JP2002164884A

Proxy server, electronic signature system, electronic signature verification system, network system, electronic signature method, electronic signature verification method, recording medium and program transmission device

Abstract

(57) A summary and subject The security function by an electronic signature is realized by mounting a means to perform the electronic signature of the message sent and received through a network, verification, and logging, in the form of a proxy server, without needing change of an application program. Solution means It has the application 10 which performs data processing, and the signature proxy server 20 connected to this application 10 through LAN100, This signature proxy server 20 intercepts the message communication from the application 10 to the equipment of the exterior of LAN100, performs an electronic signature in the message document in this message communication, and transmits a message document with an electronic signature to the equipment which is a transmission destination.

JP2002164884A, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Projected expiry passed 2 November 2020, 5.9 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

20 claims: 12 independent, 8 dependent

  1. 1
    [Claims] 1. In a proxy server that relays communication between applications and performs additional processing. A key management unit that manages a key for generating a digital signature to be applied to a message document exchanged between the applications, and a key management unit. A signature key determination unit that acquires a message document transmitted from the predetermined application and determines a key for digitally signing based on the message document. Using the key obtained from the key management unit based on the determination of the signature key determination unit, the message document is digitally signed, and the signed message document is sent to another application to which the message document is sent. A proxy server characterized by having a signature generator. 【特許請求の範囲】 【請求項1】 アプリケーション間で行われる通信を中継し、付加的処理を行うプロキシサーバにおいて、 前記アプリケーション間でやりとりされるメッセージ文書に施す電子署名を生成するための鍵を管理する鍵管理部と、 所定の前記アプリケーションから送信されたメッセージ文書を取得し、当該メッセージ文書に基づいて電子署名を行うための鍵を決定する署名鍵判定部と、 前記署名鍵判定部の決定に基づいて前記鍵管理部から取得した鍵を用いて、前記メッセージ文書に対して電子署名を行い、署名された当該メッセージ文書を送信先である他の前記アプリケーションに送る署名生成部とを備えたことを特徴とするプロキシサーバ。
  2. 2
    The key management unit sets acquisition conditions for the key, and when the acquisition conditions are satisfied, the signature generation unit can acquire the corresponding key. Proxy server described in 1. 【請求項2】 前記鍵管理部は、前記鍵の取得条件を設定し、当該取得条件を満足する場合に、前記署名生成部が該当する前記鍵を取得可能とすることを特徴とする請求項1に記載のプロキシサーバ。
  3. 6
    When the signature generation unit digitally signs using the alternative key, the log management unit is used together with the electronically signed message document before the electronic signature is applied. Stores the message document of When the signature generation unit performs an electronic signature using the original key, the request is characterized in that the message document before the electronic signature is applied is acquired from the log management unit and the electronic signature is performed. The proxy server described in Section 4. 【請求項6】 前記ログ管理部は、前記署名生成部が前記代替用の鍵を用いて電子署名を行った場合に、電子署名が施された前記メッセージ文書と共に、電子署名が施される前の前記メッセージ文書を格納し、 前記署名生成部は、前記本来の鍵を用いて電子署名を行う場合に、前記ログ管理部から前記電子署名が施される前のメッセージ文書を取得して電子署名を行うことを特徴とする請求項4に記載のプロキシサーバ。
  4. 7
    An application that performs data processing and a proxy server connected to the application via a network are provided. The proxy server intercepts a message communication from the application to a device outside the network, digitally signs the message document in the message communication, and transmits the electronically signed message document to the device. Signature system. 【請求項7】 データ処理を行うアプリケーションと、ネットワークを介して当該アプリケーションに接続されたプロキシサーバとを備え、 前記プロキシサーバは、前記アプリケーションから前記ネットワーク外部の装置へのメッセージ通信をインターセプトし、当該メッセージ通信におけるメッセージ文書に電子署名を行い、電子署名付きメッセージ文書を前記装置へ送信することを特徴とする電子署名システム。
  5. 10
    An application that performs data processing and a proxy server connected to the application via a network are provided. The proxy server intercepts the message communication from the device outside the network to the application, verifies the electronic signature of the message document in the message communication, and delivers the message document whose validity has been confirmed by the verification to the application. An electronic signature verification system characterized by sending. 【請求項10】 データ処理を行うアプリケーションと、ネットワークを介して当該アプリケーションに接続されたプロキシサーバとを備え、 前記プロキシサーバは、前記ネットワーク外部の装置から前記アプリケーションへのメッセージ通信をインターセプトし、当該メッセージ通信におけるメッセージ文書の電子署名を検証し、当該検証により正当性が確認された当該メッセージ文書を前記アプリケーションへ送信することを特徴とする電子署名検証システム。
  6. 11
    A network system including a plurality of groups connected by a wide area network, and each group includes an application for processing data and a proxy server connected to the application via a local network. The proxy server Intercept the message communication from the application of the own group to the application of the other group, digitally sign the message document in the message communication, and send the message document with the electronic signature to the application of the other group. The message communication from the application of another group to the application of the own group is intercepted, the electronic signature of the message document in the message communication is verified, and the message document whose validity is confirmed by the verification is the message document of the own group. A network system characterized by sending to an application. 【請求項11】 広域ネットワークで接続された複数のグループを備え、各グループは、データ処理を行うアプリケーションと、ローカルなネットワークを介して当該アプリケーションに接続されたプロキシサーバとを備えたネットワークシステムにおいて、 前記プロキシサーバは、 自グループの前記アプリケーションから他のグループの前記アプリケーションへのメッセージ通信をインターセプトし、当該メッセージ通信におけるメッセージ文書に電子署名を行い、電子署名付きメッセージ文書を前記他のグループの前記アプリケーションへ送信し、 他のグループの前記アプリケーションから自グループの前記アプリケーションへのメッセージ通信をインターセプトし、当該メッセージ通信におけるメッセージ文書の電子署名を検証し、当該検証により正当性が確認された当該メッセージ文書を前記自グループのアプリケーションへ送信することを特徴とするネットワークシステム。
  7. 15
    In an electronic signature method that guarantees the validity of a message document by electronically signing the message document in communication performed between applications. A step of selecting a key for digitally signing the message document according to the type of the message document sent from the predetermined application, and a step of selecting the key for digitally signing the message document. When the usage conditions are set for the key and the usage conditions are not satisfied, the message document is digitally signed using a preset alternative key instead of the key. And the step of sending the message document with the digital signature to the destination when it is sent from the application. After electronically signing the message document using the alternative key, when the usage conditions of the original key are satisfied, the message document is digitally signed again using the original key. , A method of electronic signature comprising the step of transmitting a message document with the electronic signature to a destination when the message document is transmitted from the application. 【請求項15】 アプリケーション間で行われる通信におけるメッセージ文書に電子署名を施すことにより、当該メッセージ文書の正当性を保証する電子署名方法において、 所定の前記アプリケーションから送信されたメッセージ文書の種類に応じて、当該メッセージ文書に電子署名を施すための鍵を選択するステップと、 当該鍵に対して使用条件が設定されている場合であって、当該使用条件が満たされていない場合に、当該鍵に代えて予め設定された代替用の鍵を用いて前記メッセージ文書に電子署名を行い、当該電子署名付きのメッセージ文書を前記アプリケーションから送信された際の送信先に送信するステップと、 前記代替用の鍵を用いて前記メッセージ文書に電子署名を行った後、本来の前記鍵における前記使用条件が満たされた際に、当該本来の鍵を用いて前記メッセージ文書に改めて電子署名を行い、当該電子署名付きのメッセージ文書を前記アプリケーションから送信された際の送信先に送信するステップとを含むことを特徴とする電子署名方法。
  8. 16
    In an electronic signature verification method for confirming the validity of a message document by verifying the electronic signature given to the message document in communication performed between applications. When the electronic signature given to the received message document is not the key specified according to the type of the message document but the electronic signature made by using the substitute key of the key, the substitute key is used. Steps to receive the message document signed with the key of After receiving the message document signed with the alternative key, the step of receiving the message document signed with the original key, and The electronic signature verification includes a step of verifying the validity of the message document signed by using the alternative key received earlier by verifying the electronic signature using the original key. Method. 【請求項16】 アプリケーション間で行われる通信におけるメッセージ文書に施された電子署名を検証することにより、当該メッセージ文書の正当性を確認する電子署名検証方法において、 受信したメッセージ文書に施された電子署名が、当該メッセージ文書の種類に応じて定められた鍵ではなく、当該鍵の代替用の鍵を用いて行われた電子署名である場合に、当該代替用の鍵を用いて署名された当該メッセージ文書を受領するステップと、 前記代替用の鍵を用いて署名されたメッセージ文書を受領した後、本来の前記鍵を用いて署名された当該メッセージ文書を受信するステップと、 前記本来の鍵を用いた電子署名を検証することにより、先に受領した前記代替用の鍵を用いて署名されたメッセージ文書の正当性を確認するステップとを含むことを特徴とする電子署名検証方法。
  9. 17
    In a storage medium in which a program to be executed by a computer is readablely stored by an input means of the computer. The program is a key management means that manages a key for generating a digital signature that gives the computer a message document exchanged between applications. A signature key determination means for acquiring a message document transmitted from the predetermined application and determining a key for digitally signing based on the message document. A storage medium characterized in that a key obtained from the key management means based on the determination of the signature key determination means is used to function as a signature generation means for electronically signing the message document. 【請求項17】 コンピュータに実行させるプログラムを当該コンピュータの入力手段が読取可能に記憶した記憶媒体において、 前記プログラムは前記コンピュータをアプリケーション間でやりとりされるメッセージ文書に施す電子署名を生成するための鍵を管理する鍵管理手段と、 所定の前記アプリケーションから送信されたメッセージ文書を取得し、当該メッセージ文書に基づいて電子署名を行うための鍵を決定する署名鍵判定手段と、 前記署名鍵判定手段の決定に基づいて前記鍵管理手段から取得した鍵を用いて、前記メッセージ文書に対して電子署名を行う署名生成手段として機能させることを特徴とする記憶媒体。
  10. 18
    In a storage medium in which a program to be executed by a computer is readablely stored by an input means of the computer. The program A process of selecting a key for digitally signing a message document according to the type of the message document sent from a predetermined application, and In principle, the message document is digitally signed using the selected key, and when the usage conditions are set for the key and the usage conditions are not satisfied, the key is used. Instead, a process of digitally signing the message document using a preset alternative key, and After electronically signing the message document using the alternative key, when the usage conditions of the original key are satisfied, the message document is digitally signed again using the original key. A storage medium characterized by causing the computer to perform processing. 【請求項18】 コンピュータに実行させるプログラムを当該コンピュータの入力手段が読取可能に記憶した記憶媒体において、 前記プログラムは、 所定のアプリケーションから送信されたメッセージ文書の種類に応じて、当該メッセージ文書に電子署名を施すための鍵を選択する処理と、 原則として選択された前記鍵を用いて前記メッセージ文書に電子署名を行い、当該鍵に対して使用条件が設定されている場合であって、当該使用条件が満たされていない場合に、当該鍵に代えて予め設定された代替用の鍵を用いて前記メッセージ文書に電子署名を行う処理と、 前記代替用の鍵を用いて前記メッセージ文書に電子署名を行った後、本来の前記鍵における前記使用条件が満たされた際に、当該本来の鍵を用いて前記メッセージ文書に改めて電子署名を行う処理とを前記コンピュータに実行させることを特徴とする記憶媒体。
  11. 19
    The computer acquires a key management means for managing a key for generating a digital signature applied to a message document exchanged between applications, and a message document transmitted from the predetermined application, and obtains the message. The message document is digitally signed using a signature key determining means for determining a key for digitally signing based on the document and a key obtained from the key management means based on the determination of the signing key determining means. A storage means for storing a program that functions as a signature generation means for performing A program transmission device including a transmission means for reading the program from the storage means and transmitting the program. 【請求項19】 コンピュータを、アプリケーション間でやりとりされるメッセージ文書に施す電子署名を生成するための鍵を管理する鍵管理手段と、所定の前記アプリケーションから送信されたメッセージ文書を取得し、当該メッセージ文書に基づいて電子署名を行うための鍵を決定する署名鍵判定手段と、前記署名鍵判定手段の決定に基づいて前記鍵管理手段から取得した鍵を用いて、前記メッセージ文書に対して電子署名を行う署名生成手段として機能させるプログラムを記憶する記憶手段と、 前記記憶手段から前記プログラムを読み出して当該プログラムを送信する送信手段とを備えたことを特徴とするプログラム伝送装置。
  12. 20
    [Claim 20] To the computer, A process of selecting a key for digitally signing the message document according to the type of the message document sent from a predetermined application, and a digital signature of the message document using the selected key in principle. , When the usage conditions are set for the key and the usage conditions are not satisfied, a preset alternative key is used in place of the key to electronically send the message document. After the process of signing and the electronic signature of the message document using the alternative key, when the usage conditions of the original key are satisfied, the message document is used with the original key. A storage means for storing a program that executes a process of digitally signing a new digital signature. A program transmission device including a transmission means for reading the program from the storage means and transmitting the program. 【請求項20】 コンピュータに、 所定のアプリケーションから送信されたメッセージ文書の種類に応じて、当該メッセージ文書に電子署名を施すための鍵を選択する処理と、原則として選択された前記鍵を用いて前記メッセージ文書に電子署名を行い、当該鍵に対して使用条件が設定されている場合であって、当該使用条件が満たされていない場合に、当該鍵に代えて予め設定された代替用の鍵を用いて前記メッセージ文書に電子署名を行う処理と、前記代替用の鍵を用いて前記メッセージ文書に電子署名を行った後、本来の前記鍵における前記使用条件が満たされた際に、当該本来の鍵を用いて前記メッセージ文書に改めて電子署名を行う処理とを実行させるプログラムを記憶する記憶手段と、 前記記憶手段から前記プログラムを読み出して当該プログラムを送信する送信手段とを備えたことを特徴とするプログラム伝送装置。