Key management system, key management method, and program
The key management system securely manages private keys in blockchain services by encrypting them and deleting the decrypted form promptly after program execution, thereby reducing the risk of key leakage and enhancing security.
Patent Information
- Application Number
- JP2023181593
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-23
- Publication Date
- 2025-05-08
AI Technical Summary
In blockchain services, private keys must be managed securely to prevent asset leakage within the blockchain system, as leaking a private key can result in significant losses.
A key management system that includes a private key storage unit for encrypting and storing private keys and a first deletion unit that deletes the decrypted private key at a predetermined timing after program execution starts, ensuring the private key is only in plaintext for a minimal time.
This approach effectively manages private keys in a secure environment, reducing the risk of key leakage and enhancing security by minimizing the time the private key is in plaintext form.
Smart Images

Figure 2025071435000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a key management system, a key management method, and a program. [Background technology]
[0002] A known technology is that, when a data write request is received, the data is encrypted with an encryption key obtained from a key management computer via a network and stored in a storage device, and, when a data read request is received, the encrypted data read from the storage device is decrypted with the encryption key obtained from the key management computer and passed to an application program (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent No. 3516591 Summary of the Invention [Problem to be solved by the invention]
[0004] For example, various services using blockchain technology use private keys that are issued uniquely to each user. Since the leakage of a private key could lead to the leakage of assets held by the user in the blockchain system, it is necessary for the private key itself to be managed in a secure environment.
[0005] An object of the present invention is to ensure that private keys are properly managed in a secure environment. [Means for solving the problem]
[0006] One aspect of the present invention that solves the above-mentioned problems is a key management system that includes a private key memory unit that stores an encrypted private key obtained by encrypting a plaintext private key used in executing a program with an encryption key, and a first deletion unit that deletes the plaintext private key obtained by decrypting the encrypted private key stored in the private key memory unit at the start of execution of the program, at a predetermined timing after execution of the program is started.
[0007] One aspect of the present invention is a key management method in a key management system, the key management method including: a private key storage step in which a private key storage unit stores an encrypted private key obtained by encrypting a plaintext private key used in execution of a program with an encryption key; and a first deletion step in which a first deletion unit deletes the plaintext private key obtained by decrypting the encrypted private key stored in the private key storage step at the start of execution of the program, at a predetermined timing after execution of the program is started.
[0008] One aspect of the present invention is a program that causes a computer in a key management system to function as a private key memory unit that stores an encrypted private key obtained by encrypting a plaintext private key used in executing a program with an encryption key, and a first deletion unit that deletes the plaintext private key obtained by decrypting the encrypted private key stored in the private key memory unit at the start of execution of the program, at a predetermined timing after execution of the program is started. Effect of the Invention
[0009] According to the present invention, an effect is obtained in that private keys are appropriately managed in a secure environment. [Brief description of the drawings]
[0010] [Figure 1] FIG. 1 is a diagram illustrating an example of the overall configuration of a key management system according to an embodiment of the present invention. [Diagram 2] 1 is a sequence diagram illustrating an example of a processing procedure executed by the key management system according to the present embodiment in response to private key management. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0011] <Embodiment> Fig. 1 shows an example of the configuration of a key management system according to the present embodiment. The key management system according to the present embodiment manages a private key used when a user uses a service (blockchain service) provided under a blockchain environment. The private key according to the present embodiment is used in a public key cryptosystem as an example.
[0012] The key management system in FIG. 1 includes a user terminal 100, a program execution server 200, a private key storage unit 300, a key correspondence processing system 400, and a blockchain 500. The user terminal 100, the program execution server 200, the private key storage unit 300, and the key correspondence processing system 400 may be configured with, for example, hardware such as a CPU (Central Processing Unit), a ROM (Read Only Memory), a RAM (Random Access Memory), a storage device such as a HDD (Hard Disk Drive) or an SSD (Solid State Drive), etc. The functions of the user terminal 100, the program execution server 200, the private key storage unit 300, the key correspondence processing system 400, and the blockchain 500 shown in the figure may be realized by the corresponding CPU executing a program.
[0013] The user terminal 100 is a terminal operated by a user who uses a blockchain service. The user terminal 100 is communicably connected to a program execution server 200 via a network. Blockchain services that a user can use by operating the user terminal 100 are not particularly limited, and include, for example, cryptocurrency trading, NFT (Non-Fungible Token) buying and selling, wallet management, etc. Furthermore, the user terminal 100 may be a personal computer, a tablet terminal, a smartphone, or the like, owned by the user.
[0014] The program execution server 200 is a server that executes a program corresponding to the blockchain service. The program execution server 200 is communicably connected to a private key storage unit 300 and a key correspondence processing system 400 via a network.
[0015] The program execution server 200 includes, as functional units, a program execution unit 201 and a private key processing unit 202 (an example of a first deletion unit and a second deletion unit). The program execution unit 201 executes a program corresponding to the blockchain service. The private key processing unit 202 executes processing related to the private key used in the block chain service. Specifically, the private key processing unit 202 may be capable of executing processing related to the private key, such as generation of a plaintext private key (plaintext private key) in response to the start of a new node, and deletion (discarding) of the plaintext private key in response to the execution of a program by the program execution unit 201.
[0016] The private key storage unit 300 stores (stores) in the private key memory unit 301 the private key encrypted by the key correspondence processing system 400 (encrypted private key). The private key storage unit 300 may be communicably connected to the program execution server 200 and the key correspondence processing system 400 via a network. The private key storage unit 300 may be provided in, for example, a user's wallet, a system server, etc. In addition, the private key storage unit 300 may be set to prohibit the user from accessing the encrypted private key stored in the unit. In other words, the private key storage unit 300 may be set not to grant the user access rights to the encrypted private key stored in the unit.
[0017] The key corresponding processing system 400 executes processing corresponding to a private key. Specifically, the key corresponding processing system 400 may include encryption and decryption of a private key. The key processing system 400 may be, for example, a cloud-based Key Management Service (KMS) or a Hardware Security Module (HSM).
[0018] The key correspondence processing system 400 includes an encryption key storage unit 401 , an encryption unit 402 , and a decryption unit 403 . The encryption key storage unit 401 stores an encryption key. The encryption key is used to encrypt a plaintext private key and to decrypt an encrypted private key (encrypted private key). The encryption key storage unit 401 is configured not to grant a user access to the encrypted private key stored therein. The encryption unit 402 encrypts the plaintext private key transmitted from the program execution server 200. The encrypted plaintext private key becomes the encrypted private key. The encryption unit 402 may store the encrypted private key in the private key storage unit 300. In response to a request from the program execution server 200, the decryption unit 403 decrypts the encrypted private key received from the private key storage unit 300 to obtain a plaintext private key. The decryption unit 403 transmits the plaintext private key obtained by decryption to the program execution server 200 so that the program execution server 200 can execute the program using the plaintext private key.
[0019] Blockchain 500 is a ledger system constructed in such a manner that multiple nodes are connected in a P2P (Peer to Peer) manner on a network such as the Internet, and the processing and recording of transactions, etc. executed under the control of program execution server 200 are distributed among the multiple nodes.
[0020] An example of a processing procedure executed by the key management system of this embodiment in response to the management of a private key will be described with reference to the sequence diagram of FIG. First, an example of a processing procedure for managing a private key in response to the start-up of a new node will be described. Step S100: A user who wishes to use a new blockchain service operates the user terminal 100 to start up a new node corresponding to the blockchain service to be used. In the program execution server 200, the program execution unit 201 starts a new node corresponding to the block chain service to be used in response to the above operation performed on the user terminal 100. Alternatively, the new node may be started in response to the occurrence of a predetermined trigger without being started by the user terminal 100.
[0021] Step S102: The private key processing unit 202 issues (generates) a plaintext private key that is unique to the blockchain service and user corresponding to the new node started in step S100.
[0022] Step S104: The private key processing unit 202 transmits the plaintext private key issued in step S102 to the key correspondence processing system 400. The transmitted plaintext private key may be accompanied by service identification information indicating the corresponding blockchain service and user information indicating the corresponding user.
[0023] Step S106: The key correspondence processing system 400 receives the plaintext private key transmitted in step S104. In the key correspondence processing system 400, the encryption unit 402 encrypts the received plaintext private key using the encryption key stored in the encryption key storage unit 401, thereby obtaining an encrypted private key. In this case, the received plaintext private key may be converted into an encrypted private key by encryption. When conversion is performed in this manner, the received plaintext private key does not exist in the key correspondence processing system 400 after encryption.
[0024] Step S108: The encryption unit 402 transmits the encrypted private key obtained by the encryption in step S106 to the private key storage unit 300. The encrypted private key to be transmitted may be accompanied by service identification information indicating the corresponding blockchain service and user information indicating the corresponding user.
[0025] Step S110: The private key storage unit 300 receives the encrypted private key transmitted in step S108. The private key memory unit 301 of the private key storage unit 300 stores the received encrypted private key in association with the added service identification information and user information. As described above, the private key storage unit 301 is set as an environment in which the user's access rights are not granted. In other words, the user cannot access the encrypted private key stored in the private key storage unit 301 through the user terminal 100.
[0026] Step S112: After the plaintext private key is transmitted in step S104, the private key processing unit 202 in the program execution server 200 deletes the plaintext private key issued in step S102. The private key processing unit 202 may immediately delete the plaintext private key upon completion of transmission of the plaintext private key in step S104, or may delete the plaintext private key after confirming that the corresponding encrypted private key has been stored in the private key storage unit 300 upon notification from the key correspondence processing system 400, for example.
[0027] Next, with reference to the same FIG. 2, an example of a processing procedure for managing a private key in accordance with the execution of a program will be described. Step S200: When the program execution server 200 is to execute a program corresponding to a blockchain service specified by, for example, the user terminal 100, the private key processing unit 202 of the program execution server 200 transmits a private key request to the private key storage unit 300. The private key request may include service identification information and user information associated with the requested private key.
[0028] Step S202: When the private key storage unit 300 receives the private key request transmitted in step S200, it searches for an encrypted private key associated with the same service identification information and user information included in the private key request from among the encrypted private keys stored in the private key storage unit 301. The private key storage unit 300 transmits the searched encrypted private key to the key correspondence processing system 400.
[0029] Step S204: The key correspondence processing system 400 receives the encrypted private key transmitted in step S202. In the key correspondence processing system 400, the decryption unit 403 obtains a plaintext private key by decrypting the received encrypted private key using the encryption key stored in the encryption key storage unit 401. In this case, the decryption unit 403 may convert the encrypted private key into a plaintext private key by decryption. When conversion is performed in this manner, the encrypted private key received in response to step S202 becomes non-existent in the key correspondence processing system 400 as a result of the decryption.
[0030] Step S206: The decryption unit 403 transmits the plaintext private key obtained by decryption in step S204 to the program execution server 200. The program execution server 200 receives the transmitted plaintext private key, thereby acquiring the plaintext private key in response to the private key request transmitted in step S200.
[0031] Step S208: The program execution unit 201 executes a program that uses the plaintext private key received in step S206. Specifically, in this case, a contract corresponding to the target blockchain service is executed. Step S210: The program execution unit 201 newly generates one or more blocks according to the execution result of the contract in step S208.
[0032] Step S212: The program execution unit 201 transmits the block generated in step S210 to the blockchain 500. Step S214;: The blockchain 500 adds the block transmitted in step S212 to the chain.
[0033] Step S216: In addition, in the program execution server 200, the private key processing unit 202 deletes the plaintext private key received in step S206 after the block transmission in step S212. The private key processing unit 202 may delete the plaintext private key immediately in response to the completion of the block transmission in step S210, or may delete the plaintext private key in response to confirmation that the block has been added to the blockchain 500, for example.
[0034] As a mode of managing the private key, for example, the private key can be stored in a wallet to which the user has access authority, or in a server used by the blockchain system. Generally, such management of the private key is performed in a plaintext state. However, when a user uses a wallet to which the user has access authority, the private key is transferred from the wallet to the program execution server 200 every time the program corresponding to the block chain service is executed. In this case, there is a possibility that the private key may be leaked due to an external attack or a misstep during the transfer. In addition, when a user uses a wallet to which the user has access authority, the wallet itself is also vulnerable to attacks.
[0035] In response to this, the key management system of this embodiment is provided with a private key storage unit 300 for storing private keys, and stores (memorizes) encrypted private keys (encrypted private keys) in the private key storage unit 300. By storing private keys in an encrypted state in this manner, it is difficult to decrypt the private keys even if they are leaked, thereby improving security. Furthermore, when a program corresponding to the blockchain service is executed, a plaintext private key obtained by decrypting the encrypted private key stored in the private key storage unit 300 is used, and upon completion of execution of the program, the plaintext private key used is deleted (discarded). By deleting the private key in this manner, the time during which the private key exists in a plaintext state is shortened, and the possibility of the private key in a plaintext state being leaked can be reduced. Furthermore, in order to encrypt and manage the plaintext private key issued when generating a new node, the program execution server 200 deletes the plaintext private key after transmitting it to the key correspondence processing system 400. In this manner, in this embodiment, the time during which the program execution server 200 holds the private key in plaintext is shortened as much as possible, thereby effectively preventing the private key in plaintext from being leaked. In addition, since the private key storage unit 300 is in an environment where the user is not granted access authority, the user cannot operate the private key, which prevents user operation errors. In addition, security against unauthorized access to the private key storage unit 300, for example, by spoofing, can be strengthened.
[0036] In the above embodiment, the management of private keys corresponding to the use of blockchain services is given as an example, but the environment in which the private keys to be managed are used is not limited to blockchain services and may also be applied to, for example, transactions in EC (Electronic Commerce).
[0037] In addition, each of the program execution server 200, the private key storage unit 300, and the key correspondence processing system 400 may be distributed among multiple devices, and the distributed devices may be configured to cooperate with each other via communication to realize the functions. Also, at least two of the program execution server 200, the private key storage unit 300, and the key correspondence processing system 400 may be integrated into one configuration. As an example, the program execution server 200 may be provided with the function of the private key storage unit 300.
[0038] In the above description, the private key corresponds to a public key cryptosystem. However, the private key of this embodiment may correspond to a common key cryptosystem.
[0039] In addition, a program for realizing the functions of the above-mentioned user terminal 100, program execution server 200, private key storage unit 300, key correspondence processing system 400, etc. may be recorded on a computer-readable recording medium, and the program recorded on the recording medium may be read into a computer system and executed to perform processing as the above-mentioned user terminal 100, program execution server 200, private key storage unit 300, key correspondence processing system 400, etc. Here, "reading a program recorded on a recording medium into a computer system and executing it" includes installing the program into a computer system. The "computer system" here includes hardware such as an OS and peripheral devices. In addition, the "computer system" may include multiple computer devices connected via a network including a communication line such as the Internet, a WAN, a LAN, or a dedicated line. In addition, the "computer-readable recording medium" refers to a portable medium such as a flexible disk, an optical magnetic disk, a ROM, or a CD-ROM, and a storage device such as an HDD or SSD built into a computer system. In this way, the recording medium storing the program may be a non-transient recording medium such as a CD-ROM. The recording medium also includes a recording medium provided inside or outside the distribution server and accessible to distribute the program. The code of the program stored in the distribution server's recording medium may be different from the code of the program in a format executable by the terminal device. In other words, the format in which the program is stored in the distribution server does not matter as long as it can be downloaded from the distribution server and installed in a format executable by the terminal device. The program may be divided into multiple parts, downloaded at different times, and then combined in the terminal device, or each of the divided programs may be distributed by a different distribution server. Furthermore, the "computer-readable recording medium" includes a memory that holds the program for a certain period of time, such as a volatile memory (RAM) in a computer system that becomes a server or a client when the program is transmitted via a network. The program may be for realizing part of the above-mentioned functions.Furthermore, the above-mentioned functions may be realized in combination with a program already recorded in the computer system, that is, a so-called differential file (differential program).
[0040] <Additional Notes> (1) One aspect of the present embodiment is a key management system including a private key memory unit that stores an encrypted private key obtained by encrypting a plaintext private key used in execution of a program with an encryption key, and a first deletion unit that deletes the plaintext private key obtained by decrypting the encrypted private key stored in the private key memory unit at a predetermined timing after execution of the program is started.
[0041] (2) One aspect of this embodiment is the key management system described in (1), in which the private key storage unit may store an encrypted private key.
[0042] (3) One aspect of this embodiment is the key management system described in (1) or (2), in which the private key storage unit may be configured as an environment to which the user does not have access authority.
[0043] (4) One aspect of this embodiment is a key management system according to any one of (1) to (3), which may further include a second deletion unit that deletes the plaintext private key used for encryption to obtain the encrypted private key.
[0044] (5) One aspect of this embodiment is a key management system as described in any one of (1) to (4), which may be configured as an environment in which the user does not have access rights and further includes an encryption key memory unit that stores the encryption key.
[0045] (5) One aspect of the present embodiment is a key management method in a key management system, including: a private key storage step in which a private key storage unit stores an encrypted private key obtained by encrypting a plaintext private key used in execution of a program with an encryption key; and a first deletion step in which a first deletion unit deletes the plaintext private key obtained by decrypting the encrypted private key stored in the private key storage step at the start of execution of the program, at a predetermined timing after the start of execution of the program.
[0046] (6) One aspect of the present embodiment is a program that causes a computer in a key management system to function as a private key memory unit that stores an encrypted private key obtained by encrypting a plaintext private key used in execution of a program with an encryption key, and a first deletion unit that deletes the plaintext private key obtained by decrypting the encrypted private key stored in the private key memory unit at a predetermined timing after execution of the program is started. [Explanation of symbols]
[0047] 100 User terminal, 200 Program execution server, 201 Program execution unit, 202 Private key processing unit, 300 Private key storage unit, 301 Private key memory unit, 400 Key correspondence processing system, 401 Encryption key memory unit, 402 Encryption unit, 403 Decryption unit, 500 Blockchain
Claims
1. a private key storage unit for storing an encrypted private key obtained by encrypting a plaintext private key used in executing a program with an encryption key; a first deletion unit that deletes a plaintext private key obtained by decrypting the encrypted private key stored in the private key storage unit at the start of execution of the program, at a predetermined timing after the start of execution of the program; 1. A key management system comprising:
2. The private key storage unit stores an encrypted private key. The key management system of claim 1 .
3. The private key storage unit is set as an environment to which the user does not have access authority. A key management system according to claim 1 or 2.
4. The encryption method further includes the step of: A key management system according to claim 1 or 2.
5. The encryption key storage unit is set as an environment to which the user does not have access authority and stores the encryption key. A key management system according to claim 1 or 2.
6. A key management method in a key management system, comprising: a private key storage step in which a private key storage unit stores an encrypted private key obtained by encrypting a plaintext private key used in execution of the program with an encryption key; a first deletion step in which a first deletion unit deletes a plaintext private key obtained by decrypting the encrypted private key stored in the private key storage step at the start of execution of the program, at a predetermined timing after the start of execution of the program; 16. A key management method comprising:
7. A computer in a key management system, a private key storage unit for storing an encrypted private key obtained by encrypting a plaintext private key used in executing a program with an encryption key; a first deleting unit that deletes a plaintext private key obtained by decrypting the encrypted private key stored in the private key storage unit at the start of execution of the program, at a predetermined timing after the start of execution of the program; A program that functions as a
Citation Information
Patent Citations
Data storage method and system, and recording medium for data storage processing
JP3516591B2