Management Device, Management Method, and Management Program

The management device for connectors connected to distributed data storage addresses the challenge of preventing public information forgery and simplifying acquisition by using a structured management system, thereby ensuring secure and efficient data transmission and reception.

JP7684378B2Active Publication Date: 2025-05-27NTT DOCOMO BUSINESS INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023210697
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-12-14
Publication Date
2025-05-27
Estimated Expiration
2043-01-26

AI Technical Summary

Technical Problem

In Japan, to facilitate data circulation through the European data circulation infrastructure, communication carriers construct connectors on behalf of users, but there is a need to prevent forgery of public information associated with digital certificates and simplify the acquisition process of this information.

Method used

A management device that manages the use of connectors connectable to distributed data storage, which includes a reception unit for applications, acquisition units for authentication and digital certificates, a collation unit for verifying contract information, and a registration unit for issuing connector IDs and registering digital certificates.

Benefits of technology

This solution effectively prevents forgery of public information and simplifies the acquisition process, ensuring secure and efficient data transmission and reception while maintaining data sovereignty.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007684378000001
    Figure 0007684378000001
  • Figure 0007684378000002
    Figure 0007684378000002
  • Figure 0007684378000003
    Figure 0007684378000003
Patent Text Reader

Abstract

To prevent tampering of users' public information registered in a connector that can be connected to distributed data storage, and to facilitate the process of obtaining users' public information.SOLUTION: A connector usage acceptance device 110 manages the usage of a connector that can be connected to a distributed data storage via a first communication line. When an authentication result of a line number of a business terminal of a first corporation at the time of applying to use the connector matches contractor information of the first corporation, the connector usage acceptance device 110 obtains a first digital certificate including registry information on the first corporation from a government's corporate digital certificate issuing infrastructure, and registers the first digital certificate in a connector ID of the first corporation.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a management device, a management method, and a management program.

Background Art

[0002] Conventionally, for platform cooperation, a connector for relaying data has been used between the cloud and the edge (see, for example, Patent Document 1).

[0003] In addition, in European countries, a data circulation infrastructure that enables the transmission and reception of highly confidential data while maintaining data sovereignty has been constructed. In this data circulation infrastructure, data transmission and reception are performed using a container-type software connector that functions as a proxy for data exchange, and an authentication and authorization mechanism is also applied to ensure the maintenance of data sovereignty and the security of data transmission and reception. In the European data circulation infrastructure, a digital certificate including a time stamp indicating the certified country and the certified date is associated with the data.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] In Japan, in order to realize data circulation through the European data circulation infrastructure, a communication carrier constructs a connector on behalf of users, and this communication carrier develops a platform for circulating each user's data through each user's connector. In the connector, the connection destination of the data storage of the user of the connector and a digital certificate including the Japanese certification and the certification date for the user of the connector are registered.

[0006] Here, in the connectors managed by the platform, it is required to prevent forgery of the public information of the digital certificates associated with each user's data and to simplify the acquisition process of the public information.

[0007] The present invention has been made in view of the above, and an object thereof is to provide a management device, a management method, and a management program that can be registered in a connector connectable to a distributed data storage, prevent forgery of public information of users, and facilitate the acquisition process of public information of users.

Means for Solving the Problems

[0008] In order to solve the above-described problems and achieve the object, the management device of the present invention is a management device that manages the use of a connector connectable to a distributed data storage via a first communication line provided by a first telecommunications carrier, and includes: a reception unit that receives an application for using the connector of a first corporation from a first business terminal of the first corporation via the first communication line; a first acquisition unit that acquires an authentication result of a line number in the first communication line of the first business terminal at the time of the use application; a collation unit that collates the contract information of the first corporation with respect to the first communication line, information about the first corporation received from the first business terminal at the time of the use application, and the authentication result of the line number of the first business terminal at the time of the use application; a second acquisition unit that, when the contract information of the first corporation, the information about the first corporation received from the first business terminal at the time of the use application, and the authentication result of the line number of the first business terminal at the time of the use application match, acquires a first digital certificate including the registration book information of the first corporation from a digital certificate issuance infrastructure for corporate use of the government; and a registration unit that issues a first connector ID of the first connector to the first corporation and registers the first digital certificate in association with at least the identification information of the first corporation and the first connector ID.

Effects of the Invention

[0009] According to the present invention, it is possible to prevent forgery of public information of users registered in a connector connectable to a distributed data storage, and to facilitate acquisition processing of public information of users.

Brief Description of Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Figure 20

Figure 21

Figure 22

Figure 23

[0011] Hereinafter, embodiments of the management apparatus, management method, and management program according to the present application will be described in detail with reference to the drawings. Note that the management apparatus, management method, and management program according to the present application are not limited by this embodiment.

[0012] In the following embodiments, the flow of processing in the management apparatus and management method in the embodiments will be described in order, and finally the effects of the embodiments will be described.

[0013] [Embodiment 1] Embodiment 1 will be described. In Embodiment 1, a first communication carrier constructs a connector on behalf of a corporate user, constructs a platform that enables data of each corporation to flow through the connector of each user, and realizes data flow through another data flow infrastructure. An example will be described.

[0014] In Embodiment 1, on the platform side of the first communication carrier, based on the line authentication result of the user by the first communication carrier and the contract information of the first communication carrier, it is verified that the user himself uses the connector, and the connector is set. Therefore, it is possible to prevent the forgery of public information by persons other than the user.

[0015] Then, on the platform side of the first communication carrier, public information (digital certificate) is acquired on behalf of the user and registered in the attribute information of the connector. Therefore, it is not necessary for the user himself to perform the process of acquiring public information, and simple and secure use of the connector becomes possible.

[0016] Note that the connector is container-type software that enables connection to a distributed data storage. Specifically, the connector is software provided by the International Data Spaces Association (IDSA). The connector is installed on an edge computer or the like, and by being set and registered, access control to the distributed data storage is realized based on laws and contracts. Thereby, the security of data transmission and reception is ensured.

[0017] [Line contract] In Embodiment 1, the description is made on the premise that Company A (the first corporation) that applies for the use of the connector has a line contract with the first communication carrier, and further, an employee S (the second user) belonging to Company A has a line contract with the first communication carrier for the personal terminal device of employee S. FIG. 1 is a diagram for explaining the line contract of the terminal device.

[0018] As shown in FIG. 1, when making a line contract for the business terminal 10A (the first business terminal) of Company A, in the communication carrier system of the first communication carrier, an employee of the communication carrier registers data including the registration information of Company A in the corporate contract information database (DB) 30 via the business terminal 31 ((1-1) in FIG. 1). The registration information of Company A is public information obtained from the registration information providing service of the legal affairs bureau.

[0019] In the corporate contractor information DB30, registration information including the contractor ID issued by the first communications carrier to Company A, Company A's corporate number, trade name, address, and date of establishment is registered in association with the contractor ID. Then, the communications carrier system associates the contractor ID of Company A, the line number set for Company A, the email address of Company A's business terminal 10A, etc. with the termination device 10E of Company A's contract line.

[0020] When employee S enters into a line contract for his / her personal contract terminal 10S (the third terminal), in the communications carrier system of the first communications carrier, a communications carrier employee registers the data of employee S's My Number card in the personal contractor information DB40 via the business terminal 41 ((1-2) in Fig. 1). The My Number card is an identity verification card institutionalized by the Ministry of Internal Affairs and Communications, and it records the resident number assigned to each resident, name, address, date of birth, face photo, etc.

[0021] In the personal contractor information DB40, resident information including the contractor ID issued by the first communications carrier to employee S, the resident number (JPKI serial number) of employee S authenticated using the public personal authentication service (JPKI), name, address, and date of birth is registered in association with the contractor ID. Then, the communications carrier system associates the contractor ID of employee S, the line number set for employee S, the email address of the personal contract terminal 10S, etc. with the SIM of the personal contract terminal 10S of Company S.

[0022] In this way, the contractor ID, line number, and the registration information of Company A, which is the line contractor, or the resident information of employee S are registered in the communications carrier system. In the following description, for the sake of simplicity of explanation, the corporate contractor information DB30 and the personal contractor information DB40 are combined and described as the corporate and personal contractor information DB130. The corporate and personal contractor information DB130 stores the contractor information of each corporation and each individual for the first communication line.

[0023] [Application for Using Connector] Next, a case where the first telecommunications carrier newly issues the connectors used by Company A will be described. First, the communication system in Embodiment 1 will be described. FIG. 2 is a schematic diagram showing an example of the configuration of the communication system in Embodiment 1.

[0024] As shown in FIG. 2, in the first telecommunications carrier, a platform system (telecommunications carrier system 100) is constructed that builds the connectors of each corporation and enables data linkage to a data storage that stores the data of each corporation. In FIGS. 2 to 12, the process until the telecommunications carrier system 100 builds the connector 50A of Company A and accumulates data in the data storage 60A that stores the data of Company A via the connector 50A will be described as an example.

[0025] At Company A, an employee S who holds a personal contract terminal 10S applies for the use of the connector using the business terminals 10A and 10B (second business terminals) of Company A that are registered in the telecommunications carrier system 100. Employee S has a personal contract terminal 10S that the employee S has contracted with the first telecommunications carrier personally.

[0026] The telecommunications carrier system 100 can communicate with the Japanese government and local government system 200 having a corporate digital certificate issuance infrastructure 210, a register information DB 220, a personal digital certificate issuance infrastructure 230, and a resident information DB 240. The corporate digital certificate issuance infrastructure 210 is a trans-anchor that issues a digital certificate including the registration information of a corporation using the register information DB 220. The personal digital certificate issuance infrastructure 230 is a trans-anchor that issues a digital certificate including the resident number of an individual using the resident information DB 240.

[0027] The business terminal 400 is a terminal installed in the communication carrier system 100 or in a government or local government entity, and sets a library of data that can be provided by the connector 50A for the connector 50A. The business terminal 400 registers, in the library, as data storage information, the connector ID of the connector 50A and the data storage location, and also registers the ID of the party permitted to disclose the data, the nationality of the party permitted to disclose the data, the location of the party permitted to disclose the data, and the date for permitting the data disclosure.

[0028] The communication carrier system 100 includes a connector use acceptance device 110 (management device) that accepts applications for using connectors, a line authentication system 120, a corporate and individual contractor information DB 130, a mail system 140, a digital certificate management agency system 150, a logo DB 160 (database), and a seal impression DB 170.

[0029] The line authentication system 120 authenticates the line of the terminal at the communication source that communicates via the first communication line. The line authentication system 120 authenticates the line number and location information (for example, line installation location ID or radio base station ID) of the terminal at the communication source.

[0030] The mail system 140 performs mail transmission and reception with each terminal, for example, in response to an instruction from the connector use acceptance device 110.

[0031] The digital certificate management agency system 150 requests the issuance of a digital certificate from the Japanese government or local government system 200 on behalf of the contractor of the first communication carrier.

[0032] The logo DB 160 stores, in association with each other, the identification information (corporate number) of each corporation and the logo (design image) data symbolizing each corporation. The logo includes a logo mark, a symbol mark, and a logotype.

[0033] The seal impression DB 170 stores, in association with each other, the identification information of the contractor of the first communication carrier and the seal impression data of the contractor of the first communication carrier.

[0034] The connector usage acceptance device 110 accepts the use of connectors by subscribers of the first telecommunications carrier and manages the use of connectors. The connector usage acceptance device 110 manages the use of a connector (e.g., 50A) that can be connected to a distributed data storage (e.g., data storage 60A) via a first communication line provided by the first telecommunications carrier. The connector usage acceptance device 110 connects to the termination device 10E of the contract line of Company A and the personal contract terminal 10S of employee S of the company, and executes various processes until the connector 50A of Company A is set and registered, such as line authentication of each terminal, issuance of the connector ID of the connector 50A of Company A, acquisition of a digital certificate, and association with the connector ID.

[0035] FIG. 3 is a block diagram showing an example of the configuration of the connector usage acceptance device 110 shown in FIG. 2. The connector usage acceptance device 110 includes a reception unit 111, a first acquisition unit 112, a verification unit 113, a first transmission control unit 114, a second acquisition unit 115, a registration unit 116, and a second transmission control unit 117.

[0036] The reception unit 111 accepts a request to use the first connector of Company A from the business terminal 10A of Company A via the first communication line provided by the first telecommunications carrier. The reception unit 111 accepts, via the first communication line, a request to register the first connector by employee S belonging to Company A from the business terminal 10A of Company A, the name of employee S, and the telephone number of the personal contract terminal 10S personally owned by employee S.

[0037] The first acquisition unit 112 acquires, from the line authentication system 120, the authentication result (the authentication result of the line number of Company A) of the line number in the first communication line of the business terminal 10A at the time of the request to use the first connector of Company A. The first acquisition unit 112 acquires, from the line authentication system 120, the authentication result of the line number in the first communication line of the business terminal 10A and the authentication result of the line number in the first communication line of the personal contract terminal 10S at the time of the request to register the first connector by employee S.

[0038] The verification unit 113 performs data verification by sending a verification request to the corporate / individual contractor information DB 130 and receiving the verification request from the corporate / individual contractor information DB 130. The verification unit 113 verifies the contractor information of Company A in the corporate / individual contractor information DB 130 with the information about Company A received from the business terminal 10A at the time of application for use of the first connector of Company A and the authentication result of the line number in the first communication line of Company A at the time of application for use.

[0039] The verification unit 113 verifies the contractor information of Company A in the corporate / individual contractor information DB 130 with the authentication result of the line number in the first communication line of the business terminal 10A at the time of registration application of the first connector by employee S. At the same time, the verification unit 113 verifies the contractor information of employee S in the corporate / individual contractor information DB 130 with the name of employee S received at the time of registration application of the first connector by employee S and the phone number of the personal contract terminal 10S.

[0040] When the contractor information of Company A in the corporate / individual contractor information DB 130 matches the information about Company A received from the business terminal 10A at the time of application for use and the authentication result of the line number in the first communication line of the business terminal 10A at the time of application for use, the first transmission control unit 114 causes the mail system 140 to send a first one-time password to the business terminal 10B with which Company A contracts.

[0041] When the contractor information of Company A in the corporate / individual contractor information DB 130 matches the line number in the first communication line of the business terminal 10A at the time of registration application, and the contractor information of employee S in the corporate / individual contractor information DB 130 matches the name of employee S received at the time of registration application and the phone number in the first communication line of the personal contract terminal 10S of employee S, the first transmission control unit 114 causes the mail system 140 to send a second one-time password to the personal contract terminal 10S.

[0042] When the second acquisition unit 115 receives the first one-time password from the business terminal 10A, it requests the corporate digital certificate issuance infrastructure 210 to issue a digital certificate (first digital certificate) of Company A including the registration information of Company A via the digital certificate management agency system 150. Then, the second acquisition unit 115 acquires the digital certificate of Company A from the corporate digital certificate issuance infrastructure 210.

[0043] When the second acquisition unit 115 receives the second one-time password from the business terminal 10A, it requests the personal digital certificate issuance infrastructure 230 to issue a digital certificate (second digital certificate) of employee S himself / herself, that is, a digital certificate including the identification number (personal number) of employee S via the digital certificate management agency system 150. Then, the second acquisition unit 115 acquires the digital certificate of the second user, employee S, from the personal digital certificate issuance infrastructure 230.

[0044] The registration unit 116 issues the first connector ID of the connector 50A to Company A, and registers at least the identification information of Company A and the first digital certificate of Company A in association with the first connector ID. The registration unit 116 registers the second digital certificate of employee S in association with the first connector ID.

[0045] At this time, the registration unit 116 acquires the logo data of Company A from the logo DB 160, and registers the identification information of Company A, the first digital certificate of Company A, and the logo data of Company A in association with the first connector ID.

[0046] When the second transmission control unit 117 receives a disclosure request for data registered by Company A from the terminal used by the third user via the connector of the third user, it transmits the visualization information of the identification information of Company A, the first digital certificate of Company A, and the logo of Company A together with the data for which disclosure is requested to the terminal used by the third user for display. At that time, the second transmission control unit 117 may also transmit the impression data of employee S who registered the data and display it on the terminal used by the third user.

[0047] [Flow 1 of Application for Using Connector] Next, the processing flow of the application for using the connector by Company A will be described. FIG. 4 is a diagram for explaining the processing flow of the application for using the connector in Embodiment 1. FIG. 5 is a sequence diagram showing the processing flow of the application for using the connector in Embodiment 1.

[0048] An employee S of Company A operates the business terminal 10A of Company A and inputs data for applying to use the first connector of Company A (step (1) in FIG. 4, step S1 in FIG. 5). From the business terminal 10A, the contractor ID of Company A with the first communication carrier, the corporate number, the trade name, the address, the establishment date, and the email address are input.

[0049] The input data is transmitted to the connector use acceptance device 110 together with the application for using the connector via the termination device 10E of the contract line of Company A, etc. (step S2 in FIG. 5).

[0050] In the communication carrier system 100, the line authentication system 120 authenticates the line number in the first communication line of the business terminal 10A when applying to use the first connector of Company A. The line authentication system 120 transmits the line number at the time of applying to use the connector to the connector use acceptance device 110 (step (2) in FIG. 4, step S3 in FIG. 5).

[0051] The connector use acceptance device 110 requests data collation between the contractor information of Company A in the corporate / individual contractor information DB130, the information about Company A received from the business terminal 10A when applying to use the first connector of Company A, and the authentication result of the line number in the first communication line of Company A at the time of applying to use the connector (step (3) in FIG. 4, step S4 in FIG. 5). The connector use acceptance device 110 inputs the contractor ID of Company A, the corporate number, the trade name, the address, the line number authenticated by the line authentication system 120, and the email address received from the business terminal 10A into the corporate / individual contractor information DB130.

[0052] The corporate / individual contractor information DB 130 collates the data input from the connector use acceptance device 10 with the data on the corporate / individual contractor information DB 130 (Fig. 4(A), step S5 in Fig. 5), and notifies the connector use acceptance device 110 of the collation result (Fig. 4(4), step S6 in Fig. 5).

[0053] The connector use acceptance device 10 refers to the collation result. When the collation results match, it requests the mail system 140 to send the first one-time password (PW) to the business terminal 10B contracted by Company A (Fig. 4(4), step S7 in Fig. 5). The mail system 140 sends a PW notification email containing the first one-time PW to the business terminal 10B (Fig. 4(5), step S8 in Fig. 5). As a result, the business terminal 10B receives the PW notification email containing the first one-time PW. Note that the business terminal 10B may be a PC terminal in addition to a mobile terminal.

[0054] Employee S refers to the PW notification email sent to the business terminal 10B and enters the first one-time PW on the registration screen of the business terminal 10A (Fig. 4(6), step S9 in Fig. 5).

[0055] When the first one-time PW received from the business terminal 10A is correct, the connector use acceptance device 110 notifies the corporate digital certificate issuance infrastructure 210 of Company A's corporate number via the digital certificate management agency system 150 and requests the issuance of the first digital certificate of Company A (Fig. 4(7),(8), step S10 in Fig. 5).

[0056] The corporate digital certificate issuance infrastructure 210 refers to the register information in the register information DB 220 (step S11 in Fig. 5), issues the first digital certificate of Company A, and sends it to the connector use acceptance device 110 (Fig. 4(9), step S12 in Fig. 5). The first digital certificate includes Company A's corporate number, trade name, address, date of establishment, and the issuance date of this first digital certificate.

[0057] The connector usage acceptance device 110 searches for the logo of Company A using the corporate number of Company A from the logo DB 160 (Fig. 4(10)) and acquires the logo data of Company A (Fig. 4(11), step S13 in Fig. 5).

[0058] The connector usage acceptance device 110 issues the first connector ID of the connector 50A to Company A (step S14 in Fig. 5), registers the attribute information 300 of Company A in the first connector ID (Fig. 4(12), step S15 in Fig. 5), and activates the connector 50A in the business-use terminal 10A of Company A. As the attribute information of the first connector, the first connector ID, the subscriber ID of Company A in the first communications carrier, the corporate number, the trade name, the address, the establishment date, the first digital certificate of Company A, and the logo data of Company A are registered.

[0059] [Flow of Connector Usage Application 2] Next, the processing flow when employee S of Company A applies for registration of the first connector will be described. Fig. 6 is a diagram for explaining the processing flow of connector registration application in Embodiment 1. Fig. 7 is a sequence diagram showing the processing flow of connector registration application in Embodiment 1.

[0060] Employee S of Company A operates the business-use terminal 10A of Company A and inputs data for applying for registration of the first connector of employee S (Fig. 6(1), step S21 in Fig. 7). From the business-use terminal 10A, the subscriber ID of Company A in the first communications carrier, the trade name, the address, the establishment date, the phone number of the personal contract terminal (for example, the personal contract terminal 10S), the name of the personal contract terminal user (in this example, the name of employee S), and the email address of the personal contract terminal are input.

[0061] The input data is transmitted to the connector usage acceptance device 110 together with the application for using the connector via the terminal device 10E at the end of the contract line of Company A, etc. (step S22 in Fig. 7).

[0062] In the communication carrier system 100, the line authentication system 120 authenticates the line number in the first communication line of the business terminal 10A when the registration application of the first connector of the employee S is made. The line authentication system 120 transmits the line number at the time of the connector registration application to the connector usage acceptance device 110 (Figure 6(2), step S23 in Figure 7).

[0063] The connector usage acceptance device 110 requests data comparison between the contractor information of Company A in the corporate / individual contractor information DB 130 and the authentication result of the line number in the first communication line of the business terminal 10A when the employee S applies for registration of the first connector (Figure 6(3), step S24 in Figure 7). At the same time, the connector usage acceptance device 110 requests the corporate / individual contractor information DB 130 to perform data comparison between the contractor information of the employee S in the corporate / individual contractor information DB 130 and the name of the employee S and the telephone number of the personal contract terminal 10S received when the employee S applies for registration of the first connector (Figure 6(3), step S24 in Figure 7).

[0064] The connector usage acceptance device 110 inputs the contractor ID, company name, address, line number, telephone number of the personal contract terminal (in this example, the personal contract terminal 10S), name of the personal contract terminal user (in this example, the name of the employee S), and email address of the personal contract terminal received from the business terminal 10A into the corporate / individual contractor information DB 130.

[0065] The corporate / individual contractor information DB 130 compares the data input from the connector usage acceptance device 110 with the data on the DB (Figure 6(A), step S25 in Figure 7), and notifies the connector usage acceptance device 110 of the comparison result (Figure 6(4), step S26 in Figure 7).

[0066] The connector usage acceptance device 110 refers to the verification result. If the verification result matches, it requests the mail system 140 to send a second one-time PW to the personal contract terminal 10S with which employee S has a contract (step (4) in FIG. 6, step S27 in FIG. 7). The mail system 140 sends a PW notification mail including the second one-time PW to the personal contract terminal 10S (step (5) in FIG. 6, step S28 in FIG. 7). As a result, the personal contract terminal 10S receives the PW notification mail including the second one-time PW. Note that the personal contract terminal 10S may be a PC terminal in addition to a mobile terminal. Also, the mail system 140 may send a PW notification mail including the second one-time PW to the business terminal 10B.

[0067] Employee S refers to the PW notification mail sent to the personal contract terminal 10S and enters the second one-time PW on the registration screen of the business terminal 10A (step (6) in FIG. 6, step S29 in FIG. 7). Then, employee S enters the connector ID, employee ID, resident number (JPKI serial number), name, address, date of birth, and mobile phone number of the personal contract terminal 10S on the registration screen of the business terminal 10A (step (7) in FIG. 6). The input data is sent to the connector usage acceptance device 110 via the termination device 10E of the contract line of Company A or the like.

[0068] If the second one-time PW received from the business terminal 10A by the connector usage acceptance device 110 is correct, it notifies the personal digital certificate issuance infrastructure 230 of the resident number of employee S via the digital certificate management proxy system 150 and requests the issuance of the second digital certificate of employee S (steps (8) and (9) in FIG. 6, step S30 in FIG. 7).

[0069] The personal digital certificate issuance infrastructure 230 refers to the resident information in the resident information DB240 (step S31 in FIG. 7), issues the second digital certificate of employee S, and sends it to the connector usage acceptance device 110 (step (10) in FIG. 6, step S32 in FIG. 7). The second digital certificate includes the resident number, name, address, date of birth of employee S, and the issuance date of this second digital certificate.

[0070] The connector usage acceptance device 110 searches for the seal impression of employee S using the employee number of employee S from the seal impression DB 170 (Fig. 6(11)) and acquires the seal impression data of employee S (Fig. 6(12)).

[0071] The connector usage acceptance device 110 registers, as connector attribute information 300A, the information of employee S in association with the first connector ID (Fig. 6(13), step S33 in Fig. 7). At this time, the information registered in association with the first connector ID is the contractor ID of Company A, the second digital certificate of employee S, and the seal impression data of employee S.

[0072] [Example of registration screen] By executing the processes of Figs. 3 to 7 in the communication carrier system 100, as will be described later, employee S can register the connector of Company A by performing only simple processes such as inputting the corporate contract line ID, selecting the registration button, inputting the corporate personal number ID and the JPKI serial personal number, inputting the telephone numbers of the corporate contract and the personal contract, and inputting the one-time PW. That is, employee S does not need to input the corporate number, trade name, address, establishment date, and email address of Corporation A, and the resident number, name, address, and date of birth of employee S.

[0073] Therefore, the actual data input flow on the connector registration screen of the business terminal 10A will be described. Figs. 8 and 9 are diagrams showing an example of the connector registration screen.

[0074] First, when applying for connector use, on the registration screen W1 of Fig. 8 displayed on the business terminal 10A, employee S selects the first communication carrier in column D3 as the corporate contract line ID and enters the mobile phone number of the business terminal (for example, business terminal 10B) that contracts with the first communication carrier in column D4. Then, employee S selects the one-time password (PW) transmission button D5. As a result, the business terminal 10B receives a PW notification email including the first one-time PW "123456" (arrow Y1).

[0075] Here, it is assumed that, similar to the individual My Number, a system is institutionalized in which different corporate My Number IDs are assigned to each corporation.

[0076] Employee S enters the first one-time PW "123456" in column D6 and enters the corporate My Number ID of Company A in column D7. Then, Employee S selects the company information automatic acquisition button D8. As shown by arrow Y2, the corporate number, business name, address, and establishment date corresponding to the corporate My Number ID are automatically displayed in each column of area D9. The information displayed in this area D9 is set so that it cannot be rewritten. Then, when Employee S presses the registration button B1, the connector ID and user ID are issued, and the registration screen W2 shown in FIG. 9 is displayed.

[0077] As shown in the registration screen W2, when Employee S applies for registration of the connector, Employee S enters the connector ID and user ID in columns D1 and D2, and enters the employee ID in column D13. Further, Employee S selects the first telecommunications carrier in column D14 as the personal contract line ID and enters the phone number of Employee S's own personal contract terminal 10S in column D15. Employee S selects the one-time PW transmission button D16. As a result, the personal contract terminal 10S receives a PW notification email including the second one-time PW "987654" (arrow Y11).

[0078] Employee S enters the second one-time PW "987654" in column D17 and enters Employee S's JPKI serial number in column D18. Then, Employee S selects the personal information automatic acquisition button D19. As shown by arrow Y12, the name, nationality, address, and date of birth corresponding to the JPKI serial number are automatically displayed in each column of area D20. The information displayed in this area D20 is set so that it cannot be rewritten. Then, when Employee S presses the registration button B2, Employee S's residential information is registered in association with the first connector ID.

[0079] [Data registration process] Next, the process flow until data is registered in the data storage 60A of Company A will be described. FIG. 10 is a diagram for explaining the process flow of data registration in Embodiment 1. FIG. 11 is a sequence diagram showing the process flow of data registration in Embodiment 1. A case where an employee S of Company A registers the latest certificate and manufacturing data will be described as an example.

[0080] Employee S inputs data on the login screen of the connector 50A from the business terminal 10A (step (1) in FIG. 10, step S41 in FIG. 11), and requests the connector usage acceptance device 110 to log in to the connector 50A (step S42 in FIG. 11). Employee S inputs the contractor ID assigned to Company A and the login PW.

[0081] In the communication carrier system 100, the line authentication system 120 authenticates the line number and the line installation location ID (location information) in the first communication line of the business terminal 10A when a login request is made for the first connector of Company A. The line authentication system 120 transmits the line number and the line installation location ID in the login request to the connector usage acceptance device 110 (step (2) in FIG. 10, step S43 in FIG. 11).

[0082] Based on the line number in the first communication line of the business terminal 10A, the connector usage acceptance device 110 requests the corporate / individual contractor information DB 130 to confirm that the contract of Company A is still valid (step S44 in FIG. 11). The corporate / individual contractor information DB 130 confirms that the contract of Company A is still valid (step (A) in FIG. 10, step S45 in FIG. 11), and notifies the connector usage acceptance device 110 of the confirmation result (step S46 in FIG. 11).

[0083] When the confirmation result indicates that the contract of Company A is still valid, the connector usage acceptance device 110 requests the mail system 140 to send the third one-time PW (step S47 in FIG. 11).

[0084] The mail system 140 sends a PW notification mail including a third one-time PW to the business terminal 10B or the personal contract terminal 10S (step (3) in FIG. 10, steps S48 and S49 in FIG. 11).

[0085] Employee S refers to the PW notification mail sent to the business terminal 10B or the personal contract terminal 10S, and inputs the third one-time PW via the business terminal 10B or the personal contract terminal 10S. As a result, the third one-time PW is sent from the business terminal 10B or the personal contract terminal 10S to the connector use acceptance device 110 (step (4) in FIG. 10, steps S50 and S51 in FIG. 11).

[0086] Then, in the communication carrier system 100, the line authentication system 120 authenticates the line number in the first communication line of the personal contract terminal 10S and the radio base station ID (location information) when the third one-time PW of the personal contract terminal 10S is transmitted. The line authentication system 120 transmits the radio base station ID (location information) together with the line number of the personal contract terminal 10S to the connector use acceptance device 110 (step (5) in FIG. 10, step S52 in FIG. 11).

[0087] When the third one-time PW received from the business terminal 10B or the personal contract terminal 10S is correct and the authentication result of the line number of the personal contract terminal 10S matches the contractor information of employee S in the corporate and personal contractor information DB130, the connector use acceptance device 110 requests the acquisition of the latest digital certificates of Company A and employee S via the digital certificate management agency system 150 (step S53 in FIG. 11). The connector use acceptance device 110 notifies the corporate digital certificate issuance infrastructure 210 and the personal digital certificate issuance infrastructure 230 of the corporate number of Company A and the resident number of employee S (steps (6) and (8) in FIG. 10).

[0088] The corporate digital certificate issuance infrastructure 210 refers to the registry information in the registry information DB 220 (step S54 in FIG. 11), obtains the first digital certificate of Company A, and transmits it to the connector usage reception device 110 (item (7) in FIG. 10, step S56 in FIG. 11). The first digital certificate includes Company A's corporate number, trade name, address, date of establishment, and the issuance date of this first digital certificate.

[0089] Also, the personal digital certificate issuance infrastructure 230 refers to the resident information in the resident information DB 240 (step S55 in FIG. 11), obtains the second digital certificate of employee S, and transmits it to the connector usage reception device 110 (item (9) in FIG. 10, step S56 in FIG. 11). The second digital certificate includes employee S's resident number, name, address, date of birth, and the issuance date of this second digital certificate.

[0090] The connector usage reception device 110 registers, as connector attribute information 300A, the data registrant information (the latest first digital certificate (corporate certificate), the latest second digital certificate (resident certificate), line installation location ID, wireless base station ID, additional note date) in association with the first connector ID (item (10) in FIG. 10).

[0091] The business terminal 400 sets the library 500A in which the data storage location information is registered in the connector 50A (item (11) in FIG. 10). The business terminal 400 registers in the library, as data storage information, the connector ID of the connector 50A and the data storage location (URL / URI information), and also registers the ID of the party permitted to disclose the data, the nationality of the party permitted to disclose the data, the location of the party permitted to disclose the data, and the date for permitting the disclosure of the data.

[0092] Then, the connector usage reception device 110 stores, via the connector 50A, the manufacturing data requested for storage from Company A and the data registrant information (item (10) in FIG. 10) in the data storage 60A (item (12) in FIG. 10, steps S57, S58 in FIG. 11).

[0093] [Effect of Embodiment 1] In Embodiment 1, the first communications carrier constructs connectors on behalf of the corporate users, constructs a platform that enables the data of each corporation to flow through the connectors of each user, and realizes secure data flow through other data flow infrastructures.

[0094] In Embodiment 1, in response to an application for using a connector by the business terminal 10A of Company A, based on the line authentication result and the verification result of the subscriber information, the communications carrier system 100 confirms that it is an application for using a connector by Company A itself, and then issues a first connector ID to Company A.

[0095] That is, according to Embodiment 1, the communications carrier system 100 confirms that it is an application for using a connector by Company A itself. Therefore, it is not necessary for Company A to perform complicated processes to prove that it is an application for using a connector by Company A itself.

[0096] In addition, the communications carrier system 100 requests, on behalf of Company A, the issuance of the first digital certificate of Company A from the corporate digital certificate issuance infrastructure 210 of the Japanese government and local government system 200, and registers the digital certificate of Company A in the connector ID issued to Company A. Therefore, it is not necessary for Company A to perform complicated processes for obtaining public information.

[0097] Here, as shown in the screen example of FIG. 12, if the registry information is entered manually, it is possible to be forged by someone else (FIG. 12(1)). In contrast, in Embodiment 1, as shown in the registration screen W1 of FIG. 8, when the line authentication result and the subscriber information of Company A match the subscriber information in the corporate / individual subscriber information DB 130, in response to the input of the first one-time PW on the registration screen W1, the registration information of Company A is automatically displayed. Therefore, it is possible to prevent the falsification of public information by anyone other than Company A.

[0098] In addition, since the communication carrier system 100 constructs the connector on behalf of Company A, Company A can connect to the distributed DB via the originally contracted first communication line. For example, on the Company A side, manufacturing data can be stored in the data storage 60A allocated to itself via the connector 50A.

[0099] When a request for accessing Company A's data is made via the connectors of other users, the connector 50A sends the requested data with Company A's first digital certificate attached. That is, other users can access the data in a state where it is proven to the Japanese government that this data of Company A has been registered by Company A. Thus, the retention of data sovereignty can be ensured.

[0100] Furthermore, in the communication carrier system 100, regarding the individual (employee S) who registered the data registered by Company A, based on the line authentication result and the collation result with the contractor information, it is confirmed that it is the employee S himself / herself. Then, the communication carrier system 100 acquires the second digital certificate of the employee S on behalf of the employee S and registers it in association with the connector ID. Therefore, the employee S himself / herself does not need to perform complicated processes for acquiring his / her own public information.

[0101] At this time, as shown in the screen example of FIG. 13, if the residential information of the employee S is manually input, it is possible for someone else to forge it (FIG. 13(1)). On the other hand, in the first embodiment, as shown in the registration screen W2 of FIG. 9, when the line authentication result and the contractor information of the personal contract terminal 10S of the employee S match the contractor information in the corporate / individual contractor information DB 130, in response to the input of the second one-time PW on the registration screen W2, the residential information of the employee S is automatically displayed. Therefore, it is possible to prevent the falsification of public information by anyone other than the employee S.

[0102] Also, when the connector 50A receives a data reference request from Company A, it can guarantee data at a finer-grained individual level than the corporate level in order to send the requested data while ensuring that the data was registered by Employee S, who is an employee of Company A.

[0103] Thus, in Embodiment 1, a digital certificate issued by the Japanese government is attached, and the data storage registers data for which the registrants (corporations and individuals) and the registration locations have been verified by the communication carrier system 100.

[0104] And in Embodiment 1, while ensuring the retention of data sovereignty and the security of data transmission and reception, it is possible to prevent the forgery of the public information of Company A and Employee S and to facilitate the acquisition process of the public information of Company A and Employee S.

[0105] Note that in Embodiment 1, the connector was used as an example for explanation, but the applicable applications are not limited to connectors. For example, when the application itself is distributed and the ID of the application user is embedded in the application itself, Embodiment 1 can be applied. That is, the communication carrier system 100 guarantees the application users (corporations and individuals) and their registration locations based on the line authentication result and the verification result of the contract information, and registers the user ID in the application.

[0106] [Embodiment 2] Next, Embodiment 2 will be described. In Embodiment 2, an example of data provision via a connector will be described.

[0107] FIG. 14 is a schematic diagram showing an example of the configuration of the communication system in Embodiment 2. As shown in FIG. 14, for example, a case where a reference to product data is requested from the terminal 70X of Company X will be described as an example. Company X is, for example, a recycling company that disassembles automobiles and recycles the automobile batteries (storage batteries).

[0108] By communicating with the data linkage system 600, the terminal 70X requests a search for information on the battery, the components used in the battery, and their raw materials, and displays the data provided by the data linkage system 600.

[0109] The data storage 60I stores the product data registered by Battery Manufacturer I. The data storage 60J stores the product data registered by Component Manufacturer J. The data storage 60K stores the product data registered by Material Manufacturer K. The data held by the data storages 60I, 60J, and 60K is registered using the processing method in Embodiment 1, and is attached with a digital certificate issued by the Japanese government, and the registrant (corporation and individual) and the registration location are certified by the communication carrier system 100.

[0110] The data linkage system 600 includes a search unit 610 that receives a search request and provides information to the requester, connectors for each company (for example, the connector 50X for Company X), attribute information of the connectors (for example, the connector attribute information 300X of Company X), a product / part data search information DB 660 that returns search key information when receiving a search request, the connector 50I of Battery Manufacturer I, the library 500I for the connector 50I, the connector 50J of Component Manufacturer J, the library 500J for the connector 50J, the connector 50K of Material Manufacturer K, and the library 500K for the connector 50K. Note that the data linkage system 600, similar to the communication carrier system 100 shown in FIG. 2, has a connector usage acceptance device 110 and a line authentication system 120 for the communication line used in the data linkage system 600, and also performs line authentication and location information acquisition of the terminal 70X that is the data search requester.

[0111] FIG. 15 is a diagram for explaining the flow of communication processing in Embodiment 2. FIG. 16 is a sequence diagram showing the flow of communication processing in Embodiment 2. In FIG. 15, the case where product information of an automobile battery is searched from the terminal 70X of Company X is described as an example.

[0112] The terminal 70X reads the two-dimensional code attached to the battery and obtains the product passport ID (step S61 in FIG. 16). Then, the terminal 70X requests the search unit 610 to search for manufacturing data including the product passport ID ((1) in FIG. 15, step S62 in FIG. 16).

[0113] The search unit 610 performs a search for manufacturing data using the connector ID of Company X and the product passport ID from the information stored in the product / part data search information DB 660 via the connector 50X of Company X ((2) in FIG. 15, steps S63 and S64 in FIG. 16).

[0114] The product / part data search information DB 660 returns search key information to the search unit 610 ((3) in FIG. 15, step S65 in FIG. 16). The search key information includes the product passport ID and the connector ID of battery manufacturer I that manufactured the battery. Note that the same process is executed when requesting product data of products from component manufacturer J and material manufacturer K.

[0115] The search unit 610 requests the disclosure of the manufacturing data of the battery from the data storage 60I via the connector 50X of Company X and the connector 50I of Company I ((4) in FIG. 15, steps S66 and S67 in FIG. 16). In response, the data storage 60I discloses the manufacturing data ((5) in FIG. 15, steps S68 and S69 in FIG. 16). The manufacturing data includes the product passport ID, manufacturing data storage destination URL information, component ID, and data registrant information (information shown in (10) of FIG. 10).

[0116] The data storage 60I acquires the ID of Company X that owns the terminal 70X, nationality, the location of the terminal 70X, and the date of the disclosure request. If the acquired data is included in the ID of the party permitted to disclose, nationality, terminal location information, and the date permitting data housework registered in the library 500I, it permits the disclosure of the manufacturing data of the terminal 70X. Note that the data storage 60J and the data storage 60K also determine the availability of data disclosure according to the information registered in the libraries 500J and 500K when receiving a disclosure request.

[0117] Based on the manufacturing data of the battery disclosed from the data storage 60I, the search unit 610 requests the disclosure of the manufacturing data of the battery parts. For example, the search unit 610 requests the disclosure of the manufacturing data of the parts with the part ID included in the disclosure information from the data storage 60J via the connector 50X of Company X and the connector 50J of Company J ((6) in FIG. 15, steps S70 and S71 in FIG. 16). In response to this, the data storage 60J discloses the manufacturing data of the parts ((7) in FIG. 15, steps S72 and S73 in FIG. 16). The manufacturing data includes the part ID, manufacturing data storage destination URL information, material ID, and data registrant information.

[0118] Based on the manufacturing data of the parts disclosed from the data storage 60J, the search unit 610 requests the disclosure of the manufacturing data of the materials of this part. For example, the search unit 610 requests the disclosure of the manufacturing data of the materials with the material ID included in the disclosure information from the data storage 60K via the connector 50X of Company X and the connector 50K of Company K ((8) in FIG. 15, steps S74 and S75 in FIG. 16). In response to this, the data storage 60K discloses the manufacturing data of the materials ((9) in FIG. 15, steps S76 and S77 in FIG. 16). The manufacturing data includes the material ID, manufacturing data storage destination URL information, and data registrant information.

[0119] The search unit 610 integrates the received manufacturing data of the battery corresponding to the product passport ID, the manufacturing data of the battery parts, and the manufacturing data of the part materials (step S78 in FIG. 16), and transmits the integrated manufacturing data to the terminal 70X for display (step (10) in FIG. 15, steps S79 and S80 in FIG. 16).

[0120] [Example 1 of Manufacturing Data Display] FIGS. 17 to 22 are diagrams showing an example of the screen displayed on the terminal 70X. For example, when the terminal 70X reads the product code ID from the two-dimensional code 80B with a battery used in an automobile and requests a search for the manufacturing data related to this battery, this will be described as an example.

[0121] On the terminal 70X, as a screen showing the manufacturing data integrated by the search unit 610, for example, the screen W21 in FIG. 17 is displayed. On the screen W21, a tree diagram is displayed with the completed vehicle equipped with the battery at the top, followed by the battery parts (for example, parts 1 and 2), and the raw materials of part 1 (for example, raw materials 1 and 2) in order. On the right shoulder of the product name and the ID of each product, the logo of the manufacturer that manufactured this product and the national flag of the country that certified this manufacturer are displayed.

[0122] Therefore, the user of the terminal 70X can easily recognize, by visually checking the logo, which manufacturer is the manufacturer of the parts and raw materials of the battery in addition to the automobile and the battery. And the user of the terminal 70X can recognize that the manufacturer from which each product data displayed on the screen W21 originated is in a state certified by the country.

[0123] For example, when the user of the terminal 70X selects the logo of each manufacturer, as shown in FIG. 18, in addition to the name and logo of each manufacturer, the certifier (country) and its national flag, and the certification date and its timestamp (digital certificate) are each displayed. For example, when the logo of battery manufacturer I of the battery (storage battery) is selected on the screen of the terminal 70X (arrow C22), a screen W23 including the name, logo of battery manufacturer I, the Japanese government as the certifier and the national flag of Japan, the certification date and its timestamp is displayed. In this way, since the manufacturing data is attached with a Japanese digital certificate for the product manufacturer, the possibility of forgery by the registrant of the manufacturing data can be eliminated.

[0124] Furthermore, as shown in FIG. 19, when the user of the terminal 70X selects the logo of battery manufacturer I on the screen W23, a screen W24 including the registration information of this battery manufacturer I is displayed. On the screen W24, as the registration information of battery manufacturer I, the corporate number, trade name, address, establishment date of battery manufacturer I, the Japanese government as the certifier and its national flag are displayed.

[0125] Subsequently, as shown in FIG. 20, when the user of the terminal 70X selects part 2 (arrow C26), a screen W26 including the product data of this part 2 is displayed. On the screen W26, the type of part (data type), the input date and time and timestamp of this data, the data input type, the name, logo of the system operator (part manufacturer J), the national flag of the certifying country, the name and seal of the registrant and the national flag of the certifying country, the system setting company, the system seller, the names and logos of each system manufacturer and the national flag of the certifying country, the country of the data transmission location and its national flag are displayed. In this way, since the name and seal of the registrant and the national flag of the certifying country are displayed, the possibility of forgery by the registrant of the manufacturing data can be eliminated at an individual level with a finer granularity than at the corporate level.

[0126] These data are registered in the data storage after the communication carrier system 100 performs line authentication result and subscriber information verification and determines that it is access to the connector by the originating corporation and its employees. Therefore, the data input date and time, and the data inputter (corporation and its employees) are guaranteed by the communication carrier system 100.

[0127] Also, in the manufacturing data, the data transmission location of this data is registered by line authentication by the communication carrier system 100. In this example, since the data transmission location of the manufacturing data of component 2 is Japan, which is the country of certification, it has been proven that it is correctly registered in Japan. That is, since the information of the line used for data transmission is specified, the user of terminal 70X can accurately identify the location (country) where the data was actually registered.

[0128] Also, the logo of each corporation is pre-registered by the communication carrier system 100. The user of terminal 70X can easily recognize whether component 2 is a product of the manufacturer by visually recognizing this logo.

[0129] And as described in Embodiment 1, when the communication carrier system 100 automatically acquires and registers corporate information and personal information, the system input type is displayed as "system automatic input", ensuring that there is no forgery of corporate information and personal information.

[0130] Note that on any screen, when the logo of a corporation is selected, a screen including the registration information of this corporation is displayed. For example, on screen W26, when the logo of component manufacturer J, which is the manufacturer of component 2, is selected (arrow C27), screen W27 including the registration information of this component manufacturer J is displayed. On screen W27, the corporate number, trade name, address, establishment date, the Japanese government as the certifier, and its national flag are displayed as the registration information of component manufacturer J.

[0131] [Effects of Embodiment 2] Here, with reference to the screen W31 in FIG. 21, the case where the manufacturing data does not have a digital certificate issued by a country will be described. In this case, for example, for part 2, as shown in the screen W32, the logo of parts manufacturer J, the national flag of the certifying country, the logo of the related corporation, and the national flag of the certifying country are not displayed. Also, the seal impression is not displayed for the individual registrant either. Therefore, it is not possible to eliminate the possibility of impersonating the registrant of this manufacturing data or falsifying the data.

[0132] Also, with reference to the screen W33 in FIG. 22, the case where the system input type is "manual input" will be described. In this case, for part 2, as shown in the screen W34, the manufacturer of the manufacturing data, the corporate information of each related corporation, and the personal information of the registrant are not guaranteed by the communication carrier system 100. That is, since the data of part 2 is input manually, it is not possible to eliminate the possibility of fabricating or falsifying the data. Also, since no digital certificate is attached to the manufacturing data and the data transmission location is unknown, it is difficult to identify the country where the data was actually registered.

[0133] In contrast, in the second embodiment, as described above, a digital certificate is attached, and data that is guaranteed by the communication carrier system 100 to be free from impersonation of the data registrant, forgery, and falsification is provided to the user. Therefore, according to the second embodiment, it is possible to provide highly secure data to the user. Also, in the second embodiment, together with the data for which disclosure is requested, the identification information of the corporation of the registration source, the digital certificate (the first digital certificate), and the logo of this corporation are displayed, so that the user can easily recognize the corporation of the registration source of the data.

[0134] [System Configuration, etc.] Moreover, each component of each illustrated device is functionally conceptual and does not necessarily have to be physically configured as shown in the figures. That is, the specific form of distribution and integration of each device is not limited to that shown in the figures, and all or part of it can be functionally or physically distributed and integrated in any unit according to various loads, usage situations, etc. Furthermore, each processing function performed by each device can be realized in whole or in any part by a program analyzed and executed by a CPU, GPU, and the CPU or GPU, or can be realized as hardware by wired logic.

[0135] Also, among the various processes described in this embodiment, all or part of the processes described as being automatically performed can be performed manually, or all or part of the processes described as being performed manually can be automatically performed by known methods. In addition, regarding the processing procedures, control procedures, specific names, and information including various data and parameters shown in the above documents and drawings, they can be arbitrarily changed unless otherwise specified.

[0136] [Program] Also, it is possible to create a program that describes the processes executed by each device of the communication system 1 described in the above embodiment in a computer-executable language. For example, it is possible to create a program that describes the processes executed by each device of the communication system 1 in the above embodiment in a computer-executable language. In this case, by having a computer execute the program, the same effects as the above embodiment can be obtained. Furthermore, such a program can be recorded on a computer-readable recording medium, and the same processes as the above embodiment can be realized by having the computer read and execute the program recorded on this recording medium.

[0137] FIG. 23 is a diagram showing a computer that executes a program. As illustrated in FIG. 23, the computer 1000 includes, for example, a memory 1010, a CPU 1020, a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070, and these components are connected by a bus 1080.

[0138] As illustrated in FIG. 23, the memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012. The ROM 1011 stores, for example, a boot program such as a BIOS (Basic Input Output System). The hard disk drive interface 1030 is connected to a hard disk drive 1090 as illustrated in FIG. 23. The disk drive interface 1040 is connected to a disk drive 1100. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1100. The serial port interface 1050 is connected to, for example, a mouse 1110 and a keyboard 1120. The video adapter 1060 is connected to, for example, a display 1130.

[0139] Here, as illustrated in FIG. 23, the hard disk drive 1090 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. That is, the above program is stored, for example, in the hard disk drive 1090 as a program module in which instructions to be executed by the computer 1000 are described.

[0140] In addition, the various types of data described in the above embodiments are stored as program data in, for example, the memory 1010 or the hard disk drive 1090. Then, the CPU 1020 reads out the program modules 1093 and program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as necessary, and executes various processing procedures.

[0141] Note that the program modules 1093 and program data 1094 related to the program are not limited to being stored in the hard disk drive 1090, and may be stored in, for example, a removable storage medium and read out by the CPU 1020 via a disk drive or the like. Alternatively, the program modules 1093 and program data 1094 related to the program may be stored in another computer connected via a network (such as a LAN (Local Area Network) or a WAN (Wide Area Network)) and read out by the CPU 1020 via the network interface 1070.

[0142] The above embodiments and their modifications are included in the invention described in the claims and the scope equivalent thereto, in the same manner as the technology disclosed in the present application.

Explanation of Reference Numerals

[0143] 10A, 10B, 400 Business terminals 10S Personal contract terminals 50A, 50J, 50I, 50K, 50X Connectors 60A, 60J, 60I, 60K Data storages 70X Terminals 100 Communication carrier system 110 Connector usage reception device 111 Reception unit 112 First acquisition unit 113 Verification unit 114 First transmission control unit 115 Second acquisition unit 116 Registration unit 117 Second Transmission Control Unit 120 Line Authentication System 130 Corporate and Individual Contractor Information DB 140 Mail System 150 Digital Certificate Management Agency System 160 Logo DB 170 Seal Impression DB 210 Digital Certificate Issuance Infrastructure for Corporations 220 Register Information DB 230 Digital Certificate Issuance Infrastructure for Individuals 240 Resident Information DB 500A, 500J, 500I, 500K Libraries 300A, 300X Connector Attribute Information 600 Data Linkage System 610 Search Section 660 Product and Component Data Search Information DB

Claims

1. A management device that manages the use of a connector that can be connected to a distributed data storage via a first communication line provided by a first telecommunications carrier, The management device is connected to a line authentication system that authenticates the line number and location information of a terminal at the communication source that communicates via the first communication line in the first telecommunications carrier, The management device is connected to a database that stores information about corporations and individuals that have entered into a line contract in association with the line numbers set for the corporations and individuals as subscriber information, A reception unit that receives an application for using the connector of a first corporation from a first business terminal of the first corporation via the first communication line, A first acquisition unit that acquires an authentication result for the line number of the terminal at the communication source at the time of the use application from the line authentication system, A verification unit that verifies the information about the first corporation in the subscriber information of the first corporation for the first communication line stored in the database, the line number set for the first corporation stored in the database, the information about the first corporation received from the first business terminal at the time of the use application, and the line number authenticated as the line number of the terminal at the communication source at the time of the use application by the line authentication system, When the information about the first corporation in the subscriber information of the first corporation stored in the database, the line number set for the corporation stored in the database, the information about the first corporation received from the first business terminal at the time of the use application, and the line number authenticated as the line number of the terminal at the communication source at the time of the use application by the line authentication system match, a second acquisition unit that acquires a first digital certificate including the registration book information of the first corporation from the government's digital certificate issuance infrastructure for corporate use, A registration unit that issues a first connector ID of the first connector to the first corporation and registers at least the identification information of the first corporation and the first digital certificate in association with the first connector ID, A management device characterized by having the above.

2. The reception unit receives, via the first communication line, a registration application for the first connector by a second user who is an individual belonging to the first corporation from the first business terminal, and the name of the second user and the telephone number of a third terminal that the second user has as an individual. The first acquisition unit acquires, from the line authentication system, an authentication result regarding the line number of the communication source terminal at the time of the registration application. The verification unit verifies the line number set for the first corporation stored in the database and the line number authenticated as the line number of the communication source terminal at the time of the registration application by the line authentication system, and also verifies the name of the second user and the line number set for the second user in the contract information of the second user with respect to the first communication line stored in the database, and the name of the second user and the line number of the third terminal received at the time of the registration application. When the line number set for the first corporation stored in the database matches the line number authenticated as the line number of the communication source terminal at the time of the registration application by the line authentication system, and the name of the second user and the line number set for the second user in the contract information of the second user with respect to the first communication line stored in the database match the name of the second user and the line number of the third terminal received at the time of the registration application, the second acquisition unit acquires a second digital certificate including the identification number of the second user from the government's personal digital certificate issuance infrastructure. The registration unit registers the second digital certificate in association with the first connector ID. The management device according to claim 1, characterized in that.

3. The registration unit acquires the design image data of the first corporation from a database that stores, in association with each other, the identification information of each corporation and the design image data symbolizing each corporation, and registers the identification information of the first corporation, the first digital certificate, and the design image data of the first corporation in association with the first connector ID. The management device according to claim 2, characterized in that.

4. When a disclosure request for data registered by the first corporation is received from a terminal used by a third user via the connector of the third user, a second transmission control unit that transmits visualization information of the identification information of the first corporation, the first digital certificate, and the design image data of the first corporation, together with the data for which disclosure has been requested, to the terminal used by the third user. The management device according to claim 3, characterized by having the above.

5. A management method executed by a management device that manages the use of a connector that can be connected to a distributed data storage via a first communication line provided by a first telecommunications carrier, The management device is connected to a line authentication system that authenticates the line number and location information of a terminal at the communication source that communicates via the first communication line in the first telecommunications carrier, The management device is connected to a database that stores information on corporations and individuals that have entered into a line contract in association with the line numbers set for the corporations and individuals as subscriber information, A reception step of receiving a usage application for the connector of the first corporation from a first business terminal of the first corporation via the first communication line, A first acquisition step of acquiring an authentication result for the line number of the terminal at the communication source at the time of the usage application from the line authentication system, A collation step of collating the information on the first corporation in the subscriber information of the first corporation for the first communication line stored in the database, the line number set for the first corporation stored in the database, the information on the first corporation received from the first business terminal at the time of the usage application, and the line number authenticated as the line number of the terminal at the communication source at the time of the usage application by the line authentication system, When the information on the first corporation in the subscriber information of the first corporation stored in the database, the line number set for the corporation stored in the database, the information on the first corporation received from the first business terminal at the time of the usage application, and the line number authenticated as the line number of the terminal at the communication source at the time of the usage application by the line authentication system match, a second acquisition step of acquiring a first digital certificate including the registration book information of the first corporation from the digital certificate issuance infrastructure for government corporations Pay out the first connector ID of the first connector to the first corporation, and register by associating at least the identification information of the first corporation and the first digital certificate with the first connector ID. A management method characterized by including the above.

6. A management program for causing a computer as a management device to execute a method, Manage the use of a connector that can be connected to a distributed data storage via a first communication line provided by a first telecommunications carrier. The management device is connected to a line authentication system that authenticates the line number and location information of a communication source terminal that communicates via the first communication line in the first telecommunications carrier. The management device is connected to a database that stores information on corporations and individuals that have entered into a line contract in association with the line numbers set for the corporations and individuals as subscriber information. In a computer as the management device, A reception step of receiving an application for use of the connector of the first corporation from a first business terminal of the first corporation via the first communication line. A first acquisition step of acquiring an authentication result for the line number of the communication source terminal at the time of the use application from the line authentication system. A verification step of verifying the information on the first corporation in the subscriber information of the first corporation for the first communication line stored in the database, the line number set for the first corporation stored in the database, the information on the first corporation received from the first business terminal at the time of the use application, and the line number authenticated as the line number of the communication source terminal at the time of the use application by the line authentication system. When the information on the first corporation in the subscriber information of the first corporation stored in the database, the line number set for the corporation stored in the database, the information on the first corporation received from the first business terminal at the time of the use application, and the line number authenticated as the line number of the communication source terminal at the time of the use application by the line authentication system match, a second acquisition step of acquiring a first digital certificate including the registration book information of the first corporation from the government's digital certificate issuance infrastructure for corporations. A registration step of issuing a first connector ID of the first connector to the first corporation and registering, in association with the first connector ID, at least identification information of the first corporation and the first digital certificate. A management program for causing a computer to execute.

Citation Information

Patent Citations

  • A centralized authentication system and method with secure private data storage.

    JP2012517064A

  • Cloud relay device, cloud connection processing method, and program

    JP2018092565A

  • Technology for securely extending cloud service APIs for cloud service marketplaces

    JP2020503616A

  • JPP7295492B