Terminal, information processing method, and program

The information processing device enhances electronic signature security and usability by authenticating identifying information from a portable recording medium with an IC chip, addressing concerns over digital document submission.

JP7782910B2Active Publication Date: 2025-12-09NEC CORP
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2022558646
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2020-10-27
Publication Date
2025-12-09
Estimated Expiration
2040-10-27

AI Technical Summary

Technical Problem

The use of electronic document submission is limited due to concerns about security and usability, with many individuals preferring paper documents over digital methods.

Method used

An information processing device and method that acquires and authenticates individual and terminal identifying information from a portable recording medium, using sensors and a portable recording medium equipped with an IC chip to enhance security and usability of electronic signatures.

Benefits of technology

Improves the usability and security of authentication processing by securely reading and using a private key for digital signatures, preventing fraudulent acts and enabling seamless execution of identity-verified processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007782910000001
    Figure 0007782910000001
  • Figure 0007782910000002
    Figure 0007782910000002
  • Figure 0007782910000003
    Figure 0007782910000003
Patent Text Reader

Abstract

An information processing device (100) is provided with: an acquisition unit (102) which acquires first personal identification information and terminal identification information from a portable recording medium having the first personal identification information and the terminal identification information recorded thereon; an authentication unit (104) which uses the first personal identification information and the terminal identification information acquired from the recording medium to authenticate second personal identification information acquired by a sensor mounted on a terminal and terminal identification information about the terminal; and an execution unit (106) which executes a prescribed process if the authentication is successful.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing device, an information processing method, and a program, and in particular to an information processing method for electronic procedures. to The present invention relates to an information processing device, an information processing method, and a program. [Background technology]

[0002] In recent years, the digitalization of documents has become widespread. Electronic signatures are used in documents to verify identity and to prove that documents have not been tampered with. In the unlikely event that a key is stolen, it is known to generate an electronic signature based on facial recognition, as described in Patent Document 1.

[0003] In addition, Patent Document 2 discloses a method in which a user takes a photograph of his / her own identification document with a camera on a mobile terminal to obtain an identification image and store it in the mobile terminal as a matching image, and when using a service, the camera obtains an image of the user's face, and the result of matching with the matching image is sent to an identity authentication server, where the user's identity is verified. certification The server contains an identity verification system that allows service use based on the results of the verification.

[0004] Patent Document 3 describes a system that provides services using membership cards, in which card ID information and terminal ID are associated and registered in a database so that services can be received using a mobile terminal device other than the membership card. update It is stated that [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2001-265738 [Patent Document 2] Japanese Patent Publication No. 2020-87461 [Patent Document 3] Japanese Patent Application Laid-Open No. 2007-80006 Summary of the Invention [Problem to be solved by the invention]

[0006] However, the use of electronic document submission is still limited to a limited number of people. This is thought to be because many people believe that submitting paper documents is safer and easier due to concerns about the reliability of security and the incompetence of using computers and mobile devices.

[0007] The present invention has been made in view of the above circumstances, and an object of the present invention is to improve the usability and security of authentication processing such as electronic signatures. [Means for solving the problem]

[0008] In order to solve the above-mentioned problems, each aspect of the present invention employs the following configuration.

[0009] The first aspect relates to an information processing device. An information processing device according to a first aspect includes: an acquisition means for acquiring the first individual identifying information and the terminal identifying information from a portable recording medium on which the first individual identifying information and the terminal identifying information are recorded; an authentication means for authenticating second personal identification information acquired by a sensor mounted on the terminal and the terminal identification information of the terminal using the first personal identification information and the terminal identification information acquired from the recording medium; and an execution means for executing a predetermined process when the authentication is successful.

[0010] A second aspect relates to an information processing method implemented by at least one computer. An information processing method according to a second aspect includes: The information processing device Acquire the first individual identifying information and the terminal identifying information from a portable recording medium on which the first individual identifying information and the terminal identifying information are recorded; authenticating second personal identification information acquired by a sensor mounted on the terminal and the terminal identification information of the terminal using the first personal identification information and the terminal identification information acquired from the recording medium; When the authentication is successful, executing a predetermined process.

[0011] Another aspect of the present invention may be a program that causes at least one computer to execute the method of the second aspect, or a computer-readable recording medium on which such a program is recorded. This recording medium includes a non-transitory tangible medium. The computer program includes computer program code which, when executed by a computer, causes the computer to perform the information processing method on an information processing device.

[0012] Any combination of the above components, and any transformation of the present invention into a method, device, system, recording medium, computer program, etc., are also valid aspects of the present invention.

[0013] Furthermore, the various components of the present invention do not necessarily have to be independent entities, but may be formed as a single member by multiple components, one component may be formed from multiple components, one component may be part of another component, or part of one component may overlap with part of another component, etc.

[0014] Furthermore, although the method and computer program of the present invention describe a number of steps in a sequential order, the order in which the steps are performed does not limit the order in which the steps are performed. Therefore, when implementing the method and computer program of the present invention, the order of the steps can be changed as long as it does not cause any problems in terms of the content.

[0015] Furthermore, the multiple steps of the method and computer program of the present invention are not limited to being executed at different times, and therefore, a step may occur while another step is being executed, or the execution timing of a step may partially or completely overlap with the execution timing of another step, etc. [Effects of the Invention]

[0016] According to the above aspects, it is possible to improve the usability and security of authentication processing such as electronic signatures. [Brief explanation of the drawings]

[0017] [Figure 1] 1 is a diagram conceptually showing the system configuration of an electronic procedure system according to an embodiment of the present invention; [Figure 2] FIG. 1 is a block diagram illustrating a hardware configuration of a computer that realizes an information processing device according to an embodiment of the present invention. [Figure 3] 1 is a functional block diagram showing a logical configuration of an information processing device according to an embodiment of the present invention; [Figure 4] FIG. 1 is a diagram illustrating an identification card equipped with an IC chip. [Figure 5] FIG. 2 is a diagram illustrating an example of the data structure of the memory of the IC chip of the identification card. [Figure 6] 10 is a flowchart illustrating an example of the operation of the information processing device according to the present embodiment. [Figure 7] FIG. 1 is a functional block diagram showing a logical configuration of an information processing apparatus according to an embodiment of the present invention. [Figure 8] FIG. 1 is a diagram illustrating an example of a usage flow of an electronic procedure system. [Figure 9] FIG. 10 is a diagram for explaining the flow of applying for issuance of a digital certificate. [Figure 10] FIG. 2 illustrates an example of a data structure of a storage device of an AP server. [Figure 11] FIG. 2 is a diagram for explaining data stored in the memory of the IC chip of the identification card. [Figure 12]FIG. 2 is a diagram illustrating an example of a data structure of a storage unit of a user terminal. [Figure 13] FIG. 10 is a diagram for explaining a personal identification procedure. [Figure 14] FIG. 10 is a diagram showing the flow of an initial registration procedure. [Figure 15] 10 is a flowchart illustrating an example of a procedure for identity verification processing. [Figure 16] FIG. 10 is a diagram illustrating another example of the flow of the initial registration procedure. [Figure 17] FIG. 10 is a diagram illustrating yet another example of the flow of the initial registration procedure. [Figure 18] FIG. 10 is a diagram showing a detailed flow of an electronic signature procedure. [Figure 19] FIG. 1 is a diagram showing an example of the usage flow of an electronic procedure system using an identification card without an IC chip. [Figure 20] FIG. 10 is a diagram showing the flow of an initial registration procedure. [Figure 21] 10 is a flowchart illustrating an example of the operation of the information processing device according to the present embodiment. [Figure 22] FIG. 10 is a diagram showing a detailed flow of a login process to a portal site. DETAILED DESCRIPTION OF THE INVENTION

[0018] Hereinafter, embodiments of the present invention will be described with reference to the drawings. In all drawings, similar components are designated by similar reference numerals, and their description will be omitted as appropriate. In the following drawings, configurations of parts that are not related to the essence of the present invention are omitted and are not shown.

[0019] In the embodiments, "acquisition" includes at least one of the following: a device going to retrieve data or information stored in another device or storage medium (active acquisition), and inputting data or information output from another device into the device (passive acquisition). Examples of active acquisition include making a request or inquiry to another device and receiving a reply, and accessing and reading information from another device or storage medium. An example of passive acquisition is receiving information that is distributed (or transmitted, pushed, etc.). Furthermore, "acquisition" may also mean selecting and acquiring data or information from received data or information, or selecting and receiving distributed data or information.

[0020] (First embodiment) <System Overview> FIG. 1 is a diagram conceptually illustrating the system configuration of an electronic procedure system 1 according to an embodiment of the present invention. The electronic procedure system 1 includes an AP server 10 and an information processing device 100. The AP server 10 may include a certification authority 50 that issues an electronic certificate (e.g., X.509), or may use a certification authority 50 external to the AP server 10. The information processing device 100 is a mobile terminal owned or used by a user U, such as a smartphone, tablet terminal, or personal computer. Hereinafter, the information processing device 100 will also be referred to as a user terminal 100.

[0021] The information processing device 100 can be realized by installing and running the application program 40 on the user terminal 100. In response to a request from the user U, the certificate authority 50 issues a pair of a private key for electronic signature 52 and a public key for electronic signature 54, along with a digital certificate. The public key for electronic signature 54 and its digital certificate may (A) be registered in the storage device 20 of the AP server 10 without being recorded on the identification card 30, or (B) be recorded in memory on the IC chip of the identification card 30. In the case of (B), upon receiving the public key for electronic signature 54 and its digital certificate recorded in memory on the IC chip of the identification card 30, the AP server 10 has the certificate authority 50 verify the digital certificate of the public key for electronic signature 54. The private key for electronic signature 52 is recorded, for example, together with the digital certificate in memory on the IC chip of the user U's identification card 30. A user U can use the private key for electronic signature 52 recorded on the identification card 30 to attach an electronic signature 82 to an electronic document 80 and submit it from the user terminal 100 via the communication network 3 to a predetermined destination.

[0022] <Hardware configuration example> 2 is a block diagram illustrating an example of the hardware configuration of a computer 1000 that realizes an information processing device (user terminal) 100 (described later). The AP server 10 and the certificate authority 50 in FIG.

[0023] The computer 1000 includes a bus 1010 , a processor 1020 , a memory 1030 , a storage device 1040 , an input / output interface 1050 , and a network interface 1060 .

[0024] The bus 1010 is a data transmission path for transmitting and receiving data among the processor 1020, memory 1030, storage device 1040, input / output interface 1050, and network interface 1060. However, the method of connecting the processor 1020 and the like to each other is not limited to bus connection.

[0025] The processor 1020 is implemented by a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), or the like.

[0026] The memory 1030 is a main storage device realized by a RAM (Random Access Memory) or the like.

[0027] The storage device 1040 is an auxiliary storage device realized by an HDD (Hard Disk Drive), an SSD (Solid State Drive), a memory card, a ROM (Read Only Memory), or the like. The storage device 1040 stores program modules that realize each function of the information processing device (user terminal) 100 (for example, an acquisition unit 102, an authentication unit 104, an execution unit 106, a registration unit 108, etc., which will be described later). The processor 1020 loads each of these program modules into the memory 1030 and executes them, thereby realizing each function corresponding to the program module. The storage device 1040 may also store each data of the memory unit 120 of the information processing device (user terminal) 100 or the memory device 20 of the AP server 10.

[0028] The program module may be recorded on a recording medium. The recording medium on which the program module is recorded may include a non-transitory, tangible medium usable by the computer 1000, and the program code readable by the computer 1000 (processor 1020) may be embedded in the medium.

[0029] The input / output interface 1050 is an interface for connecting the computer 1000 with various input / output devices. The input / output interface 1050 also functions as a communication interface for performing short-range wireless communication such as Bluetooth (registered trademark) and NFC (Near Field Communication).

[0030] The network interface 1060 is an interface for connecting the computer 1000 to a communication network 3 (FIG. 1). This communication network 3 is, for example, a local area network (LAN) or a wide area network (WAN). Alternatively, the network interface 1060 may be an interface for connecting to the communication network 3 using a public line via a base station using various communication methods such as 4th generation (4G), 5th generation (5G), or Worldwide Interoperability for Microwave Access (WiMAX). The network interface 1060 may connect to the communication network 3 via a wireless connection or a wired connection.

[0031] The computer 1000 then connects to necessary equipment (e.g., the display (touch panel) of the user terminal 100, operation buttons, speaker, microphone, and sensors for acquiring personal identification information such as a camera and / or fingerprint sensor) via the input / output interface 1050 or the network interface 1060.

[0032] As will be described later, the information processing device 100 acquires personal identification information such as a facial photograph used to perform authentication processing to confirm the identity of the user U. In this embodiment, the authentication processing is performed using a person's facial image, but the authentication processing may also be performed using other biometric authentication information. The biometric authentication information includes at least one feature such as an iris, vein, auricle, fingerprint, or voiceprint. The authentication processing may also be performed by combining multiple pieces of biometric authentication information.

[0033] In this embodiment, since authentication processing is performed using a facial image, a guidance screen for capturing an image of the user U's face using the camera of the user terminal 100 is displayed on the display of the user terminal 100. When authentication processing is performed using other biometric authentication information, a sensor suitable for acquiring the biometric authentication information is used. For example, when a fingerprint is used, the acquisition unit 102 acquires fingerprint information using a fingerprint sensor of the user terminal 100. When a voiceprint is used, the acquisition unit 102 collects the voice of the user U using a microphone of the user terminal 100 and acquires voiceprint information.

[0034] A camera includes a lens and an imaging element such as a CCD (Charge Coupled Device) image sensor. Images generated by a camera are preferably moving images, but may also be frame images captured at predetermined intervals or still images.

[0035] 3 is a functional block diagram showing the logical configuration of information processing device 100 according to this embodiment. As described above, information processing device 100 is realized by installing application program 40 in user terminal 100 and executing it.

[0036] Each component of the information processing device 100 (user terminal) of this embodiment shown in Fig. 3 is realized by any combination of hardware and software of the computer 1000 shown in Fig. 2. Those skilled in the art will understand that there are various variations in the realization method and device. The functional block diagrams showing the information processing devices of each embodiment described below show logical functional blocks rather than hardware-based configurations.

[0037] The information processing device 100 includes an acquisition unit 102, an authentication unit 104, and an execution unit 106. The acquisition unit 102 acquires first personal identification information and terminal identification information from a portable recording medium on which the first personal identification information and terminal identification information are recorded. The authentication unit 104 authenticates second personal identification information acquired by a sensor mounted on the terminal and the terminal identification information of the terminal using the first personal identification information and terminal identification information acquired from the recording medium. The execution unit 106 executes a predetermined process when authentication is successful.

[0038] The first individual identifying information stored in the storage unit 120 of the user terminal 100 is, for example, facial photograph data or facial feature amounts of the individual whose identity has been verified in advance by eKYC (electronic Know Your Customer) or the like.

[0039] The terminal identification information is identification information that can uniquely identify the user terminal 100. As an example, the terminal identification information is identification information that the AP server 10 assigns to each user terminal 100 (or each application software installed on the user terminal 100). For example, the terminal identification information may be assigned by the AP server 10 when the user terminal 100 installs the application program 40 of the electronic procedure system 1.

[0040] In another example, the terminal identification information may be a unique identification number assigned to each individual mobile terminal, such as the user terminal 100's unique identifier (UID), IMEI (International Mobile Equipment Identifier), or MAC (Media Access Control) address.

[0041] The portable recording medium is, for example, an identification document such as a driver's license, health insurance card, My Number card, or passport, and is shown as an identification card 30 in FIG. 1 etc. The portable recording medium may be in any shape, including a card, sheet, or booklet. It is preferable that the portable recording medium bears a photograph of the person's face. The identification card 30 is preferably equipped with an IC chip including a memory capable of recording information.

[0042] Taking the My Number Card as an example, it is a plastic card of a certain thickness that has a photograph and name printed on one side and a personal number (also called My Number) printed on the other side.

[0043] FIG. 4 is a diagram illustrating an identification card 30 (My Number Card) equipped with an IC chip 32. The IC chip 32 includes a memory 34, a processor 36, and an NFC communication unit 38 that communicates with a user terminal 100, such as a smartphone, via NFC. The memory 34 stores a private key for digital signature 52, first personal identification information (facial feature values ​​42), a personal identification number (PIN) code 44, and terminal identification information (terminal ID 46). The private key for digital signature 52 is used when applying a digital signature 82 to an electronic document 80 as a predetermined process, which will be described in detail in a later embodiment. In this embodiment, a process for identity verification is performed to securely read and use the private key for digital signature 52 from the identification card 30.

[0044] The first individual identifying information (facial feature amount 42) recorded in the memory 34 is also, for example, facial photograph data or facial feature amount of the individual whose identity has been verified in advance by eKYC or the like. The first personal identification information is This is the facial feature amount authenticated in the procedure (procedure P5 in FIG. 8) of recording personal identification information in the user terminal 100. The terminal identification information (terminal ID 46) recorded in the memory 34 is information that has been written in advance from the user terminal 100 to the identification card 30 through a process of linking the user terminal 100 and the identification card 30, which will be described in detail in an embodiment below.

[0045] The PIN code 44 is a personal identification number consisting of a predetermined number of digits (e.g., four or six digits) of numbers (or may include alphabetic characters and symbols) preset by the user U, which must be entered when reading information recorded in the memory 34. The PIN code 44 is set by the user U, for example, when registering an electronic certificate on the My Number card at a government office or the like, and is recorded in the memory 34. For example, when reading information recorded in the memory 34, the user first inputs the PIN code into the user terminal 100 and transmits it to the IC chip 32. The processor 36 compares the received PIN code with the PIN code 44 recorded in the memory 34. If the authentication is successful, reading of the information recorded in the memory 34 is permitted; if the authentication is unsuccessful, reading is not permitted.

[0046] The acquisition unit 102 of the user terminal 100 transmits the PIN code to perform NFC communication with the NFC communication unit 38 of the IC chip 32, and if authentication is successful, the acquisition unit 102 can read and acquire the information recorded in the memory 34. In this way, the PIN code can prevent unauthorized reading of the information recorded in the memory 34 in the identification card 30.

[0047] Furthermore, the user terminal 100 may read or write information from or to the memory 34 via a reader / writer for reading and writing information recorded in the memory 34. That is, the acquiring unit 102 may acquire the first personal identifying information and the terminal identifying information from the IC chip 32 of the identification card 30 via the reader / writer.

[0048] Fig. 5 shows a specific example of data stored in the memory 34 of the IC chip 32 of the identification card 30. Fig. 5(a) shows an example of the data structure of the memory 34 in a form (A) above in which the public key for electronic signature 54 is not recorded on the identification card 30. Fig. 5(b) shows an example of the data structure of the memory 34 in a form (B) above in which the public key for electronic signature 54 is recorded on the identification card 30.

[0049] The memory 34 has a basic area 35a and an extended area 35b. The basic area 35a is an area used by the issuer or management organization of the identification card 30, and mainly stores information necessary for the original purpose of using the identification card 30. The extended area 35b is an area permitted for use by various organizations (e.g., private businesses) that provide various services, including electronic procedures using the identification card 30, and mainly stores information necessary for providing various services. It is desirable that the basic area 35a be structured so that it cannot be used by private businesses or the like.

[0050] The basic area 35a of the memory 34 in Figure 5(a) stores image data of a facial photograph of the user U printed on the face of the identification card 30, a first PIN code (e.g., a four-digit number) (shown as "PIN1" in the figure) for reading the image data of the facial photograph from the memory 34, a private key for electronic signature, and a second PIN code (e.g., six or more alphanumeric characters) (shown as "PIN2" in the figure) for reading the private key for electronic signature.

[0051] In addition, if it is determined that an attempt has been made to illegally read the private key for electronic signature recorded in the basic area 35a by tampering or the like without inputting the PIN code, the memory 34 may be locked, the data in the memory 34 may be erased, or the IC chip 32 including the memory 34 may be destroyed.

[0052] The extended area 35b stores encrypted information including the terminal ID, facial features, and the first and second PIN codes. The terminal ID also functions as a PIN code that authorizes access to the extended area 35b. The encrypted first PIN code stored in the extended area 35b can be decrypted if face authentication of the user U is successful by matching the facial features stored in the extended area 35b with a facial image of the user U captured by the user terminal 100. In other words, if face authentication is successful, a facial photo can be read from the basic area 35a using the decrypted first PIN code. The encrypted second PIN code stored in the extended area 35b is similar to the encrypted first PIN code described above. If face authentication is successful, a private key for electronic signatures can be read from the basic area 35a using the decrypted second PIN code. Writing information from the electronic procedure system 1 to the extended area 35b will be described later.

[0053] 5(b) shows an example in which, in addition to the information stored in the basic area 35a of the memory 34 in FIG. 5(a), a public key for electronic signature and its electronic certificate are also stored in the basic area 35a. The second PIN code is used as a PIN code for reading not only the private key for electronic signature, but also the public key for electronic signature and the electronic certificate. Similar to the encrypted first PIN code described above, if face authentication is successful, the private key for electronic signature, the public key for electronic signature, and the electronic certificate can be read from the basic area 35a using the decrypted second PIN code.

[0054] The predetermined processing executed by the execution unit 106 is, for example, processing that requires identity verification, such as processing to apply a digital signature 82 to an electronic document 80 to be submitted to a predetermined institution. For example, processing to apply a digital signature 82 to an electronic document 80 and send it to a predetermined destination when electronically submitting a tax return. Alternatively, the predetermined processing may also include authentication processing required to receive various services that use the identification card 30, such as when the identification card 30 (for example, a My Number card) is used as a health insurance card, driver's license, or identification, when carrying out administrative procedures related to My Number, when using online contracts for mortgage loans or real estate transactions, or when using services to receive a resident card or family register at a convenience store, etc.

[0055] In the example of filing a tax return, a user U starts a predetermined browser using a user terminal 100 and accesses a predetermined web page of the National Tax Agency. After entering the necessary information, the user affixes a digital signature 82 to an electronic document 80 of the tax return documents, and then transmits the tax return documents via a communication network 3 such as the Internet.

[0056] When digitally signing an electronic document 80 on the National Tax Agency's tax return web page, the information processing device 100 (application program 40) of this embodiment is started. After verifying the identity of the person using the procedure described below, the digital signature 82 is applied to the electronic document 80 using the private key for digital signature 52 stored in the memory 34 of the identification card 30, and the electronic document 80 can be sent to a predetermined address for submission.

[0057] <Example of operation> FIG. 6 is a flowchart showing an example of the operation of the information processing device 100 of this embodiment. First, the acquisition unit 102 acquires first personal identification information and terminal identification information from the IC chip 32 of the identification card 30 (step S1). In this example, the first personal identification information is a facial image or facial features of the user U. The terminal identification information is a terminal ID assigned when the application program 40 is installed in the user terminal 100.

[0058] Specifically, the acquisition unit 102 displays a guidance screen on the display to prompt the user U to read information from the identification card 30. The user U follows the instructions on the guidance screen and brings the identification card 30 close to a predetermined position on the user terminal 100. The acquisition unit 102 communicates with the NFC communication unit 38 of the identification card 30 to read and acquire the facial feature amount 42 and terminal ID 46 recorded in the memory 34 of the IC chip 32. As described above, the facial feature amount 42 is a facial feature amount whose identity has been verified in advance.

[0059] Normally, when reading information from the memory 34 of the identification card 30, it is necessary to input a preset PIN code to be successfully authenticated. As will be explained in the embodiment described later, in the electronic procedure system 1, the PIN code 44 is input in advance to link the identification card 30 with the user terminal 100, so that input of the PIN code can be omitted when performing a predetermined process later.

[0060] Next, the authentication unit 104 acquires second personal identifying information using a sensor (step S3). Specifically, the camera of the user terminal 100 is activated, and a guidance screen for taking a facial image of the user U is displayed on the display. The user U can take a facial image by following the instructions on the guidance screen. As described above, liveness verification may be used in combination to prevent fraudulent acts such as impersonation using a life-size photograph of another person's face.

[0061] Then, the authentication unit 104 compares the first individual identifying information (the facial feature amount 42 read from the IC chip 32) acquired in step S1 with the second individual identifying information (the facial image (facial feature amount) captured by the user terminal 100) acquired in step S3, and also compares the terminal identifying information (the terminal ID 46 read from the IC chip 32) acquired in step S1 with the terminal identifying information stored in the storage unit 120 (step S5). If authentication of both the individual identifying information and the terminal identifying information is successful (YES in step S7), the execution unit 106 executes a predetermined process (step S9). If authentication of at least one of the individual identifying information and the terminal identifying information is unsuccessful (NO in step S7), the execution unit 106 bypasses step S9 and ends this process. In other words, the execution unit 106 does not execute the predetermined process.

[0062] As described above, the predetermined process is, for example, a process of applying a digital signature 82 to a digital document 80. Details will be explained in the second embodiment below.

[0063] As described above, in this embodiment, the acquisition unit 102 reads out first individual identifying information (facial features) and terminal identifying information (terminal ID) from the identification card 30 or the like, and the authentication unit 104 compares second individual identifying information (facial image and facial features) acquired by a sensor such as a camera of the user terminal 100 with the first individual identifying information acquired by the acquisition unit 102, and also compares the terminal identifying information of the user terminal 100 with the terminal identifying information acquired by the acquisition unit 102. Then, if the authentication by the authentication unit 104 is successful, the execution unit 106 can perform a predetermined process, for example, digitally signing 82 the digital document 80.

[0064] As described above, according to the configuration of this embodiment, identity authentication processing is performed using the identification card 30 and the user terminal 100, thereby preventing fraudulent acts such as impersonation and enabling the legitimate execution of predetermined processing that requires identity verification. Furthermore, by simply verifying identity on the user terminal 100, it becomes possible to perform predetermined processing, such as applying a digital signature 82 to a digital document 80, without the need for complicated operations. This improves the usability and security of digital signatures.

[0065] (Second embodiment) 7 is a functional block diagram showing the logical configuration of an information processing device 100 according to this embodiment. The information processing device 100 according to this embodiment is similar to the above-described embodiments, except that it has a configuration for performing a process of linking an identification card 30, on which a private key for digital signature 52 required for a predetermined process is recorded, with a user terminal 100. The information processing device 100 according to this embodiment further includes a registration unit 108 in addition to the configuration shown in FIG. 3. However, the configuration of this embodiment may be combined with at least one of the configurations of the other embodiments as long as no contradiction occurs.

[0066] The registration unit 108 performs authentication using the first personal identification information (facial image) and the second personal identification information (facial features) that has been verified and is stored in the memory unit 120 of the user terminal 100 by the authentication unit 104, and when the authentication is successful, stores the terminal identification information (terminal ID 46) in the recording medium (IC chip 32 of the identification card 30).

[0067] <electronic procedure System usage flow> A user U must complete a predetermined procedure before using the electronic procedure system 1. The following describes the preparations required to apply a digital signature 82 to an electronic document 80 using an information processing device 100 and an identification card 30 equipped with an IC chip 32, such as a My Number card.

[0068] 8 is a diagram showing an example of a usage flow of the electronic procedure system 1. An example will be described below in which an Individual Number card equipped with an IC chip 32 is used as the identification card 30. Here, the identification card 30 is also referred to as an Individual Number card 30a. An example in which an identification card 30 without an IC chip 32 is used will be described in the fourth embodiment described later.

[0069] First, user U goes to a predetermined application location with the My Number Card 30a and conducts an application procedure for issuing an electronic certificate (procedure P1). At this time, registration for using the electronic procedure system 1 (user registration) is also performed, and the account information of user U required when logging in to the electronic procedure system 1 is also set. Then, the application program 40 of the electronic procedure system 1 is installed on the user terminal 100 (procedure P3).

[0070] Next, a face image (face feature amount) confirmed to be the user himself / herself by eKYC or the like is stored in the storage unit 120 of the user terminal 100 (procedure P5). Then, an initial registration procedure for using the electronic procedure system 1 is performed via the application 40 (procedure P7). Through the above processing, the identity card 30, the user terminal 100, and the application program 40 can be linked to each other by the terminal ID 46.

[0071] When the preparations up to this point are completed, it becomes possible to perform electronic procedures such as an electronic signature procedure when necessary (procedure P11). Hereinafter, the details of each procedure will be described.

[0072] <P1: Electronic Certificate Issuance Application Flow> FIG. 9 is a diagram for explaining the electronic certificate issuance application flow. There are electronic certificates for electronic signatures and those for user authentication for performing identity verification when using various services. Here, the issuance of an electronic certificate for an electronic signature will be described, but an application for issuing an electronic certificate for user authentication can also be made by the same process.

[0073] First, the user UThe user U takes his / her identification card 30 (e.g., My Number card 30a equipped with an IC chip 32) to a predetermined application location. There, he / she applies for issuance of an electronic certificate (step S101). For example, a person at the counter operates an operation terminal (not shown) for the AP server 10 to accept the application. When the information required for the application is entered from the operation terminal, the AP server 10 issues a user ID to the user U and registers the user (step S103). The user ID is account information required to log in to the electronic procedure system 1 when using the electronic procedure system 1. When logging in, the user U is required to enter an arbitrary password set by the user U and the user ID as the account information of the user U. The password may be changeable by the user U as needed to improve security. As shown in FIG. 10(a), the account information of the user U (user ID and password) is stored in the storage device 20.

[0074] Issuance of a user ID is not necessarily required, and a configuration may be adopted in which the user logs in using terminal identification information (terminal ID 46) assigned by the AP server 10 to each user terminal 100. In other words, if the face of the user U is photographed using the user terminal 100 and facial authentication is successful, the terminal ID 46 may be acquired and used as login information for the AP server 10. Since the terminal ID 46 is acquired upon successful facial authentication, input of a password may not be required to log in to the AP server 10.

[0075] Furthermore, the AP server 10 makes the certificate authority 50 issue a pair of the public key 54 for digital signature and the private key 52 for digital signature, and an electronic certificate (step S105). 10 This may be done after the user ID is issued and user registration is completed in step S3. Furthermore, the user U is prompted to set a personal identification number (also called a PIN code) to be entered when the digital certificate is issued, and the user U is prompted to enter this number using the operation terminal (step S107).

[0076] The AP server 10 records the private key for electronic signature 52 issued by the certificate authority 50 and the PIN code 44 entered by the user U in the memory 34 of the IC chip 32 of the My Number card 30a of the user U (step S109). FIG. 11(a) shows the data recorded in the memory 34 of the IC chip 32 of the My Number card 30a. This information is recorded, in particular, in a predetermined area of ​​the memory 34 of the IC chip 32. As described above, the data recorded in the memory 34 can be read when the PIN code 44 is input. In other words, even if the identification card 30 is lost or stolen, it is highly likely that the information recorded on the identification card 30 will not be read unless the PIN code 44 is known.

[0077] Furthermore, the AP server 10 stores the electronic signature public key 54 paired with the electronic signature private key 52 of the user U in association with the user ID of the user U in the storage device 20 (FIG. 10(b)) (step S111).

[0078] The memory 34 of the IC chip 32 in FIG. 11(b) further stores data of the facial photograph printed on the face of the My Number card 30a or a facial photograph. from A facial feature amount 42 indicating the extracted facial feature amount may be recorded.

[0079] <P3:アプリケーションのインストール> In step P3 of FIG. 8, an application program 40 for using the electronic procedure system 1 is downloaded to the user terminal 100 of the user U. A common pair of a challenge public key 58 and a challenge private key 56 is associated with the application program 40 downloaded to the user terminal 100 of each user U, and the identification information of the application program 40 and the challenge public key 58 are stored in association with each other in the storage device 20 (FIG. 10(d)). The identification information of the application program 40 may be, for example, information indicating the version of the application program 40. Furthermore, even if the application program 40 is of the same version, the challenge public key 58 may be changed to another challenge public key 58 after a predetermined period of time has elapsed or at any time to avoid risks such as hacking that may result from continued use of the same application program 40. Therefore, for example, information such as the acquisition date and time of the challenge public key 58 (the acquisition date and time from the certification authority 50) may be associated and stored in the storage device 20 (FIG. 10(d)).

[0080] The downloaded application is installed in the user terminal 100. After installation, the information processing device 100 displays a login screen on the display of the user terminal 100, requesting the user to enter account information (user ID and password) to log in to the electronic procedure system 1. Then, upon receiving the account information, the AP server 10 performs authentication processing for the user U, and stores the terminal identification information (indicated as terminal ID in the figure) of the user terminal 100 of the user U in association with the user ID of the user U in the storage device 20 (FIG. 10(c)). The terminal ID assigned by the AP server 10 is stored in the security area 122 of the storage unit 120 (FIG. 12(a)).

[0081] Furthermore, when the application program 40 is installed on the user terminal 100, the challenge secret key 56 is also downloaded and stored in the storage unit 120 of the user terminal 100. The challenge secret key 56 may be encoded and stored using white-box cryptography, or may be stored in a predetermined area of the storage unit 120. The predetermined area is preferably a security area 122 (FIG. 12(b)) that cannot be accessed by the OS (Operating System) or other applications. <P5: Personal identification procedure> FIG. 13 is a diagram for explaining the personal identification procedure. As shown in FIG. 13(a), the user U uses the camera of the user terminal 100 to take a picture of his / her face together with the face photo published on the face of the My Number card 30a. FIG. 13(b) shows a state where an image of the face of the user taken and an image of the My Number card 30a including the face photo on the face of the My Number card 30a are captured by the user terminal 100. This personal identification process may be performed by installing an application for personal identification on the user terminal 100, or may be performed on a predetermined website via a browser.

[0082] In order to ensure that the face being photographed is not a "disguise" using a photo or the like and that the person actually exists, it is preferable to take a video and perform a liveness verification.

[0083] Then, the face feature amounts extracted from the face image of the user U himself / herself and the face photo of the My Number card 30a are compared. If the result of the comparison is that the user is authenticated, the authenticated face feature amounts are stored in the security area 122 (FIG. 12(c)) of the storage unit 120 of the user terminal 100. Furthermore, the authenticated face feature amounts are written into the memory 34 of the IC chip 32 of the identification card 30.

[0084] <P7: Application initial registration procedure> 14 is a diagram showing the flow for initial setting of step P7 in FIG. 8, which is executed when the program is started for the first time after the application is downloaded to the user terminal 100 of the user U in step P3 in FIG. 8. However, this process may also be executed when the program is deleted after being downloaded and used, or when the application is downloaded and started again. Also, if the user U changes the user terminal 100 to a different model, this process is executed when the application is downloaded again to the new model and started again.

[0085] In this flow, as initial settings for using an application of the electronic procedure system 1, the user U's identity is verified and a registration procedure for the user terminal 100 that runs the application is performed. First, when the application is started on the user terminal 100, an initial registration screen is displayed and the user U enters account information to start the initial registration process (step S201). When the AP server 10 receives the account information of the user U, it executes challenge / response authentication for the user terminal 100 (step S203). Specifically, the AP server 10 generates a random number (challenge) 60 and transmits it to the user terminal 100.

[0086] Before responding to the challenge from the AP server 10, the user terminal 100 performs a process of verifying the user's identity and associating the identification card 30 with the user terminal 100 (steps S205 to S225). First, the acquisition unit 102 displays on the display of the user terminal 100 a screen for prompting the user to enter a PIN code 44 for accessing the identification card 30.

[0087] When the input of the PIN code 44 is accepted (step S205), the acquiring unit 102 performs NFC communication with the identification card 30, transmits the PIN code 44, and reads and acquires the facial feature 42 and the private key for electronic signature 52 recorded on the identification card 30 (step S207). In an example in which different PIN codes are set for the facial feature and the private key for electronic signature (the PIN code is not encrypted in the example of FIG. 5(a)), the acquiring unit 102 may accept the input of a first PIN code and a second PIN code. The facial feature may be read from the identification card 30 using the first PIN code, and the private key for electronic signature may be read from the identification card 30 using the second PIN code.

[0088] At this time, the identification card 30 compares the PIN code 44 received from the user terminal 100 with the PIN code 44 recorded on the identification card 30, and if they match, allows reading of the information recorded on the identification card 30. If the comparison results in a mismatch, reading of the information recorded on the identification card 30 is not permitted.

[0089] Then, the user terminal 100 executes identity verification processing (step S210).

[0090] 15 is a flowchart showing an example of the procedure for identity verification processing. First, the acquisition unit 102 activates the camera of the user terminal 100 and displays a guidance screen on the display of the user terminal 100 to prompt the user U to photograph his / her face. Then, the face is photographed and a facial image is acquired (step S211). The authentication unit 104 compares the facial feature amount extracted from the facial image captured by the camera with the facial feature amount 42 read and acquired from the identification card 30 in step S207 (step S213). Furthermore, when acquiring the facial image of the user by camera photography, the acquisition unit 102 preferably takes a video image to prevent impersonation, and the authentication unit 104 preferably performs liveness verification.

[0091] Here, the information used for identity verification may be the following combinations, but is not limited to these. Identity verification processing may be performed using at least one of the following patterns, or multiple patterns may be combined, or the pattern may be changed at a predetermined timing. (Pattern 1) The facial feature amount extracted from the face image captured by the camera is compared with the facial feature amount 42 acquired from the identification card 30. (Pattern 2) The facial features extracted from the face image captured by the camera are compared with the facial features recorded in the security area 122 of the memory unit 120 of the user terminal 100 when the user's identity was verified using eKYC (step P5 in Figure 8). (Pattern 3) The facial features extracted from the face image captured by the camera are compared with the facial features extracted from the face photograph image on the face of the identification card 30 captured by the camera. (Pattern 4) The facial features extracted from the image of the face photograph on the face of the identification card 30 taken with a camera are compared with the facial features recorded in the security area 122 of the memory unit 120 of the user terminal 100 when the user's identity was verified using eKYC (step P5 in Figure 8).

[0092] Returning to FIG. 14, if the result of the matching process indicates that the identity authentication has been successful (YES in step S221), the authentication unit 104 causes the acquisition unit 102 to store the acquired facial feature amount 42 and private key for electronic signature 52 in the security area 122 (FIG. 12(d)) of the storage unit 120. (Step S223) If the personal authentication fails (NO in step S221), the user U is notified that the authentication has failed and the processing will be interrupted, and the processing ends.

[0093] Furthermore, after the authentication is successful in step S221, the registration unit 108 displays on the display a guidance screen for writing the terminal identification information of the user terminal 100, in this case the terminal ID assigned when the AP server 10 installed the application program 40 in the user terminal 100, into the memory 34 of the IC chip 32 of the identification card 30. Following the instructions on the guidance screen, the user U brings the identification card 30 close to a predetermined position on the user terminal 100. The registration unit 108 communicates with the NFC communication unit 38 of the identification card 30 and writes the terminal ID 46 into the memory 34 of the IC chip 32 (FIG. 11(c)) (step S225).

[0094] In this example, the acquisition unit 102 reads the private key for electronic signature 52 from the identification card 30 in step S207, but it is also possible to read only the facial feature amount 42 in step S207, and after successful authentication in step S221, the acquisition unit 102 reads the private key for electronic signature 52 from the identification card 30 and store it in the memory unit 120 in step S223.

[0095] Then, the execution unit 106 performs processing to apply a digital signature 62 to the random number (challenge) 60 transmitted from the AP server 10 in step S203 using the challenge public key 58 and transmit the digital signature 62 to the AP server 10 (step S227).

[0096] When the AP server 10 receives the random number (challenge) 60 with the digital signature 62 from the user terminal 100, it verifies the challenge response (step S229). The challenge response verification uses the challenge public key 58 stored in the storage device 20. The AP server 10 may notify the user terminal 100 of the result of the challenge verification. For example, the AP server 10 may notify the user terminal 100 that the challenge was successful and that the user will be able to perform identity verification using the identification card 30 and execute a predetermined process in the future. Alternatively, the AP server 10 may notify the user that the challenge was unsuccessful and therefore the predetermined process cannot be executed.

[0097] Fig. 16 is a flowchart showing another example of the application initial registration procedure of Fig. 14. In this example, instead of the PIN input in step S205 of Fig. 14, face authentication is used to enable access to the memory 34 of the IC chip 32 of the identification card 30. When the initial registration process is started in step S201 of Fig. 14, the user terminal 100 executes identity verification processing (step S210) (Fig. 15).

[0098] 15, the acquisition unit 102 reads and acquires the facial image of the user U taken by the camera of the user terminal 100 and the facial feature values ​​42 of the user U stored in the basic area 35a of the memory 34 of the identification card 30. The acquired facial image is compared with the facial feature values ​​42 read from the identification card 30 (step S213 in FIG. 15), and if the result of the comparison process indicates that the user has been authenticated (YES in step S221), the acquisition unit 102 decrypts the encrypted second PIN code from the extended area 35b of the memory 34 of the identification card 30, uses the second PIN code to access the basic area 35a of the memory 34 of the identification card 30, and reads and acquires the digital signature private key 52 (step S222).

[0099] The acquisition unit 102 then stores the facial feature amount 42 and the private key for electronic signature 52 acquired from the identification card 30 in the security area 122 (FIG. 12(d)) of the storage unit 120 (step S223). If the personal authentication fails (NO in step S221), the acquisition unit 102 notifies the user U that the authentication has failed and the processing will be interrupted, and ends the processing. Steps from S223 onwards are the same as in FIG. 14, so a description thereof will be omitted.

[0100] Figure 17 shows the application initial registration in Figure 16. procedure This is a flowchart showing yet another example of the operation when the digital certificate 55 of the digital signature public key 54 is stored in the memory 34 of the IC chip 32 of the identification card 30 (FIG. 5(b)).

[0101] The process up to step S221 is the same as in Fig. 16. If the result of the matching process in step S221 indicates that the identity authentication has been successful (YES in step S221), the acquisition unit 102 decrypts the encrypted second PIN code from the extended area 35b of the memory 34 of the identification card 30, and uses the second PIN code to access the basic area 35a of the memory 34 of the identification card 30 to read and acquire the digital signature private key 52, the digital signature public key 54, and their digital certificate 55 (step S231).

[0102] The acquisition unit 102 then stores the facial feature amount 42, the private key for electronic signature 52, the public key for electronic signature 54, and the corresponding digital certificate 55 acquired from the identification card 30 in the security area 122 (FIG. 12(d)) of the storage unit 120 (step S233). If the personal authentication fails (NO in step S221), the acquisition unit 102 notifies the user U that the authentication has failed and the processing will be interrupted, and ends the processing.

[0103] The registration unit 108 communicates with the NFC communication unit 38 of the identification card 30 and writes the terminal ID 46 in the memory 34 (extension area 35b in FIG. 5(b)) of the IC chip 32 (step S225). Then, the execution unit 106 performs processing to apply an electronic signature 62 to the random number (challenge) 60 transmitted from the AP server 10 in step S203, using the challenge public key 58, and transmit the result to the AP server 10. At this time, the electronic signature public key 54 and electronic certificate 55 obtained from the identification card 30 in step S231 are also transmitted to the AP server 10 (step S235).

[0104] When the AP server 10 receives the random number (challenge) 60 with the digital signature 62 from the user terminal 100, it verifies the challenge response. At this time, the AP server 10 verifies the digital certificate 55 of the digital signature public key 54 received from the user terminal 100 by inquiring of the certificate authority 50 (step S237).

[0105] In this embodiment, when the registration unit 108 successfully authenticates using the face image (second personal identification information) captured by the camera mounted on the user terminal 100 and the face feature amount (first personal identification information) that has been confirmed to be the user and stored in the storage unit 120 of the user terminal 100 by the authentication unit 104, the terminal ID 46 (terminal specific information) is written to the IC chip 32 of the identification card 30, and the user terminal 100 is registered in the identification card 30.

[0106] As described above, according to this embodiment, since the terminal ID 46 of the user terminal 100 is recorded on the identification card 30, even if the identification card 30 is lost or stolen and an attempt is made to use the present electronic procedure system 1 from another terminal, the AP server 10 can detect a mismatch between the terminal ID of the terminal and the terminal ID registered in the identification card 30, thus preventing unauthorized use.

[0107] (Third Embodiment) The information processing apparatus 100 of this embodiment is the same as the above embodiment except that it has a configuration in which identity verification is performed using the identification card 30 prepared in advance in the above-described second embodiment and predetermined processing is performed. Since the user terminal 100 of this embodiment has the same configuration as the information processing apparatus 10 in FIG. 7, it will be described using FIG. 7. However, the configuration of this embodiment may be combined as long as it does not conflict with at least any one of the configurations of other embodiments.

[0108] <P11: Electronic Signature Procedure> FIG. 18 is a diagram showing a detailed flow of the electronic signature procedure of step P11 in FIG. 8. Here, a process of applying an electronic signature 82 to an electronic document 80 will be described using the identification card 30 that has been initially registered by the procedure P7 shown in FIG. 14 and the user terminal 100 (the associated user terminal 100 and identification card 30).

[0109] Procedure P11 in Fig. 18 includes steps S203, S227, and S229, which are the same as procedure P7 in Fig. 14, and also includes steps S301 to S305. Before issuing an electronic signature, processing is performed to verify the identity of the user and to confirm the link between the user terminal 100 and the identification card 30, according to the procedure in Fig. 6.

[0110] First, when the application program 40 is started on the user terminal 100, a login screen is displayed. The account information entered by the user U on the login screen is sent to the AP server 10 as an authentication request (step S301). Alternatively, if automatic login is permitted by the user U, the account information may be automatically sent to the AP server 10 as an authentication request using account information previously stored in the storage unit 120 of the user terminal 100.

[0111] The application program 40 may be launched by user U's operation, or may be launched from a specified website with the user U's consent when an electronic signature 82 is to be added to an electronic document 80 to be submitted on the specified website as described above.

[0112] Upon receiving the account information of the user U, the AP server 10 executes challenge / response authentication for the user terminal 100 (step S203). Specifically, the AP server 10 generates a random number (challenge) 60 and transmits it to the user terminal 100.

[0113] Before responding to the challenge from the AP server 10, the user terminal 100 proceeds to step S1 in FIG. 6. First, the acquisition unit 102 acquires the facial feature amount 42 and the terminal ID 46 from the IC chip 32 of the identification card 30 (step S1). Next, the authentication unit 104 activates the camera of the user terminal 100 and displays a guidance screen on the display for taking a facial image of the user U. The user U follows the instructions on the guidance screen to take a facial image. In this way, the authentication unit 104 acquires the facial image of the user U taken by the camera (step S3). As described above, liveness verification may be used in combination to prevent fraudulent activities such as impersonation.

[0114] The authentication unit 104, for example, compares the facial image (facial features) captured by the user terminal 100 in step S1 with the facial features 42 read from the IC chip 32 in step S3, and also compares the terminal ID 46 read from the IC chip 32 in step S1 with the terminal ID stored in the memory unit 120 (step S5).

[0115] The identity verification process using the facial image in step S5 can be performed using at least one of the above-described patterns 1 to 4. If authentication of both the individual identifying information and the terminal identifying information is successful (YES in step S7), returning to Fig. 18, the execution unit 106 performs a process of applying a digital signature 62 to the random number (challenge) 60 transmitted from the AP server 10 in step S203 using the challenge public key 58 and transmitting the resulting number to the AP server 10 (step S227).

[0116] When the AP server 10 receives the random number (challenge) 60 with the digital signature 62 from the user terminal 100, it verifies the challenge response (step S229). The challenge public key 58 stored in the storage device 20 is used to verify the challenge response.

[0117] If the challenge is successful, the AP server 10 sends a message to that effect to the user terminal 100, and the execution unit 106 reads the private key for electronic signature 52 from the security area 122 of the storage unit 120, applies the electronic signature 82 to the electronic document 80, and sends it to the AP server 10 (step S303). When the AP server 10 receives the electronic document 80 from the user terminal 100, it reads the public key for electronic signature 54 (FIG. 10(c)) associated with the terminal ID of the user U stored in the storage device 20, and verifies the electronic signature 82 (step S305).

[0118] The verification result may be sent to the user terminal 100, or if the verification of the digital signature 82 confirms the validity of the digital certificate, the digital document 80 may be sent to a predetermined destination. If the verification confirms that the digital certificate is invalid, the user terminal 100 may be notified that the digital signature 82 of the digital document 80 is invalid and therefore the digital document 80 cannot be submitted (sent). Furthermore, if the digital certificate is confirmed to be invalid, the AP server 10 may request the certificate authority 50 to revoke the pair of the digital signature public key 54 and the digital signature private key 52.

[0119] Furthermore, if the user U notices that the identification card 30 has been lost or stolen, he or she can notify the AP server 10 (by entering the necessary information on a specified screen) using a specified menu in the application program 40, which will cause the AP server 10 to request the certification authority 50 to revoke the pair of the electronic signature public key 54 and the electronic signature private key 52.

[0120] This embodiment provides the same effects as the above-described embodiment. That is, according to the configuration of this embodiment, the identity authentication process is performed using the identification card 30 and the user terminal 100 that are associated in advance, so that fraudulent acts such as impersonation can be prevented and the digital signature 82 can be applied to the digital document 80 using the digital signature private key 52 read from the identification card 30 using the user terminal 100 whose identity has been properly identified.

[0121] By recording the terminal ID 46 on the identification card 30 in advance, the identification card 30 and the user terminal 100 can be associated with each other, so that there is no need to input a PIN code when the user terminal 100 reads information from the identification card 30. In this way, the present embodiment also improves the usability and security of electronic signatures.

[0122] (Fourth embodiment) In the above embodiment, an identification card 30 equipped with an IC chip 32 is used. In this embodiment, a configuration will be described in which an identification card 30 not equipped with an IC chip 32 can be used to apply a digital signature 82 to an electronic document 80.

[0123] In the above embodiment, the IC chip 32 of the identification card 30 advance However, in this embodiment, the identification card 30 does not have an IC chip 32, so the electronic certificate cannot be recorded in advance. Therefore, in this embodiment, the user terminal 100 dynamically generates a pair of the public key for electronic signature 54 and the private key for electronic signature 52 at the time of user registration.

[0124] FIG. 19 is a diagram showing an example of the usage flow of the electronic procedure system 1 using an identification card 30 that does not have an IC chip 32 mounted thereon. First, the application program 40 of the electronic procedure system 1 is installed in the user terminal 100 (step P23). Next, a facial image (facial features) identified by eKYC or the like is stored in the storage unit 120 of the user terminal 100 (step P5). Step P5 is the same as in FIG. 8.

[0125] Then, the user performs the initial registration procedure for using the electronic procedure system 1 via the application 40 (step P27). Once the preparations up to this point are complete, the user can perform the electronic signature procedure when necessary (step P31). Each step will be explained in detail below.

[0126] <P23:アプリケーションのインストール> In step P23 of FIG. 19, an application program 40 for using the electronic procedure system 1 is downloaded to the user terminal 100 of the user U. A pair of a common challenge public key 58 and a challenge private key 56 is associated with the application program 40 downloaded to each user terminal 100 of the user U, and the identification information of the application program 40 and the challenge public key 58 are stored in the storage device 20 in an associated manner (FIG. 10(d)).

[0127] The downloaded application is installed on the user terminal 100. After installation, the information processing device 100 causes the user registration screen for using the electronic procedure system 1 to be displayed on the display of the user terminal 100. When the information necessary for user registration is input on the user registration screen, the AP server 10 issues a user ID to the user U to perform user registration. The user ID is account information necessary for logging in to the electronic procedure system 1 when using the electronic procedure system 1. At the time of login, the input of an arbitrary password set by the user U and the user ID is required as the account information of the user U. The password may be appropriately changed by the user U for security improvement. As shown in FIG. 10(a), the account information (user ID and password) of the user U is stored in the storage device 20.

[0128] Furthermore, when the application program 40 is installed on the user terminal 100, the challenge private key 56 is also downloaded together and stored in the storage unit 120 of the user terminal 100. The challenge private key 56 may be stored after being encrypted with white box encryption, or may be stored in the security area 122 (FIG. 12(a)) of the storage unit 120.

[0129] <P5: Identity verification procedure> This is the same as the above embodiment, and by this procedure P5, the authenticated face feature amount is stored in the security area 122 (FIG. 12(c)) of the storage unit 120 of the user terminal 100.

[0130] <P27: Application Initial Registration Procedure> FIG. 20 is a diagram showing a flow for initial settings of step P27 in FIG. 19, which is executed when the program is started for the first time after the application is downloaded to the user terminal 100 of user U in step P23 of FIG. 19. However, this process may be executed even when the program is deleted after downloading and using the program, or when the application is downloaded and started again. Also, this process is executed when the application is downloaded and started again on a new model even when user U changes the user terminal 100 to another model.

[0131] The flow in FIG. 20 includes the same steps S201, S203, S210, S221, S227, and S229 as the flow in FIG. 14, and further includes steps S401 to S407.

[0132] In this flow, as an initial setting for using the application of the electronic procedure system 1, authentication of user U and acquisition of an electronic certificate to be used for an electronic signature hereafter are performed. First, when the application is started on the user terminal 100, an initial registration screen is displayed, and user U inputs account information and starts the initial registration process (step S201). When the AP server 10 receives the account information of user U, it executes challenge / response authentication on the user terminal 100 (step S203). Specifically, the AP server 10 generates a random number (challenge) 60 and transmits it to the user terminal 100.

[0133] Before responding to the challenge from the AP server 10, the user terminal 100 performs identity verification and performs digital certificate registration processing. First, the user terminal 100 executes identity verification processing (step S210). The identity verification processing in step S210 is the same as the flow in FIG. 15 described above. However, since the identification card 30 does not have an IC chip 32, the verification processing is performed using at least one of patterns 2 to 4 other than pattern 1, which uses facial feature values ​​42 from the identification card 30.

[0134] If the result of the identity verification process in step S210 indicates that identity authentication has been successful (YES in step S221), the authentication unit 104 generates a pair of the public key for electronic signature 54 and the private key for electronic signature 52 (step S401). Specifically, the registration unit 108 applies for the issuance of an electronic certificate to any certificate authority (not shown) or the certificate authority 50, and obtains the pair of the public key for electronic signature 54 and the private key for electronic signature 52. On the other hand, if identity authentication has failed (NO in step S221), the registration unit 108 notifies the user U that the processing will be interrupted due to the authentication failure, and terminates this processing.

[0135] The registration unit 108 then transmits the acquired public key for electronic signature 54 and its digital certificate 55 to the AP server 10 (step S403). Furthermore, the registration unit 108 stores the acquired private key for electronic signature 52 in the security area 122 (FIG. 12(d)) of the storage unit 120 (step S405).

[0136] Then, the execution unit 106 performs processing to apply a digital signature 62 to the random number (challenge) 60 transmitted from the AP server 10 in step S203 using the challenge private key 56 and transmit the digital signature 62 to the AP server 10 (step S227).

[0137] When the AP server 10 receives the random number (challenge) 60 with the digital signature 62 from the user terminal 100, it verifies the challenge response (step S229). The challenge response verification uses the challenge public key 58 stored in the storage device 20. The AP server 10 may notify the user terminal 100 of the result of the challenge verification. For example, the AP server 10 may notify the user terminal 100 that the challenge was successful and that the user will be able to execute the specified process after verifying his or her identity. Alternatively, the AP server 10 may notify the user terminal 100 that the challenge was unsuccessful and therefore the specified process cannot be executed.

[0138] Furthermore, if the challenge is successful, the AP server 10 stores the public key for electronic signature 54 received from the user terminal 100 in the storage device 20 (FIG. 10(e)) in association with the user ID (step S407). However, the public key for electronic signature 54 does not have to be stored in the storage device 20. In that case, similar to the example described in FIG. 17, the AP server 10 can simply inquire of the certificate authority 50 about the verification of the digital certificate 55 of the public key for electronic signature 54 sent from the user terminal 100.

[0139] After the advance preparation is completed in this way, the electronic signature procedure can be carried out in step P31. Step P31 can be carried out in the same flow as in Fig. 18 of the above embodiment. The following will be explained with reference to Fig. 18.

[0140] First, when the application program 40 is started on the user terminal 100, a login screen is displayed. The account information entered by the user U on the login screen is sent to the AP server 10 as an authentication request (step S301). Alternatively, if automatic login is permitted by the user U, the account information may be automatically sent to the AP server 10 as an authentication request using account information previously stored in the storage unit 120 of the user terminal 100.

[0141] Upon receiving the account information of the user U, the AP server 10 executes challenge / response authentication for the user terminal 100 (step S203). Specifically, the AP server 10 generates a random number (challenge) 60 and transmits it to the user terminal 100.

[0142] Before responding to the challenge from the AP server 10, the user terminal 100 proceeds to step S43 in Fig. 21. Fig. 21 is a flowchart showing an example of the operation of the information processing device 100 of this embodiment. The flow in Fig. 21 includes steps S7 and S9 similar to those in Fig. 6, as well as steps S43 and S45.

[0143] First, the authentication unit 104 activates the camera of the user terminal 100 and displays a guidance screen on the display for taking a facial image of the user U. The user U operates according to the instructions on the guidance screen to take a facial image and a facial photograph for the face of the identification card 30. In this way, the authentication unit 104 acquires the facial image of the user U taken by the camera and the facial photograph for the face of the identification card 30 (step S43). As described above, liveness verification may be used in combination to prevent fraudulent activities such as impersonation.

[0144] The authentication unit 104 compares the facial features extracted from the facial image of the user U captured in step S43 with the facial features extracted from the facial photograph on the face of the identification card 30 (step S45). This is pattern 3 of the identity verification process described above, but the verification process may also be performed using at least one of patterns 2 to 4 other than pattern 1.

[0145] If the authentication of the personal identification information is successful (YES in step S7), returning to FIG. 18, the execution unit 106 performs a process of applying an electronic signature 62 to the random number (challenge) 60 sent from the AP server 10 in step S203 using the challenge public key 58 and sending it to the AP server 10 (step S227).

[0146] When the AP server 10 receives the random number (challenge) 60 with the digital signature 62 from the user terminal 100, it verifies the challenge response (step S229). The challenge public key 58 stored in the storage device 20 is used to verify the challenge response.

[0147] If the challenge is successful, the AP server 10 sends a message to that effect to the user terminal 100, and the execution unit 106 reads the private key for electronic signature 52 from the security area 122 of the storage unit 120, applies the electronic signature 82 to the electronic document 80, and sends it to the AP server 10 (step S303). When the AP server 10 receives the electronic document 80 from the user terminal 100, it reads the public key for electronic signature 54 (FIG. 10(c)) associated with the terminal ID of the user U stored in the storage device 20, and verifies the electronic signature 82 (step S305).

[0148] The verification result may be sent to the user terminal 100, or if the verification of the digital signature 82 confirms the validity of the digital certificate, the digital document 80 may be sent to a predetermined destination. If the verification confirms that the digital certificate is invalid, the user terminal 100 may be notified that the digital signature 82 of the digital document 80 is invalid and therefore the digital document 80 cannot be submitted (sent). Furthermore, if the digital certificate is confirmed to be invalid, a request can be made to the certification authority 50 to revoke the pair of the digital signature public key 54 and the digital signature private key 52.

[0149] According to this embodiment, by performing authentication processing for identity confirmation using an identification card 30 that does not have an IC chip 32, it is possible to prevent fraudulent acts such as impersonation and legitimately execute predetermined processing that requires identity confirmation. Then, by simply performing identity confirmation on the user terminal 100, it becomes possible to perform predetermined processing, such as applying a digital signature 82 to a digital document 80, without performing any complicated operations. This improves the usability and security of digital signatures.

[0150] Although the embodiments of the present invention have been described above with reference to the drawings, these are merely examples of the present invention, and various other configurations can also be adopted. For example, in the above embodiment, the information processing device 100 is realized by installing the application program 40 on the user terminal 100. However, in another embodiment, the application program 40 may be executed on a server on the cloud or on SaaS (Software as a Service), and the user terminal 100 may function as an operating terminal for the server. However, the above embodiment in which identity verification is performed on the user terminal 100 has the advantage of further reducing the risk of personal information leakage. Therefore, a configuration in which some functions of the information processing device 100 (excluding identity verification, etc.) are executed on the server may also be used.

[0151] In the above embodiment, an example of applying a digital signature to an electronic document has been described as the predetermined process. In another example, the predetermined process may be a process in which the user U receives various services using the personal identification information recorded on the identification card 30, such as a user authentication process when logging in to a portal site to receive various services related to My Number that do not involve an electronic document.

[0152] Although the same private key / public key pair as the private key / public key pair for electronic signature may be used, it is preferable to use a private key / public key pair different from the private key / public key pair for electronic signature because electronic signature processing and other processing are subject to different laws, etc. Hereinafter, they will be referred to as user authentication private key 92, user authentication public key 94, and its electronic certificate 95.

[0153] FIG. 22 is a flowchart showing an example of an operation when a login process to a portal site is performed instead of the electronic signature procedure in step P11 of FIG. First, a menu screen is displayed when the application program 40 is started on the user terminal 100. When the user U selects logging in to the portal site on the menu screen, a login request is sent to the AP server 10 (step S331).

[0154] The application program 40 may be started by an operation of the user U, or may be started by accessing a predetermined portal site using a browser and then pressing a button requesting login to the portal site.

[0155] Upon receiving the login request, the AP server 10 executes challenge / response authentication for the user terminal 100 (step S203). Specifically, the AP server 10 generates a random number (challenge) 60 and transmits it to the user terminal 100.

[0156] 6 before responding to the challenge from the AP server 10. The identity verification process in step S1 is the same as that described above, so a description thereof will be omitted here.

[0157] If authentication of both the personal identification information and the terminal identification information is successful (YES in step S7 of FIG. 7), the execution unit 106 performs processing to apply a digital signature 62 to the random number (challenge) 60 transmitted from the AP server 10 in step S203 using the challenge public key 58 and transmit the resulting signature to the AP server 10 (step S333). At this time, the user authentication public key 94 and its digital certificate 95 stored in the storage unit 120 in procedure P1 are also transmitted to the AP server 10.

[0158] When the AP server 10 receives the random number (challenge) 60 with the digital signature 62 from the user terminal 100, it verifies the challenge response (step S229). The challenge public key 58 stored in the storage device 20 is used to verify the challenge response.

[0159] If the challenge is successful, the authentication authority 50 is then queried to verify the digital certificate 95 of the received user authentication public key 94 (step S337). If the verification is successful, the login process to the portal site is performed (step S339). The user ID used when logging in may be, for example, the issue number of the digital certificate 95. In this way, the user U can log in without inputting a login ID or password during the login process.

[0160] Although the present invention has been described above with reference to the embodiments and examples, the present invention is not limited to the above-described embodiments and examples. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention. In the present invention, when information about a user (user U) is acquired and used, it is assumed that this is done lawfully.

[0161] Some or all of the above-described embodiments can be described as, but are not limited to, the following supplementary notes. 1. A computer that implements a terminal an acquisition means for acquiring the first individual identifying information and the terminal identifying information from a portable recording medium on which the first individual identifying information and the terminal identifying information are recorded; an authentication means for authenticating second personal identification information acquired by a sensor mounted on the terminal and the terminal identification information of the terminal using the first personal identification information and the terminal identification information acquired from the recording medium; an execution means for executing a predetermined process when the authentication is successful; and a program for realizing this execution means. 2. In the program described in 1., The program, wherein the predetermined process includes a process of transmitting data to which an electronic signature has been added. 3. In the program described in 1. or 2., A program for causing a computer to realize a registration means for storing the terminal identification information on the recording medium when the authentication means successfully authenticates the second personal identification information using the first personal identification information.

[0162] 4. An acquisition means for acquiring the first individual identifying information and the terminal identifying information from a portable recording medium on which the first individual identifying information and the terminal identifying information are recorded; an authentication means for authenticating second personal identification information acquired by a sensor mounted on a terminal and the terminal identification information of the terminal, using the first personal identification information and the terminal identification information acquired from the recording medium; and an execution unit that executes a predetermined process when the authentication is successful. 5. In the information processing device described in 4., The predetermined process includes a process of transmitting data to which a digital signature has been added. 6. In the information processing device according to 4. or 5., The information processing device further comprises a registration means for storing the terminal identification information in the recording medium when the authentication means has successfully authenticated the second individual identification information using the first individual identification information.

[0163] 7. The information processing device Acquire the first individual identifying information and the terminal identifying information from a portable recording medium on which the first individual identifying information and the terminal identifying information are recorded; authenticating second personal identification information acquired by a sensor mounted on the terminal and the terminal identification information of the terminal using the first personal identification information and the terminal identification information acquired from the recording medium; and executing a predetermined process when the authentication is successful. 8. In the information processing method described in 7., The information processing method, wherein the predetermined processing includes a process of transmitting data to which a digital signature has been attached. 9. In the information processing method according to 7. or 8., The information processing device, an information processing method, wherein when the authentication means successfully authenticates the second individual identifying information using the first individual identifying information, the terminal identifying information is stored in the recording medium; [Explanation of symbols]

[0164] 1 electron procedure system 3. Communication Network 10 AP Server 20 Storage device 30 Identification Card 30a My Number Card 32 IC chip 34 memory 36 processors 38 NFC communication unit 40 Application Programs 42 Facial Features 44 PIN code 46 Device ID 50 Certificate Authorities 52 Private key for electronic signature 54 Public Key for Digital Signature 56 Challenge private key 58 Challenge public key 62 Electronic Signature 80 Electronic Documents 82 Electronic Signature 100 Information processing device, user terminal 102 Acquisition Department 104 Authentication Section 106 Executive Department 108 Registration Department 120 Storage section 122 Security Area 1000 computers 1010 Bus 1020 processor 1030 memory 1040 Storage Device 1050 Input / Output Interface 1060 Network Interface

Claims

1. The computer that realizes the terminal an acquisition means for acquiring the first individual identifying information and the terminal identifying information from a portable recording medium on which the first individual identifying information and the terminal identifying information are recorded; an authentication means for performing authentication for identity confirmation using second personal identification information acquired by a sensor mounted on the terminal and terminal identification information stored in a storage unit of the terminal, the first personal identification information acquired from the recording medium, and the terminal identification information; an execution means for executing a predetermined process when the authentication is successful; and a program for realizing this execution means.

2. 2. The program according to claim 1, The program, wherein the predetermined process includes a process of transmitting data to which an electronic signature has been added.

3. 3. The program according to claim 1 or 2, the authentication means authenticates the second individual identifying information using the first individual identifying information; A program for causing a computer to realize a registration means for storing the terminal identification information stored in the memory unit of the terminal in the recording medium on which the terminal identification information is not recorded when the authentication means successfully authenticates the second personal identification information using the first personal identification information.

4. an acquisition means for acquiring the first individual identifying information and the terminal identifying information from a portable recording medium on which the first individual identifying information and the terminal identifying information are recorded; an authentication means for performing authentication for identity confirmation using second individual identifying information acquired by a sensor mounted on the terminal and terminal identifying information stored in a storage unit of the terminal, the first individual identifying information acquired from the recording medium, and the terminal identifying information; and an execution means for executing a predetermined process when the authentication is successful.

5. 5. The terminal according to claim 4, The predetermined process includes a process of transmitting data to which a digital signature has been attached.

6. 6. The terminal according to claim 4 or 5, the authentication means authenticates the second individual identifying information using the first individual identifying information; The terminal further comprises a registration means for storing the terminal identification information stored in the memory unit of the terminal in the recording medium on which the terminal identification information is not recorded when the authentication means successfully authenticates the second individual identification information using the first individual identification information.

7. The device is acquiring the first individual identifying information and the terminal identifying information from a portable recording medium on which the first individual identifying information and the terminal identifying information are recorded; performing authentication for identity verification using second individual identifying information acquired by a sensor mounted on the terminal and terminal identifying information stored in a storage unit of the terminal, and the first individual identifying information and the terminal identifying information acquired from the recording medium; and executing a predetermined process when the authentication is successful.

8. 8. The information processing method according to claim 7, The information processing method, wherein the predetermined processing includes a process of transmitting data to which a digital signature has been attached.

9. 9. The information processing method according to claim 7, The terminal authenticating the second personally identifying information using the first personally identifying information; When authentication of the second personal identification information using the first personal identification information is successful, the terminal identification information stored in the memory unit of the terminal is stored in the recording medium on which the terminal identification information is not recorded.

Citation Information

Patent Citations

  • Method for authenticating identity and device for executing the same

    JP2001202336A

  • Internet personal authentication method and information terminal equipment

    JP2001265738A

  • Registration update method for id information

    JP2007080006A

  • Encryption processing system

    JP2009071629A

  • Tamper resistant device and method

    JP2015045983A