Facsimile machine and image forming apparatus having facsimile function

JP2026123543APending Publication Date: 2026-07-30CANON KK
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
CANON KK
Filing Date
2025-01-17
Publication Date
2026-07-30

AI Technical Summary

Benefits of technology

【0011】 本開示によれば、ファクス通信における電子証明の仕組みを改善することができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026123543000001_ABST
    Figure 2026123543000001_ABST
Patent Text Reader

Abstract

To improve the electronic certification system used in fax communications. [Solution] The facsimile machine includes a reader 140 that reads the image of the document 1, an NFC communication unit 170 that acquires information necessary for authenticating the sender from an IC card 40, a controller 100, and a fax communication unit 160. The controller generates first authenticity data and second authenticity data from the information acquired by the NFC communication unit 170 and the image of the document 1 read by the reader 140, and generates a composite image by combining the image of the document 1 and the first authenticity data. The fax communication unit 160 faxes the composite image to the receiving facsimile machine 20 and also transmits the second authenticity data by binary file transfer.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a facsimile apparatus and an image forming apparatus having a facsimile function.

Background Art

[0002] A facsimile apparatus can transmit and receive data without using the Internet, which has concerns about communication eavesdropping, and can confirm that the data has reached the intended recipient. Therefore, facsimile communication by a facsimile apparatus continues to be used for applications that require security and receipt confirmation.

[0003] Non-Patent Document 1 discloses a facsimile apparatus that transmits by attaching the sender's name and facsimile number, which are information of the sender, to the upper part of the transmission document (hereinafter referred to as the transmission header area). The sender's name and facsimile number can be set by the user. That is, a malicious user can forge the sender's name and facsimile number and send them by "impersonating". In this case, the facsimile receiving side cannot determine whether the transmission is by "impersonation".

[0004] Non-Patent Document 1 also discloses an electronic signature technology using Internet facsimile (I-fax) as a technology to prevent forgery and impersonation of transmission documents. This is a technology for transmitting and receiving a PDF file with an electronic signature attached to an email via the Internet instead of an analog public line. The recipient can verify the electronic signature of the PDF file to confirm the authenticity and genuineness of the electronic signature given at the time of transmission and determine whether the sender is impersonating. However, many facsimile apparatuses that use a general analog public line do not have a binary file transfer (BFT) function and cannot transmit and receive a PDF file with an electronic signature.

[0005] Patent Document 1 discloses an optical encoding technology using QR Code (registered trademark). In fax communication, where it is not possible to send or receive PDF files with digital signatures, this optical encoding technology can be used to optically encode the digital signature and combine it with an image for transmission and reception, thereby incorporating a function equivalent to a digital signature. However, QR Code (registered trademark) is easily misused by copying it on its own, and easily forged by those who intend to misuse it. For this reason, simply using QR Code (registered trademark) for the digital signature is not enough to prevent the sender from impersonating the sender.

[0006] Patent Document 2 discloses an electronic signature device that digitizes paper documents by imaging them with an image sensor, etc., and assigns an electronic signature as a QR code (registered trademark), and a method for verifying the validity of the electronic signature and, if valid, overlaying the QR code (registered trademark) as a seal impression. In this technology, after digitizing paper documents, they are treated as electronic files, and the digitized signature data and the electronic signature using a QR code (registered trademark) are sent and received as a single electronic file. [Prior art documents] [Patent Documents]

[0007] [Patent Document 1] Patent No. 3996520 [Patent Document 2] Patent No. 6706451 [Non-patent literature]

[0008] [Non-Patent Document 1] Title: USRMA-3826-04, Publication Date: 2019-12, Publisher: CANON INC. [Overview of the project] [Problems that the invention aims to solve]

[0009] However, there was still room for further improvement in the electronic certification system used in fax communications. [Means for solving the problem]

[0010] The facsimile device of the present invention is characterized by comprising: reading means for reading an image of a document; acquisition means for acquiring information necessary for authenticating the identity of the sender; conversion means for generating first identity authentication data and second identity authentication data from the acquired information and the image of the document read; synthesis means for generating a composite image by combining the image of the document and the first identity authentication data; and first fax communication means for faxing the composite image to a receiving facsimile device and transmitting the second identity authentication data. Furthermore, the facsimile device of the present invention is characterized by comprising: a second facsimile communication means for receiving the composite image and the second identity authentication data from the above-mentioned facsimile device; a decryption means for acquiring and decrypting the first identity authentication data from the composite image and decrypting the second identity authentication data; an identity authentication request means for requesting a certification authority to verify the identity of the sender based on the decrypted first identity authentication data and the decrypted second identity authentication data; and a display means for displaying the verification result of identity authentication by the certification authority. The present invention relates to an image forming apparatus having a facsimile function, and is characterized by comprising: a reading means for reading an image of a document; an acquisition means for acquiring information necessary for authenticating the identity of the sender; a conversion means for generating first identity authentication data and second identity authentication data from the acquired information and the image of the document read; a synthesis means for generating a composite image by combining the image of the document and the first identity authentication data; and a first fax communication means for faxing the composite image to a receiving facsimile device and transmitting the second identity authentication data. Furthermore, the image forming apparatus of the present invention is an image forming apparatus having a facsimile function, and is characterized by comprising: a second facsimile communication means for receiving the composite image and the second identity authentication data from the above-mentioned image forming apparatus; a decryption means for acquiring and decrypting the first identity authentication data from the composite image and decrypting the second identity authentication data; an identity authentication request means for requesting a certification authority to verify the identity of the sender based on the decrypted first identity authentication data and the decrypted second identity authentication data; and a display means for displaying the verification result of identity authentication by the certification authority. [Effects of the Invention]

[0011] According to this disclosure, the mechanism for electronic certification in fax communications can be improved. [Brief explanation of the drawing]

[0012] [Figure 1] An example diagram illustrating the overall system configuration of a fax communication system. [Figure 2] (a) and (b) are functional block diagrams of the facsimile machine. [Figure 3] Diagram of an IC card configuration. [Figure 4] An explanatory diagram of a composite image. [Figure 5] A diagram illustrating the procedure for fax communication. [Figure 6] A sequence diagram of fax communication. [Figure 7] A flowchart illustrating the fax transmission setup process. [Figure 8] A flowchart illustrating the process of reading the image of the document being sent. [Figure 9] A flowchart illustrating the process of obtaining the information necessary for user authentication. [Figure 10] A flowchart illustrating the conversion process between the first and second identity verification data. [Figure 11] A flowchart illustrating the process of sending and receiving faxes. [Figure 12] A flowchart illustrating the process of creating verification request data for user authentication. [Figure 13] A flowchart representing personal authentication processing. [Figure 14] A flowchart representing the validity display processing of the verification result of personal authentication. [Figure 15] An exemplary diagram of the configuration of the entire fax communication system. [Figure 16] A configuration diagram of the My Number card. [Figure 17] An exemplary diagram of a fax image. [Figure 18] A sequence diagram of fax communication. [Figure 19] A flowchart representing the details of the electronic signature decryption process.

Best Mode for Carrying Out the Invention

[0013] Hereinafter, preferred embodiments of the present invention will be described with reference to the accompanying drawings.

[0014] (First Embodiment) In the first embodiment, an electronic certificate for personal authentication of the sender and an electronic signature are transmitted by a two-dimensional code image such as a QR code (registered trademark), and a hash value is transmitted by binary file transfer other than the two-dimensional code image, so that the receiver verifies the validity of the sender's personal authentication. The binary file transfer is performed by the method (file transfer mode option) defined in Attachment B of "Terminal Characteristics of Group 3 Facsimile Devices for JT-T4 Document Transmission", 13th Edition, established on June 3, 2004, by the Information and Communication Technology Committee of the Japan Electronics and Information Technology Industries Association. Hereinafter, "JT-T4" will be simply referred to as such.

[0015] By applying the technology of Patent Document 2 to fax communication, when the receiving facsimile device prints the received image on paper, the electronic signature is encoded and printed as a QR code (registered trademark). By optically reading this encoded electronic signature, a function equivalent to an electronic signature is possible.

[0016] <0000`117>However, when an image file of a paper document (the original document to be sent) that is to be signed is printed after being received by fax, it will differ from the original document. Specifically, differences in print density, blurring of characters, and paper skew will alter the details of the image from the original document. Therefore, even if the image of the data to be signed, printed after receiving the fax, is digitized again, it will differ from the original data to be signed, and may be deemed invalid during signature verification. This makes it difficult to prevent impersonation of the sender. Furthermore, it is difficult to verify if the data has been altered from the original paper document.

[0017] Figure 1 is an illustrative diagram of the overall system configuration for fax communication in this embodiment. The facsimile device 10 is the fax sending device, and the facsimile device 20 is the fax receiving device, both of which are equipped with an optional binary file transfer function. The facsimile device 10 and the facsimile device 20 communicate via an analog public telephone line 30. The facsimile devices 10 and 20 may both be dedicated facsimile machines, but at least one of them may be an image forming device such as a multifunction device that has a copy function, scanner function, printer function, facsimile function, etc.

[0018] The facsimile machine 10 comprises a controller 100, an operation unit 150, an image reader 140 for reading the image of the document to be sent 1, an NFC (Near Field Communication) communication unit 170, and a fax communication unit 160. The sender 2 operates the operation unit 150 of the facsimile machine 10 to send a fax. The facsimile machine 10 also has a printing unit 190. The printing unit 190 prints the received image onto a sheet, for example, when the facsimile machine 10 receives a fax.

[0019] The operation unit 150 is a user interface having an input interface and an output interface. The input interface is, for example, a key button or a touch panel. The output interface is, for example, a display or a speaker. In this embodiment, the operation unit 150 is configured to include a display and a touch panel. The display shows a predetermined screen under the control of the controller 100. Instructions and the like are input to the controller 100 according to the touch position on the touch panel by the transmitter 2.

[0020] The reader 140 reads the image of the document 1 and sends the reading result to the controller 100. The reader 140 is, for example, a scanner that optically reads the image of the document 1. The NFC communication unit 170 is a contactless card reader / writer that performs short-range wireless communication with an IC card 40 that is within a predetermined distance. Details of the IC card 40 will be described later. In this embodiment, it is contactless, but the NFC communication unit 170 may also have the functionality of a contact-type card reader / writer with a card slot.

[0021] The fax communication unit 160 is a communication interface for performing fax communication via the analog public telephone line 30. When sending a fax, the controller 100 generates transmission data from the image of the transmission image 1 read by the reader 140, and transmits this data to the facsimile machine 20 via the analog public telephone line 30 using the fax communication unit 160.

[0022] The controller 100 is an information processing device having a CPU (Central Processing Unit) 110, memory 120, and storage 130. The CPU 110 controls the overall operation of the facsimile machine 10 by executing computer programs stored in the storage 130. The memory 120 is the main memory used by the CPU 110 when it performs processing and stores temporary data associated with the processing. For example, the memory 120 temporarily stores the image of the transmission document 1 read by the reader 140. The memory 120 is composed of, for example, RAM (Random Access Memory). The storage 130 is a storage device such as ROM (Read Only Memory), HDD (Hard Disk Drive), or SSD (Solid State Drive).

[0023] The CPU 110 primarily performs the processing carried out by the controller 100 described above, and also communicates with the IC card 40 via the NFC communication unit 170, thereby cooperating with the IC card 40 to perform the processing related to fax communication in this embodiment.

[0024] The facsimile machine 20 comprises a controller 200, an operation unit 250, a fax communication unit 260, a network communication unit 280, and a printing unit 290. The recipient 3 operates the operation unit 250 of the facsimile machine 20 to receive the fax and verify the validity of the sender's signature 2. The operation unit 250 is a user interface with the same configuration and functions as the operation unit 150. The fax communication unit 260 is a communication interface with the same configuration and functions as the fax communication unit 160. The printing unit 290 prints the received image onto a sheet when the facsimile machine 20 receives a fax.

[0025] The network communication unit 280 is a communication interface for communicating with the certification authority 70 via the internet 60. The facsimile machine 20 communicates with the certification authority 70 via the internet 60 using the network communication unit 280 for the purpose of verifying the validity of the digital certificate and verifying the digital signature.

[0026] The controller 200, like the controller 100, is an information processing device having a CPU 210, memory 220, and storage 230. The CPU 210 controls the overall operation of the facsimile machine 20 by executing computer programs stored in the storage 230. The memory 220 is the main memory used by the CPU 210 when it performs processing and stores temporary data associated with the processing. For example, the memory 220 temporarily stores images received by the fax communication unit 260. The memory 220 is composed of, for example, RAM. The storage 230 is a storage device such as ROM, HDD, or SSD.

[0027] The CPU 210 primarily performs processing handled by the controller 200. The CPU 210 communicates with an external facsimile machine 10 via an analog public telephone line 30 using the fax communication unit 260. The CPU 210 communicates with the certification authority 70 via the internet 60 using the network communication unit 280.

[0028] The certification authority 70 is an organization that performs identity verification in publicly known electronic signatures, issues electronic certificates, and manages issued certificates. The certification authority 70 can communicate with devices connected to the Internet 60. In this embodiment, the certification authority 70 can communicate with the facsimile device 20 via the Internet 60.

[0029] Figure 2 shows the functional block diagrams of the facsimile machines 10 and 20, respectively. These functional blocks are realized by the CPUs 110 and 210 executing computer programs stored in storage devices 130 and 230. Figure 2(a) is the functional block diagram of the facsimile machine 10, which is the transmitting side. The facsimile machine 10 functions as an electronic certificate acquisition unit 131, an electronic signature acquisition unit 132, a hash value generation unit 133, a first person authentication data conversion unit 134, a second person authentication data conversion unit 135, and an image synthesis unit 136. Figure 2(b) is the functional block diagram of the facsimile machine 20, which is the receiving side. The facsimile machine 20 functions as a first person authentication data decryption unit 234, a second person authentication data decryption unit 235, a person authentication request unit 238, and a person authentication validity display unit 239. Details of each functional block will be described later.

[0030] Figure 3 is a diagram showing the configuration of an IC card 40 that communicates with the NFC communication unit 170 of a facsimile machine 10. The IC card 40 is issued by a certification authority 70 and is held by the sender 2. The IC card 40 has a CPU and memory inside. The IC card 40 can perform predetermined functions by executing a computer program stored in the memory using the CPU. The IC card 40 includes an electronic signature application program (hereinafter abbreviated as "electronic signature AP") 41. The electronic signature AP 41 has a digital signature certificate 44 with a public signature key 42, a self-signed certificate 45 of the certification authority, a private signature key 43, an electronic signature generation unit 46, and a PIN (Personal Identification Number) 47.

[0031] When an image of document 1 is sent by fax, the sender 2 brings their IC card 40 within a predetermined distance of the NFC communication unit 170, enabling the facsimile device 10 to process the data in cooperation with the IC card 40. The sending facsimile device 10 obtains an electronic certificate, generates a hash value, and generates an electronic signature when sending a fax. These processes are performed by the CPU 110 using various functional blocks.

[0032] The CPU 110 communicates with the IC card 40 via the NFC communication unit 170 using the electronic certificate acquisition unit 131, and obtains the digital signature certificate 44 and the self-signed certificate 45 of the certification authority from the IC card 40. The CPU 110 temporarily stores the obtained digital signature certificate 44 and the self-signed certificate 45 of the certification authority as digital certificates in the memory 120.

[0033] The CPU 110 generates a hash value from the image of the transmission document 1, which has been read by the reader 140 and temporarily stored in the memory 120 by the hash value generation unit 133. The hash value generation unit 133 generates the hash value using, for example, a well-known hash function such as SHA-256.

[0034] The CPU 110, via the electronic signature acquisition unit 132, sends the generated hash value to the IC card 40 via the NFC communication unit 170 and instructs it to generate an electronic signature. The electronic signature AP 41 of the IC card 40, in response to the instruction from the CPU 110 to generate an electronic signature, generates an electronic signature using the hash value obtained from the facsimile device 10 and the signature secret key 43 via the electronic signature generation unit 46. The electronic signature AP 41 sends the generated electronic signature back to the CPU 110. The CPU 110 temporarily stores the returned electronic signature in the memory 120. In the first embodiment, a known public-key cryptography technique is used for the electronic signature.

[0035] Here, we will briefly explain publicly known digital signatures and public-key cryptography. In paper documents, the fact that they were created by the person themselves is proven by their signature and seal. The presence or absence of tampering in a paper document is determined by the handwriting and seal impression. In contrast, in electronic documents, the person who created the document is proven by their electronic signature. Electronic documents are accompanied by a digital signature (a digital signature) and a digital certificate, which are encrypted using a private key possessed only by the person who created the document, along with the document's unique information (generally a hash value). The presence or absence of tampering in an electronic document is determined by verifying the electronic document (hash value), digital signature, and digital certificate with a third-party certification authority.

[0036] A digital signature is the hash value of an electronic document encrypted with a private signing key. A digital signature is sometimes referred to as an encrypted hash value. A digital signature can be decrypted using the public key contained in a digital certificate, restoring it to its original hash value.

[0037] A third-party certification authority (Certification Authority 70) compares the hash value obtained by decrypting the digital signature with the public key contained in the digital certificate with the hash value of the digital document. If they match, it is determined that the digital document has not been tampered with. A digital certificate also includes information such as the serial number of the digital certificate, the cryptographic algorithm used for the digital signature, the issuer of the digital certificate, the validity period, the cryptographic scheme of the public key, and information on the distribution points of the certificate revocation list. The information required for authenticating the identity of the creator of a digital document is the set of digital signature, digital certificate, and hash value. If any of this information differs from the information at the time of creation (signing), the authentication will be deemed invalid by the certification authority.

[0038] In this embodiment, the information necessary for identity verification is divided into two parts: the electronic signature and the electronic certificate for signing are designated as "first identity verification data," and the hash value as "second identity verification data." One part is encoded as a two-dimensional code image, while the other is handled in a different manner. This is because if all the information necessary for identity verification is encoded as a two-dimensional code image, the identity verification information can be easily forged by simply duplicating the two-dimensional code image portion. For example, if the information necessary for identity verification is encoded using only a two-dimensional code image, once a two-dimensional code image that is valid for identity verification is created, that two-dimensional code image can be duplicated and used repeatedly as a valid two-dimensional code image for identity verification.

[0039] In the first embodiment, the first user authentication data is encoded into a two-dimensional code image, and the second user authentication data is treated as binary file transfer data for facsimile other than the two-dimensional code image. Since binary file transfer between facsimile devices is handled only between facsimile devices, it is difficult for a user to analyze or falsify what is being transferred. Therefore, even if a malicious user duplicates and forges only the two-dimensional code image, if they cannot falsify the hash value obtained from the binary file transfer, they will not be able to gather the information necessary for user authentication, thus preventing easy forgery.

[0040] Furthermore, Appendix F of "JT-T30 Document Facsimile Transmission Procedure on General Switched Networks," 18th edition, established May 29, 2008, Japan Information and Communications Technology Committee, discloses G3 facsimile security based on the RSA algorithm. While this makes it possible to encrypt data for binary file transfer, it will not be used in this embodiment. Hereafter, "JT-T30 Document Facsimile Transmission Procedure on General Switched Networks," 18th edition, established May 29, 2008, Japan Information and Communications Technology Committee, will be simply referred to as "JT-T30."

[0041] This document explains the conversion of data for first-party authentication (conversion to a two-dimensional code image), the conversion of data for second-party authentication (conversion to data for binary file transfer), and image synthesis.

[0042] The CPU 110, using the first person authentication data conversion unit 134, converts the electronic certificate and electronic signature temporarily stored in the memory 120 into a two-dimensional code image and temporarily stores it in the memory 120. The CPU 110, using the second person authentication data conversion unit 135, converts the hash value into data for binary file transfer and temporarily stores it in the memory 120. The CPU 110, using the image synthesis unit 136, synthesizes the two-dimensional code image, which is the first person authentication data temporarily stored in the memory 120, with the image of the transmission document 1 read by the reader 140, and temporarily stores it in the memory 120.

[0043] Figure 4 is an explanatory diagram of a composite image of the two-dimensional code image generated by the image synthesis unit 136 and the image of the transmission document 1. The composite image is an image in which the two-dimensional code image 125, which is the first person authentication data, is added to the upper part (fax header area) of the image 121 of the transmission document 1. The position of the two-dimensional code image can be any position as long as it does not affect the image 121 of the transmission document 1.

[0044] The receiving facsimile device 20 acquires the composite image shown in Figure 4 via fax communication and obtains the second identity authentication data via binary file transfer. The CPU 210 of the facsimile device 20 extracts and decodes the first identity authentication data from the acquired composite image using the first identity authentication data decoding unit 234. The CPU 210 decodes the second identity authentication data using the second identity authentication data decoding unit 235 and generates a hash value. The CPU 210 uses the identity authentication request unit 238 to create data for identity authentication verification to the certification authority 70 using the decoded first identity authentication data, hash value, etc. The CPU 210 uses the identity authentication validity display unit 239 to display the identity authentication result obtained from the certification authority 70 on the display of the operation unit 250.

[0045] Figure 5 is a diagram illustrating the procedure for fax communication. Figure 5 shows the transmission and reception of signals between the sending device (fax machine 10) and the receiving device (fax machine 20) according to the JT-T30 binary code facsimile procedure, with time progressing from top to bottom. Here, we will explain an example of sending and receiving a one-page document (1) and its hash value (binary file) via fax communication.

[0046] Phase A500 is the call setup phase. The call setup phase is the phase in which the transmitting facsimile device 10 and the receiving facsimile device 20 are connected to enable communication via the analog public telephone line 30. Here, the terminals that perform automatic call initiation and the called terminals that perform automatic call reception as described in Operation Method 4 of JT-T30 are used.

[0047] In Phase A500, the calling transmitter detects a dial tone, and after an appropriate time has elapsed, dials the number of the called receiver and sends a 1,100 Hz tone signal (CNG) 510 to the called receiver. The called receiver detects the ring caused by the CNG 510 and responds with a 2,100 Hz called station identification signal (CED) 511.

[0048] Phase B501 is the pre-message procedure phase. The pre-message procedure phase is the phase in which the standard and non-standard functions of the calling transmitter and the calling receiver are identified and the functions to be used are configured. The pre-message procedure phase also includes training and synchronization to confirm whether communication is possible via the analog public line 30 at the set speed and signal level.

[0049] In phase B501, the receiving receiver sends a DIS (Capacity Identification Signal) 512 indicating that it has the standard function of receiving fax images and the optional function of binary file transfer. DIS 512 is a signal in which the facsimile control field (FCF) in the HDLC frame is "00000100" according to the binary code signaling procedure specified in JT-T30. Furthermore, the 53rd bit (BFT bit) of the facsimile information field (FIF) in the DIS signal, as specified in Table 5-1 of JT-T30, is "1", indicating that the receiving receiver has the optional function of binary file transfer.

[0050] Once the calling receiver has confirmed that it has standard fax image reception and binary file transfer capabilities, the calling transmitter sends a DCS (Digital Command Signal) 513 to configure the use of these functions. Upon detecting the DCS 513, the calling receiver commands the calling transmitter to use these functions with a DTC (Digital Transmission Command) 514.

[0051] The calling transmitter sends a TCF (Training Check) 515 to confirm whether communication is possible at the set speed and signal level. The calling receiver responds with a CFR (Ready to Receive) 516 indicating whether communication is possible at the set speed and signal level.

[0052] Phase C502 includes the in-message procedure phase C1 and the message transmission phase C2. Phase C502 is the phase in which message synchronization, error detection, correction, and transmission of the message as defined in JT-T4 occur between the calling transmitter and the called receiver.

[0053] In phase C502, the calling transmitter sends a hash value, temporarily stored in memory 120 as binary file transfer message 520, in a data format conforming to the binary file transfer format. The data format conforming to the binary file transfer format is defined in "JT-T434 Binary File Transfer Format for Telematics Services, 3rd Edition, established April 20, 2000, Japan Information and Communications Technology Committee." "JT-T434 Binary File Transfer Format for Telematics Services, 3rd Edition, established April 20, 2000, Japan Information and Communications Technology Committee" will hereinafter simply be referred to as "JT-T434."

[0054] The calling transmitter encodes the composite image data (composite image data) temporarily stored in memory 120 as a fax image message 521 using JT-T4 and sends out one page. Once the transmission of one page of composite image data is complete, the calling transmitter sends out an RTC (Return to Control) signal 517.

[0055] Phase D503 is the post-message procedure phase, which is the phase in which message transmission is terminated. In phase D503, the calling transmitter sends an EOM (End of Message) 518. Upon receiving the EOM 518, the called receiver sends a Message Confirmation (MCF) 519.

[0056] Phase E504 is the call release phase, in which the call transmitter and the call receiver release the analog public line 30. Here, it is assumed that the analog public line 30 is automatically released upon completion of message transmission.

[0057] In phases A500, B501, D503, and E504, signals and commands specified in JT-T30 are transmitted and received. In phase C502, message data specified in JT-T4 is transmitted and received.

[0058] Although Appendix F of JT-T30 discloses G3 facsimile security based on the RSA algorithm, it will not be used in this embodiment. This is because Appendix F uses the SHA-1 hash algorithm and does not use a certification authority. While the 160-bit hash value used in SHA-1 has been identified as having collision vulnerabilities, and it is common to use the more secure SHA-256 or higher, this does not mean that the hash algorithm is limited to SHA-256. Furthermore, because a certification authority is not used, it is not possible to have the electronic signature verified by a third-party organization.

[0059] Figure 6 is a sequence diagram of fax communication in this embodiment. This sequence diagram shows the processes of the transmitting facsimile device 10, the receiving facsimile device 20, and the certification authority 70. Flowcharts of each process in the sequence are shown in Figures 7 to 14.

[0060] The controller 100 of the sending facsimile machine 10 sets the mode and other settings related to fax transmission in response to the operation of the operation unit 150 by the sender 2 (S10). The controller 100 reads the image of the document 1 to be sent using the reader 140 (S20). The controller 100 obtains the information necessary for authenticating the sender 2 from the IC card 40 using the NFC communication unit 170 (S30). The controller 100 converts the acquired information necessary for authenticating the sender into first authentication data and second authentication data (S40). The controller 100 sends the fax data, including the image of the document 1 to be sent, etc., to the receiving facsimile machine 20 via the fax communication unit 160 (S50).

[0061] The controller 200 of the receiving facsimile machine 20 receives the fax data sent from the transmitting facsimile machine 10 (S60). Based on the received fax data, the controller 200 creates verification request data for identity authentication (S70). The controller 200 sends the verification request data to the certification authority 70 via the network communication unit 280 to request identity authentication (S80). The certification authority 70 performs identity authentication in response to the identity authentication verification request and returns the verification result to the facsimile machine 20 (S100). The controller 200 of the facsimile machine 20 displays the validity of the identity authentication based on the verification result obtained from the certification authority 70 (S90).

[0062] Fax communication is performed through the sequence described above. Each process in the sequence will be explained in detail below using Figures 7 to 14.

[0063] S10: Figure 7 is a flowchart showing the fax transmission setting process for S10. The home screen is displayed on the display of the operation unit 150, and this process starts when the sender 2 inputs a fax transmission instruction from the home screen using the operation unit 150.

[0064] When the controller 100 of the facsimile machine 10 receives a fax transmission instruction from the sender 2 (S101:Y), it displays a mode selection screen on the display of the operation unit 150 (S102). If the sender 2 does not instruct the sender to transmit a fax from the home screen (S101:N), the controller 100 terminates processing without performing fax communication.

[0065] The mode selection screen allows the user to select at least two modes: a mode with validity verification that authenticates the sender during fax communication and detects tampering with the faxed image, and a normal mode that does not perform this authentication or tampering detection. Sender 2 selects one of the modes from the mode selection screen using the operation unit 150. If the mode with validity verification is selected (103:Y), the controller 100 sets the operation mode to the fax transmission mode with validity verification (S104). If the normal mode is selected (S103:N), the controller 100 sets the operation mode to the normal fax transmission mode (S105).

[0066] The controller 100 displays a fax number input screen on the display of the operation unit 150 (S106). The sender 2 inputs the fax number of the recipient's facsimile machine 20 from the fax number input screen using the operation unit 150. The controller 100 obtains the fax number of the recipient's facsimile machine 20 from the operation unit 150 (S107). The controller 100 displays an instruction screen on the display of the operation unit 150 prompting the sender 2 to place the document 1 on the document glass of the reader 140 (S108). When the sender 2 places the document 1 on the document glass in accordance with the instruction screen, the controller 100 displays a screen for scanning the document 1 on the display of the operation unit 150 (S109).

[0067] S20: Figure 8 is a flowchart showing the process of reading the image of the document 1 to be transmitted in S20. This process starts from the state in which the screen for reading the document 1 to be transmitted is displayed on the display in the process of S109.

[0068] When the controller 100 detects that the sender 2 has pressed the start button on the screen for scanning the document 1 via the operation unit 150 (S201), the reader 140 reads the document 1 (S202). The controller 100 temporarily stores the image data representing the image of the document 1 read by the reader 140 in the memory 120.

[0069] The controller 100 checks the set operating mode, and if normal mode is set, it terminates the process in S20 and proceeds to the process in S50 (S203:N). If the fax transmission mode with validity check is set (S203:Y), the controller 100 generates a hash value from the image data of the transmission document 1 using the hash value generation unit 133 (S204). After generating the hash value, the controller 100 displays an NFC communication screen on the display of the operation unit 150 instructing the user to bring the IC card 40 close to the NFC communication unit 170 (S205).

[0070] S30: Figure 9 is a flowchart showing the process of obtaining information necessary for authenticating the identity of sender 2. This process starts from the state in which the NFC communication screen is displayed on the display in the process of S205.

[0071] The controller 100 checks whether it can communicate with the IC card 40 via the NFC communication unit 170 (S301). If communication is not possible (S302:N), the controller 100 repeatedly checks whether it can communicate with the IC card 40 until it becomes possible. When communication becomes possible (S302:Y), the controller 100 displays a PIN input screen on the display of the operation unit 150 (S303). The NFC communication unit 170 becomes able to communicate with the IC card 40 when the IC card 40 comes within a predetermined distance.

[0072] Sender 2 enters a PIN (e.g., a personal identification number) from the PIN input screen using the operation unit 150. Controller 100 accepts the PIN input from the operation unit 150 (S304). Controller 100 compares the entered PIN with the PIN 47 stored in the IC card 40 to check whether the PINs match (S305). If the PINs do not match (S305:N), Controller 100 displays a message on the operation unit 150's display indicating that the PINs do not match and displays the PIN input screen again. Note that there is a limit to the number of times the PIN input screen can be redisplayed when the PINs do not match. In other words, if the PIN is entered incorrectly a predetermined number of times, the PIN will be locked.

[0073] If the PIN matches (S305:Y), the controller 100 obtains the digital signature certificate 44 and the self-signed certificate 45 of the certification authority from the IC card 40 via the NFC communication unit 170 using the digital certificate acquisition unit 131 (S306). The digital signature certificate 44 includes the public signing key 42. The controller 100 instructs the IC card 40 to generate a digital signature by sending the hash value generated in the S204 process to the IC card 40 via the NFC communication unit 170 using the digital signature acquisition unit 132 (S307). The digital signature AP 41 of the IC card 40 generates a digital signature using the hash value and the private signing key 43 using the digital signature generation unit 46 in response to this instruction and sends it back to the facsimile device 10. As a result, the controller 100 obtains the digital signature (S308). Having obtained the digital signature, the controller 100 displays an NFC communication completion screen on the display of the operation unit 150 (S309).

[0074] S40: Figure 10 is a flowchart showing the conversion process between the first and second user authentication data. This process begins when the NFC communication completion screen is displayed on the display in the process of S309.

[0075] Controller 100 uses a first-party authentication data conversion unit 134 to convert the digital signature certificate 44 and the self-signed certificate 45 of the certification authority obtained in S306, along with the digital signature obtained in S308, into a two-dimensional code image, which is the first-party authentication data (S401). Controller 100 temporarily stores the two-dimensional code image in memory 120. Controller 100 uses a second-party authentication data conversion unit 135 to convert the hash value generated in S204 into binary file transfer message data, which is the second-party authentication data (other than the two-dimensional code image), and temporarily stores it in memory 120 (S402). Controller 100 uses an image synthesis unit 136 to synthesize the two-dimensional code image temporarily stored in memory 120 with the image data of the transmission document 1 read in S202, and temporarily stores the synthesized image data in memory 120 (S403).

[0076] S50, S60: Figure 11 is a flowchart representing the fax transmission and reception process. The processes in S50 and S60 are performed in parallel, with data being sent and received between the transmitting facsimile device 10 and the receiving facsimile device 20. This process begins when the fax transmission start screen is displayed on the display of the operation unit 150 of the transmitting facsimile device 10.

[0077] The controller 100 of the transmitting facsimile device 10 sends CNG510 via the fax communication unit 160 (S501). The controller 200 of the receiving facsimile device 20 detects the CNG510 sent from the transmitting facsimile device 10 and sends CED511 via the fax communication unit 260 (S601). The controller 200 sends DIS512 via the fax communication unit 260 (S602). DIS512 indicates that the facsimile device 20 has a standard fax image reception function and an optional binary file transfer function.

[0078] The controller 100 of the facsimile machine 10 receives DIS512 from the facsimile machine 20 and confirms via DIS512 that the receiving facsimile machine 20 has standard and optional functions. The controller 100 also sends DCS513 via the fax communication unit 160 to set the use of standard functions (S502). The controller 200 of the facsimile machine 20 receives DCS513 from the facsimile machine 10 and sends DTC514 via the fax communication unit 260 to command the facsimile machine 10 to use standard and optional functions (S603).

[0079] The controller 100 of the facsimile machine 10 sends TCF515 via the fax communication unit 160 to train the facsimile machine 20 to confirm whether communication is possible at the set speed and signal level (S503). The controller 200 of the facsimile machine 20 receives TCF515 from the facsimile machine 10 and sends CFR516 via the fax communication unit 260 to respond whether communication at the set speed and signal level is possible (S604). As a result of this process, the receiving facsimile machine 20 enters the message reception state of phase C502 in Figure 5.

[0080] The controller 100 of the facsimile machine 10 sends out data encoded using JT-T434 and JT-T4 as a binary file transfer message via the fax communication unit 160 (S504). The controller 100 also sends out fax image messages 521 sequentially, one page at a time, via the fax communication unit 160, encoding the composite image data temporarily stored in the memory 120 using JT-T4 (S505). The controller 200 of the facsimile machine 20 receives the binary file transfer message and fax image message 521 sent out from the facsimile machine 10 in S504 and S505 (S605).

[0081] When the controller 100 of the facsimile machine 10 has finished sending out one page of data, the facsimile communication unit 160 sends out RTC 517 (S506). The controller 200 of the facsimile machine 20 detects the RTC 517 sent out from the facsimile machine 10 and proceeds to the post-message procedure phase of phase D503 (S606).

[0082] The controller 100 of the facsimile machine 10 sends EOM518 via the fax communication unit 160 (S507). The controller 200 of the facsimile machine 20 detects the EOM518 sent from the facsimile machine 10 and sends a completion message confirmation via MCF519 to the facsimile machine 10 via the fax communication unit 260 (S607). This completes the processing in S50 and S60.

[0083] S70: Figure 12 is a flowchart showing the process of creating verification request data for identity authentication. The creation of verification request data for identity authentication is performed by the signature decryption process.

[0084] The controller 200 of the facsimile machine 20 prints an image based on the fax image message received from the transmitting facsimile machine 10 (S701). The controller 200 decodes a hash value from the binary file transfer message, which is the second identity authentication data received from the facsimile machine 10 (S702). The controller 200 extracts a two-dimensional code image, which is the first identity authentication data, from the fax image message received from the facsimile machine 10 (S703).

[0085] The controller 200 displays a confirmation screen on the operation unit 250's display to confirm whether or not to verify the validity of sender 2 (S704). If receiver 3 instructs the operation unit 250 to perform validity verification from the confirmation screen (S704:Y), the controller 200 decrypts the two-dimensional code image extracted in S703 (S705). As a result, the controller 200 obtains the digital signature, the digital signature certificate 44, and the self-signed certificate 45 of the certification authority provided by sender 2. The controller 200 displays a screen on the operation unit 250's display indicating that the sender 2's identity is being verified (S707), and terminates the process in S70.

[0086] If recipient 3 instructs via the operation unit 250 not to perform validity verification from the confirmation screen (S704:N), the controller 200 discards the hash value and two-dimensional code image obtained in S702 and S703 (S707), and terminates the process in S70.

[0087] S80, S100: Figure 13 is a flowchart showing the sender 2's identity authentication process. This process is performed when the receiving facsimile device 20 requests authentication from a publicly known electronic signature certification authority 70. The display on the operation unit 250 of the facsimile device 20 shows a screen indicating that identity verification is in progress.

[0088] The controller 200 of the facsimile machine 20 creates data for requesting authentication verification from the certification authority 70 (S801). The data for requesting authentication verification from the certification authority 70 is created from the second authentication data (hash value) decrypted in S702 and the first authentication data (digital signature, signing digital certificate 44, and the certification authority's self-signed certificate 45) decrypted in S705. The controller 200 transmits the created authentication verification request data and the authentication verification request to the certification authority 70 via the network communication unit 280 (S802).

[0089] The certification authority 70 obtains the identity verification request and identity verification request data transmitted from the facsimile machine 20 (S1001). From the obtained identity verification request data, the certification authority 70 extracts the digital signature certificate 44, the certification authority's self-signed certificate 45, the digital signature, and the hash value, and extracts the public signature key 42 from the digital signature certificate 44 (S1002). The certification authority 70 decrypts the extracted digital signature with the public signature key 42 and generates a hash value (S1003).

[0090] The certification authority 70 compares the hash value extracted in S1002 with the hash value generated in S1003 to determine whether they match (S1004). If the hash values ​​match (S1004:Y), the certification authority 70 determines that the digital signature is valid (S1005). If the hash values ​​do not match (S1004:N), the certification authority 70 determines that the digital signature is invalid (S1006).

[0091] If the digital signature is valid (S1005), the certification authority 70 checks whether the digital signature certificate 44 has expired (S1007). The certification authority 70 can check whether the digital certificate has expired by querying the serial number of the digital signature certificate 44 extracted in S1002 with the serial number of the certificate registered in the Certificate Revocation List (CRL) maintained by the certification authority 70. If the digital certificate has expired (S1008:Y), the certification authority 70 determines that the digital certificate has expired (S1009). If the digital certificate has not expired (S1008:N), the certification authority 70 determines that the digital certificate is valid (S1010).

[0092] The certification authority 70, having determined the validity of the electronic signature and the electronic certificate, transmits the verification result of the electronic signature (valid / invalid electronic signature and revoked / valid electronic certificate) to the facsimile machine 20 (S1011). The controller 200 of the facsimile machine 20, via the network communication unit 280, obtains the verification result of the electronic signature transmitted from the certification authority 70 as the verification result of identity authentication (S803). With this, the processes of S80 and S100 are completed.

[0093] S90: Figure 14 is a flowchart showing the validity display process of the verification result of the person authentication. This process starts when the screen showing the verification of the sender 2's person authentication is displayed on the display of the operation unit 250 of the receiving facsimile device 20.

[0094] The controller 200 of the facsimile machine 20 checks whether the digital certificate has expired based on the verification result of the identity authentication obtained from the certification authority 70 in S803 (S901).

[0095] If the digital certificate is valid (S901:N), the controller 200 checks whether the digital signature is invalid or invalid based on the verification result of the identity verification obtained from the certification authority 70 in S803 (S902). If the digital signature is valid (S902:N), the controller 200 displays on the display of the operation unit 250 that it has confirmed that the digital certificate and digital signature are valid (S904) and terminates the process. If the digital signature is invalid (S902:Y), the controller 200 displays on the display of the operation unit 250 that it has confirmed that the digital signature is invalid (S905) and terminates the process.

[0096] If the digital certificate has expired (S901:Y), the controller 200 checks whether the digital signature is invalid or not based on the verification result of the identity verification obtained from the certification authority 70 in S803 (S903). If the digital signature is valid (S903:N), the controller 200 displays on the display of the operation unit 250 that it has confirmed that the digital certificate has expired (S906) and terminates the process. If the digital signature is invalid (S903:Y), the controller 200 displays on the display of the operation unit 250 that it has confirmed that the digital signature is invalid and the digital certificate has expired (S907) and terminates the process.

[0097] In the configuration of the first embodiment described above, information equivalent to an electronic certificate and electronic signature is transmitted and received using the first identity authentication data (two-dimensional code image) within the fax image, and a hash value is transmitted and received using the second identity authentication data (binary file). The receiving facsimile device 20, having received the two-dimensional code image and the hash value, requests the certification authority 70 to verify the identity authentication of sender 2. By confirming that the identity authentication of sender 2 is valid based on the verification result, it becomes possible to determine whether sender 2 is impersonating someone else. Furthermore, it becomes possible to detect tampering with the fax image.

[0098] (Second Embodiment) The second embodiment describes a case where the receiving facsimile device does not have a binary file transfer function. The receiving facsimile device is a general-purpose facsimile device and does not have a user authentication function. In the second embodiment, user authentication is performed using an application program (hereinafter abbreviated as "smartphone AP") installed on a mobile terminal such as a smartphone owned by the recipient 3. Furthermore, in the second embodiment, instead of user authentication by the electronic signature of the IC card 40 as in the first embodiment, user authentication is performed using the user authentication electronic certificate of a publicly known My Number Card, which is a type of IC card. The differences from the first embodiment will be described below.

[0099] Figure 15 is an illustrative diagram of the overall system configuration for fax communication in this embodiment. The facsimile device 10 is the fax sending device, and the facsimile device 20a is the fax receiving device. The facsimile device 20a does not have the optional binary file transfer function. Unlike the facsimile device 20, the facsimile device 20a does not have a network communication unit 280 and cannot communicate with the certification authority 70.

[0100] Facsimile device 10 and facsimile device 20a communicate via an analog public telephone line 30. Both facsimile devices 10 and 20a may be dedicated facsimile machines, but at least one of them may be an image forming device such as a multifunction device that has copying, scanning, printing, and facsimile functions.

[0101] Sender 2 possesses a My Number Card 50, which is used in place of the IC Card 40 in the first embodiment. The facsimile device 10 on the transmitting side performs various processes by communicating with the My Number Card 50 via the NFC communication unit 170.

[0102] Recipient 3 has a mobile terminal 80 equipped with a camera function. The mobile terminal 80 is used to photograph the fax image 222 that the facsimile machine 20a receives from the facsimile machine 10 and prints. Recipient 3 photographs the two-dimensional code image 225 and the background pattern image 226 in the fax image 222 with the mobile terminal 80 and reads them with a smartphone AP 81. The mobile terminal 80 requests the certification authority 70 via the internet 60 to verify the validity of the sender 2's identity authentication.

[0103] Figure 16 is a diagram of the My Number Card 50. The My Number Card 50 is a type of IC card and, in addition to the electronic signature function described in the IC card 40 of the first embodiment, it also has a user authentication function. The My Number Card 50 is issued by the Japan Local Government Information System Organization (JLIS), which operates the public personal authentication service.

[0104] The internal storage device of the My Number Card 50 includes, in addition to the electronic signature AP 41 of the IC card 40 of the first embodiment, a public personal authentication card application program (hereinafter abbreviated as "public personal authentication AP") 51. The public personal authentication AP 51 includes a user authentication electronic certificate 54 containing a user authentication public key 52, a self-signed certificate 55 of the certification authority, a user authentication private key 53, a user authentication electronic signature generation unit 56, and a PIN 57.

[0105] In the second embodiment, since the receiving facsimile device 20a does not have a binary file transfer function, the second identity authentication data of the first embodiment cannot be handled with the binary file transfer data of the fax. For this reason, in the second embodiment, the second identity authentication data is treated as a background image to be added to the image of the transmitted document 1.

[0106] The background image is realized using known digital watermarking techniques, such as those disclosed in Japanese Patent Publication No. 4595014. In other words, in the second embodiment, the transmitting facsimile device 10 includes a background image conversion unit that generates the background image as the second person authentication data conversion unit 135 in Figure 2.

[0107] The CPU 110 of the facsimile machine 10 converts the hash value generated by the hash value generation unit 133 into a background image data using a background image conversion unit, which acts as a second data conversion unit 135 for authenticating the user, and temporarily stores it in the memory 120. The CPU 110 then temporarily stores a composite image in the memory 120, which is a composite image created by combining the two-dimensional code image temporarily stored in the memory 120, the background image data, and the image of the original document 1, using an image synthesis unit 136.

[0108] Figure 17 is an example of a fax image received and printed by the receiving facsimile device 20a. Fax image 222 is the original document 1 image 221 with a background image 226 added.

[0109] The printed watermark image 226 is an image corresponding to the watermark image data generated by the transmitting facsimile device 10d. The receiver 3 reads the watermark image 226 using a mobile terminal 80. The mobile terminal 80 analyzes and decodes the read watermark image 226 using a smartphone AP 81 and converts it into a hash value. The optical encoding used for the watermark image 226 is a known digital watermarking embedding technique, and the decoded hash value is assumed to match the hash value generated by the transmitting facsimile device 10.

[0110] In this embodiment, a digital watermarking technology using a background pattern is given as an example, but any other method is acceptable as long as it is lossless coding and the embedding area is difficult to discern. This is a countermeasure against the fact that the area to be used in two-dimensional code images is easily discernible, making forgery by copying the two-dimensional code image portion. For the second person authentication data used in combination with the two-dimensional code image, which is the first person authentication data, it is suitable to use data with an embedding area that is difficult to discern.

[0111] The fax image 222 of the second embodiment includes a two-dimensional code image 225 encoding information equivalent to an electronic signature, similar to the first embodiment, and further includes a two-dimensional code image 227 for installing the smartphone AP81. The installation two-dimensional code image 227 allows the recipient 3 to be directed to the smartphone AP81 installation site when verifying the identity of the sender 2 for the first time. The text "You can verify the validity of the fax sender's identity by scanning this two-dimensional code image with your smartphone" may be displayed at the bottom of the installation two-dimensional code image 227 to clarify the intent of the two-dimensional code image.

[0112] In the second embodiment, in the fax communication procedure shown in Figure 5, the receiving facsimile device 20a does not have the optional binary file transfer function, so the BFT bit of DIS512 is sent as "0". This notifies the sending facsimile device 10 that the receiving facsimile device 20a does not have the binary file transfer function. Also, the procedure for the binary file transfer message 520 in phase C502 is not performed. In the second embodiment, in the fax transmission and reception process shown in Figure 11, as in the fax transmission and reception in Figure 5, the receiving facsimile device 20a does not have the binary file transfer function, so the process of S504 is not executed.

[0113] Figure 18 is a sequence diagram of fax communication in this embodiment. This sequence diagram shows the processing of the sending facsimile device 10, the receiving facsimile device 20a, the mobile terminal 80, and the certification authority 70. In the second embodiment, since the receiving facsimile device 20 does not have a user authentication function, the facsimile device 20a and the mobile terminal 80 work together to verify the validity of the user authentication of the sender 2 when sending a fax.

[0114] In the second embodiment, in the S30 process, the facsimile device 10 performs the electronic signature of the user authentication electronic certificate 54 of the My Number Card 50 and acquires the user authentication electronic certificate 54. More specifically, in the S306 process in Figure 9, "acquisition of signature electronic certificate 44" is replaced with "acquisition of user authentication electronic certificate 54". Also, in the S307 process in Figure 9, "instruction to generate electronic signature for signing" is replaced with "instruction to generate electronic signature for user authentication". Furthermore, in the S308 process in Figure 9, "acquisition of electronic signature" is replaced with "acquisition of electronic signature of user authentication electronic certificate". In these replaced processes, only the electronic certificates and functional blocks used are replaced; the processing procedure itself remains unchanged.

[0115] In the second embodiment, the flowchart in Figure 9 is replaced as follows. • Electronic signature AP41 → Public personal authentication AP51 • Signature private key 43 → User authentication private key 53 • Signature electronic certificate 44 → User authentication electronic certificate 54 • Self-signed certificate of the Certificate Authority 45 → Self-signed certificate of the Certificate Authority 55 ·Electronic signature generation unit 46→Electronic signature generation unit 56 PIN47 → PIN57

[0116] The My Number Card 50 will generate an electronic signature using the hash value obtained from the facsimile device 10 and the user authentication secret key 53, via the user authentication electronic signature generation unit 56 of the public personal authentication AP 51.

[0117] In the second embodiment, the facsimile device 10 includes "conversion to a background image" in the conversion process to second identity authentication data in S40. More specifically, the process of "conversion to second identity authentication data (other than a two-dimensional code image)" in S402 of Figure 10 becomes the process of "conversion to second identity authentication data (background image)".

[0118] In the second embodiment, the mobile terminal 80 will take over the process from S702 onwards in Figure 12 of the "Create verification request data for person authentication" process in S70. Furthermore, all of the processing in S80 that the receiving facsimile device 20 in Figure 13 performs will be performed by the mobile terminal 80.

[0119] In the second embodiment, the verification of identity performed by the certification authority 70 changes from verifying the validity of the signature electronic certificate 44 of the IC card 40 to verifying the validity of the user authentication electronic certificate 54 of the My Number card 50. However, the validity verification procedure is almost the same. More specifically, the "electronic certificate" used in the process of S1002 in Figure 13 changes from the "signature electronic certificate 44" to the "user authentication electronic certificate 54".

[0120] In S801 of Figure 13, which is part of the processing in S80, the mobile terminal 80 creates data for requesting validity verification of user authentication from the certification authority 70 using the hash value obtained in S703, the digital signature obtained in S705, the user authentication digital certificate 54, and the certification authority's self-signed certificate 55. In the processing from S1001 onwards in Figure 13, the procedure for "validity verification of the signature digital certificate" by the certification authority 70 is replaced by the procedure for "validity verification of the user authentication digital certificate," but the processing itself remains the same, with only the data of the digital certificates etc. used being replaced.

[0121] In the second embodiment, the flowchart in Figure 13 is replaced as follows. • Verification of the validity of the digital signature certificate → Verification of the validity of the digital user authentication certificate • Signature electronic certificate 44 → User authentication electronic certificate 54 • Self-signed certificate of the Certificate Authority 45 → Self-signed certificate of the Certificate Authority 55 • Signing public key 42 → User authentication public key 52

[0122] Figure 19 is a flowchart showing the details of the electronic signature decryption process from the fax image 222 in S70 and S71 of Figure 18 in the second embodiment. In the first embodiment, the process of "decrypting the second party authentication data (hash value) from the fax option message" in S702 of Figure 12 is replaced in the second embodiment by the process of "decrypting the second party authentication data (hash value) from the background image" in S712 of Figure 19.

[0123] The differences between the second embodiment and the first embodiment have been explained above. As explained in Figure 18, the facsimile device of the second embodiment transmits and receives information equivalent to a user authentication electronic certificate and user authentication electronic signature using the first person authentication data (two-dimensional code image) of the fax image 222. It also transmits and receives a hash value using the second person authentication data (a background image other than the two-dimensional code image) of the fax image 222.

[0124] The facsimile machine 20a, upon receiving the fax image 222, prints the fax image 222. The mobile terminal 80 (smartphone AP81), having read the two-dimensional code image 225 and the background image 226 of the printed fax image 222, requests the certification authority 70 to verify the validity of sender 2's user authentication. This verification confirms that sender 2's user authentication is valid, making it possible to determine if sender 2 is impersonating someone else. It also enables the detection of tampering with the fax image.

[0125] In the second embodiment, it is not guaranteed that the smartphone AP81 is pre-installed on the mobile terminal 80 of the recipient 3 who operates the receiving facsimile device 20a. For this reason, as illustrated in Figure 17, a two-dimensional code image 227 for installing the smartphone AP is superimposed on the printed image. This allows the recipient 3 to install and use the smartphone AP81 after receiving the fax image.

[0126] The facsimile devices 10, 20, and 20a described above may all be devices dedicated solely to facsimile, but they may also be image forming devices such as multifunction devices that have copying, scanning, printing, and facsimile functions.

Claims

1. A reading device for reading images of the manuscript, A means of obtaining information necessary for authenticating the sender, A conversion means that generates first person authentication data and second person authentication data based on the acquired information and the image of the document read, A synthesis means for generating a composite image by combining the image of the aforementioned manuscript and the first person authentication data, The system is characterized by comprising a first fax communication means that faxes the composite image to a receiving facsimile device and also transmits the second person authentication data, Facsimile machine.

2. The acquisition means is characterized by acquiring, as information necessary for the authentication of the person, the sender's electronic certificate and an electronic signature based on the image of the document read by the reading means. The facsimile apparatus according to claim 1

3. The acquisition means is characterized by reading the electronic certificate from the IC card storing the sender's electronic certificate, causing the IC card to generate the electronic signature from the hash value of the image of the document read by the reading means, and acquiring the electronic signature. The facsimile apparatus according to claim 2.

4. The conversion means is A first conversion means that generates the first person authentication data using the electronic certificate and the electronic signature, The device is characterized by having a second conversion means that generates the second person authentication data based on the hash value of the image of the document read by the reading means. The facsimile apparatus according to claim 2.

5. The first conversion means is characterized by generating the first person authentication data by converting the electronic certificate and the electronic signature into a two-dimensional code image. The facsimile apparatus according to claim 4.

6. The synthesis means is characterized by generating the synthesized image by combining the two-dimensional code image and the image of the original document read by the reading means. The facsimile apparatus according to claim 5.

7. The second conversion means is characterized by generating the second identity authentication data by converting the hash value into data for binary file transfer. The facsimile apparatus according to claim 4.

8. The first fax communication means is characterized by transmitting the second person authentication data to the receiving facsimile device by binary file transfer. The facsimile apparatus according to claim 7.

9. The second conversion means is characterized by generating the second person authentication data by converting the hash value into a background image. The facsimile apparatus according to claim 4.

10. The first conversion means generates the first person authentication data by converting the electronic certificate and the electronic signature into a two-dimensional code image. The second conversion means generates the second personal authentication data by converting the hash value into a background image. The synthesis means is characterized by generating the synthesized image by combining the two-dimensional code image, the image of the original document read by the reading means, and the background pattern image. The facsimile apparatus according to claim 4.

11. The first fax communication means is characterized by transmitting the composite image to the receiving facsimile device via fax communication. The facsimile apparatus according to claim 10.

12. A second fax communication means for receiving the composite image and the second person authentication data from the facsimile apparatus described in claim 1, A decryption means that obtains and decrypts the first person authentication data from the composite image and decrypts the second person authentication data, A person authentication request means that requests the certification authority to verify the sender's identity using the decrypted first person authentication data and the decrypted second person authentication data, The system is characterized by comprising a display means for displaying the verification result of the authentication of the person by the aforementioned certification authority. Facsimile machine.

13. The second fax communication means receives the first identity authentication data generated by the sender's electronic certificate and an electronic signature based on the image of the document, the composite image formed by combining the image of the document, and the second identity authentication data generated by the hash value of the image of the document. The decoding means is A first decoding means for extracting and decoding the first person authentication data from the composite image, The system is characterized by having a second decryption means for decrypting the hash value from the second identity authentication data, The facsimile apparatus according to claim 12.

14. The aforementioned first data for identity verification is a two-dimensional code image, The first decryption means is characterized by decrypting the electronic certificate and the electronic signature from the two-dimensional code image. The facsimile apparatus according to claim 13.

15. The aforementioned person authentication request means is characterized by creating verification request data from the hash value, the digital certificate, and the digital signature, and transmitting the verification request data and the verification request to the certification authority. The facsimile apparatus according to claim 14.

16. The second fax communication means is characterized by receiving the second person authentication data by binary file transfer. The facsimile apparatus according to claim 12.

17. Having a printing means, The second fax communication means receives a two-dimensional code image which is the first identity authentication data generated by the sender's electronic certificate and an electronic signature based on the image of the document, a background pattern image converted from the second identity authentication data generated by the hash value of the image of the document, and the composite image which is a composite of the image of the document. The printing means is characterized by printing the composite image onto a sheet such that, when captured by a mobile terminal on which an application for decrypting the first and second person authentication data is installed, the first person authentication data is decrypted from the two-dimensional code image and the second person authentication data is decrypted from the background pattern image. The facsimile apparatus according to claim 12.

18. The composite image received by the second fax communication means includes an image for installing the application. The printing means is characterized by printing the two-dimensional code image, the background pattern image, the original image, and the image for installing the application onto the sheet. The facsimile apparatus according to claim 17.

19. An image forming apparatus having facsimile functionality, A reading device for reading images of the manuscript, A means of obtaining information necessary for authenticating the sender, A conversion means that generates first person authentication data and second person authentication data based on the acquired information and the image of the document read, A synthesis means for generating a composite image by combining the image of the aforementioned manuscript and the first person authentication data, The system is characterized by comprising a first fax communication means that faxes the composite image to a receiving facsimile device and also transmits the second person authentication data, Image forming apparatus.

20. An image forming apparatus having facsimile functionality, A second fax communication means for receiving the composite image and the second person authentication data from the image forming apparatus according to claim 19, A decryption means that obtains and decrypts the first person authentication data from the composite image and decrypts the second person authentication data, A person authentication request means that requests the certification authority to verify the sender's identity using the decrypted first person authentication data and the decrypted second person authentication data, The system is characterized by comprising a display means for displaying the verification result of the authentication of the person by the aforementioned certification authority. Image forming apparatus.