Proxy server, electronic signature system, electronic signature verification system, network system, electronic signature method, electronic signature verification method, recording medium and program transmission device
Abstract
(57) A summary and subject The security function by an electronic signature is realized by mounting a means to perform the electronic signature of the message sent and received through a network, verification, and logging, in the form of a proxy server, without needing change of an application program. Solution means It has the application 10 which performs data processing, and the signature proxy server 20 connected to this application 10 through LAN100, This signature proxy server 20 intercepts the message communication from the application 10 to the equipment of the exterior of LAN100, performs an electronic signature in the message document in this message communication, and transmits a message document with an electronic signature to the equipment which is a transmission destination.

Term
Term ended
Projected expiry passed 2 November 2020, 5.9 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
20 claims: 12 independent, 8 dependent
- 1[Claims] 1. In a proxy server that relays communication between applications and performs additional processing. A key management unit that manages a key for generating a digital signature to be applied to a message document exchanged between the applications, and a key management unit. A signature key determination unit that acquires a message document transmitted from the predetermined application and determines a key for digitally signing based on the message document. Using the key obtained from the key management unit based on the determination of the signature key determination unit, the message document is digitally signed, and the signed message document is sent to another application to which the message document is sent. A proxy server characterized by having a signature generator. 【特許請求の範囲】 【請求項1】 アプリケーション間で行われる通信を中継し、付加的処理を行うプロキシサーバにおいて、 前記アプリケーション間でやりとりされるメッセージ文書に施す電子署名を生成するための鍵を管理する鍵管理部と、 所定の前記アプリケーションから送信されたメッセージ文書を取得し、当該メッセージ文書に基づいて電子署名を行うための鍵を決定する署名鍵判定部と、 前記署名鍵判定部の決定に基づいて前記鍵管理部から取得した鍵を用いて、前記メッセージ文書に対して電子署名を行い、署名された当該メッセージ文書を送信先である他の前記アプリケーションに送る署名生成部とを備えたことを特徴とするプロキシサーバ。
- 2The key management unit sets acquisition conditions for the key, and when the acquisition conditions are satisfied, the signature generation unit can acquire the corresponding key. Proxy server described in 1. 【請求項2】 前記鍵管理部は、前記鍵の取得条件を設定し、当該取得条件を満足する場合に、前記署名生成部が該当する前記鍵を取得可能とすることを特徴とする請求項1に記載のプロキシサーバ。
- 6When the signature generation unit digitally signs using the alternative key, the log management unit is used together with the electronically signed message document before the electronic signature is applied. Stores the message document of When the signature generation unit performs an electronic signature using the original key, the request is characterized in that the message document before the electronic signature is applied is acquired from the log management unit and the electronic signature is performed. The proxy server described in Section 4. 【請求項6】 前記ログ管理部は、前記署名生成部が前記代替用の鍵を用いて電子署名を行った場合に、電子署名が施された前記メッセージ文書と共に、電子署名が施される前の前記メッセージ文書を格納し、 前記署名生成部は、前記本来の鍵を用いて電子署名を行う場合に、前記ログ管理部から前記電子署名が施される前のメッセージ文書を取得して電子署名を行うことを特徴とする請求項4に記載のプロキシサーバ。
- 7An application that performs data processing and a proxy server connected to the application via a network are provided. The proxy server intercepts a message communication from the application to a device outside the network, digitally signs the message document in the message communication, and transmits the electronically signed message document to the device. Signature system. 【請求項7】 データ処理を行うアプリケーションと、ネットワークを介して当該アプリケーションに接続されたプロキシサーバとを備え、 前記プロキシサーバは、前記アプリケーションから前記ネットワーク外部の装置へのメッセージ通信をインターセプトし、当該メッセージ通信におけるメッセージ文書に電子署名を行い、電子署名付きメッセージ文書を前記装置へ送信することを特徴とする電子署名システム。
- 10An application that performs data processing and a proxy server connected to the application via a network are provided. The proxy server intercepts the message communication from the device outside the network to the application, verifies the electronic signature of the message document in the message communication, and delivers the message document whose validity has been confirmed by the verification to the application. An electronic signature verification system characterized by sending. 【請求項10】 データ処理を行うアプリケーションと、ネットワークを介して当該アプリケーションに接続されたプロキシサーバとを備え、 前記プロキシサーバは、前記ネットワーク外部の装置から前記アプリケーションへのメッセージ通信をインターセプトし、当該メッセージ通信におけるメッセージ文書の電子署名を検証し、当該検証により正当性が確認された当該メッセージ文書を前記アプリケーションへ送信することを特徴とする電子署名検証システム。
- 11A network system including a plurality of groups connected by a wide area network, and each group includes an application for processing data and a proxy server connected to the application via a local network. The proxy server Intercept the message communication from the application of the own group to the application of the other group, digitally sign the message document in the message communication, and send the message document with the electronic signature to the application of the other group. The message communication from the application of another group to the application of the own group is intercepted, the electronic signature of the message document in the message communication is verified, and the message document whose validity is confirmed by the verification is the message document of the own group. A network system characterized by sending to an application. 【請求項11】 広域ネットワークで接続された複数のグループを備え、各グループは、データ処理を行うアプリケーションと、ローカルなネットワークを介して当該アプリケーションに接続されたプロキシサーバとを備えたネットワークシステムにおいて、 前記プロキシサーバは、 自グループの前記アプリケーションから他のグループの前記アプリケーションへのメッセージ通信をインターセプトし、当該メッセージ通信におけるメッセージ文書に電子署名を行い、電子署名付きメッセージ文書を前記他のグループの前記アプリケーションへ送信し、 他のグループの前記アプリケーションから自グループの前記アプリケーションへのメッセージ通信をインターセプトし、当該メッセージ通信におけるメッセージ文書の電子署名を検証し、当該検証により正当性が確認された当該メッセージ文書を前記自グループのアプリケーションへ送信することを特徴とするネットワークシステム。
- 15In an electronic signature method that guarantees the validity of a message document by electronically signing the message document in communication performed between applications. A step of selecting a key for digitally signing the message document according to the type of the message document sent from the predetermined application, and a step of selecting the key for digitally signing the message document. When the usage conditions are set for the key and the usage conditions are not satisfied, the message document is digitally signed using a preset alternative key instead of the key. And the step of sending the message document with the digital signature to the destination when it is sent from the application. After electronically signing the message document using the alternative key, when the usage conditions of the original key are satisfied, the message document is digitally signed again using the original key. , A method of electronic signature comprising the step of transmitting a message document with the electronic signature to a destination when the message document is transmitted from the application. 【請求項15】 アプリケーション間で行われる通信におけるメッセージ文書に電子署名を施すことにより、当該メッセージ文書の正当性を保証する電子署名方法において、 所定の前記アプリケーションから送信されたメッセージ文書の種類に応じて、当該メッセージ文書に電子署名を施すための鍵を選択するステップと、 当該鍵に対して使用条件が設定されている場合であって、当該使用条件が満たされていない場合に、当該鍵に代えて予め設定された代替用の鍵を用いて前記メッセージ文書に電子署名を行い、当該電子署名付きのメッセージ文書を前記アプリケーションから送信された際の送信先に送信するステップと、 前記代替用の鍵を用いて前記メッセージ文書に電子署名を行った後、本来の前記鍵における前記使用条件が満たされた際に、当該本来の鍵を用いて前記メッセージ文書に改めて電子署名を行い、当該電子署名付きのメッセージ文書を前記アプリケーションから送信された際の送信先に送信するステップとを含むことを特徴とする電子署名方法。
- 16In an electronic signature verification method for confirming the validity of a message document by verifying the electronic signature given to the message document in communication performed between applications. When the electronic signature given to the received message document is not the key specified according to the type of the message document but the electronic signature made by using the substitute key of the key, the substitute key is used. Steps to receive the message document signed with the key of After receiving the message document signed with the alternative key, the step of receiving the message document signed with the original key, and The electronic signature verification includes a step of verifying the validity of the message document signed by using the alternative key received earlier by verifying the electronic signature using the original key. Method. 【請求項16】 アプリケーション間で行われる通信におけるメッセージ文書に施された電子署名を検証することにより、当該メッセージ文書の正当性を確認する電子署名検証方法において、 受信したメッセージ文書に施された電子署名が、当該メッセージ文書の種類に応じて定められた鍵ではなく、当該鍵の代替用の鍵を用いて行われた電子署名である場合に、当該代替用の鍵を用いて署名された当該メッセージ文書を受領するステップと、 前記代替用の鍵を用いて署名されたメッセージ文書を受領した後、本来の前記鍵を用いて署名された当該メッセージ文書を受信するステップと、 前記本来の鍵を用いた電子署名を検証することにより、先に受領した前記代替用の鍵を用いて署名されたメッセージ文書の正当性を確認するステップとを含むことを特徴とする電子署名検証方法。
- 17In a storage medium in which a program to be executed by a computer is readablely stored by an input means of the computer. The program is a key management means that manages a key for generating a digital signature that gives the computer a message document exchanged between applications. A signature key determination means for acquiring a message document transmitted from the predetermined application and determining a key for digitally signing based on the message document. A storage medium characterized in that a key obtained from the key management means based on the determination of the signature key determination means is used to function as a signature generation means for electronically signing the message document. 【請求項17】 コンピュータに実行させるプログラムを当該コンピュータの入力手段が読取可能に記憶した記憶媒体において、 前記プログラムは前記コンピュータをアプリケーション間でやりとりされるメッセージ文書に施す電子署名を生成するための鍵を管理する鍵管理手段と、 所定の前記アプリケーションから送信されたメッセージ文書を取得し、当該メッセージ文書に基づいて電子署名を行うための鍵を決定する署名鍵判定手段と、 前記署名鍵判定手段の決定に基づいて前記鍵管理手段から取得した鍵を用いて、前記メッセージ文書に対して電子署名を行う署名生成手段として機能させることを特徴とする記憶媒体。
- 18In a storage medium in which a program to be executed by a computer is readablely stored by an input means of the computer. The program A process of selecting a key for digitally signing a message document according to the type of the message document sent from a predetermined application, and In principle, the message document is digitally signed using the selected key, and when the usage conditions are set for the key and the usage conditions are not satisfied, the key is used. Instead, a process of digitally signing the message document using a preset alternative key, and After electronically signing the message document using the alternative key, when the usage conditions of the original key are satisfied, the message document is digitally signed again using the original key. A storage medium characterized by causing the computer to perform processing. 【請求項18】 コンピュータに実行させるプログラムを当該コンピュータの入力手段が読取可能に記憶した記憶媒体において、 前記プログラムは、 所定のアプリケーションから送信されたメッセージ文書の種類に応じて、当該メッセージ文書に電子署名を施すための鍵を選択する処理と、 原則として選択された前記鍵を用いて前記メッセージ文書に電子署名を行い、当該鍵に対して使用条件が設定されている場合であって、当該使用条件が満たされていない場合に、当該鍵に代えて予め設定された代替用の鍵を用いて前記メッセージ文書に電子署名を行う処理と、 前記代替用の鍵を用いて前記メッセージ文書に電子署名を行った後、本来の前記鍵における前記使用条件が満たされた際に、当該本来の鍵を用いて前記メッセージ文書に改めて電子署名を行う処理とを前記コンピュータに実行させることを特徴とする記憶媒体。
- 19The computer acquires a key management means for managing a key for generating a digital signature applied to a message document exchanged between applications, and a message document transmitted from the predetermined application, and obtains the message. The message document is digitally signed using a signature key determining means for determining a key for digitally signing based on the document and a key obtained from the key management means based on the determination of the signing key determining means. A storage means for storing a program that functions as a signature generation means for performing A program transmission device including a transmission means for reading the program from the storage means and transmitting the program. 【請求項19】 コンピュータを、アプリケーション間でやりとりされるメッセージ文書に施す電子署名を生成するための鍵を管理する鍵管理手段と、所定の前記アプリケーションから送信されたメッセージ文書を取得し、当該メッセージ文書に基づいて電子署名を行うための鍵を決定する署名鍵判定手段と、前記署名鍵判定手段の決定に基づいて前記鍵管理手段から取得した鍵を用いて、前記メッセージ文書に対して電子署名を行う署名生成手段として機能させるプログラムを記憶する記憶手段と、 前記記憶手段から前記プログラムを読み出して当該プログラムを送信する送信手段とを備えたことを特徴とするプログラム伝送装置。
- 20[Claim 20] To the computer, A process of selecting a key for digitally signing the message document according to the type of the message document sent from a predetermined application, and a digital signature of the message document using the selected key in principle. , When the usage conditions are set for the key and the usage conditions are not satisfied, a preset alternative key is used in place of the key to electronically send the message document. After the process of signing and the electronic signature of the message document using the alternative key, when the usage conditions of the original key are satisfied, the message document is used with the original key. A storage means for storing a program that executes a process of digitally signing a new digital signature. A program transmission device including a transmission means for reading the program from the storage means and transmitting the program. 【請求項20】 コンピュータに、 所定のアプリケーションから送信されたメッセージ文書の種類に応じて、当該メッセージ文書に電子署名を施すための鍵を選択する処理と、原則として選択された前記鍵を用いて前記メッセージ文書に電子署名を行い、当該鍵に対して使用条件が設定されている場合であって、当該使用条件が満たされていない場合に、当該鍵に代えて予め設定された代替用の鍵を用いて前記メッセージ文書に電子署名を行う処理と、前記代替用の鍵を用いて前記メッセージ文書に電子署名を行った後、本来の前記鍵における前記使用条件が満たされた際に、当該本来の鍵を用いて前記メッセージ文書に改めて電子署名を行う処理とを実行させるプログラムを記憶する記憶手段と、 前記記憶手段から前記プログラムを読み出して当該プログラムを送信する送信手段とを備えたことを特徴とするプログラム伝送装置。
Independent claims12
131 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to a technique for guaranteeing message authentication and evidence by performing electronic signature and verification in inter-business message communication on the Internet or the like.
【0002】
[Conventional technology]
In recent years, with the progress of network technology such as the Internet, business forms in which business transactions and businesses are carried out by message communication via a network have become widespread. Ensuring security is a major issue in such a business form.
【0003】
An XML digital signature is being defined as a data exchange format for inter-business message communication on a network, and it is expected that this XML digital signature will ensure message authentication and transaction proof. Here, the electronic signature is a technique for guaranteeing the validity of a document by adding signature information (the signature information itself is also digital information) to digital information. Generally, public key cryptography is used for signatures. The signer creates a signature statement using the hash function-compressed document and a private key that only he knows, and sends it with the original document. The verifier verifies that the signature is correct based on the signer's public key, the signature text, and the original document.
【0004】
The electronic signature has a function that cannot be forged by a third party or a recipient (verifier) and a function that the person who signed the signature cannot deny it later. Therefore, by signing each message with a unique ID number, 1. The message was certainly created by the caller 2. The message has not been tampered with 3. Do not mistakenly accept the same message twice 4. The caller sent the message It is possible to realize the function to prove each of the above.
【0005】
[Problems to be Solved by the Invention]
However, in order to sign and verify a message using an existing cryptographic library, it is necessary to make changes to the application program that intends to use this digital signature, and the cost required for this is high.
【0006】
In addition, in order to enhance the evidence of the electronic signature, conditions for performing the electronic signature may be set. For example, a time-limited electronic signature that can be signed only in a certain time zone, or an electronic signature that cannot be signed without performing a certain process can be considered. In such a case, it may be convenient in business if another electronic signature is used as a substitute for the electronic signature and the subsequent signature can be made later by the electronic signature.
【0007】
In addition, these signed messages must be stored in a secure log to allow subsequent audits while signing and verifying. These stored messages cannot be tampered with because they are signed, but they can be viewed as they are. However, in message communication between businesses, important confidential information may be included, so access control is required for logs.
【0008】
Therefore, the present invention implements a means for digitally signing, verifying, and logging messages sent and received via a network in the form of a proxy server, so that security by digital signature is used without requiring modification of an application program. The purpose is to realize the function.
【0009】
Another object of the present invention is to realize a signature method such as a post-signature by controlling electronic signature and verification using a proxy server.
【0010】
Another object of the present invention is to enable access control to the message log by logging the message using a proxy server.
【0011】
[Means for solving problems]
In order to achieve the above object, the present invention provides a key for generating a digital signature to be applied to a message document exchanged between applications in a proxy server that relays communication performed between applications and performs additional processing. To determine the key management unit to be managed, the signature key determination unit that acquires the message document sent from a predetermined application and determines the key for digitally signing based on this message document, and the signature key determination unit. Based on this, the key obtained from this key management unit is used to digitally sign this message document, and the signature generation unit is provided to send the signed message document to another application to which it is sent. And. As a result, it is possible to digitally sign with different security according to the content of the message document.
【0012】
Here, the key management unit sets the acquisition condition of the key, and the signature generation unit can acquire the corresponding key only when the acquisition condition is satisfied. That is, since it is necessary to satisfy certain conditions in order to obtain the key, the reliability of the electronic signature using this key can be enhanced. As the acquisition condition, it is possible to set a time condition that limits the time zone in which the key can be used, and a processing condition that the key cannot be used until after a certain process has been performed on the message document.
【0013】
In addition, if the signature generator cannot acquire this key because it does not satisfy the acquisition conditions for the key for generating the electronic signature to be applied to the message document, the signature generator uses a preset alternative key to digitally sign. It can be carried out. In this case, the signature generator can acquire this original key by performing an electronic signature using the alternative key and then satisfying the original key acquisition condition determined based on the message document to be signed. In the case of, the electronic signature can be performed again using this original key. This ex post facto signature may be additionally performed on the message document signed by using the alternative key, or newly performed on the message document in the state before signing by using the alternative key. Is also good.
【0014】
Further, in addition to the above configuration, the proxy server of the present invention can be configured to include a log management unit that stores a message document digitally signed by the signature generation unit and manages the log. As described above, when a new post-signature is performed on the message document in the state before the signature using the alternative key, the signature generation unit digitally signs the message document using the alternative key. In this case, the message document before the digital signature is stored together with the message document with the digital signature, and the signature generation unit uses the original key to perform the digital signature from this log management unit. It is possible to obtain a message document in a state before the digital signature is applied and digitally sign the message.
【0015】
Further, the present invention can provide an electronic signature system characterized by being configured as follows by using the proxy server described above. That is, this digital signature system includes an application that processes data and a proxy server that is connected to this application via a network, and this proxy server intercepts message communication from the application to a device outside the network. The message document in this message communication is electronically signed, and the electronically signed message document is transmitted to the destination device.
【0016】
In this digital signature system, the proxy server is via hardware that intercepts information flowing over the network (without the receiver and sender being aware of the transparency), or through a switch that is realized by software that realizes similar functions. To connect to the network. As such a switch, a layer 4 switch can be used. As a result, the message communication by the application can be intercepted, so that the message document can be digitally signed without making any changes to the application (that is, the application is completely unaware of the digital signature).
【0017】
Further, the present invention can provide an electronic signature verification system characterized by being configured as follows. That is, this digital signature verification system includes an application that processes data and a proxy server that is connected to this application via a network, and this proxy server intercepts message communication from a device outside the network to the application. , The electronic signature of the message document in this message communication is verified, and the message document whose validity is confirmed by this verification is sent to the application.
【0018】
Also in this electronic signature verification system, this proxy server can be connected to the network via a switch such as a layer 4 switch. As a result, message communication from outside the network can be intercepted, so that the electronic signature of the message document can be verified without making any changes to the application (that is, the application is completely unaware of the electronic signature).
【0019】
Further, the present invention includes a plurality of groups connected by a wide area network, and each group is provided in a network system including an application for processing data and a proxy server connected to the application via a local network. This proxy server intercepts the message communication from the application of its own group to the application of another group, digitally signs the message document in this message communication, and the application of the other group to which the electronically signed message document is sent. Sends to, intercepts the message communication from the application of another group to the application of the own group, verifies the electronic signature of the message document in this message communication, and sends the message document whose validity is confirmed by this verification at the destination. It is characterized by sending to an application of a certain own group.
【0020】
Here, this proxy server stores the electronically signed message document and manages the log when the application of the own group sends the message document, and when the message document is received from another group, the electronic signature is electronically signed. The message document whose validity has been confirmed by the verification of is stored and the log is managed. Then, the validity of the message communication can be confirmed by comparing the log on the transmitting side and the log on the receiving side regarding the same message document at a predetermined timing. The information to be compared does not have to be all the information in the log, and it is possible to compare the signature information of the electronic signature for the same message document and the hash value used for digitally signing the same message document. .. In this case, if these information in the log are the same, the validity of the message communication can be confirmed. Then, if these information are different, a detailed examination will be conducted by comparing all the information in the log again.
【0021】
Further, the present invention is an electronic signature method for guaranteeing the validity of a message document by digitally signing the message document in communication performed between applications, depending on the type of the message document transmitted from a predetermined application. Then, in the step of selecting a key for digitally signing this message document, and when the usage conditions are set for this key and the usage conditions are not satisfied, this key is used. Instead, digitally sign the message document using a preset alternative key, send the message document with the electronic signature to the destination when it is sent from the application, and digitally sign using this alternative key. After that, when the conditions of use of the original key are satisfied, the electronic signature is re-signed using the original key, and the message document with the electronic signature is transmitted to the destination.
【0022】
Further, the present invention is an electronic signature verification method for confirming the validity of this message document by verifying the electronic signature given to the message document in the communication performed between applications. When the signature is a digital signature made using an alternative key instead of the key specified according to the type of this message document, the step of receiving this message document signed using this alternative key. After receiving the message document signed with the alternate key, receive it first by verifying the digital signature with the original key and the step of receiving the message document signed with the original key. It is characterized by including a step of confirming the validity of a message document signed by using an alternative key.
【0023】
Further, the present invention is created as a program that causes a computer to execute a process corresponding to each step of these electronic signature methods and electronic signature verification methods, or as a program product that controls a computer to realize the above-mentioned proxy server. , This program can be provided as a storage medium for storing this program or as a transmission device for transmitting this program.
【0024】
BEST MODE FOR CARRYING OUT THE INVENTION
Hereinafter, the present invention will be described in detail based on the embodiments shown in the accompanying drawings. FIG. 1 is a diagram illustrating an overall configuration of an electronic signature system according to the present embodiment. In FIG. 1, the company A and the company B include 10 groups of applications that perform message communication and a signature proxy server 20 that manages electronic signatures in messages exchanged by the 10 groups of applications. Here, the application 10 is a computer device controlled by a predetermined program and realizing various functions including message communication. In FIG. 1, each application 10 and the signature proxy server 20 are described separately, but this is a function-based distinction and does not necessarily mean a hardware configuration. That is, it may be physically configured with individual hardware, or some applications 10 may be running on common hardware.
【0025】
As shown in FIG. 1, companies A and B are connected via a wide area network 200 such as the Internet. Further, in each of the companies A and B, the application 10 is connected to the LAN 100 such as the in-house network, and is connected to the network 200 via the firewall 40. The signature proxy server 20 is connected to the LAN 100 via the switch 30. Here, the switch 30 is realized by hardware (for example, a layer 4 switch) that intercepts information flowing on the network (without being noticed by the receiver and the sender), or software that realizes a similar function. ..
【0026】
In this embodiment, an example in which an electronic signature system is used for exchanging messages between companies A and B assuming inter-business communication will be described, but regardless of the business, message communication between specific groups and message communication between specific groups will be described. The electronic signature system according to this embodiment can also be applied to the exchange of e-mails including the individual level.
【0027】
Further, the configuration shown in FIG. 1 is merely an example, and other configurations may be used as long as the application 10 and the signature proxy server 20 are grouped into one group and a plurality of groups are connected to each other via a network. .. Therefore, the switch 30 and the firewall 40 are not necessarily essential components. However, in this embodiment, the firewall 40 is provided in consideration of inter-company communication. Further, in order to intercept the communication between the applications 10 and add and manage the electronic signature without changing the application 10, the signature proxy server 20 is connected via the switch 30.
【0028】
Furthermore, in the present embodiment, the message communication between the companies A and B (or between the applications 10 of the companies A and B) is based on an XML document. However, it goes without saying that this embodiment can be directly applied to documents and e-mails in formats other than XML.
【0029】
In FIG. 1, the application 10 creates a message document necessary for business such as a purchase order, a purchase order, and a statement of a product as an XML document, and transmits the message document to the application 10 corresponding to the business of the partner company.
【0030】
The signature proxy server 20 has a function of intercepting an HTTP connection for sending a message document from an in-house application 10 to another company, and a function of intercepting an HTTP connection from outside the company to a predetermined application 10 in the company (reverse proxy). And. Then, regarding the intercepted message document, the necessary electronic signature is performed for the document transmitted from the inside to the outside, and the electronic signature is verified for the document sent from the outside to the inside. The detailed configuration and operation of the signature proxy server 20 will be described later.
【0031】
A switch 30 is provided between the firewall 40 placed at the boundary (entrance / exit) between the LAN 100 and the network 200 and each application 10, and the signature proxy server 20 and the LAN 100 are connected via this switch 30 to sign. The proxy server 20 can intercept the above HTTP connection . By changing the URL of each application 10 without using the switch 30, it is possible to set communication via the signature proxy server 20. However, by using the switch 30, the digital signature can be added and managed by the signature proxy server 20 without making any changes to the application 10.
【0032】
In addition, the signature proxy platform (OS) is required to have high security in each of the following points. That is, 1. The private key for signing must not be stolen 2. The root certificate authority key for verification must not be rewritten 3. Log access control must not be bypassed Is. Therefore, it is necessary to make the signature proxy server 20 inaccessible to the normal Internet or very limited. As a method for that, for example, a method using a network address (for example, a local address such as 192.168.xx.xx) that cannot be accessed from the outside to the proxy can be considered. Another method is to convert the intercepted packet to a medium such as RS-232C or USB that normally does not pass TCP / IP, and then send it to the signature proxy server 20. By using these methods, the keys and logs can be protected more safely.
【0033】
FIG. 2 is a diagram showing a configuration regarding the addition of a digital signature of the signature proxy server 20. The digital signature in the present embodiment is an XML digital signature by public key cryptography using a hash function. Referring to FIG. 2, the signature proxy server 20 has a signature key determination unit 21 that selects a private key for signature for digital signature, a key management unit 22 that manages a private key for signature, and a signature key determination. Signature information is generated using the signature key acquisition unit 23 that acquires the necessary private key from the key management unit 22 according to the selection of the unit 21 and the private key acquired by the signature key acquisition unit 23, and the message document is signed. It includes a signature generation unit 24 and a log management unit 25 that manages a log of message documents.
【0034】
The signature key determination unit 21 acquires an XML document which is a message document sent from the in-house application 10. Then, based on a predetermined key selection rule, the private key necessary for properly signing the XML document is selected. Here, the key selection rule is a rule for selecting a private key based on the contents of an XML document, and is described in, for example, an XML format. The electronic signature added to the XML document is something like a date stamp that is automatically added to all documents outside the company, or one that the responsible person checks and signs one by one. , Something like a company's official seal, or something with an intermediate character between them, etc., various meanings can be set. The difference in the meaning of these signatures is determined by the meaning of the signing key (usually described as an authentication practice statement in the digital certificate corresponding to the signing key). As described above, different private keys can be used depending on the contents of the XML document, but this is done by registering the pair of the contents of the XML document and the private key to be used as a rule in the signature key determination unit 21. realizable. Since the content of the XML document is expressed using XPath, it is possible to specify a complicated pattern. Furthermore, this can be used to specify only a specific range in the XML document as the signature range. FIG. 6 is a diagram showing an example of a key selection rule described in XML format. Here, in electronic commerce, a company seal (equivalent to a secret key) is used as a private key for electronic signatures for transactions with an amount of 1 million yen or more, and for transactions with an amount of 100,000 yen or more. , It is stipulated to use the person in charge seal (corresponding private key).
【0035】
The key management unit 22 manages a private key used for digitally signing an XML document. It is also possible to set acquisition conditions (use conditions) for acquiring the private key prepared for digital signature and manage it. That is, when acquisition conditions such as time and prerequisite processing are set when using the private key, if the set acquisition conditions are satisfied, the corresponding private key can be used, and in other cases, the relevant private key is applicable. Disable the private key. Whether or not the private key can be used can be controlled, for example, by loading or unloading the data of the private key. For example, if a time condition is set that a predetermined electronic signature can be signed only during a certain time period of the day, the private key required to generate the electronic signature is used only during that time period. Load and make it available. If the acquisition conditions are set in this way, it is necessary to satisfy certain conditions in order to acquire the private key, so that the reliability of the electronic signature made by using the private key can be enhanced.
【0036】
The signature key acquisition unit 23 acquires the private key selected by the signature key determination unit 21 according to the contents of the XML document from the key management unit 22 and passes it to the signature generation unit 24. As described above, if the acquisition condition is set for the private key and the signing key determination unit 21 does not satisfy the acquisition condition of the private key when the private key is selected, it is set by default. The alternative private key (hereinafter referred to as the alternative key) can be passed to the signature generator 24. In this case, when the acquisition condition of the private key selected by the signature key determination unit 21 is satisfied, the private key can be acquired again and passed to the signature generation unit 24. When the above-mentioned time constraint is set as an acquisition condition, if the time when the signing key acquisition unit 23 tries to acquire the private key is not the time zone when the private key is loaded in the key management unit 22, the signature key acquisition is performed. The unit 23 passes the alternative key to the signature generation unit 24. Then, when it is time for the private key to be loaded into the key management unit 22, the signature key acquisition unit 23 acquires the private key from the key management unit 22 and passes it to the signature generation unit 24.
【0037】
The signature generation unit 24 digitally signs the XML document using the private key acquired by the signature key acquisition unit 23. The XML document to be digitally signed is, in principle, an XML document transmitted from the application 10 and intercepted by the switch 30. However, as described above, when the acquisition condition is set for the private key and the XML document acquired by interception is digitally signed using the alternative key, the XML document is concerned. On the other hand, after acquiring the original private key, the digital signature is performed again using the private key. In this case, the subsequent digital signature using the private key may be additionally performed on the XML document that has been digitally signed using the alternative key, or before the electronic signature using the alternative key is applied. You may newly go to the XML document of the state. The XML document digitally signed by the signature generation unit 24 is returned to the LAN 100 and sent to the destination when the application 10 sends the document, and is also sent to the log management unit 25 for management.
【0038】
The log management unit 25 collects and manages a log of an XML document digitally signed by the signature generation unit 24. Digitally signed XML documents usually must be securely stored for later auditing. Logs can also be taken at the application 10 or communication level, but the best way to log with a valid signature is at the time of signing or verification. This is because the signature is guaranteed to be correct, at least at the stage of logging. If you do not log at the time of signing, you may not be able to audit what you signed for later. To log the signed XML document, the XML document signed by the signature generator 24 may be stored as it is in a long-term stable storage device (hard disk, etc.). Since the stored XML document is digitally signed, the log cannot be tampered with illegally. The log may contain highly confidential information such as a credit card number. Therefore, it is necessary to impose appropriate access restrictions on log access. This access control can also be applied to parts of the log (eg credit card numbers only). Further, as described above, when the acquisition condition is set for the acquisition of the private key, an electronic signature is added in order to re-sign the XML document signed by using the alternative key later by using the private key. It is also possible to store and manage XML documents that are not in the state.
【0039】
FIG. 3 is a diagram showing a configuration for verifying the electronic signature of the signature proxy server 20. Referring to FIG. 3, the signature proxy server 20 manages the signature information acquisition unit 31 that acquires the signature information of the electronic signature from the received message document, and the key management that manages the public key used to verify the acquired signature information. It includes a unit 32, a verification unit 33 that verifies the validity of the electronic signature based on the acquired signature information, and a log management unit 34 that manages the log of the received message document.
【0040】
The signature information acquisition unit 31 acquires an XML document which is a message document received from outside the company. Then, the signature information of the electronic signature attached to the XML document is acquired, and the public key necessary for verifying the XML document based on the information described in the XML document is obtained from the key management unit 32. Obtain it and pass it to the verification unit 33.
【0041】
The key management unit 32 manages the public key for verifying the electronic signature attached to the XML document. As the public key, the public key corresponding to the private key used for signing the XML document may be stored in advance on the signing proxy server 20 or the network system in the company by providing a storage means, or the network is stored from an external authentication authority. You may get it through.
【0042】
The verification unit 33 verifies the electronic signature using the public key corresponding to the content of the XML document. Then, when the validity of the XML document is confirmed, the XML document is returned to the LAN 100 and sent to the application 10 which is the destination, and also sent to the log management unit 34. If the validity of the XML document is denied, preset error processing is performed without returning the XML document to LAN100. When the digital signature added to the XML document is not a digital signature made using a private key according to the contents of the XML document, but a digital signature made using a predetermined alternative key (this). Can be recognized by selecting the public key when verifying the digital signature), and the verification unit 33 waits for the arrival of the XML document signed with the original private key to make a final legitimacy judgment. Do.
【0043】
In this case, the XML document signed with the alternative key may be kept in the signing proxy server 20 until the XML document signed with the original private key arrives, or the original private key may be retained. The XML document signed by the user may be sent to the application 10 without waiting for the arrival of the XML document, and the processing may proceed in advance. In either case, the expiration date of the XML document signed with the alternative key is set, and if the XML document signed with the original private key does not arrive within the expiration date, the relevant Invalidates an XML document signed with an alternate key. In order to link the XML document signed by using the alternative key and the XML document signed by using the original private key, it is possible to take measures such as collating the document ID.
【0044】
As an embodiment in which the method of digitally signing using an alternative key is effectively performed, processing is carried out using an XML document signed using the alternative key, and the original secret is kept even after a predetermined fixed time has passed. If the XML document signed with the key does not arrive, it is conceivable to perform control so as to invalidate the preceding processing.
【0045】
The log management unit 34 collects and manages a log of the signed XML document verified by the verification unit 33 and the verification result thereof. To log the signed XML document, the XML document verified by the verification unit 33 may be stored as it is in a long-term stable storage device (hard disk, etc.). Since the stored XML document is digitally signed, the log cannot be tampered with illegally. By comparing the log data accumulated in this way with the log data managed by the log management unit 25 on the signature execution side of the signature proxy server 20 of the trading partner, the integrity of the log data is guaranteed and the security of the business is ensured. It can be made even stronger.
【0046】
Here, it is not necessary to compare the log data for all the signed XML documents in the log stored in the log management unit 25, and if the signature information of the electronic signature, especially the hash value used at the time of signing, is compared. It is enough. As an example, consider the comparison of log data in the message communication between companies A and B in Fig. 1. In this case, the hash values of the log data of both companies A and B are exchanged and compared with each other at a fixed timing such as monthly. Then, if the hash value used for the message communication between the companies A and B is common, it can be seen that all the message communication is authenticated by both parties by the electronic signature. On the other hand, if the hash values are different, it can be seen that there is message communication in which either company A or company B has not authenticated. Therefore, this time, all log data is exchanged, and which message document is not certified by companies A and B is searched.
【0047】
Each component of the signature proxy server 20 shown in FIGS. 2 and 3 is a virtual software block realized by a CPU controlled by a computer program. The computer program that controls the CPU is provided by storing it in a storage medium such as a CD-ROM or a floppy (registered trademark) disk, or transmitting it via a network. Further, in the above description, FIGS. 2 and 3 show a configuration related to the addition of the electronic signature in the same signature proxy server 20 and a configuration related to the verification of the electronic signature, respectively. And the proxy server shown in FIG. 3 may be configured separately.
【0048】
Next, the operation of post-signature realized by the key management unit 22, the signature key acquisition unit 23, the signature generation unit 24, and the log management unit 25 of the signature proxy server 20 shown in FIG. 2 will be described. FIG. 4 is a flowchart illustrating the signature operation including the case where the original private key cannot be used. Referring to FIG. 4, first, the signature key acquisition unit 23 asks the key management unit 22 whether the private key selected by the signature key determination unit 21 can be used (step 401). If the private key can be used, the private key is acquired and passed to the signature generation unit 24. The signature generation unit 24 signs using the private key, transmits an XML document with a digital signature, and ends the process (step 402).
【0049】
On the other hand, if the acquisition condition of the private key is not satisfied and the key cannot be used, the signature key acquisition unit 23 acquires a default alternative key from the key management unit 22 and passes it to the signature generation unit 24. The signature generation unit 24 signs using the alternative key and transmits an XML document with a digital signature (step 403). Then, the log management unit 25 writes the XML document in the log (post-signing log) prepared for the target of post-signing (step 404). Here, when additionally signing with the original private key performed after the fact to the XML document signed with the alternative key, the XML document signed with the alternative key is stored in the post-signing log. To do. In addition, when signing with the original private key is newly performed for the XML document in the state before being signed with the alternative key, the unsigned XML document is stored in the post-signing log.
【0050】
FIG. 5 is a flowchart illustrating an operation when a predetermined private key acquisition condition is satisfied and the key management unit 22 can be used. Referring to FIG. 5, when a predetermined private key becomes available, the log management unit 25 checks whether there is an XML document that needs to be post-signed with the private key (steps 501, 502). Then, if such an XML document exists in the post-signature log, the signature generation unit 24 receives the private key via the signature key acquisition unit 23, and receives the corresponding XML document from the log management unit 25. Sign and send the digitally signed XML document (steps 503, 504).
【0051】
As described above, when the required private key cannot be used, a document signed with the alternative key is sent (Fig. 4), and when the private key becomes available, the signature is made with the private key after the fact. Send the document that you did (Fig. 5).
【0052】
A unique serial number shall be assigned to the electronic signature. In this way, even if the same message document is sent twice due to the above-mentioned post-signature or processing error, work based on the message document (for example, order processing for an order by message document, etc.) ) Can be prevented from being duplicated.
【0053】
[Effect of the invention]
As described above, according to the present invention, by implementing the means for digitally signing, verifying, and logging messages sent and received via the network in the form of a proxy server, it is not necessary to change the application program. In addition, it is possible to realize a security function by electronic signature.
【0054】
Further, according to the present invention, a signature method such as a post-signature can be realized by controlling electronic signature and verification using a proxy server.
【0055】
Furthermore, according to the present invention, it is possible to control access to the message log by logging the message using a proxy server.
[Simple explanation of drawings]
[Figure 1]
It is a figure explaining the whole structure of the electronic signature system in this embodiment.
[Figure 2]
It is a figure which shows the structure about the addition of the electronic signature of the signature proxy server in this embodiment.
[Fig. 3]
It is a figure which shows the structure about the verification of the electronic signature of the signature proxy server in this embodiment.
[Fig. 4]
It is a flowchart explaining the signature operation including the case where the original private key cannot be used.
[Fig. 5]
It is a flowchart explaining the signature operation when the acquisition condition of a private key is satisfied and it becomes usable.
[Fig. 6]
It is a figure which shows the example of the key selection rule described in XML format.
[Explanation of symbols]
10 ... Application, 20 ... Signature Proxy Server, 21 ... Signature Key Judgment Department, 22 ... Key Management Department, 23 ... Signature Key Acquisition Department, 24 ... Signature Generation Department, 25. .. Log Management Department, 30 ... Switch, 40 ... Firewall, 100 ... LAN, 200 ... Network
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2008245039A | Cited by | Japan | Examiner |
| JP2012199607A | Cited by | Japan | Examiner |
| US8831569B2 | Cited by | United States of America | Applicant |
| JP2006081180A | Cited by | Japan | Search report |
| US8385887B2 | Cited by | United States of America | Applicant |
| US7246241B2 | Cited by | United States of America | Applicant |
| US10476677B2 | Cited by | United States of America | Applicant |
| JP2006033280A | Cited by | Japan | Examiner |
| JP2006050210A | Cited by | Japan | Search report |
| JP2006050209A | Cited by | Japan | Search report |
| JP2007053569A | Cited by | Japan | Search report |
| JP2000059353A | Cites | Japan | Search report |
| JP2000138703A | Cites | Japan | Search report |
| JP2000250408A | Cites | Japan | Search report |
| JP2001512589A | Cites | Japan | Search report |
| JP2002024147A | Cites | Japan | Search report |
| JP2002033760A | Cites | Japan | Search report |
| JP2002055961A | Cites | Japan | Search report |
| JPH1032570A | Cites | Japan | Search report |
| JPH11215122A | Cites | Japan | Search report |
4 members in 2 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2000336586 | Japan | A | |
| JP20000336586 | – | – | – |
Members4
| Document | Office | Kind | |
|---|---|---|---|
| JP2002164884AThis record | Japan | A | |
| US2002116619A1 | United States of America | A1 | |
| JP3629516B2 | Japan | B2 | |
| US7165179B2 | United States of America | B2 |
20 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Notification of resignation of power of sub attorneyRD14 | RD14 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedA521 | A521 | |
| Notification of reasons for refusalA131 | A131 |
Numbers
- Publication
- 2002-164884
- Publication, DOCDB
- 2002164884
- Publication, EPODOC
- JP2002164884
- Application
- 336586
- Application, DOCDB
- 2000336586
- Application, EPODOC
- JP20000336586
Titles2
- Japanese
- 【発明の名称】プロキシサーバ、電子署名システム、電子署名検証システム、ネットワークシステム、電子署名方法、電子署名検証方法、記憶媒体及びプログラム伝送装置
- English
- Description: Proxy server, electronic signature system, electronic signature verification system, network system, electronic signature method, electronic signature verification method, storage medium, and program transmission device.
Classification
- CPC, 6
- H04L63/0281
- H04L63/06
- H04L63/12
- H04L2209/68
- H04L9/3247
- H04L2209/76
- IPC, 6
- G06Q10 00
- G06Q50 00
- G09C1 00
- H04L9 08
- H04L9 32
- H04L29 06