Information processing method, information processing system, and information processing program

JP2025006523A5Pending Publication Date: 2025-06-26DENSO CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2023107364
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-06-29
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Existing methods for secure computation in data exchange between client systems result in large encrypted data sizes, leading to increased calculation and communication costs, making data exchange inconvenient.

Method used

A data exchange system using hash values to verify data integrity, allowing data to be exchanged without encryption, thus reducing data size and associated costs, while maintaining data sovereignty and protecting trade secrets.

Benefits of technology

Ensures convenient data exchange by reducing calculation and communication costs, while ensuring data integrity and protecting trade secrets through hash value verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To provide an information processing method or the like capable of securing the convenience of data delivery between client systems.SOLUTION: A data exchange system 1 executes an information processing method to perform data delivery between client systems 150 associated with a lock chain platform 100 by using a data connector platform 140. In the case of providing a user system 150r with providing data DT from a provision source system 150m by using the data connector platform 140, a first hash value Hv1 to be generated by using the providing data DT is acquired from the provision source system 150m. Further, a second hash value Hv2 to be generated by using the providing data DT acquired by the user system 150r is acquired from the user system 150r. Then, alteration of the providing data DT is detected on the basis of comparison between the first hash value Hv1 and the second hash value Hv2.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The disclosure of this specification relates to an information processing technique for transferring data. [Background technology]

[0002] Patent Document 1 describes a method for transmitting data encrypted by secure computation in order to ensure data privacy. By using such secure computation, it becomes possible to protect data from unauthorized access and tampering while ensuring privacy. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] JP 2022-102062 A Summary of the Invention [Problem to be solved by the invention]

[0004] The method using secure computation disclosed in Patent Document 1 can also be applied to a system in which data is provided from a client system to a data storage platform. However, when data is exchanged between client systems, the size of the encrypted data increases even if the method using secure computation can protect the data while preserving the trade secret. As a result, the cost required for computation and communication increases, making it difficult to ensure the convenience of data exchange.

[0005] An object of the present disclosure is to provide an information processing method, an information processing system, and an information processing program that can ensure the convenience of data transfer between client systems. [Means for solving the problem]

[0006] In order to achieve the above-mentioned object, one disclosed aspect is an information processing method for transferring data between multiple client systems (150) linked to a data storage platform (100), which includes the steps of, when providing data (DT) from a source system (150m) to a user system (150r) using a data providing platform (140), obtaining a first hash value (Hv1) generated using the data to be provided from the source system (S20), obtaining a second hash value (Hv2) generated using the data to be provided obtained by the user system from the user system (S163), and detecting tampering with the data to be provided based on a comparison between the first hash value and the second hash value (S165, S183) in a process executed by at least one processor (11).

[0007] Another disclosed aspect is an information processing system that transfers data between multiple client systems (150) linked to a data storage platform (100), and when providing data (DT) from a source system (150m) to a user system (150r) using a data providing platform (140), the information processing system includes a first acquisition unit (51a) that acquires a first hash value (Hv1) generated using the data to be provided from the source system, a second acquisition unit (51b) that acquires a second hash value (Hv2) generated using the data to be provided acquired by the user system, and a detection unit (33, 53) that detects tampering with the data to be provided based on a comparison between the first hash value and the second hash value.

[0008] Another disclosed aspect is an information processing program for transferring data between multiple client systems (150) linked to a data storage platform (100), which, when providing data (DT) from a source system (150m) to a user system (150r) using a data providing platform (140), causes at least one processor (11) to execute processing including: obtaining from the source system (S20) a first hash value (Hv1) generated using the data to be provided; obtaining from the user system (S163) a second hash value (Hv2) generated using the data to be provided obtained by the user system; and detecting tampering with the data to be provided based on a comparison between the first hash value and the second hash value (S165, S183).

[0009] In these aspects, since a data providing platform is used to provide data from a provider system to a user system, trade secrets can be kept in the data storage platform. In addition, since tampering with the data to be provided can be detected by comparing hash values, the data to be provided can be protected. Furthermore, since the data to be provided and each hash value are smaller in size than the encrypted data for secret calculation, an increase in the cost required for calculation and communication can be avoided. Therefore, it is possible to ensure the convenience of data transfer between client systems.

[0010] In addition, the reference numbers in parentheses in the above and claims merely show an example of the correspondence with the specific configurations in the embodiments described below, and do not limit the technical scope in any way. In addition, claims that are not explicitly stated in the claims can be combined together as long as there is no particular problem with the combination. [Brief description of the drawings]

[0011] [Figure 1] FIG. 1 is a block diagram showing an overall view of a blockchain platform on which an information processing method according to an embodiment of the present disclosure is executed. [Diagram 2] 10 is a diagram for explaining details of the delivery of provision data realized by the data exchange system. FIG. [Diagram 3] 13 is a flowchart showing details of a registration process of data to be provided that is performed by a providing source system. [Figure 4] 13 is a sequence diagram showing details of a sub-process of registering data to be provided in a data connector. [Diagram 5] 13 is a flowchart showing details of a process for acquiring data to be provided, which is carried out by a user system. [Figure 6] 13 is a sequence diagram showing details of a sub-process of acquiring data to be provided from a data connector. [Figure 7] FIG. 13 is a sequence diagram showing details of a sub-process for confirming that data to be provided has not been tampered with. [Figure 8] 13 is a flowchart showing details of a tamper check process performed on past data to be provided. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0012] A blockchain platform 100 according to an embodiment of the present disclosure shown in FIG. 1 enables information sharing between participating clients (e.g., companies, etc.) using blockchain BC technology. A general-purpose blockchain BC platform such as Hyperledger Fabric is used for the blockchain platform 100. The blockchain platform 100 can build a private blockchain network (hereinafter, a channel) in which only specific participants can participate in the network and share data and transactions. As a result, it is possible to satisfy the privacy and confidentiality requirements of each participant.

[0013] The blockchain platform 100 includes multiple nodes 50 and at least one access gateway 30. As an example, each node 50 and access gateway 30 is constructed by a blockchain server (virtual machine) on the cloud. The blockchain server is mainly configured with a control circuit 10. The control circuit 10 includes a processor 11, a RAM 12, a storage 13, an input / output interface 14, and a bus connecting these, and functions as a high-performance computer that performs calculation processing at high speed.

[0014] The processor 11 is hardware for arithmetic processing coupled with the RAM 12. The processor 11 executes various processes (instructions) related to data management and provision by accessing the RAM 12. The storage 13 stores an information processing program that realizes functions related to data management and provision. The information processing program is a program for causing the blockchain server (control circuit 10) to execute the information processing method of the present disclosure.

[0015] The node 50 is a blockchain management system linked to each client system 150. As an example, in a blockchain network that manages vehicle information, the clients are an automobile manufacturer (original equipment manufacturer, OEM) that manufactures the vehicles, and a dealer that sells the vehicles. Among the multiple nodes 50, the node 50 that cooperates with the OEM's management system (OEM system 160) is the OEM node 60. Also, the node 50 that cooperates with the dealer's management system (dealer system 180) is the dealer node 80.

[0016] The OEM node 60 includes an OEM database 70. The OEM database 70 stores data to be stored DS associated with the OEM, and enables the data to be stored DS to be shared with other nodes 50. Similarly, the dealer node 80 includes a dealer database 90. The dealer database 90 stores data to be stored DS associated with the dealer, and enables the data to be stored DS to be shared with other nodes 50. The data to be stored DS is data that is stored and shared in the blockchain platform 100 using blockchain BC technology. The data to be stored DS is collected in each client system 150, and transmitted to the node 50 associated with each client system 150.

[0017] The node 50 accepts new registration requests, update requests, reference requests, deletion requests, etc., for the data DS to be archived from the client system 150. The node 50 is equipped with a data registration unit 51. The data registration unit 51 is a functional unit constructed in the node 50. The data registration unit 51 accepts new registration requests for the data DS to be archived from the client system 150. The data registration unit 51 executes registration processing for the data DS to be archived based on the registration request.

[0018] The data registration unit 51 stores the data DS to be stored in a specific channel of the blockchain BC. The channel of the blockchain BC that stores the data DS to be stored is a public channel that shares data with other nodes 50 and the access gateway 30. The data DS to be stored as transactions is stored in each block that constitutes the blockchain BC. In the blockchain BC, a hash value generated from one block is stored in the next block. Furthermore, timestamp data indicating the date and time when the data DS to be stored was added is recorded in each block.

[0019] The access gateway 30 is provided separately from each node 50, and manages access to the blockchain platform 100 by an external system or a user (user terminal 110). The access gateway 30 performs authentication and authorization for a connection to the blockchain platform 100 by the external system or the user terminal 110. The access gateway 30 includes a data acquisition unit 31 and a gateway database 40.

[0020] The data acquisition unit 31 is a functional unit constructed in the access gateway 30. The data acquisition unit 31 acquires a reference request for the storage target data DS stored by the blockchain BC from an external system, a user terminal 110, etc. The data acquisition unit 31 generates reference data from the storage target data DS based on the reference request, and provides the generated reference data to the external system or user terminal 110 that is the request source.

[0021] The gateway database 40 is a data storage area that stores information related to the access gateway 30. At least a portion of the data stored in the gateway database 40 is shared with the OEM database 70, the dealer database 90, etc., by the function of the blockchain BC.

[0022] [Details of the data exchange system] The client system 150 and the blockchain platform 100 described above, together with the data connector platform 140, constitute the data exchange system 1 shown in Fig. 2. The data exchange system 1 is a system for responding to the needs of clients who cannot trust the operator of the blockchain platform 100 and do not want to hand over their trade secrets (raw data) to the blockchain platform 100.

[0023] The data exchange system 1 enables data to be exchanged between multiple client systems 150 linked to the blockchain platform 100 without passing through the blockchain platform 100. In the data exchange system 1, the data sharing function between clients using data connector technology is combined with a tamper checking function using blockchain technology. In the data exchange system 1, the sovereignty of each client's data is protected, and the authenticity (trustworthiness) of the data being exchanged is also guaranteed.

[0024] The client system 150 is mainly configured with a server device. The server device is an arithmetic processing device equipped with a processor, RAM, storage, etc. The client system 150 uses client databases such as an OEM database 170 and a dealer database 190 to individually store client data including trade secrets. As an example, the client database is constructed in an object storage provided on the cloud. The object storage is a storage that stores files and data as objects, and is capable of permanently storing large amounts of data. As the object storage, for example, S3 (Simple Storage Service) of AWS (Amazon Web Services, registered trademark) and Azure Blob Storage of Azure (registered trademark) can be used.

[0025] The client system 150 transfers data between the other client systems 150 via the data connector platform 140. As an example, data (hereinafter, data to be provided DT) may be transferred from the OEM system 160 to the dealer system 180. In this case, the OEM system 160 is the provider system 150m, and the dealer system 180 is the user system 150r.

[0026] In addition, in the blockchain platform 100 that manages vehicle information, approval information, asset information, access information, ID information, public key information, etc. are collected by the client system 150 along with vehicle information. This vehicle information may include the vehicle identification number, model year, grade, vehicle name, mileage, collision detection results, registration inspection results, registration photos, and appraisal price. Among these pieces of information, information that corresponds to a trade secret, in other words, information that is not to be included in the storage target data DS, may be appropriately determined at the discretion of clients such as OEMs and dealers.

[0027] The client system 150 functioning as the provider system 150m and the user system 150r has a data connector 153 and a data management unit 151. The data connector 153 is a functional unit (data-connect-manager) for using the data connector platform 140. The data management unit 151 is a functional unit for using the blockchain platform 100.

[0028] The data connector 153 of the provider system 150m (OEM system 160) registers at least a portion of various client data (OEM data) corresponding to trade secrets in the data connector platform 140. The data connector 153 registers client data that can be provided to other clients as provision data DT, and links the provision data DT with unique identification information (hereinafter, data ID) that identifies the provision data DT and registers the data in the data connector platform 140 (FIG. 2 S10). The data ID may be general ID information issued by a specific ID issuer, or may be a decentralized ID (DID) issued using blockchain BC technology. The data connector 153 may register metadata or the like indicating the contents of the provision data DT in the data connector platform 140 instead of the data body of the provision data DT.

[0029] The data management unit 151 of the provider system 150m selects information that does not fall under the category of trade secrets from among the client data (OEM data) managed by the OEM system 160 as data to be stored DS. The data management unit 151 registers the selected data to be stored DS in the blockchain platform 100.

[0030] When cloud data corresponding to a trade secret is registered in the data connector platform 140 as data to be provided DT, the data management unit 151 generates a first hash value Hv1. The first hash value Hv1 is a hash value generated using the data to be provided DT registered in the data connector platform 140. The first hash value Hv1 is data in which a predetermined number of bits (for example, 256 bits) is maintained, and is a unique value reflecting the contents of the data to be provided DT. The data management unit 151 calculates the first hash value Hv1 by a calculation process in which the data to be provided DT is substituted into a hash function such as SHA-256. The data management unit 151 links the first hash value Hv1 to a data ID that identifies the original data (data to be provided DT) and uploads it to the OEM node 60 (FIG. 2, S20). The data registration unit 51 of the OEM node 60 performs a step of acquiring the first hash value Hv1 and the data ID based on a request from the data management unit 151. The data registration unit 51 registers the first hash value Hv1 acquired from the provider system 150m in the blockchain platform 100 in a state in which it is linked to the data ID.

[0031] The data connector 153 of the user system 150r (dealer system 180) can obtain trade secrets for other clients via the data connector platform 140. When obtaining a trade secret of another client, the data connector 153 obtains a file list FL from the data connector platform 140 (FIG. 2, S30).

[0032] The file list FL records what data other client systems 150 possess. That is, the file list FL shows a list of the data to be provided DT that can be acquired through the data connector platform 140. This file list FL further includes a data ID for identifying each piece of data. The data connector 153 searches the file list FL and identifies whether the data required by its own client (dealer) can be acquired from the data connector platform 140, from which client system 150 the data can be acquired, and so on.

[0033] When the data connector 153 is able to search for the required data from the file list FL, it extracts the data ID associated with the searched data, in other words, the data ID indicating the data to be provided DT, from the file list FL. The data connector 153 acquires the desired data to be provided DT from the data connector platform 140 by specifying the data ID (FIG. 2, S40). When the data connector platform 140 does not store the data body of the data to be provided DT, the data connector 153 may acquire the data body of the data to be provided DT from the data connector 153 of the provider system 150m.

[0034] The data management unit 151 of the user system 150r, like the data management unit 151 of the provider system 150m, selects client data (dealer data) that does not fall under a trade secret as data to be stored DS. The data management unit 151 registers the selected data to be stored DS in the blockchain platform 100. In addition, when the data connector 153 acquires the data to be provided DT from the data connector platform 140, the data management unit 151 generates history information Hi and a second hash value Hv2.

[0035] The history information Hi is information indicating details of the delivery of the provision data DT from the provider system 150m to the user system 150r via the data connector platform 140. The history information Hi records at least information such as what content of the provision data DT and when the user system 150r acquired it, and which client system 150 provided the acquired provision data DT. A data ID may be used as information indicating the content of the provision data DT. The data management unit 151 registers the generated history information Hi in the blockchain platform 100 (FIG. 2, S50).

[0036] The second hash value Hv2 is a hash value generated using the provision data DT acquired by the data connector 153. The second hash value Hv2 is data in which a predetermined number of bits (for example, 256 bits) is maintained, and is a unique value that reflects the contents of the provision data DT. The data management unit 151 calculates the second hash value Hv2 using the hash function used by the data management unit 151 of the providing system 150m to generate the first hash value Hv1. That is, the hash function used to generate the second hash value Hv2 is the same as the hash function used to generate the first hash value Hv1. The data management unit 151 links the second hash value Hv2 to a data ID and registers it in the blockchain platform 100 (FIG. 2, S60).

[0037] Instead of SHA-256, an encryption algorithm (hash function) such as SHA-1, SHA-2, or SHA-3 may be used to generate the first hash value Hv1 and the second hash value Hv2.

[0038] The blockchain platform 100 guarantees the authenticity of the provision data DT exchanged (data exchanged) between each client system 150 in a system in which trade secrets are managed in a distributed manner for each client. In addition to the above-mentioned data registration unit 51, the node 50 has a tamper checking unit 53. For convenience, the data registration unit 51 of the node 50 (OEM node 60) linked to the provider system 150m is referred to as the "first data registration unit 51a." Furthermore, the data registration unit 51 of the node 50 (dealer node 80) linked to the user system 150r is referred to as the "second data registration unit 51b."

[0039] The first data registration unit 51a acquires, from the client system 150 (provider system 150m), a large number of first hash values ​​Hv1 generated using the provision data DT registered in the data connector platform 140, together with the data ID. The first data registration unit 51a associates the first hash value Hv1 with the data ID and stores it in the OEM database 70.

[0040] The second data registration unit 51b acquires the second hash value Hv2 generated using the provision data DT acquired by the client system 150 (user system 150r) from this user system 150r. The second data registration unit 51b acquires the second hash value Hv2 together with a data ID that identifies the provision data DT. The second data registration unit 51b associates the second hash value Hv2 with the data ID and stores it in the dealer database 90.

[0041] The second data registration unit 51b acquires, from the user system 150r, history information Hi that records the exchange of the data DT to be provided by the data connector platform 140 and each data connector 153. The second data registration unit 51b stores the history information Hi in the dealer database 90 in a state in which it is linked to the second hash value Hv2 and its data ID.

[0042] Furthermore, the first hash value Hv1, the second hash value Hv2, the data ID, and the history information Hi stored in the OEM database 70 and the dealer database 90 are registered in the blockchain BC and are protected to make them difficult to tamper with.

[0043] The tampering check unit 53 is a functional unit of the blockchain platform 100. The tampering check unit 53 detects tampering of the provision data DT based on a comparison between the first hash value Hv1 and the second hash value Hv2. The tampering check process of the provision data DT is performed by the tampering check unit 53 of the node 50 (the dealer node 80 in FIG. 2) linked to the user system 150r. The tampering check unit 53 uses the data ID acquired by the second data registration unit 51b to extract the first hash value Hv1 linked to the provision data DT delivered this time from among the multiple first hash values ​​Hv1 registered in the blockchain BC.

[0044] In this way, the tampering check unit 53 prepares the first hash value Hv1 and the second hash value Hv2 so as to be comparable. If the first hash value Hv1 and the second hash value Hv2 are the same value, the tampering check unit 53 determines that the data to be provided DT has not been tampered with. On the other hand, if the first hash value Hv1 and the second hash value Hv2 are different values, the tampering check unit 53 determines that the data to be provided DT has been tampered with.

[0045] The data connector platform 140 cooperates with each data connector 153 of each client system 150 to enable data exchange between the client systems 150. For example, data sharing ecosystems such as Gaia-X and Catena-X can be used in the data connector platform 140. The data connector platform 140 has a function for registering the client systems 150 and manages the connection to the data connector platform 140 by the data connectors 153.

[0046] The data connector platform 140 protects the data sovereignty of each client. Even when the data to be provided DT is handed over from the providing system 150m to the user system 150r, the data connector platform 140 leaves the data sovereignty of the data to be provided DT in the providing system 150m. Data sovereignty is a concept that encompasses ownership and management rights over data. By leaving data sovereignty in the providing system 150m, the providing system 150m has the right to control (restrict) the storage, editing, deletion, use, sharing, etc. of the data to be provided DT.

[0047] [Details of the processing carried out in the data exchange system] Next, details of the registration process and acquisition process carried out in the data exchange system 1 described above will be described based on FIGS. 3 to 7 with reference to FIG.

[0048] The registration process of the data to be provided DT shown in Fig. 3 is mainly performed by the providing system 150m. In S10, the data management unit 151 and the data connector 153 of the providing system 150m register client data that can be provided to other client systems 150 as data to be provided DT in the data connector platform 140. Furthermore, in S20, the data management unit 151 registers the first hash value Hv1 based on the data to be provided DT registered in the data connector platform 140, together with the data ID, in the blockchain platform 100. Note that the order of performing S10 and S20 in the registration process may be reversed.

[0049] In S101 of the sub-process of the registration process (S10) shown in Fig. 4, the data management unit 151 acquires a trigger for registering the data to be provided DT. As one example, when a user (worker) belonging to a client performs a user operation to instruct data registration, the data registration unit 51 acquires a registration trigger. As another example, the data registration unit 51 also acquires a registration trigger when acquiring client data of a type to be registered in advance.

[0050] In S102 and S103, the data management unit 151 registers the data assets and data policies of the provision data DT to be registered in the data connector 153. Furthermore, in S104, the data management unit 151 registers a contract definition in the data connector 153. The contract definition is information indicating the conditions and rules related to the data exchange of the provision data DT to be registered.

[0051] In S105, the data management unit 151 uploads the data body of the data to be provided DT to the data connector 153. In S106, the data management unit 151 presents the registration result of the data to be provided DT to the user, and stores the registration history in the client database. As a result, the data to be provided DT can be transferred using the data connector 153 and the data connector platform 140.

[0052] The process of acquiring the provision data DT shown in Fig. 5 is performed mainly by the user system 150r. In S30, the data management unit 151 and the data connector 153 of the user system 150r acquire a file list FL from the data connector platform 140. Furthermore, in S40, the data management unit 151 and the data connector 153 acquire the necessary provision data DT.

[0053] In S50, the data management unit 151 generates history information Hi indicating the acquisition history of the data to be provided DT, and registers it in the block chain platform 100. Furthermore, in S60, the data management unit 151 cooperates with the data registration unit 51 of the node 50 (dealer node 80) to check whether the data to be provided DT acquired in S40 has been tampered with.

[0054] In S131 of the sub-process of the acquisition process (S30, S40) shown in FIG. 6, the data management unit 151 acquires a trigger to acquire the file list FL. As an example, when a user (worker) belonging to a client performs a user operation to instruct acquisition of the file list FL, the data registration unit 51 acquires the acquisition trigger. In S132, the data management unit 151 requests the data connector 153 to provide the file list FL. The data connector 153 cooperates with the data connector platform 140, and in S133, provides the file list FL to the data management unit 151. In S134, the data management unit 151 presents the contents of the file list FL to the user and stores the file list FL in the client database.

[0055] In S141, the data management unit 151 specifies the data to be provided DT to be acquired. As an example, the data management unit 151 determines the data to be provided DT based on a user operation. In S142, the data management unit 151 requests the provision of the data to be provided DT to be acquired by notifying the data connector 153 of the data ID. The data connector 153 cooperates with the data connector platform 140, and in S143, provides the specified data to be provided DT to the data management unit 151. In S144, the data management unit 151 presents the acquisition result of the data to be provided DT to the user, and stores the data to be provided DT in the client database.

[0056] 7, a sub-process of the acquisition process (S60) performs a tamper check on the data to be provided DT. Specifically, in S161, the data management unit 151 generates a second hash value Hv2 based on the data to be provided DT acquired in S40. In S162, the data management unit 151 transmits a request to perform tamper detection to the data connector 153. In S163, the data management unit 151 transmits a data ID and the second hash value Hv2 required for tamper detection to the tamper check unit 53.

[0057] In S163, the tamper checking unit 53 executes a step of acquiring a data ID and a second hash value Hv2. In S164, the tamper checking unit 53 extracts a first hash value Hv1 linked to the acquired data ID from the information shared by the blockchain BC, and prepares the first hash value Hv1 and the second hash value Hv2 so as to be comparable. Then, in S165, the tamper checking unit 53 detects tampering of the data to be provided DT based on a comparison between the first hash value Hv1 and the second hash value Hv2. In S166, the tamper checking unit 53 notifies the data management unit 151 of the tampering detection result.

[0058] In S166, the data management unit 151 acquires the result of the tampering detection by the tampering check unit 53. In S167, the data management unit 151 presents the acquired detection result to the user and also stores this detection result in the client database.

[0059] [Checking for tampering with past data exchanges] The access gateway 30 shown in Fig. 1 includes a tamper checking unit 33 in addition to a data acquiring unit 31. The tamper checking unit 33 is a functional unit of the blockchain platform 100. The tamper checking unit 33 has a tamper detection function similar to that of the tamper checking unit 53 provided in the node 50. The tamper checking unit 33 verifies whether or not tampering has been performed on past data exchanges performed in the data exchange system 1, in other words, on past provision data DT.

[0060] Hereinafter, the details of the tamper check process performed by the tamper check unit 33 for past data exchange will be described based on Fig. 8 with reference to Fig. 1 and Fig. 2. The tamper check process shown in Fig. 8 is started based on a tamper check request acquired by the data acquisition unit 31, for example.

[0061] In S181 of the falsification check process, the falsification check unit 33 acquires history information Hi of the data exchange carried out by the data exchange system 1 from the information shared by the blockchain BC. Based on the history information Hi, the falsification check unit 33 grasps the data ID of the provision data DT that was handed over in the past data exchange.

[0062] In S182, the tamper checking unit 33 uses the data ID to obtain the first hash value Hv1 uploaded from the provider system 150m and the second hash value Hv2 uploaded from the user system 150r. In S182, the first hash value Hv1 and the second hash value Hv2 are prepared so as to be comparable by data sharing using the blockchain BC. The tamper checking unit 33 extracts the first hash value Hv1 and the second hash value Hv2 that correspond to each other for all data exchanges that have been performed in the past.

[0063] In S183, the tampering check unit 33 detects tampering of the data to be provided DT based on a comparison between the first hash value Hv1 and the second hash value Hv2. When the tampering check unit 33 detects an inconsistency (mismatch) between the first hash value Hv1 and the second hash value Hv2 for at least a portion of the data exchange (S183: YES), it determines in S184 that there is a possibility of tampering. In this case, in S186, the tampering check unit 33 transmits a check result indicating that there is a possibility of tampering to the external system or user terminal 110 that is the source of the tampering check request.

[0064] On the other hand, if the first hash value Hv1 and the second hash value Hv2 match (S183: NO) for all data exchanges, the tampering check unit 33 determines in S185 that there is no possibility of tampering and that the data is normal. In this case, the tampering check unit 33 transmits a check result indicating that no tampering was detected to the external system or user terminal 110, which is the source of the tampering check, in S186.

[0065] (Summary of embodiments) In the embodiment described so far, since the data connector platform 140 is used for data provision from the provider system 150m to the user system 150r, trade secrets can be held for the blockchain platform 100. In addition, since tampering of the data to be provided DT can be detected by comparing hash values, it is possible to protect the data to be provided DT. Furthermore, since the data to be provided DT, the first hash value Hv1, and the second hash value Hv2 are smaller in size than the encrypted data for secret calculation, it is possible to avoid an increase in the cost required for calculation and communication. Therefore, it is possible to ensure the convenience of data transfer between the client systems 150.

[0066] In addition, in this embodiment, the sovereignty of the data to be provided DT remains with the provider system 150m even when the data to be provided DT is provided from the provider system 150m to the user system 150r. Therefore, even if data exchange between the client systems 150 is possible, the data sovereignty of the client data that is a trade secret can be protected.

[0067] In this embodiment, in the blockchain platform 100, the first hash value Hv1 and the second hash value Hv2 are prepared in a comparable manner by data sharing using the blockchain BC. As described above, by using the blockchain BC technology for data sharing, the first hash value Hv1 and the second hash value Hv2 can be protected from tampering. Therefore, tampering detection of the provision data DT using these hash values ​​can be performed more accurately.

[0068] As described above, in this embodiment, the data sovereignty of the data provider system 150m is protected by utilizing the data connector technology. Furthermore, the blockchain BC technology is utilized to ensure that the delivered data DT has not been tampered with. Therefore, a data exchange system 1 that achieves both the protection of data sovereignty and the assurance of data authenticity can be realized.

[0069] Furthermore, in this embodiment, the process of detecting tampering of the data to be provided DT is performed based on the user system 150r receiving the data to be provided DT via the data connector platform 140 (see FIG. 5, S60). As a result, the user system 150r can quickly determine that the acquired data to be provided DT has not been tampered with.

[0070] In addition, the blockchain platform 100 of this embodiment acquires history information Hi of the delivery of the provision data DT from the provider system 150m to the user system 150r via the data connector platform 140 (see FIG. 5, S50). Therefore, even in a system configuration in which the blockchain platform 100 is not directly involved in the delivery of the provision data DT, it is possible to leave the history of the exchange of the provision data DT under the protection of the blockchain BC.

[0071] In this embodiment, a process for detecting tampering of past data to be provided DT is performed based on the history information Hi (see FIG. 8). As a result, a third party that does not exchange data to be provided DT can check at an appropriate time whether tampering has occurred in past data exchanges.

[0072] Specifically, the source system 150m registers in the history information Hi a hash value of information about when and to whom what data was sent. Also, the user system 150r registers in the history information Hi a hash value of information about when and from whom what data was received. According to such a tampering detection process that collectively checks the past history information Hi, in addition to ensuring the authenticity of the data itself, it becomes possible to confirm that the data exchange time, exchange approval information, etc. have not been tampered with.

[0073] In the above embodiment, the falsification check unit 33 and the falsification check unit 53 correspond to the "detection unit", the first data registration unit 51a corresponds to the "first acquisition unit", and the second data registration unit 51b corresponds to the "second acquisition unit". In addition, the data exchange system 1 corresponds to the "information processing system", the blockchain platform 100 corresponds to the "data storage platform", and the data connector platform 140 corresponds to the "data provision platform".

[0074] (Other embodiments) Although one embodiment of the present disclosure has been described above, the present disclosure should not be construed as being limited to the above embodiment, and can be applied to various embodiments and combinations within the scope not departing from the gist of the present disclosure.

[0075] In the first modification of the above embodiment, a data storage platform that does not use the blockchain BC technology is used instead of the above-mentioned blockchain platform 100. In the second modification of the above embodiment, the tamper detection process at the timing when the provision data DT is handed over is performed by the tamper check unit 33 of the access gateway 30 instead of the tamper check unit 53 of each node 50.

[0076] The timing of the step of detecting tampering of the data to be provided DT may be changed as appropriate. For example, in the third modification of the above embodiment, only the tampering detection process is performed when the data to be provided DT is handed over, and the tampering detection process for past data exchange based on a request from a third party or the like is not performed. That is, the tampering check unit 33 of the access gateway 30 is omitted.

[0077] In the fourth modification of the above embodiment, only the tamper detection process is performed for past data exchanges based on a request from a third party, and the tamper detection process is not performed at the timing of delivery of the data DT. That is, the tamper check unit 53 of each node 50 is omitted.

[0078] In the fifth modification of the above embodiment, instead of the user system 150r, the data connector platform 140 provides the data exchange history information Hi to the blockchain platform 100. In the sixth modification of the above embodiment, instead of the user system 150r or together with the user system 150r, the provider system 150m provides the history information Hi to the blockchain platform 100.

[0079] In the above embodiment, each function provided by the client system 150, etc. can be provided by software and hardware that executes it, software only, hardware only, or a combination of these. Similarly, each function provided by the access gateway 30 and the node 50, etc. can be provided by software and hardware that executes it, software only, hardware only, or a combination of these. And when these functions are provided by electronic circuits as hardware, each function can also be provided by digital circuits including a large number of logic circuits, or analog circuits.

[0080] The processor of the above embodiment may be configured to include at least one arithmetic core such as a CPU (Central Processing Unit) and a GPU (Graphics Processing Unit). The processor may further include an FPGA (Field-Programmable Gate Array), an NPU (Neural network Processing Unit), and an IP core having other dedicated functions. The processor is not limited to a chip configuration individually mounted on a printed circuit board. The processor may be implemented in an ASIC (Application Specific Integrated Circuit), an SoC (System on Chip), an FPGA, or the like.

[0081] The form of the recording medium (non-transitory tangible storage medium) employed as the storage in the above embodiment and storing each program may be changed as appropriate. For example, the recording medium is not limited to a configuration provided on a circuit board, and may be provided in the form of a memory card or the like, inserted into a slot, and electrically connected to a computer bus. Furthermore, the recording medium may be an optical disk, a hard disk drive, a solid state drive, or the like used as a source from which a program is copied or distributed to a computer.

[0082] The control unit and the method described herein may be implemented by a special-purpose computer having a processor programmed to execute one or more functions embodied in a computer program. Alternatively, the device and the method described herein may be implemented by a special-purpose hardware logic circuit. Alternatively, the device and the method described herein may be implemented by one or more special-purpose computers configured by a combination of a processor that executes a computer program and one or more hardware logic circuits. The computer program may also be stored in a computer-readable non-transitory tangible recording medium as instructions to be executed by the computer.

[0083] (Disclosure of technical ideas) This specification discloses multiple technical ideas described in the following multiple dependent claims. Some of the claims may be described in a multiple dependent form, where the subsequent claim alternatively refers to the preceding claim. Furthermore, some of the claims may be described in a multiple dependent form, where the subsequent claim alternatively refers to the preceding claim. The claims described in these multiple dependent forms define multiple technical ideas.

[0084] (Technical thought 1) An information processing method for transferring data between a plurality of client systems (150) linked to a data storage platform (100), comprising: When providing data (DT) from a data providing system (150m) to a user system (150r) using a data providing platform (140), a first hash value (Hv1) generated using the data to be provided is obtained from the data providing system (S20); A second hash value (Hv2) generated using the data to be provided acquired by the user system is acquired from the user system (S163); detecting falsification of the data to be provided based on a comparison between the first hash value and the second hash value (S165, S183); The information processing method includes the steps of: (Technical thought 2) An information processing method according to technical idea 1, in which the sovereignty of the data to be provided remains with the source system even when the data to be provided is provided from the source system to the user system. (Technical Thought 3) The information processing method described in Technical Idea 1 or 2 further includes a step of preparing the first hash value and the second hash value in a comparable manner (S164, S182) by sharing data using a blockchain (BC) in the data storage platform. (Technical Thought 4) An information processing method described in any one of technical ideas 1 to 3, in which the step of detecting tampering with the provision data is carried out based on the user system receiving the provision data via the data provision platform. (Technical Thought 5) The information processing method described in any one of technical ideas 1 to 4 further includes a step of acquiring (S50) historical information (Hi) of the delivery of the data to be provided from the source system to the user system via the data providing platform. (Technical Thought 6) The information processing method according to technical idea 5, in which the step of detecting tampering with the data to be provided is performed on past data to be provided based on the history information. (Technical Thought 7) An information processing system for transferring data between a plurality of client systems (150) linked to a data storage platform (100), a first acquisition unit (51a) that acquires a first hash value (Hv1) generated by using the data to be provided (DT) from a data providing system (150m) to a user system (150r) using a data providing platform (140), from the data providing system; a second acquisition unit (51b) that acquires from the user system a second hash value (Hv2) that is generated using the data to be provided acquired by the user system; a detection unit (33, 53) that detects tampering with the data to be provided based on a comparison between the first hash value and the second hash value; An information processing system comprising: (Technical Thought 8) A storage medium that stores an information processing program for transferring data between a plurality of client systems (150) linked to a data storage platform (100) and is readable by a computer (10), The information processing program includes: When providing data (DT) from a data providing system (150m) to a user system (150r) using a data providing platform (140), a first hash value (Hv1) generated using the data to be provided is obtained from the data providing system (S20); A second hash value (Hv2) generated using the data to be provided acquired by the user system is acquired from the user system (S163); detecting falsification of the data to be provided based on a comparison between the first hash value and the second hash value (S165, S183); A storage medium configured to cause at least one processor (11) to perform processes including: [Explanation of symbols]

[0085] 1 data exchange system, 11 processor, 33, 53 tamper checking unit (detection unit), 51a first data registration unit (first acquisition unit), 51b second data registration unit (second acquisition unit), 100 blockchain platform (data storage platform), 140 data connector platform (data provision platform), 150 client system, 150m provider system, 150r user system, BC blockchain, DT data to be provided, FL file list, Hi history information, Hv1 first hash value, Hv2 second hash value

Claims

1. An information processing method for transferring data among a plurality of client systems (150) associated with a data storage platform (100), when using a data providing platform (140) that protects the data sovereignty for each client to provide the data for use (DT) from a source system (150m) to a user system (150r) while leaving the sovereignty of the data for use, obtaining a first hash value (Hv1) generated using the data for use from the source system (S20), obtaining a second hash value (Hv2) generated using the data for use obtained by the user system from the user system (S163), detecting forgery of the data for use based on comparison of the first hash value and the second hash value (S165, S183), wherein the information processing method includes a process executed by at least one processor (11).

2. The information processing method according to claim 1, further including the step of preparing to be able to compare the first hash value and the second hash value by sharing data using a blockchain (BC) in the data storage platform (S164, S182).

3. The information processing method according to claim 1, wherein the step of detecting forgery of the data for use is performed based on the user system receiving the data for use via the data providing platform.

4. The information processing method according to claim 1, further including the step of obtaining history information (Hi) of the transfer of the data for use from the source system to the user system via the data providing platform (S50).

5. The information processing method according to claim 4, wherein the step of detecting forgery of the data for use is performed on the data for use in the past based on the history information.

6. An information processing system for transferring data among a plurality of client systems (150) associated with a data storage platform (100), When providing the data for provision (DT) from the source system (150m) to the user system (150r) while leaving the sovereignty of the data for provision to the data provision platform (140) that protects the data sovereignty for each client, a first acquisition unit (51a) that acquires a first hash value (Hv1) generated using the data for provision from the source system; a second acquisition unit (51b) that acquires a second hash value (Hv2) generated using the data for provision acquired by the user system from the user system; a detection unit (33, 53) that detects falsification of the data for provision based on comparison of the first hash value and the second hash value; An information processing system comprising.

7. An information processing program for transferring data among a plurality of client systems (150) associated with a data storage platform (100), When providing the data for provision (DT) from the source system (150m) to the user system (150r) while leaving the sovereignty of the data for provision to the data provision platform (140) that protects the data sovereignty for each client, acquire a first hash value (Hv1) generated using the data for provision from the source system (S20); acquire a second hash value (Hv2) generated using the data for provision acquired by the user system from the user system (S163); detect falsification of the data for provision based on comparison of the first hash value and the second hash value (S165, S183); An information processing program that causes at least one processor (11) to execute a process including this.