JPH1083426A - Electronic cash method with monitoring institution, user device for implementing the method, and monitoring institution device - Google Patents
Electronic cash method with monitoring institution, user device for implementing the method, and monitoring institution deviceInfo
- Publication number
- JPH1083426A JPH1083426A JP12584297A JP12584297A JPH1083426A JP H1083426 A JPH1083426 A JP H1083426A JP 12584297 A JP12584297 A JP 12584297A JP 12584297 A JP12584297 A JP 12584297A JP H1083426 A JPH1083426 A JP H1083426A
- Authority
- JP
- Japan
- Prior art keywords
- user
- signature
- electronic cash
- verification key
- bank
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Landscapes
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
Abstract
(57)【要約】
【課題】 電子現金の銀行毎の発行状況を監視可能とす
る。
【解決手段】 利用者Uが金額Xの電子現金の発行を署
名検証鍵NU と共に銀行Bに送り、銀行BはXとNU の
対をUと対応して利用者データベースに保持すると共に
監視機関に送り、かつ(X,NU)に対する署名SB(X,NU)を生
成して利用者Uに送る。監視機関は(X,NU)を合計使用金
額Yと対応して監視データベースに登録する。利用者は
支払額yと、X,NU,SB(X,NU) と、小売店からの情報eに
対する署名SU(e,y) を小売店に送り、小売店は署名S
B(X,NU)、SU(e,y) を検証し、正しければ支払いを受け
る。小売店は利用者との全交信データHを監視機関に送
り、監視機関はデータH中の(X,NU)が監視データベース
に登録されており、かつ更新した支払合計金額Y+y がX
を越えなければ支払金額yを小売店の口座に振り込むよ
う銀行に指示し、そうでなければ(X,NU)を銀行に送り不
正者を特定する。
(57) [Summary] [Problem] To enable monitoring of the issuance status of electronic cash for each bank. SOLUTION: A user U sends an issue of electronic cash of an amount X to a bank B together with a signature verification key N U , and the bank B stores a pair of X and N U in a user database corresponding to U and monitors the same. feed to the engine, and sends (X, N U) signature for S B (X, N U) to generate the user U. Watchdog registers the monitoring database in correspondence with the total use amount Y of (X, N U). The user sends the payment amount y, X, N U , S B (X, N U ) and a signature S U (e, y) to the information e from the retail store to the retail store, and the retail store sends the signature S
Verify B (X, N U ) and S U (e, y) and get paid if correct. The retail store sends all the communication data H with the user to the monitoring organization, and the monitoring organization registers (X, N U ) in the data H in the monitoring database, and updates the total payment amount Y + y to X.
If not exceed the payment amount of money y to instruct the bank to transfer money to the retail store of the account, to identify the unauthorized person Feed otherwise the (X, N U) to the bank.
Description
【0001】[0001]
【発明の属する技術分野】この発明は、電気通信システ
ムを介し、又はICカードを介して、分割利用が可能
で、プライバシイを保証し、かつ不正使用を防ぐ電子的
な現金を実現する電子現金方法及びそれを実施するため
の利用者及び監視機関装置に関する。BACKGROUND OF THE INVENTION 1. Field of the Invention The present invention relates to an electronic cash system which can be used in a divided manner via a telecommunication system or via an IC card, guarantees privacy and realizes electronic cash which prevents unauthorized use. The present invention relates to a method and a user and monitoring institution apparatus for performing the method.
【0002】[0002]
【従来の技術】電気通信システムを用いた電子資金移動
が普及しつつある。一般に換金可能な証書(手形、小切
手など)は、証書の象徴的機能(証書を保持している人
に対して、証書に記載してある権利が供与されること)
を備えている。証書を電気通信システムで取り扱う場
合、証書はディジタル化されたデータであり、容易にコ
ピーを作成して複数回の不正な換金が可能となる。プリ
ペイドカードのような電子的現金を実現するときにも、
この問題が生じる。すなわち、プリペイドカードをコピ
ーすることで、不正に複数回の換金あるいは商品の購入
が可能となる。一方、クレジットカードでは、このよう
な2重使用の危険性はほとんどないが、その代わりに、
利用者の利用履歴がすべてカード会社に知られてしまう
という欠点がある(つまり、プライバシイが保証されて
ない)。これら問題の解決策として、計算機能を備えた
カードで換金時にカード読み取り装置とカードとの間の
データのやりとりを工夫することで、プライバシイを保
証し、かつカードの2重使用を検出する方法が提案され
ている。たとえば、Chaum, Fiat, Naor:"Untraceable E
lectronic Cash", Proc. of CRYPTO'88 がある。2. Description of the Related Art Electronic funds transfer using telecommunications systems is becoming widespread. Generally, redeemable certificates (bills, checks, etc.) are symbolic functions of the certificate (the person holding the certificate is granted the rights described in the certificate)
It has. When a certificate is handled by a telecommunications system, the certificate is digitized data, and a copy can be easily created and illegally redeemed a plurality of times. When realizing electronic cash like a prepaid card,
This problem arises. That is, by copying the prepaid card, it is possible to illegally redeem the cash or purchase the product a plurality of times. On the other hand, with credit cards, there is almost no danger of such double use, but instead,
There is a disadvantage that the user's usage history is completely known to the card company (that is, privacy is not guaranteed). As a solution to these problems, there is a method of guaranteeing privacy and detecting double use of a card by devising data exchange between the card reader and the card at the time of cashing with a card having a calculation function. Has been proposed. For example, Chaum, Fiat, Naor: "Untraceable E
electronic Cash ", Proc. of CRYPTO'88.
【0003】[0003]
【発明が解決しようとする課題】しかしながら、Chaum
等の方法では、ある程度の安全性(例えば、不正が成功
する確率が1/230) を確保するため、利用者の小売店に
対する電子現金による支払処理における質問、応答及び
検証の3手順をその安全性に応じた回数だけ繰り返し
(例えば、30回)実行する必要があるため、相互交信
量がかなり大きくなる。また、発行された同一電子現金
を分割して利用することができない。従来提案されてい
る分割使用可能な電子現金の分割使用原理は、例えば米
国特許No.5,224,162に示されているように、階層構造を
使った数学的に巧妙な論理に基づいている。しかしなが
ら、実際にこれを実施する場合、処理手順が多く、かつ
演算量が大となる欠点がある。元来、電子現金実施シス
テムにおいては、電子現金の発行者と利用者口座を管理
する金融機関が同一であるため、各金融機関が電子現金
を発行するという想定で構成されており、発行された電
子現金は利用者から小売店、銀行を経て、発行元の銀行
に還流する。従って、それぞれの金融機関が発行する電
子現金の発行量を監視することができない。SUMMARY OF THE INVENTION However, Chaum
In the method of equal, the degree of safety (e.g., the probability of fraud is successful 1/2 30) for securing the question in payment processing by electronic money for the retail user, the 3 steps of the response and the verification Since it is necessary to execute the process repeatedly (for example, 30 times) according to the security, the amount of mutual communication becomes considerably large. Further, the same issued electronic cash cannot be divided and used. The conventionally proposed split use principle of split-use electronic cash is based on mathematically sophisticated logic using a hierarchical structure, as shown in, for example, US Pat. No. 5,224,162. However, when this is actually performed, there are disadvantages in that the number of processing procedures is large and the amount of calculation is large. Originally, in the electronic cash implementation system, since the issuer of electronic cash and the financial institution that manages the user account are the same, it is configured on the assumption that each financial institution will issue electronic cash. The electronic cash is returned from the user to the issuing bank via a retail store and a bank. Accordingly, the amount of electronic cash issued by each financial institution cannot be monitored.
【0004】この発明の第1の目的は、プライバシイを
保証し、不正使用をも防ぐ電子現金方法において、支払
処理における通信量が少なく、分割利用が可能で、特に
各金融機関が発行する電子現金の発行量を監視すること
ができるような電子現金方法を実現することにある。こ
の発明の第2の目的は、上記電子現金方法を実施するた
めの利用者装置及び監視機関装置を実現することにあ
る。A first object of the present invention is to provide an electronic cash method which guarantees privacy and also prevents unauthorized use, in which the amount of communication in payment processing is small, and divisional use is possible. An object of the present invention is to realize an electronic cash method capable of monitoring the amount of cash issued. A second object of the present invention is to realize a user device and a monitoring institution device for implementing the above electronic cash method.
【0005】[0005]
【課題を解決するための手段】この発明による電子現金
方法は以下のステップを含む: (1) 利用者は、銀行に利用者情報Uと電子現金の額面に
対応する金額Xを送信し、利用者の口座から金額Xを引
き下ろすことを要請し、(2) 上記銀行は、上記利用者の
口座から金額Xを減額し、上記利用者の署名検証用鍵N
U 及び金額Xに対してその銀行の署名SB(X,NU)を生成し
上記利用者に送付すると共に、上記金額Xと上記署名検
証用鍵NU の情報を含む署名検証鍵情報nを上記利用者
情報Uと対応させて利用者データベースに記録し、更に
上記監視機関に上記署名検証鍵情報nを送付し、(3) 上
記監視機関は、上記署名検証鍵情報nを合計使用金額Y
と対応させて監視データベースに登録し、(4) 上記利用
者は残額xと、上記金額Xと、上記署名検証鍵NU と、
上記署名SB(X,NU)とを含む情報を額面Xの電子現金Cと
して使って支払金額yを上記小売店に支払い、上記小売
店は上記電子現金の正当性を検証して受け取り、(5) 上
記小売店は上記電子現金Cの情報を含む上記利用者との
全交信データHを上記監視機関に送信して決済を求め、
(6) 上記監視機関は受信した上記交信データH中の上記
電子現金Cの正当性を検証し、上記銀行に対し上記小売
店の口座に上記支払金額yを振り込むよう指示を与え
る。The electronic cash method according to the present invention includes the following steps: (1) The user sends the user information U and the amount X corresponding to the face value of the electronic cash to the bank for use. Requesting that the amount X be withdrawn from the user's account, and (2) the bank shall reduce the amount X from the user's account and obtain the user's signature verification key N
A signature S B (X, N U ) of the bank is generated for U and the amount X and sent to the user, and signature verification key information n including information on the amount X and the signature verification key N U is provided. Is recorded in the user database in association with the user information U, and the signature verification key information n is sent to the monitoring organization. (3) The monitoring organization transmits the signature verification key information n to the total usage amount. Y
(4) The user registers the remaining amount x, the amount X, the signature verification key N U ,
The signature S B (X, N U) payments and in the retail store the payment amount y using the information as electronic cash C of face value X containing said retail store receives and verifies the validity of said electronic cash, (5) The retail store requests the settlement by transmitting all the communication data H with the user including the information of the electronic cash C to the monitoring organization,
(6) The monitoring organization verifies the validity of the electronic cash C in the received communication data H, and instructs the bank to transfer the payment amount y to the account of the retail store.
【0006】上記方法のステップ(1) において、利用者
は監視機関の暗号鍵PKT を使って署名検証鍵NU と金額
Xを含む組を暗号関数ET により暗号化して得たET(X,N
U)と金額Xを銀行及び監視機関に送り、更に、署名検証
鍵NU をブラインド署名前処理してF(NU) を銀行に送
り、ステップ(2) で銀行は利用者名Uと対応して署名検
証鍵情報nをデータベースに記録する代わりにET(X,NU)
を記録し、また、(X,NU)に対する直接署名の代わりに、
F(NU) に対するブラインド署名Z(NU) を利用者に送り、
ステップ(4) で利用者はF(NU) ブラインド署名後処理に
より得た銀行署名SB(NU)を電子現金の一部として使うよ
うにしてもよい。[0006] In step (1) of the method, the user watchdog encryption key PK T using the signature verification key N U and amount X E set was obtained by encrypting the encryption function E T containing T ( X, N
U ) and the amount X are sent to the bank and the monitoring institution, and the signature verification key N U is pre-blind-signed and F (N U ) is sent to the bank. In step (2), the bank corresponds to the user name U. E T (X, N U ) instead of recording the signature verification key information n in the database
And instead of directly signing (X, N U )
Feed F a (N U) blind signature for Z (N U) to the user,
In step (4), the user may use the bank signature S B (N U ) obtained by the F (N U ) blind post-processing as a part of the electronic cash.
【0007】この発明による利用者装置は、利用者署名
用鍵SKU を生成する鍵生成手段と、金額Xと署名検証鍵
NU とに対する銀行の署名SB(X,NU)と、残額xと、額面
Xと,署名検証鍵NU とを含む電子現金Cと、上記署名
用鍵SKU とを保持するメモリ手段と、支払金額yと上記
小売店から受信した任意の情報eとに対する署名を上記
署名用鍵SKU を使って行い、署名SU(e,y) を生成する署
名生成手段と、上記残額xから支払金額yを減算して残
額を更新する残額更新手段と、を含む。[0007] A user device according to the present invention comprises a key generation means for generating a user signature key SK U , a bank signature S B (X, N U ) for the amount X and the signature verification key N U , x, the face value X, the electronic cash C containing the signature verification key N U , the memory means for holding the signature key SK U , the payment amount y and any information e received from the retail store. Signing is performed using the signature key SK U, and a signature generating means for generating a signature S U (e, y); and a balance updating means for subtracting the payment amount y from the balance x to update the balance. Including.
【0008】上記利用者装置において、暗号手段を設
け、監視機関の暗号鍵を使って金額Xと署名検証鍵NU
を含む情報を暗号化して銀行に送り、更に、ブラインド
前処理手段とブラインド後処理手段を設け、署名検証鍵
NU に対する銀行のブラインド署名Z(NU)を得て、そのZ
(NU)から銀行の署名SB(NU)を得てもよい。この発明によ
る監視機関装置は、発行された電子現金を所有する利用
者に対応する署名検証鍵情報nを合計使用金額Yと対応
させて登録する監視データベースと、小売店から受信し
た残金x、額面X、署名検証鍵NU 、銀行の署名SB(X,N
U)を含む電子現金Cと、支払金額yとを含む履歴データ
Hを保持する履歴データベースと、上記履歴データH中
の金額Xと検証鍵NU に対応する署名検証鍵情報nが上
記監視データベースに登録されているか検索し、登録さ
れていなければ不正使用された電子現金であると判定す
る手段と、上記署名検証鍵情報が登録されている場合、
上記履歴データH中の支払金額yを上記監視データベー
ス中の対応する合計使用金額Yに加算する加算手段と、
上記加算手段による加算結果Y+y を額面Xと比較する比
較手段と、上記比較手段による比較結果がY+y<X であれ
ば上記監視データベース中の対応する合計使用金額Yを
上記加算結果Y+y で更新し、Y+y=X であれば上記監視デ
ータベース中の対応する署名検証鍵情報nと合計使用金
額Yを削除し、Y+y>X であれば不正使用された電子現金
であると判定して上記n,Yを削除すると共に、その署
名検証鍵情報nを上記銀行に通知する制御手段、とを含
む。In the above-mentioned user apparatus, an encryption means is provided, and the amount X and the signature verification key N U are used by using the encryption key of the monitoring organization.
Is encrypted and sent to the bank. Further, blind pre-processing means and blind post-processing means are provided to obtain the bank's blind signature Z (N U ) for the signature verification key N U , and the Z
(N U) may be obtained bank signature S B (N U) from. The monitoring institution apparatus according to the present invention includes a monitoring database for registering the signature verification key information n corresponding to the user who has issued the electronic cash in association with the total usage amount Y, a balance x received from the retail store, and a face value. X, signature verification key N U , bank signature S B (X, N
U ), a history database holding history data H including a payment amount y, and a signature verification key information n corresponding to the amount X and the verification key N U in the history data H are stored in the monitoring database. If the signature verification key information is registered, means for determining whether or not the electronic cash is fraudulently used if not registered,
Adding means for adding the payment amount y in the history data H to the corresponding total usage amount Y in the monitoring database;
Comparing means for comparing the addition result Y + y by the adding means with the denomination X; and if the comparison result by the comparing means is Y + y <X, the corresponding total usage amount Y in the monitoring database is added to the addition result Y. + y, and if Y + y = X, delete the corresponding signature verification key information n and total usage amount Y in the monitoring database, and if Y + y> X, use the illegally used electronic cash. Control means for determining that there is, deleting said n and Y, and notifying said bank of said signature verification key information n.
【0009】上記監視機関装置において、復号手段を設
け、利用者からの暗号化情報ET(X,N U)を復号して得た
(X,NU)を監視データベースに登録するようにしてもよ
い。この発明によれば、電子現金発行を行う機関(銀
行)と決済のための検証処理を行う機関(監視機関)を
分離し、監視機関において銀行の発行した電子現金の流
通量を監視する。一方、利用者の支払い処理を利用者の
署名鍵を用いて行うことにより、分割支払いを可能とし
ている。つまり、支払い額に対して利用者の署名を付け
させることにより、利用者が一定金額以上の支払いをし
た場合、その不正行為を証拠として提示できる。[0009] In the above-mentioned surveillance engine device, decoding means is provided.
The encrypted information E from the userT(X, N U)
(X, NU) May be registered in the monitoring database.
No. According to the present invention, the organization that issues electronic cash (silver
Line) and the institution (monitoring institution) that performs the verification process for settlement
Separate and monitor electronic cash flows issued by banks
Monitor traffic volume. On the other hand, the payment process of the user
By using a signing key, installments can be made
ing. In other words, the payment amount is signed by the user
Allows the user to pay more than a certain amount
If so, the wrongdoing can be presented as evidence.
【0010】[0010]
【発明の実施の形態】図1は、この発明方法が適用され
るシステムの構成の例を示す。電子現金の発行を監視す
る監視機関の装置100 (この監視機関を表す情報をTと
記す)と、電子現金を発行する機関の装置200 (この銀
行を表す情報をBと記す)と、発行された電子現金を使
用する利用者の装置300 (この利用者を表す情報をUと
記す)と、利用者より電子現金を受領する小売店の装置
400 (この小売店を表す情報をWと記す)とが通信回線
などを介して接続されている。これらは情報を記録でき
るICカード等を介して接続されてもよい。以下に説明
するこの発明の実施例において使用されるディジタル署
名は既に確立した技術として様々な方式が知られてお
り、それらのどれを使ってもよい。FIG. 1 shows an example of the configuration of a system to which the method of the present invention is applied. A device 100 of a monitoring agency that monitors the issuance of electronic cash (information representing this monitoring agency is denoted as T) and a device 200 of an agency that issues electronic cash (information representing this bank is denoted as B) are issued. Of the user using the electronic cash 300 (information representing this user is denoted by U) and a device of a retail store receiving the electronic cash from the user
400 (the information indicating this retail store is denoted by W) is connected via a communication line or the like. These may be connected via an IC card or the like capable of recording information. The digital signature used in the embodiments of the present invention described below is known in various forms as a well-established technique, and any of them may be used.
【0011】図1に示したシステム構成において適応さ
れるこの発明の電子現金実施方法を次ぎに説明する。 第1実施例 (1) 電子現金の発行処理 まず、利用者が、電子現金を発行してもらう場合を図2
を用いて説明する。An electronic cash execution method of the present invention applied in the system configuration shown in FIG. 1 will be described below. First Embodiment (1) Electronic Cash Issuance Processing First, a case in which a user issues electronic cash is shown in FIG.
This will be described with reference to FIG.
【0012】銀行200 は、あらかじめディジタル署名
(池野、小山著「現代暗号理論」電子情報通信学会、等
を参照)用の公開鍵PKB 及び秘密鍵SKB の組を生成して
メモリ20M に保持する。その秘密鍵SKB と、それを用い
て署名を生成するための署名生成関数SB を秘密とす
る。更に、そのディジタル署名を検証するための署名検
証関数VB と、その署名検証関数に使用する検証用公開
鍵PKB を公開する。[0012] Bank 200, pre-digital signature held in the public key PK B and the memory 20M to generate a set of secret key SK B of (Ikeno, Koyama et al., "Modern cryptography theory" of Electronics, Information and Communication Engineers, see, etc.) for I do. The secret key SK B and a signature generation function S B for generating a signature using the secret key SK B are kept secret. Moreover, publishing the signature verification function V B in order to verify the digital signature, the verification public key PK B to be used for the signature verification function.
【0013】利用者は、銀行のその利用者300 の口座
(利用者情報Uと対応)から発行電子現金の額面と同じ
金額Xを引き下ろすことを要請するための手続きを以下
の手順で行う。 ステップ1:利用者300 は、ディジタル署名の鍵生成部
301 を用いて、署名生成鍵SKU 及び署名検証鍵NU を生
成し、メモリ30M に記録する。従って、署名検証鍵NU
は利用者情報Uと対応している。The user performs the following procedure to request that the same amount X as the face value of the issued electronic cash be withdrawn from the account (corresponding to the user information U) of the user 300 of the bank. Step 1: User 300 generates a digital signature key generation unit.
Using 301, a signature generation key SK U and a signature verification key N U are generated and recorded in the memory 30M. Therefore, the signature verification key N U
Corresponds to the user information U.
【0014】電子現金の額面と等しい金額Xを利用者30
0 の口座から引き下ろすことを要請するメッセージと利
用者情報(利用者識別情報或いは口座番号)UをNU と
共に銀行200 に送る。なお、この実施例では、利用者が
新しい電子現金の発行を行う毎に署名検証鍵NU を新し
く生成する、即ち、変更する場合について説明するが、
後述するように、同一署名検証鍵NU を複数の電子現金
に使用してもよい。An amount X equal to the face value of the electronic cash is used by the user 30.
A message requesting the user to withdraw from the account No. 0 and user information (user identification information or account number) U are sent to the bank 200 together with N U. In this embodiment, a case will be described in which a signature verification key N U is newly generated, that is, changed every time a user issues a new electronic cash.
As described later, the same signature verification key N U may be used for a plurality of electronic cash.
【0015】ステップ2:銀行200 は、利用者300 の口
座の残高をチェックし、その残高よりXを減額し、更に
利用者名Uと対応させて(X,NU)を署名検証鍵情報として
利用者データベース201 に記録しておく。そのとき、利
用者300 のディジタル署名のついた引き下ろし依頼メッ
セージがあればそれも一緒に記録しておく。次に、銀行
200 は署名関数SB の署名作成部202 を用いて、X,N
U に対する銀行200 のディジタル署名SB(X,NU)を計算
し、SB(X,NU)を利用者300 に送付するとともに、(X,NU)
を監視機関100 に送付する。 ステップ3:利用者300 はSB(X,NU)をx,X,NUと共に額面
X、残高xの電子現金C={x,X,NU,SB(X,NU)}としてメモ
リ30M に保持する。ただし、残高xの初期値はx=Xで
ある。Step 2: The bank 200 checks the balance of the account of the user 300, reduces X from the balance, and further associates (X, N U ) with the user name U as signature verification key information. It is recorded in the user database 201. At that time, if there is a withdrawal request message with a digital signature of the user 300, that message is also recorded. Next, the bank
200 uses the signature creation unit 202 of the signature function S B to obtain X, N
Digital signature S B (X, N U) of the bank 200 for the U to calculate the, S B (X, N U ) as well as send to the user 300, (X, N U)
Is sent to the monitoring organization 100. Step 3: The user 300 S B (X, N U) of x, X, par with N U X, electronic cash balance x C = {x, X, N U, S B (X, N U)} And stored in the memory 30M. However, the initial value of the balance x is x = X.
【0016】ステップ4:監査機関100 は、(X,NU)を署
名検証鍵情報として監視データベース101 に登録する。
ここで、その(X,NU)に対応する電子現金の現在までの支
払金額yの合計額Yの初期値をY=0 として(X,NU)に対応
して記録する。なお、この第1実施例では、署名検証鍵
NU を利用者が生成する例を示しているが、他の機関、
例えば監視機関100 又は銀行200 が生成することにして
もよい。その場合は、電子現金発行依頼に応じて予め監
視機関又は銀行がその署名検証鍵NU を生成し利用者30
0 に送信することになる。 (2) 電子現金の支払 次に、利用者300 が、利用者の署名検証鍵NU と銀行20
0 より発行された署名SB(X,NU)の組を含む額面X、残高
x(初期値x=X)の電子現金Cを用いて小売店Wで金
額y(y≦x)を支払う場合について図3を用いて説明
する。[0016] Step 4: regulators 100 registers (X, N U) in the monitoring database 101 as a signature verification key information.
Here, the (X, N U) in the initial value of the sum Y of the payment amount y of the current until the corresponding electronic cash Y = 0 as (X, N U) is recorded in response to. In the first embodiment, an example is shown in which the user generates the signature verification key N U.
For example, it may be generated by the monitoring agency 100 or the bank 200. In this case, the monitoring institution or the bank generates the signature verification key N U in advance in response to the electronic cash issuance request and
Will be sent to 0. (2) Payment of electronic cash Next, the user 300 enters the user's signature verification key N U and the bank 20
Pay the amount y (y ≦ x) at a retail store W using electronic cash C of published by 0 signature S B (X, N U) par X including a set of balance x (initial value x = X) The case will be described with reference to FIG.
【0017】ステップ1:利用者300 は、メモリ30M か
ら読みだした残高xを表示部30D に表示してそれが利用
しようとする金額y以上であることを確認して電子現金
C={x,X,NU,SB(X,NU)}を小売店400 に送る。 ステップ2:小売店400 は、署名検証部401 を用いて、
電子現金の発行者(銀行200 )の署名SB(X,NU)の正当性
を署名検証関数VB により検証する。正しければ、一方
向関数演算部402 により一方向関数fを用いて時間TIM
E、小売店400 に対応する情報Wから検証のための問い
合わせ情報e=f(TIME,W)を生成し、TIME,W,eを利用
者300 に送る。Step 1: The user 300 displays the balance x read from the memory 30M on the display unit 30D, confirms that the balance x is equal to or more than the amount y to be used, and checks the electronic cash C = {x, X, N U , S B (X, N U )} to the retail store 400. Step 2: The retail store 400 uses the signature verification unit 401 to
Signature S B (X, N U) of the issuer of electronic cash (bank 200) is verified by the signature verification function V B the validity of. If it is correct, the one-way function calculation unit 402 uses the one-way function f to calculate the time TIM.
E, generates inquiry information e = f (TIME, W) for verification from the information W corresponding to the retail store 400, and sends TIME, W, e to the user 300.
【0018】ステップ3:利用者300 は、一方向関数演
算部306 、比較部307 を用いて、e=f(TIME,W) の正当
性を検証する。正しければ、署名生成部305 を用いて、
送られてきたe及び支払金額y(y≦x)に対する利用者の
署名SU(e,y) を計算し、y,S U(e,y) を小売店400 に送
付する。 ステップ4:小売店400 は、利用者署名SU(e,y) と支払
金額yの正当性を、問い合わせ情報eと署名検証鍵NU
を使って署名検証部404 により検証し、更に、比較部40
3 を用いて、y≦xを検証する。いずれも正しければ、
該当支払金額yの電子現金による支払いを認め、少なく
とも1つが正しくなければ支払を認めない判定結果OK/N
G を利用者に送る。また、後の決済のため、利用者300
との間の交信データH={x,X,NU,SB(NU),TIME,W,e,y,S
U(e,y)}を小売店データ蓄積部40D に保持する。Step 3: The user 300 performs a one-way function
Using the arithmetic unit 306 and the comparing unit 307, the validity of e = f (TIME, W)
Verify the nature. If it is correct, using the signature generation unit 305,
E and the amount of payment y (y ≦ x)
Signature SU(e, y) is calculated and y, S U(e, y) to retail store 400
Attached. Step 4: Retail store 400 has user signature SU(e, y) and payment
Inquiry information e and signature verification key NU
The signature is verified by the signature verification unit 404 using
Verify y ≦ x using 3. If both are correct,
Accept payment by electronic cash for applicable payment amount y, reduce
If both are not correct, payment will not be accepted OK / N
Send G to the user. In addition, the user 300
Communication data H = {x, X, NU, SB(NU), TIME, W, e, y, S
U(e, y)} is stored in the retail store data storage unit 40D.
【0019】なお、小売店400 がTIME,W,eを利用者
300 へ送った後、SB(X,NU)の正当性の検証を行ってもよ
い。 ステップ5:利用者300 は小売店400 からの判定結果OK
/NG がOKであれば、メモリ30M の残高xを減算部302 に
よりx←x-y と更新する。 (3) 決済 最後に、小売店400 と銀行200 の間の決済方法について
図4を用いて説明する。The retail store 400 uses TIME, W, and e for the user.
After sending to 300, the validity of S B (X, N U ) may be verified. Step 5: User 300 OKs decision result from retail store 400
If / NG is OK, the balance x in the memory 30M is updated by the subtractor 302 as x ← xy. (3) Settlement Finally, a settlement method between the retail store 400 and the bank 200 will be described with reference to FIG.
【0020】ステップ1:小売店400 は決済のためにま
ず監視機関100 に利用者300 と小売店400 の間の全ての
相互通信データH={x,X,NU,SB(X,NU),TIME,W,e,y,S
U(e,y)}を自分の口座を有する銀行200 を経由して(ま
たは直接)送信する。 ステップ2:監視機関100 は、相互通信データHに含ま
れる利用者300 の署名検証用鍵NU と額面Xの組(X,NU)
が監視デーベース101 に登録されているかどうかを検査
する。登録されていれば、制御部114 は加算部107 及び
比較部103 を用いて、以下の処理を行う。まず、(X,NU)
に対応して記録されている支払金額の合計値YをY+y→Y
と更新し、更に更新されたYがXを越えてないことを検
査する。また、制御部114 は相互通信データHを履歴デ
ータベース108 に記録する。履歴データベース108 への
データの書き込みは、好ましくは予め決めた期限付きと
し、期限の切れたデータは消去することによりデータ量
を削減することが好ましい。[0020] Step 1: All intercommunication data H = {x between retailers 400 retailers 400 and first user 300 for monitoring engine 100 to settle, X, N U, S B (X, N U ), TIME, W, e, y, S
U (e, y)} (or directly) via the bank 200 that has its own account. Step 2: The monitoring organization 100 sets (X, N U ) the signature verification key N U and the face value X of the user 300 included in the mutual communication data H.
It is checked whether or not is registered in the monitoring database 101. If registered, the control unit 114 performs the following processing using the addition unit 107 and the comparison unit 103. First, (X, N U )
The total value Y of the payment amount recorded corresponding to is Y + y → Y
And further checks that the updated Y does not exceed X. Further, the control unit 114 records the mutual communication data H in the history database 108. It is preferable to write data to the history database 108 with a predetermined time limit, and to reduce the data amount by deleting expired data.
【0021】もし、更新された支払合計金額Yが額面X
を越えていなければ、使われた電子現金の発行銀行に対
し、小売店400 が指定した銀行の口座に金額yを振り込
むよう指示する。このとき、小売店400 が口座を持つ銀
行は、利用者300 の(X,NU)に対し署名した銀行200 でな
くても良い。更に、Y+y=X ならば、監視データベース10
1 から(X,NU)及びそれに対応する支払合計金額Yを削除
する。If the updated total payment amount Y is the face value X
If not, the issuing bank of the used electronic cash is instructed to transfer the amount y to the bank account designated by the retail store 400. At this time, bank retail store 400 has an account, the user 300 (X, N U) may not be the bank 200 signed to. Furthermore, if Y + y = X, the monitoring database 10
Delete (X, N U ) and the corresponding total payment amount Y from 1.
【0022】(X,NU)が監視データベース101 に登録され
ていない場合は、利用者300 による不正支払いが行われ
たものとして、不正者特定処理を行う。また、Y+y>X な
らば、制御部114 は監視データベース101 からX,NU
の対及びそれに対応するYを削除すると共に、やはり、
利用者による不正支払いが行われたものとして、不正者
特定処理を行う。If (X, N U ) is not registered in the monitoring database 101, it is assumed that the user 300 has made an unauthorized payment, and an unauthorized person identification process is performed. If Y + y> X, the control unit 114 sends X, N U from the monitoring database 101.
And the corresponding Y are deleted, and again,
Assuming that the fraudulent payment has been made by the user, the fraudulent person identification processing is performed.
【0023】ステップ3:不正者特定処理では、監視機
関100 は、(X,NU)を削除する前に履歴データベース108
より不正行為の証拠となる情報(不正支払に関する全て
の相互通信データH)を読み出し、電子現金発行元銀行
200 に送付する。銀行200 は、不正行為の証拠の正当性
を、署名検証部203 によりNU を使って検証し、正しけ
れば(X,NU)をキーワードとして利用者データベース201
から対応する利用者情報Uに該当する不正利用者300 を
特定する。[0023] Step 3: In fraudster identification process, the monitoring engine 100, (X, N U) history database 108 before removing the
Read out the information (all the intercommunication data H concerning the improper payment) that is more proof of wrongdoing, and issue the electronic cash issuing bank
Send to 200. The bank 200 verifies the validity of the proof of wrongdoing by the signature verification unit 203 using N U, and if correct, uses (X, N U ) as a keyword in the user database 201.
Then, the unauthorized user 300 corresponding to the corresponding user information U is specified.
【0024】上述において、利用者は署名検証鍵NU を
原型のまま含む情報(X,NU)を銀行及び監視機関に送る場
合を説明したが、一般には、署名検証鍵NU の情報をそ
のままの形態も含め、任意の形態に変換して送ってよ
い。この任意の形態の変換をn=f(NU) で表す。従って、
上述の実施例の説明におけるより一般的な表現として、
利用者は、n=f(NU) で表される署名検証鍵情報を額面X
と共に銀行及び監視機関に送る。例えば、利用者は一方
向関数fを使って署名検証鍵NU を含む情報をn=f(NU)
のように変換し、(X,n) を銀行200 、更に監視機関100
に送って、それぞれ署名検証鍵情報としてデータベース
201,101に書き込んでもよい。[0024] In the above, information users, including the signature verification key N U remains of the original (X, N U) has been described a case to send to the bank and monitoring agencies, in general, the information of the signature verification key N U It may be converted to any form, including the form as it is, and sent. This arbitrary form of transformation is denoted by n = f (N U ). Therefore,
As a more general expression in the description of the above embodiment,
The user sends the signature verification key information represented by n = f (N U )
Together with the bank and monitoring agencies. For example, the user uses the one-way function f to send information including the signature verification key N U to n = f (N U )
, And (X, n) is converted to the bank 200 and the monitoring agency 100
And send them to the database as signature verification key information.
201, 101 may be written.
【0025】上述の第1実施例において、銀行200 は例
えば一方向性のハッシュ関数hによりn=h(X,NU) なる圧
縮されたデータnを署名検証鍵情報として生成し、この
署名検証鍵情報nと利用者300 の名前Uとを対応させて
利用者データベース201 に記憶してもよい。同様に、監
視機関100 も銀行から受けた(X,NU)を一方向ハッシュ関
数により圧縮して得たデータn=h(X,NU) を監視データベ
ース101 に合計使用金額Yと対応して登録してもよい。
その場合、図4の監視機関100 は小売店400 からの履歴
データH中の(X,NU)を同じ一方向ハッシュ関数hにより
圧縮して得られた署名検証鍵情報nによりデータベース
101 を検索し、同じ署名検証鍵情報nが存在するか、即
ち(X,NU)が登録されているかを検査する。In the first embodiment described above, the bank 200 generates compressed data n of n = h (X, N U ) as signature verification key information using, for example, a one-way hash function h, and this signature verification is performed. The key information n and the name U of the user 300 may be stored in the user database 201 in association with each other. Similarly, the monitoring institution 100 also stores the data n = h (X, N U ) obtained by compressing (X, N U ) received from the bank by a one-way hash function in the monitoring database 101 and the total usage amount Y. You may register.
In this case, the monitoring organization 100 shown in FIG. 4 uses the signature verification key information n obtained by compressing (X, N U ) in the history data H from the retail store 400 by the same one-way hash function h to obtain a database.
Searching 101, the same signature verification key information or n is present, i.e. (X, N U) it is checked whether it is registered.
【0026】上述のようにして使用された電子現金の残
額xを使って利用者300 が任意の小売店に支払を行う場
合の手順は、上述した利用者300 と小売店400 間の支払
手順と全く同じであり、またそれにともなう小売店と監
視機関100 との間の決済手順も前述と全く同様にして行
うことができる。上述したこの発明の電子現金実施方法
によれば、各銀行200 が発行する電子現金の金額Xは全
て監視機関100 に報告されるので、それぞれの銀行によ
る電子現金の発行総量を監視することもできるし、監視
機関100 は常に流通している電子現金の総量を把握する
ことができる。The procedure in which the user 300 pays to an arbitrary retail store using the remaining amount x of the electronic cash used as described above is the same as the payment procedure between the user 300 and the retail store 400 described above. The payment procedure between the retail store and the monitoring agency 100 can be performed in exactly the same manner as described above. According to the above-described electronic cash implementation method of the present invention, all the amount X of electronic cash issued by each bank 200 is reported to the monitoring organization 100, so that the total amount of electronic cash issued by each bank can also be monitored. However, the monitoring institution 100 can always grasp the total amount of electronic cash circulating.
【0027】また、この発明によれば、電子現金で支払
を行う場合、使用金額が現残額x以下であることを確認
するだけなので、電子現金の分割使用における処理手順
は前述の米国特許No.5,224,162に示された電子現金の分
割使用手順より著しく簡単であり、かつ、そのための交
信情報量も著しく少なくてすむ。更に、この発明の特徴
とするところは、監視機関100 において、監視データベ
ース101 に保持される監視対象の登録データ(X,NU)は、
対応する電子現金がその額面Xまで全て使いきった時点
で抹消されるので、それ以降、不正により同じ電子現金
が使用されても、小売店から監視機関に決済のため送ら
れるその電子現金のデータ(X,NU)は既にデータベース10
1 から抹消されているので、不正使用が直ちに露見す
る。また、この方法において特徴的なことは、上述のよ
うにデータベース101 に保持されている監視対象として
の登録データ(X,NU)は使用済み又は不正発覚時点で抹消
されるので、データベース101 に保持されている登録デ
ータ(X,NU)は、その時点で有効なものだけである。従っ
て電子現金の発行総量がある程度一定していれば、監視
データベース101 に保持しなければならない登録デー多
量はほぼ一定となり、累積していくことはない。これに
対し、従来の電子現金方式においては、各銀行は不正使
用された電子現金と使用済み電子現金(将来不正使用さ
れる可能性がある)のリストを監視対象として保持しな
ければならず、電子現金の発行量と共に監視データ量が
累積していく問題がある。According to the present invention, when payment is made by electronic cash, it is only necessary to confirm that the amount of money used is equal to or less than the current remaining amount x. It is significantly simpler than the electronic cash split use procedure shown in 5,224,162, and the amount of communication information therefor is significantly smaller. Furthermore, it is an aspect of the invention, the monitoring engine 100, registration data monitored held in the monitoring database 101 (X, N U) is
Since the corresponding electronic cash is completely erased when it is used up to its face value X, even if the same electronic cash is used by fraud thereafter, the data of the electronic cash sent to the monitoring organization from the retail store for settlement. (X, N U) already database 10
Since it has been deleted from 1, unauthorized use is immediately revealed. Further, the characteristic that in this way, registration data (X, N U) as monitored held in the database 101 as described above so are deleted in the spent or unauthorized uncovered time, the database 101 The stored registration data (X, N U ) is only valid at that time. Therefore, if the total amount of issued electronic cash is constant to some extent, the amount of registered data that must be stored in the monitoring database 101 is substantially constant and does not accumulate. In contrast, in the conventional e-cash method, each bank must keep a list of e-cash that has been misused and used e-cash (which may be used in the future), There is a problem that the monitoring data amount accumulates together with the amount of electronic cash issued.
【0028】次に上述の第1実施例における特徴的な利
用者装置300 と監視機関100 の機能構成を以下に説明す
る。図5は上述の第1実施例において利用者300 の処理
手順を実行するための利用者装置の機能ブロック図を示
す。その構成は、図2及び3中の利用者300 が実行する
電子現金発行時の処理機能部300aと、電子現金使用時の
処理機能部300bが互いに入力部311 、制御部312 、メモ
リ30M を共有するように構成されている。電子下金発行
時の機能構成部300aは、入力部311 と、各部の動作を制
御するための制御部312 と、鍵生成部301 と、送信部31
3 と、受信部314 と、メモリ30M とから構成されてい
る。制御部312 は入力部311 からコマンド、利用者情報
U、額面Xが与えられると、電子現金発行要求のため利
用者情報Uと額面Xを送信部313 から銀行200(B)に送信
すると共に、鍵生成部301 に対し検証鍵NU と署名鍵SK
U の生成を行わせ、Xと共にメモり30M に保持させる。
更に生成した鍵NU を銀行200 に送信させる。Next, the characteristic advantage in the first embodiment described above.
The functional configuration of the user device 300 and the monitoring organization 100 will be described below.
You. FIG. 5 shows the processing of the user 300 in the first embodiment.
Shows a functional block diagram of the user device for performing the procedure.
You. The configuration is executed by the user 300 in FIGS.
The processing function unit 300a when issuing electronic cash and the
The processing function unit 300b is connected to the input unit 311, the control unit 312,
It is configured to share the file 30M. Issuance of electronic money
The functional configuration unit 300a controls the input unit 311 and the operation of each unit.
Control unit 312, a key generation unit 301, and a transmission unit 31
3, a receiving unit 314, and a memory 30M.
You. The control unit 312 receives commands and user information from the input unit 311.
If U and face value X are given, it will be
Transmit user information U and face value X from transmitting unit 313 to bank 200 (B)
In addition, the verification key NU And the signing key SK
U Is generated and stored in memory 30M together with X.
Further generated key NU To the bank 200.
【0029】制御部312 は銀行200 から(X,NU)に対する
署名SB(X,NU)を受信部314 で受信すると制御部312 はそ
れをメモり30M に保持する。電子現金使用時の機能構成
部300bは入力部311 と、制御部312 と、メモリ30Mと、
表示部30D と、減算部302 と、署名構成部305 と、一方
向関数部306 と、比較判定部307 と、送信部315 と、受
信部316 とから構成される。小売店400 に対する支払額
が入力部311 から入力されるとメモリ30M から残額xを
読み出し、表示部30D に表示し、残額xが支払額以上で
あることを確認する。次にメモリ30Mから額面X、残金
xの電子現金C={x,X,NU,SB(X,NU)}を読み出し、送信部
315 から小売店400 に送信する。これに応答して小売店
400 から問い合わせ情報e、TIME、Wを受信部316 によ
り受信するとTIMEとWを一方向関数部306 により一方向
関数処理してf(TIME,W) を得て、これが受信したeと一
致するか、比較判定部307 で判定する。一致すれば署名
生成部305 で署名鍵SKU を使ってeとyの組に対する署
名SU(e,y) を生成し、支払金額yと共に小売店400 に送
信する。それと共に減算部302 で残額xから支払金額y
を減算して更新した残額xでメモリ30M 内の残額xを更
新する。When the control unit 312 receives the signature S B (X, N U ) for (X, N U ) from the bank 200 at the receiving unit 314, the control unit 312 stores it in the memory 30 M. The function configuration unit 300b when using electronic cash includes an input unit 311, a control unit 312, a memory 30M,
It comprises a display unit 30D, a subtraction unit 302, a signature construction unit 305, a one-way function unit 306, a comparison determination unit 307, a transmission unit 315, and a reception unit 316. When the payment amount for the retail store 400 is input from the input unit 311, the balance x is read from the memory 30 M and displayed on the display unit 30 D to confirm that the balance x is equal to or larger than the payment amount. Next, the electronic cash C = {x, X, N U , S B (X, N U )} of the face value X and the remaining balance x is read from the memory 30M, and is transmitted.
315 to the retail store 400. Retail in response to this
When the inquiry information e, TIME, and W are received from the receiver 400 by the receiving unit 316, TIME and W are subjected to a one-way function processing by the one-way function unit 306 to obtain f (TIME, W). The determination is made by the comparison determination unit 307. If they match, the signature generation unit 305 generates a signature S U (e, y) for the pair of e and y using the signature key SK U and sends it to the retail store 400 together with the payment amount y. At the same time, the subtraction unit 302 calculates the payment amount y from the remaining amount x.
Is subtracted, and the remaining amount x in the memory 30M is updated with the updated remaining amount x.
【0030】監視機関装置100 は図6に示すように、監
視データベース101 と、履歴データベース108 と、加算
部107 と、比較部103 と、これらの動作を制御する加算
部107 と、履歴データベース108 と、受信部112 と、送
信部113 と、受信部115 と、制御部114 とから構成され
ている。受信部112 で銀行200 から(X,NU)を受信すると
制御部114 は(X,NU)を監視データベースに登録し、それ
に対応して電子現金の合計使用金額初期値Y=0 を記録す
る。As shown in FIG. 6, the monitoring engine device 100 includes a monitoring database 101, a history database 108, an adding unit 107, a comparing unit 103, an adding unit 107 for controlling these operations, and a history database 108. , A receiving unit 112, a transmitting unit 113, a receiving unit 115, and a control unit 114. In the receiving unit 112 from the bank 200 (X, N U) and receives a control unit 114 registers the monitoring database (X, N U), recording the total use amount initial value Y = 0 in the electronic cash correspondingly I do.
【0031】以後、小売店400 から受信部115 により電
子現金C={x,X,NU,SB(X,NU)}による支払手順の履歴デー
タH={x,X,NU,SB(X,NU),TIME,W,e,y,SU(e,y)}を受信す
ると、制御部114 は受信データ中の(X,NU)が監視データ
ベース101 に既に登録されているか検索し、登録されて
いなければその電子現金による支払いは不正なものとし
て電子現金の発行銀行に(X,NU)を通知する。既に登録さ
れていればその(X,NU)に対応する監視データベース101
中の合計使用金額YとデータH中の支払金額yとを加算
部107 で加算する。その加算結果を比較部103 でデータ
H中の額面Xと比較する114 にその比較結果がY+y>Xで
あれば不正使用であると判定し、監視データベース101
から(X,NU)及びそれと対応するYを削除すると共に(X,N
U)を電子現金発行銀行に通知する。Y+y<Xであればその
電子現金の使用は不正のないものと判定、履歴データベ
ースにデータHを記録すると共に、監視データベース10
1中の対応する合計使用金額Yを加算部107 の加算結果
により更新する。Y+y=X の場合、その電子現金の額面X
が全額使用されてしまったことを意味し、従って監視デ
ータベース101 から(X,NU)とそれに対応するYを削除す
る。Thereafter, the history data H of the payment procedure using the electronic cash C = {x, X, N U , S B (X, N U )} H = {x, X, N U , by the receiving unit 115 from the retail store 400. Upon receiving S B (X, N U ), TIME, W, e, y, S U (e, y)}, the control unit 114 already registers (X, N U ) in the received data in the monitoring database 101. If it is not registered, the payment by electronic cash is regarded as improper and (X, N U ) is notified to the issuing bank of electronic cash. As if it is already registered (X, N U) monitoring database 101 corresponding to the
The adding unit 107 adds the total usage amount Y in the data and the payment amount y in the data H. The comparison result is compared with the denomination X in the data H by the comparison unit 103. If the comparison result is Y + y> X, it is determined that the use is illegal, and the monitoring database 101
(X, N U ) and Y corresponding thereto are deleted from (X, N
U ) to the electronic cash issuing bank. If Y + y <X, it is determined that the use of the electronic cash is not fraudulent, the data H is recorded in the history database, and the monitoring database 10 is used.
The corresponding total usage amount Y in 1 is updated based on the addition result of the addition unit 107. If Y + y = X, face value X of the electronic cash
There means that had been fully used, thus the monitoring database 101 (X, N U) Remove the corresponding Y.
【0032】上述の第1実施例では、同一利用者が電子
現金の発行を要求する毎に異なる署名検証鍵NU を生成
するため、額面Xが同じでも同一利用者の複数の電子現
金を区別することができる。同一利用者が常に同一署名
検証鍵NU を使用できるようにするには、電子現金毎に
異なる変数値R(例えば乱数)を生成し、前述のデータ
(X,NU)の代わりに(X,NU,R)を使用すればよい。即ち、銀
行200 では利用者情報Uに対応してデータ(X,NU,R)又は
n=h(X,NU,R) を記録する。また、監視機関100ではデー
タ(X,NU)を登録する代わりに(X,NU,R)又はn=h(X,NU,R)
を登録する。利用者は小売店400 にデータ(X,NU,R)及び
SB(X,NU,R)を含む電子現金Cを送る。決済においては、
監視機関100 は小売店からのデータH中の(X,NU,R)又は
それを変換したnが監視データベース101 に登録されて
いるかを検査する。その他の具体的手順は前述と同様で
ある。 第2実施例 ところで、図2、3及び4を参照に説明した実施例で
は、銀行と電子現金の発行を求める場合に、利用者は自
分の署名検証鍵NU を銀行に提出するので、銀行は利用
者の情報Uと(X,NU)との対応関係を知っている。一方、
小売店では電子現金の支払を受ける場合に利用者から
(X,NU)を受け取る。そこで、もし銀行が小売店と結託す
れば、銀行は小売店で電子現金を使用した利用者の情報
Uを得ることができることになるので、図2、3及び4
の実施例はプライバシ保護の面で十分といえない。この
点を改善した実施例を以下に図7、8及び9を参照して
説明する。[0032] In the first embodiment described above, since the same user to generate a different signature verification key N U for each requesting the issuance of electronic cash, also distinguish between multiple electronic cash the same user at face value X is the same can do. To enable the same user to always use the same signature verification key N U , a different variable value R (for example, a random number) is generated for each electronic cash and the
(X, N U , R) may be used instead of (X, N U ). That is, in the bank 200, the data (X, N U , R) or
n = h (X, N U , R) is recorded. Also, the monitoring engine 100 data (X, N U) instead of registering the (X, N U, R) or n = h (X, N U , R)
Register The user stores the data (X, N U , R) and
S B (X, N U, R) sends an electronic cash C including. In settlement,
The monitoring agency 100 checks whether (X, N U , R) in the data H from the retail store or n obtained by converting the data is registered in the monitoring database 101. Other specific procedures are the same as those described above. Second Embodiment By the way, in the embodiment described with reference to FIGS. 2, 3 and 4, when requesting issuance of electronic cash with a bank, the user submits his / her signature verification key N U to the bank. Knows the correspondence between user information U and (X, N U ). on the other hand,
At retail stores, users receive payment for electronic cash
(X, N U ) is received. Therefore, if the bank collaborates with the retail store, the bank can obtain the information U of the user using the electronic cash at the retail store.
Is not sufficient in terms of privacy protection. An embodiment in which this point is improved will be described below with reference to FIGS.
【0033】この第2実施例では、電子現金発行処理に
おいて利用者は銀行に利用者の(X,N U)の対が知られない
ようにするため、(X,NU)を監視機関の暗号化鍵で暗号化
して銀行に与える。また、銀行の電子現金発行手順にお
いて、銀行にNU が知れないようにするため、銀行の電
子現金に対する署名はブラインド署名を行う。以下、図
7、8、9を参照して詳細に説明する。 (1) 電子現金の発行処理 まず、利用者が、電子現金を発行してもらう場合を図7
を用いて説明する。In the second embodiment, the electronic cash issuance processing
At the bank, the user enters the user's (X, N U) Pair is unknown
(X, NU) Is encrypted with the encryption key of the monitoring organization
And give it to the bank. In addition, the bank's electronic cash issuing procedure
And N in the bankU Of the bank to prevent
The signature for the child cash is a blind signature. Below
This will be described in detail with reference to 7, 8, and 9. (1) Electronic cash issuance processing First, a case in which a user issues electronic cash is shown in FIG.
This will be described with reference to FIG.
【0034】監視機関100 は、予め公開鍵暗号方式用の
公開鍵PKT と秘密鍵SKT を生成してメモリ10M に保持し
ておき、銀行200 はブラインド署名方式用の各額面Xに
対応した対の公開鍵PKB と秘密鍵SKB を生成して保持し
ているものとする。監視機関100 は、公開鍵暗号用の暗
号化関数ET と公開鍵PKT を公開すると共に、公開鍵PK
T と対をなす復号用の秘密鍵SKT と、それを用いる復号
関数DT を秘密に保持する。The monitoring body 100, may be held in the memory 10M to generate a public key PK T and the secret key SK T for pre-public-key cryptography, bank 200 corresponding to each of the face value X for the blind signature scheme It is assumed that a pair of public key PK B and secret key SK B are generated and held. Monitoring engine 100, as well as to publish the public key PK T and encryption function E T for public key encryption, public key PK
And a secret key SK T for decoding forming a T pair, holds the decryption function D T using the same secret.
【0035】銀行200 は、ブラインド署名用の公開鍵PK
B と署名検証関数VB を公開すると共に、ブラインド署
名用公開鍵PKB と対をなすブラインド署名用秘密鍵SKB
と、それを用いた署名生成関数SB を秘密に保持する。
利用者300 は、銀行200 の利用者300 の口座から電子現
金の額面金額Xを引き下ろすことを要請するための手続
きを以下の手順で行う。The bank 200 has a public key PK for blind signature.
As well as publish the B and the signature verification function V B, the secret key for the blind signature forms a blind signature for the public key PK B and the pair SK B
When, for holding a signature generation function S B using the same secret.
The user 300 performs a procedure for requesting that the face value X of the electronic cash be deducted from the account of the user 300 of the bank 200 in the following procedure.
【0036】ただし、この実施例では利用者は電子現金
の発行を要求するときは常に同一の署名検証鍵NU を使
う場合で説明する。従って、この場合、同一利用者の複
数の電子現金をそれぞれ区別できるように、前述した変
数値(例えば乱数)Rを(X,N U)と組み合わせて使用す
る。 ステップ1:利用者300 は、ディジタル署名の鍵生成部
301 を用いて、署名生成鍵SKU 及び署名検証鍵NU を生
成し、乱数生成部30R により変数値として乱数Rを生成
する。なお、この実施例では乱数Rを使うことにより安
全性をより高めているが、乱数Rの代わりに他のどの様
な任意の変数値を使ってもよい。However, in this embodiment, the user uses electronic cash.
Is always required to issue the same signature verification key NU use
The case will be described. Therefore, in this case, the same user
In order to be able to distinguish between electronic cash
Numerical value (for example, random number) R is (X, N UUse in combination with
You. Step 1: User 300 generates a digital signature key generation unit.
Using 301, the signature generation key SKU And signature verification key NU Raw
And a random number R is generated as a variable value by the random number generation unit 30R.
I do. Note that in this embodiment, the use of the random number R
It is more perfect, but instead of random number R
Any variable value may be used.
【0037】次に、監視機関100 の暗号化用公開鍵PKT
を使って公開されている暗号関数E T を計算する暗号部
303 によりET(X,NU,R)を計算し、金額Xを利用者300 の
口座から引き下ろすことを要請するメッセージをET(X,N
U,R)とともに銀行200 に送る。このメッセージは、利用
者300 のディジタル署名等で認証されていることが望ま
しい。前述の第1実施例で説明したと同様に、利用者は
NU を所望の関数で変換してnを生成し、銀行200 に対
しXを引き下ろすように要請すると共に暗号化情報E
T(X,n) を生成して銀行へ送るようにしてもよい。Next, the public key PK for encryption of the monitoring institution 100 is used.T
Publicly known cryptographic function E T The cryptographic unit that calculates
303 by ET(X, NU, R) and calculate the amount X of the user 300
A message asking you to withdraw from your accountT(X, N
U, R) to bank 200. This message is used
Should be authenticated by the digital signature of the
New As described in the first embodiment, the user
NU Is converted by a desired function to generate n.
Requesting that X be pulled down and encrypting information E
T(X, n) may be generated and sent to the bank.
【0038】ステップ2:銀行200 は、利用者300 の口
座の残高をチェックし、その残高よりXを減額し、更に
利用者名Uと対応させてET(X,NU,R)を署名検証鍵情報と
して利用者データベース201 に記録しておく。利用者30
0 の署名のついた引き下ろし依頼メッセージがあればそ
れも一緒に記録しておく。銀行200 は暗号化データE
T(X,NU,R)を復号する復号秘密鍵SKT を持っていないの
で、(X,NU,R)を知ることはできない。Step 2: The bank 200 checks the balance of the account of the user 300, reduces X from the balance, and signs E T (X, N U , R) in association with the user name U. It is recorded in the user database 201 as verification key information. User 30
If there is a withdrawal request message with a signature of 0, record it together. Bank 200 has encrypted data E
T (X, N U, R ) does not have a decryption secret key SK T for decoding the, can not be known (X, N U, R) .
【0039】次に、{X,ET(X,NU,R)}を監視機関装置100
に送付する。 ステップ3:監視機関100 は、復号関数DT の復号部10
2 を用いて、ET(X,NU,R)を復号化して(X,NU,R)を求め
る。次に、銀行200 から送られてきたXと復号化により
得られたXの同一性を比較部103 により検証する。それ
が正しければ、(X,NU,R)を署名検証鍵情報として監視デ
ータベース105 に登録すると共に、それに対応して利用
金額の合計額Yの初期値Y=0 を記憶する。Next, {X, E T (X, N U , R)}
Send to Step 3: The monitoring institution 100 decodes the decryption function DT
2 using, E T (X, N U , R) decodes the seek (X, N U, R) . Next, the comparison unit 103 verifies the identity between X sent from the bank 200 and X obtained by decryption. If it is correct, and stores the (X, N U, R) and registers in the monitoring database 105 as a signature verification key information, the initial value Y = 0 in the sum Y of spending correspondingly.
【0040】ステップ4:利用者300 は、額面金額Xに
対応する銀行のブラインド署名公開鍵PKB を用いて、ブ
ラインド署名生成部304 によりF(NU) を生成し(ブライ
ンド署名前処理と呼ばれている)、それを銀行200 に送
る。銀行200 はF(NU) をブラインド署名作成部203 に入
力し、ブラインド署名秘密鍵SKB を使ってブラインド署
名Z(NU) を生成し、それを利用者300 に送る。Step 4: The user 300 generates F (N U ) by the blind signature generation unit 304 using the blind signature public key PK B of the bank corresponding to the face value X (referred to as pre-blind signature processing). ) And send it to Bank 200. Banks 200 inputs F a (N U) in a blind signature generating unit 203, by using a blind signature secret key SK B to generate a blind signature Z (N U), and sends it to the user 300.
【0041】利用者300 は、ブラインド署名公開鍵PKB
を使ってブラインド署名抽出部308によりZ(NU) から銀
行の署名SB(NU)を得る(一般にブラインド署名後処理と
呼ばれている)。ブラインド署名の実現法については、
RSA法を用いた方式が、Chaum, Fiat,Naorによる"Un-
traceable Electronic Cash", Proc. of CRYPTO'88"に
紹介されており、更にSchnorr法を用いたブラインド署
名がT.Okamotoによる"Provably Secure and Practical
Identification Schemes and Corresponding Signature
Schemes", Proc. of CRYPTO'92, pp.31-53, 1993のApp
endix Bで紹介されている。The user 300 receives the blind signature public key PK B
Is used to obtain the bank signature S B (N U ) from Z (N U ) by the blind signature extraction unit 308 (generally called post-blind signature processing). For how to implement blind signature,
The method using the RSA method is described in Chaum, Fiat, Naor's "Un-
traceable Electronic Cash ", Proc. of CRYPTO'88", and a blind signature using the Schnorr method has been introduced by T. Okamoto in "Provably Secure and Practical".
Identification Schemes and Corresponding Signature
Schemes ", Proc. Of CRYPTO'92, pp.31-53, 1993 App
It is introduced in endix B.
【0042】ここで、利用者300 はC={x,X,NU,R,S
B(NU)}を額面X、残高xの電子現金としてメモリ30M に
保持する。ただし、残高xの初期値はx=X である。この
第2実施例では、署名検証鍵NU を利用者300 が生成す
る例を示しているが、他の機関、例えば監視機関100 が
生成することにしてもよい。その場合は、利用者300 は
暗号鍵KU を作り、ET(KU)を銀行200 を経由して監視機
関100 に送り監視機関100 はET(K) を復号してKを求
め、生成したNU をKで暗号化してEK(NU)とし、そのEK
(NU)を銀行経由で利用者に送信する。利用者300 は暗号
鍵Kを使って受信したEK(NU)を復号してNU を得る。 (2) 電子現金の支払 次に、利用者300 が、利用者の署名検証鍵NU と銀行20
0 より発行された署名SB(NU)との組を額面X、残高x
(初期値x=X)の電子現金Cとして用いて小売店Wで
金額y(y≦x)を支払う場合について図8を用いて説
明する。一般にブラインド署名では、所望の種類の額面
Xにそれぞれ対応して固有な対の鍵SKB、PKB を生成す
ることが可能である。従って、額面を提示すれば、使用
すべきブラインド署名検証鍵PKB がわかる。即ち、署名
SB(NU)は署名検証鍵NU と額面Xの両方の情報を含んで
いることと同じである。Here, the user 300 has C = {x, X, N U , R, S
B (N U )} is stored in the memory 30M as electronic cash having a face value X and a balance x. However, the initial value of the balance x is x = X. In the second embodiment, an example is shown in which the user 300 generates the signature verification key N U , but it may be generated by another institution, for example, the monitoring institution 100. In that case, the user 300 creates an encryption key K U , sends E T (K U ) to the monitoring agency 100 via the bank 200, and the monitoring agency 100 decrypts E T (K) to obtain K, The generated N U is encrypted with K to obtain E K (N U ), and the E K
(N U ) is sent to the user via the bank. The user 300 decrypts the received E K (N U ) using the encryption key K to obtain N U. (2) Payment of electronic cash Next, the user 300 enters the user's signature verification key N U and the bank 20
0 and the signature S B (N U ) issued from
A case in which the retailer W pays the amount y (y ≦ x) using the electronic cash C of (initial value x = X) will be described with reference to FIG. Generally, in the blind signature, it is possible to generate a unique pair of keys SK B and PK B corresponding to a desired type of face value X, respectively. Therefore, if the face value is presented, the blind signature verification key PK B to be used can be known. That is, the signature
S B (N U ) is the same as including information on both the signature verification key N U and the face value X.
【0043】ステップ1:利用者300 は、メモリ30M か
ら読みだした残高xを表示部30D に表示してそれが利用
しようとする金額y以上であることを確認して電子現金
C={x,X,NU,R,SB(NU)} を小売店400 に送る。 ステップ2:小売店400 は、署名検証部401 により額面
Xに対応する公開鍵PK B を用いて、電子現金の発行者
(銀行200 )の署名SB(NU)の正当性を署名検証関数VB
により検証する。正しければ、一方向関数演算部402 に
より一方向関数fを用いて時間TIME、小売店400 に対応
する情報Wから検証のための問い合わせ情報e=f(TIME,
W)を生成し、TIME,W,eを利用者300 に送る。Step 1: The user 300 has the memory 30M
Display the balance x read out on the display unit 30D and use it
Make sure that the amount is more than y
C = {x, X, NU, R, SB(NU)} To the retail store 400. Step 2: Retail store 400 is denominated by signature verification unit 401
Public key PK corresponding to X B Using the electronic cash issuer
(Bank 200) Signature SB(NU) Is verified by the signature verification function VB
Verify by If it is correct, the one-way function operation unit 402
Using the one-way function f for time TIME and retail stores 400
Inquiry information e = f (TIME,
W), and sends TIME, W, and e to the user 300.
【0044】ステップ3:利用者300 は、一方向関数演
算部306 、比較部307 を用いて、e=f(TIME,W) の正当
性を検証する。正しければ、署名生成部305 を用いて、
送られてきたe及び支払金額y(y≦x)に対する利用
者の署名SU(e,y) を計算し、y,SU(e,y) を小売店400
に送付する。 ステップ4:小売店400 は、署名検証部401 を用いて、
利用者署名SU(e,y) と支払金額yの正当性を問い合わせ
情報eと署名検証鍵NU を使って検証し、更に、比較部
403 を用いて、y≦xを検証する。いずれも正しけれ
ば、該当支払金額yの電子現金による支払いを認める。
また、後の決済のため、利用者300 との間の交信データ
H={x,X,NU,R,SB(NU),TIME,W,e,y,SU(e,y)}を小売店デー
タ蓄積部40D に保持する。、少なくとも1つが正しくな
ければ支払を認めない判定結果OK/NG を利用者に送る。
また、後の決済のため、利用者300との間の交信データH
={x,X,NU,R,SB(NU),TIME,W,e,y,SU(e,y)}を小売店デー
タ蓄積部40Dに保持する。Step 3: The user 300 verifies the validity of e = f (TIME, W) by using the one-way function calculator 306 and the comparator 307. If it is correct, using the signature generation unit 305,
Calculate the user's signature S U (e, y) for the sent e and the payment amount y (y ≦ x), and substitute y, S U (e, y) for the retail store 400
Send to Step 4: The retail store 400 uses the signature verification unit 401 to
The validity of the user signature S U (e, y) and the payment amount y is verified using the inquiry information e and the signature verification key N U.
403 is used to verify y ≦ x. If both are correct, payment of the payment amount y by electronic cash is permitted.
Also, communication data with the user 300 for later settlement
H = {x, X, N U , R, S B (N U ), TIME, W, e, y, S U (e, y)} are stored in the retail store data storage unit 40D. If at least one of them is incorrect, the payment is not accepted. The judgment result OK / NG is sent to the user.
In addition, communication data H with the user 300 is used for later settlement.
= {x, X, N U , R, S B (N U ), TIME, W, e, y, S U (e, y)} are stored in the retail store data storage unit 40D.
【0045】なお、小売店400 がTIME,W,eを利用者
300 へ送った後、SB(NU)の正当性の検証を行ってもよ
い。 ステップ5:利用者300 は小売店400 からの判定結果OK
/NG がOKであれば、メモリ30M の残高xを減算部302 に
よりx←x-y と更新する。 (3) 決済 最後に、小売店Wと銀行Bの間の決済方法について図9
を用いて説明する。[0045] The retail store 400 uses TIME, W, and e for the user.
After sending to 300, the validity of S B (N U ) may be verified. Step 5: User 300 OKs decision result from retail store 400
If / NG is OK, the balance x in the memory 30M is updated by the subtractor 302 as x ← xy. (3) Settlement Finally, the settlement method between the retail store W and the bank B is shown in FIG.
This will be described with reference to FIG.
【0046】ステップ1:小売店400 は決済のためにま
ず監視機関100 に利用者300 と小売店400 の間の全ての
相互通信データH={x,X,NU,R,SB(NU),TIME,W,e,y,SU(e,
y)}を決済銀行名とともに送信する。 ステップ2:監視機関100 の制御部114 は、相互通信デ
ータHに含まれる利用者300 の署名検証用鍵NU と、乱
数Rと、額面Xの組(X,NU,R)が監視デタベース105 に登
録されているかどうかを検査する。登録されていれば、
制御部114 は加算部107 及び比較部103 を用いて、以下
の処理を行う。まず、(X,NU,R)に対応して記録されてい
る利用金額の合計値YをY+y→Yに更新し、更に更新され
たYがXを越えてないことを検査する。また、制御部11
4 は相互通信データHを履歴データベース108 に記録す
る。[0046] Step 1: All intercommunication data H = {x between retailers 400 retailers 400 and first user 300 for monitoring engine 100 to settle, X, N U, R, S B (N U ), TIME, W, e, y, S U (e,
y)} with the clearing bank name. Step 2: The control unit 114 of the monitoring engine 100, and the key N U for signature verification of the user 300 included in intercommunication data H, and the random number R, the face value X set (X, N U, R) is monitored Detabesu Check if it is registered in 105. If registered
The control unit 114 performs the following processing using the addition unit 107 and the comparison unit 103. First, to check that it is not exceeded (X, N U, R) and updates the total value Y of the usage amounts are recorded in correspondence with the Y + y → Y, it is further updated Y is a X. The control unit 11
4 records the mutual communication data H in the history database 108.
【0047】もし、更新された合計支払額Yが額面Xを
越えてなければ、使用された電子現金の発行銀行200 に
対し、小売店400 の指定した銀行の口座に金額yを振り
込むよう指示する。このとき、小売店400 が口座を持つ
銀行は、利用者300 の検証用鍵NU にブラインド署名し
た銀行200 (電子現金を発行した銀行)でなくても良
い。更に、Y+y=X ならば、監視データベース105 から
(X,NU,R)及びそれに対応するYを削除する。If the updated total payment amount Y does not exceed the face value X, the issuing bank 200 of the used electronic cash is instructed to transfer the amount y to the account of the designated bank of the retail store 400. . At this time, the bank in which the retail store 400 has an account need not be the bank 200 (the bank that issued the electronic cash) that blind-signed the verification key N U of the user 300. Further, if Y + y = X, from the monitoring database 105
(X, N U, R) and to remove the Y corresponding thereto.
【0048】(X,NU,R)が監視データベース105 に登録さ
れていない場合は、利用者による不正支払いが行われた
ものとして、不正者特定処理を行う。また、Y+y>X なら
ば、制御部114 は監視データベース105 から(X,NU,R)及
びそれに対応するYを削除すると共に、やはり、利用者
による不正支払いが行われたものとして、不正者特定処
理を行う。If (X, N U , R) is not registered in the monitoring database 105, it is assumed that an unauthorized payment has been made by the user, and an unauthorized person identification process is performed. Also, if Y + y> X, the control unit 114 monitoring database 105 (X, N U, R ) and deletes the corresponding Y to, again, as fraudulent payment by the user is performed, Perform unauthorized person identification processing.
【0049】ステップ3:不正者特定処理では、制御部
114 は、履歴データベース108 より不正行為の証拠とな
る情報Hを読み出し、情報H中の(X,NU,R)を暗号部116
により公開鍵PKT を使って暗号化してET(X,NU,R)を得
て、情報Hと共に電子現金の発行元銀行200 に送付す
る。銀行200 は、不正行為の証拠である情報H中のS
U(e,y),SB(NU)の正当性を鍵NU,PKB を使って署名検証
部203 により検証し、正しければET(X,NU,R)をキーとし
て利用者データベース201 から対応する不正利用者情報
Uに該当する不正利用者300 を特定する。あるいは、監
視機関100 に暗号部116を設ける代わりに、銀行200 に
暗号部を設けて、監視機関100 から受けた(X,NU,R)を暗
号化してET(X,NU,R)を得てもよい。Step 3: In the unauthorized person identification process, the control unit
114 reads out the information H as evidence of fraud from the history database 108, and (X, N U , R) in the information H is encrypted by the encryption unit 116.
Obtaining the public key PK using the T encrypted to E T (X, N U, R) and by, be sent to the issuing bank 200 of the electronic money with the information H. The bank 200 determines that S in the information H
The validity of U (e, y), S B (N U ) is verified by signature verification unit 203 using keys N U , PK B, and if correct, E T (X, N U , R) is used as a key An unauthorized user 300 corresponding to the corresponding unauthorized user information U is specified from the user database 201. Alternatively, instead of providing the encryption unit 116 in the monitoring organization 100, an encryption unit is provided in the bank 200, and (X, N U , R) received from the monitoring organization 100 is encrypted to obtain E T (X, N U , R ) May be obtained.
【0050】更に、小売店400 が実名Wを監視機関100
に教えたくない場合は、小売店が監視機関に送る通信デ
ータH中には仮名W'を用いて実名W を使わないように
する。また、小売店400 は決済銀行に400 とWの対応を
通知しておくため、その銀行は監視機関より受け取った
Wへの振り込み依頼を小売店400 への振り込み依頼であ
ると判断する。Further, the retail store 400 transmits the real name W to the monitoring organization 100.
If the retailer does not want to teach, the pseudonym W ′ is not used in the communication data H sent by the retail store to the monitoring organization so that the real name W 2 is not used. In addition, since the retail store 400 notifies the settlement bank of the correspondence between 400 and W, the bank determines that the transfer request to W received from the monitoring organization is a transfer request to the retail store 400.
【0051】次に上述の第2実施例における特徴的な利
用者装置300 と監視機関100 の機能構成を以下に説明す
る。図10は上述の第1実施例において利用者300 の処
理手順を実行するための利用者装置の機能ブロック図を
示す。その構成は、図7及び8中の利用者300 が実行す
る電子現金発行時の処理機能部300aと、電子現金使用時
の処理機能部300bが互いに入力部311 、制御部312 、メ
モリ30M を共有するように構成されている。Next, a description will be given below of the functional configuration of the user apparatus 300 and the monitoring organization 100 which are characteristic in the second embodiment. FIG. 10 is a functional block diagram of a user device for executing the processing procedure of the user 300 in the first embodiment. In the configuration, the processing function unit 300a for issuing electronic cash executed by the user 300 in FIGS. 7 and 8 and the processing function unit 300b for using electronic cash share the input unit 311, the control unit 312, and the memory 30M with each other. It is configured to be.
【0052】電子下金発行時の機能構成部300aは、入力
部311 と、各部の動作を制御するための制御部312 と、
鍵生成部301 と、暗号化部303 と、ブラインド署名前処
理部304 と、ブラインド署名後処理部308 と、送信部31
3 と、受信部314 と、メモリ30M とから構成されてい
る。制御部312 は入力部311 からコマンド、利用者情報
U、額面Xが与えられると、電子現金発行要求のため利
用者情報Uと額面Xを送信部313 から銀行200(B)に送信
すると共に、鍵生成部301 に対し検証鍵NU と署名鍵SK
U の生成を行わせ、Xと共にメモり30M に保持させる。
また、監視機関100 の暗号化用公開鍵PKT を使って暗号
化部303 によりX,NU,Rを暗号化して得たET(X,NU,R)を銀
行200 に送信する。更に銀行のブラインド署名用公開鍵
PKB を使ってブラインド署名前処理部304 により検証鍵
NU を前処理し、得られたF(NU) を銀行200 に送信す
る。The function configuration unit 300a at the time of issuing the electronic money payment includes an input unit 311 and a control unit 312 for controlling the operation of each unit.
Key generation section 301, encryption section 303, blind signature pre-processing section 304, blind signature post-processing section 308, and transmission section 31
3, a receiving unit 314, and a memory 30M. When a command, user information U, and face value X are given from the input unit 311, the control unit 312 transmits the user information U and face value X from the transmission unit 313 to the bank 200 (B) for an electronic cash issuance request, Verification key N U and signature key SK are sent to key generation section 301.
U is generated and stored in the memory 30M together with X.
Also, the encryption unit 303 using a cryptographic public key PK T of the monitoring engine 100 X, N U, transmits E T obtained by encrypting the R (X, N U, R ) and the bank 200. In addition, the public key for the bank's blind signature
The blind signature pre-processing unit 304 pre-processes the verification key N U using PK B , and sends the obtained F (N U ) to the bank 200.
【0053】制御部312 は銀行200 からF(NU) に対する
ブラインド署名Z(NU) を受信するとブラインド署名後処
理部308 により銀行のブラインド署名用公開鍵PKB を使
って銀行の署名SB(NU)を抽出し、それをメモり30M に保
持する。電子現金使用時の機能構成部300bは入力部311
と、制御部312 と、メモリ30Mと、表示部30D と、減算
部302 と、署名構成部305 と、一方向関数部306 と、比
較判定部307 と、送信部315 と、受信部316 とから構成
される。小売店400 に対する支払額が入力部311 から入
力されるとメモリ30M から残額xを読み出し、表示部30
D に表示し、残額xが支払額以上であることを確認す
る。次にメモリ30Mから額面X、残金xの電子現金C=
{x,X,NU,SB(NU)}を読み出し、送信部315 から小売店400
に送信する。これに応答して小売店400 から問い合わ
せ情報e、TIME、Wを受信部316 により受信するとTIME
とWを一方向関数部306 により一方向関数処理してf(TI
ME,W) を得て、これが受信したeと一致するか、比較判
定部307で判定する。一致すれば署名生成部305 で署名
鍵SKU を使ってeとyの組に対する署名SU(e,y) を生成
し、支払金額yと共に小売店400 に送信する。それと共
に減算部302 で残額xから支払金額yを減算して更新し
た残額xでメモリ30M 内の残額xを更新する。The control unit 312 is a signature from the bank 200 bank using F (N U) blind signature Z (N U) receives the public blind signature of the bank by the blind signature postprocessing unit 308 key PK B for S B Extract (N U ) and keep it in memory 30M. The function configuration unit 300b when using electronic cash is an input unit 311
, A control unit 312, a memory 30M, a display unit 30D, a subtraction unit 302, a signature construction unit 305, a one-way function unit 306, a comparison determination unit 307, a transmission unit 315, and a reception unit 316. Be composed. When the payment amount for the retail store 400 is input from the input unit 311, the balance x is read out from the memory 30 M and the display unit 30 is read.
Display on D and confirm that the balance x is equal to or greater than the payment amount. Next, the electronic cash C of the face value X and the balance x from the memory 30M =
{x, X, N U , S B (N U )} is read out, and the transmission
Send to When the inquiry information e, TIME, and W are received by the receiving unit 316 from the retail store 400 in response to this,
And W are processed by a one-way function by a one-way function unit 306 to obtain f (TI
ME, W), and the comparison / determination unit 307 determines whether or not this matches the received e. If they match, the signature generation unit 305 generates a signature S U (e, y) for the pair of e and y using the signature key SK U and sends it to the retail store 400 together with the payment amount y. At the same time, the subtractor 302 updates the balance x in the memory 30M with the updated balance x by subtracting the payment amount y from the balance x.
【0054】監視機関装置100 は図11に示すように、
メモリ10M と、監視データベース101 と、復号部102
と、比較部103 と、履歴データベース108 と、加算部10
7 と、比較部103 と、これらの動作を制御する加算部10
7 と、履歴データベース108 と、受信部112 と、送信部
113 と、受信部115 と、これらの各部の動作を制御する
制御部114 とから構成されている。受信部112 で銀行20
0 からXとET(X,NU,R)が受信されると、復号部102 は暗
号用秘密鍵SKT を使って(X,NU,R)を復号し、得られた金
額Xと受信したXが一致するかを比較部103 でチェック
し、一致すればN U と(X,NU,R)の対と、それに対応する
利用合計金額の初期値Y=0 を監視データベース101 に登
録する。The monitoring engine device 100 is, as shown in FIG.
Memory 10M, monitoring database 101, decoding unit 102
, A comparison unit 103, a history database 108, and an addition unit 10.
7, a comparison unit 103, and an addition unit 10 for controlling these operations.
7, the history database 108, the receiving unit 112, and the transmitting unit
113, a receiving unit 115, and control operations of these units.
And a control unit 114. Bank 20 in the receiver 112
0 to X and ET(X, NU, R), the decoding unit 102
Secret key SKT Using (X, NU, R) and the resulting gold
The comparison unit 103 checks whether the received X matches the sum X
And if they match, N U And (X, NU, R) pair and its corresponding
The initial value Y = 0 of the total usage amount is registered in the monitoring database 101.
Record.
【0055】以後、小売店400 から受信部115 により電
子現金C={x,X,NU,R,SB(NU)}による支払手順の履歴デー
タH={x,X,NU,R,SB(NU),TIME,W,e,y,SU(e,y)} を受信す
ると、制御部114 は受信データ中の(X,NU,R)が監視デー
タベース101 に既に登録されているか検索し、登録され
ていなければその電子現金による支払いは不正なものと
して電子現金の発行銀行に(X,NU,R)を通知する。既に登
録されていればその(X,NU,R)に対応する監視データベー
ス101 中の合計使用金額YとデータH中の支払金額yと
を加算部107 で加算する。Thereafter, the history data H = {x, X, N U , of the payment procedure using the electronic cash C = {x, X, N U , R, S B (N U )} from the retail store 400 by the receiving unit 115. Upon receiving R, S B (N U ), TIME, W, e, y, S U (e, y)}, the control unit 114 stores (X, N U , R) in the received data in the monitoring database 101. already or search has been registered, the payment by the electronic cash if it is not registered to notify the issuing bank of electronic cash (X, N U, R) as illegal. If it is already registered its (X, N U, R) is added by an adder 107 and a payment amount y in total use amount Y and the data H in the monitoring database 101 corresponding to the.
【0056】その加算結果を比較部103 でデータH中の
額面Xと比較する114 にその比較結果がY+y>Xであれば
不正使用であると判定し、監視データベース101 から
(X,NU,R)及びそれと対応するYを削除すると共に(X,NU,
R)を電子現金発行銀行に通知する。Y+y<Xであればその
電子現金の使用は不正のないものと判定、履歴データベ
ースにデータHを記録すると共に、監視データベース10
1 中の対応する合計使用金額Yを加算部107 の加算結果
により更新する。Y+y=X の場合、その電子現金の額面X
が全額使用されてしまったことを意味し、従って監視デ
ータベース101 から(X,NU,R)とそれに対応するYを削除
する。The result of the addition is compared with the denomination X in the data H by the comparing unit 103. If the result of the comparison is Y + y> X, it is determined that the unauthorized use has occurred.
(X, N U, R) and (X, N U deletes the corresponding Y therewith,
R) to the electronic cash issuing bank. If Y + y <X, it is determined that the use of the electronic cash is not fraudulent, the data H is recorded in the history database, and the monitoring database 10 is used.
The corresponding total usage amount Y in 1 is updated based on the addition result of the addition unit 107. If Y + y = X, face value X of the electronic cash
There means that had been fully used, thus the monitoring database 101 (X, N U, R ) to remove the Y corresponding thereto.
【0057】上述の第2実施例において、利用者はET
(X,NU,R)を銀行及び監視機関に送る代わりに、まず、
(X,NU)をハッシュ関数で署名検証鍵情報n=h(X,NU) に変
換し、(n,R) を暗号化して得たET(X,NU,R)を銀行及び監
視機関に送ってもよい。その場合、銀行はET(n,R) を署
名検証鍵情報として利用者データベースに記録紙、監視
機関はET(n,R)又は(n,R)を署名検証鍵情報として関しデ
ータベースに登録する。In the above-described second embodiment, the user is ET
Instead of sending (X, N U , R) to banks and monitoring agencies,
(X, N U) converts the signature verification key information in the hash function n = h (X, N U ) , the bank (n, R) E T obtained by encrypting the (X, N U, R) and And may be sent to a monitoring agency. In that case, the bank E T (n, R) recording paper in the user database as the signature verification key information, monitoring agencies E T (n, R) or (n, R) to respect database as the signature verification key information register.
【0058】第1実施例で述べたと同様に、利用者の署
名検証鍵NU を電子現金発行毎に変えれば、変数Rを使
用してもしなくてもよい。使用しない場合、銀行は利用
者名Uに対応して(X,NU)を利用者データベース201 に記
録し、監視機関100 は(X,NU)またはET(X,NU)を登録す
る。変数Rを使用する場合は、その変数Rを上述の第2
実施例と全く同様に扱えばよいし、あるいは変数Rを利
用者、銀行、監視機関間の通信の安全性を高めるために
のみ使用する。後者の場合、小売店400 への支払電子現
金Cには変数Rを含めないので、決済において、小売店
400 からの情報H中に含まれる利用者の署名検証鍵NU
が監視データベース105 に登録されているかを検査する
ためには、予め監視データベース105 に(X,NU)とET(X,N
U,R)の対を登録しておく。決済時に(X,NU)をキーワード
として検索し、それが登録されていれば、必要に応じて
(即ち不正利用者検出の必要があれば)検出したET(X,N
U,R)を銀行に送る。As described in the first embodiment, the variable R may or may not be used if the signature verification key N U of the user is changed every time the electronic cash is issued. If not used, the bank records (X, N U ) in the user database 201 corresponding to the user name U, and the monitoring agency 100 registers (X, N U ) or E T (X, N U ) I do. When using the variable R, the variable R is
It may be handled in exactly the same way as in the embodiment, or the variable R is used only for enhancing the security of communication between the user, the bank and the monitoring organization. In the latter case, the variable R is not included in the electronic cash C to be paid to the retail store 400.
User's signature verification key N U included in information H from 400
Is checked in the monitoring database 105 beforehand, (X, N U ) and E T (X, N
U , R) pair is registered. At the time of payment, (X, N U ) is searched as a keyword, and if it is registered, the detected E T (X, N
U , R) to the bank.
【0059】[0059]
【発明の効果】この発明の第1実施例では、銀行と小売
店が結託すると利用者のプライバシイが保証されなくな
るという欠点があるが、銀行が不正をしなければ利用者
のプライバシイを保証でき、かつ不正使用を検出でき
る、という特徴を備えている。この発明の第2実施例で
は、Chaum らの方式と同様に、銀行が小売店と結託して
も利用者のプライバシイを保証でき、かつ不正使用を検
出できる、という特徴を備えている。According to the first embodiment of the present invention, there is a disadvantage that the privacy of the user cannot be guaranteed when the bank and the retail store are collocated. However, the privacy of the user is guaranteed if the bank does not cheat. It is characterized by the ability to detect unauthorized use. The second embodiment of the present invention has a feature that, similarly to the method of Chaum et al., The privacy of a user can be guaranteed even if a bank is consigned with a retail store, and unauthorized use can be detected.
【0060】更に、この発明のいずれかの方法でも、Ch
aum らの方式よりも支払処理における通信量を少なくす
ることができる。また、分割利用が可能で、更に電子現
金の発行者と利用者の口座を管理する金融機関を階層的
に分離することができる。例えば、Chaum 等の方法で
は、電子現金の支払において、不正が成功する確率が1/
230 のとき、処理回数を30回実行する必要があるた
め、一方向関数の出力サイズを128 ビットとすると、少
なくとも(3×128×30)=11520 ビットの通信量を必要と
する。Further, in any of the methods of the present invention, Ch
The communication volume in the payment process can be reduced compared to the method of aum et al. In addition, divisional use is possible, and the financial institution that manages the issuer of the electronic cash and the user's account can be hierarchically separated. For example, in the method of Chaum et al., The probability of successful fraud in electronic cash payment is 1 /
When 2 30, it is necessary to perform the processing frequency 30 times, when the output size of the one-way function 128 bits requires at least (3 × 128 × 30) = 11520 traffic bits.
【0061】一方、この発明での支払処理においては、
y,e及びそれに対する利用者の署名のサイズが通信量
となる。y,e(更にTIME,W)のサイズの合計は高々
200ビット程度あれば十分である。署名のサイズを10
24ビットとすると高々1200ビット程度となる。従って、
この発明の通信量は、支払処理時における通信量を10
倍程度少なくすることが可能である。On the other hand, in the payment processing according to the present invention,
The communication volume is y, e, and the size of the user's signature for it. It is sufficient that the total of the sizes of y and e (and TIME, W) is at most about 200 bits. Signature size 10
If it is 24 bits, it will be around 1200 bits at most. Therefore,
According to the communication amount of the present invention, the communication amount at the time of payment processing is 10
It can be reduced about twice.
【0062】また、この発明では発行した電子現金を合
計が額面金額になるまで何回でも分割して利用が可能で
ある。更に、電子現金発行を行う機関(銀行)と決済の
ための検証処理を行う機関(監視機関)を分離し、監視
機関において銀行の発行した電子現金の流通量を監視す
ることを可能としている。つまり、監視機関では、銀行
が発行した電子現金の総量と銀行に還流してきた電子現
金の総量を知ることができるため、各時点で流通してい
る電子現金量を監視することが可能となる。Further, according to the present invention, the issued electronic cash can be divided and used any number of times until the total amount becomes the denomination. Further, an institution that issues electronic cash (bank) and an institution that performs verification processing for settlement (monitoring institution) are separated from each other, so that the monitoring institution can monitor the distribution amount of electronic cash issued by the bank. That is, the monitoring institution can know the total amount of electronic cash issued by the bank and the total amount of electronic cash returned to the bank, so that it is possible to monitor the amount of electronic cash circulating at each time.
【図1】この発明が適用されるシステム構成の例を示す
図。FIG. 1 is a diagram showing an example of a system configuration to which the present invention is applied.
【図2】この発明の第1実施例における電子現金の発行
方法を機能的に示すブロック図。FIG. 2 is a block diagram functionally showing an electronic cash issuing method according to the first embodiment of the present invention.
【図3】この発明の第1実施例における電子現金の支払
方法を機能的に示すブロック図。FIG. 3 is a block diagram functionally showing an electronic cash payment method according to the first embodiment of the present invention.
【図4】この発明の第1実施例における電子現金の決済
方法を機能的に示すブロック図。FIG. 4 is a block diagram functionally showing an electronic cash settlement method according to the first embodiment of the present invention.
【図5】この発明の第1実施例における利用者装置の機
能構成を示すブロック図。FIG. 5 is a block diagram showing a functional configuration of the user device according to the first embodiment of the present invention.
【図6】この発明の第1実施例における監視機関装置の
機能構成を示すブロック図。FIG. 6 is a block diagram showing a functional configuration of the monitoring engine device according to the first embodiment of the present invention.
【図7】の発明の第2実施例における電子現金の発行方
法を機能的に示すブロック図。FIG. 7 is a block diagram functionally showing an electronic cash issuing method according to a second embodiment of the present invention.
【図8】この発明の第2実施例における電子現金の支払
方法を機能的に示すブロック図。FIG. 8 is a block diagram functionally showing an electronic cash payment method according to a second embodiment of the present invention.
【図9】この発明の第2実施例における電子現金の決済
方法を機能的に示ブロック図。FIG. 9 is a block diagram functionally showing an electronic cash settlement method according to a second embodiment of the present invention.
【図10】この発明の第2実施例における利用者装置の
機能構成を示すブロック図。FIG. 10 is a block diagram showing a functional configuration of a user device according to a second embodiment of the present invention.
【図11】この発明の第2実施例における監視機関装置
の機能構成を示す。FIG. 11 shows a functional configuration of a monitoring engine device according to a second embodiment of the present invention.
───────────────────────────────────────────────────── フロントページの続き (51)Int.Cl.6 識別記号 庁内整理番号 FI 技術表示箇所 G09C 1/00 640 7259−5J G09C 1/00 640D 660 7259−5J 660C 7259−5J 660B H04L 9/32 G06F 15/30 Z H04L 9/00 675D 675B ──────────────────────────────────────────────────の Continuation of the front page (51) Int.Cl. 6 Identification code Agency reference number FI Technical indication location G09C 1/00 640 7259-5J G09C 1/00 640D 660 7259-5J 660C 7259-5J 660B H04L 9 / 32 G06F 15/30 Z H04L 9/00 675D 675B
Claims (18)
電子現金を発行する銀行と、電子現金を利用する利用者
と、電子現金により支払を受ける小売店とより構成され
た電子現金システムの監視機関付き電子現金方法におい
て、以下のステップを含む: (1) 上記利用者は、銀行に利用者情報Uと電子現金の額
面に対応する金額Xを送信し、利用者の口座から金額X
を引き下ろすことを要請し、 (2) 上記銀行は、上記利用者の口座から金額Xを減額
し、上記利用者の署名検証用鍵NU 及び金額Xに対して
その銀行の署名SB(X,NU)を生成し上記利用者に送付する
と共に、上記金額Xと上記署名検証用鍵NU の情報を含
む署名検証鍵情報nを上記利用者情報Uと対応させて利
用者データベースに記録し、更に上記監視機関に上記署
名検証鍵情報を送付し、 (3) 上記監視機関は、上記署名検証鍵情報nを監視デー
タベースに登録し、 (4) 上記利用者は上記金額Xと、上記署名検証鍵NU
と、上記署名SB(X,NU)とを含む情報を額面Xの電子現金
Cとして使って支払金額yを上記小売店に支払い、 上記小売店は上記電子現金の正当性を検証して受け取
り、 (5) 上記小売店は上記電子現金Cの情報を含む上記利用
者との全交信データHを上記監視機関に送信して決済を
求め、 (6) 上記監視機関は受信した上記交信データH中の上記
電子現金Cの正当性を検証し、上記銀行に対し上記小売
店の口座に上記支払金額yを振り込むよう指示を与え
る。1. A monitoring organization for monitoring issuance of electronic cash;
An electronic cash system with a monitoring system for an electronic cash system, comprising a bank that issues electronic cash, a user who uses electronic cash, and a retail store that is paid by electronic cash, includes the following steps: (1 The user sends the user information U and the amount X corresponding to the face value of the electronic cash to the bank, and sends the amount X from the user's account.
It requested that pulling down the, (2) The Bank, reduced the amount of money X from the account of the user, of the bank to the signature verification key N U and the amount X of the user's signature S B ( X, N U ) and sends it to the user, and stores the amount of money X and the signature verification key information n including the information of the signature verification key N U in the user database in association with the user information U. Record, and further send the signature verification key information to the monitoring organization. (3) The monitoring organization registers the signature verification key information n in a monitoring database. (4) The user receives the amount X and The signature verification key N U
And, the signature S B (X, N U) and using the information as electronic cash C of face value X, including the payment of the amount of payment y to the retail store, the retail stores to verify the validity of the electronic cash (5) The retail store sends all the communication data H with the user including the information of the electronic cash C to the monitoring organization for settlement, and (6) the monitoring organization receives the communication data The validity of the electronic cash C in H is verified, and the bank is instructed to transfer the payment amount y to the account of the retail store.
(1) で上記監視機関は上記署名検証鍵情報と対応させて
合計使用金額Yを上記監視データベースに記録し、上記
ステップ(2) で上記利用者は上記電子現金内に残額xを
上記電子現金の情報に含めて上記小売店に送る。2. The method of claim 1, wherein the steps are
In (1), the monitoring organization records the total usage amount Y in the monitoring database in association with the signature verification key information, and in the step (2), the user stores the remaining amount x in the electronic cash in the electronic cash. And send it to the above retailers.
(4) は以下のステップを含む: (4a) 上記小売店は任意の情報eを生成し、それを上記
利用者に送り、 (4b) 上記利用者は、支払金額yと送られてきた上記情
報eとに対する利用者の署名SU(e,y) を生成し、上記電
子現金Cと,上記支払金額yと上記利用者の署名SU(e,
y)を上記小売店に送付し、 (4c) 上記小売店は、上記銀行の署名SB(X,NU)の正当性
を検証し、また上記利用者署名SU(e,y) の正当性を上記
検証鍵NU を用いて検証し、更に上記支払金額yが上記
電子現金の残額x以下であることを検証し、いずれの検
証も正しければ、上記支払金額yの上記電子現金による
支払いを認める。3. The method of claim 2, wherein the steps are
(4) includes the following steps: (4a) The retailer generates arbitrary information e and sends it to the user, and (4b) the user receives the payment amount y and the signature of the user for information e S U (e, y) to generate, and the electronic cash C, the signature of the payment amount y and the user S U (e,
(4c) the retailer verifies the validity of the bank's signature S B (X, N U ) and reconciles the user's signature S U (e, y) The validity is verified using the verification key N U, and the payment amount y is verified to be equal to or less than the remaining amount x of the electronic cash. If all the verifications are correct, the payment amount y is calculated using the electronic cash. Accept payment.
テップ(6) は以下のステップを含む: (6a) 上記監視機関は、上記相互通信データHより得ら
れる上記署名検証鍵情報nが上記監視データベースに登
録されているかどうかを検査し、 (6b) 登録されていれば、上記署名検証鍵情報に対応す
る合計使用金額YをY+y に更新し、 (6c) その更新された合計使用金額Y+y が上記額面Xを
越えないことを検査し、この検査が正しければ上記小売
店の銀行口座に金額yを振り込むように上記銀行に指示
し、 (6d) 更に、Y+y=X ならば、上記監視データベースから
上記署名検証鍵情報とそれに対応する合計使用金額Yを
削除し、 (6e) 上記検査の何れかでも合格でない場合は上記利用
者による不正支払いが行われたものとして、上記監視デ
ータベースから上記署名検証鍵情報とそれに対応する合
計使用金額Yを削除し、上記銀行に上記署名検証鍵情報
を送り、上記利用者データベースより不正利用者名を特
定する。4. The method according to claim 2 or 3, wherein said step (6) includes the following steps: (6a) The monitoring authority determines that the signature verification key information n obtained from the intercommunication data H is (6b) If it is registered, update the total usage amount Y corresponding to the signature verification key information to Y + y, and (6c) update the total usage amount. Check that the amount Y + y does not exceed the face value X, and if the check is correct, instruct the bank to transfer the amount y to the bank account of the retail store; (6d) Further, Y + y = X Then, the signature verification key information and the corresponding total usage amount Y are deleted from the monitoring database, and (6e) If any of the above inspections does not pass, it is assumed that the user has made unauthorized payment, The signature verification from the monitoring database The key information and the total usage amount Y corresponding thereto are deleted, the signature verification key information is sent to the bank, and the unauthorized user name is specified from the user database.
記ステップ(1) は上記利用者が変数値Rを生成して、上
記検証鍵NU と共に上記銀行及び上記監視機関に送るス
テップを含み、上記ステップ(2) は上記銀行が上記署名
検証鍵NU と上記変数値Rを含む情報を上記署名検証鍵
情報として記録するステップを含み、上記ステップ(3)
は上記監視機関が上記署名検証鍵NU と上記変数値Rを
含む情報で上記署名検証鍵情報として上記監視データベ
ースに登録するステップを含む。5. The method of claim 1, 2 or 3, wherein the step (1) comprises the step of the user generating a variable value R and sending it together with the verification key N U to the bank and the monitoring agency. The step (2) includes a step in which the bank records information including the signature verification key N U and the variable value R as the signature verification key information.
Includes a step in which the monitoring organization registers the information including the signature verification key N U and the variable value R as the signature verification key information in the monitoring database.
電子現金を発行する銀行と、電子現金を利用する利用者
と、電子現金の支払いを受ける小売店とより構成され、
上記監視機関は暗号関数ET を公開し、上記銀行は署名
検証関数VB を公開した電子現金システムの電子現金方
法において、以下のステップを含む: (1) 上記利用者は、銀行に利用者情報Uと電子現金の額
面に対応する金額Xを送信して銀行に金額Xを利用者の
口座から引き下ろすことを要請すると共に、上記額面X
と、上記署名検証鍵NU とを含む署名検証鍵情報を暗号
化して、暗号化情報ET を得て銀行に送り、 (2) 上記銀行は、上記利用者の口座から金額Xを減額
し、上記金額Xと上記暗号化情報ET を上記監視機関に
送付すると共に、上記暗号化情報ET を上記利用者情報
Uに対応させて署名検証鍵情報として利用者データベー
スに記録し、 (3) 上記監視機関は、上記暗号化情報ET を復号化して
署名検証鍵情報を得て、上記署名検証鍵情報と暗号化情
報ET の少なくともいずれか一方を監視データベースに
登録し、 (4) 上記利用者は、上記署名検証鍵情報と上記額面金額
Xに対するブラインド署名を銀行に要求し、上記額面金
額Xに対応した銀行の署名SB(n) を得て、 (5) 上記利用者は上記署名SB(n) と、上記額面Xと、上
記署名検証鍵NU とを含む情報を額面Xの電子現金Cと
して使って支払金額yを上記小売店に支払い、上記小売
店は上記電子現金の正当性を検証して受け取り、 (6) 上記小売店は上記電子現金Cの情報を含む上記利用
者との全交信データHを上記監視機関に送信して決済を
求め、 (7) 上記監視機関は受信した上記交信データH中の上記
電子現金Cの正当性を検証し、上記銀行に対し上記小売
店の口座に上記支払金額yを振り込むよう指示を与え
る。6. A monitoring organization for monitoring issuance of electronic cash,
It consists of a bank that issues e-cash, a user who uses e-cash, and a retailer that receives e-cash,
The monitoring agency publishes the cryptographic function E T and the bank publishes the signature verification function V B in the electronic cash method of the electronic cash system, which includes the following steps: (1) The user is provided to the bank by the user The information U and the amount X corresponding to the face value of the electronic cash are transmitted to request the bank to withdraw the amount X from the user's account.
And the signature verification key information including the signature verification key N U is encrypted to obtain the encrypted information E T and send it to the bank. (2) The bank reduces the amount X from the user's account. , the amount X and the encrypted information E T as well as sent to the monitoring agency, the encrypted information E T recorded in the user database as the signature verification key information in correspondence with said user information U, (3 The monitoring organization decrypts the encrypted information E T to obtain signature verification key information, and registers at least one of the signature verification key information and the encryption information E T in a monitoring database. The user requests the bank to perform a blind signature for the signature verification key information and the face value X, obtains a bank signature S B (n) corresponding to the face value X, and (5) information including the above signature S B (n), and the face value X, and the signature verification key n U The payment amount y is paid to the retail store using the electronic cash C of the face value X, and the retail store verifies and receives the validity of the electronic cash. (6) The retail store includes the information of the electronic cash C. (7) The monitoring organization verifies the validity of the electronic cash C in the received communication data H, and sends the data to the bank. An instruction is given to transfer the payment amount y to the account of the retail store.
(3) は上記監視機関が上記署名検証鍵情報と上記暗号化
情報ET の上記少なくとも一方を合計使用金額Yと対応
させて上記監視データベースに登録するステップを含
み、上記ステップ(4) は上記利用者が上記電子現金の残
額xを上記電子現金の情報に含めて上記小売店に送るス
テップを含む。7. The method of claim 6, wherein said steps are:
(3) comprises the step of the monitoring authority to register to the at least one of them in correspondence with the total use amount Y the monitoring database of said signature verification key information and the encrypted information E T, the step (4) above The user includes the electronic cash balance x in the electronic cash information and sends it to the retailer.
(4) は以下のステップを含む: (4a) 上記小売店は、任意の情報eを生成し、それを利
用者に送り、 (4b) 上記利用者は、支払金額yと、送られてきた上記
情報eとに対する利用者の署名SU(e,y)を生成し、上記
電子現金C={x,X,NU,SB(n)}と、{y,SU(e,y)}を小売店
に送付し、 (4c) 上記小売店は、上記銀行の署名SB(n) の正当性を
署名検証関数VB を用いて検証し、更に利用者署名S
U(e,y) の正当性を上記署名検証鍵NU を用いて検証
し、いずれの検証も正しければ、該当支払金額yの電子
現金による支払いを認める。8. The method of claim 7, wherein said steps are:
(4) includes the following steps: (4a) The retailer generates arbitrary information e and sends it to the user, and (4b) the user receives the payment amount y and receives the information. A signature S U (e, y) of the user for the information e is generated, and the electronic cash C = {x, X, N U , S B (n)} and {y, S U (e, y) )} To the retail store. (4c) The retail store verifies the validity of the bank signature S B (n) using the signature verification function V B , and furthermore, the user signature S B
The validity of U (e, y) is verified using the signature verification key N U , and if all verifications are correct, payment of the corresponding payment amount y by electronic cash is permitted.
テップ(7) は以下のステップを含む: (7a) 上記監視機関は、上記相互通信データHより得ら
れる上記署名検証鍵情報及び上記暗号化情報ET の上記
いずれか一方が上記監視データベースに登録されている
かどうかを検査し、 (7b) 登録されていれば、上記署名検証鍵情報及び上記
暗号化情報ET の上記少なくとも一方に対応する合計使
用金額YをY+y に更新し、 (7c) その更新された合計使用金額Y+y が上記額面Xを
越えないことを検査し、この検査が正しければ上記小売
店の銀行口座に金額yを振り込むように上記銀行に指示
し、 (7d) 更に、Y+y=X ならば、上記監視データベースから
上記署名検証鍵情報及び上記暗号化情報ET の上記少な
くとも一方とそれに対応する合計使用金額Yを削除し、 (7e) 上記検査の何れかでも合格でない場合は上記利用
者による不正支払いが行われたものとして、上記監視デ
ータベースから上記署名検証鍵情報及び上記暗号化ET
の上記少なくとも一方とそれに対応する合計使用金額Y
を削除し、上記銀行に上記署名検証鍵情報n及び上記暗
号化情報ET の上記少なくとも一方を送り、上記利用者
データベースより不正利用者名を特定する。9. The method according to claim 7, wherein the step (7) includes the following steps: (7a) The monitoring authority sends the signature verification key information and the encryption code obtained from the intercommunication data H. of the one of the information E T examines whether it is registered in the monitoring database, (7b) if it is registered, corresponding to the at least one of the signature verification key information and the encrypted information E T (7c) Inspect that the updated total usage amount Y + y does not exceed the above-mentioned face value X, and if this inspection is correct, enter the retail store bank account. instructs the bank to transfer money amounts y, (7d) further, if Y + y = X, said at least one and the sum of its corresponding said signature verification key information and the encrypted information E T from the monitoring database Delete usage amount Y, (7e) If any of the above inspections do not pass, it is assumed that the user has made an unauthorized payment, and the signature verification key information and the encrypted E T
At least one of the above and the total usage amount Y corresponding thereto
Remove the, the signature verification key information n and sends the above-mentioned at least one of the encrypted information E T to the bank, to identify the unauthorized user name from the user database.
署名検証鍵情報は上記額面Xと上記署名検証鍵NU との
組で構成する。10. The method according to claim 4, wherein the signature verification key information comprises a pair of the face value X and the signature verification key N U.
法において、上記ステップ(1) は上記利用者が上記検証
鍵NU を生成するステップを含む。11. The method of claim 1, 2, 3, 6, 7 or 8, wherein said step (1) comprises the step of said user generating said verification key N U.
上記ステップ(1) は上記利用者が変数値Rを生成し、上
記検証鍵NU と上記変数値Rを含む情報を上記署名検証
鍵情報とするステップを含む。12. The method of claim 6, 7, or 8,
The step (1) includes a step in which the user generates a variable value R and uses information including the verification key N U and the variable value R as the signature verification key information.
法において、上記監視機関は上記利用者のための上記署
名検証鍵NU を生成し、上記利用者に送るステップを含
む。13. The method of claim 1, 2, 3, 6, 7, or 8, including the step of the monitoring authority generating and sending the signature verification key N U for the user to the user. .
法において、上記署名検証鍵情報は上記額面Xと上記署
名検証鍵NU の組を予め決めた一方向ハッシュ関数hに
より処理をして得る。14. The method of claim 1, 2, 3, 6, 7, or 8, wherein the signature verification key information is a combination of the face value X and the signature verification key N U by a predetermined one-way hash function h. Get by processing.
と、電子現金を発行する銀行と、電子現金を利用する利
用者と、電子現金により支払を受ける小売店とより構成
された電子現金システムを実行する利用者装置であり、 利用者署名用鍵SKU を生成する鍵生成手段と、 金額Xと署名検証鍵NU とに対する銀行の署名SB(NU)
と、残額xと、額面Xと,署名検証鍵NU とを含む電子
現金Cと、上記署名用鍵SKU とを保持するメモリ手段
と、 支払金額yと上記小売店から受信した任意の情報eとに
対する署名を上記署名用鍵SKU を使って行い、署名S
U(e,y) を生成する署名生成手段と、 上記残額xから支払金額yを減算して残額を更新する残
額更新手段と、を含む。15. An electronic cash system comprising a monitoring organization for monitoring issuance of electronic cash, a bank for issuing electronic cash, a user using electronic cash, and a retail store receiving payment by electronic cash. a user device that executes, user and key generating means for generating a signature key SK U, the amount X and the signature verification key N signature bank for the U S B (N U)
An electronic cash C including a balance x, a face value X, a signature verification key N U, and a memory for holding the signature key SK U ; a payment amount y and any information received from the retail store e is signed using the signature key SK U , and the signature S
Signature generating means for generating U (e, y); and balance updating means for updating the balance by subtracting the payment amount y from the balance x.
と、電子現金を発行する銀行と、電子現金を利用する利
用者と、電子現金の支払いを受ける小売店とより構成さ
れた電子現金システムを実施する監視機関装置であり、 発行された電子現金を所有する利用者に対応する署名検
証鍵情報を合計使用金額Yと対応させて登録する監視デ
ータベースと、 小売店から受信した残金x、額面X、署名検証鍵NU 、
銀行の署名SB(X,NU)を含む電子現金Cと、支払金額yと
を含む履歴データHを保持する履歴データベースと、 上記履歴データH中の金額Xと検証鍵NU に対応する署
名検証鍵情報が上記監視データベースに登録されている
か検索し、登録されていなければ不正使用された電子現
金であると判定する手段と、 上記署名検証鍵情報が登録されている場合、上記履歴デ
ータH中の支払金額yを上記監視データベース中の対応
する合計使用金額Yに加算する加算手段と、 上記加算手段による加算結果Y+y を額面Xと比較する比
較手段と、 上記比較手段による比較結果がY+y<X であれば上記監視
データベース中の対応する合計使用金額Yを上記加算結
果Y+y で更新し、Y+y=X であれば上記監視データベース
中の対応する署名検証鍵情報と合計使用金額Yを削除
し、Y+y>X であれば不正使用された電子現金であると判
定して上記署名検証鍵情報及び上記合計使用金額Yを削
除すると共に、その署名検証鍵情報を上記銀行に通知す
る制御手段、とを含む。16. An electronic cash system comprising a monitoring organization for monitoring issuance of electronic cash, a bank for issuing electronic cash, a user using electronic cash, and a retailer receiving payment of electronic cash. A monitoring database that registers the signature verification key information corresponding to the user who owns the issued electronic cash in association with the total usage amount Y; a balance x received from the retail store; , The signature verification key N U ,
A history database that stores history data H including a bank signature S B (X, N U ) and a payment amount y, corresponding to the amount X and the verification key N U in the history data H Means for retrieving whether the signature verification key information is registered in the monitoring database and, if not registered, determining that the electronic cash is fraudulently used; and, if the signature verification key information is registered, the history data Adding means for adding the payment amount y in H to the corresponding total usage amount Y in the monitoring database; comparing means for comparing the addition result Y + y by the adding means with the face value X; If Y + y <X, the corresponding total usage amount Y in the monitoring database is updated with the addition result Y + y. If Y + y = X, the corresponding signature verification key information in the monitoring database is updated. And the total usage amount Y If Y + y> X, it is determined that the electronic cash is fraudulently used, and the signature verification key information and the total usage amount Y are deleted, and the signature verification key information is notified to the bank. Means.
と、電子現金を発行する銀行と、電子現金を利用する利
用者と、電子現金により支払を受ける小売店とより構成
された電子現金システムを実行する利用者装置であり、 利用者署名用鍵SKU 及び署名検証鍵NU を生成する鍵生
成手段と、 監視機関の公開暗号鍵PKT を使って上記金額Xと上記署
名検証鍵NU を暗号化して暗号化情報ET を生成し、銀
行に与える暗号化手段と、 上記署名検証鍵NU に対しブラインド署名前処理を行っ
て上記銀行に与えるブラインド署名前処理手段と、 上記銀行から受信した上記署名検証鍵に対するブライン
ド署名Z(NU) を処理して上記銀行の署名SB(NU)を得るブ
ラインド署名後処理手段と、 上記残額x、額面X、署名検証鍵NU 及び署名SB(NU)を
含む電子現金Cと、上記利用者署名用鍵SKU と上記監視
機関の公開暗号鍵PKT とを保持するメモリ手段と、 支払金額yと上記小売店から受信した任意の情報eとに
対する署名を上記署名用鍵SKU を使って行い、署名S
U(e,y) を生成する署名生成手段と、 上記残額xから支払金額yを減算して残額を更新する残
額更新手段、とを含む。17. An electronic cash system comprising a monitoring organization for monitoring issuance of electronic cash, a bank for issuing electronic cash, a user using electronic cash, and a retailer receiving payment by electronic cash. a user device to be executed, the user and the signature key SK U and the signature verification key N key generating means for generating a U, the amount of money X and said signature verification key using the public encryption key PK T of monitoring bodies N U Means for generating encrypted information E T by encrypting the signature verification key N U and providing it to the bank; blind signature pre-processing means for performing the blind signature pre-processing on the signature verification key N U and providing it to the bank; Blind signature post-processing means for processing the received blind signature Z (N U ) for the signature verification key to obtain the bank's signature S B (N U ); and the balance x, face X, signature verification key N U and Electronic cash C including signature S B (N U ) A memory for holding the user signature key SK U and the public encryption key PK T of the monitoring organization; and a signature for the payment amount y and any information e received from the retail store. Done with U and signed S
Signature generating means for generating U (e, y); and balance updating means for updating the balance by subtracting the payment amount y from the balance x.
と、電子現金を発行する銀行と、電子現金を利用する利
用者と、電子現金の支払いを受ける小売店とより構成さ
れ、上記監視機関は暗号関数ET を公開し、上記銀行は
署名検証関数V B を公開した電子現金システムを実施す
る監視機関装置であり、 公開暗号関数ET を複合するための秘密複合鍵SKT を保
持するメモリと、 上記利用者が生成した署名検証鍵を含む署名検証鍵情報
に対する暗号化情報E T(n) を、上記秘密複合鍵SKT を
使って復号して署名検証鍵情報を得る復号手段と、 復号された上記署名検証鍵情報とそれに対応する合計使
用金額Yとを登録する監視データベースと、 小売店から受信した残金x、額面X、署名検証鍵NU 、
銀行の署名SB(NU)を含む電子現金Cと、支払金額yとを
含む履歴データHを保持する履歴データベースと、 上記履歴データH中の金額Xと検証鍵NU に対応する署
名検証鍵情報が上記監視データベースに登録されている
か検索し、登録されていなければ不正使用された電子現
金であると判定する手段と、 上記署名検証鍵情報が登録されている場合、上記履歴デ
ータH中の支払金額yを上記監視データベース中の対応
する合計使用金額Yに加算する加算手段と、 上記加算手段による加算結果Y+y を額面Xと比較する比
較手段と、 上記比較手段による比較結果がY+y<X であれば上記監視
データベース中の対応する合計使用金額Yを上記加算結
果Y+y で更新し、Y+y=X であれば上記監視データベース
中の対応する署名検証鍵情報と合計使用金額Yを削除
し、Y+y>X であれば不正使用された電子現金であると判
定して上記署名検証鍵情報及び合計使用金額Yを削除す
ると共に、その署名検証鍵情報を上記銀行に通知する制
御手段、とを含む。18. A monitoring organization for monitoring issuance of electronic cash
And a bank that issues e-cash
Users and retailers receiving electronic cash payments.
The surveillance authority has a cryptographic function ET And the above bank
Signature verification function V B Implement an electronic cash system that has released
Public cryptographic function ET Secret key SK for decryptingT Keep
Memory and the signature verification key information including the signature verification key generated by the user
Information E for T(n) with the secret composite key SKT To
Decryption means for obtaining the signature verification key information by decryption using the signature verification key information,
A monitoring database for registering the amount of money Y, the balance x received from the retail store, the face value X, and the signature verification key NU,
Bank Signature SB(NU) And the payment amount y
A history database holding history data H including the amount of money X and a verification key N in the history data H.UThe station corresponding to
Name verification key information is registered in the monitoring database
Search, and if not registered, the unauthorized electronic
Means for determining that the data is gold, and if the signature verification key information is registered, the history data
The payment amount y in the data H in the monitoring database
An adding means for adding to the total usage amount Y to be added, and a ratio for comparing the addition result Y + y by the adding means with the face value X.
If the result of comparison by the comparing means and the comparing means is Y + y <X, the monitoring is performed.
Add the corresponding total usage amount Y in the database to the above
Update with Y + y, and if Y + y = X, the above monitoring database
Delete the corresponding signature verification key information and total usage amount Y in
If Y + y> X, it is determined that the electronic cash is fraudulently used.
And delete the signature verification key information and total usage amount Y
And notify the above-mentioned bank of the signature verification key information.
Control means.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP12584297A JP3329438B2 (en) | 1996-05-16 | 1997-05-15 | Electronic cash method with monitoring institution, user apparatus and monitoring institution apparatus for implementing the method |
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP12168896 | 1996-05-16 | ||
| JP8-121688 | 1996-05-16 | ||
| JP12584297A JP3329438B2 (en) | 1996-05-16 | 1997-05-15 | Electronic cash method with monitoring institution, user apparatus and monitoring institution apparatus for implementing the method |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| JPH1083426A true JPH1083426A (en) | 1998-03-31 |
| JP3329438B2 JP3329438B2 (en) | 2002-09-30 |
Family
ID=26458981
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP12584297A Expired - Fee Related JP3329438B2 (en) | 1996-05-16 | 1997-05-15 | Electronic cash method with monitoring institution, user apparatus and monitoring institution apparatus for implementing the method |
Country Status (1)
| Country | Link |
|---|---|
| JP (1) | JP3329438B2 (en) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2016502703A (en) * | 2012-10-25 | 2016-01-28 | ジエマルト・エス・アー | System and method for securely storing and transferring electronic money |
| CN111105224A (en) * | 2019-11-13 | 2020-05-05 | 泰康保险集团股份有限公司 | Payment feedback information processing method and device, electronic equipment and storage medium |
| CN116057555A (en) * | 2020-07-08 | 2023-05-02 | 德国捷德进步52有限公司 | Payment system, coin register, participant unit, transaction register, supervisory register and method for payment with electronic coin data set |
-
1997
- 1997-05-15 JP JP12584297A patent/JP3329438B2/en not_active Expired - Fee Related
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2016502703A (en) * | 2012-10-25 | 2016-01-28 | ジエマルト・エス・アー | System and method for securely storing and transferring electronic money |
| CN111105224A (en) * | 2019-11-13 | 2020-05-05 | 泰康保险集团股份有限公司 | Payment feedback information processing method and device, electronic equipment and storage medium |
| CN116057555A (en) * | 2020-07-08 | 2023-05-02 | 德国捷德进步52有限公司 | Payment system, coin register, participant unit, transaction register, supervisory register and method for payment with electronic coin data set |
Also Published As
| Publication number | Publication date |
|---|---|
| JP3329438B2 (en) | 2002-09-30 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP3329432B2 (en) | Hierarchical electronic cash execution method and apparatus used therefor | |
| US6003765A (en) | Electronic cash implementing method with a surveillance institution, and user apparatus and surveillance institution apparatus for implementing the same | |
| JP3802074B2 (en) | Transaction method with portable identification elements | |
| US7184986B2 (en) | Content transaction system and method, and program providing medium therefor | |
| EP0047285B1 (en) | A system for authenticating users and devices in on-line transaction networks | |
| US7028191B2 (en) | Trusted authorization device | |
| US6766306B1 (en) | Electronic cash system | |
| US7099479B1 (en) | Information transmission system, transmitter, and transmission method as well as information reception system, receiver and reception method | |
| CA2184786C (en) | Accounting apparatus, information receiving apparatus, and communication system | |
| CN111062717B (en) | Data transfer processing method, device and computer readable storage medium | |
| US20010044786A1 (en) | Content usage management system and method, and program providing medium therefor | |
| US20030070080A1 (en) | Electronic-monetary system | |
| EP0848343A2 (en) | Shopping system | |
| JP3659090B2 (en) | Electronic information distribution system, storage medium storing electronic information distribution program, and electronic information distribution method | |
| KR20030078485A (en) | Publication and settlement of account for an electronic check | |
| JP3329438B2 (en) | Electronic cash method with monitoring institution, user apparatus and monitoring institution apparatus for implementing the method | |
| JP3641909B2 (en) | Proof data generator | |
| EP0886248B1 (en) | Method and apparatus for registration of information with plural institutions and recording medium with registration program stored thereon | |
| JP3396638B2 (en) | Electronic cash method using user signature, device and recording medium | |
| KR100261743B1 (en) | Hierarchical Electronic Cash Realization Method and Device | |
| JP3747008B2 (en) | Pre-registration type electronic payment system and pre-registration type electronic payment program | |
| JP3329431B2 (en) | Electronic cash implementation method with a trust institution | |
| JP3466478B2 (en) | Registration method for a plurality of institutions, its device and its program recording medium | |
| JPH11110464A (en) | Processing system and method for issuing, transferring, certifying and erasing electronic securities | |
| KR20180044149A (en) | Device and method to manage gift certificate |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20080719 Year of fee payment: 6 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20080719 Year of fee payment: 6 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20090719 Year of fee payment: 7 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20090719 Year of fee payment: 7 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20100719 Year of fee payment: 8 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20100719 Year of fee payment: 8 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20110719 Year of fee payment: 9 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20120719 Year of fee payment: 10 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20130719 Year of fee payment: 11 |
|
| LAPS | Cancellation because of no payment of annual fees |