JPH11110464A - Processing system and method for issuing, transferring, certifying and erasing electronic securities - Google Patents

Processing system and method for issuing, transferring, certifying and erasing electronic securities

Info

Publication number
JPH11110464A
JPH11110464A JP27177097A JP27177097A JPH11110464A JP H11110464 A JPH11110464 A JP H11110464A JP 27177097 A JP27177097 A JP 27177097A JP 27177097 A JP27177097 A JP 27177097A JP H11110464 A JPH11110464 A JP H11110464A
Authority
JP
Japan
Prior art keywords
electronic
security
electronic securities
securities
issuer
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
JP27177097A
Other languages
Japanese (ja)
Other versions
JP3428876B2 (en
Inventor
Rei Otsuka
塚 玲 大
Hideaki Onuki
貫 秀 明 大
Mitsuhiro Sugaya
谷 光 啓 菅
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Nomura Research Institute Ltd
Original Assignee
Nomura Research Institute Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nomura Research Institute Ltd filed Critical Nomura Research Institute Ltd
Priority to JP27177097A priority Critical patent/JP3428876B2/en
Publication of JPH11110464A publication Critical patent/JPH11110464A/en
Application granted granted Critical
Publication of JP3428876B2 publication Critical patent/JP3428876B2/en
Anticipated expiration legal-status Critical
Expired - Lifetime legal-status Critical Current

Links

Landscapes

  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

(57)【要約】 【課題】 電子証券の発行、移転、証明、消去の諸手続
で、各手続の正当性を保証する処理システム及びその処
理方法を提供する。 【解決手段】 発行者oの処理装置と、利用者の処理装
置と、中立機関Tの処理装置とからなり、電子証券の発
行手続において、中立機関Tの処理装置は、デジタル証
明書Cを生成し、発行者oの処理装置は、前記デジタル
証明書Cと権利義務関係の記述Dの暗号化データを含む
電子証券権利部S0と、証券番号を秘匿したブラインド
署名用データBを生成し、中立機関Tの処理装置は、ブ
ラインド署名用データBをデジタル署名してブラインド
署名済データB’を生成し、発行者oの処理装置は、ブ
ラインド署名済データをアンブラインド処理してデジタ
ル署名済証券番号を取得し、これを含む電子証券識別部
と電子証券識別部とを組み合わせて電子証券の発行手続
を完了する。
(57) [Summary] [PROBLEMS] To provide a processing system and a processing method for guaranteeing the legitimacy of each procedure in various procedures for issuing, transferring, certifying, and erasing electronic securities. SOLUTION: A processing device of an issuer o, a processing device of a user, and a processing device of a neutral institution T, a processing device of the neutral institution T generates a digital certificate C in an electronic securities issuance procedure. and, processor issuer o is said digital certificate C and rights and obligations ECN right portion S 0 containing encrypted data description D relationship, to generate a blind signature data B that concealed certificate number, The processing unit of the neutral institution T digitally signs the data B for blind signature to generate blind-signed data B ′, and the processing unit of the issuer o performs unblind processing on the blind-signed data to obtain a digitally signed security. A number is obtained, and the electronic securities identification unit including the number and the electronic securities identification unit are combined to complete the electronic securities issuing procedure.

Description

【発明の詳細な説明】DETAILED DESCRIPTION OF THE INVENTION

【0001】[0001]

【発明の属する技術分野】本発明は、自由に権利義務関
係を記述でき、同一の権利義務関係を有するものを多数
発行する種類の電子証券の発行、移転、証明、消去のた
めの処理システム及びその処理方法に関する。
BACKGROUND OF THE INVENTION 1. Field of the Invention The present invention relates to a processing system for issuing, transferring, certifying, and erasing electronic securities of a type in which rights and obligations can be freely described and a number of electronic securities having the same rights and obligations are issued. It relates to the processing method.

【0002】[0002]

【従来の技術】最近のコンピュータとその通信ネットワ
ークの発達により、通信ネットワーク上で商品の取引を
行い、デジタルデータを金銭としてやり取りすることが
行われるようになった。この金銭としてやり取りされる
デジタルデータはいわゆる電子マネーと呼ばれるもので
あって、世界中どこでも瞬時に移動可能である利点を有
し、遠隔地への支払いのコストと時間がかからず、今後
ますます利用の要求が高まりつつある。一方、電子マネ
ーは、それ自体はデジタルデータであるため、移転を物
理的に制限することができず、また、簡単にコピーする
ことができる特質を有している。このため、一つの電子
マネーが唯一であること、すなわち二重に使用されてい
ないこと、及び金銭として銀行がその価値を認める正当
なデータであることを検証する技術が必要となる。
2. Description of the Related Art With the recent development of computers and their communication networks, trading of goods and exchange of digital data as money have been performed on the communication networks. This digital data exchanged as money is what is called electronic money, has the advantage that it can be moved instantly anywhere in the world, and does not require the cost and time of payment to remote places, so it will be increasingly in the future The demand for usage is increasing. On the other hand, electronic money itself is digital data, and therefore cannot be physically restricted from being transferred, and has characteristics of being easily copied. For this reason, a technique for verifying that one electronic money is unique, that is, that it is not used twice, and that it is legitimate data that the bank recognizes as money, is required.

【0003】現在、電子マネーのデータの正当性を検証
するために、ICカード等のハードウェアを一部利用す
る方式と、全くのデジタルデータとしてソフトウェア上
でやり取りする方式とが採用されている。ICカード等
のハードウェアを利用する方式は、ICカードについて
改良を重ね、データの改竄または漏洩が困難なものに
し、そのICカードをあたかも財布のように用いて電子
マネーをデータとして蓄え、支払いに応じてICカード
から残高を減らす方式である。イギリスのNational Wes
t Minster 銀行とMidland 銀行が進めているMonex シス
テムはその例である。この場合、電子マネーの不正な改
竄・コピーの防止はハードウェアの信頼性によるところ
が大きい。
At present, in order to verify the validity of electronic money data, a method of partially using hardware such as an IC card and a method of exchanging pure digital data on software are adopted. The method of using hardware such as an IC card makes continuous improvements to the IC card to make it difficult for data to be tampered or leaked, and stores the electronic money as data using the IC card as if it were a wallet. In this method, the balance is reduced from the IC card in response. British National Wes
t The Monex system being promoted by Minster Bank and Midland Bank is an example. In this case, prevention of unauthorized tampering / copying of electronic money largely depends on hardware reliability.

【0004】一方、全くのデジタルデータとしてソフト
ウェア上でやり取りする方式は、コンピュータネットワ
ークの存在を前提とし、そのコンピュータネットワーク
に接続されたパーソナルコンピュータ間でデジタルデー
タである電子マネーをやり取りすることで決済を行う方
式である。Digi Cash社が進めているDigi Cash方式はそ
の例である。この方式は、上記ICカードを一部利用す
る方式に比べて、既存のコンピュータネットワークを利
用して、簡単に全世界的に展開することができる利点を
有しているが、データの不正な改竄・ コピーの防止はデ
ータの検証技術によらなければならない。
[0004] On the other hand, the method of exchanging pure digital data on software presupposes the existence of a computer network, and exchanges electronic money, which is digital data, between personal computers connected to the computer network for settlement. It is a method to perform. The Digi Cash system being promoted by Digi Cash is an example. This method has the advantage that it can be easily deployed worldwide using an existing computer network, as compared with the method using a part of the IC card.・ The prevention of copying must be based on data verification technology.

【0005】本願発明の電子証券は、上記ソフトウェア
上でデジタルデータをやり取りする方式であり、コンピ
ュータ上でデジタルデータのやり取りをすることによっ
て従来市場で行われていた有価証券の発行、移転、証
明、消去等の諸手続を実現するものである。そのため、
ソフトウェアによってデジタルデータを検証する点Digi
Cash方式に関係する。以下そのDigi Cash方式について
説明する。
[0005] The electronic securities of the present invention is a system for exchanging digital data on the above-mentioned software. It implements various procedures such as erasure. for that reason,
Verification of digital data by software Digi
Related to Cash method. Hereinafter, the Digi Cash method will be described.

【0006】図7は、Digi Cash 方式による電子マネー
の発行から決済の流れを示している。図中の番号は、処
理の順番を示している。
FIG. 7 shows a flow from the issue of electronic money to the settlement by the Digi Cash method. The numbers in the figure indicate the order of processing.

【0007】図7において、最初に銀行に口座を有する
消費者は、銀行に対してその口座から引き出したい金銭
の額と、身元の証明(IDカード等)を送り、銀行は電
子マネーの流通性を維持するため個々の電子マネーの内
容を知らずに電子マネーのデータにブラインド署名す
る。ブラインド署名の後、電子マネーは消費者に渡され
る。
In FIG. 7, a consumer who first has an account in a bank sends the amount of money to be withdrawn from the account and a proof of identity (such as an ID card) to the bank. In order to maintain the electronic money data blindly without knowing the contents of each electronic money. After the blind signature, the electronic money is given to the consumer.

【0008】ブラインド署名の技術は米国特許4,75
9,063号に開示されている技術を使用する。ブライ
ンド署名の目的は、どの消費者に対して発行した電子マ
ネーであることを後に確認することができないようにし
たまま、銀行が発行した電子マネーを保証するものであ
る。これにより、どの消費者がどんな商品を購入したか
等の情報を遡行するができなくなり、個人の取引のプラ
イバシーを維持することができる。
The technique of blind signature is disclosed in US Pat.
The technique disclosed in No. 9,063 is used. The purpose of the blind signature is to guarantee the electronic money issued by the bank without being able to later confirm to which consumer the electronic money was issued. This makes it impossible to trace information such as which consumer purchased which product and so on, thereby maintaining the privacy of individual transactions.

【0009】次に、電子マネーは消費者によって同一銀
行に口座を所有する店舗に支払われたとする。電子マネ
ーを受け取った店舗は、商品の引き渡し前に銀行に対し
て電子マネーの検査を依頼する。
Next, it is assumed that the electronic money has been paid by the consumer to a store having an account at the same bank. The store that has received the electronic money requests the bank to inspect the electronic money before delivering the product.

【0010】銀行は、その電子マネーが確かに自分が発
行したものであること、二重に使用されていないことを
検証する。その結果、電子マネーが正当なものである場
合には、店舗の口座にその電子マネーの金額を振り込
み、電子マネーが正当であることを店舗に知らせる。
[0010] The bank verifies that the electronic money is indeed issued by itself and that it is not used twice. As a result, when the electronic money is legitimate, the amount of the electronic money is transferred to the store account, and the store is notified that the electronic money is legitimate.

【0011】上記銀行からの知らせにより、店舗は商品
を消費者に引き渡す。
[0011] Upon notification from the bank, the store delivers the product to the consumer.

【0012】以上が、電子マネーの流通・処理の流れで
あるが、ブラインド署名、電子マネーの正当性の検証等
の要素技術は本発明でも使用するものであるので、本願
発明の実施態様の説明のところで説明することにする。
The flow of distribution and processing of electronic money has been described above. Since element technologies such as blind signature and verification of validity of electronic money are also used in the present invention, an embodiment of the present invention will be described. I will explain at the point.

【0013】[0013]

【発明が解決しようとする課題】しかしながら、上記Di
gi Cash方式等による電子マネーでは、発行、移転、証
明、消去手続を行う電子証券として機能することができ
なかった。具体的な問題点は以下の通りである。
However, the above Di
GiCash-based electronic money could not function as an electronic security that issued, transferred, certified, and erased. The specific problems are as follows.

【0014】 電子マネーを発行するのが銀行に限ら
れていた。電子マネーは、利用者が要求した額、あるい
は予め決められた幾つかの種類の額面の電子マネーを銀
行が発行するのみであった。これに対し、電子証券は財
産上の権利・ 義務を記載したものであり、複数の発行者
が発行でき、かつ、各発行者が比較的複雑な内容の権利
と義務を自由に記載できるようにしなければならない。
つまり、電子証券では、電子証券を所持する者の権利
(多くは金銭を要求することができる権利)と、発行者
がその電子証券を所持する者に対して果たすべき義務
(多くは金銭の支払い義務)とを、商取引の場で多数の
発行者が発行できるようにしなければならないが、従来
の電子マネーでは、複数の者による電子証券の発行と、
発行者の自由な権利・義務の記載をすることができなか
った。
The issue of electronic money has been limited to banks. With regard to electronic money, banks have only issued the amount requested by the user or several types of predetermined face value electronic money. Electronic securities, on the other hand, describe the rights and obligations of the property.They can be issued by multiple issuers, and each issuer can freely describe their rights and obligations with relatively complicated content. There must be.
In other words, in electronic securities, the rights of the person holding the electronic securities (mostly the right to request money) and the obligations that the issuer should fulfill to the person holding the electronic securities (often payment of money) Obligations) must be made available to a large number of issuers in the context of commercial transactions.
The issuer's free rights and obligations could not be stated.

【0015】 電子マネーは、正当な所有者であるこ
とを主張することができなかった。有価証券では、たと
えば株式証券のように自分が正当な所有者であることを
証明し、発行者に配当金の支払いを請求する必要があ
る。電子証券でも、電子証券のデータを所有する者が正
当な所有者であることを証明できるようにしなければな
らない。
[0015] Electronic money could not be claimed to be a legitimate owner. In securities, it is necessary to prove that the user is a legitimate owner, as in the case of stock securities, for example, and to request the issuer to pay a dividend. Electronic securities must also be able to prove that the person who owns the data of the electronic securities is the legitimate owner.

【0016】これに対して、従来の電子マネーでは、移
転の手続によってしか所有者であることを示すことがで
きず、移転行為を伴わずに自分が唯一正当な所有者であ
ることを証明することができなかった。
On the other hand, in the conventional electronic money, it is possible to show that the owner is the owner only by the transfer procedure, and to prove that he / she is the only valid owner without any transfer action. I couldn't do that.

【0017】そこで、本発明の目的は、有価証券の発
行、移転、証明、消去の諸手続をソフトウェア上で実現
する「電子証券の発行、移転、証明、消去のための処理
システム及びその処理方法」を提供することにある。
Therefore, an object of the present invention is to provide a processing system for issuing, transferring, certifying, and erasing electronic securities and a processing method for realizing various procedures for issuing, transferring, certifying, and erasing securities. It is to provide.

【0018】[0018]

【課題を解決するための手段】本願請求項1に係る電子
証券の発行、移転、証明、消去のための処理システム
は、発行者の処理装置と、利用者の処理装置と、中立機
関の処理装置とからなる電子証券の発行、移転、証明、
消去のための処理システムであって、電子証券の発行手
続において、前記中立機関の処理装置は、中立機関のみ
がデジタル署名し得るデジタル証明書を生成し、前記発
行者の処理装置は、発行者のみがデジタル署名し得る前
記デジタル証明書と権利義務関係の記述の暗号化データ
を含む電子証券権利部を生成する一方、証券番号を生成
し、前記証券番号を秘匿したブラインド署名用データを
生成し、前記中立機関の処理装置は、前記デジタル証明
書と前記ブラインド署名用データとを入力し、前記デジ
タル証明書をデジタル署名したのと同一の秘密鍵により
前記ブラインド署名用データをデジタル署名することに
より、中立機関のみがデジタル署名し得るブラインド署
名済データを生成し、前記発行者の処理装置は、前記ブ
ラインド署名済データを入力し、アンブラインド処理し
て中立機関のみがデジタル署名し得るデジタル署名済証
券番号を取得し、この中立機関によるデジタル署名済証
券番号を含む電子証券識別部を生成し、前記電子証券権
利部と電子証券識別部とを組み合わせて電子証券の発行
手続を完了することを特徴とするものである。
A processing system for issuing, transferring, certifying, and erasing electronic securities according to claim 1 of the present application comprises a processing unit of an issuer, a processing unit of a user, and a processing unit of a neutral organization. Issuance, transfer, certification,
A processing system for erasure, wherein in a procedure for issuing electronic securities, the processing device of the neutral institution generates a digital certificate that can be digitally signed only by the neutral institution, and the processing device of the issuer includes: Only the digital certificate that can be digitally signed and the electronic securities right part including the encrypted data of the description of the rights and obligations relationship are generated, while the security number is generated, and the blind signature data that conceals the security number is generated. The processing device of the neutral institution inputs the digital certificate and the blind signature data, and digitally signs the blind signature data with the same private key as the digital signature of the digital certificate. Generating blind-signed data that can be digitally signed only by a neutral institution, and wherein the processing device of the issuer generates the blind-signed data. And inputting a digitally signed security number that can be digitally signed only by the neutral institution by performing an unblind process, generating an electronic securities identification unit including the digitally signed security number by the neutral institution, The electronic securities issuing section is completed by combining the electronic securities identification section and the electronic securities identification section.

【0019】本願請求項2に係る電子証券の発行、移
転、証明、消去のための処理システムは、請求項1の処
理システムにおいて、前記発行者の装置が生成する証券
番号は、下式の関係を満たす3つの乱数a,b,cと発
行者の特定番号idによって計算されるものであること
を特徴とするものである。
The processing system for issuing, transferring, certifying, and erasing electronic securities according to claim 2 of the present invention is the processing system according to claim 1, wherein the security number generated by the issuer's device has the following relationship: Is calculated using three random numbers a, b, and c satisfying the following and the issuer's specific number id.

【0020】x=f(y,z) y=f(a,b) z=f(id,c) ここで、x:証券番号 f():f(x,y)=f(x′,y′)なるx≠
x′,y≠y′を見つけることが困難な一方向性ハッシ
ュ関数 本願請求項3に係る電子証券の発行、移転、証明、消去
のための処理システムは、発行者の処理装置と、利用者
の処理装置と、中立機関の処理装置とからなる電子証券
の発行、移転、証明、消去のための処理システムであっ
て、電子証券の発行手続において、前記中立機関の処理
装置は、発行者の要求に応じて電子証券ごとにRSA系
の鍵nT,eT,pT,qT,dTを生成し、その公開鍵の
nT,eTを秘密鍵dTによってデジタル署名したデジタ
ル証明書Cを生成し、ここで、 C=<nT,eT,h(nT|eT)dp mod np> < >はその内側のデータの集合 nT,eT は権利義務内容に対応する証券固有の公開鍵 dp,np は 中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)を秘密鍵dpによ
ってデジタル署名したデータ mod npはnpを法(modulus)とすることを示す 前記発行者の処理装置は、前記デジタル証明書Cと電子
証券の権利義務を記述した記述Dとを入力し、電子証券
の権利部S0を出力し、ここで、 S0=<C,D,h(C|D)do mod no> doは発行者の秘密鍵 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)を秘密鍵doによってデ
ジタル署名したデータ mod noはnoを法(modulus)とすることを示す 前記中立機関の処理装置は、前記デジタル証明書Cと電
子証券権利部S0とを入力し、電子証券発行記録データ
ベースで前記デジタル証明書Cを検索し、そのデジタル
証明書Cが他の電子証券に使用されていないことを条件
に前記デジタル証明書Cと電子証券の権利部S0を組と
して前記電子証券発行記録データベースに登録し、前記
発行者の処理装置は、証券番号乱数a,b,c(0<
a,b,c<2t、tは2進数の所定の桁数)と、ブラ
インド係数r(0<r<2t、tは2進数の所定の桁
数)とをランダムに生成し、発行者の特定番号idを用
いて証券番号xを算出し、続いて前記証券番号xを前記
ブラインド係数rによって秘匿したブラインド署名用デ
ータBを算出し、ここで、 x=f(y,z) y=f(a,b) z=f(id,c) f( )はf(x,y)=f(x′,y′)なるx≠
x′,y≠y′を見つけることが困難な一方向性ハッシ
ュ関数を示し、 B=reTh(x) modnT h(x)はxを変数とするハッシュ関数 mod nTはnTを法(modulus)とすることを示す 前記中立機関の処理装置は、前記ブラインド署名用デー
タBと前記デジタル証明書Cを入力し、前記デジタル証
明書Cのデジタル署名に使用した前記秘密鍵dTによっ
て前記ブラインド署名用データBをデジタル署名したブ
ラインド署名済データB’を生成し、ここで、 B’=(reT)dTh(x)dT mod nT =r・h(x)dT mod nT h(x)dTはh(x)を秘密鍵dTによってデジタル署
名したデータ 前記発行者の処理装置は、前記ブラインド署名済データ
B’を入力し、これを前記ブラインド係数rによって除
して電子証券の識別部S1(x)を算出し、ここで、 S1(x)=<x,h(x)dT mod nT> 続いて、電子証券権利部S0と電子証券識別部S
1(x)とを組み合わせて電子証券S(x) S(x)=<S0,S1(x)> を生成して電子証券の発行手続を完了することを特徴と
するものである。
X = f (y, z) y = f (a, b) z = f (id, c) where x: security number f (): f (x, y) = f (x ′, y ') x ≠
A one-way hash function in which it is difficult to find x ', y ≠ y'. A processing system for issuing, transferring, certifying, and erasing electronic securities according to claim 3 of the present invention comprises a processing device of an issuer and a user. A processing system for issuing, transferring, certifying, and erasing electronic securities, comprising a processing device of (i) and a processing device of a neutral institution. key n T of RSA system for each electronic securities on demand, e T, p T, q T, generates the d T, digital certificates and digital signatures n T of the public key, the e T by the secret key d T A letter C is generated, where C = <n T , e T , h (n T | e T ) dp mod n p ><> is a set of data n T and e T inside the right and obligation contents. The corresponding security-specific public keys d p and n p are the private key and the public key h (n T | e T ) is a hash function using n T and e T as variables h (n T | e T ) dp is data obtained by digitally signing h (n T | e T ) with a secret key d p mod n p is n p law said issuer processing device indicating that a (modulus) inputs the description D that describes the rights and obligations of the digital certificate C and the electronic securities, and outputs a right portion S 0 of the electronic securities, where in, S 0 = <C, D , h (C | D) do mod n o> d o is the issuer of the secret key n o is the issuer's public key h (C | D) is a variable C and D hash function h to (C | D) do the h | processing device data (C D) a digitally signed by the private key d o mod n o is the NSO indicating that the n o modulo (modulus) is inputs and said digital certificate C and ECN right portion S 0, the digital in electronic securities issuing record database Search for Le certificates C, and the electronic securities issuing record database right portion S 0 of the digital certificate C and the electronic securities on condition that the digital certificate C is not used in other electronic securities as a set And the issuer's processing device registers the security number random numbers a, b, c (0 <
a, b, c < 2t , t is a predetermined number of binary digits) and a blind coefficient r (0 <r < 2t , t is a predetermined number of binary digits) are randomly generated and issued. The security number x is calculated using the specific number id of the third party, and then the blind signature data B in which the security number x is concealed by the blind coefficient r is calculated, where x = f (y, z) y = F (a, b) z = f (id, c) f () is x ≠ such that f (x, y) = f (x ′, y ′)
x ', y ≠ y' indicates the hard one-way hash function to find a, B = r eT h (x ) modn T h (x) is a hash function mod n T to variable x to the n T The processing unit of the neutral organization inputs the blind signature data B and the digital certificate C, and uses the secret key d T used for the digital signature of the digital certificate C. Blind signed data B ′ is generated by digitally signing the blind signature data B, where B ′ = (r eT ) dTh (x) dT mod n T = r · h (x) dT mod n T h (x) dT data the issuer processing devices that digitally signed h (x) is the private key d T inputs the blind signed data B ', which was divided by the blind coefficient r electronic Identification of securities S calculated 1 (x), wherein, S 1 (x) = < x, h (x) dT mod n T> Subsequently, the electronic securities right portion S 0 and ECN identification unit S
1 (x) to generate electronic securities S (x) S (x) = <S 0 , S 1 (x)>, thereby completing the electronic securities issuance procedure.

【0021】本願請求項4に係る電子証券の発行、移
転、証明、消去のための処理システムは、発行者の処理
装置と、利用者の処理装置と、中立機関の処理装置とか
らなる電子証券の発行、移転、証明、消去のための処理
システムであって、電子証券の移転手続において、被移
転利用者の処理装置は、移転者から電子証券と移転者の
みが知り得る移転前の証券番号の乱数の一部とを取得
し、被移転利用者専用の新たな証券番号を生成し、前記
新たな証券番号を秘匿したブラインド署名用データを生
成し、中立機関の処理装置は、被移転利用者から前記ブ
ラインド署名用データと、移転前の証券番号と中立機関
のみがデジタル署名し得たデジタル署名済証券番号とか
らなる電子証券識別部と、前記移転者のみが知り得る移
転前の証券番号の乱数の一部と、前記電子証券の電子証
券権利部に含まれているデジタル証明書とを入力し、前
記デジタル証明書を介して前記移転前の電子証券識別部
と前記電子証券権利部とが一対一対応であることの検証
計算を行い、前記移転前の証券番号の乱数の一部と前記
移転前の証券番号識別部の証券番号とを用いて前記移転
前の電子証券識別部が移転利用者の合意の下に被移転利
用者に与えられたことの検証計算を行い、前記移転前の
電子証券識別部が未移転であることを電子証券移転記録
データベースで確認して未移転であったことを条件に移
転者の前記電子証券識別部を移転済の電子証券識別部と
して登録するとともに、前記デジタル証明書をデジタル
署名したのと同一の秘密鍵によって前記ブラインド署名
用データをデジタル署名することにより、中立機関のみ
がデジタル署名し得るブラインド署名済データを生成
し、前記被移転者の処理装置は、前記ブラインド署名済
データをアンブラインド処理して中立機関のみがデジタ
ル署名し得る新たなデジタル署名済証券番号を取得し、
新たな前記証券番号と前記デジタル署名済証券番号とか
らなる電子証券識別部を生成し、前記電子証券権利部と
新たな電子証券識別部とを組み合わせて電子証券の移転
手続を完了することを特徴とするものである。
A processing system for issuing, transferring, certifying, and erasing electronic securities according to claim 4 of the present application is an electronic security system comprising an issuer's processing device, a user's processing device, and a neutral organization's processing device. Is a processing system for the issuance, transfer, certification, and erasure of electronic securities. In the electronic securities transfer procedure, the processing device of the transferee uses electronic securities from the transferor and the security number before transfer, which only the transferor can know. A new security number dedicated to the transferred user, generates blind signature data concealing the new security number, and the processing unit of the neutral organization The digital signature identification unit consisting of the blind signature data from the sender, the security number before transfer and the digitally signed security number that can be digitally signed only by the neutral authority, and the security number before transfer that only the transferor can know Random number A part and a digital certificate included in the electronic securities right section of the electronic security are input, and the electronic certificate identification section and the electronic securities right section before transfer are one-to-one through the digital certificate. Perform the verification calculation of the correspondence, the electronic securities identification unit before the transfer using the part of the random number of the security number before the transfer and the security number of the security number identification unit before the transfer, the transfer user of the transfer user A verification calculation is performed to confirm that the transfer has been given to the transferred user under the agreement, and it is confirmed by the electronic securities transfer record database that the electronic securities identification unit before the transfer has not been transferred. By registering the electronic securities identification section of the transferee as a transferred electronic securities identification section on the condition, and digitally signing the blind signature data with the same private key that digitally signed the digital certificate. Blind-signed data that can only be digitally signed by a neutral institution is generated, and the processing device of the transferee unblinds the blind-signed data to generate a new digitally signed security that can be digitally signed only by a neutral institution. Get the number,
An electronic securities identification unit including the new security number and the digitally signed security number is generated, and the electronic securities right unit and the new electronic security identification unit are combined to complete an electronic securities transfer procedure. It is assumed that.

【0022】本願請求項5に係る電子証券の発行、移
転、証明、消去のための処理システムは、発行者の処理
装置と、利用者の処理装置と、中立機関の処理装置とか
らなる電子証券の発行、移転、証明、消去のための処理
システムであって、電子証券の移転手続において、被移
転利用者βの処理装置は、移転利用者αから電子証券S
(xα)と移転利用者αの証券番号xαの乱数aα,b
α,zαを取得し、被移転利用者β専用の新たな証券番
号の乱数aβ,bβ,cβと、ブラインド係数rβ(0
<rβ<2t、tは2進数の所定の桁数)とを生成し、
被移転利用者βの特定番号idβを用いて被移転利用者
β専用の新たな証券番号xβを算出し、続いて前記証券
番号xβを前記ブラインド係数rβによって秘匿したブ
ラインド署名用データBβを算出し、ここで、 S(xα)=<S0,S1(xα)> <>はその内側のデータの集合 S0=<C,D,h(C|D)do mod no> Cはデジタル証明書 Dは権利義務関係の記述 doは発行者の秘密鍵、 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)をdoによってデジタル
署名したデータ mod noはnoを法とすることを示す C=<nT,eT,h(nT|eT)dp mod np> nT,eTは権利義務内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dTはh(nT|eT)をdpによってデジ
タル署名したデータ mod npはnpを法(modulus)とすることを示す S1(xα)=<xα,h(xα)dT mod nT> xαは移転利用者αの証券番号 h(xα)はxαを変数とするハッシュ関数 h(xα)dTはh(xα)をdTによってデジタル署名
したデータ xα=f(yα,zα) yα=f(aα,bα) zα=f(idα,cα) aα,bα,cαは0<aα,bα,cα<2t idαは移転利用者αの特定番号 f( )はf(x,y)=f(x′,y′)なるx≠
x′,y≠y′を見つけることが困難な一方向性ハッシ
ュ関数 xβ=f(yβ,zβ) yβ=f(aβ,bβ) zβ=f(idβ,cβ) xβは被移転利用者β専用の新たな証券番号 aβ,bβ,cβは0<aβ,bβ,cβ<2t idβは被移転利用者βの特定番号 Bβ=rβ eTh(xβ) modnT h(xβ)はxβを変数とするハッシュ関数 eTは中立機関の秘密鍵dTに対応する公開鍵 前記中立機関の処理装置は、被移転利用者βから前記ブ
ラインド署名用データBβと、移転前の前記電子証券識
別部S1(xα)と、前記証券番号乱数aα,bα,z
αと、前記電子証券S(xα)の電子証券権利部S0に
含まれているデジタル証明書Cとを入力し、移転前の前
記証券番号xαからそのハッシュ関数h(xα)を算出
し、デジタル署名された証券番号のハッシュ関数h(x
α)dTをデジタル証明書Cで使用した秘密鍵dTと対を
なす公開鍵eTによって復号してh(xα)dT・eTを
算出し、両者を照合することにより、前記電子証券識別
部S1(xα)が前記電子証券権利部S0と一対一対応
であることを検証し、続いて前記証券番号xαがxα=
f(f(aα,bα),zα)の関係を満たすことを検
証することにより、前記電子証券識別部S1(xα)が
移転利用者αの合意の下に被移転利用者βに与えられた
ことを確認し、電子証券移転記録データベースで前記電
子証券識別部S1(xα)を検索することにより未移転
であることを確認し、未移転であることを条件に前記電
子証券識別部S1(xα)を移転済電子証券識別部とし
て登録し、前記デジタル証明書Cのデジタル署名に使用
した秘密鍵dTによって前記ブラインド署名用データB
βをデジタル署名してブラインド署名済データBβ’を
生成し、ここで、 Bβ’=(rβ eT)dTh(xβ)dT mod nT =rβ・h(xβ)dT mod nT h(xβ)dTはh(xβ)をdTによってデジタル署名
したデータ 前記被移転利用者βの処理装置は、前記ブラインド署名
済データBβ’を入力し、これを前記ブラインド係数r
βによって除してデジタル署名済証券番号h(xβ)
dT mod nTを取得し、電子証券の識別部S1(x
β)を算出し、ここで、 S1(xβ)=<xβ,h(xβ)dT mod nT> 続いて、電子証券権利部S0と電子証券識別部S1(x
β)とを組み合わせて電子証券S(xβ) S(xβ)=<S0,S1(xβ)> を生成して電子証券の移転手続を完了することを特徴と
するものである。
A processing system for issuing, transferring, certifying, and erasing electronic securities according to claim 5 of the present invention is an electronic security system comprising an issuer processing device, a user processing device, and a neutral institution processing device. Is a processing system for issuing, transferring, certifying, and erasing the electronic securities. In the transfer procedure of the electronic securities, the processing device of the transferred user β transmits the electronic securities S from the transfer user α.
(X α ) and the random numbers a α , b of the security number x α of the transfer user α
alpha, it acquires the z alpha, random a beta of transferee user beta dedicated new policy number of, b beta, and c beta, blind coefficient r beta (0
<R β <2 t , where t is a predetermined number of binary digits).
Using a specific number idβ the transferee user beta calculates the new certificate number x beta dedicated transferee user beta, followed by the policy number x beta blind signature data B that concealed by the blind coefficient r beta β is calculated, where S (x α ) = <S 0 , S 1 (x α )><<> is a set of data S 0 = <C, D, h (C | D) do mod n o> C is the description of the digital certificate D is right and obligations d o is the secret key of the issuer, n o public key h of the issuer (C | D) is a hash function as a variable C and D h ( C | D) do the h (C | D) a d o data mod n o which was digitally signed by indicates modulo n o C = <n T, e T, h (n T | e T) the secret of dp mod n p> n T, e T securities-specific public key d p corresponding to the rights and obligations content, n p is a neutral institution And the public key h (n T | e T) is n T and e T a hash function to the variable h (n T | e T) dT is h (n T | e T) digitally signed by a d p data mod n p indicates that n p is a modulus S 1 (x α ) = <x α , h (x α ) dT mod n T > x α is the security number h (x α ) is a hash function h (x alpha to variable x alpha) dT is h (x alpha) of d T by the digital signature data x α = f (y α, z α) y α = f (a α, b α ) z α = f (id α , c α ) a α , b α , c α are 0 <a α , b α , c α <2 t id α is the specific number of the transfer user α f () is f X ≠ such that (x, y) = f (x ′, y ′)
x ', y ≠ y' difficult to find a one-way hash function x β = f (y β, z β) y β = f (a β, b β) z β = f (id β, c β X β is a new security number dedicated to the transferred user β a β , b β , c β is 0 <a β , b β , c β <2 t id β is the specific number of the transferred user β B β = processing apparatus of r β eT h (x β) modn T h (x β) hash and variable x β function e T is public key the neutral institution corresponding to the private key d T of neutral institutions, transferee From the user β, the blind signature data Bβ , the electronic security identification unit S 1 ( xα ) before transfer, and the security number random numbers aα , bα , z
and alpha, the inputs the digital certificate C contained in the electronic security rights section S 0 of the electronic securities S (x α), wherein the front transfer certificate number x alpha from the hash function h a (x alpha) The hash function h (x
α ) dT is decrypted by the public key e T paired with the secret key d T used in the digital certificate C to calculate h (x α ) dT · eT , and the two are compared to obtain the electronic security identification. It is verified that the section S 1 (x α ) has a one-to-one correspondence with the electronic securities right section S 0, and then the security number x α is x α =
f (f (a α, b α), z α) by verifying that satisfies the relationship, the electronic securities identification section S 1 (x α) is to be moved to under the transfer user alpha agreement user β, and by searching the electronic securities transfer record database for the electronic securities identification unit S 1 ( xα ), it is confirmed that the electronic securities have not been transferred. The electronic security identification unit S 1 ( xα ) is registered as the transferred electronic security identification unit, and the blind signature data B is obtained using the secret key d T used for the digital signature of the digital certificate C.
The beta and digital signature 'generated, where, B beta' blind signed data B β = (r β eT) dT h (x β) dT mod n T = r β · h (x β) dT mod n T h (x β) dT is h (x β) a processor of the data the transferee user beta was digitally signed by d T inputs the blind signed data B beta ', the blind factor this r
by dividing by β digital signed policy number h (x β)
dT mod n T is obtained, and the identification part S 1 (x
β ), where S 1 (x β ) = <x β , h (x β ) dT mod n T > Then, the electronic securities right part S 0 and the electronic securities identification part S 1 (x
β ) to generate electronic securities S ( xβ ) S ( xβ ) = <S 0 , S 1 ( xβ )> to complete the transfer procedure of the electronic securities. .

【0023】本願請求項6に係る電子証券の発行、移
転、証明、消去のための処理システムは、発行者の処理
装置と、利用者の処理装置と、中立機関の処理装置とか
らなる電子証券の発行、移転、証明、消去のための処理
システムであって、電子証券の証明手続において、前記
発行者の処理装置は、電子証券を所有する利用者から電
子証券と、その利用者のみが知り得る証券番号乱数の一
部とを取得し、その電子証券の証券番号と中立機関のみ
がデジタル署名し得たデジタル署名済証券番号とからな
る電子証券識別部と、その電子証券の電子証券権利部に
含まれているデジタル証明書と、前記証券番号乱数の一
部とを前記中立機関の処理装置に送って所有の証明を要
求し、前記中立機関の処理装置は、前記デジタル証明書
を介して前記電子証券識別部が前記電子証券権利部と一
対一対応であることの検証計算を行い、前記証券番号乱
数の一部と前記証券番号識別部の証券番号とを用いて前
記証券番号の乱数が電子証券を所有する利用者のみが知
り得ることの検証の計算を行い、前記電子証券識別部を
電子証券証明記録データベースで検索し、検索と検証の
結果を前記発行者の処理装置に返送することを特徴とす
るものである。
A processing system for issuing, transferring, certifying, and erasing electronic securities according to claim 6 of the present application is an electronic security system comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral organization. Is a processing system for issuing, transferring, certifying, and erasing electronic securities. In the certification procedure of the electronic securities, the processing device of the issuer knows only the electronic securities from the user who owns the electronic securities and the user. A part of the obtained security number random number, an electronic security identification part consisting of the security number of the electronic security and a digitally signed security number obtained by digital signature only by a neutral organization, and an electronic security right part of the electronic security The digital certificate contained in the, and a part of the security number random number is sent to the processing unit of the neutral institution to request proof of ownership, the processing unit of the neutral institution, via the digital certificate The electronic certificate The identification unit performs a verification calculation that the electronic securities right unit is in one-to-one correspondence with the electronic securities right unit, and the random number of the security number identifies the electronic security using a part of the security number random number and the security number of the security number identification unit. Performing a calculation of verification that only the owning user can know, searching the electronic securities identification unit in the electronic securities certification record database, and returning the search and verification results to the processing device of the issuer. Is what you do.

【0024】本願請求項7に係る電子証券の発行、移
転、証明、消去のための処理システムは、発行者の処理
装置と、利用者の処理装置と、中立機関の処理装置とか
らなる電子証券の発行、移転、証明、消去のための処理
システムであって、電子証券の証明手続において、前記
発行者oの処理装置は、電子証券を所有する利用者Aか
ら電子証券S(xA)と、利用者Aのみが知り得る証券
番号の乱数の一部yA,idA,cAとを取得し、前記電
子証券S(xA)の電子証券識別部S1(xA)と、前記
電子証券S(xA)の電子証券権利部S0に含まれてい
るデジタル証明書Cと、前記証券番号乱数の一部yA,
idA,cAとを中立機関Tの処理装置に送って所有の証
明を要求し、ここで、 S(xA)=<S0,S1(xA)> <>はその内側のデータの集合 S0=<C,D,h(C|D)do mod no> Cはデジタル証明書 Dは権利義務関係の記述 doは発行者の秘密鍵 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)をdoによってデジタル
署名したデータ mod noはnoを法とすることを示す C=<nT,eT,h(nT|eT)dp mod np> nT,eTは権利義務内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)をdpによってデジ
タル署名したデータ mod npはnpを法(modulus)とすることを示す S1(xA)=<xA,h(xA)dT mod nT> xAは電子証券を所有する利用者Aが付与した証券番号 dTとnTはそれぞれの中立機関の秘密鍵と公開鍵 h(xA)はxAを変数とするハッシュ関数、 h(xA)dTはh(xA)をdTによってデジタル署名し
たデータ xA=f(yA,zA) yA=f(aA,bA) zA=f(idA,cA) aA,bA,cAは証券番号の乱数 0<aA,bA,cA<2t tは2進数の所定の桁数 idAは利用者Aの特定番号 f()はf(x,y)=f(x′,y′)なるx≠
x′, y≠y′を見つけることが困難な一方向性ハッシュ関数 前記中立機関Tの処理装置は、前記識別部S1(xA)
に含まれている証券番号xAからそのハッシュ関数h
(xA)を算出し、前記電子証券識別部S1(xA)に含
まれているデジタル署名された証券番号のハッシュ関数
h(xA)dTをデジタル証明書Cで使用した秘密鍵dT
と対をなす公開鍵eTによって復号してh(xA)
dT・eTを算出し、両者を照合することにより、電子証
券識別部S1(xA)が電子証券権利部S0と一対一対
応であることを検証し、続いて前記証券番号xAがxA=
f(yA,f(idA,cA))の関係を満たすことを計
算することにより、前記証券番号乱数の一部yA,i
dA,cAがその電子証券を所有する利用者のみが知り得
ることの検証を行い、電子証券証明記録データベースを
検索し、検索と検証の結果を前記発行者oの処理装置に
返送することを特徴とするものである。
A processing system for issuing, transferring, certifying, and erasing electronic securities according to claim 7 of the present application is an electronic security system comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral organization. issuing, transferring, certification, a processing system for erasing, in the proof procedure of the electronic securities processing apparatus of the issuer o includes an electronic securities from the user a who owns the electronic securities S (x a) some of the random number of the user a only knows obtained policy number y a, id a, acquires the c a, the electronic securities identification section S 1 of the electronic securities S (x a) and (x a), wherein ECN S (x a) and a digital certificate C contained in the electronic security rights section S 0 of a portion y a of the policy number random number,
id A and c A are sent to the processing unit of the neutral organization T to request proof of possession, where S (x A ) = <S 0 , S 1 (x A )><> is the data inside set S 0 = <C, D, h (C | D) do mod n o> of C digital certificate D description of the rights and obligations d o secret key of the issuer n o the public of the issuer key h (C | D) is a hash function h to the variable C and D indicate that the data | | (D C) was digitally signed by d o mod n o is modulo n o (C D) do the h C = <n T , e T , h (n T | e T ) dp mod n p > n T , e T is a public key unique to the security corresponding to the rights and obligations d p , n p is a private key of a neutral organization And the public key h (n T | e T ) is a hash function h (n T | e T ) dp with n T and e T as variables, and the digital signature of h (n T | e T ) with d p The named data mod n p indicates that n p is a modulus S 1 (x A ) = <x A , h (x A ) dT mod n T > x A is the user who owns the electronic securities The security numbers d T and n T assigned by A are the secret key and public key of the neutral institution, respectively. H (x A ) is a hash function using x A as a variable, and h (x A ) dT is h (x A ). d T data digitally signed by x A = f (y A, z A) y A = f (a A, b A) z A = f (id A, c A) a A, b A, c A securities The random number of the number 0 <a A , b A , c A <2 tt is a predetermined number of binary digits id A is the specific number of the user A f () is f (x, y) = f (x ′, y ') x ≠
One-way hash function in which it is difficult to find x ′, y ≠ y ′. The processing device of the neutral institution T includes the identification unit S 1 (x A )
The hash function h from the policy number x A, which is included in the
(X A ) is calculated, and a hash function h (x A ) dT of the digitally signed security number included in the electronic security identification unit S 1 (x A ) is used as a secret key d used in the digital certificate C. T
And decrypted by the public key e T paired with h (x A )
By calculating dT · eT and comparing the two, it is verified that the electronic securities identification unit S 1 (x A ) has a one-to-one correspondence with the electronic securities rights unit S 0, and then the security number x A is obtained. x A =
f (y A, f (id A, c A)) by calculating satisfy a relationship of a portion of the policy number random number y A, i
Verify that d A and c A are known only to the user who owns the electronic security, search the electronic security certificate record database, and return the search and verification results to the processing device of the issuer o. It is characterized by the following.

【0025】本願請求項8に係る電子証券の発行、移
転、証明、消去のための処理システムは、発行者の処理
装置と、利用者の処理装置と、中立機関の処理装置とか
らなる電子証券の発行、移転、証明、消去のための処理
システムであって、電子証券の消去手続において、前記
中立機関の処理装置は、消去を求められている電子証券
の証券番号と中立機関のみがデジタル署名し得たデジタ
ル署名済証券番号とからなる電子証券識別部と、その電
子証券の電子証券権利部に含まれているデジタル証明書
と、その電子証券の消去を求める発行者あるいは利用者
のみが知り得る前記証券番号の乱数の一部とを入力し、
前記デジタル証明書を介して前記電子証券識別部が電子
証券権利部と一対一対応であることの検証計算を行い、
前記証券番号の乱数の一部と前記証券番号識別部の証券
番号とを用いて前記証券番号乱数が電子証券の消去を求
めている発行者あるいは利用者のみが知り得ることの検
証の計算を行い、前記電子証券識別部を電子証券消去記
録データベースで検索し、未消去を条件に前記電子証券
識別部を消去済の電子証券識別部として登録することに
より、電子証券の消去手続を完了することを特徴とする
ものである。
A processing system for issuing, transferring, certifying and erasing electronic securities according to claim 8 of the present invention is an electronic security system comprising an issuer's processor, a user's processor, and a neutral institution's processor. Is a processing system for issuing, transferring, certifying and erasing electronic securities, and in the process of erasing electronic securities, the processing unit of the neutral institution only has the security number of the electronic security that is required to be erased and a digital signature of only the neutral institution. Only the digital certificate identification section consisting of the digitally signed security number obtained, the digital certificate included in the digital certificate right section of the digital certificate, and the issuer or user requesting erasure of the digital certificate. Enter a part of the random number of the security number to obtain,
Performing a verification calculation that the electronic securities identification unit is in one-to-one correspondence with the electronic securities right unit via the digital certificate,
Using a part of the security number random number and the security number of the security number identification unit, a verification calculation is performed to verify that only the issuer or user seeking the erasure of the electronic security can be known. Searching for the electronic securities identification section in the electronic securities erasure record database, and registering the electronic security identification section as an erased electronic security identification section on the condition of non-erasure, thereby completing the erasure procedure of the electronic security. It is a feature.

【0026】本願請求項9に係る電子証券の発行、移
転、証明、消去のための処理システムは、発行者の処理
装置と、利用者の処理装置と、中立機関の処理装置とか
らなる電子証券の発行、移転、証明、消去のための処理
システムであって、電子証券の消去手続において、前記
中立機関の処理装置は、電子証券の消去を求める発行者
あるいは利用者Bから、消去を求められている電子証券
の電子証券識別部S1(xB)と、その電子証券の電子
証券権利部S0に含まれているデジタル証明書Cと、そ
の電子証券の消去を求める発行者あるいは利用者Bのみ
が知り得る証券番号乱数の一部aB,bB,zBとを取得
し、ここで、 S(xB)=<S0,S1(xB)> <>はその内側のデータの集合 S0は電子証券権利部 S1(xB)は電子証券識別部 xBは消去を求められている電子証券の証券番号 S0=< C,D,h(C|D)do mod no> Cはデジタル証明書 Dは権利義務関係の記述 doは発行者の秘密鍵 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)をdoによってデジタ
ル署名したデータ mod noはnoを法(modulus)とすることを示す C=<nT,eT,h(nT|eT)dp mod np> nT,eTは権利内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)をdpによってデジ
タル署名したデータ mod npはnpを法(modulus)とすることを示す S1(xB)=<xB,h(xB)dT mod nT> dTとnTはそれぞれの中立機関の秘密鍵と公開鍵 h(xB)はxBを変数とするハッシュ関数、 h(xB)dTはh(xB)をdTによってデジタル署名し
たデータ xB=f(yB,zB) yB=f(aB,bB) zB=f(idB,cB) aB,bB,cBは証券番号の乱数 0<aB,bB,cB<2t tは2進数の所定の桁数 idBは消去を求める発行者、利用者Bの特定番号 f()はf(x,y)=f(x′,y′)なるx′≠
x′,y≠y′を見つけるのが困難な一方向性ハッシュ
関数 続いて前記中立機関の処理装置は、前記証券番号xBか
らそのハッシュ関数h(xB)を算出し、前記電子証券
識別部S1(xB)に含まれているデジタル署名された
証券番号のハッシュ関数h(xB)dTをデジタル証明書
Cで使用した秘密鍵dTと対をなす公開鍵eTによって復
号してh(xB)dT・eTを算出し、両者を照合するこ
とにより、電子証券識別部S1(xB)が電子証券権利
部S0と一対一対応であることを検証し、前記証券番号
xBがxB=f(f(aB,bB),zB))の関係を満た
すことを検証することにより、前記証券番号乱数の一部
aB,bB,zBが電子証券を消去を求める発行者あるい
は利用者Bのみが知り得ることの検証を行い、前記電子
証券識別部S1(xB)を電子証券消去記録データベー
スで検索し、未消去を条件に前記電子証券識別部S
1(xB)を消去済の電子証券識別部として登録するこ
とにより、電子証券の消去手続を完了することを特徴と
する電子証券の発行、移転、証明、消去のための処理シ
ステム。
A processing system for issuing, transferring, certifying and erasing electronic securities according to claim 9 of the present application is an electronic security system comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral organization. Is a processing system for issuing, transferring, certifying, and erasing electronic securities. In the erasure procedure of electronic securities, the processing unit of the neutral institution is required to be erased by the issuer or user B requesting erasure of the electronic securities. The electronic securities identification unit S 1 (x B ) of the electronic security, the digital certificate C included in the electronic securities rights unit S 0 of the electronic security, and the issuer or user requesting erasure of the electronic security A part of security number random numbers a B , b B , and z B that only B can know is obtained, where S (x B ) = <S 0 , S 1 (x B )><> The data set S 0 is the electronic securities rights department S 1 (x B ) Policy number S 0 = electronic securities electronic securities identification unit x B, which are required to erase <C, D, h (C | D) do mod n o> C is the description of the digital certificate D is the rights and obligations relationship d o is the issuer of the secret key n o is the issuer's public key h (C | D) is C and the hash function h to the variable D by | | (D C) a d o (C D) d o is h digital signature data mod n o is n o law (modulus) indicate that the C = <n T, e T , h (n T | e T) dp mod n p> n T, e T the right content The public key d p and n p corresponding to the security are a secret key and a public key of a neutral institution, and h (n T | e T ) is a hash function h (n T | e T ) using n T and e T as variables. dp is h (n T | e T) data was digitally signed by d p mod n p is S 1 indicating that the n p modulo (modulus) (x B) <X B, h (x B ) dT mod n T> d T and n T is the secret key of each of the neutral institution and the public key h (x B) is a hash function to the variable x B, h (x B) dT is h (x B) data was digitally signed by d T x B = f (y B, z B) y B = f (a B, b B) z B = f (id B, c B) a B , b B, c B is a random number of policy number 0 <a B, b B, c B <2 t t is a predetermined number of digits of the binary numbers id B issuer seeking erase specific number f of the user B ( ) Is x ′ ≠ such that f (x, y) = f (x ′, y ′).
A one-way hash function in which it is difficult to find x ′, y ≠ y ′. Subsequently, the processing unit of the neutral organization calculates a hash function h (x B ) from the security number x B and obtains the electronic security identification. The hash function h (x B ) dT of the digitally signed security number included in the part S 1 (x B ) is decrypted by the public key e T paired with the secret key d T used in the digital certificate C. By calculating h (x B ) dT · eT and comparing them, it is verified that the electronic securities identification unit S 1 (x B ) has a one-to-one correspondence with the electronic securities rights unit S 0, and ID x B is x B = f (f (a B, b B), z B) by verifying that satisfies the relationship), part a B of the policy number random number, b B, is z B electron Verify that only the issuer or user B seeking erasure of the security can know, Identifying portion S 1 a (x B) searching in an electronic securities erase record database, the electronic securities identifying unit S non erased condition
By registering 1 (x B) as an electron securities identification of erased, issues an electronic certificate, characterized in that to complete the erasing procedure of the electronic securities, transfer, certification, processing system for erasing.

【0027】本願請求項10に係る電子証券の発行、移
転、証明、消去のための処理方法は、発行者の処理装置
と、利用者の処理装置と、中立機関の処理装置とからな
る電子証券の発行、移転、証明、消去のための処理方法
であって、電子証券の発行手続において、前記中立機関
の処理装置は、中立機関のみがデジタル署名し得るデジ
タル証明書を生成し、前記発行者の処理装置は、発行者
のみがデジタル署名し得る前記デジタル証明書と権利義
務関係の記述の暗号化データを含む電子証券権利部を生
成する一方、証券番号を生成し、前記証券番号を秘匿し
たブラインド署名用データを生成し、前記中立機関の処
理装置は、前記デジタル証明書と前記ブラインド署名用
データとを入力し、前記デジタル証明書をデジタル署名
したのと同一の秘密鍵により前記ブラインド署名用デー
タをデジタル署名することにより、中立機関のみがデジ
タル署名し得るブラインド署名済データを生成し、前記
発行者の処理装置は、前記ブラインド署名済データを入
力し、アンブラインド処理して中立機関のみがデジタル
署名し得るデジタル署名済証券番号を取得し、この中立
機関によるデジタル署名済証券番号を含む電子証券識別
部を生成し、前記電子証券権利部と電子証券識別部とを
組み合わせて電子証券の発行手続を完了するすることを
特徴とするものである。
[0027] A processing method for issuing, transferring, certifying, and erasing electronic securities according to claim 10 of the present application is an electronic securities system comprising an issuer processing apparatus, a user processing apparatus, and a neutral institution processing apparatus. Is a processing method for issuing, transferring, certifying, and erasing, wherein in a procedure for issuing electronic securities, the processing device of the neutral organization generates a digital certificate that can be digitally signed only by the neutral organization, The processing device generates an electronic securities rights section including the digital certificate that can only be digitally signed by the issuer and encrypted data of the description of the rights and obligations relationship, while generating a security number and concealing the security number. The blind signature data is generated, and the processing unit of the neutral institution inputs the digital certificate and the blind signature data, and has the same secret as when the digital certificate is digitally signed. Digitally signing the blind signature data with a key generates blind signed data that can be digitally signed only by a neutral organization, and the processing unit of the issuer inputs the blind signed data and performs unblind processing. To obtain a digitally signed security number that only a neutral institution can digitally sign, generate an electronic securities identification unit including the digitally signed security number by this neutral institution, and combine the electronic securities rights unit and the electronic securities identification unit with each other. In combination, the electronic securities issuance procedure is completed.

【0028】本願請求項11に係る電子証券の発行、移
転、証明、消去のための処理方法は、上記請求項10の
処理方法において、前記発行者の装置が生成する証券番
号は、下式の関係を満たす3つの乱数a,b,cと発行
者の特定番号idによって計算されるものであることを
特徴とするものである。 x=f(y,z) y=f(a,b) z=f(id,c) ここで、x:証券番号 f():f(x,y)=f(x′,y′)なるx≠
x′,y≠y≠を見つけることが困難な一方向性ハッシ
ュ関数
[0028] The processing method for issuing, transferring, certifying and erasing electronic securities according to claim 11 of the present application is the processing method according to claim 10, wherein the security number generated by the issuer's device is It is characterized by being calculated by three random numbers a, b, c satisfying the relationship and the issuer's specific number id. x = f (y, z) y = f (a, b) z = f (id, c) where x: security number f (): f (x, y) = f (x ′, y ′) X
A one-way hash function that is difficult to find x ', y {y}

【0029】本願請求項12に係る電子証券の発行、移
転、証明、消去のための処理方法は、発行者の処理装置
と、利用者の処理装置と、中立機関の処理装置とからな
る電子証券の発行、移転、証明、消去のための処理方法
であって、電子証券の発行手続において、前記中立機関
の処理装置は、発行者の要求に応じて電子証券ごとにR
SA系の鍵nT,eT,pT,qT,dTを生成し、その公
開鍵のnT,eTを秘密鍵dTによってデジタル署名した
デジタル証明書Cを生成し、ここで、 C=<nT,eT,h(nT|eT)dp mod np> <>はその内側のデータの集合 nT,eT は権利内容に対応する証券固有の公開鍵 dp,np は中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)を秘密鍵dpによっ
てデジタル署名したデータ mod npはnpを法(modulus)とすることを示す 前記発行者の処理装置は、前記デジタル証明書Cと電子
証券の権利義務を記述した記述Dとを入力し、電子証券
の権利部S0を出力し、ここで、 S0=<C,D,h(C|D)do mod no> doは発行者の秘密鍵 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)を秘密鍵doによってデ
ジタル署名したデータ mod noはnoを法(modulus)とすることを示す 前記中立機関の処理装置は、前記デジタル証明書Cと電
子証券権利部S0とを入力し、電子証券発行記録データ
ベースで前記デジタル証明書Cを検索し、そのデジタル
証明書Cが他の電子証券に使用されていないことを条件
に前記デジタル証明書Cと電子証券の権利部S0を組と
して前記電子証券発行記録データベースに登録し、前記
発行者の処理装置は、証券番号乱数a,b,c(0<
a,b,c<2t、tは2進数の所定の桁数)と、ブラ
インド係数r(0<r<2t、tは2進数の所定の桁
数)とをランダムに生成し、発行者の特定番号idを用
いて証券番号xを算出し、続いて前記証券番号xを前記
ブラインド係数rによって秘匿したブラインド署名用デ
ータBを算出し、ここで、 x=f(y,z) y=f(a,b) z=f(id,c) f( )はf(x,y)=f(x′,y′)なるx≠
x′,y≠y′を見つけることが困難な一方向性ハッシ
ュ関数を示し、 B=reTh(x) mod nT h(x)はxを変数とするハッシュ関数 mod nTはnTを法(modulus)とすることを示す 前記中立機関の処理装置は、前記ブラインド署名用デー
タBと前記デジタル証明書Cを入力し、前記デジタル証
明書Cのデジタル署名に使用した前記秘密鍵dTによっ
て前記ブラインド署名用データBをデジタル署名したブ
ラインド署名済データB’を生成し、ここで、 B’=(reT)dTh(x)dT mod nT =r・h(x)dT mod nT h(x)dTはh(x)を秘密鍵dTによってデジタル署
名したデータ 前記発行者の処理装置は、前記ブラインド署名済データ
B’を入力し、これを前記ブラインド係数rによって除
して電子証券の識別部S1(x)を算出し、ここで、 S1(x)=<x,h(x)dT mod nT> 続いて、電子証券権利部S0と電子証券識別部S
1(x)とを組み合わせて電子証券S(x) S(x)=<S0,S1(x)> を生成して電子証券の発行手続を完了することを特徴と
するものである。
A processing method for issuing, transferring, certifying, and erasing electronic securities according to claim 12 of the present application is an electronic security system comprising an issuer processing device, a user processing device, and a neutral organization processing device. Is a processing method for issuing, transferring, certifying, and erasing electronic securities. In the electronic securities issuance procedure, the processing unit of the neutral institution processes R for each electronic security in response to a request from the issuer.
SA system key n T, e T, p T , q T, generates the d T, and generates the n T, e T a digital certificate C was digitally signed by the private key d T of the public key, wherein , C = <n T , e T , h (n T | e T ) dp mod n p >><> is a set of data inside n t , e T is a security-specific public key d p corresponding to the rights , N p are the secret and public keys of a neutral institution h (n T | e T ) is a hash function h (n T | e T ) with n T and e T as variables dp is h (n T | e T ) the issuer of the processor data mod n p which is digitally signed by the private key d p to indicate that the n p modulo (modulus) of the description describes the rights and obligations of the digital certificate C and the electronic securities D enter the door, and outputs the right portion S 0 of electronic securities, here, S 0 = <C, D , h (C | D) do mod n o> d o is the issuer Of the secret key n o is the issuer's public key h (C | D) is a hash function h to the variable C and D was digitally signed by the | | (D C) of the secret key d o (C D) do is h processor data mod n o is the NSO indicating that the n o modulo (modulus) inputs and said digital certificate C and ECN right portion S 0, the digital in electronic securities issuing record database Find the certificate C, registered in the electronic securities issuing record database right portion S 0 of the digital certificate C and the electronic securities on condition that the digital certificate C is not used in other electronic securities as a set The issuer's processing device then checks the security number random numbers a, b, c (0 <
a, b, c < 2t , t is a predetermined number of binary digits) and a blind coefficient r (0 <r < 2t , t is a predetermined number of binary digits) are randomly generated and issued. The security number x is calculated using the specific number id of the third party, and then the blind signature data B in which the security number x is concealed by the blind coefficient r is calculated, where x = f (y, z) y = F (a, b) z = f (id, c) f () is x ≠ such that f (x, y) = f (x ′, y ′)
x ', y ≠ y' indicates the hard one-way hash function to find a, B = r eT h (x ) mod n T h (x) is a hash function mod n T of the variables x n T Is a modulus. The processing unit of the neutral organization inputs the blind signature data B and the digital certificate C, and uses the secret key d T used for the digital signature of the digital certificate C. said blind signature data B 'to generate where, B' blind signed data B digitally signed by = (r eT) dT h ( x) dT mod n T = r · h (x) dT mod n T h (x) dT is h (x) processor of the data the issuer digitally signed by the private key d T a, enter the blind signed data B ', which was divided by the blind coefficient r Identification of electronic securities S calculated 1 (x), wherein, S 1 (x) = < x, h (x) dT mod n T> Subsequently, the electronic securities right portion S 0 and ECN identification unit S
1 (x) to generate electronic securities S (x) S (x) = <S 0 , S 1 (x)>, thereby completing the electronic securities issuance procedure.

【0030】本願請求項13に係る電子証券の発行、移
転、証明、消去のための処理方法は、発行者の処理装置
と、利用者の処理装置と、中立機関の処理装置とからな
る電子証券の発行、移転、証明、消去のための処理方法
であって、電子証券の移転手続において、被移転利用者
の処理装置は、移転者から電子証券と移転者のみが知り
得る移転前の証券番号の乱数の一部とを取得し、被移転
利用者専用の新たな証券番号を生成し、前記新たな証券
番号を秘匿したブラインド署名用データを生成し、中立
機関の処理装置は、被移転利用者から前記ブラインド署
名用データと、移転前の証券番号と中立機関のみがデジ
タル署名し得たデジタル署名済証券番号とからなる電子
証券識別部と、前記移転者のみが知り得る移転前の証券
番号の乱数の一部と、前記電子証券の電子証券権利部に
含まれているデジタル証明書とを入力し、前記デジタル
証明書を介して前記移転前の電子証券識別部と前記電子
証券権利部とが一対一対応であることの検証計算を行
い、前記移転前の証券番号の乱数の一部と前記移転前の
証券番号識別部の証券番号とを用いて前記移転前の電子
証券識別部が移転利用者の合意の下に被移転利用者に与
えられたことの検証計算を行い、前記移転前の電子証券
識別部が未移転であることを電子証券移転記録データベ
ースで確認して未移転であったことを条件に移転者の前
記電子証券識別部を移転済の電子証券識別部として登録
するとともに、前記デジタル証明書をデジタル署名した
のと同一の秘密鍵によって前記ブラインド署名用データ
をデジタル署名することにより、中立機関のみがデジタ
ル署名し得るブラインド署名済データを生成し、前記被
移転者の処理装置は、前記ブラインド署名済データをア
ンブラインド処理して中立機関のみがデジタル署名し得
る新たなデジタル署名済証券番号を取得し、新たな前記
証券番号と前記デジタル署名済証券番号とからなる電子
証券識別部を生成し、前記電子証券権利部と新たな電子
証券識別部とを組み合わせて電子証券の移転手続を完了
することを特徴とするものである。
[0030] A processing method for issuing, transferring, certifying, and erasing electronic securities according to claim 13 of the present application is an electronic security system comprising an issuer processing device, a user processing device, and a neutral institution processing device. Is a processing method for the issuance, transfer, certification, and erasure of electronic securities. In the electronic securities transfer procedure, the processing device of the transferee uses the electronic securities from the transferor and the security number before transfer that only the transferor can know. A new security number dedicated to the transferred user, generates blind signature data concealing the new security number, and the processing unit of the neutral organization Electronic signature identification unit consisting of the blind signature data from the sender, the security number before transfer and the digitally signed security number that could only be digitally signed by a neutral organization, and the security number before transfer that only the transferor can know Part of the random number of A digital certificate included in the electronic securities right section of the electronic security, and the electronic securities identification section and the electronic securities right section before the transfer are in one-to-one correspondence via the digital certificate. The electronic securities identification unit before transfer uses the part of the random number of the security number before transfer and the security number of the security number identification unit before transfer under the agreement of the transfer user. In the electronic securities transfer record database, it is confirmed that the electronic securities identification unit before the transfer has not been transferred. Registering the electronic securities identification unit of the person as a transferred electronic securities identification unit, and digitally signing the blind signature data with the same private key as the digital signature of the digital certificate, thereby achieving a neutrality. Only the Seki generates blind-signed data that can be digitally signed, and the transferee's processing device unblinds the blind-signed data so that only a neutral authority can digitally sign a new digitally signed security number. To generate an electronic securities identification unit including the new security number and the digitally signed security number, and complete the electronic securities transfer procedure by combining the electronic securities right unit and the new electronic security identification unit. It is characterized by doing.

【0031】本願請求項14に係る電子証券の発行、移
転、証明、消去のための処理方法は、発行者の処理装置
と、利用者の処理装置と、中立機関の処理装置とからな
る電子証券の発行、移転、証明、消去のための処理方法
であって、電子証券の移転手続において、被移転利用者
βの処理装置は、移転利用者αから電子証券S(xα)
と移転利用者αの証券番号xαの乱数aα,bα,zα
を取得し、被移転利用者β専用の新たな証券番号の乱数
aβ,bβ,cβと、ブラインド係数rβ(0<rβ<
2t、tは2進数の所定の桁数)とを生成し、被移転利
用者βの特定番号idβを用いて被移転利用者β専用の
新たな証券番号xβを算出し、続いて前記証券番号xβ
を前記ブラインド係数rβによって秘匿したブラインド
署名用データBβを算出し、ここで、 S(xα)=<S0,S1(xα)> <>はその内側のデータの集合 S0=<C,D,h(C|D)do mod no> Cはデジタル証明書 Dは権利義務関係の記述 doは発行者の秘密鍵 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)をdoによってデジタ
ル署名したデータ mod noはnoを法(modulus)とすることを示す C=<nT,eT,h(nT|eT)dp mod np> nT,eTは権利義務内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)をdpによってデジ
タル署名したデータ mod npはnpを法(modulus)とすることを示す S1(xα)=<xα,h(xα)dT mod nT> xαは移転利用者αの証券番号 h(xα)はxαを変数とするハッシュ関数 h(xα)dTはh(xα)をdTによってデジタル署名
したデータ xα=f(yα,zα) yα=f(aα,bα) zα=f(idα,cα) aα,bα,cαは0<aα,bα,cα<2t idαは移転利用者αの特定番号 f( )はf(x,y)=f(x′,y′)なるx≠
x′,y≠y′を見つけるのが困難な一方向性ハッシュ
関数 xβ=f(yβ,zβ) yβ=f(aβ,bβ) zβ=f(idβ,cβ) xβは被移転利用者β専用の新たな証券番号 aβ,bβ,cβは0<aβ,bβ,cβ<2t idβは被移転利用者βの特定番号 Bβ=rβ eTh(xβ) mod nT h(xβ)はxβを変数とするハッシュ関数 eTは中立機関の秘密鍵dTに対応する公開鍵 前記中立機関の処理装置は、被移転利用者βから前記ブ
ラインド署名用データBβと、移転前の前記電子証券識
別部S1(xα)と、前記証券番号乱数aα,bα,z
αと、前記電子証券S(xα)の電子証券権利部S0に
含まれているデジタル証明書Cとを入力し、移転前の前
記証券番号xαからそのハッシュ関数h(xα)を算出
し、デジタル署名された証券番号のハッシュ関数h(x
α)dTをデジタル証明書Cで使用した秘密鍵dTと対を
なす公開鍵eTによって復号してh(xα)dT・eTを
算出し、両者を照合することにより、前記電子証券識別
部S1(xα)が前記電子証券権利部S0と一対一対応
であることを検証し、続いて前記証券番号xαがxα=
f(f(aα,bα),zα)の関係を満たすことを検
証することにより、前記電子証券識別部S1(xα)が
移転利用者αの合意の下に被移転利用者βに与えられた
ことを確認し、電子証券移転記録データベースで前記電
子証券識別部S1(xα)を検索することにより未移転
であることを確認し、未移転であることを条件に前記電
子証券識別部S1(xα)を移転済電子証券識別部とし
て登録し、前記デジタル証明書Cのデジタル署名に使用
した秘密鍵dTによって前記ブラインド署名用データB
βをデジタル署名してブラインド署名済データBβ’を
生成し、ここで、 Bβ’=(rβ eT)dTh(xβ)dT mod nT =rβ・h(xβ)dT mod nT h(xβ)dTはh(xβ)をdTによってデジタル署名
したデータ 前記被移転利用者βの処理装置は、前記ブラインド署名
済データBβ’を入力し、これを前記ブラインド係数r
βによって除してデジタル署名済証券番号h(xβ)
dT mod nTを取得し、電子証券の識別部S1(x
β)を算出し、ここで、 S1(xβ)=<xβ,h(xβ)dT mod nT> 続いて、電子証券権利部S0と電子証券識別部S1(x
β)とを組み合わせて電子証券S(xβ) S(xβ)=<S0,S1(xβ)> を生成して電子証券の移転手続を完了することを特徴と
するものである。
A processing method for issuing, transferring, certifying, and erasing electronic securities according to claim 14 of the present application is an electronic security system comprising an issuer processing device, a user processing device, and a neutral institution processing device. Is a processing method for issuing, transferring, certifying, and erasing the electronic securities. In the transfer procedure of the electronic securities, the processing device of the transferred user β transmits the electronic securities S ( xα ) from the transferring user α .
And random numbers a α , b α , z α of the security number xα of the transfer user α
And the random numbers a β , b β , and c β of the new security number dedicated to the transferred user β and the blind coefficient r β (0 <r β <
2 t , t is a predetermined number of binary digits) and a new security number x β dedicated to the transferred user β is calculated using the specific number id β of the transferred user β, and then The security number x β
Was calculated blind signature data B beta was concealed by the blind coefficient r beta, where, S (x α) = < S 0, S 1 (x α)><> is set S 0 data inside = <C, D, h ( C | D) do mod n o> C digital certificate D description of the rights and obligations d o is the issuer of the secret key n o is the issuer's public key h (C | D ) is the hash function h (C whose variable C and D | indicates that a D) data mod n o which was digitally signed by a d o is n o law (modulus) | is D) d o h (C C = <n T , e T , h (n T | e T ) dp mod n p > n T , e T is a public key unique to the security corresponding to the rights and obligations d p , n p is a private key of a neutral organization And public key h (n T | e T ) is a hash function h (n T | e T ) with n T and e T as variables, and dp is h (n T | e T) ) Is digitally signed with d p , indicating that mod n p is a modulus of n p S 1 (x α ) = <x α , h (x α ) dT mod n T > x α user alpha policy number h (x α) is a hash function h (x alpha) of the variables x alpha dT is h (x alpha) data was digitally signed by d T x α = f (y α, z α ) Y α = f (a α , b α ) z α = f (id α , c α ) a α , b α , c α is 0 <a α , b α , c α < 2t id α is used for transfer The specific number f () of the person α is x ≠ such that f (x, y) = f (x ′, y ′)
x ', y ≠ y' hard one-way hash function to find the x β = f (y β, z β) y β = f (a β, b β) z β = f (id β, c β X β is a new security number dedicated to the transferred user β a β , b β , c β is 0 <a β , b β , c β <2 t id β is the specific number of the transferred user β B β = r β eT h (x β ) mod n T h (x β) the processing unit of the hash function e T is the public key the NSO corresponding to the private key d T of NSO to variable x beta is to be From the transfer user β, the blind signature data B β , the electronic security identification unit S 1 (x α ) before the transfer, and the security number random numbers a α , b α , z
and alpha, the inputs the digital certificate C contained in the electronic security rights section S 0 of the electronic securities S (x α), wherein the front transfer certificate number x alpha from the hash function h a (x alpha) The hash function h (x
α ) dT is decrypted by the public key e T paired with the secret key d T used in the digital certificate C to calculate h (x α ) dT · eT , and the two are compared to obtain the electronic security identification. It is verified that the section S 1 (x α ) has a one-to-one correspondence with the electronic securities right section S 0, and then the security number x α is x α =
f (f (a α, b α), z α) by verifying that satisfies the relationship, the electronic securities identification section S 1 (x α) is to be moved to under the transfer user alpha agreement user β, and by searching the electronic securities transfer record database for the electronic securities identification unit S 1 ( xα ), it is confirmed that the electronic securities have not been transferred. The electronic security identification unit S 1 ( xα ) is registered as the transferred electronic security identification unit, and the blind signature data B is obtained using the secret key d T used for the digital signature of the digital certificate C.
The beta and digital signature 'generated, where, B beta' blind signed data B β = (r β eT) dT h (x β) dT mod n T = r β · h (x β) dT mod n T h (x β) dT is h (x β) a processor of the data the transferee user beta was digitally signed by d T inputs the blind signed data B beta ', the blind factor this r
by dividing by β digital signed policy number h (x β)
dT mod n T is obtained, and the identification part S 1 (x
β ), where S 1 (x β ) = <x β , h (x β ) dT mod n T > Then, the electronic securities right part S 0 and the electronic securities identification part S 1 (x
β ) to generate electronic securities S ( xβ ) S ( xβ ) = <S 0 , S 1 ( xβ )> to complete the transfer procedure of the electronic securities. .

【0032】本願請求項15電子証券の発行、移転、証
明、消去のための処理方法は、発行者の処理装置と、利
用者の処理装置と、中立機関の処理装置とからなる電子
証券の発行、移転、証明、消去のための処理方法であっ
て、電子証券の証明手続において、前記発行者の処理装
置は、電子証券を所有する利用者から電子証券と、その
利用者のみが知り得る証券番号乱数の一部とを取得し、
その電子証券の証券番号と中立機関のみがデジタル署名
し得たデジタル署名済証券番号とからなる電子証券識別
部と、その電子証券の電子証券権利部に含まれているデ
ジタル証明書と、前記証券番号乱数の一部とを前記中立
機関の処理装置に送って所有の証明を要求し、前記中立
機関の処理装置は、前記デジタル証明書を介して前記電
子証券識別部が前記電子証券権利部と一対一対応である
ことの検証計算を行い、前記証券番号乱数の一部と前記
証券番号識別部の証券番号とを用いて前記証券番号の乱
数が電子証券を所有する利用者のみが知り得ることの検
証の計算を行い、前記電子証券識別部を電子証券証明記
録データベースで検索し、検索と検証の結果を前記発行
者の処理装置に返送することを特徴とするものである。
Claim 15 The processing method for issuing, transferring, certifying, and erasing an electronic security is to issue an electronic security comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral organization. , Transfer, certification, erasure, in the certification procedure of the electronic securities, the processing unit of the issuer, the electronic securities from the user who owns the electronic securities, and securities that only the user can know Get a part of the number random number,
An electronic securities identification unit composed of the security number of the electronic security and a digitally signed security number obtained by digital signature only by a neutral organization; a digital certificate included in the electronic security right section of the electronic security; A part of the number random number is sent to the processing unit of the neutral institution to request proof of ownership, and the processing unit of the neutral institution has the electronic securities identification unit and the electronic securities right unit through the digital certificate. Performs a verification calculation of one-to-one correspondence, and uses only a part of the security number random number and the security number of the security number identification unit so that only the user who owns the electronic security can know the random number of the security number. The electronic securities identification unit is searched in the electronic securities certificate record database, and the result of the search and verification is returned to the processing device of the issuer.

【0033】本願請求項16に係る電子証券の発行、移
転、証明、消去のための処理方法は、発行者の処理装置
と、利用者の処理装置と、中立機関の処理装置とからな
る電子証券の発行、移転、証明、消去のための処理方法
であって、電子証券の証明手続において、前記発行者o
の処理装置は、電子証券を所有する利用者Aから電子証
券S(xA)と、利用者Aのみが知り得る証券番号の乱
数の一部yA,idA,cAとを取得し、前記電子証券S
(xA)の電子証券識別部S1(xA)と、前記電子証券
S(xA)の電子証券権利部S0 に含まれているデジタ
ル証明書Cと、前記証券番号乱数の一部yA,idA,c
Aとを中立機関Tの処理装置に送って所有の証明を要求
し、ここで、 S(xA)=<S0,S1(xA)> <>はその内側のデータの集合 S0=<C,D,h(C|D)do mod no> Cはデジタル証明書 Dは権利義務関係の記述 doは発行者の秘密鍵 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)をdoによってデジタル
署名したデータ modnoはnoを法(modulus)とすることを示す C=<nT,eT,h(nT|eT)dp mod np> nT,eTは権利義務内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)をdpによってデジ
タル署名したデータ mod npはnpを法(modulus )とすることを示す S1(xA)=<xA,h(xA)dT mod nT> xAは電子証券を所有する利用者Aが付与した証券番号 dTとnTはそれぞれの中立機関の秘密鍵と公開鍵 h(xA)はxAを変数とするハッシュ関数、 h(xA)dTはh(xA)をdTによってデジタル署名し
たデータ xA=f(yA,zA) yA=f(aA,bA) zA=f(idA,cA) aA,bA,cAは証券番号の乱数 0<aA,bA,cA<2t tは2進数の所定の桁数 idAは利用者Aの特定番号 f()はf(x,y)=f(x′,y′)なるx≠
x′,y≠y′を見つけるのが困難な一方向性ハッシュ
関数 前記中立機関Tの処理装置は、前記識別部S1(xA)
に含まれている証券番号xAからそのハッシュ関数h
(xA)を算出し、前記電子証券識別部S1(xA)に含
まれているデジタル署名された証券番号のハッシュ関数
h(xA)dTをデジタル証明書Cで使用した秘密鍵dT
と対をなす公開鍵eTによって復号してh(xA)
dT・eTを算出し、両者を照合することにより、電子証
券識別部S1(xA)が電子証券権利部S0 と一対一対
応であることを検証し、続いて前記証券番号xAがxA
=f(yA,f(idA,cA))の関係を満たすことを
計算することにより、前記証券番号乱数の一部yA,i
dA,cAがその電子証券を所有する利用者のみが知り得
ることの検証を行い、電子証券証明記録データベースを
検索し、検索と検証の結果を前記発行者oの処理装置に
返送することを特徴とするものである。
A processing method for issuing, transferring, certifying, and erasing electronic securities according to claim 16 of the present application is an electronic security system comprising an issuer processing device, a user processing device, and a neutral institution processing device. Is a processing method for issuing, transferring, certifying, and erasing the electronic securities, in the certification procedure of the electronic securities, the issuer o
Obtains the electronic security S (x A ) from the user A who owns the electronic security, and the random numbers y A , id A , and c A of the security numbers that only the user A can know, The electronic securities S
An electronic securities identification section S 1 of the (x A) (x A) , wherein the digital certificate C contained in the electronic security rights section S 0 of the electronic securities S (x A), a part of the policy number random number y A, id A, c
A is sent to the processing unit of the neutral organization T to request proof of ownership, where S (x A ) = <S 0 , S 1 (x A )><<> is the set of data S 0 inside = <C, D, h ( C | D) do mod n o> C digital certificate D description of the rights and obligations d o is the issuer of the secret key n o is the issuer's public key h (C | D ) is the hash function h (C to variable C and D | is D) do h (C | shows that to D) data was digitally signed by d o modn o is modulo n o (modulus) C = <N T , e T , h (n T | e T ) dp mod n p > n T , e T are the public keys d p , n p specific to the securities corresponding to the rights and obligations, and the private key and the public of the neutral institution digitally signed by the | (e T n T) the d p key h (n T | | e T ) is a hash function h as a variable n T and e T (n T e T) dp is h Data mod n p is S 1 indicating that the n p modulo (modulus) (x A) = <x A, h (x A) dT mod n T> x A is the user A who owns the electronic securities The security numbers d T and n T assigned to the public and private keys of the neutral institution are respectively h (x A ), a hash function using x A as a variable, h (x A ) dT is h (x A ) data digitally signed by T x A = f (y A , z A) y A = f (a A, b A) z A = f (id A, c A) a A, b A, c A is policy number 0 <a A , b A , c A <2 tt is a predetermined number of binary digits id A is a specific number of user A f () is f (x, y) = f (x ′, y ') Becomes x ≠
One-way hash function in which it is difficult to find x ′, y ≠ y ′. The processing device of the neutral organization T includes the identification unit S 1 (x A )
The hash function h from the policy number x A, which is included in the
(X A ) is calculated, and a hash function h (x A ) dT of the digitally signed security number included in the electronic security identification unit S 1 (x A ) is used as a secret key d used in the digital certificate C. T
And decrypted by the public key e T paired with h (x A )
By calculating dT · eT and comparing the two, it is verified that the electronic securities identification unit S 1 (x A ) has a one-to-one correspondence with the electronic securities right unit S 0, and then the security number xA is x A
= F (y A , f (id A , c A )) to calculate a part of the security number random number y A , i
Verify that d A and c A are known only to the user who owns the electronic security, search the electronic security certificate record database, and return the search and verification results to the processing device of the issuer o. It is characterized by the following.

【0034】本願請求項17に係る電子証券の発行、移
転、証明、消去のための処理方法は、発行者の処理装置
と、利用者の処理装置と、中立機関の処理装置とからな
る電子証券の発行、移転、証明、消去のための処理方法
であって、電子証券の消去手続において、前記中立機関
の処理装置は、消去を求められている電子証券の証券番
号と中立機関のみがデジタル署名し得たデジタル署名済
証券番号とからなる電子証券識別部と、その電子証券の
電子証券権利部に含まれているデジタル証明書と、その
電子証券の消去を求める発行者あるいは利用者のみが知
り得る前記証券番号の乱数の一部とを入力し、前記デジ
タル証明書を介して前記電子証券識別部が電子証券権利
部と一対一対応であることの検証計算を行い、前記証券
番号の乱数の一部と前記証券番号識別部の証券番号とを
用いて前記証券番号乱数が電子証券の消去を求めている
発行者あるいは利用者のみが知り得ることの検証の計算
を行い、前記電子証券識別部を電子証券消去記録データ
ベースで検索し、未消去を条件に前記電子証券識別部を
消去済の電子証券識別部として登録することにより、電
子証券の消去手続を完了することを特徴とするものであ
る。
A processing method for issuing, transferring, certifying, and erasing electronic securities according to claim 17 of the present application is an electronic security system comprising an issuer processing device, a user processing device, and a neutral institution processing device. Is a processing method for issuing, transferring, certifying, and erasing an electronic security. In the erasure procedure of the electronic securities, the processing device of the neutral institution only has a digital signature of the security number of the electronic security required to be erased and the neutral institution. Only the electronic securities identification unit consisting of the digitally signed security number obtained, the digital certificate included in the electronic securities rights department of the electronic security, and the issuer or user requesting erasure of the electronic security A part of the random number of the security number to be obtained is input, and a verification calculation is performed to confirm that the electronic security identification unit is in one-to-one correspondence with the electronic security right unit via the digital certificate. part Using the security number of the security number identification unit, a calculation is performed to verify that the security number random number can be known only to the issuer or user who is requesting the erasure of the electronic security, and the electronic security identification unit performs The electronic securities erasure procedure is completed by searching the erasure record database and registering the electronic securities identification section as an erased electronic securities identification section on the condition of non-erasure.

【0035】本願請求項18に係る電子証券の発行、移
転、証明、消去のための処理方法は、発行者の処理装置
と、利用者の処理装置と、中立機関の処理装置とからな
る電子証券の発行、移転、証明、消去のための処理方法
であって、電子証券の消去手続において、前記中立機関
の処理装置は、電子証券の消去を求める発行者あるいは
利用者Bから、消去を求められている電子証券の電子証
券識別部S1(xB)と、その電子証券の電子証券権利
部S0に含まれているデジタル証明書Cと、その電子証
券の消去を求める発行者あるいは利用者Bのみが知り得
る証券番号乱数の一部aB,bB,zBとを取得し、ここ
で、 S(xB)=<S0,S1(xB)> <>はその内側のデータの集合 S0は電子証券権利部 S1(xB)は電子証券識別部 xBは消去を求められている電子証券の証券番号 S0=<C,D,h(C|D)do mod no> Cはデジタル証明書 Dは権利義務関係の記述 doは発行者の秘密鍵 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)をdoによってデジタル
署名したデータ mod noはnoを法(modulus)とすることを示す C=<nT,eT,h(nT|eT)dp mod np> nT,eTは権利義務内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)をdpによってデジ
タル署名したデータ mod npはnpを法(modulus)とすることを示す S1(xB)=<xB,h(xB)dT mod nT> dTとnTはそれぞれの中立機関の秘密鍵と公開鍵 h(xB)はxBを変数とするハッシュ関数、 h(xB)dTはh(xB)をdTによってデジタル署名し
たデータ xB=f(yB,zB) yB=f(aB,bB) zB=f(idB,cB) aB,bB,cBは証券番号の乱数 0<aB,bB,cB<2t tは2進数の所定の桁数 idBは消去を求める発行者、利用者Bの特定番号 f()はf(x,y)=f(x′,y′)なるx≠
x′,y≠y′を見つけるのが困難な一方向性ハッシュ
関数 続いて前記中立機関の処理装置は、前記証券番号xBか
らそのハッシュ関数h(xB)を算出し、前記電子証券
識別部S1(xB)に含まれているデジタル署名された
証券番号のハッシュ関数h(xB)dTをデジタル証明書
Cで使用した秘密鍵dTと対をなす公開鍵eTによって復
号してh(xB)dT・eTを算出し、両者を照合するこ
とにより、電子証券識別部S1(xB)が電子証券権利
部S0と一対一対応であることを検証し、前記証券番号
xBがxB=f(f(aB,bB),zB)の関係を満たす
ことを検証することにより、前記証券番号乱数の一部a
B,bB,zBが電子証券を消去を求める発行者あるいは
利用者Bのみが知り得ることの検証を行い、前記電子証
券識別部S1(xB)を電子証券消去記録データベース
で検索し、未消去を条件に前記電子証券識別部S1(x
B)を消去済の電子証券識別部として登録することによ
り、電子証券の消去手続を完了することを特徴とするも
のである。
A processing method for issuing, transferring, certifying, and erasing electronic securities according to claim 18 of the present application is an electronic security system comprising an issuer processing device, a user processing device, and a neutral institution processing device. Is a processing method for issuing, transferring, certifying, and erasing electronic securities, wherein in the electronic securities erasure procedure, the processing unit of the neutral organization is requested to erase by the issuer or user B requesting the erasure of the electronic securities. The electronic securities identification unit S 1 (x B ) of the electronic security, the digital certificate C included in the electronic securities rights unit S 0 of the electronic security, and the issuer or user requesting erasure of the electronic security A part of security number random numbers a B , b B , and z B that only B can know is obtained, where S (x B ) = <S 0 , S 1 (x B )><> Data set S 0 is the electronic securities rights department S 1 (x B ) is the electronic certificate Ticket identification unit x B securities number S of electronic securities are required to erase 0 = <C, D, h (C | D) do mod n o> C is described d o of the digital certificate D rights and obligations digitally signed by the | (D C) a d o is the public key h of the secret key n o of the issuer the issuer (C | | D) is C and the hash function to the variable D h (C D) do is h data mod n o is n o law (modulus) indicate that the C = <n T, e T , h (n T | e T) dp mod n p> n T, e T in the rights and obligations content The corresponding security-specific public keys d p and n p are the secret key and public key of the neutral institution h (n T | e T ), and the hash function h (n T | e T ) d with n T and e T as variables p is h | S 1 (n T e T) data mod n p which is digitally signed by the d p is shown that the n p modulo (modulus) (x B) = x B, h (x B) dT mod n T> d T and n T is the secret key of each of the neutral institution and the public key h (x B) is a hash function to the variable x B, h (x B) dT data x B = f (y B, z B) of h a (x B) digitally signed by d T is y B = f (a B, b B) z B = f (id B, c B) a B, b B, c B is a random number of policy number 0 <a B, b B, c B <2 t t is a predetermined number of digits id B binary issuer seeking erase specific number f of the user B () Is x ≠ such that f (x, y) = f (x ′, y ′)
A one-way hash function in which it is difficult to find x ′, y ≠ y ′. Subsequently, the processing unit of the neutral organization calculates a hash function h (x B ) from the security number x B and obtains the electronic security identification. The hash function h (x B ) dT of the digitally signed security number included in the part S 1 (x B ) is decrypted by the public key e T paired with the secret key d T used in the digital certificate C. By calculating h (x B ) dT · eT and comparing them, it is verified that the electronic securities identification unit S 1 (x B ) has a one-to-one correspondence with the electronic securities rights unit S 0, and the security number x B is x B = f (f (a B, b B), z B) by verifying that satisfies the relationship, a portion of the policy number random number a
It verifies that B , b B , and z B can be known only to the issuer or user B who wants to erase the electronic security, and searches the electronic security identification unit S 1 (x B ) in the electronic security erasure record database. , On the condition that it has not been erased, the electronic securities identification unit S 1 (x
By registering B ) as the erased electronic securities identification unit, the electronic securities erasure procedure is completed.

【0036】[0036]

【発明の実施の形態】次に、本発明による「電子証券の
発行、移転、証明、消去のための処理システム及びその
処理方法」の実施の形態について以下に説明する。
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS An embodiment of a "processing system for issuing, transferring, certifying and erasing electronic securities and a processing method thereof" according to the present invention will be described below.

【0037】最初に本発明で処理しようとする電子証券
の構成と、その電子証券の発行等を処理するための処理
システムの構成と電子証券の発行、移転、証明、消去の
諸手続について概略説明する。
First, the configuration of an electronic security to be processed by the present invention, the configuration of a processing system for processing the issuance of the electronic security, and various procedures for issuance, transfer, certification, and erasure of the electronic security will be briefly described. I do.

【0038】図1は、本発明で処理しようとする電子証
券の構成を概念的に示したものである。本発明で処理し
ようとする電子証券S(x)は、実体的には一群のデジ
タルデータであるが、概念的には図1に示すように、そ
の電子証券の所有者と発行者の権利と義務を記載した権
利部S0(以下、電子証券権利部S0という)と、その
電子証券を特定する証券番号を記載した識別部S
1(x)(以下、電子証券識別部S1(x)という)と
からなる。xは電子証券の証券番号を表わすものとす
る。
FIG. 1 conceptually shows the structure of an electronic security to be processed in the present invention. The electronic security S (x) to be processed in the present invention is, in substance, a group of digital data, but conceptually, as shown in FIG. The rights section S 0 describing the obligation (hereinafter referred to as the electronic securities rights section S 0 ) and the identification section S describing the security number identifying the electronic security
1 (x) (hereinafter referred to as electronic securities identification unit S 1 (x)). x represents the security number of the electronic security.

【0039】これらの電子証券権利部S0と電子証券識
別部S1(x)はそれぞれ、誰でも読むことができる平
文(暗号化されていないデータをいうものとする)の部
分と、特定の者しか暗号化することができない部分とを
有している。ここで、「特定の者しか暗号化することが
できない部分」とは、特定の者のみが暗号化でき、任意
の第三者は暗号化された部分から暗号化することができ
た者を確認することができる部分をいう。なお、このよ
うな暗号化した者を第三者が確認することができる暗号
化処理を、「デジタル署名」という。
Each of the electronic securities right section S 0 and the electronic securities identification section S 1 (x) includes a plaintext (which means unencrypted data) that can be read by anyone and a specific section. And a part that can only be encrypted by a third party. Here, "the part that only a specific person can encrypt" means that only a specific person can encrypt, and any third party confirms the person who was able to encrypt from the encrypted part The part that can be done. It should be noted that an encryption process in which a third party can confirm such an encrypted person is called “digital signature”.

【0040】本願発明で取扱う電子証券は、誰でも読む
ことができる権利義務関係の記述と証券番号と、それら
の特定の者によるデジタル署名とを含むのである。
The electronic securities handled in the present invention include a statement of rights and obligations that can be read by anyone, a security number, and a digital signature by those specific persons.

【0041】具体的には、電子証券権利部S0は、電子
証券発行者と所持者の権利義務関係を記載した平文の記
述Dと、所定の中立機関のみがデジタル署名し得るデジ
タル証明書Cと、デジタル証明書Cと権利義務関係の記
述Dの発行者による暗号化データh(C|D)do mo
d noとからなる。
[0041] Specifically, the electronic securities right portion S 0 is a description D plaintext describing the holder of the rights and obligations associated with electronic issuers, digital certificates only predetermined neutral institution may digitally sign C And encrypted data h (C | D) do mo by the issuer of digital certificate C and description D of rights and obligations relationship
consisting of a d n o.

【0042】デジタル証明書Cは、電子証券の発行の要
求に応じて中立機関が公開鍵nT,eTと秘密鍵pT,
qT,dTを生成し、その公開鍵nT,eTを中立機関に固
有の秘密鍵dpによってデジタル署名したものである。
h(C|D)はCとDを変数とするハッシュ関数、つま
りデータ圧縮関数であり、h(C|D)doはh(C|
D)を発行者が発行者の秘密鍵d0によってデジタル署
名したものである。なお、mod noはh(C|D)
doが発行者の公開鍵noを法(modulus)とする
ことを示すものである。公開鍵、秘密鍵、デジタル署名
した者の確認の方法等については後に説明する。
The digital certificate C is provided by a neutral authority to the public key n T , e T and the private key p T , in response to a request for issuance of electronic securities.
q T and d T are generated, and the public keys n T and e T are digitally signed with a secret key d p unique to a neutral organization.
h (C | D) is a hash function using C and D as variables, that is, a data compression function, and h (C | D) do is h (C |
D) the issuer is one that has been digitally signed by the secret key d 0 of the issuer. It should be noted, mod n o are h (C | D)
do is an indication that the public key n o of the issuer with the law (modulus). A public key, a secret key, a method of confirming a person who has digitally signed, and the like will be described later.

【0043】電子証券識別部S1(x)は、平文の電子
証券番号xと、中立機関のみがデジタル署名し得る証券
番号xの暗号化データh(x)dT mod nTとか
らなる。
The electronic security identification unit S 1 (x) includes a plaintext electronic security number x and encrypted data h (x) dT mod n T of the security number x that can be digitally signed only by a neutral organization.

【0044】ここで、デジタル署名により、任意の第3
者が「中立機関のみがデジタル署名し得る…」や「発行
者のみがデジタル署名し得る…」こと等を確認できる仕
組みを概略説明しておく。
Here, the arbitrary third
A mechanism by which a person can confirm that "only a neutral organization can digitally sign ..." or "only an issuer can digitally sign ..." will be outlined.

【0045】大きな(たとえば512bit程度)2つ
の素数p,qを選び、その積をn=p・qとする。一
方、nのオイラー数φ(n)=(p−1))(q−1)
と互いに素子ある数eを、下式(1)の関係を満たす数
dを一意に定めることができる。
Two large (for example, about 512 bits) prime numbers p and q are selected, and the product is n = p · q. On the other hand, Euler number φ (n) of n = (p−1)) (q−1)
And a number e that is a mutual element, and a number d that satisfies the relationship of the following equation (1) can be uniquely determined.

【0046】[0046]

【数1】 ここで、e,nをデジタル署名をする者の公開鍵、d,
p,qをデジタル署名をする者の秘密鍵とすると、下記
のようにして任意の第三者がデジタル署名をした者の確
認をすることができる。
(Equation 1) Here, e and n are public keys of a person who performs digital signature, d and
Assuming that p and q are private keys of a person who performs digital signature, an arbitrary third party can confirm a person who has performed digital signature as follows.

【0047】なお公開鍵は、デジタル署名をする者が世
間に公開し、任意の第三者がその公開鍵がデジタル署名
をする者のものであることを知っている数である。秘密
鍵は、デジタル署名をする者のみが知っている数であ
る。公開鍵から秘密鍵を割り出すことは計算量的に一般
に不可能である。つまり、デジタル署名をする者が自ら
秘密鍵を他人に教えない限り、第三者はデジタル署名を
する者の秘密鍵を知り得ない。
The public key is a number that is publicly disclosed by a person who performs digital signature, and that an arbitrary third party knows that the public key belongs to a person who performs digital signature. The secret key is a number known only to the person signing the digital signature. Deriving a private key from a public key is generally computationally infeasible. That is, unless the person signing the digital signature gives his / her private key to another person, the third party cannot know the secret key of the person signing the digital signature.

【0048】今、秘密鍵dによってデジタル署名された
データをZとし、デジタル署名をする前の平文のデータ
をXとすると、デジタル署名されたデータZは下式
(7)のようになる。
Now, assuming that the data digitally signed by the secret key d is Z and the plaintext data before the digital signature is X, the digitally signed data Z is given by the following equation (7).

【0049】 Z=Xdmod n …(7) 第三者が、上記暗号化データZのデジタル署名をした者
を確認するには、デジタル署名した者の公開鍵eを用い
て暗号化データZをe乗すればよい。式(6),(7)
の関係から、
Z = X d mod n (7) In order for a third party to confirm a person who has digitally signed the encrypted data Z, the encrypted data Z can be identified using the public key e of the digitally signed person. May be raised to the power of e. Equations (6) and (7)
From the relationship,

【数2】 これにより、暗号化データZから平文のXを得ることが
できる。また、公開鍵eに対応する秘密鍵は唯一dのみ
であり、秘密鍵dはデジタル署名をした者のみが知るこ
とができるので、デジタル署名をした者は確かに公開鍵
eを公表した者であることを確認することができるので
ある。なお、上記デジタル署名者の確認は第三者に限ら
ず、デジタル署名をした者自身も自らの公開鍵eを用い
て暗号化データZが確かに自分がデジタル署名したもの
であることを確認することができる。
(Equation 2) Thus, plaintext X can be obtained from the encrypted data Z. In addition, the only private key corresponding to the public key e is d, and the private key d can be known only by the person who has digitally signed the digital key. You can be sure that there is. It should be noted that the digital signer is not limited to a third party, and that the digital signer himself uses his / her own public key e to confirm that the encrypted data Z is indeed the digital signature. be able to.

【0050】上記デジタル署名とデジタル署名者の確認
の方法を上記電子証券権利部S0に適用すると、任意の
第三者は電子証券権利部S0を記述したのが発行者であ
ること、およびデジタル証明書Cが中立機関によってデ
ジタル署名されたものであることを確認することができ
る。
When the digital signature and the method of confirming the digital signer are applied to the electronic securities right section S 0 , an arbitrary third party describes the electronic securities right section S 0 as the issuer, and It can be confirmed that the digital certificate C is digitally signed by a neutral organization.

【0051】すなわち、任意の第三者は、発行者の公開
鍵eoを用いて電子証券権利部S0のh(C|D)do
をeo乗することにより、 h(C|D)=h(C|D)do・eo となって、h(C|D)を得ることができる。このh
(C|D)と、電子証券権利部S0の平文のC,Dのハ
ッシング(ハッシュ関数hを適用)したものとを比較す
ることにより、一致すれば電子証券権利部S0が確かに
発行者によってデジタル署名されたものであることを確
認することができる。
That is, an arbitrary third party uses the issuer's public key eo to obtain h (C | D) d o of the electronic securities right unit S 0.
Is raised to the power eo , h (C | D) = h (C | D) do · eo, and h (C | D) can be obtained. This h
And | (C D), the plain text electronic securities right portion S 0 C, by comparing to that D hashing (applying a hash function h), indeed issued ECN right portion S 0 if they match It can be confirmed that the digital signature has been obtained by a person.

【0052】また、同様の方法により、電子証券権利部
S0に含まれているデジタル証明書が確かに中立機関が
その電子証券S(x)に付与したものであることを確認
することができる。
[0052] In addition, in the same manner, the electronic securities right part digital certificate is certainly a neutral institution that is included in the S 0 can be sure they are granted to the electronic securities S (x) .

【0053】上記デジタル署名とデジタル署名者の確認
の方法を上記電子証券識別部S1(x)に適用すれば、
その電子証券番号xが中立機関によってデジタル署名さ
れたものであることを確認することができる。すなわ
ち、第三者は、中立機関の公開鍵eTを用いて電子証券
識別部S1(x)のh(x)dTをeT乗することによ
り、 h(x)=h(x)dT・eT となって、h(x)を得ることができる。このh(x)
と、電子証券識別部S1(x)の平文のxのハッシング
したものとを比較することにより、電子証券番号xが確
かに中立機関によってデジタル署名されたものであるこ
とを確認することができるのである。
If the method of confirming the digital signature and the digital signer is applied to the electronic securities identification unit S 1 (x),
It can be confirmed that the electronic security number x is digitally signed by a neutral organization. That is, the third party raises h (x) dT of the electronic securities identification unit S 1 (x) to the power of e T using the public key e T of the neutral institution, so that h (x) = h (x) dT -It becomes eT and h (x) can be obtained. This h (x)
And the hashed version of the plaintext x of the electronic security identification unit S 1 (x), it can be confirmed that the electronic security number x is indeed a digital signature by a neutral organization. It is.

【0054】本発明による電子証券は、所有者が変更さ
れるごとに電子証券番号xが現実の所有者の唯一専用の
電子証券番号に変更される。この電子証券番号が現実の
所有者のみが生成し得ることを確認できることにより、
その者がその電子証券の正当な所有者であることを確認
することができる。また、前記電子証券番号と電子証券
権利部S0とが、同一の中立機関の秘密鍵dTによって
デジタル署名されたことを確認できることにより、電子
証券権利部S0と電子証券識別部S1(x)とが一対一
対応であるが保証される。このことが本発明による電子
証券の利用を可能にする原理となっている。具体的な処
理方法については、後に詳細に説明する。
In the electronic security according to the present invention, each time the owner is changed, the electronic security number x is changed to the actual owner's only dedicated electronic security number. By being able to verify that this electronic security number can only be generated by the real owner,
It is possible to confirm that the person is a valid owner of the electronic securities. In addition, since it is possible to confirm that the electronic securities number and the electronic securities right section S 0 have been digitally signed with the secret key d T of the same neutral organization, the electronic securities right section S 0 and the electronic securities identification section S 1 ( x) is guaranteed one-to-one. This is the principle by which the electronic securities according to the present invention can be used. A specific processing method will be described later in detail.

【0055】なお、電子証券権利部S0と電子証券識別
部S1(x)は、分離して使用できる。このことは、上
記現実の所有者が唯一専用の電子証券番号を所有するた
めの処理を可能にしている。
[0055] The electronic securities right part S 0 and the electronic securities identification unit S 1 (x) can be used in isolation. This allows the real owner to have a unique electronic securities number.

【0056】図2は本発明による電子証券の発行等を処
理するための処理システムの構成と電子証券の発行、移
転、証明、消去の諸手続の主要な処理の流れを示したも
のである。
FIG. 2 shows the configuration of a processing system for processing issuance of electronic securities according to the present invention and the flow of main processing of various procedures for issuing, transferring, certifying, and erasing electronic securities.

【0057】図2に示すように、本発明による電子証券
のための処理システムは、発行者oの処理装置、利用者
(α,β,A,B,…)の処理装置、中立機関Tの処理
装置とからなる。発行者oとは電子証券を発行し、電子
証券を所有する者に対して所定の義務を負う者をいう。
株券で言えば会社がこれに相当する。利用者とは、電子
証券を移転したり、権利行使したり、消去したりする者
をいう。なお、発行者も電子証券を移転、証明、消去す
ることがあるので、利用者は場合によっては発行者を含
む。中立機関Tとは電子証券の発行、移転、証明、消去
の諸処理に際し、電子証券の正当性を保証するための第
三者をいう。発行者oの処理装置、利用者(α,β,
A,B,…)の処理装置、中立機関Tの処理装置は、好
ましくは発行者o、利用者(α,β,A,B,…)、中
立機関T所有のコンピュータからなり、通信ネットワー
クを介して通信可能に接続されているものとする。これ
らの処理装置は、電子証券の発行、移転、証明、消去の
諸手続において相互に関連して処理が行う。なお、図2
において破線の矢印は電子証券の発生から消滅までの経
過を示したものである。また、発行、移転、証明、消去
の諸手続の各処理過程の末尾にカッコを付して示した符
号(T,o,A,B,…)は処理を行う装置を示すもの
である。
As shown in FIG. 2, the processing system for electronic securities according to the present invention includes a processing device of the issuer o, a processing device of the user (α, β, A, B,...) And a processing device of the neutral organization T. And a processing device. The issuer o is a person who issues electronic securities and has a predetermined obligation to a person who owns the electronic securities.
In terms of stock certificates, companies are the equivalent. A user is a person who transfers, exercises, or deletes electronic securities. In some cases, the issuer also includes the issuer because the issuer may transfer, certify, or delete the electronic securities. The neutral institution T is a third party for guaranteeing the legitimacy of electronic securities when issuing, transferring, certifying, and erasing electronic securities. Issuer o's processing device, user (α, β,
A, B,...), And the processing unit of the neutral institution T preferably comprise a publisher o, a user (α, β, A, B,...), And a computer owned by the neutral institution T. It is assumed that they are connected so as to be able to communicate with each other. These processing devices are associated with each other in various procedures for issuing, transferring, certifying, and erasing electronic securities. Note that FIG.
, The broken arrow indicates the progress from the generation of electronic securities to their disappearance. Reference numerals (T, o, A, B,...) With parentheses at the end of the processing steps of various procedures such as issuance, transfer, certification, and erasure indicate the processing apparatus.

【0058】以下、電子証券の発行、移転、証明、消去
の諸手続について説明する。
Hereinafter, various procedures for issuing, transferring, certifying, and erasing electronic securities will be described.

【0059】発行手続は、電子証券を発生する手続であ
る。電子証券は、発行する者がその電子証券を所有する
者に対する義務、逆に言うとその電子証券を所有する者
の権利の内容(本明細書ではこれらをまとめて権利義務
関係の記述という)を記載し、発行される。本発明の電
子証券の発行手続は、発行者oの処理装置と中立機関T
の処理装置の連関した処理によって処理される。発行手
続においては、中立機関Tの処理装置により、発行対象
の電子証券が中立機関Tの承認の下に発行されたことを
示すデジタル証明書が付与される。一方で発行者oによ
って電子証券番号が作成され、この電子証券番号に対し
て電子証券番号の内容を秘匿したまま中立機関によって
デジタル署名がされる(この処理をブラインド署名とい
う)。このブラインド署名された電子証券番号は発行者
oの処理装置によってデジタル署名された電子証券番号
に復元される(この処理をアンブラインド処理とい
う)。最後に、上記デジタル証明書とブラインド署名さ
れた電子証券番号と電子証券の権利義務関係の記述が組
み合わされ、電子証券が発行される。
The issuance procedure is a procedure for issuing an electronic security. The issuer of the electronic securities states the issuer's obligations to the owner of the electronic securities, or conversely, the content of the rights of the owner of the electronic securities (in this specification, these are collectively referred to as a statement of rights and obligations). Described and issued. The electronic securities issuance procedure of the present invention is performed by the processing device of the issuer o and the
Is processed by the associated processing of the processing device. In the issuance procedure, a digital certificate indicating that the electronic security to be issued has been issued under the approval of the neutral institution T is given by the processing device of the neutral institution T. On the other hand, an electronic securities number is created by the issuer o, and a digital signature is given to the electronic security number by a neutral organization while keeping the contents of the electronic security number confidential (this processing is called a blind signature). The blindly signed electronic security number is restored to the digitally signed electronic security number by the processing device of the issuer o (this processing is referred to as unblind processing). Finally, the digital certificate, the blindly signed electronic security number, and the description of the rights and obligations of the electronic security are combined, and the electronic security is issued.

【0060】上記発行手続の注目すべき点は、中立機関
が電子証券権利部S0と電子証券番号(広い意味では電
子証券識別部S1(x))とが一対一対応であること
を、電子証券番号の内容を知らずに保証し、かつ第三者
が上記一対一対応を中立機関が保証していることを確認
できるようにしている点である。
It should be noted that the above issuance procedure is based on the fact that the neutral institution has a one-to-one correspondence between the electronic securities right section S 0 and the electronic securities number (in a broad sense, the electronic securities identification section S 1 (x)). The point is that the content of the electronic securities number is guaranteed without knowing it, and that a third party can confirm that the neutral organization guarantees the above-mentioned one-to-one correspondence.

【0061】移転手続は、電子証券の所有権を変更する
手続である。電子証券は発行者に所定の要求をすること
ができる権利であるため、それ自体財産的価値を有し、
複数の者の間で譲渡、移転されるものである。移転手続
はその電子証券が二重に移転されていないことを保証し
つつ権利者を変更する手続でなければならない。本発明
の移転手続は、移転を受ける者β(被移転利用者βとい
う)の処理装置と、移転をする者α(移転利用者αとい
う)の処理装置と、中立機関Tの処理装置との間で処理
される。
The transfer procedure is a procedure for changing the ownership of electronic securities. Electronic securities have the property value of their own because they have the right to make certain requests to the issuer,
It is transferred and transferred between multiple persons. The transfer procedure must be a procedure to change the right holder while ensuring that the electronic security has not been transferred twice. The transfer procedure according to the present invention includes a processing device for a person β to be transferred (referred to as a transferred user β), a processing device for a person α to be transferred (referred to as a transferred user α), and a processing device for a neutral organization T. Processed between.

【0062】被移転利用者βは、移転利用者αから電子
証券のデータと移転前の電子証券番号を算出する乱数の
一部とを入手する一方、移転後の新たな電子証券番号を
生成する。さらに、被移転利用者βの処理装置は、その
新たな電子証券番号の内容を秘匿したブラインド署名用
データを生成し、そのブラインド署名用データと、移転
前の電子証券識別部と、電子証券権利部に含まれている
デジタル証明書と、移転前の電子証券番号を算出する乱
数の一部とを中立機関Tに送る。中立機関Tの処理装置
は、前記デジタル証明書によって移転される電子証券の
電子証券権利部と電子証券識別部とが一対一対応の関係
にあることを確認する。また、中立機関Tの処理装置
は、移転前の電子証券番号の乱数の一部によってその移
転が移転利用者αの合意の下に行われていることを検証
する。さらに、移転される電子証券が二重に移転を行っ
ていないことを検証する。この結果、この電子証券の移
転全体が正当であれば、中立機関Tの処理装置は、被移
転利用者βが作成した新しい電子証券番号をブラインド
署名する。これにより、電子証券に中立機関によってデ
ジタル署名された新しい電子証券番号が付与されるとと
もに、移転前の電子証券番号を有する電子証券識別部は
移転済電子証券識別部として記録される。
The transferee β obtains the electronic security data and a part of the random number for calculating the electronic security number before the transfer from the transfer user α, and generates a new electronic security number after the transfer. . Further, the processing device of the transferred user β generates blind signature data in which the contents of the new electronic security number are concealed, and the blind signature data, the electronic security identification unit before the transfer, The digital certificate included in the section and a part of the random number for calculating the electronic security number before transfer are sent to the neutral organization T. The processing device of the neutral institution T confirms that the electronic securities right part and the electronic securities identification part of the electronic securities transferred by the digital certificate have a one-to-one correspondence. In addition, the processing device of the neutral institution T verifies that the transfer is performed under the agreement of the transfer user α by using a part of the random number of the electronic security number before the transfer. In addition, it verifies that the electronic securities to be transferred do not make double transfers. As a result, if the entire transfer of the electronic security is valid, the processing device of the neutral institution T blind-signs the new electronic security number created by the transferred user β. As a result, a new electronic security number digitally signed by a neutral organization is given to the electronic security, and the electronic security identification unit having the electronic security number before transfer is recorded as the transferred electronic security identification unit.

【0063】上記移転手続の処理の注目すべき点は、中
立機関が移転される電子証券の電子証券権利部と電子証
券識別部とが一対一対応であること、移転される電子証
券が二重に移転されていないこと、移転が移転利用者の
合意の下に行われていること、を移転後の新たな電子証
券番号の内容を知らずに保証していることである。これ
により、特定の番号の電子証券がどの番号の電子証券と
して移転されたかということを中立機関でさえ知らない
のである。すなわち、電子証券の移転経路が知られるこ
となく、取引のプライバシーが保持され、電子証券の財
産としての活用の途が広く確保されるのである。
It should be noted that the above-mentioned transfer procedure is performed in such a manner that a neutral institution has a one-to-one correspondence between the electronic securities right section and the electronic securities identification section of the electronic securities to be transferred, and that the electronic securities to be transferred are duplicated. Guaranteeing that the transfer has not been made and that the transfer has been made under the agreement of the transfer user without knowing the contents of the new electronic security number after the transfer. Thus, even a neutral institution does not know what number of electronic securities was transferred as electronic securities. That is, the privacy of the transaction is maintained without knowing the transfer route of the electronic securities, and the way of using the electronic securities as property is widely secured.

【0064】証明手続は、電子証券の所有者が自分がそ
の電子証券の正当な所有者であることを第三者に証明し
てもらう手続である。たとえば株券のように所有者が自
分が当該株券の所有者であることを主張し、発行者に配
当を求めることがある。証明手続はこのような場合に、
配当を求める者がその株券の正当な所有者であることを
第三者に証明してもらう手続である。
The certification procedure is a procedure in which the owner of the electronic security has a third party prove that he / she is a valid owner of the electronic security. For example, as in the case of a stock certificate, the owner may claim that he / she is the owner of the stock certificate and ask the issuer for a dividend. In such a case, the certification procedure
This is a procedure to have a third party prove that the person seeking the dividend is the legitimate owner of the stock.

【0065】本発明の証明手続は、所有の証明をしよう
とする利用者(電子証券の所有者)が、証明の要求と所
定のデータとを発行者oの処理装置に送り、発行者oの
処理装置が中立機関Tに依頼し、その電子証券の所有者
が正当な所有者であることを証明してもらうことで処理
される。
In the certifying procedure of the present invention, a user (owner of electronic securities) who intends to certify the ownership sends a certification request and predetermined data to the processing device of the issuer o, and The processing is performed by requesting the neutral institution T to have the proof that the owner of the electronic securities is a valid owner.

【0066】この場合、中立機関の処理装置は証明しよ
うとする電子証券の電子証券識別部と、デジタル証明書
Cと、電子証券の所有者のみが知り得るその電子証券の
証券番号を算出する乱数の一部とを入力し、デジタル証
明書Cのデジタル署名に使用した秘密鍵によって所有証
明をしようとする電子証券の電子証券権利部と電子証券
識別部とが一対一対応であることを確認する。また、中
立機関の処理装置は、電子証券の証券番号を算出する乱
数の一部から、その電子証券の証券番号が確かに電子証
券の所有者のみが知り得る隠数によって構成されている
こと、すなわちその電子証券の所有者が正当な所有者で
あることを確認する。さらに中立機関の処理装置は、そ
の電子証券の移動手続の履歴を検索し、移転済の証券に
対する所有証明を求めるものでないことを確認する。こ
の結果、この電子証券の所有証明手続全体が正当であれ
ば、中立機関Tの処理装置は、その結果を発行者oの処
理装置に送る。
In this case, the processing unit of the neutral institution has a digital certificate identification section of the digital certificate to be certified, a digital certificate C, and a random number for calculating the certificate number of the digital certificate which can be known only by the holder of the digital certificate. And confirm that there is a one-to-one correspondence between the electronic securities right unit and the electronic securities identification unit of the electronic security whose ownership is to be proofed using the private key used for the digital signature of the digital certificate C. . In addition, the processing device of the neutral institution, from a part of the random number to calculate the security number of the electronic security, that the security number of the electronic security is indeed constituted by a hidden number that only the owner of the electronic security can know, That is, it confirms that the owner of the electronic security is a valid owner. Further, the processing device of the neutral institution searches the history of the transfer procedure of the electronic security and confirms that it does not request a certificate of ownership for the transferred security. As a result, if the entire procedure for certifying ownership of the electronic security is valid, the processing device of the neutral institution T sends the result to the processing device of the issuer o.

【0067】上記証明手続の注目すべき点は、電子証券
の所有者が提供した電子証券番号算出用の乱数の一部に
よってその電子証券の所有者が正当な所有者であること
を検証することができることと、その電子証券番号算出
用の乱数の一部を入手した者が、その乱数を悪用して他
の手続を行うことができないことである。この仕組みに
ついては後にさらに説明する。
The notable point of the above certification procedure is to verify that the owner of the electronic security is a valid owner by using a part of the random number for calculating the electronic security number provided by the owner of the electronic security. And that a person who has obtained a part of the random number for calculating the electronic securities number cannot perform another procedure by misusing the random number. This mechanism will be further described later.

【0068】消去手続は、電子証券の所有者が電子証券
を消去してそれ以降の第三者による権利行使を防止する
手続である。
The erasure procedure is a procedure in which the owner of the electronic securities erases the electronic securities to prevent the third party from exercising the rights thereafter.

【0069】本発明の消去手続は、消去を求める利用者
(その電子証券の発行者を含む)が、消去の要求と所定
のデータとを中立機関Tの処理装置に送り、中立機関T
の処理装置が消去を求める利用者がその電子証券の正当
な所有者であることを確認して代わりに新証券番号の発
行を求めずにその電子証券を消去することで処理され
る。
In the erasure procedure of the present invention, a user requesting erasure (including the issuer of the electronic security) sends an erasure request and predetermined data to a processing unit of the neutral institution T, and the neutral institution T
Is processed by confirming that the user requesting the erasure is the legitimate owner of the electronic security and instead erasing the electronic security without requesting the issuance of a new security number.

【0070】この場合、中立機関Tの処理装置は、消去
を求める利用者から、消去しようとする電子証券の電子
証券識別部と、その電子証券の電子証券権利部に含まれ
ているデジタル証明書Cと、その電子証券の正当な所有
者のみが知り得る証券番号算出用の乱数の一部とを入力
し、デジタル証明書Cのデジタル署名に使用した秘密鍵
によって消去をしようとする電子証券の電子証券権利部
と電子証券識別部とが一対一対応であることを確認す
る。また、中立機関の処理装置は、電子証券の証券番号
を算出する乱数の一部から、その電子証券の証券番号が
確かに電子証券の所有者のみが知り得ること、すなわち
その電子証券の消去を求める者が正当な電子証券の所有
者であることを確認する。さらに中立機関の処理装置
は、その電子証券の移転記録を検索し、移転済の証券に
対応する消去を求めるものでないことを確認する。この
結果、この電子証券の消去手続全体が正当であれば、中
立機関Tの処理装置は、その電子証券の電子証券識別部
を消去済電子証券識別部として登録することにより、そ
の電子証券の以降の使用を防止する。
In this case, the processing unit of the neutral institution T sends, from the user who requests the erasure, the electronic certificate identification part of the electronic security to be erased and the digital certificate included in the electronic security right part of the electronic security. C and a part of the random number for calculating the security number which can be known only by the authorized owner of the electronic security, and the electronic security to be erased by the secret key used for the digital signature of the digital certificate C. It is confirmed that the electronic securities right section and the electronic securities identification section have a one-to-one correspondence. In addition, the processing unit of the neutral institution confirms that only the owner of the electronic security can know the security number of the electronic security from a part of the random number for calculating the security number of the electronic security, that is, the erasure of the electronic security. Make sure the person you are looking for is a legitimate electronic securities owner. Further, the processing unit of the neutral institution searches the transfer record of the electronic security to confirm that the electronic security does not request the erasure corresponding to the transferred security. As a result, if the entire erasure procedure of the electronic security is valid, the processing device of the neutral institution T registers the electronic security identification unit of the electronic security as an erased electronic security identification unit, and thereafter, the subsequent processing of the electronic security is performed. Prevent the use of.

【0071】上記消去手続の注目すべき点は、電子証券
の消去を求める者が提供した電子証券番号算出用の乱数
の一部によってその者がその電子証券の正当な所有者で
あることを検証することができることと、その電子証券
番号算出用の乱数の一部を入手した者が、その乱数を悪
用して他の手続を行うことができないことである。この
仕組みについては後にさらに説明する。
The point of note in the above erasure procedure is that a part of the random number for calculating the electronic security number provided by the person requesting the erasure of the electronic security verifies that the individual is a valid owner of the electronic security. And that a person who has obtained a part of the random number for calculating the electronic security number cannot perform another procedure by misusing the random number. This mechanism will be further described later.

【0072】以上が本発明による電子証券と、電子証券
の処理システムの構成と、電子証券の発行、移転、証
明、消去の諸手続の概略の説明であったが、以下に電子
証券の発行、移転、証明、消去の各手続の具体的なデー
タ処理について詳細に説明する。
The above is a brief description of the electronic securities according to the present invention, the configuration of the electronic securities processing system, and various procedures for issuing, transferring, certifying, and erasing the electronic securities. The detailed data processing of the transfer, certification, and erasure procedures will be described in detail.

【0073】図3は、本発明の処理システムによる電子
証券の発行手続の処理の流れを示している。
FIG. 3 shows the flow of processing for issuing an electronic security by the processing system of the present invention.

【0074】本実施形態の処理システムによる電子証券
の発行手続では、最初に電子証券を発行しようとする発
行者oの処理装置が中立機関Tの処理装置に電子証券発
行の要求を送信する(ステップS100)。この発行者
oの処理装置から要求を受けて、中立機関Tの処理装置
は新たに発行される電子証券ごとにRSA系の鍵nT,
eT,pT,qT,dTを生成する。ここで、nT,eTは権
利義務内容に対応する証券固有の公開鍵、pT,qT,d
Tは同秘密鍵であって、既に説明した式(1)ないし式
(8)の関係を満たす。これらのRSA系の鍵nT,
eT,pT,qT,dTを生成した後、中立機関Tの処理装
置は公開鍵nT,eTを中立機関に固有の秘密鍵dTデジ
タル署名したデジタル証明書Cを生成し(ステップS1
10)、発行者oの処理装置に返送する。
In the issuing procedure of the electronic securities by the processing system of the present embodiment, the processing device of the issuer o who first wants to issue the electronic securities transmits a request for the issuance of the electronic securities to the processing device of the neutral institution T (step). S100). In response to the request from the processing device of the issuer o, the processing device of the neutral institution T transmits the RSA key n T ,
Generate e T , p T , q T , and d T. Here, n T and e T are public keys unique to the security corresponding to the rights and obligations, and p T , q T and d.
T is the same secret key, and satisfies the relations of equations (1) to (8) described above. These RSA keys n T ,
After generating e T , p T , q T , and d T , the processing unit of the neutral authority T generates a digital certificate C in which the public keys n T and e T are digitally signed with a secret key d T unique to the neutral authority. (Step S1
10) Return to the processing device of issuer o.

【0075】ここで、 C=<nT,eT,h(nT|eT)dp mod np> < >はその内側のデータの集合 nT,eTは権利義務内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)d pはh(nT|eT)を秘密鍵dpによって
デジタル署名したデータ mod nTはnTを法(modulus)とすることを
示す。
Here, C = <n T , e T , h (n T | e T ) dp mod n p ><> is a set of data n T , e T inside it is a security corresponding to the rights and obligations The unique public key d p , n p is a secret key and a public key of a neutral organization h (n T | e T ) is a hash function h (n T | e T ) d p is a variable with n T and e T as variables (n T | e T) data mod n T which is digitally signed by the private key d p indicates that the n T modulo (modulus).

【0076】ハッシュ関数h( )は、データ圧縮関数
であって、非圧縮データから圧縮データを生成するのは
容易であるが、圧縮データから非圧縮データを復元する
のは困難な一方向性の関数である。
The hash function h () is a data compression function, and it is easy to generate compressed data from uncompressed data, but it is difficult to recover uncompressed data from compressed data. Function.

【0077】次に、発行者oの処理装置は上記電子証明
書Cを入力し、これと電子証券の権利義務関係の記述D
とを一体化して電子証券権利部S0を生成する(ステッ
プS120)。
Next, the processing device of the issuer o inputs the digital certificate C and a description D of the rights and obligations of the digital certificate.
By integrating preparative generates electronic securities right portion S 0 (step S120).

【0078】ここで、 S0=<C,D,h(C|D)do mod no> doは発行者の秘密鍵 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数,
“|”は連結を示す h(C|D)doはh(C|D)を秘密鍵doによってデ
ジタル署名したデータ mod noはnoを法(modulus)とすることを示す 上記電子証券権利部S0は、後に任意の第三者がh(C
|D)doを公開鍵eoを用いてh(C|D)doをe
o乗してh(C|D)を得、 h(C|D)do・eo=h(C|D) …(10) 一方、電子証券権利部S0に含まれているC,Dとハッ
シュ関数h()とを用いてh(C|D)を計算すること
ができる。
[0078] In this case, S 0 = <C, D , h (C | D) do mod no> d o is the secret key n o of the issuer is the issuer of the public key h (C | D) is C and D A hash function with
"|" H indicating the concatenation (C | D) do the h (C | D) data mod digitally signed by the private key d o n o is the electronic securities indicating that the n o modulo (modulus) right portion S 0 is, any third party to later h (C
| D) d o a using the public key e o h (C | D) d o a e
o ride to h | give a (C D), h (C | D) do · eo = h (C | D) ... (10) On the other hand, C, which is included in the electronic securities right portion S 0, and D H (C | D) can be calculated using the hash function h ().

【0079】 C,D,h() → h(C|D) …(11) 上記式(10)と式(11)の結果が一致すれば、公開
鍵eoと秘密鍵doは一対一の関係であり、かつ、秘密
鍵doは発行者oだけが知り得るので、この電子証券権
利部S0は確かに発行者oのみが作成し得るものであ
り、かつ、その電子証券権利部S0は電子証明書Cと一
対一の関係にあることを確認することができる。
[0079] C, D, h () → h (C | D) ... (11) If the above formula (10) and the result of the expression (11) is a match, the public key e o and the private key d o is one-to-one is a relationship, and, since only the private key d o is the issuer o may know, this electronic securities right portion S 0 is intended only certainly the issuer o can be created, and, the electronic securities right part It can be confirmed that S 0 has a one-to-one relationship with the digital certificate C.

【0080】次に、発行者oの処理装置は証券番号の乱
数a,b,c(0<a,b,c<2t、tは2進数の所
定の桁数)と、ブラインド係数r(0<r<2t、tは
2進数の所定の桁数)とを生成し、発行者oの特定番号
idを用いて証券番号xを算出し、さらに証券番号xを
前記ブラインド係数rによって秘匿したブラインド署名
用データBを算出し、ブラインド署名用データBと電子
証明書Cと電子証券権利部S0とを中立機関Tの処理装
置に送信する(ステップS130)。
Next, the processing device of the issuer o checks the random numbers a, b, c (0 <a, b, c <2 t , t is a predetermined number of binary digits) of the security number, and the blind coefficient r ( 0 <r <2 t , where t is a predetermined number of binary digits), the security number x is calculated using the specific number id of the issuer o, and the security number x is concealed by the blind coefficient r. and it was calculated blind signature data B, and transmits the blind signature data B and the electronic certificate C and ECN right portion S 0 to the processing apparatus of NSO T (step S130).

【0081】ここで、証券番号xとその乱数a,b,c
は下記の関係を満たす。
Here, the security number x and its random numbers a, b, c
Satisfies the following relationship.

【0082】x=f(y,z) y=f(a,b) z=f(id,c) xは0<x<2t、tは2進数の所定の桁数、f( )
はハッシュ関数を示し、 また、ブラインド署名用データBは、 B=reTh(x)modnT h(x)はxを変数とするハッシュ関数 mod nTはnTを法(modulus)とすることを示す 中立機関Tの処理装置は、発行者oの処理装置から送信
された電子証明書Cと電子証券権利部S0を電子証券発
行記録データベース10で検索し、電子証明書Cが他の
電子証券権利部に使用されていないことを条件に、電子
証明書Cと電子証券権利部S0を組として電子証券発行
記録データベース10に登録する(ステップS14
0)。
X = f (y, z) y = f (a, b) z = f (id, c) x is 0 <x <2 t , t is a predetermined number of binary digits, f ()
Represents a hash function, also blind signature data B is, B = r eT h (x ) modn T h (x) is a hash function mod n T to variable x to the n T modulo (modulus) processing apparatus NSO T indicating that the electronic certificate C and ECN right portion S 0 which is transmitted from the processing apparatus issuer o searched electronic securities issuing record database 10, an electronic certificate C is another on condition that it is not used in the electronic securities right unit, it registers the electronic securities issuing record database 10 the electronic certificate C and ECN right section S 0 as a set (step S14
0).

【0083】また中立機関Tの処理装置は、発行者oの
処理装置から送信されたブラインド署名用データBとデ
ジタル証明書Cとを用いて、デジタル証明書Cのデジタ
ル署名に使用した前記秘密鍵dTによってブラインド署
名用データBをデジタル署名し、ブラインド署名済デー
タB’を生成し、発行者oの処理装置に送信する(ステ
ップS150)。
Further, the processing unit of the neutral organization T uses the blind signature data B and the digital certificate C transmitted from the processing unit of the issuer o, and uses the private key used for digital signature of the digital certificate C. Digitally sign the blind signature data B with d T to generate blind signed data B ′ and send it to the processing device of issuer o (step S150).

【0084】ここで、 B’=(reT)dTh(x)dT mod nT =r・h(x)dT mod nT h(x)dTはh(x)を秘密鍵dTによってデジタル署
名したデータ なお、中立機関Tがブラインド署名用データBをデジタ
ル署名するときは、B=reTh(x)modnTとなっ
ているので、証券番号x自体はハッシングされた上にブ
ラインド係数rを乗じられているので、中立機関T証券
番号xの内容を知り得ない。つまり、中立機関Tは、証
券番号xの内容を知らないまま、電子証明書Cの秘密鍵
dTによってブラインド署名用データBをデジタル署名
するのである。
[0084] Here, B '= (r eT) digital by dT h (x) dT mod n T = r · h (x) dT mod n T h (x) dT is h (x) the secret key d T signed data Note that when the NSO T to digitally sign the blind signature data B is, B = r eT so has a h (x) modn T, policy number x itself blind coefficient r on which hashed , The contents of the neutral institution T securities number x cannot be known. That is, the neutral institution T digitally signs the blind signature data B with the secret key d T of the electronic certificate C without knowing the contents of the security number x.

【0085】上記ブラインド署名済データB’は発行者
oの処理装置に送られ、発行者oの処理装置によってア
ンブラインド処理される。具体的には、ブラインド署名
済データB’をブラインド係数rによって除すればよ
い。すなわち、 上記アンブラインド処理により、発行者oの処理装置は
中立機関Tによってブラインド署名された証券番号xを
取得する。この中立機関Tによってブラインド署名され
た証券番号xを用いて、発行者oの処理装置は電子証券
識別部S1(x)を生成する(ステップS160)。
The blind-signed data B 'is sent to the processing device of the issuer o, and subjected to unblind processing by the processing device of the issuer o. Specifically, the blind signed data B ′ may be divided by the blind coefficient r. That is, By the above unblind processing, the processing device of the issuer o acquires the security number x blind-signed by the neutral institution T. Using the security number x blind-signed by the neutral institution T, the processing device of the issuer o generates an electronic security identification unit S 1 (x) (step S160).

【0086】ここで、 S1(x)=<x,h(x)dT mod nT> この電子証券識別部S1(x)は、後に中立機関Tを含
む任意の第三者がh(x)dTを中立機関Tの公開鍵eT
を用いてh(x)dTをeT乗してh(x)を得、 h(x)dT・eT=h(x) …(12) 一方、電子証券識別部S1(x)に含まれているxとハ
ッシュ関数h()とを用いてh(x)を計算することが
できる。
Here, S 1 (x) = <x, h (x) dT mod n T > This electronic security identification unit S 1 (x) is used by an arbitrary third party, including a neutral institution T, to obtain h ( x) dT is the public key e T of the neutral institution T
H (x) dT is raised to the power of e T to obtain h (x). H (x) dT · eT = h (x) (12) On the other hand, the electronic securities identification unit S 1 (x) H (x) can be calculated using x and the hash function h ().

【0087】 x,h() → h(x) …(13) 上記式(12)と式(13)の結果が一致すれば、公開
鍵eTと秘密鍵dTは一対一の関係であり、かつ、秘密鍵
dTは中立機関Tだけが知り得るので、この電子証券識
別部S1(x)は確かに中立機関Tのみがデジタル署名
し得るものであり、かつ、秘密鍵dTを介してその秘密
鍵dTを使用する電子証明書Cや電子証券権利部S0と
一対一の関係にあることを確認することができる。
X, h () → h (x) (13) If the results of the above equations (12) and (13) match, the public key e T and the secret key d T have a one-to-one relationship. In addition, since the private key d T can be known only by the neutral institution T, this electronic securities identification unit S 1 (x) can be digitally signed only by the neutral institution T, and the private key d T Through this, it can be confirmed that there is a one-to-one relationship with the digital certificate C using the secret key d T and the electronic securities right section S 0 .

【0088】最後に、発行者oの処理装置は、既に生成
した電子証券権利部S0と上記電子証券識別部S
1(x)とを組み合わせて電子証券S(x) S(x)=<S0,S1(x)> を生成するのである(ステップS160)。
[0088] Finally, the issuer o of the processing device, the electronic securities right part S 0 and the electronic securities identification unit S that has already been generated
1 (x) to generate electronic securities S (x) S (x) = <S 0 , S 1 (x)> (step S160).

【0089】上記が本実施形態の処理システムによる電
子証券の発行手続における処理であるが、このようにし
て発行された電子証券は、電子証明書Cの同一の秘密鍵
dTを介して、電子証券権利部S0と電子証券識別部S
1(x)とが一対一対応であることが保証される。ま
た、中立機関Tは発行者oが各電子証券に付した電子証
券番号xを知らず、かつ、発行者oを除いて誰もその電
子証券番号xの乱数a,b,cを知らないことになる。
これら電子証券の性質は、以下の電子証券の移転、証
明、消去の諸手続で大変重要な役割を果たすことにな
る。
The above is the processing in the electronic securities issuance procedure by the processing system of the present embodiment. The electronic securities issued in this manner are transmitted to the electronic certificate C via the same secret key d T of the electronic certificate C. Stock right part S 0 and the electronic securities identification unit S
1 (x) is guaranteed to have a one-to-one correspondence. Further, the neutral institution T does not know the electronic security number x assigned to each electronic security by the issuer o, and no one except the issuer o knows the random numbers a, b, and c of the electronic security number x. Become.
The nature of these securities will play a very important role in the following electronic securities transfer, certification and erasure procedures.

【0090】なお、本発明において発行される電子証券
は、たとえば株券のように同一の権利義務関係の記述に
ついて多数発行される種類の電子証券である。このた
め、上記証券番号は、同一の電子証券権利部S0に対し
て多数生成される。このことは、本発明の電子証券の移
転の経路の秘密が保持されることの条件となるものであ
る。この移転の経路の秘密の保持については後にさらに
説明する。
The electronic securities issued in the present invention are electronic securities of a type issued in large numbers with the same description of rights and obligations, such as stock certificates. Therefore, the policy number is generated number for the same electronic securities right portion S 0. This is a condition that the transfer route of the electronic securities of the present invention is kept confidential. The confidentiality of this transfer path will be further described later.

【0091】次に本実施形態の処理システムによる電子
証券の移転手続における処理について説明する。
Next, the processing in the transfer procedure of the electronic securities by the processing system of this embodiment will be described.

【0092】図4に本実施形態の処理システムによる電
子証券の移転手続における処理の流れを示す。本実施形
態の電子証券の移転手続では、移転利用者αが移転に係
る電子証券S(xα)のデータと、該当証券番号xαの
部分的な乱数aα,bα,zαを被移転利用者βの処理
装置に送信する(ステップS200)。
FIG. 4 shows the flow of processing in the electronic securities transfer procedure by the processing system of this embodiment. In the electronic securities transfer procedure of the present embodiment, the transfer user α receives the data of the electronic security S (x α ) related to the transfer and the partial random numbers a α , b α , and z α of the corresponding security number x α. It is transmitted to the processing device of the transfer user β (step S200).

【0093】ここで、移転に係る電子証券S(xα)
は、 S(xα)=<S0,S1(xα)> <>はその内側のデータの集合 S0は電子証券権利部 S1(xα)は電子証券識別部 電子証券権利部S0は以下のデータからなる。
Here, the electronic securities S (x α ) related to the transfer
S ( xα ) = <S 0 , S 1 (x α )><<> is a set of data inside S 0 is an electronic securities right section S 1 ( xα ) is an electronic securities identification section Electronic securities right section S 0 consists of the following data.

【0094】 S0=< C,D,h(C|D)do mod no> Cはデジタル証明書 Dは権利義務関係の記述 doは発行者の秘密鍵、 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)をdoによってデジタル
署名したデータ mod noはnoを法とすることを示す C=<nT,eT,h(nT|eT)dp mod np> nT,eTは権利義務内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dTはh(nT|eT)をdpによってデジ
タル署名したデータ mod npはnpを法(modulus)とすることを示す 一方、電子証券識別部S1(xα)は以下のデータから
なる。
[0094] S 0 = <C, D, h (C | D) do mod n o> C is described d o of the digital certificate D is the rights and obligations related issuer secret key, n o the public of the issuer key h (C | D) is C and the hash function h to the variable D (C | D) do the h | data mod n o which was digitally signed by a (C D) d o is the modulo n o C = <n T , e T , h (n T | e T ) dp mod n p > n T , e T is the security-specific public key d p , n p corresponding to the content of rights and obligations The secret key and the public key h (n T | e T ) are hash functions h (n T | e T ) using n T and e T as variables, and dT is a digital signature of h (n T | e T ) by d p . The data mod n p indicates that n p is a modulus, while the electronic security identification unit S 1 (x α ) includes the following data.

【0095】 S1(xα)=<xα,h(xα)dT mod nT> xαは移転利用者αの証券番号 h(xα)はxαを変数とするハッシュ関数 h(xα)dTはh(xα)をdTによってデジタル署
名したデータ また、電子証券番号のxαはその乱数の一部aα,
bα,zαと以下の関係にある。
S 1 (x α ) = <x α , h (x α ) dT mod n T > x α is the security number h (x α ) of the transfer user α , and the hash function h (x α ) is a variable of x α x alpha) dT is also data digitally signed h a (x alpha) by d T, a part of the x alpha is the random number of the electronic certificate number a alpha,
It has the following relationship with b α and z α .

【0096】xα=f(yα,zα) yα=f(aα,bα) zα=f(idα,cα) aα,bα,cαは電子証券番号xαの乱数 0<aα,bα,cα<2t idαは移転利用者αの特定番号 f( )はハッシュ関数 被移転利用者βの処理装置は、被移転利用者β専用の新
たな証券番号の乱数aβ,bβ,cβを生成し、これら
の乱数と被移転利用者βの特定番号idβとを用いて被
移転利用者β専用の新たな証券番号xβを算出する。新
たな証券番号xβと乱数aβ,bβ,cβ,被移転利用
者βの特定番号idβの関係は以下の通りである。
[0096] x α = f (y α, z α) y α = f (a α, b α) z α = f (id α, c α) a α, b α, c α is the electronic security number xα Random numbers 0 <a α , b α , c α <2 t id α is a specific number of the transfer user α f () is a hash function The processing device of the transfer user β is a new security dedicated to the transfer user β A random number a β , b β , c β of a number is generated, and a new security number x β dedicated to the transferred user β is calculated using these random numbers and the specific number id β of the transferred user β. New policy number x beta and the random number a β, b β, c β , is as following relationship specific number id beta of the transfer user beta.

【0097】xβ=f(yβ,zβ) yβ=f(aβ,bβ) zβ=f(idβ,cβ) xβは被移転利用者β専用の新たな証券番号 aβ,bβ,cβは0<aβ,bβ,cβ<2t idβは被移転利用者βの特定番号 また、被移転利用者βの処理装置はブラインド係数rβ
(0<rβ<2t、tは2進数の所定の桁数)を生成
し、上記証券番号xβをブラインド係数rβによって秘
匿したブラインド署名用データBβを算出する。
[0097] x β = f (y β, z β) y β = f (a β, b β) z β = f (id β, c β) x β is a new policy number of dedicated transferee user β a β , b β , c β are 0 <a β , b β , c β <2 t id β is the specific number of the transferred user β, and the processing device of the transferred user β is a blind coefficient r β
(0 <r β <2 t , t is a predetermined number of digits of the binary numbers) to generate a calculated blind signature data B beta which concealed the certificate number x beta by blind coefficient r beta.

【0098】ここで、 Bβ=rβ eTh(xβ) modnT h(xβ)はxβを変数とするハッシュ関数 eTは中立機関の秘密鍵dTに対応する公開鍵 上記準備の後に、被移転利用者βの処理装置は、上記新
たな証券番号xβのブラインド署名用データBβと、移
転前の電子証券識別部S1(xα)と、部分的な乱数a
α,bα,zαと、電子証券権利部S0に含まれている
電子証明書Cとを中立機関Tの処理装置に送信する(ス
テップS210)。
[0098] In this case, B β = r β eT h (x β) modn T h (x β) is a hash function e T for the variable x β public key the preparation corresponding to the private key d T of neutral institutions after, the processor of the transfer user beta, and blind signature data B beta of the new policy number x beta, relocation before the electronic securities identification section S 1 and (x alpha), partial random number a
alpha, b alpha, and z alpha, it transmits the electronic certificate C contained in the electronic security rights section S 0 to the processing apparatus of NSO T (step S210).

【0099】上記データを受信した中立機関Tの処理装
置は、移転の正当性を保証するために以下の3つの検証
を行う。
The processing unit of the neutral institution T that has received the data performs the following three verifications in order to guarantee the validity of the transfer.

【0100】最初に中立機関Tの処理装置は、移転に係
る電子証券の電子証券権利部S0と電子証券識別部S1
(x)が一対一対応であることを検証する(ステップS
220)。これは、所定の権利を記述した電子証券権利
部S0と別の証券に付した任意の証券番号の電子証券識
別部S1(x)が組み合わされて移転されることを防止
するためである。
[0100] processing apparatus of the first to neutral institutions T, the electronic securities right portion S 0 of the electronic securities in accordance with the transfer and electronic securities identification section S 1
Verify that (x) is one-to-one correspondence (step S
220). This is because to prevent predetermined electronic securities rights describing the right section S 0 ECN identification and any securities number assigned to another security unit S 1 (x) are combined to move .

【0101】上記電子証券権利部S0と電子証券識別部
S1(x)が一対一対応の検証は、電子証明書Cの秘密
鍵dTを介して検証される。すなわち、中立機関Tの処
理装置は、移転前の証券番号xαを使ってそのハッシュ
関数h(xα)を算出し、一方、デジタル署名された証
券番号のハッシュ関数h(xα)dTをデジタル証明書
Cで使用した秘密鍵dTと対をなす公開鍵eTによって復
号してh(xα)dT ・eTを算出し、両者を照合する。
上記両者が一致すれば、電子証券識別部S1(xα)と
電子証券権利部S0が同一の秘密鍵dTを使用している
ことから、移転に係る電子証券識別部S1(xα)と電
子証券権利部S0とが一対一対応であることが保証され
る。
The verification of the one-to-one correspondence between the electronic securities right part S 0 and the electronic securities identification part S 1 (x) is verified through the secret key d T of the electronic certificate C. That is, the processor of NSO T uses the certificate number x alpha before transfer to calculate the hash function h (x α), whereas, the hash function h (x α) dT digitally signed certificate number The secret key d T used in the digital certificate C is decrypted with the public key e T paired with the secret key d T to calculate h (x α ) dT · eT , and the two are collated.
If the two match, the electronic securities identification unit S 1 (x α ) and the electronic securities rights unit S 0 use the same secret key d T , so the electronic security identification unit S 1 (x α) and the electronic securities right portion S 0 is guaranteed to be one-to-one correspondence.

【0102】次に、中立機関Tの処理装置は、移転が移
転利用者αの合意の下に被移転利用者βに与えられたこ
とを検証する(ステップS230)。この検証は、移転
利用者αが与えた部分的な証券番号の乱数aα,bα,
zαを使って行われる。具体的には中立機関Tの処理装
置は、証券番号xαと乱数aα,bα,zαがxα=f
(f(aα,bα),zα)の関係を満たすことを確認
する。証券番号xαと乱数aα,bα,zαがxα=f
(f(aα,bα),zα)を満たせば、aα,bα,
zαは移転利用者αのみが知り得るので、これらのデー
タが移転利用者α自身から被移転利用者βに与えられた
こと、すなわちこの移転が移転利用者αの合意の下に行
われることが保証される。
Next, the processing device of the neutral institution T verifies that the transfer has been given to the transferred user β under the agreement of the transferred user α (step S230). This verification is based on random numbers a α , b α ,
This is done using z α . The processor of NSO T Specifically, policy number xα and the random number a α, b α, z α is x alpha = f
(F (a α, b α ), z α) confirms that satisfies the relationship. The security number x α and the random numbers a α , b α , and z α are x α = f
(F (a α, b α ), z α) satisfy the, a α, b α,
Since z α can only be known by the transferring user α, these data are given by the transferring user α to the transferred user β, that is, this transfer is performed under the agreement of the transferring user α. Is guaranteed.

【0103】なお、移転利用者αが与える証券番号の乱
数が部分的なものであることにより、この証券番号の乱
数を知った中立機関Tあるいは中立機関Tからそれらを
知った者が、それらの証券番号の乱数を悪用することが
できない。つまり、zα=f(idα,cα)により、
zαからidαやcαを知ることが困難なので、第三者
がidαやcαのデータを必要とする電子証券の証明の
手続を行うことができないのである。言葉を変えて言え
ば、移転で与える証券番号の乱数は移転で移転の合意の
証明にのみ使用され、他の目的に使用することができな
いということである。
Since the random number of the security number given by the transfer user α is partial, the neutral institution T that has learned the random number of the security number or a person who has learned the random number from the neutral institution T knows them. The random number of the security number cannot be misused. That is, by z α = f (id α, c α),
Since it is difficult to know the id α and c α from z α, is the third party is not able to perform the procedure of certification of electronic securities that require the data of the id α and c α. In other words, the random number of the security number given in the transfer is only used to prove the transfer agreement in the transfer and cannot be used for any other purpose.

【0104】次に、中立機関Tの処理装置は、移転に係
る電子証券が二重に移転されたものでないことを検証す
る(ステップS240)。具体的には、中立機関Tの処
理装置は、既に移転された電子証券を登録した電子証券
移転記録データベース20で電子証券識別部S
1(xα)を検索することにより、電子証券識別部S1
(xα)が未登録すなわち二重移転でないことを確認す
る。電子証券識別部S1(xα)が過去に移転されてい
なければ、中立機関Tの処理装置は電子証券識別部S1
(xα)を移転済電子証券識別部として登録し、それ以
降の二重移転を防止する。
Next, the processing unit of the neutral institution T verifies that the electronic securities related to the transfer are not those transferred twice (step S240). More specifically, the processing device of the neutral institution T uses the electronic securities transfer record database 20 in which the electronic securities already transferred are registered in the electronic securities identification unit S.
By searching for 1 ( xα ), the electronic securities identification unit S 1
Check that (x α ) is not registered, ie not a double transfer. If the electronic securities identification unit S 1 (x α ) has not been transferred in the past, the processing device of the neutral institution T will execute the electronic securities identification unit S 1
( Xα ) is registered as the transferred electronic securities identification unit, and subsequent double transfer is prevented.

【0105】以上の検証を終了した後、中立機関Tの処
理装置は、被移転利用者βの処理装置から入力したブラ
インド署名用データBβを、デジタル証明書Cの公開鍵
nT,eTに対応するデジタル署名に使用した秘密鍵dT
によってデジタル署名する。この結果、ブラインド署名
済データBβ’が生成され、中立機関Tの処理装置は、
そのブラインド署名済データBβ’を被移転利用者βの
処理装置に送信する(ステップS250)。
After completing the above verification, the processing device of the neutral institution T converts the blind signature data Bβ input from the processing device of the transferred user β into the public keys n T and e T of the digital certificate C. Secret key d T used for the digital signature corresponding to
Digitally sign by As a result, blind signed data B β ′ is generated, and the processing unit of the neutral organization T
The blind signed data Bβ ′ is transmitted to the processing device of the transferred user β (step S250).

【0106】ここで、 Bβ’=(rβ eT)dTh(xβ)dT mod nT =rβ・h(xβ)dT mod nT h(xβ)dTはh(xβ)をdTによってデジタル署名
したデータ なお、中立機関Tの処理装置がブラインド署名用データ
Bβをデジタル署名する時は、中立機関Tは被移転利用
者βが生成した新たな証券番号を知らないままデジタル
署名するので、移転に係る電子証券権利部S0に付され
た新しい証券番号は被移転利用者βのみが知るところと
なる。
[0106] In this case, B β '= (r β eT) dT h (x β) dT mod n T = r β · h (x β) dT mod n T h (x β) dT is h (x β) data Note digitally signed by the d T, while when the processing apparatus NSO T to digitally sign the blind signature data B beta is NSO T does not know a new security number transferee user beta-generated since the digital signature, the new policy number attached to the electronic securities right part S 0 according to the transfer becomes a place where only the transfer user β know.

【0107】被移転利用者βの処理装置は、ブラインド
署名済データBβ’を入力し、これをブラインド係数r
βによって除してデジタル署名済証券番号h(xβ)
dTmod nTを取得し、電子証券の識別部S
1(xβ)を算出する(ステップS260)。
The processing device of the transferred user β inputs the blind-signed data B β ′, and
by dividing by β digital signed policy number h (x β)
Obtain dT mod n T, and identify the electronic securities S
1 ( xβ ) is calculated (step S260).

【0108】ここで、 S1(xβ)=<xβ,h(xβ)dT mod nT> 続いて被移転利用者βの処理装置は、既に入手した電子
証券権利部S0と上記電子証券の識別部S1(xβ)と
を組み合わせて被移転利用者β専有のS(xβ)、 S(xβ)=<S0,S1(xβ)> を生成する(ステップS270)。
Here, S 1 (x β ) = <x β , h (x β ) dT mod n T > Next, the processing device of the transferred user β is the same as the electronic securities right unit S 0 already obtained and Combined with the identification unit S 1 (x β ) of the electronic security to generate S (x β ), S (x β ) = <S 0 , S 1 (x β )> exclusive to the transferred user β (step). S270).

【0109】上記電子証券の移転手続では、中立機関T
ステップS220〜S240の処理により、移転される
電子証券の電子証券権利部S0と電子証券識別部S
1(xα)とが一対一対応であること、移転される電子
証券S(xα)が二重移転でないこと、移転が移転利用
者αの合意の下に行われていること、を移転後の新たな
電子証券番号の内容を知らずに保証している。中立機関
Tが移転後の新たな電子証券番号の内容を知らないとい
うことは、同一電子証券権利部S0を有する多数の電子
証券のいずれが移転されたかを知ることができないこと
と等しい。これにより、移転に係る電子証券の移転経路
を中立機関Tがたどることができず、電子証券の取引の
プライバシーが保持され、電子証券の財産としての活用
の途が広く確保されるのである。
In the above electronic securities transfer procedure, a neutral institution T
The process of step S220~S240, ECN right portion S 0 of the electronic securities transfer and electronic securities identification unit S
1 ( xα ) is one-to-one correspondence, that the electronic securities S ( xα ) to be transferred is not a double transfer, and that the transfer is performed under the agreement of the transfer user α. Guarantee without knowing the contents of the new electronic securities number later. That NSO T does not know the new contents of the electronic securities number after transfer is equal to that one of a number of electronic securities having the same electronic securities right portion S 0 can not know whether the transfer. As a result, the transfer path of the electronic securities related to the transfer cannot be followed by the neutral institution T, the privacy of the transactions of the electronic securities is maintained, and the way of using the electronic securities as property is widely secured.

【0110】次に本実施形態の処理システムによる電子
証券の証明手続における処理について説明する。
Next, a description will be given of processing in a certification procedure for electronic securities by the processing system of the present embodiment.

【0111】図5に本実施形態の処理システムによる電
子証券の証明手続における処理の流れを示す。本実施形
態の電子証券の証明手続では、電子証券の所有を主張す
る利用者をAとすると、この利用者A(利用者Aの処理
装置)は、電子証券を所有していることの主張ととも
に、電子証券S(xA)と、証券番号xAの乱数の一部y
A,cAと、利用者Aの特定番号idAを電子証券の発行
者oの処理装置に送信する(ステップS300)。
FIG. 5 shows the flow of processing in the electronic securities certification procedure by the processing system of this embodiment. In the electronic securities certifying procedure of the present embodiment, if the user who claims ownership of the electronic security is A, this user A (the processing device of the user A) together with the assertion that he owns the electronic security , Electronic securities S (x A ) and a part y of a random number of security number x A
A , c A and the specific number id A of the user A are transmitted to the processing device of the issuer o of the electronic security (step S300).

【0112】ここで、 S(xA)=<S0,S1(xA)> <>はその内側のデータの集合 S0は電子証券権利部 S1(xA)は電子証券識別部 電子証券権利部S0は記述の通り、以下に示すデータで
ある。
Here, S (x A ) = <S 0 , S 1 (x A )><> is a set of data inside S 0 is an electronic securities right unit S 1 (x A ) is an electronic securities identification unit electronic securities right portion S 0 is as described, the data shown below.

【0113】 S0=< C,D,h(C|D)do mod no> Cはデジタル証明書 Dは権利義務関係の記述 doは発行者の秘密鍵、 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)をdoによってデジタル
署名したデータ mod noはnoを法とすることを示す また、その電子証券権利部S0に含まれている電子証明
書Cは記述の通り、以下に示すデータである。
[0113] S 0 = <C, D, h (C | D) do mod n o> C is described d o of the digital certificate D is the rights and obligations related issuer secret key, n o the public of the issuer key h (C | D) is C and the hash function h to the variable D (C | D) do the h | data mod n o which was digitally signed by a (C D) d o is the modulo n o are shown also, the electronic certificate C contained in the electronic security rights section S 0 is as described, a data shown below.

【0114】 C=<nT,eT,h(nT|eT)dp mod np> nT,eTは権利義務内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と中立関係の秘密鍵と公開
鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)をdpによってデジ
タル署名したデータ mod nTはnTを法(modulus)とすることを
示す電子証券識別部S1(xA)は以下のデータからな
る。
C = <n T , e T , h (n T | e T ) dp mod n p > n T , e T is a security-specific public key d p , n p corresponding to the content of right and obligation is a neutral institution H (n T | e T ) is a hash function with n T and e T as variables, and h (n T | e T ) dp is h (n T | e T ). data mod n T a digitally signed by d p electronic securities identification section S 1 indicating that the n T modulo (modulus) (x a) comprises the following data.

【0115】 S1(xA)=<xA,h(xA)dT mod nT> xAは電子証券を所有する利用者Aが付与した証券番号 dTとnTはそれぞれの中立機関の秘密鍵と公開鍵 h(xA)はxAを変数とするハッシュ関数、 h(xA)dTはh(xA)をdTによってデジタル署名
したデータ 証券番号xAを算出する乱数は以下の関係を満たす。
S 1 (x A ) = <x A , h (x A ) dT mod n T > x A is the security number d T and n T assigned by the user A who owns the electronic security, and each of them is a neutral institution. H (x A ) is a hash function using x A as a variable, h (x A ) dT is data obtained by digitally signing h (x A ) with d T The random number for calculating the security number x A is The following relationship is satisfied.

【0116】xA=f(yA,zA) yA=f(aA,bA) zA=f(idA,cA) aA,bA,cAは証券番号の乱数 0<aA,bA,cA<2t tは2進数の所定の桁数 idAは利用者Aの特定番号 f()はハッシュ関数 発行者oの処理装置は、上記データを受信すると、電子
証券識別部S1(xA)と、電子証明書Cと、利用者A
が与えた部分的な証券番号の乱数yA,idA,cAを中
立機関Tの処理装置に送信し、利用者Aが確かに電子証
券S(xA)を所有する者であることの証明を中立機関
Tに要求する(ステップS310)。
[0116] x A = f (y A, z A) y A = f (a A, b A) z A = f (id A, c A) a A, b A, random number c A is policy number 0 < A A , b A , c A <2 tt is a predetermined number of binary digits id A is a specific number of the user A f () is a hash function When the processor of the issuer o receives the data, Electronic securities identification section S 1 (x A ), electronic certificate C, user A
Sends the partial security number random numbers y A , id A , and c A to the processing unit of the neutral institution T, and confirms that the user A is indeed the owner of the electronic security S (x A ). The proof is requested from the neutral organization T (step S310).

【0117】発行者oから上記電子証券の所有証明を要
求された中立機関Tの処理装置は、証明される電子証券
の電子証券権利部S0と電子証券識別部S1(xA)と
が一対一対応であること、電子証券識別部S1(xA)
を有する電子証券S(xA)が確かに利用者Aに帰属す
ること、電子証券S(xA)が二重に所有証明されてい
ないこと、を検証する。
[0117] processor of the issuer o NSO requested ownership certificate of the electronic securities from T is certified electronic securities right portion S 0 of the electronic securities are the electronic securities identification section S 1 (x A) and is One-to-one correspondence, electronic securities identification unit S 1 (x A )
That electronic securities S, (x A) is attributable to certainly user A with, the electronic securities S (x A) is not owned prove to double, to verify.

【0118】最初に中立機関Tの処理装置は、電子証券
権利部S0と電子証券識別部S1(xA)とが一対一対
応であることを検証する(ステップS320)。このた
め、中立機関Tの処理装置は、証券番号xAを使ってそ
のハッシュ関数h(xA)を算出し、一方、デジタル署
名された証券番号のハッシュ関数h(xA)dTをデジタ
ル証明書Cで使用した秘密鍵dTと対をなす公開鍵eTに
よって復号してh(xA)dT・eTを算出する。次に両
者(h(xA)とh(xA)dT・eT)を照合し、一致す
れば電子証券識別部S1(xA)と電子証券権利部S0
が同一の秘密鍵dTを使用していることから、所有証明
に係る電子証券識別部S1(xA)と電子証券権利部S
0とが一対一対応であることを保証することができる。
この検証により、利用者Aが発行者oに対して電子証券
識別部S1(xA)と異なる権利を主張することが防止
される。
First, the processing unit of the neutral institution T verifies that the electronic securities right section S 0 and the electronic securities identification section S 1 (x A ) have a one-to-one correspondence (step S 320). Therefore, the processing apparatus of NSO T, with the certificate number x A calculates the hash function h (x A), whereas, the hash function h (x A) of the digitally signed certificate number digital prove dT The secret key d T used in the letter C is decrypted with the public key e T paired with the secret key d T to calculate h (x A ) dT · eT . Next, both (h (x A ) and h (x A ) dT · eT ) are collated, and if they match, the electronic securities identification unit S 1 (x A ) and the electronic securities rights unit S 0
Use the same secret key d T , the electronic securities identification unit S 1 (x A ) and the electronic securities rights unit S
0 can be guaranteed to correspond one-to-one.
This verification prevents the user A from asserting a right different from the electronic securities identification unit S 1 (x A ) to the issuer o.

【0119】次に、中立機関Tの処理装置は、電子証券
S(xA)が確かに利用者Aの所有するものであること
を検証する(ステップS330)。この検証は、利用者
Aが与えた部分的な証券番号の乱数yA,idA,cAを
使って行われる。具体的には中立機関Tの処理装置は、
証券番号xAと乱数yA,idA,cAがxA=f(yA,f
(idA,cA))の関係を満たすことを確認する。証券
番号xAと乱数yA,idA,cAがxA=f(yA,f(i
dA,cA))の関係を満たせば、yA,idA,cAは利
用者Aのみが知り得るので、これらの乱数を有する電子
証券S(xA)が確かに利用者Aの所有するものである
ことが保証される。
Next, the processing device of the neutral institution T verifies that the electronic security S (x A ) is indeed owned by the user A (step S330). This verification is performed using random numbers y A , id A , and c A of the partial security numbers given by the user A. Specifically, the processing unit of the neutral engine T
The security number x A and the random numbers y A , id A and c A are x A = f (y A , f
(Id A , c A )). The security number x A and the random numbers y A , id A , and c A are x A = f (y A , f (i
d A, satisfy the relationship of c A)), the y A, id A, c since A only user A can know, ECN S (x A) is indeed the user A having these random numbers Guaranteed to own.

【0120】最後に中立機関Tの処理装置は、所有証明
に係る電子証券が二重に所有証明を要求されたものでな
いことを検証する(ステップS340)。このため、中
立機関Tの処理装置は、過去に所有証明を行った電子証
券を登録した電子証券証明記録データベース30を用い
て、電子証券識別部S1(xA)の過去の証明の履歴を
検索する。この検索結果による電子証券識別部S1(x
A)の過去の証明の履歴は、必要に応じて証明の目的、
所有を主張した者、所有を主張された者、証明の日時等
のデータを含む。この所有証明の履歴により、発行者o
はその電子証券が二重に所有証明を要求されたものでな
いことを知ることができる。中立機関Tの処理装置は、
所有証明に係る電子証券識別部S1(xA)を証明済電
子証券識別部として電子証券証明記録データベース30
に登録する。
Lastly, the processing device of the neutral institution T verifies that the electronic certificate related to the ownership certificate is not the one for which the ownership certificate is required twice (step S340). For this reason, the processing device of the neutral institution T uses the electronic securities certification record database 30 in which the electronic securities for which the certificate of ownership has been issued in the past are registered, and records the history of the past certification of the electronic securities identification unit S 1 (x A ). Search for. The electronic securities identification unit S 1 (x
A ) The history of past certifications may be used for certification purposes,
Includes data such as who claimed ownership, who claimed ownership, and date and time of certification. By the history of this proof of ownership, the issuer o
Can find out that the electronic security is not the one for which double proof of ownership was required. The processing unit of the neutral engine T
The electronic securities certification record database 30 uses the electronic securities identification unit S 1 (x A ) relating to the ownership certificate as a certified electronic securities identification unit.
Register with.

【0121】以上の検証により、証明される電子証券の
電子証券権利部S0と電子証券識別部S1(xA)とが
一対一対応であること、電子証券識別部S1(xA)を
有する電子証券S(xA)が確かに利用者Aに帰属する
こと、電子証券S(xA)が二重に所有証明されていな
いこと、の成否が判明するので、中立機関Tの処理装置
はその検証結果、所有が正当である場合には所定の所有
証明を発行者oの処理装置に送信する(ステップS35
0)。
According to the above verification, the electronic securities right part S 0 and the electronic securities identification part S 1 (x A ) of the electronic securities to be certified have a one-to-one correspondence, and the electronic security identification part S 1 (x A ) It is determined that the electronic securities S (x A ) having the following attributes belong to the user A, and that the electronic securities S (x A ) is not double-certified. As a result of the verification, if the ownership is valid, the device transmits a predetermined ownership certificate to the processing device of the issuer o (step S35).
0).

【0122】上記所有証明手続で注目すべき点は、所有
証明する際に所有者(利用者A)はその身元を特定する
idAを含む証券番号の乱数の一部を発行者oに対して
明かすが、それらのデータを取得した発行者oや中立機
関Tはそれらのデータを用いて当該電子証券を移転する
等の不正な取引をすることができないことである。
It should be noted that in the above-mentioned ownership certifying procedure, when certifying ownership, the owner (user A) sends a part of the random number of the security number including id A specifying the identity to the issuer o. As will be apparent, the issuer o and the neutral institution T that have obtained such data cannot use such data to perform unauthorized transactions such as transferring the electronic securities.

【0123】所有証明手続で利用者Aが与える部分的な
証券番号の乱数yA,idA,cAであるが、yA=f(a
A,bA)により、yAを取得した者はyAからその乱数a
A,bAを割り出すことは不可能に近いほど困難である。
ところが、電子証券の移転を行うためには、上述したよ
うに移転利用者αは乱数aA,bAを与えなければ電子証
券を移転することができない。これにより、証券番号の
乱数yA,idA,cAのデータを取得した第三者はそれ
らのデータを用いてその電子証券について不正な取引を
することができないのである。
In the ownership certification procedure, the random numbers y A , id A , and c A of the partial security numbers given by the user A , where y A = f (a
A , b A ), the person who acquired y A can obtain the random number a from y A.
It is more difficult to determine A and b A as near as possible.
However, in order to transfer the electronic securities, the transfer user α cannot transfer the electronic securities without giving the random numbers a A and b A as described above. As a result, a third party who has acquired the data of the random numbers y A , id A , and c A of the security number cannot use the data to make an illegal transaction for the electronic security.

【0124】次に本実施形態の処理システムによる電子
証券の消去手続における処理について説明する。
Next, processing in the electronic securities erasing procedure by the processing system of this embodiment will be described.

【0125】図6に本実施形態の処理システムによる電
子証券の消去手続における処理の流れを示す。本実施形
態の電子証券の消去手続において電子証券の消去を要求
する利用者をBとすると、電子証券の消去を求める際に
利用者Bは、電子証券の消去の要求と、消去する電子証
券の電子証券識別部S1(xB)と、電子証明書Cと、
証券番号xBの乱数の一部aB,bB,zBを中立機関Tに
送信する(ステップS400)。
FIG. 6 shows the flow of processing in the electronic securities erasure procedure by the processing system of this embodiment. In the electronic securities erasure procedure of this embodiment, if the user who requests the erasure of the electronic security is B, when requesting the erasure of the electronic security, the user B makes a request for the erasure of the electronic security and a request for the erasure of the electronic security. An electronic securities identification unit S 1 (x B ), an electronic certificate C,
The random numbers a B , b B , and z B of the security number x B are transmitted to the neutral institution T (step S400).

【0126】ここで、 S(xB)=<S0,S1(xB)> <>はその内側のデータの集合 S0は電子証券権利部 S1(xB)は電子証券識別部 xBは消去を求められている電子証券の証券番号 電子証券権利部S0は既に説明した通りであって以下の
データである。
Here, S (x B ) = <S 0 , S 1 (x B )><> is a set of data inside S 0 is an electronic securities right unit S 1 (x B ) is an electronic securities identification unit x B is policy number ECN right portion S 0 of the electronic securities are required to erase the data in the following be as previously described.

【0127】 S0=<C,D,h(C|D)do mod no> Cはデジタル証明書 Dは権利義務関係の記述 doは発行者の秘密鍵、 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)をdoによってデジタル
署名したデータ mod noはnoを法とすることを示す 上記電子証券権利部S0に含まれている電子証明書Cは
既に説明した通りであるが以下のデータである。
[0127] S 0 = <C, D, h (C | D) do mod n o> C is described d o of the digital certificate D is the rights and obligations related issuer secret key, n o the public of the issuer key h (C | D) is C and the hash function h to the variable D (C | D) do the h | data mod n o which was digitally signed by a (C D) d o is the modulo n o Although electronic certificate C contained in the electronic security rights section S 0 indicating a are as previously described are the following data.

【0128】 C=<nT,eT,h(nT|eT)dp mod np> nT,eTは権利義務内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)をdpによってデジ
タル署名したデータ mod nTはnTを法(modulus)とすることを示す 電子証券識別部S1(xB)は以下の通りである。
C = <n T , e T , h (n T | e T ) dp mod n p > n T , e T is a security-specific public key d p , n p corresponding to the content of rights and obligations is a neutral institution The public key h (n T | e T ) is a hash function h (n T | e T ) dp with n T and e T as variables, and the digital signature of h (n T | e T ) with d p The data mod n T indicates that n T is a modulus. The electronic securities identification unit S 1 (x B ) is as follows.

【0129】 S1(xB)=<xB,h(xB)dT mod nT> dTとnTはそれぞれの中立機関の秘密鍵と公開鍵 h(xB)はxBを変数とするハッシュ関数、 h(xB)dTはh(xB)をdTによってデジタル署名し
たデータ 上記電子証券識別部S1(xB)の証券番号xBを算出す
る乱数は以下の関係を満たす。
S 1 (x B ) = <x B , h (x B ) dT mod n T > d T and n T are the secret key and public key of a neutral institution, respectively. H (x B ) is a variable of x B H (x B ) dT is data obtained by digitally signing h (x B ) with d T The random number for calculating the security number x B of the electronic security identification unit S 1 (x B ) has the following relationship: Fulfill.

【0130】xB=f(yB,zB) yB=f(aB,bB) zB=f(idB,cB) aB,bB,cBは証券番号の乱数 0<aB,bB,cB<2t tは2進数の所定の桁数 idBは消去を求める発行者、利用者Bの特定番号 f()はハッシュ関数 利用者Bから上記電子証券の消去を要求された中立機関
Tの処理装置は、消去される電子証券の電子証券権利部
S0と電子証券識別部S1(xB)とが一対一対応であ
ること、電子証券識別部S1(xB)を有する電子証券
S(xB)が確かに利用者Aに帰属すること、電子証券
S(xB)が二重に消去されていないこと、を検証す
る。
[0130] x B = f (y B, z B) y B = f (a B, b B) z B = f (id B, c B) a B, b B, random number c B is policy number 0 <A B , b B , c B <2 tt is a predetermined number of binary digits id B is an issuer requesting erasure, user B's specific number f () is a hash function it processing apparatus NSO T requested to erase, an electronic securities right portion S 0 of the electronic securities erased ECN identifying section S 1 (x B) and is a one-to-one correspondence, the electronic securities identification unit S 1 that the electronic securities S with a (x B) to (x B) is attributable to certainly user a, the electronic securities S (x B) has not been erased to double, to verify.

【0131】最初に中立機関Tの処理装置は、電子証券
権利部S0と電子証券識別部S1(xB)とが一対一対
応であることを検証する(ステップS420)。このた
め、中立機関Tの処理装置は、証券番号xBを使ってそ
のハッシュ関数h(xB)を算出し、一方、デジタル署
名された証券番号のハッシュ関数h(xB)dTをデジタ
ル証明書Cで使用した秘密鍵dTと対をなす公開鍵eTに
よって復号してh(xB)dT・eTを算出する。次に両者
(h(xB)とh(xB)dT・eT)を照合し、一致すれ
ば電子証券識別部S1(xB)と電子証券権利部S0が
同一の秘密鍵dTを使用していることから、消去に係る
電子証券識別部S1(xB)と電子証券権利部S0とが
一対一対応であることを保証することができる。この検
証により、電子証券識別部S1(xB)と正しく対応す
る電子証券S(xB)を消去することが保証される。
First, the processing unit of the neutral institution T verifies that the electronic securities right section S 0 and the electronic securities identification section S 1 (x B ) have a one-to-one correspondence (step S 420). Therefore, the processing apparatus NSO T, with the certificate number x B to calculate the hash function h (x B), whereas, the hash function h (x B) of the digitally signed certificate number dT digital certificates The secret key d T used in the letter C is decrypted with the public key e T paired with the secret key d T to calculate h (x B ) dT · eT . Next, both (h (x B ) and h (x B ) dT · eT ) are collated, and if they match, the electronic securities identification unit S 1 (x B ) and the electronic securities rights unit S 0 have the same secret key d T Is used, it can be guaranteed that the electronic securities identification unit S 1 (x B ) related to the erasure and the electronic securities right unit S 0 have a one-to-one correspondence. This verification guarantees that the electronic securities S (x B ) correctly corresponding to the electronic securities identification unit S 1 (x B ) will be deleted.

【0132】次に、中立機関Tの処理装置は、電子証券
S(xB)が確かに利用者Bの所有するものであること
を検証する(ステップS430)。この検証は、利用者
Bが与えた部分的な証券番号の乱数aB,bB,zBを使
って行われる。具体的には中立機関Tの処理装置は、証
券番号xBと乱数aB,bB,zBがxB=f(f(aB,b
B),zB)の関係を満たすことを確認する。証券番号x
Bと乱数aB,bB,zBがxB=f(f(aB,bB),
zB)の関係を満たせば、aB,bB,zBは利用者Bのみ
が知り得るので、これらの乱数を有する電子証券S(x
B)が確かに利用者Bの所有するものであることが保証
される。これにより、他人の電子証券を誤って消去する
ことを防止することができる。
Next, the processing device of the neutral institution T verifies that the electronic security S (x B ) is indeed owned by the user B (step S430). This verification is performed using random numbers a B , b B , and z B of partial security numbers given by the user B. Specifically, the processing unit of the neutral institution T determines that the security number x B and the random numbers a B , b B , and z B are x B = f (f (a B , b
B), to confirm that satisfies the relationship of z B). Security number x
B and random numbers a B , b B , and z B are x B = f (f (a B , b B ),
If the relationship of z B ) is satisfied, a B , b B , and z B can be known only by the user B , so that the electronic securities S (x
B ) is indeed guaranteed to belong to user B. This can prevent erroneous erasure of another person's electronic security.

【0133】最後に中立機関Tの処理装置は、消去に係
る電子証券が二重に消去されたものでないことを検証す
る(ステップS440)。このため、中立機関Tの処理
装置は、過去に消去を行った電子証券を登録した電子証
券消去記録データベース40を用いて、電子証券識別部
S1(xB)を検索する。この検索結果、電子証券識別
部S1(xB)が既に消去されたものでなければ、電子
証券識別部S1(xB)を消去済電子証券識別部として
電子証券消去記録データベース40に登録する。事実
上、この電子証券消去記録データベース40への登録に
より、それ以降の同電子証券が使用されることが防止さ
れる。
[0133] Finally, the processing unit of the neutral institution T verifies that the electronic security related to the erasure is not the one double-erased (step S440). For this reason, the processing device of the neutral institution T searches the electronic security identification unit S 1 (x B ) using the electronic security erasure record database 40 in which the electronic securities that have been erased in the past are registered. As a result of this search, if the electronic security identification unit S 1 (x B ) has not been erased, the electronic security identification unit S 1 (x B ) is registered in the electronic security erasure record database 40 as an erased electronic security identification unit. I do. In effect, registration in the electronic security erasure record database 40 prevents the subsequent use of the electronic security.

【0134】[0134]

【発明の効果】以上の説明から明らかなように、本発明
の電子証券の発行、移転、証明、消去のための処理シス
テム及びその処理方法によれば、以下の特有の効果を発
揮することができるのである。
As is apparent from the above description, according to the processing system and the processing method for issuing, transferring, certifying, and erasing electronic securities of the present invention, the following specific effects can be obtained. You can.

【0135】 複数の発行者が中立機関Tに要求する
ことにより、自由に複雑な権利義務関係を記載し、証券
番号を秘密にしたまま中立機関Tによってデジタル署名
されることにより、その権利義務関係と証券番号の対応
関係を保証された電子証券を発行することができる。
A plurality of issuers request the neutral institution T to freely describe complicated rights and obligations, and the digital signature is signed by the neutral institution T while keeping the security number secret, so that the rights and obligations are described. Can be issued electronic securities with a guaranteed correspondence between the security numbers and the security numbers.

【0136】 電子証券を移転する際は、電子証券権
利部と電子証券識別部が一対一対応であること、二重に
移転されるものでないこと、移転が移転者の合意の下に
行われること、を中立機関Tによって保証し、かつ、移
転の経路をいかなる者にも秘密にすることができる。
When transferring the electronic securities, the electronic securities rights department and the electronic securities identification department have a one-to-one correspondence, must not be duplicated, and must be transferred under the agreement of the transferor , Can be guaranteed by the neutral authority T, and the transfer route can be kept secret from anyone.

【0137】 電子証券の所有を主張する際は、電子
証券権利部と電子証券識別部が一対一対応であること、
二重に所有を主張されるものでないこと、正当な所有者
による所有の主張であること、を中立機関Tによって保
証することができる。
When claiming possession of electronic securities, the electronic securities right section and the electronic securities identification section have a one-to-one correspondence,
It can be assured by the neutral authority T that the ownership is not double and that the ownership is claimed by the rightful owner.

【0138】 電子証券の消去を主張する際は、電子
証券権利部と電子証券識別部が一対一対応であること、
二重に消去を要求されるものでないこと、正当な所有者
による消去の要求であること、を中立機関Tによって保
証し、それ以降の当該電子証券の使用を防止することが
できる。
When claiming the erasure of electronic securities, the electronic securities right section and the electronic securities identification section have a one-to-one correspondence,
The neutral institution T guarantees that double erasure is not required and that the erasure is requested by a legitimate owner, thereby preventing further use of the electronic security.

【図面の簡単な説明】[Brief description of the drawings]

【図1】本願発明で処理される電子証券のデータ構造を
概念的に示した図。
FIG. 1 is a diagram conceptually showing a data structure of an electronic security processed in the present invention.

【図2】本願発明の電子証券の発行、移転、証明、消去
のための処理システムの構成とその全体的な処理の流れ
を示したブロック図。
FIG. 2 is a block diagram showing the configuration of a processing system for issuing, transferring, certifying, and erasing electronic securities according to the present invention and the overall processing flow;

【図3】電子証券の発行手続における本願発明の処理シ
ステムの処理の流れを示したブロック図。
FIG. 3 is a block diagram showing a processing flow of a processing system of the present invention in an electronic securities issuance procedure.

【図4】電子証券の移転手続における本願発明の処理シ
ステムの処理の流れを示したブロック図。
FIG. 4 is a block diagram showing a processing flow of the processing system of the present invention in a transfer procedure of electronic securities.

【図5】電子証券の証明手続における本願発明の処理シ
ステムの処理の流れを示したブロック図。
FIG. 5 is a block diagram showing a flow of processing of the processing system of the present invention in a certification procedure for electronic securities.

【図6】電子証券の消去手続における本願発明の処理シ
ステムの処理の流れを示したブロック図。
FIG. 6 is a block diagram showing a processing flow of the processing system of the present invention in an electronic securities erasing procedure.

【図7】従来の電子マネーの処理の流れを示したブロッ
ク図。
FIG. 7 is a block diagram showing a flow of processing of conventional electronic money.

【符号の説明】 10 電子証券発行記録データベース 20 電子証券移転記録データベース 30 電子証券証明記録データベース 40 電子証券消去記録データベース S(x) 電子証券 S0 電子証券権利部 S1(x) 電子証券識別部 x 証券番号 a 証券番号乱数 b 証券番号乱数 c 証券番号乱数 id 特定番号 n 公開鍵 e 公開鍵 d 秘密鍵 p 秘密鍵 q 秘密鍵 T 中立機関 o 発行者 α 移転利用者 β 被移転利用者 A 証明を求める利用者 B 消去を求める利用者[Description of Signs] 10 Electronic Securities Issuance Record Database 20 Electronic Securities Transfer Record Database 30 Electronic Securities Certification Record Database 40 Electronic Securities Erasure Record Database S (x) Electronic Securities S 0 Electronic Securities Rights Department S 1 (x) Electronic Securities Identification Unit x Securities number a Securities number random number b Securities number random number c Securities number random number id Specific number n Public key d Public key d Private key p Private key q Private key T Neutral organization o Issuer α Transfer user β Transferee A Certificate B requesting erasure B user requesting erasure

Claims (18)

【特許請求の範囲】[Claims] 【請求項1】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理システムであって、電子証
券の発行手続において、 前記中立機関の処理装置は、中立機関のみがデジタル署
名し得るデジタル証明書を生成し、 前記発行者の処理装置は、発行者のみがデジタル署名し
得る前記デジタル証明書と権利義務関係の記述の暗号化
データを含む電子証券権利部を生成する一方、証券番号
を生成し、前記証券番号を秘匿したブラインド署名用デ
ータを生成し、 前記中立機関の処理装置は、前記デジタル証明書と前記
ブラインド署名用データとを入力し、前記デジタル証明
書をデジタル署名したのと同一の秘密鍵により前記ブラ
インド署名用データをデジタル署名することにより、中
立機関のみがデジタル署名し得るブラインド署名済デー
タを生成し、 前記発行者の処理装置は、前記ブラインド署名済データ
を入力し、アンブラインド処理して中立機関のみがデジ
タル署名し得るデジタル署名済証券番号を取得し、この
中立機関によるデジタル署名済証券番号を含む電子証券
識別部を生成し、前記電子証券権利部と電子証券識別部
とを組み合わせて電子証券の発行手続を完了することを
特徴とする電子証券の発行、移転、証明、消去のための
処理システム。
1. A processing system for issuing, transferring, certifying, and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral institution, wherein issuance of electronic securities. In the procedure, the processing device of the neutral institution generates a digital certificate that can be digitally signed only by the neutral institution, and the processing device of the issuer has the rights and obligations relationship with the digital certificate that can only be digitally signed by the issuer. While generating an electronic securities right part including the encrypted data of the description, generates a security number, generates blind signature data concealing the security number, the processing device of the neutral organization, the digital certificate and the digital certificate By inputting the blind signature data and digitally signing the blind signature data with the same private key as the digital signature of the digital certificate, A blind signed data that can be digitally signed only by a legislative institution, and the processing device of the issuer inputs the blind signed data and unblinds the digitally signed certificate that can be digitally signed only by a neutral institution. Acquiring a number, generating an electronic securities identification unit including a digitally signed security number by this neutral institution, and completing the electronic securities issuing procedure by combining the electronic securities right unit and the electronic securities identification unit. Processing system for issuing, transferring, certifying and erasing electronic securities.
【請求項2】前記発行者の装置が生成する証券番号は、
下式の関係を満たす3つの乱数a,b,cと発行者の特
定番号idによって計算されるものであることを特徴と
する請求項1に記載の電子証券の発行、移転、証明、消
去のための処理システム。 x=f(y,z) y=f(a,b) z=f(id,c) ここで、x:証券番号 f():f(x,y)=f(x′,y′)なるx≠
x′,y≠y′を見つけることが困難な一方向性ハッシ
ュ関数
2. The security number generated by the issuer's device is:
2. The method according to claim 1, wherein the random number is calculated by three random numbers a, b, and c satisfying a relationship of the following expression and a specific number id of the issuer. Processing system for x = f (y, z) y = f (a, b) z = f (id, c) where x: security number f (): f (x, y) = f (x ′, y ′) X
One-way hash function that is difficult to find x ', y ≠ y'
【請求項3】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理システムであって、電子証
券の発行手続において、 前記中立機関の処理装置は、発行者の要求に応じて電子
証券ごとにRSA系の鍵nT,eT,pT,qT,dTを生
成し、その公開鍵のnT,eTを秘密鍵dTによってデジ
タル署名したデジタル証明書Cを生成し、 ここで、 C=<nT,eT,h(nT|eT)dp mod np> < >はその内側のデータの集合 nT,eT は権利義務内容に対応する証券固有の公開鍵 dp,np は 中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)を秘密鍵dpによ
ってデジタル署名したデータ mod npはnpを法(modulus)とすることを示す 前記発行者の処理装置は、前記デジタル証明書Cと電子
証券の権利義務を記述した記述Dとを入力し、電子証券
の権利部S0を出力し、 ここで、 S0=<C,D,h(C|D)do mod no> doは発行者の秘密鍵 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)を秘密鍵doによってデ
ジタル署名したデータ mod noはnoを法(modulus)とすることを示す 前記中立機関の処理装置は、前記デジタル証明書Cと電
子証券権利部S0とを入力し、電子証券発行記録データ
ベースで前記デジタル証明書Cを検索し、そのデジタル
証明書Cが他の電子証券に使用されていないことを条件
に前記デジタル証明書Cと電子証券の権利部S0を組と
して前記電子証券発行記録データベースに登録し、 前記発行者の処理装置は、証券番号乱数a,b,c(0
<a,b,c<2t、tは2進数の所定の桁数)と、ブ
ラインド係数r(0<r<2t、tは2進数の所定の桁
数)とをランダムに生成し、発行者の特定番号idを用
いて証券番号xを算出し、続いて前記証券番号xを前記
ブラインド係数rによって秘匿したブラインド署名用デ
ータBを算出し、 ここで、 x=f(y,z) y=f(a,b) z=f(id,c) f( )はf(x,y)=f(x′,y′)なるx≠
x′,y≠y′を見つけることが困難な一方向性ハッシ
ュ関数を示し、 B=reTh(x) modnT h(x)はxを変数とするハッシュ関数 mod nTはnTを法(modulus)とすることを示す 前記中立機関の処理装置は、前記ブラインド署名用デー
タBと前記デジタル証明書Cを入力し、前記デジタル証
明書Cのデジタル署名に使用した前記秘密鍵dTによっ
て前記ブラインド署名用データBをデジタル署名したブ
ラインド署名済データB’を生成し、 ここで、 B’=(reT)dTh(x)dT mod nT =r・h(x)dT mod nT h(x)dTはh(x)を秘密鍵dTによってデジタル署
名したデータ 前記発行者の処理装置は、前記ブラインド署名済データ
B’を入力し、これを前記ブラインド係数rによって除
して電子証券の識別部S1(x)を算出し、 ここで、 S1(x)=<x,h(x)dT mod nT> 続いて、電子証券権利部S0と電子証券識別部S
1(x)とを組み合わせて電子証券S(x) S(x)=<S0,S1(x)> を生成して電子証券の発行手続を完了することを特徴と
する電子証券の発行、移転、証明、消去のための処理シ
ステム。
3. A processing system for issuing, transferring, certifying, and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral institution, wherein issuance of electronic securities. In the procedure, the processing unit of the neutral institution generates an RSA key n T , e T , p T , q T , d T for each electronic security at the request of the issuer, and generates a public key n T. , E T with a secret key d T to generate a digital certificate C, where C = <n T , e T , h (n T | e T ) dp mod n p ><> The data set n T , e T is the security-specific public key d p , n p corresponding to the rights and obligations, and the neutral and private key and the public key h (n T | e T ) are n T and e T A hash function h (n T | e T ) dp as a variable is a data obtained by digitally signing h (n T | e T ) with a secret key d p . The data mod n p indicates that n p is a modulus. The processing device of the issuer inputs the digital certificate C and the description D describing the rights and obligations of the electronic security, and and outputs the right part S 0, here, S 0 = <C, D , h (C | D) do mod n o> d o is the issuer of the secret key n o is the issuer's public key h (C | D) is a hash function h (C to the variable C and D | be a D) the data mod n o which was digitally signed by a private key d o is n o law (modulus) | is D) do h (C processor of the NSO showing the inputs and the digital certificate C and ECN right portion S 0, searches the digital certificate C in the electronic securities issuing record database, the digital certificate C is another The digital certificate C and the digital certificate Kagabu registers S 0 to the electronic securities issuing record database as a set, the issuer of the processor, policy number random number a, b, c (0
<A, b, c <2 t , where t is a predetermined number of binary digits) and a blind coefficient r (0 <r <2 t , t is a predetermined number of binary digits), are randomly generated, The security number x is calculated using the issuer's specific number id, and then the blind signature data B in which the security number x is concealed by the blind coefficient r is calculated, where x = f (y, z) y = f (a, b) z = f (id, c) f () is x ≠ such that f (x, y) = f (x ′, y ′)
x ', y ≠ y' indicates the hard one-way hash function to find a, B = r eT h (x ) modn T h (x) is a hash function mod n T to variable x to the n T The processing unit of the neutral organization inputs the blind signature data B and the digital certificate C, and uses the secret key d T used for the digital signature of the digital certificate C. said blind signature data B 'to generate where, B' blind signed data B digital signature = (r eT) dT h ( x) dT mod n T = r · h (x) dT mod n T h (x) dT data the issuer processing devices that digitally signed h (x) is the private key d T inputs the blind signed data B ', which was divided by the blind coefficient r electronic Identification of securities S calculated 1 (x), wherein, S 1 (x) = < x, h (x) dT mod n T> Subsequently, the electronic securities right portion S 0 and ECN identification unit S
1 (x) by combining the electronic securities S (x) S (x) = issuance of electronic securities, characterized in that to generate the <S 0, S 1 (x )> to complete the registration procedure with the electronic securities Processing system for transfer, certification, erasure.
【請求項4】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理システムであって、電子証
券の移転手続において、 被移転利用者の処理装置は、移転者から電子証券と移転
者のみが知り得る移転前の証券番号の乱数の一部とを取
得し、被移転利用者専用の新たな証券番号を生成し、前
記新たな証券番号を秘匿したブラインド署名用データを
生成し、 中立機関の処理装置は、被移転利用者から前記ブライン
ド署名用データと、移転前の証券番号と中立機関のみが
デジタル署名し得たデジタル署名済証券番号とからなる
電子証券識別部と、前記移転者のみが知り得る移転前の
証券番号の乱数の一部と、前記電子証券の電子証券権利
部に含まれているデジタル証明書とを入力し、前記デジ
タル証明書を介して前記移転前の電子証券識別部と前記
電子証券権利部とが一対一対応であることの検証計算を
行い、前記移転前の証券番号の乱数の一部と前記移転前
の証券番号識別部の証券番号とを用いて前記移転前の電
子証券識別部が移転利用者の合意の下に被移転利用者に
与えられたことの検証計算を行い、前記移転前の電子証
券識別部が未移転であることを電子証券移転記録データ
ベースで確認して未移転であったことを条件に移転者の
前記電子証券識別部を移転済の電子証券識別部として登
録するとともに、前記デジタル証明書をデジタル署名し
たのと同一の秘密鍵によって前記ブラインド署名用デー
タをデジタル署名することにより、中立機関のみがデジ
タル署名し得るブラインド署名済データを生成し、 前記被移転者の処理装置は、前記ブラインド署名済デー
タをアンブラインド処理して中立機関のみがデジタル署
名し得る新たなデジタル署名済証券番号を取得し、新た
な前記証券番号と前記デジタル署名済証券番号とからな
る電子証券識別部を生成し、前記電子証券権利部と新た
な電子証券識別部とを組み合わせて電子証券の移転手続
を完了することを特徴とする電子証券の発行、移転、証
明、消去のための処理システム。
4. A processing system for issuing, transferring, certifying and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral institution, wherein the transfer of electronic securities is performed. In the procedure, the processor of the transferred user obtains the electronic securities from the transferor and a part of the random number of the security number before transfer which can be known only by the transferor, and obtains a new security number exclusively for the transferred user. The new security number is concealed, and the new security number is concealed to generate blind signature data.The processing unit of the neutral institution, the blind signature data from the transferee, the security number before the transfer and only the neutral institution have a digital signature An electronic securities identification unit consisting of the obtained digitally signed security number, a part of the random number of the security number before transfer that only the transferor can know, and a digital number included in the electronic securities right part of the electronic security. Enter the certificate and Performing a verification calculation that the electronic securities identification unit and the electronic securities right unit before transfer are one-to-one correspondence via the digital certificate, and a part of the random number of the security number before transfer and the Using the security number of the security number identification unit before the transfer, the electronic securities identification unit before the transfer performs a verification calculation that the transferee has been given to the transferred user under the agreement of the transfer user, and performs a verification calculation before the transfer. While confirming that the electronic securities identification unit has not been transferred in the electronic securities transfer record database and registering the electronic securities identification unit of the transferee as a transferred electronic securities identification unit on the condition that it has not been transferred, Digitally signing the blind signature data with the same private key as the digital signature of the digital certificate, thereby generating blind signed data that can be digitally signed only by a neutral authority. The processing device of the transferor unblinds the blind-signed data to obtain a new digitally signed security number that can be digitally signed only by a neutral organization, and obtains the new security number and the digitally signed security number. Issuance, transfer, certification, erasure of electronic securities, characterized in that the electronic securities right section and the new electronic securities identification section are combined to complete an electronic securities transfer procedure. Processing system for
【請求項5】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理システムであって、電子証
券の移転手続において、 被移転利用者βの処理装置は、移転利用者αから電子証
券S(xα)と移転利用者αの証券番号xαの乱数
aα,bα,zαを取得し、被移転利用者β専用の新た
な証券番号の乱数aβ,bβ,cβと、ブラインド係数
rβ(0<rβ<2t、tは2進数の所定の桁数)とを
生成し、被移転利用者βの特定番号idβを用いて被移
転利用者β専用の新たな証券番号xβを算出し、続いて
前記証券番号xβを前記ブラインド係数rβによって秘
匿したブラインド署名用データBβを算出し、 ここで、 S(xα)=<S0,S1(xα)> <>はその内側のデータの集合 S0=<C,D,h(C|D)do mod no> Cはデジタル証明書 Dは権利義務関係の記述 doは発行者の秘密鍵、 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)をdoによってデジタル
署名 したデータ mod noはnoを法とすることを示す C=<nT,eT,h(nT|eT)dp mod np> nT,eTは権利義務内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dTはh(nT|eT)をdpによってデジ
タル署名したデータ mod npはnpを法(modulus)とすることを示す S1(xα)=<xα,h(xα)dT mod nT> xαは移転利用者αの証券番号 h(xα)はxαを変数とするハッシュ関数 h(xα)dTはh(xα)をdTによってデジタル署名
したデータ xα=f(yα,zα) yα=f(aα,bα) zα=f(idα,cα) aα,bα,cαは0<aα,bα,cα<2t idαは移転利用者αの特定番号 f( )はf(x,y)=f(x′,y′)なるx≠
x′,y≠y′を見つけることが困難な一方向性ハッシ
ュ関数 xβ=f(yβ,zβ) yβ=f(aβ,bβ) zβ=f(idβ,cβ) xβは被移転利用者β専用の新たな証券番号 aβ,bβ,cβは0<aβ,bβ,cβ<2t idβは被移転利用者βの特定番号 Bβ=rβ eTh(xβ) modnT h(xβ)はxβを変数とするハッシュ関数 eTは中立機関の秘密鍵dTに対応する公開鍵 前記中立機関の処理装置は、被移転利用者βから前記ブ
ラインド署名用データBβと、移転前の前記電子証券識
別部S1(xα)と、前記証券番号乱数aα,bα,z
αと、前記電子証券S(xα)の電子証券権利部S0に
含まれているデジタル証明書Cとを入力し、移転前の前
記証券番号xαからそのハッシュ関数h(xα)を算出
し、デジタル署名された証券番号のハッシュ関数h(x
α)dTをデジタル証明書Cで使用した秘密鍵dTと対を
なす公開鍵eTによって復号してh(xα)dT・eTを
算出し、両者を照合することにより、前記電子証券識別
部S1(xα)が前記電子証券権利部S0と一対一対応
であることを検証し、続いて前記証券番号xαがxα=
f(f(aα,bα),zα)の関係を満たすことを検
証することにより、前記電子証券識別部S1(xα)が
移転利用者αの合意の下に被移転利用者βに与えられた
ことを確認し、電子証券移転記録データベースで前記電
子証券識別部S1(xα)を検索することにより未移転
であることを確認し、未移転であることを条件に前記電
子証券識別部S1(xα)を移転済電子証券識別部とし
て登録し、前記デジタル証明書Cのデジタル署名に使用
した秘密鍵dTによって前記ブラインド署名用データB
βをデジタル署名してブラインド署名済データBβ’を
生成し、 ここで、 Bβ’=(rβ eT)dTh(xβ)dT mod nT =rβ・h(xβ)dT mod nT h(xβ)dTはh(xβ)をdTによってデジタル署名
したデータ 前記被移転利用者βの処理装置は、前記ブラインド署名
済データBβ’を入力し、これを前記ブラインド係数r
βによって除してデジタル署名済証券番号h(xβ)
dT mod nTを取得し、電子証券の識別部S1(x
β)を算出し、 ここで、 S1(xβ)=<xβ,h(xβ)dT mod nT> 続いて、電子証券権利部S0と電子証券識別部S1(x
β)とを組み合わせて電子証券S(xβ) S(xβ)=<S0,S1(xβ)> を生成して電子証券の移転手続を完了することを特徴と
する電子証券の発行、移転、証明、消去のための処理シ
ステム。
5. A processing system for issuing, transferring, certifying, and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral institution, wherein the transfer of electronic securities is performed. In the procedure, the processing device of the transferred user β acquires the electronic securities S (x α ) and the random numbers a α , b α , and z α of the security number x α of the transferred user α from the transferred user α. Generate new security number random numbers a β , b β , c β dedicated to the transfer user β and a blind coefficient r β (0 <r β <2 t , where t is a predetermined number of binary digits), using a specific number idβ the transferee user beta calculates the new certificate number x beta dedicated transferee user beta, followed by the policy number x beta blind signature data B that concealed by the blind coefficient r beta calculating a beta, where, S (x α) = < S 0, S 1 (x α)><> Waso Set of the inside of the data S 0 = <C, D, h (C | D) do mod n o> C is described d o of the digital certificate D is the rights and obligations related issuer secret key, n o is the issuer public key h of (C | D) is a hash function h to the variable C and D and the law | | (D C) data mod n o which was digitally signed by a d o is n o (C D) do is h C = <n T , e T , h (n T | e T ) dp mod n p > n T , e T is the public key d p , n p unique to the security corresponding to the rights and obligations public and secret key of institutions key h (n T | e T) hash function h to the variable n T and e T (n T | e T ) dT is h | digital by the (n T e T) d p signed data mod n p is S 1 indicating that the n p modulo (modulus) (x α) = <x α, h (x α) dT mod n T> x α Securities number h of transfer user α (x α) is a hash function h (x α) to the variable x α dT is h (x α) the data was digitally signed by the d T x α = f (y α, z α) y α = f (a α, b α) z α = f (id α, c α) a α, b α, the c α 0 <a α, b α, c α <2 t id α relocations The specific number f () of the user α is x ≠ such that f (x, y) = f (x ′, y ′)
x ', y ≠ y' difficult to find a one-way hash function x β = f (y β, z β) y β = f (a β, b β) z β = f (id β, c β X β is a new security number dedicated to the transferred user β a β , b β , c β is 0 <a β , b β , c β <2 t id β is the specific number of the transferred user β B β = processing apparatus of r β eT h (x β) modn T h (x β) hash and variable x β function e T is public key the neutral institution corresponding to the private key d T of neutral institutions, transferee From the user β, the blind signature data Bβ , the electronic security identification unit S 1 ( xα ) before transfer, and the security number random numbers aα , bα , z
and alpha, the inputs the digital certificate C contained in the electronic security rights section S 0 of the electronic securities S (x α), wherein the front transfer certificate number x alpha from the hash function h a (x alpha) The hash function h (x
α ) dT is decrypted by the public key e T paired with the secret key d T used in the digital certificate C to calculate h (x α ) dT · eT , and the two are compared to obtain the electronic security identification. It is verified that the section S 1 (x α ) has a one-to-one correspondence with the electronic securities right section S 0, and then the security number x α is x α =
f (f (a α, b α), z α) by verifying that satisfies the relationship, the electronic securities identification section S 1 (x α) is to be moved to under the transfer user alpha agreement user β, and by searching the electronic securities transfer record database for the electronic securities identification unit S 1 ( xα ), it is confirmed that the electronic securities have not been transferred. The electronic security identification unit S 1 ( xα ) is registered as the transferred electronic security identification unit, and the blind signature data B is obtained using the secret key d T used for the digital signature of the digital certificate C.
The beta and digital signature 'generated, where, B beta' blind signed data B β = (r β eT) dT h (x β) dT mod n T = r β · h (x β) dT mod n T h (x β) dT is h (x β) a processor of the data the transferee user beta was digitally signed by d T inputs the blind signed data B beta ', the blind factor this r
by dividing by β digital signed policy number h (x β)
dT mod n T is obtained, and the identification part S 1 (x
β ), where S 1 (x β ) = <x β , h (x β ) dT mod n T > Then, the electronic securities right unit S 0 and the electronic securities identification unit S 1 (x
β ) to generate electronic securities S ( xβ ) S ( xβ ) = <S 0 , S 1 ( xβ )> to complete the transfer procedure of electronic securities. Processing system for issuance, transfer, certification, erasure.
【請求項6】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理システムであって、電子証
券の証明手続において、 前記発行者の処理装置は、電子証券を所有する利用者か
ら電子証券と、その利用者のみが知り得る証券番号乱数
の一部とを取得し、その電子証券の証券番号と中立機関
のみがデジタル署名し得たデジタル署名済証券番号とか
らなる電子証券識別部と、その電子証券の電子証券権利
部に含まれているデジタル証明書と、前記証券番号乱数
の一部とを前記中立機関の処理装置に送って所有の証明
を要求し、 前記中立機関の処理装置は、前記デジタル証明書を介し
て前記電子証券識別部が前記電子証券権利部と一対一対
応であることの検証計算を行い、前記証券番号乱数の一
部と前記証券番号識別部の証券番号とを用いて前記証券
番号の乱数が電子証券を所有する利用者のみが知り得る
ことの検証の計算を行い、前記電子証券識別部を電子証
券証明記録データベースで検索し、検索と検証の結果を
前記発行者の処理装置に返送することを特徴とする電子
証券の発行、移転、証明、消去のための処理システム。
6. A processing system for issuing, transferring, certifying, and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral organization, wherein the certificate of the electronic certificate is provided. In the procedure, the processing device of the issuer obtains an electronic security from a user who owns the electronic security and a part of a security number random number that only the user can know, and obtains the security number of the electronic security and a neutral organization. An electronic securities identification unit consisting of a digitally signed security number that has only been digitally signed, a digital certificate included in the electronic securities rights section of the electronic security, and a part of the security number random number, A request for proof of ownership is sent to the processing device of the institution, and the processing device of the neutral institution verifies that the electronic securities identification unit is in one-to-one correspondence with the electronic securities rights unit via the digital certificate. And said Using a part of the certificate number random number and the security number of the security number identification unit, a verification calculation that only the user who owns the electronic security can know the random number of the security number is performed. A processing system for issuing, transferring, certifying, and erasing electronic securities, wherein a search is made in an electronic securities certificate record database, and the results of the search and verification are returned to the processing device of the issuer.
【請求項7】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理システムであって、電子証
券の証明手続において、 前記発行者oの処理装置は、電子証券を所有する利用者
Aから電子証券S(xA)と、利用者Aのみが知り得る
証券番号の乱数の一部yA,idA,cAとを取得し、前
記電子証券S(xA)の電子証券識別部S1(xA)と、
前記電子証券S(xA)の電子証券権利部S0に含まれ
ているデジタル証明書Cと、前記証券番号乱数の一部y
A,idA,cAとを中立機関Tの処理装置に送って所有
の証明を要求し、 ここで、 S(xA)=<S0,S1(xA)> <>はその内側のデータの集合 S0=<C,D,h(C|D)do mod no> Cはデジタル証明書 Dは権利義務関係の記述 doは発行者の秘密鍵 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)をdoによってデジタル
署名したデータ mod noはnoを法とすることを示す C=<nT,eT,h(nT|eT)dp mod np> nT,eTは権利義務内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)をdpによってデジ
タル署名したデータ mod npはnpを法(modulus)とすることを示す S1(xA)=<xA,h(xA)dT mod nT> xAは電子証券を所有する利用者Aが付与した証券番号 dTとnTはそれぞれの中立機関の秘密鍵と公開鍵 h(xA)はxAを変数とするハッシュ関数、 h(xA)dTはh(xA)をdTによってデジタル署名
したデータ xA=f(yA,zA) yA=f(aA,bA) zA=f(idA,cA) aA,bA,cAは証券番号の乱数 0<aA,bA,cA<2t tは2進数の所定の桁数 idAは利用者Aの特定番号 f()はf(x,y)=f(x′,y′)なるx≠
x′,y≠y′を見つけることが困難な一方向性ハッシ
ュ関数 前記中立機関Tの処理装置は、前記識別部S1(xA)
に含まれている証券番号xAからそのハッシュ関数h
(xA)を算出し、前記電子証券識別部S1(xA)に含
まれているデジタル署名された証券番号のハッシュ関数
h(xA)dTをデジタル証明書Cで使用した秘密鍵dT
と対をなす公開鍵eTによって復号してh(xA)
dT・eTを算出し、両者を照合することにより、電子証
券識別部S1(xA)が電子証券権利部S0と一対一対
応であることを検証し、続いて前記証券番号xAがxA=
f(yA,f(idA,cA))の関係を満たすことを計
算することにより、前記証券番号乱数の一部yA,i
dA,cAがその電子証券を所有する利用者のみが知り得
ることの検証を行い、電子証券証明記録データベースを
検索し、検索と検証の結果を前記発行者oの処理装置に
返送することを特徴とする電子証券の発行、移転、証
明、消去のための処理システム。
7. A processing system for issuing, transferring, certifying, and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral organization, wherein the certificate of the electronic certificate is provided. In the procedure, the processing device of the issuer o includes the electronic securities S (x A ) from the user A who owns the electronic securities, and a part y A , id A , of the random number of the security number that only the user A can know. obtains the c a, the electronic securities identification section S 1 of the electronic securities S (x a) and (x a),
Wherein the digital certificate C contained in the electronic security rights section S 0 of the electronic securities S (x A), a part of the policy number random number y
A, id A, send and c A the processor of NSO T requires proof of possession, where, S (x A) = < S 0, S 1 (x A)><> its inner the public of the issuer C is described d o is the secret key n o of the issuer of the digital certificate D is right and obligations | of a set of data S 0 = <(D C) do mod n o C, D, h> key h (C | D) is C and the hash function h to the variable D (C | D) do the h | data mod n o which was digitally signed by a (C D) d o is the modulo n o C = <n T , e T , h (n T | e T ) dp mod n p > n T , e T is the security-specific public key d p , n p corresponding to the content of rights and obligations secret key and a public key h (n T | e T) hash function h to the variable n T and e T (n T | e T ) dp is h | digital by the (n T e T) d p The signed data mod n p indicates that n p is a modulus S 1 (x A ) = <x A , h (x A ) dT mod n T > x A is the use of owning the electronic securities The security numbers d T and n T assigned by the party A are the secret key and public key of the neutral institution, h (x A ) is a hash function with x A as a variable, and h (x A ) dT is h (x A ) the data was digitally signed by d T x a = f (y a, z a) y a = f (a a, b a) z a = f (id a, c a) a a, b a, c a is Random number of securities number 0 <a A , b A , c A <2 tt is a predetermined number of binary digits id A is a specific number of user A f () is f (x, y) = f (x ′) , Y ') x ≠
One-way hash function in which it is difficult to find x ′, y ≠ y ′. The processing device of the neutral organization T includes the identification unit S 1 (x A )
The hash function h from the policy number x A, which is included in the
(X A ) is calculated, and a hash function h (x A ) dT of the digitally signed security number included in the electronic security identification unit S 1 (x A ) is used as a secret key d used in the digital certificate C. T
And decrypted by the public key e T paired with h (x A )
By calculating dT · eT and comparing the two, it is verified that the electronic securities identification unit S 1 (x A ) has a one-to-one correspondence with the electronic securities rights unit S 0, and then the security number x A is obtained. x A =
f (y A, f (id A, c A)) by calculating satisfy a relationship of a portion of the policy number random number y A, i
Verify that d A and c A are known only to the user who owns the electronic security, search the electronic security certificate record database, and return the search and verification results to the processing device of the issuer o. A processing system for issuing, transferring, certifying, and erasing electronic securities.
【請求項8】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理システムであって、電子証
券の消去手続において、 前記中立機関の処理装置は、消去を求められている電子
証券の証券番号と中立機関のみがデジタル署名し得たデ
ジタル署名済証券番号とからなる電子証券識別部と、そ
の電子証券の電子証券権利部に含まれているデジタル証
明書と、その電子証券の消去を求める発行者あるいは利
用者のみが知り得る前記証券番号の乱数の一部とを入力
し、前記デジタル証明書を介して前記電子証券識別部が
電子証券権利部と一対一対応であることの検証計算を行
い、前記証券番号の乱数の一部と前記証券番号識別部の
証券番号とを用いて前記証券番号乱数が電子証券の消去
を求めている発行者あるいは利用者のみが知り得ること
の検証の計算を行い、前記電子証券識別部を電子証券消
去記録データベースで検索し、未消去を条件に前記電子
証券識別部を消去済の電子証券識別部として登録するこ
とにより、電子証券の消去手続を完了することを特徴と
する電子証券の発行、移転、証明、消去のための処理シ
ステム。
8. A processing system for issuing, transferring, certifying, and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral organization, wherein the erasure of the electronic securities is performed. In the procedure, the processing unit of the neutral institution, the electronic securities identification unit consisting of the security number of the electronic security that is required to be erased and a digitally signed security number that can be digitally signed only by the neutral institution, Enter the digital certificate included in the electronic securities rights department and a part of the random number of the security number that can be known only to the issuer or user requesting the erasure of the electronic security, via the digital certificate A verification calculation is performed to confirm that the electronic securities identification unit is in one-to-one correspondence with the electronic securities right unit, and the security number random number is electronically calculated using a part of the security number random number and the security number of the security number identification unit. Of securities A verification calculation is performed to confirm that only the issuer or user seeking erasure can know, the electronic securities identification section is searched in the electronic securities erasure record database, and the electronic security identification section has been erased on the condition that it has not been erased. A processing system for issuing, transferring, certifying, and erasing electronic securities, characterized by completing an erasure procedure of electronic securities by registering as an electronic securities identification unit of the above.
【請求項9】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理システムであって、電子証
券の消去手続において、 前記中立機関の処理装置は、電子証券の消去を求める発
行者あるいは利用者Bから、消去を求められている電子
証券の電子証券識別部S1(xB)と、その電子証券の
電子証券権利部S0に含まれているデジタル証明書C
と、その電子証券の消去を求める発行者あるいは利用者
Bのみが知り得る証券番号乱数の一部aB,bB,zBと
を取得し、 ここで、 S(xB)=<S0,S1(xB)> <>はその内側のデータの集合 S0は電子証券権利部 S1(xB)は電子証券識別部 xBは消去を求められている電子証券の証券番号 S0=< C,D,h(C|D)do mod no> Cはデジタル証明書 Dは権利義務関係の記述 doは発行者の秘密鍵 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)をdoによってデジタ
ル署名したデータ mod noはnoを法(modulus)とすることを示す C=<nT,eT,h(nT|eT)dp mod np> nT,eTは権利内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)をdpによってデジ
タル署名したデータ mod npはnpを法(modulus)とすることを示す S1(xB)=<xB,h(xB)dT mod nT> dTとnTはそれぞれの中立機関の秘密鍵と公開鍵 h(xB)はxBを変数とするハッシュ関数、 h(xB)dTはh(xB)をdTによってデジタル署名し
たデータ xB=f(yB,zB) yB=f(aB,bB) zB=f(idB,cB) aB,bB,cBは証券番号の乱数 0<aB,bB,cB<2t tは2進数の所定の桁数 idBは消去を求める発行者、利用者Bの特定番号 f()はf(x,y)=f(x′,y′)なるx′≠
x′,y≠y′を見つけるのが困難な一方向性ハッシュ
関数 続いて前記中立機関の処理装置は、前記証券番号xBか
らそのハッシュ関数h(xB)を算出し、前記電子証券
識別部S1(xB)に含まれているデジタル署名された
証券番号のハッシュ関数h(xB)dTをデジタル証明書
Cで使用した秘密鍵dTと対をなす公開鍵eTによって復
号してh(xB)dT・eTを算出し、両者を照合するこ
とにより、電子証券識別部S1(xB)が電子証券権利
部S0と一対一対応であることを検証し、前記証券番号
xBがxB=f(f(aB,bB),zB))の関係を満た
すことを検証することにより、前記証券番号乱数の一部
aB,bB,zBが電子証券を消去を求める発行者あるい
は利用者Bのみが知り得ることの検証を行い、前記電子
証券識別部S1(xB)を電子証券消去記録データベー
スで検索し、未消去を条件に前記電子証券識別部S
1(xB)を消去済の電子証券識別部として登録するこ
とにより、電子証券の消去手続を完了することを特徴と
する電子証券の発行、移転、証明、消去のための処理シ
ステム。
9. A processing system for issuing, transferring, certifying, and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral organization, wherein the erasure of the electronic securities is performed. In the procedure, the processing device of the neutral institution, the issuer or user B requesting the erasure of the electronic security, the electronic security identification unit S 1 (x B ) of the electronic security that is required to be erased, and the electronic security digital certificate C, which is included in the electronic securities right part S 0
And part of the security number random numbers a B , b B , and z B that can be known only by the issuer or user B requesting erasure of the electronic security, where S (x B ) = <S 0 , S 1 (x B ) >><> is a set of data inside S 0 is an electronic securities right section S 1 (x B ) is an electronic securities identification section x B is a security number S of an electronic security which is required to be erased 0 = <C, D, h (C | D) do mod n o> C digital certificate D description of the rights and obligations d o is the issuer of the secret key n o is the issuer's public key h (C | D) is a hash function h (C whose variable C and D | to a D) data mod n o which was digitally signed by a d o is n o law (modulus) | is D) d o h (C C = <n T, e T , h (n T | e T) dp mod n p> shown n T, e T securities-specific public corresponding to the right content Key d p, n p is the secret key of a neutral agency public key h (n T | e T) is a hash function as a variable n T and e T h (n T | e T) dp is h (n T | e T) and S 1 data mod n p which is digitally signed by d p, which indicates that the n p modulo (modulus) (x B) = <x B, h (x B) dT mod n T> d T And n T are the secret key and public key of the neutral institution, respectively. H (x B ) is a hash function using x B as a variable, h (x B ) dT is data obtained by digitally signing h (x B ) with d T x B = f (y B, z B) y B = f (a B, b B) z B = f (id B, c B) a B, b B, c B is a random number of policy number 0 <a B, b B , c B <2 tt is a predetermined number of binary digits id B is an issuer requesting erasure, user B's specific number f () is f (x, y) = f (x ′, y ′) X '≠
A one-way hash function in which it is difficult to find x ′, y ≠ y ′. Subsequently, the processing unit of the neutral organization calculates a hash function h (x B ) from the security number x B and obtains the electronic security identification. The hash function h (x B ) dT of the digitally signed security number included in the part S 1 (x B ) is decrypted by the public key e T paired with the secret key d T used in the digital certificate C. By calculating h (x B ) dT · eT and comparing them, it is verified that the electronic securities identification unit S 1 (x B ) has a one-to-one correspondence with the electronic securities rights unit S 0, and ID x B is x B = f (f (a B, b B), z B) by verifying that satisfies the relationship), part a B of the policy number random number, b B, is z B electron Verify that only the issuer or user B seeking erasure of the security can know, Identifying portion S 1 a (x B) searching in an electronic securities erase record database, the electronic securities identifying unit S non erased condition
By registering 1 (x B) as an electron securities identification of erased, issues an electronic certificate, characterized in that to complete the erasing procedure of the electronic securities, transfer, certification, processing system for erasing.
【請求項10】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理方法であって、電子証券の
発行手続において、 前記中立機関の処理装置は、中立機関のみがデジタル署
名し得るデジタル証明書を生成し、 前記発行者の処理装置は、発行者のみがデジタル署名し
得る前記デジタル証明書と権利義務関係の記述の暗号化
データを含む電子証券権利部を生成する一方、証券番号
を生成し、前記証券番号を秘匿したブラインド署名用デ
ータを生成し、 前記中立機関の処理装置は、前記デジタル証明書と前記
ブラインド署名用データとを入力し、前記デジタル証明
書をデジタル署名したのと同一の秘密鍵により前記ブラ
インド署名用データをデジタル署名することにより、中
立機関のみがデジタル署名し得るブラインド署名済デー
タを生成し、 前記発行者の処理装置は、前記ブラインド署名済データ
を入力し、アンブラインド処理して中立機関のみがデジ
タル署名し得るデジタル署名済証券番号を取得し、この
中立機関によるデジタル署名済証券番号を含む電子証券
識別部を生成し、前記電子証券権利部と電子証券識別部
とを組み合わせて電子証券の発行手続を完了することを
特徴とする電子証券の発行、移転、証明、消去のための
処理方法。
10. A processing method for issuing, transferring, certifying, and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral institution, wherein issuance of electronic securities. In the procedure, the processing device of the neutral institution generates a digital certificate that can be digitally signed only by the neutral institution, and the processing device of the issuer has the rights and obligations relationship with the digital certificate that can only be digitally signed by the issuer. While generating an electronic securities right part including the encrypted data of the description, generates a security number, generates blind signature data concealing the security number, the processing device of the neutral organization, the digital certificate and the digital certificate By inputting the blind signature data and digitally signing the blind signature data with the same private key that digitally signed the digital certificate, The issuer generates blind-signed data that can be digitally signed only by the institution, and the processing device of the issuer inputs the blind-signed data, performs unblind processing, and executes a digitally signed security number that can be digitally signed only by a neutral institution. And generating an electronic securities identification unit including the digitally signed security number by the neutral institution, and combining the electronic securities right unit and the electronic securities identification unit to complete the electronic securities issuance procedure. Processing methods for issuing, transferring, certifying, and erasing electronic securities.
【請求項11】前記発行者の装置が生成する証券番号
は、下式の関係を満たす3つの乱数a,b,cと発行者
の特定番号idによって計算されるものであることを特
徴とする請求項10に記載の電子証券の発行、移転、証
明、消去のための処理方法。 x=f(y,z) y=f(a,b) z=f(id,c) ここで、x:証券番号 f():f(x,y)=f(x′,y′)なるx≠
x′,y≠y≠を見つけることが困難な一方向性ハッシ
ュ関数
11. The security number generated by the issuer's device is calculated by three random numbers a, b, c satisfying the following relationship and the issuer's specific number id. A processing method for issuing, transferring, certifying, and erasing the electronic securities according to claim 10. x = f (y, z) y = f (a, b) z = f (id, c) where x: security number f (): f (x, y) = f (x ′, y ′) X
A one-way hash function that is difficult to find x ', y {y}
【請求項12】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理方法であって、電子証券の
発行手続において、 前記中立機関の処理装置は、発行者の要求に応じて電子
証券ごとにRSA系の鍵nT,eT,pT,qT,dTを生
成し、その公開鍵のnT,eTを秘密鍵dTによってデジ
タル署名したデジタル証明書Cを生成し、 ここで、 C=<nT,eT,h(nT|eT)dp mod np> <>はその内側のデータの集合 nT,eT は権利内容に対応する証券固有の公開鍵 dp,np は中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)を秘密鍵dpによっ
てデジタル署名したデータ mod npはnpを法(modulus)とすることを示す 前記発行者の処理装置は、前記デジタル証明書Cと電子
証券の権利義務を記述した記述Dとを入力し、電子証券
の権利部S0を出力し、 ここで、 S0=<C,D,h(C|D)do mod no> doは発行者の秘密鍵 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)を秘密鍵doによってデ
ジタル署名したデータ mod noはnoを法(modulus)とすることを示す 前記中立機関の処理装置は、前記デジタル証明書Cと電
子証券権利部S0とを入力し、電子証券発行記録データ
ベースで前記デジタル証明書Cを検索し、そのデジタル
証明書Cが他の電子証券に使用されていないことを条件
に前記デジタル証明書Cと電子証券の権利部S0を組と
して前記電子証券発行記録データベースに登録し、 前記発行者の処理装置は、証券番号乱数a,b,c(0
<a,b,c<2t、tは2進数の所定の桁数)と、ブ
ラインド係数r(0<r<2t、tは2進数の所定の桁
数)とをランダムに生成し、発行者の特定番号idを用
いて証券番号xを算出し、続いて前記証券番号xを前記
ブラインド係数rによって秘匿したブラインド署名用デ
ータBを算出し、 ここで、 x=f(y,z) y=f(a,b) z=f(id,c) f( )はf(x,y)=f(x′,y′)なるx≠
x′,y≠y′を見つけることが困難な一方向性ハッシ
ュ関数を示し、 B=reTh(x) mod nT h(x)はxを変数とするハッシュ関数 mod nTはnTを法(modulus)とすることを示す 前記中立機関の処理装置は、前記ブラインド署名用デー
タBと前記デジタル証明書Cを入力し、前記デジタル証
明書Cのデジタル署名に使用した前記秘密鍵dTによっ
て前記ブラインド署名用データBをデジタル署名したブ
ラインド署名済データB’を生成し、 ここで、 B’=(reT)dTh(x)dT mod nT =r・h(x)dT mod nT h(x)dTはh(x)を秘密鍵dTによってデジタル署
名したデータ 前記発行者の処理装置は、前記ブラインド署名済データ
B’を入力し、これを前記ブラインド係数rによって除
して電子証券の識別部S1(x)を算出し、 ここで、 S1(x)=<x,h(x)dT mod nT> 続いて、電子証券権利部S0と電子証券識別部S
1(x)とを組み合わせて電子証券S(x) S(x)=<S0,S1(x)> を生成して電子証券の発行手続を完了することを特徴と
する電子証券の発行、移転、証明、消去のための処理方
法。
12. A processing method for issuing, transferring, certifying, and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral institution, wherein issuance of electronic securities. In the procedure, the processing unit of the neutral institution generates an RSA key n T , e T , p T , q T , d T for each electronic security at the request of the issuer, and generates a public key n T. , E T with a secret key d T to generate a digital certificate C, where C = <n T , e T , h (n T | e T ) dp mod n p ><> The data set n T , e T is the public key unique to the security corresponding to the right content d p , n p is the secret key and public key of a neutral institution h (n T | e T ) is the variable n T and e T The hash function h (n T | e T ) dp is data mo that is a digital signature of h (n T | e T ) with the secret key d p d np indicates that n p is a modulus The processor of the issuer inputs the digital certificate C and the description D describing the rights and obligations of the electronic securities, and outputs the S 0, here, S 0 = <C, D , h (C | D) do mod n o> d o is of the issuer secret key n o is the issuer of the public key h (C | D) the hash function h to the variable C and D show that the | | (D C) data mod n o which was digitally signed by the private key d o is n o law (modulus) is (C D) do h processor of the NSO inputs and said digital certificate C and ECN right portion S 0, searches the digital certificate C in the electronic securities issuing record database, the digital certificate C is another electronic securities Said digital certificate C and the rights section of the electronic securities provided that they are not used 0 and registered in the electronic securities issuing record database as a set, the issuer of the processor, policy number random number a, b, c (0
<A, b, c <2 t , where t is a predetermined number of binary digits) and a blind coefficient r (0 <r <2 t , t is a predetermined number of binary digits), are randomly generated, The security number x is calculated using the issuer's specific number id, and then the blind signature data B in which the security number x is concealed by the blind coefficient r is calculated, where x = f (y, z) y = f (a, b) z = f (id, c) f () is x ≠ such that f (x, y) = f (x ′, y ′)
x ', y ≠ y' indicates the hard one-way hash function to find a, B = r eT h (x ) mod n T h (x) is a hash function mod n T of the variables x n T Is a modulus. The processing unit of the neutral organization inputs the blind signature data B and the digital certificate C, and uses the secret key d T used for the digital signature of the digital certificate C. said blind signature data B 'to generate where, B' blind signed data B digitally signed by = (r eT) dT h ( x) dT mod n T = r · h (x) dT mod n T h (x) dT is h (x) processor of the data the issuer digitally signed by the private key d T a, enter the blind signed data B ', which was divided by the blind coefficient r Identification of electronic securities Calculate the section S 1 (x), where S 1 (x) = <x, h (x) dT mod n T > Then, the electronic securities right section S 0 and the electronic securities identification section S
1 (x) by combining the electronic securities S (x) S (x) = issuance of electronic securities, characterized in that to generate the <S 0, S 1 (x )> to complete the registration procedure with the electronic securities Processing for transfer, certification, erasure.
【請求項13】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理方法であって、電子証券の
移転手続において、 被移転利用者の処理装置は、移転者から電子証券と移転
者のみが知り得る移転前の証券番号の乱数の一部とを取
得し、被移転利用者専用の新たな証券番号を生成し、前
記新たな証券番号を秘匿したブラインド署名用データを
生成し、 中立機関の処理装置は、被移転利用者から前記ブライン
ド署名用データと、移転前の証券番号と中立機関のみが
デジタル署名し得たデジタル署名済証券番号とからなる
電子証券識別部と、前記移転者のみが知り得る移転前の
証券番号の乱数の一部と、前記電子証券の電子証券権利
部に含まれているデジタル証明書とを入力し、前記デジ
タル証明書を介して前記移転前の電子証券識別部と前記
電子証券権利部とが一対一対応であることの検証計算を
行い、前記移転前の証券番号の乱数の一部と前記移転前
の証券番号識別部の証券番号とを用いて前記移転前の電
子証券識別部が移転利用者の合意の下に被移転利用者に
与えられたことの検証計算を行い、前記移転前の電子証
券識別部が未移転であることを電子証券移転記録データ
ベースで確認して未移転であったことを条件に移転者の
前記電子証券識別部を移転済の電子証券識別部として登
録するとともに、前記デジタル証明書をデジタル署名し
たのと同一の秘密鍵によって前記ブラインド署名用デー
タをデジタル署名することにより、中立機関のみがデジ
タル署名し得るブラインド署名済データを生成し、 前記被移転者の処理装置は、前記ブラインド署名済デー
タをアンブラインド処理して中立機関のみがデジタル署
名し得る新たなデジタル署名済証券番号を取得し、新た
な前記証券番号と前記デジタル署名済証券番号とからな
る電子証券識別部を生成し、前記電子証券権利部と新た
な電子証券識別部とを組み合わせて電子証券の移転手続
を完了することを特徴とする電子証券の発行、移転、証
明、消去のための処理方法。
13. A processing method for issuing, transferring, certifying, and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral institution, wherein the transfer of electronic securities is performed. In the procedure, the processor of the transferred user obtains the electronic securities from the transferor and a part of the random number of the security number before transfer which can be known only by the transferor, and obtains a new security number exclusively for the transferred user. The new security number is concealed and generates blind signature data for concealing the new security number. An electronic securities identification unit consisting of the obtained digitally signed security number, a part of the random number of the security number before transfer that only the transferor can know, and a digital number included in the electronic securities right part of the electronic security. Certificate and enter Performing a verification calculation that the electronic securities identification unit and the electronic securities right unit before transfer are in one-to-one correspondence via the digital certificate, and a part of a random number of the security number before transfer and the transfer. Using the security number of the previous security number identification unit and the electronic security identification unit before the transfer, a verification calculation is performed to determine that the electronic security identification unit was given to the transferee under the agreement of the transfer user, While confirming in the electronic securities transfer record database that the securities identification unit has not been transferred, and registering the electronic securities identification unit of the transferee as a transferred electronic securities identification unit on the condition that it has not been transferred, Digitally signing the blind signing data with the same private key as that used to digitally sign the digital certificate, thereby generating blind signed data that can be digitally signed only by a neutral authority. The processing device of the third party unblinds the blind-signed data to obtain a new digitally signed security number that can be digitally signed only by a neutral organization, and obtains the new security number and the digitally signed security number from the new security number. For issuing, transferring, certifying, and erasing electronic securities, wherein the electronic securities right section and the new electronic securities identifying section are combined to complete an electronic securities transfer procedure. Processing method.
【請求項14】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理方法であって、電子証券の
移転手続において、 被移転利用者βの処理装置は、移転利用者αから電子証
券S(xα)と移転利用者αの証券番号xαの乱数
aα,bα,zαを取得し、被移転利用者β専用の新た
な証券番号の乱数aβ,bβ,cβと、ブラインド係数
rβ(0<rβ<2t、tは2進数の所定の桁数)とを
生成し、被移転利用者βの特定番号idβを用いて被移
転利用者β専用の新たな証券番号xβを算出し、続いて
前記証券番号xβを前記ブラインド係数rβによって秘
匿したブラインド署名用データBβを算出し、 ここで、 S(xα)=<S0,S1(xα)> <>はその内側のデータの集合 S0=<C,D,h(C|D)do mod no> Cはデジタル証明書 Dは権利義務関係の記述 doは発行者の秘密鍵 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)をdoによってデジタ
ル署名したデータ mod noはnoを法(modulus)とすることを示す C=<nT,eT,h(nT|eT)dp mod np> nT,eTは権利義務内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)をdpによってデジ
タル署名したデータ mod npはnpを法(modulus)とすることを示す S1(xα)=<xα,h(xα)dT mod nT> xαは移転利用者αの証券番号 h(xα)はxαを変数とするハッシュ関数 h(xα)dTはh(xα)をdTによってデジタル署名
したデータ xα=f(yα,zα) yα=f(aα,bα) zα=f(idα,cα) aα,bα,cαは0<aα,bα,cα<2t idαは移転利用者αの特定番号 f( )はf(x,y)=f(x′,y′)なるx≠
x′,y≠y′を見つけるのが困難な一方向性ハッシュ
関数 xβ=f(yβ,zβ) yβ=f(aβ,bβ) zβ=f(idβ,cβ) xβは被移転利用者β専用の新たな証券番号 aβ,bβ,cβは0<aβ,bβ,cβ<2t idβは被移転利用者βの特定番号 Bβ=rβ eTh(xβ) mod nT h(xβ)はxβを変数とするハッシュ関数 eTは中立機関の秘密鍵dTに対応する公開鍵 前記中立機関の処理装置は、被移転利用者βから前記ブ
ラインド署名用データBβと、移転前の前記電子証券識
別部S1(xα)と、前記証券番号乱数aα,bα,z
αと、前記電子証券S(xα)の電子証券権利部S0に
含まれているデジタル証明書Cとを入力し、移転前の前
記証券番号xαからそのハッシュ関数h(xα)を算出
し、デジタル署名された証券番号のハッシュ関数h(x
α)dTをデジタル証明書Cで使用した秘密鍵dTと対を
なす公開鍵eTによって復号してh(xα)dT・eTを
算出し、両者を照合することにより、前記電子証券識別
部S1(xα)が前記電子証券権利部S0と一対一対応
であることを検証し、続いて前記証券番号xαがxα=
f(f(aα,bα),zα)の関係を満たすことを検
証することにより、前記電子証券識別部S1(xα)が
移転利用者αの合意の下に被移転利用者βに与えられた
ことを確認し、電子証券移転記録データベースで前記電
子証券識別部S1(xα)を検索することにより未移転
であることを確認し、未移転であることを条件に前記電
子証券識別部S1(xα)を移転済電子証券識別部とし
て登録し、前記デジタル証明書Cのデジタル署名に使用
した秘密鍵dTによって前記ブラインド署名用データB
βをデジタル署名してブラインド署名済データBβ’を
生成し、 ここで、 Bβ’=(rβ eT)dTh(xβ)dT mod nT =rβ・h(xβ)dT mod nT h(xβ)dTはh(xβ)をdTによってデジタル署名
したデータ 前記被移転利用者βの処理装置は、前記ブラインド署名
済データBβ’を入力し、これを前記ブラインド係数r
βによって除してデジタル署名済証券番号h(xβ)
dT mod nTを取得し、電子証券の識別部S1(x
β)を算出し、 ここで、 S1(xβ)=<xβ,h(xβ)dT mod nT> 続いて、電子証券権利部S0と電子証券識別部S1(x
β)とを組み合わせて電子証券S(xβ) S(xβ)=<S0,S1(xβ)>を生成して電子証
券の移転手続を完了することを特徴とする電子証券の発
行、移転、証明、消去のための処理方法。
14. A processing method for issuing, transferring, certifying and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral institution, wherein the transfer of electronic securities is performed. In the procedure, the processing device of the transferred user β acquires the electronic security S (x α ) and the random numbers a α , b α , and z α of the security number xα of the transferred user α from the transferred user α , and A new random number a β , b β , c β of a new security number dedicated to the user β and a blind coefficient r β (0 <r β <2 t , where t is a predetermined number of binary digits) are generated. Using the specific number id β of the transfer user β, a new security number x β dedicated to the transferred user β is calculated, and then the security number x β is concealed by the blind coefficient r β for blind signature data B. calculating a beta, where, S (x α) = < S 0, S 1 (x α)><> its Set S 0 = side of the data <C, D, h (C | D) do mod n o> C is the digital certificate D rights and obligations described d o is the secret key n o of the issuer of the issuer public key h (C | D) is a hash function as a variable C and D h (C | D) d o is h (C | D) data mod n o which was digitally signed by a d o is n o law ( C = <n T , e T , h (n T | e T ) dp mod n p > n T , e T is a security-specific public key d p , n corresponding to the content of rights and obligations p is a secret key and a public key of a neutral institution. h (n T | e T ) is a hash function h (n T | e T ) with n T and e T as variables. dp is h (n T | e T ). S 1 is data mod n p which is digitally signed by the p to indicate that the n p modulo (modulus) (x α) = <x α, h (x α) dT mod n T x α is policy number h of transfer user α (x α) is x hash function h (x α) dT to the variable α is h (x α) the data was digitally signed by the d T x α = f (y α , z α ) y α = f (a α , b α ) z α = f (id α , c α ) a α , b α , and c α are 0 <a α , b α , c α <2 t id α is the specific number of the transfer user α. f () is f (x, y) = f (x ′, y ′) x ≠
x ', y ≠ y' hard one-way hash function to find the x β = f (y β, z β) y β = f (a β, b β) z β = f (id β, c β X β is a new security number dedicated to the transferred user β a β , b β , c β is 0 <a β , b β , c β <2 t id β is the specific number of the transferred user β B β = r β eT h (x β ) mod n T h (x β) the processing unit of the hash function e T is the public key the NSO corresponding to the private key d T of NSO to variable x beta is to be From the transfer user β, the blind signature data B β , the electronic security identification unit S 1 (x α ) before the transfer, and the security number random numbers a α , b α , z
and alpha, the inputs the digital certificate C contained in the electronic security rights section S 0 of the electronic securities S (x α), wherein the front transfer certificate number x alpha from the hash function h a (x alpha) The hash function h (x
α ) dT is decrypted by the public key e T paired with the secret key d T used in the digital certificate C to calculate h (x α ) dT · eT , and the two are compared to obtain the electronic security identification. It is verified that the section S 1 (x α ) has a one-to-one correspondence with the electronic securities right section S 0, and then the security number x α is x α =
f (f (a α, b α), z α) by verifying that satisfies the relationship, the electronic securities identification section S 1 (x α) is to be moved to under the transfer user alpha agreement user β, and by searching the electronic securities transfer record database for the electronic securities identification unit S 1 ( xα ), it is confirmed that the electronic securities have not been transferred. The electronic security identification unit S 1 ( xα ) is registered as the transferred electronic security identification unit, and the blind signature data B is obtained using the secret key d T used for the digital signature of the digital certificate C.
The beta and digital signature 'generated, where, B beta' blind signed data B β = (r β eT) dT h (x β) dT mod n T = r β · h (x β) dT mod n T h (x β) dT is h (x β) a processor of the data the transferee user beta was digitally signed by d T inputs the blind signed data B beta ', the blind factor this r
by dividing by β digital signed policy number h (x β)
dT mod n T is obtained, and the identification part S 1 (x
β ), where S 1 (x β ) = <x β , h (x β ) dT mod n T > Then, the electronic securities right unit S 0 and the electronic securities identification unit S 1 (x
β ) to generate electronic securities S (x β ) S (x β ) = <S 0 , S 1 (x β )> and complete the transfer procedure of the electronic securities. Processing methods for issuance, transfer, certification, and erasure.
【請求項15】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理方法であって、電子証券の
証明手続において、 前記発行者の処理装置は、電子証券を所有する利用者か
ら電子証券と、その利用者のみが知り得る証券番号乱数
の一部とを取得し、その電子証券の証券番号と中立機関
のみがデジタル署名し得たデジタル署名済証券番号とか
らなる電子証券識別部と、その電子証券の電子証券権利
部に含まれているデジタル証明書と、前記証券番号乱数
の一部とを前記中立機関の処理装置に送って所有の証明
を要求し、 前記中立機関の処理装置は、前記デジタル証明書を介し
て前記電子証券識別部が前記電子証券権利部と一対一対
応であることの検証計算を行い、前記証券番号乱数の一
部と前記証券番号識別部の証券番号とを用いて前記証券
番号の乱数が電子証券を所有する利用者のみが知り得る
ことの検証の計算を行い、前記電子証券識別部を電子証
券証明記録データベースで検索し、検索と検証の結果を
前記発行者の処理装置に返送することを特徴とする電子
証券の発行、移転、証明、消去のための処理方法。
15. A processing method for issuing, transferring, certifying, and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral organization, wherein the certificate of the electronic certificate is provided. In the procedure, the processing device of the issuer obtains an electronic security from a user who owns the electronic security and a part of a security number random number that only the user can know, and obtains the security number of the electronic security and a neutral organization. An electronic securities identification unit consisting of a digitally signed security number that has only been digitally signed, a digital certificate included in the electronic securities rights section of the electronic security, and a part of the security number random number, A request for proof of ownership is sent to the processing device of the institution, and the processing device of the neutral institution verifies that the electronic securities identification unit is in one-to-one correspondence with the electronic securities rights unit via the digital certificate. Perform the above Using a part of the number random number and the security number of the security number identification unit, a calculation is performed to verify that the random number of the security number can be known only to the user who owns the electronic security, and the electronic security identification unit A method for issuing, transferring, certifying, and erasing electronic securities, wherein a search is made in a security certificate record database, and the results of the search and verification are returned to a processing device of the issuer.
【請求項16】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理方法であって、電子証券の
証明手続において、 前記発行者oの処理装置は、電子証券を所有する利用者
Aから電子証券S(xA)と、利用者Aのみが知り得る
証券番号の乱数の一部yA,idA,cAとを取得し、前
記電子証券S(xA)の電子証券識別部S1(xA)と、
前記電子証券S(xA)の電子証券権利部S0 に含まれ
ているデジタル証明書Cと、前記証券番号乱数の一部y
A,idA,cAとを中立機関Tの処理装置に送って所有
の証明を要求し、 ここで、 S(xA)=<S0,S1(xA)> <>はその内側のデータの集合 S0=<C,D,h(C|D)do mod no> Cはデジタル証明書 Dは権利義務関係の記述 doは発行者の秘密鍵 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)をdoによってデジタル
署名したデータ modnoはnoを法(modulus)とすることを示す C=<nT,eT,h(nT|eT)dp mod np> nT,eTは権利義務内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)をdpによってデジ
タル署名したデータ mod npはnpを法(modulus )とすることを示す S1(xA)=<xA,h(xA)dT mod nT> xAは電子証券を所有する利用者Aが付与した証券番号 dTとnTはそれぞれの中立機関の秘密鍵と公開鍵 h(xA)はxAを変数とするハッシュ関数、 h(xA)dTはh(xA)をdTによってデジタル署名し
たデータ xA=f(yA,zA) yA=f(aA,bA) zA=f(idA,cA) aA,bA,cAは証券番号の乱数 0<aA,bA,cA<2t tは2進数の所定の桁数 idAは利用者Aの特定番号 f()はf(x,y)=f(x′,y′)なるx≠
x′,y≠y′を見つけるのが困難な一方向性ハッシュ
関数 前記中立機関Tの処理装置は、前記識別部S1(xA)
に含まれている証券番号xAからそのハッシュ関数h
(xA)を算出し、前記電子証券識別部S1(xA)に含
まれているデジタル署名された証券番号のハッシュ関数
h(xA)dTをデジタル証明書Cで使用した秘密鍵dT
と対をなす公開鍵eTによって復号してh(xA)
dT・eTを算出し、両者を照合することにより、電子証
券識別部S1(xA)が電子証券権利部S0 と一対一対
応であることを検証し、続いて前記証券番号xAがxA
=f(yA,f(idA,cA))の関係を満たすことを
計算することにより、前記証券番号乱数の一部yA,i
dA,cAがその電子証券を所有する利用者のみが知り得
ることの検証を行い、電子証券証明記録データベースを
検索し、検索と検証の結果を前記発行者oの処理装置に
返送することを特徴とする電子証券の発行、移転、証
明、消去のための処理方法。
16. A processing method for issuing, transferring, certifying, and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral institution, wherein the proof of the electronic security is provided. In the procedure, the processing device of the issuer o includes the electronic securities S (x A ) from the user A who owns the electronic securities, and a part y A , id A , of the random number of the security number that only the user A can know. obtains the c a, the electronic securities identification section S 1 of the electronic securities S (x a) and (x a),
A digital certificate C included in the electronic securities right section S 0 of the electronic security S (x A ), and a part y of the security number random number
A, id A, send and c A the processor of NSO T requires proof of possession, where, S (x A) = < S 0, S 1 (x A)><> its inner the public of the issuer C is described d o is the secret key n o of the issuer of the digital certificate D is right and obligations | of a set of data S 0 = <(D C) do mod n o C, D, h> key h (C | D) is C and the hash function h to the variable D (C | D) do the h | a (C D) data was digitally signed by d o modn o is modulo n o (modulus) C = <n T , e T , h (n T | e T ) dp mod n p > n T , e T is the public key d p , n p unique to the security corresponding to the rights and obligations The institution's private key and public key h (n T | e T ) are hash functions h (n T | e T ) dp with n T and e T as variables, and h (n T | e T ) is obtained by d p Mod n p indicates that n p is a modulus S 1 (x A ) = <x A , h (x A ) dT mod n T > x A has an electronic security The security numbers d T and n T assigned by user A are the secret key and public key of the neutral institution, respectively. H (x A ) is a hash function using x A as a variable, and h (x A ) dT is h (x A ) the data was digitally signed by d T x a = f (y a, z a) y a = f (a a, b a) z a = f (id a, c a) a a, b a, c a Is the random number of the security number 0 <a A , b A , c A <2 tt is the predetermined number of binary digits id A is the specific number of the user A f () is f (x, y) = f (x ', Y') x ≠
One-way hash function in which it is difficult to find x ′, y ≠ y ′. The processing device of the neutral organization T includes the identification unit S 1 (x A )
The hash function h from the policy number x A, which is included in the
(X A ) is calculated, and a hash function h (x A ) dT of the digitally signed security number included in the electronic security identification unit S 1 (x A ) is used as a secret key d used in the digital certificate C. T
And decrypted by the public key e T paired with h (x A )
By calculating dT · eT and comparing the two, it is verified that the electronic securities identification unit S 1 (x A ) has a one-to-one correspondence with the electronic securities right unit S 0, and then the security number xA is x A
= F (y A , f (id A , c A )) to calculate a part of the security number random number y A , i
Verify that d A and c A are known only to the user who owns the electronic security, search the electronic security certificate record database, and return the search and verification results to the processing device of the issuer o. A processing method for issuing, transferring, certifying, and erasing electronic securities characterized by the following.
【請求項17】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理方法であって、電子証券の
消去手続において、 前記中立機関の処理装置は、消去を求められている電子
証券の証券番号と中立機関のみがデジタル署名し得たデ
ジタル署名済証券番号とからなる電子証券識別部と、そ
の電子証券の電子証券権利部に含まれているデジタル証
明書と、その電子証券の消去を求める発行者あるいは利
用者のみが知り得る前記証券番号の乱数の一部とを入力
し、前記デジタル証明書を介して前記電子証券識別部が
電子証券権利部と一対一対応であることの検証計算を行
い、前記証券番号の乱数の一部と前記証券番号識別部の
証券番号とを用いて前記証券番号乱数が電子証券の消去
を求めている発行者あるいは利用者のみが知り得ること
の検証の計算を行い、前記電子証券識別部を電子証券消
去記録データベースで検索し、未消去を条件に前記電子
証券識別部を消去済の電子証券識別部として登録するこ
とにより、電子証券の消去手続を完了することを特徴と
する電子証券の発行、移転、証明、消去のための処理方
法。
17. A processing method for issuing, transferring, certifying, and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral organization, wherein the erasing of the electronic securities is performed. In the procedure, the processing unit of the neutral institution, the electronic securities identification unit consisting of the security number of the electronic security that is required to be erased and a digitally signed security number that can be digitally signed only by the neutral institution, Enter the digital certificate included in the electronic securities rights department and a part of the random number of the security number that can be known only to the issuer or user requesting the erasure of the electronic security, via the digital certificate A verification calculation is performed to confirm that the electronic securities identification unit is in one-to-one correspondence with the electronic securities right unit, and the security number random number is electronically calculated using a part of the security number random number and the security number of the security number identification unit. Erasure of securities A calculation is performed to verify that only the issuer or user seeking the deletion can be known, the electronic securities identification unit is searched in the electronic securities erasure record database, and the electronic security identification unit has been erased on the condition that it has not been erased. A processing method for issuing, transferring, certifying, and erasing electronic securities, characterized in that the procedure for erasing electronic securities is completed by registering as an electronic securities identification unit.
【請求項18】発行者の処理装置と、利用者の処理装置
と、中立機関の処理装置とからなる電子証券の発行、移
転、証明、消去のための処理方法であって、電子証券の
消去手続において、 前記中立機関の処理装置は、電子証券の消去を求める発
行者あるいは利用者Bから、消去を求められている電子
証券の電子証券識別部S1(xB)と、その電子証券の
電子証券権利部S0に含まれているデジタル証明書C
と、その電子証券の消去を求める発行者あるいは利用者
Bのみが知り得る証券番号乱数の一部aB,bB,zBと
を取得し、 ここで、 S(xB)=<S0,S1(xB)> <>はその内側のデータの集合 S0は電子証券権利部 S1(xB)は電子証券識別部 xBは消去を求められている電子証券の証券番号 S0=<C,D,h(C|D)do mod no> Cはデジタル証明書 Dは権利義務関係の記述 doは発行者の秘密鍵 noは発行者の公開鍵 h(C|D)はCとDを変数とするハッシュ関数 h(C|D)doはh(C|D)をdoによってデジタル
署名したデータ mod noはnoを法(modulus)とすることを示す C=<nT,eT,h(nT|eT)dp mod np> nT,eTは権利義務内容に対応する証券固有の公開鍵 dp,npは中立機関の秘密鍵と公開鍵 h(nT|eT)はnTとeTを変数とするハッシュ関数 h(nT|eT)dpはh(nT|eT)をdpによってデジ
タル署名したデータ mod npはnpを法(modulus)とすることを示す S1(xB)=<xB,h(xB)dT mod nT> dTとnTはそれぞれの中立機関の秘密鍵と公開鍵 h(xB)はxBを変数とするハッシュ関数、 h(xB)dTはh(xB)をdTによってデジタル署名し
たデータ xB=f(yB,zB) yB=f(aB,bB) zB=f(idB,cB) aB,bB,cBは証券番号の乱数 0<aB,bB,cB<2t tは2進数の所定の桁数 idBは消去を求める発行者、利用者Bの特定番号 f()はf(x,y)=f(x′,y′)なるx≠
x′,y≠y′を見つけるのが困難な一方向性ハッシュ
関数 続いて前記中立機関の処理装置は、前記証券番号xBか
らそのハッシュ関数h(xB)を算出し、前記電子証券
識別部S1(xB)に含まれているデジタル署名された
証券番号のハッシュ関数h(xB)dTをデジタル証明書
Cで使用した秘密鍵dTと対をなす公開鍵eTによって復
号してh(xB)dT・eTを算出し、両者を照合するこ
とにより、電子証券識別部S1(xB)が電子証券権利
部S0と一対一対応であることを検証し、前記証券番号
xBがxB=f(f(aB,bB),zB)の関係を満たす
ことを検証することにより、前記証券番号乱数の一部a
B,bB,zBが電子証券を消去を求める発行者あるいは
利用者Bのみが知り得ることの検証を行い、前記電子証
券識別部S1(xB)を電子証券消去記録データベース
で検索し、未消去を条件に前記電子証券識別部S1(x
B)を消去済の電子証券識別部として登録することによ
り、電子証券の消去手続を完了することを特徴とする電
子証券の発行、移転、証明、消去のための処理方法。
18. A processing method for issuing, transferring, certifying, and erasing electronic securities, comprising a processing device of an issuer, a processing device of a user, and a processing device of a neutral institution, wherein the erasing of the electronic securities is performed. In the procedure, the processing device of the neutral institution, the issuer or user B requesting the erasure of the electronic security, the electronic security identification unit S 1 (x B ) of the electronic security that is required to be erased, and the electronic security digital certificate C, which is included in the electronic securities right part S 0
And part of the security number random numbers a B , b B , and z B that can be known only by the issuer or user B requesting erasure of the electronic security, where S (x B ) = <S 0 , S 1 (x B ) >><> is a set of data inside S 0 is an electronic securities right section S 1 (x B ) is an electronic securities identification section x B is a security number S of an electronic security which is required to be erased 0 = <C, D, h (C | D) do mod n o> C digital certificate D description of the rights and obligations d o is the issuer of the secret key n o is the issuer's public key h (C | D) is a hash function h (C whose variable C and D | indicates that a D) data mod n o which was digitally signed by a d o is n o law (modulus) | is D) do h (C C = <n T, e T , h (n T | e T) dp mod n p> n T, e T securities-specific corresponding to the rights and obligations content Public key d p, n p is the public key h and the secret key of a neutral institution (n T | e T) is a hash function h to the variable n T and e T (n T | e T ) d p is h (n T | e T) the d p by the digital signature data mod n p is S 1 (x B indicating that the n p modulo (modulus)) = <x B , h (x B) dT mod n T> d T and n T are a secret key and a public key of a neutral authority, respectively. h (x B ) is a hash function with x B as a variable, and h (x B ) dT is a digital signature of h (x B ) with d T data x B = f (y B, z B) y B = f (a B, b B) z B = f (id B, c B) a B, b B, c B is a random number of policy number 0 <a B , b B , c B <2 tt is a predetermined number of binary digits id B is an issuer requesting erasure, user B's specific number f () is f (x, y) = f (x ′, y ') x ≠
A one-way hash function in which it is difficult to find x ′, y ≠ y ′. Subsequently, the processing unit of the neutral organization calculates a hash function h (x B ) from the security number x B and obtains the electronic security identification. The hash function h (x B ) dT of the digitally signed security number included in the part S 1 (x B ) is decrypted by the public key e T paired with the secret key d T used in the digital certificate C. By calculating h (x B ) dT · eT and comparing them, it is verified that the electronic securities identification unit S 1 (x B ) has a one-to-one correspondence with the electronic securities rights unit S 0, and the security number x B is x B = f (f (a B, b B), z B) by verifying that satisfies the relationship, a portion of the policy number random number a
It verifies that B , b B , and z B can be known only to the issuer or user B who wants to erase the electronic security, and searches the electronic security identification unit S 1 (x B ) in the electronic security erasure record database. , On the condition that it has not been erased, the electronic securities identification unit S 1 (x
A method for issuing, transferring, certifying, and erasing electronic securities, which completes the erasure procedure for electronic securities by registering B ) as an erased electronic securities identification unit.
JP27177097A 1997-10-03 1997-10-03 Processing system and method for issuing, transferring, certifying, and erasing electronic securities Expired - Lifetime JP3428876B2 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
JP27177097A JP3428876B2 (en) 1997-10-03 1997-10-03 Processing system and method for issuing, transferring, certifying, and erasing electronic securities

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
JP27177097A JP3428876B2 (en) 1997-10-03 1997-10-03 Processing system and method for issuing, transferring, certifying, and erasing electronic securities

Publications (2)

Publication Number Publication Date
JPH11110464A true JPH11110464A (en) 1999-04-23
JP3428876B2 JP3428876B2 (en) 2003-07-22

Family

ID=17504613

Family Applications (1)

Application Number Title Priority Date Filing Date
JP27177097A Expired - Lifetime JP3428876B2 (en) 1997-10-03 1997-10-03 Processing system and method for issuing, transferring, certifying, and erasing electronic securities

Country Status (1)

Country Link
JP (1) JP3428876B2 (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2002074069A (en) * 2000-09-05 2002-03-12 Bank Of Tokyo-Mitsubishi Ltd Document escrow system, record media and document escrow execution method
KR100652110B1 (en) * 2001-10-26 2006-11-30 가부시키가이샤 히타치세이사쿠쇼 Electronic bill management method and system
JP2008152748A (en) * 2006-12-14 2008-07-03 Shijin Kogyo Sakushinkai Variable monetary value settlement system, method and computer-readable medium thereof

Citations (18)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH03505032A (en) * 1988-05-24 1991-10-31 チャウム、デイビッド Card computer control system
JPH06162059A (en) * 1991-11-15 1994-06-10 Citibank Na Electronic currency system
JPH07261994A (en) * 1994-03-23 1995-10-13 Nri & Ncc Co Ltd Software customization method and apparatus using interactive method
JPH08149124A (en) * 1994-03-07 1996-06-07 Nippon Telegr & Teleph Corp <Ntt> Information delivery method and system using zero-knowledge proof protocol
JPH08185448A (en) * 1994-09-30 1996-07-16 Mitsubishi Corp Data copyright management system and data copyright management device
JPH08190598A (en) * 1995-01-11 1996-07-23 N T T Data Tsushin Kk Electronic check system
JPH08249399A (en) * 1995-03-13 1996-09-27 Toshiba Corp Electronic payment device and method
JPH09500977A (en) * 1993-08-02 1997-01-28 ブランズ、ステファヌス・アルフォンスス Restricted blind signature
JPH09114904A (en) * 1995-10-23 1997-05-02 Nippon Telegr & Teleph Corp <Ntt> Information sales method and system
JPH09128465A (en) * 1995-11-06 1997-05-16 Nippon Telegr & Teleph Corp <Ntt> Electronic cashing method aided by trust organization
JPH09160492A (en) * 1995-12-13 1997-06-20 Matsushita Electric Ind Co Ltd Signature method
JPH09171349A (en) * 1995-12-19 1997-06-30 Nec Corp Method for digital signiture
JPH09218905A (en) * 1996-02-08 1997-08-19 N T T Data Tsushin Kk Electronic check system
JPH09251268A (en) * 1996-03-15 1997-09-22 Matsushita Electric Ind Co Ltd Multiple digital signature system
JPH09251502A (en) * 1996-03-18 1997-09-22 Hitachi Ltd Electronic payment method
JPH10124597A (en) * 1996-08-30 1998-05-15 Nippon Telegr & Teleph Corp <Ntt> Electronic check method and apparatus with license
JPH10162085A (en) * 1996-11-29 1998-06-19 N T T Data Tsushin Kk Electronic money system, electronic money, and electronic money history providing method
JP2000508796A (en) * 1996-04-12 2000-07-11 シティバンク、エヌ・エイ Inside money

Patent Citations (18)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH03505032A (en) * 1988-05-24 1991-10-31 チャウム、デイビッド Card computer control system
JPH06162059A (en) * 1991-11-15 1994-06-10 Citibank Na Electronic currency system
JPH09500977A (en) * 1993-08-02 1997-01-28 ブランズ、ステファヌス・アルフォンスス Restricted blind signature
JPH08149124A (en) * 1994-03-07 1996-06-07 Nippon Telegr & Teleph Corp <Ntt> Information delivery method and system using zero-knowledge proof protocol
JPH07261994A (en) * 1994-03-23 1995-10-13 Nri & Ncc Co Ltd Software customization method and apparatus using interactive method
JPH08185448A (en) * 1994-09-30 1996-07-16 Mitsubishi Corp Data copyright management system and data copyright management device
JPH08190598A (en) * 1995-01-11 1996-07-23 N T T Data Tsushin Kk Electronic check system
JPH08249399A (en) * 1995-03-13 1996-09-27 Toshiba Corp Electronic payment device and method
JPH09114904A (en) * 1995-10-23 1997-05-02 Nippon Telegr & Teleph Corp <Ntt> Information sales method and system
JPH09128465A (en) * 1995-11-06 1997-05-16 Nippon Telegr & Teleph Corp <Ntt> Electronic cashing method aided by trust organization
JPH09160492A (en) * 1995-12-13 1997-06-20 Matsushita Electric Ind Co Ltd Signature method
JPH09171349A (en) * 1995-12-19 1997-06-30 Nec Corp Method for digital signiture
JPH09218905A (en) * 1996-02-08 1997-08-19 N T T Data Tsushin Kk Electronic check system
JPH09251268A (en) * 1996-03-15 1997-09-22 Matsushita Electric Ind Co Ltd Multiple digital signature system
JPH09251502A (en) * 1996-03-18 1997-09-22 Hitachi Ltd Electronic payment method
JP2000508796A (en) * 1996-04-12 2000-07-11 シティバンク、エヌ・エイ Inside money
JPH10124597A (en) * 1996-08-30 1998-05-15 Nippon Telegr & Teleph Corp <Ntt> Electronic check method and apparatus with license
JPH10162085A (en) * 1996-11-29 1998-06-19 N T T Data Tsushin Kk Electronic money system, electronic money, and electronic money history providing method

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2002074069A (en) * 2000-09-05 2002-03-12 Bank Of Tokyo-Mitsubishi Ltd Document escrow system, record media and document escrow execution method
KR100652110B1 (en) * 2001-10-26 2006-11-30 가부시키가이샤 히타치세이사쿠쇼 Electronic bill management method and system
JP2008152748A (en) * 2006-12-14 2008-07-03 Shijin Kogyo Sakushinkai Variable monetary value settlement system, method and computer-readable medium thereof
US8032466B2 (en) 2006-12-14 2011-10-04 Institute For Information Industry System, method, and computer readable medium for micropayment with varying denomination

Also Published As

Publication number Publication date
JP3428876B2 (en) 2003-07-22

Similar Documents

Publication Publication Date Title
JP3791131B2 (en) Electronic ticket system
US5768389A (en) Method and system for generation and management of secret key of public key cryptosystem
US5768385A (en) Untraceable electronic cash
CN113994357A (en) Method for directly transmitting electronic coin data records between a terminal and a payment system
JP2020145733A (en) Method for managing a trusted identity
KR101863953B1 (en) System and method for providing electronic signature service
US20050262321A1 (en) Information processing apparatus and method, and storage medium
JP2004023796A (en) Selectively disclosable digital certificate
JP2005537559A (en) Secure record of transactions
KR102939446B1 (en) A secure, traceable, and privacy-protected digital currency transfer method through the cancellation of anonymity on a distributed ledger
US7505945B2 (en) Electronic negotiable documents
JP7222436B2 (en) Security control method, information processing device and security control program
CN115176260A (en) Method, terminal, monitoring entity and payment system for managing electronic currency data sets
JP2000215280A (en) Identity certification system
JP2001126009A (en) Electronic information distribution system, storage medium storing electronic information distribution program, and electronic information distribution method
CN115310978A (en) A digital asset transaction method and device
JPH096236A (en) Public key encryption key generation / certificate issuing method and system thereof
JP3428876B2 (en) Processing system and method for issuing, transferring, certifying, and erasing electronic securities
EP0886248B1 (en) Method and apparatus for registration of information with plural institutions and recording medium with registration program stored thereon
JPH11213104A (en) Electronic ticket system
JP3171227B2 (en) Electronic banknote implementation method with a trust institution
JP4270589B2 (en) Electronic frequency payment method and apparatus
Brands Electronic Cash.
JP3329438B2 (en) Electronic cash method with monitoring institution, user apparatus and monitoring institution apparatus for implementing the method
JP3435682B2 (en) Electronic cash deposit method, device thereof, and program recording medium

Legal Events

Date Code Title Description
R250 Receipt of annual fees

Free format text: JAPANESE INTERMEDIATE CODE: R250

R250 Receipt of annual fees

Free format text: JAPANESE INTERMEDIATE CODE: R250

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20080516

Year of fee payment: 5

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20090516

Year of fee payment: 6

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20100516

Year of fee payment: 7

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20110516

Year of fee payment: 8

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20110516

Year of fee payment: 8

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20120516

Year of fee payment: 9

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20120516

Year of fee payment: 9

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20130516

Year of fee payment: 10

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20140516

Year of fee payment: 11

R250 Receipt of annual fees

Free format text: JAPANESE INTERMEDIATE CODE: R250

R250 Receipt of annual fees

Free format text: JAPANESE INTERMEDIATE CODE: R250

R250 Receipt of annual fees

Free format text: JAPANESE INTERMEDIATE CODE: R250

R250 Receipt of annual fees

Free format text: JAPANESE INTERMEDIATE CODE: R250

EXPY Cancellation because of completion of term