Information management system and information management method
The information management system addresses the security gap in managing nuclear fuel waste extraction by using secret dispersion and authentication processes to ensure that only relevant administrators access sensitive information, thereby enhancing overall security.
Patent Information
- Application Number
- JP2023197230
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-21
- Publication Date
- 2025-06-02
AI Technical Summary
Existing information management systems for nuclear fuel waste extraction lack the capability to securely manage secret information across multiple administrators without disclosing it to non-relevant parties, thereby compromising overall security.
An information management system that includes a secret dispersion processing unit, an administrator authentication input processing unit, a partial work location decryption unit, and a partial work plan data display unit, which performs secret dispersion processing, authenticates administrators, decrypts partial work plan data, and displays it only to authenticated administrators.
The system effectively manages secret information related to nuclear fuel waste extraction by ensuring that only relevant administrators have access to specific data, thereby enhancing overall security and compliance.
Smart Images

Figure 2025083697000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information management system and an information management method for managing, without disclosing to non - relevant persons, a working space and working hours corresponding to a process for taking out waste containing nuclear fuel.
Background Art
[0002] As background art in this technical field, there is Patent Document 1 which describes a method for managing nuclear fuel waste. Patent Document 1 describes that "management information is written into an RFID, and associated information related to a database in an information terminal and information necessary for nuclear material protection management are registered and managed" (paragraphs 0023, 0024). Also, Patent Document 1 describes that "the individual information of waste stored in a storage container is written into an RFID by a portable information terminal and registered in the database in the portable information terminal. As a result, the storage container, which is a management target unit, always moves together with the management information stored in its RFID, and the data is distributedly managed" (paragraph 0018). Furthermore, Patent Document 1 describes that "by performing management using a portable information terminal with limited access to the database, the information security is enhanced" (paragraph 0019).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In an actual field, the administrators are different for each step of waste treatment, and the content of the information managed as a secret also often differs for each step. However, Patent Document 1 focuses on easily obtaining the secret information of a nuclear fuel handling facility. That is, Patent Document 1 lacks the idea of improving the overall security level by informationally separating a plurality of administrators from each other. Therefore, an object of the present invention is to manage the secret information regarding the extraction of nuclear fuel waste without disclosing it to anyone other than the relevant parties.
Means for Solving the Problems
[0005] The information management system of the present invention includes a secret dispersion processing unit that creates secret-dispersed data by performing secret dispersion processing for each step on the secret-dispersion target data related to the steps for extracting fuel debris as nuclear fuel waste, an administrator authentication input processing unit that authenticates a plurality of administrators in charge of each of the steps, and a partial work location decryption unit that creates partial work plan data by performing decryption processing on the secret-dispersed data related to the step in charge of the administrator on the condition that the plurality of administrators have been authenticated, and a partial work plan data display unit that displays the partial work plan data to the authenticated administrator. Other means will be described in the mode for carrying out the invention.
Effects of the Invention
[0006] According to the present invention, the secret information regarding the extraction of nuclear fuel waste can be managed without disclosing it to anyone other than the relevant parties.
Brief Description of the Drawings
[0007]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8A
Figure 8B
Figure 9
Modes for Carrying Out the Invention
[0008] Hereinafter, embodiments of the present invention (referred to as "the present embodiments") will be described in detail with reference to the drawings. The present embodiments are an example of removing fuel debris (molten fuel that has cooled and solidified) in the decommissioning process of a nuclear power plant in a power plant. However, the present invention is not limited to nuclear power plants and can be generally applied to sites where nuclear fuel waste is discharged.
[0009] (Hardware Configuration of the Information Management System) FIG. 1 is a diagram for explaining the hardware configuration of the information management system 1. The information management system 1 is a general computer. The information management system 1 includes a central control device 11, input devices 12 such as a mouse and a keyboard, output devices 13 such as a display, a main memory device 14, an auxiliary storage device 15, and a communication device 16.
[0010] The secret - dispersion processing unit 21, the administrator authentication input processing unit 22, the activity information input unit 23, the partial work location decryption unit 24, and the partial work plan data display unit 25 in the main memory device 14 are programs. In the following description, when the subject is described as "○○ unit is", it means that the central control device 11 realizes the functions (detailed later) described in advance in each program by reading each program from the auxiliary storage device 15 to the main memory device 14.
[0011] The auxiliary storage device 15 stores the data to be secret-shared 31, the secret-shared data 41, and the partial work plan data 51. The data to be secret-shared 31 stores the plant 3D model 32, the P&ID data 33, and the overall process data 34. The secret-shared data 41 stores the equipment decentralized 3D model 42, the function decentralized P&ID data 43, and the process decentralized data 44. The partial work plan data 51 stores the 3D model 52 related to the location of the fuel debris, the P&ID functional drawing data 53 for fuel debris removal, and the fuel debris removal and transfer process data 54. The auxiliary storage device 15 may have a configuration independent of the information management system 1.
[0012] (Data to be secret-shared) The data to be secret-shared 31 is the original data (source data) regarding the extraction of nuclear fuel waste. Among these, the plant 3D model 32 is a three-dimensional drawing of the physical configuration of the nuclear power plant. The P&ID data 33 is information indicating the components to be disassembled in the nuclear power plant, the components of the surrounding environment, the robots involved in disassembly, the logical connection relationships through piping of equipment, the relationships of the flow of things, etc. P&ID is the abbreviation of "Process & Instrumentation Diagram". The overall process data 34 is information regarding all the processes related to the extraction of nuclear fuel waste in the nuclear power plant.
[0013] Each of the plant 3D model 32, the P&ID data 33, and the overall process data 34 has not yet undergone "secret-sharing processing" at the stage of being managed as the data to be secret-shared 31. Secret-sharing processing includes encrypting information, dividing one piece of integrated information into multiple parts, storing the information in different logical or physical areas that cannot be accessed at once, and limiting the administrators who have the right to access and decrypt the information.
[0014] (Secret-shared data) The secret-shared data 41 is the result after performing secret-sharing processing on the data 31 to be secret-shared. The contents of the facility-distributed 3D model 42, the function-distributed P&ID data 43, and the process-distributed data 44 are the same as the contents of the plant 3D model 32, the P&ID data 33, and the overall process data 34 before the secret-sharing processing is performed, respectively. However, each of the facility-distributed 3D model 42, the function-distributed P&ID data 43, and the process-distributed data 44 has already undergone "secret-sharing processing" at the stage of being managed as the secret-shared data 41. Due to drawing limitations, for example, the facility-distributed 3D model 42 is represented as a single cylindrical shape, but is distributed and stored in different regions for each process.
[0015] (Partial work plan data) The partial work plan data 51 is the result after performing partial decryption processing on the secret-shared data 41. "Partially" means "for the purpose of disclosing only to the managers in charge of the relevant process" and "without decrypting other parts". The contents of the 3D model 52 related to the location of the fuel debris, the P&ID functional drawing data 53 for fuel debris removal, and the process data 54 for fuel debris removal and transfer are the same as the corresponding parts of the contents of the facility-distributed 3D model 42, the function-distributed P&ID data 43, and the process-distributed data 44 before the decryption processing is performed, respectively. That is, the partial work plan data 51 is information about the work site that is displayed only to the relevant parties (managers).
[0016] FIG. 2 is a diagram for explaining the functional configuration of the information management system 1. The secret-sharing processing unit 21 takes the administrator group information 61 and the data 31 to be secret-shared as inputs and creates (performs secret-sharing processing on) the secret-shared data 41. The administrator group information 61 associates a plurality of administrators with each of a plurality of processes. For example, the administrators 1 and 2 in charge of process 1 cooperate with each other and check and balance each other.
[0017] Managers 1 and 2 belong to a certain vendor (contractor) entrusted with Process 1 by the operator of the nuclear power plant. Managers 3 and 4 belong to another vendor entrusted with Process 2 by the operator of the nuclear power plant. There is a so-called "responsibility demarcation point" between Process 1 and Process 2. Simply put, the responsibility demarcation point refers to when and in what state to take over the previous process and when and in what state to hand it over to the subsequent process. Managers 1 and 2 are not informed of the specific work content of Process 2. Managers 3 and 4 are not informed of the specific work content of Process 1. However, by clarifying the responsibility demarcation point and having multiple vendors take responsibility for the processes they are in charge of and abide by their secrets, the overall reactor decommissioning process proceeds safely.
[0018] When multiple managers corresponding to any one process of the manager group information 61 are simultaneously authenticated, the manager authentication input processing unit 22 activates the activity information input unit 23. The activity information input unit 23 identifies the activity information (information related to the process) corresponding to the manager.
[0019] The partial work location decoding unit 24 creates (performs decoding processing on) the partial work plan data 51 using the secret-shared data 41 as input data. Furthermore, the partial work plan data display unit 25 displays the combined partial work plan data 51 to the responsible manager.
[0020] Figure 3 is a diagram showing an example of the dismantling site. Figure 3 shows, for example, the nuclear power plant 1101 where core fuel melting has occurred. Figure 3 is also an example of the plant 3D model 32. The nuclear power plant 1101 stores the containment vessel 1102 and the pressure vessel 1103 in a multi-layer structure, and stores the fuel assembly 1104 inside the pressure vessel 1103.
[0021] In the nuclear power plant 1101 where core fuel melting occurred, fuel debris 1105, 1106, and 1107 exist in the fuel assembly 1104, the lower part of the pressure vessel 1103, and the lower part of the pedestal 1108. In the decommissioning work of such an accident reactor, due to the high radioactivity of the accident reactor, people cannot approach and work. Instead of people, an underwater work robot 1111, a robot 1112 that moves a storage can 1109 containing fuel debris pieces, a transport vehicle 1113 that moves a storage can 1110 taken out of the nuclear power plant 1101, etc. perform the work. These are remotely operated.
[0022] In the future, depending on the amount of fissile uranium contained in the fuel debris, it is necessary to secretly proceed with the work outside the relevant parties regarding the location and movement time of the taken-out fuel debris pieces, and to take security measures against theft and sabotage of nuclear fuel-containing substances.
[0023] Figure 4 is a diagram for explaining the work process. Figure 4 is also an example of the overall process data 34. As shown in Figure 3, the fuel debris solidifies as an individual in the fuel assembly 1104 in the storage container 1102, the lower part of the pressure vessel 1103, and the lower part of the pedestal 1108, and is taken out and recovered externally by cutting through remote work. The process of the remote work at this time consists of, for example, three steps: robot placement 1301, debris cutting 1302, and cut object transfer 1303. In order to facilitate the processing of the information management system 1, as shown in Figure 4, activity IDs (A1, A2, and A3) are given to each step as unique identifiers. In this embodiment, the step and the activity are the same.
[0024] Also, for each of the activities A1, A2, and A3, as the work start time, t 1s , t 2s and t 3s are given, and as the work end time, t 1e , t 2e and t 3e are given. The work content and work time of the process of handling the fuel debris are identified by the activity ID, the work start time, and the work end time.
[0025] Figure 5 is a diagram for explaining the functional connection relationships at the site. Figure 5 shows the object to be disassembled, the components of the surrounding environment, the robots involved in disassembly, the logical connection relationships through equipment piping, etc., and the relationships of the flow of things, etc. It is also known as Process & Instrumentation Diagram (P&ID) for short. That is, Figure 5 is also an example of the P&ID data 33.
[0026] First, in water, the recovery robot 1204 (PI 2 ) cuts the fuel debris from the pedestal 1205 (PI 1 ) and horizontally transfers it to the relay container 1206 (PI 3 ). Next, the recovery robot 1204 (PI 2 ) vertically transfers the cut pieces of the fuel debris from the relay container 1206 (P1 3 ) in water to the recovery container 1203 (PI 4 ) in the air. Note that "PI 1 " etc. are symbol IDs that are identifiers uniquely specifying the graphical figures indicating parts related to the process.
[0027] The inside of the recovery container 1203 (PI 4 ) is washed and dehydrated by the water flow supplied from the makeup water tank 1201 when the valve 1202 is "open" and the valve 1207 is "open". The functional connection relationships described in the P&ID are essential for understanding the work procedures.
[0028] Figure 6 is an example of the management master table. The management master table 1001 in Figure 6 is a representative example of the data 31 to be decentralized in Figure 1. Furthermore, the management master table 1001 in Figure 6 is obtained by adding the information of the administrator group information 61 (Figure 2) to the data 31 to be decentralized (Figure 1).
[0029] The management master table 1001 uses the activity ID (column 1311) and the administrator ID (column 1314) as the main keys for searching. The work start time 1312, work end time 1313, part ID 1100, and symbol ID 1200 corresponding to these are called the secret sharing target information 2001. In the present embodiment, the part ID, which is an identifier that uniquely identifies the part itself (pedestal, recovery robot, relay container, ···), and the symbol ID, which is an identifier that uniquely identifies the figure indicating the part, are distinguished. Spatial coordinate values are stored in association with the part ID and the symbol ID. After the secret sharing target information 2001 is converted into a plurality of secret sharing data 41 by the secret sharing process (FIG. 8A), the secret sharing target information 2001 itself is discarded or isolated so that it cannot be accessed by normal means.
[0030] FIG. 7 is an example of secret sharing data. The secret sharing data 2002 in FIG. 7 is a representative example of the secret sharing data 41 shown in FIG. 1. The secret sharing processing unit 21 digitizes each of the secret sharing target data 31 and makes it the target of the secret sharing process. The secret sharing processing unit 21 sets three values: the number n to be distributed (for example, "6"), the number k of the number n required for restoration (for example, "3"), and a large prime number m. m is proven to be a prime number, for example, "2 127 -1", which prevents a malicious person from factorizing the result of multiplying the numerical value by m in a short time by the brute-force method. In the present embodiment, for the sake of explanation, the secret sharing data and the secret sharing information are distinguished, and also the secret sharing target data and the secret sharing target information are distinguished.
[0031] The secret sharing processing unit 21 uses Shamir's secret sharing method. For example, the work start time t associated with the activity ID "A1", the administrator ID "H1", and the administrator ID "H2" 1sDisperse “20230919 13:43” (symbol 1312a) among 6 pieces of “secret information”. Each of the secret information here is a 1-digit + 32-digit number. The 6 pieces of secret information constitute 1 piece of secret dispersion information. The secret dispersion processing unit 21 performs the same processing for the work end time (symbol 1313a) corresponding to the work start time. The secret dispersion processing unit 21 can also disperse any information included in the secret dispersion target data 31 into secret information, in addition to the work start time and work end time. Shamir's secret dispersion method is described in “A. Shamir, “How to share a secret”, communication of the ACM 22 (1979) PP. 612-613)”.
[0032] Unless k values out of the 6 pieces of secret information are aligned, this work start time cannot be decrypted. For example, by storing the values divided into 6 pieces in 6 physically isolated storage devices and managing them so that the divided values cannot be retrieved without a specific authentication process, malicious decryption of the original data can be prevented.
[0033] Figure 8A is a flowchart of the secret dispersion process. In step S21, the secret dispersion processing unit 21 of the information management system 1 sets a sufficiently large prime number m. In step S22, the secret dispersion processing unit 21 sets the number n to be dispersed and the number k required for restoration.
[0034] In step S23, the secret sharing processing unit 21 first accepts, via the input device 12, the input of the administrator group information 61 (FIG. 2) by the user (administrator). Then, the secret sharing processing unit 21 creates a management master table 1001 (FIG. 6). Subsequently, the secret sharing processing unit 21 encrypts the start time of work, end time of work, part information (e.g., part name, identifier for specifying the part, etc.) and symbol ID associated with the activity ID and administrator ID by the method described in FIG. 7, and then distributes the encrypted information into secret information, and stores the distributed secret information in separate storage areas. Note that a symbol is something like an icon that graphically represents a part.
[0035] Specifically, the secret sharing processing unit 21 uses Shamir's secret sharing method to create a k - 1 degree polynomial f(x) with a constant term of s where the secret information is s. Then, the secret sharing processing unit 21 uses the coordinates of the points (i, f(i)) (i = 1, 2, ···, n) through which f(x) passes as the secret sharing information (see FIG. 7). Note that "ISO / IEC 19592-2:2047 Information technology - Security techniques - Secret sharing - Part 2: Fundamental mechanisms" stipulates five representative types of secret sharing processing as international standards. Shamir's secret sharing processing (Shamir secret sharing scheme) is one of the international standards.
[0036] FIG. 8B is a flowchart of the decryption process. The decryption process is a process of collecting at least k pieces of 1 - digit + 32 - digit secret information that has been secret - shared in FIG. 8A and decrypting it. In step S31, the administrator authentication input processing unit 22 of the information management system 1 confirms that two administrators have authenticated (simultaneous authentication) within a predetermined time. When two administrators have authenticated within a predetermined time, the partial work location decoding unit 24 performs a decoding process on the secret-shared data on the assumption that the conditions for the decoding process are satisfied. When the management master table 1001 defines a plurality of three or more administrators, simultaneous authentication of three or more administrators may be required.
[0037] In step S32, the activity information input unit 23 of the information management system 1 confirms and acquires secret-shared information (see FIG. 7) about the activities (processes) assigned to two administrators. In step S33, the partial work location decoding unit 24 of the information management system 1 decodes the work start time, work end time, part ID, and symbol ID corresponding to the activity ID from the secret-shared information. In step S34, the partial work plan data display unit 25 of the information management system 1 visualizes (for example, displays on the output device 13) the spatial information and functional connection relationships of the processes assigned to two administrators, together with the work start time and work end time, as partial work plan data.
[0038] Regarding FIG. 8A, the secret sharing processing unit 21 basically performs the secret sharing process for each process (activity). This is because the secret sharing processing unit 21 can use different algorithms for each process. Of course, the secret sharing processing unit 21 may also perform the secret sharing process for all processes at once. On the other hand, regarding FIG. 8B, after the authentication of the administrator of a certain process, the partial work location decoding unit 24 performs the decoding process for each such process.
[0039] Figure 9 is an example of the visualization display after decrypting the secret-shared information. The partial work plan data display unit 25 synchronizes the same or different terminals operated by administrator 1 and administrator 2 and launches the partial work plan data display application 6000. When administrator 1 clicks the authentication button 6031, the partial work plan data display unit 25 authenticates the login ID 6011 and password etc. entered by administrator 1.
[0040] For the sake of convenience of explanation, now, assume that administrator 1 and administrator 2 are only in charge of the process "A3 cutting material transfer" 6325 and do not have the display authority for spatial information etc. of the processes "A1 robot placement" 6323 and "A2 debris cutting" 6324. When administrator 2 clicks the authentication button 6032 within a preset time range (for example, within 30 seconds after administrator 1 clicks the authentication button 6031), the partial work plan data display unit 25 authenticates the login ID 6012 and password etc. entered by administrator 2. If these two simultaneous authentications are not established, the partial work plan data display unit 25 does not enable the partial work plan data display application 6000.
[0041] In the example of Figure 9, the activity ID is not the secret-shared target information 2001 (Figure 6). Therefore, when administrator 1 or 2 clicks the "previous activity display button" 6101 or "next activity display button" 6102, the partial work plan data display unit 25 displays the names and activity IDs (symbols 6323 and 6324) of the previous and next activities. However, the partial work plan data display unit 25 does not display any other information about the previous and next activities. When administrator 1 and administrator 2 are simultaneously authenticated, the coordinate display button 6341, the process display button 6342, and the process display button 6343 can be clicked.
[0042] When Manager 1 or Manager 2 clicks the coordinate display button 6341, the partial work plan data display section 25 uses the partial work plan data 51 to display only the portion related to the process "Transfer of Cut Pieces in Process A3" among the spatial arrangements of the fuel debris as spatial information (column 6333). At this time, the partial work plan data display section 25 also displays the spatial coordinates, the surrounding environment, and the operating postures of the remote operation robots. Information inside the storage container is not displayed in column 6333. This is because the processes "Robot Placement in Process A1" and "Debris Cutting in Process A2" inside the storage container are not the responsibility of Manager 1 and Manager 2.
[0043] When Manager 1 or Manager 2 clicks the process display button 6342, the partial work plan data display section 25 partially displays the start time and end time of the work as the work time related only to the transfer of the cut pieces (column 6334).
[0044] When Manager 1 or Manager 2 clicks the process display button 6343, the partial work plan data display section 25 displays the relationship between the relay container 6314 and the collection container 6315 as the process information 6313 related only to the transfer of the cut pieces, and displays the collection speed, the upper limit of the collection amount, etc. as the performance-related attribute information related thereto.
[0045] From the above, according to the information management system of the present embodiment, in the state of the fuel debris being taken out, by notifying only a plurality of and the minimum necessary relevant persons of the work time, the work location, etc., the work can proceed in accordance with the security rules corresponding to the plant in operation.
[0046] (Modification Example 1) A nuclear power plant includes many components other than the reactor. Focusing on the specific content of the data 31 to be decentralized for secrecy, while there are attributes (such as radiation dose) that are particularly important and should be strictly subject to secrecy decentralization processing, there are also attributes (such as weather conditions) with relatively less importance. And the importance varies from process to process and often changes over time. Therefore, the secrecy decentralization processing unit 21 may accept the administrator's designation of the attributes for which secrecy decentralization processing should be performed for each process among the attributes of the data 31 to be decentralized for secrecy.
[0047] (Modification Example 2) Even if two administrators are authenticated almost simultaneously in terms of time, if other persons can peek at the display screen, the secret cannot be protected. Therefore, the partial work plan data display unit 25 may display the partial work plan data 51 on an output device arranged in a space where no one other than the two administrators exists. The partial work plan data display unit 25 confirms that no person other than the administrator to be authenticated exists in the image of the space captured by the camera serving as the input device 12.
[0048] (Modification Example 3) The data 31 to be decentralized for secrecy may include the radiation dose of the fuel debris for each process, each process, or each time. The greater the radiation dose, the more strictly the secret should be protected. Therefore, when the data 31 to be decentralized for secrecy includes the radiation dose of the fuel debris, the administrator authentication input processing unit 22 may set the number of administrators to be authenticated according to the radiation dose. The administrator authentication input processing unit 22 applies, for example, a plurality of thresholds TH1, TH2, TH3,... (TH1 < TH2 < TH3 <...) to the radiation dose x. Moreover, the administrator authentication input processing unit 22 may require the authentication of two administrators when x < TH1, require the authentication of three administrators when TH1 ≤ x < TH2, require the authentication of four administrators when TH2 ≤ x < TH3, and so on. Note that "radiation dose" is a concept including the radiation dose itself, the time differential value (change rate) of the radiation, and the time integral value of the radiation dose.
[0049] (Modification Example 4) Furthermore, in Modification Example 1, the secret sharing processing unit 21 may automatically set, according to the radiation dose, the attributes of the data 31 to be secret shared for which secret sharing processing should be performed for each process, without waiting for a designation by the administrator.
[0050] (Modification Example 5) In the above, authentication by a plurality of administrators was the condition for performing the decryption process. However, even when transmitting the encrypted secret shared data 41 itself from the information management system 1 to any other device in its encrypted state, it is preferable that authentication by a plurality of administrators be performed at the transmission destination or the transmission source. Therefore, the administrator authentication input processing unit 22 may transmit the secret shared data 41 to the device designated by the administrator without performing the decryption process, on the condition that authentication by a plurality of administrators has been performed.
[0051] (Modification Example 6) The above is an example in which the secret sharing processing unit 21 performs the secret sharing process using Shamir's secret sharing method. However, for more rigorous secret retention, the secret sharing processing unit 21 can also perform the secret sharing process using other algorithms. Generally, when there are a plurality of available algorithms, the secret sharing processing unit 21 can change the algorithm for the secret sharing process according to an instruction from the user (administrator) or automatically. Furthermore, the secret sharing processing unit 21 can also change the algorithm for each process.
[0052] (Effects of the Embodiment) (1) The information management system can display partial work plan data related to a specific process for taking out the fuel debris only to the administrators in charge of the specific process, after restraining each other among the administrators. (2) The information management system can decrypt the secret shared data only when two administrators are authenticated almost simultaneously. (3) The information management system can use, as data to be secret shared, the work start time, work end time, etc. of the process. (4) The information management system can display spatial information and the like regarding the processes for which the administrator is in charge. (5) The information management system can store the data to be secret-shared in a secure storage area in a secure state.
[0053] (6) The information management system can cause the administrator to specify the attributes of the information to be made secret. (7) The information management system can prevent unauthorized persons other than the administrator from peeking at the information to be made secret. (8) The information management system can set the number of administrators to be authenticated according to the radiation dose of the fuel debris. (9) The information management system can set the attributes for which secret-sharing processing should be performed according to the radiation dose of the fuel debris. (10) Even when transmitting the secret-shared data without decrypting it, the information management system can authenticate the administrator. (11) The information management system can prevent persons other than the administrator in charge of the secret-sharing processing algorithm from knowing it.
[0054] Note that the present invention is not limited to the above-described embodiments, and includes various modifications. For example, the above-described embodiments have been described in detail for easy understanding of the present invention, and are not necessarily limited to those having all the configurations described. Also, a part of the configuration of one embodiment can be replaced with the configuration of another embodiment, and the configuration of another embodiment can be added to the configuration of one embodiment. Also, for a part of the configuration of each embodiment, addition, deletion, or replacement with other configurations is possible.
Description of Reference Numerals
[0055] 1 Information management system 11 Central control device 12 Input device 13 Output device 14 Main memory device 15 Auxiliary storage device 16 Communication device 21 Secret sharing processing unit 22 Administrator authentication input processing unit 23 Activity information input unit 24 Partial work location decoding unit 25 Partial work plan data display unit 31 Secret sharing target data 32 Plant 3D model 33 P&ID data 34 Overall process data 41 Secret sharing data 42 Facility decentralized 3D model 43 Function decentralized P&ID data 44 Process decentralized data 51 Partial work plan data 52 Fuel debris location related 3D model 53 Fuel debris extraction P&ID functional drawing data 54 Fuel debris extraction and movement process data
Claims
1. A secret distribution processing unit that creates secret-distributed data by performing secret distribution processing for each process on data to be secret-distributed related to a process for retrieving fuel debris as nuclear fuel waste, An administrator authentication input processing unit that authenticates a plurality of administrators in charge of each of the processes, A partial work location decryption unit that creates partial work plan data by performing decryption processing on the secret-distributed data related to the process in charge of the administrator on the condition that the plurality of administrators have been authenticated, A partial work plan data display unit that displays the partial work plan data to the authenticated administrator, An information management system comprising the above.
2. The administrator authentication input processing unit, When authenticating two of the administrators within a predetermined time, it is assumed that the condition is satisfied, The information management system according to claim 1, characterized in that.
3. The secret distribution processing unit, Using any one of the work start time, work end time, information on parts used in the process, and symbols that graphically represent the parts in the process as the data to be secret-distributed, The information management system according to claim 1, characterized in that.
4. The partial work plan data display unit, Based on the partial work plan data, display the spatial information about the process in charge of the authenticated administrator, as well as the work start time and work end time of the process, The information management system according to claim 1, characterized in that.
5. The secret distribution processing unit, Dividing and encrypting the data to be secret-distributed and storing it dispersedly in a plurality of storage areas that cannot be accessed at once, The information management system according to claim 1, characterized in that.
6. The secret distribution processing unit, Receiving the designation by the administrator of the attributes to be subject to secret distribution processing for each process among the attributes of the data to be secret-distributed, The information management system according to claim 1, characterized in that.
7. The partial work plan data display unit, Displaying the partial work plan data on an output device arranged in a space where there are no people other than the two administrators, The information management system according to claim 2, characterized in that.
8. The data to be secret-distributed, Including the radiation dose of the fuel debris, The administrator authentication input processing unit, Setting the number of administrators to be authenticated according to the radiation dose, The information management system according to claim 1, characterized in that
9. The secret sharing processing unit According to the radiation dose, Among the attributes of the data to be secretly shared, set the attributes for which the secret sharing process should be performed for each process. The information management system according to claim 8, characterized in that
10. The administrator authentication input processing unit On the condition that the authentication of the plurality of administrators has been performed, transmit the secretly shared data to the device designated by the administrator without performing a decryption process. The information management system according to claim 1, characterized in that
11. The secret sharing processing unit Change the algorithm of the secret sharing process. The information management system according to claim 1, characterized in that
12. The secret sharing processing unit of the information management system Create secretly shared data by performing a secret sharing process for each process on the data to be secretly shared related to the process for removing fuel debris as nuclear fuel waste. The administrator authentication input processing unit of the information management system Authenticate a plurality of administrators in charge of each of the processes. The partial work location decryption unit of the information management system On the condition that the authentication of the plurality of administrators has been performed, create partial work plan data by performing a decryption process on the secretly shared data related to the process in charge of the administrator. The partial work plan data display unit of the information management system Display the partial work plan data to the authenticated administrator. An information management method, characterized in that
Citation Information
Patent Citations
Waste management method using RFID
JP2010061271A