Certificate, certificate issuing system, and method for verifying the authenticity of a certificate

The certificate with an IC tag and encrypted HASH values within the IC chip ensures secure, offline verification, addressing vulnerabilities in existing methods by preventing tampering and counterfeiting.

JP7775619B2Active Publication Date: 2025-11-26TOPPAN HOLDINGS INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2021164767
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-10-06
Publication Date
2025-11-26
Estimated Expiration
2041-10-06

AI Technical Summary

Technical Problem

Existing certificate verification methods are vulnerable to counterfeiting and tampering, particularly when using IC tags, due to the need for external devices and the risk of key leakage during encryption, and are difficult to apply to general certificates due to size constraints.

Method used

A certificate with an IC tag containing an IC chip and antenna, storing an encryption key, where data is encrypted and signed within the IC chip, allowing offline verification by comparing printed data with stored data using a HASH value and public key cryptosystem.

Benefits of technology

Enables secure, offline verification of certificate authenticity by comparing encrypted and signed HASH values, preventing tampering and counterfeiting without external devices, enhancing security with public key cryptosystems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007775619000001
    Figure 0007775619000001
  • Figure 0007775619000002
    Figure 0007775619000002
  • Figure 0007775619000003
    Figure 0007775619000003
Patent Text Reader

Abstract

To provide certificates, a certificate issuing system, and a method for confirming validity of the certificates that can prevent forgery or alteration of the certificates, and confirm validity by collating and verifying offline without connecting to an external apparatus such as a server.SOLUTION: A certificate has an information printed portion with predetermined information printed on its surface. An IC tag sticker in which an IC chip that allows data to be electrically read and written and stores an encryption key inside and an antenna connected to the IC chip and for communicating with the outside are sealed in a support is pasted on the surface of the certificate. Data including information printed on the information printed portion and data with a signature obtained by signing and encrypting a HASH value generated from a part or all of the data of information printed on the information printed portion with the encryption key stored in the IC chip is written in a memory of the IC chip.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to certificates such as various certificates, which are effective in preventing counterfeiting and tampering, a certificate issuing system, and a method for verifying the authenticity of certificates. [Background technology]

[0002] In recent years, there has been a study into attaching IC tags with built-in IC chips to various certificates and reading the IC tags electronically to improve the efficiency of verification processes and prevent counterfeiting and tampering. In this case, the information printed and recorded on the certificate is stored in the IC chip of the IC tag, and the information printed on the document is compared with the information stored in the IC chip to verify whether it is a counterfeit.

[0003] For example, Patent Document 1 discloses an admission ticket with a contactless IC attached, which states that information printed on the front of the admission ticket, such as the visitor's name and admission ticket control number, can be written to the IC's information storage unit and electronically read to be used for managing entrance and exit to venues, managing the provision of various services, etc. However, this ticket is still vulnerable to methods such as tampering with the printing or replacing the contactless IC, and improvements were desired.

[0004] In addition to the above, various techniques have been proposed to prevent the counterfeiting of media on which predetermined information is printed, such as certificates and cards. For example, one method involves printing the details of a security on the surface of a credit card-sized card, writing the same details as the details into an IC chip, and verifying that both are identical, thereby detecting counterfeits. However, this method has the same vulnerabilities as the above example, and is difficult to apply to general certificates due to the size constraints of cards.

[0005] Other proposals have included encrypting some or all of the information printed on the surface and printing it separately on the surface while also writing it to an IC chip, or preparing separate verification data, encrypting it, and writing it to the IC chip. However, these have presented problems such as the need to store the encryption key in the encryption device, requiring a separate verification device for decryption, and the risk of the key being leaked if encryption is performed somewhere other than an IC chip. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] Japanese Patent Application Publication No. 11-277963 Summary of the Invention [Problem to be solved by the invention]

[0007] Therefore, an object of the present invention is to provide a certificate, a certificate issuing system, and a method for verifying the authenticity of a certificate, which can prevent counterfeiting or tampering by rewriting print data on the certificate or replacing the IC chip, and which allows for verification and validation offline without connecting to an external device such as a server, by storing all the data necessary for verifying the data on the IC chip and the print data in the IC chip. [Means for solving the problem]

[0008] In order to solve the above problems, the present invention provides: A certificate having an information printing section on which predetermined information is printed, An IC tag seal is made by sealing an IC chip that can electrically read and write data and stores an encryption key inside, and an antenna connected to the IC chip for communicating with the outside, on a support. It is attached to the surface, data including information printed on the information printing unit; A HASH value generated from a part or all of the data of the information printed on the information printing unit is encrypted with an encryption key stored in an IC chip, and the signature data is signed; is written in the memory of the IC chip.

[0009] In the above document, The document may have a code printing section in which the signature data is printed on the surface of the document in the form of a QR code (registered trademark), a barcode, or converted alphanumeric characters.

[0010] In the above document, The encryption key may be signed with a private key of a public key cryptosystem held by the certificate issuing organization and may be usable after being decrypted with the corresponding public key.

[0011] Another aspect of the present invention is A certificate issuing system that issues a certificate having predetermined information printed on its surface, It includes a control PC and a printer with IC chip read / write functions. It is an IC chip that can read and write data electrically and stores an encryption key inside, and a device connected to the IC chip for communicating with the outside. Ta The antenna and the IC tag sticker sealed in the support are attached to the surface of the paper. The printer stores data containing the same information as that to be printed on the surface of the paper in an IC chip, and prints the information to be printed on the surface of the paper; The HASH value generated from part or all of the printed data is encrypted with the encryption key stored on the IC chip and signed. The certificate issuing system is characterized in that the signature data is written into the memory of the IC chip.

[0012] In the above certificate issuing system, The signature data may further be printed on the surface of the document in the form of a QR code, a barcode or converted alphanumeric characters.

[0013] In the above certificate issuing system, The encryption key may be signed with a private key of a public key cryptosystem held by the certificate issuing organization and may be usable after being decrypted with the corresponding public key.

[0014] Another aspect of the present invention is The method of claim 1 includes optically reading the printed data of the information printing section of the certificate, generating a HASH value from a part or all of the information, transmitting the HASH value to the IC tag, encrypting the HASH value with an encryption key stored in the IC chip of the IC tag, and signing the HASH value. Verifying whether the signature is identical to the signature stored in the memory of the IC chip using the IC chip; This is a method for verifying the authenticity of a certificate, characterized in that if the two are identical, the certificate is deemed to be authentic.

[0015] Another aspect of the present invention is The method of claim 2 is to optically read the printed data of the information printing section of the certificate, generate a HASH value from a part or all of the information, transmit the HASH value to the IC tag, encrypt the HASH value with an encryption key stored in the IC chip of the IC tag, and sign the HASH value. The IC chip is used to verify whether the signature, the signature read from the code printed portion of the certificate, and the signature stored in the memory of the IC chip are the same; This is a method for verifying the authenticity of a certificate, characterized in that the certificate is deemed to be authentic when the two are identical.

[0016] In the method for verifying the authenticity of the above documents, The encryption key may be a key that is signed with a private key held by the certificate issuing organization and can be used after decryption with the corresponding public key. [Effects of the Invention]

[0017] According to the present invention, when forgery or alteration is carried out by tampering with the printed data of documents or replacing the IC chip, since all the data necessary for collating the data of the IC chip and the printed data is stored in the IC chip, it is possible to perform collation and verification offline without connecting to an external device such as a server. Thus, documents, a document issuance system, and a method for confirming the validity of documents can be obtained.

Brief Description of the Drawings

[0018] [Figure 1] It is a schematic diagram of one form of the documents of the present invention. [Figure 2] It is a schematic configuration diagram of one form of the document issuance system of the present invention. [Figure 3] It is a flowchart showing an example of the document issuance flow of the present invention. [Figure 4] It is a schematic configuration diagram of a configuration example of a document verification system. [Figure 5] It is a flowchart showing an example of the document verification flow of the present invention. [Figure 6] It is a flowchart showing another example of the document issuance flow of the present invention. [Figure 7] It is a flowchart showing another example of the document verification flow of the present invention.

Embodiments for Carrying Out the Invention

[0019] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. Note that the present invention is not limited to the embodiments described below. Also, in the embodiments shown below, technically preferable limitations are made for carrying out the invention, but this limitation is not an essential requirement of the present invention. Note that "signature" in this specification and the drawings refers to an electronic signature unless otherwise specified.

[0020] <Documents with an IC tag attached> FIG. 1 is a schematic diagram of one form of the certificate of the present invention, specifically a certificate with an IC tag attached. Authenticity of the certificate is important and it is easily counterfeited, such as, but not limited to, securities, vehicle inspection certificates, and various official certificates. The certificate of this embodiment is constructed by attaching an IC tag to a sheet-like certificate body, such as a paper or plastic sheet, which is equipped with an IC chip and antenna storing an encryption key inside and sealed with a sealant, and which is capable of contactless communication with the outside. For this reason, the IC tag is in the form of an IC tag sticker, with an adhesive layer provided on one surface of the IC tag.

[0021] Predetermined text information and the like are printed on the information printing section on the front of the certificate, and information including the printed text information and the like is written as data on the IC chip. In addition to the predetermined text information, the information printing section may also be printed with ruled lines, item name columns, decorations, etc. as needed, for example, to create a table format. To improve the usability of the certificate, the HASH value of the predetermined text information to be printed may be taken, encrypted with an encryption key stored in the IC chip, converted into a QR code (registered trademark), and printed on the code printing section, but printing a QR code (registered trademark) is not required.

[0022] The above configuration will be explained in more detail. A contactless IC tag sticker is affixed to the certificate body, which is a large paper sheet such as A5 or A4 size. The use of a large paper sheet dramatically increases the degree of freedom in the content printed on the information printing section. However, the use of an IC tag sticker raises the risk of forgery, such as by replacing the IC tag sticker or attaching an IC chip to counterfeit paper. Therefore, an issuance system is configured that ensures consistency between the printed content and the data stored in the IC chip.

[0023] <Certificate Issuance System> Figure 2 is a schematic diagram of one embodiment of the certificate issuance system of the present invention. The issuance data server and the certificate issuance system are connected via the Internet or a dedicated line. The certificate issuance system is composed of a certificate printer equipped with a reader / writer that has the function of communicating with IC tags, and a PC for issuance operations that is connected to the Internet or a dedicated line.

[0024] The PC receives the issuance data from the issuance data server and begins the issuance process. First, it writes the specified printing content data for the information printing unit into the memory of the IC chip, and then prints the same content. In this case, the printing data obtained from the certificate issuance data server can be used as is to write it into the memory of the IC chip and print it on the information printing unit, but if greater reliability is required, it is better to read the content that was once written into the memory of the IC chip and print it on the information printing unit.

[0025] Next, a HASH value is calculated using part or all of the printed data. Because the HASH value cannot be decrypted, this is not encryption in the strict sense. The HASH value is sent to the IC chip via a reader / writer, where it is encrypted using the IC chip's encryption key and returned. Alternatively, the HASH value may be encrypted on the PC side without using the IC chip's encryption function. To encrypt on the PC side, for example, the encryption key signed with the private key and the public key stored on the IC chip may be read, the encryption key signed with the public key may be decrypted within the PC, and the resulting encryption key may be encrypted. The encrypted HASH value data is written to the IC chip's memory. As mentioned above, the encrypted HASH value data may also be converted into a barcode such as a QR Code (registered trademark) and printed on the code printing section.

[0026] <Issue flow> Figure 3 shows an example of a flow chart for issuing a certificate. It shows the flow when the HASH value is encrypted on an IC chip. The steps after starting the issuance process are as follows: S101: Issuance data including print data is acquired from an issuance data server. S102: The certificate paper is set in the certificate printer. S103: The encryption key is written to the IC chip of the IC tag on the certificate via the reader / writer on the PC. Set. S104: Similarly, the issuing data is written. S105: The issued data is read again from the IC chip. S106: Print the information printing section on the certificate printer using the print data in the read issuance data. conduct. S107: Calculate a HASH value from the print data. S108: The calculated HASH value is transmitted to the IC chip via the reader / writer. The data is encrypted and signed using the chip's encryption key and sent back to the PC. S109: The signed HASH value is stored in the collation area of ​​the memory of the IC chip. S110: The signed HASH value is converted into a QR code (registered trademark) and printed on the code printing unit. S111: Take out the printed certificate paper. If a QR code (registered trademark) is not to be printed, step S110 is omitted. By following the above procedure, a certificate is issued in which the print data and the encrypted HASH value are stored in the memory of the IC chip in the IC tag.

[0027] <Verifying the authenticity of the documents> To verify the authenticity of an issued certificate, the information printed on the certificate is optically read using OCR, a HASH value is calculated from some or all of the information, and the calculated value is sent to the IC chip in the IC tag via a reader / writer. The IC chip then encrypts and signs the received HASH value. The signed HASH value returned from the IC chip is sent back to the IC chip, and is compared within the IC chip with the signed HASH value recorded in the verification area of ​​the IC chip's memory, thereby verifying that the IC chip has not been swapped or counterfeited.

[0028] Furthermore, if a QR code (registered trademark), for example, is printed in the code printing section, the information printed on the certificate is first optically read using OCR, as described above, and a HASH value is calculated from some or all of that information, which is then sent to the IC chip in the IC tag via a reader / writer. The IC chip then encrypts and signs the received HASH value and returns it to the reader / writer. The QR code (registered trademark) printed in the code printing section is read using a QR code (registered trademark) scanner or similar to restore the signed HASH value, which is then compared with the signed HASH value returned from the IC chip and confirmed to be identical, thereby verifying authenticity. The signed HASH value received from the IC chip can also be sent back to the IC chip and compared internally with the signed HASH value recorded in the verification area of ​​the IC chip's memory, thereby verifying that the IC chip has not been swapped or counterfeited.

[0029] <Verification system> Figure 4 shows a schematic diagram of an example of the configuration of a verification system that verifies the authenticity of certificates. A verification system that verifies the authenticity of certificates can be configured offline, independent of the issuing system and the internet mentioned above. It can be configured with at least a PC, a contactless IC reader / writer, and a scanner (for OCR). If there is a scanner that can read QR Codes (registered trademark), reading the code will be easier, but an OCR scanner can also be used instead. The verification procedure is explained in the verification flow below.

[0030] <Verification flow> The verification procedure will be explained according to the verification flow shown in Figure 5. After the verification starts, S201: The print data of the information printing section on the printed side of the certificate is read by a scanner. If a QR code (registered trademark) or similar is printed on the card, it can also be read using a scanner or a QR code (registered trademark) scanner. S202: A HASH value is calculated from the print data of the read information print section. S203: The HASH value is sent to the IC chip of the IC tag by the contactless IC reader / writer. Encrypt and sign using an IC chip. S204: Convert the QR code (registered trademark) printed on the code into signature data, encrypt it with the IC chip, and Compare with the signed HASH value. S205: If both are identical, proceed to S206. If they do not match, a verification error occurs. If a QR code (registered trademark) or the like is not printed in the code printing section, steps S204 and S205 are omitted. S206: The signed HASH value stored in the verification area of ​​the memory of the IC chip and compare it with the HASH value that is generated from the print data, encrypted, and signed. S207: If both are the same, go to S208. If they do not match, a verification error occurs. S208: Verification is completed as the certificate is deemed valid. In this manner, the certificate is verified.

[0031] <Signature generation using public key cryptography> The method explained above is a method that does not cause any problems even if the signature key set in the IC card is a key of a symmetric key cryptosystem such as DES or AES. If the symmetric key is properly managed through strict management and regular key updating procedures, there will be few problems, but it is also possible to adopt an even more secure method in consideration of unforeseen events such as key leakage.

[0032] Generally, the cryptographic key that generates the signature is a public key held by another party, usually another organization called a CA. It is safer to use a key whose signature has been verified using a key pair of an open-key cryptosystem. This makes it difficult to leak the cryptographic key, and prevents the key itself from being forged. To utilize this, the IC chip must also have functionality compatible with the public-key cryptosystem, which may require a special IC chip. However, an embodiment that employs the public-key cryptosystem to further improve security will be described below. Note that the device configurations of the issuing system and verification system can be similar to those of the previously described embodiment, so a description thereof will be omitted.

[0033] <Issuance flow when using public key cryptography> The basic flow is the same as that described above except that the encryption key is a key pair of the public key cryptosystem, so the issuing procedure will be explained using the flowchart in FIG. S301: The issuing data including the print data is acquired from the issuing data server. S302: The certificate paper is set in the certificate printer. S303: The CA signs the IC chip of the IC tag on the certificate via the reader / writer. The encryption key and the public key of the CA are set together. S304: Similarly, the issuing data is written. S305: The issued data is read again from the IC chip. S306: Print the information printing section on the certificate printer using the print data in the read issuance data. conduct. S307: Calculate a HASH value from the print data. S308: The encryption key signed by the CA and the public key of the CA are sent to the IC chip and encrypted. The key is decrypted and made available within the IC chip. S309: The calculated HASH value is sent to the IC chip via the reader / writer and can be used. The data is then encrypted using the resulting encryption key and sent back to the PC. S310: The encrypted HASH value is stored in the collation area of ​​the memory of the IC chip. S311: The encrypted HASH value is converted into a QR code (registered trademark) and printed on the code printing unit. S312: Take out the printed certificate paper. If a QR code (registered trademark) is not to be printed, step S311 is omitted. Through the above procedure, a certificate is issued in which print data and signature data are stored in the memory of the IC chip in the IC tag.

[0034] <Verification flow when using public key cryptography> The verification procedure when using the public key cryptosystem will be described along the verification flow shown in FIG. After the verification begins, S401: The print data of the information printing section on the printed side of the certificate is read by a scanner. If a QR code (registered trademark) or similar is printed on the card, it can also be read using a scanner or a QR code (registered trademark) scanner. S402: A HASH value is calculated from the print data of the read information print section. S403: The encryption key signed by the CA and the public key of the CA are extracted from the IC chip. S404: The signed encryption key and the CA public key are sent to the IC chip, and the encryption key is decrypted. It can be used within the chip. S405: The HASH value calculated in S402 is read by the contactless IC reader / writer into the IC tag. The data is sent to the chip and encrypted using the IC chip's encryption key. S406: The QR code (registered trademark) printed on the code is converted into signature data, and compared with the HASH value encrypted and signed in the previous step using the IC chip. S407: If both are identical, proceed to S408. If they do not match, a verification error occurs. If a QR code (registered trademark) or the like is not printed in the code printing section, steps S406 and S407 are omitted. S408: Encrypted and signed HA stored in the verification area of ​​the memory of the IC chip The HASH value is compared with the HASH value that was encrypted and signed using the print data. S409: If both are identical, proceed to S410. If they do not match, a verification error occurs. S410: Verification is completed as the certificate is valid. In this manner, the certificate is verified.

[0035] As explained above, according to the present invention, it is possible to reliably detect the swapping, forgery, and alteration of data printed on an IC chip and on paper by verification. Furthermore, since all necessary information is stored in the IC chip, verification can be performed offline without connecting to a server, etc. Furthermore, applying a public key cryptosystem can further enhance security. [Explanation of symbols]

[0036] S101~S111...Issuance Flowchart S201~S208 Verification flowchart S301~S312: Issuance flowchart when using public key cryptography S401 to S410: Verification flowchart when using public key cryptography

Claims

1. A certificate having an information printing section on which predetermined information is printed, An IC tag sticker is attached to the surface, and the IC tag sticker has a support body that is sealed with an IC chip that can electrically read and write data and stores an encryption key therein, and an antenna connected to the IC chip for communicating with the outside, and the support body seals the IC chip. data including information printed on the information printing unit; A HASH value generated from a part or all of the data of the information printed on the information printing unit is encrypted with an encryption key stored in the IC chip, and the signature data is signed; is written in the memory of the IC chip.

2. 2. The document according to claim 1, further comprising a code printing portion in which the signature data is printed on the surface of the document in the form of a QR code (registered trademark), a barcode, or converted alphanumeric characters.

3. The certificate according to claim 1 or 2, characterized in that the encryption key is signed with a private key of a public key cryptosystem held by the certificate issuing organization and can be used after being decrypted with the corresponding public key.

4. A certificate issuing system that issues a certificate having predetermined information printed on its surface, It includes a control PC and a printer with a read / write function for the IC chip, The IC tag sticker is attached to the surface of a sheet of paper, which has an IC chip that can electrically read and write data and stores an encryption key inside, and an antenna connected to the IC chip for communicating with the outside sealed in a support, The printer stores data containing the same information as that to be printed on the surface of the paper in an IC chip, and prints the information to be printed on the surface of the paper; A HASH value generated from a part or all of the printed data is encrypted with an encryption key stored in the IC chip and signed; The certificate issuing system is characterized in that the signature data is written into the memory of the IC chip.

5. 5. The document issuing system according to claim 4, wherein the signature data is further printed on the surface of the document in the form of a QR code (registered trademark), a barcode, or converted alphanumeric characters.

6. The certificate issuance system according to claim 4 or 5, characterized in that the encryption key is signed with a private key of a public key cryptosystem held by the certificate issuing organization and can be used after being decrypted with the corresponding public key.

7. The method of claim 1 further comprises: optically reading the printed data of the information printing section of the certificate; generating a HASH value from a part or all of the information; transmitting the HASH value to the IC tag; encrypting the HASH value with an encryption key stored in an IC chip of the IC tag; and signing the HASH value; Verifying whether the signature is identical to the signature stored in the memory of the IC chip using the IC chip; A method for verifying the authenticity of a certificate, characterized in that the certificate is deemed to be authentic when the two are identical.

8. The method of claim 2 further comprises: optically reading the printed data of the information printing section of the certificate; generating a HASH value from a part or all of the information; transmitting the HASH value to the IC tag; encrypting the HASH value with an encryption key stored in the IC chip of the IC tag; and signing the HASH value; The IC chip is used to verify whether the signature, the signature read from the code printed portion of the certificate, and the signature stored in the memory of the IC chip are the same; A method for verifying the authenticity of a certificate, characterized in that the certificate is deemed to be authentic when the two are identical.

9. 9. The method for verifying the authenticity of a certificate according to claim 7 or 8, wherein the encryption key is signed with a private key held by the certificate issuing organization and can be used after being decrypted with a corresponding public key.

Citation Information

Patent Citations

  • Entrance ticket having noncontact type ic stuck thereon

    JP1999277963A

  • Sheet-like medium, method and device for judging authenticity, and certificate issuing machine

    JP2001357377A

  • Recording and reproducing device and program

    JP2006197090A

  • Individual authentication medium issuing system and individual authentication medium issuing method

    JP2009032004A