Data management system
The data management system addresses the challenge of maintaining data confidentiality and reducing costs by encrypting, splitting, and distributing data across servers, along with splitting the decryption key, ensuring effective and cost-efficient data recovery.
Patent Information
- Application Number
- JP2022033638
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-03-04
- Publication Date
- 2025-06-11
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing data restoration devices face challenges in maintaining data confidentiality while minimizing costs, particularly due to the reliance on local storage of restoration information, which can be inaccessible.
The proposed data management system employs encryption, splits the encrypted data, and stores it across different servers, while also splitting the decryption key, allowing for cost-effective data recovery and confidentiality maintenance.
This approach ensures data confidentiality and reduces costs by utilizing cloud servers for data storage and on-premises servers for critical decryption information, maintaining data recoverability even without local access.
Smart Images

Figure 2025087932000001_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a data management system and the like.
Background Art
[0002] Japanese Patent No. 6664785 describes a data restoration device. The invention described in this publication separates data into two parts. Then, after storing one part of the data via a network and storing the remaining data locally, the data is restored. This data restoration device can reduce the amount of data stored locally.
[0003] The data restoration device described in Japanese Patent No. 6664785 stores information necessary for restoring data locally. Therefore, if local access is not possible, the data cannot be restored.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] This specification aims to provide a data restoration device that can maintain data confidentiality while suppressing costs.
Means for Solving the Problems
[0006] The above problems are basically based on the finding that by encrypting data, splitting the encrypted data and storing it on another server, and also splitting the information for decrypting, it is possible to maintain data confidentiality while suppressing costs.
[0007] One invention described in this specification relates to a data management system 1. This system 1 includes an encryption unit 17, an encrypted data splitting unit 25, a decryption key splitting unit 35, a data output unit 47, and a decryption unit 51. The encryption unit 17 is an element for encrypting the original data 11 to obtain encrypted data 13 and issuing a decryption key 15 including decryption information for decrypting the encryption. The encrypted data splitting unit 25 is an element for splitting the encrypted data 13 to obtain first encrypted data 21 (chaos data) and second encrypted data 23 (piece data). The decryption key splitting unit 35 is an element for splitting the decryption key 15 to obtain a first decryption key 31 (chaos data) and a second decryption key 33 (piece data). The data output unit 47 is an element for storing the first encrypted data 21 in the first server 41, storing the second encrypted data 23 in the second server 43 (a server different from the first server 41), and storing the first decryption key 31 in the third server 45 (which may be the same as or different from the second server 43 and different from the first server 41). The decryption unit 51 is an element for decrypting the original data 11 using the first encrypted data 21, the second encrypted data 23, the first decryption key 31, and the second decryption key 33.
[0008] This system splits the encrypted data, stores it in different servers, and also splits the decryption key for decrypting the encryption, so it can reduce costs and maintain data recoverability and confidentiality. The second decryption key 33 may be stored in any one (for example, the second server 43) or stored locally. The second decryption key 33 may be code information printed on a medium. When the second decryption key 33 is code information printed on a medium, it is preferable that this system has a code information reading unit for reading the code information and inputting the second decryption key 33 into the system.
[0009] In a preferred example of the above system 1, the data volume of the first encrypted data 21 is 3 times or more and 10 times 4It is less than or equal to a certain multiple. And the first server 41 and the third server 45 may be the same or different cloud servers. The second server 43 is an on-premises server.
[0010] Although cloud servers have relatively low data management costs, their security is not high. On the other hand, on-premises servers have relatively high data management costs. In the above example, while storing a large amount of data in a server with relatively low data management costs, a part of the information necessary for data restoration is stored in a server with relatively high data management costs. Therefore, while reducing the management cost, the confidentiality of the data can be ensured.
[0011] In a preferred example of the above system 1, the data volume of the first encrypted data 21 is 3 times or more and 10 4 times or less than that of the second encrypted data 23. And the first server 41 and the third server 45 may be the same or different on-premises servers, and the second server 43 is a blockchain.
[0012] A preferred example of the above system 1 further includes a second decryption key encoding unit 55 and a second decryption key restoration unit 57. The second decryption key encoding unit 55 is an element for obtaining an encoded second decryption key 53 obtained by converting the second decryption key 33 into code information. The second decryption key restoration unit 57 is an element for restoring the second decryption key 33 based on the encoded second decryption key 53. The encoded second decryption key 53 is preferably code information printed on a medium. An example of the code information is a two-dimensional code (preferably a color two-dimensional code).
[0013] By making only a part of the decryption key be the code information printed on the medium, the data that does not exist in the server among the information necessary for data decryption can be minimized.
[0014] A preferred example of the above-described system 1 further includes a first server 41, a second server 43, and a third server 45. This system also provides a computer-based encryption and decryption method. The method is a computer-based method that includes an encryption step (S101), an encrypted data splitting step (S102), a decryption key splitting step (S103), a data output step (S104), and a decryption step (S105).
[0015] The following invention described in this specification relates to a program for causing a computer to function as the above-described system and a program for causing a computer to execute the above-described steps. The specific program causes a computer to function as a data management system that executes an encryption step (S101), an encrypted data splitting step (S102), a decryption key splitting step (S103), a data output step (S104), and a decryption step (S105).
[0016] The encryption step (S101) is a step for encrypting original data 11 to obtain encrypted data 13 and issuing a decryption key 15 including decryption information for decrypting the encryption. The encrypted data splitting step (S102) is a step for splitting the encrypted data 13 to obtain first encrypted data 21 (chaos data) and second encrypted data 23 (piece data). The decryption key splitting step (S103) is a step for splitting the decryption key 15 to obtain a first decryption key 31 (chaos data) and a second decryption key 33 (piece data). The data output step (S104) is a step for storing the first encrypted data 21 in the first server 41, storing the second encrypted data 23 in the second server 43, and storing the first decryption key 31 in the third server 45. The decryption step (S105) is a step for decrypting the original data 11 using the first encrypted data 21, the second encrypted data 23, the first decryption key 31, and the second decryption key 33.
[0017] The following invention described in this specification relates to an information recording medium readable by a computer storing the above program.
Effects of the Invention
[0018] In this way, by encrypting data, splitting the encrypted data, storing it on another server, and also splitting the information for decrypting, it is possible to maintain the confidentiality of the data while suppressing costs.
Brief Description of the Drawings
[0019]
Figure 1
Figure 2
Embodiments for Carrying Out the Invention
[0020] Hereinafter, embodiments for carrying out the present invention will be described with reference to the drawings. The present invention is not limited to the embodiments described below, and also includes those appropriately modified by those skilled in the art within an obvious range from the following embodiments.
[0021] FIG. 1 is a block diagram showing a data management system. This system includes a computer, and each element described below is an element implemented by the computer. The computer may be any of various terminals, mobile terminals, notebook computers, personal computers, servers, and computer-server systems. Also, this system may be implemented by a processor, or may be implemented by the cooperation of various hardware and software such as programs. The computer has a processor, and the processor may perform various functions and processes.
[0022] A computer has an input unit, an output unit, a control unit, an arithmetic unit, and a storage unit, and each element is connected by a bus or the like so that information can be exchanged. For example, a program may be stored in the storage unit, or various types of information may be stored. The computer may have a processor and perform various operations and various processes based on the instructions of the program. When predetermined information is input from the input unit, the control unit reads out the control program stored in the storage unit. Then, the control unit appropriately reads out the information stored in the storage unit and transmits it to the arithmetic unit. Also, the control unit appropriately transmits the input information to the arithmetic unit. The arithmetic unit performs arithmetic processing using the received various types of information and stores it in the storage unit. The control unit reads out the arithmetic result stored in the storage unit and outputs it from the output unit. In this way, various processes are executed. Each element described below may correspond to any element of the computer. Examples of the output unit are a monitor and a screen.
[0023] As shown in FIG. 1, this system 1 has an encryption unit 17, an encrypted data division unit 25, a decryption key division unit 35, a data output unit 47, and a decryption unit 51. Also, as shown in FIG. 1, this system 1 may further have a second decryption key encoding unit 55 and a second decryption key restoration unit 57.
[0024] FIG. 2 is a flowchart for explaining an encryption and decryption method. As shown in FIG. 2, this method includes an encryption step (S101), an encrypted data division step (S102), a decryption key division step (S103), a data output step (S104), and a decryption step (S105). Also, as shown in FIG. 2, this method may further have a second decryption key encoding step (S201) and a second decryption key restoration step (S202).
[0025] Encryption step (S101) The encryption unit 17 of system 1 encrypts the original data 11 to obtain encrypted data 13 and issues a decryption key 15 that includes decryption information for decrypting. To encrypt and then revert information, it is necessary to know the rules for encryption. The information regarding these rules is the decryption key. Using the decryption key, the encrypted data can be reverted to the original data. Encryption methods are already known. Therefore, encryption can be performed using known methods. For example, the control unit reads necessary information from the storage unit based on the commands of the control program stored in the storage unit and causes the arithmetic unit to perform various operations. In this way, this system can obtain the rules for encryption. This system stores in the storage unit, as the decryption key, the obtained rules for encryption and the rules for reverting the information encrypted based on those rules. Also, this system reads the original data 11 from the storage unit and reads the rules for encryption from the storage unit, causes the arithmetic unit to perform the encryption process, and obtains the encrypted data 13 obtained by encrypting the original data 11. The obtained encrypted data 13 may be stored in the storage unit. In the example shown in FIG. 1, for the original data 11 which is binary data, after performing the randomization process twice, the data is compressed, and the compressed data is obtained as the encrypted data 13. Thus, data may be appropriately compressed after the encryption process.
[0026] Encrypted Data Division Step (S102) The encryption data splitting unit 25 of the system 1 splits the encrypted data 13 to obtain the first encrypted data 21 (chaos data) and the second encrypted data 23 (piece data). The encrypted data 13 is stored in the storage unit. Then, upon receiving a program instruction, the system reads out the encrypted data 13 from the storage unit and causes the arithmetic unit to perform a process of splitting the encrypted data 13. In this way, the system obtains the first encrypted data 21 and the second encrypted data 23. The first encrypted data is also called chaos data, and the second encrypted data is also called piece data. It is preferable to split the encrypted data 13 so that the encrypted data 13 or the data from which the encrypted data 13 is derived cannot be restored using only the chaos data or only the piece data. For this reason, after further encrypting or compressing the encrypted data 13, it is preferably split into the first encrypted data 21 (chaos data) and the second encrypted data 23 (piece data). In the example shown in FIG. 1, the system 1 further encrypts (randomizes) the encrypted data 13 (the first encrypted data) to obtain the second encrypted data 13a. Then, the system 1 performs a compression operation on the second encrypted data to obtain the compressed encrypted data 13b. The system 1 performs a splitting process on the compressed encrypted data to obtain the first encrypted data 21 and the second encrypted data 23. Regarding the second encryption rule and compression method at this time, it is preferably possible to restore the original information (encrypted data 13) using, for example, a decryption key issued for each user. Note that the first encrypted data 21 (chaos data) may be further split and stored in a plurality of servers.
[0027] Let the data volume ratio (the first data volume ratio) be the data volume of the first encrypted data 21 (chaos data) / the second encrypted data 23 (piece data). In this case, the data volume ratio is preferably 3 or more and 10 4 or less, more preferably 3 or more and 10 3 or less, and may also be 3 or more and 10 2 or less, and may also be 4 or more and 10 2 or less, or may be 10 or more and 10 4 or less.
[0028] Decryption key splitting step (S103) The unlocking key splitting unit 35 of the system 1 splits the unlocking key 15 to obtain a first unlocking key 31 (chaos data) and a second unlocking key 33 (piece data). This step may be a step after the encrypted data splitting step (S102), a previous step, or a step performed simultaneously. The unlocking key 15 is stored in the storage unit. Then, the system receives a program command, reads out the unlocking key 15 from the storage unit, and causes the arithmetic unit to perform a process of splitting the unlocking key 15. The system may obtain the first unlocking key 31 and the second unlocking key 33 after randomizing or encrypting the unlocking key 15. In this way, the system obtains the first unlocking key 31 and the second unlocking key 33. The first unlocking key is also called chaos data, and the second unlocking key is also called piece data. It is preferable to split the unlocking key 15 so that the unlocking key 15 or the data that was the basis of the unlocking key 15 cannot be restored with only the chaos data or only the piece data.
[0029] Let the data volume ratio (second data volume ratio) be the data volume of the first unlocking key 31 (chaos data) / the second unlocking key 33 (piece data). In this case, the data volume ratio is preferably 3 or more and 10 4 or less, preferably 3 or more and 10 3 or less, and may be 3 or more and 10 2 or less, and may be 4 or more and 10 2 or less, or may be 10 or more and 10 4 or less.
[0030] Data output step (S104) The data output unit 47 of system 1 causes the first encrypted data 21 to be stored in the first server 41, the second encrypted data 23 to be stored in the second server 43, and the first decryption key 31 to be stored in the third server 45. The data output unit 47 of system 1 outputs each data towards each server. Then, the storage unit of each server stores the received each data in a readable manner. The second server 43 is a server different from the first server 41. The second server 43 is preferably a server installed in a facility different from the first server 41. The third server 45 may be the same as or different from the second server 43, and is a server different from the first server 41. The third server 45 is preferably also a server installed in a facility different from the first server 41.
[0031] The second decryption key is preferably deleted from all storage devices as data other than electronic data. Or, the second decryption key may be stored only in a stand-alone computer not connected to the Internet and used only when restoring data or the decryption key. Or, the second decryption key is preferably backed up in a stand-alone computer, left as data other than electronic data, and deleted from other media. Hereinafter, an example in which the second decryption key 33 is stored encoded in a medium will be described.
[0032] Second decryption key encoding step (S201) The second release key encoding unit 55 is an element for obtaining an encoded second release key 53 obtained by converting the second release key 33 into code information. The encoded second release key 53 is preferably code information printed on a medium. An example of the code information is a two-dimensional code (preferably a color two-dimensional code). Instead of encoding the second release key 33, either the first encrypted data 21 (chaos data) or the second encrypted data 23 (peace data) (preferably the second encrypted data 23 (peace data)) may be encoded. However, by converting the second release key 33 related to the release key into code information instead of the data related to the original data 11, the confidentiality can be enhanced while improving the restorability of the original data 11.
[0033] The second release key encoding unit 55 converts the second release key (peace data) 33 into code information to obtain an encoded second release key 53. The encoded second release key 53 is information for outputting code information. For example, a control unit and an arithmetic unit of a computer function as the second release key encoding unit 55. The control unit can obtain the encoded second release key by causing the arithmetic unit to perform an appropriate operation on the second release key based on a program command. The encoded second release key obtained in this way is appropriately stored in a storage unit. Methods and apparatuses for encoding data are known. For example, Japanese Patent No. 6664785 (Patent Document 1) describes a data code generation server. Japanese Patent No. 5945376 describes a two-dimensional code generation apparatus. By using such an apparatus, data can be encoded. An example of the encoded second release key is AQR code (registered trademark) information for printing a color QR code (registered trademark). The encoded second release key may be stored in an encoded second release key storage unit 29 described later.
[0034] The second decryption key output unit of the system 1 outputs the second decryption key after outputting it as the second decryption key. For example, the control unit, arithmetic unit, and output unit (printer, interface, and communication unit) of a computer function as the second decryption key output unit. The output unit preferably includes a color printer. The second decryption key after output may be identification information capable of reading the second decryption key stored in the second decryption key storage unit. In this case, when the second decryption key after output is input, the computer can read the second decryption key from the storage unit using the second decryption key after output.
[0035] An example of the second decryption key after output is a color QR code (registered trademark) printed on a medium. Another example of the second decryption key after output is code information recognized by ultraviolet or infrared rays printed on a medium. In this case, the code information reading unit reads the second decryption key based on the code information recognized by ultraviolet or infrared rays. Preferred examples of the second decryption key after output include code information recognized by ultraviolet or infrared rays in addition to visible code information (QR code (registered trademark) or color QR code (registered trademark)). In this case, for example, even if someone copies the medium and copies the visible code information part, the code information recognized by ultraviolet or infrared rays cannot be restored, so the second decryption key after output cannot be completely copied, preventing unauthorized use. Another example of the second decryption key after output is a QR code (registered trademark) transmitted to a personal terminal (e.g., a mobile terminal). In this case, related terminals and identification information (e-mail address) related to the previous individual can be registered, and the second decryption key after output can be transmitted using the registered identification information.
[0036] For example, it is preferable that the computer stores in the storage unit so that the second decryption key and the second decryption key can be restored based on the second decryption key after output.
[0037] The code information reading unit is an element for reading the second encoding release key based on the second encoding release key after output. For example, the input unit of a computer, or the input unit, control unit, and arithmetic unit function as the code information reading unit 25. For example, Japanese Patent No. 6664785 (Patent Document 1) and Japanese Patent No. 5945376 describe an apparatus for reading a two-dimensional code. For example, a photographing unit connected to a computer functions as the code information reading unit 25. For example, hold the second encoding release key after output (a color QR code (registered trademark) printed on a medium or a color QR code (registered trademark) displayed on a mobile terminal) in front of the photographing unit. Then, the photographing unit photographs the second encoding release key after output and inputs the photographed image into the system. The control unit causes the arithmetic unit to analyze the image based on the instruction of the program, and reads the second encoding release key from the storage unit based on the second encoding release key after output.
[0038] Second release key restoration step (S202) The second release key restoration unit 57 is an element for restoring the second release key 33 based on the second encoding release key 53. In the storage unit of the system, the second release key 33 is stored in association with the second encoding release key 53. Therefore, when the second encoding release key 53 is input to the system, the system can read the second encoding release key 53 from the storage unit and output it. In this way, the second release key restoration unit 57 of the system restores the second release key 33 based on the second encoding release key 53.
[0039] Decryption step (S105) The decryption unit 51 of the system 1 decrypts the original data 11 using the first encrypted data 21, the second encrypted data 23, the first release key 31, and the second release key 33. In the storage unit of the system 1, the first release key 31 and the second release key 33 are stored. The control unit of the system 1 reads the first release key 31 and the second release key 33 from the storage unit, and based on the instruction of the program, causes the arithmetic unit to perform an operation for restoring the release key 15. The system 1 stores the obtained release key 15 in the storage unit in this way. The storage unit of System 1 stores first encrypted data 21 and second encrypted data 23. The control unit of System 1 reads the first encrypted data 21 and the second encrypted data 23 from the storage unit, and based on the instructions of the program, causes the arithmetic unit to perform an operation to restore the encrypted data 13. System 1 stores the encrypted data 13 thus obtained in the storage unit. The storage unit of System 1 stores the encrypted data 13 and the decryption key 15. The control unit of System 1 reads the encrypted data 13 and the decryption key 15 from the storage unit, and based on the instructions of the program, causes the arithmetic unit to perform an operation to restore the original data 11. System 1 stores the original data 11 thus obtained in the storage unit.
[0040] In a preferred example of the above System 1, the first server 41 and the third server 45 are cloud servers that may be the same or different. The second server 43 is an on-premises server. A cloud server is a server located on the Internet (external network). On the other hand, an on-premises server is a server located on an intranet (internal network constructed within a company such as a LAN or WAN). The on-premises server may be a server located on the user's intranet or a server located on the same intranet as System 1. For example, Japanese Patent Application Laid-Open No. 2018-98538 describes a system that switches between using a cloud server and an on-premises server. Thus, a system that takes advantage of the characteristics of a cloud server and an on-premises server is already known.
[0041] In a preferred example of the above System 1, the first server 41 and the third server 45 are on-premises servers that may be the same or different, and the second server 43 is a blockchain (blockchain network). A blockchain, also called a distributed ledger, is a network that can prevent the falsification of transaction history data by linking multiple ledgers by a plurality of nodes (computers). The fact that the second server 43 is a blockchain means that the server is composed of a plurality of node computers.
[0042] The present invention includes a program for causing a computer to function as any of the above-described systems, and an information recording medium (e.g., DVD, CD-ROM, USB memory, hard disk, SIM card) readable by a computer storing such a program. This information recording medium is a non-transitory recording medium.
Industrial Applicability
[0043] The present invention can be used in the information and communication related industries.
Explanation of Signs
[0044] 1 Data management system 11 Source data 13 Encrypted data 15 Decryption key 17 Encryption unit 21 First encrypted data 23 Second encrypted data 25 Encrypted data splitting unit 31 First decryption key 33 Second decryption key 35 Decryption key splitting unit 41 First server 43 Second server 45 Third server 47 Data output unit 51 Decryption unit 53 Encoded second decryption key 55 Second decryption key encoding unit 57 Second decryption key restoration unit
Claims
1. An encryption unit (17) for encrypting original data (11) to obtain encrypted data (13) and issuing a decryption key (15) including decryption information for decrypting the encryption, An encrypted data splitting unit (25) for splitting the encrypted data (13) to obtain first encrypted data (21) and second encrypted data (23), A decryption key splitting unit (35) for splitting the decryption key (15) to obtain a first decryption key (31) and a second decryption key (33), A data output unit (47) for storing the first encrypted data (21) in a first server (41), storing the second encrypted data (23) in a second server (43) different from the first server (41), and storing the first decryption key (31) in a third server (45) different from the first server (41), A data management system having a decryption unit (51) for decrypting the original data (11) using the first encrypted data (21), the second encrypted data (23), the first decryption key (31), and the second decryption key (33). Data management system.
2. The data management system according to claim 1, The data volume of the first encrypted data (21) is 3 times or more and 10 4 times or less that of the second encrypted data (23), and wherein the first server (41) and the third server (45) may be the same or different cloud servers, and the second server (43) is an on-premises server. Data management system.
3. The data management system according to claim 1, The data volume of the first encrypted data (21) is 3 times or more and 10 4 times or less that of the second encrypted data (23), and wherein the first server (41) and the third server (45) may be the same or different on-premises servers, and the second server (43) is a blockchain. Data management system.
4. The data management system according to any one of claims 1 to 3, wherein the data output unit (47) stores the second decryption key (33) in the second server (43). Data management system.
5. The data management system according to any one of claims 1 to 3, further comprising a second decryption key encoding unit (55) for obtaining an encoded second decryption key (53) by converting the second decryption key (33) into code information, and a second decryption key restoration unit (57) for restoring the second decryption key (33) based on the encoded second decryption key (53). Data management system.
6. The data management system according to claim 5, wherein the encoded second decryption key (53) is a two-dimensional code printed on a medium. Data management system.
7. The data management system according to claim 1, A data management system further including a first server (41), a second server (43), and a third server (45).
8. A computer, an encryption step of encrypting original data (11) to obtain encrypted data (13) and issuing a decryption key (15) including decryption information for decrypting the encryption; an encrypted data splitting step of splitting the encrypted data (13) to obtain first encrypted data (21) and second encrypted data (23); a decryption key splitting step of splitting the decryption key (15) to obtain a first decryption key (31) and a second decryption key (33); a data output step of storing the first encrypted data (21) in a first server (41), storing the second encrypted data (23) in a second server (43) different from the first server (41), and storing the first decryption key (31) in a third server (45) different from the first server (41); a decryption step of decrypting the original data (11) using the first encrypted data (21), the second encrypted data (23), the first decryption key (31), and the second decryption key (33); A program for causing a data management system to function as a system that executes the above steps.
9. An information recording medium readable by a computer storing the program according to Claim 8.
Citation Information
Patent Citations
Data restoration device, data management server, data management system, data restoration method, and program
JP6664785B1