ledger that there was an unauthorized opening of the storage device before the second inspection.
[0139] In other words, when the second information processing device 200b receives digital signature second predetermined information, which is encrypted digital signature second predetermined information, from the electronic tag 100 in response to transmitting the second encrypted information to the electronic tag 100, it may generate multi-signature second predetermined information by encrypting the digital signature second predetermined information using the third secret key information and store it in the storage device 400.
[0140] It has been explained that the electronic tag 100 may detect the opening of the storage device based on a predetermined signal received from a locking mechanism 110 provided in the storage device. More specifically, predetermined information or signals may be transmitted and received between the locking mechanism 110 and the electronic tag 100. That is, if the storage device is provided with a locking mechanism 110 that can lock the storage device, and the locking mechanism 110 and the communication unit 101 provided in the electronic tag 100 are capable of transmitting and receiving predetermined information or signals, the second predetermined information may be generated by the electronic tag 100 based on predetermined information or signals received from the locking mechanism 110.
[0141] Furthermore, the second information processing device 200b may, for example, perform information processing to prove that it is associated with the legitimate secret key information after step S908 in Figure 9 has been performed and before transmitting the second cryptographic information to the electronic tag 100.
[0142] Figure 10 is a sequence diagram showing an example of the procedure for sending and receiving information and processing information between an electronic tag and a second information processing device according to Embodiment 1 of the present invention.
[0143] As shown in Figure 10, the second information processing device 200b may, for example, generate predetermined random number information and transmit it to the electronic tag 100 (step S1001). The transmission of this random number information is performed to confirm that the electronic tag 100 is a legitimate electronic tag to which the secret key information has been properly assigned by an administrator or the like.
[0144] The electronic tag 100 that receives the random number information may encrypt the random number information using the information of the first secret key (step S1002). The electronic tag 100 may then transmit the third encrypted information, which is the encrypted random number information, and key management information that can identify the information of the first public key held in the storage device 400 corresponding to the first secret key, to the second information processing device 200b (step S1003).
[0145] The second information processing device 200b may identify the information of the first public key held in the storage device 400 based on the received key management information, and decrypt the third encrypted information using the information of the first public key (step S1004). In this case, when observed from the second information processing device 200b, there is no confirmation that the third encrypted information is information encrypted using the information of the legitimate private key, and it is only after the third encrypted information is decrypted using the information of the public key identified based on the key management information that it is determined that the third encrypted information is information encrypted using the information of the legitimate private key.
[0146] The second information processing device 200b may determine whether the decrypted random number information matches the random number information transmitted to the electronic tag 100. If the decrypted random number information matches the random number information transmitted to the electronic tag 100, the second information processing device 200b can determine that the electronic tag that transmitted the encrypted random number information is the electronic tag 100 to which the legitimate secret key information is associated. This contributes to the further validity of the first and second checks.
[0147] In other words, the second information processing device 200b may, when the information decrypted from the digital signature unique information matches the information decrypted from the multisig unique information, further transmit random number information to the electronic tag 100, and when it receives third encrypted information from the electronic tag 100, transmit second encrypted information to the electronic tag 100 if the information decrypted from the third encrypted information using the first public key information is said to be the random number information.
[0148] In the above explanation, the legitimacy of the electronic tag 100 was determined by whether the decrypted random number information matched the random number information transmitted to the electronic tag 100. However, for example, the second information processing device 200b may determine the legitimacy of the electronic tag 100 based on whether it was able to decrypt the encrypted random number information using the public key information identified based on the key management information.
[0149] As described above, the storage device 400 may have one of the multiple distributed ledgers maintained in the P2P network including the storage device 400. That is, the storage device 400 may store one of the multiple distributed ledgers using blockchain, and the information encrypted by the electronic tag 100 and the information processing device 200 may be added to that blockchain. In this case, the P2P network may be formed by at least some of the multiple devices included in the information processing system 1, and various types of encrypted information may be managed by multiple distributed ledgers using blockchain maintained by at least two or more of the multiple devices that constitute the P2P network.
[0150] Furthermore, in a P2P network, each encrypted piece of information may be broadcast as transaction data. The method for identifying the neighboring node to which the broadcast is directed in a P2P network may include, for example, a fixed IP address list, DNS, enode-URL format, or a combination thereof. This method is merely an example; for instance, a gossip-style protocol may be employed, and the specific details of such protocols are not limited to the scope of this disclosure. Since P2P networks and broadcasting are publicly known technologies, a detailed explanation is omitted.
[0151] Furthermore, only some of the devices constituting the P2P network may maintain a distributed ledger, or all of the devices may maintain a distributed ledger. For example, the storage device 400 included in the information processing server 30 may maintain one or more distributed ledgers.
[0152] This allows for the management of unique information encrypted in the electronic tag 100 using a distributed ledger, thereby improving accessibility and reliability of the information for users, inspectors, and third parties.
[0153] The basic operation procedure of the electronic tag 100 according to this embodiment has been described above with reference to Figures 9 and 10.
[0154] In the above explanation with reference to Figure 10, it was explained that the second information processing device 200b transmits random number information to the electronic tag 100, and the electronic tag 100 determines the legitimacy of the second information processing device 200b. However, for example, in the above explanation with reference to Figure 10, the information processing contents of the electronic tag 100 and the second information processing device 200b may be interchangeable.
[0155] Specifically, for example, the electronic tag 100 may generate predetermined random number information and transmit it to the second information processing device 200b. The second information processing device 200b, upon receiving the random number information, may encrypt the random number information using the information of the third secret key. The second information processing device 200b may then transmit to the electronic tag 100 the fourth encrypted information, which is the encrypted random number information, and key management information that can identify the information of the third public key held in the storage device 400 corresponding to the third secret key. The electronic tag 100 may identify the information of the third public key held in the storage device 400 based on the received key management information and decrypt the fourth encrypted information using the information of the third public key. In this case, when observed from the electronic tag 100, there is no confirmation that the fourth encrypted information is information encrypted using the information of the legitimate secret key, and it is only after the fourth encrypted information is decrypted using the information of the public key identified based on the key management information that it is determined that the fourth encrypted information is information encrypted using the information of the legitimate secret key.
[0156] The electronic tag 100 may determine whether the decrypted random number information matches the random number information transmitted to the second information processing device 200b. If the decrypted random number information matches the random number information transmitted to the second information processing device 200b, the electronic tag 100 can determine that the second information processing device 200b that transmitted the encrypted random number information is the second information processing device 200b to which the legitimate secret key information is associated. This contributes to the further validity of the first and second checks.
[0157] The information processing described above may be inserted between predetermined steps in Figure 9, for example, before step S906 in Figure 9. Furthermore, in the above description, the legitimacy of the second information processing device 200b was determined by whether the decrypted random number information matched the random number information transmitted to the second information processing device 200b. However, for example, the electronic tag 100 may determine the legitimacy of the second information processing device 200b based on whether it was able to decrypt the encrypted random number information using the public key information identified based on the key management information.
[0158] In other words, the electronic tag 100 may further transmit random number information to the second information processing device 200b, and when it receives fourth encrypted information from the second information processing device 200b, if the information obtained by decrypting the fourth encrypted information using the third public key information is said to be the random number information, it may transmit first encrypted information to the electronic tag 100.
[0159] Figure 11 is a flowchart showing an example of the operation flow of the first information processing device in the information processing method according to Embodiment 1. Figure 12 is a flowchart showing an example of the operation flow of the second information processing device in the information processing method according to Embodiment 1. The flow of the information processing method according to Embodiment 1 will be described below with reference to Figures 11 and 12.
[0160] The flowcharts described below are merely illustrative examples of the steps necessary to explain the processing procedures of the operation of the information processing device relating to this disclosure. Within the scope of the functionality of this embodiment, this does not prevent the appropriate insertion of steps relating to the processing of other operations between each step in each flowchart. For the sake of clarity, the flowcharts in this disclosure do not necessarily have to be based on event-driven flowcharts. Event processing may be performed in the electronic tag 100 or in the information processing device 200. The subject of event generation or event processing is not limited to this invention. The above explanation of the flowcharts may apply to all flowcharts in this disclosure.
[0161] In Figure 11, the information processing from point A to point B shows the flow of operation in the first information processing device 200a. First, the first information processing device 200a may determine whether or not it has received digital signature unique information from the electronic tag 100, which is encrypted using the first secret key information in the electronic tag 100 (step S1101). If the first information processing device 200a has not received the digital signature unique information (step S1101: NO), it may wait until it receives the information.
[0162] On the other hand, when the first information processing device 200a receives digital signature unique information from the electronic tag 100 (step S1101: YES), it may encrypt the digital signature unique information using the information of a unique second secret key associated with the first information processing device 200a to generate multisig unique information (step S1102).
[0163] Next, the first information processing device 200a may associate the unique information previously stored in the storage device 400 by the electronic tag 100 with the multisig unique information and store it in the storage device 400 (step S1103).
[0164] Next, in Figure 12, the information processing from point B to point C shows the flow of operation in the second information processing device 200b. First, the second information processing device may determine whether or not it has received the first encrypted information from the electronic tag 100 (step S1104). If the contents of the unique information or digital signature unique information held in the electronic tag 100 have not been tampered with, the first encrypted information is the digital signature unique information.
[0165] If the second information processing device 200b has not received the first encrypted information (step S1104: NO), it may wait until it receives the first encrypted information. On the other hand, if the second information processing device 200b has received the first encrypted information (step S1104: YES), it may decrypt the first encrypted information using predetermined first public key information held in the storage device 400 (step S1105).
[0166] The second information processing device 200b may then determine whether or not the storage device 400 holds multisig-specific information associated with the information decrypted using the first public key information (step S1106). If the storage device 400 does not hold the multisig-specific information (step S1106: NO), the second information processing device 200b may transmit information to the electronic tag 100 indicating that the multisig-specific information is not held (step S1107). In such a case, for example, based on circumstances such as the information held in the electronic tag 100 being tampered with, the storage device 400 may digitally sign information indicating that an abnormality has occurred with respect to the electronic tag 100 and then store it in the storage device 400.
[0167] On the other hand, if the storage device 400 holds the multisig-specific information, the second information processing device 200b may transmit the second encrypted information, which is encrypted using the third secret key information held in the storage device 400, to the electronic tag 100 (step S1108).
[0168] Next, the second information processing device 200b may determine from the electronic tag 100 whether it has received the first predetermined digital signature information, which is encrypted, containing the first predetermined information regarding permission to open the second encrypted information in response to the decryption of the second encrypted information using the third public key in the electronic tag 100 (step S1109). If the second information processing device 200b has not received the first predetermined digital signature information from the electronic tag 100 (step S1109: NO), it may wait until it receives the information.
[0169] On the other hand, when the second information processing device 200b receives first predetermined digital signature information from the electronic tag 100, which is encrypted first predetermined digital signature information relating to permission to open in response to decryption of the second encrypted information using the third public key in the electronic tag 100, it may generate first predetermined multisig information by encrypting the first predetermined digital signature information using the third secret key information (step S1110). The second information processing device 200b may then store the first predetermined multisig information in the storage device 400 (step S1111).
[0170] The flow of the information processing method according to Embodiment 1 has been described above with reference to Figures 11 and 12.
[0171] Thus, the information processing method in this disclosure is an information processing method in an information processing system 1 including an electronic tag 100 which is openable and closable and built into or attached to a storage device 10 for storing articles, and a plurality of information processing devices 200 which can be connected to a storage device 400 using one or more communication means, wherein the first information processing device 200a, upon receiving digital signature unique information from the electronic tag 100 which has been encrypted using the information of a first secret key in the electronic tag 100, encrypts the digital signature unique information using the information of a second secret key to generate multisig unique information, associates it with unique information previously held in the storage device 400 by the electronic tag 100, and causes the storage device 400 to hold the multisig unique information, and the second information processing device 200b The system may also include the following steps: when first encrypted information is received from the electronic tag 100, the first encrypted information is decrypted using predetermined first public key information held in the storage device 400; when multisig unique information associated with the information decrypted using the first public key information is held in the storage device 400, the corresponding third public key information is encrypted using third private key information held in the storage device 400 and second encrypted information is transmitted to the electronic tag 100; and when first predetermined digital signature information, which is encrypted with first predetermined information regarding permission to open in response to the decryption of the second encrypted information using the third public key in the electronic tag 100, is received from the electronic tag 100, multisig first predetermined information is generated by encrypting the digital signature first predetermined information using third private key information and stored in the storage device 400.
[0172] This allows an information processing device capable of encrypting information using a legitimate private key corresponding to a public key stored in a storage device to receive opening and closing information of a storage device equipped with an electronic tag from the electronic tag, encrypt the information, and store it in the storage device. This contributes to the easy management of information related to the opening and closing of a storage device in the storage device.
[0173] In the above descriptions of embodiments and modifications, explanations of known technologies related to each function and each information processing have been omitted. For example, in this disclosure, the specific details of the encryption process using private key information and the decryption process using public key information can be implemented using known technologies, so a detailed explanation of those specific details has been omitted.
[0174] (An example of a computer hardware configuration) The functions of each part in the embodiments and each modified example may be implemented by a program.
[0175] In other words, an information processing program according to one aspect of the present invention is an information processing system 1 including an electronic tag 100 that is openable and closable and built into or attached to a storage device 10 for storing articles, and a first information processing device 200a and a second information processing device 200b that can be connected to a storage device 400 using one or more communication means, wherein when the electronic tag 100 receives digital signature unique information encrypted using first secret key information, the computer in the first information processing device 200a performs a control process to generate multisig unique information by encrypting the digital signature unique information using second secret key information, associates it with unique information previously held in the storage device 400 by the electronic tag 100, and causes the computer to hold the multisig unique information in the storage device 400, and the first encrypted information is stored in the electronic tag When received from 100, the first encrypted information is decrypted using predetermined first public key information held in the storage device 400. When multisig unique information associated with the information decrypted using the first public key information is held in the storage device 400, the corresponding third public key information is encrypted using the third private key information held in the storage device 400 and transmitted to the electronic tag 100. When the electronic tag 100 receives first predetermined digital signature information, which is encrypted with first predetermined information regarding permission to open the digital signature in response to the decryption of the second encrypted information using the third public key, the computer in the second information processing device 200b may execute a control process to generate first predetermined multisig information, which is encrypted using the third private key information, and hold it in the storage device 400.
[0176] Figure 13 shows an example of the computer hardware configuration in such a case.
[0177] As shown in Figure 13, the computer 9000 includes, for example, a CPU (Central Processing Unit) 9001, RAM (Random Access Memory) 9002, ROM (Read Only Memory) 9003, a storage device 9004, an input / output interface (I / F) 9005, a read interface (I / F) 9006, and a communication interface (I / F) 9007. Each of the above components is connected directly or indirectly via a bus 9008.
[0178] The storage device 9004 is, for example, an HDD (Hard Disk Drive), an SSD (Solid State Drive), etc. The computer 9000 is connected to the input / output (I / O) device 9009 via the input / output interface 9005. The input / output device 9009 includes devices having input and output functions, such as magnetic disk drives, as well as input devices whose primary function is input and output devices whose primary function is output. Examples of input devices include input keys, mice, touch panels, and scanners. Examples of output devices include displays, speakers, and printers.
[0179] The read interface 9006 reads the program or data recorded on the recording medium 9010. The recording medium 9010 is, for example, a semiconductor memory, an optical recording medium, a magnetic recording medium, a magneto-optical recording medium, etc.
[0180] The communication interface 9007 receives data from other devices and transmits data to other devices via the network 9011. The network 9011 may be a wired network or a wireless network. The other devices may be client devices or server devices.
[0181] For example, a program stored in ROM 9003, a program stored in storage device 9004, a program recorded on recording medium 9010, or a program received by the communication interface from another device is loaded into RAM 9002. In the above embodiments and their respective modifications, for example, the CPU 9001 executes a program loaded into RAM 9002, thereby realizing the functions of each part in the above embodiments.
[0182] Furthermore, the functions of each component in the computer 9000 may be implemented through cloud computing.
[0183] Furthermore, the information processing program or the described function to be executed by the computer in the information processing system 1 may be recorded on a non-transitory, tangible computer-readable storage medium. The non-transitory, tangible computer-readable storage medium is any storage medium that can be accessed by a computer, CPU, MPU (Micro Processing Unit), etc. Any storage medium is, for example, ROM, RAM, flash memory, magnetic storage device, optical disc, etc., and is not limited to those exemplified.
[0184] In the above explanation, "at least one of A, B, and C is included" may also mean "one or two or more of A, B, and C are included." [Industrial applicability]
[0185] The information processing method, information processing system, information processing program, and recording medium according to the present invention are effective for all technologies related to managing information regarding the opening and closing of storage devices. [Explanation of Symbols]
[0186] 1. Information Processing System 10 Storage Tools 30 Information Processing Server 100 Information Processing Devices 101 Communications Department 102 Memory section 103 Control Unit 110 Locking mechanism 200 devices 201 Communications Department 202 Memory section 203 Control Unit 204 Input section 205 Display media 300 Information Processing Devices 400 storage device 9000 Computers 9001 CPU 9002 RAM 9003 ROM 9004 Storage device 9005 Input / Output Interface 9006 Read Interface 9007 Communication Interface 9008 Bus 9009 Input / Output Device 9010 Recording media 9011 Network
Claims
1. An information processing method in an information processing system that includes an electronic tag that is openable and closable and built into or attached to a storage device for storing articles, and a plurality of information processing devices that can be connected to a storage device using one or more communication means, The first information processing device is When the electronic tag receives digital signature unique information, which is encrypted using the first secret key information, from the electronic tag, the digital signature unique information is encrypted using the second secret key information to generate multisig unique information. The electronic tag is used to associate the unique information previously stored in the storage device with the multi-signature unique information, and the storage device is made to store the multi-signature unique information. The second information processing device is When the first encrypted information is received from the electronic tag, the first encrypted information is decrypted using predetermined first public key information held in the storage device, and when the multisig unique information associated with the information decrypted using the first public key information is held in the storage device, the corresponding third public key information is encrypted using the third secret key information held in the storage device and the second encrypted information is transmitted to the electronic tag. When a first predetermined digital signature, which is encrypted first predetermined digital signature, is received from the electronic tag, the first predetermined digital signature, which is encrypted first predetermined digital signature, is encrypted using the third private key information of the electronic tag in response to the decryption of the second encrypted information using the third public key of the electronic tag, and multi-signature first predetermined digital signature is generated and stored in the storage device. Information processing methods.
2. The aforementioned unique information is information based on storage information, which is at least one of the following: information about one or more articles stored in the storage device, information about the time the storage device was closed, and identification information unique to the user operating the communication terminal. The storage information is information that the electronic tag receives from the communication terminal. The information processing method according to claim 1.
3. The aforementioned unique information is the hash value of the storage information. The information processing method according to claim 2.
4. The information of the predetermined first public key is information received by the second information processing device from the storage device based on the key management information received from the electronic tag. The information processing method according to claim 1.
5. The first predetermined information is information regarding permission to open the electronic tag, The information processing method according to claim 1.
6. The first predetermined information is information obtained by decrypting the second encrypted information using the third public key information held in the storage device. The information processing method according to claim 1.
7. The first digital signature predetermined information is transmitted from the electronic tag to the second information processing device when the information obtained by decrypting the second cryptographic information using the third public key information in the electronic tag satisfies predetermined conditions. The information processing method according to claim 1.
8. The first digital signature information is not transmitted from the electronic tag to the second information processing device when the decrypted information of the second encrypted information does not satisfy the predetermined conditions. The information processing method according to claim 7.
9. The second information processing device is In response to transmitting the second encrypted information to the electronic tag, when the second predetermined digital signature information, which contains encrypted information regarding an opening anomaly, is received from the electronic tag, the system generates multi-signature second predetermined information by encrypting the second predetermined digital signature information using the third secret key information and stores it in the storage device. The information processing method according to claim 1.
10. When the storage device is provided with a locking mechanism that allows the storage device to be locked, and the locking mechanism and the communication unit provided in the electronic tag are capable of sending and receiving predetermined information or signals, The second predetermined information is generated based on the predetermined information or signal received by the electronic tag from the locking mechanism. The information processing method according to claim 9.
11. The second information processing device is When the information obtained by decrypting the digital signature unique information matches the information obtained by decrypting the multisig unique information, random number information is further transmitted to the electronic tag. When the third encrypted information is received from the electronic tag, and the information obtained by decrypting the third encrypted information using the first public key information is the random number information, the second encrypted information is transmitted to the electronic tag. The information processing method according to claim 1.
12. The electronic tag further transmits random number information to the second information processing device, and when it receives fourth encrypted information from the second information processing device, if the information obtained by decrypting the fourth encrypted information using the third public key information is the random number information, it transmits the first encrypted information to the second information processing device. The information processing method according to claim 1.
13. The storage device has one of a plurality of distributed ledgers maintained in the P2P network including the storage device. The information processing method according to claim 1.
14. A system comprising an electronic tag that is openable and closable and built into or attached to a storage device for storing articles, and a plurality of information processing devices that can be connected to a storage device using one or more communication means, The first information processing device is When the electronic tag receives digital signature unique information, which is encrypted using the first secret key information, from the electronic tag, the digital signature unique information is encrypted using the second secret key information to generate multisig unique information. The electronic tag is used to associate the unique information previously stored in the storage device with the multi-signature unique information, and the storage device is made to store the multi-signature unique information. The second information processing device is When the first encrypted information is received from the electronic tag, the first encrypted information is decrypted using predetermined first public key information held in the storage device, and when the multisig unique information associated with the information decrypted using the first public key information is held in the storage device, the corresponding third public key information is encrypted using the third secret key information held in the storage device and the second encrypted information is transmitted to the electronic tag. When a first predetermined digital signature, which is encrypted first predetermined digital signature, is received from the electronic tag, the first predetermined digital signature, which is encrypted first predetermined digital signature, is encrypted using the third private key information of the electronic tag in response to the decryption of the second encrypted information using the third public key of the electronic tag, and multi-signature first predetermined digital signature is generated and stored in the storage device. Information processing system.
15. An information processing system including an electronic tag that is openable and closable and built into or attached to a storage device for storing articles, and a first information processing device and a second information processing device that can be connected to a storage device using one or more communication means, When the electronic tag receives digital signature unique information encrypted using the first secret key information, the computer in the first information processing device performs a control process to encrypt the digital signature unique information using the second secret key information to generate multisig unique information, associate it with the unique information previously held in the storage device by the electronic tag, and hold the multisig unique information in the storage device. When first encrypted information is received from the electronic tag, the first encrypted information is decrypted using predetermined first public key information held in the storage device, and when the multisig unique information associated with the information decrypted using the first public key information is held in the storage device, the corresponding third public key information is encrypted using the third private key information held in the storage device and second encrypted information is transmitted to the electronic tag, and when first predetermined digital signature information relating to permission to open the information corresponding to the decryption of the second encrypted information using the third public key in the electronic tag is received from the electronic tag, the computer in the second information processing device is instructed to execute a control process to generate multisig first predetermined information by encrypting the digital signature first predetermined information using the third private key information and to hold it in the storage device. Information processing program.
16. An information processing system including an electronic tag that is openable and closable and built into or attached to a storage device for storing articles, and a first information processing device and a second information processing device that can be connected to a storage device using one or more communication means, When the electronic tag receives digital signature unique information encrypted using the first secret key information, the computer in the first information processing device performs a control process to encrypt the digital signature unique information using the second secret key information to generate multisig unique information, associate it with the unique information previously held in the storage device by the electronic tag, and hold the multisig unique information in the storage device. When first encrypted information is received from the electronic tag, the first encrypted information is decrypted using predetermined first public key information held in the storage device, and when the multisig unique information associated with the information decrypted using the first public key information is held in the storage device, the corresponding third public key information is encrypted using the third private key information held in the storage device and second encrypted information is transmitted to the electronic tag, and when first predetermined digital signature information relating to permission to open the information corresponding to the decryption of the second encrypted information using the third public key in the electronic tag is received from the electronic tag, the computer in the second information processing device is instructed to execute a control process to generate multisig first predetermined information by encrypting the digital signature first predetermined information using the third private key information and to hold it in the storage device. A computer-readable recording medium on which information processing programs are stored.
Citation Information
Patent Citations
Control method, rfid tag, and control system for air freight baggage
JP2002362730A
Delivery confirmation system, portable terminal, and program
JP2010128535A