Management device, method for controlling management device, and program
Patent Information
- Application Number
- JP2024575159
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-20
- Publication Date
- 2026-03-26
- Estimated Expiration
- 2044-09-20
AI Technical Summary
Existing digital signature systems face challenges in ensuring the reliability of digital signatures due to the potential for tampering with information stored in ledger systems like blockchain.
A management device that utilizes a multi-registered ledger system to store digital certificate information, aggregates responses from multiple ledger systems, and determines a matching response based on calculated aggregated values, thereby reducing the likelihood of tampering and enhancing signature reliability.
The proposed solution effectively improves the reliability of digital signatures by reducing the possibility of tampering with digital certificate information and ensuring the authenticity of digital signatures.
Abstract
Description
[Technical field]
[0001] The present disclosure relates to a management device, a control method for the management device, and a program. [Background technology]
[0002] Conventionally, electronic signatures have been used to guarantee that data of electronic content such as electronic documents is authentic. For example, Patent Document 1 discloses an electronic signature management system for applying an electronic signature to data to be signed. In addition, for example, Patent Document 2 proposes a method of storing an electronically signed personal identification information hash value in a blockchain as an identity authentication method using a blockchain, which is a distributed ledger system. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2018-067807 A [Patent Document 2] JP 2024-077561 A Summary of the Invention [Problem to be solved by the invention]
[0004] It is possible to store certificates (electronic certificates) to certify matters related to electronic signatures in a ledger system such as a blockchain. However, since the information stored in the ledger system itself could be tampered with, there was a need to further improve the reliability of electronic signatures.
[0005] The present invention has been made in consideration of the above-mentioned conventional situation, and has an object to improve the reliability of electronic signatures. [Means for solving the problem]
[0006] A management device according to an embodiment of the present invention is a management device for managing electronic signatures for electronic content, and includes an acquisition unit that acquires signature instructions for the electronic content, a signature generation unit that generates an electronic signature in accordance with the instructions, an assignment unit that assigns the generated electronic signature to the electronic content, an electronic certificate generation unit that generates an electronic certificate related to the electronic signature, an electronic certificate information storage unit that executes processing to store electronic certificate information, which is information contained in the electronic certificate, in each of a plurality of ledger systems, an answer acquisition unit that acquires multiple answers that are outputs from each of the multiple ledger systems in response to the request by sending a request for electronic certificate information stored in each of the multiple ledger systems to each of the multiple ledger systems, an aggregate value calculation unit that calculates an aggregate value for each of the same answers included in the multiple answers by aggregating coefficients associated with the ledger system that output the answer, for each identical answer included in the multiple answers, a determination unit that determines one of the multiple answers as the answer that matches the electronic certificate information based on the aggregate value, and an output unit that outputs the one answer.
[0007] As a result, electronic certificate information, which is at least a part of the electronic certificate related to the electronic signature, is stored in each of the multiple ledger systems, and responses to the request for electronic certificate information are obtained from each of the multiple ledger systems, and for each identical response, an aggregate value is calculated by aggregating the coefficients associated with the ledger system that output the response, and based on the aggregate value, one of the multiple responses is determined to be the answer that matches the electronic certificate information, and this is output. This reduces the possibility of tampering with the electronic certificate information, making it possible to improve the reliability of the electronic signature. Effect of the Invention
[0008] According to the present invention, it is possible to improve the reliability of electronic signatures. [Brief description of the drawings]
[0009] [Figure 1]1 is a schematic diagram showing an overview of an electronic signature management system 100 using a management device 1 according to an embodiment. [Diagram 2] 1 is a schematic diagram showing an electronic document D to which a digital signature S generated by a management device 1 according to an embodiment has been affixed. [Diagram 3] 1 is a block diagram showing a configuration of a management device 1 according to an embodiment. [Figure 4] 4 is a schematic diagram illustrating an example of a data structure of an electronic certificate according to the embodiment. [Diagram 5] 2 is a schematic diagram illustrating an example of a data structure of a ledger system table according to the embodiment. FIG. [Figure 6] FIG. 2 is a block diagram showing a configuration of a user terminal 4 according to the embodiment. [Figure 7] FIG. 2 is a sequence diagram showing an example of operation processing such as generation of a digital signature and a digital certificate executed by the digital signature management system 100 according to the embodiment. [Figure 8] 11 is an operational flow diagram showing an example of a process of querying electronic certificate information, which is executed by the management device 1 according to the embodiment. FIG. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0010] A preferred embodiment of the present invention will be described with reference to the accompanying drawings. (Note that in each drawing, the same reference numerals denote the same or similar configurations.)
[0011] (1) Overview FIG. 1 is a schematic diagram showing an overview of an electronic signature management system 100 using a management device 1 according to an embodiment.
[0012] As shown in FIG. 1, the electronic signature management system 100 includes, for example, a management device 1, an electronic content database 2, multiple ledger systems 3, and multiple user terminals 4. In the example shown in FIG. 1, the ledger system 3 includes a first ledger system 3A, a second ledger system 3B, and a third ledger system 3C. Note that the ledger system 3 according to the embodiment is not limited to three, and may include two or four or more ledger systems 3. The management device 1 is connected to each of the electronic content database 2 and the ledger system 3 so as to be able to manage (store, delete, change, etc.) information. In addition, the management device 1 is connected to multiple user terminals 4 via a communication network N such as the Internet so as to be able to send and receive information to and from each other.
[0013] The management device 1 is, for example, a computer (information processing device) such as a server, and has a processing unit such as a CPU and a storage unit such as a memory. The management device 1 is a device that generates an electronic signature S for electronic content D such as a user's contract. The electronic content D is stored, for example, in an electronic content database 2. In other words, the management device 1 is a device that has a function of generating an electronic signature S to be attached to the user's electronic content D. The management device 1 may create electronic content D that indicates consent to the electronic content D, for example, by visibly attaching the electronic signature S to the electronic content D.
[0014] In the following embodiments, the term "electronic content" may include an "electronic document" or an "electronic image." The term "electronic document" refers to any document, such as a contract, estimate, application, purchase order, delivery note, invoice, receipt, waybill, minutes, request form, application, signature book, etc., and may include a document created electronically. The term "electronic image" may be a still image, or a video (image) consisting of a plurality of still images that are successive in time series. The video may be combined with audio. The term "electronic signature" may include a process of electronically performing the act of stamping a paper contract or the like on the electronic content D. The term "electronic certificate" may be a certificate for certifying matters related to an electronic signature, and may include, for example, an electromagnetic record created to certify that matters used to confirm that a user has made an electronic signature relate to the user.
[0015] FIG. 2 is a schematic diagram showing an electronic document D to which a digital signature S generated by a management device 1 according to an embodiment is affixed. In particular, the management device 1 may affix a visible digital signature S to the electronic document D as shown in FIG. 2. The management device 1 may, for example, visibly affix a digital signature S corresponding to an individual user. The management device 1 may, for example, affix a digital signature S shown as a QR code (registered trademark) to electronic content D. When the management device 1 affixes a digital signature S to an electronic image as electronic content, the management device 1 may superimpose the digital signature S on a part of at least one of the still images included in the electronic image, or may affix the digital signature S to metadata held by the electronic image.
[0016] As shown in FIG. 1, the management device 1 is connected to ledger systems 3 (first ledger system 3A, second ledger system 3B, and third ledger system 3C). The management device 1 creates an electronic certificate for electronic content D to which an electronic signature S has been added. The management device 1 stores at least a part (electronic certificate information) of the created electronic certificate for electronic content D in each of the first ledger system 3A, the second ledger system 3B, and the third ledger system 3C. Each ledger system 3 may be a distributed ledger system. The ledger system 3 may be configured to include, for example, a plurality of node computers (nodes) that store a blockchain. The format of the blockchain is not particularly limited, and may be configured as, for example, any of a public type, a consortium type, and a private type private blockchain. The management device 1 stores, for example, an electronic certificate in the first ledger system 3A, the second ledger system 3B, and the third ledger system 3C that are configured as the blockchain or the like.
[0017] The management device 1 executes a process (inquiry process) of inquiring about desired electronic certificate information from a plurality of ledger systems 3 included in the electronic signature management system 100 at a predetermined timing. The management device 1 requests electronic certificate information stored in each of the plurality of ledger systems 3 from each of the plurality of ledger systems 3, and acquires a response from each ledger system 3 in response to the request. Here, if electronic certificate information is tampered with in at least one of the ledger systems 3, the plurality of responses acquired from the plurality of ledger systems 3 may include a plurality of different responses. However, in the management device 1 according to the embodiment, since electronic certificate information is managed by the plurality of ledger systems 3, it is possible to guarantee genuine electronic certificate information. That is, the management device 1 calculates a tally value of each of the same answers included in the plurality of answers by tallying up the coefficients associated with the ledger system that output the answer for each identical answer included in the answers acquired from each ledger system 3. The management device 1 determines one answer out of the plurality of answers as an answer that matches the electronic certificate information based on the tally value, and outputs the one answer. In this way, in the electronic signature management system 100 according to the embodiment, electronic certificate information is stored in multiple ledger systems 3, and at a predetermined timing, the management device 1 determines and outputs genuine electronic certificate information by performing a process of querying the multiple ledger systems 3 for electronic certificate information. This reduces the possibility of tampering with the electronic certificate information, thereby improving the reliability of electronic signatures.
[0018] As shown in FIG. 1, the user terminal 4 is configured as, for example, a device different from the management device 1. The user terminal 4 is, for example, a computer (information processing device) such as a smartphone, tablet terminal, or personal computer having an imaging function, and has a processing unit such as a CPU and a storage unit such as a memory. The user terminal 4 acquires information contained in the electronic certificate held in the ledger system 3 via the management device 1 based on the electronic signature S generated by the management device 1, and executes a process for confirming the authenticity of the electronic content D based on the acquired information. In addition, the user terminal 4 executes a display process for various information based on the information contained in the acquired electronic certificate. In particular, the user terminal 4 displays a URL for identifying a storage area in the electronic content database 2 in which the electronic content D is stored. When the user selects the URL, the user terminal 4 acquires the electronic content D from the electronic content database 2 and displays it. This makes it possible to confirm the contents of the electronic content D in an environment in which the authenticity of the electronic content D is guaranteed. Furthermore, since the contents of electronic content D can be confirmed from electronic signature S, a user can maintain evidential force (backed up by the information on the electronic certificate) by storing a paper printout of electronic content D rather than a file of electronic content D.
[0019] (2) Composition (2-1) Management device 1 3 is a block diagram showing the configuration of a management device 1 according to an embodiment. The management device 1 includes a document management unit 11, an instruction acquisition unit 12, a user information acquisition unit 13, a signature generation unit 14, an assignment unit 15, a digital certificate generation unit 16, a digital certificate information storage unit 17, a response acquisition unit 18, a tally calculation unit 19, a determination unit 20, and a transmission / reception unit 21. These various functional units are realized by the operation of a processing unit such as a CPU included in the management device 1.
[0020] The document management unit 11 is realized, for example, by the operation of a CPU. The document management unit 11 executes the creation, acquisition, modification, storage in a memory unit, etc. of electronic content D that is the subject of an electronic signature. The document management unit 11 acquires electronic content D, for example, from the electronic content database 2 or the user terminal 4. The electronic content D may be electronic data created by word processing software or image creation software, or may be data obtained by scanning a printed matter such as paper. The document management unit 11 may also create and modify electronic content based on instructions acquired from the user terminal 4. The document management unit 11 may also store electronic content in the electronic content database 2.
[0021] The instruction acquisition unit 12 acquires an instruction (signature instruction) for signing the acquired electronic content to be signed. The instruction acquisition unit 12 acquires the signature instruction from the user terminal 4, for example.
[0022] The user information acquisition unit 13 acquires user information as user information. In addition, in an embodiment, the user information acquisition unit 13 acquires a user ID and a user name issued in advance to the user. Here, the user information acquisition unit 13 acquires user IDs and user names between contracting parties (users) as user information. In addition, in an embodiment, the user information acquisition unit 13 acquires user information from the user terminal 4, etc., when generating the electronic signature S. The user information may include any information specific to the user that is managed by the user.
[0023] The signature generation unit 14 generates a digital signature in which a digital certificate identifier, which is an identifier of a digital certificate, is coded. The signature generation unit 14 may include a unique character string in the digital certificate identifier. The character string may be unique for each digital signature S, for example. The digital certificate identifier is generated (numbered) by, for example, adding the digital signature S to the digital content D.
[0024] The adding unit 15 adds the generated electronic signature S to the electronic content D. For example, the adding unit 15 may add the electronic signature S to the electronic content D in a visibly recognizable manner. This makes it easy to identify that the electronic signature S has been added to the electronic content D. For example, as shown in FIG. 2, the adding unit 15 may add the generated electronic signature S to a position where it is displayed next to the corporate name and the representative name, which are user information described in the electronic content D. For example, the adding unit 15 may add the electronic signature S to a position in the electronic content D where it is clear that the electronic signature S corresponds to the described user information. In the embodiment, the adding unit 15 may write the name of the user included in the acquired user information together with the electronic signature S. For example, as shown in FIG. 2, the adding unit 15 writes the user name together with the corresponding user's electronic signature S (QR code) below the display surface of the electronic content D (electronic document). This makes it clear which user's electronic signature S belongs to the coded electronic signature S. Furthermore, by adding the code to the coded electronic signature S, the code can be treated like a seal impression, creating a visual effect similar to that of a seal imprinted on paper.
[0025] The digital certificate generating unit 16 generates various digital certificates related to the digital signature S. The digital certificates are stored in the ledger system 3, for example.
[0026] Fig. 4 is a schematic diagram showing an example of the data structure of a digital certificate according to an embodiment. Each row shown in Fig. 4 corresponds to one digital certificate. For example, each time a digital signature is applied to digital content, a digital certificate is added to the ledger system 3 one by one.
[0027] The electronic certificate may include, for example, the issuer name, issue number, issue date and time, expiration date, series ID, branch number, user ID, organization to which the user belongs, user position, user name, signature content, original text hash value, pre-signature hash value, post-signature hash value, URL for publishing electronic content, and password.
[0028] The issuer name is the name of the issuer of the electronic certificate, and may be, for example, the name of the administrator of the management device 1. The issue number is an electronic certificate identifier (an identifier for identifying an electronic certificate) issued by the management device 1. The issue date and time is the date and time when the electronic certificate was issued, and may be time information of the signature. The issue date and time is an example of ranking information indicating the ranking of an electronic signature (information indicating, each time an electronic signature is granted, the ranking of that electronic signature among a series of electronic signatures). The validity expiration date is the date on which the validity period of the electronic certificate expires.
[0029] The series ID is an example of lineage identification information, which is identification information for identifying the lineage of electronic content D. The series ID may be unique identification information for electronic content D (its lineage) that does not change even if one or more digital signatures S are assigned to the electronic content D. In other words, the series ID is identification information given to the content (which may include modified content) represented by the electronic content D. This makes it possible, when digital signatures S are assigned consecutively to electronic content D, to manage the electronic content D and the series of digital signatures S as a series, to confirm which digital signature S among the series of digital signatures S is the latest, and to confirm whether the digital signature S assigned to the electronic content D in one's possession is the latest, etc.
[0030] The branch number is an example of ranking information indicating the ranking of the electronic signature S (information indicating, each time an electronic signature S is added, the ranking of the electronic signature S among a series of electronic signatures S). In the example shown in Fig. 4, natural numbers such as 1, 2, and 3 are used as the branch numbers, but the branch numbers (ranking information) may be arbitrarily configured using symbols, signs, etc., as long as they can indicate the ranking.
[0031] The user ID is identification information of the user. The user organization is information indicating the organization to which the user belongs. The user job title is information indicating the job title of the user in the organization. The user name is the name of the user (the name of the person in charge at each company).
[0032] The signature content is information accompanying the electronic signature S, and may be text-format data arbitrarily entered by the user. The signature content may be, for example, a statement of the user's intention accompanying the electronic signature, or, if the electronic content to be signed has been modified, information indicating that a modification has been made and information indicating the details of the modification. This makes it possible to confirm the user's intention regarding the electronic signature, the presence or absence of modifications to the electronic content, and the details of the modifications, by checking the electronic certificate.
[0033] The original hash value, pre-signature hash value, and post-signature hash value are used, for example, in a process of checking the integrity of electronic content D. The integrity checking process will be described later. The original hash value is the hash value of electronic content D (original) that does not include any electronic signatures. The pre-signature hash value is the hash value of electronic content D immediately before the latest electronic signature S is added (electronic content D that includes an electronic signature S that is ranked earlier than the electronic signature S). The post-signature hash value is the hash value of electronic content D to which the latest electronic signature S has been added.
[0034] The electronic content publication URL may be a URL for identifying a storage area in which the electronic content D is saved (for example, the URL of the electronic content D in the electronic content database 2). An expiration date may be set for the electronic content publication URL. The password may be a password required to access the file publication URL and view the electronic content D, and may be arbitrary or may be assigned by the system.
[0035] It should be noted that the above-mentioned electronic certificates are merely examples, and the electronic certificate in the embodiment may not include any of the items described above, or may include items other than the items described above.
[0036] The electronic certificate information storage unit 17 stores at least a part of the generated electronic certificate (electronic certificate information) in the ledger system 3 (the first ledger system 3A, the second ledger system 3B, and the third ledger system 3C). The electronic certificate information, which is at least a part of the electronic certificate information, may include, for example, at least a part of the information shown in FIG.
[0037] The answer acquisition unit 18 acquires electronic certificate information stored in each ledger system 3 from each ledger system 3. Specifically, the answer acquisition unit 18 transmits, for example, a request for electronic certificate information stored in each ledger system 3 to each ledger system 3. When the ledger system 3 receives a request for electronic certificate information from the management device 1, it outputs electronic certificate information stored in the ledger system 3 in response to the request, and transmits the output electronic certificate information to the management device 1 as a response to the request. The answer acquisition unit 18 acquires the response from each ledger system 3. The timing at which the answer acquisition unit 18 executes the answer acquisition process may be any timing, and may be, for example, when a request for an inquiry about electronic certificate information is received from a user terminal 4 or the like, or when a new electronic signature is generated for an electronic document.
[0038] The tally calculation unit 19 calculates an tally value for each identical answer included in the multiple answers acquired by the answer acquisition unit 18 from the multiple ledger systems 3 by tallying up the coefficients associated with the ledger system 3 that output the answer. That is, the tally value may be the sum of the coefficients of at least one ledger system 3 that output the same answer. The tally value is a value calculated in association with the answer of the electronic certificate information, and can be considered a score for selecting genuine electronic certificate information that has not been tampered with.
[0039] The determination unit 20 determines one of the multiple answers acquired from each ledger system 3 as an answer that matches the electronic certificate information, for example, based on the aggregated value calculated by the aggregated value calculation unit 19. The determination unit 20 may determine, for example, the answer with the highest aggregated value among the answers acquired from the multiple ledger systems 3 as the answer that matches the electronic certificate information.
[0040] The transmitting / receiving unit 21 transmits and receives various information to and from the user terminal 4. For example, the transmitting / receiving unit 21 receives a signature instruction for electronic content D from the user terminal 4. The transmitting / receiving unit 21 also transmits, for example, electronic content D (including that to which a digital signature S has been added) to the user terminal 4. The transmitting / receiving unit 21 is also an example of an output unit, and outputs an answer determined by the determining unit 20 as an answer that matches the digital certificate information. Here, the process of outputting the answer may be, for example, a process of transmitting the answer to another external device such as the user terminal 4, or a process of displaying the answer on an arbitrary display device.
[0041] Each of the components included in the management device 1 can be realized by hardware, software, or a combination of these. Here, being realized by software means being realized by a computer reading and executing a program. The program can be stored and provided to a computer using various types of non-transitory computer readable media. The non-transitory computer readable media includes various types of tangible storage media. Examples of the non-transitory computer readable media include magnetic recording media (e.g., flexible disks, magnetic tapes, hard disk drives), magneto-optical recording media (e.g., magneto-optical disks), CD-ROMs (Read Only Memory), CD-Rs, CD-R / Ws, and semiconductor memories (e.g., mask ROMs, PROMs (Programmable ROMs), EPROMs (Erasable PROMs), flash ROMs, and RAMs (random access memories)). The display program may also be provided to a computer by various types of transitory computer readable media. Examples of the transitory computer readable media include electrical signals, optical signals, and electromagnetic waves. The temporary computer-readable medium can supply the program to the computer via a wired communication path such as an electric wire or an optical fiber, or via a wireless communication path.
[0042] Fig. 5 is a schematic diagram showing an example of a data structure of a ledger system table according to an embodiment. The ledger system table may be stored in a storage unit accessible by the management device 1, such as a storage unit included in the management device 1. The ledger system table may include information on each ledger system 3 included in the electronic signature management system 100. In the example shown in Fig. 5, the ledger system table includes, for each ledger system 3, coefficients and characteristic information of the ledger system 3.
[0043] The coefficient is a numerical value associated with each ledger system 3, and serves as a basis for calculating an aggregate value, for example, during a process of querying electronic certificate information. In other words, the coefficient may be a numerical value indicating the possibility or likelihood that information stored as electronic certificate information in the ledger system 3 matches genuine electronic certificate information.
[0044] The ledger system table may include characteristic information indicating the characteristics of each ledger system 3. The characteristic information may be, for example, information indicating the type of the ledger system 3. The type of the ledger system 3 may be, for example, whether it is distributed or non-distributed, or the type (public, consortium, private, etc.) if it is distributed. The characteristic information may also include, for example, an algorithm type. The algorithm type is information indicating the type of algorithm (consensus algorithm, etc.) used by the ledger system 3 to store information. Specifically, the algorithm type may include blockchain, Ethereum, and other algorithms. The characteristic information may also include, for example, the number of nodes. The number of nodes may be the number of nodes constituting the ledger system 3. Note that the characteristic information shown in FIG. 5 is merely an example, and the ledger system table may include any characteristic information indicating the characteristics of the ledger system 3.
[0045] The management device 1 may calculate and update the coefficient based on the characteristic information indicating the characteristics of each ledger system 3. The management device 1 may calculate the coefficient so that the coefficients of all ledger systems 3 are equal. In this case, one answer is determined as an answer that matches the electronic certificate information by a majority vote of the multiple ledger systems 3. Alternatively, the management device 1 may calculate the coefficient so that, for example, the coefficient of the ledger system 3 increases as the characteristic information of the ledger system 3 is less likely to be tampered with. Specifically, for example, the coefficient may be increased when the ledger system 3 is distributed rather than non-distributed. Also, for example, the coefficient may increase in the order of the type of the distributed ledger system 3, from public type to consortium type to private type. Also, the coefficient may increase as the number of nodes in the ledger system 3 increases.
[0046] (2-2) User terminal 4 6 is a block diagram showing the configuration of a user terminal 4 according to an embodiment. The user terminal 4 includes an imaging unit 41, an identifier acquisition unit 42, a retained information acquisition unit 43, a hash value calculation unit 43, a consistency check unit 44, an output unit 45, and an operation reception unit 46. These various functional units are realized by the operation of a processing unit such as a CPU included in the user terminal 4.
[0047] The imaging unit 41 is an imaging mechanism including a so-called camera. The imaging unit 41 captures, for example, an arbitrary electronic signature S attached to electronic content D. The imaging unit 41 captures, for example, an arbitrary electronic signature S included in electronic content D displayed on a display unit (not shown) of another terminal.
[0048] The identifier acquisition unit 42 acquires the electronic certificate identifier included in the captured electronic signature S by capturing an image of the electronic signature S (QR code).
[0049] The hash value calculation unit 43 calculates various hash values based on the electronic content D. For example, the hash value calculation unit 43 may calculate a hash value (post-signature hash value) of the electronic content D including the latest digital signature S. The hash value calculation unit 43 may also calculate a hash value (pre-signature hash value) of the electronic content D that does not include only the latest digital signature S. The hash value calculation unit 43 may also calculate a hash (original text hash value) of the electronic content D as the original text that does not include any digital signature S.
[0050] The consistency checking unit 44 obtains the electronic certificate stored in the ledger system 3 via the management device 1, and performs a process of checking the consistency of the electronic content D based on the electronic certificate. The process of checking the consistency of the electronic content D makes it possible to determine whether the electronic content D is authentic. For example, the consistency checking unit 44 obtains an electronic certificate from the management device 1 based on an electronic certificate identifier obtained by imaging any one of the electronic signatures S included in the electronic content D, and checks the consistency between the hash value (original hash value, pre-signature hash value, and / or post-signature hash value) included in the obtained electronic certificate and the hash value (original hash value, pre-signature hash value, and / or post-signature hash value) calculated from the electronic content D by the hash value calculation unit 43. The consistency checking unit 44 may determine whether the electronic content D as the original has not been altered, for example, by determining whether the original hash value obtained from the target electronic content D matches the original hash value included in the electronic certificate. Also, the consistency check unit 44 may determine whether the electronic content D has not been altered during the period from when the previous electronic signature S was made to when the latest electronic signature S was made, for example, by determining whether a pre-signature hash value (a hash value calculated based on electronic content obtained excluding only the latest electronic signature) obtained from the target electronic content D matches a post-signature hash value included in the immediately previous electronic certificate. A specific operation example is as follows. That is, a user can access the electronic content D (original) stored in the management device 1 (electronic content database 2, etc.) by, for example, capturing an image of the electronic signature S of the electronic content D printed on paper (handed over, delivered, etc.) with the user terminal 4, and display the electronic content D on the user terminal 4. The management device 1 may calculate a hash value for the accessed electronic content D, and inquire of the ledger system 3 about the hash values (original hash value, pre-signature hash value, and post-signature hash value) to determine whether the electronic content D is authentic.With regard to the personally delivered electronic content D, the user can confirm whether the electronic content D is authentic, for example, by visually comparing the personally delivered electronic content D with the electronic content D stored in the management device 1 displayed on the user terminal 4. In addition, whether the electronic content D stored in the management device 1 is authentic may be determined, for example, by querying the ledger system 3.
[0051] The output unit 45 outputs various types of information related to the electronic content D. For example, the output unit 45 outputs information on various types of electronic certificates acquired from the management device 1. In addition, for example, the output unit 45 outputs the result of the consistency check performed by the consistency check unit 44.
[0052] The operation accepting unit 46 accepts various operations by the user. For example, the operation accepting unit 46 accepts a selection to perform a process of checking the consistency of the electronic content D. In addition, the operation accepting unit 46 accepts, for example, transitions of various screens that display information about the electronic content D, selection of links, and the like.
[0053] The transmitting / receiving unit 47 transmits and receives various information between the management device 1 and other user terminals 4. For example, the transmitting / receiving unit 47 transmits a signature instruction for electronic content to the management device 1. In addition, the transmitting / receiving unit 47 receives, for example, electronic content D (including that to which a digital signature S has been added) and a digital certificate from the management device 1.
[0054] (3) Example of operation (3-1) Creation of digital signatures and digital certificates FIG. 7 is a sequence diagram showing an example of operation processing such as generation of an electronic signature and an electronic certificate executed by the electronic signature management system 100 according to the embodiment. In the following, an example will be described in which an order-receiving company, which is an example of a user, places an order for a product or service provided by the receiving company to an order-receiving company, which is another example of a user. The user terminal 4 used by the receiving company is assumed to be user terminal 4A, and the user terminal 4 used by the ordering company is assumed to be user terminal 4B. In this case, it is assumed that a person in charge at the receiving company has created an electronic document D0 as an invoice for the ordering company of the product or service. The electronic document D0 may be created by the user terminal 4A using an electronic document creation service provided by the management device 1, or may be created by using general document creation software or the like without using such a creation service. The created electronic document D0 may be stored in the electronic document database 2 by the management device 1, or may be stored in a storage unit accessible by the user terminal 4A. Note that this sequence diagram illustrates an example in which the electronic signature management system 100 according to the embodiment handles electronic documents as electronic content, but is applicable not only to electronic documents but also to other electronic content such as electronic images.
[0055] When a user terminal 4A used by a person in charge of an order receiving company accepts an operation of a signature instruction for electronic document D0 from the person in charge of the order receiving company, the user terminal 4A transmits the signature instruction for electronic document D0 to management device 1 (S101). Management device 1 receives the signature instruction for electronic document D0 from user terminal 4A (S102).
[0056] The signature instructions for electronic document D0 may include, for example, the data of electronic document D0 itself, or may include information (such as a series ID) for identifying electronic document D0 stored in electronic document database 2 or a storage unit accessible to user terminal 4A. The signature instructions may also include, for example, any item recorded in ledger system 3 (such as an item related to the person in charge of the order-receiving company). The signature instructions may also include, for example, the signature content entered by the person in charge of the order-receiving company. In the example shown in FIG. 4, the signature content "make a claim" entered by the person in charge of the order-receiving company is shown.
[0057] The management device 1 generates an electronic signature S1 by the person in charge of the receiving company based on the signature instruction, and also generates an electronic certificate (S103). Regarding the generation of the electronic certificate, the management device 1 generates a hash value of the electronic document D0 immediately before the electronic signature S1 is added, and includes this in the electronic certificate as a pre-signature hash value. The management device 1 also generates a hash value of the electronic document D1 after the electronic signature S1 is added, and includes this in the electronic certificate as a post-signature hash value. The management device 1 also generates a hash value of the electronic document D0 that does not include any electronic signature S, and includes this in the electronic certificate as an original text hash value. The management device 1 stores at least a part of the generated electronic certificate (for example, the electronic certificate in the first row shown in FIG. 4) in the first ledger system 3A, the second ledger system 3B, and the third ledger system 3C (S104).
[0058] The management device 1 generates an electronic document D1 by adding the generated digital signature S1 to the electronic document D0. The management device 1 then transmits the generated electronic document D1 to the user terminal 4A (S105). The user terminal 4A may store the received electronic document D1 in a storage unit accessible by the user terminal 4A.
[0059] In response to an operation by a person in charge of the receiving company, the user terminal 4A transmits the electronic document D1 to the user terminal 4B used by the person in charge of the ordering company (S106). Note that the transmission of the electronic document D1 to the user terminal 4B may be performed via the management device 1. The user terminal 4B receives the electronic document D1 (S107). The user terminal 4B may store the received electronic document D1 in a storage unit accessible by the user terminal 4B.
[0060] The person in charge of the ordering company appropriately checks the contents of the received electronic document D1 (the contents of the invoice), and then performs an operation to instruct the person in charge of the ordering company to sign electronic document D1. When user terminal 4B accepts this operation, it transmits an instruction to sign electronic document D1 to management device 1 (S108). Management device 1 receives the instruction to sign electronic document D1 from user terminal 4B (S109).
[0061] The signature instructions for electronic document D1 may include, for example, the data of electronic document D1 itself, or may include information (such as a series ID) for identifying electronic document D1 stored in electronic document database 2 or a storage unit accessible to user terminal 4B. The signature instructions may also include, for example, any item recorded in ledger system 3 (such as items related to the person in charge of the ordering company). The signature instructions may also include, for example, the signature content entered by the person in charge of the ordering company. In the example shown in FIG. 4, the signature content entered by the person in charge of the ordering company, "I will pay as invoiced," is shown.
[0062] The management device 1 generates an electronic signature S2 by the person in charge of the ordering company based on the signature instruction, and also generates an electronic certificate (S110). Regarding the generation of the electronic certificate, the management device 1 generates a hash value of the electronic document D1 immediately before the electronic signature S2 is added, and includes this in the electronic certificate as a pre-signature hash value. The management device 1 also generates a hash value of the electronic document D2 after the electronic signature S2 is added, and includes this in the electronic certificate as a post-signature hash value. The management device 1 also generates a hash value of the electronic document D0 that does not include any electronic signature S, and includes this in the electronic certificate as an original text hash value. The management device 1 stores at least a part of the generated electronic certificate (for example, the electronic certificate in the second row shown in FIG. 4) in the first ledger system 3A, the second ledger system 3B, and the third ledger system 3C (S111).
[0063] The management device 1 may determine whether the contents of the electronic document D1 have been altered. That is, the management device 1 may determine whether the contents of the electronic document D1 to which the electronic signature S2 is to be added have been altered from the contents of the electronic document D1 immediately after the previous electronic signature S1 was added. For example, the management device 1 queries the ledger system 3 for the post-signature hash value of the electronic certificate in the first line shown in FIG. 4 and the pre-signature hash value of the electronic certificate in the second line, and compares them. If the two values match, the management device 1 determines that the electronic document D1 has not been altered, and if the two values do not match, the management device 1 determines that the electronic document D1 has been altered. The management device 1 may output the determination result by transmitting it to the user terminal 4B, etc. This allows the person in charge at the ordering company to check the continuity of the contents of the electronic document D1 to be the target when applying the electronic signature S2.
[0064] The management device 1 generates an electronic document D2 by adding the generated digital signature S2 to the electronic document D1. The management device 1 then transmits the generated electronic document D2 to the user terminal 4B (S112). The user terminal 4B may store the received electronic document D2 in a storage unit accessible by the user terminal 4B.
[0065] In response to an operation by a person in charge of the ordering company, user terminal 4B transmits electronic document D2 to user terminal 4A used by a person in charge of the order-receiving company (S113). Note that transmission of electronic document D2 to user terminal 4A may be performed via management device 1. User terminal 4A receives electronic document D2 (S114). Note that a notification of payment acceptance may be transmitted from user terminal 4B to user terminal 4A, with or without the intervention of management device 1. User terminal 4A may store the received electronic document D2 in a storage unit accessible to user terminal 4A.
[0066] (3-2) Checking electronic certificate information 8 is an operational flow diagram showing an example of an electronic certificate information inquiry process executed by the management device 1 according to the embodiment. The electronic certificate information inquiry process is a process for inquiring about desired electronic certificate information from a plurality of ledger systems 3 included in the electronic signature management system 100. The electronic certificate information inquiry process may be executed at any timing, for example, when a request for an inquiry about electronic certificate information is received from a user terminal 4 or the like, or when a new electronic signature is generated for an electronic document (for example, at the timing of step S110 described above, etc.).
[0067] The answer acquiring unit 18, for example, transmits a request for electronic certificate information stored in each ledger system 3 to each ledger system 3, and acquires from each ledger system 3 the electronic certificate information output by each ledger system 3 as a response to the request (S201). The answer acquiring unit 18 may execute this process in response to a request from the user terminal 4 to inquire about electronic certificate information.
[0068] The aggregate value calculation unit 19 calculates an aggregate value for each of the same answers included in the multiple answers acquired by the answer acquisition unit 18 from the multiple ledger systems 3 by aggregating the coefficients associated with the ledger system 3 that output the answer (S202).
[0069] The determination unit 20 determines, for example, one answer out of the multiple answers acquired from each ledger system 3 based on the tally calculated by the tally calculation unit 19 as the answer that matches the electronic certificate information (S203).
[0070] Here, we will explain a specific example of a method for determining one answer as an answer that matches the electronic certificate information by calculating an aggregate value, using an electronic signature management system 100 having three ledger systems 3: a first ledger system 3A, a second ledger system 3B, and a third ledger system 3C.
[0071] [Table 1]
[0072] For example, as shown in Table 1, assume that in response to a request for specific electronic certificate information, the response from the first ledger system 3A is "123", the response from the second ledger system 3B is "123", and the response from the third ledger system 3C is "456". Assume that the coefficients of the first ledger system 3A, the second ledger system 3B, and the third ledger system 3C are all "1".
[0073] In this case, the tally calculation unit 19 calculates the tally of the answer "123" as "2", which is the sum of the coefficients of the ledger systems 3 that output the answer, i.e., the sum of the coefficient "1" of the first ledger system 3A and the coefficient "1" of the second ledger system 3B. In addition, in this case, the tally calculation unit 19 calculates the tally of the answer "456" as "1", which is the sum of the coefficients of the ledger systems 3 that output the answer, i.e., the sum of the coefficient "1" of the third ledger system 3C. Then, the determination unit 20 determines that the answer "123" is the answer that matches the electronic certificate information, since the tally value "2" of the answer "123" is the highest among the tally values of all the answers (answer "123" and answer "456").
[0074] In addition, when the coefficients of all the ledger systems 3 are equal, such as when the coefficients of the first ledger system 3A, the second ledger system 3B, and the third ledger system 3C are all "1", one answer is essentially determined as the answer that matches the electronic certificate information by majority vote of the multiple ledger systems 3. Furthermore, when the number of ledger systems 3 possessed by the electronic signature management system 100 according to the embodiment is odd, the number of answers with the highest aggregate value is narrowed down to one in principle, making it possible to efficiently determine the answer that matches the electronic certificate information.
[0075] [Table 2]
[0076] Also, for example, assume that in response to a request for specific electronic certificate information, the response from the first ledger system 3A is "123", the response from the second ledger system 3B is "123", and the response from the third ledger system 3C is "456", as shown in Table 2. Assume that the coefficient of the first ledger system 3A is "1", the coefficient of the second ledger system 3B is "1.5", and the coefficient of the third ledger system 3C is "3".
[0077] In this case, the tally calculation unit 19 calculates the tally of the answer "123" as "2.5", which is the sum of the coefficients of the ledger systems 3 that output the answer, i.e., the sum of the coefficient "1" of the first ledger system 3A and the coefficient "1.5" of the second ledger system 3B. In addition, in this case, the tally calculation unit 19 calculates the tally of the answer "456" as "3", which is the sum of the coefficients of the ledger systems 3 that output the answer, i.e., the sum of the coefficient "3" of the third ledger system 3C. Then, the determination unit 20 determines that the answer "456" is the answer that matches the electronic certificate information, since the tally value "3" of the answer "456" is the highest among the tally values of all the answers (answer "123" and answer "456").
[0078] The transmitting / receiving unit 21 transmits the answer determined by the determining unit 20 as the answer that matches the electronic certificate information to the user terminal 4 (S204).
[0079] (4) Additional Notes In the above-described embodiment, the process of determining whether or not the electronic document (electronic content) has been altered is performed at the timing of generating an electronic signature in response to a signature instruction (steps S110, S206, S214, and S307). However, the process of determining whether or not the electronic document (electronic content) has been altered is not limited to these timings, and may be performed, for example, at any timing when the user requests the management device 1 to make a determination via the user terminal 4. In this case, the user terminal 4 may, for example, receive information on the electronic signature designated by the user as the target of the determination process, and transmit the information to the management device 1 together with the request for determination. The management device 1 may compare the pre-signature hash value of the designated electronic signature with the post-signature hash value of the electronic signature immediately preceding the designated electronic signature, and if the two values match, determine that the electronic document (electronic content) has not been altered at the time of the designated electronic signature, and if the two values do not match, determine that the electronic document (electronic content) has been altered at the time of the designated electronic signature.
[0080] The above-described electronic signature management system 100 can also be applied to a case where an arbitrary user modifies the contents of a contract after the contract is concluded. That is, for example, when the user needs to modify the contents (delivery date, amount, etc.) of a concluded contract, the user performs an operation to acquire the target electronic document on the user terminal 4. As a result, the user terminal 4 acquires the target electronic document from the electronic document database 2 via the management device 1. Next, the user terminal 4 appropriately modifies the electronic document in response to the user's operation. Then, the user terminal 4 transmits a signature instruction for the modified electronic document (modified electronic document) to the management device 1 in response to the user's operation. The management device 1 generates an electronic signature for the modified electronic document and assigns it to the modified electronic document.
[0081] The amended electronic document to which the electronic signature has been added may be transmitted from the management device 1 to a user terminal 4 used by another user (such as the other party to a contract). The other user then confirms the contents of the amended electronic document displayed on the user terminal 4 and performs an operation of adding an electronic signature to the amended electronic document on the user terminal 4. The user terminal 4 transmits a signature instruction to the management device 1, which generates an electronic signature of the other user and further adds it to the amended electronic document (to which the electronic signature of the user has been added). This makes it possible to amend the contract contents on the same electronic document file without exchanging an amendment memorandum, for example. In the conventional electronic signature, the content of the electronic document or the hash value based thereon may change, making the original electronic signature invalid. On the other hand, in the electronic signature management system 100 according to the embodiment, even if the hash value of the electronic document changes due to the electronic signature, it is possible to confirm a series of electronic signatures that are associated with each other by a series ID (series identification information), so that amendments to the contract contents can be easily managed.
[0082] The above-mentioned digital signature management system 100 is capable of verifying a series of digital signatures associated with each other by a series ID (series identification information) even if the hash value of the digital content changes due to the digital signature, and is therefore applicable to any digital content to which digital signatures are expected to be continuously affixed, not limited to contracts. For example, the digital signature management system 100 is also applicable to cases where multiple signers sequentially affix digital signatures to an electronic document on a signature book in a signature campaign in a political activity, etc. [Explanation of symbols]
[0083] 1... management device, 2... electronic content database, 3, 3A, 3B, 3C... ledger system, 4, 4A, 4B, 4C, 4D... user terminal, 11... document management unit, 12... instruction acquisition unit, 13... user information acquisition unit, 14... signature generation unit, 15... assignment unit, 16... electronic certificate generation unit, 17... electronic certificate information storage unit, 18... answer acquisition unit, 19... aggregate value calculation unit, 20... determination unit, 21... transmission / reception unit, 41... imaging unit, 42... identifier acquisition unit, 43... hash value calculation unit, 44... consistency verification unit, 45... output unit, 46... operation reception unit, 47... transmission / reception unit, 100... electronic signature management system, N... communication network, S... electronic signature, D... electronic content, D0, D1, D2... electronic document
Claims
1. A management device for managing digital signatures for digital content, comprising: an acquisition unit that acquires a signature instruction for electronic content; a signature generation unit that generates an electronic signature in response to the instruction; an adding unit that adds the generated digital signature to the digital content; a digital certificate generating unit for generating a digital certificate related to the digital signature; an electronic certificate information storage unit that executes a process for storing electronic certificate information, which is at least a part of the electronic certificate, in each of the plurality of ledger systems; a response acquisition unit that transmits a request for the electronic certificate information stored in each of the plurality of ledger systems to each of the plurality of ledger systems, and acquires a plurality of responses that are outputs from each of the plurality of ledger systems in response to the request; an aggregate value calculation unit that calculates an aggregate value of each of the same answers included in the plurality of answers by aggregating coefficients associated with the ledger system that output the answer, for each of the same answers included in the plurality of answers; a determination unit that determines one of the plurality of answers as an answer that matches the electronic certificate information based on the aggregated value; an output unit that outputs the one answer; A management device comprising:
2. The management device according to claim 1 , wherein the determination unit determines the answer with the highest count value as the one answer.
3. The management device according to claim 1 , wherein at least one of the plurality of ledger systems is a distributed ledger system.
4. The management device according to claim 1 , wherein the coefficient is determined based on characteristic information indicating characteristics of the ledger system.
5. The management device according to claim 4 , wherein the characteristic information is determined based on at least one of an algorithm used by the ledger system to store data and a number of nodes included in the ledger system.
6. The management device according to claim 1 , wherein the coefficients associated with each of the plurality of ledger systems are equal to each other.
7. The management device according to claim 6 , wherein the number of the plurality of ledger systems is an odd number.
8. The management device according to claim 1 , wherein the electronic content is an electronic document.
9. The management device according to claim 1 , wherein the electronic certificate information is a hash value generated based on the electronic content.
10. 1. A control method executed by a management device for managing digital signatures for digital content, comprising: obtaining a signature instruction for the electronic content; generating an electronic signature in response to said instructions; adding the generated digital signature to the digital content; generating a digital certificate for said digital signature; A step of executing a process for storing electronic certificate information, which is at least a part of the electronic certificate, in each of a plurality of ledger systems; transmitting a request for the electronic certificate information stored in each of the plurality of ledger systems to each of the plurality of ledger systems, thereby obtaining a plurality of responses that are outputs from each of the plurality of ledger systems in response to the request; a step of calculating an aggregate value of each of the same answers included in the plurality of answers by aggregating coefficients associated with the ledger system that output the answer for each of the same answers included in the plurality of answers; determining, based on the aggregated value, one answer of the plurality of answers as an answer that matches the electronic certificate information; outputting said one answer; A control method comprising:
11. A program for causing an information processing device to function as a management device for managing digital signatures for digital content, the management device comprising: an acquisition unit that acquires a signature instruction for electronic content; a signature generation unit that generates an electronic signature in response to the instruction; an adding unit that adds the generated digital signature to the digital content; a digital certificate generating unit for generating a digital certificate related to the digital signature; an electronic certificate information storage unit that executes a process for storing electronic certificate information, which is at least a part of the electronic certificate, in each of the plurality of ledger systems; a response acquisition unit that transmits a request for the electronic certificate information stored in each of the plurality of ledger systems to each of the plurality of ledger systems, and acquires a plurality of responses that are outputs from each of the plurality of ledger systems in response to the request; an aggregate value calculation unit that calculates an aggregate value of each of the same answers included in the plurality of answers by aggregating coefficients associated with the ledger system that output the answer, for each of the same answers included in the plurality of answers; a determination unit that determines one of the plurality of answers as an answer that matches the electronic certificate information based on the aggregated value; an output unit that outputs the one answer; A program to function as a