credential signing device and credential signing program

The qualified signature device addresses the issue of unqualified signatures by using credential signing keys and digital certificates to enforce qualification-based electronic signatures, ensuring reliable and qualified signatories in electronic contracts.

JP2026091906APending Publication Date: 2026-06-04SEIKO SOLUTIONS

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
SEIKO SOLUTIONS
Filing Date
2026-03-19
Publication Date
2026-06-04

AI Technical Summary

Technical Problem

Existing electronic contract systems lack mechanisms to ensure that witness-type electronic signatures are made by qualified individuals, allowing unqualified individuals to sign or qualified individuals to mistakenly sign with incorrect qualifications, compromising the integrity of electronic contracts.

Method used

A qualified signature device that performs witness-type electronic signatures based on predefined qualifications, using credential signing keys and digital certificates specific to each qualification, ensuring only qualified individuals can sign and allowing verification of qualifications through a credential signing system.

Benefits of technology

Ensures that electronic signatures are made by qualified individuals, enhancing the reliability and integrity of electronic contracts by verifying the qualifications of the signatories.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026091906000001_ABST
    Figure 2026091906000001_ABST
Patent Text Reader

Abstract

Ensuring that electronic signatures are based on appropriate qualifications. [Solution] If at least one of the contracting parties performing a witness-type electronic signature is a qualified person with predetermined qualifications, then each signature field in the electronic contract is restricted to only those with the qualifications required for that signature field. For example, various electronic contracts can be linked to a required qualification such as "doctor" for signer 1, or a required qualification signature form can be provided in each signature field of the electronic contract with the required qualifications embedded, thereby preventing electronic signatures by persons other than those with restricted qualifications. When the qualifications of the contracting parties match the qualifications required in the electronic contract, a qualified signature is performed as an electronic signature using a qualified signature key, which is a private key created in accordance with the qualifications of the qualified person, and an electronic certificate that records the specific information of the qualifications.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an apparatus and a program for performing an electronic signature on an electronic contract.

Background Art

[0002] Electronic contracts in which an electronic signature is applied to an electronic contract document (including an electronic consent form) electronically recording the contract content between parties are in use. Depending on the processing content of the contract, a party-type electronic signature and a business operator-type (witness-type) electronic signature are performed on the electronic contract document. An electronically signed electronic contract document is guaranteed to be a contract by the contractee himself / herself and that the content has not been tampered with. In the case of the party-type electronic signature, an electronic signature of an electronic contract document is performed using a private key and an electronic certificate (hereinafter referred to as a private key, etc.) owned exclusively by the contracting party. On the other hand, in the case of the witness-type electronic signature, as described in Patent Document 1, an electronic signature of an electronic contract document is performed using a private key, etc. of an electronic signature business operator serving as a witness. In such a witness-type electronic signature, generally, since a private key, etc. of the witness rather than a private key, etc. of the contractee himself / herself is used, after strict identification of the contractee by a service provider (for example, confirmation of an ID (identification number) and a PW (password)), an e-mail address, etc. identifying the contractee is included in the attribute information and targeted for electronic signature.

[0003] By the way, not only the content of the electronic contract document is diverse, but there are also various parties who conclude a contract. For example, a qualified person such as a doctor or an architect may conclude an electronic contract under his / her qualification. In such a case, it is preferable that a third party including the contractee himself / herself can confirm that the electronically signed electronic contract document has been made by a predetermined qualification holder. However, in the case of the witness-type electronic signature, the qualification of the electronic contractee could not be known from the electronically signed electronic contract document.

[0004] Furthermore, in some contracts, such as consent forms between doctors and patients, there are qualification requirements for those who can sign them (in this case, a medical license is required). However, conventional electronic contract services lacked mechanisms to prevent signatures from being submitted by individuals who did not meet the eligibility requirements, making it impossible to prevent signatures from being made by the wrong person. Furthermore, verifying whether a signature was made by the wrong person was also difficult. Therefore, due to the intentional actions or errors of unqualified individuals, there was a possibility that someone might sign as a qualified person, or that a qualified person might mistakenly sign as someone with a different qualification (for example, a nurse signing as a doctor). [Prior art documents] [Patent Documents]

[0005] [Patent Document 1] Japanese Patent Publication No. 2013-114641 [Overview of the Initiative] [Problems that the invention aims to solve]

[0006] The present invention aims to ensure that electronic signatures are made by contracting parties in electronic contracts using a witness-type electronic signature system, based on their appropriate qualifications. [Means for solving the problem]

[0007] The present invention is a qualified signature device that sequentially performs witness-type electronic signatures on electronic contracts based on requests from each contracting party, A signature key storage means for storing the private key, which is the qualification signing key, and its digital certificate, issued for each of the multiple pre-defined qualifications, A means of presenting an electronic contract in which, if at least one of the contracting parties is a person with predetermined qualifications, signature restrictions are stipulated in each signature field, allowing only persons with the required qualifications to electronically sign; If the contracting party requesting an electronic signature is a qualified person, a means for determining whether the qualifications of that contracting party match the qualifications required in the signature field of the electronic contract.、 The aforementioned qualifications Match In that case, the electronic contract said Yes Qualified person Using the aforementioned credential signing key and its digital certificate corresponding to the qualification An electronic signature method for performing an electronic signature, The present invention provides a qualification signature device characterized by being equipped with the following: [Effects of the Invention]

[0008] In this invention, if a contracting party requesting an electronic signature is a qualified person, the qualifications of that contracting party match the qualifications required in the signature field of the electronic contract. In such cases, the credential signing key and its digital certificate corresponding to the qualification of the qualified person are used. Since electronic signatures are used, it is more reliable to ensure that electronic signatures are based on appropriate qualifications. Uko It is possible. [Brief explanation of the drawing]

[0009] [Figure 1] This is an explanatory diagram illustrating the configuration of a credential signing system, including a credential signing device. [Figure 2] This is an explanatory diagram showing the configuration of a credential signing device. [Figure 3] This is a conceptual diagram illustrating the required signature list based on signature restriction A. [Figure 4A] This is an explanatory diagram showing an unrestricted template for surgical consent forms before the requirement for a specific qualification signature form is added. [Figure 4B] This is an explanatory diagram showing the display screen of a surgical consent form with a signature requirement B embedded in an unrestricted template. [Figure 4C] This is an explanatory diagram showing the display screen of a surgical consent form with signature restriction B, after electronic signature and timestamping by a qualified signature device. [Figure 4D] This is an explanatory diagram showing the display screen of a surgical consent form that has been signed by a qualified person, using the signature-only B method. [Figure 5] This is a conceptual diagram illustrating the contents of the account database stored in the storage device of the credential signing device. [Figure 6] This is a conceptual diagram illustrating the contents of the credentials database stored in the memory of the credentials signing device. [Figure 7] It is a flowchart showing the flow of account registration processing by an eligibility signature system. [Figure 8] It is a flowchart showing part of the flow of eligibility signature processing by an eligibility signature system. [Figure 9] It is a flowchart showing the continuation of the flow of eligibility signature processing by an eligibility signature system. [Figure 10] It is an explanatory diagram showing a display screen of an electronic contract document (surgery consent form) file displayed on a user terminal. [Figure 11] It is an explanatory diagram showing an electronic signature selection screen displayed on a user terminal. [Figure 12] It is an explanatory diagram conceptually showing the structure of an eligibility signature electronic contract document in which an eligibility signature has been performed by an eligibility signature system. [Figure 13] It is a flowchart showing the flow of verification processing for an eligibility signature electronic contract document for which an eligibility signature has been performed. [Figure 14] It is an explanatory diagram conceptually showing the structure of an eligibility signature electronic contract document according to a modification example.

Mode for Carrying Out the Invention

[0010] Hereinafter, a preferred embodiment of the eligibility signature device 1 of the present invention will be described in detail with reference to FIGS. 1 to 14. (1) Outline of the Embodiment When at least one of the contracting parties (users) who perform witness-type electronic signatures of the eligibility signature device 1 is a person (qualified person) having a predetermined qualification, for each signature column of the electronic contract document, a signature limitation A or a signature limitation B that only a person having the qualification required in the signature column can electronically sign is performed. In signature limitation A, it is possible to link the required qualifications such as "doctor" to signatory 1 and "nurse" to signatory 2 in the templates of various electronic contract documents. When the required qualifications are linked, by setting a signature request by a person other than the corresponding qualified person (doctor, nurse, etc.) as an error, it is possible to surely perform an electronic signature by the required qualified person. Regarding the linking of required qualifications to the electronic contract template, the required qualification signature number is linked according to the required qualification signature list 58 (see Figures 2 and 3) which specifies the required qualifications. For example, by linking the required qualification signature number "01" in "Medical Consent Form 1," the required qualifications are linked as follows: "Doctor" for Signer 1, "Nurse" for Signer 2, and so on. When a user uses a template with associated required qualifications, the qualification signing device 1 controls the selection of a qualified signer based on the conditions of the required qualification signing list 58.

[0011] In Signature-Only B, each signature field in the electronic contract is equipped with a form field (hereinafter referred to as the "Required Qualification Signature Form") into which the required qualifications (qualification information) are embedded, thereby preventing electronic signatures from being made by anyone other than the qualified person specified by the embedded required qualifications. For example, in the request qualification signature form, the input form name will be "SYOMEI01@N001," which is the original form name "SYOMEI01" with the qualification code "N001" of the request qualification specified in this form appended to it. Here, "@" indicates that additional information about the required qualifications follows, and the qualification code to be added is added according to the qualification DB56 (see Figures 2 and 6) described later. In addition, other signature restrictions include including required qualifications such as those of a doctor as input restrictions for electronic contracts with input restriction functions, or including the conditions for required qualifications in the properties of the electronic contract.

[0012] In electronic signatures using the qualified signature device 1, regardless of whether the signature is restricted or not, the electronic signature is performed on the electronic contract in a manner that allows the contracting parties and third parties to verify, after the electronic contract is completed, what qualifications the electronic contract was signed by at the request of a qualified person. Verifiable qualifications include various national and private certifications, qualifications obtained through enrollment in social insurance or national health insurance, and various other qualifications such as Japanese nationality and residence status. However, whether or not the contract holder (user) signs their qualifications is a separate matter; the qualification signing process will only be performed if the contract holder requests it and specifies their own qualifications.

[0013] Specifically, the qualified signature device 1 performs a so-called witness-type electronic signature (qualified signature) on an electronic contract, including an electronic consent form (hereinafter referred to as "electronic contract"), not using the private keys of the contracting party or consenting party (hereinafter referred to as "contracting party") themselves, but using a qualified signature key (private key) and electronic certificate issued to the qualified signature device 1 for each qualification. Each digital certificate for a qualified signing key includes credentials (e.g., qualification name, qualification code, etc.) that indicate the requester of the digital signature (contracting party) is the holder of the qualification corresponding to that qualified signing key, using the subject, subject alias, or policy OID (Object Identifier).

[0014] Furthermore, when performing an electronic signature, the credential signing device 1 includes credential information that can verify the contractor's qualifications in the attribute information (reason for electronic signature), calculates a hash value together with the electronic contract, and performs the electronic signature using a credential signing key, etc. (credential signing key and electronic certificate) corresponding to the contractor's qualifications. The attribute information (reason for digital signature) is a section of the credential signature processing format where any text information included in the scope of encryption can be entered. This allows contracting parties and third parties to verify, through the electronic certificate and attribute information of the qualified signing key, that the electronic contract processed by the qualified signing device 1 is a contract by at least one qualified person.

[0015] In the qualified signature processing of this embodiment, an electronic signature is performed each time a signature request is received from a party to a contract, corresponding to multiple contracting parties. If the qualifications of a contracting party match the qualifications required by the electronic contract, a qualified signature is performed using a qualified signing key, which is a private key created corresponding to the qualifications of the qualified person, and an electronic certificate that records the qualification identification information. If a contracting party is not qualified, an electronic signature (general signature) is performed using a common signing key (a private key used in common by all unqualified parties) that does not correspond to any qualifications.

[0016] (2) Details of the embodiment Figure 1 is a diagram showing the system configuration of a qualified signature system for witness-type electronic signatures on electronic contracts, including the qualified signature device 1 in this embodiment. As shown in Figure 1, the credential signing device 1 forms a credential signing system together with user terminals 91, 92, 93, ... used by contracting parties and users who act as verifiers, a list publishing server 6, a certification authority 7, and a timestamp server 8. The credentials signing device 1 is connected to user terminals 91, 92, and 93, and the list publishing server 6 via the internet or telephone lines, and is connected to the timestamp server 8 and the certification authority 7 via a VPN (Virtual Private Network), etc.

[0017] List publishing server 6 publishes the qualification comparison table 61 via the internet and other means. This qualification comparison table 61 is used to verify the validity of the qualifications of the contracting parties in an electronically signed contract (qualified-signed electronic contract (TS)), and is configured to display a list of qualification codes, qualification names, and methods for verifying the identity of qualified persons for each qualification. The qualification comparison table 61 is generated from the qualification DB 56 of the qualification signing device 1, which will be described later. The URI of this qualification comparison table 61 is stored in the qualification database of the qualification signing device 1 (described later) and is also recorded in the attribute information during qualification signing. The qualification comparison table 61, published on the list publication server 6, is used to verify the validity of the qualifications of the contracting parties. In addition, other electronic signature service providers can use the qualification comparison table 61 to adopt the same standards as the qualification signature device 1. Although the list publishing server 6 is operated by an external organization of the credential signing device 1, it may also be operated by the same entity that operates the credential signing device 1.

[0018] A Certification Authority (CA) is an organization that verifies the identity of those who perform electronic signatures. It verifies the identity of users based on their applications and various certificates, generates private and public keys for users, and issues electronic certificates that link the public key to the owner (user) of the corresponding private key. In this embodiment, the credential signing device 1, as a user of the certification authority 7, has in advance received a credential signing key (private key), public key, and digital certificate (hereinafter referred to as "credential signing key, etc.") for each of the multiple existing credential types, and has stored them in the signing key DB. In addition, the credential signing device 1 has also in advance stored in the signing key DB a common signing key, public key, and digital certificate (hereinafter referred to as "common signing key, etc.") that are commonly used for digital signatures for uncredential users.

[0019] The timestamp server 8, based on a request from the credential signing device 1, assigns a timestamp to the credential signed electronic contract after it has undergone credential signing processing.

[0020] User terminals 91, 92, 93, ... are terminals used by contracting parties who enter into electronic contracts using witness-type electronic signatures provided by the qualified signature device 1, or by persons who verify the qualified signature electronic contracts. Furthermore, the following explanations common to user terminals 91, 92, and 93 will be collectively referred to as user terminal 9. The user terminal 9 is a computer that can connect to a communication network wirelessly or via a wired connection, and consists of, for example, a personal computer, smartphone, mobile phone, or game console. The user terminal 9 is equipped with a browser, a display device for displaying electronic contracts and the like provided by the credential signing device 1, and is configured to allow the use of short message service (SMS) and / or email using a telephone number. The user terminal 9 is also equipped with a touch panel and keyboard for performing various input operations in the credential signing process.

[0021] In Figure 1, user terminals 9 are shown as user terminal (qualified person) 91, user terminal (unqualified person) 92, and user terminal (verifier) ​​93. However, in reality, there are multiple terminals corresponding to the number of contracting parties who have accounts for electronic contracts with the qualified signature device 1, such as user terminal (administrator / qualified identity verifier) ​​94 shown in Figure 7. However, provided that at least one user (contracting party) has completed the registration of a qualified account, it is possible to perform qualified signature processing for electronic contracts where an unregistered party who has not registered an account is a contracting party.

[0022] The qualification signature device 1 comprises a qualification signature processing unit 2, a signature verification unit 3, an account registration unit 4, and a storage device 5, all of which are function implementation units. The storage device 5 stores various programs and data for implementing the functions of each of these function implementation units 2 to 4, including a template DB 54 and an account DB 55, which store templates for electronic contracts with specified signature restrictions, such as linked required qualifications and embedded required qualification signature forms in each signature field (details will be described later). The account registration unit 4 registers and updates user accounts (such as qualified and unqualified contracting parties, verifiers, and qualified administrators) in the account database 55 based on various registration information transmitted from user terminals 91 and above. The qualified signature processing unit 2 performs a witness-type qualified signature processing on the target electronic contract based on signature requests from, for example, a user (qualified person) on user terminal 91 and a user (unqualified person) on user terminal 92. The signature verification unit 3 receives verification requests for electronic contracts that have undergone qualified signature processing (hereinafter referred to as qualified signed electronic contracts) from, for example, a user terminal (verifier) ​​93 or a user terminal of a contracting party, and performs verification of the non-tampering of the qualified signed electronic contract and verification of the validity period of the qualifications of the contracting parties. Each device in Figure 1 that forms the credential signing system is capable of communicating via a communication network such as the Internet, while encrypted using SSL or TLS.

[0023] Figure 2 shows the hardware configuration that implements each function of the credential signing device 1 described in Figure 1. As shown in Figure 2, the credential signing device 1 consists of a CPU 11, ROM 12, RAM 13, storage device 5, communication control unit 14, and other devices connected by a bus line. The CPU 11 is a central processing unit that operates according to various programs stored in the storage device 5 and performs communication processing with external devices such as the list publishing server 6, the certification authority 7, the timestamp server 8, and the user terminal 9. Furthermore, CPU 11 functions as the credential signature processing unit 2 shown in Figure 1 by executing the credential signature processing PG (program) 50, functions as the signature verification unit 3 by executing the signature verification PG 51, and functions as the account registration unit 4 by executing the account registration PG 52.

[0024] ROM12 is a read-only memory that stores the basic programs and parameters necessary for the CPU11 to operate. RAM13 is a read / write memory that serves as working memory for the CPU11 when it performs electronic contract processing in this embodiment. For example, in the qualified signature processing, RAM13 stores the login ID of the qualified party to the contract, and the electronic contract at each processing stage until the qualified signature processing is completed. The communication control unit 14 performs communication processing with external devices such as the user terminal 9.

[0025] The storage device 5 is configured using one or more large-capacity storage media, such as a hard disk, and stores various programs such as the credential signature processing PG50, signature verification PG51, and account registration PG52 for the CPU 11 to perform the functions of this embodiment, as well as various data such as the template DB (database) 54, account DB 55, credential DB 56, signing key DB 57, and requested credential signature list 58. As mentioned above, the credential signature processing PG50, signature verification PG51, and account registration PG52 are programs that function as the credential signature processing unit 2, signature verification unit 3, and account registration unit 4, respectively, and the details of each process will be described later.

[0026] Template DB54 is used for electronic contracts involving dummy figures and stores templates for various contracts (including consent forms, oaths, pledges, etc.) that are subject to the qualified signature processing of this embodiment. The templates stored in Template DB54 include original electronic contract templates usable in various fields such as healthcare, architecture and civil engineering, public institutions, the judiciary, finance, and other situations. In this embodiment, template DB54 stores templates for various electronic contracts, categorized and saved according to predetermined industry types. However, it is also possible to store them according to other classifications, such as the Japan Standard Industrial Classification. Electronic contract templates are stored not only when created, collected, and stored by the operator of Qualified Signature Device 1, but also when created and uploaded by registered users, administrators, etc.

[0027] The various templates stored in template DB54 can be downloaded from the user terminal 91 of an account-registered user who has logged into the credential signing device 1. Furthermore, registered users can use electronic contracts stored in template DB54, as well as electronic contracts stored in external devices other than the Qualified Signature Device 1, or in their own devices, and have them authenticated by the Qualified Signature Device 1. In this case, the user terminal 9 uploads the electronic contract to be used to the Qualified Signature Device 1, which performs the authenticated signature process on it and, if necessary, saves the electronic contract before electronic signing to template DB54.

[0028] The templates for various contracts stored in Template DB54 include templates for Signature Restriction A (electronic contracts linked to required qualifications), Signature Restriction B (electronic contracts using a "required qualification signature form" in which qualification information restricting signatories is embedded in the signature field), and other electronic contract templates with specified signature restrictions. Furthermore, template DB54 also stores templates for electronic contracts that do not specify signature restrictions. For example, there are templates for electronic contracts where not all parties are required to be qualified. In addition, templates for electronic contracts from before signature restrictions were stipulated (hereinafter referred to as "unrestricted templates") are also stored. The unrestricted template is a template for retroactively adding signature restrictions based on required qualifications. Electronic contracts with signature restrictions are saved separately from the original unrestricted template as a new template.

[0029] Here, we will explain Signature Restriction A and Signature Restriction B, which limit electronic signatures to only those who are predetermined as qualified. Figure 3 conceptually represents the required qualifications signature list 58 for linking electronic contract templates based on required qualifications, using signature restriction A. This request qualification signature list 58 is stored in storage device 5 in Figure 2. As shown in Figure 3, the required qualification signature list 58 is managed for each "required qualification signature number (No)" and contains a required qualification list that defines the "electronic contract file name," which is the name of the electronic signature to be handled, and the qualifications required for each signature field of the electronic contract (Signature 1, Signature 2, ...). The electronic contract file name functions as a header when searching for the target electronic contract template.

[0030] In Signature Restriction A, the required qualification signature number is linked to the electronic contract template, thereby linking the required qualification list. Each signature field in the electronic contract is then limited to electronic signatures by persons possessing the linked qualifications (required qualifications). For example, if the required qualification signature number "01" for "Medical Consent Form 1" is linked to an electronic contract template, then, as specified in the required qualification list, the "Signature 2" field of the electronic contract will be linked to a doctor and the "Signature 3" field to a nurse. Only qualified individuals (doctors, nurses, etc.) who meet the required qualifications will be able to electronically sign, and signature requests from individuals other than those qualified will not be accepted. However, it may be possible to select the option to request signatures from individuals other than qualified individuals, but an error may be displayed if this is selected. When a user uses a template with associated required qualifications, the qualification signing device 1 controls the selection of a qualified signer based on the conditions of the required qualification signing list 58.

[0031] In this context, depending on the required qualifications, there may be qualifications that are in a higher or lower relationship. Therefore, when a required qualification is a lower-level qualification, it is also possible to specify the higher-level qualification as well. In such cases, under Signature Restriction A, if a lower-level qualification is specified as a required qualification in the "Signature x" field, it is possible to specify a higher-level qualification as well. For example, there are qualifications such as First-Class Architect, Second-Class Architect, and Wooden Structure Architect, listed in descending order of rank. And when requesting a "Wooden Structure Architect" in the "Signature x" field, it is possible to specify the higher-ranking qualifications, including First-Class Architect and Second-Class Architect. Similarly, since doctors are superior to nurses, if the required qualification is nursing, it is also possible to specify doctors in the "Signature x" field. On the other hand, similarly in the case of signature-only type B, which will be discussed later, it is possible to specify higher qualifications as well when requiring lower qualifications in the qualification requirement form embedded in each signature field of the electronic contract.

[0032] On the other hand, "Unqualified" in the "Signature 1" field under required qualification signature number "01" indicates that no specific qualification is associated with it. Therefore, persons other than those with the required qualifications specified in other signature fields, such as those without specific qualifications or those with other qualifications such as architects, can sign. In this unqualified signature field 1, a general signature will be made, as described later.

[0033] The required qualifications list 58 illustrated in Figure 3 shows the case where the required qualifications are specified for each signature field. However, it is also possible to specify, for example, that signatures from persons other than designated qualified persons are restricted, such as requiring at least one doctor and at least one nurse for signature fields 1 to N, and to specify the number of designated qualified persons. When the number of people is specified in this way, the qualified signature device 1 completes the witness-type electronic signature on the electronic contract on the condition that the electronic signatures of the specified number of qualified persons are made. The witness-type electronic signature remains incomplete until the electronic signatures of the specified number of people are made. If multiple consecutive signature fields, such as Signature 1 to Signature N, are designated with Qualification A, a qualified person possessing Qualification A can use any of the signature fields to electronically sign. If multiple individuals are designated with multiple required qualifications (for example, Qualification A, Qualification B) for Signature 1 to Signature N, then it becomes possible to electronically sign any of the signature fields using Qualification A and Qualification B.

[0034] If the desired list of required qualifications does not exist, a newly created list of required qualifications and its electronic contract file name can be added to the list of required qualification signatures 58. Alternatively, the contents of an existing list of required qualification signatures can be modified and added separately as a new list of required qualifications. When these additions are made, a new list of required qualification signatures will be assigned.

[0035] The timing of linking required qualifications can be as follows: sometimes the linking is done in advance when the template is created on the user's (qualified person or their administrator's) terminal or qualification signing device 1; and sometimes the linking is done retrospectively when an unlinked template is read from the template DB 54 of the qualification signing device 1 to the user's terminal and linked. In the case of retrospective linking, the linked template is saved as a new template in the template DB 54.

[0036] Next, I will explain signature restriction B. In Signature-Only B, a required qualification signature form is embedded in each signature field of the electronic contract, specifying the required qualifications (credential information). This excludes electronic signatures from persons who do not meet the specified required qualifications. The required qualification signature form is embedded for each signature field. The embedding of the required qualification signature form into each signature field may be done by the creator of the electronic contract (unrestricted template), or it may be done by a qualified person, their manager, or the operator of the qualification signature device 1, who has read the unrestricted template from template DB54. When an unrestricted template is retrieved from template DB54 and the required qualification signature form is embedded, it is saved in template DB54 as a new electronic contract template. When an electronic contract with an embedded request qualification signature form is acquired by the qualification signing device 1, for example when uploaded by a user or after embedded by the operator of the qualification signing device 1, it is electronically signed with the private key of the qualification signing device 1 and a timestamp is added. This prevents the request qualification from being altered by the embedded request qualification signature form, guarantees that the request qualification is correct, and provides proof of existence. However, it is also possible to save an electronic contract with an embedded required qualification signature form in template DB54 with only an electronic signature by qualification signature device 1, or with only a timestamp attached.

[0037] The following explains the electronic contract (template) before and after the inclusion of a required qualification signature form, using a surgical consent form created in PDF format as an example. Figure 4A shows an unrestricted template of the surgical consent form before the requirement for a specific qualification signature form was added. Figure 4B shows the display screen of a surgical consent form with the required qualifications signature form (signature restriction B) embedded in an unrestricted template. Figure 4C shows the display screen of the surgical consent form with electronic signature by the qualified signature device 1 and signature restriction B after timestamping.

[0038] As shown in Figure 4A, in the surgical consent form (unrestricted template) before the requirement qualification signature form was established, signature fields 401-403 for each contracting party are provided in the lower right corner. If a witness-type electronic signature is applied to the surgical consent form shown in Figure 4A, it is possible to estimate the required qualifications from the text and format of the electronic contract, such as the names of each signature field (patient name, doctor, explaining nurse), and determine whether they match the qualifications of the signatory. However, in this case, discrepancies may arise due to estimation errors, and a purely mechanical judgment cannot be made. Therefore, as shown in Figure 4B, form fields are provided for each signature field 401 to 403 of the surgical consent form (electronic contract), and a required qualification signature form specifying the corresponding required qualifications is embedded therein, so that electronic signature symbols 411 to 413 indicating that it is an area to be electronically signed by signature restriction B are displayed. For example, in signature field 402, the requested qualification signature form will contain "SYOMEI01@N001," which is the name of the form field "SYOMEI01" with the requested qualification code "N001" (see Figure 6) appended to it.

[0039] Each signature field 401-403, into which the required qualification signature form is embedded, displays the electronic signature symbols 411-413. Details of the required qualification signature forms corresponding to electronic signature symbols 411-413 can be found in the latter of the two unsigned fields 420b, which are reserved in the signature details section 420 on the right side of the screen (signature field 420a). For example, the details corresponding to the signature field 401 of the patient's name are displayed in the details field 421 of the unsigned field 420b, which shows "patient" and "Page:1," the page on which the signature field 401 is located. Furthermore, the details corresponding to the physician's signature field 402 are described in the details field 422 of the unsigned field 420b, which includes "@" indicating the embedding of the required qualification, the qualification code "N001" (see Figure 6) corresponding to the required qualification, the qualification name ""Physician", and the page on which the signature field 402 is located, "Page:1". Furthermore, the details corresponding to the signature field 403 of the explaining nurse are described in the details field 423 of the unsigned field 420b, which contains "@" indicating the embedding of the required qualification, the qualification code "N002" corresponding to the required qualification, the qualification name ""Nurse"", and the page on which the signature field 403 is located, "Page:1". Note that Figure 4B shows an electronic contract with the required qualification signature form embedded in each signature field 401-403, but no actual signatures have been made, so signature field 420a is blank.

[0040] By embedding the required qualification signature form into each signature field of the electronic contract using signature restriction B, the qualification signature device 1 can mechanically and reliably determine whether the qualifications held by the signatory match or not with the required qualifications specified in the required qualification signature form. In other words, when the qualified signature device 1 adds a witness-type electronic signature, it verifies that the required qualification "N001" is specified after the "@" in the embedded required qualification signature form, and then mechanically determines whether the account (signer) has the corresponding qualification (in this case, a doctor) before authorizing the electronic signature.

[0041] When an electronic contract with the required qualification signature form embedded in each signature field 401-403 is uploaded to the qualification signature device 1, or when the operator of the qualification signature device 1 has finished embedding the required qualification signature form, the qualification signature device 1 applies an electronic signature and timestamp using its private key and saves it as a new electronic contract template in the template DB 54. In this electronic contract (surgical consent form) with signature restriction B after electronic signature and timestamping, as shown in Figure 4C, a signature panel 450 indicating that it has been electronically signed by the qualified signature device 1 is displayed at the top of the surgical consent form. Regarding the presence of a timestamp, you can check the details from the electronic signature panel (not shown) displayed on the left side of the screen by clicking on signature panel 450. Furthermore, once the electronic signature is performed by the qualified signature device 1, the signature field 420a of the signature details section 420 will display the name and email address of the representative of the qualified signature device 1. After digital signature and timestamping, the electronic contract with the required qualification signature form embedded is saved in template DB54 as a template for new electronic contracts.

[0042] Figure 4D shows the screen during the process of a witness-type electronic contract using the qualified signature device 1, where an electronic contract with signature restriction B (surgical consent form) is read from template DB54, and the qualified signature is made by the physician who is the required qualified person. As shown in Figure 4D, after the physician's qualified signature corresponding to the required qualifications of the required qualification signature form embedded in signature field 402 is completed, the physician's name, who is the signatory, is displayed in signature field 402 instead of the electronic signature symbol 412 that was displayed before the signature. In other words, signature field 402 displays the signatory's "name," "@," "qualification code," and "qualification name," as well as the date and time of signing. Furthermore, since the physician has completed the qualification signature, the details field 422 of the unsigned field 420b corresponding to the signature field 402 is deleted, and the physician's signature content "Name + @ + Qualification Number + Qualification Name" is entered in the signature field 420a.

[0043] Returning to Figure 2, the signature key DB57 stores the credential signing keys and common signing keys issued by the certification authority 7, corresponding to various qualifications. Multiple credential signing keys (credential signing keys and digital certificates) and common signing keys are managed using predetermined signing key numbers. Each qualified signing key's digital certificate records the subject, subject alias, or policy OID. This allows the digital certifier to verify that the user (contractor) entering into the electronic contract with the dummy possesses the necessary qualifications, such as a doctor or architect, and that the electronic signature is based on those qualifications.

[0044] Account DB55 stores various information about users and others through the account registration process. Account registration is required of users such as contracting parties and verifiers in order to have the authority to use the credential signing service provided by credential signing device 1. Figure 5 conceptually represents the contents stored in account DB55. As shown in Figure 5, the account DB 55 stores an account table 551, a qualified / identity verification information table 552, and a file table 553 for each user, and is managed by an ID set for each user.

[0045] The account table 551 stores basic information necessary to identify accounts of users who have the required qualifications (register their qualifications) and users who do not have the qualifications (do not register), including a user ID, a password (PW) required along with the ID when logging into the qualification signing device 1, the user's name, the name of their affiliated organization (optional item if applicable), an email address, and a phone number used for short message service (SMS).

[0046] Table 552 of the Eligibility and Identity Verification Information Table stores identity verification information 5521 and identity verification document data 5522, qualification verification information 5523 and qualification verification document data 5524, and qualification code 5525. Identity verification information 5521 and identity verification document data 5522 are data that identifies (shows) the user and data about the documents used for identity verification. The qualification verification information 5523 and qualification verification document data 5524 are data that indicates (identifies) the qualification if the user is a qualified person (only if they wish to register that qualification (including at the time of electronic signature as well as registration)) and data about the documents used for qualification verification.

[0047] Identity verification information 5521 contains information used to identify (verify) the user who has registered an account, and includes address, name, gender, date of birth, place of origin, age, telephone number, identity verifier ID, and identity verification method. It is also possible to include other information such as the user's email address and data stored in the IC chip used to verify their identity in identity verification information 5521. The identity verification ID is the ID of the person who verified the user's identity according to the identity verification document data 5522, and the identity verification method indicates how that verification was performed. This identity verification ID functions as identifying information for the person who verified the identity. The person who verified the identity (identity verifier) ​​may be the operator of the Qualified Signature Device 1, the organization to which the individual belongs (for example, the corporation to which the individual belongs), or a third-party auditing organization, and the identifying information for the verifier includes the ID and name of the qualified signature device.

[0048] Identity verification document data 5522 is data related to the documents used (requested for submission) by the identity verifier when verifying the user's identity. Examples of identification documents used include resident registration certificates, driver's licenses, and My Number cards. The identity verification document data 5522 stores information such as the document name, scanned image, category, identification number, and expiration date (next scheduled verification date) of the identity verification document. The expiration date is the one specified (stated) on the identification document. If no expiration date is specified, an expiration date (the next scheduled verification date) calculated from the date and time of this action may be set as necessary.

[0049] Eligibility verification information 5523 is used to confirm that a user who has registered an account is eligible, and it stores the user's address, name, gender, date of birth, place of origin, age, telephone number, eligibility verifier ID, and eligibility verification method. The Qualification Verifier ID is the identification number of the person who verified that the user possesses valid qualifications according to the qualification verification document data 5524. This Qualification Verifier ID functions as identifying information for the person who verified the qualifications of the qualified person. The person who verified the qualifications (Qualification Verifier) ​​may be the operator of the Qualification Signature Device 1, the organization to which the qualified person belongs (for example, the hospital to which the qualified doctor belongs), or a third-party auditing organization, and the identifying information includes the ID and name of the Qualification Verifier. The qualification verification method indicates how the qualification verifier performed the verification. The specific method of qualification verification is carried out in accordance with the regulations for each qualification predetermined in the qualification DB56 qualification verification method shown in Figure 6 below, or in accordance with the regulations of laws and guidelines if applicable. The qualifications that can be verified include national and private qualifications, enrollment in social insurance or national health insurance, or having nationality or residence status. The qualifications that can be registered are specified in Qualification DB56 shown in Figure 6.

[0050] Qualification verification document data 5524 contains data related to the documents used (requested to be submitted) by the qualification verifier when verifying the user's qualifications. Examples of documents that can be used to verify qualifications include, for example, copies of medical license certificates, copies of nursing license certificates, driver's licenses, and IC chips on My Number cards that record qualifications.

[0051] While each qualified individual may submit their own qualification verification documents, a qualification verification list created by a representative of multiple qualified individuals, such as a hospital director or other administrator, after verifying the qualifications of qualified individuals (doctors, nurses, etc.) belonging to that hospital (which must include the administrator's signature and seal, and a record of the verification date) is also acceptable. Furthermore, it includes a qualification verification list that compiles multiple different qualifications, such as those of lawyers, patent attorneys, and administrative scriveners belonging to a designated general practice firm. In this case, the qualification verification list should, in principle, be submitted in writing, but it is also possible to submit it as electronic data with the administrator's electronic signature in lieu of a signature and seal.

[0052] The qualification verification document data 5524 stores the document name, scanned image, category, identification number, and expiration date (next scheduled verification date) of the qualification verification document. The expiration date is the one specified (stated) in the qualification verification document. If no expiration date is specified, an expiration date (the next scheduled verification date) calculated from the date and time of this action may be set as necessary.

[0053] Qualification code 5525 stores the qualification code corresponding to the qualification name of the qualified person who registered the account, and is read and stored from qualification DB56 (described later in Figure 6). If a user has multiple qualifications, multiple qualification codes will be stored.

[0054] File table 553 stores files to be digitally signed and digitally signed files, associated with the ID of each account. A file subject to digital signature is a file to which a certified signature or similar process is performed. For digitally signed files stored here, it is possible to grant different permissions for operation, viewing, and access to each ID within the same organization (for example, the hospital, company, or workplace to which the user of that ID belongs). The electronically signed file stores the electronic contract file (certified electronic contract) after the certified signature processing (and timestamping) according to this embodiment has been performed. In other words, when certified signature processing according to this embodiment is performed between user A and user B, the certified electronic contract is stored in the electronic signature target file associated with user A's ID, and also in the electronic signature target file associated with user B's ID. Electronic contracts that have undergone the credential signing process and are saved in the electronically signed file include not only electronic contracts read from template DB54, but also electronic contracts read by contracting parties from other devices.

[0055] Of the specific information that identifies the user and their qualifications, stored in the account table 551 and the qualified / identity verification information table 552, the following data (a) to (g) are recorded as attribute information to be hashed in the qualification signature process. (a) ID, email address, and phone number (SMS) from account table 551 (b) Identity verification information 5521: Identity verification ID and identity verification method (c) Document name, category, identification number, and expiration date of identity verification document data 5522 (d) Qualification verification information 5523: Qualification verifier ID, qualification verification method, (e) Document name, category, identification number, and expiration date of qualification verification document data 5524 (f) Qualification code for qualification code 5525 (g) The qualification name, location of the qualification comparison table, and method of verifying the identity of the qualified person, which are stored in the qualification DB56 corresponding to the qualification code. However, of these specific pieces of information, other than (a) the ID, email address, and phone number (SMS) in account table 551, it is not necessary to record all of the credential information that can verify the user's (qualified person's) qualifications in the attribute information (reason for electronic signature); it is sufficient to record at least one. For example, one such piece of information could be the qualification code 5525 or the qualification name. This allows contracting parties and third parties to verify, through attribute information, that an electronic contract that has been processed with a qualified signature by the qualified signature device 1 is a contract made by at least one qualified person. Furthermore, the attribute information for the credential signature may store either the verifier ID and the verification method from (b), and either the credential verifier ID and the verification method from (d).

[0056] Furthermore, for electronic signatures for users who do not possess the necessary qualifications (non-qualified individuals) or users who possess the qualifications but do not wish to use their own qualifications for their signature, (a) the ID, email address, and telephone number (SMS) from account table 551 will be recorded in the attribute information (reason for electronic signature).

[0057] Returning to Figure 2, the qualification DB56 is a database of qualifications specified as targets for qualification signing processing according to this embodiment. Figure 6 conceptually represents the contents stored in the qualification DB56. As shown in Figure 6, the qualification DB56 stores information such as the qualification name, qualification code, method of verifying the identity of the qualified person, location of the qualification comparison table, and location of the qualification signing key, etc. A qualification name is a name that represents a qualification, and examples include doctor, financial planner, and Japanese citizenship. The qualification code is a regular set of letters, numbers, symbols, and signs that are uniquely assigned to each qualification and are subject to storage for qualification code 5525. For example, as shown in Figure 6, the qualification codes for doctors ("N001"), nurses ("N002"), and so on are defined and stored.

[0058] The method for verifying the identity of qualified individuals is specified for each qualification code. The following (a) to (d) and other various methods are stipulated as examples of specific methods prescribed in the Act on Verification of the Identity of Qualified Persons. For each qualification, one or more verification methods are specified for the verification of the identity of qualified persons. The method used when actually verifying the identity of a qualified person is stored in the qualification verification method section of the qualification verification information 5523 in the qualification / identity verification information table 552. (i) In person, the required documents (copy of professional license (medical license in the case of a doctor), copy of resident registration, email address, telephone number / professional license and photo ID) will be presented. (b) Conduct official personal authentication remotely using eKYC (electronic Know Your Customer). (h) The organization's representative (for example, the hospital director) shall verify the qualifications and identities of the qualified persons belonging to the organization, and submit a list containing the personal information and qualification information (name, address, gender, date of birth, qualification name, qualification code, etc.) of the qualified persons, along with a copy of their qualification certificate, on paper. (ii) The operator of the Qualification Signature Device 1 (verification officer) verifies the documents submitted by the qualified person (copy of qualification certificate and copy of identification card). During verification, the "qualification verification information" is read from the identification card, etc., and introduced to an external database to confirm that the qualified person actually exists.

[0059] The location of the qualification comparison table is the URI (Uniform Resource Identifier) ​​of the qualification comparison table 61 that is made publicly available on the internet by the list publication server 6. The location of the credential signing keys, etc., is the address where the credential signing key and its digital certificate used for digital signatures corresponding to each credential code are stored, and the address where the common signing key and its digital certificate are stored. In this embodiment, the list publishing server 6 classifies the qualification comparison table 61 according to a predetermined qualification (for example, medical-related, legal-related, construction-related, etc.), and publishes the qualification comparison table 61 for each classification. For this reason, different URIs are defined for each classification in the qualification DB 56 where the qualification comparison table is located. However, it is also possible to combine all qualifications into one qualification comparison table 61, and accordingly define the same URI for the location of the qualification comparison table in the qualification DB 56.

[0060] Next, we will explain the various processing operations performed by the credential signing system using the credential signing device 1. Figure 7 is a flowchart illustrating the flow of the account registration process using the credential signing system. This account registration process is a process that registers each user's account as a prerequisite for performing the credential signing process according to this embodiment. In the credential signing device 1, this is done by the CPU 11 executing the account registration PG52 in the storage device 5. In the following description, the processes performed by the CPU 11 executing various programs will be described as the operation of the credential signing device 1 (the same applies to the user terminal 9). Figure 7 illustrates an example of account registration, specifically the account registration process for hospitals. It describes the account registration process from the user terminal 91 of a physician (qualified person) belonging to a designated hospital, the user terminal 94 of the hospital administrator (qualified identity verifier), and the user terminal 92 of a patient (unqualified person).

[0061] As shown in Figure 7, when a patient who is not qualified registers an account, the patient submits their identification document, such as a resident registration certificate, My Number card, or driver's license, as registration information to the qualified signature device 1 from the patient's user terminal 92 (step 921).

[0062] On the other hand, when a qualified physician registers an account, they submit their physician's license, which serves as proof of their qualifications, along with identification documents such as a resident registration certificate, My Number card, or driver's license, as registration information to the qualification signature device 1 or the administrator (step 911). Furthermore, if registration information is submitted to the administrator instead of the qualification signature device 1, the physician's account will be submitted to the qualification signature device 1 from the user terminal 94 along with other qualified individuals, based on an identity verification list created by the administrator, rather than from the physician's own user terminal 91.

[0063] In other words, the administrator receives the qualification certificates and identification documents from doctors, nurses, physical therapists, occupational therapists, etc., who belong to the organization they manage (in this case, the hospital), and verifies their qualifications and identity (Step 941). Then, the administrator's user terminal 94 collects all submitted qualification certificates and identity verification documents to create a list of qualified and identity verification information, and saves it to the database of the user terminal 94 or the hospital to which the user belongs (step 942). The list of qualified and verified information created here is a list of the contents of account table 551 and qualified and verified information table 552, excluding the ID.

[0064] The administrator then records their own signature and seal, the verification date, etc., on the created list of qualified and verified information, and submits it to the qualified signature device 1 (step 943). In addition to submitting the list of qualified and verified information as a PDF file attached to an email, submission is possible through various other methods. Details will be explained in the processing section for user terminal 92.

[0065] When registration information is submitted by the user terminal 9 or its user, the credentials signing device 1 acquires it (step 101). Here, there are various patterns for submitting and obtaining registration information, as follows: (i) When a non-qualified person, a qualified person, or an administrator submits registration information in physical media (copies, printed materials) or data (by mail, email attachment, upload, etc.) and the qualification signature device 1 receives it. (b) When the user accesses the account registration screen of the credential signing device 1 from the user terminal 9 and enters each item of registration information.

[0066] If the acquired registration information includes a qualification such as a qualification name, the qualification signing device 1 refers to the qualification comparison table 61 on the list publishing server 6 and obtains the qualification code corresponding to the qualification (step 102). The qualification signature device 1 then determines whether a qualification code corresponding to the qualification included in the registration information exists (step 103). If the qualification code does not exist (step 103; N), it sends an error in the registration information to the corresponding user terminal 9 (step 104). If the registration information is submitted by mail or other means instead of from the user terminal 9, the device notifies the user who sent the information of the postal error.

[0067] If the registration information is for an unqualified person, or if a qualification code corresponding to the qualification included in the registration information exists (step 103; Y), the qualification signing device 1 verifies the contents of the registration information (including identity verification), assigns an ID to each account, and saves it to the account DB 55 (step 105). In other words, if the registration information is for an unqualified person, the operator of the qualification signature device 1 checks the contents of the registration information obtained and saves it to the account table 551. On the other hand, if the registration information is from a qualified individual, the operator of the qualification signature device 1 verifies the contents of the registration information (including identity verification and qualification verification) and stores it in the account table 551 and the qualified / identity verification information table 552. Furthermore, if the information is registration information from the administrator (eligible person / identity verification information list), the details for each eligible person listed are checked, and an ID is assigned to each eligible person before saving them in account table 551 and eligibility / identity verification information table 552. Furthermore, for qualification code 5525 in the qualified / identity verification information table 552, the qualification code obtained in step 102 will be stored.

[0068] The following methods can be used to verify and save registration information. In other words, the operator of the credentials signing device 1 verifies, inputs, and saves the contents of the submitted physical media. In addition, users may enter information into an account registration input form provided by the credential signing device 1 from their user terminal 9, and the operator may verify and save that information. In this case, it is possible to automatically register an account using only online identity verification (eKYC).

[0069] The above describes how to register an account in the credential signing device 1. The process is similar when updating (modifying or adding) an already registered account. However, when updating, since an account already exists, the user must submit registration information that includes the account and any information to be corrected or added. If the acquired registration information contains an account, the credential signing device 1 determines it to be an update request and updates the contents of that account.

[0070] Once account registration / renewal is complete, the credential signing device 1 notifies the user of the account of the registration / renewal (step 106) and terminates the process.

[0071] Next, we will explain the process of authorized signing of electronic contracts by registered users. Figure 8 is a flowchart showing part of the credential signing process by the credential signing system, and Figure 9 is a flowchart showing the continuation of that process. Figures 8 and 9 illustrate an example of an electronic contract using a mannequin between a qualified person (doctor) and an unqualified person (patient), where the user terminals 91 and 92 and the qualified signature device 1 perform qualified signature processing on a surgical consent form (electronic contract) with signature restriction A or signature restriction B. It is assumed that both the doctor and the patient have completed account registration.

[0072] As shown in Figure 8, the doctor logs in to the electronic signature service provided by the credential signing device 1 from the user terminal 91 (step 912). In other words, the doctor opens the login screen for the electronic signature service on the user terminal 91, enters their account ID and password (PW), and sends them to the credential signing device 1.

[0073] When the credential signing device 1 receives the ID and PW sent from the user terminal (doctor) 91, it checks whether they are already registered in the account DB 55 and performs login authentication (step 110). Furthermore, once login authentication is complete, the credentials signing device 1 notifies the user terminal (doctor) 91 of this fact and temporarily stores the ID of the logged-in doctor in RAM 13. On the other hand, if at least one of the ID or password is not registered, a login error is returned to the user terminal (doctor) 91.

[0074] Once the user terminal (doctor) 91 completes the login to the electronic signature service, it uploads or retrieves the electronic contract with signature restriction that is the subject of the electronic contract and displays it on the screen (step 913). Here, the target is a surgical consent form with signature restriction A, which is linked to required qualification signature number 01 (see Figure 3) as shown in Figure 4A, or a surgical consent form with signature restriction B, as shown in Figure 4C (after electronic signature by qualification signature device 1).

[0075] In other words, the user terminal (doctor) 91 reads a surgical consent form that is stored in its own device or in a designated storage device managed by the hospital and has one of the signature restrictions, and uploads it to the qualified signature device 1 as the surgical consent form subject to this qualified signature processing. On the other hand, if the user terminal (doctor) 91 does not use the surgical document stored in its own device or the hospital's management storage device, the user terminal (doctor) 91 accesses the template DB 54 stored in the storage device 5 of the qualification signature device 1 and retrieves the desired surgical consent form.

[0076] When a surgical consent form is uploaded from the user terminal (doctor) 91, the credentials signing device 1 applies an electronic signature and timestamp to the surgical consent form using the credentials signing device 1's private key, and then saves it to the electronically signed file in the file table 553 corresponding to the doctor's ID. Alternatively, with the doctor's consent, it may be saved to the template DB 54. On the other hand, if a surgical consent form is requested via access, the qualified signature device 1 reads the corresponding surgical consent form template (electronic contract) from the template DB 54 and provides it to the user terminal (doctor) 91 (step 111).

[0077] Figure 10 shows the display screen of the surgical consent form file as it appears on the user terminal (doctor) 91. The surgical consent form file shown in Figure 10 is, for example, a surgical consent form file that was created and saved in advance within the hospital where the doctor works. As shown in Figure 10, the display screen for the surgical consent form file shows fields such as the format field 801, thumbnail field 802, internal management field 803, recipient field 804, and signature selection button 809. Form field 801 records the file name "Surgical Consent Form 11.pdf," along with its expiration date, date and time of transmission, and sender. In the example in Figure 10, the sender field indicates that it was created by "Takumi Fuko," an office worker at the Memorial Hospital. Thumbnail field 802 displays a thumbnail image linked to the "surgical consent form" that is subject to the qualified signature processing. The contracting parties, such as doctors and patients, will click on this thumbnail image to view the contents of the surgical consent form (see Figures 4A to 4C) and then consent to the electronic signature by the qualified signature device 1.

[0078] Internal management section 803 is where the management information created within the hospital is recorded. The recipient field 804 records the names of the contracting parties under this surgical consent form (Dr. Itataro, Outpatient Masao) and the address to which each surgical consent form will be sent. The signature selection button 809 displays a screen for selecting the type of electronic signature (general, qualified, etc.) for the surgical consent form. This signature selection button 809 can only be selected by the user after selecting the thumbnail field 802 to view and confirm the linked surgical consent form.

[0079] Figure 11 shows the electronic signature selection screen that appears when the signature selection button 809 is selected. The electronic signature selection screen functions as an electronic signature request form in which a contracting party requests a qualified signature from qualified signing device 1. As shown in Figure 11, the electronic signature selection screen displays the signature qualification selection field 901, the qualified signature request button 909, and other elements. The signature qualification selection field 901 specifies the following signature forms that can be selected in relation to the contract (surgical consent form): a general signature without a qualification signature, a qualification signature (Japanese national), a qualification signature (physician), a qualification signature (dentist), etc. The qualified signature request button 909 is a button that requests the qualified signature device 1 to provide an electronic signature corresponding to one of the selected signature formats.

[0080] Here, the user terminal (physician) 91 determines whether the user's qualifications (physician) match any of the required qualifications specified in the signature-only section of the surgical consent form, that is, whether the required qualifications corresponding to the user's qualifications (physician) are specified in the signature-only section of the surgical consent form (hereinafter referred to as "match determination"). If they are not specified, an error is output; if they are specified (match), only the corresponding signature field is displayed as selectable. In this case, since the processing is being done by a qualified person (physician), as shown in Figure 11, only the qualified signature (physician) field is activated and selectable, and is displayed in a darker color, while the general signature field and other qualified signature fields are deactivated and cannot be selected, and are displayed in a lighter color.

[0081] In this embodiment, the user terminal (doctor) 91 performs the determination of whether the user qualifications match the qualifications required for the surgical consent form, and creates an electronic signature selection screen (see Figure 11) in which only the relevant qualification signature field or general signature field is activated (selectable). However, these steps may be performed by the qualification signature device 1. In this case, the user terminal (doctor) 91 sends a message to the credential signing device 1 indicating that the signature selection button 809 has been selected. The credential signing device 1 then checks for a match between the logged-in doctor's ID, which is temporarily stored in RAM 13, and the eligibility restrictions on the surgical consent form. If a match is found, it creates the electronic signature selection screen shown in Figure 11 and sends it to the user terminal (doctor) 91.

[0082] Returning to Figure 8, the user terminal (doctor) 91 designates users other than doctors (patients, nurses) for the surgical consent form (step 914). In other words, the doctor enters the name, recipient, patient's name, and recipient's name in the recipient field 804. However, this step 914 can be omitted if it has already been filled in by the creator of the file, as shown in the surgical consent form file in Figure 10.

[0083] Next, the user terminal (doctor) 91 clicks the thumbnail image in the thumbnail column 802 to display the "Surgical Consent Form". Specifically, clicking the thumbnail image displays the surgical consent form shown in Figure 4A if signature restriction A is selected, and the surgical consent form shown in Figure 4C if signature restriction B is selected. The user, a physician, confirms the contents of the surgical consent form displayed on the user terminal (physician) 91 and enters their name in the signature field 402 (see Figures 4A and 4C) within the surgical consent form (confirms the name if it has already been entered by the creator).

[0084] In this embodiment, we have used a surgical consent form with signature restrictions A and B as an example. However, as another type of signature restriction, if the required qualifications are described in a script for an electronic contract such as a surgical consent form, it is also possible to display a signature selection screen so that the user can only select to sign for the types of qualifications described.

[0085] Subsequently, the doctor selects the signature selection button 809 (see Figure 10) displayed on the user terminal (doctor) 91 screen to display the electronic signature selection screen (see Figure 11). Here, as mentioned above, based on the signature restriction (Signature Restriction A or Signature Restriction B), only the Qualified Signature (Physician) field is activated and selectable. Therefore, the user (doctor) selects the option by checking the checkbox in the "Qualification Signature (Doctor)" field. As a result, the user terminal (doctor) 91 transmits to the credential signing device 1 that "credential signing (doctor)" has been selected (step 915).

[0086] When "Qualified Signature (Physician)" is notified from the user terminal (physician) 91, the qualified signature device 1 queries the qualified code associated with the ID (step 112). In other words, the credential signing device 1 reads the ID stored in RAM 13 in step 110, compares the qualification identified by the credential code 5525 (see Figure 5) associated with this ID with the qualification based on the notified signature format (in this case, a doctor), and mechanically determines whether the two match. If they match, it returns confirmation information to the user terminal (doctor) 91; otherwise, it returns mismatch information. If the user terminal (doctor) 91 receives confirmation information, it will enable the selection of the credential signature request button 909 shown in Figure 11. If mismatched information is returned, a message to that effect will be displayed on the screen, and the user will need to change to a different credential signature format.

[0087] When the physician selects the now-selectable qualified signature request button 909, the user terminal (physician) 91 sends a request for an electronic signature by that qualified person to the qualified signature device 1 (step 916), and the qualified signature device 1 receives the request for an electronic signature (step 113).

[0088] The qualification signing device 1 then checks the expiration date of the qualification corresponding to the physician's ID stored in RAM 13 (step 114). In other words, the credentials signing device 1 determines that the document is still valid if the expiration date stored in the credentials verification document data 5524 corresponding to the ID is later than the current date. Furthermore, the system may be configured to consider the item as still valid if the expiration date is at least a predetermined period T away from the current date. While the predetermined period T is arbitrary, a default period of, for example, one month is set. If the qualification has expired (step 114; N), the qualification signing device 1 sends an error screen (expired) to the user terminal (doctor) 91 (step 115), and the user terminal (doctor) 91 notifies the doctor that the qualification has expired based on the error screen.

[0089] On the other hand, if the qualification is still valid (Step 114; Y), the qualification signing device 1 creates attribute information to be attached to the surgical consent form (Step 116). In other words, the qualified signature device 1 refers to the account DB 55 corresponding to the ID of the doctor to whom the signature request has been made, reads each of the above-mentioned data (a) to (g) from the account table 551 and the qualified / identity verification information table 552, and creates attribute information to be attached to the surgical consent form.

[0090] Subsequently, the qualified signing device 1 performs qualified signing to create a "primary signed electronic contract" (step 117). In other words, the credential signing device 1 looks up the location of the credential signing key etc. from the credential code 5525 of the credential (doctor) corresponding to the signature format notified by the user terminal (doctor) 91 in step 915, reads the credential signing key etc. for the credential (doctor) (credential signing key and digital certificate) from the signing key DB 57, temporarily stores it in RAM 13, and performs credential signing using the credential signing key etc.

[0091] Figure 12 is a conceptual diagram illustrating the structure of an electronically signed contract after it has been signed by a qualified professional. Note that Figure 12 does not depict a specific surgical consent form, but rather a more general representation of the structure of an electronic contract (including a surgical consent form) between parties A and B after it has been signed by a qualified professional. The following explanation of the credential signing process using the credential signing key, etc., in Step 117 will be provided with reference to Figure 12. The Qualified Signature Device 1 attaches the attribute information 122 of Contractor A (Doctor) created in step 116 to the "Electronic Contract (Original) 120" (Surgical Consent Form) to create the "First Electronic Contract" 123, and calculates the hash value 124 of this First Electronic Contract.

[0092] Furthermore, the credential signing device 1 uses the credential signing key (private key) corresponding to the signature format (credential signing (doctor)) notified by the user terminal (doctor) 91 in step 915, and calculates a signature value 125 by encrypting the calculated hash value 124. The qualified signature device 1 creates a "primary signed electronic contract" 127 based on the request of party A (qualified signature (doctor)) by embedding the calculated signature value 125 and the "electronic certificate" 126 corresponding to the qualified signature key used into the "first electronic contract" 123. Note that while the "Primary Signature Electronic Contract" 127 embeds an electronic certificate, it is also acceptable to embed both the electronic certificate and its revocation information. If the revocation information is not embedded, it will be necessary to check whether the electronic certificate has expired from the revocation information of the certification authority 7, which issued the electronic certificate.

[0093] Returning to Figure 8, after the qualification signature (step 117) based on the user's (doctor's) request is completed, the qualification signature device 1 sends a qualification signature completion screen to the user terminal (doctor) 91 that requested the qualification signature (step 118). Meanwhile, the user terminal (doctor) 91 displays the received qualification signature completion screen to notify the user (doctor) (step 917).

[0094] Next, the qualified signature (by the nurse) is performed on the "Primary Signature Electronic Contract" 127 using the qualified signing key (private key) corresponding to Hanako Iida, a nurse, who is specified as the second signatory in the recipient column 804 of Figure 10. The process of obtaining a qualified signature (nurse) for this "primary signed electronic contract" 127 is carried out in the same manner as the process of obtaining a qualified signature (doctor) for the "electronic contract (original) 120" (surgical consent form), so the outline is explained below. In other words, after the qualified signature process (physician) is completed, the qualified signature device 1 sends a URL containing the "primary signed electronic contract" 127 to the email address of the nurse's user terminal (nurse) 91, prompting confirmation and a request for electronic signature. Here, the email address used is that of Hanako Itai, the user (nurse) specified in the recipient field 804 of Figure 10. Upon receiving a request for an electronic signature via email, the user (nurse) accesses the specified URL from the user terminal (nurse) 91 to display the "Primary Signature Electronic Contract" 127 on the screen. At this time, the user (nurse) enters their ID and password, and the qualified signature device 1 performs login authentication in the same manner as in the case of a doctor (step 110). Subsequently, similar to the case of a physician, the user terminal (nurse) 91 of the nurse is processed in the same way as in steps 914-917, and the credentials signing device 1 is processed in the same way as in steps 112-118.

[0095] Next, the user (patient), who is specified as the third signatory in the recipient column 804 of Figure 10, will perform a general signature on the "Primary Signature Electronic Contract No. 2" using the shared key (private key). In this embodiment, since the user's (patient's) electronic signature is specified as the third item, "Primary Signature Electronic Contract No. 2" is the document to be signed. In contrast, if other qualified individuals are specified as required qualifications, and the user (patient = unqualified person) is specified as the fourth signatory, then "Primary Signature Electronic Contract No. 3" will be subject to general signature by the user (patient). Furthermore, if the required qualified person is a physician and the user (patient) is designated as the second signatory, then the "primary signature electronic contract" 127 will be subject to general signature by the user (patient). Therefore, the following explanation will focus on the case where there is only one qualified applicant, the user (patient) is designated as the second signatory, and the "Primary Signature Electronic Contract" 127 is subject to general signature.

[0096] As shown in Figure 9, the qualified signature device 1 presents the "primary signed electronic contract" 127 to the user terminal (patient) 92 of the user (patient) who is an unsigned contracting party (step 119), and the user terminal 92 displays this on its screen (step 922). In other words, the qualified signature device 1 sends an SMS to the user's (patient's) phone number containing a URL where the "primary signed electronic contract" 127 is stored, prompting the user to confirm it and request an electronic signature. Here, the phone number used for the SMS is that of Masao Nagai, the user (patient) specified in the recipient field 804 of Figure 10. If this recipient field 804 is not specified, the phone number of the user, etc., specified by the user terminal (doctor) 91 in step 914 is used.

[0097] Upon receiving a request for an electronic signature via SMS, the user (patient) accesses the specified URL from their terminal (patient) 92. After entering their ID and password and being authenticated, the "Primary Signature Electronic Contract" 127 is displayed on the screen (step 922). For the "Primary Signature Electronic Contract" 127 displayed on the screen, the user (patient), like the user (doctor), clicks the thumbnail image in the thumbnail column 802 (Figure 10) to display the "Surgical Consent Form" and confirms its contents. Then, the patient enters their name in the signature column 401 (see Figures 4A and 4C) within the surgical consent form (confirming the name if it has already been entered by the creator). Furthermore, the patient selects the signature selection button 809 to display the electronic signature selection screen. On this electronic signature selection screen, since the user (patient) is determined not to be a qualified person based on their ID, only the general signature field is activated and selectable, unlike in Figure 11 where only the qualified signature (doctor) field is activated. The user (patient) selects their option by checking the checkbox in the general signature field. If a general signature is selected, the credential code verification by the credential signing device 1 (step 112) is unnecessary, so the credential signing device 1 makes the credential signing request button 909 selectable. When the user (patient) selects the credential signature request button 909, the user terminal (patient) 92 requests a general signature from the credential signature device 1 (step 924).

[0098] When the qualified signature device 1 receives an electronic signature request from the user terminal (patient) 92, it creates attribute information to be attached to the "primary signature electronic contract" 127, which includes the surgical consent form (step 120). In other words, since the request for an electronic signature is a general signature, the qualified signature device 1 refers to the account DB 55 corresponding to the user's (patient's) ID, reads the ID, email address, and phone number (SMS) from the account table 551, and creates attribute information.

[0099] Then, the credential signing device 1 reads the common signing key from the common key DB 58 and performs a general signature (step 121). In other words, as shown in Figure 12, the qualified signature device 1 attaches the attribute information (attribute information of contractor B) created to the "primary signed electronic contract" 127 to create the "second electronic contract" 132, calculates the hash value 133 of this "second electronic contract" 132, and encrypts it with a common signing key to calculate the signature value 134. The qualified signature device 1 embeds the calculated signature value 134 and the "electronic certificate" 135 corresponding to the common signing key into the "second electronic contract" 132, thereby creating a "qualified signature electronic contract" 136 based on the requests of the doctor (party A) and the patient (party B). In addition, revocation information can also be embedded along with the electronic certificate 135, similar to the case of qualified signatures.

[0100] At this stage, the authorized signature device 1 sends a general signature completion screen to the user terminal (patient) 92 indicating that the general signature based on the patient's request has been completed (step 122), and the user terminal (patient) 92 displays the received general signature completion screen to notify the user (patient) (step 925).

[0101] The qualified signing device 1 further requests the timestamp server 8 to apply a timestamp to the "qualified signed electronic contract" 136, thereby creating a "qualified signed electronic contract (TS)" 138 (step 123). Then, the "Qualified Signature Electronic Contract (TS)" 138 is saved with a predetermined signature management number attached to the electronically signed file in the file table 553 of the two parties in the account DB 55 associated with the ID of the user (doctor) who performed the qualified signature and the ID of the user (patient), and is transmitted to the user terminal (doctor) 91 and the user terminal (patient) 92 (step 124), thus ending the qualified signature process. Meanwhile, the user terminal (doctor) 91 and the user terminal (patient) 92 display the received "certified electronic contract (TS)" 138 on their screens. After the doctor and patient confirm it, they save it to a designated storage device according to the save processing operation (steps 918 and 926), and then the process ends.

[0102] Next, we will explain the verification process for certified electronic contracts (TS). Figure 13 is a flowchart illustrating the verification process for a certified electronic contract (TS) that has been signed by a qualified person. Furthermore, since the verification of the Qualified Signature Electronic Contract (TS) is performed not only by the parties to the contract but also by qualified administrators and other verifiers, this is indicated on the user terminal 95 used by these individuals. As shown in Figure 13, the user terminal (verifier) ​​95 displays the designated qualified electronic contract (TS) on the screen based on the verifier's operation (step 951). Then, when the verifier selects the verify button, the signature management number attached to the qualified electronic contract (TS) is sent to the qualified signing device 1 to request verification (step 952).

[0103] The qualified signature device 1 reads the qualified electronic contract (TS) with the specified signature management number and performs checks for non-tampering and expiration (step 131). In other words, the credential signing device 1 obtains the hash value 133 of the second electronic contract 132 by decrypting the signature value 134 using the public key contained in the electronic certificate 135 embedded in the credential signed electronic contract (TS). This hash value 133 is the value calculated during the credential signing process. Furthermore, the credential signing device 1 obtains a new verification hash value from the second electronic contract 132 (see Figure 12) and verifies that it matches the hash value 133.

[0104] Furthermore, the credential signing device 1 obtains the hash value 124 of the first electronic contract 123 by decrypting the signature value 125 using the public key described in the electronic certificate 126, and verifies that it matches the hash value of the first electronic contract 123 calculated for verification purposes. Then, the credential signing device 1 verifies that the electronic contract (original) is unaltered (not tampered with) if the hash values ​​133 and 124 both match.

[0105] Furthermore, as part of the validity period check, the qualification signature device 1 verifies that the validity period recorded based on the qualification verification document data 5524 is later than the date and time of the qualification signature on the qualification-signed electronic contract (TS) being verified. This verification proves that the electronic contract was made by a qualified person with valid credentials. Alternatively, the timestamp acquisition date and time can be used instead of the qualification signing date and time. In this case, the qualification signing device 1 verifies that the qualification's expiration date is later than the timestamp acquisition date and time.

[0106] In this way, in addition to verifying the non-tampering of a qualified electronic contract (TS), by including the expiration date of the qualification in the attribute information that is to be signed (hashed), it is possible to verify that the electronic contract was signed by a qualified person at the request of a qualified person who has valid qualifications.

[0107] After the authentication signature device 1 has finished checking for non-tampering and expiration date, it presents the verification results to the user terminal (verifier) ​​95 (step 132), and the user terminal (verifier) ​​95 displays the verification results on its screen (step 953). The user (verifier) ​​can confirm from the verification results displayed on the screen that the qualified signature electronic contract (TS) has not been tampered with and that the qualified signature device 1 has verified that it was signed by the qualified person within the validity period of the qualification.

[0108] Based on the actions of the verifier who requests further specific qualification verification, the user terminal (verifier) ​​95 displays the qualification comparison table on the screen (step 954). In other words, the user terminal (verifier) ​​95 reads the location (URI) of the qualification comparison table recorded in the attribute information 122 of contractor A (qualified person) in the qualified electronic contract (TS) 138, accesses the list publication server 6 to read the qualification comparison table 61 and displays it on the screen. The user terminal (verifier) ​​95 also displays attribute information and the contents of the electronic certificate in accordance with the verifier's operations, along with the qualification comparison table.

[0109] The verifier can confirm the following (A) to (E) by referring to and comparing the qualification comparison table and the contents of the qualification signature (attribute information 122, 131, electronic certificates 126, 135, etc.) displayed on the user terminal (verifier) ​​95 (step 955). (A) It can be confirmed that the qualification name that the qualification signature device 1 determines the contractor possesses is listed in the attribute information 122 of the qualification signature electronic contract (TS) 138. Alternatively, you can verify the common name of the electronic certificate used for the signature. (B) Refer to the qualification comparison table 61 to confirm the qualification code corresponding to the qualification name. Alternatively, it can be confirmed that the common name of the electronic certificate in (A) above corresponds to the qualification name.

[0110] (C) You can verify whether the qualification name recorded in attribute information 122 of the qualified electronic contract (TS) 138 matches the qualification comparison table 61. This allows us to verify that the signature was performed by the appropriate entity. (D) It can be confirmed that the expiration date stated in attribute information 122 is later than the date and time of the authorized signature recorded in authorized signature electronic contract (TS) 138. This allows us to confirm that the user's (qualified person's) account has been registered and provided after proper eligibility verification has been carried out. (E) By referring to the "Identity Verification Method" and "Qualification Verification Method" in the Qualification Comparison Table 61, it is possible to confirm whether the qualification verification and identity verification for the qualified person in question have been carried out appropriately. Furthermore, it can be confirmed that third parties also adhere to the "identity verification method" and "qualification verification method" policies established by the qualification signature device 1 and the organization (company, hospital, etc.) to which the qualified person belongs.

[0111] As explained above, in electronic contracts using witness-type electronic signatures, the qualified signature device 1 performs prior qualification verification and party verification before registering an account if the contracting parties are qualified individuals with prescribed qualifications such as doctors or architects. Furthermore, electronic contracts such as surgical consent forms are electronically signed (certified signatures) using a different certified signing key for each qualification and an electronic certificate that describes the qualification information indicating that the person is the holder of the qualification corresponding to that certified signing key. Therefore, the qualifications held by the contracting parties can be confirmed from the certified electronic contract (certified electronic contract 136, or certified electronic contract (TS) 138) (referred to as the first certified verification configuration). Furthermore, when performing a qualified signature, at least one piece of qualification verification information is recorded in the attribute information 122 of the qualified person (contractor A), which is the target of the hash value calculation. Therefore, the qualification information of the contracting parties can also be confirmed from the attribute information 122 of the electronically signed electronic contract (referred to as the second qualification verification configuration). Furthermore, each qualified person's account records the verifier of their qualification and the expiration date, and since this information is recorded in the attribute information, it is possible to verify that the electronic contract was made by a qualified person with valid qualifications.

[0112] Furthermore, in the qualified signature device 1 of this embodiment, when at least one of the contracting parties in a witness-type electronic contract is a qualified person, signature restrictions (such as signature restriction A, which links a list of required qualifications to the electronic contract, or signature restriction B, which embeds a required qualification signature form in each signature field) are applied to each signature field of the electronic contract, thereby ensuring that electronic signatures are made based on appropriate qualifications. Since the qualification signature device 1 has restrictions on the required qualifications for each signature field of the electronic contract, it can mechanically and reliably determine whether the restricted qualifications match or do not match the qualifications held by the signatory.

[0113] Furthermore, in the qualified signature device 1 of this embodiment, the electronic contract with signature restrictions used in witness-type electronic contracts by contracting parties including qualified persons is one that has been electronically signed and time-stamped by the private key of the qualified signature device 1 at least before the electronic contract is made. This allows electronic contracts and information on required qualifications (such as the list of required qualifications, the required qualification signature form, and the script) to be distributed in a manner that proves the identity of the issuer (qualification signature device 1), as well as the non-tampering and existence of the required qualifications.

[0114] When performing an electronic signature using the private key of the qualified signature device 1, if the electronic signature does not include attribute information of the contracting parties, it is possible to indicate that the electronic contract is registered with the qualified signature device 1's service and that it is an electronic contract. An example of this would be a template electronic contract provided by the qualified signature device 1. On the other hand, when adding a witness-type electronic signature that includes the contractor's attribute information to the electronic signature by the qualified signature device 1, the creator of the electronic contract template can be indicated. An example of this would be a medical consent form template supervised by a lawyer, specifying the required qualifications of the signatory from the perspective of medical procedures, treatment details, and informed consent. (Example: For outpatient surgery with low risk to life, only a doctor would be required. For high-risk surgery, a nurse would be added to the doctor to attend the explanation.)

[0115] Although an embodiment of the credential signing device 1 has been described, it is also possible to modify it as follows. For example, in the embodiment described above, the case where credential signing is performed using both the first credential configuration and the second credential configuration was explained. Alternatively, the qualification signature may be performed using only one of the two qualification configurations, either the first or the second. The structure of the electronically signed contract 136(138) in these cases will be explained with reference to Figure 12.

[0116] When using only the first qualification verification configuration, the qualification signing device 1 includes the information described in (a) above in the attribute information 122 of contractor A (qualified person), similar to the attribute information 131 of contractor B (unqualified person), but does not include the information described in (b) to (g). Then, the qualification signing device 1 performs an electronic signature (qualified signature) using a qualification signing key corresponding to the qualification and an electronic certificate that describes the qualification information indicating that the person is the holder of the qualification corresponding to the qualification signing key, similar to the embodiment.

[0117] When using only the second credential verification configuration, the credential signing device 1 includes the information (a) to (g) in the attribute information 122 of contractor A (qualified person) in the same manner as in the embodiment, and performs an electronic signature (general signature) on its hash value 124 using a common signing key and an electronic certificate. Furthermore, when using only the second qualification verification configuration, the qualification signing device 1 may, as shown in Figure 14, attach the attribute information of all contracting parties (qualified parties should include (a) to (g), and unqualified parties should include (a)) to the first electronic contract 123 and perform a general signature using the common signing key and electronic certificate. In this case, each attribute information item will include (a) to (g) for qualified parties and (a) for unqualified parties.

[0118] Furthermore, the embodiments and modifications described above describe a case in which the qualified signature device 1 performs qualified signature processing based on confirmation and signature requests for surgical consent forms from two individuals: a physician from user terminal (physician) 91 and a patient from user terminal (patient) 92. In addition, the qualified signature device 1 can perform qualified signature processing even when there are three or more contracting parties, such as a qualified physician, a patient, and the patient's guarantor. In this case, the qualified signature device 1 performs qualified signature processing using a qualified signature key, etc., for the qualified physician's signature request, a general signature using a common key, etc., for the patient's signature request, and a general signature using a common key, etc., for the guarantor's signature request.

[0119] Furthermore, the embodiments and modifications described above describe a case where, after a qualified signature is obtained from a qualified person (physician), a general signature is obtained in response to a request for a general signature from a non-qualified person (patient). In contrast, the order in which signature requests are made does not matter, with either qualified or unqualified individuals signing first. If the request comes first from an unqualified individual, the first electronic contract (corresponding to the first electronic contract 123 in Figure 12) will be signed by general signatory, including the ID, email address, and phone number (SMS) in the attribute information of contractor B (unqualified), and then signed by qualified signatory, including the qualification information (a) to (g) in the attribute information of contractor A (qualified).

[0120] Furthermore, two or more of the multiple contractors may be qualified, and in this case, their qualifications may be the same or different. For example, in the case of a hospital construction contract, the construction contract between a qualified person (doctor) and a qualified person (architect) may be signed using a qualified signature key corresponding to the doctor and a qualified signature key corresponding to the architect.

[0121] Furthermore, if there are multiple qualified and unqualified parties to the contract, for example, in the case of N contracting parties, instead of performing a total of seven separate qualified or general signatures, qualified and unqualified parties with the same qualification may be grouped together to perform either a qualified or unqualified signature. For example, in the case of an electronic contract involving a total of seven people: qualified individuals a1-a3 (qualified under qualification A), b1-b2 (qualified under qualification B), and two unqualified individuals x1-x2, the attribute information (including qualification information) of each qualified individual a1-a3 is attached together and signed using the signing key for qualification A; the attribute information (including qualification information) of each qualified individual b1-b2 is attached together and signed using the signing key for qualification B; and the attribute information (excluding qualification information) of each unqualified individual x1-x2 is attached together and signed using the common signing key. This allows for the completion of the qualification signature process with a number of electronic signatures corresponding to the number of qualified and unqualified individuals (3 signatures), rather than a number of electronic signatures corresponding to the total number of subscribers N (7 signatures).

[0122] Furthermore, in the embodiments and modified examples described, the qualified signature device, etc., when the contract type is an electronic contract using a witness-type electronic signature can be configured as follows. (Configuration 1) A qualified signature device that sequentially performs witness-type electronic signatures on electronic contracts based on requests from each contracting party, If at least one of the contracting parties is qualified to meet predetermined qualifications, only those who meet the required qualifications will be eligible. electronic The limits on the types of signatures that can be signed are specified for each signature field. Ta The means of presenting an electronic contract, A means for determining whether the qualifications of a contracting party requesting an electronic signature match those required in the signature section of the electronic contract, if that contracting party is a qualified person. If the aforementioned qualifications match, an electronic signature means that performs an electronic signature on the electronic contract that can be verified as being by the qualified person, A qualification signature device characterized by being equipped with the following. (Configuration 2) The electronic signature means performs an electronic signature on the electronic contract using a qualified signature key, which is a private key created in accordance with the qualifications of the qualified person, and an electronic certificate on which the specific information of the qualifications is recorded, as an electronic signature that can be verified as being an electronic signature by a qualified person. A qualification signing device according to configuration 1, characterized in that it is a device that signs documents. (Configuration 3) The electronic signature means is Yes As an electronic signature that can be verified as being made by a qualified person, the electronic signature is made by attaching attribute information that records the personal information identifying the qualified person and the qualification information identifying the qualification to the electronic contract. A qualification signature device according to configuration 1 or configuration 2, characterized by the above. (Configuration 4) The electronic contract presented above has a list of required qualifications that specifies the required qualifications corresponding to each signature field, linked to the electronic contract. A qualification signature device according to configuration 1, configuration 2, or configuration 3, characterized by the above. (Configuration 5) The system includes a list storage means for storing a list of required qualifications, in which a list of required qualifications corresponding to each signature field is defined for each required qualification signature number, The aforementioned electronic contract is linked to the required qualification signature number from the required qualification list. The qualification signing device according to configuration 4, characterized in that (Configuration 6) The electronic contract presented above has form fields in each signature field that contain the required qualifications of the contracting parties. A qualification signing device according to any one of the configurations 1 to 5, characterized by the above. (Configuration 7) A means for providing a request form to each contracting party, which provides a request form in which only persons qualified to sign in the signature field corresponding to that contracting party can select to request an electronic signature, The qualification determination means determines, when a request for an electronic signature is made via the request form, whether the qualifications of the contracting party match those required in the signature section of the electronic contract. A qualification signing device according to any one of the configurations 1 to 6, characterized by the above. (Configuration 8) The electronic signature means performs a general signature in response to a signature request from a contracting party who is an unqualified person and does not possess the necessary qualifications, using a common signing key which is a private key that does not correspond to qualifications and an electronic certificate which does not contain any information identifying the qualifications. A qualification signing device according to any one of the configurations 1 to 7, characterized by the above. (Configuration 9) If the contracting party is an unqualified person who does not have the qualifications, the electronic signature means attaches attribute information recording personal information that identifies the unqualified person to the electronic contract and performs the general signature. A qualification signing device according to any one of the configurations 1 to 8, characterized by the above. (Configuration 10) A qualified signature program that causes a computer to function as a qualified signature device that sequentially performs witness-type electronic signatures on electronic contracts based on requests from each contracting party, If at least one of the contracting parties is a person with predetermined qualifications, then each signature field is specified to restrict electronic signatures so that only persons with the required qualifications can electronically sign. Ta A presentation function for displaying electronic contracts, If the contracting party requesting an electronic signature is a qualified person, the system includes a qualification determination function that determines whether the qualifications of the contracting party match those required in the signature section of the electronic contract, If the aforementioned qualifications match, the electronic signature function provides an electronic signature to the electronic contract that can be verified as being made by the qualified person, A credential signing program characterized by enabling a computer to perform the following actions.

[0123] It is also possible to configure it as follows: (Configuration 11) A qualified signature device that performs witness-type electronic signatures on electronic contracts by contracting parties, An electronic contract acquisition means for acquiring an electronic contract that is the subject of an electronic contract by the aforementioned contracting parties, A means for determining whether the aforementioned contracting party is a qualified person with the prescribed qualifications, If the contracting party is a qualified person, the electronic signature means performs an electronic signature on the electronic contract using a qualified signing key, which is a private key created in accordance with the qualifications of the qualified person, and an electronic certificate on which the specific information of the qualifications is recorded. A qualification signature device characterized by being equipped with the following. (Configuration 12) The electronic signature means, upon receiving a request from the qualified person, performs an electronic signature using the qualified signing key and the electronic certificate. A qualification signature device according to configuration 11, characterized by the above. (Configuration 13) The electronic signature means is In response to a request for signature from the aforementioned qualified contracting party, the qualified signature is performed using the aforementioned qualified signing key and the aforementioned electronic certificate. In response to a signature request from an unqualified contracting party, a general signature is performed using a common signing key (a private key that does not correspond to qualifications) and an electronic certificate that does not contain information identifying the qualifications. A qualification signature device according to configuration 11 or configuration 12, characterized by the above. (Configuration 14) The account of the qualified person is provided with an account DB in which identity verification information and qualification verification information are stored, and the account of the unqualified person is provided with an account DB in which identity verification information is stored. The qualification determination means determines whether the contracting party is a qualified person or not using the account database. A qualification signature device according to configuration 11, configuration 12, or configuration 13, characterized by the above. (Configuration 15) The account DB stores login identification numbers and passwords for each qualified and unqualified user. The aforementioned qualification determination means determines whether the contracting party is qualified or ineligible based on the identification number used when logging in. A qualification signature device according to configuration 14, characterized by the above. (Configuration 16) If the contracting party is a qualified person, the electronic signature means attaches attribute information recording the qualification information identifying the qualified person's qualifications to the electronic contract and performs an electronic signature using the qualified signing key and electronic certificate. A qualification signing device according to any one of the configurations 11 to 15, characterized in that... (Configuration 17) A qualified signature program that enables a computer to function as a qualified signature device that performs witness-type electronic signatures on electronic contracts by contracting parties, An electronic contract acquisition function that acquires electronic contracts that are subject to electronic contracts by the aforementioned contracting parties, A qualification determination function that determines whether the aforementioned contracting party is a qualified person with the prescribed qualifications, If the contracting party is a qualified person, the electronic signature function performs an electronic signature on the electronic contract using a qualified signing key, which is a private key created in accordance with the qualifications of the qualified person, and an electronic certificate on which the specific information of the qualifications is recorded. A credential signing program characterized by enabling a computer to perform the following actions.

[0124] It is also possible to configure it as follows: (Configuration 21) A qualified signature device that performs witness-type electronic signatures on electronic contracts by contracting parties, An electronic contract acquisition means for acquiring an electronic contract that is the subject of an electronic contract by the aforementioned contracting parties, A means for determining whether the aforementioned contracting party is a qualified person with the prescribed qualifications, If the aforementioned contracting party is a qualified person, the electronic signature means attaches personal information that identifies the qualified person and attribute information recording the qualification information that identifies the qualification to the electronic contract and performs an electronic signature. A qualification signature device characterized by being equipped with the following. (Configuration 22) The electronic signature means, upon receiving a request from the qualified person, attaches the attribute information containing the personal information and the qualification information to the electronic contract and performs an electronic signature. A qualification signature device according to configuration 21, characterized by the above. (Configuration 23) If the contracting party is an unqualified person who does not possess the necessary qualifications, the electronic signature means attaches attribute information containing personal information that identifies the unqualified person to the electronic contract and performs the electronic signature. A qualification signature device according to configuration 21 or configuration 22, characterized by the above. (Configuration 24) The account of a qualified person is provided with an account DB in which personal information and qualification information are stored, and personal information and qualification information are stored in the account of an unqualified person. The qualification determination means determines whether the contracting party is a qualified person or not using the account database. A qualification signing device according to configuration 21, configuration 22, or configuration 23, characterized by the above. (Configuration 25) The account DB stores login identification numbers and passwords for each qualified and unqualified user. The aforementioned qualification determination means determines whether the contracting party is qualified or ineligible based on the identification number used when logging in. A qualification signature device according to configuration 24, characterized by the features described above. (Configuration 26) If the contracting party is a qualified person, the electronic signature means attaches attribute information to the electronic contract that further records at least one of the identifying information of the person who verified the qualification of the qualified person and the method of verifying the qualification, and then performs an electronic signature. A qualification signing device according to configuration 2 of any one of configurations 21 to 25, characterized by the following: (Configuration 27) A qualified signature program that enables a computer to function as a qualified signature device that performs witness-type electronic signatures on electronic contracts by contracting parties, An electronic contract acquisition function that acquires electronic contracts that are subject to electronic contracts by the aforementioned contracting parties, A qualification determination function that determines whether the aforementioned contracting party is a qualified person with the prescribed qualifications, If the aforementioned contracting party is a qualified person, the electronic signature function attaches personal information that identifies the qualified person and attribute information that records the qualification information identifying the qualification to the electronic contract and performs an electronic signature. A credential signing program characterized by enabling a computer to perform the following actions. [Explanation of symbols]

[0125] 1. Qualified Signature Device 2. Qualified Signature Processing Unit 3. Signature Verification Department 4. Account Registration Section 5 Storage device 6. List publishing servers 7. Certificate Authority 8 Timestamp Server 9, 91-95 User terminals 11 CPU 12 ROM 13 RAM 14. Communication Control Unit 50 Qualified Signature Processing PG 51 Signature Verification PG 52 Account Registration PG 54 Template DB 55 Account DB 56 Qualification DB 57 Signing key DB 58 Required Qualification Signature List 61. Qualification Comparison Table 122 Attribute information 123 Electronic Contract 124, 133 hash values 125 Signature Value 126 Electronic Certificates 131 Attribute information 132 Electronic Contract 134 Signature Value 135 Electronic Certificates 136. Electronic Contract with Qualified Signature 401-403 Signature section 411-413 Electronic signature symbols 420 Signature Details 420a Signature Field 420b Unsigned Field 421~423 Details column 450 Signature Panel 401~402 Each signature field 411-413 Request for Qualification Signature Form 411-413 Electronic signature symbols 411~413 Electronic signature activation 412 Electronic Signature Symbol 420 Signature Details 420a Signature Field 420b Unsigned Field 421~423 Details column 450 Signature Panel 551 Account Table 552 Qualification and Identity Verification Information Table 5521 Identity Verification Information 5522 Identity Verification Document Data 5523 Qualification Verification Information 5524 Qualification Verification Document Data 5525 Qualification Code 553 File Table 801 Formatting field 802 Thumbnail section 803 Internal Management Section 804 Recipient field 809 Signature Selection Button 901 Signature Qualification Selection Field 909 Request for Qualification Signature Button

Claims

1. A qualified signature device that sequentially performs witness-type electronic signatures on electronic contracts based on requests from each contracting party, A signature key storage means for storing the private key, which is the qualification signing key, and its digital certificate, issued for each of the multiple pre-defined qualifications, A means of presenting an electronic contract in which, if at least one of the contracting parties is a person with predetermined qualifications, signature restrictions are stipulated in each signature field, allowing only persons with the required qualifications to electronically sign; A means for determining whether the qualifications of a contracting party requesting an electronic signature match those required in the signature section of the electronic contract, if that contracting party is a qualified person. If the qualifications match, an electronic signature means performs an electronic signature on the electronic contract using the qualification signing key and its electronic certificate corresponding to the qualifications of the qualified person, A qualification signature device characterized by being equipped with the following.

2. The electronic certificate contains specific information that identifies the qualification, The qualification signature device according to feature 1.

3. The aforementioned electronic signature means performs the electronic signature by attaching attribute information, which records personal information identifying the qualified person and qualification information identifying the qualification, to the electronic contract, as an electronic signature that can be verified as being an electronic signature by a qualified person. The qualification signature device according to claim 1 or claim 2.

4. The electronic contract presented above has a list of required qualifications linked to it, which specifies the required qualifications corresponding to each signature field. The qualification signature device according to feature 1.

5. The system includes a list storage means for storing a list of required qualifications, in which a list of required qualifications for each required qualification signature number is defined for each required qualification signature number. The aforementioned electronic contract is linked to the required qualification signature number from the required qualification list. The qualification signature device according to feature 4.

6. The electronic contract presented above has form fields embedded in each signature section containing the required qualifications of the contracting parties. The qualification signature device according to feature 1.

7. The system includes a means for providing a request form to each contracting party, which allows only qualified individuals who meet the qualifications specified for signing the signature field corresponding to that contracting party to select the option to request an electronic signature. The qualification determination means determines, when a request for an electronic signature is made via the request form, whether the qualifications of the contracting party match those required in the signature section of the electronic contract. The qualification signature device according to feature 1.

8. The aforementioned electronic signature means performs a general signature in response to a signature request from a contracting party who is an unqualified person and does not possess the necessary qualifications, using a common signing key, which is a private key that does not correspond to qualifications, and an electronic certificate that does not contain any information identifying the qualifications. The qualification signature device according to feature 1.

9. If the contracting party is an unqualified person who does not possess the necessary qualifications, the electronic signature means attaches attribute information containing personal information that identifies the unqualified person to the electronic contract and performs the general signature. The qualification signature device according to feature 8.

10. A qualified signature program that causes a computer to function as a qualified signature device that sequentially performs witness-type electronic signatures on electronic contracts based on requests from each contracting party, A presentation function that presents an electronic contract in which, if at least one of the contracting parties is a person with predetermined qualifications, signature restrictions are defined in each signature field, allowing only those with the required qualifications to electronically sign. If the contracting party requesting an electronic signature is a qualified person, the system includes a qualification determination function that determines whether the qualifications of the contracting party match those required in the signature section of the electronic contract, If the qualifications match, the electronic signature function performs an electronic signature on the electronic contract using the qualification signing key and its corresponding electronic certificate, which are private keys issued for each of the predetermined multiple qualifications, in the signature key storage means that stores the qualification signing key and its electronic certificate, and A credential signing program characterized by enabling a computer to perform the following actions.