Trust management system, trust management method, trust management server, and trust management program
The trust management system enforces multiple approval conditions and verifies operations using monitoring private keys to prevent fraud in trust property disposal, ensuring secure and transparent asset management.
Patent Information
- Application Number
- JP2022069125
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-04-19
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2042-04-19
AI Technical Summary
Existing trust management systems fail to strictly adhere to multiple approval conditions and prevent fraud in the disposal of trust property, especially in family trusts where assets are managed by others, leading to disputes and potential misuse.
A trust management system that includes a trust management server, settlor and trust party terminals, and a network, which manages trust property through a trust property information table, operation record table, and monitoring private keys, ensuring multiple approvals are met before property disposal, and verifies operations using signatures.
The system ensures strict adherence to approval conditions, preventing fraud by allowing only authorized parties to dispose of trust property, providing a transparent and secure method for asset management.
Smart Images

Figure 0007756043000001 
Figure 0007756043000002 
Figure 0007756043000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a trust management system and a trust management method, and in particular to a trust management system and a trust management method that are suitable for strictly adhering to approval conditions and preventing fraud among parties when the disposal of trust property requires multiple approvals. [Background technology]
[0002] In recent years, the aging society has brought attention to the family trust system. This is due to phenomena such as the increase in assets held by the elderly, the increase in dementia patients, and the growing need for proxy asset management for the elderly. A family trust is an asset management system in which a person entrusts their real estate holdings, savings, etc. to a trusted family member for management and disposal in preparation for their retirement or nursing care. The family trust system allows for a wider range of inheritance than a will, and is characterized by the fact that, since the management of assets is entrusted to a trusted family member, there is generally no high fee involved.
[0003] In the case of asset management for the elderly, including family trusts, it is important to prevent fraud by authorized persons because the assets are managed by others. An example of the use of information processing technology in asset management for the elderly is disclosed in Patent Document 1, for example.
[0004] In the system of Patent Document 1, even if approval from the elderly person in question cannot be obtained to manage their "end-of-life preparations," an agent who has received approval from multiple agents is permitted to "log in in an emergency" and can view information and dispose of the elderly person's assets. This allows the agent to take appropriate action regarding the elderly person's assets even if the elderly person's situation suddenly changes, while respecting the elderly person's right to self-determination. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Publication No. 2020-109712 Summary of the Invention [Problem to be solved by the invention]
[0006] In a family trust, the trustee is legally obligated to report the trust books to the settlor in order to prevent misuse, but even so, there are many cases where disputes arise between relatives over the disposal of trust assets.
[0007] If the method described in Patent Document 1 is applied to a family trust, and a person without the principal's approval is required to obtain the approval of another agent when logging in in the event of an emergency, or if authority is simply set to yes or no, it will not be possible to prevent operations after logging in or fraud by authorized persons.
[0008] Furthermore, in asset disposal operations, depending on the importance of the asset, there may be cases where multiple patterns of approval conditions exist for the operation, or where operations with different approval conditions are performed consecutively.
[0009] In order to prevent fraud by authorized persons, it is necessary to set flexible conditions according to the importance of the operation, as well as to provide an efficient method for obtaining approval and providing proof.
[0010] The object of the present invention is to provide a trust management system and a trust management method that can strictly adhere to approval conditions and prevent fraud among parties when the disposal of trust property requires multiple approvals. [Means for solving the problem]
[0011] The trust management system of the present invention is preferably a trust management system that manages the disposal of trust property by trust parties, and includes a trust management server, a settlor terminal that entrusts the trust property, and a trust party terminal that inputs information about the trust of the trust party related to the trust agreement, the trust management server, the settlor terminal, and the trust party terminal are connected via a network, the trust management server holds a trust property information table that holds trust property information for each property item of the trust property and an operation record table related to the disposal of the trust property, calculates the number of approvals from trust parties for each property item of the trust property, the trust management server creates a monitoring private key for each property item of the trust property and creates a trust property agreement signed with the monitoring private key for each property item of the trust property, the trust management server receives a request for disposal of trust property for a trust item of the trust property from the trust party terminal, and when approvals equal to the number of approvals from the trust parties are received, the trust management server signs the operation record table with the monitoring private key and carries out the disposal of the trust property for the trust item of the trust property, and verifies the operation trail of the trust property using the signature of the monitoring private key on the trust property agreement and the signature on the operation record table. [Effects of the Invention]
[0012] According to the present invention, it is possible to provide a trust management system and a trust management method that can strictly adhere to the approval conditions and prevent fraud among parties when the disposal of trust property requires multiple approvals. [Brief explanation of the drawings]
[0013] [Figure 1] FIG. 1 is an overall configuration diagram of a trust management system. [Figure 2] FIG. 2 is a functional configuration diagram of a trust management server. [Figure 3] This is a hardware and software configuration diagram of the trust management server. [Figure 4] FIG. 10 is a diagram illustrating an example of a trust property information table. [Figure 5] FIG. 2 is a diagram illustrating an example of a public key certificate. [Figure 6] FIG. 10 is a diagram illustrating an example of an asset disposal agreement. [Figure 7] FIG. 10 is a diagram illustrating an example of an operation record table. [Figure 8A] This is a sequence diagram showing a series of steps in the trust management system (part 1). [Figure 8B] This is a sequence diagram showing the flow of the trust management system (part 2). [Figure 9] FIG. 10 is a sequence diagram showing a process for setting approval conditions for property disposal. [Figure 10] FIG. 10 is a sequence diagram showing a secret sharing execution process. [Figure 11] 10 is a diagram illustrating the relationship when secret sharing of a monitoring private key for each property item is performed in accordance with the approval conditions for property disposal. FIG. [Figure 12] FIG. 10 is a sequence diagram showing a process for creating an asset disposal agreement. [Figure 13] FIG. 10 is a sequence diagram showing the process of creating a trust property operation trail. [Figure 14] FIG. 10 is a sequence diagram showing a process for verifying a trust property operation trail. [Figure 15] 10 is a diagram illustrating the relationship between a public key certificate, an operation record table, and a property disposal agreement in the verification of a trust property operation trail. FIG. DETAILED DESCRIPTION OF THE INVENTION
[0014] An embodiment of the present invention will be described below with reference to FIGS. First, the configuration of the trust management system will be described with reference to FIGS.
[0015] Generally, a "trust" is a system in which the person who sets up the trust (the settlor) treats a certain amount of his or her own property (trust property) separately, entrusts it to a trustworthy person (the trustee), and transfers the title to that person. The entrusted person manages, utilizes, and disposes of the property in accordance with a certain purpose, and allows the person who enjoys the benefits of the trust (the beneficiary) to use the trust property or pay investment profits, etc.
[0016] A family trust is a type of trust, and is a system of asset management in which you entrust your real estate and savings to a trusted family member to manage and dispose of them in preparation for your retirement or when you need nursing care.
[0017] In this embodiment, we consider a case where an elderly person acts as a trustor (or in some cases, both trustor and beneficiary) and entrusts his or her assets to his or her eldest son as a trustee. Also, those involved in the trust agreement are referred to as "trust parties." Trust parties include the trustee and, in some cases, relatives who will be beneficiaries. We also assume that the trust agreement includes a clause requiring the approval of multiple trust parties before any disposition of the trust assets can be made.
[0018] As shown in Figure 1, the trust management system is configured with a trust management server 100, a trustor terminal 10, trust related party terminals 20 (represented as 20a, 20b, ... in Figure 1), and a trust financial institution server 30 connected via a network 5.
[0019] The trust management server 100 is a server that receives necessary information from outside, manages information related to family trusts, and outputs information that should be output to outside. The trust management server 100 is operated, for example, by a law firm that handles legal matters as a business.
[0020] The trustor terminal 10 is a terminal where the trustor inputs necessary information and uploads the input information to the trust management server 100.
[0021] The trustee terminal 20 is a terminal through which the trustee enters the necessary information, and in response to inquiries from the trust management server 100, enters whether or not approval is given for the disposal of assets, and uploads the entered information to the trust management server 100.
[0022] The trust financial institution server 30 is a server that disposes of deposit accounts related to the disposal of trust assets in response to a request from the trust management server 100.
[0023] The network 5 is assumed to be a global network such as the Internet, but the trust management server 100, the trustor terminal 10, and the trustee terminal 20 may be connected via a LAN (Local Area Network).
[0024] As shown in Figure 2, the trust management server 100 has a functional configuration including an approval condition calculation unit 101, a distributed information creation unit 102, a property disposal agreement creation unit 103, an operation record creation unit 104, an operation trail verification unit 105, an external terminal I / F (Interface) unit 110, and a memory unit 120.
[0025] The approval condition calculation unit 101 is a functional unit that calculates the approval conditions (described in detail below) of the trust parties involved in the asset disposal. The shared information creation unit 102 is a functional unit that creates the shared information (described in detail below) of the trust parties that serves as a condition for permitting the asset disposal. The asset disposal agreement creation unit 103 is a functional unit that creates an asset disposal agreement (described in detail below) that indicates the conditions for disposing of the trust property and the agreement of the trust parties. The operation record creation unit 104 is a functional unit that creates a record of the operations performed by the trust parties when disposing of the asset. The operation trail verification unit 105 is a functional unit that verifies whether the operation trail performed by the trust parties is legitimate in accordance with the asset disposal agreement. The external terminal I / F (Interface) unit 110 is a functional unit that allows the trust management server 100 to input and output data from and to external terminals. The memory unit 120 is a functional unit that stores data necessary for the family trust involving the trust management server 100.
[0026] The storage unit 120 stores contract information data 200 , a trust property information table 201 , public key certificate data 202 , property disposal agreement data 203 , an operation record table 204 , and operation trail verification data 205 .
[0027] Contract information data 200 is data representing the contents of the trust contract. Public key certificate data 202 is data representing a public key certificate that certifies the legitimacy of the issuance of a public key to the trustee. Property disposal agreement data 203 is data representing a property disposal agreement that indicates the conditions for disposing of the trust property and the agreement of the trust parties. Operation trail verification data 205 is data related to the verification of the operation trail. Specific examples of public key certificates and property disposal agreements will be described in detail later. The trust property information table 201 and operation record table 204 will also be described in detail later.
[0028] Next, the hardware and software configuration of the trust management server 100 will be described with reference to FIG. The hardware configuration of the trust management server 100 is realized by a general information processing device such as the server device shown in FIG.
[0029] The trust management server 100 is configured such that a CPU (Central Processing Unit) 302, a main memory device 304, a network I / F (Interface) 306, a display I / F 308, an input / output I / F 310, and an auxiliary memory I / F 312 are connected by a bus.
[0030] The CPU 302 controls each unit of the trust management server 100, and loads and executes necessary programs into the main memory device 304.
[0031] The main storage device 304 is typically configured as a volatile memory such as a RAM, and stores the programs executed by the CPU 302 and data referenced by the CPU 302.
[0032] The network I / F 306 is an interface for connecting to the network 5 .
[0033] The display I / F 308 is an interface for connecting a display device 320 such as an LCD (Liquid Crystal Display).
[0034] The input / output I / F 310 is an interface for connecting input / output devices, and in the example of Fig. 3, a keyboard 330 and a mouse 332, which is a pointing device, are connected.
[0035] The auxiliary storage I / F 312 is an interface for connecting an auxiliary storage device such as an HDD (Hard Disk Drive) 350 or an SSD (Solid State Drive).
[0036] The HDD 350 has a large storage capacity and stores programs for executing this embodiment. The trust management server 100 has installed therein an approval condition calculation program 361, a shared information creation program 362, a property disposal agreement creation program 363, an operation record creation program 364, an operation trail verification program 365, and an external terminal I / F program 370.
[0037] The approval condition calculation program 361, the shared information creation program 362, the property disposal agreement creation program 363, the operation record creation program 364, the operation trail verification program 365, and the external terminal I / F program 370 are programs for realizing the functions of the approval condition calculation unit 101, the shared information creation unit 102, the property disposal agreement creation unit 103, the operation record creation unit 104, the operation trail verification unit 105, and the external terminal I / F unit 110, respectively.
[0038] The HDD 350 also stores contract information data 200 , a trust property information table 201 , public key certificate data 202 , property disposal agreement data 203 , an operation record table 204 , and operation trail verification data 205 .
[0039] Next, the data used in the trust management system and the format related to the trust contract will be explained using Figs. 4 to 7.
[0040] The trust property information table 201 is a table that stores information about the trust property entrusted by the settlor, and as shown in Figure 4, it consists of fields for property ID 201a, property classification 201b, property item 201c, assessed value 201d, and disposal details 201e.
[0041] Property ID 201a stores an ID that uniquely identifies the trust property represented by this record. Property classification 201b stores the classification of the trust property represented by this record. Property item 201c stores the name used to describe the trust property represented by this record. Valuation amount 201d stores the current monetary valuation of the trust property. The trust property may be valued by the settlor himself or may be valued by a tax accountant or other professional. Disposal details 201e stores the specific details of the disposal of the trust property specified by the settlor. If the settlor does not specify the disposition details, for example, this field is left blank.
[0042] Public key certificate 212 is a document that digitally certifies the authenticity of the electronic signature made with a private key (hereinafter simply referred to as a "monitoring private key"; details will be described later) used for monitoring the disposition of property for each property item in the operation record, and is used to verify the signature made with the monitoring private key used when the trustee disposes of property. As shown in Figure 5, public key certificate 212 consists of the following items: public key information 212a, trustee information 212b, certification authority digital signature 212c, and validity period 212d.
[0043] Public key information 212a describes information on the public key issued to the trustee, corresponding to the monitoring private key corresponding to the property item. Trustee information 212b describes information on the trustee, such as name and address. Certification authority digital signature 212c describes information on the digital signature issued by the certification authority. Validity period 212d describes the validity period of this public key certificate.
[0044] The property disposal agreement 213 is a document regarding the agreement on the disposal of the trust property, and as shown in FIG. 6, includes approval conditions 213a, the principal's private key signature 213b, and monitoring private key signature 213c.
[0045] The approval conditions 213a describe the approval conditions of the trust parties for the asset disposal for each asset item. In the example of FIG. 6, for example, when the asset ID is "tp01" and the asset item is "watches, etc.", it describes that approval from five trust parties is required and the disposal content is "sale." The principal private key signature 213b describes a signature using the private key of the trust party himself / herself, which indicates the intention of the trust party to have agreed. The monitoring private key signature 213c describes a signature using the monitoring private key to be used for verifying the asset disposal. The monitoring private key signature is signed by restoring the monitoring private key from the shares distributed to each trust party (hereinafter simply referred to as "shares") (details will be described later).
[0046] The operation record table 204 is a table that holds records regarding the disposal of trust property, and as shown in Figure 7, it consists of fields for operation date 204a, operator 204b, operated property item 204c, operation amount 204d, disposal content 204e, approver 204f, and approval signature 204g.
[0047] The operation date 204a stores the date on which the operation on the trust property was performed in "yyyy / mm / dd" format. The operator 204b stores the ID or name of the person who performed the operation. In the example of Figure 7, for ease of understanding, the ID is illustrated along with the relationship to the principal. The operated property item 204c stores information on the property item that was operated. The operation amount 204d stores the amount used for the trust property on which the operation was performed. The disposal content 204e stores information on the disposal operation related to the trust property, such as "sale." The approver 204f stores the ID or name of the person who approved the operation content in list format. The approval signature 204g stores a signature using the monitoring private key that is restored when the operation on the trust property is approved. If a signature using the monitoring private key is not used, data indicating that it is unsigned, such as a NULL value, is stored.
[0048] Next, the processing in the trust management system will be described with reference to FIGS. 8A to 15. FIG. 10 is a diagram illustrating the relationship between intentions.
[0049] First, a series of flows in the trust management system will be explained using FIG. 8A and FIG. 8B. First, the trustor (an elderly person who entrusts his / her property) applies for entrustment of the trust property to the trust management server 100 from the trustor terminal 10 (Figure 8A: S111), and the trust management server 100 accepts the application for entrustment of the trust property (S131) and, if necessary, prompts the trustor to enter information about the trustor (name, age, financial situation, family relationships, etc.), and presents appropriate contract terms (S132), which are received by the trustor terminal 10 (S112).
[0050] Here, the settlor consults with the trustee and other trust-related parties, such as family members, and once the contract contents have been decided (S01), the settlor requests the trust management server 100 from the settlor terminal 10 to enter into a trust contract for the trust property (S113), and inputs information about the trust property from the settlor terminal 10 (S114).
[0051] The trust management server 100 performs the property disposal approval condition setting process based on this request and the information on the trust property (S133). Details of the property disposal approval condition setting process will be explained later with reference to FIG.
[0052] Next, the trusted party terminal 20 and the trust management server 100 perform secret sharing execution processing (S134). Details of the secret sharing execution processing will be explained later with reference to FIG.
[0053] Next, the trust related person terminal 20 and the trust management server 100 perform processing to create an asset disposal agreement (S135). Details of the processing to create an asset disposal agreement will be explained later using FIG.
[0054] The trust management server 100 transmits the property disposal agreement to the trustor terminal 10 (S136, S115). In response to this, the parties to the trust, including the settlor and the trustee, will enter into a trust agreement with the force of notarial authority, in accordance with the notary's procedures (S02).
[0055] Then, the notarized document is transmitted from the entrustor terminal 10 to the trust management server 100 (S116, S137). In response, the trust management server 100 requests the trust financial institution to open a trust account for this family trust (S138), and the trust financial institution server 30 opens the trust account (S151).
[0056] Next, the trustee, who is a trustee, makes a request to the trust management server 100 from the trust person terminal 20 to manage and dispose of the trust property (S121). In response to this, the trust related person terminal 20 and the trust management server 100 perform processing to create a trust property manipulation trail (S139). Details of the processing to create a trust property manipulation trail will be explained later using FIG.
[0057] Next, the trust management server 100 requests the trust financial institution server 30 to execute disposal of the trust property in accordance with the request for disposal of the trust property received from the trust related person terminal 20 (S140, S152).
[0058] Then, the trust financial institution server 30 executes the disposal of the trust property (S153) and reports this to the trust management server 100, and the trust management server 100 creates a ledger relating to the trust property (S141).
[0059] Next, the trust management server 100 prepares a report on the ledger related to the trust property and the operation record of the trust property (S142) and sends it to the trustor terminal 10 (S143, S117). Reporting to the trustor in this way is a process based on Articles 36 and 37 of the Trust Act.
[0060] Next, if necessary, the trustor requests verification of the trust property operation trail from the trustor terminal 10 to the trust management server 100 (S118). Upon receiving the verification request, the trust management server 100 executes the verification process for the trusted property operation trail (S144). Details of the verification process for the trusted property operation trail will be explained later with reference to FIGS.
[0061] Then, the trust management server 100 transmits the verification result of the trust property operation trail (verification report (not shown)) to the settlor terminal 10 (S145, S119).
[0062] Next, the details of the process for setting approval conditions for property disposal will be described with reference to FIG. The entrustor terminal 10 transmits the trust property information to the trust management server 100 (S201), and the trust management server 100 receives the trust property information from the entrustor terminal 10 (S202).
[0063] Next, the trust management server 100 sets the importance of each property item based on the property classification or the assessed value of the trust property information (S203).
[0064] For example, if the asset classification of an asset item is real estate, the importance is high, and if the asset classification is other than real estate and the assessed value of the asset item is less than 1 million yen, the importance is low, if the assessed value of the asset item is between 1 million and 5 million yen, the importance is medium, and if the assessed value of the asset item is 5 million yen or more, the importance is high.The ratios related to the importance are then sorted in order of importance, for example, 100 percent for high importance, 60 percent for medium importance, and 40 percent for low importance.
[0065] Next, the trust management server 100 calculates the number of approvers from the ratio of importance of the property items in the trust property information and the trust parties using the following (Equation 1) (S204). Number of approvers = (ratio of importance of property items x number of trustees) (integer part)... (Equation 1)
[0066] For example, when there are six people involved in the trust, the asset category is jewelry, and the assessed value of the asset item is 4 million yen. Since the importance is medium and the importance ratio is 60%, the number of approvers is three, which is the integer part of (0.6 x 6).
[0067] Next, the trust management server 100 stores the number of approvers in, for example, a work table (not shown) for the property item of the trust property information (S205).
[0068] Next, details of the secret sharing execution process will be described with reference to FIG. First, the trust management server 100 acquires the trust property information (S301). Next, the trust management server 100 creates a monitoring private key for each property item (S302).
[0069] Then, the trust management server 100 requests the certificate authority and acquires the public key certificate 212 of the public key paired with the monitoring private key issued to the trustee shown in FIG. 5 (S303).
[0070] Next, the trust management server 100 acquires the number of approvers calculated in S133 (S304) and generates shares of the monitoring private key for each property item using the (k, n) threshold method (S305). Here, k is the number of approvers calculated for each property item in step S133, and n is the number of trust parties. The (k, n) threshold method is a method for managing secret information that divides a piece of secret information into n pieces and allows the secret information to be restored when k of the pieces are collected.
[0071] Then, the trust management server 100 transmits the shares of the monitoring private key for each property item to all the trust related party terminals 20 (S306, S307).
[0072] If the trust parties do not agree (S308: NO), the process returns to S01 in Figure 8A and the contents of the contract are renegotiated. If the trust parties agree (S308: YES), the trust party terminal 20 stores the shares of the monitoring private key for each property item and reports to the trust management server 100 that the shares have been received (S309).
[0073] When the shared information of the monitoring private key for each property item is managed by the individual trustee, it can be combined with a mechanism for managing it by biometric authentication using PBI (Public Biometric Infrastructure).In addition to storing and managing it in the trustee terminal 20, it is also possible to prepare a tamper-resistant area in the server, and operate it by authenticating and accessing it from the trustee terminal 20.
[0074] The trust management server 100 determines whether or not the shared information of the monitoring private key for all property items has been sent (S310), and if there is any property item for which the shared information of the monitoring private key has not been sent (S310: NO), it returns to S302, and if the shared information of the monitoring private key for all property items has been sent (S310: YES), it terminates the processing.
[0075] A specific example of the shares of the monitoring private key for each property item will be explained below with reference to the trusted property information table 201 in Fig. 3 and Fig. 11. For example, suppose there are five trustees.
[0076] The assessed value of the asset item "Watches, etc." with asset ID = "tp01" is "10 million yen," so when applying the example of S203, the importance is high and the ratio related to the importance is 100 percent. In this case, according to (Equation 1), the number of approvers is 5, and the (5,5) threshold method is applied.
[0077] Furthermore, since the assessed value of the asset item "Bank A Trust Account" with asset ID = "tp02" is "4 million yen," applying the example of S203, the importance is medium and the ratio related to the importance is 60 percent. In this case, according to (Formula 1), the number of approvers is 3, and the (3,5) threshold method is applied.
[0078] Next, the details of the process for creating the property disposal agreement will be described with reference to FIG. First, the trust management server 100 sets information on the approval conditions 213a of the property disposal agreement 213 based on the information in the trust property information table 201 shown in FIG. 4 and the calculated number of approvers for each property item (S401).
[0079] Next, a request for approval of the disposal of the property is made to the trustee terminal 20 (S402, S403). When the trustees agree (S403: YES), the trustee terminal 20 of each trustee signs the signature using the trustee's private key for identity verification and sends it to the trust management server 100 (S404), and the trust management server 100 receives the signature (S405).
[0080] If the parties to the trust do not agree (S403: NO), the process returns to S01 in FIG. 8A and the contents of the contract are renegotiated.
[0081] Next, the trust management server 100 requests the transmission of shared information of the monitoring private key for the property item using the (k, n) threshold method (S406), and the trust related party terminal 20 transmits shared information of the monitoring private key for the property item using the (k, n) threshold method (S407).
[0082] Next, the trust management server 100 determines whether it has received the approved number of shares of the monitoring private key for the property items using the (k, n) threshold method (S408). If it has not received the approved number of shares (S408: NO), it requests approval of the property disposal from the trust party terminal 20 of the next trust party. If it has received the approved number of shares of the monitoring private key for the property items using the (k, n) threshold method (S408: YES), it restores the monitoring private key from the shares and signs the monitoring private key signature 213c part of the property disposal agreement 213 (S409).
[0083] Then, it is determined whether there is an unsigned monitoring private key for the property item (S410), and if there is an unsigned monitoring private key (S410: YES), the process returns to S406 and requests the transmission of the shared information for the next monitoring private key (S410), and if there is no unsigned monitoring private key (S410: NO), the trust parties are stored in the created property disposal agreement 213 and it is sent to all trust parties and the settlor (S411).
[0084] Next, the details of the process for creating a trusted property manipulation trail will be described with reference to FIG. First, the trustee requests the trust management server 100 to dispose of the trust property from the trust related person terminal 20 (S501).
[0085] The trust management server 100 determines whether the person requesting the disposal of the trust property is a trustee, for example, by means of ID, password, biometric authentication, etc. (S502), and if the person is not a trustee, rejects the request (S503), because only trustees can request the disposal of the trust property.
[0086] Next, the property items are clearly indicated to the trustee terminal 20 of each trustee and an approval request is made (S504).
[0087] If the trusted party does not approve (S505: NO), the trusted party terminal 20 sends a rejection response to the trust management server 100.
[0088] When the trustee approves (S505: YES), the trustee terminal 20 selects shared information according to the property item (S506) and transmits the shared information according to the property item to the trust management server 100 (S507, S508).
[0089] The trust management server 100 determines whether the shared information sent is invalid (S509), and if it is invalid (S509: NO), it rejects the shared information (S510), and if it is valid (S509: YES), it proceeds to S511.
[0090] Next, the trust management server 100 determines whether the shared information corresponding to the property item satisfies the restoration conditions of the (k, n) threshold method (whether the shared information has been collected for the number of approvers) (S511). If the restoration conditions are not met (S511: NO), the process proceeds to S512; if the restoration conditions are met (S511: YES), the process proceeds to S514.
[0091] If the restoration conditions are not met, the trust management server 100 determines whether an approval request has been sent to the trust party terminals 20 of all trust parties (S512), and if an approval request has not been sent to the trust party terminals 20 of all trust parties (S512: NO), it returns to S504 and makes an approval request to the next trust party, and if an approval request has been sent (S512: YES), this means that even when the approval request was sent to the trust party terminals 20 of all trust parties, the required number of approvals was not collected, so the request for disposal of the trust property is rejected (S513).
[0092] On the other hand, when the restoration conditions are met (S511: YES), the trust management server 100 restores the monitoring private key for the property item using the shared information corresponding to the property item, and signs the approval signature 204g of the operation record table 204 using the restored monitoring private key (S515).
[0093] Finally, the trusted management server 100 discards the signed monitoring private key (S516).
[0094] Next, the details of the process for verifying the trusted property manipulation trail will be described with reference to FIGS. The entrustor requests the trust management server 100 to verify the operation trail from the entrustor terminal 10 (S601, S602).
[0095] Next, the trust management server 100 verifies the signature of the monitoring private key of the approval signature 204g of the operation record table 204 from the public key certificate 212 (checks the validity date, whether or not it has been tampered with, and the validity of the signature) (S603, A01 in FIG. 15).
[0096] Next, the trust management server 100 verifies whether the signature in the operation record table 204 matches the monitoring private key signature 213c in the property disposal agreement 213 (S604, A02).
[0097] Next, the trust management server 100 verifies whether the disposition details in the operation record table 204 match the disposition details indicated in the approval conditions 213a of the property disposal agreement 213, and whether the monitoring private key indicated by the property item has been correctly restored (S605, A03).
[0098] Next, the trust management server 100 creates a verification report (not shown) of the trust property operation trail based on the results of the verification in S603 to S605 (S606).
[0099] In this embodiment, the private key for monitoring the disposal of the trust property is divided using a secret sharing scheme, and the shared information is collected, restored, and signed to serve as proof of agreement and approval. However, it is also possible to consider a method in which agreement and approval are achieved using multi-signatures (multiple electronic signatures) instead of the secret sharing scheme.
[0100] Furthermore, although the present embodiment has been described using the example of a family trust in which an elderly person is the trustor, the idea of the invention can be applied to other cases, such as a trust for business succession, i.e., a case in which management rights, business assets, and intellectual property are managed as trust assets in a relationship between a business owner, relatives, potential successors, and employees, or a welfare trust, i.e., a case in which living expenses are managed as trust assets in a relationship between a parent and a disabled person.
[0101] As described above, according to the trust management system of this embodiment, a monitoring private key for each property item is distributed to the trust parties as distributed information, and when the trust property is disposed of, the monitoring private key is restored only when a predetermined number of approvers are present, thereby preventing the fraudulent disposal of the property of the trust parties, and also providing the settlor with a function to verify the trust property, so the settlor himself can verify the legitimacy of the disposal of the trust property. [Explanation of symbols]
[0102] 5...network, 10...trustor terminal, 20...trust related party terminal, 30...trust financial institution server, 100...trust management server, 101... Approval condition calculation unit, 102... Shared information creation unit, 103... Property disposal agreement creation unit, 104... Operation record creation unit, 105... Operation trail verification unit, 110... External terminal I / F (Interface) unit, 120... Storage unit, 200...contract information data, 201...trust property information table, 202...public key certificate data, 212...public key certificate, 203...property disposal agreement data, 213...property disposal agreement, 204...operation record table, 205...operation trail verification data
Claims
1. A trust management system that manages the disposal of trust assets by trust parties, a trust management server; a trustor terminal for entrusting trust assets; a trustee terminal for inputting information about the trust of the trustee involved in the trust agreement; The trust management server, the trustor terminal, and the trustee terminal are connected by a network, The trust management server a trust property information table that holds trust property information for each property item of the trust property; and maintaining an operation record table relating to the disposal of trust assets; For each property item in the trust assets, the number of trustees who approved it was calculated. The trust management server A monitoring private key is created for each property item in the trust assets, preparing a trust property agreement signed with the monitoring private key for each property item of the trust property; the trust management server, when requested by the trust related party terminal to dispose of the trust property of the trust item of the trust property and approval is received from the number of approvals of the trust related parties, signs the operation record table with the monitoring private key and executes the disposal of the trust property of the trust item of the trust property; A trust management system characterized in that the operation trail of the trust property is verified by the signature of the monitoring private key of the trust property agreement and the signature of the operation record table.
2. The trust items of the trust property shall state the property classification of the trust property and the assessed value of the trust property, 2. The trust management system according to claim 1, wherein the trust management server calculates the number of approvals based on the property classification of the trust property or the assessed value of the trust property.
3. the trust management server distributes the supervisory private key to the number of trusted parties and distributes the shared information of the supervisory private key to the trusted party terminals; 2. The trust management system according to claim 1, wherein when approvals equal to the number of approvals are received, the monitoring private key is restored using a secret sharing scheme to restore the monitoring private key, and the operation record table is signed with the monitoring private key.
4. A trust management method using a trust management system that manages the disposal of trust property by trust parties, The trust management system comprises: a trust management server; a trustor terminal for entrusting trust assets; a trustee terminal for inputting information about the trust of the trustee involved in the trust agreement; The trust management server, the trustor terminal, and the trustee terminal are connected by a network, The trust management server a trust property information table that holds trust property information for each property item of the trust property; and maintaining an operation record table relating to the disposal of trust assets; The trust management server sets the number of trustees' approvals for each property item of the trust property; the trust management server creating a monitoring private key for each property item of the trust property; The trust management server creates a trust property agreement signed with a monitoring private key for each property item of the trust property; a step in which the trust management server, when requested by the trust related party terminal to dispose of the trust property of the trust item of the trust property and approval is received from the number of trust related parties, signs the operation record table with the monitoring private key and executes the disposal of the trust property of the trust item of the trust property; A trust management method characterized by comprising a step of verifying the operation trail of the trust property using the signature of the monitoring private key of the trust property agreement and the signature of the operation record table.
5. The trust items of the trust property shall state the property classification of the trust property and the assessed value of the trust property, 5. The trust management method according to claim 4, wherein the trust management server calculates the number of approvals based on the property classification of the trust property or the assessed value of the trust property.
6. the trust management server distributes the supervisory private key to the number of trusted parties and distributes the shared information of the supervisory private key to the trusted party terminals; The trust management method according to claim 4, characterized in that when approvals equal to the number of approvals are received, the monitoring private key is restored using a secret sharing method for restoring the monitoring private key, and the operation record table is signed with the monitoring private key.
7. A trust management server that manages the disposal of trust property by trust parties, a trust property information table that holds trust property information for each property item of the trust property; and maintaining an operation record table relating to the disposal of trust assets; For each property item in the trust assets, the number of trustees who approved it was calculated. A monitoring private key is created for each property item in the trust assets, preparing a trust property agreement signed with the monitoring private key for each property item of the trust property; When a request for disposal of the trust property of the trust items of the trust property is made and approval is received from the number of trust parties, a signature is made with the monitoring private key in the operation record table, and the disposal of the trust property of the trust items of the trust property is carried out; A trust management server that verifies the operation trail of the trust property using the signature of the monitoring private key of the trust property agreement and the signature of the operation record table.
8. A trust management program stored in a storage medium, which manages the disposal of trust property by trust parties by an information processing device, The information processing device includes: a trust property information table that holds trust property information for each property item of the trust property; and maintaining an operation record table relating to the disposal of trust assets; For each property item in the trust assets, the number of trustees who approved it was calculated. A function to create a monitoring private key for each property item of the trust property, A function of creating a trust property agreement signed with a monitoring private key for each property item of the trust property; a function of signing the operation record table with the monitoring private key and executing the disposal of the trust property of the trust item of the trust property when the disposal of the trust property of the trust item of the trust property is requested and approval is received from the number of the trust parties; A trust management program characterized by executing a function of verifying the operation trail of the trust property using the signature of the monitoring private key of the trust property agreement and the signature of the operation record table.
Citation Information
Patent Citations
Digital asset management system, information processing system, and management system
JP2020058008A
Program, information processing method, information processing device and information processing system
JP2020086723A
Program, information processing method, and information processing system
JP2020109712A