PROGRAM, INFORMATION PROCESSING APPARATUS AND INFORMATION PROCESSING METHOD

The system ensures the legitimacy of data processing processes by issuing electronic certificates for pre-processing, post-processing data, and history information, addressing the lack of process legitimacy in conventional digital certificate technologies.

JP7768515B2Active Publication Date: 2025-11-12JCB CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023107335
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-06-29
Publication Date
2025-11-12
Estimated Expiration
2043-06-29

AI Technical Summary

Technical Problem

Conventional digital certificate technologies do not guarantee the legitimacy of data processing processes, such as who generated the data and how it was processed.

Method used

A system that includes a management device to acquire, issue, and provide electronic certificates certifying the combination of pre-processing, post-processing data, and history information, ensuring legitimacy through digital certificates.

Benefits of technology

Guarantees the legitimacy of data processing processes by providing electronic certificates that validate the data processing chain.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007768515000001
    Figure 0007768515000001
  • Figure 0007768515000002
    Figure 0007768515000002
  • Figure 0007768515000003
    Figure 0007768515000003
Patent Text Reader

Abstract

To provide a program capable of guaranteeing the validity of a data processing process, an information processing device and an information processing method.SOLUTION: A program makes a computer achieve an acquisition function for acquiring first unprocessed data of first data processing executed by a first user and first processed data of the first data processing, an issuance function for issuing a first electronic certificate for proving a combination of the first unprocessed data and the first processed data, and a provision function for providing a second user different from the first user with the first electronic certificate.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a program, an information processing device, and an information processing method. [Background technology]

[0002] In recent years, technologies related to digital certificates that certify the legitimacy of data (including, for example, the validity and authenticity of data) have become known. For example, Patent Document 1 discloses a method of generating a digital signature based on a generated document and issuing a digital certificate including this digital signature as a digital certificate that certifies the legitimacy (authenticity) of the document. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] International Publication No. 2022 / 220062 Summary of the Invention [Problem to be solved by the invention]

[0004] Incidentally, value can be found not only in the data itself but also in the process of data processing (hereinafter also referred to as "processing process"), such as in the so-called process economy, where value can be found in who generated the data, and who subsequently processed it, when, where, and how. However, the above-mentioned conventional technology cannot guarantee the legitimacy of such data processing processes.

[0005] Therefore, an object of the present invention is to provide a program, an information processing device, and an information processing method that can ensure the validity of the data processing process. [Means for solving the problem]

[0006] A program according to one embodiment of the present invention causes a computer to realize an acquisition function for acquiring first pre-processing data of a first data processing executed by a first user and first post-processing data of the first data processing, an issuance function for issuing a first electronic certificate that certifies the combination of the first pre-processing data and the first post-processing data, and a provision function for providing the first electronic certificate to a second user different from the first user.

[0007] A program according to one embodiment of the present invention causes a computer to realize an acquisition function that acquires first pre-processing data and / or first post-processing data of a first data processing executed by a first user, and first history information regarding the history of the first data processing, an issuance function that issues a first electronic certificate that certifies the combination of the first pre-processing data and / or the first post-processing data and the first history information, and a provision function that provides the first electronic certificate to a second user different from the first user.

[0008] An information processing device according to one embodiment of the present invention includes an acquisition unit that acquires first pre-processing data of a first data processing executed by a first user and first post-processing data of the first data processing, an issuance unit that issues a first electronic certificate that certifies the combination of the first pre-processing data and the first post-processing data, and a provision unit that provides the first electronic certificate to a second user different from the first user.

[0009] An information processing device according to one embodiment of the present invention includes an acquisition unit that acquires first pre-processing data and / or first post-processing data of a first data processing executed by a first user, and first history information relating to the history of the first data processing, an issuance unit that issues a first electronic certificate that certifies the combination of the first pre-processing data and / or the first post-processing data and the first history information, and a provision function that provides the first electronic certificate to a second user different from the first user.

[0010] An information processing method according to one embodiment of the present invention includes a computer acquiring first pre-processing data for a first data processing executed by a first user and first processed data for the first data processing, issuing a first electronic certificate that certifies the combination of the first pre-processing data and the first processed data, and providing the first electronic certificate to a second user different from the first user.

[0011] An information processing method according to one embodiment of the present invention comprises a computer acquiring first pre-processing data and / or first post-processing data of a first data processing executed by a first user, and first history information relating to the history of the first data processing, issuing a first electronic certificate that certifies the combination of the first pre-processing data and / or first post-processing data and the first history information, and providing the first electronic certificate to a second user different from the first user. [Effects of the Invention]

[0012] According to the present invention, it is possible to guarantee the legitimacy of the data processing process. [Brief explanation of the drawings]

[0013] [Figure 1] 1 is a diagram illustrating an example of the system configuration of a data processing and recording system according to an embodiment of the present invention. [Figure 2] 1 is a diagram illustrating an example of an overview of a data processing and recording system according to an embodiment of the present invention. [Figure 3] 1 is a diagram illustrating an example of an overview of a data processing and recording system according to an embodiment of the present invention. [Figure 4] FIG. 2 is a diagram illustrating an example of a functional configuration of a management device according to the present embodiment. [Figure 5] FIG. 10 is a diagram illustrating an example of the operation of the management device according to the present embodiment. [Figure 6] FIG. 2 is a diagram illustrating an example of a hardware configuration of a management apparatus according to the present embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0014] A preferred embodiment of the present invention (hereinafter referred to as "the present embodiment") will be described with reference to the accompanying drawings. In the drawings, components with the same reference numerals have the same or similar configurations.

[0015] In this invention, the terms "unit," "means," "device," or "system" do not simply mean physical means, but also include cases where the functions of the "unit," "means," "device," or "system" are realized by software. Furthermore, the functions of one "unit," "means," "device," or "system" may be realized by a combination of two or more physical means, devices, or software modules, and the functions of two or more "units," "means," "device," or "system" may be realized by one physical means, device, or software module.

[0016] The data processing and recording system 1 according to this embodiment is a system for recording the process of data processing up to now (hereinafter also referred to as "processing process") and providing the record in response to a user's request, etc. In other words, the data processing and recording system 1 discloses to the outside world under certain conditions (or unconditionally) the processing process, such as who generated the data and who subsequently processed it, when, where, and how.

[0017] Specifically, data processing may include generating data, acquiring data (including referencing and / or copying), registering data (including storing in a memory unit), updating data by processing, providing data (including outputting, displaying, and / or transmitting to other devices), etc.

[0018] The data according to this embodiment is assumed to be various types of data, and may be, for example, still images, moving images, audio data, text data (including source code, for example), programs, and the like.

[0019] <1. System configuration> An example of the system configuration of a data processing and recording system 1 according to this embodiment will be described with reference to Fig. 1. As shown in Fig. 1, the data processing and recording system 1 includes a management device 100, a first user device 200a, a second user device 200b, and a handling carrier device 300. The first user device 200a and the second user device 200b are also collectively referred to as "user devices 200."

[0020] The management device 100 is communicably connected to the user device 200 and the agent device 300 via a network N to exchange data, pre- and post-processing data (described later), history information, and / or digital certificates between these devices. The management device 100 may also be communicably connected to other external devices, such as a certification authority device 400 of an external system 4, via the network N.

[0021] The network N is configured by a wireless network or a wired network. Examples of the network include a mobile phone network, a PHS (Personal Handy-phone System) network, a wireless LAN (a local area network, including communication conforming to IEEE802.11 (so-called WI / Fi (registered trademark))), 3G (3rd Generation), LTE (Long Term Evolution), 4G (4th Generation), 5G (5th Generation), WiMax (registered trademark), infrared communication, visible light communication, Bluetooth (registered trademark), a wired LAN, a telephone line, a power line communication network, a network conforming to IEEE1394, etc.

[0022] The management device 100 is an information processing device for providing a service (hereinafter referred to as a "processing record providing service") that enables the provision of information recorded regarding the data processing process (hereinafter also referred to as "processing record information"). By executing a predetermined program, the management device 100 realizes a server function that provides users with processing record information acquired from the user device 200 or the handling provider device 300 or issued by its own device, and a digital certificate for the processing record information (hereinafter also simply referred to as a "digital certificate").

[0023] The processing record information may be, for example, data before processing of a data processing such as the first data processing or the second data processing (hereinafter also referred to as "pre-processing data"), data after processing of the data processing (hereinafter also referred to as "post-processing data"), or history information related to the history of the data processing. The pre-processing data and post-processing data are also collectively referred to as "pre- and post-processing data." The pre- and post-processing data may be, for example, a copy of all or part of the data on which processing has been performed. The processing record information may also be a combination of these data.

[0024] The first data processing is a data processing executed by the first user. The second data processing is a processing executed by the first user and is a processing subsequent to the first data processing. The data to be processed by the second data processing has a certain relationship, such as continuity, with the data to be processed by the first data processing. For example, the pre-processing data of the second data processing may be the same data as the post-processing data of the first data processing, or may be updated data of the post-processing data of the first data processing.

[0025] The second data processing may be, for example, the following processing in response to the first data processing. A series of actions performed by a user that are included in the same transaction - Processing that has a certain continuity (e.g., performed subsequent to the first data processing)

[0026] For example, when the history information indicates the history of the first data processing, it may include user identification information for identifying the first user. According to this configuration, for example, the user identification information itself or information that can identify the second user using the user identification information can be extracted from the user information, etc., and provided to the second user. This allows the second user to confirm which user performed the data processing. Furthermore, the history information may be, for example, a log output when the data processing is performed.

[0027] For example, when acquiring the processing record information, the management device 100 may use an API (Application Programming Interface) provided by the user device 200 and / or the handling business device 300. Furthermore, the management device 100 may provide the user device 200 with an API for providing the processing record information and / or the digital certificate. The user device 200 may acquire the processing record information, etc., using this API. Such cooperation between devices (in other words, external I / F) may be realized using an SDK (Software Development Kit) for the data processing recording system 1 that includes such an API.

[0028] The user device 200 is an information processing device used by a user, such as a terminal device such as a smartphone, laptop, or tablet. By executing a predetermined program, the user device 200 connects to the management device 100 and / or the handling company device 300 to send and receive processing record information and the like, and accepts request inputs from the user. Note that this predetermined program may be, for example, a web browser that is included as standard in the user device 200, or an application program dedicated to the data processing record system 1 installed on the user device 200.

[0029] A user is a person who uses the data processing recording system 1, and may be, for example, a data owner, a data user, a data manager (administrator), a business providing a processing record providing service (including an employee), or the like. In this embodiment, an example will be described in which the business providing the processing record providing service is the administrator of the management device 100. A user may also be identified by, for example, a user account (a combination of a user ID and a password) for the processing record providing service or a service provided by the business. Hereinafter, a user who is a processor who has executed data processing (i.e., a user who has instructed the execution) will also be referred to as a "first user." Hereinafter, a user different from the first user (for example, a third-party user who wants to inquire about the processing record information of the data processing) will also be referred to as a "second user."

[0030] The handling business device 300 is an information processing device that processes data and is used by a business that handles the data to be processed (hereinafter also referred to as "handling business"). The handling business may be a user of the data processing recording system 1. In this case, the handling business device 300 may also serve as the user device 200. The handling business may be, for example, an operator that operates a platform for a virtual space such as a metaverse or a game, or an operator that operates various sites such as an e-commerce site.

[0031] The certification authority device 400 is a device of a certification authority (for example, a government or trusted third party) that can issue a digital certificate for a user's digital signature. The certification authority may be a public or private institution, and may be, for example, a trusted third party such as a TTP (Trusted Third Party) or a Certification Authority (CA).

[0032] <2. Overview> An example of the outline of the data processing and recording system 1 will be described with reference to Fig. 2. In the example of Fig. 2, an example will be described in which the processing target is image data. Note that in this example, an example will be described in which the same handling service provider device 300 executes the first data processing and the second data processing, but the device that executes the data processing is not limited to this. For example, the first user device 200a may execute the data processing locally, or multiple different handling service provider devices 300 may execute the first data processing and the second data processing, respectively.

[0033] (1) As shown in FIG. 2, the first A user (one embodiment of the first user) instructs the handling provider device 300 to process image data D (one embodiment of the first pre-processed data) as the first data processing from the first user device 200a1 (one embodiment of the first user device 200a).

[0034] (2) Upon receiving this instruction, the handling business device 300 registers the unprocessed image data D in the management device 100 as first processing record information of the first data processing before executing the processing process on the image data D. As another example of the timing of registering the unprocessed image data D, the first user device 200a1 may register the unprocessed image data D stored in its own device as a backup after executing the processing process.

[0035] (3) Upon receiving the instruction from the first A user, the handling company device 300 executes a processing process on the image data D as the first data processing.

[0036] (4) After executing the processing, the handling business device 300 registers the processed image data D2 (one aspect of the first processed data) and a log indicating the processing history of the processing (one aspect of the first history information) as first processing record information of the first data processing in the management device 100. In addition, at this time, the first processing record information may include a user ID (one aspect of user identification information) indicating that the person who processed the processing is the firstA user.

[0037] (5) The management device 100 issues a first digital certificate for the registered first processing record information. The first digital certificate is, for example, information for verifying the legitimacy of the first processing record information. This legitimacy may be, for example, the validity of the first processing record information, the completeness of the first processing record information, and / or the authenticity of the registered processor (first A user) and / or the first processing record information. The management device 100 may also combine the first pre-processing data, the first post-processing data, and / or the first history information, which are the first processing record information. The management device 100 may issue a digital certificate for this combination. (6) The management device 100 associates this combination with the first digital certificate and registers them in the storage unit 130.

[0038] (7) The management device 100 receives a request for a query of the first processing record information and / or the first digital certificate from the second user device 200b of the second user. When the management device 100 receives this query request, it provides the second user with the first processing record information and / or the first digital certificate to be queried via the second user device 200b. This allows the second user to confirm that the image data D1 has been processed by the first A user to become the image data D2. Furthermore, the management device 100 can guarantee the legitimacy of this to the second user using the first digital certificate.

[0039] (8) The first B user (one aspect of the first user) instructs the handling company device 300, from the first user device 200a2 (one aspect of the first user device 200a), to process the image data D2 (one aspect of the data before the second processing) as the second data processing subsequent to the first data processing. The processes (9) to (11) related to this second data processing are similar to the above (2) to (4), and therefore will not be described here.

[0040] (12) The management device 100 issues a second electronic certificate for the registered second processing record information and information for associating the first data processing with the second data processing (hereinafter also referred to as "associated information"). In this example, the associated information is a serial number assigned to each of the first data processing and the second data processing. The process (13) related to the second data processing is the same as (6) above, so a description thereof will be omitted.

[0041] (14) The management device 100 receives a request for a query for the second processing record information and / or the second electronic certificate from the second user device 200b of the second user. Upon receiving this query request, the management device 100 provides the second user with the second processing record information and / or the second electronic certificate via the second user device 200b. This allows the second user to confirm that the image data D2 has been processed by the first B user to become image data D3. Furthermore, the management device 100 can ensure the legitimacy of this information to the second user using the second electronic certificate. Furthermore, in response to the query request from the second user, the management device 100 may provide the second user with the first processing record information and / or the first electronic certificate of the first data processing preceding the second data processing, along with the second processing record information.

[0042] With the above configuration, the second user can check the processing record information of the data processing while ensuring the legitimacy of the processing record information to a certain extent. Therefore, the data processing and recording system 1 can guarantee the legitimacy of the data processing process.

[0043] In this example, the data processing to be recorded and / or certified is data manipulation, but this is not intended to limit the data processing in the data processing recording system 1. The data processing may be at least one of the following processes (A) to (C), such as (A) the first user device 200a acquiring first data, (B) registering the acquired first data in a storage unit of its own device, and (C) transmitting the registered first data to the second user device 200b, in response to an instruction from a first A user who is the processor.

[0044] Referring to FIG. 3, the processing of each functional unit of the management device 100 will be described. <A1) Handler Registration> (0-1) As shown in FIG. 3, as a pre-registration of the handling business operator, the acquisition unit 111 of the management device 100 acquires the handling business operator information from the handling business operator device 300 of the handling business operator and registers it in the storage unit 130.

[0045] The handling business operator information is information regarding the handling business operator. The handling business operator information may include, for example, name, address, and / or email address, etc. as attribute information when the handling business operator is an individual. Also, the handling business operator information may include, for example, corporate name, trade name, location, contact information, and / or information regarding the corporate website (e.g., URL, etc.) as attribute information when the handling business operator is a corporation. Further, the handling business operator information may include, for example, the type of data to be handled (e.g., still image, video, text, program, etc.).

[0046] <A2) Processor Registration> (0-2) As a pre-registration of the first user who is a processor, the acquisition unit 111 of the management device 100 acquires the user information of the first user from the first user device 200a of the first user and registers it in the storage unit 130.

[0047] The user information is information regarding the user. The user information may include information regarding the user account such as the user identification information (user ID) and the corresponding password. Also, the user information may include, for example, name, address, and / or email address, etc. as attribute information when the user is an individual. Also, the user information may include, for example, corporate name, trade name, location, contact information, and / or information regarding the corporate website as attribute information when the user is a corporation (or its employee). Further, the user information may include the device information of the user device 200 used by the user.

[0048] User information is, for example, information related to user identification. In addition to the user's name, address, and contact information, it may also include information related to the user's My Number card used for identification, and / or information related to the user's driver's license used for identification, etc.

[0049] User information may include, for example, as information used for user authentication, the user's possession information (information identifying the possessions held by the user, and / or location information indicating the location of the possessions, etc.), biometric information (for example, the user's face, fingerprint, palm print, voiceprint, and / or iris, etc.), and / or memory information (for example, password or PIN code, etc.).

[0050] Device information may include device identification information, product name, MAC address, IP address, and / or manufacturing number, etc. for identifying various devices such as the user device 200.

[0051] <A3) Data Registration> (1) The acquisition unit 111 of the management device 100 acquires pre-processed data and / or post-processed data of data processing from the first user device 200a of the first user or the handling business operator device 300, and registers it in the storage unit 130.

[0052] <B1) History Recording> (2) The acquisition unit 111 of the management device 100 acquires history information indicating the history of data processing from the first user device 200a or the handling business operator device 300, and registers it in the storage unit 130. At this time, the acquisition unit 111 may generate history information indicating the processing history of the acquisition of pre-processed data, post-processed data, and / or history information as processing record information, and record it in the storage unit 130.

[0053] (3) The generation unit 114 of the management device 100 may generate processing content information indicating the content of the executed data processing, and record it in the storage unit 130, for example, instead of (or in addition to complementarily) the history information acquired from the first user device 200a or the handling business operator device 300. Also, for example, when the first user has successfully authenticated with the user authentication via the first user device 200a and provided the pre-processing and post-processing data and the history information to the management device 100 as processing record information, the authentication unit 118 of the management device 100 may generate history information of this user authentication processing history (including the result of user authentication).

[0054] <B2) Certificate Issuance> (4) The issuance unit 113 of the management device 100 issues an electronic certificate that proves at least any one of the following combinations. The issuance unit 113 registers the issued electronic certificate in the storage unit 130 in association with the corresponding processing record information (in other words, the processing record information to be proved). · The combination of pre-processing data and post-processing data · The combination of pre-processing data and / or post-processing data and the history information of data processing

[0055] (5) The provision unit 116 of the management device 100 provides the electronic certificate issued in (4) above to the first user via the first user device 200a.

[0056] <B3) Certificate Verification> (6) The acquisition unit 111 of the management device 100 acquires a verification request for an electronic certificate of the processing record information of data processing from the second user device 200b of the second user. The electronic certificate to be verified may be, for example, an electronic certificate that the management device 100 has provided to a user such as the second user in the past, or an electronic certificate registered in the storage unit 130. In the former case, the electronic certificate provided in the past may be included in the verification request.

[0057] (7) The verification unit 115 of the management device 100 verifies the electronic certificate required in (6) above. (8) The verification unit 115 provides the verification result information indicating the result of this verification to the second user via the second user device 200b.

[0058] <B4) Inquiry> (9) The acquisition unit 111 of the management device 100 acquires, as an inquiry of the processing record, a request for providing the processing record information of the data processing and / or its electronic certificate from the second user device 200b of the second user.

[0059] (10) The providing unit 116 of the management device 100 provides the processing record information and / or the electronic certificate required in (6) above to the second user via the second user device 200b.

[0060] Under the above configuration, the second user can confirm this processing record information and can also ensure the validity of the electronic certificate of the processing record information to a certain extent. Therefore, the data processing record system 1 can ensure the validity of the data processing process.

[0061] <3. Functional Configuration> Referring to FIG. 4, the functional configuration of the management device 100 according to the present embodiment will be described. As shown in FIG. 4, the management device 100 includes a control unit 110, a communication unit 120, and a storage unit 130.

[0062] The control unit 110 includes an acquisition unit 111, an issuance unit 113, and a providing unit 116. Further, the control unit 110 may include, for example, an identification unit 112, a generation unit 114, a verification unit 115, a providing unit 116, an identity confirmation unit 117, and / or an authentication unit 118.

[0063] [Acquisition Unit] The acquisition unit 111 acquires various data (including various instructions and requests from the user) from the user device 200 and / or the handling provider device 300, etc. The acquisition unit 111 may acquire various data in any manner. For example, the acquisition unit 111 may receive a data file indicating pre- and post-processing data or history information from the user device 200 or the handling provider device 300 in an event-driven manner or periodically in response to a provision request from the acquisition unit 111 or the first user device 200a. For example, the acquisition unit 111 may instruct an API or SDK library implemented in the handling provider device 300 to refer to the pre- and post-processing data or history information as an information query, and acquire these data as a result.

[0064] The acquiring unit 111 acquires first pre-processing data of a first data processing executed by a first user and first post-processing data of the first data processing. The acquiring unit 111 may also acquire, for example, second post-processing data of a second data processing subsequent to the first data processing and second history information relating to the history of the second data processing.

[0065] For example, when an encryption key of a user such as an administrator or processor is leaked, the acquiring unit 111 may acquire a revocation request for an electronic certificate issued using this encryption key from the user device 200 of this user. When acquiring this revocation request, the acquiring unit 111 may register the requested electronic certificate (or an electronic signature encrypted with the encryption key included in the electronic certificate) in a certificate revocation list (so-called CRL: Certificate Revocation List).

[0066] For example, the acquiring unit 111 may acquire the digital signature generated by the issuing unit 113 from the storage unit 130. As another example, the acquiring unit 111 may acquire the digital signature of a user, such as an administrator or a processor, from the user device 200 of the user. The digital certificate may include information (for example, user key information, etc.) for proving the validity of the digital signature acquired in this manner.

[0067] The acquiring unit 111 may, for example, acquire the portions of the pre-processing data and the post-processing data identified by the identifying unit 112. If history information is used for this identification, the acquiring unit 111 needs to acquire this history information prior to acquiring the pre-processing and post-processing data.

[0068] For example, when acquiring the first processed data from the user device 200 or the handling provider device 300, the acquiring unit 111 may determine consistency with the first pre-processed data provided by these devices. The acquiring unit 111 may acquire the first processed data based on the result of this determination. For example, if there is a discrepancy in file format between the pre-processed and post-processed data (for example, a JPEG file and a TXT file), the acquiring unit 111 may determine that the data are inconsistent.

[0069] [Specific part] The identification unit 112 identifies the portions of the pre-processing data and the post-processing data that are the target of data processing. The identification unit 112 may identify the portions that are the target of processing, for example, based on history information corresponding to the pre- and post-processing data to be identified. Alternatively, the identification unit 112 may extract feature amounts of the pre- and post-processing data to be identified, and identify the portions that are the target of processing, for each of the pre-processing data and the post-processing data, based on the extracted feature amounts.

[0070] [Publishing Department] The issuing unit 113 acts as a so-called private CA and issues a digital certificate that certifies a combination of processing record information. The issuing unit 113 may register this issued digital certificate in the storage unit 130. Furthermore, the issuing unit 113 may, for example, assign a serial number generated by the generation unit 114 to the digital certificate it issues. In this case, the issuing unit 113 may include the assigned serial number in the digital certificate.

[0071] The issuing unit 113 may generate a digital signature of the user based on the processing record information, for example. The issuing unit 113 may register the generated digital signature in the storage unit 130. Specifically, the issuing unit 113 may generate a hash value of all or part of the combination of the processing record information. The issuing unit 113 may encrypt the generated hash value using key information to generate a digital signature. The issuing unit 113 may include the generated digital signature in a digital certificate.

[0072] The key information is, for example, information about the encryption key of a user such as an administrator or processor. The key information may not be the encryption key itself, but may be a token that has the authority to use the encryption key. The encryption key may be, for example, a common key in a common key cryptosystem, or a pair of a public key and a private key in a public key cryptosystem. When encrypting a digital signature, the private key of the first user or administrator is used as the key information. In this case, the digital certificate may include a public key that is paired with the encrypted private key.

[0073] For example, when using a public key cryptography method as described above, the issuing unit 113 may issue an electronic certificate based on X.509, which is the standard for the public key infrastructure (PKI) of the ITU-T (International Telecommunication Union-Telecommunication sector).

[0074] For example, the issuing unit 113 may generate a hash value of all or part of the digital certificate. The issuing unit 113 may encrypt the generated hash value using key information of a user such as an administrator, and use the encrypted value as the digital signature of the user.

[0075] The issuing unit 113 may issue a first digital certificate that certifies, for example, the combination of the first pre-processing data and the first post-processing data. The issuing unit 113 may also issue a first digital certificate that certifies, for example, the combination of the first pre-processing data and / or the first post-processing data and the first history information.

[0076] The issuing unit 113 may, for example, set an expiration date for the issued digital certificate. The issuing unit 113 may include the set expiration date in the digital certificate. The issuing unit 113 may set the expiration date of the digital certificate based on, for example, the type of data before and after processing to be certified, user authentication result information, and / or user identity verification result information.

[0077] As another example, the issuing unit 113 may request the authentication device to issue a digital certificate for processing record information (e.g., information generated by the device itself, such as history information regarding acquisition of data before and after data processing), rather than issuing a digital certificate by itself. The issuing unit 113 may, for example, obtain a digital certificate issued by the authentication authority system from the authentication authority system in response to this issuance request.

[0078] The issuing unit 113 may issue, for example, an electronic certificate (hereinafter also referred to as a "combined electronic certificate") that certifies the combination of the first pre-processing data and / or the second post-processing data, the first history information, and the second history information.

[0079] The issuing unit 113 may issue a second digital certificate that certifies, for example, the combination of the second pre-processing data and / or the second post-processing data with the second history information.

[0080] The issuing unit 113 may issue, for example, a digital certificate that certifies the combination of the portions of the pre-processing data and the post-processing data identified by the identifying unit 112. The issuing unit 113 may, for example, extract the identified portions from the pre-processing data and the post-processing data registered in the storage unit 130 and generate a hash value of the combination of the extracted portions. The issuing unit 113 may encrypt the hash value thus generated using key information, generate a digital signature, and include the digital signature in the digital certificate. This configuration makes it possible to narrow down the objects to be certified, and efficiently ensure the legitimacy of the processing process.

[0081] [Generation part] The generation unit 114 generates various data in response to a user request or the like. The generation unit 114 generates association information indicating the association between the first data processing and the second data processing, and indicating that the second data processing follows the first data processing. For example, the generation unit 114 may generate and assign a serial number to each digital certificate issued by the issuing unit 113 as the association information. The first digital certificate and / or the second digital certificate issued by the issuing unit 113 may include, for example, this generated association information. With this configuration, the digital certificate can include information indicating the association between the first digital certificate and the second digital certificate.

[0082] The generating unit 114 may generate processing content information indicating the content of the executed data processing, for example. The generating unit 114 may identify a difference between the pre-processing data and the post-processing data, and use the identified difference as the content of the data processing (in other words, the processing steps of the data processing).

[0083] [Verification Department] The verification unit 115 verifies the digital certificate in response to a request from a user, etc. Specifically, the verification unit 115 may determine the presence or absence and / or degree of legitimacy of the digital certificate (e.g., the authenticity and / or validity of the digital certificate). The verification unit 115 may, for example, obtain key information for the digital signature and verify the digital signature using the obtained key information. For example, if the digital signature is a hash value of the digital certificate, the verification unit 115 may decrypt the digital signature using a public key and compare the decrypted digital signature with the hash value of the digital certificate. By verifying the digital signature in this manner, the integrity of the digital certificate and the authenticity of the issuer of the digital certificate (e.g., an administrator or a certification authority) may be ensured.

[0084] For example, if the digital signature included in the digital certificate is a hash value of the processing record information, the verification unit 115 may decrypt the digital signature using an encryption key and compare the decrypted digital signature with the hash value of the processing record information. By performing verification in this manner, the integrity of the processing record information that the digital certificate is to certify and the authenticity of the issuer of the digital certificate may be ensured.

[0085] The verification unit 115 may verify the validity of the electronic certificate based on, for example, revocation list information indicating a certificate revocation list or the expiration date included in the electronic certificate.

[0086] The verification unit 115 may provide the second user with information for verifying the digital certificate (e.g., key information of the public key of the user who is the administrator or processor), and the second user may verify the digital certificate by himself / herself using the second user device 200b based on the provided information.

[0087] [Provider] The providing unit 116 provides various data to the user device 200 and the like. The providing unit 116 may provide various data in any manner. For example, the providing unit 116 may send a data file or a message including pre- and post-processing data, history information, and / or a digital certificate to these devices in an event-driven manner. As another example, the providing unit 116 may provide these data to the user device 200 and the like via an API or SDK library implemented by the providing unit 116 itself.

[0088] The providing unit 116 provides the first digital certificate issued by the issuing unit 113 to the second user via the second user device 200b or the like.

[0089] According to the above configuration, the providing unit 116 can provide the second user with a digital certificate for certifying the legitimacy of the processing record information of the data processing. Therefore, the data processing recording system 1 can ensure the legitimacy of the data processing process.

[0090] For example, the providing unit 116 may provide the combined digital certificate issued by the issuing unit 113 to the second user via the second user device 200b or the like.

[0091] According to the above configuration, the providing unit 116 can provide the second user with a digital certificate for collectively verifying the legitimacy of the processing record information of the second data processing that has a certain continuity with the first data processing. Therefore, the data processing recording system 1 can guarantee the legitimacy of the processing steps of multiple data processings.

[0092] For example, the providing unit 116 may provide the second digital certificate issued by the issuing unit 113 in association with the first digital certificate to the second user via the second user device 200b or the like.

[0093] According to the above configuration, the providing unit 116 can provide the second user with a second electronic certificate that certifies the legitimacy of the processing record information of the second data processing that has a certain continuity with the first data processing, in association with the first electronic certificate. This makes it possible for the data processing recording system 1 to guarantee the legitimacy of a series of multiple data processing steps.

[0094] For example, the providing unit 116 may provide verification result information indicating the result of the verification by the verifying unit 115 to the second user via the second user device 200b or the like.

[0095] According to the above configuration, the providing unit 116 can provide the second user with the result of verifying the legitimacy of the digital certificate. This makes it possible for the data processing and recording system 1 to guarantee the legitimacy of the digital certificate.

[0096] For example, the providing unit 116 may provide the digital signature acquired by the acquiring unit 111 to the second user in association with a digital certificate that includes information for verifying the validity of the digital signature.

[0097] [Identity Verification Department] The identity verification unit 117 verifies the identity of the user based on the user information. This identity verification electronically verifies the authenticity of the user being a real person (so-called eKYC), and may be, for example, identity proofing specified by NIST (National Institute of Standards and Technology) SP 800-63-3.

[0098] The identity verification unit 117 may generate, as the processing record information, history information relating to the identity verification processing history, including identity verification result information indicating the result of the identity verification of the user. The identity verification unit 117 may register this generated history information in the storage unit 130.

[0099] [Authentication section] The authentication unit 118 performs user authentication one or more times in response to the authentication request acquired by the acquisition unit 111. Performing user authentication multiple times may mean, for example, performing multi-factor authentication such as two-factor authentication using multiple authentication factors, or performing multi-stage authentication such as two-stage authentication performing authentication in stages. As another example, performing user authentication multiple times may mean performing two or more authentications with different authentication levels.

[0100] The user authentication may be, for example, authentication defined by NIST SP 800-63-3. The authentication level applied to the user authentication may be, for example, AAL (Authenticator Assurance Level) defined by NIST SP 800-63B as follows: Level 1: One or more of the three authentication factors (knowledge, possession, and biometrics) must be used, and there is a certain degree of confidence in the person's authentication. In other words, this can be achieved by performing at least single-factor authentication. Level 2: Of the three factors, multiple factors such as ID password + one-time password must be used, and there is a high degree of reliability in authenticating the person. Unlike Level 3, Level 2 can be achieved by using software as the second authentication factor. Level 3: Two-factor authentication, where the second factor must be tamper-resistant hardware and the authenticity of the person must be very high (e.g., PIN code + IC chip card + My Number card).

[0101] The authentication unit 118 may generate, as the processing record information, history information relating to the processing history of the user authentication, including authentication result information indicating the result of the user authentication. The authentication unit 118 may register this generated history information in the storage unit 130.

[0102] [Communications Department] The communication unit 120 transmits and receives various data to and from the user device 200, the agent device 300, and / or other devices of the external system 4 via the network N.

[0103] [Storage] The storage unit 130 stores processing record information (pre- and post-processing data and history information), digital certificates, and / or user information. The storage unit 130 may use a database management system (DBMS) to store each piece of data, or may use a file system to store each piece of information. When a DBMS is used, the storage unit 130 may provide a table for each piece of data, and manage these pieces of data by associating the tables with each other.

[0104] <4. Example of operation> An example of the operation of the management device 100 will be described with reference to Fig. 5. Fig. 5(a) is a flow diagram showing the flow of processing in the management device 100 from acquiring processing record information to registering it in the storage unit 130. Fig. 5(b) is a flow diagram showing the flow of processing from acquiring a request to provide processing record information, etc. from the second user to providing the requested information. Note that the order of processing shown below is an example and may be changed as appropriate.

[0105] 5(a), the acquisition unit 111 of the management device 100 acquires processing record information such as pre- and post-processing data and / or history information (S10). The issuance unit 113 of the management device 100 issues a digital certificate for a combination of the acquired processing record information (S11). The control unit 110 of the management device 100 associates the acquired processing record information with the issued digital certificate and registers them in the storage unit 130 (S12).

[0106] 5(b), the acquisition unit 111 of the management device 100 acquires a provision request from the second user via the second user device 200b, requesting the provision of a combination of processing record information and / or a digital certificate (S20). The provision unit 116 of the management device 100 provides the requested combination of processing record information and / or a digital certificate to the second user via the second user device 200b (S21).

[0107] <6. Hardware Configuration> 6, an example of a hardware configuration in which the above-described management device 100 is realized by a computer 800 will be described. Note that the functions of each device can also be realized by dividing them among a plurality of devices.

[0108] As shown in FIG. 6, the computer 800 includes a processor 801, a memory 803, a storage device 805, an input I / F unit 807, a data I / F unit 809, a communication I / F unit 811, and a display device 813.

[0109] The processor 801 controls various processes in the computer 800 by executing programs stored in the memory 803. For example, each functional unit included in the control unit 110 of the management device 100 can be realized by the processor 801 executing a program temporarily stored in the memory 803.

[0110] The memory 803 is a storage medium such as a RAM (Random Access Memory), etc. The memory 803 temporarily stores the program code of the program executed by the processor 801 or data required when the program is executed.

[0111] The storage device 805 is a non-volatile storage medium such as a hard disk drive (HDD) or flash memory. The storage device 805 stores an operating system or various programs for implementing the above-mentioned configurations. In addition, the storage device 805 can also store tables for registering various data such as processing record information, digital certificates, and / or user information, and a DB for managing the tables. Such programs or data are loaded into the memory 803 as needed and can be referenced by the processor 801.

[0112] The input I / F unit 807 is a device for receiving input from a user. Specific examples of the input I / F unit 807 include a keyboard, a mouse, a touch panel, various sensors, and a wearable device. The input I / F unit 807 may be connected to the computer 800 via an interface such as a USB (Universal Serial Bus).

[0113] The data I / F unit 809 is a device for inputting data from outside the computer 800. A specific example of the data I / F unit 809 is a drive device for reading data stored in various storage media. The data I / F unit 809 may be provided outside the computer 800. In this case, the data I / F unit 809 is connected to the computer 800 via an interface such as a USB.

[0114] The communication I / F unit 811 is a device for performing data communication via the Internet N, either wired or wirelessly, with devices external to the computer 800. The communication I / F unit 811 may be provided outside the computer 800. In this case, the communication I / F unit 811 is connected to the computer 800 via an interface such as a USB.

[0115] The display device 813 is a device for displaying various types of information. Specific examples of the display device 813 include a liquid crystal display, an organic EL (Electro-Luminescence) display, and a display of a wearable device. The display device 813 may be provided outside the computer 800. In this case, the display device 813 is connected to the computer 800 via, for example, a display cable. Furthermore, when a touch panel is adopted as the input I / F unit 807, the display device 813 can be configured as an integral part of the input I / F unit 807.

[0116] The above-described embodiments are merely examples for explaining the present invention, and are not intended to limit the present invention to these embodiments. Furthermore, the present invention can be modified in various ways without departing from the spirit of the invention. Furthermore, those skilled in the art can adopt embodiments in which the elements described below are replaced with equivalents, and such embodiments are also within the scope of the present invention.

[0117] [Variations] Although the present invention has been described based on the above embodiment, the following cases are also included in the present invention.

[0118] [Variation 1] At least some of the components included in the management device 100 according to the above embodiment may be included in the user device 200 and / or the dealer device 300. [Explanation of symbols]

[0119] 1...data processing recording system, 100...management device, 110...control unit, 111...acquisition unit, 113...issuance unit, 116...provision unit, 120...communication unit, 130...storage unit, 200...user device, 300...dealer device, 400...certification authority device, 800...computer, 801...processor, 803...memory, 805...storage device, 807...input I / F unit, 809...data I / F unit, 811...communication I / F unit, 813...display device

Claims

1. On the computer, an acquisition function for acquiring first pre-processing data of a first data processing executed by a first user and first post-processing data of the first data processing; an issuing function for issuing a first digital certificate that certifies a combination of the first pre-processing data and the first post-processing data; a providing function for providing the first digital certificate to a second user different from the first user; a verification function for verifying the first digital certificate in response to a request from a user; Realize this, the providing function provides verification result information indicating a result of the verification to the second user. program.

2. On the computer, an acquisition function for acquiring first pre-processing data of a first data processing executed by a first user and / or first post-processing data of the first data processing, and first history information relating to a history of the first data processing; an issuing function for issuing a first digital certificate that certifies a combination of the first pre-processing data and / or the first post-processing data and the first history information; a providing function for providing the first digital certificate to a second user different from the first user; a verification function for verifying the first digital certificate in response to a request from a user; Realize this, the providing function provides verification result information indicating a result of the verification to the second user. program.

3. the first data processing is generation of first data, acquisition of first data, registration of first data, update of first data, or provision of first data; The program according to claim 1 or 2.

4. the first history information includes user identification information for identifying the first user; The program according to claim 2.

5. A computer, an acquisition function that acquires first pre-processing data of a first data processing executed by a first user and / or first post-processing data of the first data processing, and first history information relating to the history of the first data processing, and acquires second post-processing data of a second data processing executed by the first user and subsequent to the first data processing, and second history information relating to the history of the second data processing; an issuing function for issuing a first digital certificate certifying a combination of the first pre-processing data and / or the first post-processing data with the first history information, and for issuing a combined digital certificate certifying a combination of the first pre-processing data and / or the second post-processing data with the first history information and the second history information; a providing function for providing the first digital certificate and the combined digital certificate to a second user different from the first user; To realize program.

6. A computer, an acquisition function for acquiring first pre-processing data of a first data processing executed by a first user and / or first post-processing data of the first data processing, and first history information relating to the history of the first data processing, and for acquiring second post-processing data of a second data processing executed by the first user, which is a second processing on data subsequent to the first data processing, and second history information relating to the history of the second data processing; an issuing function for issuing a first electronic certificate that certifies a combination of the first pre-processing data and / or the first post-processing data with the first history information, and for issuing a second electronic certificate that certifies a combination of the second post-processing data with the second history information; a providing function of providing the first electronic certificate and the second electronic certificate associated with the first electronic certificate to a second user different from the first user; To realize program.

7. A computer, an acquisition function for acquiring first pre-processing data of a first data processing executed by a first user and / or first post-processing data of the first data processing, and first history information relating to the history of the first data processing, and for acquiring second post-processing data of a second data processing executed by the first user, which is a second processing on data subsequent to the first data processing, and second history information relating to the history of the second data processing; an issuing function for issuing a first electronic certificate that certifies a combination of the first pre-processing data and / or the first post-processing data with the first history information, and for issuing a second electronic certificate that certifies a combination of the second post-processing data with the second history information; a providing function of providing the first electronic certificate and the second electronic certificate associated with the first electronic certificate to a second user different from the first user; realizing a generating function of generating association information indicating an association between the first data processing and the second data processing, the association information indicating that the second data processing follows the first data processing; the first digital certificate and / or the second digital certificate includes the related information; The program according to claim 6.

8. the acquiring function acquires a digital signature of the first user generated based on the first pre-processing data and / or the first post-processing data; the first digital certificate includes information for verifying the authenticity of the digital signature; The providing function associates the digital signature with the first digital certificate and provides it to the second user. provide, The program according to claim 1 or 2.

9. A computer, an acquisition function for acquiring first pre-processing data of a first data processing executed by a first user and first post-processing data of the first data processing; an issuing function for issuing a first digital certificate that certifies a combination of the first pre-processing data and the first post-processing data; a providing function for providing the first digital certificate to a second user different from the first user; realizing a specifying function for specifying a portion of the first pre-processing data and the first processed data that has been subjected to the first data processing; the issuing function issues the first digital certificate certifying a combination of the specified portions of the first pre-processing data and the first post-processing data. The program according to claim 1.

10. an acquisition unit that acquires first pre-processing data of a first data processing executed by a first user and first post-processing data of the first data processing; an issuing unit that issues a first digital certificate that certifies a combination of the first pre-processing data and the first post-processing data; a providing unit that provides the first digital certificate to a second user different from the first user; a verification unit that verifies the first digital certificate in response to a request from a user; Preparation, the providing unit provides verification result information indicating a result of the verification to the second user. Information processing device.

11. The computer acquiring first pre-processing data of a first data processing executed by a first user and first processed data of the first data processing; issuing a first digital certificate certifying a combination of the first pre-processing data and the first processed data; providing the first digital certificate to a second user different from the first user; verifying the first digital certificate in response to a request from a user; providing verification result information indicating a result of the verification to the second user; Information processing methods.

12. an acquisition unit that acquires first pre-processing data of a first data processing executed by a first user and / or first post-processing data of the first data processing, and first history information relating to a history of the first data processing; an issuing unit that issues a first digital certificate that certifies a combination of the first pre-processing data and / or the first post-processing data and the first history information; a providing function for providing the first digital certificate to a second user different from the first user; a verification function for verifying the first digital certificate in response to a request from a user; Equipped with the providing function provides verification result information indicating a result of the verification to the second user. Information processing device.

13. The computer acquiring first pre-processing data of a first data processing executed by a first user and / or first post-processing data of the first data processing, and first history information relating to a history of the first data processing; issuing a first digital certificate certifying a combination of the first pre-processing data and / or the first post-processing data with the first history information; providing the first digital certificate to a second user different from the first user; verifying the first digital certificate in response to a request from a user; providing verification result information indicating a result of the verification to the second user; Information processing methods.

Citation Information

Patent Citations

  • Document processing apparatus and document processing program

    JP2009284138A

  • Message processing device, map management device, map company device, and automobile company device

    WO2018207424A1

  • Data transaction device, data transaction system, data transaction method, and non-transitory computer-readable medium

    WO2022123671A1

  • Artwork management method, computer, and program

    WO2022220062A1