Secret information distribution system using biological authentication

The secret information distribution system employs n-of-k secret sharing and biometric authentication to securely back up and recover secret information across a terminal and file servers, preventing exposure in case of leaks and ensuring easy recovery.

JP2025093152AActive Publication Date: 2025-06-23BLOCKSMITH & CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023208713
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-11
Publication Date
2025-06-23
Estimated Expiration
2043-12-11

AI Technical Summary

Technical Problem

Existing secret information distribution systems face challenges in securely backing up and recovering secret information, particularly when using third-party file servers, and in preventing immediate exposure of original secret information in case of leaks.

Method used

A secret information distribution system using n-of-k secret sharing, where k pieces of secret information are distributed across a terminal and (k - 1) file servers, requiring biometric authentication to access fragments from the file servers, thereby ensuring secure backup and recovery while preventing unauthorized access.

Benefits of technology

The system effectively secures secret information by dispersing it across multiple servers and requiring biometric authentication, ensuring that even if fragments leak, they cannot be used to access the original secret information, and facilitating easy recovery in case of terminal loss.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025093152000001_ABST
    Figure 2025093152000001_ABST
Patent Text Reader

Abstract

To provide a secret information distribution system using biological authentication.SOLUTION: A secret information distribution system 11 respectively stores (k) pieces of fragments obtained by distributing secret information by n-of-k secret distribution in a terminal 13 and (k-1) file servers 14. The terminal 13 acquires (n) pieces of fragments from the terminal 13 and any (n-1) file servers 14 in the (k-1) file servers 14 and executes a transaction based on the secret information in accordance with the acquired (n) pieces of fragments. Biological authentication is required for acquiring fragments from the file servers 14. Each of the file servers 14 stores the fragment after applying encryption thereto in such a manner that the fragment can be decrypted by a common decryption key, and the decryption key is stored in a key server 15. The biological authentication is performed via the terminal 13, such that the terminal 13 may also acquire the decryption key and decrypt the encrypted fragment read out of each of the file servers 14.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a secret information distribution system using a terminal and a file server.

Background Art

[0002] In order to determine whether a person who attempts to execute an important process (transaction) has legitimate authority, it is widely practiced to use secret information. For example, there is a technique that employs various passwords as secret information.

[0003] Also, by adopting a secret key as secret information, signing a message with the secret key, and verifying the signature with a public key that forms a key pair with the secret key, it is possible to confirm whether the person who signed the message is legitimate.

[0004] Such signature technology for personal identification is also used when executing important processes (transactions) such as withdrawing cryptocurrency in a cryptocurrency wallet.

[0005] On the other hand, a secret sharing technology has been proposed in which secret information is dispersed into a plurality of fragments so that the original secret information cannot be obtained from each fragment, and by collecting the fragments, the same role as when using the original secret information is played. A mode in which secret information is dispersed into k fragments and the same role as when using the original secret information can be played by collecting n of them (n < k) is called n-of-k secret sharing.

[0006] For example, in Shamir's secret sharing technology, one piece of secret information is divided into k fragments, and the original secret information can be restored from n of them (Non-Patent Document 1).

[0007] On the one hand, according to the secret sharing using the signature technology based on the homomorphic encryption such as BLS (Boneh-Lynn-Shacham) signature using a point P on the elliptic curve, k distributed secret keys s1, s2, ..., s are generated from one master secret key s, k and using n of these distributed secret keys s1, s2, ..., s, n and a hash function H, a signature is made for one message m, thereby obtaining n distributed signatures s1H(m), s2H(m), ..., s n H(m), and the master signature sH(m) to be made for the one message by the master secret key s, that is, the master signature sH(m) that can be verified by the verification key (master public key) sP corresponding to the master secret key s, is restored from the n distributed signatures s1H(m), s2H(m), ..., s n H(m) (Non-Patent Document 2). Note that when restoring, since it is not necessary to use the master secret key itself, after the secret sharing is performed, the master secret key itself can be discarded and erased.

[0008] Extending this, a technique has also been proposed in which k distributed secret keys s1, s2, ..., s k are randomly generated, and the verification key sP is directly obtained from these. According to this technique, since the master secret key s itself, which is secret information, is not generated at all, it remains hidden from third parties as well as from any user.

[0009] Such dispersion of secret information is also used in majority voting and sharding in blockchain.

Prior Art Documents

Non-Patent Documents

[0010]

Non-Patent Document 1

[0011] When backing up secret information, there is a desire to be able to use a file server such as a network storage operated by others as a backup destination.

[0012] Also, even if the information backed up on the file server leaks due to some accident or incident, it is necessary to prevent a situation where the original secret information is immediately passed to a third party.

[0013] On the other hand, there is also a desire to reduce the trouble when performing a transaction based on the original secret information by recovering from a backup in the case where the owned terminal is lost or the like.

[0014] The present invention solves the above problems, and an object thereof is to provide a secret information distribution system using biometric authentication, a terminal in the secret information distribution system, a method executed by the terminal, and a program.

Means for Solving the Problems

[0015] The secret information distribution system according to the present invention stores k pieces obtained by distributing secret information by n-of-k secret sharing (n < k) respectively in a terminal and (k - 1) file servers, The terminal acquires n pieces from the terminal and any (n - 1) of the (k - 1) file servers, executes a transaction based on the secret information with the acquired n pieces, Biometric authentication is required to acquire pieces from some or all of the (k - 1) file servers. It is configured as follows.

Effects of the Invention

[0016] According to the present invention, it is possible to provide a secret information distribution system using biometric authentication, a terminal in the secret information distribution system, a method executed by the terminal, and a program.

Brief Description of the Drawings

[0017]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Embodiments for Carrying Out the Invention

[0018] Hereinafter, embodiments of the present invention will be described. Note that this embodiment is for explanation purposes and does not limit the scope of the present invention. Therefore, those skilled in the art can adopt an embodiment in which each element or all elements of this embodiment are replaced with equivalents. Also, the elements described in each example can be appropriately omitted according to the application. Thus, embodiments configured according to the principles of the present invention are all included in the scope of the present invention.

[0019] (Secret Information Distribution System) FIG. 1 is an explanatory diagram showing the configuration of a secret information distribution system according to an embodiment of the present invention. Hereinafter, an explanation will be given with reference to this figure.

[0020] The secret information distribution system 11 according to this embodiment includes a terminal 13a and a file server 14 for storing various information by the terminal via a computer communication network 12 such as the Internet, and may also include a key server 15 as an additional element. Also, when the user loses the terminal 13a or the like, another terminal 13b used by the user can be used as a component in place of the terminal 13a. Hereinafter, the terminals 13a and 13b used by the user will be collectively referred to as "terminal 13" as appropriate.

[0021] The terminal 13, file server 14, and key server 15 that constitute the secret information distribution system 11 are typically realized by a computer executing a program. The computer is connected to various output devices and input devices and exchanges information with these devices.

[0022] The program executed on each computer can be distributed and sold by a web server or the like to which the computer is communicably connected. In addition, after being recorded on a non-transitory information recording medium such as a CD-ROM (Compact Disk Read Only Memory), flash memory, or EEPROM (Electrically Erasable Programmable ROM), the information recording medium can also be distributed and sold.

[0023] The program is installed on a non-transitory information recording medium such as a hard disk, solid state drive, flash memory, or EEPROM that the computer has. Then, the terminal and server in the present embodiment are realized by the computer.

[0024] Generally, the CPU (Central Processing Unit) of a computer reads a program from an information recording medium into the RAM (Random Access Memory) under the management of the computer's OS (Operating System), and then interprets and executes the code included in the program. However, in an architecture where the information recording medium can be mapped within the memory space accessible by the CPU, an explicit loading of the program into the RAM may not be necessary. In addition, various information required during the execution of the program can be temporarily recorded in the RAM.

[0025] Note that instead of implementing the information processing apparatus of the present embodiment using a general-purpose computer, it is also possible to configure the information processing apparatus of the present embodiment using a dedicated electronic circuit. In this aspect, the program can also be used as a material for generating wiring diagrams, timing charts, etc. of the electronic circuit. In such an aspect, an electronic circuit that satisfies the specifications defined in the program is configured by an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit), and the electronic circuit functions as a dedicated device that performs the functions defined in the program to realize the information processing apparatus of the present embodiment.

[0026] Typically, the terminal 13 is configured by a smartphone. The smartphone executes an application program downloaded and installed from an app store to perform the functions of the terminal 13 according to the present embodiment.

[0027] Also, the file server 14 and the key server 15 are configured by server computers that provide services for storing information. In the secret information distribution system according to the present embodiment, it is possible to use dedicated servers for the file server 14 and the key server 15, but if they are configured by a general-purpose network storage that enables social login, the convenience for users can be maintained.

[0028] Hereinafter, for ease of understanding, an aspect in which the terminal 13, the file server 14, and the key server 15 are realized by a computer executing a program will be assumed and described.

[0029] Now, in the secret information distribution system 11 according to the present embodiment, One piece of secret information is distributed into k fragments by n-of-k secret sharing, and the k fragments are respectively stored in the terminal 13 and (k - 1) file servers 14.

[0030] Here, the file server 14 can encrypt and store the fragments.

[0031] Also, when storing the fragments in the file server 14, encryption that can be decrypted with a decryption key common to the file server 14 can be performed.

[0032] The common decryption key can be stored by the key server 15.

[0033] Here, if the terminal 13a is configured to be able to perform social login using an account of a specific web service for the file server 14 and the key server 15, even if the terminal 13a is lost, it becomes easy to use another terminal 13b instead.

[0034] Now, in this embodiment, as one of the features, biometric authentication is required to obtain the fragments stored in the file server 14 from the terminal 13.

[0035] The first method to achieve this is when signing in to the file server 14, in addition to authentication by social login, biometric information such as a face photo image of the user taken by the terminal 13 or fingerprint information of the user obtained by the terminal 13 is sent to the file server 14, and the file server 14 performs biometric authentication. That's what it is.

[0036] The first method is suitable for a mode in which each file server 14 does not use the key server 15. That is, each file server 14 may store the fragments without encrypting them as they are. Also, the file server 14 may encrypt the fragments by an encryption technique that each adopts (not necessarily common to other file servers 14), and may be able to decrypt the fragments by successfully signing in.

[0037] The second method is Send biometric information such as the user's face photo image taken by the terminal 13 and the user's fingerprint information obtained by the terminal 13 to the file server 14, In addition to authentication by social login, the key server 15 performs biometric authentication, Only when the biometric authentication is successful, the terminal 13 can obtain the decryption key from the key server 15, is what it is supposed to be.

[0038] In the second method, what is stored in each file server 14 is an encrypted fragment that can be decrypted with a decryption key. The terminal 13 reads the encrypted fragment from the file server 14 and uses the decryption key obtained from the key server 15 to decrypt the original fragment.

[0039] In this embodiment, since n-of-k secret sharing is used, when the terminal 13a stores one fragment, the terminal 13a obtains (n - 1) fragments from (n - 1) file servers 14, and by aligning the n fragments, execute a transaction based on the original secret information.

[0040] On the other hand, when the user loses the terminal 13a, etc., the terminal 13b can execute a transaction based on the original secret information by obtaining n fragments from n file servers 14. Thus, in this embodiment, the backup of the secret information is made by secret sharing.

[0041] (Terminal) FIG. 2 is an explanatory diagram showing the configuration of the terminal of the secret information distribution system according to the embodiment of the present invention. Hereinafter, it will be described with reference to this figure.

[0042] The terminal 13 includes an acquisition unit 101 and an execution unit 102.

[0043] Here, if the terminal 13 stores one fragment, the acquisition unit 101 obtains one fragment from the terminal 13, From any (n - 1) of the (k - 1) file servers 14, obtain (n - 1) fragments, and thus obtain n fragments in total.

[0044] On the other hand, if the terminal 13 does not store the fragment, the acquisition unit 101 obtains n fragments from any n of the (k - 1) file servers 14, and thus obtains n fragments in total.

[0045] Then, the execution unit 102 executes a transaction based on the secret information using the n obtained fragments.

[0046] Hereinafter, for ease of understanding, an example of the mode of performing BLS signature on the terminal 13 will be described. BLS signature uses a hash function H to an elliptic curve and a point P on the elliptic curve, and is applicable when signing various transactions and the like used in a cryptographic asset wallet.

[0047] (Distributed processing) First, the distributed processing for initializing the terminal 13 and the file server 14 to store the fragmented secret information will be described. FIG. 3 is a flowchart showing the control flow of the distributed processing for generating the master secret key s in the embodiment of the present invention. Hereinafter, the description will be made with reference to this figure.

[0048] The terminal 13 first generates a master secret key s for the transaction (step S300), and obtains a master verification key sP based on the master secret key (step S301). The master secret key corresponds to the secret information in the present embodiment.

[0049] Then, the terminal 13 generates k distributed secret keys s1, s2,..., s k based on the master secret key s (step S302). The distributed secret keys s1, s2,..., s kFrom this, corresponding distributed verification keys s1P, s2P, ..., s k P can be generated respectively. The distributed secret keys s1, s2, ..., s k correspond to the fragments in this embodiment.

[0050] Next, the terminal 13 generates a decryption key e -1 (and, if necessary, an encryption key e) for the k distributed secret keys (step S303). When public-key cryptography is adopted as the encryption method, a key pair including the public key e and the secret key e -1 is generated, the secret key e -1 is used as the decryption key, and the public key e is used as the encryption key. When symmetric-key cryptography is adopted, the encryption key and the decryption key are the same, and e = e -1 .

[0051] Then, the terminal 13 encrypts the k distributed secret keys s1, s2, ..., s k with the encryption key generated in step S303 to obtain encrypted fragments e(s1), e(s2), ..., e(s k )(step S304).

[0052] Next, the terminal 13 signs in to the key server 15 to store the decryption key e -1 (step S305), and publishes the master verification key sP (step S306). Here, to publish the master verification key sP, the key server 15 may be used, or key publishing techniques used in blockchain may be utilized.

[0053] Note that the decryption key e -1 is information to be concealed. To obtain the decryption key e -1 , it is necessary to successfully perform biometric authentication on the key server 15 using the biometric information obtained by the terminal 13.

[0054] Furthermore, the terminal 13 signs in to (k - 1) file servers 14 to obtain (k - 1) encrypted fragments e(s2), ..., e(s kHave each of them stored (step S306).

[0055] Next, the terminal 13 stores the encrypted fragment e(s1) or the original fragment s1 that has not been encrypted in its non-volatile storage area (step S307). In this flowchart, it is illustrated that the encrypted fragment e(s1) is stored. Note that in the mode of storing the original fragment s1 in the terminal 13, encryption of s1 is not necessary in step S304.

[0056] And then, the terminal 13 stores at least the master secret key s, the distributed secret keys s2,..., s k , In the mode of encrypting the distributed secret key s1 and storing it in the terminal 13, the original distributed secret key s1, the encrypted fragments e(s2),..., e(s k ), In the mode of directly storing the original distributed secret key s1 in the terminal 13, if s1 has been encrypted, the encrypted fragment e(s1) and other information to be concealed are deleted from the memory or the recording medium and discarded (step S308), and this process ends.

[0057] In this way, the master secret key s, which is secret information, is secretly distributed and stored in the terminal 13 and (k - 1) file servers 14, and the master secret key s itself does not remain anywhere.

[0058] In the above process, the master secret key s is generated. However, as disclosed in Non-Patent Document 3 and the like, the master verification key sP can be obtained while keeping the master secret key s concealed. FIG. 4 is a flowchart showing the control flow of the distribution process for concealing the master secret key s from anyone in the embodiment of the present invention. Hereinafter, it will be described with reference to this figure. Note that in this figure, the same processes as those shown in FIG. 3 are denoted by the same reference numerals.

[0059] The terminal 13 first generates k distributed secret keys s1, s2,..., sk Generate them randomly (step S400), and obtain a master verification key sP corresponding to the master secret key s secretly shared among the k distributed secret keys s1, s2, ..., s k by, for example, the technique disclosed in Non-Patent Document 3 (step S401).

[0060] That is, the k distributed secret keys s1, s2, ..., s k are those obtained by secretly sharing the master secret key s corresponding to the master verification key sP. However, in this process, the master secret key s is not directly generated. That is, the master secret key s remains concealed from everyone including the terminal 13.

[0061] Thereafter, the terminal 13 generates a decryption key e in the same manner as the process shown in FIG. 3 (step S303), -1 and obtains encrypted fragments e(s1), e(s2), ..., e(s ) (step S304). k The terminal 13 stores the decryption key e -1 in the key server 15 (step S305), publishes the master verification key sP (step S306), and causes (k - 1) file servers 14 to store (k - 1) encrypted fragments e(s2), ..., e(s k ) respectively (step S306), and stores the encrypted fragment e(s1) or the original fragment s1 that has not been encrypted in itself (step S307).

[0062] Finally, in the mode of encrypting the distributed secret keys s2, ..., s k and storing them in the terminal 13, for the original distributed secret key s1, in the mode of storing the encrypted fragments e(s2), ..., e(s and storing the original distributed secret key s1 directly in the terminal 13, if encryption is performed on s1, the encrypted fragment e(s1) k ) ​​Erase the information to be kept secret, such as , from the memory or recording medium, and discard it (step S408), and end this process.

[0063] As described above, in this process, the terminal 13 has not generated the master secret key s and it is also kept secret from the terminal 13. Therefore, different from the process shown in FIG. 3, it is not necessary to erase and discard the master secret key s.

[0064] As described above, in the distributed process according to this embodiment, fragments based on the distributed secret key obtained by secretly distributing the master secret key corresponding to the master public key for signature verification are stored in the terminal 13 and the file server 14, respectively. Also, when the master secret key itself is generated by the terminal 13, it may be discarded and erased from the terminal 13. However, when generating the master public key from the distributed secret key, the master secret key itself is secret information that is also kept secret from the terminal 13.

[0065] Now, in the following description, for ease of understanding, the terminal 13 and the file server 14 store encrypted fragments e(s1), e(s2),..., e(s k instead of the original fragments s1, s2,..., s k ). However, in some parts of the terminal 13 and the file server 14, it is also possible to omit encryption.

[0066] (Signature process) In the following, a signature process will be described in which fragments secretly distributed and pre-stored in the terminal 13 and the file server 14 by the above distributed process are obtained using biometric authentication and a signature based on the original master secret key s is performed. In this embodiment, it is possible to perform a signature based on the master secret key s that has already disappeared from this world, and this signature can be verified with the publicly available verification key sP. FIG. 5 is a flowchart showing the control flow of the signature process according to the embodiment of the present invention. The following will be described with reference to this figure.

[0067] First, the terminal 13 acquires the message m to be signed (step S401).

[0068] Next, the terminal 13 attempts to sign in to the key server 15 (step S402). If the sign-in is successful (step S402; success), the terminal 13 acquires the biometric information of the user of the terminal 13 (step S403), transmits it to the key server 15, and attempts biometric authentication (step S404).

[0069] If the sign-in to the key server fails (step S402; failure) or the biometric authentication fails (step S404; failure), the terminal 13 outputs a message indicating that signing is not possible (step S405) and ends this process.

[0070] On the other hand, if the biometric authentication is successful (step S404; success), the terminal 13 receives the decryption key e -1 stored by the key server 15 from the key server 15 (step S406).

[0071] If the terminal 13 stores the encrypted fragment (step S407; doing so), the terminal 13 acquires the encrypted fragment e(s1) (step S408), and further sets the required number of fragments N to n - 1 (step S409).

[0072] On the other hand, if the terminal 13 does not store the encrypted fragment (step S407; not doing so), the terminal 13 sets the required number of fragments N to n (step S410). This corresponds to the case where the original terminal 13a has been lost and a new terminal 13b is used to recover from the backup.

[0073] Next, the terminal 13 repeats the following process (step S416) until N encrypted fragments are acquired from (k - 1) file servers 14 or until the following process is executed for all of the (k - 1) file servers 14.

[0074] That is, the terminal 13 selects one of the (k - 1) file servers 14 (step S417), attempts to sign in to the selected file server 14 (step S418), and if the sign-in is successful (step S418; success), it repeats the process of obtaining the encrypted fragments transmitted from the selected file server 14 (step S419) (step S420).

[0075] If the sign-in to the file server 14 fails (step S418; failure), the terminal 13 advances the control to step S420.

[0076] Note that as for which (n - 1) file servers to select from the (k - 1) file servers 14, it may follow a predetermined order, may be determined randomly, or if a failure or the like has occurred in the file server 14, other file servers 14 may be appropriately selected.

[0077] Then, the terminal 13 determines whether it has obtained N encrypted fragments by repeating steps S416 - S420 (step S430). If not (step S430; failure), it advances the control to step S405, outputs that the signature cannot be made, and ends this process.

[0078] On the other hand, when N encrypted fragments have been obtained (step S430; success), in the terminal 13, since n encrypted fragments e(s1), e(s2),..., e(s n ) have been obtained, the following process is executed (since the subscripts for the distributed secret keys in the case of distributed processing can be arbitrarily rearranged, considering the obtained fragments as e(s1), e(s2),..., e(s n ) does not lose generality).

[0079] That is, the terminal 13 decrypts each of the obtained encrypted fragments e(s1), e(s2),..., e(s n ) with the decryption key e -1 to obtain the distributed secret keys s1, s2,..., sn to obtain (step S432).

[0080] Then, the terminal 13 applies the hash function H to the message m to obtain the hash value H(m) (step S433).

[0081] Next, the terminal 13 applies the decrypted distributed secret keys s1, s2, ..., s n to the calculated hash value H(m) respectively to obtain the distributed signatures s1H(m), s2H(m), ..., s n H(m) (step S434).

[0082] Furthermore, the terminal 13 calculates sH(m) that should be obtained from the original master secret key s from the distributed signatures s1H(m), s2H(m), ..., s n H(m) (step S435). As described above, in this embodiment, the master secret key s is discarded / erased or not generated at all. However, by the techniques disclosed in Non-Patent Documents 2 and 3 or techniques having the same function, the terminal 13 can calculate sH(m).

[0083] Then, the terminal 13 outputs sH(m) as the master signature for the message m (step S435) and ends this process.

[0084] Note that when the terminal 13 stores the original fragment s1 instead of the encrypted fragment e(s1), in step S434, the decryption for the encrypted fragment e(s1) may be omitted.

[0085] The signature sH(m) obtained by the above process can be verified with the publicly available verification key sP. Also, the original master secret key s does not remain anywhere and is secretly shared by the terminal 13 and (k - 1) file servers 14. Only the encrypted fragments are stored in the file servers 14. Therefore, even if a fragment leaks from any of the file servers 14, it is possible to prevent a situation where a third party executes a transaction.

[0086] In addition, when the terminal 13a that stores the fragments for itself is lost and the use of a new terminal 13b is started, in the above control, instead of from (n - 1) file servers 14, from n file servers 14, n encrypted fragments e(s2), ..., e(s n ), e(s n+1 ) are obtained, and e(s n+1 ) may be used instead of e(s1). In this way, in this embodiment, recovery from backup is also easy.

[0087] In the above embodiment, by using the BLS signature technology or the like, the signature sH(m) by the master secret key s can be obtained without directly restoring the original master secret key s. In addition, this embodiment can also be applied to various homomorphic encryption technologies other than the BLS signature. For example, instead of the BLS signature, the Shamir's (t, n) threshold method, the Pedersen's verifiable secret sharing method, the m-of-n multisignature scheme using the Schnorr signature and the verifiable secret sharing method, and the secret sharing by the threshold method using an elliptic curve can also be adopted.

[0088] In the above embodiment, at the time of signature, the signature was made without directly restoring the original master secret key s, but an aspect of directly restoring the original master secret key from n fragments and making the signature with the restored master secret key can also be adopted. Generalizing this, it is also possible to restore arbitrary secret information from n fragments and execute various transactions based on the restored secret information. In such an aspect, any secret sharing technology including Shamir secret sharing can be used.

[0089] Examples of transactions include, in addition to the withdrawal of virtual currency from a cryptocurrency wallet, etc., the process of verifying the identity on a new terminal 13b prior to the update of the master secret key related to the lost terminal 13a.

[0090] Also, as described above, when acquiring fragments from the terminal 13 or some of the file servers 14, it is also possible to adopt a mode that does not require biometric authentication. For example, For the terminal 13 and some of the file servers 14, encryption is omitted. For some of the file servers 14, encrypted fragments are stored, but the decryption key for decrypting these fragments is stored in another key server where social login is possible without requiring biometric authentication. And so on.

[0091] Even in this mode, if the remaining file servers 14 are encrypted with the decryption keys stored by the key server 15, biometric authentication will be required to obtain fragments from the remaining file servers 14.

[0092] These modes can be combined arbitrarily and can be omitted, and such modes are also included in the technical scope of this embodiment.

[0093] (Summary) Regarding the secret information distribution system according to this embodiment described above, the terminal in the secret information distribution system, the method executed by the terminal, and the program, the following are appended.

[0094] (Appended Note 1) In a secret information distribution system that stores k fragments obtained by distributing secret information by n-of-k secret sharing (n < k) in a terminal and (k - 1) file servers respectively, The terminal An acquisition unit that acquires n fragments from the terminal and any (n - 1) file servers among the (k - 1) file servers, An execution unit that executes a transaction based on the secret information using the acquired n fragments, And is provided with Biometric authentication is required to obtain fragments from some or all of the (k - 1) file servers. A secret information distribution system characterized by this.

[0095] (Appendix 2) The (k - 1) file servers each encrypt and store the fragments. The secret information distribution system according to Appendix 1, characterized in that.

[0096] (Appendix 3) The fragments stored in the (k - 1) file servers are encrypted in a manner that can be decrypted with a decryption key common to the (k - 1) file servers. The system further includes a key server that stores the common decryption key. Biometric authentication is required to obtain the decryption key stored in the key server. Read (n - 1) encrypted fragments from the (n - 1) file servers. Decrypt the (n - 1) fragments from the (n - 1) encrypted fragments by using the obtained decryption key. The secret information distribution system according to Appendix 1 or 2, characterized in that.

[0097] (Appendix 4) The biometric authentication for the key server is performed via the terminal. The terminal Obtains the decryption key from the key server. Reads the (n - 1) encrypted fragments from the (n - 1) file servers. Decrypts the fragments from the read (n - 1) encrypted fragments by using the obtained decryption key. The secret information distribution system according to Appendix 3, characterized in that.

[0098] (Appendix 5) The system further includes another terminal in place of the terminal. The other terminal Obtains the n fragments from any n file servers among the (k - 1) file servers. The secret information distribution system according to any one of Appendices 1 to 4, characterized in that.

[0099] (Appendix 6) The secret information is the master secret key, The k pieces are k distributed secret keys obtained by secretly distributing the master secret key, The terminal, For a message, by signing using each of the n distributed secret keys that are the n pieces, n distributed signatures are obtained, From the obtained n distributed signatures, the master signature made using the master secret key for the message is restored, The transaction is executed using the restored master signature The secret information distribution system according to any one of Appendices 1 to 5, characterized by the above.

[0100] (Appendix 7) The master secret key is erased from both the terminal and the (k - 1) file servers, The secret information distribution system according to Appendix 6, characterized by the above.

[0101] (Appendix 8) The n-of-k secret distribution is performed by a signature technique using an elliptic curve (including the BLS signature technique). The secret information distribution system according to Appendix 7, characterized by the above.

[0102] (Appendix 9) The terminal, Randomly generates the k distributed secret keys, From the k distributed secret keys, a master public key, which is a verification key for verifying the master signature, is generated while keeping the master secret key concealed. The secret information distribution system according to Appendix 9, characterized by the above.

[0103] (Appendix 10) The terminal, Restores the secret information from the n pieces, The transaction is executed using the restored secret information A secret information distribution system according to any one of Appendices 1 to 5, characterized in that...

[0104] (Appendix 11) In a terminal in a secret information distribution system that stores k fragments obtained by distributing secret information by n-of-k secret sharing (n < k) to a terminal and (k - 1) file servers respectively, an acquisition unit that acquires n fragments from the terminal and any (n - 1) file servers among the (k - 1) file servers; an execution unit that executes a transaction based on the secret information using the acquired n fragments. The terminal is provided with: Biometric authentication is required to acquire fragments from some or all of the (k - 1) file servers. A terminal characterized by the above.

[0105] (Appendix 12) A method executed by a terminal in a secret information distribution system that stores k fragments obtained by distributing secret information by n-of-k secret sharing (n < k) to a terminal and (k - 1) file servers respectively, the method comprising: an acquisition step in which the terminal acquires n fragments from the terminal and any (n - 1) file servers among the (k - 1) file servers; an execution step in which the terminal executes a transaction based on the secret information using the acquired n fragments. The method is provided with: Biometric authentication is required to acquire fragments from some or all of the (k - 1) file servers. A method characterized by the above.

[0106] (Appendix 13) A program that causes a computer to function as a terminal in a secret information distribution system that stores k fragments obtained by distributing secret information by n-of-k secret sharing (n < k) to a terminal and (k - 1) file servers respectively, the program causing the computer to: An acquisition unit that acquires n pieces of fragments from the terminal and any (n - 1) file servers among the (k - 1) file servers An execution unit that executes a transaction based on the secret information using the acquired n pieces of fragments Function as Biometric authentication is required to acquire fragments from some or all of the (k - 1) file servers A program characterized by the above

[0107] The present invention can be implemented in various embodiments and variations without departing from the broad spirit and scope of the present invention. Further, the above-described embodiments are for explaining the present invention and do not limit the scope of the present invention. That is, the scope of the present invention is indicated by the claims rather than the embodiments. And various modifications made within the scope of the claims and within the scope of the meaning of the invention equivalent thereto are considered to be within the scope of the present invention

Industrial Applicability

[0108] According to the present invention, it is possible to provide a secret information distribution system using biometric authentication, a terminal in the secret information distribution system, a method executed by the terminal, and a program

Explanation of Signs

[0109] 11 Secret information distribution system 12 Computer communication network 13, 13a, 13b Terminal 14 File server 15 Key server 101 Acquisition unit 102 Execution unit

Claims

1. In a secret information distribution system that stores k pieces obtained by distributing secret information by n-of-k secret sharing (n < k) respectively in a terminal and (k - 1) file servers, the terminal includes: an acquisition unit that acquires n pieces from the terminal and any (n - 1) file servers among the (k - 1) file servers; an execution unit that executes a transaction based on the secret information using the acquired n pieces; and biometric authentication is required to acquire pieces from some or all of the (k - 1) file servers. A secret information distribution system characterized by the above.

2. The (k - 1) file servers each store the pieces after encrypting them. The secret information distribution system according to Claim 1, characterized by the above.

3. The pieces stored in the (k - 1) file servers are encrypted in a manner that can be decrypted with a decryption key common to the (k - 1) file servers, and further includes a key server that stores the common decryption key, biometric authentication is required to acquire the decryption key stored in the key server, (n - 1) encrypted pieces are read from the (n - 1) file servers, and (n - 1) pieces are decrypted from the (n - 1) encrypted pieces by using the acquired decryption key. The secret information distribution system according to Claim 1, characterized by the above.

4. The biometric authentication for the key server is performed via the terminal, and the terminal acquires the decryption key from the key server, reads the (n - 1) encrypted pieces from the (n - 1) file servers, Decrypt the fragment from the (n - 1) encrypted fragments read using the obtained decryption key The secret information distribution system according to claim 3, characterized in that.

5. Further comprising another terminal replacing the terminal, The other terminal is, Obtain the n fragments from any n file servers among the (k - 1) file servers The secret information distribution system according to claim 1, characterized in that.

6. The secret information is a master secret key, The k fragments are k distributed secret keys obtained by secretly distributing the master secret key, The terminal is, For a message, obtain n distributed signatures by signing with each of the n distributed secret keys that are the n fragments, Restore a master signature made using the master secret key for the message from the obtained n distributed signatures, Execute the transaction using the restored master signature The secret information distribution system according to claim 1, characterized in that.

7. The master secret key is erased from both the terminal and the (k - 1) file servers The secret information distribution system according to claim 6, characterized in that.

8. The n-of-k secret sharing is performed by a signature technique using an elliptic curve (including the BLS signature technique). The secret information distribution system according to claim 7, characterized in that.

9. The terminal is, Randomly generate the k distributed secret keys, Generate, while keeping the master secret key concealed, a master public key, which is a verification key for verifying the master signature, from the k distributed secret keys. The secret information distribution system according to claim 8, characterized in that.

10. The terminal Restores the secret information from the n fragments, And executes the transaction with the restored secret information. The secret information distribution system according to claim 1, characterized in that.

11. In a terminal in a secret information distribution system that stores k fragments obtained by distributing secret information by n-of-k secret sharing (n < k) respectively in the terminal and (k - 1) file servers, An acquisition unit that acquires n fragments from the terminal and any (n - 1) of the (k - 1) file servers, An execution unit that executes a transaction based on the secret information with the acquired n fragments. Comprising Biometric authentication is required to acquire fragments from some or all of the (k - 1) file servers. A terminal characterized in that.

12. A method executed by a terminal in a secret information distribution system that stores k fragments obtained by distributing secret information by n-of-k secret sharing (n < k) respectively in the terminal and (k - 1) file servers, An acquisition step in which the terminal acquires n fragments from the terminal and any (n - 1) of the (k - 1) file servers, An execution step in which the terminal executes a transaction based on the secret information with the acquired n fragments. Comprising Biometric authentication is required to acquire fragments from some or all of the (k - 1) file servers. A method characterized in that.

13. A program that causes a computer to function as a terminal in a secret information distribution system that stores k pieces of fragments obtained by distributing secret information by n-of-k secret sharing (n < k) to the terminal and (k - 1) file servers, respectively. The program causes the computer to an acquisition unit that acquires n pieces of fragments from the terminal and any (n - 1) of the (k - 1) file servers, an execution unit that executes a transaction based on the secret information using the acquired n pieces of fragments function as, biometric authentication is required to obtain fragments from some or all of the (k - 1) file servers A program characterized by that.

Citation Information

Patent Citations

  • Data management program and data management method

    JP2019028940A

  • Electronic tally type storage method and operation system therefor

    JP2020155911A

  • Data sharing system

    WO2013065135A1

  • Restoration terminal, communication system, restoration method, communication method, and program

    WO2022039095A1