Certification method, certification system, and program
The certification system addresses the lack of provider certification and data integrity in GHG emissions by using a certification method with public and private keys to verify provider authenticity and data integrity, enhancing data exchange efficiency and reducing costs.
Patent Information
- Application Number
- PCT/JP2024/006516
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-22
- Publication Date
- 2025-08-28
AI Technical Summary
Existing systems lack a specific mechanism to certify providers of GHG emissions data and verify the authenticity of such data, relying solely on APIs without addressing the need for provider certification and data integrity.
A certification system and method that involves a certification server transmitting certification data to a providing server, which then transmits this data along with verification data to a receiving server, ensuring the provider's authenticity and data integrity through the use of public and private keys.
Enables the certification of providers, ensuring the authenticity and integrity of provided data, reducing operational costs by eliminating the need for data transmission to the certifier and allowing for efficient data exchange among multiple parties.
Smart Images

Figure JP2024006516_28082025_PF_FP_ABST
Abstract
Description
Certification method, certification system and program
[0001] The present disclosure relates to a certification method, a certification system, and a program.
[0002] Generally, a mechanism for sharing GHG (Green House Gas) information related to the amount of GHG emissions of products between companies in a product supply chain is being considered (see, for example, Non-Patent Document 1 and Non-Patent Document 2). Non-Patent Document 1 and Non-Patent Document 2 assume that information will be shared using an API (Application Programming Interface).
[0003] Generally, there is a method in which a credential issuer issues verifiable credentials (see, for example, Non-Patent Document 3). Non-Patent Document 3 discloses that when requesting issuance of verifiable credentials from a credential issuer, an access token is presented to the credential issuer. In Non-Patent Document 3, the credential issuer signs target data with a private key to generate signature data, and a third party verifies the signature data with the credential issuer's public key. If the verification is successful, it is guaranteed that the target data has been issued by a legitimate credential issuer and that the target data has not been tampered with.
[0004] "Technical Specifications for PCF Data Exchange (Version 2.1.1-wip)," [online], [searched February 10, 2024], Internet <URL: https: / / wbcsd.github.io / data-exchange-protocol / v2 / #api-auth> Green x Digital Consortium, "Technical Specifications for Data Exchange Version 1.0," [online], [searched February 10, 2024], Internet <URL: https: / / www.gxdc.jp / pdf / data01.pdf> AUTHLETE, "OpenID for Verifiable Credential Issuance", [online], [Retrieved February 10, 2024], Internet〈URL: https: / / www.authlete.com / ja / developers / oid4vci / #25-%E3%82%AF%E3%83%AC%E3%83%87%E3%83%B3%E3%82%B7%E3%83%A3%E3%83%AB%E6%A4%9C%E8%A8%BC〉
[0005] Non-Patent Documents 1-2 merely assume that information will be linked using an API (Application Programming Interface), but do not disclose a specific mechanism. Non-Patent Documents 1-2 require a provider of data such as GHG information, as well as a certifier that certifies that the provider is capable of generating the data, and a mechanism that can verify that the provider is certified by the certifier.
[0006] The present disclosure has been made in consideration of the above circumstances, and an object of the present disclosure is to provide a technology that can certify a provider who provides provided data.
[0007] In one aspect of the certification method of the present disclosure, a certification server transmits certification data indicating that the provider has been certified and data that can verify that the certification server generated the certification data to a providing server used by the provider that generates the provided data, and the providing server transmits (i) the certification data, (ii) data that can verify that the certification server generated the certified data, (iii) the provided data, and (iv) data that can verify that the provided data was generated by the providing server to a receiving server.
[0008] A certification system according to one aspect of the present disclosure includes a providing server used by a provider that generates provided data, a certification server used by a certifier that certifies the provider, and a receiving server used by a recipient that uses the provided data. The certification server includes a certification unit that transmits, to the providing server, certification data indicating that the provider has been certified and data that can verify that the certification server generated the certified data. The providing server includes a certification request unit that requests certification of the provider from the certification server, and a providing unit that transmits, to the receiving server, (i) the certification data, (ii) data that can verify that the certification server generated the certified data, (iii) the provided data, and (iv) data that can verify that the providing server generated the provided data.
[0009] A program according to one aspect of the present disclosure causes a computer to function as a certification request unit that requests certification of a provider that generates provided data from a certification server used by a certifier who certifies providers, and a providing unit that transmits to a receiving server (i) certification data indicating that the certifier has certified the provider, (ii) data that can verify that the certification server generated the certified data, (iii) the provided data, and (iv) data that can verify that the provided data was generated by the computer.
[0010] According to the present disclosure, it is possible to provide a technology that can certify a provider who provides provided data.
[0011] FIG. 1 is a diagram illustrating the system configuration of a certification system according to the present disclosure. FIG. 2 is a sequence diagram illustrating a process for transmitting and receiving certification data in the certification system. FIG. 3 is a sequence diagram illustrating a process for transmitting and receiving certification data and provided data in the certification system. FIG. 4 is a diagram illustrating functional blocks of a certification server. FIG. 5 is a diagram illustrating functional blocks of a provision server. FIG. 6 is a diagram illustrating functional blocks of a receiving server. FIG. 7 is a sequence diagram illustrating a process for transmitting and receiving certification data and provided data in a certification system according to a modified example. FIG. 8 is a sequence diagram illustrating a process for transmitting and receiving provided data between a certification server and a provision server in a certification system according to a modified example. FIG. 9 is a diagram illustrating functional blocks of a certification server according to a modified example. FIG. 10 is a diagram illustrating functional blocks of a provision server according to a modified example. FIG. 11 is a diagram illustrating functional blocks of a receiving server according to a modified example. FIG. 12 is a diagram illustrating the hardware configuration of computers used in the certification server, the provision server, and the receiving server.
[0012] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In the description of the drawings, the same parts are designated by the same reference numerals and the description thereof will be omitted.
[0013] (Authorization System) The authorization system 5 includes a providing server 1, an authorization server 2, and a receiving server 3. The providing server 1, the authorization server 2, and the receiving server 3 are connected via a communication network 4 so as to be able to communicate bidirectionally. In addition, general communication techniques such as using an access token may be used for communication between the servers.
[0014] The provision server 1 is used by a provider who generates provision data F. The provision server 1 provides the provision data F generated by the provider. The provision server 1 has a pair of a public key Y and a private key Y.
[0015] The providing server 1 transmits the certification data C received from the certification server 2 and the provided data F generated by the provider to the receiving server 3. The certification data C indicates that the certifier has certified the provider. By sending the certification data C and the provided data F together, the providing server 1 indicates that the provided data F was created by a provider certified by the certifier.
[0016] The providing server 1 converts the provided data F into "data that can be verified as having been generated by the providing server 1" and transmits it to the receiving server 3. In the present disclosure, "data that can be verified as having been generated by the providing server 1" refers to target data including the provided data F that the providing server 1 has signed with the private key Y. The receiving server 3 verifies the data signed with the private key Y with the public key Y.
[0017] The certification server 2 is used by a certifier who certifies a provider. The certification server 2 transmits certification data C indicating that the certifier certifies the provider to the provision server 1. The certification server 2 has a pair of a public key X and a private key X.
[0018] The certification data C includes the provider's identifier, the provider's name, the certifier's identifier, the certifier's name, the date and time when the certifier certified the provider, the expiration date of the certification, the identifier of the provider server 1, and the certification details.
[0019] The certification server 2 transmits the certification data C to the providing server 1. The certification data C is also transmitted to the receiving server 3 via the providing data F.
[0020] The certification server 2 converts the certification data C into "data that can verify that the certification server 2 generated the certification data C" and transmits it to the provision server 1. In the present disclosure, the "data that can verify that the certification server 2 generated the certification data C" is data in which the certification server 2 has signed target data including the certification data C with the private key X. The provision server 1 verifies the data signed with the private key X with the public key X.
[0021] The receiving server 3 is used by a recipient who uses the provided data F. The receiving server 3 receives the provided data F and the certified data C, and the recipient uses the provided data F and the certified data C. If the certified data C and the provided data F are each signed with a private key, each signature is verified using the respective public keys.
[0022] In this disclosure, the certification system 5 is assumed to certify providers of GHG information, but is not limited to this. The certification system 5 may be applied to any linkage, such as linkage with other information provision systems or software bills of materials (SBOMs) in software supply chains, academic degrees, course completion certificates, professional qualification certificates, personal information certificates, vaccination certificates, license certificates, insurance certificates, and other qualification certificates.
[0023] In this disclosure, the provider, certifier, and recipient may be natural persons or legal entities. In this disclosure, the explanation is given on the assumption that the public key is obtained from the owner of the public key, but this is not limited to this. The public key may be obtained by any method.
[0024] Referring to FIG. 2, a process for transmitting and receiving certification data in the certification system 5 according to the present disclosure will be described.
[0025] In step S11, the providing server 1 requests the certification server 2 to send certification data C indicating that the provider has been certified. At this time, the certification server 2 holds the address of the providing server 1.
[0026] When the certifier certifies the provider, certification data C is generated in step S12. In step S13, the certification server 2 acquires the public key Y from the provision server 1. In step S14, the certification server 2 verifies the public key Y acquired in step S13 by any method.
[0027] In step S15, the certification server 2 signs the first target data T1 with the private key X to generate first signature data A1. Here, the first target data T1 is data of the certification data C and the public key Y. The certification data C includes at least the identifier of the provider.
[0028] In step S16, the provision server 1 transmits the certification data C and the first signature data A1 to the provision server 1. In step S17, the provision server 1 acquires the public key X of the certification server 2. The provision server 1 may verify the public key X in the same manner as in step S14.
[0029] In step S18, the provision server 1 verifies the first signature data A1 with the public key X. Here, the provision server 1 confirms that the certification data C has been generated by a certifier.
[0030] Referring to FIG. 3, a process of transmitting and receiving the certification data C and the provided data F in the certification system 5 according to the present disclosure will be described.
[0031] In step S31, the receiving server 3 requests the provision data F from the provision server 1.
[0032] In step S32, the provision server 1 signs the second target data T2 with the private key Y to generate second signature data A2. The second target data T2 is the first signature data A1 and the provided data F. The second target data T2 may further include data of the certification data C and the public key Y.
[0033] In step S33, the providing server 1 transmits the certification data C, public key Y, first signature data A1, provided data F, and second signature data A2 to the receiving server 3. In step S34, the receiving server 3 verifies the second signature data A2 with the public key Y to confirm that the second signature data A2 was generated by the providing server 1. If the provided data F extracted by this verification is identical to the provided data F acquired in step S33, the receiving server 3 confirms that the provided data F has not been tampered with.
[0034] In step S35, the receiving server 3 obtains the public key X from the certification server 2. The receiving server 3 may verify the public key X.
[0035] In step S36, the receiving server 3 verifies the first signature data A1 obtained in step S33 using the public key X to confirm that the first signature data A1 was generated by the certification server 2. If the certification data C extracted by this verification is identical to the certification data C obtained in step S33, the receiving server 3 confirms that the certification data C has not been tampered with.
[0036] Thereafter, in step S37, the receiving server 3 utilizes the provided data F and the certification data C.
[0037] (Authorization Server) The authorization server 2 will be described with reference to Fig. 4. The authorization server 2 includes an authorization unit 11.
[0038] The certification unit 11 transmits certification data C indicating that the provider has been certified to the provision server 1 .
[0039] The certification unit 11 transmits to the providing server 1 certification data C indicating that the provider has been certified, and data with which it is possible to verify that the certification server 2 has generated the certification data C. The data with which it is possible to verify that the certification server 2 has generated the certification data C is first signature data A1.
[0040] The certification unit 11 acquires the address of the provision server 1 and the public key Y from the provision server 1 along with a request for certification data C. The certification unit 11 associates and stores the address of the provision server 1 with an identifier of the certification server 2, such as the public key Y. The certification unit 11 signs the certification data C and public key Y, which are generated when the certifier certifies the provider, with the private key X to generate first signature data A1. The certification unit 11 transmits the first signature data A1, the certification data C, and the public key X to the provision server 1.
[0041] The authentication unit 11 also transmits the public key X to the receiving server 3 that has received the first signature data A1 via the providing server 1.
[0042] (Provision Server) The provision server 1 will be described with reference to Fig. 5. The provision server 1 includes a certification request unit 21 and a provision unit 22.
[0043] The certification request unit 21 requests the certification server 2 to certify the provider.
[0044] The certification requesting unit 21 transmits the address of the provision server 1 and the public key Y to the certification server 2 along with a request for the certification data C. The certification requesting unit 21 receives the first signature data A1, the certification data C, and the public key X from the certification server 2. The certification requesting unit 21 verifies the first signature data A1 with the public key X.
[0045] When the certification requesting unit 21 verifies the first signature data A1, the providing unit 22 signs the provided data F with the private key Y to generate second signature data A2.
[0046] The providing unit 22 transmits to the receiving server 3 (i) the certification data C, (ii) data that can verify that the certification server 2 generated the certification data, (iii) the provided data F, and (iv) data that can verify that the providing server 1 generated the provided data F. The providing unit 22 may further transmit a public key Y to the receiving server 3. (ii) The data that can verify that the certification server 2 generated the certification data is the first signature data A1. (iv) The data that can verify that the providing server 1 generated the provided data F is the second signature data A2.
[0047] The providing unit 22 transmits the provided data F to the receiving server 3 together with the certification data C. The recipient can understand that the provider who created the provided data F has been certified by the certifier.
[0048] Here, (iv) data that can verify that the providing server generated the provided data F may be data that associates (ii) data that can verify that the authorization server 2 generated the authorization data C with (iii) the provided data F. The data that associates the data (ii) with the data (iii) is data signed with one private key, with the data (ii) and the data (iii) as target data. In the present disclosure, the data that associates the data (ii) with the data (iii) is the second signature data A2, which is data that includes not only the provided data F but also the first signature data A1, signed with the private key Y. However, other methods of association are also possible. For example, the data may be data that instructs the receiving server 3 to associate the data (ii) with the data (iii) and retain and utilize them. The receiving server 3 can more clearly confirm that the authorized person generated the authorization data C and that the provided data F and the authorization data C are linked.
[0049] (Receiving Server) The receiving server 3 includes a request unit 31 .
[0050] The request unit 31 requests the provision data F from the provision server 1, and receives the certification data C, public key Y, first signature data A1, the provision data F, and second signature data A2 from the provision server 1. The request unit 31 verifies the first signature data A1 with the public key Y. The request unit 31 also obtains the public key X from the certification server 2 and verifies the first signature data A1.
[0051] When the verification is completed, the request unit 31 links the certified data C with the provided data F and uses these data.
[0052] According to the present disclosure, certification data C indicating that the certifier has certified the provider and provided data F generated by the provider can both be transmitted to the receiving server 3. The recipient can use the provided data F together with the certification by the certifier.
[0053] According to the present disclosure, since the certifier certifies the provider, there is no need to transmit the provided data F to the certifier, and it is possible to prevent the spread of the provided data F. This is expected to reduce the implementation and operation costs of the certification server 2.
[0054] Furthermore, the certification system 5 according to the present disclosure can appropriately transmit and receive the certification data C and the provided data F even when there are multiple certifiers, providers, and recipients.
[0055] (Modification) Next, a modification will be described. In the embodiment, a case where the certifier certifies the provider has been described, but in the modification, a case where the certifier irregularly acquires the provided data F generated by the provider will be described. In the modification, the certifier not only simply certifies the provider, but also acquires and checks the provided data F, thereby enabling the certifier to carry out an audit accompanying the certification of the provider.
[0056] In this modification, the process of transmitting and receiving the certification data C between the certification server 2a and the providing server 1a is as shown in Fig. 2. The process of transmitting and receiving the certification data C and the providing data F will be described with reference to Fig. 7. By the process shown in Fig. 7, the receiving server 3a and the certification server 2a know the identifier of the providing data F.
[0057] The processing of steps S51 to S53 is the same as the processing of steps S31 to S33 in Fig. 3. However, the difference is that the second signature data A2 is data obtained by signing the first signature data A1, the provided data F, and the identifier of the provided data F with the private key Y. Also, in step S53, the receiving server 3a obtains the address of the providing server 1a. In step S54, the receiving server 3a verifies the second signature data A2 with the public key Y and identifies the identifier of the provided data F.
[0058] In step S55, the receiving server 3a notifies the authorization server 2a of the identifier of the provided data F and the address of the providing server 1a. This allows the authorization server 2a to grasp the identifier of the provided data F created by the provider. In this disclosure, a case will be described in which the receiving server 3a notifies the authorization server 2a of the identifier of the provided data F, but the providing server 1a may also notify the authorization server 2a of the identifier of the provided data F.
[0059] In step S56, the certification server 2a verifies the address of the provision server 1a acquired in step S55. Specifically, the certification server 2a verifies that the address of the provision server 1a acquired in step S11 of FIG. 2 matches the address of the provision server 1a acquired in step S55. When the certification server 2a acquires the address of the provision server 1a from each of the multiple providers to be certified, the certification server 2a verifies that the address of the provision server 1a acquired in step S55 matches any of the address of the provision server acquired in the past.
[0060] The processes in steps S57 to S59 are similar to the processes in steps S35 to S37 in FIG.
[0061] 7 illustrates an example in which the second target data T2 includes an identifier of the provided data F, but this is not limiting. When the providing server 1a and the receiving server 3a share a function for calculating a hash value, the receiving server 3a may calculate a hash value from the provided data F and the function received from the providing server 1a, and use the calculated hash value as the identifier of the provided data F.
[0062] Referring to FIG. 8, a process for transmitting and receiving the provided data F between the authorization server 2a and the providing server 1a will be described.
[0063] In step S71, the certification server 2a requests the provision data F from the provision server 1a to be inspected, specifying the identifier of the provision data F.
[0064] In step S72, the provision server 1a signs the third target data T3 with the private key Y to generate third signature data A3. The third target data T3 is the first signature data A1 and the provided data F having the identifier specified in step S72. In step S73, the provision server 1a transmits the certification data C, the public key Y, the first signature data A1, the provided data F, and the third signature data A3 to the certification server 2a.
[0065] In step S73, the certification server 2a verifies the third signature data A3 with the public key Y. In step S74, the certification server 2a verifies the first signature data A1 with the public key X. In step S75, the certification server 2a utilizes the provided data F.
[0066] (Authorization Server) A modification of the authorization server 2a will be described with reference to Fig. 9. The authorization server 2a according to the modification differs from the authorization server 2 shown in Fig. 4 in that it includes the functions of an authorization unit 11a and a verification unit 12.
[0067] The certification unit 11a acquires the address of the providing server 1a and the identifier of the provided data F, for example, when receiving a request for the public key X from the receiving server 3a. The certification unit 11a confirms that the known address of the providing server 1a matches the address of the providing server 1a received from the receiving server 3a. The known address of the providing server 1a is the address of the providing server 1a when the certification server 2a receives a request for the certification data C from the providing server 1a.
[0068] The verification unit 12 acquires the identifier of the provided data F from the certification unit 11a. The verification unit 12 requests the provided data F from the providing server 1a by specifying the identifier of the provided data F acquired from the certification unit 11a. The verification unit 12 receives the certification data C, the public key Y, the first signature data A1, the provided data F, and the third signature data A3 from the providing server 1a. The verification unit 12 verifies the first signature data A1 and the third signature data A3. After confirming that the provided data F was generated by the providing server 1a and that the provided data F has not been tampered with, the verification unit 12 utilizes the provided data F.
[0069] (Provision Server) A provision server 1a according to a modified example will be described with reference to Fig. 10. The provision server 1a according to the modified example differs from the provision server 1 shown in Fig. 5 in that it includes a response unit 23.
[0070] The response unit 23 transmits the provided data F to the authorization server 2 in response to a request for the provided data F from the authorization server 2a. The response unit 23 transmits to the authorization server 2a the provided data F corresponding to the identifier specified by the authorization server 2a and data that can verify that the provided data F was generated by the providing server 1a. The data that can verify that the provided data F was generated by the providing server 1a is third signature data A3.
[0071] The response unit 23 receives from the certification server 2a a request for the provided data F along with the identifier of the provided data F. The response unit 23 transmits the certification data C, the public key Y, the first signature data A1, the provided data F, and the third signature data A3 to the certification server 2a.
[0072] (Receiving Server) A receiving server 3a according to a modified example will be described with reference to Fig. 11. The receiving server 3a according to the modified example differs from the receiving server 3 shown in Fig. 6 in that the request unit 31a transmits the address of the providing server 1a and an identifier of the provided data to the certification server 2a.
[0073] According to the modified example, the certifier can check not only the provider but also the provided data F created by the provider, which is expected to improve the accuracy of provider certification. Furthermore, the certification server 2a can acquire any number of provided data F from the identifiers of the provided data F received from the receiving server 3a at any timing. This allows the modified example to adjust the balance between the monitorability of the provider and the provided data F and the operating costs.
[0074] The providing server 1, the certification server 2, and the receiving server 3 of the present embodiment described above are implemented, for example, by a general-purpose computer system including a CPU (Central Processing Unit, processor) 901, a memory 902, a storage 903 (HDD: Hard Disk Drive, SSD: Solid State Drive), a communication device 904, an input device 905, and an output device 906. In this computer system, the CPU 901 executes a program loaded on the memory 902, thereby realizing the functions of the providing server 1, the certification server 2, and the receiving server 3.
[0075] The providing server 1, the authorization server 2, and the receiving server 3 may be implemented on a single computer or on multiple computers, or may be virtual machines implemented on a computer.
[0076] The programs of the providing server 1, the certification server 2, and the receiving server 3 can be stored in a computer-readable recording medium such as a HDD, an SSD, a USB (Universal Serial Bus) memory, a CD (Compact Disc), or a DVD (Digital Versatile Disc), or can be distributed via a network. The computer-readable recording medium is, for example, a non-transitory recording medium.
[0077] The present disclosure is not limited to the above-described embodiments, and various modifications are possible within the scope of the present disclosure.
[0078] REFERENCE SIGNS LIST 1 providing server 2 certification server 3 receiving server 5 certification system 11 certification unit 12 verification unit 21 certification request unit 22 providing unit 23 response unit 31 request unit 901 CPU 902 memory 903 storage 904 communication device 905 input device 906 output device A signature data C certification data F provided data T target data
Claims
1. A certification method in which an authorization server transmits, to a providing server used by a provider that generates provided data, certification data indicating that the provider has been authorized and data that can verify that the authorization server generated the certified data, and the providing server transmits, to a receiving server, (i) the certification data, (ii) data that can verify that the authorization server generated the certified data, (iii) the provided data, and (iv) data that can verify that the provided data was generated by the providing server.
2. The certification method of claim 1, wherein (iv) the data that can verify that the provided data was generated by the providing server is (ii) data that can verify that the certification server generated the certification data, and (iii) data that corresponds to the provided data.
3. The certification method according to claim 1, wherein the certification data includes one or more pieces of information selected from an identifier of the provider, a name of the provider, an identifier of the certifier, a name of the certifier, a date and time when the provider was certified, an expiration date of the certification, an identifier of the providing server, and certification details.
4. The certification method described in claim 1, wherein the providing server transmits to the certification server the provided data corresponding to the identifier specified by the certification server and data that can verify that the provided data was generated by the providing server, and the certification server confirms that the provided data was generated by the providing server.
5. The certification method according to claim 4, wherein the receiving server transmits the address of the providing server and an identifier of the provided data to the certification server, and the certification server confirms that the known address of the providing server matches the address of the providing server received from the receiving server.
6. A certification system comprising: a providing server used by a provider that generates provided data; a certification server used by a certifier that certifies the provider; and a receiving server used by a recipient that uses the provided data, wherein the certification server comprises: a certification unit that transmits to the providing server certification data indicating that the provider has been certified and data that can verify that the certification server has generated the certified data; and the providing server comprises: a certification request unit that requests the certification server to certify the provider; and a providing unit that transmits to the receiving server (i) the certification data, (ii) data that can verify that the certification server has generated the certified data, (iii) the provided data, and (iv) data that can verify that the provided data was generated by the providing server.
7. A program that causes a computer to function as: a certification request unit that requests certification of a provider that generates provided data from a certification server used by a certifier that certifies providers; and a providing unit that transmits to a receiving server (i) certification data indicating that the certifier has certified the provider, (ii) data that can verify that the certification server generated the certified data, (iii) the provided data, and (iv) data that can verify that the provided data was generated by the computer.
Citation Information
Patent Citations
Contents certifying server
JP2002163394A
Authentication methods, devices, and systems
JP2015516616A