Information processing system, information processing method, and program

The information processing system addresses the high frequency of commission certificate issuance and verification challenges by enabling broader and longer-term power of attorney delegation with electronic signatures, reducing burden and ensuring agent legitimacy verification.

WO2026083656A1PCT designated stage Publication Date: 2026-04-23HITACHI LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
HITACHI LTD
Filing Date
2025-07-01
Publication Date
2026-04-23

AI Technical Summary

Technical Problem

Existing electronic commissioning systems face challenges with the high frequency of issuing commission certificates and the need for frequent verification of agency content, leading to a burden on principals and uncertainty about the legitimacy of agent actions.

Method used

An information processing system that includes a principal device, counterparty device, and agent device, which allows for broader scope and longer duration of power of attorney delegation based on principal and agent attributes, reducing the frequency of certificate issuance and enabling accurate verification of agency content through electronic signatures.

Benefits of technology

Reduces the burden of issuing power of attorney and ensures accurate verification of agent legitimacy by allowing broader and longer-term delegation, thereby minimizing the frequency of certificate issuance and enhancing trust in agency actions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025023746_23042026_PF_FP_ABST
    Figure JP2025023746_23042026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention provides an information processing system, an information processing method, and a program capable of reducing the load of issuing a power of attorney and accurately confirming the validity of the content of agency performed by an agent. This information processing system includes a delegator device, a counterparty device, and an agent device, wherein: the delegator device includes a memory for storing a program, and a processor for executing processing in accordance with the program; and the processor executes the program to create a power of attorney having agency content with a wide delegation scope and a long delegation period in accordance with attributes of the delegator and the agent regarding authority delegated to the agent by the delegator, transmit the power of attorney to the agent device to issue the power of attorney to the agent, and, when receiving agency content data including information on the content of agency actions performed by the agent and an electronic signature for authenticating the counterparty and certifying the content of the agency content data from the counterparty device, verify the electronic signature and notify the delegator of the agency content.
Need to check novelty before this filing date? Find Prior Art

Description

Information Processing System, Information Processing Method, and Program

[0001] The present disclosure relates to an electronic commissioning technology for one party among two parties to commission an agent to perform an act on the other party.

[0002] Among organizations such as companies, one organization commissions a third party such as a business consignment destination to act as an agent for the business to be performed by the other organization. Also, among individuals such as family members or friends, one party may commission a third party to act as an agent for errands to be performed by the other party. When the principal commissions a third party as an agent, depending on the content of the commission, it may be necessary to issue a commission certificate or the like. For example, when a parent requests an adult child to act as an agent for administrative procedures, even if it is an agency appointment within the family, a commission certificate is required. In recent years, the principal has come to electronically issue a commission certificate to the agent using an electronic commissioning system. The electronic commission certificate includes an electronic signature for authenticating the principal and proving the content of the commission certificate in addition to the content of the commission certificate.

[0003] As an example of technology related to electronic commissioning, an electronic commission certificate creation device that guarantees the legitimacy of the relationship between the principal and the agent has been proposed (see, for example, Patent Document 1). When the electronic commission certificate creation device disclosed in Patent Document 1 receives a login, it verifies the electronic certificate of the logged-in person, and if the specified authentication information is correctly entered, determines that the logged-in person is a legitimate agent, and links the agent and the principal.

[0004] Japanese Patent Application Laid-Open No. 2023-15830

[0005] In electronic commissioning, when the principal issues a commission certificate each time the principal commissions an agent with authority, if the frequency of commissioning is high, the burden of issuing the commission certificate becomes heavy. Also, when the agent exercises the agency authority, the other party may want to confirm with the principal whether the agency content performed by the agent is legitimate. The device disclosed in Patent Document 1 has room for improvement regarding the frequency of issuing commission certificates and the method of confirming agency content.

[0006] One of the purposes included in this disclosure is to provide an information processing system, information processing method, and program that reduces the burden of issuing power of attorney and allows for accurate verification of the legitimacy of the representation provided by the agent.

[0007] An information processing system in one aspect included in this disclosure is an information processing system comprising a principal device operated by a principal, a counterparty device operated by a counterparty, and an agent device operated by an agent acting on behalf of the principal to the counterparty, wherein the principal device comprises a first memory for storing a first program and a first processor for executing processing according to the first program, the first processor, by executing the first program, creates a power of attorney with respect to the authority that the principal delegates to the agent, wherein the scope of the delegation is broader than a predetermined range and the delegation period is longer than a predetermined period, according to the attributes of the principal and the agent, transmits the power of attorney to the agent device for issuance to the agent, and receives from the counterparty device agency content data including information on the agency content performed by the agent, as well as an electronic signature that authenticates the counterparty and certifies the content of the agency content data, verifies the electronic signature, and notifies the principal of the received agency content.

[0008] According to one aspect included in this disclosure, the scope of the issued power of attorney is broad depending on the attributes of the principal and the agent, and the term of authorization is set for a long period, thus reducing the frequency of power of attorney issuance and alleviating the burden of issuing power of attorney for the principal. The principal can accurately verify the legitimacy of the authorization as the details of the authorization performed by the agent are notified from the counterparty device.

[0009] This is a configuration diagram showing an example of the configuration of an information processing system according to the embodiment. This is a diagram showing an example of the hardware configuration of each device of the information processing system shown in Figure 1. This is a sequence diagram showing an example of the registration process for the principal and the counterparty that the information processing system according to the embodiment performs to register the principal and the counterparty. This is a sequence diagram showing an example of the agent registration process that the information processing system according to the embodiment performs to register the agent. This is a sequence diagram showing an example of the power of attorney issuance process that the information processing system according to the embodiment performs to issue a power of attorney from the principal to the agent. This is a sequence diagram showing an example of the power of attorney presentation process and verification process that the information processing system according to the embodiment performs for the agent to present the power of attorney to the counterparty and have it verified. This is a sequence diagram explaining the agent content confirmation process that the information processing system according to the embodiment performs to send agent content data to the principal and have the principal confirm it. This is a diagram showing an example of the power of attorney issuance image displayed on the display device of the principal device in step S401 shown in Figure 5. This is a diagram showing an example of the power of attorney confirmation image displayed on the display device of the agent device in step S414 shown in Figure 5. This is a diagram showing an example of the operation image displayed on the display device of the agent device in step S507 shown in Figure 6, which displays the power of attorney for inputting agent content and selecting the power of attorney. Figure 6 shows an example of an image for confirming the agency details and power of attorney displayed on the display device of the other party's device in step S512. Figure 7 shows an example of an image for inputting agency details data displayed on the display device of the other party's device in step S601. Figure 7 shows an example of an image for confirming agency details data displayed on the display device of the principal's device in step S605. Figure 7 shows an example of an image for inputting confirmation data displayed on the display device of the principal's device in step S610. Figure 7 shows an example of an image for confirming confirmation data displayed on the display device of the other party's device in step S614.

[0010] Embodiments of the present invention will be described with reference to the drawings. The drawings and the following description are illustrative for illustrating the present invention and have been omitted and simplified as appropriate for clarity. The present invention can be implemented in various forms other than those described herein. Unless otherwise specified, each component may be singular or plural. In each drawing, the position, size, shape, and extent of each component may not represent the actual position, size, shape, and extent in order to facilitate understanding of the invention. Therefore, the present invention is not necessarily limited to the position, size, shape, and extent disclosed in the drawings.

[0011] This section outlines the information processing system of this embodiment. The information processing system of this embodiment is a system in which the principal, the counterparty, and the agent acting on behalf of the principal to the counterparty each operate an information processing device to perform electronic delegation and verification of agency details via a network. Before describing the information processing system of this embodiment in detail, the objects of information processing will be explained to make the characteristics of the information processing easier to understand. In this embodiment, the objects of information processing include power of attorney documents, agency details data, and verification data.

[0012] A power of attorney is data that represents the authority delegated by a principal to an agent. Specifically, a power of attorney includes, for example, a power of attorney ID (IDenifier), which is a unique identifier for each power of attorney, information about the principal and agent, the delegated authority, and information such as the scope and duration of the delegation. The principal and agent information may include, for example, the personal information of the principal and agent. The principal and agent information may also include the relationship between the principal and agent, as well as attribute information of the principal and agent. The relationship may be, for example, a parent-child relationship, or a workplace relationship, such as a boss-subordinate relationship. Attributes may be, for example, gender, age, job or occupation. The delegated authority may be, for example, contract procedures, payment procedures, or attendance at a meeting.

[0013] Information regarding the scope of delegation includes, for example, the target party to whom the agent's authority is valid, and the conditions under which the agent can exercise their authority. Conditions for exercising authority include, for example, the time period during which the authority can be exercised. If the authority is for payment procedures, conditions for exercising authority include, for example, the payment amount. The delegation period is the period during which the authority delegated to the agent by the principal is valid. The period during which the authority is valid is determined by the start date and end date of the delegation. The start date and end date are each expressed as specific dates. For example, if the start date of the delegation is April 1, 2024, and the end date of the delegation is December 31, 2025, the delegation period is from April 1, 2024 to December 31, 2025.

[0014] The agency details data is data containing information about the services rendered by the agent. This information may include, for example, the agent's information, the power of attorney presented by the agent to the other party, details and results of the services rendered by the agent, and the date on which the services were rendered by the agent based on the power of attorney. The agency details data may include not only the date but also the time of service. The confirmation data is data containing information about the results of the principal's confirmation of the agency details data received from the other party. In addition to the principal's confirmation results, the confirmation data may also include information about the agency details data.

[0015] An electronic signature is affixed to each of the power of attorney, the proxy details data, and the confirmation data. An electronic signature is a signature generated by the principal or the recipient using their private key with an arbitrary public-key cryptography or signature scheme on the data to which the electronic signature is affixed. The creation of the electronic signature is performed by an information processing device. By affixing an electronic signature to the target data, the principal or the recipient can prove the creator and legitimacy of the target data. An arbitrary public-key cryptography scheme is, for example, the RSA (Rivest-Shamir-Adleman) cryptography scheme. An arbitrary signature scheme is, for example, the "BBS + signature" scheme.

[0016] Hereafter, the principal's public key will be referred to as the principal's public key. The principal's private key will be referred to as the principal's private key. The agent's public key will be referred to as the agent's public key. The agent's private key will be referred to as the agent's private key. The other party's public key will be referred to as the other party's public key. The other party's private key will be referred to as the other party's private key.

[0017] The power of attorney, agency details data, and confirmation data can be represented in any data format or structure. Examples of data formats include tables, lists, XML (Extensible Markup Language), JSON (JavaScript Object Notation), or VC (Verifiable Credential).

[0018] An example of the procedure using the information processing system of this embodiment is as follows (a) to (e). The series of processes (a) to (e) are carried out by the principal, agent, and counterparty each operating the information processing device, but the explanation is omitted here. (a) The principal issues a power of attorney to the agent when issuing the power of attorney. (b) When the agent performs the agency, the agent presents the power of attorney to the counterparty for verification. (c) If the counterparty wishes to confirm the legitimacy and accuracy of the content of the agency performed by the agent, the counterparty creates agency content data and requests the principal to confirm the agency content data. (d) The principal confirms the agency content data and creates confirmation data including the confirmation result. (e) The counterparty confirms and verifies the confirmation data created by the principal. If there is any fraud in the content of the agency performed by the agent, the principal notifies the counterparty of this fact. If the principal deems it necessary in response to the notification from the counterparty, the principal may revoke the agent's authority. In this way, it is possible to prevent the agent from performing the principal's agency to the counterparty in a scope and for a period not intended by the principal.

[0019] <Overall Configuration of Information Processing System 9> Figure 1 is a configuration diagram showing one example of the configuration of an information processing system according to an embodiment. The information processing system 9 of this embodiment has a delegator device 1, an agent device 2, a counterparty device 3, a first server 4, and a second server 5. The delegator device 1, agent device 2, counterparty device 3, first server 4, and second server 5 are connected via a network 6. The network 6 is a network such as the Internet. The delegator device 1 is an information processing device operated by the delegator. The agent device 2 is an information processing device operated by the agent. The counterparty device 3 is an information processing device operated by the counterparty.

[0020] <Configuration of each device> (Delegator device 1) Delegator device 1 performs the delegator registration process. Delegator device 1 performs user authentication, power of attorney generation, signature generation for the power of attorney, verification of proxy content data, and signature verification of proxy content data as needed. User authentication is the process of identifying a user who has been registered in advance. Delegator device 1 performs verification data creation and signature generation for verification data as needed. Delegator device 1 has a delegator key generation unit 11, an authentication unit 12, a data generation unit 13, a data verification unit 14, a signature generation unit 15, a signature verification unit 16, and a database 17.

[0021] The delegator key generation unit 11 generates a delegator key pair consisting of the delegator's public key and the delegator's private key. The authentication unit 12 performs user authentication on the agent via the agent device 2. The data generation unit 13 generates a power of attorney to be issued to the agent. The data generation unit 13 retrieves data from the database 17, etc. The data generation unit 13 generates confirmation data to be sent to the counterpart device 3 as needed. When the data confirmation unit 14 receives the agent content data from the counterpart device 3, it confirms the content of the agent content data. If there is any fraud in the agent content, the data confirmation unit 14 performs processing to revoke the agent's authority as needed. The signature generation unit 15 generates an electronic signature for the power of attorney and confirmation data generated by the data generation unit 13 using the delegator's private key. The signature verification unit 16 verifies the electronic signature attached to the agent content data received from the counterpart device 3 as needed. The database 17 holds data such as the content of the power of attorney to be issued to the agent and the delegator's private key.

[0022] (Agent Device 2) Agent Device 2 performs agent registration processing. When the power of attorney is issued by the principal device 1, Agent Device 2 performs user authentication, power of attorney verification, and receipt of the power of attorney. When presenting the power of attorney to the other party, Agent Device 2 performs user authentication, creates data including the power of attorney to be presented to the other party, generates an electronic signature on the created data, and presents the data to the other party. Agent Device 2 may be a personal device such as a smartphone, or a shared device installed in a store or facility. Agent Device 2 has an agent key generation unit 21, an authentication unit 22, a signature generation unit 23, and a database 24.

[0023] The agent key generation unit 21 generates an agent key pair consisting of an agent public key and an agent private key. The authentication unit 22 performs user authentication on the principal via the principal device 1. The authentication unit 22 performs user authentication on the counterparty via the counterparty device 3. The authentication unit 22 performs user authentication on the second server 5. The signature generation unit 23 generates an electronic signature on the data, including the power of attorney, to be presented to the counterparty device 3, using the agent private key. The database 24 stores, for example, the agent private key and data related to the agent.

[0024] (Respondent Device 3) Respondent Device 3 performs the registration process for the counterparty. Respondent Device 3 performs user authentication and verification of data, including the power of attorney, received from Agent Device 2, as needed. Respondent Device 3 verifies the electronic signature for each of the multiple data received from other devices, as needed. Respondent Device 3 generates proxy content data, generates a signature for the proxy content data, and transmits the proxy content data to the delegator device 1, as needed. Respondent Device 3 verifies the confirmation data and signature received from the delegator device 1, as needed. Respondent Device 3 includes a counterparty key generation unit 31, an authentication unit 32, a data verification unit 33, a proxy content data generation unit 34, a signature generation unit 35, a signature verification unit 36, and a database 37.

[0025] The counterparty key generation unit 31 generates a counterparty key pair consisting of a counterparty public key and a counterparty private key. The authentication unit 32 performs user authentication on the agent via the agent device 2. The data verification unit 33 verifies the data including the power of attorney received from the agent device 2 and the verification data received from the principal device 1. The agent content data generation unit 34 generates agent content data containing information about the agent's actions. The signature generation unit 35 generates an electronic signature for the agent content data to be sent to the principal device 1 using the counterparty private key. The signature verification unit 36 ​​verifies the electronic signature attached to the data including the power of attorney received from the agent device 2 using the agent's public key. The signature verification unit 36 ​​verifies the electronic signature attached to the verification data received from the principal device 1 using the principal's public key. The database 37 holds, for example, data necessary for creating the agent content data and the counterparty private key.

[0026] (First Server 4) The first server 4 is a management server that manages the delegator's public key, the counterparty's public key, and the status of the power of attorney. The first server 4 stores the delegator's public key, the counterparty's public key, and the power of attorney ID of the issued power of attorney, along with the delegation period and the status of the power of attorney. The first server 4 transmits the counterparty's public key to the delegator device 1 upon the delegator's request. The first server 4 transmits information about the delegator's public key or the status of the power of attorney to the counterparty device 3 upon the counterparty's request. The status of the power of attorney may be, for example, "valid," indicating that the power of attorney is valid, or "expired" or "invalid," indicating that the power of attorney is not valid. These statuses of the power of attorney are examples and are not limited to these descriptions.

[0027] The first server 4 includes a data registration unit 41, a data acquisition unit 42, and a database 43. The data registration unit 41 registers the delegator's public key received from the delegator device 1 and the counterparty's public key received from the counterparty device 3 in the database 43. When the data registration unit 41 receives information such as the power of attorney ID, delegation period, and power of attorney status from the delegator device 1, it registers the information such as the delegation period and power of attorney status in the database 43 in correspondence with the power of attorney ID. The data acquisition unit 42 acquires information about the counterparty's public key from the database 43 in response to a request from the delegator device 1 and transmits the acquired information about the counterparty's public key to the delegator device 1. The data acquisition unit 42 acquires information about the delegator's public key and / or power of attorney status from the database 43 in response to a request from the counterparty device 3 and transmits the acquired information to the counterparty device 3. The database 43 holds the delegator's public key and the counterparty's public key, and holds information such as the delegation period and power of attorney status in correspondence with the power of attorney ID. The database 43 is a database of a trusted organization or a database where data tampering is difficult. The data registered in database 43 is managed, for example, by blockchain.

[0028] (Second Server 5) The second server 5 is a management server that manages the agent's public key and the power of attorney issued to the agent. The second server 5 holds the agent's public key and the power of attorney issued by the principal to the agent in a data storage area such as a wallet associated with the agent. The second server 5 registers the agent's public key and power of attorney data in the wallet at the agent's request. The second server 5 retrieves data from the wallet at the agent's request and transmits the retrieved data to the agent device 2. The wallet is a data storage area defined for each agent using agent information. The wallet stores agent public key and power of attorney data for each agent. Agent information is, for example, an agent ID, which is a different identifier for each agent. The wallet has any structure or format. The wallet may be implemented using, for example, a table or a list.

[0029] The second server 5 includes a data registration unit 51, an authentication unit 52, a data acquisition unit 53, and a database 54. The data registration unit 51 registers data such as the agent's public key and power of attorney in the wallet associated with the agent in the database 54. The authentication unit 52 performs user authentication on the agent via the agent device 2. The data acquisition unit 53 acquires the agent's public key or power of attorney data from the wallet associated with the agent in the database 54 in response to a request from the agent device 2, and transmits the acquired data to the agent device 2. The database 54 stores the agent's public key and power of attorney in the form of a wallet associated with the agent.

[0030] <Hardware Configuration Example> Figure 2 shows an example of the hardware configuration of each device in the information processing system shown in Figure 1. Since the hardware configuration of the second server 5 is the same as that of the first server 4, the example hardware configuration of the second server 5 is not shown in Figure 2.

[0031] As shown in Figure 2, the delegator device 1 has a processor 101a, memory 102a, input device 103a, display device 104a, communication device 105a, and storage device 106a. These components are connected via bus 107a. The agent device 2 has a processor 101b, memory 102b, input device 103b, display device 104b, communication device 105b, and storage device 106b. These components are connected via bus 107b. The partner device 3 has a processor 101c, memory 102c, input device 103c, display device 104c, communication device 105c, and storage device 106c. These components are connected via bus 107c. The first server 4 has a processor 101d, memory 102d, input device 103d, display device 104d, communication device 105d, and storage device 106d. These components are connected via bus 107d.

[0032] The hardware configurations of the delegator device 1, agent device 2, counterparty device 3, first server 4, and second server 5 are all the same. Therefore, the hardware configuration of the delegator device 1 will be described in detail, and detailed descriptions of the hardware configurations of the other devices will be omitted.

[0033] The input device 103a is a device for a user or operator to input instructions or data to the delegate device 1. The input device 103a is, for example, an input device such as a keyboard or mouse. The input device 103a includes a disk drive device that reads data from a recording medium such as an optical disc. The input device 103a may also be a biometric information acquisition device such as a camera or an infrared sensor. The biometric information acquisition device is a device that acquires the biometric information of the delegate. The biometric information may be, for example, a face, finger veins, fingerprints, or iris.

[0034] The display device 104a is a device that outputs the calculation results of various processes in a format that can be viewed by the user or operator. The display device 104a is, for example, a display. The display device 104a displays images and processing results for each process: registration of the delegator, issuance of a power of attorney, confirmation of the proxy content data, and creation of confirmation data. The communication device 105a is a network interface device that communicates with other devices according to a predetermined communication protocol. The storage device 106a is, for example, an HDD (Hard Disk Drive) or an SSD (Solid State Drive). The database 17 is built on the storage device 106a.

[0035] Memory 102a stores the program executed by processor 101a. Memory 102a is a non-volatile memory such as flash memory. The processor 101a may be a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit), but it may be any other semiconductor device that performs the predetermined processing.

[0036] The processor 101a executes a program stored in memory 102a, which causes the delegator key generation unit 11, authentication unit 12, data generation unit 13, data verification unit 14, signature generation unit 15, and signature verification unit 16 to operate. The processor 101a also controls the input device 103a, display device 104a, communication device 105a, and storage device 106a by executing a program stored in memory 102a. The program executed by the processor 101a does not necessarily have to be pre-stored in memory 102a. For example, the program may be installed into memory 102a via the input device 103a from a recording medium that pre-stores the program.

[0037] The hardware configuration of the delegator device 1 has been described, but in the agent device 2, the counterparty device 3, the first server 4, and the second server 5, the processor executes a program stored in memory, causing multiple functional units in each device to operate. For example, the processor 101b executes a program stored in memory 102b, causing the agent key generation unit 21, the authentication unit 22, and the signature generation unit 23 to operate. The display device 104b displays images and processing results for the agent registration, power of attorney receipt, and power of attorney presentation processes. The display device 104c displays images and processing results for the counterparty registration, power of attorney verification, agent content data creation, and confirmation data verification processes. Furthermore, the multiple functional units in each device shown in Figure 1 may operate when a program is installed on an information processing device such as a personal computer or server, and the program is executed by a processor in the information processing device.

[0038] <Operation of Information Processing System 9> The operation of the information processing system 9 in this embodiment will be explained with reference to Figures 3 to 7. Specifically, the registration process for the principal and the counterparty will be explained with reference to Figure 3. The agent registration process will be explained with reference to Figure 4. The power of attorney issuance process will be explained with reference to Figure 5. The power of attorney presentation and verification processes will be explained with reference to Figure 6. The agent details confirmation process will be explained with reference to Figure 7.

[0039] (Registration Process for Delegator and Counterparty) Figure 3 is a sequence diagram showing an example of the registration process for the delegator and counterparty that the information processing system according to the embodiment performs to register the delegator and counterparty. The processing of each step shown in Figure 3 will be described below.

[0040] In step S201, the delegator key generation unit 11 of the delegator device 1 generates a delegator key pair consisting of the delegator's public key and delegator's private key. The delegator key pair is generated by performing a key pair generation process of a general-purpose cryptographic library, for example, using a key pair generation process in any public-key cryptography or signature scheme. At this time, the delegator key generation unit 11 may generate the key pair by inputting information such as a PIN or password as a seed into the key pair generation process. A biometric information acquisition device such as a camera or infrared sensor may be connected to the input device 103a of the delegator device 1. In this case, the delegator key generation unit 11 may generate a key pair consisting of the delegator's private key and delegator's public key, and auxiliary information as necessary, from the delegator's biometric information acquired via the biometric information acquisition device, based on a predetermined algorithm. The predetermined algorithm is, for example, Fuzzy Extractor or Fuzzy Signature. Auxiliary information means information used to derive information necessary for predetermined information processing. In this embodiment, a detailed explanation of the auxiliary information is omitted.

[0041] In step S202, the delegator key generation unit 11 securely stores the delegator private key generated in step S201 using any storage method. For example, the delegator key generation unit 11 stores the delegator private key in the database 17. The delegator key generation unit 11 may also securely store the delegator private key in a storage medium such as a USB (Universal Serial Bus) or IC (Integrated Circuit) card, or in another terminal. Furthermore, if the delegator key generation unit 11 generated a delegator key pair in step S201 based on a PIN, password, or biometric information, it may save auxiliary information in the database 17, a storage medium, or another terminal as needed. In this case, the delegator key generation unit 11 may delete the delegator private key from memory 102a.

[0042] In step S203, the delegator key generation unit 11 transmits the delegator public key generated in step S201 to the first server 4 via the network 6. The first server 4 receives the delegator public key from the delegator device 1. At this time, the delegator device 1 may specify an identifier for the delegator public key and transmit the identifier along with the delegator public key to the first server 4. The identifier for the delegator public key is, for example, a delegator ID, which is a different identifier for each delegator. The following explanation will describe the case where the identifier for the delegator public key is the delegator ID. In step S204, the data registration unit 41 of the first server 4 registers and stores the delegator public key received in step S203 in the database 43. If the data registration unit 41 received the delegator ID along with the delegator public key in step S203, it stores the delegator public key in the database 43 in association with the received delegator ID.

[0043] In steps S205 to S208, the remote device 3 and the first server 4 perform the same processing as in steps S201 to S204. In step S205, the remote key generation unit 31 of the remote device 3 generates a remote key pair of a remote public key and a remote private key for an arbitrary public key cryptography and signature scheme. In step S206, the remote key generation unit 31 securely stores the remote private key in an arbitrary manner. In step S207, the remote key generation unit 31 transmits the remote public key to the first server 4 via the network 6. In step S208, the data registration unit 41 of the first server 4 registers and stores the remote public key in the database 43. When the data registration unit 41 receives the remote public key identifier along with the remote public key, it stores the remote public key in the database 43 in association with the received identifier, similar to step S204. The remote public key identifier is, for example, a remote ID, which is a different identifier for each remote. The following explanation will describe the case where the remote public key identifier is the remote ID.

[0044] Referring to FIG. 3, although the registration processes for the delegator's public key and the counterpart's public key are shown in the same processing flow, these registrations may be performed separately. For example, after the delegator device 1 and the first server 4 execute the processes of steps S201 to S204, on another day, the counterpart device 3 and the first server 4 may execute the processes of steps S205 to S208. Also, either steps S201 to S204 or steps S205 to S208 may be performed first, or they may be performed simultaneously. The delegator device 1 may execute step S202 at any time after step S201. The counterpart device 3 may execute step S206 at any time after step S205.

[0045] (Agent registration process) FIG. 4 is a sequence diagram showing an example of an agent registration process executed by the information processing system according to the embodiment to register an agent. The processing of each step shown in FIG. 4 will be described below.

[0046] In step S301, agent information for identifying an agent who is a user of the agent device 2 is input by the agent to the agent device 2. The agent information may be automatically generated according to a predetermined procedure by the processor 101b executing a program. In step S302, the agent key generation unit 21 generates an agent key pair of an agent public key and an agent private key of the agent. Since the method of generating the key pair is the same as the method described in step S201, a detailed description thereof is omitted. In step S303, the agent key generation unit 21 transmits the agent information input in step S301 and the agent public key generated in step S302 to the second server 5 via the network 6. If necessary, the agent key generation unit 21 also transmits auxiliary information to the second server 5 via the network 6.

[0047] The second server 5 receives the agent information and the agent public key from the agent device 2. When the agent device 2 transmits the auxiliary information to the second server 5, the second server 5 also receives the auxiliary information. In step S304, the data registration unit 51 of the second server 5 creates a wallet corresponding to the agent information received in step S303. The data registration unit 51 registers the created wallet in the database 54. In step S305, the data registration unit 51 registers the agent public key received in step S303 in the wallet created in step S304. When the agent device 2 transmits the auxiliary information to the second server 5 in step S303, the data registration unit 51 also registers the auxiliary information in the wallet. In step S306, the agent key generation unit 21 of the agent device 2 securely stores the agent secret key generated in step S301 by any method. Since the storage method is the same as the method described in step S202, its detailed description is omitted.

[0048] (Power of Attorney Issuance Process) FIG. 5 is a sequence diagram showing an example of a power of attorney issuance process executed by the information processing system according to the embodiment to issue a power of attorney from a principal to an agent. Hereinafter, the processing of each step shown in FIG. 5 will be described.

[0049] In step S401, the data generation unit 13 of the principal device 1 generates a power of attorney to be issued from the principal to the agent. The power of attorney is generated, for example, based on the content input by the principal operating the principal device 1. The power of attorney may be automatically generated based on the information stored in the database 17 according to a predetermined procedure by the processor 101a executing a program. It is desirable that the scope of authorization is wider than a predetermined scope. Also, it is desirable that the term of authorization is longer than a predetermined period. The reason is that the number of power of attorney issuances is reduced, and the burden on the principal for issuing the power of attorney is reduced.

[0050] An example of how to determine the scope and duration of a power of attorney is described below. Memory 102a stores either or both of the following as information about the principal and agent: the relationship between the principal and the agent, and the respective attributes of the principal and the agent. Processor 101a determines the scope and / or duration of the power of attorney based on the information about the principal and the agent.

[0051] For example, suppose memory 102a stores information that the principal and agent are colleagues at the same company. In this case, processor 101a sets the scope of delegation to a predetermined standard range and the delegation period to a predetermined standard period. On the other hand, suppose memory 102a stores information that the principal and agent are employees at the same company, and the agent is the principal's superior. In this case, processor 101a sets the scope of delegation to a wider range than the standard range and the delegation period to a longer period than the standard period. Also suppose memory 102a stores information that the principal is in his 20s and the agent is in his 50s as attributes of the principal and agent. In this case, processor 101a sets the scope of delegation to a wider range than the standard range and the delegation period to a longer period than the standard period. In this way, the scope of delegation and the delegation period are automatically determined according to the relationship between the principal and agent. The scope of delegation and the delegation period are automatically determined according to the respective attributes of the principal and agent.

[0052] In step S401, the data generation unit 13 assigns a power of attorney ID to the generated power of attorney. Furthermore, if the delegator device 1 has specified the delegator ID as the identifier for the delegator's public key in steps S203 and S204, and has registered the delegator ID along with the delegator's public key in the first server 4, the delegator ID may also be included in the power of attorney.

[0053] In step S402, the data generation unit 13 obtains the delegator's private key generated in step S201. The data generation unit 13 obtains the delegator's private key based on the private key storage method performed in step S202. The data generation unit 13 obtains the delegator's private key from the database 17 of the delegator device 1. If the delegator's private key is stored on a storage medium such as a USB or IC card, or on another terminal, the data generation unit 13 obtains the delegator's private key from the storage location. Also, if the delegator key pair was generated in step S201 based on a PIN, password, or biometric information, the data generation unit 13 generates and obtains the delegator's private key in the same way as in step S201. At this time, if auxiliary information is required for the generation of the delegator's private key, the data generation unit 13 appropriately obtains the auxiliary information from, for example, the database 17, the storage medium, or another terminal.

[0054] In step S403, the signature generation unit 15 generates an electronic signature on the power of attorney generated in step S401 using the principal's private key and attaches the generated electronic signature to the power of attorney. The power of attorney and the electronic signature may be data that integrates the power of attorney and the electronic signature, or they may be separate data that are associated with each other. For the sake of simplicity, in the following explanation, the data to which the electronic signature is attached to the power of attorney will be described as data that integrates the power of attorney and the electronic signature. This also applies when an electronic signature is attached to data other than the power of attorney. Furthermore, if the principal device 1 specifies the principal ID as the identifier of the principal's public key in steps S203 and S204, and registers the principal ID together with the principal's public key in the first server 4, the principal ID may be associated with the electronic signature. In step S404, the data generation unit 13 transmits information that the power of attorney is being issued to the agent device 2 via the network 6 in order to notify the agent of the issuance of the power of attorney.

[0055] In step S405, agent information is input to the agent device 2 by the agent. The agent information may be automatically input by the processor 101b executing a program according to a predetermined procedure. In step S406, the agent device 2 transmits the agent information input in step S405 to the second server 5 via the network 6. The second server 5 receives the agent information from the agent device 2. In step S407, the authentication unit 52 of the second server 5 identifies the wallet corresponding to the agent information received in step S406 and obtains the agent's public key from the identified wallet. At this time, if auxiliary information is registered in the wallet along with the agent's public key, the authentication unit 52 obtains the auxiliary information from the wallet along with the agent's public key and transmits the auxiliary information to the agent device 2.

[0056] In step S408, the authentication unit 22 of the agent device 2 acquires the agent's private key based on the method for storing the private key performed in step S306. The method for acquiring the private key is the same as the method described in step S402, so a detailed explanation is omitted. In step S409, the authentication unit 52 of the second server 5 performs user authentication on the agent device 2. During the authentication process, the authentication unit 22 of the agent device 2 uses the agent's private key. During the authentication process, the authentication unit 52 of the second server 5 uses the agent's public key. An example of the user authentication method is described below. The authentication unit 52 of the second server 5 generates a challenge such as a random number and sends it to the agent device 2. The authentication unit 22 of the agent device 2 generates an electronic signature using the agent's private key in response to the challenge received from the second server 5. The authentication unit 22 sends the generated electronic signature to the second server 5. The authentication unit 52 of the second server 5 verifies the signature of the electronic signature received from the agent device 2 using the agent's public key. If user authentication in step S409 is successful, the second server 5 proceeds to the next step, S410. If user authentication in step S409 fails, the second server 5 terminates the process. By performing user authentication on the agent, the second server 5 can confirm that the user attempting to access the wallet corresponding to the agent information managed by the second server 5 is indeed the agent.

[0057] In step S410, the data acquisition unit 53 of the second server 5 transmits the agent's public key acquired in step S407 to the agent device 2 via the network 6. The agent device 2 receives the agent's public key from the second server 5. In step S411, the agent device 2 transmits the agent's public key to the delegator device 1 via the network 6. The delegator device 1 receives the agent's public key from the agent device 2. In step S412, the authentication unit 12 of the delegator device 1 performs user authentication on the agent device 2. During the authentication process, the authentication unit 12 of the delegator device 1 uses the agent's public key received in step S411. During the authentication process, the authentication unit 22 of the agent device 2 uses the agent's private key. By performing user authentication on the agent, the delegator device 1 can verify the agent's identity. The method of user authentication is the same as the method described in step S409, so a detailed explanation is omitted. If user authentication in step S412 is successful, the delegator device 1 proceeds to the next step, S413. If user authentication in step S412 fails, the delegator device 1 terminates the process.

[0058] In step S413, the principal device 1 transmits the power of attorney, to which an electronic signature has been added by the processing in step S403, to the agent device 2 via the network 6. The agent device 2 receives the power of attorney from the principal device 1. In step S414, the agent device 2 prompts the agent operating the agent device 2 to confirm the contents of the power of attorney received in step S413. Specifically, the agent device 2 identifies information such as the principal and agent's information, the delegated authority, the scope of the delegation, and the delegation period from the received power of attorney through data processing, and displays the identified information on the display device 104b. The agent confirms the contents of the power of attorney displayed on the display device 104b. If the contents of the power of attorney are correct as a result of step S414, the agent device 2 proceeds to the next step S415 when the agent inputs information indicating that the power of attorney is correct. On the other hand, if there is an error in the contents of the power of attorney as a result of step S414, the agent device 2 stops processing when the agent inputs information indicating that there is an error in the contents of the power of attorney.

[0059] In step S415, the agent device 2 transmits agent information and power of attorney to the second server 5 via the network 6. The second server 5 receives the agent information and power of attorney from the agent device 2. In step S416, the agent device 2 transmits information that it has received the power of attorney to the principal device 1 via the network 6. In step S417, the second server 5 identifies the wallet corresponding to the agent information received in step S415 and registers the power of attorney in the identified wallet.

[0060] In step S418, the delegator device 1 transmits the power of attorney ID and delegation period information generated in step S401 to the first server 4 via the network 6. The first server 4 receives the power of attorney ID and delegation period information from the delegator device 1. In step S419, the data registration unit 41 of the first server 4 registers the power of attorney ID and delegation period information received in step S418 into the database 43. The data registration unit 41 registers the delegation period and the status of the power of attorney in the database 43, corresponding to the power of attorney ID. The data registration unit 41 registers information associating the power of attorney ID with the delegator ID in the database 43 so that the delegator and the delegator's public key can be identified from the power of attorney ID. If the date on which the power of attorney ID and delegation period information was registered falls within the delegation period, the data registration unit 41 registers the status of the power of attorney as "valid" in the database 43. In step S420, the delegator device 1 securely stores the delegator's private key obtained in step S402 using any storage method. In step S421, the agent device 2 securely stores the agent's private key obtained in step S408 using a storage method of its choice. The method for storing the private key is the same as the method described in step S202, so a detailed explanation is omitted.

[0061] In the sequence diagram shown in Figure 5, the delegator device 1 may execute the process in step S420 at any time after performing the process in step S403. The agent device 2 may execute the process in step S421 at any time after performing the process in step S415. Furthermore, the delegator device 1 may execute the processes in steps S401 to S403 of the above-described power of attorney issuance process flow between steps S412 and S413. In this case, in step S411, the agent device 2 may send information about the agent along with the agent's public key as reference information to the delegator device 1. Also, if the delegator device 1 executes the processes in steps S401 to S403 between steps S412 and S413, the process in step S404 may be omitted. In this case, for example, in step S411, the agent operates the agent device 2 to cause the agent device 2 to execute the process of sending power of attorney issuance application data to the delegator device 1 indicating that the agent is applying to the delegator for the issuance of a power of attorney.

[0062] If the delegator device 1 executes the processes in steps S401 to S403 between steps S412 and S413, it is possible that several hours to several days may pass between the execution of step S412 and the execution of step S413. For example, after the delegator device 1 has completed the process in step S412, the delegator may spend several hours to several days creating the necessary documents for the power of attorney generated in step S401 and verifying the contents of the power of attorney. In this case, to prevent information leakage, such as the leakage of the agent's private key from the memory 102b of the agent device 2, it is desirable for the agent device 2 to delete the agent's private key from memory 102b after a certain period of time has elapsed since the authentication process in step S412. If the agent device 2 has deleted the agent's private key from memory 102b after step S412, it may simply re-execute the processes in steps S405 to S412 before performing the process in step S413.

[0063] (Power of Attorney Presentation and Verification Process) Figure 6 is a sequence diagram showing an example of the power of attorney presentation and verification process performed by the information processing system according to the embodiment when an agent presents a power of attorney to the other party for verification. The processing of each step shown in Figure 6 will be described below. The processing of steps S501 to S505 shown in Figure 6 is the same as the processing of steps S405 to S409 in the power of attorney issuance process, so a detailed explanation will be omitted.

[0064] The data acquisition unit 53 of the second server 5 acquires a power of attorney from the wallet associated with the agent information received in step S502. In step S506, the data acquisition unit 53 transmits the power of attorney and the agent's public key to the agent device 2 via the network 6. The agent device 2 receives the power of attorney and the agent's public key from the second server 5. At this time, the second server 5 may acquire all powers of attorney registered in the wallet associated with the agent information and transmit them to the agent device 2, or it may acquire only specific powers of attorney and transmit them to the agent device 2. If the second server 5 transmits only specific powers of attorney to the agent device 2, it receives a designation of the power of attorney from the agent device 2 before processing in step S506. The designation of the power of attorney is made by input by the agent to the agent device 2. The designation of the power of attorney may also be made automatically from the agent device 2 to the second server 5 according to a predetermined procedure by the processor 101b executing a program.

[0065] In step S507, the agent device 2 creates presentation data, which is data to be presented to the other party, based on the power of attorney received in step S506. The presentation data includes information that identifies the power of attorney in question and information regarding the scope of agency. As mentioned above, the information regarding the scope of agency includes, for example, information about the agent, the power of attorney issued by the principal to the agent, details of the scope of agency performed by the agent, and information on the date on which the scope of agency performed by the agent is carried out. If the power of attorney contains all the necessary information, the agent device 2 may use the power of attorney as the presentation data. Furthermore, if the electronic signature attached to the power of attorney is created using a signature method that enables the presentation and verification of partial data by zero-knowledge proof, such as the "BBS + signature" method, the agent device 2 may create the presentation data based only on the necessary information.

[0066] The signature generation unit 23 generates an electronic signature to be attached to the presented data using the agent's private key obtained in step S504. In step S508, the signature generation unit 23 attaches the generated electronic signature to the presented data. The method for attaching the electronic signature to the presented data is the same as the method described in step S403, so a detailed explanation is omitted. In step S509, the agent device 2 transmits the agent's public key received in step S506 to the counterpart device 3 via the network 6. The counterpart device 3 receives the agent's public key from the agent device 2.

[0067] In step S510, the authentication unit 32 of the remote device 3 performs user authentication on the agent device 2. During the authentication process, the authentication unit 32 of the remote device 3 uses the agent's public key received in step S509. During the authentication process, the authentication unit 22 of the agent device 2 uses the agent's private key obtained in step S504. By performing user authentication on the agent, the remote device 3 can verify the agent's identity. The method of user authentication is the same as the method described in step S409, so a detailed explanation is omitted. If the user authentication in step S510 is successful, the agent device 2 proceeds to the next step, S511. If the user authentication in step S510 fails, the agent device 2 terminates the process.

[0068] In step S511, the agent device 2 transmits the presentation data, to which an electronic signature has been added by the processing in step S508, to the counterpart device 3 via the network 6. The counterpart device 3 receives the presentation data from the agent device 2. The data verification unit 33 of the counterpart device 3 performs data processing on the presentation data received in step S511 and obtains information such as a power of attorney from the presentation data. In step S512, the data verification unit 33 has the counterpart confirm the information regarding the contents of the power of attorney and the details of the agency obtained from the presentation data. Specifically, the data verification unit 33 displays the contents of the power of attorney and the information regarding the agency on the display device 104c. If the presentation data includes information that identifies the principal, such as the identifier of the principal's public key, the data verification unit 33 confirms the information that identifies the principal. If the counterpart device 3 receives a response from the counterpart indicating that there are no problems with the confirmed information, it proceeds to the next step S513. On the other hand, if the counterpart device 3 receives a response from the counterpart indicating that there are problems with the confirmed information, it terminates the process.

[0069] In step S513, the signature verification unit 36 ​​verifies the electronic signature of the presented data received in step S511 using the agent's public key received in step S509. If the signature verification is successful, the counterparty device 3 proceeds to the next step S514. If the signature verification fails, the counterparty device 3 terminates the process. In step S514, the counterparty device 3 requests the principal's public key and the status of the power of attorney from the first server 4 via the network 6, based on the information confirmed by the user in step S512. The counterparty device 3 may also send information about the power of attorney ID to the first server 4 so that the first server 4 can identify the power of attorney being requested. In addition, the counterparty device 3 sends information about the date on which the agent performed the proxy duties to the first server 4 along with the above request so that the first server 4 can determine whether or not the power of attorney falls within the proxy period.

[0070] When the data acquisition unit 42 of the first server 4 receives the power of attorney ID and information on the date the agency was performed from the counterparty device 3, it checks the power of attorney period registered in accordance with the power of attorney ID. If, as a result of checking the power of attorney period, the date the agency was performed does not fall within the power of attorney period, the data acquisition unit 42 updates the status of the power of attorney from "valid" to "expired" or "invalid". On the other hand, if, as a result of checking the power of attorney period, the date the agency was performed falls within the power of attorney period, the data acquisition unit 42 maintains the status of the power of attorney as "valid". In step S515, in response to a request from the counterparty device 3, the data acquisition unit 42 obtains from the database 43 the delegator's public key for the delegator ID identified by the power of attorney ID and information on the updated status of the power of attorney corresponding to the power of attorney ID. In step S516, the data acquisition unit 42 transmits the delegator's public key and the status of the power of attorney obtained in step S515 to the counterparty device 3 via the network 6. The counterparty device 3 receives the information on the delegator's public key and the status of the power of attorney from the first server 4.

[0071] In step S517, the data verification unit 33 of the counterparty device 3 verifies the status information of the power of attorney received in step S516. If the status of the power of attorney is "valid", the counterparty device 3 proceeds to the next step, S518. If the status of the power of attorney is "expired" or "invalid", the counterparty device 3 cancels the process. The counterparty device 3 can confirm whether the status of the power of attorney is valid, expired, or invalid. The counterparty device 3 may display the confirmation result on the display device 104c. In this case, the counterparty can determine whether the action by the agent is legitimate or not. If the status of the power of attorney is "expired" or "valid", and the counterparty wants to confirm the details of the agency with the principal, they may have the counterparty device 3 proceed to the process in step S518.

[0072] In step S518, the signature verification unit 36 ​​of the counterparty device 3 verifies the electronic signature of the power of attorney in the presented data using the delegator's public key received in step S516. If the signature verification is successful, the signature verification unit 36 ​​displays information on the display device 104c indicating that the signature verification of the power of attorney was successful. If the signature verification fails, the signature verification unit 36 ​​displays information on the display device 104c indicating that the signature verification failed. In step S519, the agent device 2 securely stores the agent's private key obtained in step S504 using any storage method. The storage method is the same as the method described in step S202, so a detailed explanation is omitted. The agent device 2 may execute the process in step S519 at any time after the processing in step S510.

[0073] In step S514 of the above-described power of attorney presentation and verification process flow, the case in which the counterparty device 3 requests the status of a specific power of attorney from the first server 4 based on the information confirmed by the user in step S512 was described, but this is not limited to this case. The counterparty device 3 may also request the status of all powers of attorney registered in the first server 4 for the same delegate. In step S514, the counterparty device 3 sends the delegate ID to the first server 4 along with information indicating that it is requesting the status of all powers of attorney. In step S515, the first server 4 identifies all power of attorney IDs associated with the delegate ID received from the counterparty device 3. For each power of attorney corresponding to all power of attorney IDs, the first server 4 checks the delegation period and updates the status of the power of attorney as necessary for the confirmed delegation period. After updating the status of the power of attorney as necessary, the first server 4 obtains information on the status of all powers of attorney. In step S516, the first server 4 sends the information on the status of all powers of attorney to the counterparty device 3.

[0074] If the remote device 3 requests the status of only specific powers of attorney from the first server 4, there is a disadvantage that the powers of attorney that the remote device wants to check will be recognized by the first server 4. On the other hand, there is an advantage that the processing time at the first server 4 and the amount of data communicated between the remote device 3 and the first server 4 are reduced. Conversely, if the remote device 3 requests the status of all powers of attorney from the first server 4, there is an advantage that the powers of attorney that the remote device wants to check will not be recognized by the first server 4. On the other hand, there is a disadvantage that the processing time at the first server 4 and the amount of data communicated between the remote device 3 and the first server 4 increase in proportion to the number of powers of attorney registered at the first server 4.

[0075] (Confirmation of Agent Details) This section describes the operation of the information processing system 9 when the other party wishes to confirm with the principal the details of the agent's actions taken by the agent. Figure 7 is a sequence diagram illustrating the confirmation of agent details process performed by the information processing system according to the embodiment to send agent details data to the principal and obtain confirmation from the principal. The processing of each step shown in Figure 7 will be described below.

[0076] In step S601, the proxy content data generation unit 34 of the counterparty device 3 creates proxy content data to be sent to the principal based on the proxy content performed by the proxy. The proxy content data is created, for example, based on the content entered into the counterparty device 3 by the counterparty. The proxy content data may also be automatically created by the processor 101c executing a program according to a predetermined procedure based on the information held in the database 37. Furthermore, if the counterparty device 3 has specified the counterparty ID as the identifier of the counterparty public key in steps S207 and S208 shown in Figure 3, and has registered the counterparty ID together with the counterparty public key in the first server 4, the counterparty ID may also be included in the proxy content data. In step S602, the counterparty device 3 obtains the counterparty private key based on the private key storage method performed in step S206. The method for obtaining the private key is the same as the method described in step S402, so a detailed explanation is omitted.

[0077] In step S603, the signature generation unit 35 generates an electronic signature for the proxy content data using the counterparty's private key obtained in step S602, and attaches the generated electronic signature to the proxy content data. The method for attaching the electronic signature to the proxy content data is the same as the method described in step S403, so a detailed explanation is omitted. In step S604, the counterparty device 3 transmits the proxy content data to which the electronic signature was attached in step S603 to the principal device 1 via the network 6. The principal device 1 receives the proxy content data from the counterparty device 3. The data verification unit 14 of the principal device 1 performs data processing and other processing on the proxy content data received in step S604 to obtain information about the proxy performed by the agent from the proxy content data. In step S605, the data verification unit 14 has the principal confirm the information about the proxy performed by the agent. Specifically, the data verification unit 14 displays the information about the proxy performed by the agent on the display device 104a. If the proxy data contains the identifier of the counterparty's public key, the data verification unit 14 verifies whether the identifier of the counterparty's public key is a legitimate counterparty ID.

[0078] In this embodiment, the data verification unit 14 has been described as informing the principal of the agency information by displaying the information contained in the agency content data on the display device 104a. However, the method of informing the principal of the information is not limited to this method. For example, if the principal device 1 has a speaker that outputs sound, the data verification unit 14 may inform the principal of the agency information by voice via the speaker.

[0079] In step S605, if the principal determines that there are no problems such as fraud with respect to the agency information, the principal inputs a response to the principal device 1 indicating that there are no problems with the agency information. Upon receiving the response that there are no problems with the agency information, the principal device 1 proceeds to the next step, S606. On the other hand, if the principal determines in step S605 that there are problems such as fraud with respect to the agency information, the principal performs a status check. A status check is, for example, when the principal confirms the details of the agency act performed by the agent using written documents or telephone or other means of communication with the agent and / or the other party. This status check may be performed after step S609, which will be explained later.

[0080] If the principal determines, after reviewing the situation, that there are no problems with the actions taken by the agent, the principal inputs the information of the reviewed actions into the principal device 1. If the principal determines, after reviewing the situation, that there are problems such as fraud with the actions taken by the agent, the principal inputs a response indicating that there are problems with the actions into the principal device 1. When the principal device 1 receives a response indicating that there are problems with the actions, it sends update request information to the first server 4 to update the power of attorney ID and status of the power of attorney to "expired" or "invalid," if necessary. When the first server 4 receives the update request information from the principal device 1, it updates the status of the power of attorney registered in accordance with the power of attorney ID to "expired" or "invalid." As a result, the authority granted by the power of attorney used is revoked from the agent. If the actions have already been taken by an agent without the necessary authority, those actions are treated as invalid.

[0081] In step S606, the delegator device 1 requests the counterparty's public key from the first server 4 via the network 6, based on the information confirmed by the delegator in step S605. For example, the delegator device 1 sends information to the first server 4 including a request for the counterparty's public key and the counterparty ID. In step S607, the data acquisition unit 42 of the first server 4 acquires the counterparty's public key requested by the delegator device 1 in step S606 from the database 43. Specifically, the data acquisition unit 42 acquires the counterparty's public key corresponding to the counterparty ID from the database 43. In step S608, the data acquisition unit 42 sends the counterparty's public key acquired in step S607 to the delegator device 1 via the network 6. The delegator device 1 receives the counterparty's public key from the first server 4. In step S609, the signature verification unit 16 of the delegator device 1 uses the counterparty's public key received in step S608 to verify the electronic signature of the proxy content data received in step S604. If signature verification is successful, the delegator device 1 proceeds to the next step, S610. If signature verification fails, the delegator device 1 terminates the process.

[0082] In step S610, the data generation unit 13 of the delegator device 1 creates confirmation data to be transmitted to the counterparty device 3 based on the information of the agency details data confirmed by the delegator in step S605. The confirmation data includes the information of the agency details confirmed by the delegator. The agency details include, for example, the power of attorney presented to the counterparty by the agent, information about the counterparty and / or the agent, details of the agency details, and the confirmation result by the delegator. If the delegator determines in step S605 that there are no problems with the agency details, the data generation unit 13 includes information such as "approved" or "no problem" in the confirmation data as the confirmation result by the delegator. If the delegator determines in step S605 that there are problems with the agency details, the data generation unit 13 includes information such as "fraudulent" or "problematic" in the confirmation data as the confirmation result by the delegator.

[0083] The confirmation data is created, for example, based on the input of the delegator operating the delegator device 1. The confirmation data may also be automatically created by the processor 101a executing a program, following a predetermined procedure, based on the information held in the database 17. Furthermore, if the delegator device 1 specifies the delegator ID as the identifier of the delegator's public key in steps S203 and S204 shown in Figure 3, and registers the delegator ID together with the delegator's public key in the first server 4, the confirmation data may also include the delegator ID.

[0084] In step S611, the delegator device 1 acquires the delegator's private key based on the private key storage method performed in step S202. The method for acquiring the private key is the same as the method described in step S402, so a detailed explanation is omitted. In step S612, the signature generation unit 15 generates an electronic signature for the confirmation data using the delegator's private key acquired in step S611, and attaches the generated electronic signature to the confirmation data generated in step S610. The method for attaching the electronic signature to the confirmation data is the same as the method described in step S403, so a detailed explanation is omitted. In step S613, the delegator device 1 transmits the confirmation data to which the electronic signature was attached in step S612 to the counterpart device 3 via the network 6. The counterpart device 3 receives the confirmation data from the delegator device 1.

[0085] In step S613, the data verification unit 33 of the other device 3 performs data processing on the verification data received and obtains its contents from the verification data. In step S614, the data verification unit 33 allows the other party to confirm the results of the delegator's verification of the proxy contents. Specifically, the data verification unit 33 displays the information obtained from the verification data on the display device 104c. If the verification data contains the identifier of the delegator's public key, the data verification unit 33 verifies whether the identifier of the delegator's public key is a legitimate delegator ID.

[0086] In step S614, if the confirmation data contains information such as "approved" or "no problem" as a result of the delegator's confirmation, the counterparty device 3 proceeds to the next step S615. On the other hand, if the confirmation data contains information such as "fraudulent" or "problematic" as a result of the delegator's confirmation, the counterparty performs a status check. A status check is, for example, when the counterparty confirms with the delegator and / or agent, using written documents or communication means such as telephone, whether or not the agency agreement was fraudulent. This status check may be performed after step S618, which will be explained later. If the counterparty determines, as a result of the status check, that the agency agreement was not fraudulent, it inputs to the counterparty device 3 that it will delete the information such as "fraudulent" or "problematic" from the confirmation data. In this case, the counterparty device 3 proceeds to the next step S615. On the other hand, if the counterparty determines, as a result of the status check, that the agency agreement was fraudulent, it takes necessary measures such as canceling or invalidating the agency agreement. This cancels the agency agreement made by the agent.

[0087] In step S615, the remote device 3 requests the delegator's public key from the first server 4 via the network 6, based on the information confirmed by the user in step S614. For example, the remote device 3 sends information to the first server 4 including a request for the delegator's public key and the delegator ID. In step S616, the data acquisition unit 42 of the first server 4 retrieves the delegator's public key requested by the remote device 3 in step S615 from the database 43. Specifically, the data acquisition unit 42 retrieves the delegator's public key corresponding to the delegator ID from the database 43. In step S617, the data acquisition unit 42 sends the delegator's public key obtained in step S616 to the remote device 3 via the network 6. The remote device 3 receives the delegator's public key from the first server 4.

[0088] In step S618, the signature verification unit 36 ​​of the counterpart device 3 verifies the electronic signature of the confirmation data received in step S613 using the delegator's public key received in step S617. If the signature verification is successful, the counterpart device 3 proceeds to the next step, S619. If the signature verification fails, the counterpart device 3 terminates the process. In step S619, the counterpart device 3 securely stores the counterpart private key obtained in step S602 using any method. In step S620, the delegator device 1 securely stores the delegator private key obtained in step S611 using any method. The storage method is the same as the method described in step S202, so a detailed explanation is omitted. The counterpart device 3 may execute the process in step S619 at any time after the process in step S603. The delegator device 1 may execute the process in step S620 at any time after the process in step S612.

[0089] <Images displayed on display devices 104a to 104c> In the information processing system 9 of this embodiment, specific examples of images displayed on display devices 104a to 104c will be described with reference to Figures 8 to 15. Specifically, in the power of attorney issuance process described with reference to Figure 5, an example of an image displayed on display devices 104a and 104b will be described with reference to Figures 8 and 9. In the power of attorney presentation and verification process described with reference to Figure 6, an example of an image displayed on display devices 104b and 104c will be described with reference to Figures 10 and 11. In the proxy content confirmation process described with reference to Figure 7, an example of an image displayed on display devices 104a and 104c will be described with reference to Figures 12 to 15. Each of the input devices 103a to 103c is, for example, a keyboard connected to the information processing device, or a touch panel provided on each of the display devices 104a to 104c.

[0090] Before describing each of Figures 8 to 15 in detail, we will explain the common content of Figures 8 to 15. The interface sections shown in each image of Figures 8 to 15 display content entered through input functions such as text boxes, pull-down menus, or pop-up menus. The content displayed in each interface section is entered by the principal, agent, or counterparty. The content displayed in each interface section may also be entered automatically by the processor of each device executing a program according to a predetermined procedure. Furthermore, the selection of buttons shown in each image of Figures 8 to 15 may be deactivated until the content requiring input is entered in the interface section displayed with the button. The content displayed in the message section, interface section, and buttons shown in each image of Figures 8 to 15, and the methods of inputting into the interface section, are examples and are not limited to those shown in Figures 8 to 15.

[0091] (Power of Attorney Issuance Image) An example of a power of attorney issuance image displayed on the display device 104a of the delegator device 1 during the power of attorney issuance process is described below. Figure 8 is a diagram showing an example of a power of attorney issuance image displayed on the display device of the delegator device in step S401 shown in Figure 5. The power of attorney issuance image 150 displays a message section 151 that displays a message to notify the delegator, an interface section 152 that displays the input content, and a button 153 for instructing the issuance of the power of attorney.

[0092] The message unit 151 contains a message prompting the principal to enter detailed information about the power of attorney before issuance. The interface unit 152 displays the entered information corresponding to each of several predetermined items in the power of attorney. These items include, for example, the power of attorney ID, the principal's name, the agent's name, the details of the authorization, and the authorization period. The authorization period corresponds to the last day of the authorization period. In the example shown in Figure 8, the principal's name is "AAA" and the agent's name is "BBB". The interface unit 152 may also display information that has been automatically entered according to a predetermined procedure by the processor 101a executing a program. For example, since the principal may not know the power of attorney ID, the processor 101a reads the power of attorney ID from memory 102a or storage device 106a and displays it on the interface unit 152. Button 153 contains instructions to "issue". In step S401 shown in Figure 5, when the delegator selects button 153 via input device 103a, the delegator device 1 proceeds to the process in step S402.

[0093] (Image for confirming the power of attorney) An example of an image for confirming the power of attorney displayed on the display device 104b of the agent device 2 during the power of attorney issuance process is described below. Figure 9 is a diagram showing an example of an image for confirming the power of attorney displayed on the display device of the agent device in step S414 shown in Figure 5. The power of attorney confirmation image 160 displays a message section 161 that displays a message to notify the agent, an interface section 162 that displays the contents of the received power of attorney, and a button 163 for the agent to input that they have confirmed the power of attorney.

[0094] The message section 161 contains a message prompting the agent to confirm the contents of the power of attorney received from the principal. The interface section 162 displays information about the principal's electronic signature, in addition to the contents of the power of attorney shown in Figure 8. This electronic signature information includes, for example, the signatory's name, signature value, signing date and time, and public key information. The signing date and time serves as a timestamp at the time the signature was issued. "HH:MM:SS" represents the time in 24-hour format, "HH hours, MM minutes, SS seconds". Button 163 contains input indicating confirmation. In step S415 shown in Figure 5, when the agent selects button 163 via the input device 103b, the agent device 2 proceeds to the processing of step S415.

[0095] (Operational image for displaying the input of agency details and the selected power of attorney) An example of an operational image for displaying the input of agency details and the selected power of attorney, which is displayed on the display device 104b of the agent device 2 during the power of attorney presentation process, is described below. Figure 10 is a diagram showing an example of an operational image for displaying the input of agency details and the selected power of attorney, which is displayed on the display device of the agent device in step S507 shown in Figure 6. The operational image 200 displays a message unit 201 for displaying a message to be notified to the agent, an interface unit 202 for displaying the input of agency details, an interface unit 203 for displaying the selected power of attorney, and a button 204. The button 204 is selected by the agent when presenting the agency details and power of attorney to the other party.

[0096] Message unit 201 contains a message prompting the agent to input the details of the agency to be performed and to select a power of attorney. Interface unit 202 contains the details of the agency entered by the agent. Interface unit 203 displays the power of attorney selected by the agent. Button 204 contains an instruction to "present". In step S507 shown in Figure 6, when the agent selects button 204 via input device 103b, the agent device 2 proceeds to step S508.

[0097] (Confirmation image for verifying the details of the agency and the power of attorney) An example of a confirmation image for the details of the agency and the power of attorney that is displayed on the display device 104c of the other party device 3 during the verification process is described below. Figure 11 is a diagram showing an example of a confirmation image for the details of the agency and the power of attorney that is displayed on the display device of the other party device in step S512 shown in Figure 6. The confirmation image 210 displays a message section 211 that displays a message to notify the other party, interface sections 212 and 213, and a button 214 for the other party to instruct to verify the presented data.

[0098] Message unit 211 contains a message prompting the other party to confirm the details of the agency and the power of attorney in the data presented by the agent. Interface unit 212 displays information regarding the details of the agency and the electronic signature in the data presented by the agent. Specifically, interface unit 212 displays the details of the agency entered by the agent in step S507 and the electronic signature information attached to the data presented in step S508. Interface unit 213 displays information regarding the power of attorney in the data received from the agent. Specifically, interface unit 213 displays the power of attorney selected by the agent in step S507. Button 214 contains instructions to "verify". In step S512 shown in Figure 6, when the other party selects button 214 via input device 103c, the other party device 3 proceeds to the process in step S513.

[0099] (Image for inputting proxy content data) An example of an image for inputting proxy content data, which is displayed on the display device 104c of the other device 3 during the proxy content confirmation process, is described below. Figure 12 is a diagram showing an example of an image for inputting proxy content data, which is displayed on the display device of the other device in step S601 shown in Figure 7. The image for inputting proxy content data 220 displays a message section 221 that displays a message to be notified to the other party, an interface section 222, and a button 223 for the other party to request confirmation of the proxy content from the delegator.

[0100] The message unit 221 contains a message prompting the other party to input detailed information about the agency act performed by the agent. The interface unit 222 displays the information entered by the other party regarding the agency act performed by the agent, as well as the power of attorney. Button 223 contains an instruction to "request confirmation." In step S601 shown in Figure 7, when the other party selects button 223 via the input device 103c, the other party device 3 proceeds to the process in step S602.

[0101] (Image for verifying proxy content data) An example of an image for verifying proxy content data displayed on the display device 104a of the delegator device 1 during the proxy content verification process is described below. Figure 13 is a diagram showing an example of an image for verifying proxy content data displayed on the display device of the delegator device in step S605 shown in Figure 7. The proxy content data verification image 230 displays a message section 231 that displays a message to notify the delegator, an interface section 232, and a button 233 for the delegator to instruct verification of the proxy content data.

[0102] The message unit 231 contains a message prompting the principal to confirm the proxy details and power of attorney information included in the proxy details data received from the other party. The interface unit 232 displays information about the proxy details and electronic signature included in the proxy details data received from the other party. Specifically, the interface unit 232 displays the proxy details entered by the other party in step S601 and the electronic signature information attached to the proxy details data in step S603. The signature date and time in the electronic signature information serves as a timestamp at the time of signature issuance. "hh:mm:ss" represents the time in 24-hour format, "hh hours, mm minutes, ss seconds". The button 233 contains instructions to "verify". In step S605 shown in Figure 7, when the principal selects button 233 via the input device 103a, the principal device 1 proceeds to the process in step S606.

[0103] The display device 104a installed in the principal device 1 displays to the other party the details of the agency act performed by the agent. Therefore, the principal can confirm the validity of the actions performed by the agent to the other party.

[0104] (Image for inputting confirmation data) An example of an image for inputting confirmation data, which is displayed on the display device 104a of the delegator device 1 during the proxy content confirmation process, is described below. Figure 14 is a diagram showing an example of an image for inputting confirmation data, which is displayed on the display device of the delegator device in step S610 shown in Figure 7. The image for inputting confirmation data 240 displays a message section 241 that displays a message to notify the delegator, an interface section 242, and a button 243 for the delegator to instruct the creation of confirmation data.

[0105] The message unit 241 contains a message prompting the delegator to input the results of confirming the proxy content data. The interface unit 242 displays the confirmation results entered by the delegator, along with the power of attorney and electronic signature information. Button 243 contains the instruction to "create". In step S610 shown in Figure 7, when the delegator selects button 243 via the input device 103a, the delegator device 1 proceeds to the process in step S611.

[0106] (Confirmation image of confirmation data) An example of a confirmation image of confirmation data displayed on the display device 104c of the other device 3 during the proxy content confirmation process is described below. Figure 15 is a diagram showing an example of a confirmation image of confirmation data displayed on the display device of the other device in step S614 shown in Figure 7. The confirmation image of confirmation data 250 displays a message section 251 that displays a message to notify the other party, an interface section 252, and a button 253 for the other party to instruct verification of the confirmation data.

[0107] The message unit 251 contains a message notifying the other party that the confirmation result has been received from the delegator regarding the proxy content data. The interface unit 252 displays information regarding the confirmation result and the electronic signature information contained in the received confirmation data. Specifically, the interface unit 252 displays the confirmation result entered by the delegator in step S610 and the electronic signature information attached to the confirmation data in step S612. The button 253 contains an instruction to "verify". In step S614 shown in Figure 7, when the other party selects button 253 via the input device 103c, the other party device 3 proceeds to the process in step S615.

[0108] The display device 104c on the other party's device 3 displays the result of the principal's confirmation of the agency details. The other party can refer to the information displayed on the display device 104c to confirm the principal's judgment regarding the appropriateness of the agency details provided by the agent.

[0109] <Summary of this embodiment> An example of the procedure by the information processing system 9 of this embodiment is as follows (a) to (e). The series of processes (a) to (e) are performed by the principal operating the principal device 1, the agent operating the agent device 2, and the counterparty operating the counterparty device 3. (a) When issuing the power of attorney, the principal issues a power of attorney to the agent that shows the scope of the agency and the duration of the agency. (b) When the agent performs the agency, the agent presents the power of attorney to the counterparty for verification. (c) If the counterparty wants to confirm the legitimacy and accuracy of the agency performed by the agent, the counterparty creates agency content data and asks the principal to confirm the agency content data. (d) When the principal confirms the agency content data, the principal creates confirmation data including the confirmation result and attaches an electronic signature to the confirmation data. (e) The counterparty confirms the confirmation data created by the principal and verifies the electronic signature attached to the confirmation data. If there is any fraud in the agency performed by the agent, the principal notifies the counterparty of this fact. The principal may, if deemed necessary in response to a notice from the other party, revoke the agent's authority. This prevents the agent from acting on behalf of the principal in a manner unintended by the principal or for a period unintended by the principal.

[0110] According to this embodiment, the number of times the principal issues a power of attorney is reduced by delegating broad and long-term power of attorney. Furthermore, the principal verifies the details of the agent's authority, and the principal generates an electronic signature on the verification result. The other party can verify the electronic signature generated by the principal and determine that it is a legitimate verification result from the principal, thereby accurately confirming the legitimacy of the agent and the details of the authority from the verification result.

[0111] In the information processing system 9 according to the above embodiment, all or some of the configurations and functional units of each configuration may be executed by another device. For example, the database 17 may be provided on a separate device or server from the delegator device 1, and the delegator device 1 may acquire various data from the database 17 via the network 6. The agent device 2 may also include multiple functional units and a database 54 provided by the second server 5. The first server 4 and the second server 5 are not limited to separate servers, but may be integrated into the same server.

[0112] Furthermore, although the above embodiment described a case where the second server 5 stores the power of attorney issued to the agent, if there are multiple powers of attorney, the agent device 2 may encrypt each of the multiple powers of attorney with the agent's public key before storing them in the second server 5. By encrypting multiple powers of attorney with the agent's public key, only the agent can decrypt the target power of attorney from the multiple powers of attorney and present it to the other party. Therefore, in addition to verification by user authentication, the presentation of the power of attorney by the agent can enhance the reliability that the user presenting the power of attorney is indeed the agent.

[0113] When the agent device 2 encrypts multiple powers of attorney and stores them on the second server 5, it may encrypt the multiple powers of attorney using the same agent public key, or it may encrypt each of the multiple powers of attorney using a different public key. When the agent device 2 encrypts the powers of attorney using different public keys, each time a new power of attorney is issued, the agent device 2 generates a public key and a private key pair using an arbitrary encryption scheme, and encrypts and decrypts the powers of attorney based on the generated key pair. In this case, the agent device 2 may manage the private key used for decryption in the same manner as described in the embodiment, or it may encrypt the private key used for decryption with the agent public key and store the encrypted private key together with the encrypted powers of attorney on the second server 5. Furthermore, the agent device 2 does not have to encrypt and decrypt the powers of attorney using a public key cryptography scheme. For example, the agent device 2 may encrypt the powers of attorney using a symmetric key cryptography scheme such as AES (Advanced Encryption Standard), and protect the symmetric key by encrypting it with a public key cryptography scheme. In this case, the encrypted shared key, along with the encrypted power of attorney, is sent and received between each device and each server. Encrypting multiple powers of attorney with the same public key reduces the burden of key pair generation and private key management. On the other hand, encrypting multiple powers of attorney with different public keys improves the security of each power of attorney.

[0114] The information processing system 9 of this embodiment includes a principal device 1 operated by the principal, a counterparty device 3 operated by the counterparty, and a counterparty device 2 operated by the agent acting on behalf of the principal to the counterparty. The principal device 1 includes a memory 102a corresponding to a first memory that stores a first program, and a processor 101a corresponding to a first processor that executes processing according to the first program. The processor 101a operates as follows by executing the first program. The processor 101a creates a power of attorney with a scope of delegation that is wider than a predetermined scope and a delegation period that is longer than a predetermined period, according to the attributes of the principal and the agent, regarding the authority that the principal delegates to the agent. The processor 101a transmits the power of attorney to the counterparty device 2 in order to issue the power of attorney to the agent. When the processor 101a receives from the counterparty device 3 the delegation content data, which includes information on the delegation content performed by the agent, and an electronic signature that authenticates the counterparty and proves the content of the delegation content data, it verifies the electronic signature and notifies the principal of the delegation content.

[0115] According to this embodiment, the scope of the power of attorney issued is broad according to the attributes of the principal and agent, and the duration of the power of attorney is set to be long, thus reducing the frequency of power of attorney issuance. As a result, the burden of issuing power of attorney is reduced for the principal. The principal can accurately verify the legitimacy of the power of attorney because the details of the power of attorney performed by the agent are notified by the counterparty device.

[0116] Traditionally, when delegating authority, the principal must issue a power of attorney to the agent each time authority is delegated, which becomes cumbersome if the delegation is frequent. In contrast, according to this embodiment, the scope of the delegated authority in the issued power of attorney is broad and the delegation period is long, thus reducing the frequency of power of attorney issuance. Furthermore, when an agent exercises their authority, the other party may want to confirm with the principal whether the authority is legitimate and whether the delegated actions are not fraudulent. In particular, when the delegated actions involve money, the legitimacy and accuracy of the delegated actions are important. Moreover, if a highly urgent event occurs, the agent may exercise authority beyond the scope of what was delegated. In this case, the principal needs to confirm the delegated actions and approve them afterward. In contrast, according to this embodiment, the delegate is notified of the delegated actions taken with respect to the other party. Therefore, the principal can accurately confirm the legitimacy of the delegated actions because the delegate is notified of the delegated actions by the agent through the other party's device.

[0117] This disclosure is not limited to the embodiments described above, but includes various modifications. Furthermore, the embodiments described above are described in detail for the purpose of clearly illustrating the present invention and are not necessarily limited to having all the configurations and processes described. It is possible to replace some of the configurations and processes of these embodiments with those of other embodiments. It is also possible to add configurations and processes of other embodiments to the configurations and processes of these embodiments. Moreover, it is possible to add, delete, or replace some of the configurations and processes of these embodiments with those of other embodiments.

[0118] Some or all of the above-described configurations, functions, processing units, and processing methods may be implemented in dedicated hardware, for example, by designing them as integrated circuits. Alternatively, each of the above-described configurations and functions may be implemented in software by a processor interpreting and executing programs that implement each function. Information such as programs or files that implement each function and process is stored in a storage device such as memory or a hard disk. Furthermore, information such as programs or files that implement each function and process may be stored in a storage medium such as an IC card, an SD (Secure Digital) card, or a DVD (Digital Versatile Disc).

[0119] The embodiments described above are illustrative for explaining the present invention and are not intended to limit the scope of the invention to those embodiments only. Those skilled in the art can implement the present invention in various other forms without departing from the scope of the invention.

[0120] Furthermore, the embodiments described above include the following items. However, the items included in these embodiments are not limited to those listed below.

[0121] (Item 1) An information processing system comprising a principal device operated by a principal, a counterparty device operated by a counterparty, and a counterparty device operated by an agent acting on behalf of the principal to the counterparty, wherein the principal device comprises a first memory for storing a first program and a first processor for executing processing according to the first program, and the first processor, by executing the first program, creates a power of attorney with respect to the authority that the principal delegates to the agent, wherein the scope of the delegation is wider than a predetermined range and the delegation period is longer than a predetermined period, according to the attributes of the principal and the agent; transmits the power of attorney to the agent device in order to issue the power of attorney to the agent; and, upon receiving from the counterparty device agency content data including information on the agency content performed by the agent and an electronic signature that authenticates the counterparty and certifies the content of the agency content data, verifies the electronic signature and notifies the principal of the agency content.

[0122] According to this, the scope of the power of attorney issued is broad, depending on the attributes of the principal and the agent, and the duration of the power of attorney is set to be long, thus reducing the frequency of power of attorney issuance. As a result, the burden of issuing power of attorney is reduced for the principal. The principal can accurately verify the legitimacy of the actions taken by the agent because the details of the actions taken by the agent are notified from the other party's device.

[0123] (Item 2) An information processing system as described in Item 1, comprising a management server including a second memory for storing a second program and a second processor for executing processing according to the second program, wherein the second processor, by executing the second program, manages the status of the power of attorney in accordance with a power of attorney identifier which is a different identifier for each power of attorney, and when it receives information from the principal device that there is fraud in the agency details along with the power of attorney identifier, it updates the status of the power of attorney identified by the received power of attorney identifier to expire or invalid. As a result, if there is fraud in the agency details by the agent, the status of the power of attorney is updated to expire or invalid.

[0124] (Item 3) In the information processing system described in Item 2, the second processor transmits to the other party device information on the status of the power of attorney corresponding to the power of attorney identifier when the other party device requests information on the status of the power of attorney regarding the status of the power of attorney. This allows the other party device to confirm whether the status of the power of attorney is valid, expired, or invalid. Therefore, the other party device can determine whether the actions of the agent are legitimate or not.

[0125] (Item 4) Information processing system as described in Item 3, wherein the second processor, upon receiving a request from the counterparty device including information on the date on which the agent performed the agency, refers to the agency period corresponding to the power of attorney identifier, and updates the status of the power of attorney to expire or invalid if the date on which the agent performed does not fall within the agency period. As a result, if the date on which the agent performed the agency does not fall within the agency period, the power of attorney is expired or invalidated.

[0126] (Item 5) An information processing system according to any one of Items 1 to 4, wherein the counterparty device has a third memory for storing a third program and a third processor for executing processing according to the third program, and when the first processor issues the power of attorney to the agent, it receives the electronic signature from the agent device and authenticates the agent using the agent's public key, which is the agent's public key, with respect to the received electronic signature, and when the third processor executes the third program and receives the power of attorney with the electronic signature attached from the agent device, it authenticates the agent using the agent's public key, with respect to the received electronic signature, an information processing system.

[0127] The principal's device authenticates the agent when issuing the power of attorney, and the counterparty's device authenticates the agent when receiving the power of attorney from the agent. The principal can recognize that they have issued the power of attorney to a legitimate agent, and the counterparty can recognize that they have received the power of attorney from a legitimate agent.

[0128] (Item 6) An information processing system according to any one of Items 1 to 5, wherein the first memory stores the attributes of the principal and the agent and the relationship between the principal and the agent as information of the principal and the agent, and the first processor determines the scope of delegation and / or the delegation period based on the information of the principal and the agent.

[0129] In addition to the attributes of the principal and agent, the scope and duration of the delegation are automatically determined in accordance with the relationship between the principal and agent.

[0130] (Item 7) An information processing system described in any one of Items 1 to 6, wherein the delegator device has a first display for displaying information, and the first processor reads the agency content from the agency content data and displays it on the first display in order to allow the delegator to confirm the agency content.

[0131] A first display installed on the principal's device shows the details of the agency act performed by the agent to the other party. Therefore, the principal can confirm the validity of the actions performed by the agent to the other party.

[0132] (Item 8) An information processing system as described in Item 7, wherein the counterparty device has a third memory for storing a third program, a third processor for executing processing according to the third program, and a third display for displaying information, the first processor transmits confirmation data including the confirmation result information to the counterparty device when the confirmation result of the delegator is input to the proxy content displayed on the first display, and the third processor displays the information contained in the confirmation data on the third display by executing the third program so that the counterparty can confirm the confirmation result.

[0133] A third display on the other party's device shows the result of the principal's confirmation of the agency agreement. By referring to the information displayed on the third display, the other party can confirm the principal's judgment regarding the validity of the agency agreement made by the agent.

[0134] 1 Delegator device, 2 Agent device, 3 Counterparty device, 4 First server, 5 Second server, 6 Network, 9 Information processing system, 11 Delegator key generation unit, 12 Authentication unit, 13 Data generation unit, 14 Data verification unit, 15 Signature generation unit, 16 Signature verification unit, 17 Database, 21 Agent key generation unit, 22 Authentication unit, 23 Signature generation unit, 24 Database, 31 Counterparty key generation unit, 32 Authentication unit, 33 Data verification unit, 34 Agent content data generation unit, 35 Signature generation unit, 36 Signature verification unit, 37 Database, 41 Data registration unit, 42 Data acquisition unit, 43 Database, 51 Data registration unit, 52 Authentication unit, 53 Data acquisition unit, 54 Database, 101a-101d Processor, 102a-102d Memory, 103a-103d Input device, 104a-104d Display device, 105a-105d Communication device, 106a-106d Storage device, 107a-107d Bus, 150 Power of attorney issuance image, 151 Message section, 152 Interface section, 153 Button, 160 Confirmation image, 161 Message section, 162 Interface section, 163 Button, 200 Operation image, 201 Message section, 202, 203 Interface section, 204 Button, 210 Confirmation image, 211 Message section, 212, 213 Interface section, 214 Button, 220 Input image, 221 Message section, 222 Interface section, 223 Button, 230 Confirmation image, 231 Message section, 232 Interface section, 233 Button, 240 Input image, 241 Message section, 242 Interface section, 243 Button, 250 Confirmation image, 251 Message section, 252 Interface section, 253 Button.

Claims

1. An information processing system comprising: a principal device operated by a principal; a counterparty device operated by a counterparty; and a counterparty device operated by an agent acting on behalf of the principal to the counterparty, wherein the principal device comprises: a first memory for storing a first program; and a first processor for executing processing according to the first program, the first processor, by executing the first program, creates a power of attorney with respect to the authority that the principal delegates to the agent, wherein the scope of the delegation is wider than a predetermined range and the delegation period is longer than a predetermined period, according to the attributes of the principal and the agent; transmits the power of attorney to the counterparty device for issuing the power of attorney to the agent; and, upon receiving from the counterparty device agency content data including information on the agency content performed by the agent, and an electronic signature authenticating the counterparty and certifying the content of the agency content data, verifies the electronic signature and notifies the principal of the received agency content.

2. An information processing system according to claim 1, comprising a management server including a second memory for storing a second program and a second processor for executing processing according to the second program, wherein the second processor, by executing the second program, manages the status of a power of attorney in correspondence with a power of attorney identifier which is a different identifier for each power of attorney, and when it receives the power of attorney identifier along with information from the delegator device indicating that there is fraud in the agency content, it updates the status of the power of attorney identified by the received power of attorney identifier to expire or invalid.

3. An information processing system according to claim 2, wherein the second processor, when the counterparty device requests information including the information of the power of attorney identifier regarding the status of the power of attorney, transmits information on the status of the power of attorney corresponding to the power of attorney identifier to the counterparty device.

4. An information processing system according to claim 3, wherein the second processor, upon receiving a request from the counterparty device including information on the date on which the agent performed the agent's duties, refers to the delegation period corresponding to the power of attorney identifier, and updates the status of the power of attorney to expire or invalid if the date on which the agent's duties were performed does not fall within the delegation period.

5. An information processing system according to claim 1, wherein the counterparty device has a third memory for storing a third program and a third processor for executing processing according to the third program, and the first processor, when issuing the power of attorney to the agent, receives the electronic signature from the agent device and authenticates the agent using the agent's public key, which is the agent's public key, with respect to the received electronic signature, and the third processor, by executing the third program, receives the power of attorney with the electronic signature attached from the agent device and authenticates the agent using the agent's public key, with respect to the received electronic signature.

6. An information processing system according to claim 1, wherein the first memory stores the attributes of the principal and the agent and the relationship between the principal and the agent as information of the principal and the agent, and the first processor determines the scope of delegation and / or the delegation period based on the information of the principal and the agent.

7. An information processing system according to claim 1, wherein the delegator device has a first display for displaying information, and the first processor reads the proxy content from the proxy content data and displays it on the first display for the delegator to confirm the proxy content.

8. An information processing system according to claim 7, wherein the counterparty device comprises a third memory for storing a third program, a third processor for executing processing according to the third program, and a third display for displaying information, wherein the first processor transmits confirmation data including the confirmation result information to the counterparty device when the confirmation result of the delegate is input to the proxy content displayed on the first display, and the third processor executes the third program to display the information contained in the confirmation data on the third display in order to allow the counterparty to confirm the confirmation result.

9. An information processing method performed by an information processing device connected to a counterparty device operated by the counterparty of the principal, and an agent device operated by an agent acting on behalf of the principal to the counterparty, the method comprising: creating a power of attorney with respect to the authority that the principal delegates to the agent, wherein the scope of the delegation is broader than a predetermined range and the delegation period is longer than a predetermined period, according to the attributes of the principal and the agent; transmitting the power of attorney to the agent device in order to issue the power of attorney to the agent; receiving from the counterparty device agency content data including information on the agency content performed by the agent, and an electronic signature that authenticates the counterparty and certifies the content of the agency content data, verifying the electronic signature; and notifying the principal of the received agency content.

10. A program for causing a computer connected to a counterparty device operated by the counterparty of the principal, and an agent device operated by an agent acting on behalf of the principal to the counterparty, to perform the following: create a power of attorney with respect to the authority that the principal delegates to the agent, where the scope of the delegation is broader than a predetermined range and the delegation period is longer than a predetermined period, according to the attributes of the principal and the agent; transmit the power of attorney to the agent device in order to issue the power of attorney to the agent; and upon receiving from the counterparty device agency content data including information on the agency content performed by the agent, as well as an electronic signature that authenticates the counterparty and certifies the content of the agency content data, verify the electronic signature and notify the principal of the received agency content.