Management device, management system, management method, and program
The management system addresses the challenge of proving membership in sub-organizations by issuing hierarchical digital certificates, improving convenience and reducing organizational workload.
Patent Information
- Application Number
- JP2025058227
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-11-26
- Estimated Expiration
- 2045-03-31
AI Technical Summary
Conventional digital certificate technologies do not effectively prove membership in sub-organizations within a larger organization, leading to inconvenience in accessing specific activities or services.
A management system that issues hierarchical digital certificates, linking affiliation with a sub-organization to a higher-level certificate, allowing organizations to manage and edit these certificates efficiently, thereby proving membership in both the parent and sub-organizations.
Enhances convenience by allowing easy proof of affiliation to both the main organization and its sub-organizations without increasing the organization's workload.
Smart Images

Figure 0007776038000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a management device, a management system, a management method, and a program. [Background technology]
[0002] Conventionally, there are technologies relating to digital certificates that certify affiliation to an organization. For example, Patent Document 1 discloses a technology that can improve the reliability of digital student ID cards. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] International Publication No. 2024 / 024043 Summary of the Invention [Problem to be solved by the invention]
[0004] However, the above-mentioned conventional technologies have room for improvement in terms of convenience. Specifically, while conventional technologies allow consumers to obtain digital certificates that prove they belong to an organization, they do not prove their membership in communities (small organizations) formed within that organization.
[0005] For example, in organizations such as schools, communities such as student councils and clubs are formed, and members of each community participate in various activities, such as tournaments. Some of these activities are open to all students at the school, but others are open to only members of specific communities, such as student councils and clubs. In cases where only members of a community are eligible to participate, it would be more convenient to be able to prove that one belongs not only to the school but also to the school's student council, club, or other community. In addition, for example, when a specific person in a company is given access rights to specific electronic information, the access rights are generally applicable only to the system within that company and are not certified to third parties outside the company.
[0006] In view of the above-mentioned problems, an object of the present invention is to provide a management device, a management system, a management method, and a program that can improve the convenience of digital certificates that certify affiliation to an organization. [Means for solving the problem]
[0007] In order to solve the above-mentioned problems, a management device according to one aspect of the present invention comprises: A hierarchical digital certificate created by an organization to prove affiliation with a sub-organization based on a certificate proving affiliation with the organization. Application for issuance of From the organization and a reception unit that receives the issuance request and responds to the issuance request received by the reception unit. The above a certificate issuing unit that issues hierarchical digital certificates; an authority setting unit that grants an editing authority to edit the hierarchical digital certificate issued by the certificate issuing unit to a user designated by the organization; Equipped with.
[0008] A management system according to one aspect of the present invention includes the management device described above, and an affiliate terminal that is communicatively connected to the management device and transmits the issuance request to the management device.
[0009] A management method according to one aspect of the present invention is a management method performed by a computer that is a management device, the management method comprising: A hierarchical digital certificate created by an organization to prove affiliation with a sub-organization based on a certificate proving affiliation with the organization. Application for issuance of From the organization The receiving and issuing unit responds to the issuance request received by the receiving unit. The above Issue hierarchical digital certificates an authority setting unit granting an editing authority for editing the hierarchical digital certificate issued by the certificate issuing unit to a user designated by the organization; do.
[0010] A program according to one aspect of the present invention is provided for a computer that is a management device, A hierarchical digital certificate created by an organization to prove affiliation with a sub-organization based on a certificate proving affiliation with the organization. Application for issuance of From the organization and in response to the accepted issuance application, The above Hierarchical digital certificates are issued. and granting an editing authority for editing the issued hierarchical digital certificate to a user designated by the organization. It is a program. [Effects of the Invention]
[0011] According to the present invention, it is possible to improve the convenience of digital certificates that certify affiliation to an organization. [Brief explanation of the drawings]
[0012] [Figure 1] 1 is a block diagram showing an example of the configuration of a management system 100 according to an embodiment. [Figure 2] FIG. 2 is a diagram illustrating an example of an organizational hierarchical structure according to an embodiment. [Figure 3] 1 is a block diagram showing an example of the configuration of a certificate management server 10 according to an embodiment. [Figure 4] FIG. 2 is a diagram for explaining management information 120 according to the embodiment. [Figure 5] FIG. 10 is a diagram for explaining the issuance of a higher-level digital certificate according to an embodiment. [Figure 6] FIG. 10 is a sequence diagram showing an example of a hierarchical digital certificate issuing process (organization-driven) according to the embodiment. [Figure 7] FIG. 10 is a sequence diagram showing an example of a hierarchical digital certificate issuing process (member-initiated) according to the embodiment. [Figure 8] FIG. 10 is a sequence diagram showing an example of a hierarchical digital certificate issuing process (external cooperation type) according to the embodiment. [Figure 9] FIG. 10 is a sequence diagram showing an example of a hierarchical digital certificate issuing process (external cooperation type) according to the embodiment. [Figure 10] FIG. 2 is a diagram showing an example of a screen displayed on a member terminal 20 according to the embodiment. [Figure 11] FIG. 2 is a diagram showing an example of a screen displayed on a member terminal 20 according to the embodiment. [Figure 12] FIG. 2 is a diagram showing an example of a screen displayed on a member terminal 20 according to the embodiment. [Figure 13] FIG. 2 is a diagram showing an example of a screen displayed on a member terminal 20 according to the embodiment. [Figure 14] FIG. 2 is a diagram showing an example of a screen displayed on a business operator terminal 30 according to the embodiment. [Figure 15] FIG. 2 is a diagram showing an example of a screen displayed on a business operator terminal 30 according to the embodiment. [Figure 16] FIG. 2 is a diagram showing an example of a screen displayed on a business operator terminal 30 according to the embodiment. [Figure 17] FIG. 2 is a diagram showing an example of a screen displayed on a business operator terminal 30 according to the embodiment. [Figure 18] FIG. 1 is a diagram illustrating an example of an image of a hierarchy according to an embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0013] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.
[0014] (Regarding the management system 100) A management system 100 according to this embodiment will be described with reference to Fig. 1. Fig. 1 is a block diagram showing an example of the configuration of the management system 100 according to this embodiment. The management system 100 includes a certificate management server 10, a member terminal 20, a business operator terminal 30, and a verifier terminal 40.
[0015] In the management system 100, a certificate management server 10, an affiliate terminal 20, an operator terminal 30, and a verifier terminal 40 are communicably connected via a communication network NW.
[0016] The management system 100 is a system that manages certificates issued to members who belong to an organization. A certificate here is something that proves membership in an organization, such as a student ID card issued by a school organization or an employee ID card issued by a corporate organization. Furthermore, the certificate in this embodiment is a digital certificate, which is an electronic certificate, and more specifically, a VC (Verifiable Credentials).
[0017] The business operator terminal 30 is a computer managed by a business operator corresponding to an organization. The business operator terminal 30 executes operations related to issuing certificates via the certificate management server 10. For example, the business operator terminal 30 may be a terminal device, such as a PC (personal computer), a server, or a tablet terminal, operated by a person in charge of general affairs, which is an operation related to issuing certificates, in a business operator such as a school organization.
[0018] The member terminal 20 is a computer operated by a member (user) who belongs to the organization. The member terminal 20 obtains a certificate issued by the certificate management server 10. The member terminal 20 may be, for example, a terminal device operated by a student who belongs to the school organization, such as a PC, a smartphone, a mobile phone, or a tablet terminal.
[0019] 1 shows an example in which one member terminal 20 is provided in the management system 100, but it is common for there to be multiple users belonging to an organization. For this reason, although omitted in FIG. 1, it is common for the management system 100 to be provided with multiple member terminals 20 corresponding to the number of users belonging to the organization.
[0020] The verifier terminal 40 is a computer managed by a business that provides services to users. The verifier terminal 40 verifies the certificate provided by the member terminal 20. The verifier terminal 40 may be, for example, a terminal device operated by a provider that provides services to users, such as a PC or a tablet terminal.
[0021] Here, the services provided to the user are those that, by proving that the user belongs to an organization, the user can receive certain benefits, admission permits, instructions, and guidance, services and treatments that would not be available to the user if the user did not belong to the organization. Examples of services provided to the user include transportation services such as trains, buses, and airplanes, and services providing products from retail stores and restaurants. Some of these services offer so-called student discounts, which provide discounts on fares, books, and food and drink prices by proving that the user is a student (belongs to a school organization). When the user requests a service using such a student discount, the verifier terminal 40 verifies the certificate presented by the user, and if it is verified that the certificate presented by the user is authentic, i.e., that it is a legitimate student ID card issued by a school organization, the verifier terminal 40 provides the service using the student discount requested by the user.
[0022] The certificate management server 10 is a computer that executes processes related to the issuance of digital certificates and manages the issued digital certificates. The certificate management server 10 performs processes related to digital certificates, such as issuing, providing, verifying, and updating digital certificates.
[0023] (Regarding the issuance of digital certificates) The certificate management server 10 issues digital certificates in response to requests from organizations. Specifically, in response to a request from an organization, the certificate management server 10 issues a digital certificate to a member of the organization, certifying that the member belongs to the organization. For example, in response to a request from the business terminal 30 corresponding to a school organization, the certificate management server 10 issues a digital student ID card to a student belonging to that school, certifying that the student belongs to that school. The certificate management server 10 stores, for example, information associating student attribute information with information related to the student's identity verification as management information 120, which will be described later. The identity verification information is, for example, information indicating that identity verification has been performed by online identity verification (eKYC: electronic Know Your Customer) or a public personal authentication service (JPKI: Japanese Public Key Infrastructure). In response to a user's operation of the member terminal 20, the certificate management server 10 displays the digital student ID card that has been issued to the user on the member terminal 20. The digital student ID card displayed on the member terminal 20 shows, for example, the student's attribute information, such as the student ID number, name, date of birth, and other information related to the student ID, such as the issue date and expiration date, and is an image showing a statement such as "I certify that the above person is a student of this school," as well as the name of the school and a seal.
[0024] (Providing digital certificates) The certificate management server 10 generates a VP (Verifiable Presentation), which is a VC converted into a format for presenting the proof content to a verifier. For example, a user operates the member terminal 20 to request the certificate management server 10 to generate a VP to be presented to a verifier. In response to the user's request, the certificate management server 10 generates the student's attribute information, etc. linked to the digital student ID card as a VP. The user sends the VP generated by the certificate management server 10 to the verifier terminal 40 via the member terminal 20 or the certificate management server 10. The verifier terminal 40 verifies the VP notified by the user. This allows the user to prove to the verifier that they are a student. Here, the certificate management server 10 uses zero-knowledge proof technology to provide the minimum personal information necessary for the verifier to verify, and to prevent the verifier from providing unnecessary information. Zero-knowledge proof is a method of communication that can prove the "authenticity" of information via an information network without disclosing the information itself. For example, if a verifier wants to verify that "the user is a student," he or she will generate a VP that contains only information that can verify that "the user is a student," and will not include information that is not necessarily required to verify that "the user is a student," such as the name of the school the user belongs to, their grade, student ID number, etc. This will prevent personal information from being disclosed unnecessarily.
[0025] The certificate management server 10 may be configured to generate a VP that combines all or part of the content certified in each of multiple different digital certificates. For example, if a user wants to prove to a verifier that he or she is a student and has a driver's license, the certificate management server 10 generates a VP that combines information for proving the student status extracted from a first digital certificate corresponding to a student ID card and information for proving the driver's license extracted from a second digital certificate corresponding to a driver's license. This allows the user to easily generate an original VP that corresponds to the verification items requested by the verifier, without having to go through the trouble of obtaining certificates from multiple issuers of affiliation certificates or qualification certificates and combining and submitting them to the verifier.
[0026] (About digital certificate verification) In response to a request from a verifier, the certificate management server 10 verifies that the proof content to be verified has not been tampered with, whether the VP has been presented by the user who should have the digital certificate, etc. Technologies used for this verification include, for example, distributed ledger technology used in the verification function of VC, technology related to digital signatures, DID (Decentralized Identifiers), etc. Furthermore, the certificate management server 10 may verify whether the VP has been presented by the user who should have the digital certificate by performing identity verification using online identity verification or a public personal authentication service, etc.
[0027] (Digital certificate renewal) The certificate management server 10 updates an issued digital certificate in response to a request from an organization or a user. For example, when an organization updates its member information at the end of the academic year or a set deadline, such as when a student advances to a higher education or graduates, the certificate management server 10 updates the issued digital certificate in accordance with the updated content. At this time, when a student graduates, a graduation certificate may be issued by updating the digital student ID card that the student held before graduation. Alternatively, if the user changes their status due to withdrawal or taking a leave of absence, the certificate management server 10 updates the issued digital certificate in accordance with the changed content. When the certificate management server 10 updates an issued digital certificate, it transmits the updated content to the member terminal 20 and the business operator terminal 30, and notifies the organization and the user that the digital certificate has been updated.
[0028] (Regarding other digital certificate processing) The certificate management server 10 may be configured to respond to inquiries from users, such as inquiries about viewing digital certificates held by users, checking details, updating, and requesting reissue. In addition, if the user does not possess a digital certificate for the verifier to certify the information required for verification, the certificate management server 10 may be configured to notify the member terminal 20 of the information required for verification and request the user to obtain a digital certificate related to the information required for verification.
[0029] (About the assignment) As described above, the certificate management server 10 is configured to be able to certify that a user belongs to an organization by performing processes related to digital certificates. However, conventional processes related to digital certificates do not certify that a community (small organization) formed within an organization belongs to the organization.
[0030] FIG. 2 is a diagram illustrating an example of an organizational hierarchical structure according to an embodiment. In this diagram, a school (TOPPAN High School) as an organization has numerous communities (small organizations) such as a student council, track and field club, and optional groups. Furthermore, each small organization, such as the track and field club, further forms teams (small organizations even lower in rank than the small organizations), such as tournament participants and rookie tournament registered members. These small organizations or teams are made up of students belonging to the organization (TOPPAN High School). However, simply issuing a digital student ID card that can prove that a student belongs to the organization (TOPPAN High School) does not enable the digital student ID card to prove that the student who possesses the digital student ID belongs to a small organization (student council, track and field club, or optional group). Furthermore, even if it is known that a student belongs to a small organization (student council, track and field club, or optional group), it is not possible to verify with the digital student ID whether that small organization belongs to the organization (TOPPAN High School).
[0031] One possible solution to this problem is for communities (small organizations) to generate their own digital certificates to prove that they belong to the organization, but this can make it difficult to prove membership in an organization because the organization may not necessarily certify the affiliation of each and every small organization formed within it. As a countermeasure, when it becomes necessary to prove one's affiliation with a community formed within an organization, one could ask the organization for proof each time, or change the database managed by the organization to reissue a digital certificate that proves one's affiliation with the organization and its communities. However, this is time-consuming and not very convenient.
[0032] As a countermeasure to this problem, the management system 100 of this embodiment is capable of issuing a hierarchical digital certificate that proves that a sub-organization belongs to an organization, based on a digital certificate (higher-level digital certificate) that proves affiliation to the parent organization. In this case, the management system 100 is configured to arrange the digital certificates issued to the users in a hierarchical structure, with a higher-level digital certificate and a hierarchical digital certificate placed below it. This makes it possible to link the affiliation to an organization attested by a higher-level digital certificate with the certification content of a hierarchical digital certificate, making it easy for a sub-organization to prove that it belongs to the organization. Moreover, by making digital certificates hierarchical, it is possible to issue a hierarchical digital certificate when a sub-organization is formed and link it to a higher-level digital certificate, eliminating the need to change the higher-level digital certificate. Therefore, an organization does not need to change the higher-level digital certificate every time a sub-organization is formed, abolished, or merged, and there is no increase in the organization's workload for updating digital certificates.
[0033] In addition, in the management system 100, the authority setting unit 132 is capable of issuing a hierarchical digital certificate that certifies that a team formed in a small organization belongs to the small organization and, by extension, to an organization higher than that. Even in this case, the management system 100 is configured so that the digital certificates issued to users have a hierarchical structure. Specifically, the hierarchical digital certificate that certifies affiliation to a team formed in a small organization whose affiliation is certified in the hierarchical digital certificate (first hierarchical digital certificate) is set as the second hierarchical digital certificate. This makes it possible to link the affiliation to the small organization certified by the first hierarchical digital certificate with the certification content of the second hierarchical digital certificate, just like the hierarchical structure of higher-level digital certificates and hierarchical digital certificates, and makes it easy to prove that the team belongs to the small organization.
[0034] This type of hierarchical structure allows for the placement of even lower-level hierarchical digital certificates. By linking the hierarchical digital certificate of a group (small organization, team, etc.) to which you belong, it becomes easy to prove that the issued hierarchical digital certificate belongs to that group (small organization, team, etc.).
[0035] Furthermore, the management system 100 allows an organization or a user to be granted the authority to issue hierarchical digital certificates and the authority to edit the contents of hierarchical digital certificates. This allows the organization or user to issue and edit hierarchical digital certificates. Therefore, for sub-organizations that should be managed within the organization, the organization can manage the issuance and editing of hierarchical digital certificates. However, for those for which issuing authority has been granted to a user, the user can freely issue and edit hierarchical digital certificates, thereby preventing the organization's workload from increasing more than necessary.
[0036] Furthermore, the management system 100 allows the user to set approval levels, such as whether organizational approval is required, when issuing a hierarchical digital certificate. Specifically, approval levels can be set so that when issuing a hierarchical digital certificate for a small organization officially recognized by a school, approval from a higher-level member of the school organization (e.g., the principal or the chairman of the board of directors) is required, while small organizations such as temporary action groups require approval from a middle-level member of the school organization (e.g., the homeroom teacher), and groups such as friendship groups formed independently by students do not require approval from the school organization. This allows the organization to keep track of the issuance status of hierarchical digital certificates for small organizations that it should manage, and does not require approval for small organizations not under its management, thereby preventing the organization from unnecessarily increasing its workload.
[0037] In this way, in the management system 100 of this embodiment, the convenience of users is improved by issuing hierarchical digital certificates, while the process for issuing hierarchical digital certificates has been devised so that issuing these hierarchical digital certificates does not unnecessarily increase the workload of the organization. This makes it possible to improve the convenience of digital certificates that prove affiliation to an organization without increasing the workload of the organization.
[0038] (Regarding Certificate Management Server 10) 3 is a block diagram showing an example of the configuration of the certificate management server 10 according to the embodiment. The certificate management server 10 includes, for example, a communication unit 11, a storage unit 12, and a control unit 13.
[0039] The communication unit 11 has a function of transmitting and receiving various information, and communicates with the member terminal 20, the business operator terminal 30, and the verifier terminal 40 via the communication network NW.
[0040] The storage unit 12 has a function of storing various types of information. The storage unit 12 is configured by a storage medium provided as hardware in the certificate management server 10, such as a hard disk drive (HDD), a solid state drive (SSD), a flash memory, an electrically erasable programmable read-only memory (EEPROM), a random access read / write memory (RAM), a read-only memory (ROM), or any combination of these storage media.
[0041] The storage unit 12 stores management information 120. The management information 120 is information registered by an organization or a user when a digital certificate (including a higher-level digital certificate and a hierarchical digital certificate) is issued, and information about the issued digital certificate.
[0042] 4 is a diagram for explaining management information 120 according to an embodiment. This diagram shows an example in which management information 120 stored in the storage unit 12 of the certificate management server 10 is displayed on the management screen of the business operator terminal 30. In this diagram, the management information 120 includes personal information and organization information. The personal information is information about the individual user to whom the digital certificate has been issued, and includes information corresponding to items such as student ID number, name, date of birth, issue date, expiration date, photograph, and status. The student ID number stores the user's student ID number. The name stores the user's name (in kanji or kana). The date of birth stores the user's date of birth. The issue date stores the date on which the digital certificate was issued to the user. The expiration date stores the expiration date of the digital certificate issued to the user. The photograph stores an image file of the user's face photo that is displayed in the digital certificate issued to the user. The status stores the status of the user's affiliation to the organization, such as normally attending school or on leave of absence. The organization information is information about the organization whose affiliation is certified in the digital certificate, and includes information corresponding to items such as issue type, issuing organization, organization name, organization address, organization logo, organization seal, card design, and authority / qualification management. The issue type is the type of digital certificate issued by the organization, and types such as student ID card and qualification certificate are stored. The issuing organization stores information indicating the department in the organization responsible for the work related to issuing digital certificates. The organization name stores the name of the organization that issued the digital certificate. The organization address stores the address of the organization that issued the digital certificate. The organization logo stores image information of an image showing the logo of the organization that issued the digital certificate. The organization seal stores image information of an image showing the seal impression of the organization that issued the digital certificate. The card design stores image information of an image showing the card design used when displaying an image of the digital certificate on the member terminal 20, etc.
[0043] The authority / qualification management item stores information indicating the authority (including publishing authority and editing authority) granted to a user. For example, if a user is the student council president of a small group in a school organization, he or she can grant a student council member the position of vice president or student council committee member with the approval of the student council members and advisor. In this case, the user has the editing authority to assign student council committee members to each position, such as vice president or student council committee member, in the hierarchical digital certificate of the student council (small group). For example, if a user is the captain of a track and field club (small organization) in a school organization, he or she can grant a member of the track and field club the position of vice captain or the right to participate in competitions, with the approval of the advisor, etc. In this case, the user has the editing authority to assign members to the position of vice captain or to compete in competitions, etc., in the hierarchical digital certificate of the track and field club (small organization). For example, if a user is an ordinary student in a school organization, the user can form a community such as a class group of friends. In this case, the user has the authority to issue hierarchical digital certificates for the class group of friends (small organization).
[0044] 3, the control unit 13 has a function of controlling the overall operation of the certificate management server 10. The control unit 13 is realized, for example, by causing a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit) provided as hardware in the certificate management server 10 to execute a program. The control unit 13 includes, for example, a reception unit 130, a certificate issuance unit 131, an authority setting unit 132, a certificate management unit 133, and a display control unit 134.
[0045] The reception unit 130 receives requests for issuance of digital certificates. Specifically, the reception unit 130 receives various requests for digital certificate-related processing from organizations or users. More specifically, the reception unit 130 receives requests for issuance, editing, renewal, etc. of higher-level digital certificates from the business operator terminal 30 or from a person in charge of issuing digital certificates at the organization. The reception unit 130 also receives requests for issuance, authorization, editing, renewal, etc. of hierarchical digital certificates linked to a lower level of an issued higher-level digital certificate from the member terminal 20 or the business operator terminal 30. If the received request is an issuance request, the management information 120 outputs the received request to the certificate issuance unit 131. If the received request is an authorization request, the management information 120 outputs the received request to the authorization setting unit 132. If the received request is an editing request or renewal request for an issued digital certificate, the management information 120 outputs the received request to the certificate management unit 133.
[0046] The certificate issuing unit 131 issues a digital certificate. The certificate issuing unit 131 issues a higher-level digital certificate in response to an issuance request from the operator terminal 30 or a person in charge of issuing digital certificates in an organization.
[0047] 5 is a diagram for explaining the issuance of a higher-level digital certificate according to an embodiment. This diagram shows the flow of processing when manually applying for the issuance of a higher-level digital certificate. However, this is not limiting, and the processing related to the application for issuance of a higher-level digital certificate may be executed through communication between the certificate management server 10 and the business operator terminal 30. In this diagram, the organization is a school (TOPPAN High School). The person in charge of issuing digital certificates in the organization is a person in the general affairs department of the high school (General Affairs Department).
[0048] First, the high school general affairs department provides personal information of the high school students to a responsible employee of the business that undertakes the digital certificate issuance service (the business that manages the certificate management server 10), and submits an application to issue a digital student ID card (high-level digital certificate) to the student corresponding to the provided personal information (step S10). The employee in charge registers the student's personal information provided by the high school general affairs department as management information 120 in the memory unit 12 of the certificate management server 10, and performs pre-registration for the issuance of a digital student ID card (higher-level digital certificate) (step S11). The high school general affairs department checks the management screen of the business terminal 30, for example, the management screen shown in Fig. 3, and verifies that the applied content is correctly reflected on the management screen, and approves it. The high school general affairs department also sets the approval level for the issuance of hierarchical digital certificates for students (users) who have been issued digital student ID cards (higher digital certificates), and sets issuing authority and editing authority as necessary (step S12).
[0049] Furthermore, certificate issuance unit 131 issues a hierarchical digital certificate. Specifically, in response to an issuance request received by reception unit 130, certificate issuance unit 131 issues a hierarchical digital certificate that certifies affiliation to a sub-organization formed within an organization, based on a higher-level digital certificate (a certificate that certifies affiliation to the organization).
[0050] The certificate issuing unit 131 issues a hierarchical digital certificate based on the details of an issuance application from an organization, or based on the details of an issuance application from a user who has the authority to issue a hierarchical digital certificate. For example, at TOPPAN High School, in response to the establishment of various communities (small organizations) such as the student council, track and field club, and brass band club, the high school's general affairs department submits an issuance application from business operator terminal 30 to certificate management server 10, requesting that a hierarchical digital certificate be issued for each of the established small organizations. This issuance application is accepted by reception unit 130, and the accepted content is output to certificate issuance unit 131. Certificate issuance unit 131 issues a hierarchical digital certificate in accordance with the application content acquired via reception unit 130, and notifies member terminal 20 of the user to whom the certificate is issued that the hierarchical digital certificate has been issued.
[0051] The certificate issuing unit 131 stores the contents of the issuance request made by the organization or a user with issuing authority in the management information 120 of the memory unit 12, and notifies the member terminal 20 of the user who issued the hierarchical digital certificate that the hierarchical digital certificate has been issued. For example, at TOPPAN High School, when an ordinary student creates a community (small organization) such as a friendship group, the ordinary student submits an issuance application from member terminal 20 to certificate management server 10 to request that a hierarchical digital certificate be issued for the friendship group. This issuance application is accepted by reception unit 130, and the accepted content is output to certificate issuance unit 131. Certificate issuance unit 131 issues a hierarchical digital certificate according to the application content acquired via reception unit 130, and notifies member terminal 20 of the user to whom the certificate is issued that the hierarchical digital certificate has been issued.
[0052] Returning to the explanation of FIG. 3, the authority setting unit 132 sets the issuing authority or editing authority of a hierarchical digital certificate in response to a grant application from an organization or a user.
[0053] For example, when applying for issuance of a digital student ID card (higher-level digital certificate), or after issuing this digital student ID card, the high school general affairs department uses the business operator terminal 30 to apply to the certificate management server 10 for issuance authority to issue hierarchical digital certificates linked to the lower levels of these digital student ID cards (higher-level digital certificates), for small groups formed by ordinary students, such as friendship groups, that are not managed by the school. This issuance application is accepted by the acceptance unit 130, and the accepted content is output to the authority setting unit 132. The authority setting unit 132 sets the issuance authority for the hierarchical digital certificate in accordance with the application content acquired via the acceptance unit 130, and notifies the member terminal 20 of the target user that the issuance authority for the hierarchical digital certificate has been granted.
[0054] Alternatively, when applying for the issuance of a hierarchical digital certificate for each community (small organization) such as the student council, track and field club, or brass band club, or after issuing these hierarchical digital certificates, the high school general affairs department submits an application from the business operator terminal 30 to the certificate management server 10 to grant editing authority for these hierarchical digital certificates to users designated by the organization, such as the president and vice president of the student council, the advisor and director of the track and field club, and the advisor and director of the brass band club. This issuance application is accepted by the acceptance unit 130, and the accepted content is output to the authority setting unit 132. The authority setting unit 132 sets editing authority for the hierarchical digital certificate in accordance with the application content obtained via the acceptance unit 130, and notifies the member terminal 20 of the user for whom the authority was set that editing authority for the hierarchical digital certificate has been granted.
[0055] Furthermore, the authority setting unit 132 may grant editing authority to edit a hierarchical digital certificate issued by the certificate issuing unit 131 to a user who has issuing authority related to that hierarchical digital certificate. In this case, when a hierarchical digital certificate is issued by the certificate issuing unit 131 in response to an issuance request from a user with issuing authority, the authority setting unit 132 sets editing authority for the hierarchical digital certificate issued by the certificate issuing unit 131 to the user with issuing authority.
[0056] In addition, the authority setting unit 132 may grant issuing authority to issue a second hierarchical digital certificate that certifies affiliation to a team formed in a small organization (a small organization subordinate to the small organization) to a user who has editing authority to edit the first hierarchical digital certificate that certifies affiliation to that small organization. For example, if the small organization is a track and field club, the hierarchical digital certificate that proves affiliation to the small organization is the first hierarchical digital certificate, and a user who has editing authority to edit the first hierarchical digital certificate is, for example, the track and field club's advisor or club president. The track and field club advisor or club president, who is a user with editing authority, edits the content of the first hierarchical digital certificate to assign track and field club members to positions such as vice president or manager of the track and field club. In such a small organization (track and field club), a team may be formed consisting of participating athletes when participating in a competition, etc. If the authority to issue second hierarchical digital certificates is granted to the track and field club advisor or manager, who is a user with editing authority, when a team of such participating athletes is formed, the track and field club advisor or manager, who is a user with editing authority, can conveniently issue a second hierarchical digital certificate that certifies that the team formed by the track and field club belongs to the track and field club. In this case, when a hierarchical digital certificate is issued by the certificate issuing unit 131 in response to an issuance request from an organization or a user with issuing authority, the authority setting unit 132 sets the issuing authority for the user with issuing authority to issue a hierarchical digital certificate (second hierarchical digital certificate) that is linked to a lower level of the currently issued hierarchical digital certificate (first hierarchical digital certificate).
[0057] Among the processes related to digital certificates, the certificate management unit 133 performs functions other than those performed by the reception unit 130, the certificate issuance unit 131, and the authority setting unit 132, such as providing, verifying, and updating digital certificates, responding to inquiries, and notifying information necessary for verification, etc. The certificate management unit 133 can be executed using the method described above, and therefore a description thereof will be omitted here.
[0058] The display control unit 134 controls images displayed on the member terminal 20 and the provider terminal 30. For example, the display control unit 134 causes the provider terminal 30 to display a management screen such as that shown in Fig. 3. The display control unit 134 also causes the member terminal 20 to display a list of digital certificates issued to users, etc.
[0059] FIG. 6 is a sequence diagram showing an example of a hierarchical digital certificate issuing process (organization-driven) according to the embodiment. Figure 6 shows the flow of the process when a hierarchical digital certificate is issued in response to an issuance request from an organization. This figure assumes that a higher-level digital certificate has already been issued by applying for issuance of the higher-level digital certificate as shown in Figure 5.
[0060] The business operator terminal 30 notifies the certificate management server 10 of an application for issuance of a hierarchical VC (hierarchical digital certificate) for a community (small organization) such as a student council or club activity formed in an organization (step S100). The certificate management server 10 creates a hierarchical VC based on the application information indicated in the issuance application notified from the business operator terminal 30 (step S101). In addition, the business operator terminal 30 notifies the certificate management server 10 of an application (application for authorization) to grant editing authority for the hierarchical VC for which an issuance application was made in step S100 and / or lower hierarchical VC issuance authority to the designated user (advisor, department manager, etc.) (step S102). The lower hierarchical VC is a second hierarchical digital certificate that is linked to a lower level of the hierarchical VC (first hierarchical digital certificate) for which an issuance application was made in step S100. The certificate management server 10 sets the editing authority in the hierarchical VC created in step 101 and / or the lower hierarchical VC issuing authority based on the application information indicated in the authorization application notified from the business operator terminal 30 (step S103). The certificate management server 10 notifies the member terminal 20 that it has issued the hierarchical VC, that is, the hierarchical VC issued in step S101 and to which the editing authority and / or issuing authority has been granted in step S103 (step S104). The member terminal 20 notifies the certificate management server 10 of an issuance application for a lower hierarchical VC based on the issuance authority from the user who has the issuance authority for the hierarchical VC notified of issuance in step S104 (step S105). The certificate management server 10 creates a lower hierarchical VC based on the application information indicated in the issuance application notified from the member terminal 20 (step S106). The certificate management server 10 notifies the member terminal 20 that the lower hierarchical VC has been issued (step S107). The member terminal 20 also notifies the certificate management server 10 of various inquiries regarding digital certificates, such as requests to view a list of VCs or details about VCs (digital certificates) held by the user, or inquiries such as requests to renew or reissue VCs (step S108).The certificate management server 10 responds to the inquiries notified from the member terminal 20 (step S109).
[0061] Here, the flow of processing when the status of a user who holds a digital certificate is changed will be explained.
[0062] Steps S110 to S113 will be described taking as an example a case where a student who has a digital student ID card (higher-level digital certificate) has graduated. The business operator terminal 30 notifies the business operator terminal 30 that the user's status has been changed, and notifies the certificate management server 10 of an application to change the digital certificate held by the user (status change application) (step S110). The certificate management server 10 modifies the management information 120 linked to the issued digital certificate based on the application information indicated in the status change application notified from the business operator terminal 30, and reflects the modified information in the issued digital certificate (step S111). The certificate management server 10 notifies the member terminal 20 that the status of the issued digital certificate has been changed (step S112). The certificate management server 10 also notifies the business operator terminal 30 that the processing related to the status change requested in step S110 has been completed (step S113).
[0063] Steps S114 to S114 will be described taking as an example a case where a student who has a digital student ID card (higher-level digital certificate) takes a leave of absence or withdraws from school. The business operator terminal 30 notifies the user that the status has been changed, and notifies the certificate management server 10 of an application to change the digital certificate held by the user (status change application) (step S114). The certificate management server 10 modifies the management information 120 linked to the issued digital certificate based on the application information indicated in the status change application notified from the business operator terminal 30, and reflects the modified items in the issued digital certificate (step S115). For example, when a student takes a leave of absence or withdraws from school, the certificate management server 10 changes the status and performs settings to revoke the authority granted regarding the digital certificate (authority to edit hierarchical VCs and authority to issue lower hierarchical VCs). The certificate management server 10 notifies the member terminal 20 that the status of the issued digital certificate has been changed (step S116). The certificate management server 10 also notifies the business operator terminal 30 that the processing related to the status change requested in step S110 has been completed (step S117).
[0064] FIG. 7 is a sequence diagram showing an example of a hierarchical digital certificate issuing process (member-initiated type) according to the embodiment. Figure 7 shows the flow of processing when a hierarchical digital certificate issuance process is executed in response to an issuance request from a user. This figure assumes that a higher-level digital certificate has already been issued by requesting issuance of the higher-level digital certificate as shown in Figure 5.
[0065] The member terminal 20 notifies the certificate management server 10 of a hierarchical VC issuance application for a community (small organization) such as a friend group created by the user (step S200). The certificate management server 10 creates a hierarchical VC based on the application information indicated in the issuance application notified to the member terminal 20 (step S201). In addition, the member terminal 20 notifies the certificate management server 10 of an application (application for authorization) to grant editing authority for the hierarchical VC for which issuance was requested in step S200 and / or lower hierarchical VC issuance authority to the specified user (such as other members of the close group) (step 202). The certificate management server 10 sets the editing authority in the hierarchical VC created in step 201 and / or the lower hierarchical VC issuing authority based on the application information indicated in the authorization application notified from the member terminal 20 (step S203). Here, the certificate management server 10 may notify the member terminal 20 that it has issued the hierarchical VC, that is, the hierarchical VC issued in step S201 and to which the editing authority and / or issuing authority has been granted in step S203. The member terminal 20 notifies the certificate management server 10 of an issuance application for a lower hierarchical VC based on the issuance authority from a user who has the issuance authority for the hierarchical VC issued in steps S201 and S203 (step S204). The certificate management server 10 creates a lower hierarchical VC based on the application information indicated in the issuance application notified from the member terminal 20 (step S205). The certificate management server 10 notifies the member terminal 20 that the lower hierarchical VC has been issued (step S206). The member terminal 20 also notifies the certificate management server 10 of various inquiries regarding digital certificates, such as requests to view a list of VCs or details about VCs (digital certificates) held by the user, or inquiries such as requests to renew or reissue VCs (step S207).The certificate management server 10 responds to the inquiries notified from the member terminal 20 (step S208).
[0066] FIG. 8 is a sequence diagram showing an example of a hierarchical digital certificate issuing process (external cooperation type) according to the embodiment. Figure 8 shows the process flow when a hierarchical digital certificate issuance process is carried out in response to an issuance request from an external organization, in this case the Japan Association of Athletics Federations (JAAF), and the hierarchical digital certificate issued here is linked to an organization (TOPPAN High School). In this figure, it is assumed that an application for issuance of a higher-level digital certificate as shown in FIG. 5 has been made in advance, and that a higher-level digital certificate has already been issued. It is also assumed that the organization (TOPPAN High School) has already issued a hierarchical VC for the sub-organization (TOPPAN High School Track and Field Club) in advance.
[0067] The verifier terminal 40 notifies the certificate management server 10 of an application for issuance of a hierarchical VC for an athletics event (sub-organization) held in an external organization (Athletics Federation) (step 300). The certificate management server 10 creates a hierarchical VC for the athletics event based on the application information indicated in the issuance application notified from the verifier terminal 40 (step S301). In addition, the verifier terminal 40 notifies the certificate management server 10 of an issuance application for a hierarchical VC in which a participation quota for a 400m relay race (a small organization formed one level below the small organization) to be held in a track and field meet (small organization) is set (step S302). The certificate management server 10 creates a hierarchical VC for the 400m relay race based on the application information indicated in the issuance application notified from the verifier terminal 40 (step S303).
[0068] Furthermore, the verifier terminal 40 notifies the certificate management server 10 of an application for issuance of a hierarchical VC in which the participation quota for participants of each school in the 400m relay race (small organizations formed two levels below the small organizations) is set (step S304). The certificate management server 10 creates a hierarchical VC for registering participants of each school in the 400m relay race based on the application information indicated in the issuance application notified from the verifier terminal 40 (step S305). The certificate management server 10 links the hierarchical VC for participant registration of each school created in step S305, and notifies the member terminal 20 that the hierarchical VC for participant registration has been issued (step S306).
[0069] Then, the business operator terminal 30 notifies the certificate management server 10 of an application (application for authorization) to grant editing authority for the hierarchical VC for which an issuance application was made in step S304 and / or lower hierarchical VC issuance authority to the designated user (school representative such as track and field club advisor of each school) (step S307). The certificate management server 10 sets editing authority in the hierarchical VC created in step 304 and / or lower hierarchical VC issuance authority based on the application information indicated in the application for authorization notified from the verifier terminal 40 (step S308). The certificate management server 10 notifies the member terminal 20 that editing authority for the hierarchical VC for participant registration has been granted (step S309).
[0070] A user with editing authority sets the participating students of TOPPAN High School in the participation slots provided for participant registration in the hierarchical VC for participant registration. The member terminal 20 cooperates with the edited content for the hierarchical VC for participant registration, notifies the edited content to the certificate management server 10, and notifies the certificate management server 10 of a creation request for creating a VP (step S310).
[0071] The VP to be created here is a VP used to prove that the student is eligible to participate in the 400m relay race, and is, for example, a VP that proves that the participating student belongs to the track and field club (small organization) and that the track and field club to which the participating student belongs is a club activity at TOPPAN High School. The certificate management server 10 creates a VP based on the application information indicated in the creation application notified from the member terminal 20. For example, the certificate management server 10 creates a VP for a participating student that combines information proving that the student belongs to TOPPAN High School, information proving that the student belongs to the track and field club, and information proving that the track and field club is a club activity belonging to TOPPAN High School. The certificate management server 10 registers (saves) the created VP in the management information 120 (step S311).
[0072] The certificate management server 10 associates the edited content for the hierarchical VC for participant registration edited by the member terminal 20, and notifies the verifier terminal 40 of the edited content (step S312).
[0073] Here, if it becomes necessary to edit the hierarchical VC for participant registration, for example, by adding or changing the students participating in the 400m relay race, a user with editing authority will edit the hierarchical VC for participant registration. The member terminal 20 links the edited content to the hierarchical VC for participant registration and notifies the certificate management server 10 of the edited content (step S313). The certificate management server 10 determines whether the time when the edited content was notified from the member terminal 20 was within the deadline for the registration period for participating students in the 400m relay race (step S314). If it is within the deadline, the certificate management server 10 reflects the edited content in the management information 120 and notifies the verifier terminal 40 of the edited content (step S315). On the other hand, if it is after the deadline, the certificate management server 10 rejects the edit and notifies the member terminal 20 of that fact.
[0074] The external organization (JAAF) staff member will check the student's VP and the student's hierarchical VC for participant registration and determine whether the student is eligible to participate. If the student is eligible, the student will be approved to participate in the 400m relay. The verifier terminal 40 notifies the certificate management server 10 whether or not the participation of the participating students set in the hierarchical VC has been approved (step S316).
[0075] The certificate management server 10 stores the information indicating whether or not the participation has been approved, which has been notified from the verifier terminal 40, in the management information 120, and reflects the stored information (information indicating whether or not the participation has been approved) in the hierarchical VC for participant registration (step S317). The certificate management server 10 notifies the member terminal 20 that the information indicating whether or not the participation has been approved has been reflected in the hierarchical VC for participant registration (step S318).
[0076] The member terminal 20 also notifies the certificate management server 10 of various inquiries regarding digital certificates, such as requests to view a list of VCs or details about VCs (digital certificates) held by the user, or inquiries such as requests to renew or reissue VCs (step S319). The certificate management server 10 responds to the inquiries notified from the member terminal 20 (step S320).
[0077] FIG. 9 is a sequence diagram showing an example of a hierarchical digital certificate issuing process (external cooperation type) according to the embodiment. FIG. 9 shows the flow of processing that is carried out on the day of the competition and after the competition has ended, after the series of processing shown in FIG. 8 (processing for registering participants in the 400m relay competition) has been completed.
[0078] On the day of the competition, when entering the competition venue, the user (participating student) operates the member terminal 20 to present the VC, and the VC is transmitted to the verifier terminal 40 via the certificate management server 10 (step S400). The VC presented here includes a hierarchical VC for participant registration in the 400m relay competition. In this hierarchical VC for participant registration, the user (participating student) is set as a participant in the competition. The VC presented here may include the digital student ID (higher level digital certificate) of the participating student. Also, the VC presented here may include a facial photograph registered in the management information 120. Furthermore, instead of the VC presented here, the member terminal 20 may display a two-dimensional code or the like indicating a link to the VP. The VP indicated in this link is the VP created by the certificate management server 10 in step S311 of FIG. 8 and registered in the management information 120. For example, a person in charge of the external organization (JAAF) reads the two-dimensional code displayed on the member terminal 20 with the verifier terminal 40. The verifier terminal 40 references the VP by accessing the link embedded in the read two-dimensional code, and verifies, based on the referenced VP, that the participating student is a student who has been pre-registered to participate.
[0079] The verifier terminal 40 requests the certificate management server 10 to verify the VC notified from the member terminal 20 in step S400 in order to confirm its authenticity (step S401). The certificate management server 10 verifies the VC notified from the verifier terminal 40, confirms that the certification content to be verified has not been tampered with (step S402), and notifies the verifier terminal 40 of the verification result (step S403).
[0080] After the end of the competition, the verifier terminal 40 notifies that the status of the user who holds the hierarchical VC for contestant registration has been changed due to the end of the competition, and notifies the certificate management server 10 of an application to change the hierarchical VC held by the user (status change application) (step S405). The certificate management server 10 corrects the management information 120 linked to the issued VC (hierarchical VC for contestant registration) based on the application information indicated in the status change application notified from the verifier terminal 40, and reflects the corrected items in the hierarchical VC for contestant registration (step S406). The certificate management server 10 notifies the member terminal 20 that the status of the hierarchical VC for contestant registration has been changed (step S407). In addition, the certificate management server 10 notifies the verifier terminal 40 that the processing related to the status change requested in step S405 has been completed (step S408).
[0081] Here, examples of screens displayed on the member terminal 20 will be described with reference to Fig. 10 to Fig. 13. Fig. 10 to Fig. 13 are diagrams showing examples of screens displayed on the member terminal 20 according to the embodiment.
[0082] 10 and 11 show examples of screens that are displayed on the member terminal 20 when a user creates a hierarchical digital certificate.
[0083] An example of a VC creation screen is shown in Fig. 10. In this figure, the image displayed on the member terminal 20 has an input field for inputting a community name, a selection field for selecting a position, an input field for setting an issue date, an input field for setting an expiration date, and a specification field for specifying an image of a card icon. The input field for entering the community name is an input field for entering the name of the small organization that will correspond to the hierarchical digital certificate being created. The selection field for selecting the position is a selection field for selecting the position of a user with issuing authority in the small organization that will correspond to the hierarchical digital certificate being created (whether they are the administrator of the hierarchical digital certificate or a member). The input field for setting the issue date is an input field for entering the date on which the hierarchical digital certificate being created will be issued. The input field for setting the expiration date is an input field for entering the expiration date of the hierarchical digital certificate being created. The specification field for specifying the card icon image is a specification field for specifying the card icon image to be used when displaying the hierarchical digital certificate being created. An organization or user with issuing authority can create a hierarchical digital certificate for a community (small organization) by setting the name of the community (small organization) and other information according to the creation screen shown in Figure 10.
[0084] Figure 11 shows an example of the VC management screen. This figure shows that a hierarchical digital certificate has been created for a small organization with the community name "26th Student Council." This figure also has operation buttons for editing and deleting, and a registration field for registering member names. An organization or user with editing privileges can register, edit, or delete members belonging to a community (small organization) in the small organization's hierarchical digital certificate using the management screen shown in Figure 11.
[0085] 12 shows an example of a presentation screen displayed on member terminal 20 when a hierarchical digital certificate is presented to a verifier. In this figure, the hierarchical digital certificate of the TOPPAN High School Student Council is displayed in a card design on member terminal 20. This hierarchical digital certificate indicates that the sub-organization is the "Student Council" and that Toppan Hanako is a member of the Student Council. This figure also has a selection button labeled "QR (registered trademark) display." When this selection button is operated, a two-dimensional code with the information indicated in the hierarchical digital certificate embedded therein is displayed together with, or instead of, the hierarchical digital certificate with a card design.
[0086] 13 shows an example in which a series of digital certificates (including higher-level digital certificates and hierarchical digital certificates) held by a user are displayed on the member terminal 20. In this figure, the digital certificate for "TOPPAN High School" corresponds to the higher-level digital certificate. Below this higher-level digital certificate, hierarchical digital certificates for the small organizations that belong to "TOPPAN High School," such as the "Student Council," "High School Athletic Meet Relay Members," and "Fun Friends Club," are displayed.
[0087] In this diagram, if you select the higher-level digital certificate, which is the digital certificate for "TOPPAN High School," and scroll horizontally, higher-level digital certificates from other organizations, such as certificates from other issuing organizations, will be displayed. If hierarchical digital certificates have been issued below the higher-level digital certificate corresponding to this other issuing organization certificate, those hierarchical digital certificates will be displayed. For example, if the issuing organization is an organization that issues certificates for various qualifications, a higher-level digital certificate indicating that the user belongs to that issuing organization will be displayed as the higher-level digital certificate, and below that, hierarchical digital certificates corresponding to the various qualifications the user has obtained under that issuing organization will be displayed.
[0088] Here, examples of screens displayed on the business operator terminal 30 will be described with reference to Fig. 14 to Fig. 17. Fig. 14 to Fig. 17 are diagrams showing examples of screens displayed on the business operator terminal 30 according to the embodiment.
[0089] Fig. 14 is a diagram similar to Fig. 4, showing an example of a management screen displayed on the operator terminal 30 when an organization creates a higher-level digital certificate or a hierarchical digital certificate. In this diagram, by operating button B1 set in the authority / qualification management item, it is possible to set authority (issuance authority and / or editing authority) for the user to whom the higher-level digital certificate or hierarchical digital certificate is to be issued.
[0090] Fig. 15 shows an example of a screen displayed on the business operator terminal 30 when button B1 shown in Fig. 14 is operated. This figure shows the hierarchical digital certificate issued to the user (Toppan Hanako) displayed in Fig. 14 and the contents set in that hierarchical digital certificate. In this example, a hierarchical digital certificate for the track and field club is issued to the user shown in Figure 14, and the hierarchical digital certificate for the track and field club indicates that Toppan Hanako has been set as the vice-captain of the track and field club, and that the vice-captain of the track and field club can manage authority and grant qualifications. "Manage authority" here refers to managing the authority to appoint and expel regular members of the track and field club, and the authority to appoint and expel students who have provisionally joined the track and field club. "Granting qualifications" here refers to granting regular members of the track and field club the right to participate in events (such as track and field competitions). In this diagram, the execute button B2 is set in the authority management column, and the execute button B3 is set in the qualification column. By operating the execute button B2 or B3, settings related to authority management or qualification can be made.
[0091] Fig. 16 shows an example of a screen displayed on the operator terminal 30 when the execute button B2 shown in Fig. 15 is operated. In this figure, a registration field is provided for registering club members by grade level. Tapping on the registration field displays a search field for searching for students, and students searched using the search field can be registered as track and field club members. Tapping on the plus button to the right of the registration field also allows a new registration field to be created, allowing the number of registrants to be increased.
[0092] Fig. 17 shows an example of a screen displayed on the operator terminal 30 when the execute button B3 shown in Fig. 15 is operated. In this figure, the "3rd TOP Competition" is set as an event, and participants for this competition can be registered. In this diagram, there is a registration field for registering participants for each of the short and middle distance events. Tapping on the registration field displays a search field for searching for students, and students found using the search field can be registered as participants. Additionally, by tapping the plus button on the right side of the registration field, a new registration field can be created, allowing the number of participants to be increased.
[0093] FIG. 18 is a diagram showing an example of a hierarchy according to an embodiment. Some parts of this diagram overlap with FIG. 15. This diagram shows a list of hierarchical digital certificates issued to the user (Hanako Toppan) displayed in FIG. 14. In this diagram, hierarchical digital certificates corresponding to the student council, the track and field club, and an optional group have been issued to the user (Hanako Toppan) displayed in FIG. 14. Of these, the hierarchical digital certificate for the student council indicates that the user (Hanako Toppan) displayed in FIG. 14 is set as a general student council committee member. Furthermore, the hierarchical digital certificate for the track and field club indicates that the user (Hanako Toppan) displayed in FIG. 14 is set as vice-president. Furthermore, it shows that hierarchical digital certificates for the optional groups, namely, the close friends group, the school trip group, and the summer vacation amusement park group, have been issued to the user (Hanako Toppan) displayed in FIG. 14.
[0094] As described above, the certificate management server 10 (management device) according to the embodiment includes a receiving unit 130 and a certificate issuing unit 131. The receiving unit 130 receives an application for issuance of a digital certificate. In response to the issuance application received by the receiving unit 130, the authority setting unit 132 issues a hierarchical digital certificate attesting to affiliation with a sub-organization formed within the organization, based on a certificate attesting to affiliation with the organization. With this configuration, a hierarchical digital certificate attesting to affiliation with a sub-organization formed within the organization can be issued by linking it to a digital certificate (higher digital certificate) attesting to affiliation with the organization, and it is possible to show that the sub-organization belongs to the organization without changing or updating the higher digital certificate. Therefore, it is possible to easily prove that a user belonging to a small organization certainly belongs to the small organization, and that the small organization belongs to the organization.
[0095] In the certificate management server 10 according to the embodiment, a small organization is created by the organization. The accepting unit 130 accepts an application for issuance of a hierarchical digital certificate attesting to affiliation with the small organization from the organization. The certificate issuance unit 131 issues a hierarchical digital certificate in response to the issuance application accepted by the accepting unit 130. In this way, the certificate management server 10 according to the embodiment can issue a hierarchical digital certificate attesting to affiliation with the small organization at the initiative of the organization.
[0096] The certificate management server 10 according to the embodiment further includes an authority setting unit 132. The authority setting unit 132 grants editing authority to edit a hierarchical digital certificate issued by the certificate issuing unit 131 to a user designated by an organization. This allows the certificate management server 10 according to the embodiment to grant editing authority to a hierarchical digital certificate issued by an organization to a user designated by the organization, thereby enabling appropriate management of the issuance and editing of hierarchical digital certificates.
[0097] Furthermore, in the certificate management server 10 according to the embodiment, a small organization is created by a user belonging to the organization. The receiving unit 130 receives, from the user belonging to the organization, an application for issuance of a hierarchical digital certificate attesting to the user's affiliation to the small organization. The certificate issuance unit 131 issues a hierarchical digital certificate in response to the issuance application received by the receiving unit 130. As a result, in the certificate management server 10 according to the embodiment, a hierarchical digital certificate attesting to the user's affiliation to the small organization can be issued at the initiative of the user, and the organization can be spared the trouble of issuing a hierarchical digital certificate for a small organization that is not managed by the organization.
[0098] The certificate management server 10 according to the embodiment further includes an authority setting unit 132. The authority setting unit 132 grants issuance authority to issue a hierarchical digital certificate based on a higher-level digital certificate (a higher-level digital certificate proving affiliation to an organization) issued to a user who belongs to an organization. The certificate issuance unit 131 issues a hierarchical digital certificate on the condition that the issuance request accepted by the acceptance unit 130 is from a user who has been granted issuance authority. In this way, by granting issuance authority, the certificate management server 10 according to the embodiment can manage the issuance of a hierarchical digital certificate so that a hierarchical digital certificate is not issued to an unknown administrator.
[0099] Furthermore, in the certificate management server 10 according to the embodiment, the authority setting unit 132 grants editing authority to edit a hierarchical digital certificate issued by the certificate issuing unit 131 to a user who has issuing authority. This allows the certificate management server 10 according to the embodiment to enable the user who issued the hierarchical digital certificate to edit the hierarchical digital certificate, thereby improving convenience.
[0100] Moreover, the certificate management server 10 according to the embodiment further includes an authority setting unit 132. The authority setting unit 132 grants issuance authority to issue a hierarchical digital certificate that certifies that a team formed in a small organization corresponding to the hierarchical digital certificate issued by the certificate issuance unit 131 belongs to the small organization. As a result, the certificate management server 10 according to the embodiment can link a lower hierarchical digital certificate (second hierarchical digital certificate) to a higher hierarchical digital certificate (first hierarchical digital certificate), thereby forming a certificate tree with a multi-level hierarchical structure.
[0101] The certificate management server 10 according to the embodiment further includes an authority setting unit 132. The authority setting unit 132 grants issuing authority to issue hierarchical digital certificates and sets the approval level by the organization for issuing the hierarchical digital certificate. As a result, the certificate management server 10 according to the embodiment can set the issuing authority and the approval level by the organization required for issuance when issuing a hierarchical digital certificate, thereby enabling appropriate management of the issuance of hierarchical digital certificates.
[0102] Moreover, the management system 100 according to the embodiment includes a certificate management server 10 and a member terminal 20. The member terminal 20 is communicably connected to the certificate management server 10 (management device) and transmits an issuance request to the certificate management server 10. As a result, the management system 100 according to the embodiment achieves the effects described above.
[0103] The management system 100 and the certificate management server 10 in the above-described embodiment may be implemented in part or in whole by a computer. In this case, a program for implementing this function may be recorded on a computer-readable recording medium, and the program recorded on the recording medium may be read into a computer system and executed. Note that the term "computer system" here includes hardware such as an OS and peripheral devices. Additionally, "computer-readable recording media" refers to portable media such as flexible disks, optical magnetic disks, ROMs, CD-ROMs, etc., and storage devices such as hard disks built into computer systems. Furthermore, "computer-readable recording media" may also include devices that dynamically store programs for a short period of time, such as communication lines when transmitting programs via networks such as the Internet or communication lines such as telephone lines, and devices that store programs for a certain period of time, such as volatile memory within computer systems that serve as servers or clients in such cases. Furthermore, the above program may be one that realizes part of the above-mentioned functions, or may be one that can realize the above-mentioned functions in combination with a program already recorded in a computer system, or may be one that is realized using a programmable logic device such as an FPGA (Field Programmable Gate Array).
[0104] The embodiments of the present invention have been described in detail above with reference to the drawings, but the specific configuration is not limited to that described above, and various design changes can be made within the scope of the gist of the present invention. [Explanation of symbols]
[0105] 10...certificate management server, 20...member terminal 20, 30...business operator terminal, 40...verifier terminal, 11...communication unit, 12...storage unit, 13...control unit, 130...reception unit, 131...certificate issuing unit, 132...authority setting unit, 133...certificate management unit, 134...display control unit
Claims
1. A method of providing a method for providing a hierarchical digital certificate to an organization, the method comprising: receiving an application for issuance of a hierarchical digital certificate from the organization, the hierarchical digital certificate being used to certify affiliation with a sub-organization created by the organization based on a certificate certifying affiliation with the organization; a certificate issuing unit that issues the hierarchical digital certificate in response to the issuance request received by the receiving unit; an authority setting unit that grants an editing authority to edit the hierarchical digital certificate issued by the certificate issuing unit to a user designated by the organization; A management device comprising:
2. A method for providing a hierarchical digital certificate to a user belonging to an organization, the method comprising: receiving an application for issuance of a hierarchical digital certificate from the user belonging to the organization, the hierarchical digital certificate being created by the user and certifying the user's affiliation with the organization based on a certificate certifying the user's affiliation with the organization; a certificate issuing unit that issues the hierarchical digital certificate in response to the issuance request received by the receiving unit; an authority setting unit that grants authority to issue the hierarchical digital certificate based on a higher-level digital certificate issued to a user belonging to the organization and proving the user's affiliation with the organization; Equipped with the certificate issuing unit issues the hierarchical digital certificate on the condition that the issuance request accepted by the accepting unit is an application from a user who has been granted the issuing authority. Management device.
3. the authority setting unit grants editing authority to edit the hierarchical digital certificate issued by the certificate issuing unit to the user having the issuing authority; The management device according to claim 2 .
4. an authority setting unit that grants authority to issue the hierarchical digital certificate that certifies that a team formed in the small organization, corresponding to the hierarchical digital certificate issued by the certificate issuing unit, belongs to the small organization; The management device according to claim 1 .
5. a reception unit that receives applications for issuance of digital certificates; a certificate issuing unit that issues a hierarchical digital certificate that proves affiliation to a sub-organization formed in an organization based on a certificate that proves affiliation to the organization in response to the issuance application accepted by the accepting unit; and an authority setting unit that grants authority to issue the hierarchical digital certificate and sets an approval level by the organization regarding the issuance of the hierarchical digital certificate; A management device comprising:
6. The management device according to claim 1 ; an affiliate terminal that is communicably connected to the management device and that transmits the issuance request to the management device; A management system comprising:
7. A management method performed by a computer that is a management device, a receiving unit receiving, from an organization, an application for issuance of a hierarchical digital certificate that certifies affiliation with a sub-organization created by the organization based on a certificate certifying affiliation with the organization; a certificate issuing unit issues the hierarchical digital certificate in response to the issuance request accepted by the accepting unit; an authority setting unit granting an editing authority for editing the hierarchical digital certificate issued by the certificate issuing unit to a user designated by the organization; Management method.
8. The computer that is the management device receiving, from an organization, an application for issuance of a hierarchical digital certificate that certifies affiliation with a sub-organization based on a certificate created by the organization and certifying affiliation with the organization; issuing the hierarchical digital certificate in response to the accepted issuance request; granting an editing authority for editing the issued hierarchical digital certificate to a user designated by the organization; program.
9. The management device according to claim 2; an affiliate terminal that is communicably connected to the management device and that transmits the issuance request to the management device; A management system comprising:
10. A management method performed by a computer that is a management device, a receiving unit receiving, from a user belonging to an organization, an application for issuance of a hierarchical digital certificate that certifies affiliation to a sub-organization based on a certificate created by the user belonging to the organization, and a certificate issuing unit issues the hierarchical digital certificate in response to the issuance request accepted by the accepting unit; an authority setting unit granting an issuing authority to issue the hierarchical digital certificate based on a higher-level digital certificate issued to a user belonging to the organization and certifying the user's affiliation with the organization; the certificate issuing unit issues the hierarchical digital certificate on the condition that the issuance request accepted by the accepting unit is an application from a user who has been granted the issuing authority. Management method.
11. The computer that is the management device accepting an application for issuance of a hierarchical digital certificate from a user belonging to an organization, the hierarchical digital certificate being created by the user and certifying the user's affiliation with the sub-organization based on a certificate certifying the user's affiliation with the organization; issuing the hierarchical digital certificate in response to the accepted issuance request; granting an issuing authority to issue the hierarchical digital certificate based on a higher-level digital certificate issued to a user belonging to the organization and certifying the user's affiliation with the organization; issuing the hierarchical digital certificate on the condition that the accepted issuance request is from a user who has been granted the issuing authority; program.
12. The management device according to claim 5 ; an affiliate terminal that is communicably connected to the management device and that transmits the issuance request to the management device; A management system comprising:
13. A management method performed by a computer that is a management device, The reception department accepts the application for issuance of a digital certificate, a certificate issuing unit, in response to the issuance application received by the receiving unit, issues a hierarchical digital certificate certifying affiliation to a sub-organization formed in the organization based on a certificate certifying affiliation to the organization; an authority setting unit granting authority to issue the hierarchical digital certificate and setting an approval level by the organization regarding the issuance of the hierarchical digital certificate; Management method.
14. The computer that is the management device Accept applications for the issuance of digital certificates, In response to the accepted issuance application, a hierarchical digital certificate is issued that proves affiliation with a sub-organization formed within the organization based on a certificate that proves affiliation with the organization; granting issuing authority to issue the hierarchical digital certificate and setting an approval level by the organization for issuing the hierarchical digital certificate; program.
Citation Information
Patent Citations
Device and method for authentication
JP2000148012A
Trust establishment method and service control system based on trust
JP2006004314A
Authentication-authorization system, and authentication-authorization method
JP2009205230A
Management device, specification program, specification method and management system
JP2019164683A
System and method
WO2024024043A1