Information processing system
The information processing system addresses the challenges of verifying block transfers and detecting tampering in blockchain technologies by using a management server to verify the legitimacy of transfers and ensure the integrity of the blockchain, resulting in enhanced security and efficiency.
Patent Information
- Application Number
- JP2023185606
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-30
- Publication Date
- 2025-05-14
AI Technical Summary
Existing blockchain technologies face challenges in verifying the validity of block transfers and detecting tampering with previously created blocks, leading to issues with hard forks, uneven data distribution, and reduced participation due to high computational requirements.
An information processing system that includes a management server periodically acquiring location information from multiple terminals, where a second terminal is authorized to write data to a new block if it meets specific handover conditions, and the management server verifies the legitimacy of the transfer to ensure the integrity of the blockchain.
This solution enables real-time verification of block transfers, reduces computational load, detects tampering with past blocks, and prevents hard forks, thereby enhancing the security and efficiency of the blockchain system.
Smart Images

Figure 2025074647000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to an information processing system. [Background technology]
[0002] Patent Literature 1 describes a control method executed by a first device among a plurality of devices in a distributed ledger system having a plurality of devices each holding a distributed ledger. This control method executes a storage process that receives a second identification information of the second device from a second device different from the first device among the plurality of devices via short-range wireless communication, generates a block including transaction data selected from a transaction pool held by the first device, the second identification information, and the first identification information of the first device, and stores the generated block in the distributed ledger held by the plurality of devices. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] International Publication No. 2021 / 215401 Summary of the Invention [Problem to be solved by the invention]
[0004] The present invention aims to make it possible to verify the validity of block handover in a blockchain. [Means for solving the problem]
[0005] An information processing system according to the present invention includes a plurality of terminals and a management server that manages the plurality of terminals. The management server periodically acquires location information of the plurality of terminals. When a first block in a blockchain in which a first terminal has the authority to write data becomes full, a second terminal that satisfies a handover condition, including a condition that the distance from the first terminal is less than a predetermined distance, has the authority to write data to a second block following the first block. The management server verifies whether the handover from the first terminal to the second terminal was valid. Effect of the Invention
[0006] According to the present invention, it becomes possible to verify the validity of block handover in a blockchain. [Brief description of the drawings]
[0007] [Figure 1] FIG. 1 is an explanatory diagram illustrating an information processing system. [Diagram 2] 2 is a block diagram showing functional units of a terminal and a management server; FIG. [Figure 3A] FIG. 2 is a sequence diagram showing processing performed in the information processing system. [Figure 3B] FIG. 2 is a sequence diagram showing processing performed in the information processing system. [Figure 3C] FIG. 2 is a sequence diagram showing processing performed in the information processing system. [Figure 4] FIG. 2 is a block diagram illustrating an example of a hardware configuration of a computer. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0008] Hereinafter, the present invention will be described based on the illustrated embodiment, however, the present invention is not limited to the embodiment described below.
[0009] <Studies conducted by the inventor> First, the inventors conducted the following studies.
[0010] Many media for recording information, such as memo pads and ledgers, are widely used and are becoming increasingly electronic in recent years. Among the technologies for managing electronic records, a technology called a distributed ledger that utilizes communication has been put into practical use, and among them, a technology characterized by multiple terminals contributing to the record has been put into practical use. In particular, it is widely known that by utilizing blockchain technology as a type of distributed ledger, it is possible to make records more difficult to tamper with, and it has been put into practical use as a technology that supports services such as Bitcoin.
[0011] Existing blockchain technology is based on the fact that the first terminal that completes a difficult task (Proof of Work) using special and very large computing resources takes over the next block. Here, Proof of Work is an example of a consensus algorithm. Proof of Work has issues such as consuming a lot of electricity and requiring expensive computers, and it is not easy for anyone to participate (large-scale computing resources and special technology, knowledge, and know-how are required).
[0012] Patent Document 1 discloses a technology that, unlike proof of work, does not require a huge amount of calculation processing and the power required to execute such calculation processing, and reduces the bias of approving terminals. However, such conventional techniques have the following problems.
[0013] <Issue 1 (transaction data is not included in the hash value)> The hash value does not contain data (transaction data) (according to the prior art, the hash value is based on the identification information of terminal 1 and terminal 2, or on parameters α and β). Therefore, if a block that was once approved and stored in the blockchain in a terminal is tampered with, there is no method shown to verify that it has been tampered with (the prior art shows a function to detect fraud in newly created blocks, but does not show a function to detect tampering with previously created blocks).
[0014] <Problem 2 (When multiple vehicles pass each other at the same time)> It is stated that the use of passing each other reduces the bias of blocks that are generated, but when at least two or more pairs of terminals are generated simultaneously due to passing each other independently and simultaneously in various places, no method is shown for determining which is the correct blockchain. In other words, no control method is shown for terminals that have passed each other at two distant locations to recognize that they have passed each other, evaluate the newly generated blocks, and determine a terminal pair with less bias (or with a higher reward), or for determining which of the two terminal pairs is the correct one. As a result, hard forks occur frequently, but no control method is shown for managing the identity of the blockchains between pairs, or for approving the legitimacy of each non-identical blockchain. If hard forks were allowed, there would be an issue that different blockchains would be generated for each region and each terminal.
[0015] <Issue 3 (Detection of block fraud)> In conventional technology, the process of detecting fraud in a block is performed when the block is broadcast, but not when the block is generated. For a newly generated block, fraud can be detected by the other terminal when it is broadcast, but it is difficult to detect tampering with a block created in the past.
[0016] <Topic 4 (Urban and Depopulated Areas)> It is possible that a terminal may go out of communication range or move to a depopulated area where passing rarely occurs, and no passing occurs for a long period of time. In that case, the terminal is less involved in block generation, so the block that the terminal happens to generate is more likely to be adopted. In other words, the more likely a terminal is to pass in an urban area, the less likely it is to approve the block it generates, and the more likely it is to approve the block it generates in a depopulated area. In this way, blocks are less likely to be generated in urban areas where there is a high demand for data (there is a lot of data with high rewards), and blocks are more likely to be generated in depopulated areas where there is little demand for data (there is also little data with high rewards), resulting in a problem of a mismatch between supply and demand. The same problem occurs when it is easier to approve a block the longer the time interval since the previous passing occurs. In addition, the opportunities to generate blocks themselves become fewer. This is thought to be due to an attempt to suppress the uneven distribution of processing volume per device.
[0017] <First embodiment> 1, the information processing system SS includes a plurality of mobile terminals (for example, four terminals 1 to 4) and a management server IS. The terminals may be mobile phones, smartphones, portable game consoles, on-board terminals for automobiles, wild animal tracking devices, etc. Terminals 1 and 2 are located within the coverage area of base station BS and communicate with the base station via a communication carrier line such as an LTE line. Each of the terminals 3 and 4 also communicates with a base station (not shown) located near the terminal through the above-mentioned communication carrier line. The base station BS, a base station (not shown) located near the terminal 3, and a base station (not shown) located near the terminal 4 communicate with the management server IS through the network NW.
[0018] Each of the terminals 1 to 4 is configured to be able to determine its current location based on a signal transmitted from a positioning satellite PS of a Global Navigation Satellite System (GNSS). The management server IS is configured to be able to periodically acquire the location information of each terminal. At this time, the location information of each terminal may be acquired by RTK-GNSS together with the communication data of the base station.
[0019] 2, the terminal 1 includes a processing unit 11 and a communication unit 12. The processing unit 11 performs processing as described below. The communication unit 12 performs short-distance communication with other terminals, communication with a management server IS via a base station and a network NW, and communication with a positioning satellite PS. Like terminal 1, terminal 2 includes a processing unit 21 and a communication unit 22, terminal 3 includes a processing unit 31 and a communication unit 32, and terminal 4 includes a processing unit 41 and a communication unit .
[0020] The management server IS includes a processing unit 91 and a communication unit 92. The processing unit 91 performs processing as described below. The communication unit 92 communicates with the terminals 1 to 4 through the network NW and the base station. The management server IS is configured to record the terminal IDs of the terminals to be managed, and the periodically acquired location information of the terminals and the corresponding times.
[0021] 3A to 3C show the flow of processing performed in the information processing system SS. Of the four terminals 1 to 4, only terminal 1 has the authority to write transaction data to the current block in the information processing system SS. Transaction data is data for transactions such as remittance. Transactions are not limited to remittances, and actions other than remittances, such as proof of existence of a certain document, can also be called transactions.
[0022] In step S1, the processing unit 11 of the terminal 1 determines whether or not to hand over the block writing authority to another terminal. Specifically, the following three determinations are made. -Whether the current block record (for example, 50MB capacity) is full -Is terminal 1 within the communication range of the base station? Was the current location of terminal 1 determined based on signals from the positioning satellite PS?
[0023] If all three determinations in step S1 are YES, step S2 is subsequently performed. If any one of the three determinations in step S1 is NO, step S1 is performed again.
[0024] In step S2, the processing unit 11 of the terminal 1 requests the current takeover conditions from the management server IS. The takeover conditions are conditions for identifying another terminal that takes over from the terminal 1, and are specified by the management server IS. Alternatively, if the terminal 1 has a predetermined handover condition, this step does not need to be performed, and the risk of the handover condition being leaked can be reduced. The handover conditions may be a combination of multiple conditions described below. If multiple terminals meet the conditions, the priority is determined based on different conditions and the block is handed over to one terminal. In the present invention, multiple blockchains can be managed, but as the number of chains increases, the processing volume and communication volume of the management server IS also increases. Below, an example of management with one chain is shown.
[0025] <Examples of handover conditions> The handover conditions that must be met when two terminals pass each other (described later) are, for example, as follows: (1) The terminal closest to terminal 1 (when communicating with infrastructure, this can be interpreted as the terminal that communicated next after terminal 1) (2) The Nth closest terminal from terminal 1 (when communicating with infrastructure, this can be interpreted as the Nth terminal that communicated from terminal 1) (3) All devices closest to device 1, from device 1 to device 1's nearest device (4) The device with the smallest ID within a radius of R meters from device 1 (5) The terminal furthest east within a radius of R meters from terminal 1 (6) The newest terminal within a radius of R meters from terminal 1 (7) The terminal within a radius of R meters from terminal 1 that has inherited the blockchain the least number of times (to equalize the chance of handing over the blockchain) (8) The terminal within a radius of R meters from terminal 1 that has the fastest recent movement speed (further passing by terminal 1 is expected after handover). (9) A terminal that is within a radius of R meters from terminal 1 and has a non-zero moving speed and is the slowest moving speed (can save communication time) (10) A terminal that is within a radius of R meters from terminal 1 and was the last terminal to enter an area within a radius of R meters (can earn communication time) (11) The closest terminal among terminals that are within a radius of R meters from terminal 1 and are at least a radius of r meters away from terminal 1 (where R>r) (to prevent the transfer of blockchain between adjacent terminals) (12) A terminal that is within a radius of R meters from terminal 1 and whose registered owner's location has the highest population density (further crossings are expected after delivery). (13) The terminal within a radius of R meters from terminal 1 that has the longest continuous operating time (further passing is expected after delivery). (14) The terminal with the most battery power remaining within a radius of R meters from terminal 1 (in the case of an in-vehicle terminal, the remaining fuel of the vehicle) (further passing is expected after delivery) (15) A device within a radius of R meters from device 1 that has the highest application launch frequency (further communication is expected after the handover). (16) The terminal within a radius of R meters from terminal 1 that has the largest average movement volume in the recent past (further passing is expected after delivery). (17) A terminal within a radius of R meters from terminal 1 that has maintained communication capability for the longest period of time (further communication is expected after handover). (18) The terminal within a radius of R meters from terminal 1 that has the fastest recent average communication speed (smooth processing can be expected) (19) The terminal within a radius of R meters from terminal 1 that has been determined to be an unauthorized terminal the least number of times (this is expected to improve security). (20) The terminal within a radius of R meters from terminal 1 that has had the fewest block tampering detections (this is expected to improve security). (21) The terminal with the most free memory capacity within a radius of R meters from terminal 1 (smooth processing can be expected) (22) The terminal with the most available computing power within a radius of R meters from terminal 1 (smooth processing can be expected) (23) A terminal that is within a radius of R meters from terminal 1 and has a lot of available computing power (smooth processing can be expected) (24) A terminal that is within a radius of R meters from terminal 1 and has moved from the farthest point from terminal 1 (further passing is expected after the handover). (25) The terminal within a radius of R meters from terminal 1 that completed writing the previous block in the shortest time (further communication is expected after the handover). (26) A terminal within a radius of R meters from terminal 1 that has had the fewest block freezing processes to date (further crossings are expected after handover).
[0026] A combination of two or more of the conditions (1) to (26) may be used as the handover condition. It is also possible to switch the handover condition to a different one, such as switching to condition (2) after a certain period of time has passed since condition (1) was used as the handover condition. This makes it difficult to identify the blockchain handover terminal from the outside.
[0027] As described above, in step S2, the processing unit 11 of the terminal 1 requests the current takeover conditions from the management server IS.
[0028] In step S3, the processing unit 91 of the management server IS sends the current takeover conditions to the terminal 1 through the communication unit 92.
[0029] In step S4, the control unit 11 of the terminal 1 receives, via the communication unit 12, the current takeover conditions from the management server IS.
[0030] In step S5, the control unit 11 of the terminal 1 determines whether a terminal that satisfies the handover condition exists, and if so, determines whether the terminal is an unauthorized terminal. If a terminal that satisfies the handover condition exists and is determined to be an unauthorized terminal, step S6 is subsequently performed, and otherwise step S1 is performed again. An "unauthorized terminal" is, for example, a terminal that satisfies the handover conditions but has been in close proximity to terminal 1 for a certain period of time (this can be determined by both terminal 1 and the management server), a terminal that has been registered in the information processing system SS very recently (this can be determined by the management server, and may be determined in step S12 described later), a terminal that is unlikely to pass by terminal 1 based on its location information history (similar to step S12 described later), a terminal that has been determined to be an unauthorized terminal in the past, etc. It is also possible to determine as an unauthorized terminal a terminal that is considered unlikely to pass by other terminals, such as a terminal that does not pass by other terminals at a predetermined frequency, a terminal that has been turned off recently for more than a predetermined period of time, or a terminal that has not been within communication range recently for more than a predetermined period of time. Note that verification of whether the block has been tampered with is not performed in this step, but in step S17 described later. As an example, the following steps will be described assuming that terminal 2 is determined to be a terminal that satisfies the handover condition and is not an unauthorized terminal.
[0031] In step S6, the control unit 11 of the terminal 1 notifies the management server IS of the start of takeover via the communication unit 12. At this time, it is not necessary to notify that the takeover destination is the terminal 2.
[0032] The processing unit 91 of the management server IS that has received the notification of the start of the handover verifies the validity of the terminal 1 in step S7. Specifically, it verifies whether the previous handover of the block creation to the terminal 1 was performed legitimately. If it is determined that the previous handover was performed legitimately, step S8 is then performed. In other cases, the processing unit 91 of the management server IS notifies the other terminals 2 to 4 via the communication unit 92 that the terminal 1 is an unauthorized terminal. It should be noted that verification as to whether or not the block has been tampered with is not performed in this step, but in step S17, which will be described later.
[0033] In step S8, the processing unit 91 of the management server IS gives permission to the terminal 1 to open a secure peer-to-peer line with the terminal of the takeover destination. Alternatively, the terminal 1 may determine by itself, based on the judgment result of the management server IS, that it is permitted to open a peer-to-peer line, and open the peer-to-peer line.
[0034] In step S9, the processing unit 11 of the terminal 1 opens a peer-to-peer line with the terminal 2 which is the takeover destination, and requests the terminal 2 to send the terminal ID of the terminal 2 through the line to the terminal 1. Thereafter, the terminal 2 sends the terminal ID of the terminal 2 to the terminal 1.
[0035] In step S10, terminal 2 notifies management server IS that it has sent its own terminal ID to another terminal. At this time, it does not have to notify that the destination is terminal 1. Upon receiving this notification, management server IS recognizes that terminal 2 is the destination to take over the blocks. At this stage, only terminal 1 and the management server IS know that terminal 2 has been selected as the takeover terminal. Other terminals do not know yet. Third parties do not know either.
[0036] In step S11, the processing unit 11 of terminal 1 creates a nonce (number used once) including the terminal ID of terminal 1, the current time, the location information of terminal 1, and the terminal ID of terminal 2. Furthermore, the processing unit 11 of terminal 1 uses a hash function based on the created nonce and the current block (recording section and header section) of terminal 1 that has become full, to generate a hash value to be handed over to the next block, and transmits it to terminal 2.
[0037] In step S12, the processing unit 91 of the management server IS performs additional verification of the result of the determination (step S5) that terminal 1 "satisfies the handover conditions." If the verification shows that there is no problem, step S13 is performed. If the verification shows that there is a problem (such as a problem that terminal 2 and terminal 1 cannot actually pass each other based on the relationship between time and location information), the processing unit 91 of the management server IS notifies all terminals that terminal 2 is an unauthorized terminal, and then this flow ends.
[0038] In step S13, the processor 91 of the management server IS sends to the terminal 1 a notification that the takeover to the terminal 2 is permitted.
[0039] In step S14, the processing unit 11 of the terminal 1 sends to the terminal 2 the current block that is now full, a hash value created using a hash function based on the current block that is now full and the nonce, and the header portion of the new block.
[0040] In step S15, the processing unit 11 of the terminal 1 transmits a block chain consisting of past blocks excluding the current block, which is now full, to all terminals.
[0041] In step S16, terminal 2, terminal 3, and terminal 4 each confirm the identity of the block chain sent in step S15 with the block chain held by that terminal, and send the confirmation result to management server IS.
[0042] In step S17, the processing unit 91 of the management server IS determines whether or not the identity of the majority of the blockchains held by the terminal 1 has been confirmed based on the confirmation results sent from the terminals 2 to 4. If it has been confirmed, step S20 is subsequently performed, and if it has not been confirmed, step S18 is performed.
[0043] In step S18, the processing unit 91 of the management server IS instructs a terminal (e.g., terminal 3) for which the majority of the terminals have been confirmed to be identical based on the results of the check of all terminals, to send the correct blockchain (the blockchain with the majority of the terminals being identical) to terminal 1. If there is a terminal other than terminal 1 that has tampered with a block created in the past, it can be corrected in this step. This ensures that the blockchain is correctly updated even when a terminal that has been frozen for a long time is restarted.
[0044] In step S19, terminal 1 receives the correct blockchain from terminal 3, and replaces the blockchain held by terminal 1 with the correct blockchain received from terminal 3. Then, step S20 is performed. In steps S18 and S19, blocks that were created in the past and were tampered with are corrected, and the accuracy of the blockchain is maintained.
[0045] At the time step S20 is performed, the identity of the majority of the blockchains in terminal 1 has been confirmed. In step S20, it is determined whether the identity of the majority of the blockchains held by terminal 2 has been confirmed based on the confirmation results of all terminals. If it has been confirmed, step S23 is performed next, and if it has not been confirmed, step S21 is performed.
[0046] In step S21, the processing unit 91 of the management server IS instructs a terminal (e.g., terminal 3) for which the majority of the terminals have been confirmed to be identical based on the results of the check of all terminals, to send the correct blockchain (the blockchain with the majority of the terminals being identical) to terminal 2.
[0047] In step S22, terminal 2 receives the correct blockchain from terminal 3, and replaces the blockchain held by terminal 2 with the correct blockchain received from terminal 3. Then, step S23 is performed.
[0048] In step S23, the processing unit 91 of the management server IS notifies the terminal 1 that the takeover of the blockchain has been approved. In the next step S23a, the blocks are handed over from terminal 1 to terminal 2.
[0049] In step S24, terminal 1 notifies all terminals 2 to 4 that the takeover of the blockchain has been approved. It is not necessary to notify that terminal 2 has taken over. It is also possible to notify only the fact that the takeover has been performed.
[0050] Although not required, in step S25, the processing unit 91 of the management server IS can notify the terminal 2 that the takeover of the blockchain has been approved.
[0051] In step S26, terminal 2 links the full block and its header to the correct block chain.
[0052] In step S27, terminal 1 sends the full block to terminals 3 and 4. As a result, the number of blocks in the blockchain held by each of terminals 3 and 4 increases by one.
[0053] In step S28, terminal 2 starts writing to the new block. Then, terminal 2 determines whether or not to perform a takeover (step S1).
[0054] In this embodiment, the terminal is not limited to a smartphone, but may be a vehicle equipped with a communication device for vehicle-to-vehicle (V2V) communication, a wearable computer equipped with a communication device, an infrastructure equipped with a communication device, or an in-vehicle IC reader equipped with a communication device. Alternatively, the terminal may be a fixed reader that does not move. Furthermore, the fixed reader may be part of a management server connected to the management server.
[0055] This embodiment provides a new consensus algorithm (consensus formation algorithm) suitable for a distributed ledger (blockchain) by using an information processing system SS equipped with a management server IS in addition to multiple terminals 1 to 4. This embodiment uses multiple terminals managed by a management server, whose positional relationships change due to non-reproducible (or extremely low-reproducible) social activities and natural activities. This provides a consensus algorithm for managing a distributed ledger system that does not require expensive terminals, keeps the computational load low, and is capable of detecting even if blocks are tampered with.
[0056] In this embodiment, a block (or ledger) has a recording section and a header section. Transaction data is stored in the recording section. The header section stores the hash value of the block immediately preceding the block in the blockchain, a nonce, and a digital signature. The hash value in the header section of a block is generated from the information (recording section and header section) in the block immediately preceding the block. If any part of a block (recording section or header section) is tampered with, the hash value of the block following the block in question will change, making it possible to detect the tampering.
[0057] When the recording section of a block becomes full, terminal 1, which has the authority to write to the block currently being created, hands over the blockchain to another terminal (for example, terminal 2) that meets certain handover conditions. When handing over the blockchain from terminal 1 to terminal 2, terminal 1 receives terminal information of terminal 2 from terminal 2 through terminal-to-terminal communication with terminal 2, and creates a nonce from the information of terminal 1 and terminal 2. Based on the full block (recording section and header section) of terminal 1 and the created nonce, terminal 1 uses a hash function to generate a hash value to be handed over to the next block, and sends it to terminal 2.
[0058] The write authority is granted to the terminal 2 that is the transfer destination when the correctness is approved by a majority vote of the entire information processing system (or when the management server IS confirms that the terminal 2 is not an unauthorized terminal and the correctness of the blockchain is approved by a majority vote of the entire information processing system). When the terminal 1's record section becomes full, it selects another terminal that satisfies the above-mentioned transfer condition. Then, after the terminal 1 or the management server IS confirms whether "the own terminal is an unauthorized terminal, whether the other terminal is an unauthorized terminal," whether "the own terminal belongs to the majority and has not been tampered with, whether the other terminal belongs to the majority and has not been tampered with, and whether there are any other terminals that have been tampered with," the blockchain of the terminal that was found to have been tampered with is replaced with the majority blockchain, and the write authority is transferred from terminal 1 to terminal 2. After the write authority is transferred to terminal 2, the record section that became full in terminal 1 is shared with the entire distributed ledger, and further prepared for the next confirmation of "whether there has been tampering."
[0059] Terminal 1 creates a nonce by appropriately combining its own terminal ID, the time of the encounter, the coordinates of the location where the encounter occurred, the ID of the other terminal, etc. Terminal 1 then creates a hash value using a hash function based on the current full block and the nonce. Terminal 1 then creates a header section that includes the created hash value. Terminal 2 receives the header section created by terminal 1 through terminal-to-terminal communication with terminal 1. A new block is created by combining this header section with an empty record section.
[0060] In this embodiment, a management server IS that manages information on each of the terminals 1 to 4 is provided. The management server IS is operated by a business that manages the terminals 1 to 4. In other words, for a business that already operates a management server, there is an advantage that a distributed ledger system (blockchain) can be started using the existing management server without separately preparing a new management server. For example, a business that operates a vehicle management server that manages vehicles equipped with a V2X (Vehicle-to-Everything) communication device can start a distributed ledger system using the vehicle management server as the management server.
[0061] The management server IS may or may not store the contents of the blockchain, which has multiple blocks. In the former case, the contents stored in the management server IS are treated as a backup of the entire distributed ledger by each terminal. Alternatively, the contents of the blockchain in the management server may be treated as a single terminal blockchain. However, when multiple blockchains are operated simultaneously in parallel, the management server can store multiple blockchains at the same time and act as a terminal for each blockchain.
[0062] The database of the management server IS records IDs (such as the chassis number of the vehicle in which the terminal is installed, the SIM number in the on-board communication device, etc.) that identify each terminal 1-4, the location information of each terminal, and the moving speed of each terminal along with the time. The management server IS is configured to use this database to easily verify when and where terminals passed each other, making it possible or impossible to carry out a blockchain handover.
[0063] A distinctive feature of terminals participating in the blockchain, except for the management server that manages the terminals, is that the terminals themselves cannot prove the correctness of their own delivery.
[0064] Furthermore, the management server IS can record terminal information required for determining whether the above-mentioned handover conditions (consensus formation conditions) have been met. After the validity of the takeover (whether the takeover was possible) is verified by the management server IS, the takenover block is shared from terminal 1 to all other terminals 2 to 4 via the network (by terminal-to-terminal communication), and the block chain is updated. That is, in this embodiment, the same block chain is shared by all terminals 1 to 4. However, only terminal 2, which is the takeover destination, starts writing to the latest block before the other terminals.
[0065] When the blockchain is handed over from terminal 1 to terminal 2, terminal 1 transmits only the fact that terminal 1 has handed over the blockchain to the management server IS. Terminal 1 does not need to transmit, for example, information about which terminal the blockchain was handed over to or a copy of the block to the management server IS.
[0066] Terminal 2 transmits only the fact that it has taken over the blockchain to the management server IS. Terminal 2 does not need to transmit information about which terminal it took over from or the contents of the block to the management server IS.
[0067] This makes it difficult for third parties to determine which terminal has handed the blockchain over to which other terminal. On the other hand, the management server IS can independently compare the information obtained from terminal 1 with the information obtained from terminal 2 to find out which terminal has handed over the blockchain to which terminal. Furthermore, only the management server IS can retroactively verify the results of the blockchain handover and easily determine whether the handover was genuine. This not only improves the blockchain's resistance to tampering, but also makes it easier to verify.
[0068] <Modification> As a modified example, terminal 1 having write authority may once pass the header portion including the hash value to management server IS when the block becomes full, and then pass the header portion (or a new block including the header portion) to another terminal (e.g. terminal 2) that passed by when the block became full. In other words, the handover does not have to be performed at the same time as the passing, and the handover does not have to be performed by terminal-to-terminal communication between terminal 1 and terminal 2. After transmitting the header portion from management server IS to terminal 2, management server IS may automatically delete the information of the header portion (or a new block including the header portion) from the server, thereby reducing the risk of information leakage (details will be described later).
[0069] In step S14, terminal 1 creates a header section including a hash value and sends the header section to terminal 2. However, terminal 1 may send the hash value to terminal 2, and terminal 2 may create a header section including the hash value.
[0070] In this embodiment, when a block (header portion) is handed over, terminal 2 does not know from which terminal among multiple terminals (including terminal 2) that move freely around terminal 1 and when the block (i.e., the header portion) will be handed over. In other words, when terminal 1 happens to be full of blocks, the block is handed over to a terminal (e.g., terminal 2) that happens to be closest to terminal 1 and satisfies the consensus formation condition. In other words, from the perspective of terminal 2, there are cases where the block is handed over and cases where it is not handed over. In addition, from a terminal other than terminal 1 and terminal 2 (e.g., terminal 3), there is no way to know from which terminal to which terminal and where the block was handed over, or whether the handover of the block was performed normally. As described with reference to Figures 3A to 3C, the blockchain verification process by all terminals (determining by majority vote whether previously created blocks have been tampered with and correcting any tampered blockchains) is carried out during or after the pass-by between terminal 1 and terminal 2. Terminal 2 uses the received header to create a new block and records transaction records, etc. in the record section.
[0071] <Mechanism for making tampering difficult in this embodiment> The following describes a mechanism by which this embodiment makes tampering difficult, even though it does not require complex calculations (conventional proof of work) using large computational resources. In this embodiment, if an attempt is made to tamper with a past block in the middle of the blockchain, the hash values of all subsequent blocks will be different, making it easy to tell that tampering has occurred (the continuity of hash values will be broken). Therefore, in order to successfully tamper with a block, it is necessary to tamper with all subsequent blocks that need to be tampered with, and to identify each terminal participating in the blockchain and rewrite the blockchain held by the majority of terminals, which is extremely difficult.
[0072] In addition, in this embodiment, the accidental cross-over is incorporated into the consensus formation conditions (handover conditions), and the nonce is generated from the information of the two terminals that cross. There is no necessity for the destination of the blockchain to be handed over, it is decided by chance. Therefore, it is possible to make it difficult to identify the terminal that is the target of tampering by changing the consensus formation conditions based on the cross-over as needed or as appropriate (the distance between terminals or the selection order of the block handover terminal, for example, the second closest terminal, etc.).
[0073] In both the conventional technology and the present embodiment, if a terminal with write authority is hacked while writing to the recording section and data is tampered with, the tampering cannot be undone. This is because the tampered content becomes the official history, is recorded in the blockchain, and cannot be corrected later. In this regard, according to the present embodiment, it becomes difficult to identify "which terminal among terminals around the world currently has write authority," making it difficult to be hacked.
[0074] Furthermore, for a malicious person to arbitrarily generate a new block, he or she must predict the terminal that currently has writing authority, the terminal's location, and the time when the block will be full, and be in a position that satisfies the handover conditions at the time of blockchain handover. This is extremely difficult. Even if an attempt is made to hand over the blockchain to a terminal that does not satisfy the consensus formation conditions (handover conditions), the block will have been generated even though there was no misunderstanding between the terminals, and the management server will be able to detect such tampering and refuse to hand over the blockchain.
[0075] In other words, in the above embodiment, there is a difficulty in that the consensus conditions must be met in the real world at a limited time (when the block becomes full) among multiple terminals that are spread throughout society and move from moment to moment.
[0076] Next, we will consider an example of a malfunction (handover to an unauthorized terminal) in which, when creating a new header section and passing the blockchain to the next terminal, a malicious person actually causes it to pass by an intentionally prepared terminal and thereby encloses the blockchain.
[0077] First, a malicious actor needs to wait near terminal 1 (which holds the full block) in a state where the consensus formation conditions are met. However, it is difficult to know which terminal 1 is, where it is currently located, and when the block will become full. Even the management server IS has difficulty in accurately determining when the block will become full. This has the advantage that surrounding terminals will not know that the block is full until the terminal with the full block starts communicating with another terminal that meets the handover conditions.
[0078] Secondly, if two terminals generate a blockchain transfer to a new terminal in an environment without sufficient liquidity, the management server IS can detect that an unauthorized transfer has occurred from the IDs, time, location information and movement speed of the two terminals. Therefore, it can immediately detect the unauthorized transfer and refuse to approve the transfer. This configuration makes it possible to prevent the blockchain from being trapped in a group of terminals prepared by a malicious individual. Even if one person happens to have two terminals and the handover conditions are always met between the two terminals, causing the blockchain to be repeatedly handed over between the two terminals, the management server can easily refuse to approve the handover of the blockchain. If a malicious person were to try to take over the block of terminal 1, they would have to grasp and track the status of terminal 1 themselves, without the help of the management server IS, prepare terminal 2, and move terminal 1, terminal 2, and several other terminals in the vicinity in sufficient numbers in advance, while bringing terminal 1 and terminal 2 close to each other when the block becomes full (while keeping all other terminals away from terminal 1), which is extremely difficult. The difficulty lies in the need to artificially create a gap at a limited time while excluding terminals other than terminal 1. In other words, it is difficult to commit fraud.
[0079] The present embodiment can be applied to terminals that pass each other, such as airplanes, ships, trains, and artificial satellites. However, it is possible for a third party to predict the next pass where the blockchain will be handed over based on a previously created operation plan, and identify and track the terminal 1 that has the blockchain and the terminal 2 that will next take over the blockchain. For this reason, a mobile terminal carried by the user is preferable as the terminal.
[0080] In addition, it is very costly for the management server IS, which approves or rejects cross-connects, to be managed and maintained by anyone other than the operator who manages a huge number of terminals. Therefore, it is difficult for a malicious individual to incur a large cost in duplicating the management server and having it approve blocks that have been tampered with.
[0081] <Effects> According to the above embodiment, since the handover condition is, for example, "the terminal closest to the other terminal," the blockchain can be handed over to the next terminal quickly and simply without requiring complex calculation processing and with only very small calculation resources. The blockchain can be handed over to the next terminal quickly and simply with very little computational resources. This has the following advantages: 1) The handover process is completed quickly, improving real-time performance (conventional blockchains have the issue of a time lag until more than 51% approval is obtained from all participating devices). 2) Terminal costs can be reduced (conventional blockchains require computing resources to calculate nonces). 3) Terminal costs can be reduced and portability improved. 4) Power consumption can be reduced, reducing CO2 emissions per device. 2 Not only does it reduce emissions, it also requires a smaller power source and is easier to carry. 5) Since there are no terminals that perform unnecessary calculations (terminals that do not become number one), as in the past, the amount of wasted computing resources and power input can be reduced (the only energy wasted is the power used to search for nearby terminals). 6) Distributed ledgers can be easily created and used even if you do not have special computing equipment. 7) By appropriately changing the block handover conditions (consensus formation conditions), it is possible to make it difficult to identify the terminals that make up the blockchain, and to increase resistance to tampering. In other words, by changing it to "the Nth closest terminal from terminal 1 (N can be a random number less than the maximum value that the terminals can communicate with)," it is possible to make it difficult for malicious parties to actually build a cross-connect environment. 8) Because it is easy to create a distributed ledger, you can easily use NFTs (non-fungible tokens, a technology that uses blockchain technology to guarantee the original version of information assets that can be easily copied and edited) for information you use on a daily basis, such as in notepads and social media, making it easy to increase the reliability of information you use on a daily basis. 9) Unlike blockchains, which have no central administrator, this technology has an administrative server (administrator) that manages all terminal information going back to the past and verifies and approves the legitimacy of blockchain handovers at any time. However, although the management server IS manages each terminal, it does not manage blocks (it does not have the function of managing or recording and editing the information within blocks), and it only plays the role of a verifier that verifies the authenticity of the delivery of the blockchain, and the role of an approver that responds with the verification results. In the above embodiment, it is possible to easily and automatically confirm the authenticity of the handover of the blockchain at any time (obtain a response from the administrator) by checking only with the management server IS. Compared to the conventional proof of work, which requires a consistency judgment of 51% or more on all terminals participating in the blockchain, this has the advantage of being more efficient in terminal matching and lighter and faster information processing required for authenticating the legitimacy of the blockchain handover. However, this technology still requires judgment by majority vote. (It is necessary to prepare a separate handover verification program on the management server side that can efficiently search through a huge database.)
[0082] <Other embodiments> Each terminal in the information processing system is not limited to a smartphone, but may be a vehicle equipped with a communication function, a wearable computer, an IC reader, infrastructure, etc. All terminals in the information processing system do not need to be mobile, and some terminals may be stationary terminals whose positions do not change.
[0083] When terminal 1 becomes full of blocks, it may pass a block (or the entire blockchain) to the management server, and the management server may subsequently pass the blockchain to terminal 2 that it passed when it became full of blocks. After the transfer, the management server may delete the information of the block (or the entire blockchain) from the management server. If it is not deleted, the block or the entire blockchain left on the management server will be treated as backup data, or the management server will be treated as a terminal. By doing this, it is not necessary to take over the blockchain in real time when a collision occurs, and the blockchain can be taken over after the collision occurs. This improves the robustness of the system because even if an error occurs in communication between terminals during block exchange when a collision occurs, blocks can be exchanged after communication is restored.
[0084] In existing blockchains, all data is shared among all terminals participating in the blockchain, and the correctness is verified by all terminals. The data that is approved by the majority and has the longest chain is considered the legitimate branch. Therefore, it was necessary for only one terminal to hand over the blockchain (handing over to two or more terminals is called a hard fork and is considered an exceptional measure). In the embodiment of the present invention, the correctness of the blockchain (that it has not been tampered with) is confirmed by the terminals of the entire blockchain. However, the verification of the validity of the handover of the blockchain (the verification of whether a crossover has really occurred) can only be performed by the management server, not by the terminals. Therefore, even if multiple terminals are selected and blocks are handed over, verification (verification) is possible. Whether the handover terminal is one or multiple (i.e., a hard fork), only the management server, which can verify the crossover record, can verify and guarantee the correctness of the hard fork, and does not depend on the number of terminals that take over the blockchain. By handing over to multiple terminals, it is possible to allow the blockchain, including past hash values, to increase exponentially, so that the number of terminals that need to rewrite information when tampering becomes enormous, making tampering even more difficult (it also becomes very difficult to identify the terminals that need to be tampered with). In addition, there is an advantage that many terminals have the opportunity to generate new blocks. On the other hand, since the blockchain branches exponentially, there is a problem that the matching process of the management server increases exponentially. Therefore, in the embodiment of the present invention, when the blockchain is handed over from terminal 1 to multiple terminals (for example, terminals 2 and 3), the multiple terminals are prioritized, and the blockchain of the terminal with the lower priority (for example, terminal 3) is frozen and can be resumed when necessary. By doing so, for example, even if terminal 2 moves to a depopulated area and no cross-talk occurs even after a certain period of time has passed and the blockchain is no longer handed over, it becomes easy to resume the blockchain of terminal 3 by hard forking (the blockchain of terminal 2 is frozen until cross-talk occurs), and it is possible to prevent the blockchain from stalling. In addition, even if many terminals are disconnected from the network due to a communication failure or the like and the identity of the majority of all terminals cannot be obtained temporarily, it is possible to prevent the block from being erroneously determined to have been tampered with even though it is normal by temporarily freezing the block. In addition, since the majority blockchain is updated by majority vote, it is easy to resume.
[0085] Based on the present invention, the roles of the terminal group that participates in the blockchain and records information and the management server that manages the terminals and plays the role of a blockchain handover verifier may be reversed. That is, blocks may be created on the server, information may be recorded, and the validity of the server's block creation may be verified by responses from multiple terminals. However, such a mechanism cannot be called a distributed ledger, but a data recording server with a distributed verifier. The data recording server with a distributed verifier periodically verifies based on the fact that multiple terminals have passed each other, and when a block on the server is tampered with, it is possible to detect data tampering by having the external terminal group respond that there has been tampering as a verification result.
[0086] Conventional blockchains use the maximum computing power to achieve the first proof of work, so there is no room for proof of work on other blockchains. Also, when meeting the proof of stake, it is more efficient to focus on one blockchain to earn the number of blocks. The present invention requires light computational processing, and the decision to hand over the blockchain is also made by the management server, so one terminal may have multiple blockchains. Multiple blockchains can be operated simultaneously in parallel. It is possible to increase the number of blockchains until the market demand is met. In addition, it is easier to manage than meeting demand by hard forking one blockchain multiple times. This increases the chances that more terminals can participate in the blockchain.
[0087] An example of the computer hardware configuration of the management server IS is shown in Fig. 4. This device comprises a CPU 191, a communication device 192, a display device 193, an input device 194, a drive device 195, an auxiliary storage device 196, and a memory device 197, which are interconnected by a bus 199.
[0088] A program for realizing the functions of management server IS is provided by a recording medium 198 such as a CD-ROM. When recording medium 198 on which the program is recorded is set in drive device 195, the program is installed from recording medium 199 via drive device 195 into auxiliary storage device 196. Alternatively, the program does not necessarily have to be installed by recording medium 199, but can also be installed via a network. Auxiliary storage device 196 stores the installed program as well as necessary files, data, and the like.
[0089] The memory device 197 reads out and stores the program from the auxiliary storage device 196 when an instruction to start the program is received. The CPU 191 realizes the functions of the management server IS in accordance with the program stored in the memory device 197. The communication device 192 is used as a communication interface for connecting to other computers via a network. The display device 193 displays a GUI (Graphical User Interface) or the like according to a program. The input device 194 is a keyboard, a mouse, a touch panel, or the like.
[0090] The terminals 1 to 4 each have the same computer hardware configuration as the management server IS.
[0091] The following supplementary notes are provided with respect to the above-described aspects. <Appendix A1> An information processing system having a plurality of terminals and a management server that manages the plurality of terminals, The management server periodically acquires location information of the plurality of terminals; The first terminal has the authority to write a first hash value (a hash value created based on the block immediately preceding the first block and a nonce) and a first set of transaction data to a first block in the blockchain; the management server approves a second terminal that satisfies a takeover condition including a condition that a distance from the first terminal is equal to or less than a predetermined distance when the first block becomes full; the first terminal generates a nonce from identification information of the first terminal and the second terminal, and generates a second hash value from the nonce, the first hash value, and the first group of transaction data; a terminal different from the first terminal has an authority to write the second hash value and a second set of transaction data into a second block following the first block; Information processing system. <Effect A1> The second terminal that satisfies the handover condition is approved by the management server, a nonce is generated based on the first terminal and the second terminal, and the second hash value is handed over to a terminal different from the first terminal. While the first transaction data group is included as a factor in the second hash value, the amount of calculation and memory required for generating the nonce can be reduced. The second terminal to be approved may be specified by either the first terminal or the management server. In addition, the "terminal different from the first terminal" may be the second terminal. When the second terminal has write authority to the second block and the second block becomes full, the second terminal generates a nonce from identification information of the second terminal and a terminal that passes by the second terminal, and generates a third hash value from the nonce, the second hash value, and the second group of transaction data. <Appendix A2> The information processing system described in Appendix A1, wherein the first terminal generates the nonce from identification information of the first terminal and the second terminal, location information of the first terminal and the second terminal, and a time when it is determined that the handover condition is satisfied. <Effect A2> This makes it difficult for anyone other than the server that knows the time and location information to verify the legitimacy of the handover, further preventing tampering. <Appendix A3> The information processing system according to claim 1 or 2, wherein a terminal different from both the first terminal and the second terminal writes the second hash value and a second transaction data group to the second block. <Effect A3> The server can decide where to take over the block. The nonce is generated from the information of the first and second terminals, and it is possible to take over the block to a terminal that is neither the first nor the second terminal. Furthermore, it becomes difficult for a third party to know about the block takeover, which can suppress tampering.
[0092] <Appendix B1> An information processing system having a plurality of terminals and a management server that manages the plurality of terminals, The management server periodically acquires location information of the plurality of terminals; A second terminal that satisfies a handover condition including a condition that a distance from the first terminal is equal to or less than a predetermined distance when a first block in a blockchain in which a first terminal has the authority to write data becomes full has the authority to write data to a second block following the first block, The management server verifies whether the handover from the first terminal to the second terminal was valid. Information processing system. <Effect B1> After the block transfer, the server can verify whether the transfer was valid. Even if a previously generated block is tampered with, the tampering can be easily detected by verification by majority vote. <Appendix B2> The information processing system according to claim 1, wherein the management server performs the verification based on the time at which the second terminal is determined to satisfy the handover condition and the location information of the first terminal and the second terminal at the time. <Effect B2> This makes it difficult for anyone other than the server that knows the time and location information to verify the legitimacy of the handover, further preventing tampering. <Appendix B3> The information processing system according to claim 1 or 2, wherein the takeover condition is changeable by the management server. <Effect B3> In conventional blockchain technology, once a consensus algorithm is set, the transaction history is managed by all participating users according to the conditions. Therefore, changing the consensus algorithm midway (for example, changing from Proof of Work to Proof of Stake) is costly. On the other hand, according to the above configuration, since the conditions can be managed by the server, it is easy to change the conditions themselves, combine a plurality of conditions, etc. It is possible to suppress tampering by making it difficult to identify a terminal that is the target of tampering. <Appendix B4> The first terminal identifies the second terminal that satisfies the handover condition from among the plurality of terminals; The first terminal transmits to the management server delivery information that indicates that the block write has been delivered to a terminal different from the first terminal; The second terminal transmits to the management server takeover information that is information indicating that the block write has been taken over from a terminal different from the second terminal; The management server further performs the verification by comparing the delivery information with the handover information. 10. An information processing system according to claim 1, wherein the information processing system comprises: <Effect B4> The first terminal sends only information that it has handed over the block to the management server, and the second terminal sends only information that it has taken over the block. The management server compares both pieces of information and can only verify that the block has been taken over from the first terminal to the second terminal. Compared to managing a single piece of information that indicates that the block has been taken over from the first terminal to the second terminal, information is managed in a distributed manner, which makes it possible to prevent tampering. <Appendix B5> The management server identifies a third terminal having a lower satisfaction level with respect to the handover condition than the second terminal; The handover is performed from the first terminal to the second terminal and the third terminal, The management server instructs the third terminal to suspend block writing; the management server instructs the third terminal to resume block writing when a predetermined restart condition is satisfied; 10. An information processing system according to claim 1, wherein the information processing system comprises: <Effect B5> There is a possibility that a situation may occur in which the second terminal moves to a depopulated area, the power of the second terminal is turned off, or the second terminal breaks down, resulting in no communication with the second terminal and making it impossible to take over the blocks. Therefore, by transferring the blocks to a third device and freezing them, it is possible to resume the transfer of blocks from the third device when the above situation occurs. The number of terminals at the transfer destination is not limited to two, but may be three or more.
[0093] Although the embodiment of the present invention has been described above, the present invention is not limited to the above-described embodiment, and various modifications and changes can be made based on the technical concept of the present invention. For example, the terminal to which the data is to be taken over may be specified by the management server, or may be specified by the source terminal. [Explanation of symbols]
[0094] SS Information Processing System IS Management Server NW Network BS base station PS Positioning Satellite 1~4 Terminals 11, 21, 31, 41, 91 Processing section 12, 22, 32, 42, 92 Communications Department
Claims
1. An information processing system having a plurality of terminals and a management server that manages the plurality of terminals, The management server periodically acquires location information of the plurality of terminals; A second terminal that satisfies a handover condition including a condition that a distance from the first terminal is equal to or less than a predetermined distance when a first block in a blockchain in which a first terminal has the authority to write data becomes full has the authority to write data to a second block following the first block, The management server verifies whether the handover from the first terminal to the second terminal is valid. Information processing system.
2. The information processing system according to claim 1 , wherein the management server performs the verification based on a time at which the second terminal is determined to satisfy the handover condition and location information of the first terminal and the second terminal at the time.
3. The information processing system according to claim 1 , wherein the takeover condition is changeable by the management server.
4. The first terminal identifies the second terminal that satisfies the handover condition from among the plurality of terminals; The first terminal transmits delivery information to the management server, the delivery information being information indicating that the block write has been delivered to a terminal different from the first terminal; The second terminal transmits to the management server takeover information that is information indicating that the block write has been taken over from a terminal different from the second terminal; The management server further performs the verification by comparing the delivery information with the handover information.
3. The information processing system according to claim 1 or 2.
5. The management server identifies a third terminal having a lower satisfaction level with respect to the handover condition than the second terminal; The handover is performed from the first terminal to the second terminal and the third terminal, The management server instructs the third terminal to suspend block writing; the management server instructs the third terminal to resume block writing when a predetermined restart condition is satisfied; 3. The information processing system according to claim 1 or 2.
Citation Information
Patent Citations
Control method, control device, and program
WO2021215401A1