Information processing device and information processing method

The information processing device verifies electronic certificates and signatures to authenticate companies participating anonymously, addressing the challenge of ensuring authenticity in supply chain information sharing.

JP7893162B2Active Publication Date: 2026-07-22TOYOTA JIDOSHA KK
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
TOYOTA JIDOSHA KK
Filing Date
2023-02-15
Publication Date
2026-07-22

AI Technical Summary

Technical Problem

Existing systems struggle to guarantee the authenticity of companies participating in a platform anonymously, particularly in scenarios involving information sharing across a supply chain, such as carbon footprint tracking, traceability, and other product-related information.

Method used

An information processing device that verifies the authenticity of a second company by sending invitation data with an electronic certificate from a certification authority, obtaining and verifying the company's electronic signature, and ensuring the validity of these credentials using public keys, thereby approving the company's participation in the platform.

Benefits of technology

Guarantees the authenticity of companies participating anonymously by validating their identity and ensuring the integrity of the information shared across the supply chain.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007893162000001
    Figure 0007893162000001
  • Figure 0007893162000002
    Figure 0007893162000002
  • Figure 0007893162000003
    Figure 0007893162000003
Patent Text Reader

Abstract

To provide a technique which is effective in securing authenticity of a company desiring to join a platform anonymously.SOLUTION: A control unit of an information processing apparatus receives an application for approval of participation of a second company to a platform from an account of a first company joining the platform, and transmits, to the second company, invitation data including an address and a request for submission of an electronic certificate issued by an authentication agency. If there is access to the address included in the invitation data, the control unit acquires the electronic certificate and an electronic signature of the second company. The control unit uses an open key of the authentication agency to verify validity of the acquired electronic certificate. The control unit uses an open key of the second company included in the electronic certificate to verify validity of the acquired electronic signature. If the verification of validity of the acquired electronic certificate and the acquired electronic signature is successful, then the control unit approves participation of the second company.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information processing apparatus and an information processing method.

Background Art

[0002] <000...A system for sharing information on transaction products between a vendor company and a customer company has been proposed (for example, Patent Document 1). According to this system, information can be shared among companies through a common platform in a supply chain or the like.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] An object of the present disclosure is to provide an effective technique for guaranteeing the authenticity of a company that wishes to participate in a platform anonymously.

Means for Solving the Problems

[0005] One aspect of the present disclosure is receiving an application for approval of the participation of a second company in the platform from an account of a first company participating in the platform; as a response to the application, transmitting invitation data including a request for submission of an address and an electronic certificate issued by a certification authority to the second company; receiving access by a terminal of the second company to the address included in the invitation data; acquiring the electronic certificate and the electronic signature of the second company from the terminal of the second company in response to the access; The validity of the acquired digital certificate is verified using the public key of the aforementioned certification authority, The validity of the acquired digital signature is verified using the public key of the second company contained in the digital certificate, In accordance with the successful verification of the validity of the aforementioned electronic certificate and electronic signature, the participation of the second company in the aforementioned platform will be approved. This is an information processing device comprising a control unit configured to perform the following actions.

[0006] One aspect of this disclosure is: Computers The platform accepts applications from the account of the first company participating in the platform for approval of the second company's participation in the said platform, In response to the aforementioned application, the second company shall be sent invitation data including a request for submission of an address and an electronic certificate issued by a certification authority. Accepting access from the second company's terminal to the address included in the invitation data, In response to the aforementioned access, the electronic certificate and the electronic signature of the second company are obtained from the terminal of the second company, The validity of the acquired digital certificate is verified using the public key of the aforementioned certification authority, The validity of the acquired digital signature is verified using the public key of the second company contained in the digital certificate, In accordance with the successful verification of the validity of the aforementioned electronic certificate and electronic signature, the participation of the second company in the aforementioned platform will be approved. This is an information processing method that performs the following actions.

[0007] Other embodiments of this disclosure may include a program for causing a computer to execute the above-mentioned information processing method, or a non-temporary storage medium for storing the above-mentioned program. [Effects of the Invention]

[0008] According to the present disclosure, it is possible to provide a technology effective in guaranteeing the authenticity of a company that wishes to participate in the platform anonymously.

Brief Description of the Drawings

[0009] [Figure 1] A diagram showing an outline of an example of processing performed in the system according to the embodiment. [Figure 2] A diagram for explaining an example of a supply chain according to the embodiment. [Figure 3] A diagram for explaining an example of the relationship between products supplied by the supply chain. [Figure 4] A diagram showing an outline of processing performed between the enterprise terminal and the server device. [Figure 5] Hardware configuration diagram of the server device according to the embodiment. [Figure 6] Hardware configuration diagram of the enterprise terminal according to the embodiment. [[ID=?]] [Figure 7] Software configuration diagram of the server device according to the embodiment. [Figure 8] Software configuration diagram of the enterprise terminal according to the embodiment. [Figure 9] An example of product information generated by the product information generation unit. [Figure 10] An example of transaction data generated by the product information generation unit. [Figure 11] An example of a user interface output by the authority setting unit. [Figure 12] An example of permission information generated by the authority setting unit based on the input information. [Figure 13] An example of a user interface including a list of products that are candidates for the linked destination. <000l089> [Figure 14] A diagram showing an example of the flow of processing executed by the server device. [Figure 15] A sequence diagram for explaining the processing performed by the server device and the enterprise terminal in the first to third phases. [Figure 16] A sequence diagram for explaining the processing performed by the server device and the enterprise terminal in the fourth phase. [Figure 17] A sequence diagram for explaining the processing performed by the system when issuing an account to an anonymous company. [Figure 18] An example of a user interface output by the management department. [Figure 19] A flowchart showing the processing flow performed by the server device when issuing an account to an anonymous company.

Mode for Carrying Out the Invention

[0010] Carbon footprint (CFP: Carbon Footprint of Products) is a mechanism for displaying the amount of greenhouse gas emissions converted to CO2 over the entire life cycle of a product from raw material procurement to disposal and recycling. To realize CFP, it is important to record each supplier involved from raw material procurement to disposal and recycling of the product and keep the history traceable.

[0011] To ensure the traceability of information such as CFP, it is required to collect such information not only between adjacent companies but also throughout the entire supply chain. By the way, there may be companies in the supply chain that wish to participate in the platform anonymously. However, in the conventional system, there was a problem that it was difficult to guarantee the authenticity of companies participating in the platform anonymously. Note that this problem does not occur only in the scenario of collecting carbon footprint. For example, this problem can occur in any scenario of collecting any information related to products, such as other traceability-related information (e.g., recycling rate of raw materials, due diligence information, etc.), other product-related information (e.g., components, identification information, etc.). There was a problem that it was difficult to guarantee the authenticity of the company. Note that this problem does not occur only in the scenario of collecting carbon footprint. For example, this problem can occur in any scenario of collecting any information related to products, such as other traceability-related information (e.g., recycling rate of raw materials, due diligence information, etc.), other product-related information (e.g., components, identification information, etc.).

[0012] Therefore, an information processing device, which is one aspect of this disclosure, receives an application from the account of a first company participating in the platform for approval of a second company's participation in the platform; in response to the application, sends invitation data to the second company including a request for submission of an address and an electronic certificate issued by a certification authority; accepts access from the second company's terminal to the address included in the invitation data; in response to the access, obtains the electronic certificate and the second company's electronic signature from the second company's terminal; verifies the validity of the electronic certificate using the certification authority's public key; verifies the validity of the electronic signature using the second company's public key included in the electronic certificate; and, in response to the successful verification of the validity of the electronic certificate and the electronic signature, approves the second company's participation in the platform. The system now includes a control unit configured to perform the following actions:

[0013] The information processing device relating to this disclosure may be a server that manages the platform, or it may be a server independent of the platform. The information processing device may also be a computer configured to run a web server for interacting with terminals of companies that have already joined the platform. In this case, the terminal of the first company can access the web server through a browser and log in to the web server with the first company's account to apply for approval of the second company's participation. Alternatively, the information processing device may achieve the same functionality as the web server described above by running a service that interacts with a dedicated application program installed on the first company's terminal using a predetermined protocol. In this case, the terminal of the first company may log in to the information processing device by running the dedicated application program using the first company's account.

[0014] Upon receiving the above application from the first company's account, the information processing device's control unit sends invitation data to the second company. The invitation data may be sent to the second company via the first company, or it may be sent directly to the second company. The second company, upon receiving the invitation data, can access the address included in the invitation data through its terminal. The address included in the invitation data may be, for example, the URL (Uniform Resource Locator) of a website provided by the information processing device through the execution of a web server. In one example, the URL may be a one-time URL. The control unit obtains an electronic certificate and the second company's electronic signature by interacting with the second company's terminal that accessed the address included in the invitation data. The control unit verifies the validity of the obtained electronic certificate using the public key of the certification authority. If the verification of the electronic certificate's validity is successful, it is guaranteed that the certification authority's verification of the second company's identity is valid. The control unit also verifies the validity of the second company's electronic signature using the public key included in the obtained electronic certificate. If the verification of the second company's electronic signature is successful, it is guaranteed that the source of access to the address included in the invitation data and the second company, whose identity has been verified by the certification authority, are consistent. Therefore, if the validity of the electronic certificate and electronic signature is verified successfully, the control unit can determine that the authenticity of the second company is guaranteed. Then, on the condition that the authenticity of the second company is guaranteed, the control unit of the information processing device can approve the second company's participation in the platform.

[0015] Therefore, the information processing device relating to this disclosure can guarantee the authenticity of a second company even when the second company participates in the platform anonymously.

[0016] Here, the electronic signature of the second company may be generated by encrypting predetermined information using a private key corresponding to the public key of the second company (the public key included in the second company's electronic certificate). The predetermined information may be arbitrarily selected. For example, the predetermined information may be information specified by the control unit of the information processing device. In that case, the predetermined information may be included in the invitation data transmitted by the control unit. This makes it possible for the control unit to verify the consistency between the recipient of the invitation data and the source of access to the address included in the invitation data by verifying the validity of the electronic signature.

[0017] The specified information may be generated, for example, based on transaction data relating to a transaction between a first company and a second company. As an example, the control unit of the information processing device may be configured to select one or more transaction data from among multiple transaction data relating to a transaction between a first company and a second company in response to receiving an application from a second company for approval to participate in the platform, and to generate the specified information from the selected one or more transaction data. By using transaction data relating to a transaction between a first company and a second company as the specified information, it is guaranteed that a transaction exists between the first company and the second company. Furthermore, by having the control unit select one or more transaction data to be used to generate the specified information, it is possible to suppress the identification of the transaction data used to generate the specified information by a third party.

[0018] Furthermore, multiple transaction data records relating to transactions between the first company and the second company may be retained on the platform. In that case, selecting one or more transaction data records may include receiving the specification of multiple transaction data records from the first company's account, and selecting one or more transaction data records from among the specified multiple transaction data records.

[0019] Furthermore, the specified information may be generated by adding a specified value to transaction data and then hashing or encrypting the transaction data to which the specified value has been added. This makes it possible to more reliably prevent third parties from identifying the transaction data used to generate the specified information.

[0020] The specified information may also be random numbers generated by the control unit. This allows for verification of the consistency between the recipient of the invitation data and the source of access to the address included in the invitation data.

[0021] The embodiments of this disclosure will be described below with reference to the drawings. The configurations of the following embodiments are illustrative, and this disclosure is not limited to the configurations of the embodiments. Furthermore, the following embodiments can be combined as much as possible.

[0022] <Embodiment> The system in this embodiment is a system for providing information about products supplied by a supply chain that includes multiple companies. Product information typically refers to traceability information. The provision of information about products supplied by the supply chain is achieved by multiple companies belonging to the supply chain using a common platform. The companies belonging to the supply chain may be selected as appropriate depending on the attributes of the products, etc.

[0023] Figure 1 is a diagram illustrating an example of the processing performed by the system in this embodiment. In the example shown in Figure 1, it is assumed that a second company wishes to participate in the platform anonymously. The first company is a company participating in the platform and has business dealings with the second company. Server device 1 is configured to manage information indicating the supply relationships of products between multiple companies included in the supply chain. Furthermore, server device 1 accepts applications from the second company for approval to participate in the platform and verifies the authenticity of the second company. It is configured in this way.

[0024] In the system of this embodiment, a second company wishing to participate in the platform anonymously applies to the server device 1 for approval to participate in the platform (Figure 1 (1)). Since the second company is not participating in the platform, it does not have an account to log in to the server device 1. Therefore, the above application is made through a company that is already participating in the platform and has business dealings with the second company (the first company). That is, the second company requests the first company to apply for approval to participate in the platform. Upon receiving the above request, the first company logs in to the server device 1 using its account and submits the above application to the server device 1. Upon receiving the above application, the server device 1 sends invitation data to the second company (Figure 1 (2)). As an example, the invitation data includes an address, an electronic certificate issued by the certification authority 3, and specified information. The address included in the invitation data is the URL of a website provided through the execution of web server processing by the server device 1. The URL may be a general URL or a one-time URL. The specified information included in the invitation data will be described later. Such invitation data may be sent to the second company via the first company. Furthermore, if the second company's contact information (e.g., email address) is included in the above application, server device 1 may send the invitation data to the second company without going through the first company.

[0025] Upon receiving the above invitation data, the second company generates its own private and public keys. Subsequently, the second company requests the issuance of an electronic certificate from Certification Authority 3 ((3) in Figure 1). This issuance request includes the public key generated by the second company. Note that the second company's private and public keys may be generated by Certification Authority 3. In that case, the issuance request should include a request for the generation of the second company's private and public keys. Certification Authority 3 is a third-party organization that processes information related to authentication, such as issuing electronic certificates to companies.

[0026] Upon receiving the above issuance request, Certification Authority 3 verifies the identity of the second company based on certification information such as a company register or tax certificate. In one example, if the identity verification of the second company is successful, Certification Authority 3 creates owner identification information for the second company. Certification Authority 3 calculates a hash value of the plaintext containing the created owner identification information and the second company's public key. The generation of the owner identification information and the structure of the plaintext may be changed as desired. Certification Authority 3 generates its digital signature by encrypting the calculated hash value with Certification Authority 3's private key. Certification Authority 3 generates a digital certificate containing information for reconstructing the plaintext (in the above example, the second company's owner identification information), the second company's public key, and Certification Authority 3's digital signature. Certification Authority 3 issues the generated digital certificate to the second company ((4) in Figure 1). Certification Authority 3 also registers the generated digital certificate in its repository. If the issuance request from the second company includes a request for the generation of the second company's private and public keys, Certification Authority 3 also generates the second company's private and public keys when generating the digital certificate.

[0027] The timing of generating the digital certificate is not limited to the examples described above and can be changed at will. In another example, the digital certificate may be generated at any time before the second company receives the invitation data. Similarly, the timing of generating the second company's private and public keys is not limited to the examples described above and can be changed at will. In another example, the second company's private and public keys may be generated at any time before the second company receives the invitation data.

[0028] Upon receiving the digital certificate issued by the certification authority 3, the second company accesses the address included in the invitation data through the second company's terminal. In response, the server device 1 interacts with the second company's terminal to obtain the digital certificate issued by the certification authority 3, the second company's digital signature, and predetermined information (Figure 1 (5)). In this embodiment, The digital signature of the second company is different from the digital signature of Certificate Authority 3, and is generated by encrypting specified information with the second company's private key. In one example, the digital signature of the second company may be generated by encrypting the hash value of plaintext containing the specified information with the second company's private key. Note that the timing of generating the digital signature of the second company is not limited to this example and may be changed as desired. In another example, the digital signature of the second company may be generated before accessing the address included in the invitation data mentioned above.

[0029] Server device 1, having obtained the digital certificate, the digital certificate of the second company, and predetermined information, obtains the public key of the certification authority 3 ((6) in Figure 1). Server device 1 uses the public key obtained from the certification authority 3 to verify the authenticity of the second company ((7) in Figure 1). In this embodiment, the authenticity of the second company is verified by verifying the validity of the digital certificate and the validity of the digital signature of the second company.

[0030] In verifying the validity of an electronic certificate, first, Server Device 1 uses the public key of Certificate Authority 3 to decrypt the digital signature of Certificate Authority 3 contained in the electronic certificate. Server Device 1 also calculates the plaintext hash value of the owner identification information and the public key of the second company contained in the electronic certificate. Next, Server Device 1 compares the decrypted information of Certificate Authority 3's digital signature with the calculated hash value. If the comparison between the decrypted information of Certificate Authority 3's digital signature and the calculated hash value is successful, Server Device 1 refers to the repository of Certificate Authority 3 to determine whether the electronic certificate has expired. If the electronic certificate has not expired, Server Device 1 determines that the verification of the validity of the electronic certificate has been successful.

[0031] Furthermore, in verifying the validity of the second company's digital signature, server device 1 first decrypts the second company's digital signature using the second company's public key contained in the digital certificate. Next, server device 1 compares the decrypted information of the second company's digital signature with predetermined information. For example, server device 1 may hash the plaintext containing the predetermined information and compare the resulting hash value with the decrypted information. If the comparison of the decrypted information of the second company's digital signature with the predetermined information is successful, it is proven that the digital signature was generated using the second company's private key (the private key corresponding to the public key contained in the digital certificate) and the predetermined information contained in the invitation data. This allows it to be considered that the source accessing the address contained in the invitation data holds the second company's private key, and that the recipient of the invitation data and the source accessing the address are consistent. In other words, it can be determined that the source accessing the address contained in the invitation data is consistent with the second company whose identity has been verified by the certification authority. Therefore, if the comparison of the decrypted information of the digital signature with the predetermined information is successful, server device 1 determines that the second company's digital signature is valid. Note that the order in which the validity of the digital certificate and the second company's digital signature are verified is arbitrary. In one example, the validity of the electronic certificate of the second company may be verified after the validity of the electronic certificate of the first company has been verified. In another example, the validity of the electronic certificate may be verified after the validity of the electronic signature of the second company has been verified. In yet another example, the validity of the electronic certificate and the electronic signature of the second company may be verified at least partially in parallel.

[0032] If the validity of the electronic certificate and electronic signature provided by the second company is verified successfully, server device 1 approves the second company's participation in the platform. That is, server device 1 generates an account for the second company and issues the generated account to the second company (Figure 1, (8)).

[0033] The above-described process is performed by the system, which ensures the authenticity of a second company if it wishes to participate in the platform anonymously.

[0034] [Supply chain structure] The structure of the supply chain to which the system in this embodiment is applied will be described. In one example, at least some companies included in the supply chain (intermediate suppliers) may receive parts from one or more upstream companies, use the received parts to produce their own products, and deliver the produced products to companies in the next stage (downstream companies). The upstream company may directly produce its own products and deliver the produced products to companies in the next stage. Some companies in the supply chain may deliver products received from other companies directly to other companies (i.e., participate in distribution). Multiple companies repeat this process until the final product is obtained in the final stage.

[0035] Figure 2 is a diagram illustrating an example of a supply chain according to this embodiment. The example in Figure 2 assumes a scenario in which products related to automobiles are obtained. Specifically, the supply chain shown in Figure 2 consists of an OEM company and multiple supplier companies. The example in Figure 2 assumes a supply chain that manufactures, for example, the automobile itself or automobile-related products such as batteries. The OEM company assembles the final product. Multiple supplier companies (companies A to C) supply parts, materials, assemblies, etc., for manufacturing the final product. Each of the multiple supplier companies produces one or more products and delivers them to a company located one level lower in the hierarchy. Multiple companies repeat this process, and the final product is obtained at the final stage (i.e., the OEM company).

[0036] In this embodiment, the side that supplies products at each level of the supply chain is referred to as the upstream side, and the side that purchases those products and produces new products is referred to as the downstream side. In this specification, companies located on the upstream side are referred to as upstream companies, and companies located on the downstream side are referred to as downstream companies. Furthermore, products produced by upstream companies are referred to as upstream products, and products produced by downstream companies are referred to as downstream products. Downstream products include upstream products.

[0037] Furthermore, in this embodiment, the layers included in the supply chain are referred to as Tiers. Tier 0 is the lowest layer, which assembles the final product (corresponding to OEM companies). As you progress through Tier 1, 2, and 3, you move towards the upstream side. Depending on the tier you focus on, downstream companies may... They can also become upstream companies. For example, company B, which is located in Tier 2, is a downstream company in relation to Tier 3, but an upstream company in relation to Tier 1. In this way, upstream companies and downstream companies... The definition can vary depending on the hierarchy.

[0038] Figure 3 illustrates an example of the relationships between products supplied by a supply chain. Here, the supply relationships of multiple products that make up the final product X are represented by a tree diagram. In this example, the final product X is produced by assembling products A1, B1, C1, D1... Product A1 is produced by assembling products A11, A12, A13... In this way, the relationships between multiple products that make up the final product can be represented by a tree diagram in which each product is a node. Hereafter, a tree diagram relating to a specific final product will be referred to as a product tree. In one example, the final product X is a battery installed in an electric vehicle (BEV: Battery Electric Vehicle). In another example, the final product X is a car, an automobile assembly Products related to automobiles, such as those from Bri, may be included.

[0039] The server device 1 according to this embodiment collects information about the products produced by each company (hereinafter referred to as "product information") and information for linking the product information from terminals (corporate terminals 2) corresponding to each company, and generates a product tree based on these. The product information also includes information about traceability (for example, information about greenhouse gas emissions, etc.; hereinafter referred to as "traceability-related information"), and by following the product tree, it is possible to track carbon footprints, etc. Note that the traceability-related information may include any information that could be subject to ensuring traceability.

[0040] As shown in Figure 2, an example of the information processing system according to this embodiment includes a server device 1 and a plurality of corporate terminals 2.

[0041] Enterprise terminal 2 is a terminal corresponding to each of the multiple companies that make up the supply chain. The number of terminals corresponding to each company may be arbitrary. In addition, the terminals corresponding to the target company may include terminals of companies that perform operations related to that target company (for example, a proxy company).

[0042] Server device 1 collects information for generating a product tree from each of the multiple corporate terminals 2, and generates the product tree based on the collected information. Furthermore, server device 1 can perform traceability-related processing (typically, processing to calculate carbon dioxide emissions, etc.) based on the generated product tree. It can also transmit the results of the processing to the corporate terminals 2.

[0043] Next, we will explain the overview of the process by which server device 1 generates a product tree using Figure 4. Figure 4 is a diagram showing the overview of the process that takes place between enterprise terminal 2 and server device 1. In the example in Figure 4, it is assumed that there are downstream companies, company A and upstream companies, company B, at any given hierarchy. It is assumed that company B produces product B and delivers it to company A, and company A produces product A using product B. In other words, in the example in Figure 4, product B becomes a child node of product A in the product tree.

[0044] To generate a product tree, each company's corresponding company terminal 2 transmits information about the products it produces to the server device 1. In this example, company terminal 2 corresponding to company A transmits product information about product A (referred to as product information A) to the server device 1. Similarly, company terminal 2 corresponding to company B transmits product information about product B (referred to as product information B) to the server device 1. The product information for each company is stored in the server device 1.

[0045] The operation to link product information stored in server device 1 is performed by corporate terminal 2. In one example, a representative from a downstream company logs into server device 1 from corporate terminal 2 using the downstream company's account and selects the upstream product to which the downstream product (their own company's product) will be linked. In this way, the linking of product information is performed from downstream products to upstream products. Server device 1 links the product information based on the selection.

[0046] By the way, when allowing users to select a product to link to, presenting all products included in the supply chain and all information about those products as options would compromise the confidentiality of information about the companies that make up the supply chain, and the products that those companies produce. Furthermore, disclosing the entire product tree to a single supplier may not always be appropriate.

[0047] Therefore, in accordance with this embodiment, the server device 1 grants the downstream company access rights to the product information of the upstream product in advance, in response to a request from the upstream company. The server device 1 allows the downstream company to access the information within the scope of the granted rights.

[0048] In the example in Figure 4, enterprise terminal 2, which corresponds to the upstream company B, sends a request (information) to server device 1 instructing it to "grant company A access rights to product information B." When server device 1 receives a linking request from enterprise terminal 2, which corresponds to company A, it provides only a list of product information for which company A has access rights, allowing company A to select it as the linking destination. Furthermore, when enterprise terminal 2, which corresponds to company A, requests to refer to the product tree, server device 1 provides enterprise terminal 2 with a product tree in which information other than that for which company A has access rights is kept confidential. This prevents unrelated companies and products from being linked. This allows for the concealment of information.

[0049] [Hardware configuration] Next, the hardware configuration of each device constituting the system will be described. Figure 5 is a schematic diagram showing an example of the hardware configuration of the server device 1 according to this embodiment. The server device 1 is configured as a computer having a control unit 11, a storage unit 12, a communication module 13, and an input / output device 14.

[0050] Server device 1 is an example of an information processing device related to this disclosure. Server device 1 can be configured as a computer having a processor (CPU, GPU, etc.), main memory (RAM, ROM, etc.), and auxiliary storage (EPROM, hard disk drive, removable media, etc.). The auxiliary storage device stores an operating system (OS), various programs, various tables, etc., and by executing the programs stored therein, various functions (software modules) that match a predetermined purpose, as described later, can be realized. However, some or all of the modules may be realized as hardware modules by hardware circuits such as ASIC (Application Specific Integrated Circuit) or FPGA (Field Programmable Gate Array).

[0051] The control unit 11 is a computing unit that realizes various functions of the server device 1 by executing a predetermined program. The control unit 11 can be realized by a hardware processor such as a CPU. The control unit 11 may also be configured to include RAM, ROM (Read Only Memory), cache memory, etc.

[0052] The storage unit 12 is a means for storing information and is composed of storage media such as RAM, magnetic disks, and flash memory. The storage unit 12 stores programs executed by the control unit 11, data used by those programs, and so on. A database is also built into the storage unit 12, and this database stores information collected from multiple corporate terminals 2 and account information related to the companies. Details of the information stored in the storage unit 12 will be described later.

[0053] The communication module 13 is a communication interface for connecting the server device 1 to a network. The communication module 13 may be configured to include, for example, a network interface board and a wireless communication interface for wireless communication. The server device 1 can communicate data with other computers (for example, other server devices 1 or each enterprise terminal 2) via the communication module 13.

[0054] The input / output device 14 is a means of receiving input operations performed by the operator and presenting information to the operator. Specifically, the input / output device 14 includes devices for input such as a mouse and keyboard, and devices for output such as a display and speakers. The input / output device may be integrated with, for example, a touch panel display.

[0055] The specific hardware configuration of server device 1 can be appropriately omitted, replaced, and added depending on the embodiment. For example, the control unit 11 may include multiple hardware processors. The hardware processors may consist of microprocessors, FPGAs, and GPUs, etc. The input / output device 14 may be omitted, or input / output devices other than those exemplified (e.g., optical drives, etc.) may be added. Also, server device 1 may be composed of multiple computers. In this case, the hardware configuration of each computer may or may not be the same.

[0056] Figure 6 is a schematic diagram showing an example of the hardware configuration of the enterprise terminal 2 according to this embodiment. Yes, it exists. The enterprise terminal 2 is configured as a computer having a control unit 21, a storage unit 22, a communication module 23, and an input / output device 24.

[0057] The enterprise terminal 2 can be configured as a computer having a processor (CPU, GPU, etc.), main memory (RAM, ROM, etc.), and auxiliary memory (EPROM, hard disk drive, removable media, etc.), similar to the server device 1. However, some or all of the functions (software modules) may be implemented as hardware modules by hardware circuits such as ASICs or FPGAs.

[0058] The control unit 21 is a computing unit that implements various functions (software modules) of the enterprise terminal 2 by executing a predetermined program. The control unit 11 can be implemented by a hardware processor such as a CPU. The control unit 21 may also be configured to include RAM, ROM (Read Only Memory), cache memory, etc.

[0059] The memory unit 22 is a means for storing information and is composed of storage media such as RAM, magnetic disks, and flash memory. The memory unit 22 stores programs executed by the control unit 21, data used by those programs, and so on.

[0060] The communication module 23 is a communication interface for connecting the enterprise terminal 2 to a network. The communication module 23 may be configured to include, for example, a network interface board and a wireless communication interface for wireless communication. The enterprise terminal 2 can communicate data with other computers (for example, server device 1) via the communication module 23.

[0061] The input / output device 24 is a means of receiving input operations performed by the operator and presenting information to the operator. Specifically, the input / output device 24 includes devices for input such as a mouse and keyboard, and devices for output such as a display and speakers. The input / output device may be integrated with, for example, a touch panel display.

[0062] Furthermore, the specific hardware configuration of the enterprise terminal 2 can be modified as appropriate, depending on the embodiment, by omitting, substituting, or adding components, similar to the server device 1.

[0063] [Software Configuration] Next, the software configuration of each device constituting the system will be described. Figure 7 is a schematic diagram showing an example of the software configuration of the server device 1 according to this embodiment. In this embodiment, the control unit 11 is configured with five software modules: an information collection unit 111, an authorization setting unit 112, a linking unit 113, an information provision unit 114, and a management unit 115. Each software module may be realized by the control unit 11 (CPU) executing a program stored in the storage unit 12. Note that the information processing performed by the information collection unit 111, authorization setting unit 112, linking unit 113, information provision unit 114, and management unit 115 described below is synonymous with the information processing performed by the control unit 11.

[0064] The information collection unit 111 is configured to receive product information and transaction data transmitted from the corporate terminal 2 and to store the received information in the storage unit 12. The authorization setting unit 112 is configured to receive information (hereinafter referred to as authorization information) from the corporate terminal 2 for setting access permissions to the product information. Furthermore, the authorization setting unit 112 is configured to perform a process to set access permissions to the product information stored in the storage unit 12 based on the received information.

[0065] The linking unit 113 interacts with the enterprise terminal 2, thereby allowing the enterprise terminal 2 to access the product The system is configured to acquire information for linking information together. Furthermore, the linking unit 113 is configured to perform a process of writing information representing the linking relationship to the product information stored in the storage unit 12 based on the acquired information. The linking unit 113 is also configured to receive a request to add termination information and, in response, perform a process of adding termination information to the product information stored in the storage unit 12. A product tree is formed by reflecting the linking and termination additions. In other words, forming a product tree is done by saving the linking information and termination information in the storage unit 12. The linking unit 113 is configured to generate a product tree according to the results of the linking and termination additions.

[0066] The information provision unit 114 is configured to perform information processing related to the product tree and to output the results of the information processing. The information processing related to the product tree may include processing that performs traceability calculations on the product tree. Outputting the results of the information processing may include processing that provides the generated product tree information to the enterprise terminal 2. In one example, the information provision unit 114 is configured to generate information about the product tree and to output the generated information about the product tree.

[0067] The management unit 115 is configured to receive applications for approval from companies within the supply chain that wish to participate in the platform, and to issue accounts to those companies. For example, the management unit 115 is configured to verify the authenticity of the company and issue an account only if the verification is successful. The specific process for issuing accounts will be described later.

[0068] In this embodiment, the storage unit 12 is configured to include multiple logical storage areas. Each of the multiple storage areas can be set with different access permissions, such as an area where access is granted to company A, an area where access is granted to company B, or an area where access is granted to both company A and company B. The permission setting unit 112 sets access permissions by storing product information received from the company terminal 2 in the appropriate storage area. The specific processing method will be described later.

[0069] Furthermore, account information is stored in the memory unit 12. In this embodiment, interaction between the server device 1 and the corporate terminal 2 occurs when an operator from each company logs in to the server device 1 using the corresponding company's account via the corporate terminal 2. The account information is information about the account corresponding to each company that makes up the supply chain. Note that logging in using an account is one example of accessing the server device 1 as the corresponding company. However, the method of accessing the server device 1 is not limited to this example and may be appropriately selected depending on the embodiment.

[0070] Figure 8 is a schematic diagram showing the software configuration of the enterprise terminal 2 according to this embodiment. In this embodiment, the control unit 21 is composed of five software modules: a product information generation unit 211, an authorization setting unit 212, an association request unit 213, an information acquisition unit 214, and a management unit 215. Each software module may be implemented by the control unit 21 (CPU) executing a program stored in the storage unit 22. Note that the information processing performed by the product information generation unit 211, authorization setting unit 212, association request unit 213, information acquisition unit 214, and management unit 215 described below is synonymous with the information processing performed by the control unit 21.

[0071] The product information generation unit 211 is configured to generate information (product information) about the company's products corresponding to the company terminal 2. Figure 9 shows an example of product information generated by the product information generation unit 211. The product information may also be entered via the operator of the company terminal 2. In this embodiment, the product information has the following fields: company ID, company name, product ID, and product name. It is composed as follows: The company ID and company name are the identifier and name of the company that produces the target product (i.e., the company that uses company terminal 2). The product ID and product name are the identifier and name of the target product.

[0072] Furthermore, the product information is configured to include linking-related information. Linking-related information is information for identifying the upstream product associated with the target product. In this embodiment, the linking-related information includes the fields "upstream product information" and "termination flag".

[0073] The upstream product information field is configured to store information for identifying product information corresponding to upstream products linked to the target product (i.e., products used in the production process of the target product and included in the target product). The upstream product information field is used when the server device 1 links products together. Basically, at the stage when product information is generated, the target product is not linked to an upstream product, so the upstream product information field does not need to store a value indicating an upstream product.

[0074] The termination flag field is configured to store a flag indicating whether the target product is a leaf node, i.e., the node located at the very top (end) of the product tree. In this embodiment, since multiple corporate terminals 2 transmit product information, this flag is used to determine whether further products are linked upstream of a product in the product tree, or whether no further linking occurs (i.e., whether the target product is located at the top). In other words, the termination flag field is used when the server device 1 confirms the linking of products. Basically, at the stage when product information is generated, the linking relationships of the target products are not yet determined, so the termination flag field may store "0 (not currently the end)". Finally, in order to generate the product tree, the product information of each company stored in the server device 1 is set to one of the following states: "Linking with upstream products has been performed" and "The termination flag is set to "1".

[0075] Furthermore, the product information is configured to include traceability-related information. For example, the traceability-related information may include the amount of material (e.g., upstream product) used per unit of product production, information on the recycling rate of a given raw material, the amount of greenhouse gas emissions (CFP value) emitted during the production of the product, due diligence-related information, or a combination thereof. The given raw material may be, for example, lithium, nickel, cobalt, lead, graphite, etc. The recycling rate may be expressed directly or indirectly, such as a combination of the total amount used and the amount of recycled material used. These values ​​correspond to the processes involved in producing the target product. For example, in the example shown in Figure 4, the traceability-related information included in product information A stores the amount of greenhouse gases emitted during the production activities of product A. The traceability-related information included in product information A does not include information about the processes leading up to the production of the upstream product (e.g., the amount of greenhouse gases emitted until upstream product B is produced).

[0076] Furthermore, traceability-related information may be appropriately selected depending on the embodiment. In one example, greenhouse gas emissions (carbon footprint) may include Scope 1, Scope 2, and Scope 3 emissions. Scope 1 may be direct greenhouse gas emissions by the company itself. Scope 2 may be indirect emissions resulting from the use of electricity, heat, and steam supplied by other companies. Scope 3 may be indirect emissions other than Scope 1 and Scope 3. In another example, due diligence-related information may include technical documentation showing the amount of raw materials contained in the product and whether the company is fulfilling its obligations for responsible mineral sourcing, such as that of smelters, for products containing the target raw materials (e.g., cobalt, natural graphite, lithium, nickel, etc.). In yet another example, due diligence-related information may include a score indicating the degree to which the above obligations are being fulfilled.

[0077] Furthermore, the product information generation unit 211 is configured to generate transaction data for companies corresponding to the company terminal 2. Figure 10 shows an example of transaction data generated by the product information generation unit 211. The transaction data may also be entered via the operator of the company terminal 2. In the example shown in Figure 10, the transaction data consists of fields such as company ID, product ID, trading partner company ID, transaction product ID, and transaction date.

[0078] The Company ID field is configured to store the identifier of the company that produces the target product (i.e., the company using Company Terminal 2). The Product ID field is configured to store the identifier of the target product. The Supplier Company ID field is configured to store the identifier of the supplier company of the products used in the production of the target product (products included in the target product). The identifier stored in the Supplier Company ID field may be an identifier that can identify the name of the supplier company. However, if the supplier company is participating in (or wishing to participate in) the platform anonymously, the Supplier Company ID field will store an identifier that cannot identify the name of the supplier company by companies other than the company that produces the target product and the operators of Server Device 1, etc. The Transaction Product ID field is configured to store the identifier of the product purchased from the supplier company (product used in the production of the target product). The Transaction Date field is configured to store the date on which a transaction regarding the transaction product took place between the company that produces the target product and the supplier company.

[0079] The structure of the transaction data is not limited to the example shown in Figure 10, and fields can be added, modified, and deleted as appropriate. For example, the transaction data may be configured to include fields such as the quantity of the transaction product purchased, the identifier of the company that transported the transaction product from the trading partner to the company in question, the identifier of the company that is the customer (delivery destination) of the product, and the identifier of the company that transported the product from that company to the customer. Furthermore, the above-mentioned transaction data may be configured to be included in the product information of the product in question.

[0080] The product information generation unit 211 is configured to acquire the above-mentioned information via the operator of the corporate terminal 2 and transmit it to the server device 1 at any time.

[0081] The authorization setting unit 212 is configured to specify which downstream companies are permitted to access product information sent from the corporate terminal 2 to the server device 1. Figure 11 is an example of the user interface output by the authorization setting unit 212. As shown, the authorization setting unit 212 is configured to accept the specification of which downstream companies are permitted to access any of the company's own products. Figure 12 is an example of permission information generated by the authorization setting unit 212 based on the input information. The authorization setting unit 212 is configured to send the permission information to the server device 1 at any time. Access permissions may be set on a per-product information basis, or on an item basis included in the product information ("permitted items" in Figure 11). This makes it possible to implement partial disclosure, for example, by disclosing the existence of a product, but not disclosing specific information such as the materials used or the amount used.

[0082] The list of companies presented in the user interface of Figure 11 can be a list of companies that have previously transacted with the company that produces the target product (the company using the company terminal 2). For this reason, the authorization setting unit 212 may generate the list of companies based on the transaction data generated by the product information generation unit 211. If the list of companies that have previously transacted with the company that produces the target product includes companies participating in the platform anonymously, the authorization setting unit 212 may generate the list using an identifier instead of the company name of such company. In this case, the identifier is the same as the identifier used for the transaction data explained with reference to Figure 10, and is an identifier that prevents companies other than the company that produces the target product and the operator of the server device 1 from identifying the company name of such company.

[0083] The linking request unit 213 is configured to request the server device 1 to link the company's product information, which it has sent to the server device 1, with upstream products. In one example, the linking request unit 213 first sends the company's corporate ID and product ID to the server device 1 and requests the linking of product information corresponding to the product ID. In response, the server device 1 generates a user interface that includes a list of product information that the target company is permitted to access (i.e., candidate linking destinations) and provides the generated user interface to the corporate terminal 2. Figure 13 is an example of a user interface that includes a list of products that the target company is permitted to access.

[0084] The product list shown in Figure 13 can be a list of products with which the company has had past transactions. The server device 1 may generate this list based on the transaction data stored in the storage unit 12.

[0085] Next, the linking request unit 213 is configured to allow the operator to select the upstream product to be linked from the list. Furthermore, the linking request unit 213 is configured to send the identifier of the product to be linked (downstream product) and the identifier of the upstream product to be linked as a pair to the server device 1. The server device 1 can then link the product information accordingly.

[0086] If there is no upstream product linked to the target product, this can be clearly indicated by checking the checkbox shown by the dotted line in Figure 13. In this case, no linking of product information will be performed.

[0087] The information acquisition unit 214 is configured to request the server device 1 to provide a product tree and to output the information transmitted from the server device 1.

[0088] Management Unit 215 is configured to mediate applications from other companies for approval to participate in the platform. For example, one of these other companies might be an upstream company with which the other company has business dealings. The specific processing method for mediating applications for participation approval will be described later.

[0089] [Details of the process for forming the product tree] Next, we will explain the specific details of the processing performed by server device 1 and enterprise terminal 2. Figure 14 is a diagram showing an example of the processing flow executed by server device 1 based on a request from enterprise terminal 2. The processing performed by server device 1 can be broadly divided into the following four phases. (1) First phase: Receiving product information and transaction data transmitted from enterprise terminal 2 and storing the received information. (2) The second phase involves receiving permission information transmitted from the corporate terminal 2 and setting access rights to product information according to the received permission information. (3) The third phase involves linking product information by interacting with the enterprise terminal 2. (4) A fourth phase in which information about the product tree is provided based on the results of the linking.

[0090] In the example in Figure 14, company A is a downstream company and company B is an upstream company. The product produced by company A is called product A, and the product produced by company B is called product B. The product information corresponding to product A is called product information A, and the product information corresponding to product B is called product information B.

[0091] In the first phase, the information collection unit 111 of server device 1 acquires product information and transaction data from the product information generation unit 211 of enterprise terminal 2. In the example in Figure 14, server device 1, Product information A and transaction data A are acquired from company terminal 2 corresponding to company A, and product information B and transaction data B are acquired from company terminal 2 corresponding to company B. The information collection unit 111 stores product information A and transaction data A in a storage area (hereinafter referred to as storage area A) to which access rights are granted only to company A. The information collection unit 111 also stores product information B and transaction data B in a storage area (hereinafter referred to as storage area B) to which access rights are granted only to company B. In this way, the information collection unit 111 stores product information and transaction data transmitted from any company in a dedicated storage area to which access rights are granted only to that company. Note that the timing of registering transaction data is not limited to this example and can be determined arbitrarily. In one example, transaction data may be generated for each transaction of the target product, and the generated transaction data may be stored in a dedicated storage area for each transaction.

[0092] In the second phase, the authorization setting unit 112 of the server device 1 receives authorization information from the authorization setting unit 212 of the corporate terminal 2, and sets access permissions for product information according to the received authorization information. As shown in Figure 12, the authorization information associates a product with a company that is permitted to access the product information of that product.

[0093] In the example shown in Figure 14, it is assumed that the authorization setting unit 112 has received authorization information granting access to product information B of the upstream company from company A, which is a downstream company. In this case, the authorization setting unit 112 copies product information B, which is stored in storage area B, to storage area AB, which is granted access rights to both companies A and B. As a result, product information B becomes accessible to both companies A and B. If access rights are not set for a specific item included in the product information, that item is excluded from being copied to storage area AB.

[0094] In the following explanation, a storage area to which access rights are granted only to a specific company will be referred to as a "dedicated storage area," and a storage area to which access rights are granted to multiple companies will be referred to as a "shared storage area."

[0095] The copying of product information is performed by the server device 1 in response to receiving authorization information from the corporate terminal 2. In other words, the corporate terminal 2 sends authorization information to the server device 1, causing the server device 1 to copy the product information identified by the authorization information from the target company's dedicated storage area to a shared storage area accessible by downstream companies.

[0096] In the third phase, the linking unit 113 of the server device 1 receives a linking request from the linking request unit 213 of the corporate terminal 2, and links the product information based on the received linking request.

[0097] First, the linking unit 113 receives a linking request from the corporate terminal 2. The linking request is sent from the corporate terminal 2 of a downstream company. In the example in Figure 14, it is assumed that the corporate terminal 2 of company A sent the linking request. The linking request includes the company ID and the product ID of the target product. The linking unit 113 retrieves the product information stored in the memory area accessible from that company and generates a list of the retrieved product information. In the example in Figure 14, company A can access product information B stored in memory area AB. Therefore, product information B can be selected as the linking destination on the corporate terminal 2 of company A.

[0098] The linking request unit 213 of the enterprise terminal 2 presents a list to the operator and allows the operator to select the products to be linked. In this example, products A and B are the products to be linked to each other. For example, the operator inputs information indicating that the upstream product for product A is product B via the input / output device 24. The linking request unit 213 then processes the upstream product (product B). Data (linking data) for linking the downstream product (product A) to each other is transmitted to the linking unit 113.

[0099] As illustrated in Figure 9, the product information includes fields related to the linked product (linking-related information). Based on the aforementioned linking data, the linking unit 113 stores information corresponding to product information B (i.e., the upstream product) in the linking-related information of product information A. For example, the linking-related information may include an identifier for the upstream product and an identifier for the company that produces the upstream product.

[0100] Furthermore, the linking-related information may include pointers to the product information to which the linking is made. The pointers indicate the address of the product information corresponding to the upstream product. Through the process described above, a part of a tree structure is formed in which the product information of the downstream product is the parent node and the product information of the upstream product is the child node.

[0101] Furthermore, no further linking is performed at the end of the product tree. In this case, instead of sending linking data, the linking request unit 213 sends data indicating that the product is at the end of the tree. Upon receiving this data, the linking unit 113 sets the end flag field of the corresponding product information to "1". In other words, in the third phase, either the process of "setting the upstream product to be linked" or the process of "setting the end flag" is executed.

[0102] In the fourth phase, the information provision unit 114 of the server device 1 generates information about the product tree based on the stored product information and outputs the information about the product tree. Generating information about the product tree may include processes to generate various types of product information (for example, traceability information and images representing the link relationships between products using a tree diagram) after links between nodes have been formed by linking the product information together. This process of generating information about the product tree is an example of information processing about the product tree. In order to generate information about the product tree, all linking of product information must be completed, and the termination flag of all leaf nodes must be set to "1". The information provision unit 114 can appropriately generate the information when these conditions are met.

[0103] The product tree in this embodiment, as described with reference to Figure 3, represents the supply relationships between product information in the supply chain using a tree diagram. The information provision unit 114 can generate an image representing the tree diagram based on the product information.

[0104] Furthermore, when generating information about the product tree, the information provision unit 114 integrates the traceability-related information defined for each product and outputs the result. For example, when generating information about the product tree, the information provision unit 114 may repeatedly perform a process of sequentially integrating the traceability-related information defined for each product from the upstream to the downstream. Examples of traceability-related information to be integrated include carbon dioxide emissions, recycling rates for specified raw materials, and due diligence scores. If the traceability-related information is numerical, the integration may be performed by numerical calculations, and if the traceability-related information is not numerical (for example, due diligence-related information), the integration may be simply information collection.

[0105] In another example, product information may include information indicating the location of traceability-related information for the corresponding product (hereinafter referred to as "location information," typically an address, pointer, etc.). In this case, the traceability-related information does not necessarily have to be included in the product information. Furthermore, the integration may involve collecting the location information included in the product information.

[0106] The information provision unit 114 may output the generated product tree in image format. It may also output traceability-related information corresponding to any product at the same time. Furthermore, the information provision unit 114 may provide the generated product tree to the corporate terminal 2 (information acquisition unit 214) upon request from the said corporate terminal 2. It should be noted that disclosing the entire product tree to a specific company may not be appropriate in some cases. Therefore, when the information provision unit 114 provides the product tree to a corporate terminal 2 corresponding to a certain company, it may perform a process to keep confidential the portion that the company does not have access rights to.

[0107] [Processing flow] Next, we will explain the flow of processing performed by the server device 1 and the corporate terminal 2 when the corporate terminal 2 registers its own product information, referring to Figures 15 and 16. Figure 15 is a sequence diagram corresponding to the first to third phases described above.

[0108] In one example, the interaction between server device 1 and corporate terminal 2 begins when an operator from each company logs into server device 1 via corporate terminal 2 using the corresponding company's account. In this example, it is assumed that each company's operator logs into server device 1 using their own company's account.

[0109] First, in step S11, the product information generation unit 211 of the corporate terminal 2 acquires the company's product information and transaction data via the operator and transmits the acquired product information and transaction data to the server device 1. The transmitted product information and transaction data are received by the server device 1 (information collection unit 111) and stored in the storage unit 12 (step S12). At this time, the information collection unit 111 stores the product information and transaction data in a storage area to which access rights are granted only to companies that produce the corresponding products.

[0110] Next, in step S13, the authorization setting unit 212 of the corporate terminal 2 receives input (authorization information) via the operator, specifying the downstream companies that are permitted to access the product information transmitted in step S11. In this step, a user interface as described with reference to Figure 11 may be provided, allowing the user to specify any combination of product and the downstream companies that are permitted to access the product information. The input authorization information is transmitted to the server device 1.

[0111] In step S14, the authorization setting unit 112 of the server device 1 grants access rights to the target product information based on the received authorization information. In this step, as explained with reference to Figure 14, the authorization setting unit 112 grants access rights to any product information to any company by copying the target product information to a storage area where access rights have been granted to multiple companies. If there is no storage area with appropriate access rights, a new storage area may be created and access rights granted to the appropriate company.

[0112] Next, in step S15, the linking request unit 213 of the corporate terminal 2 sends data (linking request) to the server device 1 requesting that the product information sent to the server device 1 be linked to the upstream product. This linking request includes the company's corporate ID and the product ID of the target product.

[0113] In step S16, the server device 1 (linking unit 113) generates a list of product information that the target company is permitted to access, and provides the corporate terminal 2 with a user interface that includes this list. In this step, the server device 1 provides the corporate terminal 2 with a user interface as described with reference to Figure 13, and allows access to any product and the linking of that product. You may also specify the combination with the upstream product to be attached.

[0114] In step S17, the linking request unit 213 of the enterprise terminal 2 receives a specification from the operator regarding the combination of the target product and the upstream product associated with that product. The linking request unit 213 generates data (linking data) indicating the association between the upstream product and the downstream product, and sends the generated linking data to the server device 1.

[0115] In step S18, the linking unit 113 of the server device 1 updates the stored product information based on the linking data, reflecting the linking between the product information. The linking of product information may also be performed by storing information about the upstream product (identifier, pointer, etc.) in the linking-related information contained in the product information of the downstream product.

[0116] If no downstream companies exist, steps S13 to S14 may be omitted. Similarly, if no upstream companies exist (i.e., no linked product exists), instead of requesting the linking of product information, the process of setting the termination flag described above may be executed. In this case, steps S15 to S18 described above are omitted.

[0117] Figure 16 is a sequence diagram corresponding to the fourth phase described above. First, in step S21, the information acquisition unit 214 of the enterprise terminal 2 requests the server device 1 to provide a product tree. This request includes, for example, the identifier of the target product. The target product may be the final product or other products (intermediate products).

[0118] Upon receiving the request, the server device 1 (information provision unit 114) generates information about the product tree through the process described above (step S22). At this time, the information provision unit 114 performs a process to integrate the traceability-related information defined in each product information from the upstream to the downstream. The result of the integration may be reflected in each product information.

[0119] Next, in step S23, the server device 1 performs a process to conceal information for which access rights have not been granted, based on the access rights held by the target company. For example, if the existence of a company's product information from another company is not publicly disclosed, the server device 1 may perform a process to conceal the existence of that product information. Also, if only specific items included in the product information are not publicly disclosed, the server device 1 may perform a process to conceal the contents of those items. The concealed information regarding the product tree is provided to the company terminal 2 (information acquisition unit 214) and output (step S24).

[0120] [Details of the account issuance process] Next, the specific details of the process for issuing accounts to companies newly joining the platform in this embodiment will be described. Here, we assume a case where a downstream company has already joined the platform (the downstream company's account information is registered in Server Device 1), but an upstream company has not yet joined the platform (the upstream company's account information is not registered in Server Device 1). The downstream company is an example of a first company, and the upstream company is an example of a second company. In such a case, unless the downstream company registers the upstream company's product information by other alternative means, it cannot link its own products to the upstream products. On the other hand, if anonymous companies are allowed to freely participate in order to widely solicit the registration of upstream companies' product information, it becomes difficult to guarantee the authenticity of the participating companies. Therefore, in this embodiment, if an upstream company wishes to participate in the platform anonymously, in order to guarantee the authenticity of the upstream company on the system, the upstream company is required to apply for approval to participate in the platform through a downstream company that has already joined the platform.

[0121] Figure 17 is a sequence diagram of the processing performed by the system according to this embodiment. In the example shown, the enterprise terminal corresponding to a downstream company is referred to as enterprise terminal 2A, and the enterprise terminal corresponding to an upstream company is referred to as enterprise terminal 2B. A downstream company is a company belonging to the supply chain whose account information is registered in server device 1. An upstream company is a company belonging to the supply chain whose account information is not registered in server device 1. Furthermore, it is assumed that transaction data between the downstream company and the upstream company is registered in the dedicated storage area for the downstream company in the storage unit 12 of server device 1.

[0122] In the upstream company, the operator sends a request for approval to participate in the platform to the enterprise terminal 2A via enterprise terminal 2B (step S31). Note that the request for approval to participate from the upstream company to the downstream company may also be made verbally or otherwise, without going through enterprise terminals 2A and 2B.

[0123] When a request for approval of participation from an upstream company is received by enterprise terminal 2A, the operator of enterprise terminal 2A logs in to server device 1 from enterprise terminal 2A using the downstream company's account. The operator of enterprise terminal 2A inputs a request for approval of participation targeting the upstream company via input / output device 24. Once the input of the above request is complete, the management unit 215 of enterprise terminal 2A sends the application for approval of participation from the upstream company to server device 1 (step S32). The application for approval of participation includes the identifier of the upstream company. The identifier of the upstream company included in the application for approval of participation is the same identifier used for transaction data stored in the downstream company's dedicated storage area. However, in this case, the identifier of the upstream company is an identifier that does not allow companies other than the downstream company and the operator of server device 1 to identify the upstream company.

[0124] When the server device 1 receives the application for participation approval sent from the corporate terminal 2A, the management unit 115 of the server device 1 sends invitation data to the corporate terminal 2A (step S33). The invitation data includes an address and a request to submit an electronic certificate issued by the certification authority 3. For example, the address included in the invitation data may be the URL of a website provided by the server device 1 through the execution of a web server. In one example, the website may be a website for uploading various data such as electronic certificates to the server device 1. Such a website URL may be a one-time URL with a limited access period or number of accesses. When the corporate terminal 2A receives the invitation data sent from the server device 1, the management unit 115 of the corporate terminal 2A forwards the invitation data received from the server device 1 to the corporate terminal 2B.

[0125] Furthermore, the transmission of invitation data from enterprise terminal 2A to enterprise terminal 2B may be performed by the operator of enterprise terminal 2A using email or the like. Also, if the application for participation approval sent from enterprise terminal 2A to server device 1 includes contact information (e.g., email address) of the upstream company, the management unit 115 of server device 1 may send an invitation email to that contact information. The above contact information may be one that does not identify the upstream company (e.g., a free email address).

[0126] When the above invitation data is received by the upstream company's enterprise terminal 2B, the operator of enterprise terminal 2B prepares an electronic certificate in accordance with the request contained in the invitation data (a request to submit an electronic certificate issued by Certification Authority 3). In one example, the operator of enterprise terminal 2 generates the upstream company's private key and the public key corresponding to that private key (step S34). Hereinafter, the upstream company's private key will be referred to as private key A, and the public key corresponding to private key A will be referred to as public key A. Once private key A and public key A are generated, the operator of enterprise terminal 2B sends a request for the issuance of an electronic certificate to Certification Authority 3 through enterprise terminal 2B (step S35). The request for the issuance of an electronic certificate includes the upstream company's public key A. Note that the upstream company's private key A and public key A may be generated by Certification Authority 3. In that case, the operator of enterprise terminal 2B may send the request for the generation of private key A and public key A together with the request for the issuance of an electronic certificate to Certification Authority 3. The request for the issuance of an electronic certificate to certification authority 3 may be made without going through corporate terminal 2B.

[0127] Upon receiving a request for the issuance of an electronic certificate, Certification Authority 3 verifies the identity of the upstream company based on information such as the company register and tax certificates. If the identity of the upstream company is successfully verified, Certification Authority 3 creates owner identification information for the upstream company. Certification Authority 3 calculates a plaintext hash value containing the created owner identification information and the upstream company's public key A. Certification Authority 3 generates its own digital signature by encrypting the calculated hash value with its private key. Hereafter, Certification Authority 3's private key will be referred to as private key B, and the public key corresponding to private key B will be referred to as public key B. The digital signature generated by Certification Authority 3 will be referred to as digital signature A. Certification Authority 3 generates an electronic certificate containing the second company's owner identification information, the second company's public key, and Certification Authority 3's digital signature A. Certification Authority 3 transmits the generated electronic certificate to the upstream company's enterprise terminal 2B (step S36). Certification Authority 3 also registers the generated electronic certificate in its repository.

[0128] In another example, the generation of private key A and public key A, and the acquisition of the digital certificate may be performed at any time before receiving the invitation data. That is, steps S34-S36 in Figure 17 may be performed at any time before step S33. Also, in another example, step S34 may be performed by Certificate Authority 3. In this case, step S34 may be omitted, and Certificate Authority 3 may generate private key A and public key A in step S36.

[0129] When the digital certificate issued by the certification authority 3 is received by the corporate terminal 2B, the operator of corporate terminal 2 accesses the address (URL) included in the invitation data through the browser of corporate terminal 2 (step S37). When the server device 1 accepts corporate terminal 2B's access to the address included in the invitation data, the server device 1 interacts with corporate terminal 2B by executing web server processing. As an example, the server device 1 uploads the digital certificate, digital signature, and specified information to corporate terminal 2 through interaction with corporate terminal 2. In this case, the digital signature is generated by encrypting the specified information with the upstream company's private key A, unlike digital signature A generated by the certification authority 3. Hereinafter, the digital signature generated by the upstream company will be referred to as digital signature B.

[0130] In one example, the predetermined information may be information specified by the server device 1. The information specified by the server device 1 may consist of information provided by downstream companies. For example, the server device 1 may generate the predetermined information based on transaction data relating to transactions between upstream and downstream companies. In this case, the management unit 115 of the server device 1 accesses the transaction data stored in the downstream company's dedicated storage area to identify the transaction data between the downstream company and the upstream company. For example, in the example shown in Figure 10, the management unit 115 identifies the transaction data in which an identifier matching the upstream company identifier included in the application for participation approval is registered in the trading partner company ID field. The management unit 115 selects one or more transaction data from the identified transaction data. The management unit 115 of the server device 1 may calculate the hash value of the selected one or more transaction data and use the calculated hash value as the predetermined information. Alternatively, the management unit 115 of the server device 1 may encrypt the selected one or more transaction data and use the encrypted one or more transaction data as the predetermined information. Furthermore, in order to prevent third parties from identifying one or more transaction data selected by the server device 1, a predetermined value may be added to the above one or more transaction data, and the predetermined information may be generated by hashing or encrypting the transaction data to which the predetermined value has been added. The predetermined value may be any value obtained by the server device 1 (for example, a random number, a timestamp, etc.).

[0131] As another example, one or more transaction data points used to generate the specified information may be selected from multiple transaction data points specified through the downstream company's account. The management unit 115 then sends a list of transaction data in which an identifier matching the identifier of the upstream company included in the application for participation approval is registered in the trading partner company ID field to the company terminal 2A. Upon receiving the list of transaction data, the management unit 215 presents the list of transaction data received from the server device 1 to the operator and accepts the selection of multiple transaction data from the list. Figure 18 is an example of a user interface output by the management unit 215. In this case, the management unit 215 is configured to accept the selection of multiple transaction data from the list of transaction data, as illustrated in Figure 18. When the operator of the company terminal 2A selects multiple transaction data in the user interface illustrated in Figure 18, the management unit 215 sends information identifying the selected multiple transaction data to the server device 1. Upon receiving this information, the server device 1, the management unit 115, selects one or more transaction data from the selected multiple transaction data and generates predetermined information from the selected one or more transaction data.

[0132] The generation of the specified information may occur when the server device 1 receives a request for participation approval sent from the downstream company's enterprise terminal 2A. In this case, the management unit 115 of the server device 1 may accept the specification of the multiple transaction data through interaction with the downstream company's enterprise terminal 2A. The management unit 115 of the server device 1 may select one or more transaction data from the specified multiple transaction data and generate the specified information using the selected one or more transaction data. The management unit 115 of the server device 1 may then send invitation data, which further includes the generated specified information, to the upstream company's enterprise terminal 2B via the downstream company's enterprise terminal 2A. If the specified information is included in the invitation data, the generation of the electronic signature B by the upstream company may occur before the enterprise terminal 2B accesses the address included in the invitation data.

[0133] If transaction data between downstream and upstream companies is not stored in the storage unit 12, when a request for participation approval is sent from the corporate terminal 2A to the server device 1, multiple transaction data between downstream and upstream companies may be sent from the corporate terminal 2A to the server device 1. The predetermined information used to generate the upstream company's electronic signature B is not limited to the above transaction data, but may consist of any information such as a timestamp, a random number generated by the server device 1 or the corporate terminal 2B, etc.

[0134] When accessing server device 1, enterprise terminal 2B generates digital signature B by encrypting predetermined information with secret key A (step S38). In one example, enterprise terminal 2B may generate digital signature B by hashing plaintext containing the predetermined information and encrypting the resulting hash value with secret key A. Once digital signature B is generated, the operator of enterprise terminal 2B transmits (uploads) the digital certificate, digital signature B, and predetermined information to server device 1 through enterprise terminal 2B (step S39). Note that the timing of step S38 is not limited to this example. Step S38 may be executed at any time before step S37.

[0135] When the server device 1 receives the electronic certificate, electronic signature B, and specified information transmitted from the upstream company's enterprise terminal 2B, the management unit 115 of the server device 1 obtains the public key B of the certification authority 3 (step S40). The management unit 115 uses the obtained public key B to verify the authenticity of the upstream company (step S41).

[0136] In verifying the authenticity of the upstream company, first, the management unit 115 uses the public key B of the certification authority 3 to verify the validity of the digital certificate received from the upstream company's enterprise terminal 2B. Specifically, the management unit 115 uses the public key B of the certification authority 3 to decrypt the digital signature A (the digital signature of the certification authority 3) contained in the digital certificate. The management unit 115 also calculates the hash value of the plaintext of the owner identification information contained in the digital certificate and the public key A of the upstream company. The decrypted information of name A is compared with the calculated hash value. If the comparison between the decrypted information of digital signature A and the calculated hash value is successful, the management unit 115 refers to the repository of certification authority 3 to determine whether the digital certificate has expired. If the digital certificate has not expired, the management unit 115 determines that the digital certificate is valid (the identity verification of the upstream company by certification authority 3 is valid).

[0137] Next, the management unit 115 verifies the validity of the upstream company's electronic signature B. Specifically, the management unit 115 decrypts the upstream company's electronic signature B using the public key A contained in the electronic certificate. The management unit 115 then compares the decrypted information of electronic signature B with predetermined information. For example, the management unit 115 may hash the plaintext containing the predetermined information and compare the resulting hash value with the decrypted information. If the comparison between the decrypted information and the predetermined information is successful, it is proven that the electronic signature B was generated using the private key A corresponding to the public key A contained in the electronic certificate and the predetermined information contained in the invitation data. This allows us to conclude that the company that accessed the address contained in the invitation data possesses the private key A, and that the company that received the invitation data and the company that accessed the address are consistent. In other words, it can be concluded that the source of access to the address contained in the invitation data is consistent with the upstream company whose identity has been verified by the certification authority 3. Therefore, if the comparison between the decrypted information of electronic signature B and the predetermined information is successful, the management unit 115 determines that the upstream company's electronic signature B is valid. The order in which the validity of the electronic certificate and electronic signature B is verified is arbitrary.

[0138] If the validity of the electronic certificate and electronic signature B received from the upstream company's terminal 2B is verified successfully, the management unit 115 of the server device 1 generates an account for the upstream company and sends the generated account to the company terminal 2B (step S42).

[0139] [Processing flow] Figure 19 is a flowchart showing an example of the processing flow performed by Server Device 1 when issuing accounts for companies that wish to participate in the platform anonymously (specific processing steps S33, S40-S42 above). The processing flow shown in Figure 19 is executed when an application for participation approval is received.

[0140] In the example shown in Figure 19, similar to the example explained using Figure 17, we assume that a company wishing to participate in the platform anonymously is the upstream company, and a company mediating the upstream company's application for approval of participation is the downstream company. The downstream company's terminal is referred to as terminal 2A, and the upstream company's terminal is referred to as terminal 2B. Furthermore, the upstream company's private key and public key are referred to as private key A and public key B, and the private key and public key of Certification Authority 3 are referred to as private key B and public key B. In addition, the digital signature of Certification Authority 3 is referred to as digital signature A, and the upstream company's digital signature is referred to as digital signature B.

[0141] Although the execution entity of the processing flow shown in Figure 19 is the processor of server device 1, the explanation will be given using the software module of server device 1 as the execution entity.

[0142] In the processing flow illustrated in Figure 19, when the server device 1 receives a participation approval request sent from the downstream company's enterprise terminal 2A, the management unit 115 accepts the participation approval request (step S101). After the management unit 115 finishes executing the process in step S101, it executes the process in step S102.

[0143] In step S102, the management unit 115 generates predetermined information. In one example, the management unit 115 generates predetermined information using transaction data between downstream and upstream companies. In this case, the management unit 115 accesses the transaction data stored in the downstream company's dedicated storage area to identify the transaction data between downstream and upstream companies. The management unit 115 identifies The management unit 115 sends a list of the collected transaction data to the enterprise terminal 2A. For example, the management unit 115 sends a user interface as described in Figure 18 to the enterprise terminal 2A. In response, when information specifying multiple transaction data items from the above list (information identifying multiple transaction data items) is sent from the enterprise terminal 2A to the server device 1, the management unit 115 selects one or more transaction data items from the specified multiple transaction data items. The management unit 115 generates predetermined information using the selected one or more transaction data items. As an example, the management unit 115 adds a predetermined value to the above one or more transaction data items and generates a predetermined value by hashing or encrypting the transaction data to which the predetermined value has been added. After the management unit 115 has finished executing the process in step S102, it executes the process in step S103.

[0144] In step S103, the management unit 115 sends invitation data to the corporate terminal 2A. The invitation data includes an address and a request for submission of an electronic certificate issued by the certification authority 3. The invitation data may also include predetermined information generated in step S102. In that case, the invitation data may also include a request to generate an electronic signature B of the upstream company using the predetermined information. The address included in the invitation data may be the URL of a website for uploading various data such as electronic certificates to the server device 1. As mentioned above, such an address may be a one-time URL. After completing the processing in step S103, the management unit 115 executes the processing in step S104.

[0145] In step S104, the management unit 115 determines whether access to the address included in the invitation data has occurred. If no access to the address included in the invitation data has occurred (negative determination in step S104), the management unit 115 waits until access to that address occurs. On the other hand, if access to that address has occurred (positive determination in step S105), the management unit 115 executes the process in step S105.

[0146] In step S105, the management unit 115 interacts with the corporate terminal 2B through the execution of a web server to obtain the digital certificate, digital signature B, and predetermined information. For example, the management unit 115 may display a user interface on the browser of the corporate terminal 2B for uploading the digital certificate, digital signature B, and predetermined information. After completing the process in step S105, the management unit 115 executes the process in step S106.

[0147] In step S106, the management unit 115 obtains the public key B of the certification authority 3. For example, the public key B of the certification authority 3 may be entered via the operator of the server device 1. After completing the process in step S106, the management unit 115 executes the process in step S107.

[0148] In step S107, the management unit 115 verifies the validity of the digital certificate obtained in step S105. In verifying the digital certificate, the management unit 115 first decrypts the digital signature A contained in the digital certificate using the public key B of the certification authority 3. The management unit 115 also calculates the hash value of the plaintext of the owner identification information and the public key A of the upstream company contained in the digital certificate. The management unit 115 compares the decrypted digital signature A information with the calculated hash value. Furthermore, the management unit 115 refers to the repository of the certification authority 3 to determine whether the digital certificate has expired. As an example, information on whether the digital certificate has expired may be entered via the operator of the server device 1. After completing the process in step S107, the management unit 115 executes the process in step S108.

[0149] In step S108, the management unit 115 determines whether the verification of the validity of the electronic certificate in step S107 was successful. If the comparison between the information decrypted from electronic signature A and the calculated hash value is successful and it is determined that the electronic certificate has not expired, the management unit The logic unit 115 determines that it has successfully verified the validity of the electronic certificate (positive determination in step S108). If a positive determination is made in step S108, the management unit 115 executes the process in step S109.

[0150] In step S109, the management unit 115 verifies the validity of the upstream company's electronic signature B. In verifying electronic signature B, the management unit 115 first decrypts the upstream company's electronic signature B using the public key A contained in the electronic certificate. Subsequently, the management unit 115 compares the decrypted information of electronic signature B with predetermined information. After completing the process in step S109, the management unit 115 executes the process in step S110.

[0151] In step S110, the management unit 115 determines whether the verification of the validity of the electronic signature B in step S109 was successful. If the verification of the information decrypted from the electronic signature B with the predetermined information is successful, the management unit 115 determines that the verification of the electronic signature B was successful (affirmative determination in step S110). If an affirmative determination is made in step S110, the management unit 115 executes the process in step S111.

[0152] In step S111, the management unit 115 issues an account to the upstream company. The account is information used for authentication when the upstream company logs in to the server device 1. For example, the account includes information that identifies the upstream company and a password. When the management unit 115 finishes executing the process in step S111, the processing flow shown in Figure 19 is completed.

[0153] If a negative result is obtained in step S108 (if the validity of the electronic certificate fails to be verified) or in step S110 (if the validity of the upstream company's electronic signature B fails to be verified), the processing flow in Figure 19 will end without an account being issued to the upstream company. In that case, the management unit 115 may send a user interface to the upstream company's enterprise terminal 2B indicating that the validity of the electronic certificate failed to be verified or that the validity of the upstream company's electronic signature B failed to be verified.

[0154] As explained above, in this embodiment, when an application for approval of participation is received from a company that wishes to participate in the platform anonymously, the server device 1 verifies the validity of the electronic certificate and electronic signature submitted from the source of access to the address included in the invitation data, and approves the company's participation in the platform on the condition that the verification is successful. If the validity of the submitted electronic certificate is successfully verified, the company's identity verification by the certification authority 3 can be considered valid. Furthermore, if the validity of the submitted electronic signature is successfully verified, it is proven that the submitted electronic signature was generated using the company's private key (the private key corresponding to the public key included in the electronic certificate) and predetermined information included in the invitation data. This allows it to be considered that the source of access to the address included in the invitation data holds the company's private key, and that the recipient of the invitation data and the source of access to the address are consistent. Therefore, if the validity of the electronic certificate and the company's electronic signature is successfully verified, it can be determined that the source of access to the address included in the invitation data is consistent with the company whose identity has been verified by the certification authority 3.

[0155] Therefore, according to this embodiment, it becomes possible to guarantee the authenticity of companies participating in the platform anonymously.

[0156] Furthermore, with a configuration that generates predetermined information using transaction data related to transactions between companies wishing to participate in the platform anonymously and companies that have applied for approval to participate, it is possible to identify companies wishing to participate in the platform anonymously as companies that have transactions with companies already participating in the platform.

[0157] Furthermore, in a configuration where server device 1 selects one or more transaction data from among multiple transaction data related to transactions between companies wishing to participate in the platform anonymously and companies that have applied for approval to participate, and generates predetermined information, it is possible to suppress the identification of the transaction data used to generate the predetermined information by a third party.

[0158] Furthermore, in a configuration in which predetermined information is generated by adding a predetermined value to one or more transaction data selected by the server device 1, and then hashing or encrypting the transaction data to which the predetermined value has been added, it is possible to more reliably suppress the identification of the transaction data used to generate the predetermined information by a third party.

[0159] (Other embodiments) The embodiments described above are merely examples, and this disclosure may be modified as appropriate without departing from its essence. For example, the processes and means described in this disclosure can be freely combined and implemented as long as no technical inconsistencies arise.

[0160] In the description of the embodiments, the first and second companies related to this disclosure are given as examples of adjacent upstream and downstream companies in the supply chain, but the invention is not limited to these examples. For example, the first and second companies do not have to be adjacent to each other in the supply chain, as long as they are companies that have a trading relationship with each other among multiple companies belonging to the supply chain.

[0161] Furthermore, in the description of the embodiment, the server device 1 stores product information and transaction data in a database, but product information and transaction data may be stored by means other than a database.

[0162] Furthermore, while the description of the embodiments illustrates a platform to which this disclosure applies in which the server device 1 completes the product tree by executing the first to fourth phases, it is not limited to this. For example, this disclosure can also be applied to a platform in which the role of the server device 1 is distributed among multiple corporate terminals 2. This disclosure can also be applied to a platform in which product information is stored in a distributed database using a blockchain platform. In another example, this disclosure may be applied to a platform in which metadata of product information (e.g., information to identify a product) is held on a central server, and product information of each company is held on each company's terminal.

[0163] The configuration of the digital certificate and the digital signature of the second company is not limited to the configuration of the embodiment described above and may be modified as appropriate. The configuration of the digital certificate is not particularly limited as long as it can verify the authenticity of the public key of the second company and may be determined as appropriate depending on the embodiment. Similarly, the configuration of the digital signature of the second company is not particularly limited as long as it can be decrypted with the public key of the second company and its validity can be verified and may be determined as appropriate depending on the embodiment.

[0164] Furthermore, while the embodiment describes a platform provided by server device 1, the invention is not limited to this. For example, server device 1 may be a server independent of the platform and provide information obtained from enterprise terminal 2 to the platform.

[0165] Furthermore, in the above embodiment, access control for each company is achieved by providing dedicated storage areas and shared storage areas. However, the method of achieving access control is not limited to this example. Any method may be used for access control.

[0166] Furthermore, in the above embodiment, multiple companies included in the supply chain were described as companies that produce products. However, companies included in the supply chain are not necessarily products. The companies included in the supply chain do not necessarily have to be those that produce the products. For example, companies that transport, import, store, or wholesale products may also be included in the supply chain. For instance, some of the companies among several may not be companies that perform the manufacturing process, such as trading companies, sales agents, or import agents, and may receive products from companies located one level up (upstream companies) and deliver them to companies located one level down (downstream companies).

[0167] Furthermore, in the above embodiment, a supply chain for products related to automobiles was assumed, and OEM manufacturers were described as the lowest-level companies, while companies supplying parts, materials, assemblies, etc., were described as suppliers. However, the companies belonging to the supply chain are not necessarily limited to these. The companies at each stage may be determined as appropriate depending on the product, etc. Also, the manufacturing activities carried out by each company until the final product is obtained may be determined as appropriate depending on the embodiment, and may include, for example, all activities that can be carried out until the final product is obtained, such as excavation, processing, assembly, transportation, and storage. The product is not limited to those related to automobiles and may be selected as appropriate depending on the embodiment. For example, the product may be a battery used for purposes other than automobiles.

[0168] Furthermore, in the above embodiment, the server device 1 is configured to perform the information processing of the first to fourth phases described above. However, the configuration of the server device 1 is not limited to this example. In another example, at least one of the information processing of the first to fourth phases described above may be omitted in the server device 1. The server device 1 may be configured to perform any other information processing.

[0169] In the above embodiment, each company (Tier N-1) excluding the upstream company has its own traceability Instead of storing related information in a shared storage area between itself and its downstream companies, the integration results of each company may be stored in a shared storage area between each company and its downstream companies (Tier N-2). This allows us to obtain traceability-related information (integrated results) for the final product without requiring each company to disclose its own traceability-related information.

[0170] Furthermore, in the above embodiment, it was assumed that each company places an order with one company for a certain material. However, in the above embodiment, the ordering format of each company is not limited to this example. At least some of the companies belonging to the supply chain may place orders with multiple upstream companies for the same product and selectively use the obtained upstream products in their own products. For example, in the example in Figure 2 above, Tier 1 product A1 may selectively use Tier 2 products A11_1, A11_2, or A11_3. In this case, the server device 1 will specify the pattern A linking relationship may be maintained for each unit. In the example above, server device 1 is linked to product A1 of Tier 1. Therefore, Pattern 1 is "Tier 2 product A11_1, ...", and Pattern 2 is "product A11_2, ...". And linking information may be maintained, such as in pattern 3 "Product A11_3, ...".

[0171] Furthermore, a process described as being performed by a single device may be divided and executed by multiple devices. Conversely, a process described as being performed by different devices may be executed by a single device. In a computer system, the hardware configuration (server configuration) by which each function is implemented can be flexibly changed.

[0172] This disclosure can also be realized by supplying a computer program implementing the functions described in the above embodiments to a computer, and having one or more processors in the computer read and execute the program. Such a computer program may be provided to the computer by a non-temporary computer-readable storage medium that can be connected to the computer's system bus, or it may be provided to the computer via a network. Non-temporary computer-readable storage mediums include, for example, magnetic disks (floppy disks, hard disk drives (HDDs), etc.), optical disks (CD-ROMs, etc.) This includes any type of disc (such as DVD discs and Blu-ray discs), read-only memory (ROM), random access memory (RAM), EPROM, EEPROM, magnetic cards, flash memory, optical cards, and any type of medium suitable for storing electronic instructions. [Explanation of symbols]

[0173] 1 Server device 2. Enterprise terminals 11 Control Unit 12 Storage section 13. Communication Module 14 Input / Output Devices 111 Information Gathering Department 112 Permissions Setting Section 113 String attachment part 114 Information Provision Department 115 Management Department

Claims

1. An information processing device, The platform accepts applications from the account of the first company participating in the platform for approval of the second company's participation in the said platform, In response to the aforementioned application, invitation data including a URL for a website to upload data to the information processing device and a request for submission of an electronic certificate issued by a certification authority will be transmitted to the second company via the first company. Accepting access from the second company's terminal to the URL included in the invitation data, In response to the aforementioned access, the electronic certificate and the electronic signature of the second company are obtained from the terminal of the second company, The validity of the acquired digital certificate is verified using the public key of the aforementioned certification authority, The validity of the acquired digital signature is verified using the public key of the second company contained in the digital certificate, In accordance with the successful verification of the validity of the aforementioned electronic certificate and electronic signature, the participation of the second company in the aforementioned platform will be approved. A control unit configured to perform the following actions: Information processing device.

2. The electronic signature of the second company is generated by encrypting predetermined information using the private key corresponding to the public key of the second company. The information processing apparatus according to claim 1.

3. The invitation data transmitted by the control unit is configured to further include the predetermined information, The information processing apparatus according to claim 2.

4. The aforementioned predetermined information is based on transaction data relating to transactions between the first company and the second company. The following is generated The information processing apparatus according to claim 3.

5. The control unit, in response to receiving the application, Selecting one or more transaction data from among multiple transaction data relating to the transaction between the aforementioned first company and the aforementioned second company, To generate predetermined information from the selected one or more transaction data, It is configured to perform further actions. The information processing apparatus according to claim 4.

6. The multiple transaction data relating to the transaction between the first company and the second company are stored on the platform. Selecting one or more transaction data points as described above means The designation of the aforementioned multiple transaction data is accepted from the account of the first company, and Selecting one or more transaction data from the specified multiple transaction data, including, The information processing apparatus according to claim 5.

7. The predetermined information is generated by adding a predetermined value to the transaction data and hashing or encrypting the transaction data to which the predetermined value has been added. The information processing apparatus according to claim 4.

8. The predetermined information is a random number generated by the control unit. The information processing apparatus according to claim 2.

9. Computers The platform accepts applications from the account of the first company participating in the platform for approval of the second company's participation in the said platform, In response to the aforementioned application, invitation data including a URL for a website to upload data to the computer and a request for submission of an electronic certificate issued by a certification authority will be transmitted to the second company via the first company. Accepting access from the second company's terminal to the URL included in the invitation data, In response to the aforementioned access, the electronic certificate and the electronic signature of the second company are obtained from the terminal of the second company, The validity of the acquired digital certificate is verified using the public key of the aforementioned certification authority, The validity of the acquired digital signature is verified using the public key of the second company contained in the digital certificate, In accordance with the successful verification of the validity of the aforementioned electronic certificate and electronic signature, the participation of the second company in the aforementioned platform will be approved. Execute Information processing methods.

10. The electronic signature of the second company is generated by encrypting predetermined information using the private key corresponding to the public key of the second company. The information processing method according to claim 9.

11. The invitation data transmitted by the computer is configured to further include the predetermined information, The information processing method according to claim 10.

12. The aforementioned predetermined information is generated based on transaction data relating to transactions between the first company and the second company. The information processing method according to claim 11.

13. In response to the computer receiving the application, Selecting one or more transaction data from among multiple transaction data relating to the transaction between the aforementioned first company and the aforementioned second company, To generate specified information from one or more selected transaction data, To further execute, The information processing method according to claim 12.

14. The multiple transaction data relating to the transaction between the first company and the second company are stored on the platform. Selecting one or more transaction data points as described above means The designation of the aforementioned multiple transaction data is accepted from the account of the first company, and Selecting one or more transaction data from the specified multiple transaction data, including, The information processing method according to claim 13.

15. The predetermined information is generated by adding a predetermined value to the transaction data and hashing or encrypting the transaction data to which the predetermined value has been added. The information processing method according to claim 12.

16. The predetermined information is a random number generated by the computer. The information processing method according to claim 10.