Management device, method for controlling management device, and program
By distributing electronic certificate information across multiple ledger systems and using an aggregate value to determine a matching response, the management device enhances the reliability of electronic signatures by minimizing tampering risks.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-20
- Publication Date
- 2026-03-26
Smart Images

Figure JP2024033739_26032026_PF_FP_ABST
Abstract
Description
Management device, control method for management device, and program
[0001] The present disclosure relates to a management device, a control method for the management device, and a program.
[0002] Conventionally, in order to ensure that data of electronic content such as electronic documents is authentic, an electronic signature is used. For example, Patent Document 1 discloses an electronic signature management system for performing an electronic signature on signature target data. Also, for example, Patent Document 2 proposes a method of storing a hash value of personal identification information with an electronic signature in a blockchain, which is a distributed ledger system, as a personal authentication method using the blockchain.
[0003] Japanese Patent Application Laid-Open No. 2018-067807 Japanese Patent Application Laid-Open No. 2024-077561
[0004] Although it is conceivable to store a certificate (electronic certificate) for proving matters related to an electronic signature in a ledger system such as a blockchain, there is a possibility that the information stored in the ledger system itself may be tampered with, so further improvement in the reliability of the electronic signature has been desired.
[0005] Therefore, the present invention has been made in view of the above conventional situation, and an object thereof is to improve the reliability of an electronic signature.
[0006] An embodiment of the present invention is a management device for managing electronic signatures on electronic content, comprising: an acquisition unit for acquiring instructions to sign electronic content; a signature generation unit for generating electronic signatures in accordance with the instructions; an assignment unit for assigning the generated electronic signatures to electronic content; an electronic certificate generation unit for generating electronic certificates relating to electronic signatures; an electronic certificate information storage unit for executing a process to store electronic certificate information, which is information contained in an electronic certificate, in each ledger system of a plurality of ledger systems; an answer acquisition unit for acquiring a plurality of answers, which are outputs from each of the plurality of ledger systems, by transmitting a request for electronic certificate information stored in each ledger system to each of the plurality of ledger systems; an aggregate value calculation unit for calculating an aggregate value for each identical answer in a plurality of answers by aggregating coefficients associated with the ledger system that output the answer for each identical answer in the plurality of answers; a determination unit for determining one of the plurality of answers as an answer that matches the electronic certificate information based on the aggregate value; and an output unit for outputting one answer.
[0007] As a result, electronic certificate information, which is at least a part of the electronic certificate related to the electronic signature, is stored in each ledger system of multiple ledger systems. Responses to requests for electronic certificate information are obtained from each of the multiple ledger systems, and for each identical response, a coefficient associated with the ledger system that output the response is aggregated to calculate an aggregate value. Based on this aggregate value, one of the multiple responses is determined to be the response that matches the electronic certificate information, and this is output. Therefore, the possibility of tampering with the electronic certificate information is reduced, making it possible to improve the reliability of electronic signatures.
[0008] According to the present invention, it is possible to improve the reliability of electronic signatures.
[0009] This is a schematic diagram showing an overview of the electronic signature management system 100 using the management device 1 according to the embodiment. This is a schematic diagram showing an electronic document D with an electronic signature S generated by the management device 1 according to the embodiment. This is a block diagram showing the configuration of the management device 1 according to the embodiment. This is a schematic diagram showing an example of the data structure of an electronic certificate according to the embodiment. This is a schematic diagram showing an example of the data structure of a ledger system table according to the embodiment. This is a block diagram showing the configuration of a user terminal 4 according to the embodiment. This is a sequence diagram showing an example of the operation processing such as the generation of electronic signatures and electronic certificates performed by the electronic signature management system 100 according to the embodiment. This is an operation flow diagram showing an example of the inquiry processing of electronic certificate information performed by the management device 1 according to the embodiment.
[0010] A preferred embodiment of the present invention will be described with reference to the attached drawings. (Note that in each drawing, components denoted by the same reference numerals have the same or similar components.)
[0011] (1) Overview Figure 1 is a schematic diagram showing an overview of the electronic signature management system 100 using the management device 1 according to the embodiment.
[0012] As shown in Figure 1, the electronic signature management system 100 includes, for example, a management device 1, an electronic content database 2, multiple ledger systems 3, and multiple user terminals 4. In the example shown in Figure 1, the ledger system 3 includes a first ledger system 3A, a second ledger system 3B, and a third ledger system 3C. Note that the ledger system 3 in this embodiment is not limited to three, but may include two or four or more ledger systems 3. The management device 1 is connected to the electronic content database 2 and each of the ledger systems 3 so as to be able to manage (store, delete, modify, etc.) information. The management device 1 is also connected to multiple user terminals 4 via a communication network N such as the Internet so as to be able to send and receive information to and from each other.
[0013] The management device 1 is, for example, a computer (information processing device) such as a server, and has a processing unit such as a CPU and a storage unit such as memory. The management device 1 is a device that generates an electronic signature S for the user's electronic content D, such as a contract. The electronic content D is stored, for example, in the electronic content database 2. In other words, the management device 1 is a device that has the function of generating an electronic signature S to be attached to the user's electronic content D. The management device 1 may, for example, create electronic content D that indicates consent to the electronic content D by visibly attaching the electronic signature S to the electronic content D.
[0014] In the following embodiments, "electronic content" may include "electronic documents" or "electronic images." "Electronic documents" include any documents such as contracts, quotations, application forms, purchase orders, delivery notes, invoices, receipts, shipping labels, minutes, approval documents, application forms, signature lists, etc., and may include documents created electronically. "Electronic images" may be still images or videos (images) composed of multiple still images in a chronological sequence. Videos may be combined with audio. "Electronic signature" may include the process of electronically performing the act of stamping a paper contract, etc., on the electronic content D. "Electronic certificate" may be a certificate for proving matters related to an electronic signature, and may include, for example, an electromagnetic record created to prove that the matters used to confirm that the user has made the electronic signature pertain to that user.
[0015] Figure 2 is a schematic diagram showing an electronic document D with an electronic signature S generated by a management device 1 according to an embodiment. In particular, as shown in Figure 2, the management device 1 may affix a visible electronic signature S to the electronic document D. For example, the management device 1 may affix a visible electronic signature S corresponding to individual users. For example, the management device 1 may affix an electronic signature S represented as a QR code (registered trademark) to the electronic content D. When the management device 1 affixes an electronic signature S to an electronic image as electronic content, it may superimpose the electronic signature S on a part of at least one of the still images contained in the electronic image, or it may affix the electronic signature S to the metadata contained in the electronic image.
[0016] As shown in Figure 1, the management device 1 is connected to the ledger system 3 (first ledger system 3A, second ledger system 3B, and third ledger system 3C). The management device 1 creates an electronic certificate for the electronic content D to which an electronic signature S has been attached. The management device 1 stores at least a portion (electronic certificate information) of the created electronic certificate for the electronic content D in the first ledger system 3A, the second ledger system 3B, and the third ledger system 3C, respectively. Each ledger system 3 may be a distributed ledger system. The ledger system 3 may be configured to include, for example, a plurality of node computers (nodes) that store a blockchain. The format of the blockchain is not particularly limited, but may be configured as a private blockchain, for example, a public type, a consortium type, or a private type. The management device 1 stores, for example, the electronic certificate in the first ledger system 3A, the second ledger system 3B, and the third ledger system 3C, which are configured as the blockchain, etc.
[0017] The management device 1 performs a query process (query process) at a predetermined timing to query the multiple ledger systems 3 provided by the electronic signature management system 100 for desired electronic certificate information. The management device 1 requests the electronic certificate information stored in each of the multiple ledger systems 3 from each of the multiple ledger systems 3 and obtains a response from each ledger system 3 to the request. Here, if the electronic certificate information is tampered with in at least one of the ledger systems 3, the multiple responses obtained from the multiple ledger systems 3 may include multiple different responses. However, in the management device 1 according to this embodiment, since the electronic certificate information is managed by the multiple ledger systems 3, it is possible to guarantee the authenticity of the electronic certificate information. That is, for each identical response included in the responses obtained from each ledger system 3, the management device 1 calculates the aggregate value for each identical response included in the multiple responses by aggregating the coefficients associated with the ledger system that output the response. Based on the aggregate value, the management device 1 determines one of the multiple responses as the response that matches the electronic certificate information and outputs that one response. As described above, in the electronic signature management system 100 according to this embodiment, electronic certificate information is stored in multiple ledger systems 3, and at a predetermined timing, the management device 1 performs an inquiry process for electronic certificate information against the multiple ledger systems 3 to determine and output genuine electronic certificate information. This reduces the possibility of tampering with electronic certificate information and, consequently, improves the reliability of electronic signatures.
[0018] As shown in Figure 1, the user terminal 4 is configured as a device different from the management device 1, for example. The user terminal 4 is a computer (information processing device) such as a smartphone, tablet terminal, or personal computer with an imaging function, and has a processing unit such as a CPU and a storage unit such as memory. Based on the electronic signature S generated by the management device 1, the user terminal 4 obtains information contained in the electronic certificate held in the ledger system 3 via the management device 1, and performs processing to verify the authenticity of the electronic content D based on the obtained information. The user terminal 4 also performs display processing of various information based on the information contained in the obtained electronic certificate. In particular, the user terminal 4 displays a URL to identify the storage area in the electronic content database 2 where the electronic content D is stored. When the user selects the URL, the user terminal 4 obtains the electronic content D from the electronic content database 2 and displays it. This makes it possible to verify the content of the electronic content D in an environment in which the authenticity of the electronic content D is guaranteed. Furthermore, since the content of electronic content D can be verified from the electronic signature S, users can maintain evidentiary value (backed by information on the electronic certificate) even by storing a printout of electronic content D on paper or other similar material, rather than the file itself.
[0019] (2) Configuration (2-1) Management device 1 Figure 3 is a block diagram showing the configuration of the management device 1 according to the embodiment. The management device 1 comprises a document management unit 11, an instruction acquisition unit 12, a user information acquisition unit 13, a signature generation unit 14, an assignment unit 15, an electronic certificate generation unit 16, an electronic certificate information storage unit 17, a response acquisition unit 18, an aggregate value calculation unit 19, a determination unit 20, and a transmission / reception unit 21. These various functional units are realized by the operation of a processing unit such as a CPU in the management device 1.
[0020] The document management unit 11 is implemented, for example, by the operation of the CPU. The document management unit 11 performs tasks such as creating, acquiring, modifying, and storing electronic content D, which is subject to electronic signature, in the storage unit. The document management unit 11 acquires electronic content D from, for example, the electronic content database 2 or the user terminal 4. Electronic content D may be electronic data created by word processing software or image processing software, or it may be data obtained by scanning printed materials such as paper. The document management unit 11 may also create or modify electronic content based on instructions acquired from the user terminal 4. The document management unit 11 may also store electronic content in the electronic content database 2.
[0021] The instruction acquisition unit 12 acquires an instruction (signature instruction) to sign the acquired electronic content that is to be signed. For example, the instruction acquisition unit 12 acquires a signature instruction from the user terminal 4.
[0022] The user information acquisition unit 13 acquires user information as user information. In this embodiment, the user information acquisition unit 13 also acquires the user ID and username of a user that have been issued in advance. Here, the user information acquisition unit 13 acquires the user ID and username of the contracting party (user) as user information. In this embodiment, the user information acquisition unit 13 also acquires user information from the user terminal 4, etc., when generating the electronic signature S. The user information may include arbitrary information unique to the user that is managed by the user.
[0023] The signature generation unit 14 generates an electronic signature in which the electronic certificate identifier, which is the identifier of the electronic certificate, is encoded. The signature generation unit 14 may include a unique string in the electronic certificate identifier. This string may be unique for each electronic signature S, for example. The electronic certificate identifier is generated (numbered) for example when the electronic signature S is attached to the electronic content D.
[0024] The signature unit 15 assigns the generated electronic signature S to the electronic content D. The signature unit 15 may, for example, assign the electronic signature S to the electronic content D in a visible manner. This makes it easy to identify that the electronic content D has an electronic signature S assigned to it. The signature unit 15 may, for example, assign the generated electronic signature S to the corporate name and the name of the representative, which are user information described in the electronic content D, in a position where they are displayed side by side, as shown in Figure 2. The signature unit 15 may, for example, assign the electronic signature S to the electronic content D in a position where it is clear that it corresponds to the electronic signature S of the described user information. In this embodiment, the signature unit 15 may also include the name of the user included in the acquired user information with the electronic signature S. The signature unit 15 may, for example, include the user name below the display surface of the electronic content D (electronic document) for the corresponding user's electronic signature S (QR code), as shown in Figure 2. This makes it clear which user's electronic signature S the coded electronic signature S belongs to. Furthermore, by including it alongside the coded electronic signature S, the code can be treated like a seal impression, thus achieving a visual effect similar to stamping a seal on paper.
[0025] The electronic certificate generation unit 16 generates various electronic certificates related to the electronic signature S. The electronic certificates are stored, for example, in the ledger system 3.
[0026] Figure 4 is a schematic diagram showing an example of the data structure of an electronic certificate according to this embodiment. Each row shown in Figure 4 corresponds to one electronic certificate. For example, each time an electronic signature is applied to electronic content, one electronic certificate is added to the ledger system 3.
[0027] An electronic certificate may include, for example, the issuer name, issue number, issue date and time, expiration date, series ID, sub-number, user ID, user's organization, user's job title, user's name, signature content, original hash value, pre-signature hash value, post-signature hash value, URL for publishing electronic content, and a password.
[0028] The issuer name is the name of the issuer of the electronic certificate, and may be, for example, the name of the administrator of management device 1. The issue number is the electronic certificate identifier (an identifier for identifying the electronic certificate) issued by management device 1. The issue date and time is the date and time the electronic certificate was issued, and may be the time information of the signature. The issue date and time is an example of ranking information indicating the rank of the electronic signature (information indicating the rank of a series of electronic signatures each time an electronic signature is granted). The expiration date is the date on which the validity period of the electronic certificate expires.
[0029] A series ID is an example of lineage identification information, which is identification information used to identify the lineage of electronic content D. The series ID may be unique identification information for electronic content D (or its lineage) and does not change even if one or more electronic signatures S are assigned to electronic content D. In other words, the series ID is identification information assigned to the content represented by electronic content D (which may include modified content). This makes it possible to manage electronic content D and the series of electronic signatures S as a series when electronic signatures S are assigned to electronic content D sequentially, to verify which of the series of electronic signatures S is the latest, and whether the electronic signature S attached to the electronic content D one possesses is the latest.
[0030] The sub-number is an example of ranking information that indicates the rank of an electronic signature S (information that indicates the rank of a series of electronic signatures S each time an electronic signature S is assigned). In the example shown in Figure 4, natural numbers such as 1, 2, and 3 are used as sub-numbers, but any symbols or codes may be used to arbitrarily construct the sub-number (ranking information) as long as it is possible to indicate the rank.
[0031] The User ID is the user's identification information. The User's Organization is information indicating the organization to which the user belongs. The User's Position is information indicating the user's position within that organization. The User's Name is the user's name (the name of the contact person at each company).
[0032] The signature content is information associated with the electronic signature S, and may be text data arbitrarily entered by the user. For example, the signature content may be an expression of the user's intent associated with the electronic signature, or, if modifications have been made to the electronic content being signed, it may be information indicating that modifications have been made or information indicating the content of those modifications. This makes it possible to verify the user's intent regarding the electronic signature, whether or not modifications have been made to the electronic content, and the content of those modifications, by checking the electronic certificate.
[0033] The original hash value, pre-signature hash value, and post-signature hash value are used, for example, in integrity verification processing for electronic content D. Integrity verification processing will be described later. The original hash value is the hash value of electronic content D (original text) that does not contain any digital signatures. The pre-signature hash value is the hash value of electronic content D immediately before the latest digital signature S is applied (electronic content D containing digital signature S that is ranked earlier than the current digital signature S). The post-signature hash value is the hash value of electronic content D to which the latest digital signature S has been applied.
[0034] The URL for publishing electronic content may be a URL that identifies the storage area where electronic content D is stored (for example, the URL of electronic content D in electronic content database 2). The URL for publishing electronic content may have an expiration date. The password may be a password required when accessing the URL for publishing the file and viewing electronic content D, and may be assigned arbitrarily or by the system.
[0035] It should be noted that the electronic certificate described above is merely an example, and the electronic certificate in the embodiment does not have to include any of the items described above, nor does it have to include items other than those described above.
[0036] The electronic certificate information storage unit 17 stores at least a portion of the generated electronic certificate (electronic certificate information) in the ledger system 3 (first ledger system 3A, second ledger system 3B, and third ledger system 3C). The electronic certificate information, which is at least a portion of the electronic certificate information, may include, for example, at least a portion of the information shown in Figure 4.
[0037] The response acquisition unit 18 acquires the electronic certificate information stored in each ledger system 3 from each ledger system 3. Specifically, the response acquisition unit 18 sends a request for the electronic certificate information stored in each ledger system 3 to each ledger system 3. When the ledger system 3 receives the request for electronic certificate information from the management device 1, it outputs the electronic certificate information stored in the ledger system 3 in response to the request and sends the outputted electronic certificate information to the management device 1 as a response to the request. The response acquisition unit 18 acquires the response from each ledger system 3. The timing of the response acquisition process by the response acquisition unit 18 may be arbitrary, but for example, it may be when a request for inquiry of electronic certificate information is received from a user terminal 4, etc., or when a new electronic signature is generated for an electronic document.
[0038] The aggregate value calculation unit 19 calculates the aggregate value for each identical response included in multiple responses obtained from multiple ledger systems 3 by the response acquisition unit 18 by aggregating the coefficients associated with the ledger system 3 that output the response. In other words, the aggregate value may be the sum of the coefficients from at least one ledger system 3 that output the same response. Furthermore, the aggregate value is a value calculated in association with the response containing electronic certificate information, and can be considered a score for selecting genuine electronic certificate information that has not been tampered with.
[0039] The determination unit 20, for example, determines one of the multiple responses obtained from each ledger system 3 as the response that matches the electronic certificate information, based on the aggregated value calculated by the aggregated value calculation unit 19. The determination unit 20 may also determine, for example, that the response with the highest aggregated value among the responses obtained from the multiple ledger systems 3 is the response that matches the electronic certificate information.
[0040] The transmitting / receiving unit 21 transmits and receives various types of information with the user terminal 4. For example, the transmitting / receiving unit 21 receives a signature instruction for electronic content D from the user terminal 4. The transmitting / receiving unit 21 also transmits, for example, electronic content D (including one with an electronic signature S) to the user terminal 4. The transmitting / receiving unit 21 also outputs an example of an output unit, which is a response determined by the determination unit 20 as a response that matches the electronic certificate information. Here, the process of outputting the response may be, for example, a process of transmitting the response to another external device such as the user terminal 4, or a process of displaying the response on any display device.
[0041] Each component included in the management device 1 can be implemented by hardware, software, or a combination thereof. Here, implementation by software means implementation by a computer reading and executing a program. The program can be stored and supplied to the computer using various types of non-transitor computer-readable media. Non-transitor computer-readable media include various types of tangible storage media. Examples of non-transient computer-readable media include magnetic recording media (e.g., flexible disks, magnetic tapes, hard disk drives), magneto-optical recording media (e.g., magneto-optical disks), CD-ROMs (Read Only Memory), CD-Rs, CD-R / Ws, and semiconductor memory (e.g., mask ROMs, PROMs (Programmable ROMs), EPROMs (Erasable PROMs), flash ROMs, and RAMs (random access memory)). Display programs may also be supplied to a computer by various types of transient computer-readable media. Examples of transient computer-readable media include electrical signals, optical signals, and electromagnetic waves. Transient computer-readable media can supply programs to a computer via wired communication channels such as electric wires and optical fibers, or via wireless communication channels.
[0042] Figure 5 is a schematic diagram showing an example of the data structure of a ledger system table according to an embodiment. The ledger system table may be stored in a storage unit accessible by the management device 1, such as a storage unit provided by the management device 1. The ledger system table may also include information about each ledger system 3 provided by the electronic signature management system 100. In the example shown in Figure 5, the ledger system table includes coefficients and characteristic information for each ledger system 3.
[0043] The coefficient is a numerical value associated with each ledger system 3 and serves as a basis for calculating an aggregated value, for example, during the query process of electronic certificate information. In other words, the coefficient may be a numerical value indicating the possibility or likelihood that the information stored as electronic certificate information in the ledger system 3 matches genuine electronic certificate information.
[0044] The ledger system table may include characteristic information indicating the characteristics of each ledger system 3. The characteristic information may be, for example, information indicating the type of the ledger system 3. The type of the ledger system 3 may be, for example, whether it is a distributed type or a non - distributed type, or in the case of a distributed type, the type (such as public type, consortium type, and private type, etc.). Also, the characteristic information may include, for example, an algorithm type. The algorithm type is information indicating the type of algorithm (such as a consensus algorithm, etc.) adopted by the ledger system 3 for storing information. Specifically, the algorithm type may include blockchain, Ethereum, and other algorithms. Also, the characteristic information may include, for example, the number of nodes. The number of nodes may be the number of nodes constituting the ledger system 3. Note that the characteristic information shown in FIG. 5 is merely an example, and the ledger system table may include any characteristic information indicating the characteristics of the ledger system 3.
[0045] The management device 1 may calculate and update the coefficient based on the characteristic information indicating the characteristics of each ledger system 3. The management device 1 may calculate the coefficient so that the coefficients of all ledger systems 3 are equal. In this case, substantially, one answer is determined as the answer that matches the electronic certificate information by a majority vote of a plurality of ledger systems 3. Alternatively, the management device 1 may calculate the coefficient such that, for example, the coefficient of the ledger system 3 increases as the characteristic information of the ledger system 3 has a lower likelihood of being tampered with. Specifically, for example, the coefficient may be made larger when the ledger system 3 is of a distributed type rather than a non - distributed type. Also, for example, the coefficient may be made larger in the order of the types of the distributed ledger system 3 being public type, consortium type, and private type. Also, the coefficient may be made larger as the number of nodes of the ledger system 3 increases.
[0046] (2-2) User Terminal 4 FIG. 6 is a block diagram showing the configuration of the user terminal 4 according to the embodiment. The user terminal 4 includes an imaging unit 41, an identifier acquisition unit 42, a held information acquisition unit 43, a hash value calculation unit 43, a consistency confirmation unit 44, an output unit 45, and an operation reception unit 46. These various functional units are realized by the operation of a processing unit such as a CPU included in the user terminal 4.
[0047] The imaging unit 41 is an imaging mechanism including a so-called camera. The imaging unit 41 images, for example, any electronic signature S given to the electronic content D. The imaging unit 41 images, for example, any electronic signature S included in the electronic content D displayed on a display unit (not shown) of another terminal.
[0048] The identifier acquisition unit 42 acquires an electronic certificate identifier included in the imaged electronic signature S by imaging the electronic signature S (QR code).
[0049] The hash value calculation unit 43 calculates various hash values based on the electronic content D. The hash value calculation unit 43 may calculate, for example, a hash value (post-signature hash value) of the electronic content D including the latest electronic signature S. Further, the hash value calculation unit 43 may calculate, for example, a hash value (pre-signature hash value) of the electronic content D not including only the latest electronic signature S. Further, the hash value calculation unit 43 may calculate, for example, a hash (original text hash value) of the electronic content D as the original text not including any electronic signature S.
[0050] The consistency verification unit 44 obtains the electronic certificate stored in the ledger system 3 via the management device 1, and then performs a consistency verification process for the electronic content D based on this certificate. The consistency verification process for the electronic content D makes it possible to determine whether or not the electronic content D is authentic. For example, the consistency verification unit 44 obtains the electronic certificate from the management device 1 based on the electronic certificate identifier obtained by imaging one of the electronic signatures S contained in the electronic content D, and then verifies the consistency between the hash values (original hash value, pre-signature hash value, and / or post-signature hash value) contained in the obtained electronic certificate and the hash values (original hash value, pre-signature hash value, and / or post-signature hash value) calculated from the electronic content D by the hash value calculation unit 43. The consistency verification unit 44 may, for example, determine whether or not the electronic content D as the original has been altered by determining whether or not the original hash value obtained from the target electronic content D matches the original hash value contained in the electronic certificate. Furthermore, the integrity verification unit 44 may determine, for example, whether the electronic content D has not been altered during the period between the previous electronic signature S and the latest electronic signature S by determining whether the pre-signature hash value obtained from the target electronic content D (a hash value calculated based on the electronic content obtained excluding only the latest electronic signature) matches the post-signature hash value included in the electronic certificate with the rank of the previous one. A specific example of operation is as follows: That is, for example, a user can access the electronic content D (original) stored in the management device 1 (electronic content database 2, etc.) by taking a picture of the electronic signature S of the electronic content D printed on paper (handed over, delivered, etc.) with the user terminal 4, and display the electronic content D on the user terminal 4. The management device 1 may calculate a hash value for the accessed electronic content D and determine whether the electronic content D is authentic by querying the ledger system 3 for the hash values (original hash value, pre-signature hash value, and post-signature hash value).Regarding the electronic content D that has been handed over or delivered, the user can verify its authenticity, for example, by visually comparing the handed-over or delivered electronic content D with the electronic content D stored in the management device 1 and displayed on the user terminal 4. Alternatively, the authenticity of the electronic content D stored in the management device 1 may be determined, for example, by querying the ledger system 3.
[0051] The output unit 45 outputs various information related to the electronic content D. For example, the output unit 45 outputs information on various electronic certificates obtained from the management device 1. Also, for example, the output unit 45 outputs the consistency verification results from the consistency verification unit 44.
[0052] The operation reception unit 46 receives various operations from the user. For example, the operation reception unit 46 receives a selection to perform a consistency check process regarding the electronic content D. The operation reception unit 46 also receives, for example, transitions between various screens displaying information about the electronic content D, and selection of links.
[0053] The transmitting / receiving unit 47 transmits and receives various types of information with the management device 1 and other user terminals 4. For example, the transmitting / receiving unit 47 transmits a signature instruction for electronic content to the management device 1. The transmitting / receiving unit 47 also receives, for example, electronic content D (including those with an electronic signature S) and electronic certificates from the management device 1.
[0054] (3) Example of Operation (3-1) Generation of Electronic Signatures and Electronic Certificates Figure 7 is a sequence diagram showing an example of an operation process such as the generation of electronic signatures and electronic certificates performed by the electronic signature management system 100 according to the embodiment. In the following, we will explain using as an example a case in which an order is placed by a client company, which is an example of a user, to a receiving company, which is another example of a user, for goods and services provided by the receiving company. The user terminal 4 used by the receiving company will be referred to as user terminal 4A, and the user terminal 4 used by the client company will be referred to as user terminal 4B. In this case, it is assumed that the person in charge at the receiving company has created an electronic document D0 as an invoice for the goods and services to the client company. Note that the electronic document D0 may be created by user terminal 4A using the electronic document creation service provided by the management device 1, or it may be created using general document creation software that does not use such a creation service. Furthermore, the created electronic document D0 may be stored in the electronic document database 2 by the management device 1, or it may be stored by user terminal 4A in a storage unit accessible to user terminal 4A. Although the sequence diagram illustrates the case where the electronic signature management system 100 according to this embodiment handles an electronic document as electronic content, it is applicable not only to electronic documents but also to other electronic content such as electronic images.
[0055] When the user terminal 4A used by the person in charge of the contracting company receives an operation from the person in charge of the contracting company to instruct the signing of electronic document D0, it transmits the signature instruction for electronic document D0 to the management device 1 (S101). The management device 1 receives the signature instruction for electronic document D0 from the user terminal 4A (S102).
[0056] A signature instruction for electronic document D0 may include, for example, the data of electronic document D0 itself, or it may include information (such as a series ID) for identifying electronic document D0 stored in the electronic document database 2 or a storage unit accessible by the user terminal 4A. The signature instruction may also include, for example, any item recorded in the ledger system 3 (such as an item related to the person in charge at the receiving company). The signature instruction may also include, for example, the signature content entered by the person in charge at the receiving company. In the example shown in Figure 4, the signature content "I request payment" entered by the person in charge at the receiving company is shown.
[0057] Based on the signature instruction, the management device 1 generates an electronic signature S1 by the person in charge of the receiving company and also generates an electronic certificate (S103). Regarding the generation of the electronic certificate, the management device 1 generates a hash value of the electronic document D0 immediately before the electronic signature S1 is applied and includes this as the pre-signature hash value in the electronic certificate. The management device 1 also generates a hash value of the electronic document D1 after the electronic signature S1 has been applied and includes this as the post-signature hash value in the electronic certificate. The management device 1 also generates a hash value of the electronic document D0 that does not contain any electronic signature S and includes this as the original hash value in the electronic certificate. The management device 1 stores at least a portion of the generated electronic certificate (for example, the electronic certificate on the first line shown in Figure 4) in the first ledger system 3A, the second ledger system 3B, and the third ledger system 3C (S104).
[0058] The management device 1 generates an electronic document D1 by attaching the generated electronic signature S1 to the electronic document D0. Then, the management device 1 transmits the generated electronic document D1 to the user terminal 4A (S105). The user terminal 4A may store the received electronic document D1 in a storage unit accessible to the user terminal 4A.
[0059] User terminal 4A transmits the electronic document D1 to user terminal 4B used by the ordering company's representative in response to an operation by the receiving company's representative (S106). The transmission of the electronic document D1 to user terminal 4B may be performed via the management device 1. User terminal 4B receives the electronic document D1 (S107). User terminal 4B may store the received electronic document D1 in a storage unit accessible to user terminal 4B.
[0060] The person in charge at the ordering company appropriately checks the contents of the received electronic document D1 (the contents of the invoice) and then performs the operation to instruct the person in charge at the ordering company to sign electronic document D1. When the user terminal 4B receives this operation, it transmits the signature instruction for electronic document D1 to the management device 1 (S108). The management device 1 receives the signature instruction for electronic document D1 from the user terminal 4B (S109).
[0061] The signature instruction for electronic document D1 may include, for example, the data of electronic document D1 itself, or it may include information (such as a series ID) for identifying electronic document D1 stored in the electronic document database 2 or a storage unit accessible by the user terminal 4B. The signature instruction may also include, for example, any item recorded in the ledger system 3 (such as an item related to the person in charge at the ordering company). The signature instruction may also include, for example, the signature content entered by the person in charge at the ordering company. In the example shown in Figure 4, the signature content entered by the person in charge at the ordering company, "I will pay as per the invoice," is shown.
[0062] Based on the signature instruction, the management device 1 generates an electronic signature S2 by the person in charge of the ordering company and also generates an electronic certificate (S110). Regarding the generation of the electronic certificate, the management device 1 generates a hash value of the electronic document D1 immediately before the electronic signature S2 is applied and includes this as the pre-signature hash value in the electronic certificate. The management device 1 also generates a hash value of the electronic document D2 after the electronic signature S2 is applied and includes this as the post-signature hash value in the electronic certificate. The management device 1 also generates a hash value of the electronic document D0 that does not contain any electronic signature S and includes this as the original hash value in the electronic certificate. The management device 1 stores at least a portion of the generated electronic certificate (for example, the electronic certificate on the second line shown in Figure 4) in the first ledger system 3A, the second ledger system 3B, and the third ledger system 3C (S111).
[0063] The management device 1 may determine whether the content of electronic document D1 has been altered. That is, the management device 1 may determine whether the content of electronic document D1 to which the electronic signature S2 is to be applied has been altered from the content of electronic document D1 immediately after the previous electronic signature S1 was applied. For example, the management device 1 queries the ledger system 3 for the post-signature hash value of the electronic certificate on the first line shown in Figure 4 and the pre-signature hash value of the electronic certificate on the second line, compares them, and determines that if they match, electronic document D1 has not been altered; if they do not match, determines that electronic document D1 has been altered. The management device 1 may output the determination result by sending it to the user terminal 4B, etc. This makes it possible for the person in charge at the ordering company to confirm the continuity of the content of the target electronic document D1 when performing the electronic signature S2.
[0064] The management device 1 generates an electronic document D2 by attaching the generated electronic signature S2 to the electronic document D1. The management device 1 then transmits the generated electronic document D2 to the user terminal 4B (S112). The user terminal 4B may store the received electronic document D2 in a storage unit accessible to the user terminal 4B.
[0065] User terminal 4B transmits the electronic document D2 to user terminal 4A, which is used by the person in charge of the receiving company, in response to an operation by the person in charge of the ordering company (S113). The transmission of the electronic document D2 to user terminal 4A may be performed via the management device 1. User terminal 4A receives the electronic document D2 (S114). A notification of acceptance of payment may be transmitted from user terminal 4B to user terminal 4A, with or without the management device 1. User terminal 4A may store the received electronic document D2 in a storage unit accessible to user terminal 4A.
[0066] (3-2) Inquiry of Electronic Certificate Information Figure 8 is an operation flow diagram showing an example of the electronic certificate information inquiry process performed by the management device 1 according to the embodiment. The electronic certificate information inquiry process is a process of inquiring about desired electronic certificate information from a plurality of ledger systems 3 provided by the electronic signature management system 100. The electronic certificate information inquiry process may be performed at any time, for example, when a request for inquiry of electronic certificate information is received from a user terminal 4 or the like, or when a new electronic signature is generated for an electronic document (for example, at the timing of step S110 described above).
[0067] The response acquisition unit 18, for example, sends a request for electronic certificate information stored in each ledger system 3 to each ledger system 3, and acquires the electronic certificate information output by each ledger system 3 as a response to the request (S201). The response acquisition unit 18 may also perform this process in response to a request for inquiry of electronic certificate information from the user terminal 4.
[0068] The aggregate value calculation unit 19 calculates the aggregate value for each identical response included in multiple responses obtained from multiple ledger systems 3 by the response acquisition unit 18 by aggregating the coefficients associated with the ledger system 3 that output the response (S202).
[0069] The determination unit 20, for example, determines one of the multiple responses obtained from each ledger system 3 as the response that matches the electronic certificate information, based on the aggregated value calculated by the aggregated value calculation unit 19 (S203).
[0070] Here, using an electronic signature management system 100 having three ledger systems 3—a first ledger system 3A, a second ledger system 3B, and a third ledger system 3C—a specific example of a method for determining a single answer as a match for electronic certificate information by calculating aggregate values will be explained.
[0071]
[0072] For example, as shown in Table 1, suppose that in response to a request for a predetermined electronic certificate information, the response from the first ledger system 3A is "123", the response from the second ledger system 3B is "123", and the response from the third ledger system 3C is "456". Assume that the coefficients of the first ledger system 3A, the second ledger system 3B, and the third ledger system 3C are all "1".
[0073] In this case, the aggregate value calculation unit 19 calculates the aggregate value of answer "123" as "2," which is the sum of the coefficients of the ledger system 3 that output the answer, i.e., the sum of the coefficient "1" of the first ledger system 3A and the coefficient "1" of the second ledger system 3B. Also in this case, the aggregate value calculation unit 19 calculates the aggregate value of answer "456" as "1," which is the sum of the coefficients of the ledger system 3 that output the answer, i.e., the sum of the coefficients "1" of the third ledger system 3C. Then, the determination unit 20 determines that answer "123" is the answer that matches the electronic certificate information because the aggregate value "2" for answer "123" is the highest among the aggregate values of all the answers (answers "123" and answer "456").
[0074] Furthermore, when the coefficients of all ledger systems 3 are equal, such as when the coefficients of the first ledger system 3A, the second ledger system 3B, and the third ledger system 3C are all "1", then, in effect, one answer is determined as the answer that matches the electronic certificate information by a majority vote of the multiple ledger systems 3. Also, when the number of ledger systems 3 in the electronic signature management system 100 according to this embodiment is odd, in principle, the number of answers with the highest aggregate value is narrowed down to one, making it possible to efficiently determine the answer that matches the electronic certificate information.
[0075]
[0076] Furthermore, for example, as shown in Table 2, suppose that in response to a request for predetermined electronic certificate information, the response from the first ledger system 3A is "123", the response from the second ledger system 3B is "123", and the response from the third ledger system 3C is "456". We assume that the coefficient of the first ledger system 3A is "1", the coefficient of the second ledger system 3B is "1.5", and the coefficient of the third ledger system 3C is "3".
[0077] In this case, the aggregate value calculation unit 19 calculates the aggregate value of answer "123" as "2.5", which is the sum of the coefficients of the ledger system 3 that output the answer, i.e., the sum of the coefficient "1" of the first ledger system 3A and the coefficient "1.5" of the second ledger system 3B. Also in this case, the aggregate value calculation unit 19 calculates the aggregate value of answer "456" as "3", which is the sum of the coefficients of the ledger system 3 that output the answer, i.e., the sum of the coefficients "3" of the third ledger system 3C. Then, the determination unit 20 determines that answer "456" is the answer that matches the electronic certificate information because the aggregate value "3" for answer "456" is the highest among all the aggregate values of all the answers (answers "123" and answer "456").
[0078] The transmitting / receiving unit 21 transmits the response determined by the determination unit 20 as a response that matches the electronic certificate information to the user terminal 4 (S204).
[0079] (4) Note In the embodiments described above, the process for determining whether or not an electronic document (electronic content) has been altered is performed at the timing when an electronic signature is generated in response to a signature instruction (steps S110, S206, S214, S307). However, the process for determining whether or not an alteration has been altered is not limited to these timings, and may be performed, for example, at any timing at which the user requests a determination from the management device 1 via the user terminal 4. In this case, the user terminal 4 may, for example, receive information on the electronic signature that the user has designated as the target of the determination process, and include this information in the determination request and send it to the management device 1. The management device 1 compares the pre-signature hash value related to the designated electronic signature with the post-signature hash value of the electronic signature immediately preceding the designated electronic signature. If the two match, the management device 1 determines that the electronic document (electronic content) has not been altered at the time of the designated electronic signature; if the two do not match, the management device 1 determines that the electronic document (electronic content) has been altered at the time of the designated electronic signature.
[0080] The electronic signature management system 100 described above can also be applied when any user modifies the contents of a contract after it has been concluded. Specifically, for example, if a user needs to modify the contents of an already concluded contract (such as the delivery date or amount), the user terminal 4 performs an operation to acquire the relevant electronic document. As a result, the user terminal 4 acquires the relevant electronic document from the electronic document database 2 via the management device 1. Next, the user terminal 4 modifies the electronic document as appropriate according to the user's operation. Then, the user terminal 4 sends a signature instruction for the modified electronic document (modified electronic document) to the management device 1 according to the user's operation. The management device 1 generates an electronic signature for the modified electronic document and attaches it to the modified electronic document.
[0081] The modified electronic document with an electronic signature may, for example, be sent from the management device 1 to a user terminal 4 used by another user (such as a contracting party). The other user then confirms the contents of the modified electronic document displayed on the user terminal 4 and performs the electronic signature operation on the modified electronic document on the user terminal 4. The user terminal 4 sends a signature instruction to the management device 1, which generates the other user's electronic signature and further adds it to the modified electronic document (which already has the user's electronic signature). This makes it possible to modify the contract contents on the same electronic document file without, for example, exchanging a revised memorandum. With conventional electronic signatures, the original electronic signature could become invalid if the contents of the electronic document or the hash value based on it changed. On the other hand, in the electronic signature management system 100 according to this embodiment, even if the hash value of the electronic document changes due to the electronic signature, it is possible to confirm a series of electronic signatures that are associated with each other by a series ID (system identification information), making it possible to easily manage modifications to the contract contents.
[0082] The electronic signature management system 100 described above can verify a series of electronic signatures that are associated with each other by a series ID (system identification information), even if the hash value of the electronic content changes due to the electronic signature. Therefore, it can be applied to any electronic content where electronic signatures are expected to be applied sequentially, not just contracts. For example, the electronic signature management system 100 can be applied to signature campaigns in political activities, where multiple signatories sequentially apply electronic signatures to an electronic document of a signature list.
[0083] 1...Management device, 2...Electronic content database, 3, 3A, 3B, 3C...Ledger system, 4, 4A, 4B, 4C, 4D...User terminal, 11...Document management unit, 12...Instruction acquisition unit, 13...User information acquisition unit, 14...Signature generation unit, 15...Assignment unit, 16...Electronic certificate generation unit, 17...Electronic certificate information storage unit, 18...Response acquisition unit, 19...Aggregated value calculation unit, 20...Determination unit, 21...Transmission / reception unit, 41...Imaging unit, 42...Identifier acquisition unit, 43...Hash value calculation unit, 44...Consistency verification unit, 45...Output unit, 46...Operation reception unit, 47...Transmission / reception unit, 100...Electronic signature management system, N...Communication network, S...Electronic signature, D...Electronic content, D0, D1, D2...Electronic document
Claims
1. A management device for managing electronic signatures on electronic content, comprising: an acquisition unit for acquiring instructions for signing electronic content; a signature generation unit for generating an electronic signature in accordance with the instructions; an assignment unit for assigning the generated electronic signature to the electronic content; an electronic certificate generation unit for generating an electronic certificate relating to the electronic signature; an electronic certificate information storage unit for executing a process for storing electronic certificate information, which is at least a part of the electronic certificate, in each of a plurality of ledger systems; an answer acquisition unit for acquiring a plurality of answers, which are outputs from each of the plurality of ledger systems, by transmitting a request for the electronic certificate information stored in each of the plurality of ledger systems to each of the plurality of ledger systems; an aggregate value calculation unit for calculating an aggregate value for each of the identical answers included in the plurality of answers by aggregating coefficients associated with the ledger system that output the answer for each identical answer included in the plurality of answers; a determination unit for determining one of the plurality of answers as an answer that matches the electronic certificate information based on the aggregate value; and an output unit for outputting the one answer.
2. The management device according to claim 1, wherein the determination unit determines the response with the highest aggregate value as the single response.
3. The management device according to claim 1, wherein at least one of the plurality of ledger systems is a distributed ledger system.
4. The management device according to claim 1, wherein the coefficient is determined based on characteristic information indicating the characteristics of the ledger system.
5. The management device according to claim 4, wherein the characteristic information is determined based on at least one of the algorithm used by the ledger system for storing data and the number of nodes included in the ledger system.
6. The management device according to claim 1, wherein the coefficients associated with each of the plurality of ledger systems are equal.
7. The management device according to claim 6, wherein the number of the plurality of ledger systems is odd.
8. The management device according to claim 1, wherein the electronic content is an electronic document.
9. The management device according to claim 1, wherein the electronic certificate information is a hash value generated based on the electronic content.
10. A control method to be performed by a management device for managing electronic signatures on electronic content, comprising: a step of obtaining an instruction to sign electronic content; a step of generating an electronic signature in accordance with the instruction; a step of applying the generated electronic signature to the electronic content; a step of generating an electronic certificate relating to the electronic signature; a step of performing a process to store electronic certificate information, which is at least a part of the electronic certificate, in each of a plurality of ledger systems; a step of obtaining a plurality of responses, which are outputs from each of the plurality of ledger systems to the request, by transmitting a request for the electronic certificate information stored in each of the plurality of ledger systems to each of the plurality of ledger systems; a step of calculating an aggregate value for each of the identical responses included in the plurality of responses by aggregating coefficients associated with the ledger system that output the response for each identical response included in the plurality of responses; a step of determining one of the plurality of responses as a response that matches the electronic certificate information based on the aggregate value; and a step of outputting the one response.
11. A program for causing an information processing device to function as a management device for managing electronic signatures on electronic content, wherein the management device comprises: an acquisition unit for acquiring instructions for signing electronic content; a signature generation unit for generating an electronic signature in accordance with the instructions; an assignment unit for assigning the generated electronic signature to the electronic content; an electronic certificate generation unit for generating an electronic certificate relating to the electronic signature; an electronic certificate information storage unit for executing a process for storing electronic certificate information, which is at least a part of the electronic certificate, in each of a plurality of ledger systems; an answer acquisition unit for acquiring a plurality of answers, which are outputs from each of the plurality of ledger systems, by transmitting a request for the electronic certificate information stored in each of the plurality of ledger systems to each of the plurality of ledger systems; an aggregate value calculation unit for calculating an aggregate value for each of the identical answers included in the plurality of answers by aggregating coefficients associated with the ledger system that output the answer for each identical answer included in the plurality of answers; a determination unit for determining one of the plurality of answers as an answer that matches the electronic certificate information based on the aggregate value; and an output unit for outputting the one answer.
Citation Information
Patent Citations
Electronic signature system, electronic signature client, electronic signature program, server, and electronic signature method
JP2018067807A
Method for identity verification and system thereof
JP2024077561A
Management method of secrete data file, management system and proxy server therefor
JP2008250369A
Integrity protected capacity license counting
WO2018050229A1
Virtual blockchain system, data management method, and program
WO2019186747A1