Information processing apparatus and information processing system
The information processing device generates and distributes time-limited second distributed files to restore original files, ensuring information leakage prevention even during server access failures.
Patent Information
- Application Number
- JP2024020863
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-15
- Publication Date
- 2025-08-27
AI Technical Summary
Existing file management systems fail to maintain effective information leakage prevention measures when network communication failures prevent access to the server for downloading files.
An information processing device generates and outputs a time-limited second distributed file from a server-stored second distributed file, which can be combined with a user terminal's first distributed file to restore the original file, even when server access is unavailable.
Ensures effective information leakage prevention by enabling the generation and distribution of distributed files outside the server, allowing restoration of original files despite network issues.
Smart Images

Figure 2025125034000001_ABST
Abstract
Description
[Technical Field]
[0001] An embodiment of the present invention relates to an information processing device and an information processing system. [Background technology]
[0002] In recent years, companies have been taking measures to prevent information leakage of confidential information such as company-confidential information and customer information from information processing devices owned by the company. One measure to prevent information leakage is, for example, a file management system that manages files by linking user terminals used by employees with a server, distributing files to each of the user terminals and the server (for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent No. 6705999 Summary of the Invention [Problem to be solved by the invention]
[0004] When using a file management system like the one described above, if a network communication failure or other issue occurs that makes it impossible to access the server to download files from the server to the user terminal, it may not be possible to obtain files from the server. Therefore, even if there is no abnormality in the distributed files, it may not be possible to restore the files.
[0005] Therefore, one example of the problem solved by the present invention is to provide an information processing device and an information processing system that can generate distributed files while maintaining effective information leakage prevention measures even when files cannot be obtained from the server. [Means for solving the problem]
[0006] A first aspect of the present invention is an information processing device that reads a second distributed file from a server that holds a second distributed file among original files that can be restored by combining a first distributed file and a second distributed file, generates a second distributed file that can be combined with the first distributed file, and is capable of outputting the generated second distributed file outside the server.
[0007] In addition, a second aspect of the present invention is an information processing system capable of restoring an original file by combining a first distributed file and a second distributed file, the information processing system comprising: a server that holds the second distributed file; and an information processing device that reads the second distributed file from the server, generates a second distributed file that can be combined with the first distributed file, and is capable of outputting the generated second distributed file outside the server.
[0008] The information processing device may also generate a second distributed file with a time limit.
[0009] The information processing device may also output the second distributed file to an external storage device.
[0010] The information processing device may also output the second distributed file as a two-dimensional code.
[0011] The system may further include a user terminal that holds the first distributed file, and the user terminal may acquire a second distributed file with a time limit and combine it with the first distributed file. [Effects of the Invention]
[0012] According to the present invention, even if a file cannot be acquired from a server, distributed files can be generated while measures against information leakage are effective. [Brief explanation of the drawings]
[0013] [Figure 1] FIG. 1 is a diagram illustrating an example of a schematic configuration of an information processing system according to an embodiment. [Figure 2]FIG. 2 is a block diagram illustrating an example of a hardware configuration of the information processing device according to the embodiment. [Figure 3] FIG. 3 is a block diagram illustrating an example of a functional configuration of the information processing device according to the embodiment. [Figure 4] FIG. 4 is a flowchart illustrating an example of processing executed by the information processing device according to the embodiment. [Figure 5] FIG. 5 is a flowchart illustrating an example of processing executed by the user terminal according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0014] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. The configuration of the embodiment described below, and the actions and effects brought about by the configuration, are merely examples, and the present invention is not limited to the following description.
[0015] FIG. 1 is a diagram showing an example of a schematic configuration of an information processing system 1 according to an embodiment. The information processing system 1 according to this embodiment is a system that processes files under management through file management processing. The information processing system 1 processes the files under management in a state where the files can be operated on the user terminal 3 by linking the user terminal 3 with a server 4, but the original files cannot be obtained by the user terminal 3 alone. An original file is also called original data, original file, original data, or original.
[0016] The information processing system 1 includes a user terminal 3, a server 4 connected to the user terminal 3 via an internal company network N, an information processing device 2 connected to the server 4, and an external storage device 5 capable of acquiring files from the information processing device 2. The internal company network includes a wireless network (also called wireless) and a wired network (also called wired).
[0017] The user terminal 3 is a device through which an operator (specifically, a company employee) performs file operations on the original files of files under management. The user terminal 3 is a portable device that can be taken outside the company (i.e., an environment that cannot be connected to the company network) and used. The user terminal 3 is, for example, a personal computer. The user terminal 3 may be any device that is capable of file operations, and may be, for example, a smartphone, a tablet-type personal computer, or the like.
[0018] The user terminal 3 distributes the original file into a first distributed file and a second distributed file. The user terminal 3 stores the first distributed file and distributes the second distributed file to the server 4. This makes it possible to prevent information leaks. When combining the original files, the user terminal 3 can combine the original files by acquiring the second distributed file and combining it with the first distributed file.
[0019] The server 4 stores the second distributed file. The server 4 sends the second distributed file to the user terminal 3 via the internal network N. The server 4 is a non-volatile storage device that is accessible from the internal network N (in other words, accessible only under limited circumstances). The server 4 is managed in an environment where strict crime prevention and security measures are implemented, for example, within the company or in a data center.
[0020] The information processing device 2 can read the distributed file from the server 4 and output the distributed file to the external storage device 5. The information processing device 2 has a secret sharing application and can read the distributed file from the server 4 using the secret sharing application.
[0021] Here, if the user terminal 3 cannot connect to the server 4, the second distributed file stored in the server 4 cannot be acquired even if there is no abnormality in the second distributed file. In this case, the information processing device 2 can read the second distributed file stored in the server 4, generate a second distributed file, and output the generated second distributed file to the external storage device 5. The generated distributed file may be a time-limited distributed file that sets a limit on the number of days until it can be read.
[0022] As a result, the generated second distributed file can be output to the external storage device 5 with information leakage prevention measures enabled. Therefore, even from an information processing device 2 outside the server, the second distributed file can be sent to the user terminal 3 using the external storage device 5. In addition, the time-limited second distributed file, which sets a readable deadline, can limit the period of use to a certain number of days.
[0023] The external storage device 5 may be any device capable of storing the second distributed file output from the information processing device 2. For example, an auxiliary storage device is used. The auxiliary storage device is a non-volatile memory that stores various data required for CPU processing. The auxiliary storage device may be configured, for example, as an HDD (Hard Disc Drive) or SSD (Solid State Drive).
[0024] The external storage device 5 may be any terminal equipped with a storage device, and may take the form of, for example, a USB (Universal Serial Bus) memory, a tablet-type personal computer, a digital camera, a portable music player, a mouse, a pen, headphones, a card-type storage medium (for example, an IC (Integrated Circuit) card), etc. The external storage device 5 may be a two-dimensional code because the memory capacity of the distributed files output from the information processing device 2 is small.
[0025] 2 is a block diagram showing an example of a hardware configuration of an information processing device 2 according to an embodiment. The information processing device 2 illustrated here has a configuration similar to that of a general-purpose computer, and includes a CPU (Central Processing Unit) 21, a RAM (Random Access Memory) 22, a ROM (Read Only Memory) 23, an auxiliary storage device 24, a user I / F (Interface) 25, and an external I / F 26.
[0026] The CPU 21 performs predetermined arithmetic processing using the RAM 22 as a working area in accordance with programs stored in the ROM 23 and the auxiliary storage device 24. The auxiliary storage device 24 is a non-volatile memory and stores various data necessary for the processing of the CPU 21. The auxiliary storage device 24 is configured, for example, by an HDD (Hard Disc Drive) or an SSD (Solid State Drive). The auxiliary storage device 24 is an example of an internal storage unit.
[0027] The user I / F 25 is a device that enables transmission and reception of information between a user (company employee) and the server 4, and may be an LCD display, a keyboard, etc. The external I / F 26 is, for example, a device for establishing communication with the external storage device 5 via a network in accordance with a predetermined standard. Note that the configuration of the information processing device 2 is not limited to that described above.
[0028] Fig. 3 is a block diagram showing an example of the functional configuration of the information processing device 2 according to the embodiment. The information processing device 2 according to the present embodiment includes an acquisition unit 201, a generation unit 202, and an output unit 203. These functional components 201 to 203 can be configured, for example, by cooperation between hardware elements and software elements (such as programs stored in the ROM 23 or auxiliary storage device 24) of the information processing device 2 as shown in Fig. 2. Note that the functional configuration of the information processing device 2 is not limited to the above.
[0029] The acquisition unit 201 reads the second distributed file from the server 4. Specifically, the acquisition unit 201 acquires the second distributed file stored in the server 4. For example, after the secret sharing app is launched, the acquisition unit 201 acquires the second distributed file stored in the server 4. The acquisition unit 201 is realized, for example, by the auxiliary storage device 24 provided in the information processing device 2.
[0030] The generation unit 202 acquires the data of the second distributed file read from the acquisition unit 201. From the read second distributed file, a time-limited second distributed file is generated, which sets a time limit for when the file can be read. A time-limited distributed file is a distributed file that can be read by the user terminal 3 within a time limit, such as within one week of its generation. This makes it possible to prevent information leakage from the generated second distributed file. Note that the second distributed file does not have to be a time-limited second distributed file, and a copy of the read second distributed file may also be used.
[0031] The output unit 203 acquires the time-limited second distributed file generated from the generation unit 202. The output unit 203 outputs the time-limited second distributed file to, for example, the external storage device 5. Alternatively, the output unit 203 may output the time-limited second distributed file as a two-dimensional code.
[0032] In this embodiment, the acquisition unit 201, the generation unit 202, and the output unit 203 have been described separately, but these functions may be provided by a single functional unit.
[0033] Here, we will explain the process of restoring the original file by combining the two distributed files after the original file has been distributed.
[0034] The user terminal 3 distributes the original file into a first distributed file and a second distributed file using, for example, a secret sharing encryption scheme. Note that since the original file is generated by distributing it, the sizes of the first distributed file and the second distributed file are smaller than the size of the original file. The first distributed file is stored, for example, in the user terminal 3. The second distributed file is stored in the server 4. When the user terminal 3 restores the original file, it can do so by obtaining the second distributed file from the server 4 and combining it with the first distributed file.
[0035] The encryption algorithm used is, for example, a common key encryption algorithm such as AES (Advanced Encryption Standard), which allows the user terminal 3 to decrypt the original file without causing inconsistencies in the original file even when the user terminal 3 cannot access the server 4.
[0036] 4 and 5, a description will be given of the processing executed by the information processing device 2 and the user terminal 3. Here, a case where the server 4 cannot be accessed from the user terminal 3 will be taken as an example.
[0037] 4 is a flowchart showing an example of processing executed by the information processing device according to this embodiment. As shown in Fig. 4, in the information processing device 2, a secret sharing application is started by a user (step S1).
[0038] Next, the acquisition unit 201 of the information processing device 2 acquires the second distributed file from the server 4 (step S2).
[0039] Next, the generation unit 202 generates a time-limited second distributed file from the acquired second distributed file, or replicates the second distributed file. Then, the generation unit 202 outputs the generated second distributed file to the output unit 203 (step S3).
[0040] Furthermore, when the external storage device 5 is connected, the output unit 203 outputs the second distributed file with a time limit to the external storage device 5. Alternatively, the output unit 203 outputs the second distributed file with a time limit as a two-dimensional code. Then, when the information processing device 2 completes the output process of step S4, this process ends. Note that the generated second distributed file does not need to be time-limited (step S4).
[0041] By performing the processes from step S1 to step S4, it is possible to generate a time-limited second distributed file from the information processing device 2 and output the generated second distributed file to the external storage device 5. This allows the user terminal 3 to obtain the generated second distributed file from the external storage device 5 outside the server 4.
[0042] Next, Fig. 5 is a flowchart showing an example of processing executed by a user terminal according to an embodiment. As shown in Fig. 5, when the user terminal 3 decrypts an original file, it acquires the second distributed file generated by the information processing device 2. The acquisition method may be, for example, acquiring the time-limited second distributed file from the external storage device 5. Alternatively, the second distributed file may be acquired by reading a two-dimensional code generated from the time-limited second distributed file with a camera or the like provided on the user terminal 3 (step S21).
[0043] The user terminal 3 determines whether the acquired second distributed file is within the time limit (step S22). If it is determined that the second distributed file is within the time limit (step S22: Yes), the process proceeds to step S24. On the other hand, if it is determined that the second distributed file is outside the time limit (step S22: No), the process proceeds to step S23.
[0044] In step S22, if the user terminal 3 determines that the second distributed file is outside the time limit, the user terminal 3 makes it impossible to acquire the distributed file, thereby contributing to measures against information leakage (step S23).
[0045] In step S22, if the user terminal 3 determines that the second distributed file is within the time limit, it combines the first distributed file of the user terminal 3 with the acquired second distributed file with the time limit (step S24).
[0046] The user terminal 3 acquires the decrypted original file. When the user terminal 3 completes the process of step S23 or step S25, this process ends (step S25).
[0047] As a result, by acquiring the time-limited second distributed file from the information processing device 2 through the processes from step S21 to step S25, it is possible to combine the first distributed file with the generated second distributed file and decrypt the original file even when the server 4 cannot be accessed from the user terminal 3. Therefore, it is possible to decrypt the original file while taking measures to prevent information leakage.
[0048] As described above, an information processing device 2 according to one embodiment of the present invention reads a second distributed file from a server 4 that holds a second distributed file among original files that can be restored by combining a first distributed file and a second distributed file, generates a second distributed file that can be combined with the first distributed file, and makes it possible to output the generated second distributed file outside the server.
[0049] As a result, according to this embodiment, even when the user terminal 3 cannot access the server 4, the information processing device 2 can generate the second distributed file and decrypt the original file while measures to prevent information leakage are effective.
[0050] Although the second distributed file is stored in the server 4, the first distributed file may be stored in the server 4 and the second distributed file may be stored in the user terminal 3.
[0051] In the above-described embodiment, the information processing device 2 may generate a second distributed file with a time limit, which sets a time limit for when the file can be read.
[0052] As a result, according to this embodiment, the information processing device 2 can generate a second distributed file with a time limit, thereby contributing to preventing information leakage and decrypting the original file.
[0053] Furthermore, the information processing device 2 may output the second distributed file to the external storage device 5.
[0054] As a result, the generated second distributed file can be output to the external storage device 5, and the original file can be composited by the external storage device 5.
[0055] Furthermore, the information processing device 2 may output the second distributed file as a two-dimensional code.
[0056] As a result, the generated second distributed file can be output as a two-dimensional code because it has a smaller data capacity than the original file. Therefore, the generated second distributed file can be used to composite the original file.
[0057] The above-described embodiment can be modified as needed by changing a portion of the configuration of the device. Therefore, several modifications of the above-described embodiment will be described below as other embodiments. The following mainly focuses on differences from the above-described embodiment, and detailed descriptions of commonalities with the content already described will be omitted. The modifications described below may be implemented individually or in appropriate combination.
[0058] (Variation 1) In the above embodiment, the server 4 connected to the information processing device 2 is described as being connected to the information processing device 2 via an internal company network, but this is not intended to be limiting. For example, the server 4 may be a portable terminal device. The portable terminal device is, for example, a non-volatile storage device that can be accessed outside the company, such as a smartphone.
[0059] Although the embodiments and modifications of the present invention have been described above, they are presented as examples and are not intended to limit the scope of the invention. These novel embodiments and modifications may be embodied in various other forms, and various omissions, substitutions, and modifications may be made without departing from the spirit of the invention. These embodiments and modifications are included within the scope and spirit of the invention, and are also included in the inventions and their equivalents as defined in the claims. [Explanation of symbols]
[0060] 1. Information processing system 2...Information processing device 3...User terminal 4...Server 5…External storage device 201…Acquisition Department 202...Generation section 203...Output section
Claims
1. reading the second distributed file from a server that stores the second distributed file among original files that can be restored by combining the first distributed file and the second distributed file; generating a second distributed file that can be combined with the first distributed file that is different from the second distributed file stored on the server; The generated second distributed file can be output to an outside of the server. Information processing device.
2. 1. An information processing system capable of restoring an original file by combining a first distributed file and a second distributed file, a server that stores the second distributed file; reading the second distribution file from the server; generating a second distributed file that can be combined with the first distributed file that is different from the second distributed file stored on the server; an information processing device that can output the generated second distributed file to an outside of the server; An information processing system comprising:
3. the information processing device generates the second distributed file with a time limit. The information processing system according to claim 2 .
4. the information processing device outputs the second distributed file to an external storage device. The information processing system according to claim 2 .
5. the information processing device outputs the second distributed file as a two-dimensional code. The information processing system according to claim 2 .
6. a user terminal that holds the first distributed file, The user terminal acquires the time-limited second distributed file; The first distributed file can be combined with the second distributed file. The information processing system according to claim 3 .
Citation Information
Patent Citations
Duplicated data management method, device, and program
JP2005108133A
Secrecy distribution apparatus, method, and program
JP2007124032A
Image forming device, and genuineness determination system
JP2011189637A
System and method for cloud control operations plane based on proactive security algorithms
US9846596B1
Encoding method, decoding method, encoder, and decoder
WO2020090088A1