Verification method, verification device, and verification program for verifying product identity
The verification method uses a ledger with public keys and encoded product information to prevent counterfeiting by ensuring only legitimate manufacturers can generate valid codes, addressing the issue of counterfeit verification information and enabling authentic product verification.
Patent Information
- Application Number
- JP2022058678
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-31
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2042-03-31
AI Technical Summary
Conventional methods for generating verification basis information based on predetermined generation rules allow third parties to identify and generate counterfeit verification information, making it difficult to distinguish genuine products from counterfeits.
A verification method using a ledger that associates public keys, brand information, and encoded product identification information, where the encoded code is generated with a private key, ensuring only the legitimate manufacturer can create valid codes, and a monitoring unit prevents unauthorized registration, while a distribution tracking system verifies the authenticity of products through a blockchain.
This method reduces the burden of generating verification information and prevents counterfeiting by ensuring only legitimate manufacturers can create valid codes, allowing consumers to verify product authenticity and distribution legitimacy.
Smart Images

Figure 0007748721000001 
Figure 0007748721000002 
Figure 0007748721000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a verification method for verifying the identity of a manufactured product and a purchased product. [Background technology]
[0002] Conventionally, the following methods have been known as methods for verifying the identity of products, specifically, methods for verifying the identity of a manufactured product (manufactured product) and a purchased product (purchased product). Specifically, a method is known in which identification information that can uniquely identify a manufactured product, such as product information, is registered in a server, and the manufactured product is sold with the product information assigned to it, and the product information assigned to the purchased product is compared with the product information registered in the server. Various attempts have also been made to reduce the burden associated with generating information (basic verification information) that can be used to verify product identity, such as the above-mentioned product information, and registering it in a server. For example, Patent Document 1 listed below discloses a technology that reduces the burden associated with generating basic verification information by configuring the basic verification information as a combination of major category serial codes and minor category serial codes.
[0003] When basic verification information is generated based on predetermined generation rules as proposed in the related art, a large amount of basic verification information can be generated at once, and the generated large amount of basic verification information can be registered on a server at once, thereby reducing the burden associated with generating basic verification information that can be used to verify the identity of products. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Publication No. 2020-95649 Summary of the Invention [Problem to be solved by the invention]
[0005] However, the present inventors have discovered the following problem with conventional methods of generating verification basis information based on predetermined generation rules. Specifically, when a manufacturer (a genuine manufacturer) of a certain product generates verification basis information based on predetermined generation rules, a third party other than the genuine manufacturer may be able to identify the verification basis information by, for example, analyzing a large amount of verification basis information. The third party who identified the verification rule may then generate a large amount of false verification basis information based on the identified generation rules, which is indistinguishable from the verification basis information generated by the genuine manufacturer. If such a third party assigns a large amount of false verification basis information to a large number of counterfeit products and sells them, the false verification basis information assigned to each of the large number of counterfeit products cannot be distinguished from the verification basis information generated by the genuine manufacturer. In other words, depending on the verification basis information, a situation may arise in which it is impossible to determine whether a product to which the verification basis information is assigned is a genuine product (a legitimate product) or a counterfeit. This situation is significant not only for the genuine manufacturer but also for those who purchase products that they believe to be manufactured by the genuine manufacturer.
[0006] In one aspect, the present invention has been made in consideration of such problems, and its purpose is to provide a verification method, etc. that reduces the burden associated with generating basic verification information that can be used to verify the identity of a product, while preventing third parties from understanding the rules for generating the basic verification information. [Means for solving the problem]
[0007] In order to solve the above-mentioned problems, the present invention employs the following configuration.
[0008] That is, the verification method according to the first aspect of the present invention is a verification method in which a computer verifies the identity of a product, by searching a ledger in which (A) a public key and (B) brand information, which is information about a product group including the product and includes at least one of a brand name that is the name of the product group and the name of the manufacturer that manufactured the product, are associated with each other, and further, (C) product identification information that can uniquely identify a product manufactured by the manufacturer, which is an encoded code generated by encoding product identification information that includes at least a part of the public key using a private key that corresponds to the public key, and (D) product information that includes information that can identify the product in the product group, are associated with each other and registered, using an attached public key that is the public key assigned to the product to be purchased. The method includes a first acquisition step of acquiring the brand information registered in the ledger in association with a registered public key, which is a public key registered in the ledger and which matches the attached public key; a second acquisition step of acquiring the product information registered in the ledger in association with a registered encoding code, which is a encoding code registered in the ledger and which matches the attached encoding code, by searching the ledger using the attached encoding code, which is a encoding code assigned to the product to be purchased; and a determination step of determining that the manufactured product and the product to be purchased are the same product if at least a part of the public key included in decoded information obtained by decoding the attached encoding code using the attached public key matches at least a part of the attached public key.
[0009] In this configuration, the computer acquires the brand information in the first acquisition step. Therefore, for example, a consumer (end consumer) purchasing the product can verify the authenticity of the brand information, i.e., whether the product is a genuine brand, by comparing the brand information acquired by the computer with commonly known information about the product's brand. If the brand information is true (e.g., matches commonly known information about the product's brand), the consumer can determine that the product they are purchasing is genuine (the product they are purchasing is the same as a product manufactured by a legitimate manufacturer). On the other hand, if the brand information is false (e.g., does not match commonly known information about the product's brand), the consumer can determine that the product they are purchasing is a counterfeit (the product they are purchasing is not the same as a product manufactured by a legitimate manufacturer).
[0010] The computer also acquires the product information in the second acquisition step. Therefore, for example, a consumer purchasing the product can verify the authenticity of the product information, i.e., whether the product is genuine (whether it is part of a legitimate brand), by comparing the product information acquired by the computer with commonly available information about the product (e.g., information printed on the product's packaging). If the product information is true (e.g., matches commonly available information about the product), the consumer can determine that the product they are purchasing is authentic (the product they are purchasing is the same as a product manufactured by a legitimate manufacturer). If the product information is false (e.g., does not match commonly available information about the product), the consumer can determine that the product they are purchasing is a counterfeit (the product they are purchasing is not the same as a product manufactured by a legitimate manufacturer).
[0011] Furthermore, if at least a portion of the public key included in the decryption information matches at least a portion of the attached public key, the computer determines that the manufactured product and the purchased product are the same product.
[0012] Here, if the manufactured product (manufactured product) and the purchased product (purchased product) are the same product, the attached encoded code should have been generated by encoding product identification information, including at least a portion of the public key, using a private key corresponding to the public key. Furthermore, if the manufactured product and the purchased product are the same product, the attached public key should match the public key corresponding to the private key used to generate the attached encoded code. Therefore, if the manufactured product and the purchased product are the same product, the attached encoded code should be decoded using the attached public key. Furthermore, if the manufactured product and the purchased product are the same product, the decryption information obtained by decoding the attached encoded code using the attached public key should match the product identification information. The product identification information includes at least a portion of the public key. Therefore, if the manufactured product and the purchased product are the same product, the decryption information should include "at least a portion of the public key" that matches at least a portion of the attached public key. Therefore, the configuration can use the encoded code to verify whether the manufactured product and the purchased product are the same product, that is, to verify the identity of the products.
[0013] Additionally, in this configuration, the encoded code that is assigned to the product to determine its identity and registered in the ledger is generated by encoding the product identification information with the private key. Therefore, even if a person other than the person who holds the private key analyzes the encoded code, they cannot identify the generation rule of the encoded code (i.e., the private key), the product identification information, or the generation rule of the product identification information. In other words, no one other than the person who holds the private key can know the generation rule of the encoded code (the private key). Therefore, this configuration can prevent a situation in which a person other than the person who holds the private key identifies the generation rule of the encoded code and generates a large number of false (illegal) encoded codes that cannot be distinguished from genuine (legitimate) encoded codes.
[0014] In contrast, a person who holds the private key can generate a large amount of product identification information, each of which can uniquely identify each of the multiple products, by any method, and can easily generate a large amount of the encoded codes from the large amount of product identification information by using the private key.
[0015] In other words, this configuration can prevent a situation in which the rules for generating the encoded code are discovered by a third party and the encoded code is counterfeited in large quantities, while reducing the burden on genuine (legitimate) manufacturers involved in generating the encoded code, etc.
[0016] Therefore, with this configuration, it is possible to reduce the burden associated with generating the encoded code (basic verification information) that can be used to verify the identity of a product, while preventing third parties from understanding the rules for generating the encoded code.
[0017] A verification method according to a second aspect of the present invention is the verification method according to the first aspect, further comprising: a business ID, which is identification information capable of uniquely identifying each business, being made public to purchasers of the product at the store of each of the business; and (E) the business ID and (F) business information, which includes at least one of the name of the business uniquely identified by the business ID and information identifying the location of the store, being registered in the ledger in association with each other; and further, the business ID and (F) business information, which includes at least one of the name of the business uniquely identified by the business ID and information identifying the location of the store, are associated with each other and registered in the ledger in association with the encoded code generated by encoding the product identification information with the private key, so that (1) if the product uniquely identified by the product identification information has not yet been transferred (bought and sold) between businesses, the business ID capable of uniquely identifying the manufacturer of the product, and (2) if the product uniquely identified by the product identification information has been transferred between businesses, the business ID capable of uniquely identifying the business that purchased the product ... registered in association with each other and the encoded code generated by encoding the product identification information with the private key. The business ID is registered as an owned business ID, and the computer further executes a third acquisition step of searching the ledger using a public business ID, which is the business ID made public in the store, to acquire the business information registered in the ledger, which is associated with a registered business ID, which is a business ID registered in the ledger and which matches the public business ID; an owned business identification step of searching the ledger using the attached coded code to identify the owned business ID registered in the ledger, which is associated with a registered coded code, which is a coded code registered in the ledger and which matches the attached coded code; and a distribution determination step of determining that the product is distributed through a legitimate distribution route if the owned business ID identified in the owned business identification step matches the public business ID.
[0018] In this configuration, the computer acquires the business information in the third acquisition step. Therefore, for example, a consumer (end consumer) purchasing the product can verify the authenticity of the business information by comparing the business information acquired by the computer with generally known information about the business. If the business information is true (e.g., matches generally known information about the business), the consumer can determine that the product they are purchasing is authentic (the product they are purchasing is the same as a product manufactured by an authorized manufacturer). If the business information is false (e.g., does not match generally known information about the business), the consumer can determine that the product they are purchasing is a counterfeit (the product they are purchasing is not the same as a product manufactured by an authorized manufacturer).
[0019] The computer also identifies the owner business ID using the attached coded code, and determines whether the identified owner business ID matches the published business ID published in the store selling the product. If the two match, the computer determines that the product is distributed through a legitimate distribution channel.
[0020] Here, there is a risk that a fake (illegal) coded code identical to the genuine coded code may be generated by copying the genuine (authorized) coded code attached to the product. For example, a situation can be imagined in which a genuine product held by a genuine (authorized) retailer D1 is attached with an attached coded code (A), and a counterfeit product held by a fake (illegal) retailer D2 is attached with an attached coded code (B), which is a fake coded code generated by copying the attached coded code (A).
[0021] In such a situation, the attached coded code (B) is generated by copying the attached coded code (A), so the contents of the attached coded code (A) and the attached coded code (B) are exactly the same.
[0022] However, even under such circumstances, the business ID registered in the ledger as the owning business ID in association with the registered coded code that matches the attached coded code (A) (=attached coded code (B)) should be, for example, the following business ID: In other words, the business ID that can uniquely identify "the business that intends to sell the product purchased through a legitimate distribution channel to the consumer (i.e., the legitimate retailer D1)" should be registered in the ledger as the owning business ID.
[0023] Therefore, by searching the ledger using the attachment coding code (A) (= attachment coding code (B)), it can be determined that retailer D1 is a genuine (legitimate) retailer and retailer D2 is a fake (illegitimate) retailer.
[0024] Therefore, in this configuration, even if the encoding code (legitimate encoding code) is copied to generate an illegal encoding code, it is possible to determine whether the distribution route of the product to which the encoding code is assigned is legitimate or not.
[0025] A verification method according to a third aspect of the present invention is the verification method according to the second aspect, further comprising the steps of: a sales report receiving step in which a second computer receives a report from a business uniquely identified by the owning business ID associated with the encoded code and registered in the ledger, the report notifying the purchasing business ID, which is the business ID that can uniquely identify the purchasing business that is the business that purchased the product; an inquiry step in which the second computer inquires of the business uniquely identified by the purchasing business ID included in the report received in the sales report receiving step whether it is the current owner of the product; and an owner update step in which, upon receiving a response to the inquiry from the business uniquely identified by the purchasing business ID acknowledging that it is the current owner of the product, the second computer updates the business ID associated with the encoded code and registered in the ledger as the owning business ID to the purchasing business ID.
[0026] In this configuration, the second computer confirms the authenticity of the transfer (sale) of the product with the purchasing business based on a report from the business that is uniquely identified by the owning business ID that is associated with the encoded code and registered in the ledger. Then, when the second computer confirms the transfer of the product based on the response from the purchasing business, it updates the business ID registered as the owning business ID to the purchasing business ID, that is, to the business ID that can uniquely identify the purchasing business.
[0027] Therefore, in this configuration, the authenticity of the business operator associated with the encoded code and registered in the ledger as the owner of the product can be ensured.
[0028] A verification method according to a fourth aspect of the present invention is the verification method according to any one of the first to third aspects, further comprising: an application acceptance step in which a third computer accepts a registration application from the manufacturer of the product requesting that the public key and the brand information be registered in the ledger; a registration determination step in which the third computer determines whether the registration application accepted in the application acceptance step is acceptable; and a brand registration step in which the third computer registers the public key and the brand information in the ledger in association with each other if the third computer determines in the registration determination step that the registration application is acceptable.
[0029] In this configuration, the third computer accepts the registration request and determines whether to approve the registration request. If the third computer determines that the registration request is acceptable, it registers the public key and the brand information related to the registration request in the ledger in association with each other. In other words, only combinations of the public key and the brand information that the third computer determines to be acceptable for registration are registered in the ledger.
[0030] Therefore, in this configuration, only combinations of the public key and the brand information that are determined by the third computer to be acceptable for registration are registered in the ledger, thereby preventing, for example, fake (illegitimate) businesses from registering the brand information, etc. in the ledger.
[0031] The present invention may not be limited to the above-described verification method. As another aspect of the verification method according to the above-described embodiment, one aspect of the present invention may be a verification device that realizes all or part of the above-described configurations. Furthermore, one aspect of the present invention may be an information processing method that realizes all or part of the above-described configurations, a program, or a storage medium that stores such a program and is readable by a computer or other device, machine, etc. Here, a storage medium that is readable by a computer, etc. is a medium that stores information such as a program by electrical, magnetic, optical, mechanical, or chemical action.
[0032] For example, a verification device according to a fifth aspect of the present invention is a verification device for verifying the identity of a product, and the verification device verifies the identity of a product by searching a ledger in which (A) a public key and (B) brand information, which is information about a product group including the product and includes at least one of a brand name that is the name of the product group and the name of the manufacturer that manufactured the product, are associated with each other, and further in which (C) product identification information that can uniquely identify a product manufactured by the manufacturer, which is an encoded code generated by encoding product identification information that includes at least a part of the public key using a private key that corresponds to the public key, and (D) product information that includes information that can identify the product in the product group, are associated with each other and registered, using an attached public key that is a public key assigned to the product to be purchased. and a first acquisition unit that acquires the brand information registered in the ledger in association with a registered public key, which is a public key registered in the ledger and matches the attached public key; a second acquisition unit that acquires the product information registered in the ledger in association with a registered encoding code, which is a encoding code registered in the ledger and matches the attached encoding code, by searching the ledger using an attached encoding code, which is a encoding code assigned to the product to be purchased; and a determination unit that determines that the manufactured product and the product to be purchased are the same product when at least a part of the public key included in decoded information obtained by decoding the attached encoding code using the attached public key matches at least a part of the attached public key.
[0033] For example, a verification program according to a sixth aspect of the present invention is a verification program that causes a computer to verify the identity of a product, and the computer uses an attached public key that is a public key assigned to the product to verify a ledger in which (A) a public key and (B) brand information, which is information about a product group that includes the product and includes at least one of a brand name that is the name of the product group and the name of the manufacturer that manufactured the product, are associated with each other, and further in which (C) product identification information that can uniquely identify a product manufactured by the manufacturer, which is an encoded code generated by encoding product identification information that includes at least a part of the public key using a private key that corresponds to the public key, and (D) product information, which includes information that can identify the product in the product group, are associated with each other and registered. a first acquisition step of acquiring the brand information registered in the ledger in association with a registered public key, which is a public key registered in the ledger and which matches the attached public key, by searching the ledger using an attached encoded code, which is an encoded code assigned to the product to be purchased, and which is registered in the ledger in association with a registered encoded code, which is an encoded code registered in the ledger and which matches the attached encoded code; and a determination step of determining that the manufactured product and the product to be purchased are the same product if at least a part of the public key included in decoded information obtained by decoding the attached encoded code using the attached public key matches at least a part of the attached public key. [Effects of the Invention]
[0034] According to the present invention, it is possible to provide a verification method etc. that prevents the mass counterfeiting of verification basic information that can be used to verify the identity of a product, while reducing the burden associated with generating such verification basic information. [Brief explanation of the drawings]
[0035] [Figure 1]FIG. 1 is a diagram illustrating an example of an overall overview of a verification system according to an embodiment. [Figure 2] FIG. 2 is a block diagram showing a schematic configuration of a monitoring device that operates as a monitoring unit. [Figure 3] FIG. 3 is a block diagram showing a schematic configuration of an application device operating as a manufacturer. [Figure 4] FIG. 4 is a diagram illustrating various types of information generated by a manufacturer (application device) and how the manufacturer uses the generated information. [Figure 5] FIG. 5 is a block diagram showing a schematic configuration of a reporting device that operates as a distributor and / or retailer. [Figure 6] FIG. 6 is a block diagram showing a schematic configuration of the management server. [Figure 7] FIG. 7 is a block diagram showing a schematic configuration of a verification device operating as a consumer. [Figure 8] FIG. 8 is a diagram illustrating an outline of a method for registering public keys and brand information in a ledger. [Figure 9] FIG. 9 is a flow diagram illustrating the flow from brand registration application to brand registration in the verification system of FIG. [Figure 10] FIG. 10 is a diagram illustrating a plurality of monitoring units having a hierarchical structure provided in the verification system of FIG. [Figure 11] FIG. 11 is a diagram illustrating an overview of MICA adopted by the verification system of FIG. [Figure 12] FIG. 12 is a flow diagram outlining the product registration process and the like executed by a manufacturer (application device) in MICA. [Figure 13] FIG. 13 is a flow diagram outlining various verification processes executed by a consumer (verification device) in MICA. [Figure 14] FIG. 14 is a diagram illustrating an overview of SICA employed by the verification system of FIG. [Figure 15]FIG. 15 is a flow diagram outlining the owner business operator ID update process and the like executed by the management server in the SICA. [Figure 16] FIG. 16 is a diagram illustrating a ledger in which the owner business ID is updated by the management server every time a product is sold between businesses. [Figure 17] FIG. 17 is a flow diagram outlining various verification processes executed by a consumer (verification device) in SICA. DETAILED DESCRIPTION OF THE INVENTION
[0036] An embodiment according to one aspect of the present invention (hereinafter also referred to as "the present embodiment") will be described below with reference to the drawings. However, the present embodiment described below is merely an example of the present invention in all respects. Needless to say, various improvements and modifications can be made without departing from the scope of the present invention. In other words, when implementing the present invention, specific configurations according to the embodiment may be appropriately adopted. Note that, although data appearing in the present embodiment are described in natural language, more specifically, they are specified using pseudo-language, commands, parameters, machine language, etc. that can be recognized by a computer.
[0037] §1 Application Examples The verification system S and verification method M according to this embodiment verify the identity of a product P, for example, the identity of a manufactured product P(X) and a purchased product P(Y), and specifically, use an encoded code CPid or the like to verify the identity of the product P. For example, the verification system S and verification method M verify the identity of the product P using an encoded code CPid (registered encoded code rCPid) or the like registered in the ledger Led and an encoded code CPid (attached encoded code aCPid) or the like assigned to the product P.
[0038] In this embodiment, an example will be described in which the ledger Led is a distributed ledger built on the Green Chain GC platform, which is a blockchain, and in which multiple ledgers Led have the same content. In the present invention, it is not necessary for the ledger Led to be a distributed ledger built on the blockchain (Green Chain GC) platform. However, by using the ledger Led as a distributed ledger built on the blockchain platform, the following effects can be achieved, for example: Because data within blocks in a blockchain cannot be retroactively changed, tampering with data in the ledger Led becomes more difficult, improving the reliability of the ledger Led. Furthermore, in a distributed ledger realized by a blockchain, information registered (stored) in the ledger can be viewed at any time, and the legitimacy and consistency of the content can be ensured by consensus among participants when updating. Blockchain enables traceability, preventing falsification and tampering of information registered in the ledger without the involvement of a third party, thereby improving reliability and transparency. The Green Chain GC in this embodiment is, for example, a consortium-type blockchain.
[0039] In this embodiment, Ledger Led is registered (stored) in each block of Green Chain GC, which is a blockchain, so hereinafter, "registering various information in Ledger Led" may be expressed as "registering various information in Green Chain GC." Similarly, "searching for various information registered in Ledger Led" may be expressed as "searching for various information registered in Green Chain GC." Information registered in Green Chain GC specifically means information registered in Ledger Led.
[0040] First, to facilitate understanding of the verification system S and verification method M according to this embodiment, the problems of a conventional verification system using a blockchain for verifying the identity of a product P will be explained.
[0041] (Problems with conventional verification systems) The following three problems can be pointed out with conventional blockchain-based verification systems for verifying product identity:
[0042] First, conventional verification systems cannot detect fake (illegible) businesses that attempt to manufacture and sell product P manufactured and sold by a genuine (legitimate) business without the authorization of the genuine business. Therefore, conventional verification systems lack effective measures to prohibit the manufacture and sale of such products by fake businesses. For example, a fake manufacturer can register itself as a genuine business on the blockchain provided by a conventional verification system, thereby making purchasers of product P believe that it is the genuine business.
[0043] Second, blockchains provided by conventional verification systems have the potential for the registration of large amounts of counterfeit (illegal) verification basic information, which is a forged version of verification basic information that can be used to verify the identity of product P. Generating verification basic information based on predetermined generation rules allows for the easy generation of large amounts of verification basic information, and the large amounts of generated verification basic information can also be registered, for example, in bulk, on the blockchain. Therefore, using such generation rules can reduce the burden associated with generating verification basic information and registering it on the blockchain. However, methods of generating verification basic information based on generation rules have the drawback that a third party who understands the generation rules can forge verification basic information and generate large amounts of counterfeit verification basic information. For example, if a manufacturer of counterfeit products becomes aware of the generation rules used by a genuine (legitimate) manufacturer to generate verification basic information, the following situation is likely to occur. That is, the manufacturer of counterfeit products could use the understood generation rules to create large amounts of counterfeit verification basic information that is indistinguishable from information generated by the genuine manufacturer, and then attach it to counterfeit products for sale. In such a situation, it is difficult to determine whether product P is genuine or a counterfeit from the basic verification information attached to product P, which is undesirable for both the purchaser of product P and the genuine manufacturer.
[0044] Third, conventional verification systems cannot distinguish between genuine products that have genuine (legitimate) verification information attached by a genuine manufacturer and counterfeit products that have fake (illegal) verification information that was created by copying the genuine verification information attached to the genuine product. Generating verification information without using generation rules increases the burden associated with generating the verification information, but it can prevent a situation in which "a third party learns the generation rules and a large amount of verification information is forged." However, even if verification information is generated without using generation rules, it cannot prevent a third party from illegally copying the verification information (genuine verification information) attached to each genuine product P (genuine product) in the market. Furthermore, conventional verification systems cannot distinguish between genuine products that have genuine verification information attached and counterfeit products that have fake verification information that was created by copying the genuine verification information.
[0045] (Outline of the verification system according to this embodiment) The verification system S (and verification method M) according to this embodiment employs the following configurations to solve the above three problems.
[0046] As a configuration for solving the first problem, the verification system S is equipped with a monitoring unit A that prevents "fake (illegal) businesses (for example, businesses that attempt to manufacture and sell product P without the permission of a true (legitimate) business) from registering fraudulent information in the Green Chain GC."
[0047] In the following explanation, an example will be described in which "manufacturer B manufactures product P." That is, an example will be described in which the true (authorized) manufacturer of product P is "manufacturer B." Furthermore, a fake (unauthorized) manufacturer that attempts to manufacture and sell product P without the permission of manufacturer B will be referred to as "manufacturer I." Furthermore, a consumer (end consumer) who purchases (or attempts to purchase) product P will be referred to as "consumer E." This embodiment assumes a situation in which consumer E is attempting to purchase product P from retailer D.
[0048] The monitoring unit A protects "Manufacturer B, the true manufacturer" and consumer E from "Manufacturer I, the fake manufacturer." Specifically, if the monitoring unit A determines that Manufacturer B is the "true manufacturer" of Product P, it registers the public key PuK (public key PuK(B)) provided by Manufacturer B in the ledger Led (Green Chain GC) in association with the brand information IB of Product P. On the other hand, if the monitoring unit A determines that Manufacturer I is not the "true manufacturer" of Product P, it does not register the public key PuK (public key PuK(I)) provided by Manufacturer I in the Green Chain GC. In the verification system S, only the monitoring unit A can register the public key PuK in association with the brand information IB of Product P in the ledger Led (Green Chain GC). Therefore, the monitoring unit A can prevent Manufacturer I from registering fraudulent information in the ledger Led (Green Chain GC) and disguising itself as the "true manufacturer" of Product P.
[0049] To solve the second problem, the verification system S employs a technique called MICA (Massive Illegal Copied Avoidance). MICA reduces the burden of generating basic verification information (specifically, the CPid code described below) that can be used to verify the identity of a product P, while preventing third parties from learning the rules for generating the basic verification information. In other words, MICA is a technique for preventing a third party who understands the rules for generating basic verification information from using those rules to create large quantities of false basic verification information (Massive Illegal Copied Avoidance). MICA reduces the burden on genuine (legitimate) businesses associated with generating the CPid code. MICA also prevents a situation in which a fake business identifies the rules for generating the CPid code (the generation rules and generation method) and creates large quantities of counterfeit CPid codes.
[0050] To solve the third problem, the verification system S employs a technique called SICA (Single Illegal Copied Avoidance) to distinguish between genuine products bearing true basic verification information and counterfeit products bearing false basic verification information created by copying the true basic verification information of genuine products. In other words, SICA is a technique for preventing true basic verification information from being individually copied to create false basic verification information (Single Illegal Copied Avoidance). As will be described in detail later, SICA manages information (owner business ID) identifying the business that owns product P (the legitimate business) from the time that product P is manufactured by manufacturer B until it is sold to consumer E. Therefore, when consumer E purchases (or attempts to purchase) product P, SICA enables him or her to determine whether the business selling product P is a legitimate business or an unauthorized business. In other words, a person who purchases (or intends to purchase) product P can use SICA (SICA verification) to determine whether the business selling product P is legitimate or illegitimate.
[0051] A specific example of the configuration of the verification system S and verification method M outlined above will be described below with reference to FIG.
[0052] §2 Configuration example FIG. 1 is a diagram illustrating an overall overview of a verification system S according to this embodiment. The verification system S illustrated in FIG. 1 includes a manufacturer B that manufactures a product P, a distributor C that purchases the product P from the manufacturer B, a retailer D that purchases the product P from the distributor C, and a consumer E that purchases the product P from the retailer D. The verification system S illustrated in FIG. 1 also includes a monitoring unit A and a management server F. As will be described in detail later, in the verification system S, the monitoring unit A receives an application for registration of brand information IB and the like (brand registration application) from the manufacturer B, determines whether the registration is permitted, and if it determines that the registration is permitted, executes brand registration. In addition, in the verification system S, the manufacturer B registers detailed information about the product P (such as product information IP) in the ledger Led (Green Chain GC) (product registration). In addition, in the verification system S, the management server F updates the owner business ID 20 registered in the ledger Led (Green Chain GC) based on sales reports and sales approvals from each business (manufacturer B, distributor C, and retailer D).
[0053] In the verification system S (and verification method M), at least the following information is registered (stored) in the ledger Led (Green Chain GC): a public key PuK, brand information IB, an encoding code CPid, product information IP which is detailed information about the product P, a business ID 10 which uniquely identifies each business, business information IC which is detailed information about each business, and an owner business ID 20 which can uniquely identify the business that owns the product P.
[0054] The public key PuK corresponds to the private key PrK used to generate the "encoding code CPid used to verify the identity of the product P." Manufacturer B generates the corresponding private key PrK and public key PuK using an asymmetric key algorithm such as the RSA encryption algorithm. The generated private key PrK is managed by Manufacturer B so that it is not known to third parties. The public key PuK is registered in the ledger Led (Green Chain GC) in association with the brand information IB. As will be described in more detail later, only the monitoring unit A can register the public key PuK in the ledger Led (Green Chain GC), and the monitoring unit A registers the public key PuK in the Green Chain GC in association with the brand information IB.
[0055] The brand information IB is information about a product group (product series) that includes product P, and includes at least one of the "brand name," which is the name of the product group that includes product P, and the name of the manufacturer that produced product P (manufacturer B in this embodiment). The brand information IB may also include the address of the manufacturer that produced product P (e.g., the address of the head office) and the logo mark attached to the product group that includes product P. In other words, the brand information IB is information about the brand of the product group that includes product P. A brand is, for example, a name, word, sign, symbol, design, or a combination of these used for a certain product group (product series) to distinguish that product group from other product groups. The brand information IB is registered in the ledger Led (Green Chain GC) in association with the public key PuK. As will be described in detail later, only the monitoring unit A can register the brand information IB in the ledger Led (Green Chain GC), and the monitoring unit A registers the brand information IB in the Green Chain GC in association with the public key PuK.
[0056] The coding code CPid is a code (identification code) that can uniquely identify each of multiple products P (e.g., product P(1), product P(2), product P(3), ..., product P(X)). In the following description, "X" is an integer equal to or greater than "1." Furthermore, in the following description, when product P(1), product P(2), product P(3), ..., product P(X) are collectively referred to without distinction, they will simply be referred to as "product P." For example, in ledger Led (Green Chain GC), a coding code CPid(1) that can uniquely identify product P(1) is registered. Similarly, in Green Chain GC, a coding code CPid(2) that can uniquely identify product P(2) is registered, and a coding code CPid(X) that can uniquely identify product P(X) is also registered. The coding code CPid is registered in ledger Led (Green Chain GC) in association with product information IP. The coded code CPid, which can uniquely identify the product P, can be generated only by the manufacturer who produced the product P (manufacturer B in this embodiment). Specifically, only the manufacturer who possesses the private key PrK corresponding to the public key PuK registered in the ledger Led (Green Chain GC) can generate the coded code CPid. In this embodiment, manufacturer B generates the coded code CPid using the private key PrK, and registers the generated coded code CPid in the ledger Led (Green Chain GC) in association with the product information IP.
[0057] Product information IP is public information (detailed information) about product P, which is uniquely identified by the coding code CPid. Product information IP includes the name of product P, and in particular, information that uniquely identifies product P within the "product group (product series) that includes product P," i.e., the "product group indicated by brand information IB." For example, product information IP includes an identification number that uniquely identifies product P within the "product group that includes product P." Product information IP may also include, for example, the "brand name," which is the name of the product group that includes product P, the place where product P was manufactured, the date of manufacture of product P, external features, a summary of functions, performance, and uses, major sales regions, the names of major retailers, and the name of the manufacturer. Product information IP is registered in the ledger Led (Green Chain GC) in association with the coding code CPid. The manufacturer that manufactured product P (Manufacturer B in this embodiment) registers product information IP in the ledger Led (Green Chain GC) in association with the coding code CPid. Only the manufacturer that produced the product P can associate the encoding code CPid, which can uniquely identify the product P, with the product information IP, which contains information that can uniquely identify the product P, and register them in the Green Chain GC. In other words, in this embodiment, only manufacturer B can associate the encoding code CPid and the product information IP with each other and register them in the ledger Led (Green Chain GC).
[0058] By searching the Green Chain GC for the encoding code CPid, it is possible to obtain product information IP registered in the Green Chain GC in association with the encoding code CPid. Then, using the obtained product information IP, it is possible to confirm information that can uniquely identify the product P identified by the encoding code CPid. For example, the Green Chain GC registers the encoding code CPid(X) of the product P(X) and product information IP(X) that includes information that can uniquely identify the product P(X), in association with each other. By searching the Green Chain GC using the encoding code CPid(X), it is possible to confirm the product information IP(X).
[0059] The business operator ID 10 is identification information (business operator identification information) that can uniquely identify each business operator (each entity), such as manufacturer B, distributor C, and retailer D. The business operator ID 10 is registered in the ledger Led (Green Chain GC) in association with the business operator information IC. Each business operator registers the business operator ID 10 that uniquely identifies itself in the ledger Led (Green Chain GC) in association with its own business operator information IC.
[0060] The business information IC is public information (detailed information) about each business (each entity), such as manufacturer B, distributor C, or retailer D, uniquely identified by the business ID 10. The business information IC includes at least one of the name of the business uniquely identified by the business ID 10 and information identifying the location of the store (business office) operated by the business. The store operated by the business may be a physical store (a physically existing business office) or a virtual store (virtual business office) such as an e-commerce (electronic market) website. The business office may be, for example, the head office or branch office of the business. "Information identifying the location of the store (business office)" is, for example, information indicating the address of the physical store operated by the business, or information indicating the address of the e-commerce website operated by the business. The business information IC may further include, for example, information indicating the name of the representative of the business uniquely identified by the business ID 10, an overview of the business, the main products handled, etc. The business information IC is registered in the ledger Led (Green Chain GC) in association with the business ID 10. Each business operator associates its own business operator information IC with its business operator ID 10 and registers it in the ledger Led (Green Chain GC).
[0061] By searching for a business ID 10 in the ledger Led (Green Chain GC), it is possible to obtain the business information IC registered in Green Chain GC in association with that business ID 10. The obtained business information IC then allows confirmation of information such as the business's name and store address for the business identified by the business ID 10. For example, Green Chain GC registers a business ID 10(B) for manufacturer B and a business information IC(B) containing information indicating the name of manufacturer B and the address of the store it operates, in association with each other. Searching Green Chain GC using business ID 10(B) allows confirmation of manufacturer B's business information IC(B). Similarly, Green Chain GC registers a business ID 10(C) and a business information IC(C) for distributor C in association with each other, and a business ID 10(D) and a business information IC(D) for retailer D in association with each other.
[0062] The owner business ID 20 is information that can uniquely identify the owner of the product P (the business that owns the product P) during the period when the product P is (was) sold (transferred) between businesses. The owner business ID 20 of the product P is registered in the ledger Led (Green Chain GC) in association with the coding code CPid of the product P.
[0063] For example, during the period from when manufacturer B manufactures product P until when manufacturer B sells (transfers) product P to distributor C, Green Chain GC registers "owner business ID20 = business ID10(B)" in association with product P's coding code CPid. During the period from when manufacturer B sells product P to distributor C until distributor C sells product P to retailer D, Green Chain GC registers "owner business ID20 = business ID10(C)" in association with product P's coding code CPid. After retailer D purchases product P from distributor C, Green Chain GC registers "owner business ID20 = business ID10(D)" in association with product P's coding code CPid. Therefore, when consumer E purchases (or attempts to purchase) product P from retailer D, Green Chain GC registers "owner business ID20 = business ID10(D)" in association with product P's coding code CPid.
[0064] That is, in the Green Chain GC, in association with the coding code CPid of the product P, (1) if the product P has not yet been transferred (sold) between businesses, the business ID 10(B) of the manufacturer B that produced the product P is registered as the owning business ID 20. Also, (2) if the product P has been transferred between businesses, the business ID 10 of the business (purchasing business, buyer) that purchased the product P is registered as the owning business ID 20.
[0065] The owning business operator ID 20 registered in the ledger Led (Green Chain GC) in association with the encoding code CPid is first registered by the manufacturer B that manufactured the product P identified by the encoding code CPid. For example, when manufacturer B manufactures product P, it registers "owning business operator ID 20 = business operator ID 10(B)" in the ledger Led (Green Chain GC) in association with the encoding code CPid of the manufactured product P. Thereafter, when product P is bought and sold (transferred) between businesses, the owning business operator ID 20 registered in the ledger Led (Green Chain GC) is updated by the management server F to the business operator ID of the purchasing business each time a sale is made. The registration of the owning business operator ID 20 in the ledger Led (Green Chain GC) and the update of the owning business operator ID 20 registered in the Green Chain GC will be described in detail below.
[0066] Next, the monitoring unit A, manufacturer B, distributor C, retailer D, management server F, and consumer E included in the verification system S will be described in detail with reference to FIGS.
[0067] (Example of monitoring device configuration) Fig. 2 is a block diagram showing a schematic configuration of a monitoring device 100 that operates as a monitoring unit A. The monitoring device 100 corresponds to the "third computer" of the present invention. The monitoring device 100 shown in Fig. 2 includes, as its hardware configuration, a control unit 101, an operation unit 102, a display unit 103, and a storage unit 104.
[0068] The control unit 101 controls the overall operation of the monitoring device 100 and is composed of a hardware processor such as a central processing unit (CPU) 101a, a read only memory (ROM) 101b, and a random access memory (RAM) 101c. The control unit 101 is configured to execute information processing based on a program (for example, a first program 104p) and the like.
[0069] The operation unit 102 is an input interface and is composed of, for example, switches, buttons, a mouse, a keyboard, a touch panel, etc. for giving various execution instructions to the monitoring device 100. The display unit 103 displays various operation menus, operating status, etc. of the monitoring device 100, and is realized by, for example, a display, instruments, etc.
[0070] The storage unit 104 is an example of a memory, and is configured, for example, by a hard disk drive, a solid state drive, or the like. In this embodiment, the storage unit 104 stores (memorizes) a first program 104p, which is an operating program for the monitoring device 100. The first program 104p is a program for causing the monitoring device 100 to execute a brand registration process. The storage unit 104 may further store operating condition data (not shown), etc.
[0071] The monitoring device 100 may include a communication interface (not shown). The communication interface may be, for example, a wired LAN (Local Area Network) module or a wireless LAN module, and is an interface for performing wired or wireless communication via a network. The monitoring device 100 can use the communication interface to perform data communication with other information processing devices (computers) via a network. The monitoring device 100 may also include an external interface (not shown). The external interface may be, for example, a USB (Universal Serial Bus) port or a dedicated port, and is an interface for connecting to an external device. The type and number of external interfaces may be selected arbitrarily. The first program 104p may be acquired from an external device. In this case, the monitoring device 100 may be connected to the external device via at least one of the communication interface and the external interface.
[0072] Note that, with regard to the specific hardware configuration of the monitoring device 100, components may be omitted, replaced, or added as appropriate depending on the embodiment. For example, the control unit 101 may include multiple hardware processors. The hardware processor may be configured with a microprocessor, a field-programmable gate array (FPGA), a digital signal processor (DSP), or the like. The storage unit 104 may be configured with RAM and ROM included in the control unit 101. At least one of the operation unit 102, the display unit 103, the communication interface, and the external interface may be omitted. The monitoring device 100 may be configured with multiple computers. In this case, the hardware configurations of the computers may or may not be identical. Furthermore, the monitoring device 100 may be an information processing device designed specifically for the services provided, as well as a general-purpose server device, a PC (Personal Computer), or the like.
[0073] The control unit 101 of the monitoring device 100 loads the first program 104p stored in the storage unit 104 into the RAM. Then, the control unit 101 controls each component by interpreting and executing instructions included in the first program 104p loaded into the RAM using the CPU. As a result, as shown in FIG. 2, the monitoring device 100 according to this embodiment operates as a computer including an application acceptance unit 110, an application judgment unit 120, a brand registration unit 130, and an authorization unit 140 as software modules. That is, in this embodiment, each software module of the monitoring device 100 is realized by the control unit 101 (CPU).
[0074] The application receiving unit 110 receives an application for registration of brand information IB, etc. (brand registration application) from the manufacturer B, and notifies the application determination unit 120 of the contents of the received brand registration application. For example, the application receiving unit 110 receives from the manufacturer B the public key PuK, the brand information IB, and attached information that is information used by the monitoring device 100 (particularly the application determination unit 120) to determine whether or not to permit the registration of the brand information IB, etc.
[0075] The application determination unit 120 determines whether or not to permit registration of the brand information IB, etc., based on the content of the brand registration application accepted by the application acceptance unit 110. For example, the application determination unit 120 determines whether the information indicated by the attached information matches generally known information about the manufacturer B and the product P, and if so, determines that registration of the brand information IB, etc., may be permitted. Furthermore, if the information indicated by the attached information does not match generally known information about the manufacturer B and the product P, the application determination unit 120 determines that registration of the brand information IB, etc., cannot be permitted. The application determination unit 120 notifies the brand registration unit 130 of the result of this determination, along with the content of the brand registration application accepted by the application acceptance unit 110.
[0076] The brand registration unit 130 controls the registration of brand information IB, etc. in the ledger Led (Green Chain GC) in accordance with the result of the determination by the application determination unit 120. Specifically, if the application determination unit 120 determines that "registration of brand information IB, etc. may be permitted," the brand registration unit 130 associates the public key PuK related to the brand registration application with the brand information IB and registers them in the Green Chain GC. On the other hand, if the application determination unit 120 determines that "registration of brand information IB, etc. cannot be permitted," the brand registration unit 130 does not register the public key PuK related to the brand registration application and the brand information IB in the Green Chain GC.
[0077] When the brand information IB, etc. is registered in the Green Chain GC by the brand registration unit 130, the monitoring device 100 may notify (transmit) that fact to manufacturer B. In addition, when the brand information IB, etc. is not registered in the Green Chain GC by the brand registration unit 130 (i.e., when the application determination unit 120 determines that "registration of brand information IB, etc. cannot be permitted"), the monitoring device 100 may notify manufacturer B of that fact.
[0078] When the brand registration unit 130 registers the brand information IB, etc. in the Green Chain GC, the authorization unit 140 grants the business operator who applied to register the brand information IB, etc. in the Green Chain GC the authorization to operate as the monitoring device 100. For example, when the public key PuK and brand information IB that Manufacturer B applied to register are registered in the Green Chain GC by the brand registration unit 130, the authorization unit 140 grants Manufacturer B the authorization to operate as the monitoring device 100. Manufacturer B, who has been granted the authorization to operate as the monitoring device 100, can accept brand registration applications from other businesses (other manufacturers) and determine whether to allow the registration of the brand information IB, etc. related to the accepted application. Then, when Manufacturer B, who has been granted the authorization to operate as the monitoring device 100, determines that the registration of the brand information IB, etc. related to the accepted application may be permitted, it registers the public key PuK and brand information IB related to the application in the Green Chain GC.
[0079] (Example of application device configuration) Fig. 3 is a block diagram showing a schematic configuration of an application device 200 operating as manufacturer B. The application device 200 shown in Fig. 3 includes, as hardware components, a control unit 201, an operation unit 202, a display unit 203, and a storage unit 204. Like the monitoring device 100, the application device 200 may further include a communication interface and an external interface (not shown).
[0080] The control unit 201 to the storage unit 204 of the application device 200 may be configured similarly to the control unit 101 to the storage unit 104 of the monitoring device 100 described above. The control unit 201 includes a CPU, RAM, ROM, etc., which are hardware processors, and is configured to execute various information processes based on programs and data. The storage unit 204 is configured, for example, with a hard disk drive, a solid state drive, etc. In this embodiment, the storage unit 204 stores a second program 204p.
[0081] The control unit 201 of the application device 200 loads the second program 204p stored in the storage unit 204 into the RAM. Then, the control unit 201 interprets and executes instructions included in the second program 204p loaded into the RAM using the CPU to control each component. As a result, as shown in FIG. 3 , the application device 200 according to this embodiment operates as a computer including, as software modules, a key generation unit 210, a brand information generation unit 220, an application unit 230, an encoded code generation unit 240, a product information generation unit 250, a business ID generation unit 260, a business information generation unit 270, a registration unit 280, and a reporting unit 290. That is, in this embodiment, each software module of the application device 200 is realized by the control unit 201 (CPU).
[0082] The key generation unit 210 generates a mutually corresponding private key PrK and public key PuK using an asymmetric key algorithm such as the RSA encryption algorithm. The key generation unit 210 notifies the request unit 230 of the generated public key PuK, and also notifies the encoded code generation unit 240 of the generated private key PrK.
[0083] The brand information generation unit 220 generates brand information IB, which is information about a product group (product series) that includes the product P. The brand information generation unit 220 notifies the application unit 230 of the generated brand information IB.
[0084] The application unit 230 transmits the public key PuK generated by the key generation unit 210 and the brand information IB generated by the brand information generation unit 220 in a mutually associated state to the monitoring unit A (monitoring device 100) (brand registration application). When transmitting the public key PuK and the brand information IB to the monitoring unit A, the application unit 230 may also transmit attached information, which is information used by the monitoring unit A to determine whether or not to permit registration of the brand information IB, etc., to the monitoring unit A. In other words, the application unit 230 may transmit the public key PuK, the brand information IB, and the attached information in a mutually associated state to the monitoring unit A.
[0085] The coded code generation unit 240 generates a coded code CPid by encoding a product ID50 (product identification information) that can uniquely identify the product P, using the private key PrK generated by the key generation unit 210. The coded code generation unit 240 notifies the registration unit 280 of the generated coded code CPid.
[0086] The product information generation unit 250 generates product information IP, which is public information (detailed information) about the product P that is uniquely identified by the encoded code CPid and includes information that can identify the product P in a product group that includes the product P. The product information generation unit 250 notifies the registration unit 280 of the generated product information IP.
[0087] The business ID generation unit 260 generates a business ID10(B) that can uniquely identify manufacturer B. The business ID generation unit 260 notifies the registration unit 280 of the generated business ID10(B). The business ID10 only needs to be able to uniquely identify each business, and each business identifies itself by the business ID10. Manufacturer B may use the public key PuK generated by the key generation unit 210 as the business ID10(B). Manufacturer B makes the business ID10(B) generated by the business ID generation unit 260 public at Manufacturer B's store (business establishment).
[0088] The business information generation unit 270 generates business information IC(B), which is public information (detailed information) about manufacturer B and includes at least one of the name of manufacturer B and information specifying the location of a store operated by manufacturer B. The product information generation unit 250 notifies the registration unit 280 of the generated business information IC(B).
[0089] The registration unit 280 registers various types of information in the ledger Led (Green Chain GC). Specifically, the registration unit 280 associates the encoded code CPid generated by the encoded code generation unit 240 with the product information IP generated by the product information generation unit 250, and registers them in the ledger Led (Green Chain GC). The registration unit 280 also associates the business operator ID 10(B) generated by the business operator ID generation unit 260 with the business operator information IC(B) generated by the business operator information generation unit 270, and registers them in the ledger Led (Green Chain GC). Furthermore, when a product P is manufactured by the manufacturer B, the registration unit 280 associates the business operator ID 10(B) with the encoded code CPid that can uniquely identify the product P, and registers the business operator ID 20 that owns the product P in the ledger Led (Green Chain GC). That is, the registration unit 280 associates the coded code CPid with "owning business operator ID20=business operator ID10(B)" and registers them in the green chain GC.
[0090] When product P is sold (transferred) from manufacturer B to distributor C, the reporting unit 290 reports the sale to management server F (sales report). For example, as a sales report relating to the sale of product P from manufacturer B to distributor C, the reporting unit 290 reports the following information to management server F in association with the coded code CPid of product P. That is, the reporting unit 290 reports to management server F "transferor ID30=business ID10(B)" and "purchasing business ID40=business ID10(C)" in association with the coded code CPid of product P. Business ID10(C) is business ID10 that can uniquely identify distributor C.
[0091] (e.g., information generated by manufacturers) 4 is a diagram illustrating various types of information generated by manufacturer B (application device 200) and how the generated information is used by manufacturer B. As shown in Fig. 4, manufacturer B generates an encoding code CPid that uniquely identifies product P manufactured by manufacturer B, a private key PrK used to generate the encoding code CPid, and a public key PuK corresponding to the private key PrK.
[0092] That is, as shown in Fig. 4(A), manufacturer B (key generation unit 210 of application device 200) generates a mutually corresponding private key PrK and public key PuK using an asymmetric key algorithm such as the RSA encryption algorithm. Also, as shown in Fig. 4(B), manufacturer B generates product ID 50 as product identification information that can uniquely identify product P. Product ID 50 includes at least a part of public key PuK and an additional code.
[0093] Manufacturer B (application device 200) can generate an additional code that can uniquely identify product P based on any generation method or generation rule. That is, manufacturer B can generate a product ID 50 that includes at least a portion of public key PuK and the additional code based on any generation method or generation rule. By generating the product ID 50 so that it includes only a portion of public key PuK rather than the entire public key PuK, the amount of information in the product ID 50 can be reduced. For example, if the public key PuK is 256 bits in total, the product ID 50 may be composed of the first 32 bits of the public key PuK and the additional code. However, it is not necessary for the product ID 50 to include only a portion of public key PuK; the product ID 50 may include the entire public key PuK. In other words, the product ID 50 only needs to include an additional code that can uniquely identify product P and at least a portion of public key PuK. Manufacturer B (the encoding code generation unit 240 of the application device 200) generates the encoding code CPid by encoding the product ID 50 generated based on an arbitrary generation method and generation rules using the private key PrK generated by the key generation unit 210.
[0094] Manufacturer B (application device 200) registers the generated coded code CPid in ledger Led (Green Chain GC) ((C) of FIG. 4). For example, the registration unit 280 of the application device 200 associates the coded code CPid generated by the coded code generation unit 240 with product information IP about the product P that is uniquely identified by the coded code CPid, and registers them in the Green Chain GC. Manufacturer B also assigns the generated coded code CPid and public key PuK to the product P, and, for example, writes the coded code CPid and public key PuK on a label of the product P ((D) of FIG. 4).
[0095] (Example of reporting device configuration) Fig. 5 is a block diagram showing a schematic configuration of a reporting device 300 that operates as at least one of distributor C and retailer D. The reporting device 300 shown in Fig. 5 includes, as hardware components, a control unit 301, an operation unit 302, a display unit 303, and a storage unit 304. Similar to the monitoring device 100, the reporting device 300 may further include a communication interface and an external interface (not shown).
[0096] The control unit 301 to the storage unit 304 of the reporting device 300 may be configured similarly to the control unit 101 to the storage unit 104 of the monitoring device 100 described above. The control unit 301 includes a CPU, RAM, ROM, etc., which are hardware processors, and is configured to execute various information processes based on programs and data. The storage unit 304 is configured, for example, with a hard disk drive, a solid state drive, etc. In this embodiment, the storage unit 304 stores a third program 304p.
[0097] The control unit 301 of the reporting device 300 loads the third program 304p stored in the storage unit 304 into the RAM. Then, the control unit 301 uses the CPU to interpret and execute instructions included in the third program 304p loaded into the RAM, thereby controlling each component. As a result, as shown in FIG. 5 , the reporting device 300 according to this embodiment operates as a computer including a business ID generation unit 310, a business information generation unit 320, a registration unit 330, a sales information reception unit 340, and a sales information transmission unit 350 as software modules. That is, in this embodiment, each software module of the reporting device 300 is realized by the control unit 301 (CPU).
[0098] The business ID generation unit 310, business information generation unit 320, and registration unit 330 of the reporting device 300 are similar to the business ID generation unit 260, business information generation unit 270, and registration unit 280 of the application device 200, respectively. That is, the business ID generation unit 310 generates a business ID10(C) (or a business ID10(D)) that can uniquely identify a distributor C (or a retailer D). The business information generation unit 320 generates business information IC(C) (business information IC(D)), which is public information (detailed information) about the distributor C (or a retailer D). The registration unit 330 associates the business ID10(C) and the business information IC(C) with each other and registers them in the ledger Led (Green Chain GC). The registration unit 330 also associates the business ID10(D) and the business information IC(D) with each other and registers them in the ledger Led (Green Chain GC).
[0099] Furthermore, distributor C publishes the "business operator ID10(C) that can uniquely identify distributor C" generated by the business operator ID generation unit 310 in distributor C's store (business establishment). For example, distributor C publishes the business operator ID10(C) on a sign or the like displayed in distributor C's store (business establishment). Similarly, retailer D publishes the "business operator ID10(D) that can uniquely identify retailer D" generated by the business operator ID generation unit 310 in retailer D's store (business establishment). For example, retailer D publishes the business operator ID10(D) on a sign displayed in retailer D's store (business establishment), at a counter where consumer E makes payments, and on an e-commerce site operated by retailer D where consumer E can purchase product P.
[0100] The sales information receiving unit 340 receives an inquiry from the management server F about the sales report received by the management server F (an inquiry to confirm the authenticity of the sales report received by the management server F). For example, the sales information receiving unit 340 of the reporting device 300 operating as distributor C receives an inquiry from the management server F to confirm the authenticity of "sale of product P from manufacturer B to distributor C." Also, the sales information receiving unit 340 of the reporting device 300 operating as retailer D receives an inquiry from the management server F to confirm the authenticity of "sale of product P from distributor C to retailer D."
[0101] The sales information transmitting unit 350 notifies the management server F of a response to an inquiry from the management server F received by the sales information receiving unit 340. For example, if the sales information transmitting unit 350 of the reporting device 300 operating as distributor C finds that a sale of product P from manufacturer B to distributor C actually exists, it transmits a response (sales approval) to the management server F stating that a sale of product P from manufacturer B to distributor C has occurred. If the sales information transmitting unit 350 of the reporting device 300 operating as distributor C finds that a sale of product P from manufacturer B to distributor C does not actually exist, it transmits a response (sales denial) to the management server F stating that no sale of product P from manufacturer B to distributor C has occurred. Similarly, if the sales information transmitting unit 350 of the reporting device 300 operating as retailer D finds that a sale of product P from distributor C to retailer D actually exists, it transmits a response (sales approval) to the management server F stating that a sale of product P from distributor C to retailer D has occurred. In addition, if the sales information transmission unit 350 of the reporting device 300 operating as retailer D does not actually have a "sale of product P from distributor C to retailer D," it sends a response (sale denial) to the management server F stating that "there was no sale of product P from distributor C to retailer D."
[0102] Furthermore, when a product P is sold (transferred) from distributor C to retailer D, the sales information transmission unit 350 of the reporting device 300 operating as distributor C reports the sale to management server F (sales report). For example, as a sales report relating to the sale of product P from distributor C to retailer D, the sales information transmission unit 350 reports the following information to management server F in association with the encoded code CPid of product P. That is, the sales information transmission unit 350 reports to management server F "transferor ID30 = business ID10(C)" and "purchasing business ID40 = business ID10(D)" in association with the encoded code CPid of product P. Business ID10(D) is business ID10 that can uniquely identify distributor C.
[0103] (Example of management server configuration) Fig. 6 is a block diagram showing a schematic configuration of a management server 400 that operates as the management server F. The management server 400 corresponds to the "second computer" of the present invention. The management server 400 shown in Fig. 6 includes, as hardware components, a control unit 401, an operation unit 402, a display unit 403, and a storage unit 404. Like the monitoring device 100, the management server 400 may further include a communication interface and an external interface (not shown).
[0104] The control unit 401 to the storage unit 404 of the management server 400 may be configured similarly to the control unit 101 to the storage unit 104 of the monitoring device 100 described above. The control unit 401 includes a CPU, RAM, ROM, etc., which are hardware processors, and is configured to execute various information processes based on programs and data. The storage unit 404 is configured, for example, with a hard disk drive, a solid state drive, etc. In this embodiment, the storage unit 404 stores a fourth program 404p.
[0105] The control unit 401 of the management server 400 loads the fourth program 404p stored in the storage unit 404 into the RAM. Then, the control unit 401 controls each component by interpreting and executing, using the CPU, instructions included in the fourth program 404p loaded into the RAM. As a result, as shown in Fig. 6, the management server 400 according to this embodiment operates as a computer including a sales report receiving unit 410, an inquiry unit 420, a response receiving unit 430, and an update unit 440 as software modules. That is, in this embodiment, each software module of the management server 400 is realized by the control unit 401 (CPU).
[0106] The sales report receiving unit 410 receives (accepts) a sales report from a business (in this embodiment, manufacturer B or distributor C) that sold product P to another business. For example, the sales report receiving unit 410 receives the following information from manufacturer B (application device 200) as a sales report related to the sale (transfer) of product P from manufacturer B to distributor C, in association with the coded code CPid of product P. That is, the sales report receiving unit 410 receives "transferor ID30=business ID10(B)" and "purchasing business ID40=business ID10(C)." Similarly, the sales report receiving unit 410 receives the following information from distributor C (reporting device 300) as a sales report related to the sale (transfer) of product P from distributor C to retailer D, in association with the coded code CPid corresponding to product P. That is, the sales report receiving unit 410 receives "transferor ID30=business ID10(C)" and "purchasing business ID40=business ID10(D)." The sales report receiving unit 410 notifies the inquiry unit 420 of the contents of the received sales report, that is, the transferring business ID 30 and purchasing business ID 40 included in the sales report, in association with the coded code CPid related to the sales report.
[0107] The inquiry unit 420 inquires of a business uniquely identified by the purchasing business ID 40 included in the sales report whether the sale related to the sales report actually occurred (inquiry about the sales report). For example, when a sales report is received that indicates "transfer business ID 30 = business ID 10(B)" and "purchasing business ID 40 = business ID 10(C)" in association with the coding code CPid of the product P, the inquiry unit 420 executes the following process. That is, the inquiry unit 420 inquires of a distributor C uniquely identified by the business ID 10(C) whether "a sale of product P from manufacturer B to distributor C" occurred (sends an inquiry). For example, when a sales report is received that indicates "transfer business ID 30 = business ID 10(C)" and "purchasing business ID 40 = business ID 10(D)" in association with the coding code CPid of the product P, the inquiry unit 420 executes the following process. That is, the inquiry unit 420 inquires (sends an inquiry) about whether or not there has been a "sale of product P from distributor C to retailer D" to retailer D, which is uniquely identified by business ID 10(D).
[0108] The response receiving unit 430 receives a response to the inquiry from the business to which the inquiry unit 420 sent the inquiry. If the response to the inquiry is "approving the sales report (sales approval)," the response receiving unit 430 notifies the updating unit 440 of the coded code CPid and purchasing business ID 40 included in the sales report. Furthermore, if the response is sales approval, the response receiving unit 430 notifies the business that submitted the sales report that the owning business ID 20, which is associated with the coded code CPid and registered in the ledger Led (Green Chain GC), has been updated in accordance with the sales report. If the response to the inquiry is "denying the sales report (sales denial)," the response receiving unit 430 notifies the business that submitted the sales report that the owning business ID 20 was not updated.
[0109] For example, when distributor C responds (sales approval) that "manufacturer B has sold product P to distributor C," the response receiving unit 430 executes the following two processes. That is, the response receiving unit 430 notifies the updating unit 440 of the coded code CPid included in the sales report and that "purchasing business ID40 = business ID10(C)." The response receiving unit 430 also notifies manufacturer B that the owning business ID20, which is associated with the coded code CPid and registered in the Green Chain GC, has been updated from business ID10(B) to business ID10(C) in accordance with the sales report.
[0110] For example, when retailer D responds (sales approval) that "distributor C has sold product P to retailer D," the response receiving unit 430 executes the following two processes. That is, the response receiving unit 430 notifies the updating unit 440 of the coded code CPid included in the sales report and "purchasing business ID40 = business ID10(D)." The response receiving unit 430 also notifies distributor C that the owning business ID20, which is associated with the coded code CPid and registered in the Green Chain GC, has been updated from business ID10(C) to business ID10(D) in accordance with the sales report.
[0111] When the update unit 440 is notified of the encoded code CPid and the purchasing business ID 40 by the response receiving unit 430, the update unit 440 updates the owning business ID 20, which is associated with the encoded code CPid and registered in the ledger Led (Green Chain GC), with the purchasing business ID 40. For example, when the update unit 440 is notified of the encoded code CPid and "purchasing business ID 40 = business ID 10(C)," the update unit 440 updates the owning business ID 20, which is associated with the encoded code CPid and registered in the Green Chain GC, to business ID 10(C). For example, when the update unit 440 is notified of the encoded code CPid and "purchasing business ID 40 = business ID 10(D)," the update unit 440 updates the owning business ID 20, which is associated with the encoded code CPid and registered in the Green Chain GC, to business ID 10(D).
[0112] (Example of verification device configuration) Fig. 7 is a block diagram showing a schematic configuration of a verification device 500 operating as consumer E. The verification device 500 shown in Fig. 7 includes, as hardware components, a control unit 501, an operation unit 502, a display unit 503, and a storage unit 504. Similar to the monitoring device 100, the verification device 500 may further include a communication interface and an external interface (not shown).
[0113] The control unit 501 to the storage unit 504 of the verification device 500 may be configured similarly to the control unit 101 to the storage unit 104 of the monitoring device 100 described above. The control unit 501 includes a CPU, RAM, ROM, etc., which are hardware processors, and is configured to execute various information processes based on programs and data. The storage unit 504 is configured, for example, with a hard disk drive, a solid state drive, etc. In this embodiment, the storage unit 504 stores a fifth program 504p.
[0114] The control unit 501 of the verification device 500 loads the fifth program 504p stored in the storage unit 504 into the RAM. Then, the control unit 501 interprets and executes instructions included in the fifth program 504p loaded into the RAM using the CPU to control each component. As a result, as shown in FIG. 7 , the verification device 500 according to this embodiment operates as a computer including a reading unit 510, a brand information acquisition unit 520 (first acquisition unit), a product information acquisition unit 530 (second acquisition unit), a decryption unit 540, a key determination unit 550 (determination unit), a business information acquisition unit 560, an owner business identification unit 570, and a distribution determination unit 580 as software modules. That is, in this embodiment, each software module of the verification device 500 is realized by the control unit 501 (CPU).
[0115] The reading unit 510 reads the attachment public key aPuK, which is the public key PuK assigned to the product P purchased by the consumer E, and the attachment encoded code aCPid, which is the encoded code CPid assigned to the product P purchased by the consumer E. For example, if the attachment public key aPuK and the attachment encoded code aCPid are written on the label of the product P by the manufacturer B, the reading unit 510 reads the attachment public key aPuK and the attachment encoded code aCPid written on the label. The reading unit 510 notifies the brand information acquisition unit 520 and the decryption unit 540 of the read attachment public key aPuK. The reading unit 510 also notifies the product information acquisition unit 530 and the decryption unit 540 of the read attachment encoded code aCPid.
[0116] The reading unit 510 further reads the disclosed business operator ID11, which is the business operator ID10 published at the store (business premises) of the business operator selling the product P (in this embodiment, the retailer D from whom the consumer E is purchasing (or intending to purchase) the product P). For example, if the business operator ID10 of the retailer D is published by the retailer D at the counter of the store (business premises) where the consumer E makes payments, the reading unit 510 reads the disclosed business operator ID11 of the retailer D published at the counter. The reading unit 510 notifies the business operator information acquisition unit 560 and the distribution determination unit 580 of the read disclosed business operator ID11.
[0117] The brand information acquisition unit 520 corresponds to the first acquisition unit of the present invention and acquires brand information IB registered in the ledger Led (Green Chain GC) using the attached public key aPuK read by the reading unit 510. That is, the brand information acquisition unit 520 searches the Green Chain GC using the attached public key aPuK to identify a registered public key rPuK, which is a public key PuK registered in the Green Chain GC that matches the attached public key aPuK. Then, the brand information acquisition unit 520 acquires brand information IB registered in the Green Chain GC in association with the identified registered public key rPuK. The brand information acquisition unit 520 can notify the consumer E of the acquired brand information IB, and may, for example, display the acquired brand information IB on the display unit 503. The brand information acquisition unit 520 enables the consumer E to verify the identity of the product P using the brand information IB. Using the brand information IB, consumer E can verify, for example, the authenticity of the brand of the product P to be purchased, that is, whether the product group (brand) including the product P to be purchased is a genuine product group (genuine brand).
[0118] The product information acquisition unit 530 corresponds to the second acquisition unit of the present invention and acquires product information IP registered in the ledger Led (Green Chain GC) using the attached coded code aCPid read by the reading unit 510. That is, the product information acquisition unit 530 searches the Green Chain GC using the attached coded code aCPid to identify the registered coded code rCPid, which is the coded code CPid registered in the Green Chain GC that matches the attached coded code aCPid. The product information acquisition unit 530 then acquires the product information IP registered in the Green Chain GC in association with the identified registered coded code rCPid. The product information acquisition unit 530 can notify the consumer E of the acquired product information IP, for example, by displaying the acquired product information IP on the display unit 503. The product information acquisition unit 530 enables the consumer E to verify the identity of the product P using the product information IP. The consumer E can use the product information IP to verify, for example, the authenticity of the product P to be purchased, i.e., whether the product P to be purchased belongs to a legitimate brand (a legitimate product group).
[0119] The decryption unit 540 obtains decryption information by decrypting the attached public key aPuK read by the reading unit 510 using the attached encoded code aCPid read by the reading unit 510. The decryption unit 540 notifies the key determination unit 550 of the obtained decryption information.
[0120] The key judgment unit 550 corresponds to the judgment unit of the present invention, and judges whether at least a portion of the public key PuK contained in the decryption information acquired by the decryption unit 540 matches at least a portion of the attached public key aPuK read by the reading unit 510.
[0121] Here, if the product P(X) (manufactured product P(X)) manufactured by manufacturer B and the product P(Y) (purchased product P(Y)) purchased by consumer E are the same product P, the attached encoded code aCPid should have been generated by encoding the product ID50 (product identification information) including at least a part of the public key PuK using the private key PrK corresponding to the public key PuK. Furthermore, if the manufactured product P(X) and the purchased product P(Y) are the same product P, the attached public key aPuK should match the public key PuK corresponding to the private key PrK used to generate the attached encoded code aCPid. Therefore, if the manufactured product P(X) and the purchased product P(Y) are the same product P, the attached encoded code aCPid should be able to be decoded using the attached public key aPuK. Furthermore, if the manufactured product P(X) and the purchased product P(Y) are the same product P, the decryption information obtained by decoding the attached encoding code aCPid using the attached public key aPuK should match the product ID(X) of the manufactured product P(X). As mentioned above, the product ID(X) contains "at least a part of the public key PuK." Therefore, if the manufactured product P(X) and the purchased product P(Y) are the same product P, the decryption information should contain "at least a part of the public key PuK" that matches at least a part of the attached public key aPuK.
[0122] Therefore, when the key determination unit 550 confirms that at least a portion of the public key PuK included in the decryption information matches at least a portion of the attached public key aPuK read by the reading unit 510, it determines that the manufactured product P(X) and the purchased product P(Y) are the same product P. Furthermore, when at least a portion of the public key PuK included in the decryption information does not match at least a portion of the attached public key aPuK read by the reading unit 510, the key determination unit 550 determines that the manufactured product P(X) and the purchased product P(Y) are not the same. The key determination unit 550 can notify the consumer E of the above-mentioned determination result regarding the identity of the product P, and may, for example, cause the display unit 503 to display the above-mentioned determination result regarding the identity of the product P.
[0123] The business information acquisition unit 560 acquires business information IC registered in the ledger Led (Green Chain GC) using the public business ID 11 read by the reading unit 510. That is, the business information acquisition unit 560 searches the Green Chain GC using the public business ID 11 to identify a registered business ID 12 registered in the Green Chain GC, which is a business ID 10 that matches the public business ID 11. The business information acquisition unit 560 then acquires the business information IC registered in the Green Chain GC in association with the identified registered business ID 12. The business information acquisition unit 560 may display the acquired business information IC on the display unit 503. The business information acquisition unit 560 enables the consumer E to verify the identity of the product P, etc., using the business information IC. The consumer E can use the business information IC to verify, for example, whether the business (retailer D) selling the product P is a legitimate business.
[0124] The owning business entity identification unit 570 acquires the owning business entity ID20 registered in the ledger Led (Green Chain GC) using the attached coded code aCPid read by the reading unit 510. That is, the owning business entity identification unit 570 searches the Green Chain GC using the attached coded code aCPid to identify the registered coded code rCPid, which is the coded code CPid registered in the Green Chain GC and matches the attached coded code aCPid. The owning business entity identification unit 570 then acquires the owning business entity ID20 registered in the Green Chain GC in association with the identified registered coded code rCPid. The owning business entity identification unit 570 notifies the distribution determination unit 580 of the acquired owning business entity ID20.
[0125] The distribution determination unit 580 determines whether the owner business ID 20 acquired by the owner business identification unit 570 matches the disclosing business ID 11 read by the reading unit 510. If it is confirmed that the owner business ID 20 matches the disclosing business ID 11, the distribution determination unit 580 determines that the product P is being sold by retailer D through a legitimate distribution route. If it is confirmed that the owner business ID 20 does not match the disclosing business ID 11, the distribution determination unit 580 determines that the product P is being sold by retailer D through an unauthorized distribution route. The distribution determination unit 580 can notify the consumer E of the determination result as to whether the distribution route of the product P is legitimate or unauthorized, and may, for example, display the determination result as to whether the distribution route of the product P is legitimate or unauthorized on the display unit 503.
[0126] The operation (processing) of each of the monitoring device 100 (monitoring unit A), application device 200 (manufacturer B), reporting device 300 (distributor C, retailer D), management server 400 (management server F), and verification device 500 (consumer E), whose configurations have been described above, will now be described. In this embodiment, an example is described in which the software modules of the monitoring device 100, application device 200, reporting device 300, management server 400, and verification device 500 are all implemented by a general-purpose CPU. However, some or all of the above software modules may be implemented by one or more dedicated processors (e.g., graphics processing units). Each of the above modules may also be implemented as a hardware module. Furthermore, with regard to the software configurations of the monitoring device 100, application device 200, reporting device 300, management server 400, and verification device 500, software modules may be omitted, replaced, or added as appropriate depending on the embodiment.
[0127] §3 Example of operation (Public key and brand information registration in the ledger) FIG. 8 is a diagram outlining the registration method for the public key PuK and brand information IB to be registered in the ledger Led (Green Chain GC) in this embodiment. As described above, in the verification system S (and verification method M), only the monitoring unit A can register the public key PuK and brand information IB in the ledger Led (Green Chain GC). Therefore, as shown in FIG. 8, when manufacturer B generates the public key PuK and brand information IB, it applies to the monitoring unit A for registration of the generated public key PuK and brand information IB in the ledger Led (Green Chain GC) (brand registration application). Upon receiving the brand registration application, the monitoring unit A determines whether the application is acceptable, and if it confirms that there are no problems with the application, it registers the public key PuK and brand information IB related to the request in the ledger Led (Green Chain GC) (brand registration).
[0128] FIG. 9 is a flow diagram illustrating the process from brand registration application to brand registration in the verification system S (and verification method M). As illustrated in FIG. 9, manufacturer B (key generation unit 210 of application device 200) generates a mutually corresponding private key PrK and public key PuK using an asymmetric key algorithm such as the RSA encryption algorithm (S110). Manufacturer B manages the generated private key PrK so that it is not known to third parties other than manufacturer B. Manufacturer B (application device 200) also generates brand information IB and attached information; for example, the brand information generation unit 220 of the application device 200 generates the brand information IB.
[0129] In the verification system S (and the verification method M), only the monitoring unit A can register the public key PuK and brand information IB in the ledger Led (Green Chain GC). Therefore, the manufacturer B (application device 200) provides the public key PuK and brand information IB to the monitoring unit A and applies to the monitoring unit A for registration of the public key PuK and brand information IB in the Green Chain GC (S120, brand registration application). The manufacturer B (application device 200) also provides the monitoring unit A with attached information as materials (evidence) for the monitoring unit A to determine whether to approve the brand registration application.
[0130] The monitoring unit A (the application receiving unit 110 of the monitoring device 100) receives an application for brand registration from Manufacturer B (S210, application receiving step). Then, the monitoring unit A (the application determining unit 120 of the monitoring device 100) determines whether the content of the application is acceptable, that is, determines whether the public key PuK and the brand information IB may be registered in the ledger Led (Green Chain GC) (S220, registration determining step). As an example, the monitoring unit A determines whether the content of the attached information provided by Manufacturer B matches the publicly available content for at least one of Manufacturer B and a product group (product series) including Product P. For example, the monitoring unit A may check whether the content of the attached information provided by Manufacturer B matches the content registered for Manufacturer B in a commercial register or the like. Alternatively, the monitoring unit A may check whether the content of the attached information provided by Manufacturer B matches the content of the trademark registration for the product group including Product P. The monitoring unit A (application determination unit 120 of the monitoring device 100) may determine whether to allow or deny registration based on at least one of the following: whether the manufacturer who submitted the brand registration application is the "true manufacturer of product P" and whether the brand information IB related to the brand registration application is true or false.
[0131] If it is determined that the public key PuK and the brand information IB cannot be registered in the ledger Led (Green Chain GC) (i.e., registration cannot be permitted) (No in S220), the monitoring unit A (monitoring device 100) executes the following process: The monitoring unit A notifies the business operator that applied for brand registration, i.e., manufacturer B, of the determination result, i.e., the denial of registration (S230).
[0132] If it is determined that the registration may be permitted (Yes in S220), the monitoring unit A (brand registration unit 130 of the monitoring device 100) registers the contents of the permitted application in the ledger Led (Green Chain GC). Specifically, the monitoring unit A associates the public key PuK and brand information IB related to the brand registration application received in S210 with each other and registers them in the Green Chain GC (S240, brand registration step). As a result, the public key PuK and brand information IB related to the brand registration application are registered in the ledger Led (Green Chain GC) with each other associated with each other.
[0133] Furthermore, monitoring unit A (monitoring device 100) notifies manufacturer B, who has applied for brand registration, that the public key PuK and brand information IB related to the brand registration application have been associated with each other and registered in ledger Led (Green Chain GC) (S250). Furthermore, monitoring unit A (authorization granting unit 140 of monitoring device 100) grants the authority of monitoring unit A to manufacturer B, who has applied for brand registration (S260).
[0134] Manufacturer B (application device 200) receives (receives) (S310) the notification made by monitoring unit A in S230 or the notification made by monitoring unit A in S250. Specifically, Manufacturer B receives from monitoring unit A (monitoring device 100) a notification that the brand registration application has been denied, or a notification informing Manufacturer B that the public key PuK and brand information IB related to the brand registration application have been registered in the ledger Led (Green Chain GC).
[0135] As described above, in the verification system S (verification method M), the application device 200 (third computer) accepts a brand registration application (registration application) and determines whether the brand registration application should be approved, i.e., whether the brand information IB, etc. related to the brand registration application should be approved for registration. If the application device 200 determines that the brand information IB, etc. can be registered, it registers the public key PuK and the brand information IB related to the brand registration application in the ledger Led (Green Chain GC) in association with each other. In other words, only combinations of the public key PuK and the brand information IB that the application device 200 has determined can be registered are registered in the ledger Led (Green Chain GC).
[0136] Since only the monitoring unit A can register the public key PuK and brand information IB in the ledger Led (Green Chain GC), it is expected that a large number of manufacturers will apply for brand registration in the verification system S (and verification method M). In order to process such a large number of brand registration applications efficiently and accurately, the verification system S includes multiple monitoring units A, for example, multiple monitoring units A having a hierarchical structure.
[0137] (Hierarchical structure of monitoring units) FIG. 10 is a diagram illustrating the multiple monitoring units A with a hierarchical structure provided in the verification system S. In the verification system S, the hierarchical structure of the monitoring units A is realized, for example, as follows. First, in the initial state (at the time of creation) of the ledger Led (Green Chain GC), there is only one monitoring unit A, specifically, the top-level (Root) monitoring unit, monitoring unit A(0). When monitoring unit A(0) receives a brand registration application (an application to register a public key PuK and brand information IB in the ledger Led (Green Chain GC)) from a manufacturer who is not authorized by monitoring unit A, it executes the following process. That is, monitoring unit A(0) determines whether to permit the registration of the public key PuK and brand information IB related to the brand registration application. If it determines that the registration is permitted, monitoring unit A(0) registers the public key PuK and brand information IB related to the brand registration application in the ledger Led (Green Chain GC). Furthermore, monitoring unit A(0) grants authority as monitoring unit A to the business that has applied for the above-mentioned brand registration, and that business becomes monitoring unit A(1) that belongs to the hierarchical level one level below that to which monitoring unit A(0) belongs, that is, the first-level monitoring unit A(1). Figure 10 shows an example in which n manufacturers are thus granted authority as monitoring units A by monitoring unit A(0), and each becomes monitoring units A(1-1), A(1-2), ..., A(1-n) (where "n" is an integer equal to or greater than "1"). In the following description, when monitoring units A(1-1), A(1-2), ..., A(1-n) are referred to collectively without distinction, they will be simply referred to as "monitoring unit A(1)."
[0138] Next, when a brand registration application is submitted by a manufacturer that has not been authorized by the monitoring unit A, the monitoring unit A(1) in the first tier determines whether to permit the registration of the public key PuK and brand information IB associated with the brand registration application. If it determines that the registration is permitted, the monitoring unit A(1) registers the public key PuK and brand information IB associated with the brand registration application in the ledger Led (Green Chain GC). The monitoring unit A(1) also grants the manufacturer that submitted the brand registration application the authority to act as a monitoring unit A, and designates the manufacturer as a monitoring unit A(2) belonging to the tier one below the tier to which the monitoring unit A(1) belongs, i.e., as a monitoring unit A(2) in the second tier. Figure 10 shows an example in which three manufacturers are authorized by the monitoring unit A(1-2) as monitoring units A, respectively, and become monitoring units A(2-1), A(2-2), and A(2-3).
[0139] As described above, the verification system S has multiple monitoring units A with a hierarchical structure, with monitoring unit A(0) as the top-level monitoring unit, followed by first-level monitoring unit A(1), second-level monitoring unit A(2), ..., nth-level monitoring unit A(n).
[0140] A monitoring unit A at a higher level may be able to revoke the authority as monitoring unit A that has been granted to a monitoring unit A that belongs to a level lower than the level to which it belongs. For example, a monitoring unit A(m) (where "m" is an integer greater than or equal to "0") that belongs to the mth level may be able to revoke the authority as monitoring unit A that has been granted to a monitoring unit A(m+n) that belongs to the m+nth level, which is the level after the m+1th level.
[0141] As explained above, the monitoring unit A will only approve brand registration applications from manufacturer B that it has determined to be "the true manufacturer of product P," and will reject brand registration applications from manufacturer I that it has determined to be "not the true manufacturer of product P." Therefore, the monitoring unit A can prevent situations in which manufacturer I registers fraudulent information in ledger Led (Green Chain GC) and falsely represents itself as the "true manufacturer" of product P. In other words, the monitoring unit A can exclude manufacturer I, a false manufacturer, from Green Chain GC, thereby protecting manufacturer B, who produces product P, and consumer E from manufacturer I.
[0142] <MICA(Massive Illegal Copy Avoidance)> FIG. 11 is a diagram illustrating an overall overview of MICA adopted by the verification system S (and verification method M). As mentioned above, manufacturer B generates a private key PrK and a public key PuK in advance, and provides the generated public key PuK together with brand information IB to monitoring unit A (brand registration application). For example, when monitoring unit A determines that manufacturer B is the "true manufacturer of product P," it associates the public key PuK and brand information IB provided by manufacturer B with each other and registers them in ledger Led (Green Chain GC).
[0143] In MICA, when manufacturer B manufactures product P, it generates an encoded code CPid by encoding a product ID 50 that can uniquely identify product P with a private key PrK corresponding to a public key PuK registered in ledger Led (Green Chain GC). Manufacturer B can generate an encoded code CPid that includes at least a part of the public key PuK and an additional code using any generation method or rule, in other words, according to any generation method or rule. Manufacturer B associates the generated encoded code CPid with product information IP, which is public information (detailed information) about product P, and registers them in ledger Led (Green Chain GC). Manufacturer B also assigns the public key PuK and the encoded code CPid to product P, puts product P on a distribution route, and sells product P to distributor C, for example.
[0144] Consumer E uses the attached public key aPuK, which is the public key PuK assigned to the product P to be purchased, to acquire brand information IB registered in the ledger Led (Green Chain GC), and verifies the identity, etc., of the product P to be purchased using the acquired brand information IB (verification using brand information). Consumer E uses the attached encoding code aCPid, which is the encoding code CPid assigned to the product P to be purchased, to acquire product information IP registered in the ledger Led (Green Chain GC), and verifies the identity, etc., of the product P to be purchased using the acquired product information IP (verification using product information). Consumer E decodes the attached encoding code aCPid using the attached public key aPuK to acquire decrypted information, and determines whether at least a portion of the public key PuK included in the acquired decrypted information matches at least a portion of the attached public key aPuK. If the two match, consumer E determines that the product P he is purchasing is genuine (identical to the product P manufactured by manufacturer B); if the two do not match, consumer E determines that the product P he is purchasing is a counterfeit (verification by comparing the public keys).
[0145] Fig. 12 is a flow diagram outlining the product registration process and the like executed by manufacturer B (application device 200) in MICA. As shown in Fig. 12, manufacturer B (application device 200) first generates a product ID 50 (S310) as product identification information that includes at least a portion of the public key PuK and can uniquely identify each of multiple products P manufactured by manufacturer B. As illustrated in Fig. 4(B), the product ID 50 includes, for example, at least a portion of the public key PuK and an additional code, and uniquely identifies product P.
[0146] Manufacturer B (the coded code generation unit 240 of the application device 200) generates a coded code CPid by encoding the product ID 50 using the private key PrK corresponding to the public key PuK (S320). Then, Manufacturer B (the registration unit 280 of the application device 200) registers the generated coded code CPid as public information (detailed information) of the product P together with the product information IP in the ledger Led (Green Chain GC) (S330, product registration).
[0147] Furthermore, the manufacturer B assigns the generated coding code CPid together with the public key PuK to the product P manufactured by the manufacturer B (S340). When the manufacturer B transfers (sells) the product P manufactured by itself to another business (for example, distributor C), the manufacturer B assigns the coding code CPid and the public key PuK to the product P to be transferred before the transfer.
[0148] Fig. 13 is a flow diagram outlining various verification processes performed by consumer E (verification device 500) in MICA. As shown in Fig. 13, consumer E (verification device 500) in MICA performs "verification using brand information IB (Fig. 13(A))," "verification using product information IP (Fig. 13(B))," and "verification by comparison of public key PuK (Fig. 13(C))."
[0149] (First verification: verification based on brand information) As shown in FIG. 13A, the consumer E (the brand information acquisition unit 520 of the verification device 500) or the like searches the ledger Led (Green Chain GC) using the attached public key aPuK, which is the public key PuK assigned to the product P to be purchased (S1110). Then, the consumer E (the brand information acquisition unit 520 of the verification device 500) or the like identifies a registered public key rPuK, which is a public key PuK registered in the ledger Led (Green Chain GC) that matches the attached public key aPuK (S1120). The consumer E (the brand information acquisition unit 520 of the verification device 500) or the like acquires brand information IB, which is associated with the identified registered public key rPuK and registered in the ledger Led (Green Chain GC) (S1130). The consumer E (the verification device 500) or the like performs verification using the acquired brand information IB (S1140). For example, consumer E verifies the authenticity of brand information IB by comparing brand information IB acquired by verification device 500 (particularly brand information acquisition unit 520) with commonly known information about the brand of product P. If brand information IB is true (e.g., commonly known information about the brand of product P matches brand information IB), consumer E determines that the brand of product P to be purchased is a genuine brand and that product P to be purchased is a genuine product. In other words, if commonly known information about the brand of product P matches brand information IB, consumer E determines that product P(Y) to be purchased is the same product P as product P(X) manufactured by manufacturer B. If brand information IB is false (e.g., commonly known information about the brand of product P does not match brand information IB), consumer E determines that the brand of product P to be purchased is not a genuine brand and that product P to be purchased is a counterfeit product. In other words, if the generally known information about the brand of product P does not match the brand information IB, consumer E will determine that the product P(Y) he or she is purchasing is not identical to product P(X) manufactured by manufacturer B.
[0150] (Second verification: verification based on product information) As shown in FIG. 13B, the consumer E (the product information acquisition unit 530 of the verification device 500) or the like searches the ledger Led (Green Chain GC) using the attached coded code aCPid, which is the coded code CPid assigned to the product P to be purchased (S1210). The consumer E (the product information acquisition unit 530 of the verification device 500) or the like identifies the registered coded code rCPid, which is the coded code CPid registered in the ledger Led (Green Chain GC) and matches the attached coded code aCPid (S1220). The consumer E (the product information acquisition unit 530 of the verification device 500) or the like acquires product information IP registered in the ledger Led (Green Chain GC) in association with the identified registered coded code rCPid (S1230). The consumer E (the verification device 500) or the like performs verification using the acquired product information IP (S1240). For example, consumer E verifies the authenticity of product information IP by comparing the product information IP acquired by verification device 500 (particularly, product information acquisition unit 530) with commonly known information about product P (e.g., information written on the package of product P). If the product information IP is true (e.g., the commonly known information about product P matches the product information IP), consumer E determines that the product P to be purchased is genuine (it belongs to the authorized brand (authorized product group)). In other words, if the commonly known information about product P matches the product information IP, consumer E determines that the product P(Y) to be purchased is the same product P as product P(X) manufactured by manufacturer B. If the product information IP is false (e.g., the commonly known information about product P does not match the product information IP), consumer E determines that the product P to be purchased is a counterfeit (it does not belong to the authorized brand (authorized product group)). In other words, if the information generally available about product P does not match the product information IP, consumer E determines that the product P(Y) he or she is purchasing is not identical to product P(X) manufactured by manufacturer B.
[0151] (Third verification: Verification by public key comparison) 13C, the consumer E (the decryption unit 540 of the verification device 500) or the like decodes the attached encoded code aCPid attached to the product P to be purchased using the attached public key aPuK attached to the product P to be purchased to obtain decrypted information (S1310). The consumer E (the key determination unit 550 of the verification device 500) or the like determines whether at least a part of the public key PuK included in the decrypted information obtained in S1310 matches at least a part of the attached public key aPuK attached to the product P to be purchased (S1320). If the consumer E (the key determination unit 550 of the verification device 500) or the like confirms that the two match (Yes in S1320), the consumer E (the key determination unit 550 of the verification device 500) or the like determines that the product P to be purchased is authentic (the product P to be purchased is the product P manufactured by manufacturer B) (S1330). If it is confirmed that the two do not match (No in S1320), consumer E (key judgment unit 550 of verification device 500) or the like determines that the product P to be purchased is a counterfeit (the product P to be purchased is not the product P manufactured by manufacturer B) (S1340).
[0152] In the following description, the above-mentioned three verifications (verification using brand information IB, verification using product information IP, and verification by comparison of public key PuK) performed by consumer E (verification device 500) or the like in MICA may be collectively referred to as "MICA verification."
[0153] As mentioned above, brand information IB is information about a product group (product series) that includes product P, and includes at least one of the "brand name," which is the name of the product group that includes product P, and the name of manufacturer B that produced product P. Therefore, in verification using brand information IB (brand verification), consumer E and others can verify the authenticity of product P at the brand (product group) level. Furthermore, product information IP is information about product P alone (individual product P), and includes the name of product P, and in particular, information that uniquely identifies product P within the product group (product series) indicated by brand information IB. Therefore, in verification using product information IP (individual product verification), consumer E and others can verify the authenticity of product P at the level of each individual product included in the brand (product group).
[0154] In MICA, manufacturer B generates the encoded code CPid by encoding the product ID50, which has been generated using a given generation method and generation rules, with a private key PrK. Therefore, even if an entity other than manufacturer B, which holds the private key PrK, analyzes the encoded code CPid, they cannot identify the generation rules for the encoded code CPid (i.e., the private key PrK), the product ID50, or the generation method and generation rules for the product ID50. In other words, no entity other than manufacturer B, which holds the private key PrK, can know the generation rules for the encoded code CPid (i.e., the private key PrK). Therefore, MICA can prevent a situation in which an entity other than manufacturer B, which holds the private key PrK, identifies the generation rules for the encoded code CPid and generates a large number of illegal encoded codes CPid that cannot be distinguished from genuine encoded codes CPid.
[0155] In contrast, manufacturer B, who holds the private key PrK, can generate a large number of product IDs 50, each capable of uniquely identifying one of multiple products P, using any generation method and generation rules, and can easily generate a large number of encoding codes CPid from these large number of product IDs 50 using the private key PrK.
[0156] In other words, MICA can prevent a situation in which the rules for generating the encoding code CPid are discovered by a third party and large quantities of the encoding code CPid are counterfeited, while reducing the burden on manufacturer B in generating the encoding code CPid, etc.
[0157] <SICA(Single Illegal Copy Avoidance)> FIG. 14 is a diagram illustrating an overall overview of SICA employed by the verification system S (and verification method M). As described above, in the verification system S (and verification method M), each business operator registers a business operator ID 10 that uniquely identifies itself and a business operator information IC that includes its name in the ledger Led (Green Chain GC), associating them with each other. Furthermore, each business operator publishes the business operator ID 10 that uniquely identifies itself at the store (business establishment) that it operates. For example, retailer D (registration unit 330 of reporting device 300) registers a business operator ID 10(D) that uniquely identifies itself and a business operator information IC(D) that includes its name in the ledger Led (Green Chain GC), associating them with each other. Furthermore, retailer D publishes the business operator ID 10(D) at retailer D's store.
[0158] Furthermore, manufacturer B associates owner business ID20 (specifically, "owner business ID20 = business ID10(B)") with the encoding code CPid and registers it in ledger Led (Green Chain GC). From the time manufacturer B manufactures product P until the time manufacturer B sells product P to distributor C, manufacturer B registers "owner business ID20 = business ID10(B)" in ledger Led (Green Chain GC) in association with the encoding code CPid.
[0159] In SICA, when a product P is transferred between businesses, the owning business ID 20, which is "information indicating the business that owns the product P in the ledger Led (Green Chain GC)," is updated by the management server F. Specifically, the management server F updates the owning business ID 20, which is associated with the coding code CPid of the product P and registered in the Green Chain GC, based on a report (sales report) from the seller of the product P and a response (sales approval) from the buyer of the product P.
[0160] Consumer E uses business ID 10 published at retailer D's store to obtain business information IC registered in ledger Led (Green Chain GC), and verifies whether retailer D is a legitimate business using the obtained business information IC (business information verification). Furthermore, as described above, Consumer E performs MICA verification using attached coding code aCPid, which is the coding code CPid assigned to the product P to be purchased, and attached public key aPuK, which is the public key PuK assigned to the product P to be purchased. That is, Consumer E uses attached coding code aCPid and attached public key aPuK to perform verification using brand information IB, product information IP, and by comparing the public key PuK. Furthermore, Consumer E uses attached coding code aCPid to obtain owner business ID 20 (registered owner business ID 21) registered in ledger Led (Green Chain GC). Consumer E determines whether the acquired registered owner business ID 21 matches the business ID 10 published at the store of retailer D that sells product P (store comparison in SICA). If the two match, Consumer E determines that product P to be purchased is distributed through a legitimate distribution channel, and if the two do not match, Consumer E determines that product P to be purchased is distributed through an unauthorized distribution channel.
[0161] 15 is a flow diagram outlining the owner business operator ID update process and the like executed by management server F (management server 400) in SICA. As described above, when manufacturer B manufactures product P, before transferring product P to distributor C, it registers "owner business operator ID20=business operator ID10(B)" in ledger Led (Green Chain GC) in association with the coding code CPid of product P. Therefore, before manufacturer B sells (transfers) product P to distributor C, "owner business operator ID20=business operator ID10(B)" is registered in ledger Led (Green Chain GC) in association with the coding code CPid of product P.
[0162] When manufacturer B sells product P to distributor C, it reports the following three pieces of information identifying the sale to management server F (sales report). That is, in the sales report, manufacturer B (reporting unit 290 of application device 200) reports to management server F the coded code CPid of product P sold to distributor C, transferor business ID30 that uniquely identifies the business that sold product P, and purchasing business ID40 that uniquely identifies the business that bought product P. Specifically, manufacturer B (reporting unit 290 of application device 200) reports to management server F "transferor business ID30 = business ID10(B)" and "purchasing business ID40 = business ID10(C)" in association with the coded code CPid as information identifying the sale of product P (S410).
[0163] The management server F (sales report receiving unit 410 of the management server 400) receives a sales report about the product P from the manufacturer B (S510, sales report receiving step). Then, the management server F (management server 400) determines whether or not it is okay to update the owner business ID 20, which is associated with the coded code CPid and registered in the ledger Led (Green Chain GC), in accordance with the received sales report.
[0164] For example, management server F (management server 400) first determines whether the owner business ID 20 associated with the coding code CPid and registered in Green Chain GC matches the transfer business ID 30 in the received sales report. As described above, before manufacturer B sold product P to distributor C, "owner business ID 20 = business ID 10(B)" was registered in Green Chain GC in association with coding code CPid. Furthermore, in the sales report, "transfer business ID 30 = business ID 10(B)" is associated with coding code CPid. Therefore, management server F confirms that the owner business ID 20 associated with coding code CPid and registered in Green Chain GC matches the transfer business ID 30 associated with coding code CPid in the sales report. If management server F confirms that the two match, it determines that the received sales report is a sales report from a business that legally owned product P corresponding to coding code CPid. If the two do not match, management server F determines that the received sales report is not from the business that legally owned product P corresponding to the encoding code CPid. Management server F then notifies the business that submitted the received sales report (manufacturer B) of the determination result and stops (ends) the owner business ID update process.
[0165] When the management server F determines that the received sales report is from a business that legitimately owned the product P corresponding to the coded code CPid, the management server F inquires about the authenticity of the received sales report from the business that purchased the product P (S520, inquiry step). That is, the management server F (inquiry unit 420 of the management server 400) inquires about whether the business identified by the purchasing business ID 40 in the sales report purchased the product P corresponding to the coded code CPid in the sales report. As described above, in the sales report, the coded code CPid is associated with "purchasing business ID 40 = business ID 10(C)." Therefore, the management server F inquires about whether the distributor C identified by the business ID 10(C) purchased the product P corresponding to the coded code CPid from the manufacturer B identified by the "transfer business ID 30 = business ID 10(B)."
[0166] Distributor C (sales information receiving unit 340 of reporting device 300) receives the above-mentioned inquiry from management server F (S610). Then, distributor C (sales information transmitting unit 350 of reporting device 300) reports (transmits) a response to the above-mentioned inquiry to management server F (S620). Specifically, if distributor C purchases product P from manufacturer B, distributor C (sales information receiving unit 340 of reporting device 300) transmits a response from manufacturer B of product P to management server F acknowledging distributor C's sale of product P (sales approval). On the other hand, if distributor C has not purchased product P from manufacturer B, distributor C (sales information receiving unit 340 of reporting device 300) transmits a response from manufacturer B of product P to management server F denying distributor C's sale of product P (sales denial).
[0167] Management server F (response receiving unit 430 of management server 400) receives the response from distributor C (S530). Then, management server F (response receiving unit 430 of management server 400) determines whether the response from distributor C approves the sale (sales approval) or denies the sale (sales denial) (S540).
[0168] If distributor C denies the sale (No in S540), management server F (update unit 440 of management server 400) does not update the owning business entity ID 20 that is associated with the encoded code CPid and registered in ledger Led (Green Chain GC). Then, management server F (management server 400) notifies manufacturer B, which has submitted a sales report to management server F, that it has received a sales denial response and / or that it has not updated the owning business entity ID 20. In other words, management server F (management server 400) notifies manufacturer B that it is not permitted to update the owning business entity ID 20 (S550).
[0169] If distributor C's response is approval for the sale (Yes in S540), management server F (update unit 440 of management server 400) updates the owner business ID 20 registered in ledger Led (Green Chain GC) in association with the coded code CPid (owner business ID update). Specifically, management server F (update unit 440 of management server 400) updates the owner business ID 20 on the Green Chain GC, that is, the owner business ID 20 registered in Green Chain GC in association with the coded code CPid, with the purchasing business ID 40 (= business ID 10(C)) related to the sales report (S560, owner update step). As a result, the owner business ID 20 registered in Green Chain GC in association with the coded code CPid is updated from "business ID 10(B)" to "business ID 10(C)."
[0170] Furthermore, management server F (management server 400) notifies manufacturer B, which has submitted a sales report to management server F, of at least one of the following: that owning business entity ID 20 has been updated from "business entity ID 10(B)" to "business entity ID 10(C)" (S570). In addition to or instead of updating owning business entity ID 20, management server F (management server 400) may notify manufacturer B that it has received a sales approval response.
[0171] Manufacturer B (application device 200), which has submitted a sales report to management server F, receives the notification of S550 or S570 from management server F (S420).
[0172] When distributor C sells product P to retailer D, the owning business ID 20 associated with the coded code CPid and registered in Green Chain GC is updated from "business ID 10(C)" to "business ID 10(D)" by the same process as described above. That is, distributor C reports to management server F the coded code CPid, "transfer business ID 30 = business ID 10(C)," and "purchasing business ID 40 = business ID 10(D)" as information identifying the sale of product P (sales report). Upon receiving the sales report from distributor C, management server F inquires of retailer D about the authenticity of the sales report. Upon receiving sales approval from retailer D in response to this inquiry, management server F updates the owning business ID 20 associated with the coded code CPid and registered in Green Chain GC with the purchasing business ID 40 (= business ID 10(D)) related to the sales report.
[0173] In this way, when a product P is sold (transferred) between businesses, the management server F (management server 400) updates the owning business ID 20, which is associated with the coding code CPid of the product P and registered in the Green Chain GC, to the business ID 10 of the business that purchased the product P. Therefore, in SICA, by searching the ledger Led (Green Chain GC) using the coding code CPid, it is possible to identify the business that owns the product P at that time.
[0174] As described above, in the verification system S (verification method M), the management server 400 (second computer) executes the following processing based on a report (sales report) from a business operator uniquely identified by the owning business operator ID 20 registered in the ledger Led in association with the coding code CPid of the product P. That is, the management server 400 confirms the authenticity of the transfer (sale) of the product P with the business operator (purchasing business operator) uniquely identified by the purchasing business operator ID 40 in the sales report. Then, upon confirming the transfer of the product P based on the response from the purchasing business operator, the management server 400 updates the business operator ID 10 registered as the owning business operator ID 20 to the purchasing business operator ID 40 in the sales report, that is, to the business operator ID 10 that can uniquely identify the purchasing business operator. Therefore, the verification system S (verification method M) can ensure the authenticity of the business operator registered in the ledger Led as the owner of the product P in association with the coding code CPid of the product P.
[0175] 16 is a diagram illustrating the ledger Led (Green Chain GC) in which the management server F (management server 400) updates the owner business ID 20 for each sale of product P between businesses. As shown in FIG. 16, in the ledger Led (Green Chain GC), the encoded code CPid(X) of product P(X) is associated with the product information IP(X) of product P(X) (blocks (n), (n+1), (n+2)).
[0176] Before manufacturer B sells product P(X) to distributor C, "owner business ID20 = business ID10(B)" is associated with the coded code CPid(X) of product P(X) (block (n)). Also, in block (n), business ID10(B), which uniquely identifies manufacturer B, is associated with coded code CPid(X) as the origin ID of product P(X) (business ID10 that can uniquely identify the business that manufactured product P(X)). Furthermore, in block (n), business ID10(B) is associated with coded code CPid(X) as the tracking ID of product P(X) (information indicating the transition of the business that owns product P(X) using business ID10).
[0177] During the period from when manufacturer B sells product P(X) to distributor C until distributor C sells product P(X) to retailer D, "owner business ID20 = business ID10(C)" is associated with the coded code CPid(X) of product P(X) (block (n+1)). Also, in block (n+1), business ID10(B) is associated with coded code CPid(X) as the origin ID of product P(X). Furthermore, in block (n+1), "business ID10(B) to business ID10(C)" is associated with coded code CPid(X) as the tracking ID of product P(X).
[0178] After distributor C sells product P(X) to retailer D, "owner business ID20 = business ID10(D)" is associated with the coded code CPid(X) of product P(X) (block (n+2)). Also, in block (n+2), business ID10(B) is associated with coded code CPid(X) as the origin ID of product P(X). Furthermore, in block (n+2), "from business ID10(B), via business ID10(C), to business ID10(D)" is associated with coded code CPid(X) as the tracking ID of product P(X).
[0179] 17 is a flow diagram outlining various verification processes performed by consumer E (verification device 500) in SICA. As shown in FIG. 17, in SICA, consumer E (verification device 500) performs "verification using business information IC ((A) in FIG. 17)" and "(store comparison in SICA) ((B) in FIG. 17)" in addition to MICA verification.
[0180] (First verification: verification using business information IC (store search)) As described above, each business (manufacturer B, distributor C, retailer D, etc.) registers its own business ID 10 in ledger Led (Green Chain GC) and also makes it public at the store (business establishment) that it operates. For example, retailer D makes its business ID 10(D) public by writing it on a signboard displayed in its store (business establishment). In addition, ledger Led (Green Chain GC) registers the business information IC of each business in association with the business ID 10.
[0181] Consumer E (the business information acquisition unit 560 of the verification device 500) or the like searches the ledger Led (Green Chain GC) using the business ID 10 (public business ID 11) printed on the signboard of the store of retailer D selling product P (S1410). Consumer E (the business information acquisition unit 560 of the verification device 500) or the like identifies a registered business ID 12 registered in the ledger Led (Green Chain GC) that is the business ID 10 matching the public business ID 11 (S1420). Consumer E (the business information acquisition unit 560 of the verification device 500) or the like acquires a business information IC registered in the ledger Led (Green Chain GC) that is associated with the identified registered business ID 12 (S1430). Consumer E (the verification device 500) or the like performs verification using the acquired business information IC (S1440). For example, Consumer E verifies the authenticity of the business information IC by comparing the business information IC acquired by the verification device 500 (particularly, the business information acquisition unit 560) with generally known information about the store of Retailer D that sells Product P. Specifically, Consumer E (verification device 500) or the like may verify whether the name (actual name) of Retailer D that sells Product P matches the name of the business indicated in the business information IC. Consumer E (verification device 500) or the like may also verify whether the address (actual address) of Retailer D's store that sells Product P matches the location of the store of the business indicated in the business information IC. If the business information IC is authentic (e.g., generally known information about Retailer D's store matches the business information IC), Consumer E determines that Retailer D is a legitimate business. In other words, if the business information IC matches generally known information about Retailer D's store, Consumer E determines that Retailer D is a legitimate business and that Product P sold by Retailer D is authentic. Furthermore, if the business information IC is false (for example, the business information IC does not match the information generally known about Retailer D's store), Consumer E will determine that Retailer D is an unauthorized business.In other words, if the business information IC matches the information generally available about Retailer D's store, Consumer E will determine that Retailer D is an unauthorized business and that Product P sold by Retailer D is likely to be a counterfeit.
[0182] (Second verification: store comparison) The consumer E (the owner business identification unit 570 of the verification device 500) or the like searches the ledger Led (Green Chain GC) using the attached coded code aCPid, which is the coded code CPid assigned to the product P to be purchased (S1510). The consumer E (the owner business identification unit 570 of the verification device 500) or the like identifies the registered coded code rCPid, which is the coded code CPid registered in the ledger Led (Green Chain GC) and matches the attached coded code aCPid (S1520). The consumer E (the owner business identification unit 570 of the verification device 500) or the like acquires (identifies) the owner business ID 20 registered in the Green Chain GC in association with the identified registered coded code rCPid (S1530). The consumer E (the distribution determination unit 580 of the verification device 500) or the like determines whether the owner business ID 20 identified in S1530 matches the public business ID 11 printed on the signboard of the store of the retailer D selling the product P (S1540). If the owning business ID 20 and the disclosing business ID 11 match (Yes in S1540), consumer E (the distribution determination unit 580 of the verification device 500) or the like determines that product P is being sold by retailer D through a legitimate distribution channel (S1550). If the owning business ID 20 and the disclosing business ID 11 do not match (No in S1540), consumer E (the distribution determination unit 580 of the verification device 500) or the like determines that product P is being sold by retailer D through an unauthorized distribution channel (S1560).
[0183] The SICA described above enables the distinction between a product P bearing a genuine coding code CPid (a coding code CPid generated by manufacturer B) and a counterfeit product bearing a fake coding code CPid generated by copying the genuine coding code CPid.
[0184] Here, there is a risk that a fake (illegal) coded code CPid(B) with the exact same content as the true coded code CPid(A) is generated by copying the true (authorized) coded code CPid(A) that manufacturer B assigned to product P. For example, it is conceivable that a coded code aCPid(A) is assigned to a genuine product (authorized product P) held by authorized retailer D1, and a coded code aCPid(B) is assigned to a counterfeit product held by unauthorized retailer D2.
[0185] In this situation, the attached encoded code aCPid(B) is generated by copying the attached encoded code aCPid(A), and therefore the attached encoded code aCPid(A) and the attached encoded code aCPid(B) have exactly the same content. However, even in this situation, the following business ID 10 should be associated with the encoded code CPid that matches the attached encoded code aCPid(A) (=attached encoded code aCPid(B)) and registered in the ledger Led (Green Chain GC) as the owning business ID 20. In other words, the business ID 10 that can uniquely identify "the business (i.e., the legitimate retailer D1) that purchased product P through a legitimate distribution channel and intends to sell the purchased product P to a new purchaser (e.g., consumer E)" should be registered in the ledger Led (Green Chain GC) as the owning business ID 20.
[0186] Therefore, by searching the ledger Led (Green Chain GC) using the attached coded code aCPid(A) (= attached coded code aCPid(B)), it can be determined that retailer D1 is a legitimate retailer and retailer D2 is an unauthorized retailer. Therefore, even if the attached coded code aCPid(A) (true coded code CPid) is copied to generate a fake attached coded code aCPid(B), SICA can determine whether the distribution route of product P to which the coded code CPid is assigned is legitimate or not.
[0187] The above-mentioned three verifications (verification using business information IC (store search), MICA verification, and store comparison) performed by consumer E (verification device 500) or the like in SICA may be collectively referred to as "SICA verification."
[0188] (Features) As described above, the verification method M according to this embodiment is a verification method in which the verification device 500 (computer) verifies the identity of a product P. The ledger Led stores (A) a public key PuK and (B) brand information IB, which is information about a product group including the product P and includes at least one of a brand name, which is the name of the product group, and the name of the manufacturer (manufacturer B in this embodiment) that produced the product P, in association with each other. The ledger Led also stores (C) an encoding code CPid and (D) product information IP, which includes information that can identify the product P in the product group that includes the product P, in association with each other. The encoding code CPid is a product ID50 (product identification information) that can uniquely identify the product P manufactured by manufacturer B, and is generated by encoding the product ID50, which includes at least a part of the public key PuK, using a private key PrK that corresponds to the public key PuK.
[0189] The verification method M includes a first acquisition step (S1110 to S1130 in FIG. 13A), a second acquisition step (S1210 to S1230 in FIG. 13B), and a determination step (S1310 to S1340 in FIG. 13C). The first acquisition step searches the ledger Led with an attached public key aPuK, which is a public key PuK assigned to the product P to be purchased, to acquire brand information IB registered in the ledger Led in association with a registered public key rPuK, which is a public key PuK registered in the ledger Led and matches the attached public key aPuK. The second acquisition step searches the ledger Led by the attached encoding code aCPid, which is the encoding code CPid assigned to the product P to be purchased, to acquire product information IP registered in the ledger Led in association with the registered encoding code rCPid, which is the encoding code CPid registered in the ledger Led and which matches the attached encoding code aCPid.The determination step determines that the product P manufactured by manufacturer B (manufactured product P(X)) and the product P to be purchased (purchased product P(Y)) are the same product P when at least a part of the public key PuK included in decrypted information obtained by decoding the attached encoding code aCPid assigned to the product P to be purchased using the attached public key aPuK assigned to the product P to be purchased matches at least a part of the attached public key aPuK.
[0190] In this configuration, the verification device 500 acquires brand information IB in a first acquisition step. Therefore, for example, a consumer E (end consumer) who purchases a product P can verify the authenticity of the brand information IB, that is, whether the brand of the product P is a genuine brand, by comparing the brand information IB acquired by the verification device 500 with generally known information about the brand of the product P. If the brand information IB is true (e.g., matches generally known information about the brand of the product P), the consumer E can determine that the product P he is purchasing is genuine (the purchased product P(Y) and the manufactured product P(X) are identical). On the other hand, if the brand information IB is false (e.g., does not match generally known information about the brand of the product P), the consumer E can determine that the product P he is purchasing is a counterfeit (the purchased product P(Y) and the manufactured product P(X) are not identical).
[0191] Furthermore, the verification device 500 acquires the product information IP in the second acquisition step. Therefore, for example, a consumer E who purchases a product P can verify the authenticity of the product information IP, that is, whether the product P is genuine (whether it is included in a genuine brand), by comparing the product information IP acquired by the verification device 500 with generally known information about the product P (e.g., information printed on the package of the product P). If the product information IP is true (e.g., matches generally known information about the product P), the consumer E can determine that the product P he is purchasing is genuine (the purchased product P(Y) and the manufactured product P(X) are identical). If the product information IP is false (e.g., does not match generally known information about the product P), the consumer E can determine that the product P he is purchasing is a counterfeit (the purchased product P(Y) and the manufactured product P(X) are not identical).
[0192] Furthermore, if at least a part of the public key PuK included in the decryption information matches at least a part of the attached public key aPuK, the verification device 500 determines that the purchased product P(Y) and the manufactured product P(X) are the same product P.
[0193] Here, if the manufactured product P (manufactured product P(X)) and the purchased product P (purchased product P(Y)) are the same product P, the attached encoded code aCPid should have been generated by encoding the product ID50, which includes at least a part of the public key PuK, using the private key PrK corresponding to the public key PuK. Furthermore, if the manufactured product P(X) and the purchased product P(Y) are the same product P, the attached public key aPuK should match the public key PuK corresponding to the private key PrK used to generate the attached encoded code aCPid. Therefore, if the manufactured product P(X) and the purchased product P(Y) are the same product P, the attached encoded code aCPid should be able to be decoded using the attached public key aPuK. Furthermore, if the manufactured product P(X) and the purchased product P(Y) are the same product P, the decrypted information obtained by decoding the attached encoding code aCPid using the attached public key aPuK should contain "at least a part of the public key PuK" that matches at least a part of the attached public key aPuK. Therefore, this configuration can use the encoding code CPid to verify whether the manufactured product P(X) and the purchased product P(Y) are the same product P, that is, can verify the identity of the product P.
[0194] Additionally, in this configuration, the encoded code CPid, which is assigned to the product P to determine the identity of the product P and registered in the ledger Led, is generated by encoding the product ID 50 with the private key PrK. Therefore, even if a person other than the person who holds the private key PrK (manufacturer B in this embodiment) analyzes the encoded code CPid assigned to the product P, they cannot identify the generation rule of the encoded code CPid (i.e., the private key PrK), the product ID 50, or the generation rule of the product ID 50. In other words, no one other than the person who holds the private key PrK can know the generation rule of the encoded code CPid (the private key PrK). Therefore, this configuration can prevent a situation in which a person other than the person who holds the private key PrK identifies the generation rule of the encoded code CPid and generates a large number of false (illegal) encoded codes CPid that cannot be distinguished from genuine (regular) encoded codes CPid.
[0195] In contrast, a person who has the private key PrK can generate, by any method, a large number of product IDs 50, each capable of uniquely identifying one of a plurality of products P. Then, by using the private key PrK, a person who has the private key PrK can easily generate a large number of the encoded codes CPid from the large number of product IDs 50.
[0196] In other words, this configuration can prevent a situation in which the rules for generating the encoding code CPid are discovered by a third party and a large number of encoding codes CPid are counterfeited, while reducing the burden on genuine (authorized) manufacturers regarding the generation of the encoding code CPid, etc.
[0197] Therefore, with this configuration, it is possible to reduce the burden associated with generating an encoding code CPid (basic verification information) that can be used to verify the identity of product P, while preventing third parties from understanding the rules for generating the encoding code CPid.
[0198] In the verification method M (verification system S), a business ID 10, which is identification information that can uniquely identify each business, is made public to purchasers of product P at each business's store. In the ledger Led, (E) the business ID 10 and (F) business information IC, which includes at least one of the name of the business uniquely identified by the business ID 10 and information that identifies the location of the business's store, are registered in association with each other. The ledger Led also registers an owning business ID 20, which is associated with the encoding code CPid and uniquely identifies the business that owns product P uniquely identified by the encoding code CPid (product ID 50). Specifically, (1) if product P has not yet been transferred (sold) between businesses, the business ID 10, which can uniquely identify the manufacturer of product P (manufacturer B in this embodiment), is associated with the encoding code CPid and registered in the ledger Led as the owning business ID 20. Also, (2) when product P is transferred between businesses, a business ID 10 that can uniquely identify the business that purchased product P is associated with the encoding code CPid and registered in the ledger Led as the owning business ID 20.
[0199] Verification method M includes a third acquisition step (S1410 to S1430 in FIG. 17A), an owning business identification step (S1510 to S1530 in FIG. 17B), and a determination step (S1540 to S1560 in FIG. 17B). The third acquisition step searches ledger Led by public business ID11, which is the business ID10 of the business that sells product P (for example, retailer D for consumer E), that is published in the store of that business, and acquires business information IC that is registered in ledger Led and is associated with registered business ID12, which is the business ID10 that matches public business ID11. The owning business identification step searches the ledger Led using the attached coded code aCPid assigned to the product P, and identifies the owning business ID 20 registered in the ledger Led in association with the registered coded code rCPid, which is the coded code CPid registered in the ledger Led and matches the attached coded code aCPid. The distribution determination step determines that the product P is distributed through a legitimate distribution route if the owning business ID 20 identified in the owning business identification step matches the disclosed business ID 11 published in the store of the business selling the product P.
[0200] In this configuration, the verification device 500 acquires the business entity information IC in the third acquisition step. Therefore, for example, a consumer E (end consumer) who purchases a product P can verify the authenticity of the business entity information IC by comparing the business entity information IC acquired by the verification device 500 with generally known information about the business entity selling the product P. If the business entity information IC is true (e.g., matches generally known information about the business entity selling the product P), the consumer E can determine that the purchased product P (i.e., the product P sold by that business entity) is authentic (the purchased product P(Y) and the manufactured product P(X) are identical). If the business entity information IC is false (e.g., does not match generally known information about the business entity selling the product P), the consumer E can determine that the purchased product P is a counterfeit (the purchased product P(Y) and the manufactured product P(X) are not identical).
[0201] The verification device 500 also identifies the owner business entity ID 20 using the attached coded code aCPid assigned to the product P, and determines whether the identified owner business entity ID 20 matches the disclosed business entity ID 11 (the business entity ID of retailer D in this embodiment) disclosed in the store selling the product P. If the two match, the verification device 500 determines that the product P is distributed through a legitimate distribution route.
[0202] Here, there is a risk that a fake (illegal) coded code CPid with the exact same content as the true coded code CPid may be generated by copying the true (authorized) coded code CPid assigned to the product P. For example, a situation can be imagined in which an attached coded code aCPid(A) is assigned to a genuine product held by a true (authorized) retailer D1, and an attached coded code aCPid(B), which is a fake coded code CPid generated by copying the attached coded code aCPid(A), is assigned to a counterfeit product held by a fake (illegal) retailer D2.
[0203] In such a situation, the attached encoded code aCPid(B) is generated by copying the attached encoded code aCPid(A), so the attached encoded code aCPid(A) and the attached encoded code aCPid(B) have exactly the same content.
[0204] However, even under such circumstances, the business ID 10 below should be associated with the registered coding code rCPid that matches the attached coding code aCPid(A) (=attached coding code aCPid(B)) and registered in the ledger Led as the owning business ID 20. In other words, the business ID 10 that can uniquely identify "the business that sells (to consumer E, etc.) product P purchased through a legitimate distribution channel (i.e., legitimate retailer D1)" should be registered in the ledger Led as the owning business ID 20.
[0205] Therefore, by searching the ledger Led using the attached coding code aCPid(A) (=attached coding code aCPid(B)), it can be determined that retailer D1 is a genuine (legitimate) retailer and retailer D2 is a fake (illegitimate) retailer.
[0206] Therefore, in this configuration, even if an encoding code CPid (a legitimate encoding code CPid) is copied to generate an illegal encoding code CPid, it is possible to determine whether the distribution route of the product P to which the encoding code CPid is assigned is legitimate.
[0207] §4 Variations So far, we have explained an example in which the ledger Led is a distributed ledger built on the foundation of the Green Chain GC, which is a blockchain. However, it is not essential for the verification system S and the verification method M that the ledger Led be a distributed ledger.
[0208] Although the above description deals with an example in which consumer E (verification device 500) performs MICA verification and SICA verification, in the verification system S and verification method M, a person other than consumer E (verification device 500) may perform MICA verification and SICA verification. In the verification system S and verification method M, MICA verification and SICA verification are performed to verify the identity of product P being purchased (or attempted to be purchased). Therefore, anyone who purchases (or attempts to purchase) product P can perform MICA verification and SICA verification. For example, MICA verification and SICA verification may be performed by at least one of distributor C, which purchases product P from manufacturer B, and retailer D, which purchases product P from distributor C.
[0209] Furthermore, as an example of realizing a hierarchy of monitoring units, an example has been described in which a monitoring unit A (the authorization unit 140 of the monitoring device 100) grants authorization as monitoring unit A to a manufacturer (e.g., manufacturer B), thereby realizing multiple monitoring units A having a hierarchical structure. However, the method of realizing a hierarchy of monitoring units is not limited to the above-mentioned method. The monitoring unit A may grant authorization as monitoring unit A to any person determined to be authorized to be authorized as monitoring unit A. For example, the monitoring unit A may grant authorization as monitoring unit A to a business operator registered with business ID 10 in the ledger Led (Green Chain GC) that the monitoring unit A has determined to be authorized to be authorized as monitoring unit A (e.g., determined to be a legitimate business operator). In other words, the monitoring unit A may grant authorization as monitoring unit A to a business operator determined to be a legitimate business operator based on a certified copy of a corporate registry or the like. Furthermore, it is not necessary for the person authorized by the monitoring unit A to be a business operator. [Explanation of symbols]
[0210] 10...Business ID, 11...Public Business ID, 12...Registered Business ID, 20...Owner business ID, 21...Registered owner business ID, 40...Purchaser business ID, 50...Product ID (product identification information), 100...Monitoring device (third computer) 400... management server (second computer), 500... verification device (computer), 504p...5th Program (Verification Program), 520... brand information acquisition unit (first acquisition unit), 530... product information acquisition unit (second acquisition unit), 550...key determination unit (determination unit), aPuk...attached public key, aCPid...attached encoding code, CPid...encoding code, IB...brand information, IC...business information, IP...product information, Led... ledger, M... verification method, P... product, Puk... public key, Prk... private key, rPuk...Registration public key, rCPid...Registration encoding code, S210...Application acceptance step, S220...Registration decision step, S240...Brand registration step, S510...Sales report reception step, S520...Inquiry step, S530~S560...Ownership renewal steps, S1110 to S1130: First acquisition step, S1210 to S1230: Second acquisition step S1310 to S1340: Judgment steps S1410 to S1430: Third acquisition step S1510~S1530...Ownership company identification steps, S1540~S1560...Distribution judgment steps
Claims
1. A verification method for verifying the identity of a product by a computer, comprising: (A) a public key and (B) brand information, which is information about a product group including the product, and which includes at least one of a brand name, which is the name of the product group, and the name of a manufacturer that manufactured the product, are associated with each other; moreover, (C) an encoded code that is product identification information that can uniquely identify a product manufactured by the manufacturer and that is generated by encoding product identification information that includes at least a part of the public key using a private key that corresponds to the public key, and (D) product information that includes information that can identify the product in the product group, which are associated with each other. The registered ledger, a first acquisition step of acquiring the brand information registered in the ledger in association with a registered public key, which is a public key registered in the ledger and which matches the attached public key, by searching using an attached public key, which is a public key assigned to the product to be purchased; a second acquisition step of searching the ledger using an attached coded code, which is a coded code assigned to the product to be purchased, to acquire the product information registered in the ledger in association with a registered coded code, which is a coded code registered in the ledger and matches the attached coded code; a determining step of determining that the manufactured product and the purchased product are the same product when at least a part of a public key included in decrypted information obtained by decoding the attached encoded code using the attached public key matches at least a part of the attached public key; Including, Verification method.
2. A business ID, which is identification information that can uniquely identify each business, is made public to purchasers of the product at the store of each business, The ledger includes: (E) the business ID and (F) business information including at least one of the name of the business uniquely identified by the business ID and information identifying the location of the store are registered in association with each other, Furthermore, the product identification information is associated with the encoded code generated by encoding the product identification information with the secret key, (1) If the product uniquely identified by the product identification information has not yet been transferred between businesses, the business ID that can uniquely identify the manufacturer of the product is: (2) When the product uniquely identified by the product identification information is transferred between businesses, the business ID that can uniquely identify the business that purchased the product is: It is registered as the owner business ID, The computer a third acquisition step of searching the ledger using a public business ID that is the business ID made public at the store, and acquiring the business information registered in the ledger in association with a registered business ID that is a business ID that is registered in the ledger and matches the public business ID; an owning business operator identification step of searching the ledger using the attached coded code to identify the owning business operator ID registered in the ledger in association with a registered coded code that is a coded code registered in the ledger and that matches the attached coded code; a distribution determination step of determining that the product is distributed through a legitimate distribution route if the owner business ID identified in the owner business identification step matches the disclosure business ID; Further implementation of The verification method of claim 1 .
3. The second computer a sales report receiving step of receiving a report from a business operator uniquely identified by the owning business operator ID registered in the ledger in association with the coded code, the sales report notifying the purchasing business operator ID, which is the business ID that can uniquely identify the purchasing business operator that purchased the product; an inquiry step of inquiring of a business operator uniquely identified by the purchasing business operator ID included in the sales report received in the sales report receiving step as to whether or not the business operator is the current owner of the product; an owner updating step of updating the business ID registered in the ledger as the owning business ID in association with the coded code to the purchasing business ID when a response to the inquiry is received from the business uniquely identified by the purchasing business ID acknowledging that the business is the current owner of the product; To execute The verification method of claim 2 .
4. A third computer an application receiving step of receiving a registration application from the manufacturer of the product to register the public key and the brand information in the ledger; a registration determination step of determining whether or not the registration application accepted in the application acceptance step is permitted; a brand registration step of registering the public key and the brand information in the ledger in association with each other when it is determined in the registration determination step that the registration application is permitted; Further implementation of The verification method according to any one of claims 1 to 3.
5. A verification device for verifying the identity of a product, comprising: (A) a public key and (B) brand information, which is information about a product group including the product, and which includes at least one of a brand name, which is the name of the product group, and the name of a manufacturer that manufactured the product, are associated with each other; moreover, (C) an encoded code that is product identification information that can uniquely identify a product manufactured by the manufacturer and that is generated by encoding product identification information that includes at least a part of the public key using a private key that corresponds to the public key, and (D) product information that includes information that can identify the product in the product group, which are associated with each other. The registered ledger, a first acquisition unit that acquires the brand information registered in the ledger in association with a registered public key that is a public key registered in the ledger and that matches the attached public key by searching using an attached public key that is a public key assigned to the product to be purchased; a second acquiring unit that searches the ledger using an attached coded code that is a coded code assigned to the product to be purchased, and acquires the product information registered in the ledger in association with a registered coded code that is a coded code registered in the ledger and that matches the attached coded code; a determination unit that determines that the manufactured product and the purchased product are the same product when at least a part of a public key included in decryption information obtained by decoding the attached encoded code using the attached public key matches at least a part of the attached public key; Equipped with Verification device.
6. A verification program for causing a computer to verify the identity of a product, the program comprising: (A) a public key and (B) brand information, which is information about a product group including the product, and which includes at least one of a brand name, which is the name of the product group, and the name of a manufacturer that manufactured the product, are associated with each other; moreover, (C) an encoded code that is product identification information that can uniquely identify a product manufactured by the manufacturer and that is generated by encoding product identification information that includes at least a part of the public key using a private key that corresponds to the public key, and (D) product information that includes information that can identify the product in the product group, which are associated with each other. The registered ledger, a first acquisition step of acquiring the brand information registered in the ledger in association with a registered public key, which is a public key registered in the ledger and which matches the attached public key, by searching using an attached public key, which is a public key assigned to the product to be purchased; a second acquisition step of searching the ledger using an attached coded code, which is a coded code assigned to the product to be purchased, to acquire the product information registered in the ledger in association with a registered coded code, which is a coded code registered in the ledger and matches the attached coded code; a determining step of determining that the manufactured product and the purchased product are the same product when at least a part of a public key included in decrypted information obtained by decoding the attached encoded code using the attached public key matches at least a part of the attached public key; Execute Verification program.
Citation Information
Patent Citations
Anti-counterfeiting traceability method based on RFID and block chain
CN111639729A
Writing apparatus, reading apparatus and examination method
JP2003196360A
Determination system, generation device, determination device, determination method, and the like
JP2007164290A
Digitally protected electronic titles for supply chain products
JP2015537472A
Shipping product authentication system and server apparatus
JP2018055149A