Apparatus and method for securely realizing cooperative processing
Abstract
A device for facilitating verification of an electronic signature in an exchange of instructions between an in-house server and an outside server. Each server which is to execute a partial process of a cooperative service has, in a key storage unit ( 206 ), secret keys corresponding to public key certificates issued by an in-house CA and by an outside public CA. A signature key selection unit 216 judges whether a server which is to execute a process next is a device within or outside the company and selects an in-house secret key when the next server is an in-house device and an outside secret key when the next server is an outside device. A signature creation unit ( 218 ) calculates a value of an electronic signature for an job flow instruction to the next server using the selected secret key. An instruction division/integration unit ( 204 ) transmits to the next server the job flow instruction with the electronic signature value attached.
Claims
exact text as granted — not AI-modified1 . An information processor for instructing a job processor to execute a job process, the information processor comprising:
a selection unit for selecting one of a first signature key certified by a first certificate authority and a second signature key certified by a second certificate authority for signing instruction data having a process description for instructing a job process or data to be processed in a job process; a signing unit for signing the instruction data or the data to be processed using the signature key selected by the selection unit; and a transmitter unit for transmitting, to the job processor, the instruction data or the data to be processed signed by the signing unit, wherein the selection unit selects the first signature key when the job processor is located within a predetermined network and selects the second signature key otherwise.
2 . An information processor according to claim 1 , wherein
the certificate authority certifying the first signature key is a certificate authority which certifies users within the predetermined network, and the certificate authority certifying the second signature key is a certificate authority which certifies other users outside the predetermined network.
3 . An information processing method executed by an information processor for instructing a job processor to execute a job process, the method comprising the steps of;
selecting one of a first signature key certified by a first certificate authority and a second signature key certified by a second certificate authority for signing instruction data having a process description for instructing a job process or data to be processed in a job process; electronically signing the instruction data or the data to be processed using the signature key selected the selection step; transmitting, to the job processor, the instruction data or the data to be processed which is electronically signed in the electronically signing, step, wherein the selecting selects the first signature key when the job processor is located within a predetermined network and selects the second signature key otherwise.
4 . A proxy device provided between an internal network and an external network, for exchanging documents between a device on the internal network and a device on the external network, the proxy device comprising:
a first signature verification unit that verifies a first electronic signature attached to a document transmitted from a device on an internal network to a device on an external network is signed using a signature key for the internal network, and a first signature conversion unit that deletes the first electronic signature once the signature is verified by the first verification unit and attaches a second electronic signature to the document using a signature key of the proxy device for the external network, the signature key for the internal network and the signature key for the external network being separately generated and exclusive of each other, and a transmitter unit for transmitting the electronically signed document to the device on the external network.
5 . A proxy device according to claim 4 , further comprising:
a second signature verification unit that verifies a third electronic signature attached to a document transmitted from a device on the external network to a device on the internal network is signed using a signature key for the external network, and a second signature conversion unit that deletes the third electronic signature once the signature is verified by the second signature verification unit and attaches a fourth electronic signature to the document using a signature key of the proxy device for the internal network, the signature key for the external network and the signature key for the internal network being separately generated and exclusive of each other, and a transmitter unit for transmitting the electronically signed document to the device on the internal network.
6 . A method for exchanging, in a proxy device provided between an internal network and an external network, documents between a device on the internal network and a device on the external network, the method comprising the steps of:
verifying a first electronic signature attached to a document transmitted from a device on the internal network to a device on the external network; deleting the first electronic signature from the document when it is determined in the verification that the first electronic signature attached to the document is signed using a signature key for the internal network; attaching a second electronic signature to the document from which the first electronic signature has been deleted using a signature key of the proxy device for the external network, the signature key for the internal network and the signature key for the external network being separately generated and exclusive of each other, and transmitting the document to which an electronic signature is re-attached using the signature key for the external network to the device on the external network.
7 . A proxy device provided between an internal network and an external network for exchanging documents between a device on the internal network and a device on the external network, the proxy device comprising:
a signature verification unit that verifies a first electronic signature attached to a document transmitted from a device on the external network to a device on the internal network is signed using a signature key for the external network; a signature conversion unit that deletes the first signature once the signature is verified by the the signature verification unit and attaches a second electronic signature to the document using a signature key of the proxy device for the internal network, the signature key for the external network and the signature key for the internal network being separately generated and exclusive of each other, and a transmitter unit for transmitting the document to the device on the internal network.
8 . A method for changing, in a proxy device provided between an internal network and an external network, documents between a device on the internal network and a device on the external network, the method comprising the steps of:
verifying a first electronic signature attached to a document transmitted from a device on the external network to a device on the internal network; deleting the first electronic signature from the document when the verification is successful; attaching a second electronic signature to the document from which the first electronic signature is deleted using a signature key of the proxy device for the internal network, the signature key for the external network and the signature key for the internal network being separately generated and exclusive of each other, and transmitting the document having an electronic signature re-attached using the signature key for the internal network to the device on the internal network.Join the waitlist — get patent alerts
Track US2007245146A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.