Data protection method, authentication server, data protection system and data structure

By using encryption verification and distributed ledger records of authentication servers and data servers in the data protection system, the contradiction between data privacy protection and effective utilization is resolved, and the security and integrity of data are achieved.

CN110826079BActive Publication Date: 2025-09-23PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN201910716321.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-05-23
Filing Date
2019-08-05
Publication Date
2025-09-23
Estimated Expiration
2039-08-05

AI Technical Summary

Technical Problem

In data collection and circulation systems, existing technologies make it difficult to effectively utilize data while protecting data privacy, and there is a risk of data leakage.

Method used

The data protection system uses multiple authentication servers and data servers. By receiving the hash value transaction data generated by the device, it verifies the data consistency using encrypted secure calculation methods and records the transaction data in a distributed ledger to achieve data privacy protection and effective utilization.

Benefits of technology

It achieves effective use of data while protecting data privacy, ensuring data security and integrity and preventing data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN110826079B_ABST
    Figure CN110826079B_ABST
Patent Text Reader

Abstract

A data protection method, an authentication server, a data protection system, and a data structure capable of effectively utilizing data while protecting the privacy of data, the method comprising: a step (S104a) of receiving transaction data including a first hash value obtained from historical information of a residence (100); a step (S107) of obtaining a second hash value from a data server, the second hash value being obtained by the data server performing a calculation on encrypted historical information obtained from the residence in an encrypted state, the encrypted historical information being encrypted historical information obtained by encrypting the historical information of the residence using a secure calculation method capable of being calculated in an encrypted state; a step (S108) of verifying the transaction data and confirming whether the first hash value and the second hash value are consistent; and a step (S111) of recording the transaction data in a distributed ledger when the legitimacy of the transaction data is confirmed and the first hash value and the second hash value are consistent.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a data protection method, an authentication server, a data protection system and a data structure, and in particular to a data protection method, an authentication server, a data protection system and a data structure for effectively utilizing data collected from users. Background Art

[0002] In recent years, research has been underway into systems that collect, analyze, and distribute user and device data. With the advancement of IoT (Internet of Things) and the widespread adoption of AI, it is expected that even more data will be collected than ever before. Consequently, there is a growing desire to utilize this collected data effectively.

[0003] However, in order to effectively utilize collected data, it is important to protect the private information included in the data, that is, to protect the privacy of the data.

[0004] For example, security in industrial control systems (ICS) and IoT is described in Non-Patent Document 1. According to Non-Patent Document 1, protection of privacy information related to not only sensor information but also personal data such as healthcare and wearables is important.

[0005] Prior art literature

[0006] Non-patent literature

[0007] Non-Patent Document 1: Cyber ​​Physical Security for Industrial Control Systems and IoT, IEICE TRANS.INF.&SYST., Vol. E99-D, No. 4 April 2016

[0008] Non-Patent Literature 2: ABY-A Framework for Efficient Mixed-Protocol Secure Two-Party Computation, NDSS Symposium 2015

[0009] Non-Patent Document 3: Fully Homomorphic Encryption without Bootstrapping, https: / / eprint.iacr.org / 2011 / 277.pdf (retrieved on July 20, 2018) Summary of the Invention

[0010] Problems to be solved by the invention

[0011] However, when systems that collect and distribute data encrypt and distribute the data to protect its privacy, businesses seeking to provide services, for example, find it difficult to effectively utilize the data because the data is encrypted. On the other hand, when the system distributes collected data directly in plain text, users are reluctant to provide the data themselves due to the risk of data leakage, preventing the system from collecting data that can be effectively utilized.

[0012] The present invention has been made in view of the above circumstances, and an object of the present invention is to provide a data protection method and the like that can effectively utilize data while protecting the privacy of the data.

[0013] Means of solving the problem

[0014] In order to achieve the above-mentioned purpose, the data protection method of the present invention is a data protection method executed by a first authentication server among the multiple authentication servers in a data protection system comprising a device, multiple authentication servers and multiple data servers, and is characterized in that it includes: a step of receiving transaction data generated by the device and containing a first hash value obtained from historical information of the device; a step of obtaining a second hash value from the data server, the second hash value being obtained by the data server performing a calculation on the encrypted historical information obtained from the device in an encrypted state, the encrypted historical information being encrypted historical information recorded by the data server and obtained by encrypting the historical information of the device using a secure calculation method that can be calculated in an encrypted state; a step of verifying the transaction data and confirming whether the first hash value is consistent with the second hash value; and a step of synchronizing with the multiple authentication servers other than the first authentication server and recording the transaction data in a distributed ledger when the legitimacy of the transaction data is confirmed and the first hash value is consistent with the second hash value.

[0015] In addition, these general or specific technical solutions can be implemented through systems, integrated circuits, computer programs or computer-readable recording media such as CD-ROMs, or through any combination of systems, methods, integrated circuits, computer programs and recording media.

[0016] Effects of the Invention

[0017] According to the present invention, it is possible to realize a data protection method and the like that can effectively utilize data while protecting the privacy of the data. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 This is a diagram showing an example of the overall configuration of a data distribution system according to an embodiment.

[0019] Figure 2 This is a diagram showing an example of the overall structure of a house according to the embodiment.

[0020] Figure 3 Yes Figure 2 A block diagram showing an example of the functional configuration of the controller shown.

[0021] Figure 4 This is a diagram showing an example of the data structure of transaction data according to the embodiment.

[0022] Figure 5 This is a block diagram showing an example of the functional configuration of a terminal according to an embodiment.

[0023] Figure 6 This is a diagram showing an example of the overall configuration of an in-vehicle network system included in a vehicle according to the embodiment.

[0024] Figure 7 Yes Figure 5 A block diagram showing an example of the functional structure of a gateway shown.

[0025] Figure 8 This is a block diagram showing an example of the functional configuration of an authentication server according to an embodiment.

[0026] Figure 9 This is an explanatory diagram showing the data structure of the blockchain.

[0027] Figure 10 This is a block diagram showing an example of the functional configuration of a data server according to an embodiment.

[0028] Figure 11 It is an overall timing diagram of data protection in an implementation method.

[0029] Figure 12 This is a sequence diagram of transaction data registration processing according to the embodiment.

[0030] Figure 13 It is a sequence diagram of the data verification process in the embodiment.

[0031] Description of Reference Signs

[0032] 100 residences

[0033] 101 Controller

[0034] 102 Photovoltaic power generation

[0035] 103 batteries

[0036] 104 Electricity Meter

[0037] 105, 400 communication network

[0038] 106 Power Network

[0039] 110 Terminal

[0040] 120 vehicles

[0041] 121 Gateway

[0042] 200a, 200b, 200c authentication servers

[0043] 211 Transaction Data Verification Department

[0044] 212 Block Generation Department

[0045] 213 Synchronization Department

[0046] 214 Data Verification Department

[0047] 215, 313, 1013, 1103, 1213 Records Department

[0048] 216, 314, 1014, 1104, 1214 Department of Communications

[0049] 300a, 300b, 300c data servers

[0050] 311 Management Department

[0051] 312, 1012, 1102, 1212 Secure Computing Department

[0052] 1011, 1101, 1211 Transaction Data Generation Department

[0053] 1210 Engine

[0054] 1220 Driving Assistance Department

[0055] 1230 battery

[0056] 1240 Vehicle-mounted Unit

[0057] 1250 Ministry of Communications

[0058] 1211a, 1221, 1231, 1241, 1251 ECU DETAILED DESCRIPTION

[0059] A data protection method according to an embodiment of the present invention is executed by a first authentication server among the multiple authentication servers in a data protection system comprising a device, multiple authentication servers and multiple data servers, and is characterized in that it includes: a step of receiving transaction data generated by the device, the transaction data including a first hash value obtained from historical information of the device; a step of obtaining a second hash value from one or more of the data servers, the second hash value being obtained by the one or more data servers performing arithmetic processing on encrypted historical information obtained from the device in an encrypted state, the encrypted historical information being encrypted historical information recorded by the one or more data servers and obtained by encrypting the historical information of the device using a secure calculation method that can be operated in an encrypted state; a step of verifying the transaction data and confirming whether the first hash value is consistent with the second hash value; and a step of synchronizing with the multiple authentication servers other than the first authentication server and recording the transaction data in a distributed ledger when the legitimacy of the transaction data is confirmed and the first hash value is consistent with the second hash value.

[0060] This makes it possible to realize a data protection method that can effectively utilize data while protecting the privacy of the data.

[0061] In addition, it also includes: a step of obtaining identification information and a third hash value from the device, wherein the identification information identifies the first encrypted history information of the first history information as the data verification object, and the third hash value is obtained from the first history information; a step of generating first transaction data containing the identification information and indicating a delegation of data verification, and sending the data to the one or more data servers; a step of obtaining a fourth hash value from the one or more data servers, wherein the fourth hash value is obtained by the one or more data servers performing a calculation in an encrypted state on the first encrypted history information determined by the identification information in the encrypted history information obtained from the device and recorded by the one or more data servers; a step of confirming whether the third hash value is consistent with the fourth hash value; and a step of generating second transaction data when the third hash value is inconsistent with the fourth hash value, and sending the data to the one or more data servers, wherein the second transaction data contains the identification information and indicates a delegation of deletion of the first encrypted history information determined by the identification information.

[0062] Thus, when the history information of the device to be verified does not match the history information stored in the data server, the encrypted history information of the device on the data server side can be deleted.

[0063] In addition, the data protection method may further include the step of synchronizing between the plurality of authentication servers and recording the second transaction data in a distributed ledger when the third hash value is inconsistent with the fourth hash value.

[0064] As a result, any inconsistency between the historical information of the device and the historical information of the device stored in the data server is retained in the blockchain.

[0065] Furthermore, for example, the history information may contain personal data of the user of the device.

[0066] In addition, an authentication server of one embodiment of the present invention is one of the multiple authentication servers in a data protection system comprising a device, multiple authentication servers and multiple data servers, and is characterized in that it comprises: a communication unit, which receives transaction data generated by the device and includes a first hash value obtained from historical information of the device, and obtains a second hash value from the data server, wherein the second hash value is obtained by the data server performing a calculation on the encrypted historical information obtained from the device in an encrypted state, and the encrypted historical information is encrypted historical information recorded by the one or more data servers and obtained by encrypting the historical information of the device using a secure calculation method that can be calculated in an encrypted state; a transaction data verification unit, which verifies the transaction data; a data verification unit, which confirms whether the first hash value is consistent with the second hash value; and a recording unit, which synchronizes with the multiple authentication servers and records the transaction data in a distributed ledger when the legitimacy of the transaction data is confirmed and the first hash value is consistent with the second hash value.

[0067] In addition, a data protection system according to an embodiment of the present invention comprises: a device; a plurality of authentication servers; and a plurality of data servers, wherein the device comprises: a transaction data generation unit, which generates transaction data including a first hash value obtained from historical information of the device and sends the transaction data to one of the plurality of authentication servers; and a first security calculation unit, which encrypts the historical information by using a security calculation method capable of operating in an encrypted state, generates encrypted historical information, and sends the encrypted historical information to the plurality of data servers, each of the plurality of data servers comprising: a recording unit, which records the encrypted historical information obtained from the device; and a second security calculation unit, which generates encrypted historical information by processing the recorded encrypted historical information. The historical information is processed in an encrypted state to obtain a second hash value of the recorded encrypted historical information, and the second hash value is sent to the one authentication server, wherein the one authentication server comprises: a communication unit, which receives the transaction data including the first hash value from the device and obtains the second hash value from one or more data servers; a transaction data verification unit, which verifies the transaction data; a data verification unit, which confirms whether the first hash value is consistent with the second hash value; and a recording unit, which synchronizes with the multiple authentication servers and records the transaction data in a distributed ledger when the legitimacy of the transaction data is confirmed and the first hash value is consistent with the second hash value.

[0068] In addition, a data structure of an embodiment of the present invention is used for recording a block as a blockchain in a data protection system having a device, multiple authentication servers and multiple data servers, and is characterized in that the data structure includes: a blockchain address, included in the block of the blockchain, as an identifier for identifying the subject that generated the transaction data; a transaction ID, identifying the transaction data; a first hash value, which is the first hash value included in the transaction data and obtained from the historical information of the device; and an electronic signature of the user of the transaction data, the transaction data being included in the block when the second hash value is consistent with the first hash value, the second hash value being obtained by one or more of the data servers performing arithmetic processing on the encrypted historical information obtained from the device in an encrypted state, the encrypted historical information being encrypted historical information obtained by encrypting the historical information of the device using a secure computing method that can be operated in an encrypted state.

[0069] Hereinafter, the embodiments will be described with reference to the accompanying drawings. In addition, the embodiments described below each represent a specific example of the present invention. Therefore, the numerical values, shapes, materials, constituent elements, configurations of constituent elements, and connection methods shown in the following embodiments are examples and do not limit the subject matter of the present invention. In addition, among the constituent elements in the following embodiments, constituent elements that are not described in the independent claims representing a method of realizing one embodiment of the present invention are described as arbitrary constituent elements. The embodiments of the present invention are not limited to the current independent claims, but can also be represented by other independent claims.

[0070] (Implementation Method)

[0071] First, the system configuration of the present invention will be described.

[0072] [1. System structure]

[0073] The data protection system of the present invention records encrypted data, such as device history information, in a secure computational manner to a data server, and also records transaction data, including a hash value of the encrypted data, to a distributed ledger. Thus, the data protection system of the present invention can utilize blockchain technology to protect data privacy while simultaneously collecting and effectively utilizing data.

[0074] Hereinafter, a data protection system and the like in the embodiments will be described with reference to the drawings.

[0075] [1.1 Overall Structure of Data Protection System 10]

[0076] Figure 1 This is a diagram showing an example of the overall configuration of the data protection system 10 according to this embodiment.

[0077] like Figure 1 As shown, the data protection system 10 includes a house 100 , a terminal 110 , a vehicle 120 , authentication servers 200 a , 200 b , and 200 c , and data servers 300 a , 300 b , and 300 c , which are connected via a communication network 400 .

[0078] Furthermore, authentication servers 200a, 200b, and 200c (hereinafter also referred to as authentication servers 200) are connected to storage devices 201a, 201b, and 201c (hereinafter also referred to as storage devices 201). Authentication servers 200 may be connected to storage devices 201 via a communication network 400, or may include storage devices 201 internally. Storage devices 201 contain a distributed ledger that electronically records transaction data and blocks of the blockchain.

[0079] In addition, Figure 1In FIG. 4 , an example is shown in which the data protection system 10 includes three authentication servers and three data servers, but the present invention is not limited thereto. That is, the data protection system 10 may include four or more authentication servers and four or more data servers.

[0080] [1.2 Structure of Residence 100]

[0081] Figure 2 This is a diagram showing an example of the overall structure of a house 100 according to this embodiment.

[0082] like Figure 2 As shown, house 100 includes a controller 101, a photovoltaic power generation system 102, a storage battery 103, and an electricity meter 104. Controller 101, photovoltaic power generation system 102, storage battery 103, and electricity meter 104 are connected via a communication network 105. Furthermore, photovoltaic power generation system 102, storage battery 103, and electricity meter 104 are connected via an electricity network 106. House 100 is, for example, a house such as a residence, but is not limited thereto. House 100 may also be a building such as a factory or a building. That is, as long as house 100 is a building used by a user, its form is not limited. In the following, the equipment located within house 100 will be referred to as equipment within the house. Equipment within the house is an example of the equipment of the present invention. Equipment within the house may or may not include photovoltaic power generation system 102, storage battery 103, and electricity meter 104. House 100 may also be an example of the equipment of the present invention.

[0083] <Controller 101>

[0084] Controller 101 is, for example, a controller for an energy management system. In this embodiment, controller 101 controls photovoltaic power generation 102, displays the power generation status of photovoltaic power generation 102 and the power storage status of battery 103, and inputs applications for electricity sales or purchases. Furthermore, controller 101 manages the amount of electricity transmitted to an external power grid (not shown) via power meter 104 and notifies authentication server 200. In this way, controller 101 operates residential devices, displays the status of residential devices, performs input to residential devices, and manages the operation history and status changes of residential devices.

[0085] Photovoltaic Power Generation 102

[0086] Photovoltaic power generation 102 is a device equipped with a power generation system that uses solar cells to directly convert sunlight into electricity. Photovoltaic power generation 102 uses the generated electricity within house 100, stores the generated electricity in battery 103, or transmits the generated electricity to the power grid.

[0087] <Battery 103>

[0088] Battery 103 stores the electricity generated by photovoltaic power generation 102. For example, battery 103 transmits the stored electricity to the power grid in response to power transmission instructions from controller 101. Alternatively, battery 103 can store electricity received from the power grid in response to power reception instructions from controller 101. Battery 103 is not a required component and may not be installed in house 100.

[0089] <Electricity meter 104>

[0090] The power meter 104 measures the amount of power transmitted to or received from the external power grid. Based on power transmission instructions from the controller, when photovoltaic power generation 102 or storage battery 103 transmits power to the power grid, the power meter 104 measures the time and amount of power transmitted by photovoltaic power generation 102 or storage battery 103, and notifies the controller 101. Furthermore, based on power usage instructions from the controller 101, the power meter 104 measures the power used by the power grid received.

[0091] An example of the configuration of the controller 101 will be described below.

[0092] [1.3 Structure of Controller 101]

[0093] Figure 3 Yes Figure 2 A block diagram showing an example of the functional configuration of the controller 101 is shown.

[0094] The controller 101 includes a processor and a memory storing a program for causing the processor to execute a predetermined process. That is, the controller 101 is implemented by the processor executing the predetermined program using the memory. Figure 3 As shown, the controller 101 includes a transaction data generation unit 1011 , a secure calculation unit 1012 , a recording unit 1013 , and a communication unit 1014 .

[0095] <Transaction Data Generation Unit 1011>

[0096] When a user operates a device in a home and receives an operation history from the device, or when a device in a home changes state and receives a status history from the device, the transaction data generation unit 1011 generates transaction data in the blockchain based on the device's historical information, such as the operation history and status history. Here, the device's historical information is an example of personal data, including the personal data of the device's user.

[0097] In this embodiment, the transaction data generation unit 1011 calculates a hash value (referred to as a first hash value) of the device history information received from the device, and generates transaction data including the calculated first hash value.

[0098] Here, use Figure 4 An example of the structure (data structure) of transaction data generated by the transaction data generation unit 1011 will be described. Figure 4 This is a diagram showing an example of the data structure of transaction data according to this embodiment.

[0099] like Figure 4 As shown in FIG, the data structure of the transaction data generated by the transaction data generation unit 1011 includes a transaction ID, a blockchain address, a first hash value, and a signature. The transaction ID is an identifier for identifying the transaction data. The blockchain address is an identifier for identifying the subject that generated the transaction data. Figure 4 In this embodiment, the user or controller that obtains the historical information of the first hash value can be determined by the blockchain address. The first hash value is obtained from the historical information of the device and is included in the transaction data. Figure 4 As shown, the first hash value is included in the payload portion, which is the data body of the transaction data. The signature is the user's electronic signature. In this embodiment, the signature is generated using the user's unique signature generation key. Furthermore, the transaction data generation unit 1011 may generate transaction data that also includes an identifier for identifying the device's historical information.

[0100] Furthermore, the transaction data generation unit 1011 records the generated transaction data in the recording unit 1013. Furthermore, the transaction data generation unit 1011 transmits the generated transaction data to at least one authentication server 200 among the authentication servers 200a, 200b, and 200c via the communication unit 1014.

[0101] <Secure Calculation Unit 1012>

[0102] The secure calculation unit 1012 generates encrypted history information by encrypting the device's history information using a secure calculation method capable of performing operations in an encrypted state. In this embodiment, the secure calculation unit 1012 encrypts the device's history information received from the transaction data generation unit 1011 using the secure calculation method. The secure calculation unit 1012 transmits the encrypted history information, obtained by encrypting the device's history information using the secure calculation method, to the data server 300 via the communication unit 1014.

[0103] Here, data encrypted using a secure computing method can be subjected to computational processing, including image recognition, while in an encrypted state. Encryption using a secure computing method can be performed using, for example, the methods disclosed in Non-Patent Documents 2 or 3. By performing encryption using the methods disclosed in Non-Patent Documents 2 or 3, arithmetic operations can be performed while in an encrypted state, and a hash value can be calculated. The encryption method used can be determined in advance, or the method used can be determined based on the data, etc. Furthermore, multiple encryption methods can be used.

[0104] <Recording Unit 1013>

[0105] The recording unit 1013 records the transaction data generated by the transaction data generation unit 1011 and the encrypted history information, which is the data encrypted by the secure calculation unit 1012. In this embodiment, the recording unit 1013 records the encrypted history information, which is the data that can be securely calculated, and records the transaction data including the first hash value generated by the transaction data generation unit 1011.

[0106] <Communication Department 1014>

[0107] The communication unit 1014 communicates with the data server 300 and the authentication server 200 via the communication network 400. This communication may also be performed using TLS (Transport Layer Security). In this case, the encryption key used for TLS communication may be stored by the communication unit 1014.

[0108] Next, terminal 110 will be described.

[0109] [1.4 Structure of Terminal 110]

[0110] Figure 5 This is a block diagram showing an example of the functional configuration of the terminal 110 according to this embodiment.

[0111] The terminal 110 is an example of a device of the present invention, and is implemented by a processor executing a predetermined program using a memory. The terminal 110 is, for example, a device having a display and an input unit such as a smartphone, or a device that obtains sensor information of a user such as a wearable device.

[0112] In this embodiment, if Figure 5 As shown, the terminal 110 includes a transaction data generation unit 1101 , a secure calculation unit 1102 , a recording unit 1103 , and a communication unit 1104 .

[0113] <Transaction Data Generation Unit 1101>

[0114] The transaction data generation unit 1101 generates transaction data in the blockchain based on historical information, including a history of user operations on the terminal 110, a history of information input by the user to the terminal 110, and a history of information related to the user collected by the terminal 110. An example of the history of information input by the user to the terminal 110 is a plurality of past photos taken by the user using the terminal 110. An example of the history of information related to the user collected by the terminal 110 is a history of sensor information such as the user's body temperature.

[0115] In this embodiment, the transaction data generation unit 1101 calculates a hash value (also referred to as a first hash value) of the history information acquired from the terminal 110 , and generates transaction data including the calculated first hash value.

[0116] Here, the structure (data structure) of the transaction data generated by the transaction data generation unit 1101 is as follows: Figure 4 That is, the data structure of the transaction data generated by the transaction data generation unit 1101 includes the transaction ID, blockchain address, first hash value and signature.

[0117] As described above, the blockchain address is an identifier for identifying the entity that generated the transaction data, and can identify the user or terminal 110. The transaction data generation unit 1101 may generate transaction data that includes an identifier for identifying history information separately from the blockchain address.

[0118] Furthermore, the transaction data generation unit 1101 records the generated transaction data in the recording unit 1103. Furthermore, the transaction data generation unit 1101 transmits the generated transaction data to at least one authentication server 200 among the authentication servers 200a, 200b, and 200c via the communication unit 1104.

[0119] <Secure Calculation Unit 1102>

[0120] The secure calculation unit 1102 generates encrypted historical information by encrypting the terminal 110's historical information using a secure calculation method capable of performing operations in an encrypted state. In this embodiment, the secure calculation unit 1102 encrypts the terminal 110's historical information received from the transaction data generation unit 1101, or historical information such as a history of multiple past photos or sensor information stored by the terminal 110, using the secure calculation method. Furthermore, the secure calculation unit 1102 transmits the encrypted historical information, obtained by encrypting the historical information using the secure calculation method, to the data server 300 via the communication unit 1104.

[0121] The encryption process using the secure computing method is described above, so a detailed description thereof will be omitted. However, for example, the methods disclosed in Non-Patent Documents 2 and / or 3 may be used. Furthermore, as described above, the method used in the encryption process may be determined in advance, or the method used may be determined based on the data obtained. Furthermore, multiple methods may be used in the encryption process.

[0122] <Recording Unit 1103>

[0123] The recording unit 1103 records the transaction data generated by the transaction data generation unit 1101 and the encrypted history information, which is the data encrypted by the secure calculation unit 1102. In this embodiment, the recording unit 1103 records the encrypted history information, which is the data encrypted by the secure calculation unit 1102 and can be securely calculated, and also records the transaction data including the first hash value generated by the transaction data generation unit 1101.

[0124] <Communication Department 1104>

[0125] The communication unit 1104 communicates with the data server 300 and the authentication server 200 via the communication network 400. This communication may be performed using TLS. In this case, the encryption key used for TLS communication may be stored by the communication unit 1104.

[0126] Next, the vehicle 120 will be described.

[0127] [1.5 Structure of Vehicle 120]

[0128] The vehicle 120 is, for example, a car, but is not limited thereto. The vehicle 120 may also be a motorcycle, a ship, etc. That is, the vehicle 120 or the like only needs to have a plurality of ECUs connected to a network within the vehicle 120.

[0129] Figure 6 This is a diagram showing an example of the overall configuration of an in-vehicle network system included in vehicle 120 according to the present embodiment.

[0130] Multiple electronic control units (ECUs) 1211a, 1221, 1231, 1241, and 1251, as well as gateway 121, are connected via an in-vehicle network. The in-vehicle network can be CAN, Ethernet (registered trademark), or a hybrid of CAN and Ethernet (registered trademark). Even when the in-vehicle network includes Ethernet (registered trademark), messages can be transmitted via broadcast.

[0131] For example, the engine 1210, the battery 1230, the electric motor (not shown), and the drive ECU related to fuel control are connected to the in-vehicle network. Figure 6In the example shown, an ECU 1211 a for an engine 1210 and an ECU 1231 for a battery 1230 are connected to the in-vehicle network.

[0132] In addition, the vehicle network is connected to the driving assistance unit 1220 and safety and comfort function ECUs such as automatic braking, lane keeping, distance keeping, collision avoidance, and airbags (not shown). Figure 6 In the example shown, an ECU 1221 for a driving support unit 1220 is connected to the in-vehicle network.

[0133] In addition, the vehicle network is connected to an infotainment ECU such as the vehicle unit 1240. Figure 6 In the illustrated example, an ECU 1241 for an onboard unit 1240 is connected to the in-vehicle network. Alternatively, the ECU 1241 for the onboard unit 1240 may not be provided, and the onboard unit 1240 may be directly connected to the in-vehicle network without intermediary of the ECU 1241. Furthermore, the onboard unit includes a display unit and an input unit, and maintains the function of displaying a screen to a user in the vehicle 120, i.e., a user riding in the vehicle, and accepting information input.

[0134] In addition, a communication ECU such as a communication unit 1250 having a communication function for communicating with the authentication server 200 is connected to the in-vehicle network. Figure 6 In the example shown, an ECU 1251 for a communication unit 1250 is connected to the in-vehicle network.

[0135] Furthermore, the aforementioned ECUs 1211a to 1251 may be integrally formed with their respective connected components, i.e., may be formed as a single component. For example, the engine 1210 and the ECU 1211a connected thereto for the engine 1210 may be formed as a single component. The same applies to the other ECUs 1221 and the like.

[0136] These multiple electronic control units, ECUs 1211a through ECU 1251, transmit messages periodically or irregularly. For example, ECU 1211a for engine 1210 obtains the engine 1210's rotational speed and periodically transmits a message indicating the obtained engine 1210 rotational speed. Furthermore, ECU 1221 for driving assistance unit 1220 transmits a message indicating that the driving assistance function has been activated. Alternatively, a message indicating this may be transmitted when the ECU is newly connected to the in-vehicle network.

[0137] Next, the gateway 121 connected to the in-vehicle network will be described.

[0138] [1.6 Structure of Gateway 121]

[0139] Figure 7 Yes Figure 6 A block diagram of an example of the functional structure of the gateway 121 shown.

[0140] The gateway 121 is implemented by executing a prescribed program using a memory by a processor. Figure 7 As shown, it includes a transaction data generation unit 1211 , a security calculation unit 1212 , a recording unit 1213 , and a communication unit 1214 .

[0141] <Transaction Data Generation Unit 1211>

[0142] The transaction data generation unit 1211 generates transaction data in the blockchain based on the historical information of the vehicle 120 , wherein the historical information includes the manual driving history or the automatic driving history of the vehicle 120 , the history of the sensor information of the vehicle 120 , and the like.

[0143] In the present embodiment, the transaction data generation unit 1211 calculates a hash value (referred to as a first hash value) of the history information acquired from the vehicle 120 , and generates transaction data including the calculated first hash value.

[0144] Here, the structure (data structure) of the transaction data generated by the transaction data generating unit 1211 is as follows: Figure 4 That is, the data structure of the transaction data generated by the transaction data generation unit 1211 includes the transaction ID, blockchain address, first hash value, and signature.

[0145] As described above, the blockchain address is an identifier for identifying the entity that generated the transaction data, and can identify the user of the vehicle 120, the gateway 121, or the vehicle 120. Similarly to the above, the transaction data generation unit 1211 may generate transaction data that includes an identifier for identifying historical information separately from the transaction ID.

[0146] Furthermore, the transaction data generation unit 1211 records the generated transaction data in the recording unit 1213. Furthermore, the transaction data generation unit 1211 transmits the generated transaction data to at least one authentication server 200 among the authentication servers 200a, 200b, and 200c via the communication unit 1214.

[0147] <Secure Calculation Unit 1212>

[0148] The secure calculation unit 1212 generates encrypted historical information by encrypting the historical information of the vehicle 120 using a secure calculation method capable of performing operations in an encrypted state. In this embodiment, the secure calculation unit 1212 encrypts the historical information of the vehicle 120, such as the driving history and sensor information history, received from the transaction data generation unit 1211 using the secure calculation method. Furthermore, the secure calculation unit 1212 transmits the encrypted historical information, obtained by encrypting the historical information using the secure calculation method, to the data server 300 via the communication unit 1214.

[0149] In addition, the encryption processing using the secure calculation method is as described above, so detailed description is omitted, but for example, the method disclosed in Non-Patent Document 2 and / or Non-Patent Document 3 may be used.

[0150] In addition, as described above, the method used in the encryption process may be determined in advance, or which method to use may be determined based on data etc.

[0151] <Recording Unit 1213>

[0152] Recording unit 1213 records the transaction data generated by transaction data generation unit 1211 and the encrypted history information, which is data encrypted by secure calculation unit 1212. In this embodiment, recording unit 1213 records the encrypted history information, which is data encrypted by secure calculation unit 1212 and can be securely calculated, and records the transaction data including the first hash value generated by transaction data generation unit 1211.

[0153] <Communication Department 1214>

[0154] The communication unit 1214 communicates with the data server 300 and the authentication server 200 via the communication network 400. This communication may be performed using TLS. In this case, the encryption key used for TLS communication may be stored by the communication unit 1214.

[0155] Next, the authentication server 200a and the like will be described.

[0156] [1.7 Configuration of Authentication Server 200a]

[0157] Figure 8 200a is a block diagram showing an example of the functional configuration of the authentication server 200a according to the present embodiment. Since the authentication servers 200b and 200c have the same configuration, the following description will take the authentication server 200a as an example.

[0158] like Figure 8As shown, the authentication server 200a includes a transaction data verification unit 211, a block generation unit 212, a synchronization unit 213, a data verification unit 214, a recording unit 215, and a communication unit 216. The authentication server 200a can be implemented by a processor executing a predetermined program using a memory. The following describes each component.

[0159] <Transaction Data Verification Unit 211>

[0160] The transaction data verification unit 211 verifies received transaction data. Specifically, when receiving transaction data from a device such as the residence 100, terminal 110, or vehicle 120, the unit verifies whether the transaction data format matches and the signature is legitimate. Thus, the transaction data verification unit 211 verifies the legitimacy of the received transaction data.

[0161] When the transaction data verification unit 211 confirms the legitimacy of the transaction data as a result of the verification, the transaction data verification unit 211 records the transaction data in the recording unit 215 and notifies the synchronization unit 213 of the same.

[0162] <Block Generation Unit 212>

[0163] If the transaction data verification unit 211 successfully verifies the transaction data, the block generation unit 212 executes a consensus algorithm for the transaction data among multiple authentication servers. The consensus algorithm may be a Practical Byzantine Fault Tolerance (PBFT) consensus algorithm or another well-known consensus algorithm.

[0164] Thus, in this embodiment, the block generation unit 212 executes a consensus algorithm between the authentication servers 200a, 200b, and 200c. Specifically, the block generation unit 212 first generates a block in the blockchain containing one or more transaction data. Next, the block generation unit 212 executes the consensus algorithm. If consensus is reached through the execution of the consensus algorithm, the block generation unit 212 records the generated block in the recording unit 215. The block generated by the block generation unit 212 is connected to the blockchain via the recording unit 215 and recorded.

[0165] Here, the data structure of the blockchain and the data structure of part of the transaction data included in the blockchain are explained.

[0166] Figure 9 This is an explanatory diagram showing the data structure of the blockchain.

[0167] A blockchain is a chain of blocks, which serve as the unit of record. Each block contains multiple transaction data and the hash value of the previous block. Specifically, block B2 contains the hash value of the previous block B1. Then, a hash value calculated from the multiple transaction data contained in block B2 and the hash value of block B1 is included in block B3 as the hash value of block B2. This chaining of blocks effectively prevents tampering of the linked transaction data while including the contents of the previous block as a hash value.

[0168] If past transaction data is altered, the hash value of the block becomes different from the value before the change. In order to make the tampered block appear correct, all subsequent blocks must be recreated, which is very difficult in reality.

[0169] <Synchronization Unit 213>

[0170] The synchronization unit 213 synchronizes blocks of blockchain or transaction data between the authentication servers (authentication servers 200 a to 200 c ).

[0171] The synchronization units 213 of the multiple authentication servers 200a to 200c synchronize the transaction data of the blockchain in a peer-to-peer manner. The synchronization units 213 then record the synchronized transaction data of the blockchain in the recording unit 215.

[0172] For example, if the synchronization unit 213 verifies the legitimacy of the transaction data in the transaction data verification unit 211, it transmits the verified transaction data to the authentication servers 200b and 200c, which are other authentication servers 200. Furthermore, if the synchronization unit 213 receives verified transaction data from other authentication servers 200, it records the received verified transaction data in the recording unit 215.

[0173] <Data Verification Unit 214>

[0174] The data verification unit 214 sends a verification request for the encrypted history information, which is data recorded in the data server 300, and receives from the data server 300 a hash value obtained from the encrypted history information being the subject of data verification. More specifically, the data verification unit 214 generates transaction data, which includes identification information for identifying the encrypted history information of the device being verified, and indicates the data verification request, and sends it to the data server 300. The data verification unit 214 then obtains from the data server 300 a hash value obtained by performing a computation on the encrypted history information identified by the identification information in the encrypted history information recorded in the data server 300, in an encrypted state.

[0175] The data verification unit 214 verifies whether or not a hash value obtained from the history information of the device to be verified, recorded in the recording unit 215 , matches the hash value acquired from the data server 300 .

[0176] Furthermore, when requesting verification of encrypted history information, data verification unit 214 transmits transaction data containing identification information identifying the encrypted history information to data server 300, but the present invention is not limited thereto. Data verification unit 214 may transmit only the identifier, or may instead transmit transaction data indicating a request for data verification and containing information indicating the attribute type of the data. This allows identification of the encrypted history information being the subject of data verification.

[0177] <Recording Unit 215>

[0178] The recording unit 215 includes the transaction data in a block and records it in the blockchain in the distributed ledger of the storage device 201a. The storage device 201a can be constructed inside the recording unit 215 or as Figure 1 As shown, it is configured outside the authentication server 200a.

[0179] The transaction data includes transaction data received from the residence 100 , the terminal 110 , or the vehicle 120 .

[0180] In this embodiment, when the legitimacy of the transaction data received from the device is confirmed and the hash value recorded in the recording unit 215 matches the hash value obtained from the data server 300 , the recording unit 215 records the transaction data in the distributed ledger.

[0181] <Communication Department 216>

[0182] The communication unit 216 communicates with the house 100, the terminal 110, the vehicle 120, the authentication servers 200b and 200c, and the data servers 300a, 300b, and 300c. This communication may also be performed via TLS. In this case, the encryption key used for TLS communication may be maintained by the communication unit 216.

[0183] In this embodiment, communication unit 216 receives transaction data generated by the device, including a hash value derived from the device's history information. Furthermore, communication unit 216 obtains a hash value from data server 300. This hash value is obtained by data server 300 performing a computation on encrypted history information obtained from the device. The encrypted history information is encrypted history information recorded by data server 300 using a secure computation method capable of computation in an encrypted state.

[0184] Next, the data server 300a and the like will be described.

[0185] [1.8 Structure of Data Server 300a]

[0186] Figure 10 300a is a block diagram showing an example of the functional configuration of the data server 300a according to the present embodiment. The data servers 300b and 300c have the same configuration, so the following description will take the data server 300a as an example.

[0187] Data server 300a Figure 10 As shown, it includes a management unit 311 , a secure calculation unit 312 , a recording unit 313 , and a communication unit 314 .

[0188] <Administration Department 311>

[0189] The management unit 311 records encryption history information, which is encrypted data received from a device such as the house 100 , the terminal 110 , or the vehicle 120 , in the recording unit 313 .

[0190] Furthermore, when management unit 311 receives a verification request for encrypted history information of data recorded in recording unit 313 from authentication server 200, it transmits the encrypted history information of the data to be verified to security calculation unit 312. More specifically, management unit 311 transmits a request for secure calculation of a hash value for the encrypted history information of the data to be verified, recorded in recording unit 313, based on the information indicating the identifier or attribute type assigned to the verification request.

[0191] The management unit 311 receives the hash value of the encrypted history information as the data verification target received from the security calculation unit 312 , and transmits the hash value to the authentication server 200 .

[0192] <Secure Calculation Unit 312>

[0193] Upon receiving a request from management unit 311 for secure hash value calculation processing for encrypted history information subject to data verification, secure calculation unit 312 performs secure calculation using the encrypted history information subject to data verification, recorded in recording unit 313, to calculate a hash value. Furthermore, secure calculation unit 312 may collaborate with other data servers 300b and 300c to perform secure calculations to calculate hash values ​​for the encrypted history information subject to data verification. The secure hash value calculation processing may be performed using the methods disclosed in Non-Patent Document 2 and / or Non-Patent Document 3.

[0194] The secure calculation unit 312 transmits the calculated hash value to the management unit 311 .

[0195] <Recording Unit 313>

[0196] The recording unit 313 records encryption history information, which is encrypted data received from devices such as the house 100 , the terminal 110 , or the vehicle 120 .

[0197] <Communication Department 314>

[0198] The communication unit 314 communicates with the authentication servers 200a, 200b, and 200c. This communication may also be performed via TLS. In this case, the encryption key used for TLS communication may be stored by the communication unit 314.

[0199] [1.9 Overall sequence of data flow between residence, authentication server, and data server]

[0200] Next, the sequence of data flow among the house 100, the authentication servers 200a to 200c, and the data servers 300a to 300c will be described.

[0201] Figure 11 This is the overall timing diagram of data protection in this embodiment. Each process will be described later. Figure 11 The illustrated house 100 may also be a terminal 110 or a vehicle 120, both of which are examples of the device of the present invention.

[0202] First, in step S100, transaction data registration processing is performed between the residence 100, the authentication servers 200a, 200b, 200c, and the data servers 300a, 300b, 300c. Next, in step S200, data verification processing is performed between the authentication servers 200a, 200b, 200c and the data servers 300a, 300b, 300c.

[0203] The data verification process may be executed periodically, after a certain period of time has passed since the transaction data registration process was executed, or after the transaction data registration process has been executed a plurality of times.

[0204] [1.9.1 Transaction Registration Processing between the Residence and the Authentication Server]

[0205] Next, the transaction data registration process between the house 100 and the authentication servers 200a, 200b, and 200c will be described.

[0206] Figure 12 This is a sequence diagram of the transaction data registration process of this embodiment. Figure 12 In the description, the case where transaction data is registered is described using a residence 100 as an example of the device of the present invention, but the present invention is not limited thereto. The device of the present invention may also be a terminal 110 or a vehicle 120, and the same procedure applies.

[0207] First, in step S101, the controller 101 of the residence 100 obtains historical information about devices within the residence and generates data that forms the basis for transaction data. For example, the residence 100 obtains historical information such as the operation history of home appliances within the residence, the amount of power generated by the photovoltaic power generation system 102, or the amount of power output from the battery 103, and generates data that forms the basis for transaction data.

[0208] Next, in step S102, the controller 101 of the residence 100 performs hash value calculation and secure calculation, i.e., encryption using a secure calculation method, on the historical information and other data acquired in step S101. The secure calculation method may be pre-shared between the authentication servers 200a, 200b, 200c, the data servers 300a, 300b, 300c, and the controller 101 of the residence 100, or may be determined by the data protection system 10.

[0209] Next, in step S103, the controller 101 of the residence 100 generates transaction data using the hash value of the historical information obtained through the hash value calculation process in step S102 (hereinafter referred to as the first hash value). More specifically, transaction data is generated that includes the first hash value obtained from the historical information of the device. In addition to the first hash value, the transaction data also includes the transaction ID, blockchain address, and signature, as described above.

[0210] Next, in step S104, the controller 101 of the house 100 transmits the transaction data including the first hash value generated in step S103 to the authentication server 200a. Then, the authentication server 200a receives the transaction data including the first hash value and obtains the first hash value (S104a). Figure 12 In the example shown, the controller 101 of the house 100 transmits the generated transaction data to the authentication server 200a, but the transaction data may be transmitted to the authentication server 200b or the authentication server 200c. This is because the same processing is performed even when the transaction data is transmitted to the authentication server 200b or the authentication server 200c.

[0211] Next, in step S105, the controller 101 of the house 100 transmits the encrypted history information obtained by the secure calculation process in step S102 to the data servers 300a to 300c. Then, the data servers 300a to 300c receive and record the encrypted history information (S105a).

[0212] Next, in step S106, the data servers 300a to 300c perform a hash value calculation process based on a secure calculation on the encryption history information as the received encrypted data to calculate a hash value (hereinafter referred to as a second hash value). The data server 300a transmits the calculated second hash value to the authentication server 200a.

[0213] In addition, Figure 12 In the example shown, the second hash value is calculated by performing secure calculations in cooperation between the plurality of data servers 300 (data servers 300a to 300c). However, the second hash value may be calculated by performing secure calculations by one or more data servers 300.

[0214] Next, in step S107, authentication server 200a obtains the second hash value sent from data server 300a. In other words, authentication server 200a obtains the second hash value from data server 300a. This second hash value is obtained by data server 300a performing a computation on encrypted history information received from the device, which is encrypted history information recorded by data server 300a using a secure computation method capable of computation in an encrypted state.

[0215] Next, in step S108, the authentication server 200a verifies the transaction data received from the residence 100 and checks whether the hash values ​​obtained from the residence 100 and the data server 300a match. In other words, the authentication server 200a verifies the transaction data and checks whether the first hash value matches the second hash value.

[0216] In step S108 , if verification of the transaction data is unsuccessful or if the obtained first hash value and the second hash value do not match (No in S108 ), the authentication server 200a transmits a notification to that effect to the residence 100 ( S109 ) and ends the process.

[0217] On the other hand, in step S108, if verification of the transaction data is successful and the obtained first hash value matches the second hash value (Yes in S108), authentication server 200a transmits the transaction data to the other authentication servers 200 (authentication servers 200b and 200c) (S110). Furthermore, authentication servers 200b and 200c also verify the received transaction data.

[0218] Next, in step S111, authentication servers 200a, 200b, and 200c execute a consensus algorithm. Upon verifying that the received transaction data is legitimate (i.e., legitimate), authentication servers 200a, 200b, and 200c each generate a block containing the transaction data. Authentication servers 200a, 200b, and 200c then record the block containing the transaction data in the distributed ledgers of storage devices 201a, 201b, and 201c. In other words, upon confirming the legitimacy of the transaction data received from residence 100 and that the first hash value matches the second hash value, authentication server 200a synchronizes with authentication servers 200b and 200c other than authentication server 200a and records the transaction data in the distributed ledger.

[0219] [1.9.2 Data Verification Processing between Data Server and Authentication Server]

[0220] Next, the data verification process between the data server 300 and the authentication servers 200a, 200b, and 200c will be described.

[0221] Figure 13 This is a timing diagram of the data verification process of this embodiment. Figure 13 In the above description, it is assumed that the authentication server 200a performs the data verification request and performs the data verification process, but the authentication server 200b or the authentication server 200c may also perform the data verification process. The same process is performed when the authentication server 200b or the authentication server 200c performs the data verification process.

[0222] First, in step S201a, the authentication server 200a obtains identification information (ID) of encrypted historical information that identifies the historical information of the device that is the data verification target, and a hash value (hereinafter referred to as the third hash value) obtained from the historical information, from the transaction data recorded in the distributed ledger or the transaction data sent from the device.

[0223] Next, in step S201, the authentication server 200a requests verification of the history information of the device to be verified. Specifically, the authentication server 200a selects the history information to be verified from the identification information included in the acquired transaction data and generates a data verification request.

[0224] Next, in step S202, the authentication server 200a generates transaction data (hereinafter referred to as first transaction data) indicating a request for data verification of the historical information to be verified. For example, the authentication server 200a generates the first transaction data, which includes a transaction ID, identification information that identifies encrypted historical information of the device to be verified, and a signature.

[0225] Next, in step S203 , the authentication server 200 a transmits the first transaction data indicating the request for data verification generated in step S202 to the data servers 300 a to 300 c .

[0226] Next, in step S204, data servers 300a-300c, in collaboration with data servers 300b and 300c, perform secure hash value calculations on the encrypted history information serving as the data verification target, based on the first transaction data received from authentication server 200a. Furthermore, secure hash value calculations are not limited to being performed collaboratively between multiple data servers 300; they may also be performed by more than one data server 300.

[0227] Next, in step S205 , the data server 300 a transmits to the authentication server 200 a a hash value (hereinafter referred to as a fourth hash value) calculated by performing a hash value calculation process based on a secure calculation on the encrypted history information serving as the data verification target.

[0228] Next, in step S206, authentication server 200a obtains a fourth hash value from data server 300a. In other words, authentication server 200a obtains a fourth hash value from data server 300a and the like. This fourth hash value is obtained by performing a calculation on the encrypted history information identified by the identification information in the encrypted history information recorded by data server 300a and the like, while the encrypted history information is encrypted.

[0229] Next, in step S207 , the authentication server 200 a verifies whether the third hash value obtained in step S201 a and the fourth hash value obtained in step S206 match.

[0230] In step S207, when the third hash value and the fourth hash value are consistent with each other (yes in S207), the authentication server 200a determines that the data verification is successful and the processing ends. On the other hand, in step S207, when the third hash value and the fourth hash value are inconsistent with each other (no in S207), the authentication server 200a determines that the data verification is unsuccessful and generates transaction data for a delegation for data deletion (S208). Hereinafter, the transaction data for a delegation for data deletion will be referred to as the second transaction data. In other words, when the third hash value and the fourth hash value are inconsistent with each other, the authentication server 200a generates the second transaction data that includes identification information and represents a delegation for deletion of encrypted information determined by the identification information.

[0231] In step S208a, the authentication server 200a transmits the second transaction data generated in step S208 to the data servers 300a to 300c as an error notification (S208a).

[0232] Furthermore, in step S209 , the authentication server 200 a transmits the second transaction data generated in step S208 to the other authentication servers 200 (authentication servers 200 a and 200 b ).

[0233] Next, in step S210, authentication servers 200a, 200b, and 200c execute a consensus algorithm. Upon verifying that the received transaction data is correct (i.e., legitimate), authentication servers 200a, 200b, and 200c each generate a block containing the transaction data. Authentication servers 200a, 200b, and 200c then record the block containing the transaction data in the distributed ledgers of storage devices 201a, 201b, and 201c. In other words, if the third hash value and the fourth hash value do not match, authentication server 200a synchronizes with authentication servers 200b and 200c other than authentication server 200a and records the second transaction data in the distributed ledger.

[0234] Furthermore, in step S211 , the data servers 300 a to 300 c perform data deletion processing based on the data deletion request received from the authentication server 200 a .

[0235] [1.10 Effects of Implementation Method 1]

[0236] In implementation mode 1, encrypted data of personal data such as historical information encrypted in a manner that enables secure calculation is recorded in a data server from a device such as a residence 100, a terminal 110, or a vehicle 120, and transaction data containing only a hash value of the encrypted data is recorded in a distributed ledger.

[0237] This effectively prevents tampering with encrypted data and, even if the transaction data contained in the blockchain blocks is made public, personal data will not be leaked, thus ensuring privacy protection. Furthermore, by using secure computing, personal data stored in the data server can be effectively utilized without decryption.

[0238] In addition, as needed, personal data recorded in the data server can be verified by comparing the hash value of the encrypted data obtained by secure calculation with the hash value included in the transaction data of the distributed ledger.

[0239] Therefore, it is possible to verify the personal data recorded in the data server without leaking the personal data.

[0240] As a result, even if the user provides personal data, privacy is protected, and it is easy to provide personal data to the data server 300, that is, to provide transaction data including encrypted data encrypted in a manner that enables secure calculation.

[0241] In this way, by utilizing blockchain technology, it is possible to build a secure system that not only effectively prevents tampering of personal data, but also effectively utilizes data including data verification while protecting the privacy of personal data.

[0242] [2. Other Modifications]

[0243] Furthermore, although the present invention has been described based on the above-mentioned embodiments, the present invention is not limited to the above-mentioned embodiments, and the present invention also includes the following aspects.

[0244] (1) In the above embodiment, the authentication server 200 and the data server 300 are described as separate devices. However, the authentication server 200 and the data server 300 may be the same device.

[0245] (2) In the above embodiment, when verification of transaction data fails, authentication server 200 notifies house 100, terminal 110, or vehicle 120, but may notify data server 300. In this case, data server 300 deletes the received encrypted data.

[0246] (3) As described in the above embodiment, multiple data servers 300 may cooperate to perform secure computation processing, or a single data server 300 may perform secure computation processing based on existing secure computation encryption methods.

[0247] (4) In the above-mentioned embodiment, the encryption process based on the secure calculation may use multiple encryption methods, thereby being able to cope with various methods.

[0248] (5) In the above-described embodiment, the residence 100, terminal 110, and vehicle 120 encrypt historical information and transmit the encrypted historical information to the data server 300. However, an encryption method based on secure computing that allows multiple servers to collaborate on decryption may also be used. In this case, the encrypted data recorded by the data server 300 can be decrypted based on the authorization of the authentication server 200 and the permission of the user of the residence 100, terminal 110, or vehicle 120. This allows historical information, etc., to be decrypted when necessary, enabling efficient use of the data.

[0249] (6) In the above-described embodiment, the house 100, the terminal 110, and the vehicle 120 transmit encrypted historical information obtained by encrypting historical information to the data server 300, but the present invention is not limited to this. The house 100, the terminal 110, or the vehicle 120 can receive the encrypted historical information recorded in the data server 300 and decrypt the encrypted historical information to verify tampering. If tampering is detected as a verification result, the authentication server 200 or the data server 300 can be notified of this fact. Thus, by recording the encrypted historical information as encrypted data in the data server 300, it is unnecessary to store the encrypted data on the device side such as the house 100. In addition, if the house 100, the terminal 110, or the vehicle 120 receives the encrypted data recorded in the data server 300 and decrypts the encrypted data to verify tampering, a token can be issued to the authenticated house 100, the terminal 110, or the vehicle 120. In this case, the token can be issued by the authentication server 200, the data server 300, or a token held by the authentication server 200 or the data server 300 can be sent.

[0250] (7) In the above embodiment, if the data verification performed in step S108 is unsuccessful, the data server 300 may be notified and the encrypted data recorded in the data server 300 may be deleted.

[0251] (8) In the above embodiment, authentication server 200 generates a request for data verification, and data server 300 calculates a hash value. However, the present invention is not limited thereto. Data server 300 may periodically or irregularly perform hash value calculation processing and request data verification by notifying authentication server 200 of the hash value obtained by the hash value calculation processing.

[0252] (9) In the above-described embodiment, the blockchain recorded by the authentication server 200 may be disclosed to the residence 100 , the terminal 110 , and the vehicle 120 .

[0253] (10) In addition, the present invention includes a data structure for a block recorded as a blockchain in the data protection system 10 of the above-mentioned embodiment. More specifically, the data structure of the present invention includes: a blockchain address, which is an identifier for identifying the subject that generated the transaction data included in the block of the blockchain; a transaction ID, which identifies the transaction data; a first hash value, which is a first hash value included in the transaction data and obtained from the history information of the device; and an electronic signature of the user of the transaction data. Furthermore, when the second hash value is consistent with the first hash value, the transaction data is included in the block. The second hash value is obtained by the data server 300 performing a calculation on the encrypted history information obtained from the device in an encrypted state. The encrypted history information is encrypted history information obtained by encrypting the history information of the device using a secure calculation method that can be calculated in an encrypted state.

[0254] (11) Specifically, each device in the above-mentioned embodiment is a computer system composed of a microprocessor, ROM, RAM, hard disk unit, display unit, keyboard, mouse, etc. A computer program is recorded in the RAM or hard disk unit. The microprocessor operates according to the computer program, thereby realizing the function of each device. Here, the computer program is composed of a combination of multiple command codes representing instructions to the computer in order to realize the specified function.

[0255] (12) In each of the devices in the above-described embodiments, some or all of the components may be formed by a system LSI (Large Scale Integration). A system LSI is a highly multifunctional LSI manufactured by integrating multiple components on a single chip. Specifically, it is a computer system composed of a microprocessor, ROM, RAM, etc. A computer program is recorded in the RAM. The microprocessor operates according to the computer program, thereby achieving the functions of the system LSI.

[0256] Furthermore, each component constituting each of the above-mentioned devices may be individually integrated into a single chip, or a part or all of the components may be integrated into a single chip.

[0257] Although referred to here as a system LSI, it is sometimes also referred to as an IC, LSI, super LSI, or ultra-large-scale LSI, depending on the degree of integration. Furthermore, integrated circuitry is not limited to LSIs and can also be achieved using dedicated circuits or general-purpose processors. FPGAs (Field Programmable Gate Arrays) that can be programmed after LSI fabrication, or reconfigurable processors that allow the connections and settings of circuit cells within the LSI to be reconfigured, can also be used.

[0258] Furthermore, if semiconductor technology or other derived technologies lead to the emergence of integrated circuit technology that replaces LSIs, it is natural that such technology could be used to integrate functional blocks. Biotechnology, etc., could also be applied.

[0259] (13) Some or all of the components of each of the above-mentioned devices may be composed of an IC card or a single module that can be attached to or detached from the device. The IC card or module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or module may also include the above-mentioned ultra-multifunctional LSI. The microprocessor operates according to the computer program, thereby enabling the IC card or module to realize its functions. The IC card or module may also be tamper-resistant.

[0260] (14) The present invention may also be the methods shown above. In addition, it may be a computer program that realizes these methods on a computer, or it may be a digital signal composed of the computer program.

[0261] In addition, the present invention may also include recording the computer program or the digital signal on a computer-readable recording medium, such as a floppy disk, hard disk, CD-ROM, MO, DVD, DVD-ROM, DVD-RAM, BD (Blu-ray Disc), semiconductor memory, etc. Alternatively, the digital signal may be recorded on these recording media.

[0262] Furthermore, the present invention may also be implemented by transmitting the computer program or the digital signal via a telecommunication line, a wireless or wired communication line, a network represented by the Internet, data broadcasting, or the like.

[0263] Furthermore, the present invention may be a computer system including a microprocessor and a memory, wherein the memory stores the computer program and the microprocessor operates according to the computer program.

[0264] Furthermore, the program or the digital signal may be recorded on the recording medium and transferred, or the program or the digital signal may be transferred via the network or the like, thereby being implemented by another independent computer system.

[0265] (15) The above-mentioned embodiments and modifications may be combined.

[0266] Industrial Applicability

[0267] In the data protection system of the present invention, historical information of a device is encrypted and sent in a secure computing manner, and a hash value is calculated by a server in an encrypted state, thereby being able to verify data while protecting privacy.

Claims

1. A data protection method, performed by a first authentication server among a data protection system comprising a device, a plurality of authentication servers, and a plurality of data servers, wherein: Include: receiving transaction data generated by the device, the transaction data including a first hash value obtained from historical information of the device; a step of obtaining a second hash value from one or more of the data servers, the second hash value being obtained by the one or more data servers cooperatively performing a calculation on encrypted history information obtained from the device using a secure calculation method capable of performing calculations in an encrypted state, the encrypted history information being encrypted history information of the device recorded by the one or more data servers using a secure calculation method capable of performing calculations in an encrypted state; A step of verifying the transaction data and confirming whether the first hash value is consistent with the second hash value; as well as When the legitimacy of the transaction data is confirmed and the first hash value is consistent with the second hash value, the step of synchronizing with the plurality of authentication servers other than the first authentication server and recording the transaction data in a distributed ledger is performed; In the data protection system, the encrypted history information is decrypted based on the permission of the user of the device through a decryption process in a secure computing manner in which the plurality of data servers can collaboratively perform decryption.

2. The data protection method according to claim 1, wherein: Also includes: a step of acquiring identification information and a third hash value from the device, wherein the identification information identifies first encrypted history information of first history information to be verified as a data object, and the third hash value is obtained from the first history information; a step of generating first transaction data including the identification information and indicating a request for data verification, and transmitting the first transaction data to the one or more data servers; a step of obtaining a fourth hash value from the one or more data servers, the fourth hash value being obtained by performing a calculation by the one or more data servers on the first encrypted history information identified by the identification information in the encrypted history information obtained from the device and recorded by the one or more data servers in an encrypted state; a step of confirming whether the third hash value is consistent with the fourth hash value; A step of generating second transaction data and transmitting the second transaction data to the one or more data servers when the third hash value does not match the fourth hash value, wherein the second transaction data includes the identification information and indicates a request to delete the first encrypted history information identified by the identification information.

3. The data protection method according to claim 2, wherein: The data protection method further comprises: When the third hash value and the fourth hash value are inconsistent, the plurality of authentication servers are synchronized and the second transaction data is recorded in the distributed ledger.

4. The data protection method according to any one of claims 1 to 3, characterized in that: The history information contains personal data of the user of the device.

5. An authentication server, which is one of the authentication servers in a data protection system comprising a device, a plurality of authentication servers, and a plurality of data servers, characterized in that: have: a communication unit that receives transaction data generated by the device and includes a first hash value obtained from history information of the device, and obtains a second hash value from the data server, the second hash value being obtained by the plurality of data servers cooperatively performing a calculation on the encrypted history information obtained from the device using a secure calculation method capable of performing calculations in an encrypted state, the encrypted history information being encrypted history information of the device recorded by the one or more data servers using a secure calculation method capable of performing calculations in an encrypted state; A transaction data verification unit, configured to verify the transaction data; a data verification unit, confirming whether the first hash value is consistent with the second hash value; as well as a recording unit that synchronizes with the plurality of authentication servers and records the transaction data in a distributed ledger when the legitimacy of the transaction data is confirmed and the first hash value is consistent with the second hash value; In the data protection system, the encrypted history information is decrypted based on the permission of the user of the device through a decryption process in a secure computing manner in which the plurality of data servers can collaboratively perform decryption.

6. A data protection system, characterized in that: have: equipment; multiple authentication servers; and Multiple data servers, The device has: a transaction data generating unit that generates transaction data including a first hash value obtained from the historical information of the device and sends the transaction data to one of the plurality of authentication servers; as well as The first secure calculation unit encrypts the history information using a secure calculation method capable of being operated in an encrypted state, generates encrypted history information, and transmits the encrypted history information to the plurality of data servers. Each of the plurality of data servers comprises: a recording unit that records the encryption history information obtained from the device; and The second secure calculation unit performs calculation processing on the recorded encrypted history information using a secure calculation method capable of performing calculations in an encrypted state through the cooperation of the plurality of data servers to obtain a second hash value of the recorded encrypted history information and sends the second hash value to the one authentication server. The one authentication server has: a communication unit that receives the transaction data including the first hash value from the device and obtains the second hash value from one or more data servers; A transaction data verification unit, configured to verify the transaction data; a data verification unit, confirming whether the first hash value is consistent with the second hash value; as well as a recording unit that synchronizes with the plurality of authentication servers and records the transaction data in a distributed ledger when the legitimacy of the transaction data is confirmed and the first hash value is consistent with the second hash value; In the data protection system, the encrypted history information is decrypted based on the permission of the user of the device through a decryption process in a secure computing manner in which the plurality of data servers can collaboratively perform decryption.

Citation Information

Patent Citations

  • Finger vein identification trusted operation control method and system

    CN106971101A

  • Method and device for processing service request

    CN107196989A

  • Distributed transaction processing and authentication system

    CN109691016A

  • Data distribution method, authentication server, and data structure

    CN110795721A

  • Secure Distributed Patient Consent and Information Management

    US20180082023A1