Storage system and information processing system
By introducing non-volatile memory and controllers into the storage system, generating key pairs and recording utilization logs, the high cost and security issues of content sharing management in the storage system are solved, and secure and reliable content sharing and management are achieved.
Patent Information
- Application Number
- CN202510274168.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-08-20
- Filing Date
- 2025-03-10
- Publication Date
- 2026-03-03
AI Technical Summary
Existing storage systems suffer from high server costs, limited storage media capacity, and insecure content management, especially in multi-member group sharing environments where content is easily lost or leaked.
The storage system, which uses non-volatile memory and a controller, enables secure management of content and logging of usage by generating and managing key pairs. It supports peer-to-peer communication and ensures secure sharing and monitoring of content usage status.
It enables secure and reliable management of content sharing across multiple member groups, reduces server dependence and management costs, and improves content security and utilization efficiency.
Smart Images

Figure CN121597115A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to a storage system and an information processing system having non-volatile memory. Background Technology
[0002] In recent years, storage systems with non-volatile memory have become widely used. One such storage system is the solid-state drive (SSD), which incorporates NAND flash memory. SSDs are used as main storage devices in a wide variety of computing devices.
[0003] Digital content is sometimes shared among multiple members belonging to a group. Hereinafter, digital content will also be simply referred to as content.
[0004] One method for managing such content is to centrally manage it using a server. In this method, the content is stored, for example, in a storage system built into or connected to the server. Members can access the managed content by accessing the server. However, this method, for example, requires the purchase of a server, the construction of an access management system on the server, and the operation of the access management system, resulting in high implementation costs.
[0005] As an alternative management method that does not utilize a server, there is a way to manage files via Digital Versatile Disc (DVD). TM ) or SD TM This method involves using storage media like memory cards to store and share content. Such media have a smaller storage capacity compared to storage systems (e.g., SSDs). Therefore, multiple storage media are used to share content. Consequently, it's necessary to associate the shared content with the storage media containing that content and manage lending to members. As a management method, when content (i.e., the storage media containing the content) is lent out, the name of the member borrowing the content is often automatically recorded in a lending list. In lending management implemented through automatic recording, it's unclear which member is currently borrowing the content, resulting in the risk of content (storage media) being lost or leaked to third parties. Summary of the Invention
[0006] One implementation provides a storage system and an information processing system that can easily manage the use of content by members belonging to a group.
[0007] According to the implementation, the storage system is used by the first user belonging to the group. The storage system includes non-volatile memory and a controller. The controller is electrically connected to the non-volatile memory. The controller is capable of communicating with one or more other storage systems used by one or more users belonging to the group other than the first user. The controller manages a first key pair including a first private key and a first public key. The controller stores one or more pieces of content information, each including one or more pieces of content, in the non-volatile memory. When the controller requests the first user to use the first piece of content from the one or more pieces of content, it generates a first access log related to the use. The controller uses the first private key to generate first signature data for the first access log. The controller stores the first access log and the first signature data in the non-volatile memory. The controller sends the first access log and the first signature data to one or more other storage systems. Attached Figure Description
[0008] Figure 1 This is a block diagram illustrating an example configuration of an information processing system including a storage system of an embodiment.
[0009] Figure 2 This is a block diagram illustrating an example configuration of a storage system according to an embodiment.
[0010] Figure 3 This is a diagram illustrating an example of the structure of a group public key management table used in the storage system of an implementation.
[0011] Figure 4 This is a diagram illustrating an example of the structure of a content information management table used in the storage system of the embodiment.
[0012] Figure 5 This is a diagram illustrating an example of the structure of a content management table used in the storage system of an embodiment.
[0013] Figure 6 This is a diagram illustrating an example of a public key registration operation in an information processing system that includes a storage system with an implementation method.
[0014] Figure 7 This diagram illustrates an example of a public key exchange and registration operation in a storage system of an embodiment, where a public key is exchanged with another storage system.
[0015] Figure 8 This diagram illustrates an example of a public key verification and registration operation in a storage system according to an embodiment, where public key information is received from multiple other storage systems.
[0016] Figure 9 This is a diagram illustrating an example of content registration operations in an information processing system that includes a storage system according to an embodiment.
[0017] Figure 10 This diagram illustrates an example of a content registration and transmission operation in a storage system according to an embodiment, where content information is received from a host.
[0018] Figure 11 This diagram illustrates an example of a content receiving and registration operation in a storage system according to an embodiment, where content information is received from another storage system.
[0019] Figure 12 This is a diagram illustrating an example of recording an action using start information in an information processing system that includes a storage system of an embodiment.
[0020] Figure 13 This diagram illustrates an example of the control and start information recording action in a storage system according to an embodiment, when requesting content.
[0021] Figure 14 This diagram illustrates an example of a start information receiving and recording operation in a storage system according to an embodiment, where start information representing the start of utilization is received from another storage system.
[0022] Figure 15 This is a diagram illustrating an example of an information processing system that utilizes a storage system including an embodiment to perform an information recording operation.
[0023] Figure 16 This diagram illustrates an example of a completion detection and completion information recording operation in a storage system according to an embodiment, where content utilization is completed.
[0024] Figure 17 This diagram illustrates an example of a completion information receiving and recording operation in a storage system according to an embodiment, where completion information representing the completion of utilization is received from another storage system.
[0025] Figure 18 This is a flowchart illustrating an example of the steps involved in public key registration processing performed in a storage system according to an implementation.
[0026] Figure 19 This is a flowchart illustrating an example of the steps involved in public key verification and registration processing performed in the storage system of an implementation.
[0027] Figure 20 This is a flowchart illustrating an example of the steps involved in the control-start information recording process performed in the storage system of the embodiment.
[0028] Figure 21 This is a flowchart illustrating an example of the steps involved in completing information recording processing performed in the storage system of an embodiment.
[0029] Figure 22 This is a flowchart illustrating an example of the steps involved in the record verification and registration process performed in the storage system of the implementation method.
[0030] Explanation of reference numerals in the attached figures
[0031] 1…Information processing system, 2…Host (terminal), 3…Storage system, 3-1…First storage system, 3-2…Second storage system, 3-3…Third storage system, 3-n…nth storage system, 4…Non-volatile memory, 5…DRAM, 6…Controller, 7…Group, 11…Data communication I / F, 12…P2P communication I / F, 13…Near field communication I / F, 14…Memory I / F, 15…DRAM I / F, 16…CPU, 160…Key Pair Generation and Management Department, 161…Public Key Sending and Receiving Department, 162…Public Key Management Department, 163…Content Management Department, 164…Content Sending and Receiving Department, 165…Content Utilization Control Department, 166…Utilization Record Management Department, 167…Utilization Record Sending and Receiving Department, 168…Signature Department, 169…Signature Verification Department, 411…Private Key, 412…Public Key, 413…Group Public Key Management Table, 414…Content Information Management Table, 415…Content Utilization Record Management Table. Detailed Implementation
[0032] The embodiments will now be described with reference to the accompanying drawings.
[0033] First, refer to Figure 1 An example of the configuration of an information processing system 1, including a storage system with an implementation method, will be described. Information processing system 1 is a system for sharing and utilizing digital content (content) among multiple users belonging to a group 7. Information processing system 1 manages the utilization (e.g., audiovisual or reading) of the shared content. Group 7 is, for example, a small community. Users belonging to group 7 are also referred to as members or group members. Content refers to various data that are expected to be shared among members. Content includes, for example, video data produced by members, data on e-books purchased by members, or meeting minutes related to discussions among members, audio data, and video data.
[0034] Information processing system 1 includes multiple storage systems 3. These multiple storage systems 3 are, for example, storage systems used by multiple members respectively. The multiple storage systems 3 are, for example, n storage systems 3-1, 3-2, ..., and 3-n, where n is an integer greater than 2. The n storage systems 3-1, 3-2, ..., and 3-n are respectively referred to as the first storage system 3-1, the second storage system 3-2, ..., and the nth storage system 3-n. Furthermore, any one of the n storage systems 3-1, 3-2, ..., and 3-n that is not specifically designated is also referred to as storage system 3.
[0035] Information processing system 1 may also include multiple host devices 2 (hereinafter referred to as hosts 2). The multiple hosts 2 are terminals corresponding to multiple storage systems 3 respectively. The multiple hosts 2 are, for example, n hosts 2-1, 2-2, ..., and 2-n. The n hosts 2-1, 2-2, ..., and 2-n are respectively referred to as the first host 2-1, the second host 2-2, ..., and the nth host 2-n. Furthermore, any one of the n hosts 2-1, 2-2, ..., and 2-n that is not specifically designated is also referred to as host 2.
[0036] The host 2 can use the corresponding storage system 3 as a storage device. The host 2 can be connected to the corresponding storage system 3 via cable or network, or the corresponding storage system 3 can be built into the host. The host 2 has an input device for users to input information (data). The input device is, for example, a keyboard, and a pointing device such as a mouse or a touchscreen display.
[0037] Storage system 3 is a storage device configured to write data to and read data from non-volatile memory. The non-volatile memory is, for example, NAND flash memory. Storage system 3 is also called a storage device or a semiconductor storage device. Storage system 3 is implemented, for example, as a solid-state drive (SSD) or a hard disk drive (HDD) equipped with NAND flash memory. The following primarily illustrates the case where storage system 3 is an SSD.
[0038] Figure 2 This is a block diagram illustrating an example of the configuration of storage system 3.
[0039] The storage system 3 may include, for example, non-volatile memory 4 and a controller 6. The storage system 3 may also include DRAM 5.
[0040] The non-volatile memory 4 comprises multiple blocks. Each block functions as the smallest unit for data erasure operations. A block is also called an erase block or a physical block. Each block comprises multiple pages. Each page comprises multiple memory cells connected to a single word line. Each page functions as a unit for both data write and data read operations. Additionally, a single word line can also function as a unit for both data write and data read operations.
[0041] There is an upper limit to the number of program / erase cycles (P / E cycles) for each block, known as the maximum P / E cycle number. One P / E cycle for a block includes data erasure operations to put all memory cells in the block into an erased state and data programming operations to write data to the pages of the block.
[0042] The non-volatile memory 4 stores, for example, a private key 411, a public key 412, a group public key management table 413, a content information management table 414, and one or more content utilization record management tables 415.
[0043] Private key 411 and public key 412 are key pairs corresponding to members using storage system 3. Private key 411 is used for encrypting data and decrypting data encrypted using public key 412. Private key 411 cannot be read from outside storage system 3 and will not be disclosed to the outside. Public key 412 is used for encrypting data and decrypting data encrypted using private key 411.
[0044] Group public key management table 413 is used to manage data corresponding to the public keys 412 of each member belonging to a group 7. Group public key management table 413 can also be temporarily read from non-volatile memory 4 to DRAM 5 (i.e., it can also be cached in DRAM 5).
[0045] Content information management table 414 is used to manage data for one or more contents stored in non-volatile memory 4. These contents are contents that can be used by members belonging to group 7. Content information management table 414 can also be temporarily read from non-volatile memory 4 to DRAM 5.
[0046] One or more pieces of content are associated with one or more pieces of content stored in non-volatile memory 4 using a record management table 415. Each of the one or more pieces of content uses record management table 415 to manage the usage of its corresponding content. For example, a content usage record management table 415 is generated in response to a piece of content being stored in non-volatile memory 4. The content usage record management table 415 can also be temporarily read from non-volatile memory 4 to DRAM 5.
[0047] Reference Figures 3-5 The following provides an explanation of the group public key management table 413, the content information management table 414, and the content utilization record management table 415 for one or more items.
[0048] (Group Public Key Management Table 413)
[0049] Figure 3 The diagram illustrates an example of the structure of a group public key management table 413. The group public key management table 413 includes, for example, multiple entries corresponding to multiple members. Each entry includes a member name field, a public key field, a signer name field, and a signer data field.
[0050] The member name field represents the name of the corresponding member. The member name is information that uniquely identifies the member. For example, the member name field can be set to a string representing the member name.
[0051] The public key field represents the public key 412 of the corresponding member. The member's public key 412 is a public key generated and managed in the storage system 3 used by that member. For example, the public key field can be set to a public key 412 based on the Privacy-Enhanced Mail (PEM) format.
[0052] The Signature Member Name field and the Signature Data field are paired fields.
[0053] The Signer Name field indicates the name of the member who created the signing data for public key 412 set in the Public Key field. More specifically, the member who created the signing data is the member who used the storage system 3 that generated the signing data. For example, the Signer Name field can be set with a string representing the name of the member who created the signing data.
[0054] The Signature Data field represents the signature data for public key 412 set in the Public Key field. This signature data is generated in storage system 3 used by the member whose Signature Member Name field is set.
[0055] Furthermore, each entry can include multiple pairs of a signer name field and a sign data field. Specifically, each entry may include, for example, multiple pairs such as a pair of a first signer name field and a first sign data field, and a pair of a second signer name field and a second sign data field. The number of multiple pairs of signer name fields and sign data fields included in each entry can be arbitrarily set, for example, based on the number of members belonging to group 7.
[0056] exist Figure 3 In the example shown, a connection is established between member "B's" signature data "keysigB" and member "A's" public key "keyA". This means that the authenticity of member "A's" public key "keyA" is guaranteed by using member "B's" signature data "keysigB".
[0057] Through the above composition of the group public key management table 413, the storage system 3 can securely manage the public key 412 corresponding to each member.
[0058] (Content Information Management Table 414)
[0059] Figure 4 The following is an example of the structure of the content information management table 414. The content information management table 414 includes one or more entries corresponding to one or more pieces of content. Each of the one or more entries includes, for example, a content ID field, a content name field, a content body field, and a field for limiting the number of simultaneous users.
[0060] The Content ID field represents information that can uniquely identify the corresponding content (hereinafter referred to as Content ID). For example, a Universally Unique Identifier (UUID) can be used as the Content ID.
[0061] The Content Name field represents the name of the corresponding content (hereinafter referred to as the Content Name). The Content Name is, for example, a string assigned by the user who provides (e.g., creates) the content.
[0062] The Content Ontology field represents the data of the corresponding content. For example, if the content is video data, the Content Ontology field stores that video data.
[0063] The "Number of Users Limit" field indicates information related to the limitation on the number of people who can simultaneously use the corresponding content. Specifically, it indicates whether there is a limit to the number of people who can simultaneously use the content; if so, it represents that number. If there is no limit, the field is set to, for example, 0. Alternatively, if a limit exists, the field can be set to a numerical value representing that number of people.
[0064] In addition, Content Information Management Table 414 can replace the Simultaneous User Limit field or, in addition to the Simultaneous User Limit field, include a field indicating the conditions under which the corresponding content can be used (hereinafter, Use Conditions).
[0065] exist Figure 4 In the example shown, a limit of 5 people is set for the content "dataA" with content ID "AAAA" and content name "contentA".
[0066] Through the above content information management table 414, the storage system 3 is able to manage the information for members to use.
[0067] (Content Utilization Record Management Form 415)
[0068] Figure 5This example illustrates the structure of one or more content utilization record management tables 415. Each of the one or more content utilization record management tables 415 is associated with one or more pieces of content. For example, the one or more content utilization record management tables 415 include content utilization record management tables 415A, 415B, ..., 415M. Content utilization record management table 415A is associated with the content whose content ID is "AAAA". Content utilization record management table 415B is associated with the content whose content ID is "BBBB". Content utilization record management table 415M is associated with the content whose content ID is "MMMM".
[0069] Each of the more than one items in the record management table 415 includes multiple entries corresponding to multiple members. Each of these entries includes, for example, a member name field, an access log field, a usage status field, and a signature data field.
[0070] Here, we will use record management table 415A as an example to explain each field, which is associated with content with content ID "AAAA" (hereinafter, content A).
[0071] The member name field represents the name of the corresponding member.
[0072] The access log field represents log data (i.e., the access log) related to the corresponding member's use of content A. The access log includes information such as the access date and time, member name, and content ID. Specifically, for example, in member "A's" access to content A, the access date and time represent, for example, the date and time member "A" began or ended using content A. The member name represents member "A". The content ID represents content ID "AAAA". The access log may also include other information related to the use of content A.
[0073] The status field indicates the usage status of the corresponding member for content A. The usage status field can be set to either a value indicating unused or completed usage (information), or a value indicating the start of usage.
[0074] "Unused" means that the corresponding member has not yet used content A. "Used Completed" means that the corresponding member has completed (finished) using content A. In other words, "Unused" or "Used Completed" means that the corresponding member has not currently used content A. For example, "0" can be set as the value to indicate "Unused" or "Used Completed" in the usage status field. Furthermore, the usage status field can contain any information indicating "Unused" or "Used Completed," not limited to "0."
[0075] "Start of utilization" means that the corresponding member has begun utilizing content A. In other words, "start of utilization" means that the corresponding member is currently utilizing content A. For example, "1" can be set as the value indicating the start of utilization in the utilization status field. Furthermore, the utilization status field can contain any information indicating the start of utilization, not limited to "1".
[0076] Therefore, in the content usage record management table 415A, the number of people currently using content A can be obtained by counting the total number of entries with "1" set in the usage status field.
[0077] The Signature Data field represents the signature data for the access logs set in the Access Log field. The signature data is used to verify the authenticity of the access logs. Specifically, the authenticity of the access logs can be verified using the signature data and the corresponding member's public key.
[0078] exist Figure 5 In the example of content usage record management table 415A shown, member "A" is using content A (usage state "1"), managing the access log "logA" related to member "A's" use of content A and the signature data "logsigA" for the access log "logA". Additionally, member "B" is not using content A (usage state "0"), managing the access log "logB" related to member "B's" use of content A and the signature data "logsigB" for the access log "logB". Furthermore, member "C" is using content A (usage state "1"), managing the access log "logC" related to member "C's" use of content A and the signature data "logsigC" for the access log "logC". In this case, the number of people currently using content A is 2.
[0079] Through the structure of the content utilization record management table 415A described above, the storage system 3 can securely manage the utilization status of content A by each member belonging to group 7. Furthermore, each of the content utilization record management tables 415B, ..., and 415M has the same structure as the aforementioned content utilization record management table 415A. Therefore, the storage system 3 can securely manage the utilization status of each member belonging to group 7 for more than one piece of content.
[0080] return Figure 2 .
[0081] DRAM5 is volatile memory. In DRAM5, for example, there is a storage area for firmware (FW) 51.
[0082] FW51 is a program used to control the operation of controller 6. For example, FW51 loads data from non-volatile memory 4 into DRAM 5.
[0083] The controller 6 can be implemented using circuitry such as a System-on-a-Chip (SoC). The controller 6 is configured to control the non-volatile memory 4. The functions of the various parts within the controller 6 can be implemented by dedicated hardware within the controller 6, or by a processor (e.g., CPU 16) executing the FW51.
[0084] The controller 6 can function as a flash translation layer (FTL) configured to perform data management and block management of the non-volatile memory 4. The data management performed by this FTL includes: (1) management of mapping information representing the correspondence between logical addresses and physical addresses of the non-volatile memory 4; and (2) processing for hiding the differences between page-level data read / write operations and block-level data erase operations. Block management includes management of bad blocks, wear leveling, and garbage collection.
[0085] Logical addresses are used by host 2 to assign addresses to storage areas in storage system 3. A logical address is, for example, a logical block address (LBA).
[0086] The management of the mapping between logical addresses and physical addresses is performed, for example, using a logical-physical address translation table (LPTD). Controller 6 uses the LPTD to manage the mapping between logical addresses and physical addresses in specific management units. The physical address corresponding to a logical address represents the physical storage location within non-volatile memory 4 where data is written. Controller 6 uses the LPTD to manage multiple storage regions logically divided from the storage areas of non-volatile memory 4. These multiple storage regions correspond to multiple logical addresses. That is, each of these multiple storage regions is specified by one logical address. The LPTD can be loaded from non-volatile memory 4 into DRAM 5 during the startup of storage system 3.
[0087] Writing data to one page can only be done once per P / E cycle. Therefore, controller 6 writes the updated data corresponding to a certain logical address to a different physical storage location instead of the physical storage location that stores the previous data corresponding to that logical address. Furthermore, controller 6 invalidates the previous data by updating the logical physical address translation table (LPD) to associate the logical address with that different physical storage location. Data referenced from the LPD (i.e., data associated with a logical address) is called valid data. Data not associated with any logical address is called invalid data. Valid data is data that can be read from host 2 later. Invalid data is data that can no longer be read from host 2.
[0088] The controller 6 may include, for example, a data communication interface circuit (data communication I / F) 11, a peer-to-peer communication interface circuit (P2P communication I / F) 12, a near-field communication interface circuit (near-field communication I / F) 13, a memory interface circuit (memory I / F) 14, a DRAM interface circuit (DRAM I / F) 15, and a CPU 16. These data communication I / F 11, P2P communication I / F 12, near-field communication I / F 13, memory I / F 14, DRAM I / F 15, and CPU 16 can be connected via bus 10.
[0089] The data communication I / F11 functions as a circuit for data communication with an external source (e.g., host 2). Specifically, the data communication I / F11 functions as a circuit for receiving various commands and data from the external source. Commands include, for example, input / output (I / O) commands and control commands. I / O commands include, for example, read commands or write commands. Control commands include, for example, flush commands. Additionally, the data communication I / F11 functions as a circuit for responding to commands and sending data to the external source. When the data communication I / F11 functions as a circuit for communication with host 2, it is also referred to as the host interface circuit (host I / F). The interface circuit for connecting the storage system 3 to host 2 is based on PCI Express. TM (PCIe TM Ethernet TM ,Fibre channel,NVM Express TM (NVMe TM Standards such as ) are also applicable. Furthermore, when the storage system 3 is built into the host 2, the data communication I / F11 can function as a circuit that communicates with any component within the host 2.
[0090] The P2P communication I / F12 functions as a circuit for P2P communication with external devices (e.g., other storage systems 3). P2P communication, for example, is communication that directly exchanges data between two devices without going through a server. Specifically, the P2P communication I / F12 establishes a P2P connection between storage system 3 and another storage system 3 without going through a server. The P2P communication I / F12 functions as a circuit that sends data to and receives data from the other storage system 3 within the established P2P connection. The P2P communication I / F12 is based on standards such as Ethernet, Transmission Control Protocol / Internet Protocol (TCP / IP). In this case, the P2P communication I / F12 uses the IP addresses assigned to each storage system 3 for P2P communication. Furthermore, if the storage system 3 is built into the host 2, the P2P communication I / F12 can use the IP address assigned to the host 2 for P2P communication.
[0091] The Near Field Communication (NFC) I / F13 functions as a circuit for near field communication with external devices (e.g., other storage systems 3). Near field communication is the exchange of data between two devices in close proximity. That is, the two devices performing near field communication are within range (distance) capable of conducting the communication. Examples of near field communication include Bluetooth. TM Communication. In this case, the near-field communication I / F13 is based on the Bluetooth standard. Specifically, the near-field communication I / F13 establishes a Bluetooth connection between storage system 3 and another storage system 3, for example. The near-field communication I / F13 functions as a circuit configured to send data to and receive data from the other storage system 3 within the established Bluetooth connection.
[0092] Furthermore, when the storage system 3 is built into the host 2, at least one of the P2P communication I / F12 and the near-field communication I / F13 can be provided as a component of the host 2 (i.e., an external component of the storage system 3). In this case, the storage system 3 can communicate with the outside via the P2P communication I / F12 or the near-field communication I / F13 provided in the host 2.
[0093] The memory I / F14 electrically connects the controller 6 to the non-volatile memory 4. The memory I / F14 supports interface standards such as ToggleDDR and Open NAND Flash Interface (ONFI).
[0094] The memory I / F14 functions as a memory control circuit configured to control the non-volatile memory 4. The memory I / F14 can be connected to multiple non-volatile memory chips within the non-volatile memory 4 via multiple channels. By driving multiple non-volatile memory chips in parallel, wideband access to the entire non-volatile memory 4 can be achieved.
[0095] DRAM I / F15 functions as a DRAM control circuit configured to control access to DRAM5.
[0096] CPU 16 is a processor configured to control data communication I / F 11, P2P communication I / F 12, near-field communication I / F 13, memory I / F 14, and DRAM I / F 15. CPU 16 performs various processes by executing FW 51, which is loaded from non-volatile memory 4 into DRAM 5. FW 51 is a control program containing a group of commands for causing CPU 16 to perform various processes. CPU 16 can execute command processing, etc., to process various commands from host 2. The operation of CPU 16 is controlled by FW 51 executed by CPU 16.
[0097] CPU 16 functions, for example, as a key pair generation and management unit 160, a public key transceiver unit 161, a public key management unit 162, a content management unit 163, a content transceiver unit 164, a content utilization control unit 165, a utilization record management unit 166, a utilization record transceiver unit 167, a signature unit 168, and a signature verification unit 169. CPU 16 functions as these units, for example, by executing FW51.
[0098] The key pair generation and management unit 160 generates key pairs corresponding to members using the storage system 3 (hereinafter referred to as the first object member) and manages the generated key pairs. The generated key pair is a pair of private key 411 and public key 412. For example, the key pair generation and management unit 160 generates key pairs corresponding to the information of the first object member, which is input via the host 2, including the member name and the group 7 to which it belongs. The input member name is the name of the first object member. The input group 7 information is information that can uniquely identify the group 7 to which the first object member belongs. The key pair generation and management unit 160 stores the generated key pairs, for example, in non-volatile memory 4.
[0099] The public key transceiver unit 161 is configured to send information related to the public key 412 of the first object member to another storage system 3, and to receive information related to the public keys 412 of other members belonging to group 7 from the other storage system 3. Specifically, the public key transceiver unit 161 sends information related to the public key 412 of the first object member to the other storage system 3 via either near-field communication I / F 13 or P2P communication I / F 12. Additionally, the public key transceiver unit 161 receives information related to the public keys 412 of other members from the other storage system 3 via either near-field communication I / F 13 or P2P communication I / F 12.
[0100] The public key management unit 162 uses the group public key management table 413 to manage the public keys 412 of each member. Specifically, the public key management unit 162 registers (stores) information related to the public keys 412 of other members in the group public key management table 413. That is, the public key management unit 162 appends entries containing information related to the public keys 412 of other members to the group public key management table 413. Alternatively, the public key management unit 162 updates the entries in the group public key management table 413 corresponding to that other member using at least a portion of the information related to that other member's public key 412. In addition, the public key management unit 162 may register information related to the public key 412 of the first object member in the group public key management table 413.
[0101] Content management unit 163 uses content information management table 414 to manage one or more pieces of content. Specifically, content management unit 163 receives, for example, information (hereinafter referred to as content information) related to content input according to the operation of the first object member from host 2 via data communication I / F 11. Alternatively, content management unit 163 can receive content information from content transceiver unit 164. Content information includes, for example, content ID, content name, content (i.e., content body), and usage conditions. Content management unit 163 registers (saves) the received content information in content information management table 414. Furthermore, content management unit 163 sends the content information received from host 2 and registered in content information management table 414 via data communication I / F 11 to content transceiver unit 164.
[0102] The content transceiver unit 164 is configured to send content information to and receive content information from another storage system 3. Specifically, the content transceiver unit 164 sends the content information received from the content management unit 163 to the other storage system 3 via P2P communication I / F 12. As a result, the content information is registered in the content information management table 414 in that other storage system 3. Additionally, the content transceiver unit 164 sends the content information received from the other storage system 3 via P2P communication I / F 12 to the content management unit 163. The sent content information is registered in the content information management table 414 by the content management unit 163.
[0103] The content utilization control unit 165 controls the first object member's utilization of various contents. Specifically, when the content utilization control unit 165 requests the first object member's utilization of content (hereinafter referred to as object content) from the host 2, it uses the content information management table 414 to control the utilization of the object content. If the utilization conditions of the object content are met, the content utilization control unit 165 sends the object content to the host 2 via data communication I / F 11 and generates an access log related to the first object member's utilization of the object content. Thus, the first object member can utilize the object content. On the other hand, if the utilization conditions of the object content are not met, the content utilization control unit 165 notifies the host 2 of the inability to utilize the object content via data communication I / F 11. Therefore, the first object member cannot utilize the object content.
[0104] Furthermore, the content utilization control unit 165 detects the completion of the first object member's utilization of the object content. The content utilization control unit 165 determines that the content utilization is complete, for example, based on a threshold time obtained by adding a certain time to the time required for the overall reproduction of the object content since the start of the utilization. For example, if the time required for the overall reproduction of the object content is 1 hour and the certain time is 1 hour, the threshold time is 2 hours. Alternatively, the content utilization control unit 165 can determine that the utilization of the object content is complete if a threshold is exceeded (i.e., a timeout) after the start of the utilization of the object content, no request (e.g., a read command) to read at least a portion of the object content from the non-volatile memory 4 is received from the host 2.
[0105] The Record Management Department 166 uses the Record Management Form 415 to manage the start and end of the use of content by group members.
[0106] Specifically, the utilization record management unit 166 saves (registers) information indicating the start of the first object member's use of the object content (hereinafter referred to as utilization start information) to the content utilization record management table 415 in the non-volatile memory 4. The utilization start information includes, for example, an access log, a value indicating the start of utilization, and signature data for the access log. The utilization record management unit 166 cooperates with the signature unit 168 (described later) to generate signature data for the access log using the private key 411. The utilization record management unit 166 sends the utilization start information to the utilization record transceiver unit 167.
[0107] Additionally, the utilization record management unit 166 saves information indicating the completion of the first object member's use of the object content (hereinafter referred to as utilization completion information) to the utilization record management table 415 in the non-volatile memory 4. The utilization completion information includes, for example, an access log, a value indicating utilization completion, and signature data for the access log. The utilization record management unit 166 then sends the utilization completion information to the utilization record transceiver unit 167.
[0108] The usage record transceiver unit 167 is configured to send and receive usage start or completion information to and from the storage systems 3 used by other group members via P2P communication I / F12. Other group members are members of group 7 other than the first target member. Specifically, the usage record transceiver unit 167 sends the usage start or completion information received from the usage record management unit 166 to the storage systems 3 used by other group members. The storage systems 3 that receive the usage start or completion information can register this information in the content usage record management table 415. Additionally, the usage record transceiver unit 167 receives usage start or completion information from the storage systems 3 used by other group members. The usage record transceiver unit 167 then sends the received usage start or completion information to the usage record management unit 166.
[0109] The usage record management department 166 receives usage start information or usage completion information from the usage record receiving and sending department 167. Upon confirming the authenticity of the access logs included in the received usage start information or usage completion information, the usage record management department 166 saves (registers) the usage start information or usage completion information in the content usage record management table 415. Furthermore, the usage record management department 166 collaborates with the signature verification department 169 (described later) to obtain the verification result of the authenticity of the access logs.
[0110] The signing unit 168 uses the private key 411 to generate signature data for specific data. The specific data may be, for example, the public key 412 or an access log. Specifically, the signing unit 168 uses a specific hash function to calculate the hash value of the specific data. This specific hash function may be, for example, a hash function predefined in the information processing system 1. Furthermore, the signing unit 168 encrypts the calculated hash value using the private key 411 to generate the signature data.
[0111] The signature verification unit 169 uses public key 412 (hereinafter referred to as verification public key 412) and signature data for that data to verify the authenticity of specific data. Specific data may be, for example, another public key 412 other than verification public key 412, or an access log. Verification public key 412 is presumed to be a public key 412 paired with the private key 411 set to be used in the generation of the signature data. In other words, verification public key 412 is the public key 412 set to correspond to the member who generated the signature data.
[0112] Specifically, the signature verification unit 169 generates a hash value by decrypting the signature data using the verification public key 412. The signature verification unit 169 uses a specific hash function to calculate the hash value of the data whose authenticity is being verified. If the two hash values match, the signature verification unit 169 determines that the authenticity of the data has been confirmed. The signature verification unit 169 can generate (output) a verification result indicating that the authenticity of the data has been confirmed. On the other hand, if the two hash values do not match, the signature verification unit 169 determines that the authenticity of the data has not been confirmed. The signature verification unit 169 can generate a verification result indicating that the authenticity of the data has not been confirmed.
[0113] Through the above structure, storage system 3 manages the utilization of content by each member.
[0114] Next, the actions in information processing system 1 will be described in more detail. The actions in information processing system 1 include, for example, public key registration, content registration, recording using start information, and recording using completion information.
[0115] (Public key registration action)
[0116] Figure 6 An example of a public key registration action in information processing system 1 is shown. The public key registration action is used to register a member's public key 412 along with signature data for that public key 412 in a group public key management table 413 within multiple storage systems 3 used by multiple members. The public key registration action is performed, for example, when public keys 412 are exchanged between two nearby storage systems 3.
[0117] Here, the public key registration operation in the first storage system 3-1, the second storage system 3-2, and the third storage system 3-3 is illustrated. It is assumed that the first storage system 3-1 and the second storage system 3-2 are within range capable of near-field communication.
[0118] Storage system 3-1 is used by member 9-1. Storage system 3-1 is, for example, built into host 2-1 (terminal 2-1). Alternatively, storage system 3-1 can be located outside of host 2-1 and connected to host 2-1. Storage system 3-1 manages the public key management table 413-1.
[0119] The second storage system 3-2 is used by the second member 9-2. The second storage system 3-2 is, for example, built into the second host (second terminal) 2-2. Alternatively, the second storage system 3-2 can be located externally to and connected to the second host 2-2. The second storage system 3-2 manages the public key management table 413-2.
[0120] The third storage system 3-3 is used by the third member 9-3. The third storage system 3-3 may be built into the third host (third terminal) 2-3, for example. Alternatively, the third storage system 3-3 may be located externally to and connected to the third host 2-3. The third storage system 3-3 manages the public key management table 413-3.
[0121] In addition, member 1 (9-1), member 2 (9-2), and member 3 (9-3) belong to group 7.
[0122] The following are examples of specific public key registration actions.
[0123] First, the first storage system 3-1 receives the owner information of the first storage system 3-1 and the information of the group 7 to which the first member 9-1 belongs (hereinafter referred to as group information) input to the first host 2-1 in accordance with the operation of the first member 9-1. Figure 6 (1)). Owner information is the member name of member 9-1 (hereinafter referred to as member name 1). Group information is information that can uniquely identify the corresponding group. More specifically, member 9-1, for example, uses an input device set on host 2-1 to input owner information and group information. The first storage system 3-1 receives the input owner information and group information from host 2-1 via data communication I / F11.
[0124] The first storage system 3-1 generates a key pair including the first private key 411-1 and the first public key 412-1 in accordance with the received owner information and group information. Figure 6 (2)). The first private key 411-1 and the first public key 412-1 are a key pair corresponding to the first member 9-1. In addition, the first storage system 3-1 can append entries including the first member name and the first public key 412-1 to the group public key management table 413-1.
[0125] and Figure 6The same actions as in (1) and (2) are also performed in the second storage system 3-2. That is, the second storage system 3-2, in accordance with the owner information (second member name) and group information related to the second member 9-2 received from the second host 2-2, generates a key pair including the second private key 411-2 and the second public key 412-2. The second private key 411-2 and the second public key 412-2 are the key pair corresponding to the second member 9-2.
[0126] In addition, with Figure 6 The same actions as in (1) and (2) are also performed in the third storage system 3-3. The third storage system 3-3, in accordance with the owner information (third member name) and group information received from the third host 2-3 related to the third member 9-3, generates a key pair including the third private key 411-3 and the third public key 412-3. The third private key 411-3 and the third public key 412-3 are the key pair corresponding to the third member 9-3.
[0127] Next, the first storage system 3-1 and the second storage system 3-2, located within range of near-field communication, exchange the first public key 412-1 and the second public key 412-2 using near-field communication. Figure 6 (3)). In other words, the fact that member 1 9-1 and member 2 9-2 verify each other's identities face-to-face enables storage system 1 3-1 and storage system 3-2 to exchange public key 412-1 and public key 412-2. More specifically, storage system 3-1 sends the first member name and public key 412-1 to storage system 3-2 via near-field communication I / F13 and receives the second member name and public key 412-2 from storage system 3-2. In addition, storage system 3-2 sends the second member name and public key 412-2 to storage system 3-1 via near-field communication I / F13 and receives the first member name and public key 412-1 from storage system 3-1.
[0128] Storage system 3-1 uses the first private key 411-1 to generate signature data (hereinafter referred to as signature data A) for the received second public key 412-2. Figure 6 (4)). Specifically, the first storage system 3-1 uses a specific hash function to calculate the hash value of the second public key 412-2. The first storage system 3-1 generates the signed data A by encrypting the calculated hash value using the first private key 411-1.
[0129] Next, the first storage system 3-1 saves (registers) the information related to the second public key 412-2 (hereinafter referred to as the second public key information) to the group public key management table 413-1 in the non-volatile memory 4. Figure 6(5)). The second public key information includes, for example, the second member name, the second public key 412-2, the first member name, and the signature data A. Specifically, the first storage system 3-1 appends an entry containing the second public key information to the group public key management table 413-1. Furthermore, if an entry containing the second member name and the second public key 412-2 already exists in the group public key management table 413-1, the first storage system 3-1 appends a portion of the second public key information to that entry. A portion of the second public key information is, for example, the first member name and the signature data A.
[0130] The following refers to appending entries containing information related to public key 412 (hereinafter referred to as public key information) to the group public key management table 413, or appending a portion of the public key information to an entry in the group public key management table 413, also known as registering the public key information to the group public key management table 413. The public key information includes, for example, public key 412, the member name corresponding to public key 412, signing data for public key 412, and the member name that generated the signing data (more specifically, the member name corresponding to the private key 411 used in generating the signing data). A portion of the public key information includes, for example, the signing data for public key 412 and the member name that generated the signing data.
[0131] and Figure 6 The same actions as in (4) and (5) are also performed in the second storage system 3-2. That is, the second storage system 3-2 uses the second private key 411-2 to generate signature data (hereinafter referred to as signature data B) for the first public key 412-1. And, the second storage system 3-2 registers the first public key 412-1 together with signature data B in the group public key management table 413-2.
[0132] Next, the first storage system 3-1 sends the second public key information registered in the group public key management table 413-1 to the storage system 3 used by group members other than the second member 9-2 via P2P communication. Figure 6 (6-1)). Specifically, the first storage system 3-1, for example, communicates via P2P communication I / F12 to the storage system 3 used by group members other than the first member 9-1 and the second member 9-2 (in Figure 6 The third storage system 3-3 sends the second public key information. The first storage system 3-1 may, for example, obtain in advance information for P2P communication with other storage systems 3 used by group members.
[0133] In addition, the second storage system 3-2 sends information related to the first public key 412-1 registered in the group public key management table 413-2 (hereinafter referred to as the first public key information) to the storage system 3 used by group members other than the first member 9-1 via P2P communication. Figure 6(6-2)). The first public key information includes, for example, the first member name, the first public key 412-1, the second member name, and the signature data B. Specifically, the second storage system 3-2 is used, for example, via P2P communication I / F12 to the storage system 3 used by group members other than the first member 9-1 and the second member 9-2 (in Figure 6 The third storage system (3-3) sends the first public key information. The second storage system (3-2) can, for example, obtain in advance information for P2P communication with the storage system (3) used by group members.
[0134] The third storage system 3-3 receives the second public key information from the first storage system 3-1 via P2P communication I / F12. Additionally, the third storage system 3-3 receives the first public key information from the second storage system 3-2 via P2P communication I / F12.
[0135] The third storage system 3-3 uses the received first public key information and second public key information to verify the authenticity of the first public key 412-1 and the second public key 412-2. Figure 6 (7)). Specifically, the third storage system 3-3 uses the second public key 412-2 included in the second public key information and the signature data B included in the first public key information to verify the authenticity of the first public key 412-1. In addition, the third storage system 3-3 uses the first public key 412-1 included in the first public key information and the signature data A included in the second public key information to verify the authenticity of the second public key 412-2.
[0136] The method used by the third storage system 3-3 to verify the authenticity of the first public key 412-1 using the second public key 412-2 and the signature data B is described. The third storage system 3-3 generates a hash value by decrypting the signature data B using the second public key 412-2. The third storage system 3-3 then uses a specific hash function to calculate the hash value of the first public key 412-1. If the two hash values match, the third storage system 3-3 determines that the authenticity of the first public key 412-1 has been verified. If the two hash values differ, the third storage system 3-3 determines that the authenticity of the first public key 412-1 has not been verified.
[0137] The method used by the third storage system 3-3 to verify the authenticity of the second public key 412-2 using the first public key 412-1 and the signature data A is described. The third storage system 3-3 generates a hash value by decrypting the signature data A using the first public key 412-1. The third storage system 3-3 then calculates the hash value of the second public key 412-2 using a specific hash function. If the two hash values match, the third storage system 3-3 determines that the authenticity of the second public key 412-2 has been verified. If the two hash values differ, the third storage system 3-3 determines that the authenticity of the second public key 412-2 has not been verified.
[0138] Here, we assume that the authenticity of the first public key 412-1 and the second public key 412-2 have been verified.
[0139] The third storage system 3-3 updates the group public key management table 413-3 with information related to the first public key 412-1 and the second public key 412-2 (i.e., the first public key information and the second public key information) that has been verified to be authentic. Figure 6 (8) in the middle.
[0140] Specifically, the third storage system 3-3 uses the first public key information, for example, to append (save) an entry including the first member name, the first public key 412-1, the second member name, and signature data B to the group public key management table 413-3. Furthermore, if an entry including the first member name and the first public key 412-1 already exists in the group public key management table 413-3, the third storage system 3-3, for example, appends the second member name and signature data B to that entry.
[0141] Additionally, the third storage system 3-3 uses the second public key information, for example, to append an entry to the group public key management table 413-3 containing the second member name, the second public key 412-2, the first member name, and signature data A. Furthermore, if an entry containing the second member name and the second public key 412-2 already exists in the group public key management table 413-3, the third storage system 3-3, for example, appends the first member name and signature data A to that entry.
[0142] Through the above public key registration actions, the member's public key 412 and the signature data for that public key 412 can be registered together in the group public key management table 413 in the storage system 3.
[0143] Specifically, the first storage system 3-1 registers the second member 9-2's second public key 412-2 along with the signature data A of the first member 9-1 for the second public key 412-2 in the group public key management table 413-1. The second storage system 3-2 registers the first member 9-1's first public key 412-1 along with the signature data B of the second member 9-2 for the first public key 412-1 in the group public key management table 413-2. The first storage system 3-1 and the second storage system 3-2 exchange the first public key 412-1 and the second public key 412-2 via near-field communication (i.e., the first member 9-1 and the second member 9-2 exchange face-to-face). Therefore, the authenticity of the second public key 412-2 can be guaranteed in the group public key management table 413-1, and the authenticity of the first public key 412-1 can be guaranteed in the group public key management table 413-2.
[0144] Furthermore, the third storage system 3-3 registers the first public key 412-1 of the first member 9-1, along with the signature data B used to verify the authenticity of the first public key 412-1, in the group public key management table 413-3. The third storage system 3-3 also registers the second public key 412-2 of the second member 9-2, along with the signature data A used to verify the authenticity of the second public key 412-2, in the group public key management table 413-3. Therefore, in the group public key management table 413-3, the authenticity of the first public key 412-1 can be guaranteed using the signature data B, and the authenticity of the second public key 412-2 can be guaranteed using the signature data A.
[0145] Reference Figure 7 as well as Figure 8 Regarding the public key registration process, the internal operations of each storage system 3 will be explained in more detail.
[0146] Figure 7 This illustrates an example of a public key exchange / registration operation in storage system 3 when exchanging public keys with another storage system 3. Here, the example illustrates the public key exchange / registration operation in storage system 3-1 when storage system 3-1 exchanges public key 412 with storage system 3-2. During the exchange of public key 412, storage system 3-1 and storage system 3-2 are within range capable of near-field communication. Figure 7 The first storage system 3-1 shown includes data communication I / F11, P2P communication I / F12, near-field communication I / F13, key pair generation and management unit 160, public key transceiver unit 161, public key management unit 162, signature unit 168, and a first private key 411-1, a first public key 412-1, and a group public key management table 413-1 stored in non-volatile memory 4.
[0147] In the first storage system 3-1, the public key transceiver unit 161 and the public key management unit 162 receive the first member name and group information from the host 2 via data communication I / F11. Figure 7 (1)). The first member name and group information can be provided to other parts within the first storage system 3-1.
[0148] The key pair generation and management unit 160, for example, generates a key pair including a first private key 411-1 and a first public key 412-1 in accordance with the first member name and group information received from the host 2. Figure 7 (2)). The key pair generation and management unit 160 saves the first private key 411-1 and the first public key 412-1 to the non-volatile memory 4.
[0149] When the first storage system 3-1 and the second storage system 3-2 exchange public keys 412, the public key transceiver 161 reads the first public key 412-1 from the non-volatile memory 4. Figure 7 (3)). Furthermore, the public key transceiver 161 sends the first member name and the first public key 412-1 to the second storage system 3-2 via near-field communication I / F13. Figure 7 (4)). Thus, in the second storage system 3-2, the first public key 412-1 associated with the first member name is registered in the group public key management table 413-2.
[0150] Additionally, the public key transceiver 161 receives the second member name and the second public key 412-2 from the second storage system 3-2 via near-field communication I / F13. Figure 7 (5)). Furthermore, after receiving the second member name and the second public key 412-2 from the second storage system 3-2, the public key transceiver 161 can send the first member name and the first public key 412-1 to the second storage system 3-2. The public key transceiver 161 then sends the received second member name and the second public key 412-2 to the public key management unit 162. Figure 7 (6) in the middle.
[0151] Public Key Management Department 162 receives the second member name and the second public key 412-2 from Public Key Sending and Receiving Department 161, and sends the second public key 412-2 to Signature Department 168. Figure 7 (7) in the middle.
[0152] The signing unit 168 receives the second public key 412-2 from the public key management unit 162, and accordingly reads the first private key 411-1 from the non-volatile memory 4. Figure 7 (8)). The signing unit 168 uses the first private key 411-1 to generate signing data A for the second public key 412-2, and sends the signing data A to the public key management unit 162. Figure 7 (9) in the middle.
[0153] Public Key Management Unit 162 registers the second public key information, including the second member name, the second public key 412-2, the first member name, and the signature data A, in the Group Public Key Management Table 413-1. Figure 7 (10)). Furthermore, the public key management unit 162 sends the second public key information to the public key sending and receiving unit 161. Figure 7 (11) in the middle.
[0154] Public key transceiver 161 will send the second public key information received from public key management 162 to the third storage system 3-3 via P2P communication I / F12. Figure 7 (12)). Therefore, in the third storage system 3-3, the group public key management table 413-3 is updated using the second public key information.
[0155] Through the public key exchange and registration operations in the first storage system 3-1 described above, the second public key 412-2 (second public key information) is registered in the group public key management table 413-1 within the first storage system 3-1. Additionally, the first public key 412-1 (first public key information) is registered in the group public key management table 413-2 within the second storage system 3-2. Furthermore, the second public key 412-2 (second public key information) is registered in the group public key management table 413-3 within the third storage system 3-3.
[0156] Furthermore, in other storage systems 3 besides the first storage system 3-1, the same public key exchange and registration operation is also performed when exchanging public keys 412 with other storage systems 3 via near-field communication.
[0157] Figure 8 This illustrates an example of public key verification and registration in storage system 3 when public key information is received from multiple other storage systems 3. Here, the example demonstrates public key verification and registration in storage system 3-3 when public key information is received from storage systems 1-1 and 2-2. Figure 8 The third storage system 3-3 shown includes a P2P communication I / F12 associated with public key verification and registration operations, a public key transceiver unit 161, a public key management unit 162, a signature verification unit 169, and a group public key management table 413-3 in the non-volatile memory 4.
[0158] In the third storage system 3-3, the public key transceiver 161 receives the second public key information from the first storage system 3-1 via P2P communication I / F12. Figure 8(1)). The second public key information includes the second member name, the second public key 412-2, the first member name, and the signature data A. Additionally, the public key transceiver 161 receives the first public key information from the second storage system 3-2 via P2P communication I / F12. Figure 8 (2)). The first public key information includes the first member name, the first public key 412-1, the second member name, and the signature data B. Furthermore, the order in which the public key transceiver 161 receives the first and second public key information can be arbitrary. The public key transceiver 161 sends the first and second public key information to the public key management 162. Figure 8 (3) in the middle.
[0159] Public Key Management Unit 162 sends the first public key 412-1 included in the first public key information, along with the signature data B and the second public key 412-2 included in the second public key information, to Signature Verification Unit 169. Figure 8 (4)). The signature verification unit 169 uses signature data B and the second public key 412-2 to verify the authenticity of the first public key 412-1, and sends the verification result to the public key management unit 162. Figure 8 (5)). Furthermore, if the verification result confirms the authenticity of the first public key 412-1, the public key management unit 162 registers the first public key information in the group public key management table 413-3. Figure 8 (6) in the middle.
[0160] In addition, the public key management unit 162 sends the second public key 412-2 included in the second public key information, as well as the signature data A and the first public key 412-1 included in the first public key information, to the signature verification unit 169. Figure 8 (7)). The signature verification unit 169 uses signature data A and the first public key 412-1 to verify the authenticity of the second public key 412-2, and sends the verification result to the public key management unit 162. Figure 8 (8)). Furthermore, if the verification result confirms the authenticity of the second public key 412-2, the public key management unit 162 registers the second public key information in the group public key management table 413-3. Figure 8 (9) in the middle.
[0161] In addition, the public key management department 162 and the signature verification department 169 can conduct Figure 8 Actions (4), (5), and (6) are performed after actions (7), (8), and (9). Alternatively, the public key management unit 162 and the signature verification unit 169 can perform... Figure 8 The actions (4) and (5) and (7) and (8) are followed by the actions (6) and (9).
[0162] Through the public key verification and registration actions in the third storage system 3-3 described above, information related to the verified first public key 412-1 (first public key information) and information related to the verified second public key 412-2 (second public key information) can be registered in the group public key management table 413-3 within the third storage system 3-3.
[0163] Furthermore, in other storage systems 3 besides the third storage system 3-3, the same public key verification and registration operation is also performed when public key information is received from multiple other storage systems 3 via P2P communication.
[0164] (Content registration action)
[0165] In information processing system 1, multiple members belonging to group 7 share and utilize content. Therefore, content registered (saved) in storage system 3 used by one member is also registered in storage system 3 used by other members.
[0166] Figure 9 This illustrates an example of a content registration action in information processing system 1. The content registration action involves registering content and related information in content information management tables 414 within multiple storage systems 3, which are used by multiple members respectively.
[0167] Here, the content registration actions in storage system 1 (3-1), storage system 2 (3-2), and storage system 3 (3-3) are illustrated. Storage system 1 (3-1) manages content information management table 414-1. Storage system 2 (3-2) manages content information management table 414-2. Storage system 3 (3-3) manages content information management table 414-3.
[0168] The following are examples of specific content registration actions.
[0169] First, the first storage system 3-1 receives content information input to the first host 2-1 in response to the operation of user 9-L. Figure 9 (1)). User 9-L can be the same user as member 9-1 or a different user. Content information includes, for example, content ID, content name, content body, and information indicating the conditions for using the content. Information indicating the conditions for using the content includes, for example, the limit on the number of users who can use the content at the same time. Specifically, user 9-L, for example, uses an input device set on host 2-1 to input content information. The first storage system 3-1 receives the input content information from host 2-1 via data communication I / F11.
[0170] The first storage system 3-1 saves (registers) the received content information to the content information management table 414-1 in the non-volatile memory 4. Figure 9 (2)). That is, based on the content information, the first storage system 3-1 adds entries including content ID, content name, content body, and access conditions (e.g., the number of users at the same time) to the content information management table 414-1.
[0171] Next, the first storage system 3-1 sends the content information to the storage systems 3 used by other group members via P2P communication. Figure 9 (3)). Specifically, the first storage system 3-1 sends content information to the second storage system 3-2 via P2P communication I / F12. In addition, the first storage system 3-1 sends content information to the third storage system 3-3 via P2P communication I / F12.
[0172] The second storage system 3-2 will register the content information received from the first storage system 3-1 to the content information management table 414-2. Figure 9 (4-1)). Additionally, the third storage system 3-3 will register the content information received from the first storage system 3-1 to the content information management table 414-3 (…). Figure 9 (4-2) in the middle.
[0173] Through the above content registration actions, the first storage system 3-1 can register the content information input from the first host 2-1 into the content information management table 414-1 within the first storage system 3-1. Furthermore, the first storage system 3-1 can also register the same content information into the content information management table 414-2 within the second storage system 3-2 and the content information management table 414-3 within the third storage system 3-3 used by other group members.
[0174] Furthermore, in both cases where content information is input from the second host 2-2 to the second storage system 3-2 and from the third host 2-3 to the third storage system 3-3, the content information can be registered not only in the content information management table 414 in the storage system 3 where the content information was input, but also in the content information management table 414 in the storage system 3 used by other group members.
[0175] Reference Figure 10 as well as Figure 11 Regarding the content registration action, the internal actions of each storage system 3 will be explained in more detail.
[0176] Figure 10This illustrates an example of content registration and transmission in storage system 3 when content information is received from host 2. Here, the content registration and transmission operation in the first storage system 3-1 is illustrated when content information is received from the first host 2-1. Figure 10 The first storage system 3-1 shown includes a data communication I / F11, a P2P communication I / F12, a content management unit 163, a content transceiver unit 164, and a content information management table 414-1 in the non-volatile memory 4, which are associated with the content registration and transmission operation.
[0177] In the first storage system 3-1, the content management unit 163 receives content information from the first host 2-1 via data communication I / F11. Figure 10 (1)). Content Management Department 163 registers the content information to Content Information Management Form 414-1 ( Figure 10 (2)). That is, the content management department 163 adds entries including content ID, content name, content body, and usage conditions to the content information management table 414-1. Furthermore, the content management department 163 sends the content information to the content receiving and sending department 164. Figure 10 (3) in the middle.
[0178] Content transceiver 164 will send the content information received from content management 163 to the second storage system 3-2 and the third storage system 3-3 via P2P communication I / F12. Figure 10 (4) in the middle.
[0179] Through the content registration and transmission actions in the first storage system 3-1 described above, content information is registered in the content information management table 414-1 within the first storage system 3-1. Additionally, content information transmitted by the first storage system 3-1 is registered in the content information management table 414-2 within the second storage system 3-2 and the content information management table 414-3 within the third storage system 3-3.
[0180] Furthermore, in other storage systems 3 besides the first storage system 3-1, the same content registration and transmission operation is performed when content information is received from the corresponding host 2.
[0181] Figure 11 This illustrates an example of content reception and registration in storage system 3 when content information is received from another storage system 3. Here, the content reception and registration operation in storage system 3-2 is illustrated when content information is received from the first storage system 3-1. Figure 11The second storage system 3-2 shown includes a P2P communication I / F12 associated with the content reception and registration operation, a content management unit 163, a content transceiver unit 164, and a content information management table 414-2 in the non-volatile memory 4.
[0182] In the second storage system 3-2, the content transceiver unit 164 receives content information from the first storage system 3-1 via P2P communication I / F12. Figure 11 (1)). The content receiving and sending unit 164 sends the received content information to the content management unit 163. Figure 11 (2) in the middle.
[0183] Content Management Department 163 will register the content information received from Content Receiving and Distributing Department 164 into Content Information Management Form 414-2. Figure 11 (3)). That is to say, the content management department 163 will add entries including content ID, content name, content body, and usage conditions to the content information management table 414-2.
[0184] Through the content reception and registration operation in the second storage system 3-2 described above, content information is registered in the content information management table 414-2 within the second storage system 3-2. Furthermore, in other storage systems 3 besides the second storage system 3-2, when content information is received from other storage systems 3, the same content reception and registration operation is performed.
[0185] (Use start information to record actions)
[0186] Figure 12 An example of a start information recording action is shown in information processing system 1. The start information recording action is an action used to control members' access to content and to record information indicating the start of a member's access to the content (access start information) in the content access record management table 415 of multiple storage systems 3 used by multiple members respectively. The start information recording action is performed when a member requests access to content from storage system 3 via host 2. Here, the start information recording actions in the first storage system 3-1, the second storage system 3-2, and the third storage system 3-3 are illustrated.
[0187] Storage system 3-1 receives access requests for content (object content) generated by host 2-1 in response to the operations of member 9-1. Figure 12(1)). The request to access the object content is, for example, an initial read access request (e.g., a read command) to read the object content from the non-volatile memory 4 of the first storage system 3-1. More specifically, the first member 9-1, for example, uses an input device provided on the first host 2-1 to perform the operation of requesting access to the object content. The first storage system 3-1 receives the request to access the object content generated accordingly from the first host 2-1 via data communication I / F11.
[0188] The first storage system 3-1, in response to receiving a request to utilize the object content, determines whether the conditions for utilizing the object content are met. Figure 12 (2)). Specifically, for example, the first storage system 3-1 obtains the limit on the number of users simultaneously using the object content from the content information management table 414-1. The first storage system 3-1 obtains the number of users currently using the object content from the content usage record management table 415-1. Furthermore, the first storage system 3-1 determines whether the number of users currently using the object content is less than the limit on the number of users simultaneously using it.
[0189] Here, it is assumed that the number of people currently using the object content is less than the limit for simultaneous users (i.e., the conditions for using the object content are met). In this case, the first storage system 3-1 provides the object content to the first member 9-1 by reading at least a portion of the object content from the content information management table 414-1 (non-volatile memory 4) and sending it to the first host 2-1. Figure 12 (3)). In addition, the first storage system 3-1 may, for example, read the entire data of the object content from the content information management table 414-1 and send it to the first host 2-1. Alternatively, the first storage system 3-1 may also read multiple data parts constituting the object content sequentially from the content information management table 414-1 and send them to the first host 2-1.
[0190] Storage system 3-1 generates an access log related to member 9-1's use of object content, using private key 411-1 to generate signed data for the access log. Figure 12 (4)). Furthermore, the first storage system 3-1 records the start-of-use information indicating the start of use of the object content by the first member 9-1 to the content use record management table 415-1. Figure 12(5)). The start information includes, for example, access logs, a value indicating the start of use (e.g., 1), and signature data. Specifically, the first storage system 3-1 appends an entry based on the start information to the content use record management table 415-1 associated with the object content. Furthermore, if an entry including the first member name already exists in the content use record management table 415-1 associated with the object content, the first storage system 3-1 updates that entry, for example, using the start information. Hereinafter, the situation of appending an entry based on the start information to the content use record management table 415 associated with the object content, or updating an entry in the content use record management table 415 associated with the object content using the start information, will also be referred to as recording the start information in the content use record management table 415.
[0191] Next, the first storage system 3-1 will send the start information to other storage systems 3 used by group members other than the first member 9-1 via P2P communication. Figure 12 (6)). Specifically, the first storage system 3-1 sends a start-of-use message to the second storage system 3-2 via P2P communication I / F12. In addition, the first storage system 3-1 sends a start-of-use message to the third storage system 3-3 via P2P communication I / F12.
[0192] The second storage system 3-2, in accordance with the start information received from the first storage system 3-1, uses the first public key 412-1 and signature data to verify the authenticity of the access log. Figure 12 (7-1)). Specifically, when the entries representing the first member 9-1 (first member name), the first public key 412-1, and the signature data for the first public key 412-1 (i.e., public key information) are stored in the group public key management table 413-2 in the non-volatile memory 4, the second storage system 3-2 obtains the first public key 412-1 corresponding to the first member 9-1 from the group public key management table 413-2 based on the first member name included in the access log. The second storage system 3-2 uses the obtained first public key 412-1 and the signature data included in the start information to verify the authenticity of the access log included in the start information.
[0193] Here, it is assumed that the authenticity of the access log included in the start-of-use information is confirmed. In this case, the second storage system 3-2 will record the start-of-use information in the content access record management table 415-2. Figure 12 (8-1) in the middle.
[0194] Similarly, the third storage system 3-3, in accordance with the utilization start information received from the first storage system 3-1, uses the first public key 412-1 and signature data to verify the authenticity of the access log. Figure 12 (7-2)). Specifically, the third storage system 3-3 obtains the first public key 412-1 corresponding to the first member 9-1 from the group public key management table 413-3 based on the first member name included in the access log. The third storage system 3-3 uses the obtained first public key 412-1 and the signature data included in the start information to verify the authenticity of the access log included in the start information.
[0195] Here, it is assumed that the authenticity of the access log included in the start-up information is confirmed. In this case, the third storage system 3-3 will record the start-up information in the content access record management table 415-3. Figure 12 (8-2) in the middle.
[0196] Through the above-described actions of recording the start information, information processing system 1 can control members' access to content and record the start information in content access record management tables 415 in multiple storage systems 3 used by multiple members. Thus, each storage system 3 can securely and easily manage the content access of members belonging to group 7. Specifically, each storage system 3 can use the content access record management table 415 to, for example, manage which member is currently using each piece of content and the number of people currently using each piece of content.
[0197] Furthermore, the first storage system 3-1 records the access log along with signature data that can verify the authenticity of the access log in the content usage record management table 415-1. Therefore, the authenticity of the access log can be guaranteed in the content usage record management table 415-1 using signature data.
[0198] Furthermore, the second storage system 3-2 records the access log along with the signature data used to verify the authenticity of the access log in the content usage record management table 415-2. Therefore, the authenticity of the access log can be guaranteed in the content usage record management table 415-2 using the signature data. The same applies to the third storage system 3-3.
[0199] Reference Figure 13 as well as Figure 14 Regarding the use of start information to record actions, the internal actions of each storage system 3 will be explained in more detail.
[0200] Figure 13This example illustrates the access control / start information recording operation in storage system 3 when access is requested for content. Specifically, it illustrates the access control / start information recording operation in the first storage system 3-1 when access is requested from the first host 2-1 (object content). Furthermore, it is assumed that the access condition for the object content is a limit on the number of simultaneous users. Figure 13 The first storage system 3-1 shown includes a data communication I / F11, a P2P communication I / F12, a content utilization control unit 165, a utilization record management unit 166, a utilization record transceiver unit 167, a signature unit 168, and a first private key 411-1, a content information management table 414-1, and a content utilization record management table 415-1 stored in the non-volatile memory 4.
[0201] In the first storage system 3-1, the content access control unit 165 receives access requests for target content from the first host 2-1 via data communication I / F11. Figure 13 (1)). Upon receiving a usage request, the content access control unit 165 retrieves the target content from the content information management table 414-1, simultaneously limiting the number of users ( ) Figure 13 (2)). Additionally, the content utilization control unit 165 uses the content utilization record management table 415-1 to obtain the number of people currently utilizing the target content. Figure 13 (3) in the middle.
[0202] If the number of users currently accessing the content exceeds the limit for simultaneous access, the content access control unit 165 will notify the first host 2-1 via data communication I / F11 that the content cannot be accessed. Figure 13 (4)). That is to say, member 9-1 cannot use the object content until the number of people currently using the object content is less than the limit of the number of people using it at the same time.
[0203] Conversely, if the number of people currently using the content is less than the limit for simultaneous use, the content access control unit 165 reads at least a portion of the content from the content information management table 414-1. Figure 13 (5)). The content is transmitted by the control unit 165 to the first host 2-1 via data communication I / F11. Figure 13 (6)). Thus, member 9-1 is able to utilize the object content. Furthermore, the content utilization control unit 165 generates an access log for the object content and a value indicating the start of utilization, and sends it to the utilization record management unit 166. Figure 13 (7) in the middle.
[0204] The access management department 166 receives the access log and the value indicating the start of access from the content access control department 165, and sends the access log to the signature department 168. Figure 13 (8) in the middle.
[0205] The signature unit 168, in accordance with the access log received from the access record management unit 166, reads the first private key 411-1 from the non-volatile memory 4. Figure 13 (9)). The signing unit 168 uses the first private key 411-1 to generate signing data for the access log and sends the signing data to the utilization record management unit 166. Figure 13 (10) in the middle.
[0206] The Utility Management Department 166 records the utilization start information, including access logs, values indicating the start of utilization, and signature data, into Content Utility Record Management Table 415-1. Figure 13 (11)). Furthermore, the utilization start information is sent from the utilization record management unit 166 to the utilization record receiving and sending unit 167. Figure 13 (12) in the middle.
[0207] The usage record transceiver unit 167 will send the usage start information received from the usage record management unit 166 to the second storage system 3-2 and the third storage system 3-3 via P2P communication I / F12. Figure 13 (13)). Therefore, in the second storage system 3-2, the start information is recorded in the content usage record management table 415-2. In addition, in the third storage system 3-3, the start information is recorded in the content usage record management table 415-3.
[0208] The utilization control and start information recording actions in the first storage system 3-1 described above allow control over the utilization of object content by the first member 9-1. Furthermore, when object content is utilized, utilization start information is recorded in the content utilization record management table 415-1 within the first storage system 3-1. Utilization start information is also recorded in the content utilization record management table 415-2 within the second storage system 3-2 and the content utilization record management table 415-3 within the third storage system 3-3.
[0209] Furthermore, in other storage systems 3 besides the first storage system 3-1, the same access control and start information recording action is performed when access is requested from the corresponding host 2.
[0210] Figure 14This illustrates an example of a start information receiving and recording operation in storage system 3 when start information is received from another storage system 3. Here, the example of a start information receiving and recording operation in storage system 3-2 when start information is received from a first storage system 3-1 is shown. Figure 14 The second storage system 3-2 shown includes a P2P communication I / F12 associated with the start of information reception and recording, a record management unit 166, a record transceiver unit 167, a signature verification unit 169, a group public key management table 413-2 in the non-volatile memory 4, and a content usage record management table 415-2.
[0211] In the second storage system 3-2, the recording transceiver 167 receives the start-of-use information from the first storage system 3-1 via P2P communication I / F12. Figure 14 (1)). The start information includes the first member name, access log, value indicating the start of use, and signature data. The use record transceiver 167 sends the received start information to the use record management 166. Figure 14 (2) in the middle.
[0212] In response to receiving the start-of-use information, the record management department 166 retrieves the first public key 412-1 from the group public key management table 413-2. Figure 14 (3) Specifically, the first member name included in the access log is obtained using the record management unit 166. The record management unit 166 determines the entry including the obtained first member name in the group public key management table 413-2. The record management unit 166 obtains the first public key 412-1 from the determined entry. Furthermore, the record management unit 166 sends the obtained first public key 412-1, the access log included in the start information, and the signature data to the signature verification unit 169. Figure 14 (4) in the middle.
[0213] The signature verification unit 169 uses the signature data and the first public key 412-1 to verify the authenticity of the access log, and sends the verification result to the access record management unit 166. Figure 14 (5) in the middle.
[0214] If the verification result confirms the authenticity of the access log, the Record Management Department 166 will record the information in the Content Access Record Management Table 415-2 using the start information. Figure 14 (6) in the middle.
[0215] Through the start information reception and recording operation in the second storage system 3-2 described above, the start information of use, including the access log that has been verified to be genuine, can be recorded in the content use record management table 415-2. Furthermore, in other storage systems 3 besides the second storage system 3-2, when start information of use is received from another storage system 3 via P2P communication, the same start information reception and recording operation is also performed.
[0216] (Utilizing the action of completing information recording)
[0217] Figure 15 This example illustrates a utilization completion information recording action in information processing system 1. The utilization completion information recording action is an action used to detect when a member has completed utilizing content (object content) and to record information indicating the completion of object content utilization (utilization completion information) in content utilization record management tables 415 in multiple storage systems 3 used by multiple members. The utilization completion information recording action is performed after a member begins utilizing the object content (more specifically, a read access to the object content by host 2). Here, utilization completion information recording actions in the first storage system 3-1, the second storage system 3-2, and the third storage system 3-3 are illustrated.
[0218] Storage system 3-1 detects that member 9-1 has completed the utilization of the object content. Figure 15 (1)). In response to the detection that the use of object content has been completed, the first storage system 3-1 generates an access log related to the use of object content by the first member 9-1, and uses the first private key 411-1 to generate signed data for the access log. Figure 15 (2) in the middle.
[0219] Furthermore, the first storage system 3-1 records the completion information indicating that the first member 9-1 has completed the utilization of the object content to the content utilization record management table 415-1. Figure 15(3)). Utilization completion information includes, for example, the first member name, access log, a value indicating utilization completion (e.g., 0), and signature data. Specifically, the first storage system 3-1 appends an entry containing utilization completion information to the content utilization record management table 415-1 associated with the object content. Furthermore, if an entry containing the first member name already exists in the content utilization record management table 415-1 associated with the object content, the first storage system 3-1 updates that entry, for example, using a portion of the utilization completion information. A portion of the utilization completion information includes, for example, the access log, a value indicating utilization completion, and signature data. Hereinafter, the situation of appending an entry containing utilization completion information to the content utilization record management table 415 associated with the object content, or updating an entry in the content utilization record management table 415 associated with the object content using a portion of the utilization completion information, will also be referred to as recording utilization completion information to the content utilization record management table 415.
[0220] The future Figure 15 The actions (4), (5-1), (6-1), (5-2), and (6-2) are equivalent to referring to Figure 12 In the actions (6), (7-1), (8-1), (7-2), and (8-2) described above, which use start information to record actions, the use of start information is replaced with the use of completion information.
[0221] Through the above-described information recording process, information processing system 1 can detect the completion of content usage by members and record the completion information in content usage record management tables 415 within multiple storage systems 3 used by different members. Thus, each storage system 3 can securely and easily manage content usage by members belonging to group 7. Specifically, each storage system 3 can use the content usage record management table 415 to, for example, manage which member is currently using each piece of content and the number of people currently using each piece of content.
[0222] Furthermore, the first storage system 3-1 records the access log along with signature data that can verify the authenticity of the access log in the content usage record management table 415-1. Therefore, the authenticity of the access log can be guaranteed in the content usage record management table 415-1 using signature data.
[0223] Furthermore, the second storage system 3-2 records the access log along with the signature data used to verify the authenticity of the access log in the content usage record management table 415-2. Therefore, the authenticity of the access log can be guaranteed in the content usage record management table 415-2 using the signature data. The same applies to the third storage system 3-3.
[0224] Reference Figure 16 as well as Figure 17 Regarding the completion of information recording, the internal operations of each storage system 3 will be explained in more detail.
[0225] Figure 16 This example illustrates the completion detection and completion information recording action in storage system 3 when host 2 completes access to content. Here, the completion detection and completion information recording action in the first storage system 3-1 is illustrated when the first host 2-1 completes its use of content (object content). Figure 16 The first storage system 3-1 shown includes a data communication I / F11, a P2P communication I / F12, a content utilization control unit 165, a utilization record management unit 166, a utilization record transceiver unit 167, a signature unit 168, a first private key 411-1 stored in the non-volatile memory 4, and a content utilization record management table 415-1.
[0226] In the first storage system 3-1, when the content access control unit 165 detects that the first host 2-1 has completed accessing the object content, it generates an access log of the object content and a value indicating the completion of access, and sends it to the access record management unit 166. Figure 16 (1) in the middle.
[0227] The future Figure 16 The actions in (2) to (7) are equivalent to referring to Figure 13 In the actions (8) to (13) described above, which use control and start information to record actions, the use of start information is replaced with the use of completion information.
[0228] Through the completion detection and completion information recording actions in the first storage system 3-1 described above, the completion of the first member 9-1's use of the object content can be detected. Upon detection of completed use of the object content, the completion information is recorded in the content use record management table 415-1 within the first storage system 3-1. Furthermore, completion information is also recorded in the content use record management table 415-2 within the second storage system 3-2 and the content use record management table 415-3 within the third storage system 3-3.
[0229] Furthermore, in other storage systems 3 besides the first storage system 3-1, the same completion detection and completion information recording action is performed when the corresponding host 2 is detected to have completed its use of the content.
[0230] Figure 17This illustrates an example of a completion information reception and recording operation in storage system 3 when completion information representing the application completion is received from another storage system. Here, the completion information reception and recording operation in storage system 3-2 is illustrated when completion information is received from storage system 3-1. Figure 17 The second storage system 3-2 shown includes a P2P communication I / F12 associated with the completion of information reception and recording operations, a record transceiver unit 167, a record management unit 166, a signature verification unit 169, a group public key management table 413-2 in the non-volatile memory 4, and a content usage record management table 415-2.
[0231] In the second storage system 3-2, the recording transceiver 167 receives utilization completion information from the first storage system 3-1 via P2P communication I / F12. Figure 17 (1)). The utilization completion information includes the first member's name, access log, value indicating utilization completion, and signature data. The utilization record receiving unit 167 sends the received utilization completion information to the utilization record management unit 166. Figure 17 (2) in the middle.
[0232] The future Figure 17 Actions (3) to (6) are equivalent to referencing Figure 14 In the actions (3) to (6) of the previously described start information receiving and recording action, the start information will be replaced by the completion information.
[0233] By performing the completion information reception and recording operation in the second storage system 3-2 described above, utilization completion information, including access logs confirming authenticity, can be recorded in the content utilization record management table 415-2. Furthermore, the same completion information reception and recording operation is performed in other storage systems 3 besides the second storage system 3 when utilization completion information is received from another storage system 3 via P2P communication.
[0234] Next, refer to Figures 18-22 The flowchart shown illustrates the steps of the processing performed in storage system 3.
[0235] (Public key registration processing)
[0236] Figure 18This is a flowchart illustrating an example of the steps of a public key registration process performed by the CPU 16 of storage system 3. The public key registration process is used to exchange public keys 412 with other storage systems 3 via near-field communication and to register the obtained public keys 412 in the group public key management table 413. The CPU 16 performs the public key registration process, for example, in response to a specific operation performed by a member using storage system 3. The specific operation is the action that instructs the member using storage system 3 to perform the public key registration process. The specific operation is performed by a member using storage system 3, for example, when they want to exchange public keys with storage systems 3 used by other members via near-field communication.
[0237] Here, the case where public key registration processing is performed in the first storage system 3-1 is illustrated. Furthermore, the storage system 3 for which public keys are exchanged between the first storage system 3-1 and the second storage system 3-2 is designated as the second storage system 3-2. The first storage system 3-1 and the second storage system 3-2 are located within range capable of near-field communication. In the first storage system 3-1, a key pair including the first private key 411-1 and the first public key 412-1 is stored in non-volatile memory 4. In the second storage system 3-2, a key pair including the second private key 411-2 and the second public key 412-2 is stored in non-volatile memory 4.
[0238] First, the CPU 16 of the first storage system 3-1 exchanges the first public key 412-1 of the first storage system 3-1 with the second public key 412-2 of the second storage system 3-2 via near-field communication (step S101). Specifically, the CPU 16 sends the first public key 412-1 to the second storage system 3-2 and receives the second public key 412-2 from the second storage system 3-2 via near-field communication I / F13.
[0239] CPU16 uses a specific hash function to calculate the hash value of the second public key 412-2 (hereinafter referred to as the first hash value) (step S102). CPU16 generates signature data A by encrypting the first hash value using the first private key 411-1 (step S103).
[0240] Next, CPU16 determines whether the group public key management table 413-1 includes an entry corresponding to the second member 9-2 using the second storage system 3-2 (i.e., an entry including the name of the second member) (step S104).
[0241] If the group public key management table 413-1 includes an entry corresponding to the second member 9-2 ("Yes" in step S104), the CPU 16 appends the first member 9-1 and signature data A to that entry (step S105), and proceeds to step 107. Specifically, the CPU 16 determines the xth signature member name field and the xth signature data field, which have not yet been set, in the entry corresponding to the second member 9-2. Then, the CPU 16 sets the name of the first member 9-1 (first member name) in the determined xth signature member name field and sets the signature data A in the xth signature data field.
[0242] If the group public key management table 413-1 does not contain an entry corresponding to the second member 9-2 (No in step S104), CPU 16 will append an entry representing the second member 9-2, the second public key 412-2, the first member 9-1, and the signature data A to the group public key management table 413-1 (step S106), and proceed to step S107. Specifically, CPU 16 will append entries to the group public key management table 413-1 that respectively set the name of the second member 9-2 (second member name), the second public key 412-2, the first member name, and the signature data A in the member name field, public key field, first signature member name field, and first signature data field.
[0243] Then, CPU16 sends information (second public key information) representing second member 9-2, second public key 412-2, first member 9-1, and signature data A to storage system 3 (e.g., third storage system 3-3) used by group members other than first member 9-1 and second member 9-2 via P2P communication I / F12, thereby ending the public key registration process.
[0244] Through the above public key registration process, the CPU 16 of the first storage system 3-1 can exchange public key 412 with the second storage system 3-2 and register the obtained second public key 412-2 along with signature data A in the group public key management table 413-1. Furthermore, the CPU 16 sends the second public key information representing the second member 9-2, the second public key 412-2, the first member 9-1, and signature data A to the storage systems 3 used by group members other than the first member 9-1 and the second member 9-2. The signature data A for the second public key 412-2 is generated using the first private key 411-1. Therefore, the storage system 3 receiving the second public key information can use the first public key 412-1 and signature data A to verify the authenticity of the second public key 412-2.
[0245] Furthermore, in the foregoing description, the public key registration process is illustrated when the first storage system 3-1 exchanges public key 412 with the second storage system 3-2 via near-field communication. The same public key registration process is also performed when the other two storage systems 3 exchange public key 412 via near-field communication.
[0246] (Public Key Verification & Registration Processing)
[0247] Figure 19 This is a flowchart illustrating an example of the steps of public key verification and registration processing performed by the CPU 16 of storage system 3. Public key verification and registration processing is the process of verifying the authenticity of the public key 412 included in public key information received from another storage system 3 and registering the verified public key 412 in the group public key management table 413. For example, the CPU 16 performs public key verification and registration processing accordingly when receiving public key information from two other storage systems 3.
[0248] Here, we illustrate the case where public key verification and registration processing is performed in the third storage system 3-3. Assume that the third storage system 3-3 receives public key information from the first storage system 3-1 and the second storage system 3-2, respectively. The public key information received from the second storage system 3-2 (the first public key information) represents the first member 9-1, the first public key 412-1, the second member 9-2, and signature data B. Signature data B is the signature data for the first public key 412-1. The public key information received from the first storage system 3-1 (the second public key information) represents the second member 9-2, the second public key 412-2, the first member 9-1, and signature data A. Signature data A is the signature data for the second public key 412-2.
[0249] First, the CPU 16 of the third storage system 3-3 uses a specific hash function to calculate the hash value of the first public key 412-1 included in the first public key information (hereinafter referred to as the second hash value) (step S201). The CPU 16 generates a hash value (hereinafter referred to as the third hash value) by decrypting the signature data B using the second public key 412-2 included in the second public key information (step S202). Then, the CPU 16 determines whether the second hash value and the third hash value are equal (step S203). The equality of the second hash value and the third hash value means that the authenticity of the first public key 412-1 is confirmed based on the second public key 412-2 and the signature data B.
[0250] If the second hash value differs from the third hash value (No in step S203), the processing performed by CPU 16 proceeds to step S207. That is, since the authenticity of the first public key 412-1 has not been confirmed, CPU 16 does not register the first public key information in the group public key management table 413-3, but instead proceeds to the processing used to verify the authenticity of the second public key 412-2.
[0251] If the second hash value is equal to the third hash value ("Yes" in step S203), the CPU16 determines whether the group public key management table 413-3 includes an entry corresponding to the first member 9-1 using the first storage system 3-1 (i.e., an entry with the first member name set in the member name field) (step S204).
[0252] If the group public key management table 413-3 includes an entry corresponding to member 9-1 ("Yes" in step S204), CPU 16 appends member 9-2 and signature data B to the entry corresponding to member 9-1 (step S205), and proceeds to step 207. Specifically, CPU 16 determines the xth signature member name field and xth signature data field, which have not yet been set, in the entry corresponding to member 9-1. Then, CPU 16 sets the name of member 9-2 (2nd member name) in the determined xth signature member name field and sets the signature data B in the xth signature data field.
[0253] If the group public key management table 413-3 does not contain an entry corresponding to the first member 9-1 (No in step S204), CPU 16 will append an entry representing the first member 9-1, the first public key 412-1, the second member 9-2, and the signature data B to the group public key management table 413-3 (step S206), and proceed to step S207. Specifically, CPU 16 will append entries to the group public key management table 413-3 that respectively set the first member name, the first public key 412-1, the second member name, and the signature data B in the member name field, the public key field, the first signature member name field, and the first signature data field.
[0254] Next, CPU 16 uses a specific hash function to calculate the hash value of the second public key 412-2 (hereinafter referred to as the fourth hash value) (step S207). CPU 16 generates a hash value (hereinafter referred to as the fifth hash value) by decrypting the signature data A using the first public key 412-1 (step S208). Then, CPU 16 determines whether the fourth hash value and the fifth hash value are equal (step S209). The equality of the fourth hash value and the fifth hash value means that the authenticity of the second public key 412-2 has been confirmed based on the first public key 412-1 and the signature data A.
[0255] If the fourth hash value differs from the fifth hash value (No in step S209), CPU16 terminates the public key verification and registration process. That is, since the authenticity of the second public key 412-2 has not been confirmed, CPU16 does not register the second public key information to the group public key management table 413-3, but terminates the public key verification and registration process.
[0256] If the fourth hash value is equal to the fifth hash value ("Yes" in step S209), the CPU16 determines whether the group public key management table 413-3 includes an entry corresponding to the second member 9-2 using the second storage system 3-2 (i.e., an entry with the second member name set in the member name field) (step S210).
[0257] If the public key management table 413-3 includes an entry corresponding to the second member 9-2 ("Yes" in step S210), the CPU16 appends the first member 9-1 and the signature data A to the entry corresponding to the second member 9-2 (step S211), and ends the public key verification and registration process.
[0258] If the group public key management table 413-1 does not contain an entry corresponding to the second member 9-2 (No in step S210), the CPU16 will append the entry representing the second member 9-2, the second public key 412-2, the first member 9-1, and the signature data A to the group public key management table 413-3 (step S212), and end the public key verification and registration process.
[0259] Through the above public key verification and registration process, the CPU 16 of the third storage system 3-3 can use the first public key information received from the second storage system 3-2 and the second public key information received from the first storage system 3-1 to verify the authenticity of the first public key 412-1 and the second public key 412-2. Furthermore, the CPU 16 can register the information related to the verified authenticity of the first public key 412-1 and the second public key 412-2 in the group public key management table 413-3.
[0260] Furthermore, CPU 16 may perform steps S201 to S206 related to the verification and registration of the first public key 412-1 after the processing of steps S207 to S212 related to the verification and registration of the second public key 412-2. Alternatively, the processing of steps S201 to S206 related to the verification and registration of the first public key 412-1 and the processing of steps S207 to S212 related to the verification and registration of the second public key 412-2 may be performed in parallel.
[0261] Furthermore, in the foregoing description, the public key verification and registration process is illustrated when the third storage system 3-3 receives public key information from the first storage system 3-1 and the second storage system 3-2, respectively. However, the same public key verification and registration process is also performed when a storage system 3 receives public key information from two other storage systems 3.
[0262] (Utilizing control to begin information recording and processing)
[0263] Figure 20 This is a flowchart illustrating an example of the steps of utilization control / start information recording processing performed by the CPU 16 of storage system 3. Utilization control / start information recording processing is a process used to control member access to content and register utilization start information indicating the commencement of access to content in the content utilization record management table 415. For example, the CPU 16 performs utilization control / start information recording processing in response to a request for member access to content.
[0264] Here, an example is given of a case where control-start information recording processing is performed in the first storage system 3-1. In this case, for example, the host 2 requests access to the content from the first member 9-1 via data communication I / F11.
[0265] First, the CPU 16 of the first storage system 3-1 retrieves the simultaneous user limit corresponding to the content (object content) requested by the first member 9-1 from the content information management table 414-1 (step S301). Specifically, the CPU 16, for example, determines an entry in the content information management table 414-1 that includes the content ID of the object content. Furthermore, the CPU 16 retrieves the value set in the simultaneous user limit field of the specific entry as the simultaneous user limit corresponding to the object content.
[0266] CPU 16 determines whether there is a limit on the number of users simultaneously using the object content (step S302). Specifically, CPU 16 determines, for example, whether the obtained value of the limit on the number of users simultaneously using the object content is greater than 0. If the value of the limit on the number of users simultaneously using the object content is 0, CPU 16 determines that there is no limit on the number of users simultaneously using the object content. If the value of the limit on the number of users simultaneously using the object content is greater than 0, CPU 16 determines that there is a limit on the number of users simultaneously using the object content.
[0267] If there is no limit to the number of users who can use the object content at the same time (No in step S302), the processing performed by CPU16 proceeds to step S305.
[0268] If there is a limit to the number of users simultaneously using the content ("Yes" in step S302), the CPU 16 calculates the number of users currently using the content by referring to the content usage record management table 415-1 (step S303). Specifically, the CPU 16 determines, for example, the content usage record management tables 415-1 associated with the content ID of the content in the non-volatile memory 4, which are stored in one or more content usage record management tables 415A, 415B, ..., and 415M corresponding to one or more contents respectively. The CPU 16 counts the number of entries in all the entries included in the determined content usage record management table 415-1 that have a value indicating the start of usage (e.g., 1) set in the usage status field. Thus, the CPU 16 obtains the number of users currently using the content.
[0269] Next, CPU16 determines whether the number of people currently using the object content is less than the limit for the number of people using the object content at the same time (step S304). Furthermore, in the determination in step S304, any condition for deciding whether or not the object content can be used, not limited to the condition that the number of people currently using the object content is less than the limit for the number of people using it at the same time.
[0270] If the number of people currently using the object content is less than the limit of the number of people using the object content at the same time ("Yes" in step S304), the processing performed by CPU16 proceeds to step S305.
[0271] In step S305, CPU16 generates an access log indicating that member 1 9-1 has begun accessing the object content. The generated access log includes, for example, the date and time the access began, the member name of member 1 9-1, and the content ID of the object content.
[0272] CPU16 uses a specific hash function to calculate the hash value of the generated access log (step S306). CPU16 generates signed data for the access log by encrypting the calculated hash value using the first private key 411-1 (step S307).
[0273] Next, CPU 16 updates the content utilization record management table 415-1 associated with the object content using the utilization start information representing the access log, utilization start, and signature data (step S308). Specifically, CPU 16 determines, for example, an entry in the content utilization record management table 415-1 associated with the object content (e.g., the content ID of the object content) that includes the member name of member 9-1. Furthermore, CPU 16 sets the access log, the value representing the utilization start (e.g., 1), and the signature data in the access log field, utilization status field, and signature data field of the determined entry, respectively.
[0274] CPU16 sends utilization start information to the storage system 3 used by group members other than member 9-1 via P2P communication I / F12 (step S309), and ends utilization control and start information recording processing.
[0275] In addition, if the number of people currently using the object content is greater than the limit for the number of people using the object content at the same time (No in step S304), the CPU16 will notify the host 2-1 that it is unable to use the object content (step S310) and end the utilization control / start information recording process.
[0276] Through the above-described utilization control and start information recording process, the CPU 16 of the first storage system 3-1 can control the access of the first member 9-1 to the object content according to whether a specific condition is met (e.g., less than the limit for the number of users at the same time). Furthermore, when the specific condition is met, the CPU 16 can register the utilization start information indicating the start of access to the object content to the content utilization record management table 415-1.
[0277] Furthermore, CPU 16 sends a utilization start message to storage system 3 used by group members other than member 9-1. The utilization start message includes access logs and signature data generated using the first private key 411-1 for the access logs. Therefore, storage system 3 receiving the utilization start message can use the first public key 412-1 and the signature data to verify the authenticity of the access logs.
[0278] Furthermore, in the foregoing description, the utilization control and start information recording process is exemplified when access to content is requested for the first storage system 3-1, but the same utilization control and start information recording process is also performed when access to content is requested for other storage systems 3.
[0279] (Information recording and processing completed)
[0280] Figure 21This is a flowchart illustrating an example of the steps of completion information recording processing performed by the CPU 16 of the storage system 3. Completion information recording processing is a process for registering completion information indicating that a member has completed (ended) their use of the content to the content use record management table 415. The CPU 16 performs completion information recording processing, for example, in response to a member's completion of content use.
[0281] Here, an example is given of the case where information recording processing is performed in the first storage system 3-1. In this case, the CPU 16 of the first storage system 3-1 and the first member 9-1 perform information recording processing accordingly upon completion of access to the content (object content).
[0282] First, CPU16 generates an access log indicating that member 9-1 has completed its access to the object content (step S401). The generated access log includes, for example, the date and time of the access completion, the member name of member 9-1, and the content ID of the object content.
[0283] CPU 16 uses a specific hash function to calculate the hash value of the generated access log (step S402). CPU 16 generates signed data for the access log by encrypting the calculated hash value using the first private key 411-1 (step S403).
[0284] Next, CPU 16 updates the content utilization record management table 415-1 associated with the object content using the utilization completion information representing the access log, utilization completion, and signature data (step S404). Specifically, CPU 16 determines, for example, an entry in the content utilization record management table 415-1 associated with the object content that includes the member name of member 1 9-1. Then, CPU 16 sets the access log, the value indicating utilization completion (e.g., 0), and the signature data in the access log field, utilization status field, and signature data field of the determined entry, respectively.
[0285] CPU16 sends completion information to the storage system 3 used by group members other than member 9-1 via P2P communication I / F12 (step S405), and ends the completion information recording process.
[0286] Through the above completion information recording process, the CPU 16 of the first storage system 3-1 can register the utilization completion information indicating the completion of access to the content to the content utilization record management table 415-1.
[0287] Furthermore, CPU 16 sends a utilization completion message to storage system 3 used by group members other than member 9-1. The utilization completion message includes the access log and signature data generated using the first private key 411-1 for the access log. Therefore, storage system 3, upon receiving the utilization completion message, can use the first public key 412-1 and the signature data to verify the authenticity of the access log.
[0288] Furthermore, in the foregoing description, the control start information recording process is exemplified when the access to the content in the first storage system 3-1 is completed, but the same completion information recording process is also performed when the access to the content in the other storage systems 3 is completed.
[0289] (Verification and registration using records)
[0290] Figure 22 This is a flowchart illustrating an example of the steps of a utilization record verification and registration process performed by the CPU 16 of storage system 3. The utilization record verification and registration process is used to verify the authenticity of the access logs included in utilization record information received from another storage system 3 and to register the verified access logs in the content utilization record management table 415. The utilization record information is either utilization start information indicating the commencement of access to content or utilization completion information indicating the completion of access to content. The utilization record information includes access logs, values indicating the start or completion of utilization, and signature data for the access logs. The CPU 16 performs the utilization record verification and registration process, for example, in response to the utilization record information received from another storage system 3.
[0291] Here, an example is given of the second storage system 3-2 receiving the usage record information from another storage system 3.
[0292] First, the CPU 16 of the second storage system 3-2 uses a specific hash function to calculate the hash value of the access log included in the record information (hereinafter referred to as the 6th hash value) (step S501). Based on the member name included in the access log, the CPU 16 obtains the public key 412 corresponding to the member (hereinafter referred to as the 2nd object member) from the group public key management table 413-2 (step S502). The CPU 16 generates a hash value (hereinafter referred to as the 7th hash value) by decrypting the signature data included in the record information using the obtained public key 412 (step S503). Then, the CPU 16 determines whether the 6th hash value and the 7th hash value are equal (step S504). The 6th hash value and the 7th hash value being equal means that the authenticity of the access log is confirmed.
[0293] If the 6th hash value differs from the 7th hash value (No in step S504), CPU 16 terminates the access log verification and registration process. In other words, since CPU 16 has not verified the authenticity of the access log, it does not register the access log information in the content access log management table 415-2, and terminates the access log verification and registration process.
[0294] If the 6th hash value is equal to the 7th hash value ("Yes" in step S504), the CPU 16 uses the utilization record information to update the content utilization record management table 415-2 associated with the content ID included in the access log (step S505), and ends the utilization record verification and registration process. Specifically, the CPU 16, for example, determines the content utilization record management table 415-2 associated with the content ID included in the access log in one or more content utilization record management tables 415A, 415B, ... and 415M stored in the non-volatile memory 4, each corresponding to one or more contents. The CPU 16 determines an entry in the determined content utilization record management table 415-2 that includes the member name of the second object member. Then, the CPU 16 sets the access log included in the utilization record information, the value indicating the start or end of utilization, and the signature data in the access log field, utilization status field, and signature data field of the determined entry, respectively.
[0295] Through the above-described usage record verification and registration process, the CPU 16 of the second storage system 3-2 verifies the authenticity of the access logs included in the usage record information received from the other storage system 3. Furthermore, the CPU 16 registers the usage record information, including the verified access logs, in the content usage record management table 415-2. In other words, the CPU 16 can update the content usage record management table 415-2 using the usage record information including the verified access logs.
[0296] Furthermore, in the foregoing description, the example illustrates the usage record verification and registration process when the second storage system 3-2 receives usage record information from another storage system 3. However, the same usage record verification and registration process is also performed when other storage systems 3 receive usage record information from other storage systems 3.
[0297] As explained above, according to this embodiment, the use of content by members belonging to a group can be easily managed. Storage system 3 is used by the first user belonging to group 7. Controller 6 (e.g., P2P communication I / F 12, or near-field communication I / F 13) can communicate with one or more other storage systems 3 used by one or more users belonging to group 7 other than the first user. Key pair generation management unit 160 manages a first key pair including a first private key 411 and a first public key 412. Content management unit 163 stores one or more content information, each including one or more content items, in non-volatile memory 4. Content utilization control unit 165 generates a first access log related to utilization when the first user requests utilization of the first content item among one or more content items. Utilization record management unit 166 and signature unit 168 use the first private key 411 to generate first signature data for the first access log. The first access log and the first signature data are stored in non-volatile memory 4 using the record management unit 166 (for example, the content is stored in the record management table 415). The first access log and the first signature data are sent to one or more other storage systems 3 using the record transceiver unit 167.
[0298] Therefore, in each of the other storage systems 3, the first access log and the first signature data are stored in the non-volatile memory 4. That is, the first access log and the first signature data are shared among the multiple storage systems 3 used by multiple members belonging to group 7. Thus, each storage system 3 can easily manage the use of content by members belonging to group 7.
[0299] Furthermore, each storage system 3 can use the first signature data to verify the authenticity of the first access log. Therefore, each storage system 3 can use the access logs whose authenticity has been verified (i.e., highly reliable access logs) to securely manage the use of content by members belonging to group 7.
[0300] The various functions described in this embodiment can each be implemented by a circuit (processing circuit). Examples of processing circuits include a programmed processor such as a central processing unit (CPU). This processor executes the described functions by executing a computer program (command set) stored in memory. The processor can be a microprocessor that includes electrical circuitry. Examples of processing circuits also include digital signal processors (DSPs), application-specific integrated circuits (ASICs), microcontrollers, controllers, and other electrical circuit components. Other components besides the CPU described in this embodiment can also be implemented by the processing circuit.
[0301] Several embodiments of the present invention have been described, but these embodiments are provided by way of example and are not intended to limit the scope of the invention. These new embodiments can be implemented in a variety of other ways, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their variations are included in the scope and spirit of the invention, and are included in the scope of the invention as set forth in the claims and its equivalents.
Claims
1. A storage system used by the first user belonging to a group, comprising: Non-volatile memory; and The controller, electrically connected to the non-volatile memory, is capable of communicating with one or more other storage systems used by one or more users belonging to the group other than the first user. The controller is configured as follows: Manage the first key pair, which includes the first private key and the first public key. One or more pieces of content information, each containing more than one element, are stored in the non-volatile memory. If the first user is requested to use the first content among the more than one content, a first access log related to the use is generated. Use the first private key to generate the first signature data for the first access log. The first access log and the first signature data are stored in the non-volatile memory. The first access log and the first signature data are sent to one or more other storage systems.
2. The storage system according to claim 1, The more than one piece of content information includes the first piece of content information. The first content information includes the first content and information indicating the first condition that enables the use of the first content. The controller is configured such that, upon requesting the utilization, if the first condition is met, then... Generate the first access log. Generate the first signature data, The first access log and the first signature data are stored in the non-volatile memory. The first access log and the first signature data are sent to one or more other storage systems.
3. The storage system according to claim 1 or 2, The one or more other storage systems include a second storage system. The second storage system, Used by the second user among the aforementioned one or more users. Manage the second key pair, which includes the second private key and the second public key. The controller is further configured to, Send the first public key to the second storage system and receive the second public key from the second storage system. The first private key is used to generate second signature data for the second public key. The second public key information, representing the second user, the second public key, the first user, and the second signature data, will be sent to one or more other storage systems besides the second storage system.
4. The storage system according to claim 3, The controller is further configured to store the second public key information in the non-volatile memory.
5. The storage system according to claim 3, The controller is configured as follows: The first public key is sent to the second storage system via a first interface circuit for near-field communication, and the second public key is received from the second storage system. The second public key information is sent to one or more other storage systems other than the second storage system via the second interface circuit.
6. The storage system according to claim 3, The controller is further configured to, Receive information from the host that includes the second content. The second content information is stored in the non-volatile memory. The second content information is sent to one or more other storage systems.
7. The storage system according to claim 6, The controller is configured as follows: The first public key is sent to the second storage system via a first interface circuit for near-field communication, and the second public key is received from the second storage system. The second public key information is sent to one or more other storage systems other than the second storage system via the second interface circuit.
8. The storage system according to claim 7, The controller is configured to send the first access log and the first signature data to one or more other storage systems via the second interface circuit.
9. The storage system according to claim 8, The controller is configured as follows: The second content information is received from the host via the third interface circuit. The second content information is sent to one or more other storage systems via the second interface circuit.
10. A storage system used by the first user belonging to a group, comprising: Non-volatile memory; and The controller, electrically connected to the non-volatile memory, is capable of communicating with one or more other storage systems used by one or more users belonging to the group other than the first user. The one or more other storage systems include a second storage system. The second storage system is used by the second user among the more than one users. The controller is configured as follows: Manage the first key pair, which includes the first private key and the first public key. One or more pieces of content information, each containing more than one element, are stored in the non-volatile memory. The second storage system receives a first access log relating to the second user's use of the first content among the more than one types of content, and first signature data relating to the first access log. When the second public key information, representing the second user, the second public key, and the second signature data for the second public key, is stored in the non-volatile memory, the second public key and the first signature data are used to verify the authenticity of the first access log.
11. The storage system according to claim 10, The controller is further configured to, upon confirming the authenticity of the first access log, store the first access log and the second signature data in the non-volatile memory.
12. The storage system according to claim 10 or 11, The other storage systems mentioned above also include a third storage system. The third storage system is used by the third user among the more than one users. The controller is further configured to, Receive information from the second storage system representing the third user, the third public key, the second user, and third signature data for the third public key. Receive information representing the second user, the second public key, the third user, and the second signature data from the third storage system. Perform at least one of the following: verifying the authenticity of the second public key using the third public key and the second signature data, and verifying the authenticity of the third public key using the second public key and the third signature data.
13. The storage system according to claim 12, The controller is further configured to, Upon confirming the authenticity of the second public key, the second public key information, representing the second user, the second public key, the third user, and the second signature data, is stored in the non-volatile memory. If the authenticity of the third public key is confirmed, the information of the third public key representing the third user, the third public key, the second user, and the third signature data is stored in the non-volatile memory.
14. The storage system according to claim 10, The controller is further configured to, Send the first public key to the second storage system and receive the second public key from the second storage system. The first private key is used to generate the second signature data for the second public key. The second public key information, representing the second user, the second public key, the first user, and the second signature data, is stored in the non-volatile memory.
15. The storage system according to claim 14, The controller is configured as follows: The first public key is sent to the second storage system via a first interface circuit for near-field communication, and the second public key is received from the second storage system. The first access log and the first signature data are received from the second storage system via the second interface circuit.
16. The storage system according to claim 14, The controller is further configured to send the second public key information to one or more other storage systems besides the second storage system.
17. The storage system according to claim 16, The controller is configured as follows: The first public key is sent to the second storage system via a first interface circuit for near-field communication, and the second public key is received from the second storage system. The second public key information is sent to one or more other storage systems besides the second storage system via the second interface circuit. The first access log and the first signature data are received from the second storage system via the second interface circuit.
18. The storage system according to claim 14, The controller is further configured to, Receive second content information, including the second content, from the second storage system. The second content information is stored in the non-volatile memory.
19. The storage system according to claim 18, The controller is configured as follows: The first public key is sent to the second storage system via a first interface circuit for near-field communication, and the second public key is received from the second storage system. The second content information is received from the second storage system via the second interface circuit.
20. An information processing system comprising multiple storage systems used separately by multiple users belonging to a group. The plurality of storage systems includes a first storage system and a second storage system. The first storage system is used by the first user among the plurality of users. The second storage system is used by the second user among the plurality of users. The first storage system is configured as follows: Manage the first key pair, which includes the first private key and the first public key. One or more pieces of content information, each containing more than one item, are stored in the non-volatile memory within the first storage system. If the first user is requested to use the first content among the more than one content, a first access log related to the use is generated. Use the first private key to generate the first signature data for the first access log. The first access log and the first signature data are stored in the non-volatile memory. The first access log and the first signature data shall be sent to at least the second storage system. The second storage system is configured as follows: Receive the first access log and the first signature data from the first storage system. When the first public key information, representing the first user, the first public key, and the second signature data for the first public key, is stored in the non-volatile memory within the second storage system, the first public key and the first signature data are used to verify the authenticity of the first access log.