Information management method and information management system

By using homomorphic encryption technology and public key sharing mechanism in supply chain management, non-disclosure of information of each trader is achieved, and the overall information of the supply chain is allowed to be obtained, solving the problems of information disclosure and overall information acquisition in the existing technology.

CN120202498APending Publication Date: 2025-06-24DENSO CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202380079054.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-11-17
Filing Date
2023-10-11
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

It is difficult for the prior art to realize non-disclosure of information of each trader in supply chain management, and at the same time to obtain information of the overall supply chain.

Method used

By using homomorphic encryption technology, each trader shares the public key, and the front-side trader encrypts the carbon release amount of other companies and the carbon release amount of our company, performs secret calculations, generates the cumulative release amount of encrypted, and uses it as information to provide back-side traders.

Benefits of technology

The information of each trader is not disclosed, and the private key holder is allowed to decrypt the accumulated release amount through the accumulated encryption to obtain the overall information of the supply chain.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120202498A_ABST
    Figure CN120202498A_ABST
Patent Text Reader

Abstract

In an information management method implemented by a supply chain management system, information associated with each of a plurality of traders (TR) constituting a supply chain (SC) is managed. In the information management method, a private key (sk) and a public key (pk) based on homomorphic encryption are prepared, and the public key (pk) is shared by a plurality of traders (TR). Furthermore, an encrypted other company release amount, which is encrypted using the public key (pk) by a front-side trader who supplies the delivery item, is acquired, and an encrypted local company release amount, which is encrypted using the public key (pk), item-related information relating to handling of the delivery item is prepared. Then, an encrypted cumulative release amount calculated by using a secret that encrypts the other company release amount and the own company release amount is used as provision information to a back-side trader that offers the shipping item.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - reference to related applications

[0002] This application is based on Japanese Patent Application No. 2022 - 184387 filed in Japan on November 17, 2022, and incorporates by reference the entire contents of the basic application. Technical field

[0003] The disclosure of this specification relates to a technology for information management. Background art

[0004] A supply chain management method is disclosed in Patent Document 1, which manages transaction records among each trader in a supply chain constructed with multiple traders.

[0005] In addition, a cryptographic system is disclosed in Patent Document 2, which can perform homomorphic operations on encrypted data encrypted with a user's public key and decrypt the operation result of the homomorphic operation using a master private key.

[0006] Patent Document 1: International Publication No. 2021 / 002226;

[0007] Patent Document 2: Japanese Unexamined Patent Application Publication No. 2018 - 36418.

[0008] In principle, each trader constructing the supply chain disclosed in Patent Document 1 does not want information to be publicly disclosed to the outside. Therefore, it may be difficult to obtain information on the entire supply chain by receiving information from all traders. Therefore, it has been studied to use the homomorphic operation used in the cryptographic system of Patent Document 2 to obtain information on the entire supply chain.

[0009] However, it is difficult to achieve either avoiding information disclosure by each trader to the outside or obtaining information on the entire supply chain only by using the general cryptographic system disclosed in Patent Document 2 in the information management of the supply chain. Summary of the invention

[0010] An object of the present disclosure is to provide an information management method and an information management system that can keep the information of each trader non - public and obtain information on the entire supply chain.

[0011] To achieve the above object, one disclosed approach is an information management method implemented by a computer to manage information associated with each of a plurality of traders constituting a supply chain. The processing executed by at least one processor includes the following steps: Prepare a private key and a public key based on homomorphic encryption, and share the public key among the plurality of traders; Obtain acquired encrypted information encrypted by a previous trader using the public key, where the previous trader is a trader in the previous process of supplying a delivery item; Prepare generated encrypted information obtained by encrypting item-related information related to the disposition of the delivery item using the public key; Use the secret calculation result obtained by performing a secret calculation using the acquired encrypted information and the generated encrypted information as the provided information to a subsequent trader, where the subsequent trader is a trader in the next process of providing a shipped item.

[0012] In addition, one disclosed approach is an information management system that manages information associated with each of a plurality of traders constituting a supply chain. The information management system includes: A key generation unit that prepares a private key and a public key based on homomorphic encryption and shares the public key among the plurality of traders; An information acquisition unit that obtains acquired encrypted information encrypted by a previous trader using the public key, where the previous trader is a trader in the previous process of supplying a delivery item; An information generation unit that prepares generated encrypted information obtained by encrypting item-related information related to the disposition of the delivery item using the public key; And an information providing unit that uses the secret calculation result obtained by performing a secret calculation using the acquired encrypted information and the generated encrypted information as the provided information to a subsequent trader, where the subsequent trader is a trader in the next process of providing a shipped item.

[0013] In these approaches, the acquired encrypted information encrypted by the previous trader providing the delivery item and the generated encrypted information obtained by encrypting the item-related information related to the disposition of the delivery item are used for secret calculation to calculate the secret calculation result. Then, the secret calculation result is used as the provided information to the subsequent trader supplying the shipped item. According to the above configuration, even if the subsequent trader holds the private key, the acquired encrypted information encrypted by the previous trader and the generated encrypted information will not be provided to the subsequent trader. Therefore, the item-related information of the previous trader and the item-related information of the current trader will not be disclosed to the subsequent trader. In addition, as the transaction progresses, the generated encrypted information of each trader is appended to the secret calculation result. Therefore, the holder of the private key can obtain the information of the entire supply chain by decrypting the accumulated secret calculation results.

[0014] Therefore, it is possible to keep the information of each trader non-public and obtain the information of the entire supply chain.

[0015] Among them, the reference numbers in parentheses in the claims only represent an example of the correspondence relationship with the specific structures in the following embodiments, and do not impose any limitations on the technical scope. In addition, as long as the combination is not particularly hindered, combinations of claims not explicitly shown in the claims may also be made. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 FIG. is a diagram for explaining the use of public keys and private keys in the supply chain of the first embodiment of the present disclosure.

[0017] Figure 2 FIG. is a diagram showing an overall image of the supply chain management system.

[0018] Figure 3 FIG. is a detailed flowchart showing a key sharing process of providing the public key generated in this process to the trader in the previous process.

[0019] Figure 4 FIG. is a detailed flowchart showing a key sharing process of providing the public key obtained from the subsequent process to the trader in the previous process.

[0020] Figure 5 FIG. is a detailed flowchart showing a secret calculation process of calculating the cumulative carbon emissions through secret calculation.

[0021] Figure 6 FIG. is a detailed flowchart showing a decryption and addition process of decrypting the cumulative carbon emissions up to the previous process and adding the carbon emissions in this process.

[0022] Figure 7 FIG. is a detailed flowchart showing a process of registering the acquired information from the trader terminal in the management server process implemented by the information management server.

[0023] Figure 8 FIG. is a detailed flowchart showing a process of providing the registered information to the information viewing server in the management server process.

[0024] Figure 9 FIG. is a detailed diagram showing the viewing server process implemented by the information viewing server.

[0025] Figure 10 FIG. is a diagram for explaining the use of public keys and private keys in the supply chain of the second embodiment of the present disclosure.

[0026] Figure 11 FIG. is a diagram showing an overall image of the supply chain management system. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] Hereinafter, a plurality of embodiments of the present disclosure will be described based on the accompanying drawings. In addition, there are cases where redundant explanations are omitted by assigning the same reference numerals to corresponding components in each embodiment. When only a part of the structure is described in each embodiment, the structure of other embodiments described previously can be applied to other parts of the structure. In addition, not only the combinations of structures clearly shown in the description of each embodiment, but also the structures of multiple embodiments can be partially combined with each other as long as the combination is not particularly hindered even if not clearly shown. Moreover, the combinations not clearly shown between the structures described in multiple embodiments and modification examples are also disclosed by the following description.

[0028] (First Embodiment)

[0029] Figure 1 The supply chain SC shown is a connection between traders TR for delivering industrial products, agricultural products, aquatic products, etc. to end users. The supply chain SC is constructed by a plurality of traders TR (refer to Figure 1 Companies A to F). The final products supplied by the supply chain SC can be various items such as automobiles, batteries, semiconductors, fresh food, aquatic products, food, flowers, pharmaceuticals, and chemical products.

[0030] The supply chain management system according to the first embodiment of the present disclosure manages the transaction records of items traded between each trader TR as information associated with each trader TR in the supply chain SC. The transaction record is historical information that realizes the traceability of items traded between traders TR and includes a plurality of information indicating the time and place where the transaction occurred, etc.

[0031] In addition to the transaction record, the supply chain management system also manages item-related information related to the items that are the subject of the transaction. For example, information related to raw materials, information related to processing and assembly, and information related to distribution, etc. are managed as item-related information. And the supply chain management system collects and accumulates information related to the amount of greenhouse gas emissions (hereinafter, carbon emissions) discharged in each process of manufacturing and distributing the item as one of the item-related information.

[0032] The supply chain management system obtains a value obtained by combining the carbon emissions discharged by each trader TR and can be presented as a carbon footprint to end users and regulatory authorities SA, etc. The carbon footprint may also include carbon emissions in processes such as extraction and recycling of raw materials of the item, and carbon emissions in processes related to disposal such as incineration and landfill of the item. And the carbon footprint may also include carbon emissions in the transportation process, and carbon emissions from offices, etc. that are not directly related to manufacturing.

[0033] In addition, the greenhouse gas for which the emission amount is recorded may be only carbon dioxide, or may appropriately include greenhouse gases other than carbon dioxide, specifically, methane, nitrous oxide, hydrofluorocarbons, perfluorocarbons, sulfur hexafluoride, and the like. In this case, the emission amount of greenhouse gases other than carbon dioxide is converted into the emission amount of carbon dioxide and is calculated within the value of the carbon footprint presented.

[0034] Here, the carbon emission amount is mostly a trade secret in each trader TR. This is because the production rhythm and manufacturing method related to manufacturing can be inferred from the carbon emission amount. Therefore, there are many companies that do not want to disclose the carbon emission amount to other trader TRs, etc. Against this background, the supply chain management system accumulates the carbon emission amounts of each trader TR in a non-disclosed state and only obtains the carbon footprint of the final product. Hereinafter, based on Figure 1 and Figure 2 the details of the supply chain management system will be described.

[0035] The supply chain management system is composed of multiple trader terminals 50, an information management server 100s, an application distribution server 100a, an information viewing server 110, and the like. Each element constituting the supply chain management system is connected to the network as a node and can communicate with each other.

[0036] <Trader TR and Trader Terminal 50>

[0037] The trader terminal 50 is an information processing device used by each trader TR. For example, a smartphone, a tablet terminal, a personal computer, etc. can be used as the trader terminal 50. The trader terminals 50 are respectively associated with each company A to F (refer to Figure 1 ). The trader terminal 50 is used in each trader TR to collect and accumulate transaction records and item-related information. The trader terminal 50 records delivery information such as from which trader TR raw materials or components are purchased, when the items are obtained, and shipping information such as to which trader TR the goods are shipped and when as transaction records. And the trader terminal 50 records at least cost-related information and carbon emission amounts, etc. as item-related information.

[0038] The trader terminal 50 has a structure centered around the processing circuit 50c. The processing circuit 50c includes a processor 51, a RAM (Random Access Memory) 52, a storage unit 53, an input / output interface, and a bus connecting them, and functions as a computer for performing arithmetic processing. The processor 51 is hardware for arithmetic processing combined with the RAM 52. In the storage unit 53, an application program (information management application APT) for causing the processing circuit 50c to execute the information management method of the present disclosure is stored. A display, a barcode reader (or a camera), a printer, etc. are electrically connected to the input / output interface. The display, the barcode reader, and the printer may be integrated with the trader terminal 50, or may be electrically connected to the trader terminal 50 by wire or wirelessly.

[0039] By the processor 51 executing the information management application APT stored in the storage unit 53, the trader terminal 50 has functional units such as a key management unit 61, an information acquisition unit 62, an information arithmetic unit 63, an information providing unit 64, and a code output unit 65.

[0040] The key management unit 61 manages a private key sk and a public key pk based on homomorphic encryption. In addition, generally, most traders TR only hold the public key pk, but a trader TR mainly managing carbon emission amounts may also hold the private key sk. When providing information related to items equivalent to trade secrets to the trader terminal 50 of another trader TR, the private key sk and the public key pk are used for encryption and decryption of the item-related information. Homomorphic encryption is an encryption method that can process data in an encrypted state without decrypting the encrypted data. As one of the homomorphic encryptions, the key management unit 61 uses, for example, fully homomorphic encryption such as FHE (Fully Homomorphic Encryption). Fully homomorphic encryption can perform addition, subtraction, multiplication, and division in an encrypted state. Instead of fully homomorphic encryption, multiplicative homomorphic encryptions such as RSA encryption and EIGamal encryption, and additive homomorphic encryptions such as Goldwasser-Micali encryption and Paillier encryption can be used according to the processing content of secret calculation described later.

[0041] If we further explain the secret computation using homomorphic encryption, the key management unit 61 uses the key generation function KeyGen to generate the shared public key pk and the private key sk with decryption authority. Moreover, if we set M as the message space, C as the encryption space, Enc as the probabilistic encryption function, and Dec as the deterministic decryption function, then for the message m ∈ M, the encryption is set as c ← Enc(m, pk), and the decryption is set as m ← Dec(c, sk). And being able to process data in the encrypted state means that as shown in the following formula 1, for the messages m1, m2 ∈ M, there exists a

[0042] [Formula 1]

[0043]

[0044] such operator + in the message space M (right side) and operator (the symbol of "plus in ○" above, exclusive OR) in the encryption space C (left side).

[0045] The key management unit 61 performs a key sharing process in which the public key pk is shared by multiple traders TR (refer to Figure 3 and Figure 4 ). The content of the key sharing process changes according to the attributes of the trader TR using the trader terminal 50. Specifically, among the multiple traders TR, there are reporters TRs who have the obligation to report project-related information (carbon footprint) to the supervisory authority SA that supervises the supply chain SC, and non-reporters TRn who do not have the reporting obligation. Traders TR who supply the final product and traders TR who supply specific finished products to the supply chain SC are pre-selected as reporters TRs.

[0046] The key management unit 61 of the trader terminal 50 used by the reporters TRs (refer to Figure 1 companies C, D, F) performs a key sharing process of sharing the generated public key pk with the trader TR in the previous process (the previous trader) ( Figure 3 , S10). In the key sharing process, the key management unit 61 generates a pair (S11) of the private key sk and the public key pk based on fully homomorphic encryption by using the above-mentioned key generation function. The key management unit 61 stores the generated private key sk (refer to Figure 1 private key Cskc, private key Dskd, private key Fskf) without leaking it to the outside (S12).

[0047] The key management unit 61 grasps the generated public key pk (refer to Figure 1The destinations (S13) to which the public keys Cpkc, Dpkd, and Fpkf are provided. The destination to which the public key pk is provided is determined based on the connection method of the trader TR in the supply chain SC. Specifically, the source of the item delivered (supplied) to the company (hereinafter referred to as the delivered item), i.e., the previous trader, is selected as the destination to which the public key pk is provided. When multiple traders TR deliver items to the company, multiple previous traders are set as the destinations to which the public key pk is provided. The key management unit 61 provides the public key pk to the destinations it knows (S14). The key management unit 61 shares the public key pk with the key management unit 61 of the trader terminal 50 associated with the previous trader through a secure communication via the network.

[0048] Performed by the non-reporter TRn (refer to Figure 1 Companies A, B, and E) of the trader terminal 50, the key management unit 61 performs a key sharing process ( Figure 4 , S20) of sharing the public key pk obtained from the next process trader TR (the subsequent trader) with the previous trader. The key management unit 61 stores the public key pk obtained from the subsequent trader (S21). The key management unit 61 knows the destination to which the obtained public key pk is provided (S22). In this case, similar to the above process (refer to Figure 3 S13), the source of the delivered item, i.e., one or more previous traders, are selected as the destinations to which the public key pk is provided.

[0049] The key management unit 61 determines whether there is a destination to which the public key pk is provided (S23). When the company is the trader TR that is the starting point of the supply chain SC and there is no destination to which the public key pk is provided (S23: No), the key management unit 61 ends the key sharing process. On the other hand, when there is a previous trader that is the destination (S23: Yes), the key management unit 61 provides the public key pk obtained from the subsequent trader to the known destinations through secure communication (S24).

[0050] By each trader terminal 50 performing the above key sharing process, the public key pk is transferred in the direction opposite to the item (upstream side) along the supply chain SC. As a result, among the relevant multiple traders TR, the unique public key pk is shared before starting the accumulation of project-related information.

[0051] As a specific example, in the case of companies A to F (refer to Figure 1)In the supply chain SC thus constituted, the public key Cpkc, the public key Dpkd, and the public key Fpkf are shared among relevant companies. That is, in Company C, the private key Cskc is generated, and the public key Cpkc corresponding to the private key Cskc is generated. The public key Cpkc is shared among Companies A to C. Similarly, in Company D, the private key Dskd is generated, and the public key Dpkd corresponding to the private key Dskd is generated. The public key Dpkd is shared among Companies C and D. Further, in Company F, the private key Fskf is generated, and the public key Fpkf corresponding to the private key Fskf is generated. The public key Fpkf is shared among Companies D to F. In addition, the sharing of the public key pk based on each key sharing process can also be implemented via the information management server 100s.

[0052] The information acquisition unit 62 acquires the identification information of the delivered item read by the barcode reader. As the identification information of the item, at least one of the unique identification ID (hereinafter, UID) issued by the information management server 100s or the hash value generated based on the transaction record and the item-related information is used. The identification information including at least one of the UID and the hash value is recorded in a one-dimensional code or a two-dimensional code (e.g., QR code, registered trademark) attached to the delivered item in a state that can be read by a barcode reader or the like.

[0053] The information acquisition unit 62 acquires the transaction record of the item and the item-related information. In the item-related information, in addition to the information related to the handling (e.g., processing, assembly, transportation, and storage, etc.) of the delivered item by the trader TR, the information related to the above-mentioned carbon emission amount is also included. The information acquisition unit 62 can automatically acquire the transaction record and the item-related information from other server devices provided at the base of the trader TR, or can also acquire the data manually input according to a pre-specified management process as the transaction record and the item-related information.

[0054] The information acquisition unit 62 acquires the UID attached to the item shipped (provided) from the company (hereinafter, shipped item) by receiving from the information management server 100s. In the form where the hash value is used for item identification, the information acquisition unit 62 acquires the hash value generated by the information operation unit 63. The information acquisition unit 62 stores the transaction record and the item-related information in the user database DB2 in a state associated with each UID (or hash value) of the delivered item and the shipped item. The information acquisition unit 62 extracts the transaction record and the item-related information related to the UID (or hash value) from the data stored in the user database DB2 by using the UID or the hash value as a search key. In addition, the user database DB2 can be a local storage device provided at the base of the trader TR, or can also be a storage on the cloud.

[0055] The information operation unit 63 performs various operations related to transaction records and project-related information. The information operation unit 63 generates the above-mentioned hash value by inputting the transaction records associated with the project and the project-related information into the processing of a specified hash function. Further, the information operation unit 63 performs a process of encrypting the project-related information using the public key pk and a process of performing secret calculation on the encrypted information.

[0056] The information providing unit 64 provides the information collected by the trader terminal 50 to the information management server 100s. The information providing unit 64 associates the hash value generated by the information operation unit 63 with the UID and sends it to the information management server 100s (the information receiving unit 31 described later). Further, the hash value may also be generated by the information management server 100s and issued to the trader terminal 50 in the same manner as the UID. In such a form, the information providing unit 64 sends the information that is not equivalent to a trade secret in the transaction records and the project-related information obtained by the information acquisition unit 62 to the information management server 100s. The information management server 100s generates a hash value based on the received information and issues the generated hash value to the information acquisition unit 62.

[0057] The code output unit 65 is connected to a printer. The code output unit 65 causes a label printed with a two-dimensional code or the like to be output to the printer. The UID or the hash value issued by the information management server 100s (the information delivery unit 33 described later) is recorded in the two-dimensional code. The label is attached to the shipped item and circulates to the trader TR in the next process together with the shipped item. Further, the two-dimensional code may also be directly laser-engraved or printed on the item or the like. In this case, a laser marking machine or an inkjet printer or the like can be used as the output device instead of the printer.

[0058] [Secret calculation process and decryption total process]

[0059] The information acquisition unit 62, the information operation unit 63, and the information providing unit 64 described so far perform a secret calculation process (refer to Figure 5 ) or a decryption total process (refer to Figure 6 ). The secret calculation process and the decryption total process are continuously and repeatedly performed by the trader terminal 50. The secret calculation process is performed by the trader terminal 50 used by the non-reporting traders TRn (refer to Figure 1 , companies A, B, and E). In the secret calculation process, the carbon emissions are totaled while remaining encrypted. On the other hand, the decryption total process is performed by the trader terminal 50 used by the reporting traders TRs (refer to Figure 1 , companies C, D, and F). In the decryption total process, the carbon emissions are totaled, and the public key pk used for encryption is switched.

[0060] In the secret calculation process (refer toFigure 5 ) In this case, the information acquisition unit 62 determines the presence or absence of a previous-stage trader (S41). When there is a previous-stage trader (S41: Yes), it acquires information related to the carbon emissions up to the previous process (S42). Specifically, the information acquisition unit 62 acquires the information on the carbon emissions encrypted by the previous-stage trader who provides the delivery item using the public key pk (hereinafter, the encrypted emissions of other companies). In addition, the information acquisition unit 62 also acquires information such as the above-mentioned UID or hash value that identifies the delivery item. The information acquisition unit 62 stores the acquired information on the encrypted emissions of other companies in a variable (S43). The information acquisition unit 62 determines the presence or absence of other previous-stage traders (S44). When there are other previous-stage traders (S44: Yes), it repeats the acquisition and storage of the encrypted emissions of other companies and the like.

[0061] Here, the information acquisition unit 62 acquires the encrypted emissions of other companies by receiving from the information management server 100s. Specifically, the information acquisition unit 62 acquires the encrypted emissions of other companies associated with the delivery item from the information management server 100s (the information delivery unit 33 described later) by implementing a provision request to the information management server 100s using the UID or hash value of the delivery item. When multiple delivery items are used for the company's shipping items, the information acquisition unit 62 acquires multiple encrypted emissions of other companies from the information management server 100s. In addition, the information acquisition unit 62 may also directly acquire the encrypted emissions of other companies from the trader terminal 50 associated with the previous-stage trader.

[0062] If the information acquisition unit 62 acquires the encrypted emissions of other companies of all the previous-stage traders (S44: No), it acquires information such as the information indicating the carbon emissions in the company's process (hereinafter, this process) (S45). The information acquisition unit 62 determines whether it can acquire all of the encrypted emissions of other companies, the carbon emissions of this process, and other required input items (S46). When it cannot acquire the required information (S46: No), it implements corresponding exception handling (S53). On the other hand, when it can acquire all of the required information (S46: Yes), the information acquisition unit 62 determines whether the carbon emissions of this process are equal to or greater than a preset specified value (S47). The specified value is determined by the information management server 100s (the administrator ADM), for example. When the carbon emissions of this process are less than the specified value (S47: No), it implements corresponding exception handling (S53).

[0063] As described above, the information acquisition unit 62 verifies whether the calculation of the carbon release amount in this process part is omitted (S46), and whether the carbon release amount in this process part is underestimated (S47). Through the above, when the secret calculation of the total carbon release amount in this process is processed, the information acquisition unit 62 detects the occurrence of such illegal processing.

[0064] When the carbon release amount in this process is equal to or greater than the specified value (S47: Yes), the information operation unit 63 determines the presence or absence of the public key pk for encryption (refer to Figure 4 S21) (S48). When there is no public key pk for encryption (S48: No), corresponding exception handling is performed (S53). On the other hand, when there is a public key pk for encryption (S48: Yes), the information operation unit 63 encrypts the carbon release amount in this process using the stored public key pk, and prepares to encrypt the company's release amount (S49). And, the information operation unit 63 adds the carbon release amount up to the previous process to the carbon release amount in this process while maintaining the encrypted state through secret calculations using one or more encrypted release amounts of other companies and the encrypted release amount of this company (S50).

[0065] The information operation unit 63 calculates the cumulative carbon release amount (hereinafter, encrypted cumulative release amount) through secret calculations. At this time, corresponding to the types of processes implemented by this company such as additional processes, comprehensive processes, and branch processes, the information operation unit 63 can perform secret calculations such as multiplication and division in addition to simple addition. For example, when the encrypted release amount of other companies corresponds to the carbon release amount of one batch, the information operation unit 63 divides the encrypted release amount of other companies by the number included in one batch, and can calculate the carbon release amount of one item.

[0066] The information operation unit 63 calculates the hash value of the information management application APT (S51). The information providing unit 64 sets the encrypted cumulative release amount obtained as the result of the secret calculation as the information provided to the counterparty, and uploads it to the information management server 100s in association with the UID or hash value of the shipping item (S52). Specifically, the information providing unit 64 sends a registration request for data to the information management server 100s. The information providing unit 64 sends data such as information related to the previous process, input items input to this process, encrypted company release amount, encrypted cumulative release amount, hash value of the information management application APT, and public key pk used for encryption to the information management server 100s as the registered data.

[0067] In addition, information related to the previous process includes, for example, the UID or hash value read from the QR code of the delivery item. Additionally, in the case where the trader TR, who is the starting point of the supply chain SC, performs secret calculation processing, there is no previous trader. Therefore, the encrypted company release amount can be uploaded to the information management server 100s as the encrypted cumulative release amount (provided information). The encrypted cumulative release amount or the encrypted company release amount uploaded to the information management server 100s is provided to the information acquisition unit 62 as the encrypted other company release amount based on a provision request from the trader terminal 50 in the secret calculation processing or decryption aggregation processing performed by the subsequent trader.

[0068] In the decryption aggregation processing (refer to Figure 6 ), the information acquisition unit 62 acquires the encrypted other company release amount indicating the carbon release amount up to the previous process and information such as the UID or hash value identifying the delivery item (S61). The information acquisition unit 62 stores the encrypted other company release amount in a variable (S62). The information acquisition unit 62 determines the presence or absence of other previous traders (S63). If there are other previous traders (S63: Yes), the acquisition and storage of the encrypted other company release amount and the like are repeated.

[0069] If the encrypted other company release amounts of all the previous traders are acquired (S63: No), the information operation unit 63 decrypts the acquired encrypted other company release amount using the private key sk stored (refer to Figure 3 S12). As a result, the information operation unit 63 acquires (prepares) the plaintext carbon release amount up to the previous process (hereinafter, plaintext other company release amount) (S64). And the information acquisition unit 62 acquires information indicating the carbon release amount in this process, etc. (S65).

[0070] The information acquisition unit 62 uses the same method as the secret calculation processing (refer to Figure 5 ) to verify whether the calculation of the carbon release amount in this process part is omitted (S66) and whether the carbon release amount in this process part is underestimated (S67). Through the above, in the case where illegal processing is performed by aggregating the carbon release amount in this process through secret calculation, the information acquisition unit 62 detects the occurrence of such illegal processing.

[0071] The information acquisition unit 62 determines whether it is possible to acquire all of the encrypted emissions released by other companies, the carbon emissions of this process, and other required input items (S66). In the case where the required information cannot be acquired (S66: No), corresponding exception handling is performed (S73). On the other hand, in the case where all of the required information can be acquired (S66: Yes), the information acquisition unit 62 determines whether the cumulative carbon emissions up to the previous process after decryption and the carbon emissions of this process are equal to or greater than a preset specified value (S67). Each specified value is determined by, for example, the information management server 100s (administrator ADM). In the case where at least one of the carbon emissions is less than the specified value (S67: No), corresponding exception handling is performed (S73). In contrast, in the case where each carbon emission is equal to or greater than the specified value (S67: Yes), it is determined whether there is a public key pk for encryption (refer to Figure 4 of S21) (S68). In the case where there is no public key pk for encryption (S68: No), corresponding exception handling is performed (S73).

[0072] In the case where there is a public key pk for encryption (S68: Yes), the information calculation unit 63 adds the carbon emissions in this process and the carbon emissions up to the previous process to calculate the cumulative carbon emissions up to this process (hereinafter, plaintext cumulative emissions) (S69). The information calculation unit 63 encrypts the plaintext cumulative emissions using the stored public key pk to calculate the encrypted cumulative emissions (S70).

[0073] The information calculation unit 63 calculates the hash value of the information management application APT (S71). The information providing unit 64 includes the encrypted encrypted cumulative emissions in the information provided to the counterparty on the back side, and uploads it to the information management server 100s in association with the UID or hash value of the shipped item (S72). In the decryption aggregation process, the information providing unit 64 also sends a registration request for the data to the information management server 100s. Moreover, information related to the previous process, input items input to this process, encrypted cumulative emissions, the hash value of the information management application APT, the public key pk used for encryption, etc. are sent to the information management server 100s. The information providing unit 64 may also generate encrypted emissions released by this company after encrypting the carbon emissions in this process, and further send the generated encrypted emissions released by this company to the information management server 100s.

[0074] The above secret calculation process and decryption aggregation process are implemented by each trader terminal 50, so as to aggregate the carbon emissions in each trader TR. As a result, the carbon footprint associated with the final product supplied by the supply chain SC can be obtained by the trader TR of the final product and the supervisory authority SA.

[0075] As a specific example, in companies A to F (refer to Figure 1)In the supply chain SC thus constituted, the carbon emissions obtained by Company A are encrypted with the public key pkc and provided to Company B. Next, the carbon emissions obtained by Company B are encrypted with the public key pkc, and after being added to the encrypted carbon emissions obtained from Company A (encrypted emissions of other companies), they are provided to Company C.

[0076] And, the carbon emissions obtained by Company C are added to the carbon emissions up to Company B (plaintext emissions of other companies) decrypted using the private key skc. The total carbon emissions are encrypted with the public key pkd and provided to Company D. Next, the carbon emissions obtained by Company D are added to the carbon emissions up to Company C decrypted using the private key skd. The total carbon emissions are encrypted with the public key pkf and provided to Company E.

[0077] Then, the carbon emissions of Company E are encrypted with the public key pkf and added to the encrypted carbon emissions obtained from Company D, and then provided to Company F. Next, the carbon emissions of Company F are added to the carbon emissions up to Company E decrypted using the private key skf. As a result, the carbon footprint of the final product provided by Company F can be obtained.

[0078] <Manager ADM and Information Management Server 100s, etc.>

[0079] The information management server 100s and the application distribution server 100a are server devices operated by the manager ADM of the supply chain SC. The manager ADM is, for example, an agent entrusted with the management business by the provider (finished product manufacturer) of the final product supplied by the supply chain SC. The manager ADM can also be an agency entrusted with the management and audit business by the supervisory authority SA that has the supervisory authority over the type to which the final product belongs. The information management server 100s and the application distribution server 100a can be a local structure physically managed by the manager ADM or a system provider, etc., or can be a virtual server structure set up on the cloud.

[0080] The information management server 100s is an information processing device mainly composed of a processing circuit 100c. The processing circuit 100c includes a processor 11, a RAM 12, a storage unit 13, an input / output interface, and a bus connecting them, and functions as a computer for performing arithmetic processing. The processor 11 is hardware for arithmetic processing combined with the RAM 12 and executes the program stored in the storage unit 13.

[0081] The information management server 100s is an information management device on the administrator ADM side that manages transaction records and project-related information. An application program (information management application APS) for causing the processing circuit 100c to implement the information management method of the present disclosure is stored in the storage unit 13. The information management server 100s has functional units such as an information reception unit 31, an information storage unit 32, an information delivery unit 33, and an information disclosure unit 34 by executing the information management application APS based on the processor 11. The information management server 100s continuously and repeatedly implements the management server processing described later (refer to Figure 7 and Figure 8 ).

[0082] The information reception unit 31 receives a registration request for data sent from the trader terminal 50 and a viewing request for data sent from the information viewing server 110. When the information reception unit 31 receives a registration request for data, it acquires the transaction record and project-related information sent from the trader terminal 50 by reception.

[0083] Based on the data registration request, the information storage unit 32 stores the transaction record and project-related information acquired by the information reception unit 31 in association with the UID or hash value in the administrator database DB1. The administrator database DB1 stores the custody target data such as the transaction record and project-related information in a state where it cannot be substantially tampered with using the technology of the blockchain BC. The administrator database DB1 stores the acquired custody target data as a transaction in the block of the private blockchain BC. The administrator database DB1 hashes the information stored in one block and stores it in the next block, making it difficult to tamper with the custody target data stored in each block. The administrator database DB1 stores the hash value generated from the custody target data in the block of the consortium or public blockchain BC, so that the custody target data cannot be substantially tampered with either.

[0084] The information delivery unit 33 delivers the UID or hash value for identifying the project to each trader TR. The information delivery unit 33 provides the encrypted cumulative release amount up to the previous process to the information acquisition unit 62 of the trader terminal 50 that performs the secret calculation process (refer to Figure 5 ) or the decryption aggregation process (refer to Figure 6 ). The information delivery unit 33 sends a return value indicating the success or failure of the process based on the data registration request to the trader terminal 50. The information delivery unit 33 sends a return value indicating the success or failure of the process based on the data viewing request to the information viewing server 110.

[0085] Based on a data viewing request, the Information Disclosure Department 34 extracts information associated with the UID or hash value set as the viewing target from among a plurality of pieces of information stored in the Administrator Database DB1. The Information Disclosure Department 34 generates provision data based on the information extracted from the Administrator Database DB1 and provides the generated provision data to the Information Viewing Server 110 that is the request source.

[0086] The Application Distribution Server 100a functions as a server device that distributes applications related to traceability management (hereinafter, traceability applications). The Application Distribution Server 100a distributes the Information Management Applications APS, APT, and the Information Viewing Application APR as traceability applications. The Application Distribution Server 100a may also distribute the above-described key generation function KeyGen. The Information Management Application APS is a traceability application for the Administrator ADM. The Information Management Application APS is distributed to the Information Management Server 100s and installed on the Information Management Server 100s. The Information Management Application APT is a traceability application for the Trader TR. The Information Management Application APT is distributed to the Trader Terminal 50 and installed on the processing circuit 50c. The Information Viewing Application APR is a traceability application for the Supervisory Authority SA. The Information Viewing Application APR is distributed to the Information Viewing Server 110 and installed on the processing circuit 100c of the Information Viewing Server 110. Each of the applications APS, APT, APR, and the key generation function KeyGen is updated regularly so as to maintain security in traceability management.

[0087] In addition, the Application Distribution Server 100a may also have a structure operated by the platform provider of the operating system that operates the Trader Terminal 50 or each of the servers 100s, 110. In such a form, the latest application program is provided from the Administrator ADM to the platform provider and distributed from the server device operated by the platform provider to the Trader Terminal 50 or each of the servers 100s, 110.

[0088] <Supervisory Authority SA and Information Viewing Server 110>

[0089] The Information Viewing Server 110 is a server device operated by the Supervisory Authority SA. The Information Viewing Server 110 may have a local structure physically managed by the Supervisory Authority SA or a virtual server structure provided on the cloud. The Information Viewing Server 110 is an information processing device centered on the processing circuit 100c. An application program (Information Viewing Application APR) for causing the processing circuit 100c to execute the information management method of the present disclosure is stored in the storage unit 13. A display, an input device, etc. are connected to the input / output interface of the processing circuit 100c. The Information Viewing Server 110 continuously and repeatedly performs the audit server processing described later (seeFigure 9 )。

[0090] The information viewing server 110 holds the main private key skM ( Figure 1 private key M). The main private key skM is a decryption key different from the private key sk held by the trader TR. The main private key skM is upward compatible with the private key Fskf held by the trader TR (refer to Figure 1 company F) that supplies the final product, and can decrypt at least the data encrypted by the public key Fpkf. The main private key skM can also further decrypt the data encrypted by the public key Cpkc or the public key Dpkd. The information viewing server 110 can also hold other main private keys skM that can decrypt the data encrypted by the public key Cpkc or the public key Dpkd.

[0091] [Management Server Processing and Audit Server Processing]

[0092] Next, the management server processing (refer to Figure 7 and Figure 8 ) implemented by the information management server 100s, and the audit server processing (refer to Figure 9 ) implemented by the information viewing server 110 will be described in detail.

[0093] In the management server processing (refer to Figure 7 ), the information receiving unit 31 receives requests from the trader terminal 50 and the information viewing server 110. The information receiving unit 31 determines the content of the received request (S81). When a data registration request is received from the trader terminal 50 (S81: Yes), the information receiving unit 31 obtains the transaction record and item-related information sent from the trader terminal 50 by receiving (S82). Specifically, the information receiving unit 31 obtains information related to the previous process (delivery item), and the UID or hash value associated with the shipped item, etc. as the transaction record (refer to Figure 5 S52 of Figure 6 and S72 of

[0094] In the case of illegal processing through secure computing, the information receiving unit 31 detects the occurrence of such illegal processing. The information receiving unit 31 determines the authenticity of the encrypted carbon emissions without decrypting. The information receiving unit 31 determines whether it is possible to obtain each piece of information on the encrypted company emissions and the encrypted cumulative emissions (S83). When the required information can be obtained (S83: Yes), the information receiving unit 31 further determines whether the hash value of the information management application APT is the same as the hash value of the valid application that has been released (S84). That is, based on the comparison of the hash values, the information receiving unit 31 determines whether the correct information management application APT is running on the trader terminal 50.

[0095] When the obtained hash value is the same as the regular value (S84: Yes), the information receiving unit 31 compares the encrypted cumulative emissions obtained from the trader terminal 50 in the previous process with the encrypted cumulative emissions obtained from the trader terminal 50 in the current process (S85). When the two encrypted cumulative emissions are the same (S85: No), the information receiving unit 31 infers that the addition of carbon emissions in the current process has been omitted. On the other hand, when the two encrypted cumulative emissions are different (S85: Yes), the information storage unit 32 infers that the accumulation has been correctly performed, and stores the obtained transaction record and item-related information in association with the UID or the hash value in the manager database DB1 (S86). In this case, the information delivery unit 33 sends the return value indicating normal processing to the trader terminal 50 (S87). In contrast, when there is insufficient information (S83: No), when the hash value is not the same as the regular value (S84: No), and when the encrypted cumulative emissions have not changed (S85: No), the information delivery unit 33 sends the return value indicating abnormal processing to the trader terminal 50 (S88).

[0096] In the management server processing (refer to Figure 8 ), when the information receiving unit 31 receives a data viewing request from the information viewing server 110 (S81: No), the information disclosure unit 34 generates data for providing. Specifically, the information disclosure unit 34 retrieves the object ID obtained from the information viewing server 110 together with the data viewing request from the information stored in the manager database DB1 (S91), and determines whether the object ID exists in the accumulated data (S92). When the object ID does not exist (S92: No), the information disclosure unit 34 sends an error value indicating the non-existence of the object ID to the information viewing server 110 that is the request source (S93).

[0097] In the case where there is an object ID (S92: Yes), the information disclosure unit 34 retrieves all data (transaction records, etc.) related to the object ID (S94). In the case where there is no data related to the object ID in the information stored in the administrator database DB1 (S95: No), the information disclosure unit 34 sends an error value indicating the non-existence of data to the information viewing server 110 of the request source (S96). On the contrary, in the case where there is data related to the object ID (S95: Yes), the information disclosure unit 34 sends the provided data generated from the retrieved data to the information viewing server 110 of the request source (S97). The information disclosure unit 34 provides the provided data including at least the encrypted cumulative release amount and the public key pk used for encrypting the encrypted cumulative release amount to the information viewing server 110.

[0098] In the audit server process (refer to Figure 9 ), the information viewing server 110 acquires the identification information (UID or hash value) of the final product or specific finished product for which the carbon footprint is to be viewed as the above object ID (S101). The object ID can also be read from a two-dimensional code using a camera or a barcode reader, or can be read from pre-prepared data. The information viewing server 110 sends a data viewing request together with the read object ID to the information management server 100s to perform a carbon footprint query (S102).

[0099] The information viewing server 110 determines whether there is data associated with the object ID (S103). In the case of receiving a value indicating the occurrence of an error (refer to Figure 8 in S93 or S96), the information viewing server 110 determines that there is no data associated with the object ID (S103: No) and performs an error display using a display or the like (S104). On the other hand, in the case of receiving the provided data (refer to Figure 8 in S97), the information viewing server 110 determines that there is data associated with the object ID (S103: Yes). In this case, the information viewing server 110 acquires the encrypted cumulative release amount provided as the provided data (S105).

[0100] The information viewing server 110 determines whether it holds a private key sk (main private key skM) that can be decrypted for the obtained encrypted cumulative release amount (S106). When it does not hold the private key sk (S106: No), the information viewing server 110 performs an error display using a display or the like (S104). On the other hand, when it holds the private key sk (S106: Yes), the information viewing server 110 decrypts the encrypted cumulative release amount using the private key sk to obtain the plaintext carbon footprint (S107). The information viewing server 110 displays the obtained carbon footprint value on a display or the like (S108).

[0101] In the above audit server processing, not only the UID of the final product but also the UID of a specific finished product manufactured in the middle of the supply chain SC can be set as the object ID. Therefore, for a specific finished product, it is possible to query the cumulative carbon release amount registered by the reporter TRs, in other words, the value of the carbon footprint of the specific finished product.

[0102] <Summary of the First Embodiment>

[0103] In the first embodiment described so far, the encrypted other company release amount after encryption by the front-side trader who provides the delivery item and the encrypted own company release amount after encrypting the carbon release amount related to the disposal of the delivery item are used for secret calculation. Moreover, the encrypted cumulative release amount as the result of the secret calculation is calculated, and this encrypted cumulative release amount is set as the information provided to the back-side trader of the supply shipment item.

[0104] Based on the above, even if the back-side trader holds the private key sk, the encrypted other company release amount and the encrypted own company release amount encrypted by the front-side trader are not provided to the back-side trader. Therefore, the project-related information of the front-side trader and the carbon release amount of the current trader's current process are not disclosed to the back-side trader. In addition, as the transaction progresses, the encrypted own company release amount of each trader TR is added to the encrypted cumulative release amount. Therefore, the holder of the private key sk can obtain the carbon footprint of the entire supply chain SC by decrypting the accumulated encrypted cumulative release amount. Therefore, it is possible to keep the information of each trader TR non-public and obtain the information of the entire supply chain SC.

[0105] In addition, in the first embodiment, the pair of the private key skc and the public key pkc and the pair of the private key skd and the public key pkd are prepared by different traders TR. Moreover, the reporter TRs (Company C) holding the private key skc provides the public key pkc to the front-side trader (Company B) and obtains the public key pkd from the back-side trader (Company D).

[0106] Also, in the trader terminal 50 of the reporter TRs, the plaintext other company release amount after decrypting the encrypted other company release amount using the private key skc is prepared. Moreover, the plaintext cumulative release amount obtained by calculating the plaintext other company release amount and the carbon release amount related to the disposal of the delivery item by the reporter TRs in this process is encrypted using the public key pkd and included in the information provided to the subsequent trader.

[0107] According to the above key application, the traders TR sharing a public key pk are limited to only a part of the multiple traders TR constituting the supply chain SC. Therefore, even when the private key sk is leaked from the reporter TRs, the information that can be decrypted by the leaked private key sk is limited to the information encrypted by a part of the traders TR. As a result, the security level against the leakage of the private key sk can be further improved.

[0108] In addition, in the first embodiment, in the supervisor's office SA of the supply chain SC, the information viewing server 110 holds a master private key skM different from the private key sk held by the trader TR. Moreover, the information viewing server 110 decrypts the encrypted cumulative release amount using the master private key skM. In this way, the master private key skM is held in the information viewing server 110, so that even when the reporter TRs lose the private key sk, the situation where the encrypted cumulative release amount cannot be decrypted can be avoided.

[0109] Moreover, in the first embodiment, each trader terminal 50 and the information management server 100s detect illegal processing through secret calculation. Therefore, even when information is exchanged in an encrypted state, the carbon release amount discharged in the process of each trader TR can be correctly added to the encrypted cumulative release amount. As a result, even if the information of each trader TR is set to be non - public, the accuracy of the information of the entire supply chain SC can be guaranteed.

[0110] In addition, in the first embodiment, in the step of sharing the public key pk, the public key pk obtained from the subsequent trader is provided to at least one previous trader. In this way, if the public key pk is transferred in a form that traces the supply chain SC to the upstream side, the public key pk can be shared in a state where the trading relationship is non - public even between trader TRs without direct transactions.

[0111] In addition, in the first embodiment, the carbon emissions associated with the delivery items are encrypted using the public key pk in the previous process, and the encrypted emissions of other companies are obtained. In addition, the carbon emissions associated with the processing of the delivery items in this process are encrypted using the public key pk and set as the encrypted emissions of this company. Then, through secure computation, an encrypted cumulative emission is generated by summing up the carbon emissions in the encrypted state. As described above, the cumulative carbon emissions in the supply chain SC are calculated using secure computation, so that the carbon footprint of the final product can be grasped without forcing each trader TR to publicly disclose information. As a result, the entry barrier for the system for disclosing the carbon footprint can be reduced.

[0112] Moreover, in the first embodiment, a private key sk and a public key pk based on fully homomorphic encryption are prepared. Therefore, in secure computation, addition, subtraction, multiplication, and division in the encrypted state can be performed. As a result, secure computations corresponding to various processes performed by each trader TR can be implemented. Based on the above, even if the connection forms between the traders TR are complex, secure computation results with ensured accuracy can be calculated.

[0113] In addition, in the above first embodiment, the key management unit 61 corresponds to the "key generation unit", the information operation unit 63 corresponds to the "information generation unit", the processing circuits 50c and 100c correspond to the "computer", and the supply chain management system corresponds to the "information management system". In addition, the supervisory authority SA corresponds to the "supervisor", the reporters TRs correspond to the "key holders", the private key Cskc corresponds to the "first private key", the public key Cpkc corresponds to the "first public key", the private key Dskd corresponds to the "second private key", and the public key Dpkd corresponds to the "second public key". Also, the encrypted emissions of other companies correspond to the "obtained encrypted information", the plaintext emissions of other companies correspond to the "obtained plaintext information", the encrypted emissions of this company correspond to the "generated encrypted information". Moreover, the encrypted cumulative emissions correspond to the "secure computation result" and the "encrypted computation result", the plaintext cumulative emissions correspond to the "plaintext computation result", and the carbon emissions correspond to the "emission information".

[0114] (Second Embodiment)

[0115] Figure 10 and Figure 11 The second embodiment of the present disclosure shown is a modification of the first embodiment. In the second embodiment, the generation of the private key sk and the public key pk by the key management unit 61 of the trader terminal 50 is not performed. On the other hand, a key generation unit 236 is provided in the information viewing server 110 as a functional unit based on the information viewing application APR.

[0116] The key generation unit 236 performs key sharing processing in place of the key management unit 61 (see Figure 3 ), and generates a private key sk and a public key pk based on fully homomorphic encryption ( Figure 10 private key Z, public key Z) (S11). The key generation unit 236 stores the generated private key sk (S12). Further, the key generation unit 236 identifies the trader TR (see Figure 10 company F) that supplies the final product in the supply chain SC, and determines the destination for providing the prepared public key pk (S13), and provides the public key pk to the trader terminal 50 of the trader TR (S14). Each trader terminal 50 sequentially transfers the public key pk to the upstream trader TR in the form of tracing the supply chain SC by implementing the key sharing processing (see Figure 4 ). Through the cooperation of the key generation unit 236 and each key management unit 61 in this way, the public key pk designated by the supervisory authority SA is shared among the respective traders TR (see Figure 10 companies A to F).

[0117] Each trader terminal 50 combines the encrypted other company emissions released by the previous trader with the encrypted own company emissions equivalent to the carbon emissions in this process by implementing the secure computation processing (see Figure 5 ). Based on the above, the trader TR that provides the final product calculates the encrypted cumulative emissions including the information on the carbon footprint of the final product through secure computation. The encrypted cumulative emissions calculated by each trader terminal 50 are also registered in the manager database DB1 of the information management server 100s in the second embodiment.

[0118] As a specific example, in the supply chain SC composed of companies A to F, the carbon emissions obtained by company A are encrypted with the public key pk and provided to company B. Next, the carbon emissions obtained by company B are encrypted with the public key pk, added to the encrypted carbon emissions (encrypted other company emissions) obtained from company A, and then provided to company C. Further, the carbon emissions obtained by company C are also encrypted with the public key pk, added to the encrypted other company emissions (encrypted cumulative emissions) obtained from company B, and then provided to company D. Similarly, in companies D to F, the carbon emissions are encrypted with the public key pk and added to the encrypted cumulative emissions. As a result, the carbon footprint of the final product provided by company F can be obtained.

[0119] The information viewing server 110 performs the audit server processing (see Figure 9)In the implementation of this, the encrypted cumulative release amount associated with the final product or a specific finished product is obtained from the information management server 100s (S105). The information viewing server 110 decrypts the obtained encrypted cumulative release amount using the private key sk held by the private key generation unit 236 to obtain the carbon footprint (S107).

[0120] In the second embodiment described so far, the same effect as that of the first embodiment is also achieved. Since the encrypted company release amount is not provided to the subsequent traders, the carbon release amount of this process is not disclosed to the subsequent traders. On the other hand, the encrypted company release amount of each trader TR is added to the encrypted cumulative release amount through secret calculation. Therefore, the supervisory authority SA, who is the holder of the private key sk, can obtain the carbon footprint through the decryption of the encrypted cumulative release amount. Therefore, it is possible to keep the information of each trader TR confidential and obtain the information of the entire supply chain SC.

[0121] In addition, in the second embodiment, the information viewing server 110 of the supervisory authority SA prepares the private key sk and the public key pk, and the public key pk is shared among the traders TR. Moreover, the information viewing server 110 obtains the encrypted cumulative release amount associated with the final product or a specific finished product, and obtains the carbon footprint through the decryption of the encrypted cumulative release amount using the private key sk. As described above, according to the operation in which the information viewing server 110 manages the private key sk, the risk of leakage of the private key sk can be reduced. As a result, a supply chain management system with a high security level can be realized.

[0122] In addition, in the above second embodiment, the final product and the specific finished product correspond to the "supply item", and the carbon footprint corresponds to the "decryption calculation result".

[0123] (Other Embodiments)

[0124] As described above, multiple embodiments of the present disclosure have been described, but the present disclosure is not limited to the above embodiments and can be applied to various embodiments and combinations without departing from the gist of the present disclosure.

[0125] In Modification Example 1 of the above embodiment, instead of the carbon release amount of each process, the usage amount information of the electricity or energy used in relation to the processing of the item in each process is collected as the item-related information. Specifically, the usage amount information indicating the usage amount of electricity and energy is information for calculating the carbon release amount. In the electricity usage amount information, for example, information on the types of power generation methods such as hydraulic power, thermal power, wind power, geothermal energy, atomic energy, and sunlight is associated. Similarly, in the energy usage amount information, for example, information on the types of fuels such as crude oil, coal, natural gas, and hydrogen is associated.

[0126] By the secret calculation process of Modification Example 1 (refer toFigure 5 ) The obtained encrypted information is the information obtained by encrypting the usage amount information of each type of electricity or energy associated with the delivery project using the public key pk (S42). Moreover, the usage amount information associated with the processing performed in this step is encrypted using the public key pk for each type of electricity or energy (S49). And, a secret calculation result obtained by secretly calculating and summing the usage amount information of each type in an encrypted state is generated (S50). This secret calculation result is generated for each type of electricity or energy and becomes encrypted information of values obtained by separately and independently accumulating each usage amount information. The secret calculation result of each type is uploaded to the information management server 100s as information provided to the next step (S52).

[0127] In Modification Examples 2 and 3 of the above-described embodiment, the information management method of the present disclosure is applied to the accumulation of information related to items different from the carbon emission amount. Specifically, in Modification Example 2, the usage amount of rare metals is accumulated for each type of rare metal. As a result, a secret calculation result that can decrypt information indicating the total amount of rare metals used in the supply item can be obtained for each type of rare metal. In addition, in Modification Example 3, the generation amount of specific harmful substances that are set as restricted objects is accumulated for each type of harmful substance. As a result, a secret calculation result that can decrypt information indicating the total amount of harmful substances generated through the manufacturing or circulation of the supply item can be obtained for each type of harmful substance.

[0128] As in Modification Examples 1 to 3 above, the information management method of the present disclosure is particularly suitable for the accumulation of information that is legally obligated to be recorded. In addition, the information related to the item to be recorded is not limited to the above-described carbon emission amount and the like, and can be appropriately changed.

[0129] In Modification Example 4 of the above-described first embodiment, the information viewing server 110 does not hold the master private key skM. The information viewing server 110 receives the provision of the private key sk from each reporter TRs. Even with such key usage, the information viewing server 110 can obtain the information of the entire supply chain SC. In addition, it is preferable that the private key sk is not relayed to the information management server 100s and is directly provided to the information viewing server 110.

[0130] In the above-described embodiment, in each of the trader terminals 50 and the information management server 100s, detection of illegal processing in the secure computation is performed. However, the detection of illegal processing may be implemented only in a part of the configuration. For example, in Modification 5, detection of illegal processing based on each trader terminal 50 is implemented, while detection of illegal processing based on the information management server 100s is omitted. Further, in Modification 6, detection of illegal processing in the information management server 100s is implemented, while detection of illegal processing in each trader terminal 50 is omitted.

[0131] Moreover, in Modification 7, detection of illegal processing is implemented only in a part of the trader terminals 50. Specifically, in the trader terminal 50 of the reporter TRs, detection of illegal processing is implemented, while in the trader terminal 50 of the non-reporter TRn, detection of illegal processing is not implemented. Further, in Modification 8, it is confirmed whether illegal processing has been performed not on the secure computation of this process but on the secure computation of the previous process.

[0132] In the above-described embodiment, the manager ADM and the supervisory authority SA exist as different organizations from each other. On the other hand, in Modification 9 of the above-described embodiment, the supervisory authority SA also serves as the manager ADM. In such a Modification 9, the function of the integrated processing circuit 100c may also be provided in the information browsing server 110.

[0133] In the above-described embodiment, server devices are used as the information management server 100s and the information browsing server 110. However, similar to the trader terminal 50, a smartphone, a tablet terminal, a personal computer, or the like may also be used as the information management server 100s or the information browsing server 110.

[0134] In Modification 10 of the above-described embodiment, the technology of RFID (radio frequency identifier) is used to implement the attachment of the UID or the hash value to the item. In such a Modification 10, in the data recording medium, an RFID tag is used instead of the paper medium printed with the two-dimensional code. By using such RFID technology, for example, even when the RFID tag is not directly visually recognizable, remote reading of the UID or the like can be performed. Further, in Modification 10, instead of the code reader or the camera, a reader or the like that can read the RFID tag is connected to the trader terminal 50 by wire or wirelessly.

[0135] In the above-described embodiments, each function provided by the information management server 100s and the information viewing server 110 can also be provided by software and the hardware that executes the software, software only, hardware only, or a combined combination thereof. Similarly, each function provided by the trader terminal 50 can also be provided by software and the hardware that executes the software, software only, hardware only, or a combined combination thereof. In the case where such a function is provided by an electronic circuit as hardware, each function can also be provided by a digital circuit including a plurality of logic circuits or an analog circuit. In addition, at least a part of the software for implementing such a function may include code automatically generated by a neural network or a language model trained using learning data.

[0136] Each of the processors 11 and 51 in the above-described embodiments may have a structure including at least one arithmetic core such as a CPU (Central Processing Unit) and a GPU (Graphics Processing Unit). And the processor may be a structure further including an FPGA (Field-Programmable Gate Array) and an IP core having other dedicated functions.

[0137] The manner of the storage medium that is adopted as each storage unit in the above-described embodiments and stores each program related to the implementation of the information management method of the present disclosure can be appropriately changed. For example, the storage medium is not limited to a structure provided on a circuit board, and may be provided in the form of a memory card or the like, inserted into a socket portion, and electrically connected to the bus of a computer. And the storage medium may also be an optical disc, a hard disk drive, a solid state drive, etc. used as a replication source or a distribution source of a program to a computer.

[0138] The control unit and the method described in the present disclosure can also be implemented by a dedicated computer, and the dedicated computer constitutes a processor programmed to execute one or more functions embodied by a computer program. Or, the device and the method described in the present disclosure can also be implemented by dedicated hardware logic circuits. Or, the device and the method described in the present disclosure can also be implemented by one or more dedicated computers, and the one or more dedicated computers are constituted by a combination of a processor that executes a computer program and one or more hardware logic circuits. In addition, the computer program can also be stored as an instruction executed by a computer in a computer-readable non-transitory tangible recording medium.

[0139] (Disclosure of Technical Idea)

[0140] This specification discloses multiple technical ideas described in the following listed items. Sometimes, several items are described in a multiple dependent form that selectively references preceding items in subsequent items. And sometimes, several items are described in a multiple dependent form that references items in other multiple dependent forms. The items described by these multiple dependent forms define multiple technical ideas.

[0141] (Technical idea 1) An information management method implemented by a computer (50c, 100c) that manages information associated with each of multiple traders (TR) that make up a supply chain (SC).

[0142] The processing executed by at least one processor (11, 51) includes the following steps:

[0143] Prepare a private key (sk) and a public key (pk) based on homomorphic encryption and share the public key with the multiple traders (S10, S20);

[0144] Obtain acquisition encrypted information encrypted by the previous trader using the public key, and supply it to the trader in the previous process of the delivery item. The acquisition encrypted information is the trader in the previous process of the delivery item.

[0145] Prepare generated encrypted information obtained by encrypting item-related information related to the disposition of the delivery item using the public key; and

[0146] Use the obtained encrypted information and the generated encrypted information in a secret calculation, and use the secret calculation result obtained by the secret calculation as provided information to the subsequent trader. The subsequent trader is the trader in the next process of the provided shipping item.

[0147] (Technical idea 2) The information management method according to Technical idea 1, wherein

[0148] In the step of sharing the public key, the following steps are further included:

[0149] As the private key and the public key, different traders prepare a first private key (skc) and a first public key (pkc) and a second private key (skd) and a second public key (pkd).

[0150] As a key holder (TRs) of the above trader holding the above first private key, provide the above first public key to the above front-side trader, and obtain the above second public key from the above back-side trader (S14, S21).

[0151] Prepare the obtained plaintext information (S64) that the above key holder is to use the above first private key to decrypt the above obtained encrypted information.

[0152] Encrypt the plaintext calculation result using the above second public key, where the plaintext calculation result is obtained by calculation using the above obtained plaintext information and the above item-related information related to the disposal of the above delivery item by the above key holder (S70).

[0153] Include the encrypted calculation result after encryption in the above provided information (S72).

[0154] (Technical idea 3) According to the information management method described in Technical idea 2, wherein

[0155] It further includes the step of decrypting the above secret calculation result by a supervisor (SA) who supervises the above supply chain using a master private key (skM) different from the above private key held by the above trader (S107).

[0156] (Technical idea 4) According to the information management method described in Technical idea 1, wherein

[0157] It further includes the following steps:

[0158] In the step of sharing the above public key, a supervisor (SA) who supervises the above supply chain prepares the above private key and the above public key;

[0159] The above supervisor obtains the above secret calculation result associated with the supply item supplied by the above supply chain (S105); and

[0160] Obtain the decryption calculation result obtained by decrypting the above secret calculation result using the above private key (S107).

[0161] (Technical idea 5) According to the information management method described in any one of Technical ideas 1 to 4, wherein

[0162] It further includes the step of detecting illegal processing in the above secret calculation (S46, S47, S66, S67, S83 - S85).

[0163] (Technical idea 6) According to the information management method described in any one of Technical ideas 1 to 5, wherein

[0164] In the step of sharing the above public key, the above public key obtained from the above backside trader is provided to at least one of the above frontside traders (S24).

[0165] (Technical Idea 7) According to the information management method described in any one of Technical Ideas 1 to 6, wherein

[0166] In the step of obtaining the above acquisition encrypted information, the above acquisition encrypted information obtained by encrypting the emission amount information of greenhouse gases associated with the above delivery item using the above public key is obtained.

[0167] In the step of preparing the above generation encrypted information, the above emission amount information associated with the disposal of the above delivery item is encrypted using the above public key.

[0168] In the step of obtaining the above secret calculation result, the above secret calculation result obtained by summing up the above emission amount information in an encrypted state through the above secret calculation is used as the above provided information.

[0169] (Technical Idea 8) According to the information management method described in any one of Technical Ideas 1 to 6, wherein

[0170] In the step of obtaining the above acquisition encrypted information, the above acquisition encrypted information obtained by encrypting the usage amount information of each type of electricity or energy associated with the above delivery item using the above public key is obtained.

[0171] In the step of preparing the above generation encrypted information, the above usage amount information associated with the disposal of the above delivery item is encrypted for each of the above types using the above public key.

[0172] In the step of obtaining the above secret calculation result, the above secret calculation result obtained by summing up the above usage amount information of each type in an encrypted state through the above secret calculation is used as the above provided information.

[0173] (Technical Idea 9) According to the information management method described in any one of Technical Ideas 1 to 8, wherein

[0174] In the step of sharing the above public key, the above private key and the above public key based on fully homomorphic encryption are prepared (S11).

Claims

1. An information management method implemented by a computer (50c, 100c) that manages information associated with each of a plurality of traders (TR) constituting a supply chain (SC). The processing executed by at least one processor (11, 51) includes the following steps: Prepare a private key (sk) and a public key (pk) based on homomorphic encryption and share the public key among the plurality of traders (S10, S20). Obtain acquired encrypted information encrypted by a front-side trader using the public key. The front-side trader is the trader in the previous process of the supply delivery item. Prepare generated encrypted information (S49). The generated encrypted information is information obtained by encrypting item-related information related to the disposition of the delivery item using the public key. Use the secret calculation result obtained through secret calculation as the provided information to a rear-side trader (S52). The secret calculation uses the acquired encrypted information and the generated encrypted information. The rear-side trader is the trader in the next process of the provided shipping item.

2. The information management method according to claim 1, wherein: In the step of sharing the public key, the following steps are further included: As the private key and the public key, a first private key (skc) and a first public key (pkc) and a second private key (skd) and a second public key (pkd) are prepared by different traders. As the key holder (TRs) of the trader holding the first private key, provide the first public key to the front-side trader and obtain the second public key from the rear-side trader (S14, S21). The key holder prepares acquired plaintext information (S64). The acquired plaintext information is obtained by decrypting the acquired encrypted information using the first private key. Encrypt the plaintext calculation result using the second public key (S70). The plaintext calculation result is obtained through a calculation using the acquired plaintext information and the item-related information related to the disposition of the delivery item by the key holder. And Include the encrypted encrypted calculation result in the provided information (S72).

3. The information management method according to claim 2, wherein: It further includes a step of decrypting the secret calculation result using a master private key (skM) different from the private key held by the trader by a supervisor (SA) who supervises the supply chain (S107).

4. The information management method according to claim 1, wherein: The following steps are further included: In the step of sharing the public key, the supervisor (SA) who supervises the supply chain prepares the private key and the public key. The supervisor obtains the secret calculation result associated with the supply item supplied by the supply chain (S105). And Obtain the decrypted calculation result obtained by decrypting the secret calculation result using the private key (S107).

5. The information management method according to any one of claims 1 to 4, wherein: It also includes steps of detecting illegal processing (S46, S47, S66, S67, S83 - S85) in the said secret calculation.

6. The information management method according to any one of claims 1 - 4, wherein, in the step of sharing the public key, the public key obtained from the said back - side trader is provided to at least one of the said front - side traders (S24).

7. The information management method according to any one of claims 1 - 4, wherein, in the step of obtaining the said acquired encrypted information, the said acquired encrypted information obtained by encrypting the emission amount information of greenhouse gases associated with the delivery item using the public key is acquired, in the step of preparing the said generated encrypted information, the emission amount information associated with the disposal of the delivery item is encrypted using the public key, in the step of obtaining the said secret calculation result, the said secret calculation result obtained by summing up the emission amount information in an encrypted state through the said secret calculation is used as the said provided information.

8. The information management method according to any one of claims 1 - 4, wherein, in the step of obtaining the said acquired encrypted information, the said acquired encrypted information obtained by encrypting the usage amount information of each type of electricity or energy associated with the delivery item using the public key is acquired, in the step of preparing the said generated encrypted information, the usage amount information associated with the disposal of the delivery item is encrypted for each type using the public key, in the step of obtaining the said secret calculation result, the said secret calculation result obtained by summing up the usage amount information of each type in an encrypted state through the said secret calculation is used as the said provided information.

9. The information management method according to any one of claims 1 - 4, wherein, in the step of sharing the public key, a private key and the public key based on fully homomorphic encryption are prepared (S11).

10. An information management system for managing information associated with each of a plurality of traders (TR) constituting a supply chain (SC), wherein, the said information management system includes: a key generation unit (61, 236) that prepares a private key (sk) and a public key (pk) based on homomorphic encryption and shares the public key among a plurality of the said traders; an information acquisition unit (62) that acquires acquired encrypted information encrypted by a front - side trader using the public key, where the front - side trader is the trader in the previous process that supplies the delivery item; an information generation unit (63) that prepares generated encrypted information, which is information obtained by encrypting item - related information associated with the disposal of the delivery item using the public key; and an information providing unit (64) that uses the acquired encrypted information and the generated encrypted information in a secret calculation and provides the secret calculation result obtained through the secret calculation as provided information to a back - side trader, where the back - side trader is the trader in the next process that provides the shipping item.

Citation Information

Patent Citations

  • Encryption system, encryption method, and encryption program

    JP2018036418A

  • Support structure for vehicle interior material

    JP2022184387A

  • Supply chain management method, supply chain management program, supply chain management system, and transaction record display program

    WO2021002226A1