Information processing method, program, and information processing device

The method enhances information processing security by using secret sharing methods to distribute and restore original information across multiple storage devices, effectively preventing information leakage and ensuring data security even with updated information.

JP2025075728APending Publication Date: 2025-05-15MINEBEAMITSUMI INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023187106
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-10-31
Publication Date
2025-05-15

AI Technical Summary

Technical Problem

Existing information processing methods using secret sharing methods struggle to effectively prevent information leakage, particularly in scenarios where original information is updated or distributed across multiple storage devices.

Method used

The proposed method involves storing a portion of the primary dispersion piece and a portion of the secondary dispersion piece using secret sharing methods, with the remaining secondary dispersion piece stored on an external device. The system restores original information by combining the stored dispersion pieces with the acquired secondary dispersion piece from the external device.

Benefits of technology

This approach effectively prevents information leakage by ensuring that original information can only be restored when all necessary dispersion pieces are aligned and accessible, thereby maintaining data security even when the information is updated.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025075728000001_ABST
    Figure 2025075728000001_ABST
Patent Text Reader

Abstract

To provide an information processing method and the like capable of preventing information leakage.SOLUTION: An information processing method includes causing a computer to execute processing of: storing, in a storage section, some of primary shared pieces obtained by dividing original information using a secret sharing scheme and some of secondary shared pieces obtained by further dividing, using a secret sharing scheme, remaining primary shared pieces other than the some of primary shared pieces; acquiring remaining secondary shared pieces other than the some of secondary shared pieces from an external storage device that stores the remaining secondary shared pieces; and restoring the original information on the basis of the primary shared pieces and the secondary shared pieces stored in the storage section and the secondary shared pieces acquired from the external storage device.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an information processing method, a program, and an information processing device. [Background technology]

[0002] There is a technology for protecting information using a secret sharing scheme. For example, Patent Document 1 discloses a computer program or the like that uses the secret sharing scheme to distribute secret data into multiple pieces of distributed data and distribute metadata of a virtual drive that holds the secret data into multiple pieces of distributed metadata, thereby doubly protecting the secret data. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] JP 2017-126321 A Summary of the Invention [Problem to be solved by the invention]

[0004] In one aspect, an object of the present invention is to provide an information processing method and the like that can prevent information leakage. [Means for solving the problem]

[0005] In one aspect, the information processing method includes storing in a memory unit a portion of primary distribution pieces obtained by dividing original information using a secret sharing method and a portion of secondary distribution pieces obtained by further dividing the remaining primary distribution pieces other than the portion of the primary distribution pieces using a secret sharing method, acquiring the remaining secondary distribution pieces from an external storage device that stores the remaining secondary distribution pieces other than the portion of the secondary distribution pieces, and causing a computer to execute a process of restoring the original information based on the primary distribution pieces and secondary distribution pieces stored in the memory unit and the secondary distribution pieces acquired from the external storage device. Effect of the Invention

[0006] In one aspect, information leakage can be prevented. [Brief description of the drawings]

[0007] [Figure 1] FIG. 1 is an explanatory diagram illustrating an example of the configuration of an information processing system. [Diagram 2] FIG. 2 is a block diagram showing an example of the configuration of a restoration device. [Diagram 3] FIG. 2 is a block diagram showing an example of the configuration of a management device; [Figure 4] FIG. 11 is an explanatory diagram relating to a process for producing dispersed pieces. [Diagram 5] FIG. 11 is an explanatory diagram regarding a restoration process of original information. [Figure 6] 10 is a flowchart showing a procedure for a process of producing dispersed pieces. [Figure 7] 13 is a flowchart showing a procedure for a restoration process of original information. [Figure 8] FIG. 11 is an explanatory diagram showing an overview of a second embodiment. [Figure 9] 13 is a flowchart showing a procedure of a restoration process of original information according to the second embodiment. [Figure 10] FIG. 11 is an explanatory diagram showing an overview of a third embodiment. [Figure 11] 13 is a flowchart showing a procedure of a restoration process of original information according to the third embodiment. [Figure 12] FIG. 13 is an explanatory diagram showing an overview of a fourth embodiment. [Figure 13] 13 is a flowchart showing a procedure for restoring original information according to the fourth embodiment. [Figure 14] FIG. 13 is an explanatory diagram showing an overview of a fifth embodiment. [Figure 15] 13 is a flowchart showing a procedure of encryption processing of secondary distribution pieces according to the fifth embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0008] The present invention will now be described in detail with reference to the drawings showing embodiments thereof. (Embodiment 1) Fig. 1 is an explanatory diagram showing a configuration example of an information processing system. In this embodiment, an information processing system is described in which original information to be kept secret is divided into a plurality of shared pieces using a secret sharing scheme, and the plurality of shared pieces are combined to restore the original information. The information processing system includes a restoration device 1, a management device 2, and an external storage device 3. The restoration device 1 and the management device 2 are communicatively connected via a network N.

[0009] The restoration device 1 is an information processing device capable of various information processing and information transmission and reception, such as a personal computer, a smartphone, a tablet terminal, etc. As described later, the restoration device 1 acquires in advance from the management device 2 a part of the primary distributed pieces obtained by dividing the original information using a secret sharing scheme, and a part of the secondary distributed pieces obtained by further dividing the remaining primary distributed pieces using a secret sharing scheme, and stores them. When an external storage device 3 that stores the remaining secondary distributed pieces necessary for restoring the original information is connected, the restoration device 1 acquires the secondary distributed pieces from the external storage device 3, and restores the original information based on the stored primary distributed pieces and secondary distributed pieces and the acquired secondary distributed pieces. Note that "restoration" in this specification does not mean combining the primary distributed pieces and secondary distributed pieces themselves (i.e., converting the primary distributed pieces and secondary distributed pieces into original information), but means generating data called "original information" based on the information of the primary distributed pieces and secondary distributed pieces. Therefore, even after the original information is restored, the data of the primary distributed pieces and secondary distributed pieces used in the restoration remains.

[0010] The external storage device 3 is a storage device that stores the distributed fragments, and is, for example, a USB (Universal Serial Bus) memory. The external storage device 3 is not limited to a USB memory, and may be a SD (Secure Drive) card, an IC (Integrated Circuit) card, or the like. For example, the external storage device 3 may be a device equipped with a processor such as a CPU, such as a smartphone. The external storage device 3 is connected to the management device 2 via a computer (not shown) (or directly), and acquires and stores the secondary distributed fragments from the management device 2. In the following description, unless otherwise specified, the "connection" of the external storage device 3 may be an electrical connection or a communication connection. In any case, the external storage device 3 is connected so that data can be downloaded from the management device 2. When the external storage device 3 is connected, the restoration device 1 acquires the secondary distributed fragments from the external storage device 3 and uses them to restore the original information.

[0011] The management device 2 is an information processing device that manages this system, and is, for example, a server computer. The management device 2 generates a plurality of primary share pieces by dividing original information using a secret sharing scheme, and also generates a plurality of secondary share pieces by further dividing some of the generated primary share pieces. The management device 2 stores the primary share pieces that were not used in generating the secondary share pieces (i.e., were not divided) and some of the secondary share pieces in the restoration device 1, and stores the remaining secondary share pieces (secondary share pieces other than the some of the secondary share pieces) in the external storage device 3.

[0012] 2 is a block diagram showing an example of the configuration of the restoration device 1. The restoration device 1 includes a control unit 11, a main memory unit 12, a communication unit 13, a display unit 14, an operation unit 15, an input / output unit 16, and an auxiliary memory unit 17. The control unit 11 has one or more processors such as a central processing unit (CPU), a micro-processing unit (MPU), a graphics processing unit (GPU), etc., and performs various information processing by reading and executing programs stored in the auxiliary storage unit 17. The main storage unit 12 is a temporary storage area such as a static random access memory (SRAM) or a dynamic random access memory (DRAM), and temporarily stores data required for the control unit 11 to execute arithmetic processing. The communication unit 13 is a communication module for performing processing related to communication, and transmits and receives information to and from the outside. The display unit 14 is a display screen such as a liquid crystal display, and displays images. The operation unit 15 is an operation interface such as a keyboard or a mouse, and accepts operation input from a user. The input / output unit 16 is an input / output interface for connecting a portable storage medium (such as the external storage device 3), and accepts connection of the storage medium. The auxiliary storage unit 17 is a non-volatile storage area such as a hard disk, and stores programs (program products) and other data required for the control unit 11 to execute processing. The display unit 14 and the operation unit 15 are not essential components. The display unit 14 and the operation unit 15 may be separate devices from the restoration device 1 and connected to the restoration device 1 by wire or wirelessly.

[0013] The restoration device 1 may read and execute the program from a portable storage medium 1a such as a CD (Compact Disk)-ROM or a DVD (Digital Versatile Disk)-ROM.

[0014] 3 is a block diagram showing an example of the configuration of the management device 2. The management device 2 includes a control unit 21, a main memory unit 22, a communication unit 23, and an auxiliary memory unit 24. The control unit 21 has one or more processors such as CPUs, and performs various information processing by reading and executing programs stored in the auxiliary storage unit 24. The main storage unit 22 is a temporary storage area such as RAM, and temporarily stores data necessary for the control unit 21 to execute arithmetic processing. The communication unit 23 is a communication module for performing processing related to communication, and transmits and receives information to and from the outside. The auxiliary storage unit 24 is a non-volatile storage area such as a large-capacity memory or a hard disk, and stores programs (program products) and other data necessary for the control unit 21 to execute processing.

[0015] The management device 2 may be a multi-computer consisting of a plurality of computers, or may be a virtual machine virtually constructed by software.

[0016] The management device 2 may also include a reading unit that reads a portable storage medium 2a such as a CD-ROM, and may read and execute a program from the portable storage medium 2a.

[0017] Fig. 4 is an explanatory diagram of the process of generating shares. The process of generating a plurality of shares by dividing original information using the secret sharing scheme will be described with reference to Fig. 4.

[0018] First, the management device 2 generates a plurality of primary shared pieces by dividing the original information using a secret sharing scheme. In the example of Fig. 4, the management device 2 divides the original information into two primary shared pieces X and Y. Note that the management device 2 may divide the original information into three or more pieces.

[0019] Furthermore, the management device 2 uses a secret sharing scheme to generate multiple secondary share pieces by dividing a part of the primary share pieces generated above. In the example of Fig. 4, the management device 2 divides the primary share piece Y into two secondary share pieces. Note that the management device 2 may divide the primary share piece into three or more pieces.

[0020] The management device 2 generates the secondary distributed pieces multiple times with different division patterns. The "division pattern" means a compilation of the division algorithm and parameters used in the algorithm when dividing the primary distributed pieces into secondary distributed pieces. In other words, "dividing with different division patterns" refers to dividing the primary distributed pieces into secondary distributed pieces using different algorithms and / or different parameters. For example, by using random numbers as parameters used when dividing the primary distributed pieces into secondary distributed pieces, it is possible to easily make the division patterns different when dividing multiple times. By generating the secondary distributed pieces multiple times with different division patterns, as shown in FIG. 4, a set of two secondary distributed pieces is generated, such as secondary distributed pieces A and B, C and D, E and F, G and H, .... When secondary distributed pieces included in the same set (for example, secondary distributed pieces A and B) are combined, all the data constituting the primary distributed piece Y is collected, making it possible to restore it. In other words, the secondary distributed pieces in the same set can be said to be "a combination of secondary distributed pieces that can restore the primary distributed pieces." On the other hand, even if secondary distribution piece A is combined with a secondary distribution piece other than secondary distribution piece B (such as secondary distribution piece D), the data constituting primary distribution piece Y is not collected because they are divided in different patterns, and primary distribution piece Y cannot be restored. This is also true when generating a set of secondary distribution pieces from three or more pieces, and the primary distribution piece cannot be restored unless all the secondary distribution pieces of the same set are collected.

[0021] The management device 2 transmits primary dispersion pieces X that have not been used in generating the secondary dispersion pieces to the restoration device 1, and stores them in the auxiliary memory unit 17. The management device 2 also transmits some of the secondary dispersion pieces divided according to a certain division pattern (first division pattern) to the restoration device 1, and stores them in the auxiliary memory unit 17. For example, in FIG. 4, of the secondary dispersion pieces A and B that correspond to the first division pattern, the management device 2 stores the secondary dispersion piece A in the restoration device 1.

[0022] As described above, the external storage device 3 is connected to the management device 2. The management device 2 causes the external storage device 3 to store secondary distributed pieces B, which belong to the same set as the secondary distributed pieces A stored in the restoration device 1.

[0023] Furthermore, the management device 2 stores in the external storage device 3 some of the secondary distributed pieces that belong to a set different from the secondary distributed piece B. For example, in Fig. 4, the management device 2 stores in the external storage device 3 secondary distributed piece C, out of secondary distributed pieces C and D of the set generated in the second division. As will be described later, the secondary distributed piece C will be used to restore the original information the next time (second time).

[0024] Fig. 5 is an explanatory diagram regarding the restoration process of the original information. The process contents when restoring the original information from the primary distributed pieces and the secondary distributed pieces will be described with reference to Fig. 5.

[0025] When the external storage device 3 is connected, the restoration device 1 acquires the secondary distribution pieces from the external storage device 3. Specifically, the restoration device 1 acquires a secondary distribution piece B that can be combined with the secondary distribution piece A stored in the auxiliary storage unit 17 to restore the primary distribution piece Y, and a secondary distribution piece C that is divided in a pattern different from that of the secondary distribution piece B and is used for the next restoration. Note that the restoration device 1 may simply acquire the secondary distribution pieces B and C without particularly identifying their types. The restoration device 1 may also temporarily store the acquired secondary distribution pieces B and C in the auxiliary storage unit 17.

[0026] The restoration device 1 restores the original information based on the primary distribution piece X and secondary distribution piece A stored in the auxiliary memory unit 17 and the secondary distribution piece B acquired from the external storage device 3. That is, the restoration device 1 restores the primary distribution piece Y based on the secondary distribution pieces A and B, and restores the original information based on the restored primary distribution piece Y and the primary distribution piece X stored in the auxiliary memory unit 17. In addition, during this restoration, the restoration device 1 may attempt restoration by sequentially using the secondary distribution pieces (B and C) acquired from the external storage device 3 (i.e., exhaustively trying all the acquired secondary distribution pieces). As mentioned above, only the secondary distribution piece B can be restored in combination with the secondary distribution piece A, so in any case, the primary distribution piece Y is restored from the secondary distribution pieces A and B.

[0027] For example, when the connection of the external storage device 3 is disconnected, the restoration device 1 deletes the secondary distributed piece A (and B) used in the current restoration from the auxiliary storage unit 17. At this time, the restoration device 1 may delete the original information. In addition, the restoration device 1 stores the secondary distributed piece C acquired from the external storage device 3 in the auxiliary storage unit 17. Furthermore, the restoration device 1 deletes the secondary distributed pieces B and C from the external storage device 3.

[0028] In addition to the above operations, the secondary distributed pieces stored in the restoration device 1 are deleted when a predetermined condition set in advance is satisfied. The predetermined condition is, for example, the passage of a predetermined time. For example, the restoration device 1 deletes the secondary distributed pieces A (and B) from the auxiliary storage unit 17 when a predetermined time has passed since the previous restoration of the original information.

[0029] The condition for deleting the secondary dispersed pieces is not limited to the passage of time. For example, the restoration device 1 may delete the secondary dispersed pieces when a measurement value measured by a specific built-in sensor becomes equal to or greater than a threshold value. For example, the restoration device 1 may delete the secondary dispersed pieces when detecting an action such as a fall by comparing the acceleration measured by an acceleration sensor with a threshold value.

[0030] The external storage device 3 is reconnected to the management device 2 by the user. When the external storage device 3 is connected, the management device 2 stores the secondary distribution pieces in the external storage device 3 again. For example, the management device 2 stores which secondary distribution pieces were most recently downloaded to the restoration device 1 and the external storage device 3, and stores in the external storage device 3 a secondary distribution piece D corresponding to a secondary distribution piece (here, secondary distribution piece C) that cannot be used for restoration (i.e., does not form a set) among the stored secondary distribution pieces. Alternatively, the management device 2 communicates with the restoration device 1 and stores in the external storage device 3 a secondary distribution piece D that is in the same set as the secondary distribution piece (here, secondary distribution piece C) stored in the restoration device 1. In addition, the management device 2 stores in the external storage device 3 a secondary distribution piece that belongs to a different set from the secondary distribution piece D (in the example of FIG. 5, secondary distribution piece E).

[0031] Here, the management device 2 may reuse the secondary distribution pieces (e.g., secondary distribution pieces A or B) that have been downloaded once to the restoration device 1 or the external storage device 3, as long as they belong to a set different from the secondary distribution pieces D, or may not reuse them. When it is possible to reuse the secondary distribution pieces, for example, the management device 2 may identify a random set from among the sets different from the secondary distribution pieces D to be downloaded to the external storage device 3 this time. In this case, it is sufficient to store at least one but not all of the secondary distribution pieces included in the identified set in the external storage device 3. On the other hand, when the secondary distribution pieces are not reused, the management device 2 may assign an index to each set of secondary distribution pieces and store the index corresponding to the set of secondary distribution pieces downloaded to the external storage device 3. Then, the management device 2 may determine the secondary distribution pieces to be downloaded to the external storage device 3 according to the order of the indexes.

[0032] When the external storage device 3 storing the secondary distributed pieces D and E is reconnected, the restoration device 1 acquires the secondary distributed pieces D and E from the external storage device 3. The subsequent processing is the same as above, and the restoration device 1 restores the original information based on the primary distributed piece X and secondary distributed piece C stored in the auxiliary storage unit 17, and the secondary distributed piece D acquired from the external storage device 3. When the connection of the external storage device 3 is disconnected, the restoration device 1 deletes the secondary distributed piece C from the auxiliary storage unit 17, and stores the secondary distributed piece E to be used for the next restoration in the auxiliary storage unit 17. The restoration device 1 also deletes the secondary distributed pieces D and E from the external storage device 3.

[0033] In this way, the restoration device 1 obtains the secondary distributed fragments from the external storage device 3, and combines them with the primary distributed fragments and secondary distributed fragments stored in the auxiliary storage unit 17 to restore the original information. As a result, the original information cannot be restored unless the restoration device 1 and the external storage device 3 are present. In addition, since the secondary distributed fragments on the restoration device 1 are deleted periodically, the original information cannot be restored even if the restoration device 1 and the external storage device 3 are simultaneously lost or stolen. As a result, information leakage can be prevented.

[0034] 6 is a flowchart showing the procedure of a process for generating shares. The process for generating a plurality of shares by dividing original information using the secret sharing scheme will be described with reference to FIG. The control unit 21 of the management device 2 generates a plurality of primary share pieces by dividing the original information using a secret sharing scheme (step S11). The control unit 21 further divides a portion of the generated primary share pieces by using a secret sharing scheme to generate a plurality of secondary share pieces (step S12). In step S12, the control unit 21 generates secondary share pieces a plurality of times using different division patterns. The management device 2 stores the primary share pieces and secondary share pieces generated from the original information.

[0035] The control unit 21 transmits the primary dispersion pieces not used to generate the secondary dispersion pieces in step S12, among the multiple primary dispersion pieces generated in step S11, to the restoration device 1 and stores them (step S13). The control unit 21 transmits some of the secondary dispersion pieces divided according to a certain division pattern (first division pattern) to the restoration device 1 and stores them (step S14). The control unit 21 stores the remaining secondary dispersion pieces divided according to the division pattern and some of the secondary dispersion pieces divided according to a pattern different from the secondary dispersion pieces in the external storage device 3 (step S15), and ends the series of processes.

[0036] 7 is a flowchart showing the procedure of the restoration process of the original information. The process content when the restoration device 1 restores the original information from the dispersed pieces will be described with reference to FIG. When the external storage device 3 is connected, the control unit 11 of the restoration device 1 acquires secondary distribution pieces from the external storage device 3 (step S31). Specifically, the control unit 11 acquires, from the external storage device 3, distribution pieces corresponding to the secondary distribution pieces stored in the auxiliary storage unit 17 (i.e., secondary distribution pieces in the same set as the secondary distribution pieces) and secondary distribution pieces belonging to a different set from the secondary distribution pieces.

[0037] The control unit 11 restores the original information based on the primary distribution pieces and secondary distribution pieces stored in the auxiliary memory unit 17 and the secondary distribution pieces acquired from the external storage device 3 (step S32). That is, the control unit 11 restores the primary distribution pieces based on the secondary distribution pieces stored in the auxiliary memory unit 17 and the secondary distribution pieces acquired from the external storage device 3, and restores the original information based on the restored primary distribution pieces and the primary distribution pieces stored in the auxiliary memory unit 17.

[0038] For example, when the external storage device 3 is disconnected, the control unit 11 deletes the secondary distributed pieces used in the current restoration from the auxiliary storage unit 17 (step S33). The control unit 11 stores, among the secondary distributed pieces acquired from the external storage device 3, the secondary distributed pieces that were not used in the restoration in the auxiliary storage unit 17 (step S34). The control unit 11 deletes the secondary distributed pieces from the external storage device 3 (step S35), and ends the series of processes. Note that the restoration device 1 may delete the original information either before or after step S35.

[0039] In the above, it is assumed that the restoration device 1 obtains all of the secondary distributed pieces from the external storage device 3, but this embodiment is not limited to this. For example, the restoration device 1 may send a request to the management device 2 and obtain from the management device 2 the secondary distributed pieces to be used in the next restoration. In this case, in response to the request from the restoration device 1, the management device 2 sends to the restoration device 1 some of the secondary distributed pieces to be used in the next restoration. In the restoration device 1, the management device 2 may decide which set of secondary distributed pieces to use in the next restoration. In this way, it is sufficient for the restoration device 1 to be able to obtain the secondary distributed pieces to be used in the next restoration, and the source of the secondary distributed pieces is not limited to the external storage device 3.

[0040] As described above, according to the first embodiment, it is possible to prevent information leakage.

[0041] (Embodiment 2) In this embodiment, when the original information is updatable data and the original information is updated by reading, writing, etc., a form will be described in which the updated original information (hereinafter referred to as "second original information") is protected. Note that the same reference numerals will be used to designate the same contents as in the first embodiment, and the description will be omitted.

[0042] Fig. 8 is an explanatory diagram showing an overview of embodiment 2. The overview of this embodiment will be described with reference to Fig. 8. Note that the method of dividing the primary dispersion pieces and the secondary dispersion pieces in the example of Fig. 8 is the same as in Fig. 4.

[0043] As in the first embodiment, the restoration device 1 stores primary distribution pieces X obtained by dividing the original information, and secondary distribution pieces A obtained by further dividing the remaining primary distribution pieces Y. When the external storage device 3 is connected, the restoration device 1 acquires secondary distribution pieces B (and C) and combines them with the primary distribution pieces X and secondary distribution pieces A stored in the auxiliary storage unit 17 to restore the original information.

[0044] Here, consider the case where the original information is updatable information (e.g., a document file, etc.). In this case, even if the primary distributed fragments and secondary distributed fragments stored in the restoration device 1 are combined with the secondary distributed fragments stored in the external storage device 3, only the original information before the update can be restored, and the second original information after the update cannot be restored. Therefore, in this embodiment, difference information indicating the difference between the original information when the external storage device 3 is connected (e.g., when mounted) and the second original information when the external storage device 3 is disconnected (e.g., when unmounted) is stored, and the second original information is restored based on the original information and the difference information.

[0045] For example, the primary shared piece X includes an encryption key (a common key). In this way, when the shared pieces divided using the secret sharing method include some encryption key (e.g., a common key, a public key, and a private key), the encryption key can be retrieved (extracted) only when the original information is restored from the shared pieces including the encryption key. This is the same in the following embodiments. When the original information is restored, the restoration device 1 extracts the encryption key included in the primary shared piece X from the restored original information, and copies it to the main memory unit 12 (volatile memory area).

[0046] When the external storage device 3 is disconnected, the restoration device 1 encrypts difference information D1 between the original information before the update and the second original information after the update with an encryption key. The restoration device 1 stores the encrypted difference information in the auxiliary storage unit 17 and deletes the encryption key from the main storage unit 12.

[0047] When the external storage device 3 is reconnected, the restoration device 1 obtains the secondary distributed piece D (and E) from the external storage device 3 and combines it with the primary distributed piece X and the secondary distributed piece C stored in the auxiliary storage unit 17 to restore the original information. The restoration device 1 extracts an encryption key from the restored original information. Then, the restoration device 1 decrypts the differential information D1 stored in the auxiliary storage unit 17 using the encryption key. The restoration device 1 restores the second original information based on the restored original information and the decrypted differential information D1.

[0048] In the same manner, when the external storage device 3 is disconnected, the restoration device 1 encrypts and stores the difference information D2 of the current update, and uses the difference information D2 to restore the second original information the next time the original information is restored.

[0049] 9 is a flowchart showing the procedure of the restoration process of the original information according to the embodiment 2. After acquiring the secondary distributed pieces from the external storage device 3 (step S31) and combining the primary distributed pieces and the secondary distributed pieces stored in the auxiliary storage unit 17 to restore the original information (step S32), the restoration device 1 executes the following process. The control unit 11 of the restoration device 1 extracts the encryption key (common key) included in the primary shared pieces from the restored original information, and copies it to the main memory unit 12 (step S201). The control unit 11 decrypts, with the encryption key, difference information indicating the difference between the original information and the second element information that previously updated the original information (step S202). The control unit 11 restores the second element information based on the original information restored in step S32 and the difference information decrypted in step S202 (step S203).

[0050] The control unit 11 updates the second element information in response to an operation input from the user or the like (step S204). The control unit 11 encrypts the difference information obtained when the information is updated this time using the encryption key extracted in step S201 (step S205). The control unit 11 stores the encrypted difference information in the auxiliary storage unit 17 (step S206). The control unit 11 deletes the encryption key from the main storage unit 12 (step S207), and the process proceeds to step S33.

[0051] As described above, according to the second embodiment, it is possible to prevent information leakage even when the raw information is updated.

[0052] (Embodiment 3) In this embodiment, a form will be described in which the second element information is dynamically protected by dividing the element information every time the element information is updated.

[0053] Fig. 10 is an explanatory diagram showing an overview of the third embodiment. The overview of the present embodiment will be described with reference to Fig. 10.

[0054] As in the second embodiment, consider the case where the original information can be updated. In this embodiment, when the original information is updated, the restoration device 1 divides the second elemental information resulting from the update of the original information into at least three or more distributed pieces. The restoration device 1 then stores some of the distributed pieces and causes the external storage device 3 to store the remaining distributed pieces. When the external storage device 3 is reconnected, the second elemental information is restored from these distributed pieces.

[0055] For example, similar to embodiment 1, the management device 2 stores in the restoration device 1 primary distribution piece A obtained by dividing the original information, and secondary distribution piece A obtained by further dividing the primary distribution piece Y. The management device 2 also stores in the external storage device 3 secondary distribution piece B that can be combined with the secondary distribution piece A stored in the restoration device 1 to restore the primary distribution piece Y. In the example of Figure 10, the management device 2 only needs to generate primary distribution pieces X and Y, and secondary distribution pieces A and B from primary distribution piece Y, among the distribution pieces shown in Figure 4, and may or may not generate secondary distribution pieces after secondary distribution piece C.

[0056] When the external storage device 3 is connected, the restoration device 1 acquires the secondary distributed piece B from the external storage device 3 and restores the original information by combining it with the primary distributed piece X and the secondary distributed piece A stored in the auxiliary storage unit 17. After that, the original information is updated according to operation input by the user, etc.

[0057] The restoration device 1 divides the second original information, which is the updated original information, into multiple primary distributed pieces X', Y' at a predetermined timing, for example, when the connection of the external storage device 3 is disconnected, when the user instructs the disconnection of the external storage device 3, when the update of the original information is confirmed, or when the file of the updated original information is closed. Furthermore, the restoration device 1 divides the primary distributed piece Y' into multiple secondary distributed pieces A', B'. The restoration device 1 deletes the primary distributed piece X and the secondary distributed piece A used to restore the original information from the auxiliary storage unit 17, and stores the newly generated primary distributed piece X' and the secondary distributed piece A' in the auxiliary storage unit 17. Furthermore, the restoration device 1 deletes the secondary distributed piece B used to restore the original information from the external storage device 3, and stores the newly generated secondary distributed piece B' in the external storage device 3.

[0058] When the external storage device 3 is reconnected, the restoration device 1 restores the second elemental information based on the primary distributed piece X' and the secondary distributed piece A' stored in the auxiliary storage unit 17, and the secondary distributed piece B' stored in the external storage device 3. In this way, every time the original information is updated, the second elemental information obtained by updating the original information is divided into a plurality of distributed pieces and stored in the restoration device 1 and the external storage device 3, thereby dynamically protecting the information.

[0059] 11 is a flowchart showing the procedure of the restoration process of the original information according to the embodiment 3. The process contents executed by the restoration device 1 will be described with reference to FIG. When the external storage device 3 is connected, the control unit 11 of the restoration device 1 acquires from the external storage device 3 secondary distributed pieces that can be combined with the secondary distributed pieces stored in the auxiliary storage unit 17 to restore the primary distributed pieces (step S301). The control unit 11 restores the original information based on the primary distributed pieces and secondary distributed pieces stored in the auxiliary storage unit 17 and the secondary distributed pieces acquired from the external storage device 3 (step S302).

[0060] The control unit 11 updates the raw information to second raw information in response to an operational input from the user or the like (step S303).

[0061] Next, at the predetermined timing described above, the control unit 11 divides the second information into a plurality of primary shared pieces by using the secret sharing scheme (step S304). The control unit 11 further divides a part of the generated primary shared pieces into a plurality of secondary shared pieces (step S305).

[0062] The control unit 11 deletes the primary distribution pieces and secondary distribution pieces used to restore the original information in step S302 from the auxiliary storage unit 17 (step S306). The control unit 11 stores, in the auxiliary storage unit 17, the primary distribution pieces that were not used to generate the secondary distribution pieces among the primary distribution pieces generated in step S304 and some of the secondary distribution pieces generated in step S305 (step S307).

[0063] The control unit 11 deletes the secondary dispersion pieces from the external storage device 3 (step S308). The control unit 11 stores in the external storage device 3 the secondary dispersion pieces that can be combined with the secondary dispersion pieces stored in the auxiliary storage unit 17 in step S307 to restore the primary dispersion pieces, among the secondary dispersion pieces generated in step S305 (step S309), and ends the series of processes.

[0064] As described above, according to the third embodiment, the second element information can be dynamically protected by dividing the second element information successively.

[0065] (Embodiment 4) In this embodiment, a description will be given of a mode in which the secondary distributed pieces are encrypted and stored in the restoration device 1, and the secondary distributed pieces are decrypted when the original information is restored.

[0066] Fig. 12 is an explanatory diagram showing an overview of the fourth embodiment. The overview of the present embodiment will be described with reference to Fig. 12. The information processing system according to the present embodiment includes a mobile terminal 4 in addition to the various devices shown in Fig. 1. The mobile terminal 4 can be realized by, for example, a smartphone or the like.

[0067] As in the first embodiment, the management device 2 stores in the restoration device 1 primary shared piece X obtained by dividing the original information, and secondary shared piece A obtained by further dividing the primary shared piece Y. In this case, the management device 2 encrypts the secondary shared piece A using an encryption key (public key) included in the primary shared piece X, and then stores it in the restoration device 1.

[0068] The "Protection Status" row at the top of FIG. 12 shows the state of various data before the external storage device 3 is connected to the restoration device 1. As shown in the figure, the secondary distributed piece A is stored in an encrypted state in the restoration device 1, and the external storage device 3 is connected to the restoration device 1 in this state. The "Restoration Status" row at the top of FIG. 12 shows the state of various processes and data after the restoration device 1 acquires the secondary distributed piece B (and C) from the external storage device 3. When the external storage device 3 is connected, the restoration device 1 acquires the secondary distributed piece B (and C) from the external storage device 3. Here, the data required for restoring the original information (primary distributed piece X, secondary distributed pieces A and B) are all present in the restoration device 1, but the secondary distributed piece A is in an encrypted state. Therefore, the restoration device 1 decrypts this secondary distributed piece A with a private key. The restoration device 1 according to this embodiment acquires the private key via the mobile terminal 4. Note that the timing of acquiring the private key is not particularly limited. For example, the restoration device 1 may acquire the private key between the connection of the external storage device 3 and before performing the restoration process of the original information.

[0069] The mobile terminal 4 performs authentication based on authentication information in advance or upon receiving a request from the restoration device 1. Here, the authentication information is, for example, biometric information or location information of the user. In order to enhance security, this authentication is preferably authentication based on two or more pieces of authentication information (multi-factor authentication). Note that the authentication process may be executed by the restoration device 1 instead of the mobile terminal 4. Also, the contents of the authentication process based on the authentication information may be publicly known. For example, authentication may be performed using a function (face authentication, fingerprint authentication, password authentication, etc.) that is pre-installed as a function of the mobile terminal 4 (or the restoration device 1) itself.

[0070] If authentication in the mobile terminal 4 is successful, the mobile terminal 4 obtains a private key corresponding to the public key included in the primary share piece A from the management device 2 (or cloud). The mobile terminal 4 transmits the obtained private key to the restoration device 1. The restoration device 1 decrypts the secondary share piece A using the private key. The restoration device 1 restores the original information based on the primary share piece X stored in the auxiliary memory unit 17, the decrypted secondary share piece A, and the secondary share piece B obtained from the external storage device 3. The restoration device 1 deletes the private key from the main memory unit 12.

[0071] In this embodiment, the private key is obtained from the management device 2, but the private key may be managed (stored) in a memory unit of the mobile terminal 4, and the mobile terminal 4 may authenticate itself and, if the authentication is successful, transmit the private key to the restoration device 1.

[0072] The "Restoration Status" row at the bottom of FIG. 12 shows the state of the data after the secondary distributed piece A is decrypted and the original information is restored. In this state, when the external storage device 3 is disconnected from the restoration device 1, the restoration device 1 deletes the secondary distributed pieces A and B from the auxiliary storage unit 17. In addition, at a predetermined timing, such as when the connection between the restoration device 1 and the external storage device 3 is disconnected, the restoration device 1 extracts the public key from the restored original information and encrypts the secondary distributed piece C to be used for the next restoration with the public key. The "Protection Status" row at the bottom of FIG. 12 shows the state of the data after the secondary distributed piece C is encrypted. The restoration device 1 stores the encrypted secondary distributed piece C in the auxiliary storage unit 17. The restoration device 1 deletes the public key from the main storage unit 12. The original information may also be deleted at this time.

[0073] The subsequent processing is the same as above, and when the external storage device 3 is reconnected, the restoration device 1 acquires the secondary share pieces D and E, and then decrypts the secondary share piece C with the private key obtained from the mobile terminal 4, and restores the original information by combining it with the primary share piece X stored in the auxiliary storage unit 17 and the secondary share piece D acquired from the external storage device 3. Then, at the predetermined timing mentioned above, the secondary share piece E is encrypted with the public key.

[0074] Even if the external storage device 3 is connected, the restoration device 1 may encrypt the secondary distributed pieces if a predefined condition (e.g., the passage of a predetermined time) is satisfied. At this time, the restoration device 1 may delete the original information. This makes it possible to prevent a third party from viewing the original information, for example, even in cases where the external storage device 3 is left connected for a long period of time.

[0075] As described above, in this embodiment, the secondary distributed pieces are encrypted and stored in the restoration device 1, and the secondary distributed pieces are decrypted when the original information is restored. This makes it possible to more effectively prevent information leakage.

[0076] 13 is a flowchart showing the procedure of the restoration process of the original information according to the embodiment 4. The contents of the process when the original information is restored in this embodiment will be described with reference to FIG. When an external storage device 3 is connected, the control unit 11 of the restoration device 1 obtains from the external storage device 3 secondary distribution pieces that belong to the same set as the secondary distribution pieces stored in the auxiliary storage unit 17, and secondary distribution pieces that belong to a different set from the secondary distribution pieces (step S401).

[0077] If the authentication based on the authentication information is successful, the control unit 11 acquires a private key from the management device 2 (step S402). The control unit 11 decrypts the encrypted secondary share pieces stored in the auxiliary storage unit 17 using the private key (step S403). The control unit 11 restores the original information based on the primary share pieces stored in the auxiliary storage unit 17, the secondary share pieces decrypted in step S403, and the secondary share pieces acquired in step S401 (step S404). The control unit 11 deletes the private key from the main storage unit 12 (step S405).

[0078] At a predetermined timing, such as when the external storage device 3 is disconnected, the control unit 11 extracts the public key included in the primary shared fragment from the restored original information and copies it to the main memory unit 12 (step S406). The control unit 11 encrypts the secondary shared fragment to be used in the next restoration (i.e., not used in the current restoration) with this copied public key (step S407). The control unit 11 deletes the secondary shared fragment used in the current restoration from the auxiliary memory unit 17 (step S408). The control unit 11 stores the encrypted secondary shared fragment in the auxiliary memory unit 17 (step S409).

[0079] The control unit 11 deletes the duplicated public key from the main storage unit 12 (step S410). The control unit 11 deletes the secondary distributed pieces from the external storage device 3 (step S411), and ends the series of processes.

[0080] As described above, according to the fourth embodiment, information leakage can be prevented more suitably.

[0081] (Embodiment 5) In this embodiment, a form will be described in which, before encrypting the secondary dispersion pieces, it is confirmed (determined) whether or not the original information can be restored even if it is encrypted.

[0082] Fig. 14 is an explanatory diagram showing an overview of the fifth embodiment. The overview of the present embodiment will be described with reference to Fig. 14.

[0083] The "Protection Status" row at the top of Fig. 14 shows the state of various data before the external storage device 3 is connected to the restoration device 1. As shown in the figure, secondary distribution piece A is stored in an encrypted state in the restoration device 1, and the external storage device 3 is connected to the restoration device 1 in this state. As in embodiment 4, when the external storage device 3 is connected, the restoration device 1 obtains secondary distribution pieces B and C from the external storage device 3.

[0084] The row of "Restored state" in FIG. 14 shows the state of various processes and data after the restoration device 1 acquires the secondary distributed pieces B and C from the external storage device 3. The restoration device 1 acquires a private key from the mobile terminal 4, for example, after the external storage device 3 is connected. As shown in the figure, the mobile terminal 4 acquires this private key from the management device 2 in advance or upon receiving a request from the restoration device 1. The mobile terminal 4 can acquire the private key from the management device 2 according to the authentication result based on the authentication information (i.e., if the authentication is successful). When the restoration device 1 acquires the private key from the mobile terminal 4 and acquires the secondary distributed pieces B and C, it uses the private key to decrypt the secondary distributed piece A. Then, the restoration device 1 restores the original information based on the primary distributed piece X stored in the auxiliary storage unit 17, the decrypted secondary distributed piece A, and the acquired secondary distributed piece B. In this case, as described in the fourth embodiment, when a predetermined condition set in advance (for example, a predetermined time has passed since the restoration of the original information) is satisfied, the restoration device 1 encrypts the secondary distributed piece C with the public key included in the primary distributed piece X. At this time, the restoration device 1 may delete the original information.

[0085] In this embodiment, before encrypting the secondary distributed piece C, the restoration device 1 determines whether or not it is possible to restore the original information even if the secondary distributed piece C is encrypted. For example, the restoration device 1 determines whether or not it is possible to communicate with the management device 2 that manages the private key, that is, whether or not it is possible to obtain the private key required for decrypting the secondary distributed piece C.

[0086] If it is determined that the original information can be restored, the restoration device 1 encrypts the secondary distributed piece C. The "Protection Status" row at the bottom of FIG. 14 shows the state of the data after the encryption of the secondary distributed piece C has been performed. If it is determined that the original information can be restored, the secondary distributed pieces A and B may be deleted from the restoration device 1. On the other hand, if it is determined that the original information cannot be restored, the restoration device 1 does not encrypt the secondary distributed piece C, and makes a judgment again after a certain period of time. This "certain period of time" may be the same as the elapsed time ("predetermined period of time") described above, or may be different. If it is determined that the original information can be restored as a result of making a judgment again after the certain period of time, the restoration device 1 encrypts the secondary distributed piece C. The original information may also be deleted at this time.

[0087] As described above, the restoration device 1 checks whether the original information can be restored before encrypting the secondary distributed pieces. This makes it possible to prevent situations where the expiration date expires while the Internet is unavailable, such as while on an airplane, making it impossible to access the original information.

[0088] Fig. 15 is a flowchart showing the procedure of encryption processing of secondary distributed pieces according to embodiment 5. The determination processing when encrypting secondary distributed pieces will be described with reference to Fig. 15. Note that the processing of this flowchart is executed, for example, when an external storage device 3 is connected to the restoration device 1. The control unit 11 of the restoration device 1 determines whether a predetermined condition set in advance is satisfied (step S501). The predetermined condition is, for example, the passage of a predetermined time since the external storage device 3 was connected to the restoration device 1. If it is determined that the predetermined condition is not satisfied (S501: NO), the control unit 11 waits for processing.

[0089] If it is determined that the predetermined condition is satisfied (S501: YES), the control unit 11 determines whether or not the original information can be restored (step S502). Specifically, the control unit 11 determines whether or not it is possible to communicate with the management device 2 that manages the private key. If it is determined that the original information can be restored (S502: YES), the control unit 11 restores the original information, extracts the public key, encrypts the secondary shared fragments with the public key contained in the primary shared fragments, and stores them in the auxiliary storage unit 17 (step S503), and ends the series of processes. At this time, the original information may be deleted.

[0090] If it is determined that the original information cannot be restored (S502: NO), the control unit 11 determines whether or not a certain time has elapsed (step S504). If it is determined that the certain time has not elapsed (S504: NO), the control unit 11 waits for processing. If it is determined that the certain time has elapsed (S504: YES), the control unit 11 returns the processing to step S502. In this case, the control unit 11 determines again whether or not the original information can be restored (step S502), and if it is determined that the original information can be restored, it encrypts the secondary distributed pieces (step S503).

[0091] As described above, according to the fifth embodiment, the encryption of the secondary distributed pieces can be suitably performed. Note that the timing of performing the process of the flowchart shown in FIG. 15 is not limited to the timing when the external storage device 3 is connected. The flowchart shown in FIG. 15 may be executed as appropriate according to the contents of the predetermined condition determined in S501. Also, the various processes shown in FIG. 15 may be executed in parallel with the processes of the restoration device 1 described in the previous drawings and in this specification.

[0092] (Variation 1) In the fifth embodiment, a form has been described in which, when a secondary distributed piece is encrypted by satisfying a predetermined condition (e.g., the passage of a predetermined time), it is confirmed whether or not the original information can be restored. On the other hand, this embodiment may also be applied to a case in which a secondary distributed piece is deleted by satisfying a predetermined condition.

[0093] That is, when the restoration device 1 deletes the secondary distributed pieces by satisfying a predetermined condition set in advance, the restoration device 1 determines whether or not the original information can be restored. For example, the restoration device 1 determines whether an external storage device 3 is connected to the device itself, and whether or not secondary distributed pieces that can be combined with the secondary distributed pieces stored in the auxiliary storage unit 17 to restore the primary distributed pieces can be acquired from the external storage device 3. If it is determined that the original information can be restored, the restoration device 1 deletes the secondary distributed pieces stored in the auxiliary storage unit 17.

[0094] On the other hand, if it is determined that the original information cannot be restored, the restoration device 1 does not delete the secondary distributed pieces, and performs a determination again after a certain period of time. If it is determined that the original information can be restored as a result of performing the determination again after the certain period of time, the restoration device 1 deletes the secondary distributed pieces stored in the auxiliary storage unit 17.

[0095] In this way, the fifth embodiment can also be applied to the case where the secondary distributed pieces are deleted. Since the fifth embodiment is the same as the fifth embodiment except that the secondary distributed pieces are deleted instead of encrypted, the flowchart and other detailed explanations are omitted in this modification.

[0096] (Variation 2) In the fifth embodiment and the first modification, a configuration has been described in which it is confirmed whether the original information can be restored before encrypting or deleting the secondary distributed pieces. The present embodiment may be applied to a configuration in which the original information is updated as described in the second and third embodiments.

[0097] That is, when the restoration device 1 encrypts or deletes the secondary distributed pieces by satisfying a predetermined condition, the restoration device 1 may determine whether or not the second elemental information (original information after update) can be restored. If it is determined that the second elemental information can be restored, the restoration device 1 encrypts or deletes the secondary distributed pieces stored in the auxiliary storage unit 17. On the other hand, if it is determined that the second elemental information cannot be restored, the restoration device 1 does not encrypt or delete the secondary distributed pieces, and makes a determination again after a certain period of time.

[0098] In this way, the fifth embodiment can also be applied to cases where the original information is updatable information.

[0099] (Variation 3) In the fourth embodiment, the encryption key may be stored in a device other than the management device 2. The mobile terminal 4 may obtain the encryption key by communicating with the other device. In this case, the mobile terminal 4 and / or the other device authenticates the mobile terminal 4. If the authentication is successful, the other device transmits the encryption key to the mobile terminal 4. The private key in the fifth embodiment may also be stored in a device other than the management device 2. The same applies to the first and second modifications. The other device does not necessarily refer to one physical device, but may be, for example, a cloud storage device.

[0100] (Variation 4) In the fourth and fifth embodiments, the external storage device 3 may be the same device as the mobile terminal 4. In this case, the external storage device 3 may perform authentication to acquire the private key and acquire the private key in advance based on a user's instruction operation, etc. Then, when the external storage device 3 is connected to the restoration device 1, it may transmit the private key to the restoration device 1 together with the secondary distributed pieces (for example, secondary distributed pieces B and C in the fourth embodiment). (Variation 5) Embodiments 4 and 5 are also applicable to cases where the original information is updatable information, as in embodiment 2 or 3. When embodiment 4 or 5 is combined with embodiment 2 or 3, the generation, deletion, and movement of data of the primary distributed pieces and secondary distributed pieces shall conform to embodiment 2 or 3. Furthermore, authentication by the mobile terminal 4 and the method of acquiring the private key of the restoration device 1 shall conform to embodiment 4 or 5. Furthermore, in the case of embodiment 4 or 5, the secondary distributed piece encrypted by the restoration device 1 shall be the secondary distributed piece acquired from the external storage device 3 that was not used to restore the original information (for example, secondary distributed piece C in FIG. 12 or FIG. 14).

[0101] The embodiments disclosed herein are illustrative in all respects and should not be considered as limiting. The scope of the present invention is defined by the claims, not by the above meaning, and is intended to include all modifications within the scope and meaning equivalent to the claims.

[0102] The matters described in each embodiment can be combined with each other. In addition, the independent claims and dependent claims described in the claims can be combined with each other in any and all combinations regardless of the citation format. Furthermore, the claims use a format in which a claim cites two or more other claims (multi-claim format), but this is not limited to this. They may also be written using a format in which a multiple claim cites at least one other multiple claim (multi-multi claim). [Explanation of symbols]

[0103] 1. Restoration Device 11 Control section 12 Main memory 13. Communications Department 14 Display section 15 Control section 16 Input / output section 17 Auxiliary storage 2 Management device 21 Control section 22 Main memory 23 Communications Department 24 Auxiliary storage 3 External storage device 4. Mobile devices

Claims

1. A part of the primary shared pieces obtained by dividing the original information using a secret sharing scheme and a part of the secondary shared pieces obtained by further dividing the remaining primary shared pieces using the secret sharing scheme other than the part of the primary shared pieces are stored in a storage unit; Acquire the remaining secondary distribution pieces from an external storage device that stores the remaining secondary distribution pieces other than the part of the secondary distribution pieces; The original information is restored based on the primary distributed pieces and the secondary distributed pieces stored in the storage unit and the secondary distributed pieces acquired from the external storage device. An information processing method in which processing is performed by a computer.

2. the process of dividing the remaining primary dispersion pieces into secondary dispersion pieces is executed multiple times in different patterns, and the secondary dispersion pieces generated each time are regarded as one set, the remaining primary dispersion pieces can be restored when all the secondary dispersion pieces of the set are collected; the external storage device stores the same set of secondary dispersed pieces as the secondary dispersed pieces stored in the storage unit, and a part of the secondary dispersed pieces that is a different set from the secondary dispersed pieces; Obtaining the same set of secondary dispersed pieces and the different set of secondary dispersed pieces from the external storage device; deleting the secondary dispersed pieces of the same set and the secondary dispersed pieces of the different sets from the external storage device; After restoring the original information, the secondary dispersion pieces used for the restoration are deleted from the storage unit; The different sets of secondary dispersion pieces are stored in the storage unit. The information processing method according to claim 1 .

3. The secondary dispersed pieces of the same set as the different set of secondary dispersed pieces stored in the storage unit are stored in the external storage device. The information processing method according to claim 2 .

4. The raw information is updatable information, The primary shared pieces stored in the storage unit include an encryption key, When the original information is restored, the encryption key is extracted from the restored original information; encrypting difference information indicating a difference between the original information before the update and the original information after the update using the encryption key; storing the encrypted difference information in the storage unit; Delete the extracted encryption key. The information processing method according to any one of claims 1 to 3.

5. restoring the original information before the update based on the primary distributed pieces and the secondary distributed pieces stored in the storage unit and the secondary distributed pieces acquired from the external storage device; extracting the encryption key contained in the primary share from the original information; Decrypting the difference information using the encryption key; The updated original information is restored from the original information before the update and the decrypted difference information. The information processing method according to claim 4.

6. The raw information is updatable information, Dividing the updated original information into a primary distributed piece and a secondary distributed piece obtained by further dividing a part of the primary distributed piece, storing a portion of the primary dispersion pieces and a portion of the secondary dispersion pieces in the storage unit; storing in the external storage device secondary dispersion pieces that can be combined with the secondary dispersion pieces stored in the storage unit to restore the primary dispersion pieces; When the external storage device is reconnected, the secondary dispersion pieces are acquired from the external storage device; restoring the updated original information based on the primary distributed pieces and secondary distributed pieces stored in the storage unit and the secondary distributed pieces acquired from the external storage device; Delete the secondary dispersion pieces stored in the external storage device. The information processing method according to any one of claims 1 to 5.

7. When a predetermined condition set in advance is satisfied, the secondary dispersion pieces stored in the storage unit are deleted. The information processing method according to any one of claims 1 to 6.

8. When deleting the secondary dispersed pieces stored in the storage unit, determining whether or not the original information can be restored; If it is determined that restoration is possible, the secondary dispersion pieces stored in the storage unit are deleted; If it is determined that restoration is not possible, the determination will be made again after a certain period of time. The information processing method according to claim 7.

9. If the external storage device is connected, it is determined that the original information can be restored. The information processing method according to claim 8.

10. The secondary distributed pieces are encrypted using an encryption key and then stored in the storage unit, When restoring the original information, the secondary distributed pieces are decrypted with an encryption key obtained according to an authentication result based on authentication information to restore the original information. The information processing method according to any one of claims 1 to 9.

11. When encrypting the secondary distributed pieces, determining whether or not the original information can be restored; If it is determined that restoration is possible, the secondary distributed pieces are encrypted; If it is determined that restoration is not possible, the determination will be made again after a certain period of time. The information processing method according to claim 10.

12. If communication with the device that manages the encryption key is possible, it is determined that the original information can be restored. The information processing method according to claim 11.

13. A part of the primary shared pieces obtained by dividing the original information using a secret sharing scheme and a part of the secondary shared pieces obtained by further dividing the remaining primary shared pieces using the secret sharing scheme other than the part of the primary shared pieces are stored in a storage unit; Acquire the remaining secondary distribution pieces from an external storage device that stores the remaining secondary distribution pieces other than the part of the secondary distribution pieces; The original information is restored based on the primary distributed pieces and the secondary distributed pieces stored in the storage unit and the secondary distributed pieces acquired from the external storage device. A program that causes a computer to carry out processing.

14. An information processing device including a control unit, The control unit: A part of the primary shared pieces obtained by dividing the original information using a secret sharing scheme and a part of the secondary shared pieces obtained by further dividing the remaining primary shared pieces using the secret sharing scheme other than the part of the primary shared pieces are stored in a storage unit; Acquire the remaining secondary distribution pieces from an external storage device that stores the remaining secondary distribution pieces other than the part of the secondary distribution pieces; The original information is restored based on the primary distributed pieces and the secondary distributed pieces stored in the storage unit and the secondary distributed pieces acquired from the external storage device. Information processing device.

15. A part of the primary shared pieces obtained by dividing the original information using a secret sharing method and a part of the secondary shared pieces obtained by further dividing the remaining primary shared pieces using the secret sharing method other than the part of the primary shared pieces are stored in a storage unit; Acquire the remaining secondary distribution pieces from an external storage device that stores the remaining secondary distribution pieces other than the part of the secondary distribution pieces; restoring the original information based on the primary distributed pieces and secondary distributed pieces stored in the storage unit and the secondary distributed pieces acquired from the external storage device; determining whether the original information can be restored when a preset condition is satisfied; If it is determined that restoration is possible, the secondary distributed pieces stored in the storage unit are deleted, or the secondary distributed pieces are encrypted using an encryption key, If it is determined that restoration is not possible, the determination will be made again after a certain period of time. An information processing method in which processing is performed by a computer.

16. An information processing method executed by a processor of a management device, comprising: Generate primary shares by dividing the original information using a secret sharing scheme; generating secondary shares by further dividing a portion of the primary shares using a secret sharing scheme; The secondary dispersion pieces are generated a plurality of times with different division patterns; storing, in a restoration device, primary dispersion pieces that have not been used to generate the secondary dispersion pieces among the primary dispersion pieces; A part of the secondary dispersion pieces divided according to the first division pattern is stored in the restoration device; An information processing method, further comprising storing the remaining secondary dispersion pieces obtained by dividing the secondary dispersion pieces according to the first division pattern in an external storage device.

17. 17. The information processing method according to claim 16, further comprising the step of sending a portion of the secondary distributed pieces to be used in a next restoration to the restoration device in response to a request from the restoration device.

18. 18. The information processing method according to claim 16, further comprising the step of: storing, in the external storage device connected to said external storage device, a portion of the secondary dispersion pieces to be used in the next restoration.

Citation Information

Patent Citations

  • Computer program, secret management method, and system

    JP2017126321A