Data Transmission Route Confirmation System, Data Transmission Route Confirmation Method, Data Relay System, and Data Receiving Apparatus

The data transmission route confirmation system addresses the challenge of confirming data transmission routes in network systems by using an authentication mechanism to verify cumulative signature authenticity information, ensuring accurate and authentic transmission route confirmation.

JP7691025B2Active Publication Date: 2025-06-11NEC CORP
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024502713
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-02-28
Publication Date
2025-06-11
Estimated Expiration
2042-02-28

AI Technical Summary

Technical Problem

In network systems, users cannot confirm the transmission route of received data due to the deletion of intermediate processing entities' electronic signatures and certificates after verification, and the authenticity of metadata indicating the transmission route cannot be ensured.

Method used

A data transmission route confirmation system that includes an authentication means for transmitting signature authenticity information, a data transmission means that attaches its own signature information and authenticity information, one or more data relay means that cumulatively attach their own signature information and authenticity information, and a data reception means that verifies the cumulative signature authenticity information to confirm the transmission route.

Benefits of technology

Enables users to confirm the transmission route of received data by verifying the cumulative signature authenticity information, ensuring the accuracy and authenticity of the transmission route information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007691025000001
    Figure 0007691025000001
  • Figure 0007691025000002
    Figure 0007691025000002
  • Figure 0007691025000003
    Figure 0007691025000003
Patent Text Reader

Abstract

An authentication station (10) is configured to be capable of transmitting electronic certificates (C, CA, CB). A processing device (11) adds a signature (S) and an electronic certificate (C) to data (D) and transmits the same to a company-A system (1A). The company-A system (1A) adds a signature (SA) and an electronic certificate (CA) to the received data and transmits the same to a company-B system (1B). The company-B system (1B) adds a signature (SB) and an electronic certificate (CB) to the received data and transmits the same to a user terminal (12). The user terminal (12) verifies, between the authentication station (10) and itself, the electronic certificates (C, CA, CB) that are cumulatively added to the received data, and confirms the transmission path of the data (D) on the basis of the cumulatively added electronic signatures (S, SA, SB).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a data transmission path confirmation system, a data transmission path confirmation method, a data relay system, and a data receiving device.

Background Art

[0002] In a network system where a large amount of data is transmitted, such as an IoT (Internet of Things) system, in order to ensure the authenticity of data, it is required to guarantee the presence or absence of data forgery during data circulation, the data source, and the circulation path of the data.

[0003] Therefore, it is widely practiced to attach an electronic signature created using a private key to the data to be transmitted and prove the authenticity of the public key for decrypting the attached electronic signature with an electronic certificate (Patent Documents 1 to 3).

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Patent Document 2

Patent Document 3

Patent Document 4

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, generally, only the electronic signature and electronic certificate of the processing entity in the previous stage that sent the data to the user are attached to the data received by the user who is the data recipient. For data transmission, processing entities such as the data sender and multiple relays (herein referred to as intermediate processing entities) are involved. Each of these intermediate processing entities also attaches an electronic signature and electronic certificate to the data to be sent. However, the data attached by the intermediate processing entity is generally deleted after being verified by the subsequent processing entity.

[0006] Therefore, the user cannot confirm the transmission route of the received data. Although it is possible to include metadata indicating the transmission route in the received data, since the authenticity of the transmission route indicated by the metadata cannot be ensured, even in this case, the user cannot confirm whether the information on the transmission route of the received data is accurate.

[0007] This disclosure has been made in view of the above circumstances, and an object thereof is to enable a user to confirm the transmission route of data received in a network system.

Means for Solving the Problem

[0008] A data transmission route confirmation system according to an aspect of the present disclosure includes an authentication means configured to be able to transmit signature authenticity information indicating the authenticity of signature information, a data transmission means that attaches and outputs its own signature information and signature authenticity information corresponding to the own signature information obtained from the authentication means to the data to be transmitted, one or more data relay means that cumulatively attach and output its own signature information and signature authenticity information corresponding to the own signature information obtained from the authentication means to the data received from the data transmission means, and a data reception means that verifies the signature authenticity information cumulatively attached by the one or more data relay means with the authentication means and confirms the transmission route of the data to be transmitted based on the signature information cumulatively attached by the one or more data relay means.

[0009] A method for verifying a data transmission path according to one aspect of the present disclosure stores signature authenticity information indicating the authenticity of signature information in an authentication means configured to be able to transmit the signature authenticity information, and attaches to the data to be transmitted the signature information of the data transmission means and the signature authenticity information corresponding to the signature information of the data transmission means obtained from the authentication means, and outputs the result. One or more data relay means receive data from the data transmission means, and the one or more data relay means cumulatively attach their own signature information and the signature authenticity information corresponding to their own signature information obtained from the authentication means, and output the result. The signature authenticity information cumulatively attached by the one or more data relay means is verified with the authentication means, and based on the signature information cumulatively attached by the one or more data relay means, the transmission path of the data to be transmitted is confirmed.

[0010] A data relay system according to one aspect of the present disclosure includes a data acquisition means for acquiring output data from a data transmission means that attaches its own signature information and signature authenticity information corresponding to the signature information of the data transmission means obtained from an authentication means configured to be able to transmit signature authenticity information indicating the authenticity of the signature information to the data to be transmitted and outputs the result; an information attachment means for cumulatively attaching its own signature information and the signature authenticity information corresponding to its own signature information obtained from the authentication means to the data received by the data acquisition means; and a data output means for outputting the data to which the signature information and the signature authenticity information have been attached by the information attachment means. A data reception means verifies the plurality of cumulatively attached signature authenticity information with the authentication means, and based on the plurality of cumulatively attached signature information, confirms the transmission path of the data to be transmitted.

[0011] A data receiving device according to one aspect of the present disclosure is configured to add and output its own signature information and signature authenticity information corresponding to the own signature information obtained from an authentication means capable of transmitting the signature authenticity information indicating the authenticity of the signature information to the data to be transmitted. The data acquisition means for receiving data from one or more data relay means for cumulatively adding and outputting its own signature information and signature authenticity information corresponding to the own signature information obtained from the authentication means to the received data; authenticity verification means for verifying the signature authenticity information cumulatively added to the data received by the data acquisition means with the authentication means; and transmission route confirmation means for confirming the transmission route of the data to be transmitted based on the cumulatively added signature information.

Advantages of the Invention

[0012] According to the present disclosure, in a network system, it is possible to confirm the transmission route of data received by a user.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Embodiments for Carrying Out the Invention

[0014] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In each drawing, the same reference numerals are assigned to the same elements, and redundant explanations are omitted as necessary.

[0015] Embodiment 1 The data transmission path confirmation system according to Embodiment 1 will be described. FIG. 1 schematically shows the configuration of the data transmission path confirmation system 100 according to Embodiment 1. Here, an example will be described in which data created by Company A is transmitted to the user via Company B. The data transmission path confirmation system 100 includes a certification authority 10, a processing device 11, a user terminal 12, Company A's system 1A, and Company B's system 1B.

[0016] The certification authority 10 stores in advance electronic certificates C, CA, and CB that prove the authenticity of the electronic signatures generated by the processing device 11, Company A System 1A, and Company B System 1B respectively. Then, the certification authority 10 provides the electronic certificates C, CA, and CB in response to requests (not shown) from the processing device 11, Company A System 1A, and Company B System 1B. Also, the user terminal 12 can verify the authenticity of the electronic certificates C, CA, and CB with the certification authority 10.

[0017] The processing device 11 is configured as a data transmission device that transmits data to be transmitted. FIG. 2 schematically shows the configuration of the processing device 11 according to Embodiment 1. The processing device 11 includes a data acquisition unit 111, an information attachment unit 112, and a data output unit 113. The data acquisition unit 111 acquires an electronic certificate from the certification authority 10 and passes it to the information attachment unit 112. The information attachment unit 112 generates an electronic signature and attaches the generated electronic signature and the acquired electronic certificate to the input data, that is, the data D to be transmitted. The data output unit 113 outputs the data D with the electronic signature and the electronic certificate attached to Company A System 1A.

[0018] Company A System 1A and Company B System 1B are configured as data relay systems and have the same configuration as the processing device 11 or are configured to have a processing device similar to the processing device 11. Similar to the processing device 11, the data acquisition unit acquires an electronic certificate from the certification authority 10 and passes it to the information attachment unit. The information attachment unit generates an electronic signature and attaches the generated electronic signature and the acquired electronic certificate to the input data, that is, the data received from the processing device 11 or Company A System 1A. The data output unit outputs the data with the electronic signature and the electronic certificate attached to Company B System 1B or the user terminal 12.

[0019] The user terminal 12 is configured as a data receiving device. Fig. 3 schematically shows the configuration of the user terminal 12 according to Embodiment 1. The user terminal 12 includes a data acquisition unit 121, an authenticity verification unit 122, and a transmission path confirmation unit 123. The data acquisition unit 121 receives data transmitted from Company B's system 1B. The authenticity verification unit 122 verifies the authenticity of the electronic certificate included in the received data. The transmission path confirmation unit 123 decrypts the electronic signature and confirms the transmission path of the received data.

[0020] The operation of the data transmission path confirmation system 100 will be described. Fig. 4 shows a sequence diagram of the operation of the data transmission path confirmation system 100 according to Embodiment 1.

[0021] Step A_1 The processing device 11 is configured to transmit the data D to be transmitted to the user terminal 12, which is the data providing partner. First, the data acquisition unit 111 receives an electronic certificate C including the public key PU for electronic signature and its identification information (owner information) from the certification authority 10, that is, information indicating that the processing device 11 has issued the public key PU.

[0022] When issuing an electronic certificate to a device such as a processing device, the certification authority can include, as identification information, the destination to which the processing device belongs and information indicating what kind of device the processing device is. Fig. 5 shows an example of the information included in the electronic certificate. In this example, the certification authority 10 can include, as identification information, information indicating that the processing device 11 belongs to Company A and information indicating that the processing device 11 is a gateway in the electronic certificate C.

[0023] Step A_2 The information attachment unit 112 of the processing device 11 creates an electronic signature S by encrypting, for example, a hash value generated from the data D with the private key PR corresponding to the public key PU.

[0024] Step A_3 The information adding unit 112 of the processing device 11 adds the electronic certificate C and the electronic signature S to the data D, and the data output unit 113 passes the data after the addition to the Company A system 1A connected to the external network. As a result, the Company A system 1A can transmit the data D to which the electronic certificate C and the electronic signature S are added in response to a request from others.

[0025] The Company A system 1A stores the data D to which the electronic signature S and the electronic certificate C are added in a storage device (not shown), etc., and when receiving a query requesting the transmission of the data D from the outside, can transmit the data D together with the electronic signature and the electronic certificate. In this example, it will be described assuming that the user terminal 12 transmits a query Q for requesting the transmission of the data D to the Company A system 1A via the Company B system 1B.

[0026] Step A_4 The data acquisition unit 121 of the user terminal 12 transmits a query Q to the Company A system 1A via the Company B system 1B in order to request the transmission of the data D to the Company A system 1A.

[0027] Step A_5 When receiving the query Q, the data acquisition unit of the Company A system 1A receives an electronic certificate CA including the public key PUA for the electronic signature and its identification information (owner information), that is, information indicating that the Company A system 1A issued the public key PUA, from the certification authority 10.

[0028] Step A_6 The information adding unit of the Company A system 1A creates an electronic signature SA by encrypting, for example, a hash value generated from the data D with the private key PRA corresponding to the public key PUA.

[0029] Step A_7 The information - adding unit of Company A's System 1A further adds an electronic certificate CA and an electronic signature SA to the data D. That is, Company A's System 1A can cumulatively add an electronic certificate CA and an electronic signature SA to the data D to which an electronic certificate C and an electronic signature S have been previously added. Then, the data output unit transmits the data after the addition to Company B's System 1B.

[0030] Company B's System 1B receives the data D to which the electronic signatures S and SA, and the electronic certificates C and CA are added from Company A's System 1A, further adds an electronic signature and an electronic certificate, and transmits them to the user terminal 12.

[0031] Step A_8 The data acquisition unit of Company B's System 1B receives an electronic certificate CB from the certification authority 10, which includes the public key PUB for the electronic signature and its identification information (owner's information), that is, the information indicating that Company B's System 1B has issued the public key PUB.

[0032] Step A_9 The information - adding unit of Company B's System 1B generates an electronic signature SB by encrypting, for example, the hash value generated from the data D with the private key PRB corresponding to the public key PUB.

[0033] Step A_10 The information - adding unit of Company B's System 1B further adds the electronic certificate CB and the electronic signature SB to the data D. That is, Company B's System 1B can cumulatively add the electronic certificate CB and the electronic signature SB to the data D to which the electronic certificates C and CA and the electronic signatures S and SA have been previously added. Then, the data output unit transmits the data after the addition to the user terminal 12.

[0034] In addition, when issuing an electronic certificate for a target that may include a plurality of devices such as a system, the certification authority can include the attribution destination of the system as identification information in the electronic certificate. As shown in FIG. 5, the certification authority 10 can include, as identification information in the electronic certificate CA, information indicating that the Company A system 1A belongs to Company A. Similarly, the certification authority 10 can include, as identification information in the electronic certificate CB, information indicating that the Company B system 1B belongs to Company B.

[0035] Step A_11 The data acquisition unit 121 of the user terminal 12 exchanges information with the certification authority 10 as necessary. As a result, the authenticity verification unit 122 verifies the authenticity of each of the electronic certificates C, CA, and CB cumulatively attached to the data D with the certification authority 10, and also confirms that the issuers of the electronic signatures S, SA, and SB cumulatively attached to the data D are authentic.

[0036] Step A_12 The transmission path confirmation unit 123 of the user terminal 12 decrypts the electronic signatures S, SA, and SB using the public keys PU, PUA, and PUB. As a result, the user terminal 12 can confirm the electronic signatures S, SA, and SB and confirm the creator of the data D and its transmission path.

[0037] Therefore, according to this configuration, the electronic signatures cumulatively attached to the data by the data creator and the data transmission relay can be decrypted with the public key whose authenticity of the issuer is guaranteed. As a result, it becomes possible to confirm the data creator and the data transmission path.

[0038] Embodiment 2 In Embodiment 1, the configuration in which each of a plurality of processing entities such as devices and systems assigns an electronic signature and an electronic certificate to data was described. In this case, as the number of processing entities increases, the number of electronic signatures and the number of electronic signature documents assigned to the data also increase, resulting in an increase in the data volume. Therefore, when suppression of the data volume to be transmitted is required, it is assumed that there are cases where it is difficult to apply the configuration described in Embodiment 1.

[0039] Therefore, in this embodiment, a data transmission path confirmation system 200 that suppresses the data volume at the time of transmission will be described in the case where an electronic signature and an electronic certificate are cumulatively assigned to data by a plurality of processing entities.

[0040] FIG. 6 schematically shows the configuration of a data transmission path confirmation system 200 according to Embodiment 2. The data transmission path confirmation system 200 includes a certification authority 20, a processing device 21, a user terminal 22, a Company A system 2A, and a Company B system 2B. The certification authority 20, the processing device 21, the user terminal 22, the Company A system 2A, and the Company B system 2B respectively correspond to the certification authority 10, the processing device 11, the user terminal 12, the Company A system 1A, and the Company B system 1B of the data transmission path confirmation system 100.

[0041] The processing device 21 will be described. FIG. 7 schematically shows the configuration of the processing device 21 according to Embodiment 2. The processing device 21 includes a data acquisition unit 211, an information addition unit 212, and a data output unit 213. The data acquisition unit 211 acquires certificate identification information, which will be described later, from the certification authority 20 and passes it to the information addition unit 212. The information addition unit 212 generates an electronic signature and signature identification information, which will be described later, and adds the generated signature identification information and the acquired certificate identification information to the input data, that is, the data D to be transmitted. Further, the information addition unit 212 transmits the electronic signature and the signature identification information to the certification authority 20. The data output unit 213 outputs the data D to which the signature identification information and the certificate identification information are added to the Company A system 2A.

[0042] Company A's system 2A and Company B's system 2B have the same configuration as the processing device 21 or have a processing device similar to the processing device 21. Similar to the processing device 21, the data acquisition unit acquires the certificate specific information from the certification authority 20 and passes it to the information conferring unit. The information conferring unit generates an electronic signature and signature specific information, and attaches the generated signature specific information and the acquired certificate specific information to the input data, that is, the data received from the processing device 21 or Company A's system 2A. Further, the information conferring unit transmits the electronic signature and the signature specific information to the certification authority 20. The data output unit outputs the data to which the signature specific information and the certificate specific information are attached to Company B's system 2B or the user terminal 22.

[0043] The operation of the data transmission path confirmation system 200 will be described. FIG. 8 shows a sequence diagram of the operation of the data transmission path confirmation system 200 according to the second embodiment.

[0044] Step B_1 The data acquisition unit 211 of the processing device 21 receives the certificate specific information c, which is information for specifying the electronic certificate C, from the certification authority 20. The certificate specific information here is such that by presenting it to the certification authority 20, the electronic certificate specified by the certificate specific information can be received. As the certificate specific information, for example, the ID number of the electronic certificate C may be used.

[0045] Step B_2 The processing device 21 generates an electronic signature S by encryption using the private key PR corresponding to the public key PU to be certified by the electronic certificate C, which is held in advance, and generates signature specific information s for specifying the electronic signature S. The signature specific information here is such that by presenting it to the certification authority 20 that holds the signature specific information and the corresponding electronic signature in advance, the corresponding electronic signature can be received. As the signature specific information, for example, the ID number of the electronic signature may be used.

[0046] Step B_3 The information adding unit 212 of the processing device 21 transmits the generated electronic signature S and signature specific information s to the certification authority 20, and the certification authority 20 holds the received electronic signature S and signature specific information s.

[0047] Step B_4 The information adding unit 212 of the processing device 21 adds the certificate specific information c and the signature specific information s to the data D, and the data output unit 213 passes the data after addition to the Company A system 2A.

[0048] Step B_5 The user terminal 22 transmits a query Q to the Company A system 2A via the Company B system 2B in order to request the transmission of the data D to the Company A system 2A.

[0049] Step B_6 When receiving the query Q, the data acquisition unit of the Company A system 2A receives, from the certification authority 20, certificate specific information ca which is information for specifying the electronic certificate CA.

[0050] Step B_7 The information adding unit of the Company A system 2A generates an electronic signature SA by encrypting using the private key PRA corresponding to the public key PUA certified by the electronic certificate CA, which is held in advance, and generates signature specific information sa for specifying the electronic signature SA.

[0051] Step B_8 The information adding unit of the Company A system 2A transmits the generated electronic signature SA and signature specific information sa to the certification authority 20, and the certification authority 20 holds the received electronic signature SA and signature specific information sa.

[0052] Step B_9 The information adding unit of Company A's system 2A further adds the certificate specific information ca and the signature specific information sa to the received data. That is, Company A's system 2A can cumulatively add the certificate specific information ca and the signature specific information sa to the data D to which the certificate specific information c and the signature specific information s have been previously added. Then, the data output unit passes the data after the addition to Company B's system 2B.

[0053] Step B_10 The data acquisition unit of Company B's system 2B receives the data transmitted from Company A's system 2A and receives the certificate specific information cb, which is the information for specifying the electronic certificate CB from the certification authority 20.

[0054] Step B_11 The information adding unit of Company B's system 2B generates an electronic signature SB by encryption using the private key PRB corresponding to the public key PUB certified by the electronic certificate CB, which is held in advance, and generates signature specific information sb for specifying the electronic signature SB.

[0055] Step B_12 The information adding unit of Company B's system 2B transmits the generated electronic signature SB and the signature specific information sb to the certification authority 20, and the certification authority 20 holds the received electronic signature SB and the signature specific information sb.

[0056] Step B_13 The information adding unit of Company B's system 2B further adds the certificate specific information cb and the signature specific information sb to the received data. That is, Company B's system 2B can cumulatively add the certificate specific information cb and the signature specific information sb to the data D to which the certificate specific information c, ca and the signature specific information s, sa have been previously added. Then, the data output unit transmits the data after the addition to the user terminal 22.

[0057] Step B_14 The user terminal 22 transmits the received certificate specific information c, ca and cb, and the signature specific information s, sa and sb to the certification authority 20.

[0058] Step B_15 As a result, as a response from the certification authority 20, the user terminal 22 can obtain the electronic certificates C, CA, and CB, and the electronic signatures S, SA, and SB.

[0059] Step B_16 Similar to step A_11 in FIG. 4, the user terminal 22 verifies the authenticity of each of the electronic certificates C, CA, and CB corresponding to the certificate specific information cumulatively attached to the data D with the certification authority 10, thereby confirming that the issuers of the electronic signatures S, SA, and SB corresponding to the signature specific information cumulatively attached to the data D are authentic.

[0060] Step B_17 Similar to step A_12 in FIG. 4, the user terminal 22 decrypts the electronic signatures S, SA, and SB with the public keys PU, PUA, and PUB. As a result, the user terminal 22 can confirm the electronic signatures S, SA, and SB and confirm the creator of the data D and its transmission path.

[0061] Therefore, according to this configuration, similar to Embodiment 1, the electronic signatures cumulatively attached to the data by the data creator and the data transmission relay can be decrypted with the public key whose issuer authenticity is guaranteed. As a result, it becomes possible to confirm the data creator and the data transmission path.

[0062] Furthermore, according to this configuration, instead of the electronic signature and the electronic certificate, by attaching the signature specific information and the certificate specific information with a smaller data amount to the transmission target data, it becomes possible to suppress the data amount of the transmitted data.

[0063] Embodiment 3 In Embodiment 1, it has been described that the data D reaches the user terminal 12 from the processing device 11 while maintaining its identity without being modified. However, for example, it is conceivable that the data D is processed in the system 1A of Company A or the system 1B of Company B in the middle of the transmission path.

[0064] Therefore, in this configuration, a data transmission path confirmation system that can confirm the transmission path when data is processed during the transmission process and can detect that the data has been processed in the path will be described.

[0065] Fig. 9 schematically shows the configuration of a data transmission path confirmation system 300 according to Embodiment 3. The data transmission path confirmation system 300 includes a certification authority 30, a processing device 31, a user terminal 32, Company A system 3A, and Company B system 3B. The certification authority 30, the processing device 31, the user terminal 32, Company A system 3A, and Company B system 3B respectively correspond to the certification authority 10, the processing device 11, the user terminal 12, Company A system 1A, and Company B system 1B of the data transmission path confirmation system 100. Since the processing device 31, Company B system 3B, and the user terminal 32 are the same as the processing device 11, Company B system 1B, and the user terminal 12 respectively, the description thereof will be omitted.

[0066] Fig. 10 schematically shows the configuration of Company A system 3A according to Embodiment 3. Company A system 3A includes a data acquisition unit 311, a data processing unit 312, a data integration unit 313, an information attachment unit 314, and a data output unit 315. The data acquisition unit 311 acquires an electronic certificate from the certification authority 30 and passes it to the information attachment unit 314. The data processing unit 312 performs necessary processing on the received data D to generate data D'. The data integration unit 313 integrates the processed data D' with the electronic signature and the electronic certificate attached to the data D before processing, and converts it into integrated data. The information attachment unit 314 generates an electronic signature and attaches the generated electronic signature and the acquired electronic certificate to the integrated data. The data output unit 315 outputs the integrated data with the electronic signature and the electronic certificate attached to Company B system 3B.

[0067] Subsequently, the operation of the data transmission path confirmation system 300 will be described. Fig. 11 shows a sequence diagram of the operation of the data transmission path confirmation system 300 according to Embodiment 3.

[0068] Steps C_1 to C_5 Except that the processing device 11 is replaced by the processing device 31, steps C_1 to C_5 are the same as steps A_1 to A_5 respectively, so the description is omitted.

[0069] Step C_6 The data processing unit 312 of Company A's system 3A performs necessary processing on the received data D and creates processed data D'.

[0070] Step C_7 The information providing unit 314 of Company A's system 3A creates an electronic signature SA by encrypting, for example, a hash value generated from the processed data D' with the private key PRA corresponding to the public key PUA.

[0071] Step C_8 The data integration unit 313 of Company A's system 3A converts the data D with the electronic signature S and the electronic certificate CA attached and the data D' created in step C_6 into integrated data. Then, the information providing unit 314 cumulatively attaches the electronic certificate CA and the electronic signature SA to the integrated data, and the data output unit 315 transmits the data after attachment to Company B's system 3B. In FIG. 11, the integrated data is enclosed in parentheses and denoted as (D'+D<S,C>), and it is denoted that the integrated data (D'+D<S,C>) with the electronic certificate CA and the electronic signature SA cumulatively attached, i.e., (D'+D<S,C>)<SA,CA>, is transmitted to Company B's system 3B.

[0072] Step C_9 The data acquisition unit of Company B's system 3B receives the data transmitted in step C_8 from Company A's system 3A. Then, similar to step A_8 in FIG. 4, the data acquisition unit of Company B's system 3B receives an electronic certificate CB including the public key PUB for electronic signature and its identification information (owner information) from the certification authority 30, that is, information indicating that Company B's system 3B has issued the public key PUB.

[0073] Step C_10 The information provision unit of Company B's System 3B generates an electronic signature SB by encrypting, using a private key PRB corresponding to the public key PUB, for example, a hash value generated from the processed data D'.

[0074] Step C_11 The information provision unit of Company B's System 3B cumulatively attaches the electronic certificate CB and the electronic signature SB to the received data, and the data output unit 315 transmits the data after attachment to the user terminal 32. In FIG. 11, it is shown that the data (D'+D<S,C>)<SA,CA> to which the electronic certificate CB and the electronic signature SB are cumulatively attached, i.e., (D'+D<S,C>)<SA,CA,SB,CB>, is transmitted to the user terminal 32.

[0075] Step C_12 The user terminal 32 verifies the authenticity of each of the electronic certificates CA and CB cumulatively attached to the integrated data (D'+D<S,C>) with the certification authority 30, and also verifies the authenticity of the electronic certificate C attached to the data D before processing. By doing so, the user terminal 32 can confirm that the issuers of the electronic signatures S, SA, and SB cumulatively attached to the received data are authentic.

[0076] Step C_13 The user terminal 32 decrypts the electronic signatures S, SA, and SB using the public keys PU, PUA, and PUB. Thereby, the user terminal 32 can confirm the electronic signatures S, SA, and SB and confirm the creator of the data D and its transmission route.

[0077] From the above, since the user terminal 32 can receive both the data D before processing and the data D' after processing, it can recognize that the data D has been processed on the transmission route. Also, since the electronic signature S is attached to the data D before processing, and the electronic signatures SA and SB are attached to the integrated data including the data D' after processing, it can be recognized that the data D has been processed in Company A's System 3A.

[0078] Therefore, according to this configuration, the electronic signature cumulatively added to the data by the data creator and the data transmission relay can be decrypted with the public key whose authenticity of the issuer is guaranteed. As a result, it becomes possible to confirm the data creator and the data transmission path.

[0079] Also, according to this configuration, as described above, when the data to be transmitted is processed on the transmission path, it is possible to recognize the fact that it has been processed and where the data has been processed.

[0080] Furthermore, according to this configuration, since it is possible to leave evidence that the data to be transmitted has been changed, even if the data to be transmitted has been subjected to unintended tampering, it is possible to detect the fact of the tampering.

[0081] Embodiment 4 In the above-described embodiment, a data transmission path confirmation system has been described in which an electronic signature and an electronic certificate, or signature identification information and certificate identification information are cumulatively added to the data transmitted to the user terminal. However, in this case, every time a device or a system receives electronic data, a process of generating an electronic signature is required. Also, when the data transmission path becomes complex, the number of electronic signatures received by the user terminal increases, and the processing amount required for signature confirmation at the user terminal also increases. Further, when it is assumed that such data is transmitted many times in the network, a situation where a huge amount of computer resources are consumed for signature generation and signature confirmation in the entire network can also be considered.

[0082] Therefore, in this embodiment, a data transmission path confirmation system will be described that evaluates the reliability of devices and networks involved in data creation and relay and can omit the addition of electronic signatures and electronic certificates for devices and networks with ensured reliability.

[0083] Fig. 12 schematically shows the configuration of a data transmission path confirmation system 400 according to Embodiment 4. The data transmission path confirmation system 400 includes a certification authority 40, a processing device 41, a user terminal 42, Company A's system 4A, and Company B's system 4B. The certification authority 40, the processing device 41, the user terminal 42, Company A's system 4A, and Company B's system 4B respectively correspond to the certification authority 10, the processing device 11, the user terminal 12, Company A's system 1A, and Company B's system 1B of the data transmission path confirmation system 100. Since the processing device 41 and the user terminal 42 are the same as the processing device 11 and the user terminal 12 respectively, the description thereof is omitted.

[0084] In this example, the certification authority 40 has a score evaluation unit 43 that pre-holds a score, which is an index indicating whether the reliability of the processing device 41 can be guaranteed. The score of the device or system stored in the score evaluation unit 43 is determined in advance by referring to the historical information and the latest status of predetermined items such as the manufacturer, model, used parts, user, and operation purpose of the device or system to be evaluated.

[0085] Note that the score may be appropriately updated to different values by monitoring the latest status of the device or system. Thereby, the score can be changed according to the change of the situation, and it becomes possible to dynamically evaluate the reliability of the device or system.

[0086] Since the configuration and operation of the data transmission path confirmation system 400 are the same as those of the data transmission path confirmation system 100 except for the certification authority 40, Company A's system 4A, and Company B's system 4B, the configuration and operation of Company A's system 4A will be described below with attention.

[0087] First, the configuration of Company A's system 4A will be described. Fig. 13 schematically shows the configuration of Company A's system 4A according to Embodiment 4. Company A's system 4A includes a data acquisition unit 411, a score confirmation unit 412, an information provision unit 413, and a data output unit 414. The data acquisition unit 411 acquires an electronic certificate from the certification authority 40 and passes it to the information provision unit 413. The score confirmation unit 412 receives a score indicating the reliability of the processing entity (data creator or relay) in the previous stage that sent the received data from the score evaluation unit 43 of the certification authority 40. Then, the score confirmation unit 412 determines whether the received score is a value that can guarantee the reliability of the sending entity that sent the data. The information provision unit 413 deletes or maintains the electronic signature and electronic certificate attached to the received data according to the determination result of the score confirmation unit 412, and then further attaches the electronic signature and electronic certificate to the received data. The data output unit 414 outputs the data with the electronic signature and electronic certificate attached to the Company B system 4B.

[0088] Next, the operation of Company A's system 4A will be described. Fig. 14 shows a flowchart of the operation of Company A's system 4A according to Embodiment 4.

[0089] Step ST1 The data acquisition unit 411 sends an inquiry INQ_A for the score indicating the reliability of the previous-stage processing device 41 to the certification authority 40.

[0090] Step ST2 The score evaluation unit 43 sends a score RA indicating the reliability of the processing device 41 to Company A's system 4A in response to the inquiry INQ_A, and also sends an electronic certificate CA.

[0091] Step ST3 The data acquisition unit 411 compares the score RA with the threshold value RTH and determines whether the score RA is greater than or equal to the score RTH.

[0092] Step ST4 When the score RA is greater than or equal to the threshold value RTH, the information providing unit 413 replaces the electronic signature S and the electronic certificate C attached to the received data, that is, the data D to which the electronic signature S and the electronic certificate C are attached, with meta information indicating that the data has been received from the processing device 41 which is the previous processing entity.

[0093] Step ST5 When the score RA is less than the threshold value RTH, the information providing unit 413 maintains the received data, that is, the data D to which the electronic signature S and the electronic certificate C are attached, as it is.

[0094] Step ST6 The information providing unit 413 creates an electronic signature SA based on the data after Step ST4 or Step ST5 using the private key PRA corresponding to the public key PUA.

[0095] Step ST7 The data output unit 414 attaches the electronic certificate CA and the electronic signature SA to the data after Step ST4 or Step ST5. That is, the Company A system 4A can cumulatively attach the electronic certificate CB and the electronic signature SB to the meta information in which the electronic certificate C and the electronic signature S are replaced in Step ST4, or the data D to which the electronic certificate C and the electronic signature S maintained in Step ST5 are attached. Then, the data output unit 414 transmits the data after attachment to the Company B system 4B.

[0096] Note that the configuration and operation of the Company B system 4B are the same as those of the Company A system 4A. In the figure, the inquiry of the score from the Company B system 4B to the certification authority 40 is denoted as INQ_B, and the score received from the certification authority 40 is denoted as RB. Other duplicate explanations are omitted.

[0097] Next, an example of the operation of the data transmission path confirmation system 400 will be described. First, the case where both the processing device 41 and the Company A system 4A have high scores will be considered. FIG. 15 shows the case where both the processing device 41 and the Company A system 4A have high scores.

[0098] In this example, the score RA of the processing device 41 received by Company A's system 4A is equal to or higher than the threshold value RTH. Therefore, Company A's system 4A deletes the electronic signature S and the electronic certificate C from the received data, that is, the data D with the electronic signature S and the electronic certificate C attached, and replaces them with meta-information. After that, Company A's system 4A attaches the electronic signature SA and the electronic certificate CA to the remaining data D and outputs it to Company B's system 4B.

[0099] The score RB of Company A's system 4A received by Company B's system 4B is equal to or higher than the threshold value RTH. Therefore, Company B's system 4B deletes the electronic signature SA and the electronic certificate CA from the received data, that is, the data D with the electronic signature SA and the electronic certificate CA attached, and replaces them with meta-information. After that, Company B's system 4B attaches the electronic signature SB and the electronic certificate CB to the remaining data D and outputs it to the user terminal 42.

[0100] In this way, when the reliability of the previous-stage processing entity is high, the electronic signature and the electronic certificate given in the previous stage are replaced with meta-information indicating a path with a smaller data volume. Thereby, the data volume of the data to be transmitted can be compressed. In addition, since the reliability of the devices and systems involved in data transmission can be ensured by the evaluation based on the score, similar to the data transmission path confirmation system according to the above-described embodiment, the user terminal 42 can confirm the data transmission path by referring to the meta-information.

[0101] Subsequently, the case where the processing device 41 has a high score and Company A's system 4A has a low score will be considered. FIG. 16 shows the case where the processing device 41 has a high score and Company A's system 4A has a low score. Since the operation of Company A's system 4A is the same as that in the case of FIG. 15, the description thereof will be omitted.

[0102] The operation of Company B's System 4B will be described. In this example, the score RB of Company A's System 4A received by Company B's System 4B is smaller than the threshold value RTH. Therefore, Company B's System 4B maintains the received data, that is, the data D with the electronic signature SA and the electronic certificate CA attached as it is. Then, Company B's System 4B attaches the electronic signature SB and the electronic certificate CB to the maintained data and outputs it to the user terminal 42.

[0103] In this way, when the reliability of the previous processing entity is low, the electronic signature and the electronic certificate given in the previous stage are maintained as they are. As a result, when the reliability of the devices and systems involved in data transmission cannot be ensured by the evaluation based on the score, the transmission path and the signature can be confirmed by the electronic signature and the electronic certificate generated by the device or the system.

[0104] As described above, according to this configuration, by applying the score evaluation, while compressing the transmission data, it is possible to confirm the transmission path of the transmission data in the same manner as the data transmission path confirmation system according to the above-described embodiment.

[0105] Other Embodiments Note that the present invention is not limited to the above-described embodiment, and can be appropriately modified without departing from the gist. For example, the electronic signature and the electronic signature specific information in the above-described embodiment are also simply referred to as signature information. The electronic certificate and the certificate specific information in the above-described embodiment are also simply referred to as signature authenticity information.

[0106] In the above-described embodiment, the configuration in which the data transmission path confirmation system has Company A's System and Company B's System, that is, two data relay systems, has been described. However, the data transmission path confirmation system may have a configuration having one or three or more data relay systems.

[0107] In Embodiment 3, it was described that Company A's system processes the data to be transmitted. However, similar to Company A's system, Company B's system may also be configured to process the data to be transmitted. That is, part or all of the one or more data relay systems included in the data transmission path confirmation system may have the same configuration as Company A's system in Embodiment 3.

[0108] In the data transmission path confirmation system according to Embodiment 2 as well, similar to Embodiment 3, part or all of the one or more data relay systems may have the same configuration as Company A's system in Embodiment 3.

[0109] In Embodiments 2 and 3 and the above-described modifications thereof, similar to Embodiment 4, the transmitted data may be compressed using a score.

[0110] In step ST3 of FIG. 14, an example of determining whether the score is equal to or greater than the threshold value was described, but this is merely an example, and it may be determined whether the score is greater than the threshold value.

[0111] Also, in Embodiment 4, it was described that when the score is large, the reliability is high, and when the score is small, the reliability is low, but this is merely an example. It may be that when the score is large, the reliability is low, and when the score is small, the reliability is high.

[0112] In the above-described embodiments, the data creator (transmission source) was described as a processing device configured by a device, but this is merely an example. When there is no need to specify a device as the data creator (transmission source), a system composed of a plurality of devices such as Company A's system and Company B's system, or other various processing entities may be used. Also, the data relay may be various processing entities such as not only systems such as Company A's system and Company B's system but also a single device. Furthermore, the user terminal is not limited to a single device and may be various systems or devices included in a system.

[0113] In the drawings referred to in the above embodiments, the processing device, Company A's system, Company B's system, and the user terminal can exchange information via various networks including general networks such as communication lines and the Internet. When Company A's system, Company B's system, and the user terminal are connected via a network, since the connection relationship is complex, the connection relationship is not shown in the figure. Also, in the figure, in order to make it easier to visually grasp the flow of information, the flow of information is represented using arrow lines.

[0114] In the above-described embodiments, the present invention has been described in terms of a hardware configuration, but the present invention is not limited thereto. The present invention can also be realized by causing a CPU (Central Processing Unit) to execute a computer program for the processing in the processing device, Company A system, Company B system, and user terminal. Further, the above-described program can be stored using various types of non-transitory computer readable media and supplied to a computer. The non-transitory computer readable media include various types of tangible storage media. Examples of the non-transitory computer readable media include magnetic recording media (e.g., flexible disks, magnetic tapes, hard disk drives), magneto-optical recording media (e.g., magneto-optical disks), CD-ROM (Read Only Memory), CD-R, CD-R / W, and semiconductor memories (e.g., mask ROM, PROM (Programmable ROM), EPROM (Erasable PROM), flash ROM, RAM (Random Access Memory)). Further, the program may be supplied to a computer by various types of transitory computer readable media. Examples of the transitory computer readable media include electrical signals, optical signals, and electromagnetic waves. The transitory computer readable media can supply the program to a computer via wired communication paths such as electric wires and optical fibers, or wireless communication paths.

Explanation of Signs

[0115] 1A, 2A, 3A, 4A Company A system 1B, 2B, 3B, 4B Company B system 10, 20, 30, 40 Certification Authorities 11, 21, 31, 41 Processing Devices 12, 22, 32, 42 User Terminals 43 Score Evaluation Unit 100, 200, 300, 400 Data Transmission Route Confirmation Systems 111, 121, 211, 311, 411 Data Acquisition Unit 112, 212, 314, 413 Information Attachment Unit 113, 213, 315, 414 Data Output Unit 122 Authenticity Verification Unit 123 Transmission Route Confirmation Unit 312 Data Processing Unit 313 Data Integration Unit 412 Score Confirmation Unit c, ca, cb Certificate Specific Information C, CA, CB Electronic Certificates D Data D' Processed Data PR, PRA, PRB Private Keys s, sa, sb Signature Specific Information S, SA, SB Electronic Signatures

Claims

1. authentication means configured to be able to transmit signature authenticity information indicating the authenticity of signature information; data transmission means for attaching and outputting its own signature information and signature authenticity information corresponding to the own signature information obtained from the authentication means to data to be transmitted; one or more data relay means for cumulatively attaching and outputting its own signature information and signature authenticity information corresponding to the own signature information obtained from the authentication means to the data received from the data transmission means; data receiving means for verifying the signature authenticity information cumulatively attached by the one or more data relay means with the authentication means, and confirming the transmission path of the data to be transmitted based on the signature information cumulatively attached by the one or more data relay means; the signature information is signature specifying information having a smaller data amount than the specified electronic signature, which specifies an electronic signature created using a private key; the signature authenticity information is certificate specifying information having a smaller data amount than the specified electronic signature, which specifies an electronic certificate proving the authenticity of the public key corresponding to the private key; the data transmission means and the one or more data relay means generate the electronic signature and corresponding signature specifying information and transmit them to the authentication means; the authentication means holds a plurality of received electronic signatures and a plurality of signature specifying information, and transmits certificate specifying information corresponding to each electronic signature to the data transmission means and the one or more data relay means; the data receiving means transmits the plurality of cumulatively attached signature specifying information and the plurality of certificate specifying information to the authentication means, and acquires the plurality of electronic signatures and the plurality of electronic certificates corresponding to the transmitted plurality of signature specifying information and the plurality of certificate specifying information; A data transmission path confirmation system.

2. Some or all of the one or more data relay means, when processing the data to which the signature information and the signature authenticity information included in the received data are attached, attach its own signature information and signature authenticity information corresponding to the own signature information to the data obtained by integrating the data before processing to which the signature information and the signature authenticity information are attached and the processed data, and output the result; The data transmission path confirmation system according to Claim 1.

3. The authentication means holds a score indicating the reliability of the one or more data relay means, Each of the one or more data relay means inquires of the authentication means about the score of the previous-stage data transmission means or the previous-stage data relay means that transmitted the received data, When the reliability of the previous-stage data transmission means or the previous-stage data relay means is guaranteed by the inquired score, the signature information and the signature authenticity information attached to the received data are replaced with meta information indicating that data has been received from the previous-stage data transmission means or the previous-stage data relay means, When the reliability of the previous-stage data transmission means or the previous-stage data relay means is not guaranteed by the inquired score, the signature information and the signature authenticity information attached to the received data are maintained, The data transmission path confirmation system according to claim 1 or 2.

4. An authentication means configured to be able to transmit signature authenticity information indicating the authenticity of signature information, data transmission means for attaching and outputting to the data to be transmitted its own signature information and the signature authenticity information corresponding to its own signature information obtained from the authentication means, one or more data relay means for cumulatively attaching and outputting to the data received from the data transmission means its own signature information and the signature authenticity information corresponding to its own signature information obtained from the authentication means, a data reception means for verifying the signature authenticity information cumulatively attached by the one or more data relay means with the authentication means and for confirming the transmission path of the data to be transmitted based on the signature information cumulatively attached by the one or more data relay means, The authentication means holds a score indicating the reliability of the one or more data relay means, Each of the one or more data relay means inquires of the authentication means about the score of the previous-stage data transmission means or the previous-stage data relay means that transmitted the received data, When the reliability of the previous-stage data transmission means or the previous-stage data relay means is guaranteed by the inquired score, the signature information and the signature authenticity information attached to the received data are replaced with meta information indicating that data has been received from the previous-stage data transmission means or the previous-stage data relay means, When the reliability of the data transmission means or the data relay means in the previous stage is not guaranteed by the inquired score, the signature information and the signature authenticity information attached to the received data are maintained. Data transmission path confirmation system.

5. The signature information is an electronic signature created using a private key. The signature authenticity information is an electronic certificate proving the authenticity of the public key corresponding to the private key. The data transmission path confirmation system according to claim 4.

6. Some or all of the one or more data relay means When processing the data to which the signature information and the signature authenticity information included in the received data are attached, The own signature information and the signature authenticity information corresponding to the own signature information are attached to and output to the integrated data of the data before processing to which the signature information and the signature authenticity information are attached and the data after processing. The data transmission path confirmation system according to claim 5.

7. Stored in an authentication means configured to be able to transmit signature authenticity information indicating the authenticity of the signature information, The signature information of the data transmission means and the signature authenticity information corresponding to the signature information of the data transmission means acquired from the authentication means are attached to and output to the data to be transmitted. One or more data relay means receive data from the data transmission means, and the one or more data relay means cumulatively attach and output their own signature information and the signature authenticity information corresponding to their own signature information acquired from the authentication means. The data receiving means verifies the signature authenticity information cumulatively attached by the one or more data relay means with the authentication means, and based on the signature information cumulatively attached by the one or more data relay means, confirms the transmission path of the data to be transmitted. The signature information is signature specifying information that specifies an electronic signature created using a private key and has a smaller data volume than the specified electronic signature. The signature authenticity information is certificate specifying information that specifies an electronic certificate proving the authenticity of the public key corresponding to the private key and has a smaller data volume than the specified electronic signature. The data transmission means and the one or more data relay means generate the electronic signature and the corresponding signature specifying information and transmit them to the authentication means. The authentication means holds the received plurality of the electronic signatures and the plurality of the signature specifying information, and transmits the certificate specifying information corresponding to each of the electronic signatures to the data transmitting means and the one or more data relay means, The data receiving means transmits the cumulatively given plurality of the signature specifying information and the plurality of the certificate specifying information to the authentication means, and acquires the plurality of the electronic signatures and the plurality of the electronic certificates corresponding to the transmitted plurality of the signature specifying information and the plurality of the certificate specifying information, Data transmission path confirmation method.

8. A data acquisition means for acquiring the data output from a data transmission means that attaches and outputs to the data to be transmitted its own signature information and the signature authenticity information corresponding to the own signature information acquired from an authentication means configured to be able to transmit the signature authenticity information indicating the authenticity of the signature information, An information attaching means for cumulatively attaching to the data received by the data acquisition means its own signature information and the signature authenticity information corresponding to the own signature information acquired from the authentication means, A data output means for outputting the data to which the signature information and the signature authenticity information are attached by the information attaching means, A data receiving means verifies the cumulatively given signature authenticity information with the authentication means, and confirms the transmission path of the data to be transmitted based on the cumulatively given signature information, The signature information is signature specifying information that specifies an electronic signature created using a private key and has a smaller data volume than the specified electronic signature, The signature authenticity information is certificate specifying information that specifies an electronic certificate proving the authenticity of the public key corresponding to the private key and has a smaller data volume than the specified electronic signature, The information attaching means generates the electronic signature and the corresponding signature specifying information and transmits them to the authentication means, The authentication means holds the received electronic signature and the signature specifying information, and transmits the certificate specifying information corresponding to the electronic signature to the data acquisition means, The data receiving means transmits the cumulatively given plurality of the signature specifying information and the plurality of the certificate specifying information to the authentication means, and acquires the plurality of the electronic signatures and the plurality of the electronic certificates corresponding to the transmitted plurality of the signature specifying information and the plurality of the certificate specifying information, Data relay system.

9. Data acquisition means that receives data from one or more data relay means that cumulatively attach its own signature information and signature authenticity information corresponding to the said own signature information obtained from authentication means configured to be able to transmit signature authenticity information indicating the authenticity of the signature information to the data to be transmitted and output it. Authenticity verification means that verifies the signature authenticity information cumulatively attached to the data received by the said data acquisition means with the authentication means. Transmission path confirmation means that confirms the transmission path of the data to be transmitted based on the said cumulatively attached signature information. It is provided with. The signature information is signature identification information that identifies an electronic signature created using a private key and has a smaller data volume than the identified electronic signature. The signature authenticity information is certificate identification information that identifies an electronic certificate that proves the authenticity of the public key corresponding to the private key and has a smaller data volume than the identified electronic signature. The data transmission means and the one or more data relay means generate the electronic signature and corresponding signature identification information and transmit it to the authentication means. The authentication means holds a plurality of the received electronic signatures and a plurality of the signature identification information, and transmits certificate identification information corresponding to each of the electronic signatures to the data transmission means and the one or more data relay means. The data acquisition means transmits the plurality of the cumulatively attached signature identification information and the plurality of the certificate identification information to the authentication means, and acquires the plurality of the electronic signatures and the plurality of the electronic certificates corresponding to the plurality of the transmitted signature identification information and the plurality of the certificate identification information. Data receiving device.

10. Store in an authentication means configured to be able to transmit signature authenticity information indicating the authenticity of the signature information. Attach and output the signature information of the data transmission means and the signature authenticity information corresponding to the signature information of the data transmission means obtained from the authentication means to the data to be transmitted. One or more data relay means receive data from the data transmission means, and the one or more data relay means cumulatively attach its own signature information and signature authenticity information corresponding to the said own signature information obtained from the authentication means and output it. Verify the signature authenticity information cumulatively provided by the one or more data relay means with the authentication means, and confirm the transmission route of the data to be transmitted based on the signature information cumulatively provided by the one or more data relay means. The authentication means holds a score indicating the reliability of the one or more data relay means. Each of the one or more data relay means Queries the authentication means for the score of the previous-stage data transmission means or the previous-stage data relay means that transmitted the received data. When the reliability of the previous-stage data transmission means or the previous-stage data relay means is guaranteed by the queried score, replace the signature information and the signature authenticity information attached to the received data with meta information indicating that the data has been received from the previous-stage data transmission means or the previous-stage data relay means. When the reliability of the previous-stage data transmission means or the previous-stage data relay means is not guaranteed by the queried score, maintain the signature information and the signature authenticity information attached to the received data. Data transmission route confirmation method.

11. A data acquisition means that receives data output from a data transmission means configured to attach its own signature information and signature authenticity information corresponding to the own signature information obtained from an authentication means capable of transmitting the signature authenticity information indicating the authenticity of the signature information to the data to be transmitted and output it. An information adding means that cumulatively adds its own signature information and signature authenticity information corresponding to the own signature information obtained from the authentication means to the data received by the data acquisition means. A data output means that outputs the data to which the signature information and the signature authenticity information have been added by the information adding means. The data receiving means verifies the signature authenticity information cumulatively provided with the authentication means, and confirms the transmission route of the data to be transmitted based on the signature information cumulatively provided. The authentication means holds a score indicating the reliability of the transmission source of the data received by the data acquisition means. The data acquisition means queries the authentication means for the score of the transmission source. The information adding means When the reliability of the sender is guaranteed by the queried score, replace the signature information and the signature authenticity information attached to the received data with meta information indicating that the data has been received from the sender. When the reliability of the sender is not guaranteed by the queried score, maintain the signature information and the signature authenticity information attached to the received data. Data relay system.

12. A data acquisition means for receiving data from one or more data relay means that cumulatively attach and output their own signature information and the signature authenticity information corresponding to their own signature information obtained from an authentication means configured to be able to transmit the signature authenticity information indicating the authenticity of the signature information to the data to be transmitted. An authenticity verification means for verifying the signature authenticity information cumulatively attached to the data received by the data acquisition means with the authentication means. A transmission path confirmation means for confirming the transmission path of the data to be transmitted based on the cumulatively attached signature information. The authentication means holds a score indicating the reliability of the one or more data relay means. Each of the one or more data relay means Queries the authentication means for the score of the previous-stage data transmission means or the previous-stage data relay means that transmitted the received data. When the reliability of the previous-stage data transmission means or the previous-stage data relay means is guaranteed by the queried score, replace the signature information and the signature authenticity information attached to the received data with meta information indicating that the data has been received from the previous-stage data transmission means or the previous-stage data relay means. When the reliability of the previous-stage data transmission means or the previous-stage data relay means is not guaranteed by the queried score, maintain the signature information and the signature authenticity information attached to the received data. Data receiving device.

Citation Information

Patent Citations

  • Creator terminal, browser terminal and program

    JP2006107099A

  • Document information editing device, document information editing method, document information editing program, and recording medium

    JP2009020618A

  • Data distribution path verification

    JP2015026362A

  • Internet of Things device record verification method and device, and ID authentication method and device

    JP2020511016A

  • Information processing system, server apparatus, information processing apparatus, and operation control apparatus

    JP2021189715A