Real-time evacuation / restoration-based digital asset protection service provision system
The system addresses the inadequacies of current digital asset protection by using a distributed ledger and smart contracts to securely manage and restore small data volumes from high-level cyber threats, ensuring robust protection and rapid recovery.
Patent Information
- Application Number
- JP2025062151
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-24
- Filing Date
- 2025-04-03
- Publication Date
- 2025-10-16
AI Technical Summary
Current technologies are inadequate in protecting digital assets from high-level cyber attacks, such as quantum computer cryptanalysis and EMP attacks, and lack efficient real-time data preservation and restoration methods, especially for small amounts of data linked to personal information.
A real-time evacuation and restoration type digital asset guard service provision system utilizing a distributed ledger technology with smart contracts, authenticators, and a network of nodes worldwide to securely manage, encrypt, divide, and restore small volumes of data linked to personal information, ensuring resistance to quantum computer cryptanalysis and EMP attacks.
The system effectively protects and restores important information from high-level cyber attacks and physical destruction by encrypting and dividing data across multiple locations, ensuring secure management and rapid restoration without compromising personal information.
Smart Images

Figure 2025158123000001_ABST
Abstract
Description
[Technical Field]
[0001] This invention relates to a real-time evacuation and restoration type digital asset guard service provision system that protects digital assets (focusing on protecting not only from information leakage but also from information destruction) consisting of small amounts of data linked to important information such as personal information in real time from risks such as high-level cyber attacks that exceed normal levels, severe natural disasters, or physical attacks that are expected in the future. In this specification, "system" refers to a computer system that is configured by combining elements such as computers, other electronic devices, software, communication networks, and data, and that specifically realizes software-based information processing using hardware resources. [Background technology]
[0002] Conventionally, distributed encryption technology such as blockchain has been used as an example of a measure to protect data from common cyber attacks. However, in the future, we can expect to see more sophisticated cyberattacks (by state actors or actors combining state and non-state actors) that exceed the usual level, such as quantum computer-based cryptography and EMP attacks, which will be discussed later. These sophisticated cyberattacks aim to leak, alter, erase, or destroy digital assets (confidential information such as personal information and national security-related information, control modules for important functions, currencies such as stablecoins, digital currencies, and digital securities, and rights such as contracts). This makes it important to protect digital assets from high-level cyber attacks.
[0003] Digital assets subject to high levels of cyberattacks Digital assets that are subject to high-level cyber attacks are thought to cover a wide range of areas, including personal information (account information) and personal asset information held by financial institutions, confidential information such as personal information and national security-related information held by large corporations and government agencies, confidential internal information, important contracts and designs, control modules and data, and information related to lifelines.To date, there have been no services (especially for private use) that can provide a high degree of protection against high-level cyber attacks, and in fact, no services with quantum computer cryptanalysis resistance (such as PQC (Post-Quantum Cryptography)) have been put into practical use.
[0004] High-level cyber attacks High-level cyber attacks mainly include cryptographic analysis using quantum computers (often expressed as Y2Q (Years To Quantum)) and EMP attacks.
[0005] Quantum Cryptanalysis Cryptanalysis using quantum computers is a cyber attack that breaks through cryptographic guards, steals important information, and destroys systems by using SSL (Secure Sockets Layer) or blockchain public keys to decipher private keys and RSA cryptography. If quantum computers are misused, even if digital assets are protected by storing private keys in cold wallets separated from the system, there is a high risk that the private key will be decrypted using cryptanalysis performed on the public key. Cryptanalysis using quantum computers is a cyberattack that breaks through current basic security measures known as encryption. It is expected that combining various other attacks will lead to unexpected attacks with far-reaching impacts. Quantum computers are expected to be put into practical use around 2025, and with their improved performance, current general encryption methods are expected to be analyzed by around 2030. Furthermore, even if current cryptanalysis is difficult if important information is leaked, it is likely that such information will be analyzed by quantum computers in the near future. Therefore, it is important to make the information more resistant to quantum computer cryptanalysis than it is currently.
[0006] EMP attack An EMP attack is a cyberattack that uses strong electromagnetic waves generated by a nuclear explosion at high altitude (stratosphere) to destroy electronic devices, systems, and magnetically recorded digital assets. An EMP attack could destroy evacuated digital assets or the system modules that evacuate digital assets. Also, while not an EMP attack, large solar flares occur periodically. The strong magnetic field caused by these flares can cause physical destruction equal to or greater than that of an EMP attack. In recent years, analyses have been reported that if a large flare were to occur on the far side of the sun and be directed towards Earth, the damage that would result from a direct hit would be considerable. Furthermore, the risk of a Nankai Trough earthquake occurring by 2030 is becoming a concern in Japan. Data centers are concentrated in the Tokyo-Osaka area, which is within the expected damage range of such an earthquake, and so similar system destruction damage as described above is expected. Summary of the Invention [Problem to be solved by the invention]
[0007] Measures currently being considered against high-level cyber attacks Quantum cryptography is being researched as a countermeasure against cryptanalysis using quantum computers. However, considering the timing when quantum cryptography can be introduced to the general public and the cost of introducing quantum cryptography, it has not yet reached a practical level. Similarly, research is being conducted into the practical application of quantum computer cryptanalysis resistance (PQC (Post-Quantum Cryptography)), but it has not yet been put into practical use. Additionally, as a countermeasure against EMP attacks, data centers (including cloud computing) that meet US EMP resistance standards have implemented measures such as installing anti-magnetic mesh. However, only a portion of data centers in Japan have installed anti-magnetic mesh, or the measures do not meet sufficient standards. In terms of equipment destruction, there is a risk of the Nankai Trough earthquake in Japan, but the fact that approximately 90% of data centers are located in areas expected to be affected also poses a major risk.
[0008] In addition, using the cloud, it is possible to consider evacuating data to overseas regions (independent regions where data centers exist). However, the cloud poses risks, such as the risk of the cloud itself, the risk of the cloud backup itself being damaged, and the risk of insufficient user management, which has led financial institutions (especially large financial institutions) to refrain from using it. Specifically, most domestic cloud services are currently operated by overseas service providers, which means that if a problem occurs in Japan, they may be easily withdrawn, and contracts stipulate that lawsuits in the event of a problem will be held overseas. Furthermore, incorrect cloud configuration can create security holes that expose important information, or the system could be destroyed by a simple attack. Furthermore, even if you use a domestic cloud, if you only use one company's cloud to back up your digital assets, there is a risk that the backed up data will become unusable if a system failure occurs in the cloud.
[0009] In particular, measures to deal with cyber-attacks that simultaneously use quantum computer-based cryptanalysis, EMP attacks, and more advanced artificial intelligence are currently complex and costly, and have not yet reached a level at which they can be put to general practical use. In fact, even in light of current cases of cyber-attacks, there are limitations to how much can be done to counter cyber-attacks on the front end, and since in many cases attacks are actually initiated via human users, it is recognized that there are limitations to how much can be done to defend against cyber-attacks on the front end.
[0010] Other challenges Furthermore, when it comes to personal information, confidential corporate information, or state-level confidential information, the system is subject to very strict restrictions on the evacuation of digital assets. For example, if a business entity other than the individual manages digital assets, the individual's consent is required. However, in reality, it is difficult to obtain consent from the individual for all digital assets that may be subject to management. This makes digital asset management limited and complicated. Furthermore, when using cryptographic decentralization technology to evacuate digital assets, public and other blockchains cannot cut the chain that connects the blocks. Therefore, even if unnecessary data becomes junk and needs to be deleted or digital data needs to be erased for customer convenience, the digital data cannot be erased. Furthermore, because the block size is relatively small, it is not possible to record digital data exceeding the block size. Therefore, there is a limit to the amount of information that can be stored on a blockchain. Furthermore, it is impossible to manage personal information on a public chain. Furthermore, even if it were possible to create a function similar to the evacuation of digital assets using distributed ledger technology by combining public chains and freeware, the responsibility for public chains and freeware is unclear. It is undesirable to handle important or personal information with digital asset evacuation services that are fundamentally unguaranteed, given their reliability. While current attacks on blockchains involve the theft of private keys, in the future, cryptographic analysis of addresses will become the primary method. Therefore, even if technology is developed to defend against attacks that steal private keys on current blockchains, it is not reassuring.
[0011] Therefore, the inventors of the present invention have considered and examined measures to strongly and efficiently protect important information such as secret / classified information and personal information from high-level cyber attacks and physical destruction, and to restore important information without it being stolen by third parties even if it is subjected to cryptographic analysis by a quantum computer or an EMP attack, or measures to make it impossible for third parties to analyze the management information even if it is stolen by a third party.First, the inventors have considered and examined the preservation processing of backup data for internal systems, etc., which is carried out periodically in batches.
[0012] However, among the data that constitutes digital assets that need to be preserved, there is a huge amount of small-volume data linked to personal information. Unlike backup data held by corporate systems, small-volume data linked to personal information often requires real-time data preservation from the perspective of convenience (in the event of system destruction, in order to quickly restore the system, even a backup structure that allows for database-like processing is desirable, in other words, a function that realizes storage-like processing with data preservation functionality is desirable).
[0013] Furthermore, personal information is subject to strict legal regulations from the perspective of protection, and there is a strong need to further strengthen defenses against external cyber attacks in order to preserve small amounts of data linked to personal information.
[0014] Furthermore, there is a wide variety of data linked to personal information, and it is desirable to preserve the data in a variety of forms. Data linked to personal information in small units that do not exceed the block size can be saved to a blockchain, but as mentioned above, blockchains such as public chains cannot cut the chain that connects the blocks. When saving data to a blockchain, even if the data itself is subjected to a cyber attack, or as an application of this, information that exceeds the blockchain's block size is recorded in a distributed file function, with only the management information recorded on the block side, but even if this data itself is subjected to a cyber attack, it must be managed as meaningless data that is not recognized as personal information (including important information), and it must be made impossible to restore the original personal information as is.
[0015] The present invention has been made in consideration of the above-mentioned problems, and aims to provide a real-time evacuation and restoration type digital asset guard service provision system that can preserve digital assets consisting of (basically) small amounts of data linked to personal information in real time, strongly and efficiently protect important information such as confidential information and personal information from high-level cyber attacks and physical destruction, and can restore important information without it being stolen by third parties even if it is subjected to cryptographic analysis using a quantum computer or an EMP attack, or can make it impossible for a third party to restore the management information even if it is stolen by a third party. [Means for solving the problem]
[0016] In order to achieve the above object, a real-time evacuation and restoration type digital asset guard service provision system according to a first aspect of the present invention is a real-time evacuation and restoration type digital asset guard service provision system for guarding digital assets from high-level cyber attacks, constructed with a distributed ledger in distributed ledger technology such as blockchain, and a smart contract or server application for performing predetermined processing using the data managed in the distributed ledger, or a system for handling data that is difficult to manage in a system, such as personal information, mainly on-chain in two configurations, one in which the information is managed by a company, and one in which the information is managed by an individual, and is a base system for managing the personal information directly on-chain in both configurations, or for separating the personal information part based on the information and utilizing it as personal attribute information for big data analysis, etc., and is composed of a group of nodes combining nodes at multiple locations in different regions around the world (a unit that combines blockchain, file distributed management functions, etc., and is a distributed smart and a distributed ledger structure that is mainly a closed blockchain such as a private or consortium blockchain and is constructed having a plurality of planets (each forming a unit constituting a system for providing services that implement a blockchain contract, a server application, etc.), and that is composed of a plurality of chains that may include a distributed ledger group, a public blockchain, etc.; a first authenticator information management means that manages first authenticator authentication information required to authenticate a first authenticator that is one of the data administrators that manages customers and customer data, first authenticator ID information and key information required for data evacuation and restoration, etc.; a second authenticator information management means that manages second authenticator authentication information required to authenticate a second authenticator that is the other of the data administrators that manages customers and customer data, second authenticator ID information and key information required for data evacuation and restoration, etc.; an external first authenticator authentication system that authenticates the first authenticator; an external second authenticator authentication system that authenticates the second authenticator; a file data real-time evacuation system; and a file data real-time restoration system, wherein the nodes at each of the bases areBy connecting recording devices in multiple locations around the world via a network, we can build a distributed file management group. The file data real-time evacuation system includes a data evacuation processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer between the first authenticator and the second authenticator, a customer data evacuation instruction means for issuing an instruction to evacuate the data to be evacuated for the customer based on the agreement information when the agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer is acquired by the data evacuation processing agreement information acquisition means, and an encryption and division algorithm processor for accepting selection of a program (or smart contract) having a plurality of encryption and division algorithms for encrypting and dividing file data, and a program (or smart contract) having a predetermined encryption and division algorithm based on the agreement information between the first authenticator and the second authenticator (or a first parameter specified by the customer who desires to evacuate file data, which is included in the agreement information) regarding the evacuation processing of the data to be evacuated for the customer acquired by the data evacuation processing agreement information acquisition means. a file data encryption and division means for encrypting and dividing the customer data to be saved that has been received by the customer data evacuation instruction receiving means into a plurality of file data using a program (or smart contract) having the encryption and division algorithm received by the encryption and division algorithm selection receiving means; an upload means for uploading each of the file data encrypted and divided into a plurality of files by the file data encryption and division means to a first temporary storage area; a file data security point associating and sorting each of the file data encrypted and divided into a plurality of files by the file data encryption and division means and uploaded to the first temporary storage area by the upload means, by associating it with one of at least two security points for managing the file data; and information of the security points for managing the file data sorted by the file data security point associating and sortingA means for managing maintenance point information in a black box environment; a distributed file management group allocation means or a smart contract (or server application) for distributed file management group allocation, which is provided in each planet and has a function of allocating each of the file data associated with the information of the conservation point managed in a black box environment by the conservation point information management means, which is sorted by the file data conservation point correspondence sorting means based on the agreement information between the first authenticator and the second authenticator regarding the evacuation process of the data to be evacuated for the customer acquired by the data evacuation process agreement information acquisition means (or the first parameter included in the agreement information and the second parameter designated by the digital asset guard service operator), to a plurality of distributed file management groups, which are set by the digital asset guard service operator according to conditions designated by the customer and are constructed with nodes at each base constituting the planet corresponding to the conservation point and recording devices at multiple bases connected to the nodes at each base via a network; a distributed recording means or a smart contract (or server application) for distributed recording that is provided in each planet and has the function of distributing and recording each of the file data associated with the information of each of the conservation points that has been sorted by the distributed file management group sorting means or the smart contract (or server application) for distributed file management group sorting, and that is managed in a black box environment by the conservation point information management means, to each of the base nodes belonging to each of the corresponding distributed file management groups and to recording devices at multiple bases that are connected to the base nodes via a network; terminal information (information that identifies the other party, such as a fixed IP address) for uploading to the first temporary storage area using the upload means; the number of a predetermined processing means or smart contract (or server application) that performs the corresponding processing of the recording destination of the customer's file data; and information on the planet to which the recording destination of the file data belongs;a smart contract (or server application) for creating and recording system setting information that has a function of creating system setting information including information on a group of file servers (in a node at a specified location and in recording devices at multiple locations that are networked to the node at that location) that constitutes a distributed file management group, encrypting the information, and recording it in a group of nodes at a specific location in the distributed ledger structure; key information that uses the first authenticator ID information and the second authenticator ID information that are included in the agreement information between the first authenticator and the second authenticator regarding the evacuation process of the data to be evacuated for the customer that is acquired by the data evacuation process agreement information acquisition means; file name information of each of the file data that is sorted by the file data preservation point association sorting means and that is managed in a black box environment by the preservation point information management means, that is distributed and recorded by each of the distributed recording means or the smart contract (or server application) for distributed recording, and that is linked to the information on the preservation point; a smart contract (or server application) for creating server index information having a function of creating server index information containing configuration information of a file management group; a smart contract (or server application) for recording server index information having a function of encrypting the server index information created by the smart contract (or server application) for creating server index information and recording it in a node group at a specific location in the distributed ledger structure; a smart contract (or program with a wallet function) for creating customer setting information having agreement information between the first authenticator and the second authenticator (or setting information of the first parameter included in the agreement information) regarding the evacuation process of the data to be evacuated for the customer, which is linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means; and an original file name of the file data to be evacuated for the customer.a customer index information creation smart contract (or a program with a wallet function) having a function of creating customer index information having information on the upload date; a customer index information recording smart contract (or a server application) having a function of encrypting the customer index information created by the customer index information creation smart contract (or the program with a wallet function) and recording it in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means for erasing each file data uploaded to the first temporary storage area after the server index information has been encrypted and recorded in the group of nodes at a specific location in the distributed ledger structure by the server index information recording smart contract (or server application), The data saving process agreement information acquisition means includes a data saving process request instruction means for instructing a request for saving process of the data to be saved of the customer via the first authenticator, a data saving process request instruction acceptance means for accepting a request instruction for saving process of the data to be saved of the customer from the data saving process request instruction means, and when the data saving process request instruction acceptance means accepts a request instruction for saving process of the data to be saved of the customer, it acquires first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means and transmits it to an external third party. a first authenticator authentication requesting means for requesting authentication of the first authenticator when receiving a data saving process request instruction, the first authenticator authentication requesting means providing the first authenticator to the external first authenticator authentication system and requesting authentication of the first authenticator; a first authenticator ID information and key information receiving means for data saving, receiving the first authenticator ID information and key information required for saving data from the first authenticator information managing means when the first authenticator is authenticated by the external first authenticator authentication system; and a first authenticator ID information and key information receiving means for data saving, receiving the first authenticator ID information and key information required for saving data from the first authenticator information managing means when the first authenticator ID information and key information receiving means for data saving receives the first authenticator ID information and key information required for saving data. a first information notification means for notifying the second authenticator of information that a request instruction for evacuation processing of the data to be saved for the client has been issued by a third authenticator and information urging the second authenticator to issue an approval instruction for the evacuation processing of the data to be saved for the client; a data evacuation processing approval instruction means for issuing an instruction to approve the evacuation processing of the data to be saved for the client via the second authenticator who has received the notification from the first information notification means; a data evacuation processing approval instruction receiving means for receiving an instruction to approve the evacuation processing of the data to be saved for the client from the data evacuation processing approval instruction means; a data evacuation processing approval instruction receiving means, when receiving an approval instruction for evacuation processing of the data to be saved for the client, acquires second authenticator authentication information required for authenticating the second authenticator from the second authenticator information management means, provides the information to an external second authenticator authentication system, and requests authentication of the second authenticator; and, when the second authenticator is authenticated by the external second authenticator authentication system, receives second authenticator ID information and key information required for data evacuation from the second authenticator information management means.a data saving second authenticator ID information and key information receiving means; a second information notifying means for, when said data saving second authenticator ID information and key information receiving means receives said second authenticator ID information and key information necessary for data saving, notifying said first authenticator of information that said second authenticator has given an approval instruction for saving data to be saved by said second authenticator and information urging said first authenticator to give an instruction to request saving data to be saved by said second authenticator; a data saving process request instructing means for instructing a request for saving data to be saved by said first authenticator via said first authenticator who has received the notification from said second information notifying means; and data evacuation processing request instruction receiving means for receiving a request instruction for a process to save target data to be saved; and data evacuation processing agreement information creating means for, when the data evacuation processing request instruction receiving means receives a request instruction for a process to save target data to be saved for the client, creating agreement information between the first authenticator and the second authenticator regarding the process to save target data to be saved for the client, using the first authenticator ID information and key information required for data evacuation received by the first authenticator ID information and key information receiving means for data evacuation and the second authenticator ID information and key information required for data evacuation received by the second authenticator ID information and key information receiving means for data evacuation, The file data real-time restoration system includes: a data restoration processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer, between the first authenticator and the second authenticator; a customer data restoration instruction means for instructing the restoration of the data to be restored for the customer based on the agreement information when agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer is acquired by the data restoration processing agreement information acquisition means; a program (or smart contract) having a plurality of decryption and combination algorithms with different file data decryption and combination processing methods, linked to a program (or smart contract) having each of the encryption and division algorithms; a customer data restoration instruction acceptance means for accepting an instruction to restore the data to be restored for the customer from the customer data restoration instruction means; and a protection point information management means provided on each planet, which is provided on the planet corresponding to the protection point. for each group of file data linked to the information of each of the preservation points managed in a black box environment by the means, key information (or the first parameter included in the key information or a first composite parameter (composed of a pair of a first decryption parameter designated and managed offline by the customer and a first encryption parameter automatically generated from the first decryption parameter) using the first authenticator ID information and the second authenticator ID information required for data restoration in the agreement information between the first authenticator and the second authenticator regarding the restoration process of the data to be restored for the customer, which is linked to the file data to be extracted and received by the customer data restoration instruction receiving means and acquired by the data restoration process agreement information acquisition means, and the second parameter (composed of a pair of a first decryption parameter designated and managed offline by the digital asset guard service administrator and a first encryption parameter automatically generated from the first decryption parameter)a smart contract (or server application) for extracting encrypted server index information that has a function of extracting encrypted server index information (recorded in a group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on a second composite parameter (composed of a pair of a second encryption parameter incorporated and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter; and a smart contract (or server application) for extracting encrypted server index information that is provided in each planet and that, for each group of file data linked to information on each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point, extracts the encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information. a server index information decryption smart contract (or server application) having a function of decrypting server index information, the server index information being provided in each planet, and for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point, the server index information decrypted by the server index information decryption smart contract (or server application) is used to allocate the file data to each of the distributed file management groups by the distributed file management group allocation means or the distributed file management group allocation smart contract (or server application), and the file data is distributed and recorded by each of the distributed recording means or the distributed recording smart contract (or server application) in the nodes of each base belonging to each of the distributed file management groups and in recording devices of multiple bases connected to the nodes of the base via a network;an encrypted and divided file data extraction means or a smart contract (or server application) for extracting encrypted and divided file data, which has a function of extracting each of the file data in an encrypted and divided state from any of the nodes of each base belonging to each of the distributed file management groups and the recording devices of multiple bases connected to the nodes of the base via a network; a download means provided in each planet, which downloads each of the file data in an encrypted and divided state extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data for each group of the file data linked to the information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point; and a download means provided in each planet, which downloads each of the file data in an encrypted and divided state extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data to a second temporary storage area for each group of the file data linked to the information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point. a file data restoration means for decrypting and combining all of the file data linked across all of the information of the conservation points in an encrypted and divided state, which is extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data and downloaded to the second temporary storage area by the download means, into one file data to restore the client's data before it was saved, using a program (or smart contract) having the decryption and combination algorithm linked to a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means; and a second data erasure means for erasing each of the file data in an encrypted and divided state that was downloaded to the second temporary storage area after being restored to the client's data before it was saved by the file data restoration means, The data restoration processing agreement information acquisition means includes a data restoration processing request instruction means for instructing a request for restoration processing of data to be restored for the customer via the first authenticator, a data restoration processing request instruction acceptance means for accepting a request instruction for restoration processing of data to be restored for the customer from the data restoration processing request instruction means, and a data restoration processing request instruction acceptance means for acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means and issuing the first authenticator authentication information to an external third party when the data restoration processing request instruction acceptance means accepts a request instruction for restoration processing of data to be restored for the customer. a first authenticator authentication requesting means for requesting authentication of the first authenticator when receiving a data restoration processing request instruction, the first authenticator authentication requesting means providing the first authenticator to a first authenticator authentication system and requesting authentication of the first authenticator; a first authenticator ID information and key information receiving means for data restoration receiving the first authenticator ID information and key information required for data restoration from the first authenticator information managing means when the first authenticator is authenticated by the external first authenticator authentication system; a third information notification means for notifying the second certifier of information that a request instruction for restoration of the data to be restored of the customer has been given by a third information notification means and information urging the second certifier to give an approval instruction for the restoration of the data to be restored of the customer; a data restoration processing approval instruction means for instructing approval of the restoration of the data to be restored of the customer via the second certifier who has received the notification from the third information notification means; a data restoration processing approval instruction receiving means for receiving an approval instruction for the restoration of the data to be restored of the customer from the data restoration processing approval instruction means; a data restoration processing approval instruction receiving second authenticator authentication requesting means for acquiring second authenticator authentication information required for authenticating the second authenticator from the second authenticator information managing means when the original processing approval instruction receiving means receives an approval instruction for the restoration processing of the data to be restored for the customer, and providing the second authenticator authentication information to an external second authenticator authentication system, and requesting authentication of the second authenticator; and when the second authenticator is authenticated by the external second authenticator authentication system, receiving the second authenticator ID information and key information required for data restoration from the second authenticator information managing means.a data restoration second authenticator ID information and key information receiving means; a fourth information notifying means for, when said data restoration second authenticator ID information and key information receiving means receives said second authenticator ID information and key information necessary for data restoration, notifying said first authenticator of information that said second authenticator has instructed to approve the restoration process of said data to be restored by said customer and information urging said first authenticator to instruct a request for the restoration process of said data to be restored by said customer; a data restoration process request instructing means for instructing a request for the restoration process of said data to be restored by said first authenticator who has received the notification from said fourth information notifying means; and a data restoration processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer, when the data restoration processing request instruction receiving means receives an instruction to request the restoration processing of the data to be restored for the customer, using the first authenticator ID information and key information required for data restoration received by the first authenticator ID information and key information receiving means for data restoration and the second authenticator ID information and key information required for data restoration received by the second authenticator ID information and key information receiving means for data restoration.
[0017] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the file data real-time save system comprises a user-side file data real-time save system that operates on the side of a user (customer and data manager) who desires to save file data, and a digital asset guard service operator-side file data real-time save system that operates on the side of the digital asset guard service operator, and the user-side file data real-time save system comprises the data save processing agreement information acquisition means, the customer data save instruction means, a program (or smart contract) comprising a plurality of the encryption / division algorithms, the encryption / division algorithm selection acceptance means, the customer data save instruction acceptance means, the file data encryption / division means, the upload means, the file data preservation point association sorting means, and the preservation point information management means, and the digital asset guard service operator-side file data real-time save system comprises the distributed file management group allocation means or the distributed file management group allocation means. the file data real-time restoration system comprises a user-side file data real-time restoration system operated on the side of a user (customer or data manager) who desires the restoration of saved file data, and a digital asset guard service operator-side file data real-time restoration system operated on the side of the digital asset guard service operator, the user-side file data real-time restoration system comprising the data restoration processing agreement information acquisition means, the customer data restoration instruction means, a program (or smart contract) having a plurality of the decryption and combination algorithms, the downloading means, the file data restoration means, and the second data erasure means;The digital asset guard service operator-side file data real-time restoration system preferably comprises the customer data restoration instruction receiving means, the smart contract (or server application) for extracting encrypted server index information, the smart contract (or server application) for decrypting server index information, and the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data.
[0018] Furthermore, the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention comprises a file data real-time deletion system, the file data real-time deletion system comprising: data deletion processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the deletion processing of data to be deleted for the customer, customer data deletion instruction means for issuing an instruction to delete the data to be deleted for the customer based on the agreement information when the agreement information between the first authenticator and the second authenticator regarding the deletion processing of data to be deleted for the customer is acquired by the data deletion processing agreement information acquisition means, customer data deletion instruction receiving means for receiving an instruction to delete the data to be deleted for the customer from the customer data deletion instruction means, and customer data deletion instruction receiving means provided in each planet, for each group of file data linked to information of each of the protection points managed in a black box environment by the protection point information management means in the planet corresponding to the protection point. key information formed using the first authenticator ID information and the second authenticator ID information required for data deletion in the agreement information between the first authenticator and the second authenticator regarding the deletion process of the data to be deleted for the customer acquired by the data deletion process agreement information acquisition means, which is linked to the file data to be deleted received by the attachment means (or the first parameter included in the key information or a first composite parameter (composed of a pair of a first decryption parameter designated and managed offline by the customer and a first encryption parameter automatically generated from the first decryption parameter), and the second parameter or a second decryption parameter (designated and managed offline by the digital asset guard service administrator and incorporated and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing), and a second encryption parameter automatically generated from the second decryption parameter (embedded and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing), anda smart contract (or server application) for extracting encrypted server index information to be deleted, which has a function of extracting encrypted server index information (recorded in a node group at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on a second composite parameter (composed of a pair of parameters, each of which is a parameter consisting of a first composite parameter and a second composite parameter consisting of a first composite parameter and a second composite parameter), a smart contract (or server application) for decrypting encrypted server index information to be deleted, which is provided in each planet, and has a function of decrypting the encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information to be deleted, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point; and a smart contract (or server application) for deleting encrypted and divided file data that has a function of deleting, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the distributed file management group allocation means, from each of the base nodes belonging to each of the distributed file management groups and from all of the base storage devices that are connected to the base nodes via a network, the file data being allocated to each of the distributed file management groups by the distributed file management group allocation means using server index information decrypted by the smart contract (or server application) for decrypting server index information to be deleted, and being distributedly recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in all of the base storage devices that are connected to the base nodes via a network, the data deletion processing agreement information acquisition means comprising: a data deletion processing request instruction means for instructing a request for deletion processing of the data to be deleted of the customer via the first authenticator;a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of data to be deleted from the data deletion processing request instruction means, a data deletion processing request instruction receiving first authenticator authentication request means for, when the data deletion processing request instruction receiving means receives a request instruction for deletion processing of data to be deleted from the customer, acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means and providing the information to an external first authenticator authentication system to request authentication of the first authenticator, and a data deletion processing request instruction receiving first authenticator authentication request means for, when the data deletion processing request instruction receiving means receives a request instruction for deletion processing of data to be deleted from the customer, acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means and providing the information to an external first authenticator authentication system to request authentication of the first authenticator; a data deletion first authenticator ID information and key information receiving means for receiving the first authenticator ID information and key information required for deleting data from the first authenticator information management means when the first authenticator is authenticated by the data deletion first authenticator ID information and key information receiving means for receiving the first authenticator ID information and key information required for deleting data when the data deletion first authenticator ID information and key information receiving means receives the first authenticator ID information and key information required for deleting data, and transmits to the second authenticator information that the first authenticator has issued a request instruction for deletion processing of the data to be deleted for the customer and information that prompts the customer to issue an approval instruction for deletion processing of the data to be deleted. a data deletion process approval instruction means for instructing approval of a deletion process of data to be deleted for the customer via the second certifier notified from the fifth information notification means; a data deletion process approval instruction receiving means for receiving an instruction to approve the deletion process of data to be deleted for the customer from the data deletion process approval instruction means; and a second certifier authentication information management means for receiving second certifier authentication information required for authenticating the second certifier from the second certifier information management means when the data deletion process approval instruction receiving means receives an instruction to approve the deletion process of data to be deleted for the customer. a second authenticator authentication requesting means for receiving a data deletion processing approval instruction, which acquires information and provides it to an external second authenticator authentication system to request authentication of the second authenticator; a second authenticator ID information and key information receiving means for data deletion, which receives second authenticator ID information and key information necessary for data deletion from the second authenticator information managing means when the second authenticator is authenticated by the external second authenticator authentication system; and a second authenticator ID information and key information receiving means for data deletion, which receives the second authenticator ID information and key information necessary for data deletion from the second authenticator information managing means when the second authenticator ID information and key information necessary for data deletion is receiveda sixth information notification means for notifying the first authenticated person of information that the second authenticated person has given an approval instruction for the deletion process of the data to be deleted of the customer and information urging the first authenticated person to give an instruction to request the deletion process of the data to be deleted of the customer; a data deletion process request instruction means for instructing the first authenticated person who has received the notification from the sixth information notification means to request the deletion process of the data to be deleted of the customer, a data deletion process request instruction receiving means for receiving an instruction to request the deletion process of the data to be deleted of the customer from the data deletion process request instruction means; It is preferable to have a data deletion processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the deletion processing of the data to be deleted for the customer, using the first authenticator ID information and key information required for data deletion received by the first authenticator ID information and key information receiving means for data deletion and the second authenticator ID information and key information required for data deletion received by the second authenticator ID information and key information receiving means for data deletion, when the request instruction receiving means receives a request instruction for deletion processing of the data to be deleted for the customer.
[0019] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, the file data real-time deletion system comprises a user-side file data real-time deletion system operating on the side of the user (customer and data manager) who wishes to delete file data, and a digital asset guard service operator-side file data real-time deletion system operating on the side of the digital asset guard service operator-side, and the user-side file data real-time deletion system has the data deletion processing agreement information acquisition means and the customer data deletion instruction means, and the digital asset guard service operator-side file data real-time deletion system has the customer data deletion instruction acceptance means, a smart contract (or server application) for extracting the encrypted server index information to be deleted, a smart contract (or server application) for decrypting the server index information to be deleted, and a smart contract (or server application) for deleting the encrypted and divided file data.
[0020] In addition, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the data deletion processing request instruction means is configured to be able to change the setting of the generation of the file data to be deleted.
[0021] Furthermore, the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention has a file data real-time update (saving and deletion) system, the file data real-time update (saving and deletion) system including: data update (saving and deletion) processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer, when agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer is acquired by the data update (saving and deletion) processing agreement information acquisition means, customer data update (saving and deletion) instruction means for instructing the update (saving and deletion) of the data to be updated (saving and deletion) for the customer based on the agreement information, a program (or smart contract) having a plurality of encryption / division algorithms that differ in the file data encryption and division processing methods, and an update (saving and deletion) processing time encryption / division algorithm selection receiving means for receiving a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer acquired by the update (saving and deletion) processing agreement information acquisition means; an update (saving and deletion) processing time customer data evacuation instruction receiving means for receiving an instruction to evacuate the data to be evacuated for the customer from said customer data update (saving and deletion) instruction means; an update (saving and deletion) processing time file data encryption / division means for encrypting and dividing the customer data to be evacuated, which has been accepted by said update (saving and deletion) processing time customer data evacuation instruction accepting means, into a plurality of file data using a program (or smart contract) having the encryption / division algorithm accepted by said update (saving and deletion) processing time encryption / division algorithm selection accepting means; andan update (saving and deletion) processing time uploading means for uploading to a first temporary storage area; an update (saving and deletion) processing time file data conservation point associating and sorting each of the file data encrypted and divided into a plurality of pieces by the update (saving and deletion) processing time file data encryption and division means and uploaded to the first temporary storage area by the update (saving and deletion) processing time uploading means, by associating the file data with one of the conservation points corresponding to at least two planets for managing the file data; and an update (saving and deletion) processing time conservation point information management means for managing information of the conservation points for managing the file data sorted by the update (saving and deletion) processing time file data conservation point associating and sorting means in a black box environment; a distributed file management group allocation means for update (saving and deletion) processing, which is provided in each planet and has a function of allocating the file data associated with the information of the conservation point managed in a black box environment by the conservation point information management means for update (saving and deletion) processing, which is sorted by the file data conservation point association sorting means based on agreement information between the first authenticator and the second authenticator (or a first parameter included in the agreement information and a second parameter specified by the digital asset guard service administrator) regarding the saving process of the data to be saved for the customer, acquired by the data update (saving and deletion) processing agreement information acquisition means, to a plurality of distributed file management groups configured by the digital asset guard service administrator according to conditions specified by the customer and consisting of nodes at each base constituting the planet corresponding to the conservation point and recording devices at a plurality of bases connected to the nodes at each base via a network; a distributed recording means for update (saving and deleting) processing that has a function of distributively recording each of the file data associated with the information of each of the conservation points that has been sorted by the file data conservation point association sorting means for update (saving and deleting) processing and managed in a black box environment by the conservation point information management means for update (saving and deleting) processing, which has been sorted by the distributed file management group sorting means for update (saving and deleting) processing, to each of the base nodes belonging to the corresponding distributed file management group and to recording devices at multiple bases connected to the base nodes via a network; and creating system setting information that includes terminal information (information identifying the other party such as a fixed IP address) for uploading to the first temporary storage area using the update (saving and deleting) processing upload means, the number of a predetermined processing means that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and information on a group of file servers (at the node at the predetermined base and the recording devices at multiple bases connected to the node at the predetermined base via a network) that constitutes the distributed file management group;a smart contract (or server application) for creating and recording system setting information at the time of update (backup and deletion) processing, which has a function of encrypting the encrypted data and recording it in a group of nodes at a specific location in the distributed ledger structure; key information formed using the first authenticator ID information and the second authenticator ID information required for data evacuation, which are included in agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer acquired by the data update (backup and deletion) processing agreement information acquisition means; file name information of each of the file data that is distributedly recorded by each of the distributed recording means at the time of update (backup and deletion) processing and that is associated with the information of the conservation point that is sorted by the file data conservation point association sorting means at the time of update (backup and deletion) processing and managed in a black box environment by the conservation point information management means at the time of update (backup and deletion) processing; and a server index at the time of update (backup and deletion) processing, which has a function of creating server index information including configuration information of each of the distributed file management groups to which each of the file data is allocated. a smart contract (or server application) for creating information; a smart contract (or server application) for recording server index information during update (evacuation and deletion) processing, which has a function of encrypting and recording the server index information created by the smart contract (or server application) for creating server index information during update (evacuation and deletion) processing in a group of nodes at a specific location in the distributed ledger structure; a smart contract (or program with a wallet function) for creating customer setting information during update (evacuation and deletion) processing, which has a function of creating customer setting information comprising agreement information between the first authenticator and the second authenticator regarding the evacuation of data to be evacuated for the customer, acquired by the data update (evacuation and deletion) processing agreement information acquisition means linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means for update (evacuation and deletion) processing; and an original file name of the file data to be evacuated for the customer during update (evacuation and deletion) processing;a smart contract (or a program with a wallet function) for creating customer index information during update (saving and deletion) processing, which has a function of creating customer index information having information on the upload date; a smart contract (or a server application) for recording customer index information during update (saving and deletion) processing, which has a function of encrypting the customer index information created by the smart contract (or the program with a wallet function) for creating customer index information during update (saving and deletion) processing and recording it in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means during update (saving and deletion) processing, which erases each file data uploaded to the first temporary storage area after the server index information has been encrypted and recorded in the group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information during update (saving and deletion) processing; a customer data deletion instruction receiving means for update (saving and deletion) processing that receives a deletion instruction for data to be deleted from said update (saving and deletion) instruction means for said customer; and a means for receiving a deletion instruction for data to be deleted from said update (saving and deletion) processing instruction means that is provided in each planet, for each group of file data linked to information of each of said security points managed in a black box environment by said security point information management means for update (saving and deletion) processing in said planet corresponding to said security point, said means for receiving a deletion instruction for data to be deleted from said customer; and a means for receiving a deletion instruction for data to be deleted from said customer, said key information being made using said first authenticator ID information and said second authenticator ID information required for data deletion in agreement information between said first authenticator and said second authenticator regarding data deletion processing of said customer to be deleted acquired by said data update (saving and deletion) processing agreement information acquisition means that is linked to file data to be deleted accepted by said customer data deletion instruction receiving means for update (saving and deletion), said key information being made using said first authenticator ID information and said second authenticator ID information required for data deletion (or said first parameter included in said key information or (a first decryption parameter designated by said customer and managed offline and a first encryption parameter automatically generated from said first decryption parameter, in a pair) a smart contract (or server application) for extracting encrypted server index information to be deleted during update (backup and deletion) processing, which has a function of extracting encrypted server index information (recorded in a group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on the first composite parameter (composed of a first composite parameter and a second parameter or a second composite parameter (composed of a pair of a second decryption parameter (modularized and incorporated in a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is designated by the digital asset guard service administrator and managed offline, and a second encryption parameter (modularized and incorporated in a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter); anda smart contract (or server application) for decrypting server index information to be deleted during update (saving and deletion) processing, which has a function of decrypting encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information to be deleted during update (saving and deletion) processing for each group of file data linked to information on each of the conservation points managed in a black-box environment by the conservation point information management means during update (saving and deletion) processing; and a smart contract (or server application) for extracting encrypted server index information to be deleted during update (saving and deletion), which is provided in each planet and corresponds to the conservation point, and a smart contract (or server application) for deleting encrypted and divided file data during update (backup and deletion) processing, which has a function of deleting each of the encrypted and divided file data to be deleted, which has been allocated to each of the distributed file management groups by the distributed file management group allocation means and distributedly recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in recording devices at multiple bases connected to the base nodes via a network, using server index information decrypted by the smart contract (or server application) for decrypting server index information to be deleted during update (backup and deletion) processing, from each of the base nodes belonging to each of the distributed file management groups and in recording devices at all of the base nodes connected to the base nodes via a network, The data update (saving and deletion) processing agreement information acquisition means includes a data update (saving and deletion) processing request instruction means for instructing a request for update (saving and deletion) processing of data to be updated (saving and deletion) of the customer via the first authenticator, a data update (saving and deletion) processing request instruction acceptance means for accepting a request instruction for update (saving and deletion) processing of data to be updated (saving and deletion) of the customer from the data update (saving and deletion) processing request instruction means, and a data update (saving and deletion) processing request instruction receiving first authenticator authentication request means for, when receiving a request instruction for updating (saving and deleting) data to be updated (saved and deleted), acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means and providing the information to an external first authenticator authentication system, and requesting authentication of the first authenticator; and a data update (saving and deletion) processing request instruction receiving first authenticator authentication request means for, when the first authenticator is authenticated by the external first authenticator authentication system, acquiring first authenticator authentication information required for updating (saved and deleted) data from the first authenticator information management means. a first authenticator ID information and key information receiving means for data update (saving and deletion) that receives the first authenticator ID information and key information, and when the first authenticator ID information and key information receiving means for data update (saving and deletion) receives the first authenticator ID information and key information necessary for data update (saving and deletion), information indicating that a request instruction for update (saving and deletion) processing of data to be updated (saving and deletion) by the first authenticator has been issued and update (saving and deletion) of data to be updated (saving and deletion) by the customer a seventh information notification means for notifying the second authenticated person of information prompting an approval instruction for the processing; a data update (saving and deletion) processing approval instruction means for instructing approval of the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer via the second authenticated person who has received the notification from the seventh information notification means; and a data update (saving and deletion) processing approval instruction receiving means for receiving an approval instruction for the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer from the data update (saving and deletion) processing approval instruction means.a data update (saving and deletion) processing approval instruction receiving means for receiving an approval instruction for updating (saving and deleting) data to be updated (saving and deleting) by the customer, which obtains second authenticator authentication information required for authenticating the second authenticator from the second authenticator information managing means, provides the information to an external second authenticator authentication system, and requests authentication of the second authenticator; and a data update (saving and deletion) processing approval instruction receiving means for receiving an approval instruction for updating (saving and deleting) data to be updated (saving and deleting) by the customer, which obtains second authenticator authentication information required for authenticating the second authenticator from the second authenticator information managing means, provides the information to an external second authenticator authentication system, and requests authentication of the second authenticator. a data updating (saving and deleting) second authenticator ID information and key information receiving means for receiving the second authenticator ID information and key information required for updating (saving and deleting) data from the management means; and a data updating (saving and deleting) second authenticator ID information and key information receiving means for receiving the second authenticator ID information and key information required for updating (saving and deleting) data from the management means, when the second authenticator ID information and key information receiving means for receiving the second authenticator ID information and key information required for updating (saving and deleting) data receives information indicating that the second authenticator has issued an approval instruction for updating (saving and deleting) data for the customer to be updated (saving and delete) and information indicating that the second authenticator has issued an approval instruction for updating (saving and deleting) data for the customer to be updated (saving and delete). an eighth information notification means for notifying the first authenticated person of information prompting the first authenticated person to issue a request instruction for updating (saving and deleting) data to be updated (saving and deleting), a data update (saving and deletion) processing request instruction means for instructing a request for updating (saving and deleting) data to be updated (saving and deleting) data of the customer via the first authenticated person who has received the notification from the eighth information notification means; and a data update (saving and deletion) processing request instruction means for receiving a request instruction for updating (saving and deleting) data to be updated (saving and deleting) data of the customer from the data update (saving and deletion) processing request instruction means. and when the data update (saving and deletion) processing request instruction receiving means receives a request instruction for processing to update (save and delete) data to be updated (saved and deleted) by the customer, the data update (saving and deletion) first authenticator ID information and key information receiving means receives the first authenticator ID information and key information required for updating (save and delete) data and the second authenticator ID information and key information receiving means receives the second authenticator ID information and key information required for updating (save and delete) data and the second authenticator ID information and key information receiving means receives theIt is preferable to have a data update (saving and deletion) processing agreement information creation means for creating agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of data to be updated (saved and deleted) by the customer.
[0022] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the file data real-time update (saving and deletion) system comprises a user-side file data real-time update (saving and deletion) system that operates on the side of a user (customer or data administrator) who desires to update (saving and deleting) file data, and a digital asset guard service administrator-side file data real-time update (saving and deletion) system that operates on the side of the digital asset guard service administrator, and the user-side file data real-time update (saving and deletion) system comprises the data update (saving and deletion) processing agreement information acquisition means, the customer data update (saving and deletion) instruction means, a program (or smart contract) having a plurality of the encryption and division algorithms, an encryption and division algorithm selection acceptance means at the time of the update (saving and deletion) processing, a customer data save instruction acceptance means at the time of the update (saving and deletion) processing, the file data encryption and division means at the time of the update (saving and deletion) processing, and an upload at the time of the update (saving and deletion) processing. means, the file data preservation point correspondence sorting means at the time of update (saving and deletion) processing, and the preservation point information management means at the time of update (saving and deletion) processing, and the digital asset guard service operator side file data real-time update (saving and deletion) system comprises the distributed file management group allocation means at the time of update (saving and deletion) processing, the distributed recording means at the time of update (saving and deletion) processing, a smart contract (or server application) for creating server index information at the time of update (saving and deletion) processing, a smart contract (or server application) for recording server index information at the time of update (saving and deletion) processing, a first data erasure means at the time of update (saving and deletion) processing, a customer data deletion instruction receiving means at the time of update (saving and deletion) processing, a smart contract (or server application) for extracting encrypted server index information to be deleted at the time of update (saving and deletion) processing, and a smart contract (or server application) for decrypting server index information to be deleted at the time of update (saving and deletion) processing,It is preferable to have a smart contract (or server application) for encrypting and deleting divided file data during the update (backup and deletion) process.
[0023] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable that the data update (backup and deletion) processing request instruction means automatically sets all of the client's past generation file data as file data to be deleted.
[0024] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable that the data update (backup and deletion) processing request instruction means is configured to be able to change the setting of the generation of the file data to be deleted.
[0025] In the real-time backup and restoration type digital asset guard service providing system according to the first aspect of the present invention, the distributed file management group allocation means or the distributed file management group allocation smart contract (or server application) is configured to encrypt and split the file data associated with the information of the conservation points sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means before sorting the file data into the plurality of distributed file management groups, and to upload the first temporary file data to the plurality of distributed file management groups. It is preferable that the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data further has a function of converting the file format and name of each file data uploaded to the fixed storage area into a predetermined file format and name, and that after extracting each of the encrypted and divided file data for each group of file data linked to the information of each of the conservation points managed in a black-box environment by the conservation point information management means, converting the file format and name of each of the extracted file data into the original file format and name.
[0026] Furthermore, in the real-time backup / restoration type digital asset guard service providing system of the first aspect of the present invention, the agreement information (or the first parameter included in the agreement information) between the first authenticator and the second authenticator regarding the backup processing of the customer's data acquired by the data backup processing agreement information acquisition means has a file division code and a file storage code, the encryption / division algorithm selection receiving means receives a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on the file division code, and the distributed file management group allocation means or the distributed file management group allocation smart contract (or server application) encrypts and divides the files into multiple pieces by the file data encryption / division means, uploads them to the first temporary storage area by the uploading means, sorts them by the file data conservation point association sorting means, and stores the files linked to the information of the conservation points managed in a black box environment by the conservation point information management means. The digital asset guard service has a function of converting the file format and name of the file data into a predetermined file format and name based on the file storage code (or the file storage code and the second parameter), encrypting the file data, and allocating the file data to a plurality of distributed file management groups configured by nodes at multiple locations that constitute the planet corresponding to the conservation point and recording devices at multiple locations that are networked with the nodes at the locations, which are set by the digital asset guard service administrator according to conditions specified by the customer, and each of the distributed recording means or the distributed recording smart contract (or server application) sorts the file data associated with the information of each of the conservation points sorted by the distributed file management group sorting means or the distributed file management group sorting smart contract (or server application) and managed in a black box environment by the conservation point information management means,The encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data has a function of distributing and recording to the nodes of each base belonging to each of the corresponding distributed file management groups and to recording devices of multiple bases connected to the nodes of the base via a network, and the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data is allocated to each distributed file management group by the distributed file management group allocation means or the smart contract (or server application) for distributing and recording to each distributed file management group the nodes of each of the bases belonging to each of the distributed file management groups and to recording devices of multiple bases connected to the nodes of the base via a network by each of the distributed recording means or the smart contract (or server application) for distributed recording to each distributed file management group the files of each of the encrypted and divided file data extracted by the distributed recording means or the smart contract (or server application) for distributed recording to each distributed file management group the files of each of the and a file data recovery means for recovering the file data from the node of each of the bases belonging to each of the distributed file management groups and from any of the recording devices of multiple bases connected to the node of the base via a network, based on the file storage code (or the file storage code and the second parameter), and decrypting the extracted file data, and at the same time converting the file format and name of the file data to the original file format and name; and the file data recovery means has a function of recovering the file data from the node of each of the bases belonging to each of the distributed file management groups and from any of the recording devices of multiple bases connected to the node of the base via a network, based on the file storage code (or the file storage code and the second parameter), and decrypting the extracted file data, and at the same time converting the file format and name of the file data to the original file format and name; and the file data recovery means recovers the file data from the node of each of the bases belonging to each of the distributed file management groups and from any of the recording devices of multiple bases connected to the node of the base via a network, based on the file storage code (or the file storage code and the second parameter), and for each group of the file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means,It is preferable that the encryption / division algorithm selection receiving means has a function of using a program (or smart contract) having the decryption / combining algorithm linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection receiving means to decrypt and combine the data into one file data and restore the file data to the state before the backup.
[0027] Furthermore, in the real-time save / restore type digital asset guard service providing system according to the first aspect of the present invention, the customer data to be saved that has been accepted by the customer data save instruction accepting means is divided into a plurality of pieces using a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection accepting means, and each of the divided file data pieces is encrypted based on a first public key (first encryption key) created by each of the customer and the data manager, and the file data restoring means performs an encryption / division file data extraction using the encrypted / division file data extracting means or the encrypted / division file data extracting means for each group of the file data linked to the information of each of the conservation points that are managed in a black box environment by the conservation point information managing means. It is preferable that all of the file data linked across the information of all of the conservation points in an encrypted and divided state, which has been extracted by the output smart contract (or server application) and downloaded to the second temporary storage area by the downloading means, is decrypted based on a first private key (first offline decryption key) created by each of the customer and the data administrator, and that all of the file data linked across the decrypted information of all of the conservation points is combined into one file data using a program (or smart contract) having the decryption and combination algorithm linked to a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection accepting means.
[0028] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the file data encryption / division means encrypts the customer data to be saved that is accepted by the customer data save instruction acceptance means based on a first public key (first encryption key) created by the customer and the data manager, and divides the encrypted file data into multiple pieces using a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means, and the file data restoration means extracts the encrypted / division file data for each group of the file data linked to the information of each of the conservation points that are managed in a black box environment by the conservation point information management means. It is preferable that all of the file data linked across the information of all of the conservation points in an encrypted and divided state, extracted by the smart contract (or server application) for extracting encrypted and divided file data and downloaded to the second temporary storage area by the downloading means, is combined into one file data using a program (or smart contract) having the decryption and combination algorithm linked to a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection accepting means, and the combined file data is decrypted based on a first private key (first offline decryption key) created by each of the customer and the data administrator.
[0029] In the real-time backup and restoration type digital asset guard service providing system according to the first aspect of the present invention, the server index information recording smart contract (or server application) stores the server index information created by the server index information creating smart contract (or server application) in a second public key (second encryption key) created by the digital asset guard service administrator or in a second encryption key (modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from a second decryption parameter (modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is designated by the digital asset guard service administrator and managed offline. It is preferable that the server index information decryption smart contract (or server application) has a function to encrypt the encrypted server index information extracted by the encrypted server index information extraction smart contract (or server application) for each group of file data linked to the information of each of the protection points managed in a black-box environment by the protection point information management means, based on a second private key (second decryption key) created by the digital asset guard service operator or a second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) designated by the digital asset guard service operator and managed offline.
[0030] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the program (or smart contract) equipped with the encryption and division algorithm is configured to encrypt and divide file data into multiple parts using secret sharing technology.
[0031] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the program (or smart contract) equipped with the decryption and combination algorithm is configured to decrypt file data that has been encrypted and divided into multiple pieces and restore it to the original file data that has been combined into one piece using secret sharing technology.
[0032] In the real-time save / restore type digital asset guard service providing system according to the first aspect of the present invention, it is preferable that the secret sharing technique is a polynomial division processing type secret sharing technique.
[0033] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, the file data real-time backup system further comprises a planet configuration pattern setting means for selecting the number of nodes constituting the planet and the nodes at each base and the recording devices at multiple bases connected to the nodes at each base via a network (distributed file management group constructed by these) based on the recording capacity (file size) of file data specified by the customer and the number of file data divisions based on the degree of distribution, and the distributed file management group sorting means or the distributed file management group sorting smart contract (or server application) sorts each of the file data associated with the information of the conservation point sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means via the planet configuration pattern setting means according to the conditions specified by the customer. It is preferable that the digital asset guard service operator has a function of distributing the data to a plurality of distributed file management groups, which are configured by the digital asset guard service operator and the administrator, and which are constructed with the nodes of each location that constitute the planet corresponding to the security point and the recording devices of multiple locations that are connected to the nodes of the locations via a network, and each of the distributed recording means or the smart contract for distributed recording (or server application) has a function of distributing and recording each of the file data that is linked to the information of each of the security points that is sorted by the file data security point correspondence sorting means and managed in a black box environment by the security point information management means, to the nodes of each of the locations that belong to the corresponding distributed file management group and the recording devices of multiple locations that are connected to the nodes of the locations via a network.
[0034] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the planet configuration pattern setting means adds a predetermined number of dummy file data (having internal code that enables the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data to recognize that it is dummy information) to the number of divisions of the file data, and selects the number of nodes that constitute the planet, and the nodes at each base and the recording devices at multiple bases connected to the nodes at the base via a network (a distributed file management group constructed with these).
[0035] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the smart contract (or server application) for creating server index information has a function of creating the server index information by including, as configuration information for each of the distributed file management groups, information on the nodes at each location that distribute and record the dummy file data added by the planet configuration pattern setting means and information on recording devices at multiple locations that are network-connected to the nodes at those locations.
[0036] In addition, in the real-time backup and restoration type digital asset guard service providing system according to the first aspect of the present invention, the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data extracts, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means, from the configuration information of each of the distributed file management groups in the server index information decrypted by the smart contract (or server application) for decrypting server index information, a node at each base that distributes and records dummy file data (having a code therein that can be recognized as dummy information) and multiple nodes connected to the node at each base via a network. It is preferable that the system has a function to extract, using server index information excluding information on recording devices at several locations, each of the encrypted and divided file data that has been allocated to each of the distributed file management groups by the distributed file management group allocation means or the smart contract (or server application) for distributed file management group allocation and distributedly recorded by each of the distributed recording means or the smart contract (or server application) for distributed recording in each of the nodes at each of the locations belonging to each of the distributed file management groups and in recording devices at multiple locations connected to the nodes at each of the locations via a network, from any of the nodes at each of the locations belonging to each of the distributed file management groups and from any of the recording devices at multiple locations connected to the nodes at each of the locations via a network.
[0037] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable that the planet configuration pattern setting means selects the nodes of each base within each of the distributed file management groups and the recording devices of multiple bases connected to the nodes of the base via a network so that they are the nodes and recording devices located at the locations with the greatest distance (= maximum degree of distribution).
[0038] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the planet configuration pattern setting means regards the spherical Earth as a plane, creates a matrix in which the Earth's regions are divided into multiple sections both vertically and horizontally, and determines the spacing in the X-axis direction, based on the Y-axis in the matrix for the node that distributes and records one divided file data within one of the distributed file management groups and the locations of multiple recording devices connected to the node via a network, using a calculated value based on the number of divisions of the file data, and selects the nodes of each location within each of the distributed file management groups and the recording devices of multiple locations connected to the node of the location via a network.
[0039] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable that the nodes in the planet that store each divided file data in a distributed manner and the locations of multiple recording devices connected to the nodes via a network are managed using information such as GPS and classified in the matrix.
[0040] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, when the planet configuration pattern setting means is unable to open the spacing in the X-axis direction according to the calculated value based on the number of file data divisions for a node that distributes and records one divided file data and for multiple recording device locations connected to the node via a network due to insufficient remaining recording capacity of the node at a specified location or one of the recording devices at multiple locations connected to the node at that location via a network, it is preferable to select a node at a location or a recording device connected to the node at that location via a network that has a numerical difference in the Y-axis direction that is approximately the same as the calculated value of the spacing in the X-axis direction.
[0041] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the planet configuration pattern setting means selects the base of each node constituting the planet in accordance with the number of file data divisions based on the recording capacity (file size) of the file data specified by the customer, and selects multiple individual bases belonging to the distributed file management group constructed by each selected node so as to maximize the degree of distribution within the distributed file management group, and selects multiple recording devices to be disposed at each individual base (and connected to the node via a network).
[0042] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, the planet configuration pattern setting means preferably records in the matrix information such as total remaining recording capacity and total remaining communication capacity of the nodes at each base in each region to which the base of each node belongs and the recording devices at multiple bases connected to the nodes at that base via a network, and when selecting the nodes that constitute the distributed file management group and the bases of the multiple recording devices connected to the nodes via a network, uses information such as the total remaining recording capacity and total remaining communication capacity of the nodes at each base in each region and the recording devices at multiple bases connected to the nodes at that base via a network, as well as the degree of distribution, to select the optimal combination of nodes and the bases of the multiple recording devices connected to the nodes via a network.
[0043] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the planet configuration pattern setting means calculates areas where it is necessary to reinforce the recording capacity and communication capacity of each node at a specific location that constitutes the distributed file management group and the recording devices at multiple locations that are connected to the node at that location via a network.
[0044] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable that each of the distributed file management groups has a core node that designates and manages the individual pieces of equipment that constitute the recording devices at each location belonging to the distributed file management group.
[0045] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the nodes at each location are connected via a communication means such as the Internet or a closed network, and that the distributed recording means or the smart contract for distributed recording (or server application) is incorporated.
[0046] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the file data real-time backup system has a wallet function that reads the customer index information encrypted and recorded in a group of nodes at a specific location in the distributed ledger structure, and grasps the recording destination corresponding to each piece of file data encrypted and divided into multiple pieces by the file data encryption and division means.
[0047] Furthermore, in the first aspect of the real-time backup / restoration type digital asset guard service providing system of the present invention, it is preferable that the file data real-time backup system further comprises a backup file data list information creation means for creating backup file data list information linked to each of the client and the data manager, the backup file data list information including terminal information (fixed IP address) when the file data was uploaded to the first temporary storage area using the upload means, the original file name of the file data to be backed up, and information on the upload date, and a backup file data list information reference control means configured to allow the backup file data list information created by the backup file data list information creation means to be referenced only by communication devices (management / processing programs) managed by the fixed IP addresses of each of the client and the data manager.
[0048] Furthermore, in the first aspect of the present invention, the real-time backup and restoration type digital asset guard service provision system is preferably based on a closed blockchain such as the private or consortium type that forms the distributed ledger structure, and the multiple chains that may include the distributed ledger group and public blockchains are preferably provided with nodes at each location that make up the planet, recording devices at multiple locations that are network-connected to the nodes at those locations, and a multiple-level file data real-time backup and restoration system configuration for operating the file data real-time backup system and the file data real-time restoration system.
[0049] Furthermore, in the first aspect of the present invention, the real-time backup and restoration type digital asset guard service providing system is preferably equipped with a Level S file data real-time backup and restoration system configuration, which is based on next-generation distributed communications in general, and is configured to operate nodes at each location that constitutes the planet, recording devices at multiple locations that are network-connected to the nodes at those locations, the file data real-time backup system, and the file data real-time restoration system, using closed networks that are not connected to the Internet, such as satellite communications, 5G / 6G private communications, LTE networks, and dedicated closed networks.
[0050] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service provision system of the present invention, it is preferable that the system utilizes an internet communication network, is based on a closed blockchain such as the private or consortium type that forms the distributed ledger structure, and is composed of highly creditworthy companies that approve each of the participants of multiple chains that may include the distributed ledger group and public blockchains, and has a level 4 file data real-time backup and restoration system configuration in which the nodes of each base that constitutes the planet, recording devices of multiple bases that are network-connected to the base nodes, the file data real-time backup system, and the file data real-time restoration system operate in a highly secure space such as a dedicated room.
[0051] Furthermore, in the first aspect of the present invention, the real-time backup and restoration type digital asset guard service provision system preferably utilizes the Internet communication network, is primarily based on a closed blockchain such as the private or consortium type that forms the distributed ledger structure, and is composed of highly credible companies that approve each of the participants of multiple chains that may in some cases include the distributed ledger group and public blockchains, and has a level 3 file data real-time backup and restoration system configuration in which a file server for data backup is installed in a space with a security level equivalent to an office, or an inexpensive cloud service (including the use of globally distributed regional services) is used to operate nodes at each location that make up the planet, recording devices at multiple locations that are networked to the nodes at those locations, the file data real-time backup system, and the file data real-time restoration system.
[0052] Furthermore, in the first aspect of the present invention, the real-time backup and restoration type digital asset guard service providing system preferably utilizes the Internet communication network, is open to organizations such as general companies (e.g., branch network), and is provided with a level 2 file data real-time backup and restoration system configuration, configured to operate nodes at each location that make up the planet, recording devices at multiple locations that are network-connected to the location nodes, the file data real-time backup system, and the file data real-time restoration system.
[0053] Furthermore, in the first aspect of the present invention, the real-time backup and restoration type digital asset guard service providing system preferably utilizes the Internet communication network, is open to private homes, etc., and is provided with a level 1 file data real-time backup and restoration system configuration that is configured to operate nodes at each location that constitutes the planet, recording devices at multiple locations that are network-connected to the location nodes, the file data real-time backup system, and the file data real-time restoration system.
[0054] Furthermore, in the first aspect of the present invention, the real-time backup and restoration type digital asset guard service provision system, the file data real-time backup and restoration system configuration form of levels 1 to 4 is preferably configured such that the nodes at each of the locations around the world that make up each of the planets, and the recording devices (file servers) at multiple locations that are network-connected to the nodes at those locations, are network-connected to the Internet communication network and operate during nighttime hours when waste electricity can be utilized.
[0055] Furthermore, in the first aspect of the present invention, in the real-time backup and restoration type digital asset guard service provision system, the file data real-time backup and restoration system configuration form of levels 1 to 4 is preferably configured so that the nodes at each location around the world that make up each of the planets, and the recording devices (file servers) at multiple locations that are network-connected to the nodes at those locations, can operate during daytime hours using renewable energy power such as solar power generation.
[0056] Furthermore, in the real-time backup and restoration type digital asset guard service providing system according to the first aspect of the present invention, a data backup service contract application procedure acceptance means accepts a data backup service contract application procedure from a customer who wishes to save file data, and at the time of accepting the data backup service contract application procedure, accepts from the customer a designation of the recording capacity, distribution degree (whether domestically only or overseas as well), storage period, and real-time processing of the file data that the customer wishes to save; and manages the information on the recording capacity, distribution degree (whether domestically only or overseas as well), storage period, and real-time processing of the file data that the customer wishes to save that has been accepted by the data backup service contract application procedure acceptance means. It is preferable that the system further has a smart contract (or server application) for recording application acceptance information for a data evacuation service contract, which has the function of automatically calculating and generating the basic configuration of the entire planet by setting conditions from the customer (such as budget, whether the information contains the most confidential information related to personal information or security (i.e., the amount of risk, etc.), and the function of encrypting and recording the generated information as part of the system configuration information in a group of nodes at a specific location in the distributed ledger structure, so that the recorded configuration information can be read by a specified smart contract (or server application) that performs the relevant processing, along with the customer's personal information, allowing the system to grasp the overall picture.
[0057] In addition, in the real-time backup and restoration type digital asset guard service providing system according to the first aspect of the present invention, the file data real-time backup system calculates a hash value based on encrypted and divided file data that is recorded in the nodes of each of the distributed file management groups and in the storage devices of multiple locations connected to the nodes of the base via a network, and records the calculated hash value in a block in the nodes and storage devices, and constantly stores the hash value recorded in the nodes of each of the distributed file management groups and in the storage devices of multiple locations connected to the nodes of the base via a network, or in the blocks in the nodes or storage devices. It is preferable to further have a data tampering check control means which compares the hash recorded in a specific node or recording device or in a block on that node or recording device and, if there is a difference between the hash recorded in a block on another node or recording device or in that node or recording device, detects that the encrypted and divided file data recorded on that specific node or recording device has been tampered with or destroyed, excludes that specific node or recording device from the file data backup process (and deletes the blocks on that specific node or recording device), and notifies the operator of that node and the digital asset guard service operator / manager of the alarm.
[0058] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the system is configured to manage, with a fixed IP address, communication devices that can use a first private key (first offline decryption key) created by each of the customer and the data manager to restore each encrypted and divided file data that has been distributed and recorded in each of the base nodes belonging to each of the distributed file management groups and in recording devices at multiple bases connected to the base nodes via a network to the original data before the backup via the file data real-time restoration system.
[0059] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable that the management information of the IP addresses of the communication devices on which the customer and the data manager can use the first private keys (first offline decryption keys) created by each of them is presented to the digital asset guard service operator only when the multi-signature type private key transaction is approved by the holders of specific nodes at multiple locations that constitute the digital asset guard service operator.
[0060] In addition, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that node information that is permitted to access is recorded in the node group at a specific location in the distributed ledger structure.
[0061] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable to further have an upload process enabled IP address check means that controls the upload process (operation of the encryption and division algorithm selection receiving means, the customer data backup instruction receiving means, the file data encryption and division means, and the upload means) of the file data to be evacuated by the customer in the file data real-time backup system so that only operations at customer terminals whose fixed IP addresses are pre-registered as part of the system setting information in a node group at a specific location in the distributed ledger structure are possible, as terminal information for uploading to the first temporary storage area using the upload means.
[0062] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the smart contract (or server application) for recording data backup service contract application acceptance information confirms the amount of file data that the customer wishes to save and that has been accepted by the data backup service contract application procedure acceptance means, and if the confirmed amount of file data exceeds the maximum recording capacity of one file defined in the system, determines the number of divisions of the file data so that the amount of data saved is less than the maximum recording capacity.
[0063] Furthermore, in the first aspect of the real-time backup / restore type digital asset guard service providing system of the present invention, it is preferable that each base node belonging to each of the distributed file management groups and the recording devices at multiple bases connected to the base nodes via a network are provided with multiple sub-configuration file servers (or a group of file servers accessible from each base node belonging to each of the file management groups) connected to the base nodes and the recording devices at multiple bases connected to the base nodes via a network.
[0064] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, each of the distributed recording means or the distributed recording smart contract (or server application) checks the data recording capacity and usage status of each of the file servers of the sub-components connected to the node of each of the bases belonging to each of the distributed file management groups and the recording devices of the multiple bases connected to the node of the base via a network, and based on the checked data recording capacity, sorts the large file data linked to the information of the conservation points that are encrypted, divided into multiple parts, and uploaded to the first temporary storage area by the file data conservation point association sorting means, and is managed in a black box environment by the conservation point information management means. It is preferable that the system has the function of selecting a file server of a specific sub-configuration having a data recording capacity capable of recording file data, recording the large file data that has been encrypted, divided into multiple pieces, and uploaded to the first temporary storage area and sorted by the file data conservation point matching sorting means on the selected file server of the specific sub-configuration, and that is linked to the information of the conservation point managed in a black box environment by the conservation point information management means, and recording information about the file server of the specific sub-configuration that is the recording destination for the large file data that has been encrypted, divided into multiple pieces, and uploaded to the first temporary storage area as second index information on the nodes of each base belonging to each of the distributed file management groups.
[0065] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, each of the distributed recording means or the distributed recording smart contract (or server application) is recorded in a predetermined sub-configuration file server connected to each base node belonging to each of the distributed file management groups and to a recording device of a plurality of bases connected to the base node via a network, and the large file data linked to the information of the preservation point that is encrypted, divided into a plurality of parts, and uploaded to the first temporary storage area is sorted by the file data preservation point association sorting means, and managed in a black box environment by the preservation point information management means. When the upper limit of the server's recording capacity is exceeded, it is preferable to have a function to calculate the recording capacity of each base node belonging to each of the distributed file management groups and each of the other sub-configuration file servers connected to recording devices at multiple bases connected to the base node via a network for the file data that exceeds the upper limit of the recording capacity of the file server, select the file server of the sub-configuration that is the optimal recording destination based on the calculated recording capacity, record the data on the selected sub-configuration file server, and change the settings of the original file server to put it into a dormant state, and record (update) the information of the sub-configuration file servers that are the recording destination as second index information on each base node belonging to each of the distributed file management groups.
[0066] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable that each of the base nodes belonging to each of the distributed file management groups and the recording devices at multiple bases connected to the base nodes via a network are equipped with a sub-configuration file server (or a recording medium connected to the sub-configuration file server) that can be expanded.
[0067] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data has the function of referencing the second index information recorded in the nodes of each base belonging to each of the distributed file management groups, detecting multiple sub-component file servers on which the large file data linked to the information on the conservation points that have been sorted by the file data conservation point association sorting means in the encrypted and divided state recorded as the second index information and managed in a black-box environment by the conservation point information management means, extracting the file data recorded on the sub-component file servers from the multiple sub-component file servers, combining the extracted multiple file data, and restoring the large file data linked to the information on the conservation points that have been sorted by the file data conservation point association sorting means in the original encrypted and divided state and managed in a black-box environment by the conservation point information management means.
[0068] Furthermore, in the first aspect of the present invention, in the real-time backup and restoration type digital asset guard service providing system, the file data real-time backup system preferably further has a period-recording amount check means which, if the file data uploaded by a customer who desires to back up file data and distributedly recorded on each location node belonging to each of the distributed file management groups and on recording devices at multiple locations connected to the location nodes via a network, exceeds the maximum file data recording amount within a specified period, requests the customer to re-apply for a file data backup service contract, and if the customer does not go through the re-application procedure, treats it as an error.
[0069] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that at any of the locations belonging to each of the distributed file management groups, there is a node or recording device that is in a stopped state and not connected to the Internet, and that when the stopped node or recording device at that location is restarted, it is configured to receive and record encrypted and divided file data that is recorded on a node or recording device at another location that is in an operating state.
[0070] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, there is provided a data destruction attack detection means for detecting an attack (or the existence of data destruction due to equipment failure, etc.) on file data in an encrypted and divided state that is recorded in (a node or recording device at any of the bases that constitute the planet), and determining that a data destruction attack is taking place when destruction of multiple file data managed over a certain period of time (e.g., 30 minutes, 8 hours, 24 hours, etc.) is detected, and when the data destruction attack detection means detects an attack on the encrypted and divided file data, It is preferable to have an automatic data evacuation means in the event of an attack, which is configured to stop recording devices at multiple locations connected to the node of the base via a network or forcibly disconnect the Internet connection path, and to set up a separate network to automatically evacuate the encrypted and divided file data that is distributed and recorded on the node of the base that has not been attacked or on recording devices at multiple locations connected to the node of the base via a network, to each of the nodes of the base that make up another planet where attacks on the encrypted and divided file data have not been detected by the data destruction attack detection means, and to recording devices at multiple locations connected to the node of the base via a network.
[0071] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the data destruction attack detection means has a communication switching control means configured to, when it detects an attack on the encrypted and divided file data, maintain the stopped node and the recording devices at multiple locations connected to the node at that location via a network in a stopped state with their Internet connection cut off, and switch to a connection with a communication means other than the Internet (such as LTE).
[0072] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the automatic data backup means at the time of attack is configured to automatically backup, when the data destruction attack detection means detects an attack on the file data in an encrypted and divided state, the encrypted and divided file data that is distributed and recorded in the nodes of a base that is not under attack and that constitutes the planet and in recording devices of multiple bases that are network-connected to the nodes of the base, via a communication means other than the Internet (such as LTE), to the nodes of each base that constitutes another planet that is not under attack on the file data in an encrypted and divided state and in recording devices of multiple bases that are network-connected to the nodes of the base.
[0073] Furthermore, in the first aspect of the present invention, in the real-time backup and restoration type digital asset guard service provision system, it is preferable that the file data constituting the digital assets (information of some high value) to be guarded be tokens, customer information of existing business systems, asset information, source code and modules, confidential information, design documents, parameters such as settings, digital contracts, rights, designs, and any other data that can be expressed digitally.
[0074] Furthermore, in the real-time backup / restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the data backup service contract application procedure accepting means further accepts from the customer, at the time of accepting the data backup service contract application procedure, specifications of the guarantee level of the file data desired to be saved, the nodes of each of the locations constituting each of the planets, recording devices at multiple locations connected to the nodes of the locations via a network, and the level of the file data real-time backup / restoration system configuration required for the operation of the file data real-time backup system and the file data real-time restoration system.
[0075] Furthermore, in the real-time backup and restoration type digital asset guard service provision system of the first aspect of the present invention, the nodes at each location that make up each of the distributed file management groups and the recording devices at multiple locations that are connected to the nodes at each location via a network have different operating hours and are in a mixture of operating and stopped states, and all of the nodes at each location and the recording devices at multiple locations that are connected to the nodes at each location via a network are in operation over a 24-hour period, and it is preferable that at any given time, at least one of the nodes at each of the distributed file management groups or at least one of the recording devices at each location that is connected to the nodes at each location via a network is in operation.
[0076] Furthermore, in the real-time backup and restoration type digital asset guard service provision system of the first aspect of the present invention, the nodes at each of the bases constituting each of the distributed file management groups and the recording devices at multiple bases connected to the base nodes via a network operate only during nighttime hours using waste electricity during nighttime hours, and at a given point in time, at least one of the base nodes or at least one of the base recording devices connected to the base nodes via a network is operating within each of the distributed file management groups, and when switching from a stopped state to an operating state, the base node or the base recording device connected to the base node via a network is preferably configured to automatically update information such as stored file data to the latest information within each of the distributed file management groups.
[0077] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service provision system of the present invention, it is preferable that the node at each base and the recording devices at multiple bases connected to the node at that base via a network comprise a container or housing equipped with a generator of renewable energy such as solar power, a file server / CPU, a 5G communication device, and a battery.
[0078] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service provision system of the present invention, it is preferable that the node at each location and the recording devices at multiple locations connected to the node at that location via a network comprise a container or housing equipped with a file server / CPU, 5G communication equipment, a battery (capable of withstanding short-term operation), a cooling device, etc.
[0079] Furthermore, in the first aspect of the present invention, the real-time backup and restoration type digital asset guard service providing system is preferably configured to offset the file data recording capacity provided at nodes owned by node holders participating in multiple chains, which may include the distributed ledger group, public blockchains, etc., based on the private or consortium type closed blockchain that forms the distributed ledger structure, with the file data recording capacity used by the node holder, calculate the difference between the total file data recording capacity and the provided file data recording capacity, and collect and distribute an amount based on this difference from each node holder.
[0080] Furthermore, in the real-time backup and restoration type digital asset guard service providing system according to the first aspect of the present invention, there is provided a customer registration information designation receiving means for receiving, from a customer who wishes to backup file data, a customer ID and designation of terminal information (fixed IP address) to be used for backup and restoration of file data, and a customer registration smart contract (or server application) having a function of encrypting and recording the customer ID and terminal information (fixed IP address) to be used for backup and restoration of file data received by the customer registration information designation receiving means in a group of nodes at a specific location in the distributed ledger structure; It is preferred that the ion exchange resin further comprises:
[0081] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable to further have a first parameter designation receiving and recording means for receiving designation of the first parameter from the customer who wishes to back up file data, and recording the first parameter that has been designated and accepted on an offline recording medium.
[0082] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable to further have a second parameter designation receiving and setting means for receiving designation of the second parameter from the digital asset guard service operator and setting the second parameter whose designation has been received in a predetermined processing means for performing the corresponding processing or in the source code of a smart contract (or server application) to modularize it.
[0083] In addition, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, the index information creating means, the index information recording means, the encrypted index information extracting means, and the index information decrypting means are configured separately on the user (customer and data manager) side and on the digital asset guard service operation manager side, The index information creation means has a user (customer and data manager) side index information creation program (wallet function) (or smart contract) that operates on the side of the user (customer and data manager) who desires to save file data, and a digital asset guard service operator-side index information creation smart contract (or server application) that operates on the side of the digital asset guard service operator-side, and the user (customer and data manager) side index information creation program (or smart contract) has a function to create user (customer and data manager) side index information that has the original file name, upload date information, and storage date of the file data to be saved when uploaded to the first temporary storage area using the upload means, and the digital asset guard service operator-side index information creation smart contract (or server application) The digital asset guard service operator-side index information management system (or server application) has a function of creating digital asset guard service operator-side index information having information on the file name (after renaming) of each of the file data linked to the information on the preservation points that are sorted by the file data preservation point association sorting means and managed in a black box environment by the preservation point information management means, and (encrypted) corresponding recording destination information, etc., which are distributed and recorded by each of the distributed recording means or the distributed recording smart contract (or server application), and the index information recording means has a user (customer and data manager) side index information recording program (or smart contract) that operates on the side of the user (customer and data manager) who desires to save the file data, and a digital asset guard service operator-side index information recording smart contract (or server application) that operates on the side of the digital asset guard service operator-side;The user (customer and data administrator) side index information recording program (or smart contract) has a function of encrypting and recording the user (customer and data administrator) side index information created by the user (customer and data administrator) side index information creation program (or smart contract) in a group of nodes at a specific location in the distributed ledger structure when approval is given using a private key for first blockchain access generated based on a first private key (first offline decryption key) created by each of the customer and the data administrator, and the digital asset guard service operator-side index information recording smart contract has a function of encrypting and recording the digital asset guard service operator-side index information created by the digital asset guard service operator-side index information creation smart contract (or server application) in a group of nodes at a specific location in the distributed ledger structure when approval is given using a private key for second blockchain access generated based on a second private key (second decryption key) created by the digital asset guard service operator-side and a function of recording the information in a group of nodes at a specific location in a distributed ledger structure, and the encrypted index information extraction means comprises a user (customer and data administrator) side encrypted index information extraction smart contract (or server application) that operates on the side of the user (customer and data administrator) who desires to restore the file data, and a digital asset guard service administrator side encrypted index information extraction smart contract (or server application) that operates on the side of the digital asset guard service administrator, and the user (customer and data administrator) side encrypted index information extraction smart contract (or server application) links, when authorization is made using a first private key for accessing the blockchain generated based on a first private key (first offline decryption key) created by each of the customer and the data administrator, the user (customer and data administrator) side encrypted index information extraction smart contract (or server application) links, for each group of file data linked to the information of each of the preservation points managed in a black box environment by the preservation point information management means, the file data to be extracted that has been accepted by the customer data restoration instruction acceptance means.The digital asset guard service operator-side encrypted index information extracting smart contract (or server application) has a function of extracting encrypted user (customer and data manager)-side index information that is recorded in a node group at a specific location in the distributed ledger structure by the user (customer and data manager)-side encrypted index information recording smart contract (or server application) based on key information (or the first parameter and the second parameter included in the key information) that uses the first authenticator ID information and the second authenticator ID information required for data restoration in the agreement information between the first authenticator and the second authenticator regarding the restoration process of the data to be restored for the customer that is acquired by the data restoration process agreement information acquisition means, and the digital asset guard service operator-side encrypted index information extracting smart contract (or server application) has a function of extracting encrypted user (customer and data manager)-side index information that is recorded in an encrypted state in a node group at a specific location in the distributed ledger structure by the digital asset guard service operator-side encrypted index information extracting smart contract (or server application) when approval is given using a second private key for accessing the blockchain that is generated based on a second private key (second decryption key) created by the digital asset guard service operator-side encrypted index information for each group of file data linked to the information of the preservation point, the digital asset guard service operator has a function of extracting encrypted digital asset guard service operator-side index information recorded in a group of nodes at a specific location in the distributed ledger structure by the digital asset guard service operator-side encrypted index information recording smart contract (or server application) based on key information (or the first parameter and the second parameter included in the key information) consisting of the first authenticator ID information and the second authenticator ID information required for data restoration in the agreement information between the first authenticator and the second authenticator regarding the restoration process of the data to be restored for the customer, which is linked to the file data to be extracted and received by the data restoration process agreement information acquisition means, and the index information decryption means comprises a user (customer and data administrator) side index information decryption smart contract (or server application) running on the side of the user (customer and data administrator) who desires to restore the file data;and a digital asset guard service operator-side index information decryption smart contract (or server application) running on the digital asset guard service operator-side, wherein the user (customer and data manager) side index information decryption smart contract (or server application) has a function of decrypting the encrypted user (customer and data manager) side index information extracted by the user (customer and data manager) side encrypted index information extraction smart contract (or server application) based on a first private key (first offline decryption key) created by the customer and the data manager, respectively, and the digital asset guard service operator-side index information decryption smart contract (or server application) has a function of decrypting the encrypted digital asset guard service operator-side index information extracted by the digital asset guard service operator-side encrypted index information extraction smart contract (or server application) based on a second private key (second decryption key) created by the digital asset guard service operator-side.
[0084] Furthermore, in the real-time backup and restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the group of nodes at a specific location in the distributed ledger structure be configured to record, in encrypted form, the following as configuration information for each of the customer and the data administrator: IP addresses and user IDs; agreement information between the first authenticator and the second authenticator (or the first parameter included in the agreement information) regarding the backup process of the data to be backed up for the customer, acquired by the data backup process agreement information acquisition means; and a smart contract address on the digital asset guard service operator's side that can reference the configuration information for each of the customer and the data administrator; the file name and file data size, processing date and time, and storage date when the file data was backed up, as index information for the customer; configuration information for the smart contract (or server application) running on the digital asset guard service operator's side to back up the customer's file data; and information on the renamed file names of each of the file data that have been distributedly recorded by each of the distributed recording means or the distributed recording smart contract (or server application), as index information on the digital asset guard service operator's side.
[0085] Furthermore, in the real-time backup and restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the recording devices at multiple locations connected to the nodes at each location via a network consist of nodes that constitute the same blockchain network as the nodes at that location, or devices that do not belong to the blockchain network constituted by the nodes at that location but can be connected in a state that allows them to access the nodes at that location.
[0086] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable that the recording devices at multiple locations connected to the nodes at each location via a network be devices that constitute a different network from the nodes at the respective locations.
[0087] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the distributed file management group allocation means or the smart contract (or server application) for distributed file management group allocation, and the encrypted and split file data extraction means or the smart contract (or server application) for encrypted and split file data extraction each have a second parameter specified by the digital asset guard service operator hard-coded internally.
[0088] In addition, in the real-time backup and restoration type digital asset guard service providing system according to the first aspect of the present invention, it is preferable that the distributed ledger structure is constructed using a blockchain such as a private or consortium type.
[0089] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable that the private type or consortium type blockchain is constructed with a planet consisting of a group of nodes combining multiple virtual nodes at one location.
[0090] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the digital asset guard service operator-side file data real-time save system is a digital asset guard service operator-side file data real-time save system that incorporates the functions of the distributed file management group allocation means or the distributed file management group allocation smart contract (or server application), the distributed recording means or the distributed recording smart contract (or server application), the server index information creation smart contract (or server application), and the server index information recording smart contract (or server application). It is preferable that the digital asset guard service operator-side file data real-time restoration system has a smart contract (or server application) for real-time data evacuation, and that the digital asset guard service operator-side file data real-time restoration system has a smart contract (or server application) for real-time file data restoration on the digital asset guard service operator-side that is configured by incorporating the functions of the smart contract (or server application) for extracting encrypted server index information, the smart contract (or server application) for decrypting server index information, and the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data.
[0091] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable that the smart contract (or server application) for real-time backup of file data on the digital asset guard service operator's side has a second parameter specified by the digital asset guard service operator hard-coded internally.
[0092] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the smart contract (or server application) for real-time restoration of file data on the digital asset guard service operator side has hard-coded therein a second parameter specified by the digital asset guard service operator or a second composite parameter (composed of a pair of a second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) specified by the digital asset guard service operator and managed offline by the digital asset guard service operator, and a second encryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter).
[0093] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the smart contract (or server application) for real-time file data evacuation on the digital asset guard service administrator side creates a renaming and encryption key using agreement information between the first authenticator and the second authenticator regarding the evacuation process of the data to be evacuated for the customer, acquired by the data evacuation process agreement information acquisition means (or the first parameter specified by the customer who desires to evacuate the file data and the second parameter hard-coded therein, which are included in the agreement information), and changes the file name and encrypts each of the file data linked to the information of the preservation point that is encrypted and divided into multiple pieces by the file data encryption / division means, uploaded to the first temporary storage area by the upload means, sorted by the file data preservation point association sorting means, and managed in a black box environment by the preservation point information management means, using the renaming and encryption key. a function of allocating the data to a plurality of the distributed file management groups, and creating server index information including information on renamed file names of each of the distributedly recorded file data, which is sorted by the file data conservation point association sorting means and linked to information on each of the conservation points managed in a black box environment by the conservation point information management means, and address information of the nodes and recording devices that will store the file data in each of the distributed file management groups to which each of the file data will be allocated, and before encrypting and recording the information on the node group at a specific location in the distributed ledger structure, changing the information on the renamed file names and the address information of the node and recording device that will store the file data to a name that is further different from the renamed file names (based on the second parameter hard-coded internally) to create new server index information, and encrypting the created new server index information and recording it to the node group at a specific location in the distributed ledger structure, and thenIt is preferable that the distributed file management system has a function of erasing address information of the nodes and recording devices that are the storage destinations of the file data in each of the distributed file management groups to which the file data is allocated.
[0094] Furthermore, in the real-time backup and restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the smart contract (or server application) for real-time backup of file data on the digital asset guard service operator side further has the function of changing the name of the file to a name that is different from the converted file name (based on the second parameter hard-coded internally), and then adding dummy file information to the information on the changed file name and the address information of the node and recording device where the file data will be stored to create new server index information, encrypting the created new server index information and recording it on a group of nodes at a specific location in the distributed ledger structure, and then erasing the information on the file name after the name change of each of the original distributedly recorded file data and the address information of the node and recording device where the file data will be stored in each of the distributed file management groups to which each file data will be allocated.
[0095] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the smart contract (or server application) for real-time file data restoration on the digital asset guard service operator side may acquire agreement information between the first authenticator and the second authenticator regarding the save processing of the data to be saved by the customer, acquired by the data save processing agreement information acquisition means (or the first parameter specified by the customer or a first composite parameter (composed of a pair of a first decryption parameter specified by the customer and managed offline and a first encryption parameter automatically generated from the first decryption parameter, which is included in the agreement information), and a second parameter specified by the digital asset guard service operator that is hard-coded internally or a second decryption parameter (specified by the digital asset guard service operator and managed offline (modularized by being incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing)) and a second composite parameter) which is a pair of second encryption parameters automatically generated from the second decryption parameters (which are incorporated and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing), extracts encrypted server index information (recorded in a node group at a specific location in the distributed ledger structure) for each group of file data linked to the information of each of the conservation points managed in a black-box environment by the conservation point information management means, restores the server index information to a state where it is new, changed to a name that is further different from the name-converted file name (based on the second parameter or the second composite parameter hard-coded internally), then restores the changed name to the name of the name-converted file name, and then restores the file name information before the name change of each of the distributedly recorded file data based on the name restoration and decryption key.
[0096] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the smart contract (or server application) for real-time file data restoration on the digital asset guard service administrator side is configured to acquire agreement information between the first authenticator and the second authenticator regarding the save processing of the data to be saved by the customer, acquired by the data save processing agreement information acquisition means (or the first parameter specified by the customer or a first composite parameter (composed of a pair of a first decryption parameter specified by the customer and managed offline and a first encryption parameter automatically generated from the first decryption parameter, which is included in the agreement information), and a second parameter specified by the digital asset guard service administrator (specified by the digital asset guard service administrator and managed offline (modularized by being incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is hard-coded internally), and a second composite parameter) which is a pair of a second encryption parameter (which is incorporated and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) automatically generated from the decryption parameter of the second parameter, extracting encrypted server index information recorded in a node group at a specific location in the distributed ledger structure for each group of file data linked to the information of each of the conservation points managed in a black-box environment by the conservation point information management means, excluding dummy file information (based on the second parameter or the second composite parameter hard-coded internally), then restoring the name to a new server index information state in which the name has been changed to a name that is further different from the name-converted file name, then reverting the changed name to the name-converted file name information, and then restoring the file name information before the name change of each of the distributedly recorded file data based on the name recovery and decryption key.
[0097] Furthermore, a real-time backup and restoration type digital asset guard service provision system according to a second aspect of the present invention is a real-time backup and restoration type digital asset guard service provision system for guarding digital assets from high-level cyber attacks, which is constructed with a distributed ledger in distributed ledger technology and a server application for performing predetermined processing using data managed in the distributed ledger, and which includes a distributed ledger group of private or consortium type etc. constructed with a plurality of planets (forming one unit of a distributed ledger group) consisting of a group of nodes combining nodes at multiple locations in different regions around the world, and a first authentication required to authenticate a first certifier who is one of the customers and the data administrator who manages the customer data. a first authenticator information management means for managing first authenticator authentication information, first authenticator ID information and key information required for data evacuation and restoration, etc., a second authenticator information management means for managing second authenticator authentication information required for authenticating a second authenticator who is the other of the customer and the data manager who manages the customer's data, and second authenticator ID information and key information required for data evacuation and restoration, etc., an external first authenticator authentication system that authenticates the first authenticator, an external second authenticator authentication system that authenticates the second authenticator, a file data real-time evacuation system, and a file data real-time restoration system, wherein nodes at each location are connected via a network to recording devices at multiple locations in different regions around the world to form a distributed file management group, The file data real-time saving system includes: a data saving process agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the saving process of the data to be saved for the customer, the data saving process agreement information acquisition means for issuing an instruction to save the customer's data based on the agreement information when the data saving process agreement information acquisition means acquires agreement information between the first authenticator and the second authenticator regarding the saving process of the data to be saved for the customer; a customer data saving instruction means for issuing an instruction to save the customer's data based on the agreement information, when the data saving process agreement information acquisition means acquires agreement information between the first authenticator and the second authenticator regarding the saving process of the data to be saved for the customer; an encryption / division algorithm selection acceptance means for accepting a selection of a program having a plurality of encryption / division algorithms for encrypting and dividing file data, and a program having a predetermined encryption / division algorithm based on the agreement information between the first authenticator and the second authenticator regarding the saving process of the customer's data to be saved acquired by the data saving process agreement information acquisition means (or a first parameter specified by the customer who desires to save file data, which is included in the agreement information); a file data encryption and division means for encrypting and dividing the customer data to be saved, which is received by the customer data evacuation instruction receiving means, into a plurality of file data using a program having the encryption and division algorithm received by the encryption and division algorithm selection receiving means; an upload means for uploading each of the file data encrypted and divided into a plurality of pieces by the file data encryption and division means to a first temporary storage area; a file data security point associating and sorting each of the file data encrypted and divided into a plurality of pieces by the file data encryption and division means and uploaded to the first temporary storage area by the upload means, by associating it with one of at least two security points for managing the file data; and a security point information management means for managing information of the security points for managing the file data sorted by the file data security point associating and sorting means in a black box environment. a distributed file management group sorting means provided in each planet, which has a function of sorting each of the file data linked to the information of the conservation point managed in a black box environment by the conservation point information management means into a plurality of the distributed file management groups configured by the nodes of each base constituting the planet corresponding to the conservation point and recording devices of multiple bases connected to the nodes of the base via a network, on the digital asset guard service administrator side, according to conditions specified by the customer, the file data being sorted by the file data conservation point associating and sorting means based on agreement information between the first authenticator and the second authenticator regarding the saving process of the data to be saved of the customer acquired by the data saving process agreement information acquisition means (or the first parameter included in the agreement information and a second parameter specified by the digital asset guard service administrator), and the file data being linked to the information of the conservation point managed in a black box environment by the conservation point information management means; and a distributed file management group sorting means provided in each planet, which has a function of sorting each of the file data sorted by the distributed file management group sorting means into a plurality of the distributed file management groups configured by the nodes of each base constituting the planet corresponding to the conservation point and recording devices of multiple bases connected to the nodes of the base via a network, a distributed recording means having a function of distributing and recording each of the file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in each of the corresponding distributed file management groups in the nodes of each of the bases belonging to the distributed file management group and in recording devices of multiple bases connected to the nodes of the bases via a network; a system setting information creation and recording means having a function of creating system setting information including terminal information (information identifying the other party such as a fixed IP address) for uploading to the first temporary storage area using the upload means, the number of a predetermined processing means that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and information on the file server groups (in the nodes of the predetermined bases and in the recording devices of multiple bases connected to the nodes of the bases via a network) that make up the distributed file management group, encrypting the information, and recording it in the node group of a specific base in the distributed ledgers of the private type or the consortium type, etc.; and information regarding the evacuation processing of the customer's data to be evacuated that has been acquired by the data evacuation processing agreement information acquisition means.a server index information creating means for creating server index information including: key information using the first authenticator ID information and the second authenticator ID information required for data evacuation, which are included in the agreement information between the first authenticator and the second authenticator; file name information of each of the file data that is distributed and recorded by each of the distributed recording means and is linked to the information of the conservation point that is sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means; configuration information of each of the distributed file management groups to which each of the file data is allocated; a server index information recording means having a function of encrypting the server index information created by the server index information creating means and recording it in a node group at a specific location in the distributed ledgers of the private type or the consortium type; and evacuation processing of the data to be evacuated for the customer acquired by the data evacuation processing agreement information acquisition means, which is linked to a program having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means. a customer setting information creation means (or a program with a wallet function) having a function to create customer setting information including agreement information between the first authenticator and the second authenticator (or setting information of the first parameter included in the agreement information) regarding the above; a customer index information creation means (or a program with a wallet function) having a function to create customer index information including information on the original file name and upload date of the customer's file data to be saved; a customer index information recording means having a function to encrypt the customer index information created by the customer index information creation means (or the program with a wallet function) and record it in a group of nodes at a specific location in the distributed ledgers of the private type, the consortium type, etc.; and a first data erasure means for erasing each file data uploaded to the first temporary storage area after the server index information has been encrypted and recorded in a group of nodes at a specific location in the distributed ledgers of the private type, the consortium type, etc. by the server index information recording means, The data saving process agreement information acquisition means includes a data saving process request instruction means for instructing a request for saving process of the data to be saved of the customer via the first authenticator, a data saving process request instruction acceptance means for accepting a request instruction for saving process of the data to be saved of the customer from the data saving process request instruction means, and when the data saving process request instruction acceptance means accepts a request instruction for saving process of the data to be saved of the customer, it acquires first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means and transmits it to an external third party. a first authenticator authentication requesting means for requesting authentication of the first authenticator when receiving a data saving process request instruction, the first authenticator authentication requesting means providing the first authenticator to the external first authenticator authentication system and requesting authentication of the first authenticator; a first authenticator ID information and key information receiving means for data saving, receiving the first authenticator ID information and key information required for saving data from the first authenticator information managing means when the first authenticator is authenticated by the external first authenticator authentication system; and a first authenticator ID information and key information receiving means for data saving, receiving the first authenticator ID information and key information required for saving data from the first authenticator information managing means when the first authenticator ID information and key information receiving means for data saving receives the first authenticator ID information and key information required for saving data. a first information notification means for notifying the second authenticator of information that a request instruction for evacuation processing of the data to be saved for the client has been issued by a third authenticator and information urging the second authenticator to issue an approval instruction for the evacuation processing of the data to be saved for the client; a data evacuation processing approval instruction means for issuing an instruction to approve the evacuation processing of the data to be saved for the client via the second authenticator who has received the notification from the first information notification means; a data evacuation processing approval instruction receiving means for receiving an instruction to approve the evacuation processing of the data to be saved for the client from the data evacuation processing approval instruction means; a data evacuation processing approval instruction receiving means, when receiving an approval instruction for evacuation processing of the data to be saved for the client, acquires second authenticator authentication information required for authenticating the second authenticator from the second authenticator information management means, provides the information to an external second authenticator authentication system, and requests authentication of the second authenticator; and, when the second authenticator is authenticated by the external second authenticator authentication system, receives second authenticator ID information and key information required for data evacuation from the second authenticator information management means.a data saving second authenticator ID information and key information receiving means; a second information notifying means for, when said data saving second authenticator ID information and key information receiving means receives said second authenticator ID information and key information necessary for data saving, notifying said first authenticator of information that said second authenticator has given an approval instruction for saving data to be saved by said second authenticator and information urging said first authenticator to give an instruction to request saving data to be saved by said second authenticator; a data saving process request instructing means for instructing a request for saving data to be saved by said first authenticator via said first authenticator who has received the notification from said second information notifying means; a data evacuation processing request instruction receiving means for receiving a request instruction for a process to request evacuation of data to be saved for the client; and a data evacuation processing agreement information creating means for, when the data evacuation processing request instruction receiving means receives a request instruction for a process to request evacuation of data to be saved for the client, creating agreement information between the first authenticator and the second authenticator regarding the process to save the client's data, using the first authenticator ID information and key information required for data evacuation received by the first authenticator ID information and key information receiving means for data evacuation and the second authenticator ID information and key information required for data evacuation received by the second authenticator ID information and key information receiving means for data evacuation, The file data real-time restoration system includes a data restoration processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer, a customer data restoration instruction means for instructing the restoration of the customer's data based on the agreement information when the agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer is acquired by the data restoration processing agreement information acquisition means, a program having a plurality of decryption and combination algorithms with different file data decryption and combination processing methods, linked to a program having each of the encryption and division algorithms, a customer data restoration instruction acceptance means for accepting an instruction to restore the customer's data to be restored from the customer data restoration instruction means, and a data restoration information management means provided in each planet, for each group of the file data linked to information of each of the protection points managed in a black box environment by the protection point information management means in the planet corresponding to the protection point. based on key information (or the first parameter included in the key information) formed using the first authenticator ID information and the second authenticator ID information required for data restoration in the agreement information between the first authenticator and the second authenticator regarding the restoration process of the data to be restored for the customer acquired by the data restoration process agreement information acquisition means, which is linked to the file data to be extracted and accepted by the customer data restoration instruction acceptance means (or the first parameter included in the key information or a first composite parameter (composed of a pair of a first decryption parameter designated and managed offline by the customer and a first encryption parameter automatically generated from the first decryption parameter), and the second parameter or a second composite parameter (composed of a pair of a second decryption parameter designated and managed offline by the digital asset guard service operations manager (modularized and incorporated in a predetermined processing means that performs the relevant processing) and a second encryption parameter automatically generated from the second decryption parameter (modularized and incorporated in a predetermined processing means that performs the relevant processing),an encrypted server index information extraction means having a function of extracting encrypted server index information (recorded in a node group at a specific location in the distributed ledgers of the private type, the consortium type, etc. by the server index information recording means); a server index information decryption means provided in each planet and having a function of decrypting the encrypted server index information extracted by the encrypted server index information extraction means for each group of file data linked to the information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point; and a server index information decryption means provided in each planet and using the server index information decrypted by the server index information decryption means for each group of file data linked to the information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point. an encrypted and divided file data extraction means having a function of extracting, from any of the base nodes belonging to each of the distributed file management groups and the recording devices at the base nodes at the multiple bases connected to the base nodes via a network, each of the file data in an encrypted and divided state that has been allocated to each of the distributed file management groups by the distribution means and distributedly recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in the recording devices at the multiple bases connected to the base nodes via a network; a download means provided in each planet, for downloading, in the planet corresponding to the conservation point, each of the file data in an encrypted and divided state extracted by the encrypted and divided file data extraction means for each group of the file data linked to information of each of the conservation points managed in a black box environment by the conservation point information management means; and a download means provided in each planet, for downloading, in the planet corresponding to the conservation point,a file data restoration means for decrypting and combining all of the file data associated with the information of all of the security points in an encrypted and divided state that has been extracted by the encrypted and divided file data extraction means and downloaded to the second temporary storage area by the download means, for each group of file data associated with the information of each security point managed in a black box environment by the security point information management means, using a program having the decryption and combination algorithm that is associated with a program having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means, to restore the client's data before it was saved; and a second data erasure means for erasing each of the file data in an encrypted and divided state that has been downloaded to the second temporary storage area after it has been restored to the client's data before it was saved by the file data restoration means, The data restoration processing agreement information acquisition means includes a data restoration processing request instruction means for instructing a request for restoration processing of data to be restored for the customer via the first authenticator, a data restoration processing request instruction acceptance means for accepting a request instruction for restoration processing of data to be restored for the customer from the data restoration processing request instruction means, and a data restoration processing request instruction acceptance means for acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means and issuing the first authenticator authentication information to an external third party when the data restoration processing request instruction acceptance means accepts a request instruction for restoration processing of data to be restored for the customer. a first authenticator authentication requesting means for requesting authentication of the first authenticator when receiving a data restoration processing request instruction, the first authenticator authentication requesting means providing the first authenticator to a first authenticator authentication system and requesting authentication of the first authenticator; a first authenticator ID information and key information receiving means for data restoration receiving the first authenticator ID information and key information required for data restoration from the first authenticator information managing means when the first authenticator is authenticated by the external first authenticator authentication system; a third information notification means for notifying the second certifier of information that a request instruction for restoration of the data to be restored of the customer has been given by a third information notification means and information urging the second certifier to give an approval instruction for the restoration of the data to be restored of the customer; a data restoration processing approval instruction means for instructing approval of the restoration of the data to be restored of the customer via the second certifier who has received the notification from the third information notification means; a data restoration processing approval instruction receiving means for receiving an approval instruction for the restoration of the data to be restored of the customer from the data restoration processing approval instruction means; a data restoration processing approval instruction receiving second authenticator authentication requesting means for acquiring second authenticator authentication information required for authenticating the second authenticator from the second authenticator information managing means when the original processing approval instruction receiving means receives an approval instruction for the restoration processing of the data to be restored for the customer, and providing the second authenticator authentication information to an external second authenticator authentication system, and requesting authentication of the second authenticator; and when the second authenticator is authenticated by the external second authenticator authentication system, receiving the second authenticator ID information and key information required for data restoration from the second authenticator information managing means.a data restoration second authenticator ID information and key information receiving means; a fourth information notifying means for, when said data restoration second authenticator ID information and key information receiving means receives said second authenticator ID information and key information necessary for data restoration, notifying said first authenticator of information that said second authenticator has instructed to approve the restoration process of said data to be restored by said customer and information urging said customer to instruct a request for the restoration process of said data to be restored; a data restoration process request instructing means for instructing a request for the restoration process of said data to be restored by said first authenticator who has received the notification from said fourth information notifying means; and and a data restoration processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer, by combining the first authenticator ID information and key information required for data restoration received by the first authenticator ID information and key information receiving means for data restoration and the second authenticator ID information and key information required for data restoration received by the second authenticator ID information and key information receiving means for data restoration, when the data restoration processing request instruction receiving means receives an instruction to request restoration processing of the data to be restored for the customer.
[0098] Furthermore, in the real-time save / restore type digital asset guard service providing system of the second aspect of the present invention, the file data real-time save system comprises a user-side file data real-time save system that operates on the side of a user (customer and data manager) who desires to save file data, and a digital asset guard service operator-side file data real-time save system that operates on the side of the digital asset guard service operator, the user-side file data real-time save system comprises the data save processing agreement information acquisition means, the customer data save instruction means, a program having a plurality of the encryption / division algorithms, the encryption / division algorithm selection acceptance means, the customer data save instruction acceptance means, the file data encryption / division means, the upload means, the file data preservation point correspondence sorting means, and the preservation point information management means, and the digital asset guard service operator-side file data real-time save system comprises the distributed file management group allocation means, the distributed recording means, and the above The file data real-time restoration system has the server index information creation means, the server index information recording means, and the first data erasure means, and the file data real-time restoration system comprises a user-side file data real-time restoration system operating on the side of the user (customer or data manager) who wishes to restore the saved file data, and a digital asset guard service operator-side file data real-time restoration system operating on the side of the digital asset guard service operator-side, and the user-side file data real-time restoration system has the data restoration processing agreement information acquisition means, the customer data restoration instruction means, a program having a plurality of the decryption and combination algorithms, the downloading means, the file data restoration means, and the second data erasure means, and it is preferable that the digital asset guard service operator-side file data real-time restoration system has the customer data restoration instruction acceptance means, the encrypted server index information extraction means, the server index information decryption means, and the encrypted and divided file data extraction means.
[0099] In addition, in the real-time saving and restoring type digital asset guard service providing system according to the first aspect of the present invention, it is preferable that the at least two conservation points are at least two addresses in one blockchain.
[0100] In addition, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the at least two conservation points are at least one address in each of at least two blockchains.
[0101] In addition, in the second aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable that the at least two conservation points are at least two addresses in one distributed ledger group.
[0102] In addition, in the second aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable that the at least two conservation points are at least one address in each of the at least two distributed ledgers.
[0103] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the file data real-time restoration system further comprises a restoration processing time zone etc. setting receiving means for receiving settings from a customer who wishes to restore file data, such as the time zone for performing the file data restoration process, the IP address for restoration, and the period during which restoration is possible, and a file data restoration processing operation control means for controlling the customer data restoration instruction receiving means, the smart contract (or server application) for extracting encrypted server index information, the smart contract (or server application) for decrypting server index information, the smart contract (or server application) for extracting encrypted and split file data, the downloading means, the file data restoration means, and the second data erasure means to operate only during the time zones for which the restoration processing time zone etc. setting receiving means has received settings.
[0104] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the file data real-time restoration system further has an authorization code setting receiving means for receiving the setting of an authorization (license) code from a customer who wishes to restore file data, and that the file data restoration processing operation control means controls the customer data restoration instruction receiving means, the smart contract (or server application) for extracting encrypted server index information, the smart contract (or server application) for decrypting server index information, the smart contract (or server application) for extracting encrypted and split file data, the downloading means, the file data restoration means, and the second data erasure means to operate only during the time period for which the restoration processing time period, etc. setting receiving means has accepted the setting, and when the authorization code accepted by the authorization code setting receiving means has been approved by the digital asset guard service operator.
[0105] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the approval code set in the approval code setting and receiving means is a code that a customer wishing to restore file data receives from the digital asset guard service operations manager, and the file data restoration processing operation control means is configured to grant an operation license for a program (or smart contract) having the decryption and combination algorithm linked to a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection and receiving means when the approval code accepted by the approval code setting and receiving means is approved by the digital asset guard service operations manager and the customer's identity is confirmed systematically by multi-step authentication, biometric authentication, one-time passcode, etc. registered on the customer's smartphone.
[0106] In addition, in the real-time backup and restoration type digital asset guard service providing system according to the first aspect of the present invention, each divided file data recorded in the node of each base belonging to each of the distributed file management groups and in the recording devices of multiple bases connected to the node of the base via a network is managed in an encrypted state, and index information such as the hash of each file data and the distributed file group to which the recorded file data is assigned is recorded in a block, and the blocks are linked by a chain in which time data is incorporated into the hash, and the file data real-time backup system is configured to perform the data backup service contract application acceptance information recording smart contract (or server application) It is preferable that the distributed ledger structure further comprises a storage period setting smart contract (or server application) having a function of setting the storage period of the block on a planet-by-planet basis when each file data is distributedly recorded by each of the distributed recording smart contracts (or server applications) based on information on the storage period of the file data that the customer wishes to evacuate, which is recorded in a node group at a specific location in the distributed ledger structure by a smart contract for setting a storage period, and a chain disconnection smart contract (or server application) having a function of disconnecting the chain of a block that has passed the storage period set by the storage period setting smart contract (or server application).
[0107] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the file data real-time backup system further has a block deletion smart contract (or server application) that has the function of deleting unnecessary blocks that have been detached via the chain detachment smart contract (or server application).
[0108] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, the file data real-time backup system has the function of sending a notification to the customer to confirm whether or not the unnecessary blocks separated via the chain separation smart contract (or server application) can be deleted via the block deletion smart contract (or server application), and if there is no reply from the customer, notifying the digital asset guard service operator and confirming whether or not the unnecessary blocks can be deleted, and preferably further having an unnecessary block data backup means configured to provisionally record each of the encrypted and divided file data as backup data via a predetermined recording medium disconnected from the network, and to erase the provisionally recorded backup data after a certain period of time has passed.
[0109] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, when the unnecessary block data backup means sends a notification to the customer to confirm whether or not the unnecessary blocks can be deleted, if it is confirmed that the customer wishes to extend the storage period of the file data, it is preferable that the means is configured to provisionally record each of the encrypted and divided file data as backup data via a specified recording medium disconnected from the network, and at the same time select a new planet that meets the conditions of the extended storage period of the file data desired by the customer, automatically backup the file data to the nodes of each base that make up the selected planet and to recording devices of multiple bases that are network-connected to the nodes of the base, and update the server index information, and after the update, erase the provisionally recorded backup data after a certain period of time has passed.
[0110] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable to further have a rollover smart contract (or server application) that has the function of setting a new planet and distributed file management group, inheriting the management number of the old server index information and changing it to a new management number to create new server index information, in order to extend the storage period of each file data that is encrypted and divided into multiple parts and recorded as the block in each site node belonging to each of the distributed file management groups and in multiple site storage devices connected to the site nodes via a network, before the expiration of the storage period of the block set by the storage period setting smart contract (or server application), and then deleting the file data and the old server index information for the file data that are recorded in each site node belonging to the new distributed file management group and in multiple site storage devices connected to the site nodes via a network.
[0111] Furthermore, the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention preferably further comprises: a small amount of file data provisional recording means for recording small amounts of file data to be backed up in a predetermined confidential blockchain in real time, within the block capacity; a file data integration means configured to integrate each small amount of file data recorded in the predetermined confidential blockchain by the small amount of file data provisional recording means into one integrated file data in batch processing several times a day, and to use the integrated file data for backup processing, such as dividing and encrypting the file data by the file data real-time backup system and distributing the recording to each base node belonging to the distributed file management group and to recording devices at multiple bases connected to the base nodes via a network; and a small amount of file data erasure means for, after the file data real-time backup system has completed the backup processing of the integrated file data, cutting the chain of the block that records the corresponding small amount of file data in the predetermined confidential blockchain and erasing the file data recorded in that block.
[0112] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the file data integration means integrates each small amount of file data recorded in the specified confidential blockchain by the small amount file data temporary recording means into one integrated file data in batch processing several times a day, and passes the integrated file data to a smart contract (or server application) in the file data real-time backup system that has the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means, and controls the backup process to be carried out from dividing and encrypting the file data to the nodes of each base belonging to the distributed file management group and distributed recording to recording devices of multiple bases connected to the nodes of the base via a network.
[0113] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the small amount of file data erasure means has a function of setting a provisional storage period of a predetermined number of days (for example, about 7 days) for file data that has been recorded in the specified confidential blockchain by the small amount of file data provisional recording means, and that has been integrated into one integrated file data by the file data integration means, and for which the file data real-time backup system has completed the backup process for the integrated file data, and a function of cutting the chain of the corresponding block in the specified confidential blockchain after the provisional storage period has elapsed, and erasing the file data recorded in that block.
[0114] Furthermore, the real-time backup / restoration type digital asset guard service providing system of the first aspect of the present invention has a second file data real-time deletion system, the second file data real-time deletion system having: data deletion processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding deletion processing of data to be deleted for the customer; customer data deletion instruction means for issuing an instruction to delete the data to be deleted for the customer based on the agreement information when agreement information between the first authenticator and the second authenticator regarding deletion processing of data to be deleted for the customer is acquired by the data deletion processing agreement information acquisition means; customer data deletion instruction acceptance means for accepting an instruction to delete the data to be deleted for the customer from the customer data deletion instruction means; and file data preservation point deletion means for deleting information of the preservation point linked to the file data to be deleted accepted by the customer data deletion instruction acceptance means, which is managed in a black box environment by the preservation point information management means. and a data deletion processing agreement information acquisition means for acquiring first authenticator authentication information from the first authenticator information management means when the data deletion processing request instruction means receives a request for deletion of data to be deleted for the customer. a first authenticator authentication requesting means for receiving a data deletion processing request instruction, which provides the first authenticator to an external first authenticator authentication system and requests authentication of the first authenticator; a first authenticator ID information and key information receiving means for data deletion, which receives the first authenticator ID information and key information necessary for data deletion from the first authenticator information managing means when the first authenticator is authenticated by the external first authenticator authentication system; and a first authenticator ID information and key information receiving means for data deletion, which receives the first authenticator ID information and key information necessary for data deletion from the first authenticator information managing means when the first authenticator ID information and key information receiving means receives the first authenticator ID information and key information necessary for data deletion.a fifth information notification means for notifying the second authenticator of information that the first authenticator has issued a request instruction for deletion of the data to be deleted for the client and information urging the second authenticator to issue an instruction to approve the deletion of the data to be deleted for the client; a data deletion process approval instruction means for issuing an instruction to approve the deletion of the data to be deleted for the client via the second authenticator who has received the notification from the fifth information notification means; and a data deletion process approval instruction receiving means for receiving an instruction to approve the deletion of the data to be deleted for the client from the data deletion process approval instruction means. a data deletion processing approval instruction receiving means for receiving an approval instruction for a deletion processing of data to be deleted from the customer, acquiring second authenticator authentication information required for authenticating the second authenticator from the second authenticator information managing means, providing the second authenticator authentication information to an external second authenticator authentication system, and requesting authentication of the second authenticator; and a data deletion processing approval instruction receiving means for receiving an approval instruction for a deletion processing of data to be deleted from the second authenticator information managing means, providing the second authenticator authentication information to an external second authenticator authentication system, and requesting authentication of the second authenticator. a sixth information notifying means for, when the second authenticator ID information and key information receiving means for data deletion receives the second authenticator ID information and key information necessary for deleting data, notifying the first authenticator of information that the second authenticator has issued an approval instruction for deletion processing of the data to be deleted for the customer and information that prompts the customer to issue a request instruction for deletion processing of the data to be deleted; and a sixth information notifying means for, when the second authenticator ID information and key information receiving means for data deletion receives the second authenticator ID information and key information necessary for data deletion, notifying the first authenticator of information that the second authenticator has issued an approval instruction for deletion processing of the data to be deleted for the customer and information that prompts the customer to issue a request instruction for deletion processing of the data to be deleted for the customer via the first authenticator that has received the notification from the sixth information notifying means. a data deletion processing request instruction means for instructing a request for data deletion processing, a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of data to be deleted from said data deletion processing request instruction means, and when said data deletion processing request instruction receiving means receives a request instruction for deletion processing of data to be deleted from said customer, said first authenticator ID information and key information receiving means for data deletion receives said first authenticator ID information and key information necessary for data deletion and said second authenticator ID information and key information receiving means receives saidIt is preferable to have a data deletion processing agreement information creation means for creating agreement information between the first authenticator and the second authenticator regarding the deletion processing of the data to be deleted for the customer, using the second authenticator ID information and key information required for data deletion.
[0115] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, the second file data real-time deletion system comprises a user-side second file data real-time deletion system operating on the side of the user (customer and data manager) who wishes to delete file data, and a digital asset guard service operator-side second file data real-time deletion system operating on the side of the digital asset guard service operator-side, and it is preferable that the user-side second file data real-time deletion system has the data deletion processing agreement information acquisition means and the customer data deletion instruction means, and that the digital asset guard service operator-side second file data real-time deletion system has the customer data deletion instruction acceptance means and the file data preservation point information deletion means.
[0116] Furthermore, the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention has a second file data real-time update (saving and deletion) system, and the second file data real-time update (saving and deletion) system comprises: data update (saving and deletion) processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer between the first authenticator and the second authenticator; customer data update (saving and deletion) instruction means for instructing the update (saving and deletion) of the data to be updated (saving and deletion) for the customer based on the agreement information when agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer is acquired by the data update (saving and deletion) processing agreement information acquisition means; a program (or smart contract) having a plurality of the encryption / division algorithms for different file data encryption and division processing methods; and an update (saving and deletion) processing time encryption / division algorithm selection receiving means for receiving a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the customer's data to be evacuated, which is acquired by the data update (saving and deletion) processing agreement information acquisition means; an update (saving and deletion) processing time customer data evacuation instruction receiving means for receiving an instruction to evacuate the customer's data to be evacuated from said customer data update (saving and deletion) instruction means; an update (saving and deletion) processing time file data encryption / division means for encrypting and dividing the customer's data to be evacuated, which is accepted by said update (saving and deletion) processing time customer data evacuation instruction accepting means, into a plurality of file data using a program (or smart contract) having the encryption / division algorithm accepted by said update (saving and deletion) processing time encryption / division algorithm selection accepting means; andan update (saving and deletion) processing time uploading means for uploading to a first temporary storage area; an update (saving and deletion) processing time file data conservation point associating and sorting each of the file data encrypted and divided into a plurality of pieces by the update (saving and deletion) processing time file data encryption and division means and uploaded to the first temporary storage area by the update (saving and deletion) processing time uploading means, by associating the file data with one of the conservation points corresponding to at least two planets for managing the file data; and an update (saving and deletion) processing time conservation point information management means for managing information of the conservation points for managing the file data sorted by the update (saving and deletion) processing time file data conservation point associating and sorting means in a black box environment; a smart contract (or server application) for allocating distributed file management groups during update (evacuation and deletion) processing, which is provided in each planet and has a function of allocating each of the file data linked to the information of the conservation points managed in a black box environment by the conservation point information management means during update (evacuation and deletion) processing in accordance with conditions specified by the customer, to a plurality of distributed file management groups configured by nodes at each base constituting the planet corresponding to the conservation points and recording devices at multiple bases connected to the nodes at each base via a network; a smart contract (or server application) for distributed recording during update (evacuation and deletion) processing, which is provided in each planet and has a function of distributing and recording each of the file data associated with the information of each of the conservation points sorted by the file data conservation point association sorting means during update (evacuation and deletion) processing and managed in a black box environment by the conservation point information management means during update (evacuation and deletion) processing, to each of the base nodes belonging to each of the corresponding distributed file management groups and to recording devices at multiple bases connected to the base nodes via a network; terminal information (information identifying the other party, such as a fixed IP address) for uploading to the first temporary storage area using the upload means during update (evacuation and deletion) processing, the number of the predetermined processing means that performs the corresponding processing of the recording destination of the customer's file data, and information of the planet to which the recording destination of the file data belongs;a smart contract (or server application) for creating and recording system setting information during update (backup and deletion) processing, which has the function of creating system setting information having information on a group of file servers (in a node at a specified site and in recording devices at multiple sites connected to the node at the site via a network) that constitutes a distributed file management group, encrypting the information, and recording it in a group of nodes at a specific site in the distributed ledger structure; key information comprising the first authenticator ID information and the second authenticator ID information necessary for data evacuation, which is included in agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer, acquired by the data update (backup and deletion) processing agreement information acquisition means; and information on the preservation points, which are distributedly recorded by each of the distributed recording means during update (backup and deletion) processing, sorted by the file data preservation point association sorting means during update (backup and deletion) processing, and managed in a black box environment by the preservation point information management means during update (backup and deletion) processing. a smart contract (or server application) for creating server index information during update (backup and deletion) processing, which has a function to create server index information having information on the file name of each of the file data linked to the smart contract (or server application) and configuration information of each of the distributed file management groups to which each of the file data is to be allocated; a smart contract (or server application) for recording server index information during update (backup and deletion) processing, which has a function to encrypt the server index information created by the smart contract (or server application) for creating server index information during update (backup and deletion) processing and record it in a node group at a specific location in the distributed ledger structure; and a data backup process for the data to be backed up for the customer, which has been acquired by the data update (backup and deletion) processing agreement information acquisition means associated with a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means for update (backup and deletion) processing,a smart contract (or a program with a wallet function) for creating customer setting information during update (saving and deletion) processing, the smart contract having a function of creating customer setting information having agreement information between the first authenticator and the second authenticator; a smart contract (or a program with a wallet function) for creating customer index information during update (saving and deletion) processing, the smart contract having a function of creating customer index information having information on the original file name and upload date of the customer's file data to be saved during update (saving and deletion) processing; and a smart contract (or a server application) for recording customer index information during update (saving and deletion) processing, the smart contract having a function of encrypting the customer index information created by the smart contract (or the program with a wallet function) for creating customer index information during update (saving and deletion) processing and recording it in a group of nodes at a specific location in the distributed ledger structure. a first data erasure means for erasing each file data uploaded to the first temporary storage area after the server index information has been encrypted and recorded in the node group at the specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information at the time of update (saving and deletion); a customer data deletion instruction receiving means for update (saving and deletion) processing for receiving an instruction to delete data to be deleted for the customer from the update (saving and deletion) instruction means; and a file data preservation point information deletion means for updating (saving and deletion) processing for deleting information of the preservation points associated with the file data to be deleted accepted by the customer data deletion instruction receiving means at update (saving and deletion) processing, which is managed in a black box environment by the preservation point information management means at update (saving and deletion) processing; The data update (saving and deletion) processing agreement information acquisition means includes a data update (saving and deletion) processing request instruction means for instructing a request for update (saving and deletion) processing of data to be updated (saving and deletion) of the customer via the first authenticator, a data update (saving and deletion) processing request instruction acceptance means for accepting a request instruction for update (saving and deletion) processing of data to be updated (saving and deletion) of the customer from the data update (saving and deletion) processing request instruction means, and a data update (saving and deletion) processing request instruction receiving first authenticator authentication request means for, when receiving a request instruction for updating (saving and deleting) data to be updated (saved and deleted), acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means and providing the information to an external first authenticator authentication system, and requesting authentication of the first authenticator; and a data update (saving and deletion) processing request instruction receiving first authenticator authentication request means for, when the first authenticator is authenticated by the external first authenticator authentication system, acquiring first authenticator authentication information required for updating (saved and deleted) data from the first authenticator information management means. a first authenticator ID information and key information receiving means for data update (saving and deletion) that receives the first authenticator ID information and key information, and when the first authenticator ID information and key information receiving means for data update (saving and deletion) receives the first authenticator ID information and key information necessary for data update (saving and deletion), information indicating that a request instruction for update (saving and deletion) processing of data to be updated (saving and deletion) by the first authenticator has been issued and update (saving and deletion) of data to be updated (saving and deletion) by the customer a seventh information notification means for notifying the second authenticated person of information prompting an approval instruction for the processing; a data update (saving and deletion) processing approval instruction means for instructing approval of the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer via the second authenticated person who has received the notification from the seventh information notification means; and a data update (saving and deletion) processing approval instruction receiving means for receiving an approval instruction for the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer from the data update (saving and deletion) processing approval instruction means.a data update (saving and deletion) processing approval instruction receiving means for receiving an approval instruction for updating (saving and deleting) data to be updated (saving and deleting) by the customer, which obtains second authenticator authentication information required for authenticating the second authenticator from the second authenticator information managing means, provides the information to an external second authenticator authentication system, and requests authentication of the second authenticator; and a data update (saving and deletion) processing approval instruction receiving means for receiving an approval instruction for updating (saving and deleting) data to be updated (saving and deleting) by the customer, which obtains second authenticator authentication information required for authenticating the second authenticator from the second authenticator information managing means, provides the information to an external second authenticator authentication system, and requests authentication of the second authenticator. a data updating (saving and deleting) second authenticator ID information and key information receiving means for receiving the second authenticator ID information and key information required for updating (saving and deleting) data from the management means; and a data updating (saving and deleting) second authenticator ID information and key information receiving means for receiving the second authenticator ID information and key information required for updating (saving and deleting) data from the management means, when the second authenticator ID information and key information receiving means for receiving the second authenticator ID information and key information required for updating (saving and deleting) data receives information indicating that the second authenticator has issued an approval instruction for updating (saving and deleting) data for the customer to be updated (saving and delete) and information indicating that the second authenticator has issued an approval instruction for updating (saving and deleting) data for the customer to be updated (saving and delete). an eighth information notification means for notifying the first authenticated person of information prompting the first authenticated person to issue a request instruction for updating (saving and deleting) data to be updated (saving and deleting), a data update (saving and deletion) processing request instruction means for instructing a request for updating (saving and deleting) data to be updated (saving and deleting) data of the customer via the first authenticated person who has received the notification from the eighth information notification means; and a data update (saving and deletion) processing request instruction means for receiving a request instruction for updating (saving and deleting) data to be updated (saving and deleting) data of the customer from the data update (saving and deletion) processing request instruction means. and when the data update (saving and deletion) processing request instruction receiving means receives a request instruction for processing to update (save and delete) data to be updated (saved and deleted) by the customer, the data update (saving and deletion) first authenticator ID information and key information receiving means receives the first authenticator ID information and key information required for updating (save and delete) data and the second authenticator ID information and key information receiving means receives the second authenticator ID information and key information required for updating (save and delete) data and the second authenticator ID information and key information receiving means receives theIt is preferable to have a data update (saving and deletion) processing agreement information creation means for creating agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of data to be updated (saved and deleted) by the customer.
[0117] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the second file data real-time update (saving and deletion) system comprises a user-side second file data real-time update (saving and deletion) system that operates on the side of a user (customer or data administrator) who desires to update (saving and deleting) file data, and a digital asset guard service administrator-side second file data real-time update (saving and deletion) system that operates on the side of the digital asset guard service administrator, and the user-side second file data real-time update (saving and deletion) system comprises the data update (saving and deletion) processing agreement information acquisition means, the customer data update (saving and deletion) instruction means, a program (or smart contract) having a plurality of the encryption and division algorithms, the encryption and division algorithm selection acceptance means at the time of the update (saving and deletion) processing, the customer data save instruction acceptance means at the time of the update (saving and deletion) processing, the file data encryption and division means at the time of the update (saving and deletion) processing, and the The digital asset guard service operator side preferably has an upload means for updating (saving and deleting) the file data, a file data preservation point matching and sorting means for updating (saving and deleting), and a preservation point information management means for updating (saving and deleting), and the second file data real-time updating (saving and deleting) system on the digital asset guard service operator side preferably has a smart contract (or server application) for allocating distributed file management groups for updating (saving and deleting), a smart contract (or server application) for distributing data for updating (saving and deleting), a smart contract (or server application) for creating server index information for updating (saving and deleting), a smart contract (or server application) for recording server index information for updating (saving and deleting), a first data erasing means for updating (saving and deleting), a customer data deletion instruction receiving means for updating (saving and deleting), and a file data preservation point information deleting means for updating (saving and deleting).
[0118] Furthermore, a real-time evacuation and restoration type digital asset guard service provision system according to a third aspect of the present invention is a real-time evacuation and restoration type digital asset guard service provision system for guarding digital assets from high-level cyber attacks, constructed with a distributed ledger in distributed ledger technology such as blockchain, and a smart contract or server application for performing predetermined processing using the data managed in the distributed ledger, or a system for handling data that is difficult to manage in a system, such as personal information, mainly on-chain in two configurations, one in which the information is managed by a company, and the other in which the information is managed by an individual, and is a base system for managing the personal information directly on-chain in both configurations, or for separating the personal information portion based on the information and utilizing it as personal attribute information for big data analysis, etc., and is composed of a group of nodes combining nodes at multiple locations in different regions around the world (blockchain and file distributed management function, a distributed ledger structure that is constructed having a plurality of planets (planets, each of which is a unit that combines the above and constitutes one unit that constitutes a system for providing services that implement distributed smart contracts, server applications, etc.), and is mainly composed of a closed blockchain such as a private or consortium blockchain, and is composed of a plurality of chains that may include a distributed ledger group, a public blockchain, etc.; a first user information management means that manages first user ID information necessary for data evacuation and restoration, etc., of a first user who is one of the data administrators that manages the customers and their data; a second user information management means that manages second user ID information necessary for data evacuation and restoration, etc., of a second user who is the other of the customers and the data administrators that manage the customers' data; a file data real-time evacuation system; and a file data real-time restoration system, and the nodes at each of the locations are connected via a network to recording devices at multiple locations in different regions around the world to form a distributed file management group; The file data real-time evacuation system includes a data evacuation processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding the evacuation processing of the data to be evacuated for the customer between the first user and the second user, a customer data evacuation instruction means for issuing an instruction to evacuate the data to be evacuated for the customer based on the agreement information when the agreement information between the first user and the second user regarding the evacuation processing of the data to be evacuated for the customer is acquired by the data evacuation processing agreement information acquisition means, and an encryption and division algorithm processor for accepting selection of a program (or smart contract) having a plurality of encryption and division algorithms for encrypting and dividing file data, and a program (or smart contract) having a predetermined encryption and division algorithm based on the agreement information between the first user and the second user (or a first parameter specified by the customer who desires to evacuate file data, which is included in the agreement information) regarding the evacuation processing of the data to be evacuated for the customer acquired by the data evacuation processing agreement information acquisition means. a file data encryption and division means for encrypting and dividing the customer data to be saved that has been received by the customer data evacuation instruction receiving means into a plurality of file data using a program (or smart contract) having the encryption and division algorithm received by the encryption and division algorithm selection receiving means; an upload means for uploading each of the file data encrypted and divided into a plurality of files by the file data encryption and division means to a first temporary storage area; a file data security point associating and sorting each of the file data encrypted and divided into a plurality of files by the file data encryption and division means and uploaded to the first temporary storage area by the upload means, by associating it with one of at least two security points for managing the file data; and information of the security points for managing the file data sorted by the file data security point associating and sortingA means for managing maintenance point information in a black box environment; a distributed file management group allocation means or a smart contract (or server application) for distributed file management group allocation, which is provided in each planet and has a function of allocating the file data associated with the information of the conservation point managed in a black box environment by the conservation point information management means, which is sorted by the file data conservation point matching sorting means based on the agreement information between the first user and the second user (or the first parameter included in the agreement information and the second parameter specified by the digital asset guard service operator) regarding the evacuation process of the data to be evacuated by the customer, which is set by the digital asset guard service operator according to conditions specified by the customer, to a plurality of distributed file management groups, which are configured by the digital asset guard service operator according to conditions specified by the customer, and which are constituted by nodes at each base constituting the planet corresponding to the conservation point and recording devices at multiple bases connected to the nodes at each base via a network; a distributed recording means or a smart contract (or server application) for distributed recording that is provided in each planet and has the function of distributing and recording each of the file data associated with the information of each of the conservation points that has been sorted by the distributed file management group sorting means or the smart contract (or server application) for distributed file management group sorting, and that is managed in a black box environment by the conservation point information management means, to each of the base nodes belonging to each of the corresponding distributed file management groups and to recording devices at multiple bases that are connected to the base nodes via a network; terminal information (information that identifies the other party, such as a fixed IP address) for uploading to the first temporary storage area using the upload means; the number of a predetermined processing means or smart contract (or server application) that performs the corresponding processing of the recording destination of the customer's file data; and information on the planet to which the recording destination of the file data belongs;a smart contract (or server application) for creating and recording system setting information that has a function of creating system setting information including information on a group of file servers (in a node at a specified location and in recording devices at multiple locations that are networked to the node at that location) that constitutes a distributed file management group, encrypting the information, and recording it in a group of nodes at a specific location in the distributed ledger structure; key information that uses the first user ID information and the second user ID information that are included in the agreement information between the first user and the second user regarding the evacuation process of the data to be evacuated for the customer that is acquired by the data evacuation process agreement information acquisition means; file name information of each of the file data that is sorted by the file data preservation point association sorting means and that is managed in a black box environment by the preservation point information management means, that is distributed and recorded by each of the distributed recording means or the smart contract (or server application) for distributed recording, and that is linked to the information on the preservation point; a smart contract (or server application) for creating server index information having a function of creating server index information containing configuration information of a file management group; a smart contract (or server application) for recording server index information having a function of encrypting the server index information created by the smart contract (or server application) for creating server index information and recording it in a group of nodes at a specific location in the distributed ledger structure; a smart contract (or program with a wallet function) for creating customer setting information having agreement information between the first user and the second user (or setting information of the first parameter included in the agreement information) regarding the evacuation process of the data to be evacuated for the customer, which is linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means; and an original file name of the customer's file data to be evacuated.a customer index information creation smart contract (or a program with a wallet function) having a function of creating customer index information having information on the upload date; a customer index information recording smart contract (or a server application) having a function of encrypting the customer index information created by the customer index information creation smart contract (or the program with a wallet function) and recording it in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means for erasing each file data uploaded to the first temporary storage area after the server index information has been encrypted and recorded in the group of nodes at a specific location in the distributed ledger structure by the server index information recording smart contract (or server application), The data saving process agreement information acquisition means includes a data saving process request instruction means for instructing, via the first user, a request for saving process of the data to be saved of the customer, a data saving process request instruction acceptance means for accepting a request instruction for saving process of the data to be saved of the customer from the data saving process request instruction means, and a data saving process request instruction acceptance means for receiving the first user ID information required for saving data from the first user information management means when the data saving process request instruction acceptance means accepts a request instruction for saving process of the data to be saved of the customer. a first user ID information receiving means for receiving the first user ID information necessary for data evacuation, a first information notifying means for notifying the second user of information that the first user has requested a command to perform evacuation of the data to be evacuated for the customer and information urging the second user to approve the command to perform evacuation of the data to be evacuated for the customer when the first user ID information receiving means for data evacuation has received the first user ID information necessary for data evacuation, and a data evacuation processing approval instruction for instructing approval of the command to perform evacuation of the data to be evacuated for the customer via the second user who has received the command from the first information notifying means. a data evacuation processing approval instruction receiving means for receiving an approval instruction for the evacuation processing of the data to be evacuated of the customer from the data evacuation processing approval instruction means; a data evacuation second user ID information receiving means for receiving the second user ID information necessary for the data evacuation from the second user information management means when the data evacuation processing approval instruction receiving means receives an approval instruction for the evacuation processing of the data to be evacuated of the customer; a second information notification means for notifying the first user of information that the second user has issued an approval instruction for the evacuation process of the data to be evacuated of the customer and information urging the first user to issue a request instruction for the evacuation process of the data to be evacuated of the customer; a data evacuation process request instruction means for issuing an instruction to request the evacuation process of the data to be evacuated of the customer via the first user who has received the notification from the second information notification means; and a data evacuation process request instruction receiving means for receiving an instruction to request the evacuation process of the data to be evacuated of the customer from the data evacuation process request instruction means.a data evacuation processing agreement information creation means for creating agreement information between the first user and the second user regarding the evacuation processing of the data to be evacuated for the customer, using the first user ID information required for data evacuation and key information managed by the first user, which are received by the first user ID information receiving means for data evacuation, and the second user ID information required for data evacuation and key information managed by the second user, which are received by the second user ID information receiving means for data evacuation, when the data evacuation processing request instruction receiving means receives an instruction to request evacuation processing of the data to be evacuated for the customer, The file data real-time restoration system comprises: a data restoration processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding the restoration processing of the data to be restored for the customer between the first user and the second user; a customer data restoration instruction means for instructing the restoration of the data to be restored for the customer based on the agreement information when the agreement information between the first user and the second user regarding the restoration processing of the data to be restored for the customer is acquired by the data restoration processing agreement information acquisition means; a program (or smart contract) having a plurality of decryption and combination algorithms with different file data decryption and combination processing methods, linked to a program (or smart contract) having each of the encryption and division algorithms; a customer data restoration instruction acceptance means for accepting an instruction to restore the data to be restored for the customer from the customer data restoration instruction means; and a protection point information management system provided on each planet, which is provided on the planet corresponding to the protection point, for each group of file data linked to the information of each of the preservation points managed in a black box environment by the means, key information (or the first parameter included in the key information or a first composite parameter (composed of a pair of a first decryption parameter designated and managed offline by the customer and a first encryption parameter automatically generated from the first decryption parameter) using the first user ID information and the second user ID information required for data restoration in the agreement information between the first user and the second user regarding the restoration process of the data to be restored for the customer, which is linked to the file data to be extracted and received by the customer data restoration instruction receiving means and acquired by the data restoration process agreement information acquisition means), and the second parameter or a second decryption parameter (designated and managed offline by the digital asset guard service administrator and incorporated and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant process);a smart contract (or server application) for extracting encrypted server index information that has a function of extracting encrypted server index information (recorded in a group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on a second composite parameter (composed of a pair of a second encryption parameter incorporated and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter; and a smart contract (or server application) for extracting encrypted server index information that is provided in each planet and that, for each group of file data linked to information on each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point, extracts the encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information. a server index information decryption smart contract (or server application) having a function of decrypting server index information, the server index information being provided in each planet, and for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point, the server index information decrypted by the server index information decryption smart contract (or server application) is used to allocate the file data to each of the distributed file management groups by the distributed file management group allocation means or the distributed file management group allocation smart contract (or server application), and the file data is distributed and recorded by each of the distributed recording means or the distributed recording smart contract (or server application) in the nodes of each base belonging to each of the distributed file management groups and in recording devices of multiple bases connected to the nodes of the base via a network;an encrypted and divided file data extraction means or a smart contract (or server application) for extracting encrypted and divided file data, which has a function of extracting each of the file data in an encrypted and divided state from any of the nodes of each base belonging to each of the distributed file management groups and the recording devices of multiple bases connected to the nodes of the base via a network; a download means provided in each planet, which downloads each of the file data in an encrypted and divided state extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data for each group of the file data linked to the information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point; and a download means provided in each planet, which downloads each of the file data in an encrypted and divided state extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data to a second temporary storage area for each group of the file data linked to the information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point. a file data restoration means for decrypting and combining all of the file data linked across all of the information of the conservation points in an encrypted and divided state, which is extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data and downloaded to the second temporary storage area by the download means, into one file data to restore the client's data before it was saved, using a program (or smart contract) having the decryption and combination algorithm linked to a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means; and a second data erasure means for erasing each of the file data in an encrypted and divided state that was downloaded to the second temporary storage area after being restored to the client's data before it was saved by the file data restoration means, The data restoration processing agreement information acquisition means comprises: a data restoration processing request instruction means for instructing, via the first user, a request for restoration processing of the data to be restored of the customer; a data restoration processing request instruction acceptance means for accepting a request instruction for restoration processing of the data to be restored of the customer from the data restoration processing request instruction means; a first user ID information reception means for data restoration for receiving, from the first user information management means, the first user ID information necessary for data restoration when the data restoration processing request instruction acceptance means accepts a request instruction for restoration processing of the data to be restored of the customer; a third information notification means for notifying, when the first user ID information reception means for data restoration receives the first user ID information necessary for data restoration, the second user of information that the first user has issued a request instruction for restoration processing of the data to be restored of the customer and information urging the second user to give an approval instruction for the restoration processing of the data to be restored of the customer; and a data restoration processing approval instruction for instructing approval of the restoration processing of the data to be restored of the customer via the second user who has received the notification from the third information notification means. a data restoration processing approval instruction receiving means for receiving an instruction to approve the restoration processing of the data to be restored for the customer from the data restoration processing approval instruction means; a second user ID information receiving means for data restoration for receiving the second user ID information required for data restoration from the second user information management means when the data restoration processing approval instruction receiving means receives an instruction to approve the restoration processing of the data to be restored for the customer; a fourth information notifying means for notifying the first user, when the second user ID information receiving means for data restoration receives the second user ID information required for data restoration, that the second user has issued an instruction to approve the restoration processing of the data to be restored for the customer and that urges the first user to issue an instruction to request the restoration processing of the data to be restored for the customer; a data restoration processing request instruction means for issuing an instruction to request the restoration processing of the data to be restored for the customer via the first user who has received the notification from the fourth information notifying means; and a data restoration processing request instruction receiving means for receiving an instruction to request the restoration processing of the data to be restored for the customer from the data restoration processing request instruction means.and a data restoration processing agreement information creating means for creating agreement information between the first user and the second user regarding the restoration processing of the data to be restored for the customer, using the first user ID information required for data restoration and key information managed by the first user, which are received by the first user ID information receiving means for data restoration, and the second user ID information required for data restoration and key information managed by the second user, which are received by the second user ID information receiving means for data restoration, when the data restoration processing request instruction receiving means receives an instruction to request restoration processing of the data to be restored for the customer.
[0119] Furthermore, in the third aspect of the present invention, in the real-time save / restore type digital asset guard service providing system, the file data real-time save system comprises a user-side file data real-time save system that operates on the side of a user (customer or data manager) who desires to save file data, and a digital asset guard service operator-side file data real-time save system that operates on the side of the digital asset guard service operator, and the user-side file data real-time save system comprises the data save processing agreement information acquisition means, the customer data save instruction means, a program (or smart contract) having a plurality of the encryption / division algorithms, the encryption / division algorithm selection acceptance means, the customer data save instruction acceptance means, the file data encryption / division means, the upload means, the file data preservation point association sorting means, and the preservation point information management means, and the digital asset guard service operator-side file data real-time save system comprises the distributed file management group allocation means or the distributed file management group allocation means. the file data real-time restoration system comprises a user-side file data real-time restoration system operated on the side of a user (customer or data manager) who desires the restoration of saved file data, and a digital asset guard service operator-side file data real-time restoration system operated on the side of the digital asset guard service operator, the user-side file data real-time restoration system comprising the data restoration processing agreement information acquisition means, the customer data restoration instruction means, a program (or smart contract) having a plurality of the decryption and combination algorithms, the downloading means, the file data restoration means, and the second data erasure means;The digital asset guard service operator-side file data real-time restoration system preferably comprises the customer data restoration instruction receiving means, the smart contract (or server application) for extracting encrypted server index information, the smart contract (or server application) for decrypting server index information, and the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data.
[0120] Furthermore, a real-time backup and restoration type digital asset guard service providing system according to a third aspect of the present invention comprises a file data real-time deletion system, the file data real-time deletion system comprising: a data deletion processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding the deletion processing of data to be deleted for the customer; a customer data deletion instruction means for issuing an instruction to delete the data to be deleted for the customer based on the agreement information when the agreement information between the first user and the second user regarding the deletion processing of data to be deleted for the customer is acquired by the data deletion processing agreement information acquisition means; a customer data deletion instruction receiving means for receiving an instruction to delete the data to be deleted for the customer from the customer data deletion instruction means; and a customer data deletion instruction receiving means provided in each planet, which receives, in the planet corresponding to the conservation point, the customer data deletion instruction receiving means for receiving, for each group of file data linked to information of each of the conservation points managed in a black box environment by the conservation point information management means. key information formed using the first user ID information and the second user ID information required for data deletion in the agreement information between the first user and the second user regarding the deletion process of the data to be deleted for the customer acquired by the data deletion process agreement information acquisition means, which is linked to the file data to be deleted received by the attachment means (or the first parameter included in the key information or a first composite parameter (composed of a pair of a first decryption parameter designated and managed offline by the customer and a first encryption parameter automatically generated from the first decryption parameter), and the second parameter or a second decryption parameter (designated and managed offline by the digital asset guard service administrator and incorporated and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing), and a second encryption parameter automatically generated from the second decryption parameter (embedded and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing), anda smart contract (or server application) for extracting encrypted server index information to be deleted, which has a function of extracting encrypted server index information (recorded in a node group at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on a second composite parameter (composed of a pair of parameters, each of which is a parameter consisting of a first composite parameter and a second composite parameter consisting of a first composite parameter and a second composite parameter), a smart contract (or server application) for decrypting encrypted server index information to be deleted, which is provided in each planet, and has a function of decrypting the encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information to be deleted, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point; and a smart contract (or server application) for deleting encrypted and divided file data that has a function of deleting, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the distributed file management group allocation means, from each of the base nodes belonging to each of the distributed file management groups and from all of the base storage devices connected to the base nodes via a network, the file data being allocated to each of the distributed file management groups by the distributed file management group allocation means using server index information decrypted by the smart contract (or server application) for decrypting server index information to be deleted, and being distributedly recorded by each of the distributed storage means in each of the base nodes belonging to each of the distributed file management groups and in all of the base storage devices connected to the base nodes via a network, the file data being encrypted and divided into multiple pieces and being targeted for deletion, the file data being distributed to each of the distributed file management groups by the distributed file management group allocation means using server index information decrypted by the smart contract (or server application) for decrypting server index information to be deleted, and being distributedly recorded in each of the base nodes belonging to each of the distributed file management groups and from all of the base storage devices connected to the base nodes via a network, the data deletion processing agreement information acquisition means comprising: a data deletion processing request instruction means for instructing a request for deletion of the data targeted for deletion of the customer via the first user;a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of data to be deleted of the customer from the data deletion processing request instruction means; a first user ID information receiving means for data deletion for receiving the first user ID information necessary for data deletion from the first user information management means when the data deletion processing request instruction receiving means receives a request instruction for deletion processing of data to be deleted of the customer; a fifth information notifying means for notifying the second user, when the first user ID information receiving means for data deletion receives the first user ID information necessary for data deletion, of information that the first user has issued a request instruction for deletion processing of data to be deleted of the customer and of information urging the second user to give an instruction to approve the deletion processing of the data to be deleted of the customer; a data deletion processing approval instruction receiving means for giving an instruction to approve the deletion processing of the data to be deleted of the customer via the second user who has received the notification from the fifth information notifying means; a second user ID information receiving means for data deletion, which receives the second user ID information necessary for data deletion from the second user information management means when the management approval instruction receiving means receives an instruction to approve the deletion of data to be deleted for the customer; a sixth information notifying means, when the second user ID information receiving means for data deletion receives the second user ID information necessary for data deletion, notifying the first user of information that the second user has given an instruction to approve the deletion of data to be deleted for the customer and information urging the first user to give an instruction to request the deletion of data to be deleted for the customer; a data deletion processing request instruction receiving means, which receives an instruction to request the deletion of data to be deleted for the customer from the data deletion processing request instruction means when the data deletion processing request instruction receiving means receives an instruction to request the deletion of data to be deleted for the customer;It is preferable to have a data deletion processing agreement information creation means for creating agreement information between the first user and the second user regarding the deletion processing of the data to be deleted for the customer, using the first user ID information required for data deletion, key information managed by the first user, and the second user ID information required for data deletion and key information managed by the second user, which are received by the data deletion second user ID information receiving means.
[0121] Furthermore, in the third aspect of the present invention, the real-time backup and restoration type digital asset guard service providing system, the file data real-time deletion system comprises a user-side file data real-time deletion system that operates on the side of the user (customer and data administrator) who wishes to delete file data, and a digital asset guard service operator-side file data real-time deletion system that operates on the side of the digital asset guard service operator-side, and the user-side file data real-time deletion system has the data deletion processing agreement information acquisition means and the customer data deletion instruction means, and the digital asset guard service operator-side file data real-time deletion system has the customer data deletion instruction acceptance means, a smart contract (or server application) for extracting the encrypted server index information to be deleted, a smart contract (or server application) for decrypting the server index information to be deleted, and a smart contract (or server application) for deleting the encrypted and divided file data.
[0122] Furthermore, a real-time save / restore type digital asset guard service providing system according to a third aspect of the present invention comprises a file data real-time update (saving and deletion) system, the file data real-time update (saving and deletion) system comprising: a data update (saving and deletion) processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer between the first user and the second user; a customer data update (saving and deletion) instruction means for instructing the update (saving and deletion) of the data to be updated (saving and deletion) for the customer based on the agreement information when the agreement information between the first user and the second user regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer is acquired by the data update (saving and deletion) processing agreement information acquisition means; a program (or smart contract) having a plurality of encryption / division algorithms that differ in the file data encryption and division processing methods; and a data update (saving and deletion) instruction means for instructing the update (saving and deletion) of the data to be updated (saving and deletion) for the customer based on the agreement information when the agreement information between the first user and the second user regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer is acquired by the data update (saving and deletion) processing agreement information acquisition means. an update (saving and deletion) processing time encryption / division algorithm selection receiving means for receiving a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on agreement information between the first user and the second user regarding the evacuation processing of the data to be evacuated for the customer acquired by the update (saving and deletion) processing agreement information acquisition means; an update (saving and deletion) processing time customer data evacuation instruction receiving means for receiving an instruction to evacuate the data to be evacuated for the customer from said customer data update (saving and deletion) instruction means; an update (saving and deletion) processing time file data encryption / division means for encrypting and dividing the customer data to be evacuated, which has been accepted by said update (saving and deletion) processing time customer data evacuation instruction accepting means, into a plurality of file data using a program (or smart contract) having the encryption / division algorithm accepted by said update (saving and deletion) processing time encryption / division algorithm selection accepting means; andan update (saving and deletion) processing time uploading means for uploading to a first temporary storage area; an update (saving and deletion) processing time file data conservation point associating and sorting each of the file data encrypted and divided into a plurality of pieces by the update (saving and deletion) processing time file data encryption and division means and uploaded to the first temporary storage area by the update (saving and deletion) processing time uploading means, by associating the file data with one of the conservation points corresponding to at least two planets for managing the file data; and an update (saving and deletion) processing time conservation point information management means for managing information of the conservation points for managing the file data sorted by the update (saving and deletion) processing time file data conservation point associating and sorting means in a black box environment; a distributed file management group allocation means for update (saving and deletion) processing, which is provided in each planet and has a function of allocating the file data associated with the information of the conservation point managed in a black box environment by the conservation point information management means for update (saving and deletion) processing, which is sorted by the file data conservation point association sorting means based on agreement information between the first user and the second user (or a first parameter included in the agreement information and a second parameter specified by the digital asset guard service administrator) regarding the saving process of the data to be saved by the customer, acquired by the data update (saving and deletion) processing agreement information acquisition means, to a plurality of distributed file management groups configured by the digital asset guard service administrator according to conditions specified by the customer and consisting of nodes at each base constituting the planet corresponding to the conservation point and recording devices at a plurality of bases connected to the nodes at each base via a network; and a distributed file management group allocation means for update (saving and deletion) processing, which is provided in each planet and has a function of allocating the file data associated with the information of the conservation point managed in a black box environment by the conservation point information management means for update (saving and deletion) processing, to a plurality of distributed file management groups configured by nodes at each base constituting the planet corresponding to the conservation point and recording devices at a plurality of bases connected to the nodes at each base via a network; a distributed recording means for update (saving and deleting) processing that has a function of distributively recording each of the file data associated with the information of each of the conservation points that has been sorted by the file data conservation point association sorting means for update (saving and deleting) processing and managed in a black box environment by the conservation point information management means for update (saving and deleting) processing, which has been sorted by the distributed file management group sorting means for update (saving and deleting) processing, to each of the base nodes belonging to the corresponding distributed file management group and to recording devices at multiple bases connected to the base nodes via a network; and creating system setting information that includes terminal information (information identifying the other party such as a fixed IP address) for uploading to the first temporary storage area using the update (saving and deleting) processing upload means, the number of a predetermined processing means that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and information on a group of file servers (at the node at the predetermined base and the recording devices at multiple bases connected to the node at the predetermined base via a network) that constitutes the distributed file management group;a smart contract (or server application) for creating and recording system setting information at the time of update (backup and deletion) processing, which has a function of encrypting the encrypted data and recording it in a group of nodes at a specific location in the distributed ledger structure; key information formed using the first user ID information and the second user ID information necessary for data evacuation, which is included in the agreement information between the first user and the second user regarding the evacuation processing of the data to be evacuated for the customer acquired by the data update (backup and deletion) processing agreement information acquisition means; file name information of each of the file data that is distributedly recorded by each of the distributed recording means at the time of update (backup and deletion) processing and that is associated with the information of the conservation point that is sorted by the file data conservation point association sorting means at the time of update (backup and deletion) processing and managed in a black box environment by the conservation point information management means at the time of update (backup and deletion) processing; and a server index at the time of update (backup and deletion) processing, which has a function of creating server index information including configuration information of each of the distributed file management groups to which each of the file data is allocated. a smart contract (or server application) for creating information; a smart contract (or server application) for recording server index information during update (evacuation and deletion) processing, which has a function of encrypting and recording the server index information created by the smart contract (or server application) for creating server index information during update (evacuation and deletion) processing in a group of nodes at a specific location in the distributed ledger structure; a smart contract (or program with a wallet function) for creating customer setting information during update (evacuation and deletion) processing, which has a function of creating customer setting information comprising agreement information between the first user and the second user regarding the evacuation of data to be evacuated for the customer, acquired by the data update (evacuation and deletion) processing agreement information acquisition means linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means for update (evacuation and deletion) processing; and the original file name of the file data to be evacuated for the customer during update (evacuation and deletion) processing;a smart contract (or a program with a wallet function) for creating customer index information during update (saving and deletion) processing, which has a function of creating customer index information having information on the upload date; a smart contract (or a server application) for recording customer index information during update (saving and deletion) processing, which has a function of encrypting the customer index information created by the smart contract (or the program with a wallet function) for creating customer index information during update (saving and deletion) processing and recording it in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means during update (saving and deletion) processing, which erases each file data uploaded to the first temporary storage area after the server index information has been encrypted and recorded in the group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information during update (saving and deletion) processing; a customer data deletion instruction receiving means for update (saving and deletion) processing that receives a deletion instruction for data to be deleted from said update (saving and deletion) instruction means for said customer; and a means for receiving a deletion instruction for data to be deleted from said update (saving and deletion) processing instruction means that is provided in each planet, and for each group of file data linked to information of each of said security points managed in a black box environment by said security point information management means for update (saving and deletion) processing in said planet corresponding to said security point, said means for receiving a deletion instruction for data to be deleted from said customer; and a means for receiving a deletion instruction for data to be deleted from said customer, said key information being made using said first user ID information and said second user ID information required for data deletion in agreement information between said first user and said second user, which is linked to file data to be deleted and received by said data update (saving and deletion) processing agreement information acquisition means. a smart contract (or server application) for extracting encrypted server index information to be deleted during update (backup and deletion) processing, which has a function of extracting encrypted server index information (recorded in a group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on the first composite parameter (composed of a first composite parameter and a second parameter or a second composite parameter (composed of a pair of a second decryption parameter (modularized and incorporated in a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is designated by the digital asset guard service administrator and managed offline, and a second encryption parameter (modularized and incorporated in a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter); anda smart contract (or server application) for decrypting server index information to be deleted during update (saving and deletion) processing, which has a function of decrypting encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information to be deleted during update (saving and deletion) processing for each group of file data linked to information on each of the conservation points managed in a black-box environment by the conservation point information management means during update (saving and deletion) processing; and a smart contract (or server application) for extracting encrypted server index information to be deleted during update (saving and deletion), which is provided in each planet and corresponds to the conservation point, and a smart contract (or server application) for deleting encrypted and divided file data during update (backup and deletion) processing, which has a function of deleting each of the encrypted and divided file data to be deleted, which has been allocated to each of the distributed file management groups by the distributed file management group allocation means and distributedly recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in recording devices at multiple bases connected to the base nodes via a network, using server index information decrypted by the smart contract (or server application) for decrypting server index information to be deleted during update (backup and deletion) processing, from each of the base nodes belonging to each of the distributed file management groups and in recording devices at all of the base nodes connected to the base nodes via a network, The data update (saving and deletion) processing agreement information acquisition means includes a data update (saving and deletion) processing request instruction means that instructs, via the first user, a request for processing to update (saving and deletion) data that is to be updated (saving and deletion) for the customer, a data update (saving and deletion) processing request instruction receiving means that receives a request instruction for processing to update (saving and deletion) data that is to be updated (saving and deletion) for the customer from the data update (saving and deletion) processing request instruction means, and a first user ID information receiving means for data update (saving and deletion) that receives the first user ID information necessary for updating (saving and deleting) data from the first user information management means when receiving a request instruction for updating (saving and deleting) data of the customer; and a data updating (saving and deletion) first user ID information receiving means that receives the first user ID information necessary for updating (saving and deleting) data from the first user information management means when receiving the first user ID information necessary for updating (saving and deleting) data. a seventh information notification means for notifying the second user of information prompting an approval instruction for the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer, a data update (saving and deletion) processing approval instruction means for instructing approval of the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer via the second user who has received the notification from the seventh information notification means, and a data update (saving and deletion) processing approval instruction means for receiving an approval instruction for the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer from the data update (saving and deletion) processing approval instruction means. a data update (saving and deletion) processing approval instruction receiving means, which, when the data update (saving and deletion) processing approval instruction receiving means receives an approval instruction for the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer, receives the second user ID information necessary for the data update (saving and deletion) from the second user information management means; and a data update (saving and deletion) second user ID information receiving means, when the data update (saving and deletion) second user ID information receiving means receives the second user ID information necessary for the data update (saving and deletion),an eighth information notification means for notifying the first user of information that the second user has given an approval instruction for the update (evacuation and deletion) processing of the data to be updated (evacuation and deletion) of the customer and information urging the first user to give an instruction to request the update (evacuation and deletion) processing of the data to be updated (evacuation and deletion) of the customer; a data update (evacuation and deletion) processing request instruction means for instructing a request for the update (evacuation and deletion) processing of the data to be updated (evacuation and deletion) of the customer via the first user who has received the notification from the eighth information notification means; a data update (evacuation and deletion) processing request instruction receiving means for receiving a request instruction for the update (evacuation and deletion) processing of the data to be updated (evacuation and deletion) of the customer from the data update (evacuation and deletion) processing request instruction means; It is preferable to have a data update (saving and deletion) processing agreement information creating means for creating agreement information between the first user and the second user regarding the update (saving and deletion) processing of the data to be updated (saving and deletion) by the customer, using the first user ID information required for updating (saving and deleting) the data and key information managed by the first user received by the first user ID information receiving means for data update (saving and deletion) and the second user ID information required for updating (saving and deletion) the data and key information managed by the second user received by the second user ID information receiving means for data update (saving and deletion), when the processing request instruction receiving means receives a request instruction for updating (saving and deleting) the data to be updated (saving and deletion) by the customer.
[0123] Furthermore, in the real-time save / restore type digital asset guard service providing system of the third aspect of the present invention, the file data real-time update (saving and deletion) system comprises a user-side file data real-time update (saving and deletion) system that operates on the side of a user (customer or data administrator) who desires to update (saving and deleting) file data, and a digital asset guard service administrator-side file data real-time update (saving and deletion) system that operates on the side of the digital asset guard service administrator, and the user-side file data real-time update (saving and deletion) system comprises the data update (saving and deletion) processing agreement information acquisition means, the customer data update (saving and deletion) instruction means, a program (or smart contract) having a plurality of the encryption and division algorithms, an encryption and division algorithm selection acceptance means at the time of the update (saving and deletion) processing, a customer data save instruction acceptance means at the time of the update (saving and deletion) processing, the file data encryption and division means at the time of the update (saving and deletion) processing, and an upload at the time of the update (saving and deletion) processing. means, the file data preservation point correspondence sorting means at the time of update (saving and deletion) processing, and the preservation point information management means at the time of update (saving and deletion) processing, and the digital asset guard service operator side file data real-time update (saving and deletion) system comprises the distributed file management group allocation means at the time of update (saving and deletion) processing, the distributed recording means at the time of update (saving and deletion) processing, a smart contract (or server application) for creating server index information at the time of update (saving and deletion) processing, a smart contract (or server application) for recording server index information at the time of update (saving and deletion) processing, a first data erasure means at the time of update (saving and deletion) processing, a customer data deletion instruction receiving means at the time of update (saving and deletion) processing, a smart contract (or server application) for extracting encrypted server index information to be deleted at the time of update (saving and deletion) processing, and a smart contract (or server application) for decrypting server index information to be deleted at the time of update (saving and deletion) processing,It is preferable to have a smart contract (or server application) for encrypting and deleting divided file data during the update (backup and deletion) process.
[0124] Furthermore, a real-time backup / restoration type digital asset guard service providing system according to a third aspect of the present invention has a second file data real-time deletion system, the second file data real-time deletion system comprising: a data deletion processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding the deletion processing of data to be deleted for the customer; a customer data deletion instruction means for issuing an instruction to delete the customer's data to be deleted based on the agreement information when the data deletion processing agreement information acquisition means has acquired agreement information between the first user and the second user regarding the deletion processing of data to be deleted for the customer; a customer data deletion instruction receiving means for receiving an instruction to delete the customer's data to be deleted from the customer data deletion instruction means; and a file data preservation point information deletion means for deleting information on preservation points linked to the file data to be deleted accepted by the customer data deletion instruction accepting means, which is managed in a black box environment by the preservation point information management means. the data deletion processing agreement information acquisition means comprises: data deletion processing request instruction means for issuing an instruction to request deletion processing of the data to be deleted of the customer via the first user; data deletion processing request instruction acceptance means for accepting an instruction to request deletion processing of the data to be deleted of the customer from the data deletion processing request instruction means; first user ID information for data deletion receiving means for receiving the first user ID information necessary for data deletion from the first user information management means when the data deletion processing request instruction acceptance means accepts an instruction to request deletion processing of the data to be deleted of the customer; fifth information notification means for notifying the second user, when the first user ID information for data deletion receiving means receives the first user ID information necessary for data deletion, of information that the first user has issued a request instruction to request deletion processing of the data to be deleted of the customer and information prompting an instruction to approve deletion processing of the data to be deleted of the customer; and data deletion processing approval instruction means for issuing an instruction to approve deletion processing of the data to be deleted of the customer via the second user who has received the notification from the fifth information notification means.a data deletion processing approval instruction receiving means for receiving an approval instruction for the deletion processing of the data to be deleted of the customer from the data deletion processing approval instruction means; a second user ID information receiving means for data deletion for receiving the second user ID information necessary for data deletion from the second user information management means when the data deletion processing approval instruction receiving means receives an approval instruction for the deletion processing of the data to be deleted of the customer; a sixth information notifying means for notifying the first user, when the second user ID information receiving means for data deletion receives the second user ID information necessary for data deletion, of information that the second user has given an approval instruction for the deletion processing of the data to be deleted of the customer and information urging the first user to give an instruction to request the deletion processing of the data to be deleted of the customer via the first user who has received the notification from the sixth information notifying means; It is preferable to have a data deletion processing request instruction means for instructing a request for deletion proc...
Claims
1. A real-time evacuation and restoration type digital asset guard service provision system for guarding digital assets from high-level cyber attacks, constructed with a distributed ledger in distributed ledger technology such as blockchain, and a smart contract or server application for performing predetermined processing using the data managed in the distributed ledger, or a system for handling data that is difficult to manage through systems, such as personal information, primarily on-chain in two configurations: one in which the information is managed by a company, and one in which the information is managed by an individual, and which serves as a base system for managing the personal information directly on-chain in both configurations, or for separating the personal information section based on the information and utilizing it as personal attribute information for big data analysis, etc., At least one distributed ledger structure consisting of multiple chains that may include distributed ledgers, public blockchains, etc., and is primarily a private or consortium type closed blockchain, constructed with multiple planets (a unit that combines blockchains, distributed file management functions, etc., and forms one unit that constitutes a system for providing services that implement distributed smart contracts, server applications, etc.) that are made up of a group of nodes that combine nodes from multiple locations in different regions around the world; a first authenticator information management means for managing first authenticator authentication information required for authenticating a first authenticator who is one of a customer and a data manager who manages customer data, and first authenticator ID information and key information required for saving and restoring data, etc.; a second authenticator information management means for managing second authenticator authentication information required for authenticating a second authenticator who is the other of the customers and the data administrator who manages the customer data, and second authenticator ID information and key information required for saving and restoring data, etc.; an external first authenticator authentication system that authenticates the first authenticator; an external second authenticator authentication system that authenticates the second authenticator; A file data real-time evacuation system, File data real-time recovery system, and Each node in each location connects to recording devices in multiple locations around the world via a network to create a distributed file management group. The file data real-time saving system includes: a data saving process agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding a process of saving data to be saved for the client; a customer data evacuation instruction means for instructing the evacuation of the customer's data to be evacuated based on the agreement information when the data evacuation processing agreement information acquisition means acquires agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the customer's data to be evacuated; A program (or smart contract) with multiple encryption and division algorithms that have different methods for encrypting and dividing file data, an encryption / division algorithm selection receiving means for receiving a selection of a program (or a smart contract) having a predetermined encryption / division algorithm based on agreement information between the first authenticator and the second authenticator (or a first parameter specified by the customer who desires to evacuate file data, which is included in the agreement information) regarding the evacuation process of the data to be evacuated for the customer, acquired by the data evacuation process agreement information acquisition means; a customer data evacuation instruction receiving means for receiving an instruction to evacuate data to be evacuated from the customer data evacuation instruction means; a file data encryption / division means for encrypting and dividing the customer data to be saved, which has been accepted by the customer data saving instruction accepting means, into a plurality of file data using a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection accepting means; an uploading means for uploading each of the file data encrypted and divided by the file data encryption / division means to a first temporary storage area; a file data security point associating and sorting means for associating each of the file data encrypted and divided by the file data encryption and division means and uploaded to the first temporary storage area by the upload means with one of at least two security points for managing the file data; a security point information management means for managing, in a black box environment, information on the security points for managing the file data sorted by the file data security point association sorting means; a distributed file management group allocation means or a smart contract (or server application) for distributed file management group allocation, which is provided in each planet and has a function of allocating each of the file data associated with the information of the conservation point managed in a black box environment by the conservation point information management means, which is sorted by the file data conservation point correspondence sorting means based on agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer acquired by the data evacuation processing agreement information acquisition means (or the first parameter included in the agreement information and a second parameter specified by the digital asset guard service operator), to a plurality of distributed file management groups, which are set by the digital asset guard service operator according to conditions specified by the customer and are constructed with nodes at each base constituting the planet corresponding to the conservation point and recording devices at multiple bases connected to the nodes at each base via a network; a distributed recording means or a smart contract for distributed recording (or a server application) that is provided on each planet and has a function of distributing and recording each of the file data associated with the information of each of the conservation points that has been sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means, which has been sorted by the distributed file management group sorting means or the smart contract for distributed file management group sorting (or a server application), in each of the base nodes belonging to the corresponding distributed file management group and in recording devices at multiple bases that are connected to the base nodes via a network; a smart contract (or server application) for creating and recording system setting information that has the function of creating system setting information including terminal information (information identifying the other party, such as a fixed IP address) for uploading to the first temporary storage area using the upload means, the number of a predetermined processing means or smart contract (or server application) that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and information on the file server groups (in the node at a predetermined base and in recording devices at multiple bases that are networked to the node at that base) that make up the distributed file management group, encrypting the information, and recording it in the node group at a specific base in the distributed ledger structure; a smart contract (or server application) for creating server index information having: key information using the first authenticator ID information and the second authenticator ID information required for data evacuation, which are included in the agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer acquired by the data evacuation processing agreement information acquisition means; file name information of each of the file data that is distributed and recorded by each of the distributed recording means or the distributed recording smart contract (or server application) and that is linked to the information of the conservation point that is sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means; and configuration information of each of the distributed file management groups to which each of the file data is allocated; a server index information recording smart contract (or server application) that has a function of encrypting the server index information created by the server index information creation smart contract (or server application) and recording it in a node group at a specific location in the distributed ledger structure; and a smart contract (or a program having a wallet function) for creating customer setting information, which is linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection accepting means, and which has a function for creating customer setting information including agreement information between the first authenticator and the second authenticator (or setting information of the first parameter included in the agreement information) regarding the evacuation processing of the data to be evacuated for the customer acquired by the data evacuation processing agreement information acquisition means; A smart contract (or a program with a wallet function) for creating customer index information that has a function to create customer index information containing information on the original file name and upload date of the customer's file data to be saved; a smart contract (or a server application) for recording customer index information, which has a function of encrypting the customer index information created by the smart contract for creating customer index information (or a program having a wallet function) and recording the encrypted customer index information in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means for erasing each file data uploaded to the first temporary storage area after the server index information is encrypted and recorded in a node group at a specific location in the distributed ledger structure by the server index information recording smart contract (or server application); and The data saving process agreement information acquisition means a data evacuation process request instruction means for issuing an instruction to request evacuation process of data to be evacuated by the customer via the first authenticator; a data evacuation processing request instruction receiving means for receiving a request instruction for evacuation processing of the data to be evacuated from the data evacuation processing request instruction means; a data saving processing request instruction receiving first authenticator authentication requesting means for, when the data saving processing request instruction receiving means receives a request instruction for saving processing of the data to be saved by the customer, acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information managing means, providing the information to an external first authenticator authentication system, and requesting authentication of the first authenticator; a data saving first authenticated person ID information and key information receiving means for receiving the first authenticated person ID information and key information required for saving data from the first authenticated person information managing means when the first authenticated person is authenticated by the external first authenticated person authentication system; a first information notification means for notifying the second authenticator of information that the first authenticator has issued a request instruction for a data evacuation process for the data to be saved by the customer and information urging the second authenticator to issue an approval instruction for the data evacuation process for the data to be saved by the customer, when the first authenticator ID information and key information receiving means for data evacuation has received the first authenticator ID information and key information necessary for data evacuation; a data evacuation process approval instruction means for instructing approval of the evacuation process of the data to be evacuated for the client via the second authenticator who has received the notification from the first information notification means; a data evacuation processing approval instruction receiving means for receiving an approval instruction for the evacuation processing of the data to be evacuated from the data evacuation processing approval instruction means; a data saving processing approval instruction receiving second authenticator authentication requesting means for, when the data saving processing approval instruction receiving means receives an instruction to approve the saving processing of the data to be saved by the customer, acquiring second authenticator authentication information required for authenticating the second authenticator from the second authenticator information managing means, providing the second authenticator authentication information to an external second authenticator authentication system, and requesting authentication of the second authenticator; a data saving second authenticated person ID information and key information receiving means for receiving the second authenticated person ID information and key information required for saving data from the second authenticated person information management means when the second authenticated person is authenticated by the external second authenticated person authentication system; a second information notification means for notifying the first authenticator of information that the second authenticator has issued an approval instruction for the evacuation process of the data to be saved by the customer and information urging the first authenticator to issue a request instruction for the evacuation process of the data to be saved by the customer, when the second authenticator ID information and key information receiving means for data evacuation has received the second authenticator ID information and key information necessary for data evacuation; a data evacuation process request instruction means for instructing a request for evacuation process of the data to be evacuated for the client via the first authenticator who has received the notification from the second information notification means; a data evacuation processing request instruction receiving means for receiving a request instruction for evacuation processing of the data to be evacuated from the data evacuation processing request instruction means; a data saving process agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the saving process of the data to be saved for the client, using the first authenticator ID information and key information required for data saving received by the first authenticator ID information and key information receiving means for data saving and the second authenticator ID information and key information required for data saving received by the second authenticator ID information and key information receiving means for data saving, when the data saving process request instruction receiving means receives an instruction to request saving process of the data to be saved for the client; and The file data real-time restoration system includes: a data restoration processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding restoration processing of the data to be restored for the customer; a customer data restoration instruction means for instructing the restoration of the data to be restored for the customer based on the agreement information when the data restoration processing agreement information acquisition means acquires agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer; A program (or smart contract) having a plurality of decryption and combination algorithms with different methods for decrypting and combining file data, each of which is linked to a program (or smart contract) having the encryption and division algorithm; customer data restoration instruction receiving means for receiving an instruction to restore data to be restored for the customer from the customer data restoration instruction means; a data restoration instruction receiving means for receiving the data restoration instruction from the data restoration instruction receiving means for receiving the data restoration instruction for the data restoration target of the customer, ... a smart contract (or server application) for extracting encrypted server index information that has a function of extracting encrypted server index information (recorded in a group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on a meter or (a second composite parameter that is a pair of a second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) designated by the digital asset guard service operator and managed offline, and a second encryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter); a server index information decryption smart contract (or server application) that is provided in each planet and has a function of decrypting the encrypted server index information extracted by the encrypted server index information extraction smart contract (or server application) for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point; an encrypted and divided file data extraction means or a smart contract (or server application) for extracting encrypted and divided file data, which is provided in each planet and has a function of extracting, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point, from any of the nodes at each base belonging to each of the distributed file management groups and any of the recording devices at each of the multiple bases connected to the nodes at each of the multiple bases via a network, each of the encrypted and divided file data being allocated to each of the distributed file management groups by the distributed file management group allocation means or the smart contract (or server application) for allocating the file data using server index information decrypted by the smart contract (or server application) for decrypting server index information, and distributed and recorded in each of the nodes at each of the multiple bases belonging to each of the distributed file management groups and any of the recording devices at each of the multiple bases connected to the nodes at each of the multiple bases via a network; a downloading means provided in each planet, which downloads, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point, each of the encrypted and divided file data extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data, into a second temporary storage area; a file data restoration means provided in each planet, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point, for which the file data is extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data and downloaded to the second temporary storage area by the download means, and which decrypts and combines all of the file data linked across the information of all of the conservation points in an encrypted and divided state into one file data using a program (or smart contract) having the decryption and combination algorithm linked to a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means, thereby restoring the data of the client before evacuation; a second data erasing means for erasing each of the encrypted and divided file data downloaded to the second temporary storage area after the file data restoration means has restored the data of the client to the state before the backup; and The data restoration processing agreement information acquisition means a data restoration processing request instruction means for instructing a request for restoration processing of data to be restored by the customer via the first authenticator; a data restoration processing request instruction receiving means for receiving a request instruction for restoration processing of the data to be restored from the data restoration processing request instruction means; a data restoration processing request instruction receiving first authenticator authentication requesting means for, when the data restoration processing request instruction receiving means receives a request instruction for restoration processing of data to be restored by the customer, acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information managing means, providing the information to an external first authenticator authentication system, and requesting authentication of the first authenticator; a first authenticator ID information and key information receiving means for data restoration, which receives the first authenticator ID information and key information required for data restoration from the first authenticator information managing means when the first authenticator is authenticated by the external first authenticator authentication system; a third information notifying means for notifying the second certifier of information that the first certifier has issued a request instruction for restoration of the data to be restored by the first certifier and information that prompts the second certifier to issue an approval instruction for the restoration of the data to be restored by the first certifier when the first certifier ID information and key information receiving means for data restoration receives the first certifier ID information and key information necessary for data restoration; a data restoration process approval instruction means for instructing approval of restoration process of the data to be restored for the customer via the second authenticator who has received notification from the third information notification means; a data restoration processing approval instruction receiving means for receiving an approval instruction for the restoration processing of the data to be restored for the customer from the data restoration processing approval instruction means; a data restoration processing approval instruction acceptance second authenticator authentication requesting means for, when the data restoration processing approval instruction accepting means accepts an approval instruction for the restoration processing of the data to be restored for the customer, acquiring second authenticator authentication information required for authenticating the second authenticator from the second authenticator information managing means, providing the second authenticator authentication information to an external second authenticator authentication system, and requesting authentication of the second authenticator; a data restoration second authenticator ID information and key information receiving means for receiving second authenticator ID information and key information required for data restoration from said second authenticator information management means when said second authenticator is authenticated by said external second authenticator authentication system; a fourth information notifying means for notifying the first authenticator of information that the second authenticator has instructed to approve the restoration process of the data to be restored by the customer and information that prompts the first authenticator to instruct to request the restoration process of the data to be restored by the second authenticator when the second authenticator ID information and key information receiving means for data restoration receives the second authenticator ID information and key information necessary for data restoration; a data restoration processing request instruction means for instructing a request for restoration processing of the data to be restored for the customer via the first authenticator who has received the notification from the fourth information notification means; a data restoration processing request instruction receiving means for receiving a request instruction for restoration processing of the data to be restored from the data restoration processing request instruction means; a data restoration processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer, using the first authenticator ID information and key information required for data restoration received by the first authenticator ID information and key information receiving means for data restoration and the second authenticator ID information and key information required for data restoration received by the second authenticator ID information and key information receiving means for data restoration, when the data restoration processing request instruction receiving means receives an instruction to request restoration processing of the data to be restored for the customer; have A real-time evacuation and restoration type digital asset guard service providing system.
2. The file data real-time saving system comprises a user-side file data real-time saving system that operates on the side of a user (customer or data manager) who desires to save file data, and a digital asset guard service operator-side file data real-time saving system that operates on the side of the digital asset guard service operator, The user-side file data real-time saving system comprises the data saving processing agreement information acquisition means, the customer data saving instruction means, a program (or smart contract) having a plurality of the encryption / division algorithms, the encryption / division algorithm selection acceptance means, the customer data saving instruction acceptance means, the file data encryption / division means, the upload means, the file data conservation point association sorting means, and the conservation point information management means, The digital asset guard service operator-side file data real-time backup system comprises the distributed file management group allocation means or the distributed file management group allocation smart contract (or server application), the distributed recording means or the distributed recording smart contract (or server application), the server index information creation smart contract (or server application), the server index information recording smart contract (or server application), and the first data erasure means, The file data real-time restoration system comprises a user-side file data real-time restoration system that operates on the side of a user (customer or data manager) who desires to restore saved file data, and a digital asset guard service operator-side file data real-time restoration system that operates on the side of the digital asset guard service operator, the user-side file data real-time restoration system comprises the data restoration processing agreement information acquisition means, the customer data restoration instruction means, a program (or smart contract) having a plurality of the decryption and combination algorithms, the download means, the file data restoration means, and the second data erasure means; The digital asset guard service administrator-side file data real-time restoration system includes the customer data restoration instruction receiving means, the encrypted server index information extraction smart contract (or server application), the server index information decryption smart contract (or server application), and the encrypted and divided file data extraction means or the encrypted and divided file data extraction smart contract (or server application).
2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
3. It has a file data real-time deletion system, The file data real-time deletion system includes: a data deletion processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding a deletion processing of data to be deleted for the customer; a customer data deletion instruction means for instructing the deletion of the data to be deleted for the customer based on the agreement information when the data deletion processing agreement information acquisition means acquires agreement information between the first authenticated person and the second authenticated person regarding the deletion processing of the data to be deleted for the customer; a customer data deletion instruction receiving means for receiving an instruction to delete data to be deleted from the customer data deletion instruction means; a data deletion processing agreement information acquisition means for acquiring data for the data to be deleted for the customer, the ... a smart contract (or server application) for extracting encrypted server index information to be deleted, which has a function of extracting encrypted server index information (recorded in a group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on the data or (a second composite parameter consisting of a pair of a second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) designated by the digital asset guard service operator and managed offline, and a second encryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter); a smart contract (or server application) for decrypting server index information to be deleted, which is provided in each planet and has a function of decrypting the encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information to be deleted, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point; a smart contract (or server application) for deleting encrypted and divided file data that is provided in each planet and has a function of deleting, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point, each of the encrypted and divided file data to be deleted, which has been allocated to each of the distributed file management groups by the distributed file management group allocation means using server index information decrypted by the smart contract (or server application) for decrypting server index information to be deleted, and which has been distributed and recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in recording devices of multiple bases connected to the base nodes via a network; The data deletion processing agreement information acquisition means a data deletion process request instruction means for issuing an instruction to request deletion of data to be deleted from the customer via the first authenticator; a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of the data to be deleted from the data deletion processing request instruction means; a data deletion processing request instruction receiving first authenticator authentication requesting means for, when the data deletion processing request instruction receiving means receives a request instruction for deletion processing of data to be deleted by the customer, acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information managing means, providing the information to an external first authenticator authentication system, and requesting authentication of the first authenticator; a data deletion first authenticated person ID information and key information receiving means for receiving the first authenticated person ID information and key information required for data deletion from the first authenticated person information management means when the first authenticated person is authenticated by the external first authenticated person authentication system; a fifth information notifying means for notifying the second authenticator of information that the first authenticator has issued a request instruction for deletion of the data to be deleted from the customer and information that prompts the second authenticator to issue an approval instruction for the deletion of the data to be deleted from the customer, when the first authenticator ID information and key information receiving means for data deletion has received the first authenticator ID information and key information necessary for data deletion; a data deletion process approval instruction means for instructing approval of a deletion process of the data to be deleted of the customer via the second authenticator who has received a notification from the fifth information notification means; a data deletion processing approval instruction receiving means for receiving an approval instruction for the deletion processing of the data to be deleted from the data deletion processing approval instruction means; a data deletion processing approval instruction acceptance second authenticator authentication request means for, when the data deletion processing approval instruction acceptance means accepts an approval instruction for the deletion processing of the data to be deleted from the customer, acquiring second authenticator authentication information required for authenticating the second authenticator from the second authenticator information management means, providing the second authenticator authentication information to an external second authenticator authentication system, and requesting authentication of the second authenticator; a data deletion second authenticated person ID information and key information receiving means for receiving second authenticated person ID information and key information required for data deletion from said second authenticated person information managing means when said second authenticated person is authenticated by said external second authenticated person authentication system; a sixth information notifying means for notifying the first authenticator of information that the second authenticator has instructed to approve the deletion of the data to be deleted by the customer and information that prompts the customer to instruct to request the deletion of the data to be deleted by the second authenticator when the data deletion second authenticator ID information and key information receiving means has received the second authenticator ID information and key information necessary for deleting data; a data deletion process request instruction means for instructing, via the first authenticated person notified by the sixth information notification means, to request a deletion process of the data to be deleted of the customer; a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of the data to be deleted from the data deletion processing request instruction means; a data deletion processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the deletion processing of the data to be deleted for the customer, using the first authenticator ID information and key information required for data deletion received by the first authenticator ID information and key information receiving means for data deletion and the second authenticator ID information and key information required for data deletion received by the second authenticator ID information and key information receiving means for data deletion, when the data deletion processing request instruction receiving means receives a request instruction for deletion processing of the data to be deleted for the customer; have 2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
4. The file data real-time deletion system comprises a user-side file data real-time deletion system that operates on the side of a user (customer or data manager) who desires to delete file data, and a digital asset guard service operator-side file data real-time deletion system that operates on the side of the digital asset guard service operator, The user-side file data real-time deletion system comprises the data deletion processing agreement information acquisition means and the customer data deletion instruction means, The digital asset guard service administrator-side file data real-time deletion system includes the customer data deletion instruction receiving means, a smart contract (or server application) for extracting the encrypted server index information to be deleted, a smart contract (or server application) for decrypting the server index information to be deleted, and a smart contract (or server application) for deleting the encrypted and divided file data.
4. The real-time saving and restoring type digital asset guard service providing system according to claim 3.
5. A real-time backup and restoration type digital asset guard service providing system as described in claim 3, characterized in that the data deletion processing request instruction means is configured to be able to change the generation of the file data to be deleted.
6. It has a file data real-time update (backup and deletion) system, The file data real-time update (saving and deleting) system includes: a data update (saving and deletion) processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of the data to be updated (saved and deleted) for the customer, between the first authenticator and the second authenticator; a customer data update (saving and deletion) instruction means for instructing the updating (saving and deletion) of the data to be updated (saved and deleted) for the customer based on the agreement information when the data update (saving and deletion) processing agreement information acquisition means acquires agreement information between the first authenticated person and the second authenticated person regarding the updating (saved and deletion) processing of the data to be updated (saved and deleted) for the customer; A program (or smart contract) having a plurality of encryption and division algorithms that have different encryption and division processing methods for file data; an update (saving and deletion) processing encryption / division algorithm selection receiving means for receiving a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on agreement information between the first authenticator and the second authenticator regarding the saving processing of the data to be saved for the customer, which has been acquired by the data update (saving and deletion) processing agreement information acquisition means; a customer data evacuation instruction receiving means for receiving an instruction to evacuate data to be evacuated from the customer data update (evacuation and deletion) instruction means; an update (saving and deletion) processing time file data encryption / division means for encrypting and dividing the customer data to be saved, which has been accepted by the update (saving and deletion) processing time customer data saving instruction accepting means, into a plurality of file data using a program (or smart contract) having the encryption / division algorithm accepted by the update (saving and deletion) processing time encryption / division algorithm selection accepting means; an update (saving and deleting) processing time uploading means for uploading each of the file data encrypted and divided into a plurality of pieces by the update (saving and deleting) processing time file data encryption / division means to a first temporary storage area; an update (saving and deletion) processing time file data conservation point associating and sorting means for associating each of the file data encrypted and divided into a plurality of pieces by the update (saving and deletion) processing time file data encryption / division means and uploaded to the first temporary storage area by the update (saving and deletion) processing time upload means with one of the conservation points corresponding to at least two planets for managing the file data; an update (saving and deletion) processing time preservation point information management means for managing, in a black box environment, information on the preservation points for managing the file data sorted by the update (saving and deletion) processing time file data preservation point association sorting means; a distributed file management group allocation means for update (saving and deletion) processing, which is provided in each planet and has a function of allocating the file data associated with the information of the conservation points managed in a black box environment by the conservation point information management means for update (saving and deletion) processing, which is sorted by the file data conservation point association sorting means based on agreement information between the first authenticator and the second authenticator regarding the backup processing of the data to be backed up for the customer, acquired by the data update (saving and deletion) processing agreement information acquisition means (or a first parameter included in the agreement information and a second parameter specified by the digital asset guard service operator), to a plurality of distributed file management groups, which are set by the digital asset guard service operator according to conditions specified by the customer and are constituted by nodes at each base constituting the planet corresponding to the conservation points and recording devices at multiple bases connected to the nodes at each base via a network; an update (saving and deletion) processing time distributed recording means provided in each planet, which has a function of distributively recording the file data associated with the information of each of the conservation points that has been sorted by the update (saving and deletion) processing time file data conservation point association sorting means and managed in a black box environment by the update (saving and deletion) processing time conservation point information management means, in the nodes of each base belonging to the corresponding distributed file management group and in recording devices of multiple bases connected to the base nodes via a network; a smart contract (or server application) for creating and recording system setting information during update (backup and deletion) processing, which has the function of creating system setting information including terminal information (information identifying the other party, such as a fixed IP address) for uploading to the first temporary storage area using the upload means during update (backup and deletion) processing, the number of the predetermined processing means that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and information on the file server groups (in the node at a predetermined base and in recording devices at multiple bases that are networked to the node at that base) that make up the distributed file management group, encrypting the information, and recording it in the node group at a specific base in the distributed ledger structure; and a smart contract (or server application) for creating server index information during update (saving and deletion) processing, the smart contract having a function of creating server index information including: key information using the first authenticator ID information and the second authenticator ID information required for data evacuation, which are included in agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer, acquired by the data update (saving and deletion) processing agreement information acquisition means; file name information of each of the file data linked to the information of the conservation point, which is sorted by the file data conservation point association sorting means during update (saving and deletion) processing and managed in a black box environment by the conservation point information management means during update (saving and deletion) processing, and configuration information of each of the distributed file management groups to which each of the file data is allocated; and a smart contract (or server application) for recording server index information during update (backup and deletion) processing, which has a function of encrypting the server index information created by the smart contract (or server application) for creating server index information during update (backup and deletion) processing and recording it in a group of nodes at a specific location in the distributed ledger structure; and a smart contract (or a program having a wallet function) for creating customer setting information during update (saving and deletion) processing, the smart contract having a function for creating customer setting information including agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer, which has been acquired by the data update (saving and deletion) processing agreement information acquisition means linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means during update (saving and deletion) processing; a smart contract (or a program with a wallet function) for creating customer index information during update (saving and deletion) processing, which has a function of creating customer index information including information on the original file name and upload date of the customer's file data to be saved during update (saving and deletion) processing; a smart contract (or a server application) for recording customer index information during update (backup and deletion) processing, which has a function of encrypting the customer index information created by the smart contract (or a program having a wallet function) for creating customer index information during update (backup and deletion) processing and recording it in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means during the update (backup and deletion) processing, which erases each file data uploaded to the first temporary storage area after the server index information is encrypted and recorded in a node group at a specific location in the distributed ledger structure by a smart contract (or a server application) for recording server index information during the update (backup and deletion) processing; a customer data deletion instruction receiving means for receiving an instruction to delete data to be deleted from the update (saving and deletion) instruction means during update (saving and deletion) processing; and a data update (saving and deletion) processing agreement information acquisition means for acquiring a first composite parameter (or the first parameter included in the key information) which is a combination of the first and second authenticators ID information and the second authenticator ID information required for deleting data, the first composite parameter being a pair of a first decryption parameter designated by the customer and managed offline by the customer data deletion instruction acceptance means for each group of file data linked to the information of each of the security points managed in a black-box environment by the update (saving and deletion) processing time security point information management means in the planet corresponding to the security point. a smart contract (or server application) for extracting encrypted server index information to be deleted during update (backup and deletion) processing, which has a function of extracting encrypted server index information (recorded in a group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on the second parameter or a second composite parameter (composed of a pair of a second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) designated and managed offline by the digital asset guard service operator), and a second encryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter); a smart contract (or server application) for decrypting server index information to be deleted during update (saving and deletion) processing, which is provided in each planet and has a function of decrypting encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information to be deleted during update (saving and deletion) processing, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means during update (saving and deletion) processing in the planet corresponding to the conservation point; a smart contract (or server application) for deleting encrypted and divided file data during update (backup and deletion) processing, which is provided in each planet and has a function of deleting, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means during update (backup and deletion) processing, from each of the base nodes belonging to each of the distributed file management groups and from all of the base node storage devices connected to the base node via a network, the encrypted and divided file data to be deleted, which has been allocated to each of the distributed file management groups by the distributed file management group allocation means using server index information decrypted by the smart contract (or server application) for decrypting server index information to be deleted during update (backup and deletion) processing, and which has been distributed and recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in multiple base node storage devices connected to the base node via a network; and The data update (saving and deletion) processing agreement information acquisition means a data update (saving and deletion) processing request instructing means for instructing a request for processing to update (saving and deletion) data to be updated (saved and deleted) for the customer via the first authenticator; a data update (saving and deletion) processing request instruction receiving means for receiving a request instruction for updating (saving and deleting) the data to be updated (saving and deleted) by the customer from the data update (saving and deletion) processing request instruction means; a data update (saving and deletion) processing request instruction receiving means for acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means when the data update (saving and deletion) processing request instruction receiving means receives a request instruction for updating (saving and deleting) data to be updated (saving and deleting) by the customer, and providing the information to an external first authenticator authentication system to request authentication of the first authenticator; a data updating (saving and deleting) first authenticated person ID information and key information receiving means for receiving the first authenticated person ID information and key information required for updating (saving and deleting) data from the first authenticated person information managing means when the first authenticated person is authenticated by the external first authenticated person authentication system; seventh information notifying means for notifying the second authenticator of information that the first authenticator has issued a request instruction for updating (saving and deleting) the data to be updated (saving and deleting) by the customer and information urging the second authenticator to issue an approval instruction for updating (saving and deleting) the data to be updated (saving and deleting) by the customer, when the first authenticator ID information and key information receiving means for data update (saving and deletion) has received the first authenticator ID information and key information necessary for updating (saving and deleting) the data; a data update (saving and deletion) processing approval instruction means for instructing approval of the update (saving and deletion) processing of the data to be updated (saved and deleted) by the customer via the second authenticator who has received the notification from the seventh information notification means; a data update (saving and deletion) processing approval instruction receiving means for receiving an approval instruction for updating (saving and deletion) the data to be updated (saving and deletion) by the customer from the data update (saving and deletion) processing approval instruction means; a data update (saving and deletion) processing approval instruction receiving second authenticator authentication requesting means for, when the data update (saving and deletion) processing approval instruction receiving means receives an approval instruction for updating (saving and deleting) processing of the data to be updated (saving and deletion) for the customer, acquiring second authenticator authentication information required for authenticating the second authenticator from the second authenticator information managing means, providing the second authenticator authentication information to an external second authenticator authentication system, and requesting authentication of the second authenticator; a data updating (saving and deleting) second authenticator ID information and key information receiving means for receiving the second authenticator ID information and key information required for updating (saving and deleting) data from the second authenticator information managing means when the second authenticator is authenticated by the external second authenticator authentication system; an eighth information notification means for notifying the first authenticator of information that the second authenticator has given an approval instruction for the update (saving and deletion) process of the data to be updated (saving and deletion) of the customer and information that prompts the first authenticator to give a request instruction for the update (saving and deletion) process of the data to be updated (saving and deletion) of the customer, when the second authenticator ID information and key information receiving means for data update (saving and deletion) has received the second authenticator ID information and key information necessary for data update (saving and deletion); a data update (saving and deletion) processing request instruction means for instructing a request for processing to update (saving and deletion) data to be updated (saved and deleted) for the customer via the first authenticated person who has received the notification from the eighth information notification means; a data update (saving and deletion) processing request instruction receiving means for receiving a request instruction for updating (saving and deleting) the data to be updated (saving and deleted) by the customer from the data update (saving and deletion) processing request instruction means; a data update (saving and deletion) processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer, using the first authenticator ID information and key information required for the data update (saving and deletion) received by the first authenticator ID information and key information receiving means for data update (saving and deletion) and the second authenticator ID information and key information required for the data update (saving and deletion) received by the second authenticator ID information and key information receiving means for data update (saving and deletion), when the data update (saving and deletion) processing request instruction receiving means receives an instruction to request the processing of updating (saving and deletion) of the data to be updated (saving and deletion) for the customer; have 2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
7. The file data real-time update (saving and deletion) system comprises a user-side file data real-time update (saving and deletion) system that operates on the side of a user (customer or data manager) who desires to update (saving and deleting) file data, and a digital asset guard service operator-side file data real-time update (saving and deletion) system that operates on the side of the digital asset guard service operator, The user-side file data real-time update (saving and deletion) system comprises the data update (saving and deletion) processing agreement information acquisition means, the customer data update (saving and deletion) instruction means, a program (or smart contract) having a plurality of the encryption and division algorithms, an encryption and division algorithm selection acceptance means for the update (saving and deletion) processing, a customer data evacuation instruction acceptance means for the update (saving and deletion) processing, a file data encryption and division means for the update (saving and deletion) processing, an upload means for the update (saving and deletion) processing, a file data conservation point association and sorting means for the update (saving and deletion) processing, and a conservation point information management means for the update (saving and deletion) processing, The digital asset guard service operator-side file data real-time update (saving and deletion) system includes: a distributed file management group allocation means during the update (saving and deletion) processing; a distributed recording means during the update (saving and deletion) processing; a smart contract (or server application) for creating server index information during the update (saving and deletion) processing; a smart contract (or server application) for recording server index information during the update (saving and deletion) processing; a first data erasure means during the update (saving and deletion) processing; a customer data deletion instruction receiving means during the update (saving and deletion) processing; a smart contract (or server application) for extracting encrypted server index information to be deleted during the update (saving and deletion) processing; a smart contract (or server application) for decrypting server index information to be deleted during the update (saving and deletion) processing; and a smart contract (or server application) for deleting encrypted and divided file data during the update (saving and deletion) processing.
7. The real-time saving and restoring type digital asset guard service providing system according to claim 6.
8. The real-time backup and restoration type digital asset guard service providing system described in claim 6, characterized in that the data update (backup and deletion) processing request instruction means automatically sets all file data of past generations of the customer as file data to be deleted.
9. The real-time backup and restoration type digital asset guard service providing system described in claim 6, characterized in that the data update (backup and deletion) processing request instruction means is configured to be able to change the setting of the generation of the file data to be deleted.
10. The distributed file management group allocation means or the distributed file management group allocation smart contract (or server application) further has a function of converting the file format and name of each file data that has been sorted by the file data conservation point association sorting means and linked to the information of the conservation point managed in a black box environment by the conservation point information management means, encrypted and divided into multiple pieces by the file data encryption and division means, and uploaded to the first temporary storage area by the upload means, into a predetermined file format and name before sorting the file data to the multiple distributed file management groups, The encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data further has a function of extracting each of the encrypted and divided file data for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means, and then converting the file format and name of each of the extracted file data back to the original file format and name.
2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
11. the agreement information between the first certifier and the second certifier (or the first parameter included in the agreement information) regarding the data evacuation process of the client, acquired by the data evacuation process agreement information acquisition means, includes a file division code and a file storage code; the encryption / division algorithm selection receiving means receives a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on the file division code; The distributed file management group allocation means or the distributed file management group allocation smart contract (or server application) has a function of converting the file format and name of each of the file data linked to the information of the conservation point that has been encrypted and divided by the file data encryption and division means, uploaded to the first temporary storage area by the upload means, sorted by the file data conservation point association sorting means, and managed in a black box environment by the conservation point information management means, into a predetermined file format and name based on the file storage code (or the file storage code and the second parameter), while encrypting the file data, and allocating it to a plurality of distributed file management groups that are set by the digital asset guard service operator according to conditions specified by the customer and are configured by nodes at multiple locations that constitute the planet corresponding to the conservation point, and recording devices at multiple locations that are connected to the nodes at the locations via a network; Each of the distributed recording means or the distributed recording smart contract (or server application) has a function of distributively recording each of the file data associated with the information of each of the conservation points sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means, which has been sorted by the distributed file management group sorting means or the distributed file management group sorting smart contract (or server application), in each of the base nodes belonging to the corresponding distributed file management group and in recording devices at multiple bases connected to the base nodes via a network, the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data has a function of extracting, for each group of file data linked to information on each of the conservation points managed in a black-box environment by the conservation point information management means, each of the encrypted and divided file data being allocated to each of the distributed file management groups by the distributed file management group allocation means or the smart contract (or server application) for distributed file management group allocation, and distributedly recorded in each of the base nodes belonging to each of the distributed file management groups and in recording devices at multiple bases connected to the base nodes via a network by each of the distributed recording means or the smart contract (or server application), from each of the base nodes belonging to each of the distributed file management groups and from any of the recording devices at multiple bases connected to the base nodes via a network, based on the file storage code (or the file storage code and the second parameter), and decrypting the extracted file data, and at the same time converting the file format and name of the file data to the original file format and name; The file data restoration means has a function of decrypting and combining all of the file data associated with the information of all of the conservation points in an encrypted and divided state that has been extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data and downloaded to the second temporary storage area by the download means, for each group of the file data associated with the information of each of the conservation points managed in a black-box environment by the conservation point information management means, into one file data to restore the file data before saving, based on the file division code, using a program (or smart contract) having the decryption and combination algorithm that is associated with a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means.
2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
12. the file data encryption / division means divides the customer data to be saved, which has been accepted by the customer data saving instruction acceptance means, into multiple pieces using a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means, and encrypts each of the multiple pieces of file data based on a first public key (first encryption key) created by each of the customer and the data manager; The file data restoration means decrypts, for each group of file data linked to information on each of the security points managed in a black box environment by the security point information management means, all of the file data linked across the information on all of the security points in an encrypted and divided state that has been extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data and downloaded to the second temporary storage area by the download means, based on a first private key (first offline decryption key) created by each of the customer and the data manager, and combines all of the file data linked across the information on all of the decrypted security points into one file data using a program (or smart contract) having the decryption and combination algorithm that is linked to a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means.
2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
13. the file data encryption / division means encrypts the customer data to be saved that has been accepted by the customer data save instruction acceptance means based on a first public key (first encryption key) created by each of the customer and the data manager, and divides the encrypted file data into multiple pieces using a program (or smart contract) that includes the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means; The file data restoration means combines, for each group of file data linked to information on each of the conservation points managed in a black-box environment by the conservation point information management means, all of the file data linked across information on all of the conservation points in an encrypted and divided state that has been extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data and downloaded to the second temporary storage area by the download means, into one file data using a program (or smart contract) having the decryption and combination algorithm that is linked to a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means, and decrypts the one combined file data based on first private keys (first offline decryption keys) created by each of the customer and the data manager.
2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
14. The server index information recording smart contract (or server application) has a function of encrypting the server index information created by the server index information creating smart contract (or server application) based on a second encryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from a second public key (second encryption key) created by the digital asset guard service administrator or a second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is designated by the digital asset guard service administrator and managed offline, The smart contract (or server application) for decrypting server index information has a function of decrypting the encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information for each group of file data linked to the information of each of the protection points managed in a black box environment by the protection point information management means, based on a second private key (second decryption key) created by the digital asset guard service administrator or a second decryption parameter (modularized by being incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) designated by the digital asset guard service administrator and managed offline.
2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
15. The real-time backup and restoration type digital asset guard service providing system described in claim 1, characterized in that the program (or smart contract) equipped with the encryption and division algorithm is configured to encrypt and divide file data into multiple parts using secret sharing technology.
16. The real-time backup and restoration type digital asset guard service providing system of claim 1, characterized in that the program (or smart contract) equipped with the decryption and combination algorithm is configured to decrypt file data that has been encrypted and divided into multiple pieces and restore it to the original file data that has been combined into one piece using secret sharing technology.
17. 17. The real-time saving and restoring type digital asset guard service providing system according to claim 15 or 16, wherein the secret sharing technique is a polynomial division processing type secret sharing technique.
18. The file data real-time backup system further comprises a planet configuration pattern setting means for selecting the number of nodes constituting the planet, and the nodes at each base and the recording devices at multiple bases connected to the base nodes via a network (and the distributed file management group constructed therewith), based on the recording capacity (file size) of the file data specified by the customer and the number of divisions of the file data based on the degree of distribution, The distributed file management group allocation means or the distributed file management group allocation smart contract (or server application) has a function of allocating each of the file data associated with the information of the conservation point sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means to a plurality of the distributed file management groups configured by the digital asset guard service operator according to conditions specified by the customer via the planet configuration pattern setting means and consisting of nodes at each base constituting the planet corresponding to the conservation point and recording devices at multiple bases connected to the base nodes via a network, Each of the distributed recording means or the distributed recording smart contract (or server application) has a function of distributively recording each of the file data associated with the information of each of the conservation points sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means, which has been sorted by the distributed file management group sorting means or the distributed file management group sorting smart contract (or server application), in each of the base nodes belonging to the corresponding distributed file management group and in recording devices at multiple bases connected to the base nodes via a network.
2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
19. The real-time backup and restoration type digital asset guard service providing system described in claim 18, characterized in that the planet configuration pattern setting means adds a predetermined number of dummy file data (having code internally that allows the encrypted / divided file data extraction means or the smart contract (or server application) for extracting encrypted / divided file data to recognize that it is dummy information) to the number of divisions of the file data, and selects the number of nodes that constitute the planet, and the distributed file management group constructed by the nodes at each base and the recording devices at multiple bases connected to the nodes at the base via a network.
20. The real-time backup and restoration type digital asset guard service providing system described in claim 19, characterized in that the smart contract (or server application) for creating server index information has the function of creating the server index information by including, as configuration information for each of the distributed file management groups, information on the nodes at each location that distribute and record dummy file data added by the planet configuration pattern setting means and information on recording devices at multiple locations that are network-connected to the nodes at those locations.
21. The encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data extracts, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means, the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data extracts, from the configuration information of each of the distributed file management groups in the server index information decrypted by the smart contract (or server application) for decrypting server index information, information on the nodes at each base that distribute and record dummy file data (which have a code therein that can be recognized as dummy information) and information on recording devices at multiple bases that are connected to the nodes at each base via a network, the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data extracts, from the configuration information of each of the distributed file management groups in the server index information decrypted by the smart contract (or server application) for decrypting server index information, the The real-time backup and restoration type digital asset guard service providing system of claim 20, characterized in that it has the function of extracting each of the encrypted and divided file data, which is allocated to each of the distributed file management groups by an allocation means or a smart contract (or server application) for distributed file management group allocation and distributedly recorded by each of the distributed recording means or the smart contract (or server application) for distributed recording in each of the base nodes belonging to each of the distributed file management groups and in multiple base recording devices connected to the base nodes via a network, from any of the base nodes belonging to each of the distributed file management groups and any of the multiple base recording devices connected to the base nodes via a network.
22. The real-time backup and restoration type digital asset guard service providing system described in claim 18, characterized in that the planet configuration pattern setting means selects the nodes of each base within each of the distributed file management groups and the recording devices of multiple bases connected to the nodes of the base via a network so that they are the nodes and recording devices located at the greatest distance (= maximum degree of distribution).
23. The planet configuration pattern setting means regards the spherical Earth as a plane, creates a matrix in which the Earth's regions are divided into multiple sections vertically and horizontally, and within one of the distributed file management groups, determines the spacing in the X-axis direction, based on the Y-axis in the matrix for the node that distributes and records one divided file data and the bases of multiple recording devices connected to the node via a network, using a calculated value based on the number of divisions of the file data, thereby selecting the nodes of each base within each of the distributed file management groups and the recording devices of multiple bases connected to the node via a network.
24. A real-time backup and restoration type digital asset guard service providing system as described in claim 23, characterized in that the nodes in the planet that distribute and record each divided file data and the locations of multiple recording devices connected to the nodes via a network are managed using information such as GPS and classified in the matrix.
25. The real-time backup and restoration type digital asset guard service providing system of claim 23, characterized in that when the planet configuration pattern setting means is unable to open the X-axis direction spacing according to the calculated value based on the number of file data divisions due to insufficient remaining recording capacity of the node at a specified base or one of the recording devices at multiple bases connected to the node at that base via the network, it selects a base node or a recording device connected to the node at that base via the network that has a numerical difference in the Y-axis direction that is approximately the same as the calculated value of the X-axis direction spacing.
26. The planet configuration pattern setting means selects the bases of each node that constitutes the planet based on the number of file data divisions, which is based on the recording capacity (file size) of the file data specified by the customer, and selects multiple individual bases that belong to the distributed file management group constructed by each selected node so as to maximize the degree of distribution within the distributed file management group, and selects multiple recording devices to be located at each individual base (and connected to the nodes via a network), as described in claim 18.
27. The planet configuration pattern setting means records in the matrix the total remaining recording capacity, total remaining communication capacity, etc. as information on the nodes of each base in each region to which the base of each node belongs and the recording devices of multiple bases connected to the base nodes via a network, and when selecting the nodes that constitute the distributed file management group and the bases of multiple recording devices connected to the nodes via a network, uses information such as the total remaining recording capacity and total remaining communication capacity of the nodes of each base in each region and the recording devices of multiple bases connected to the base nodes via a network in each region recorded in the matrix, and the degree of distribution, to select the optimal combination of nodes and the bases of multiple recording devices connected to the nodes via a network.
28. The real-time backup and restoration type digital asset guard service providing system described in claim 18, characterized in that the planet configuration pattern setting means calculates areas where the recording capacity and communication capacity of each node at a specific location and the recording devices at multiple locations connected to the node at that location via a network need to be reinforced in a combination of nodes at a specific location that constitute the distributed file management group and recording devices at multiple locations connected to the node at that location via a network.
29. A real-time backup and restoration type digital asset guard service providing system as described in claim 1, characterized in that each of the distributed file management groups has a core node that specifies and manages individual equipment that constitutes recording devices at each location belonging to the distributed file management group.
30. The real-time backup and restoration type digital asset guard service provision system described in claim 1, characterized in that the nodes at each location are connected via communication means such as the Internet, a private network, etc., and the distributed recording means or the smart contract for distributed recording (or server application) is incorporated.
31. The real-time backup and restoration type digital asset guard service providing system of claim 1, characterized in that the file data real-time backup system has a wallet function that reads the customer index information encrypted and recorded in a group of nodes at a specific location in the distributed ledger structure, and grasps the recording destination corresponding to each piece of file data encrypted and divided by the file data encryption and division means.
32. The file data real-time saving system includes: a saving file data list information creating means for creating saving file data list information that includes terminal information (fixed IP address) associated with the client and the data manager when the file data is uploaded to the first temporary storage area using the upload means, the original file name of the file data to be saved, and information on the upload date; a saved file data list information reference control means configured to allow the saved file data list information created by the saved file data list information creation means to be referenced only by communication devices (management / processing programs) managed by the fixed IP addresses of the client and the data manager; Further having 2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
33. The real-time backup and restoration type digital asset guard service provision system of claim 1, characterized in that the multiple chains, which are mainly composed of a closed blockchain such as the private type or the consortium type that forms the distributed ledger structure and which may include the distributed ledger group and public type blockchain, are equipped with nodes at each of the locations that make up the planet, recording devices at multiple locations that are network-connected to the nodes at the locations, and a multiple-level file data real-time backup and restoration system configuration for operating the file data real-time backup system and the file data real-time restoration system.
34. The real-time backup and restoration type digital asset guard service providing system of claim 33, characterized in that it is equipped with a Level S file data real-time backup and restoration system configuration, which is based on next-generation distributed communications in general, and is configured to operate nodes at each location that constitutes the planet, recording devices at multiple locations that are network-connected to the nodes at the locations, the file data real-time backup system, and the file data real-time restoration system using closed networks that are not connected to the Internet, such as satellite communications, 5G / 6G private communications, LTE networks, and dedicated closed networks.
35. The real-time evacuation and restoration type digital asset guard service provision system of claim 33, characterized in that it utilizes an internet communication network, is based on a closed blockchain such as the private or consortium type that forms the distributed ledger structure, and is composed of highly creditworthy companies that approve each of the participants of multiple chains that may include the distributed ledger group and public blockchains, and is configured to operate nodes at each of the bases that form the planet, recording devices at multiple bases that are network-connected to the base nodes, the file data real-time evacuation system, and the file data real-time restoration system in a high-security space such as a dedicated room.
36. The real-time backup and restoration type digital asset guard service providing system of claim 33, characterized in that it utilizes an internet communication network, is primarily based on a closed blockchain such as the private or consortium type that forms the distributed ledger structure, and is composed of highly credible companies that approve each other of the participants of multiple chains that may include the distributed ledger group and public blockchains, and has a level 3 file data real-time backup and restoration system configuration in which a file server for data backup is installed in a space with a security level equivalent to an office, or an inexpensive cloud service (including the use of globally distributed regional services) is configured to operate on nodes at each base that constitutes the planet, recording devices at multiple bases that are networked to the base nodes, the file data real-time backup system, and the file data real-time restoration system.
37. The real-time backup and restoration type digital asset guard service providing system of claim 33, characterized in that it utilizes an Internet communication network, is open to organizations such as general companies (e.g., branch networks), and is configured to operate nodes at each location that make up the planet, recording devices at multiple locations that are network-connected to the location nodes, the file data real-time backup system, and the file data real-time restoration system.
38. The real-time backup and restoration type digital asset guard service providing system of claim 33, characterized in that it utilizes the Internet communication network, is open to private homes, etc., and is configured to operate nodes at each location that constitutes the planet, recording devices at multiple locations that are network-connected to the location nodes, the file data real-time backup system, and the file data real-time restoration system.
39. The real-time backup and restoration system configuration for file data at levels 1 to 4 is a real-time backup and restoration type digital asset guard service provision system described in any one of claims 35 to 38, characterized in that the nodes at each of the locations around the world that make up each of the planets, and the recording devices (file servers) at multiple locations that are network-connected to the nodes at those locations, are network-connected to the Internet communication network and operate during nighttime hours when waste electricity can be utilized.
40. The real-time backup and restoration type digital asset guard service provision system described in claim 39, characterized in that the configuration form of the file data real-time backup and restoration system for levels 1 to 4 is such that the nodes at each of the locations around the world that make up each of the planets, and the recording devices (file servers) at multiple locations that are network-connected to the nodes at those locations, are configured to be able to operate during daytime hours using renewable energy power such as solar power generation.
41. a data evacuation service contract application procedure acceptance means for accepting a data evacuation service contract application procedure from a customer who desires to evacuate file data, and accepting from the customer, at the time of accepting the data evacuation service contract application procedure, designation of the recording capacity, distribution degree (whether domestically only or overseas as well), storage period, and real-time processing speed of the file data desired to be evacuated; a smart contract (or server application) for recording data evacuation service contract application acceptance information, which has the function of managing the information on the recording capacity, distribution (whether domestically or internationally), storage period, and real-time processing of file data desired to be evacuated by the customer, accepted by the data evacuation service contract application procedure acceptance means, and automatically calculating and generating the basic configuration of the entire planet by setting the conditions from the customer (budgetary, whether it contains the most confidential content related to personal information or security = the amount of risk, etc.); encrypting and recording the generated information as part of the system configuration information in a group of nodes at a specific location in the distributed ledger structure, and enabling a specified smart contract (or server application) that performs the relevant processing to read the recorded configuration information together with the customer's personal information, thereby enabling an overall understanding of the system; Further having 2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
42. The file data real-time backup system calculates a hash value based on encrypted and divided file data that is recorded in the nodes of each base that belong to each of the distributed file management groups and in the recording devices of multiple bases that are connected to the base nodes via a network, records the calculated hash values in blocks in the nodes and recording devices, and constantly compares the hash values recorded in the nodes of each of the distributed file management groups and in the recording devices of multiple bases that are connected to the base nodes via a network, or in blocks in the nodes or recording devices, and records the calculated hash values in blocks in the nodes or recording devices. The real-time backup and restoration type digital asset guard service providing system of claim 1, further comprising a data tampering check control means that, if there is a difference between the hash recorded on the specific node or recording device and the hash recorded on another node or recording device or in a block on the node or recording device, detects that the encrypted and divided file data recorded on the specific node or recording device has been tampered with or destroyed, excludes the specific node or recording device from the file data backup process (and deletes the block on the specific node or recording device), and notifies the operator of the node and the digital asset guard service operations manager of an alarm.
43. The real-time backup and restoration type digital asset guard service providing system of claim 1, characterized in that it is configured to manage, with a fixed IP address, communication devices that can use a first private key (first offline decryption key) created by each of the customer and the data manager to restore each encrypted and divided file data that has been distributed and recorded in each location node belonging to each of the distributed file management groups and in multiple location recording devices connected to the location nodes via a network to the original data before backup via the file data real-time restoration system.
44. The real-time evacuation and restoration type digital asset guard service providing system of claim 43, characterized in that the management information of the IP addresses of communication devices on which the customer and the data manager can use the first private keys (first offline decryption keys) created by each of them is presented to the digital asset guard service operator only when a multi-signature type private key transaction is approved by the holders of specific nodes at multiple locations that constitute the digital asset guard service operator.
45. The real-time backup and restoration type digital asset guard service providing system described in claim 43, characterized in that node information that is permitted to access is recorded in a group of nodes at a specific location in the distributed ledger structure.
46. The real-time backup and restoration type digital asset guard service providing system of claim 1, further comprising an upload process-enabled IP address check means that controls the upload process (operation of the encryption / splitting algorithm selection receiving means, the customer data backup instruction receiving means, the file data encryption / splitting means, and the upload means) of the file data to be evacuated by the customer in the file data real-time backup system so that only operations at customer terminals that have a fixed IP address pre-registered as part of the system setting information in a node group at a specific location in the distributed ledger structure are possible, as terminal information for uploading to the first temporary storage area using the upload means.
47. The real-time backup and restoration type digital asset guard service providing system described in claim 41, characterized in that the smart contract (or server application) for recording data evacuation service contract application acceptance information further has the function of confirming the recorded amount of file data that the customer wishes to evacuate and that has been accepted by the data evacuation service contract application procedure acceptance means, and if the confirmed recorded amount of file data exceeds the maximum recording capacity of one file defined in the system, determining the number of divisions of the file data so that the recorded amount is less than the maximum recording capacity.
48. The real-time backup and restoration type digital asset guard service provision system described in claim 1, characterized in that each base node belonging to each of the distributed file management groups and each of the recording devices at multiple bases connected to the base node via a network are provided with multiple sub-configuration file servers (or a group of file servers accessible from each of the base nodes belonging to each of the file management groups) that are respectively connected to the base node and each of the recording devices at multiple bases connected to the base node via a network.
49. Each of the distributed recording means or the distributed recording smart contract (or server application) checks the data recording capacity and usage status of each of the sub-component file servers connected to each of the base nodes belonging to each of the distributed file management groups and to recording devices at multiple bases connected to the base nodes via a network, and based on the checked data recording capacity, selects a specific sub-component file server having a data recording capacity capable of recording the large file data associated with the information of the conservation point that has been encrypted, divided into multiple pieces, and uploaded to the first temporary storage area and sorted by the file data conservation point association sorting means, and that is managed in a black box environment by the conservation point information management means. The real-time backup and restoration type digital asset guard service providing system described in claim 48 has the function of recording the large file data that has been encrypted, divided into multiple pieces, and uploaded to the first temporary storage area, sorted by the file data conservation point correspondence sorting means, to a file server of a specific sub-configuration, and linked to the information of the conservation point that is managed in a black box environment by the conservation point information management means, and recording information of the file server of a specific sub-configuration that is the recording destination for the large file data that has been encrypted, divided into multiple pieces, and uploaded to the first temporary storage area, as second index information to each base node belonging to each of the distributed file management groups.
50. Each of the distributed recording means or the distributed recording smart contract (or server application) records the encrypted and divided file data in a predetermined sub-configuration file server connected to a node at each base belonging to each of the distributed file management groups and a recording device at a plurality of bases connected to the node at each of the bases via a network. When the large file data linked to the information of the conservation point managed in a black box environment by the conservation point information management means exceeds the upper limit of the recording capacity of the file server, the file data exceeding the upper limit of the recording capacity of the file server is sorted by the file data conservation point association sorting means in a state in which the encrypted and divided file data is uploaded to the first temporary storage area. The real-time backup and restoration type digital asset guard service providing system of claim 48, characterized in that it has the function of calculating the available recording capacity of each base node belonging to each of the distributed file management groups and each of the other sub-configuration file servers connected to recording devices at multiple bases connected to the base node via a network, selecting the sub-configuration file server that is the optimal recording destination based on the calculated available recording capacity, recording the data on the selected sub-configuration file server, and changing the settings of the original file server to put it into a dormant state, and recording (updating) the information of the sub-configuration file servers that are the recording destination as second index information on each base node belonging to each of the distributed file management groups.
51. A real-time backup / restore type digital asset guard service providing system as described in claim 50, characterized in that each base node belonging to each of the distributed file management groups and each of the recording devices at multiple bases connected to the base nodes via a network are each equipped with the ability to add sub-component file servers (or recording media connected to sub-component file servers) to which they are connected.
52. The encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data has the function of referencing the second index information recorded in the nodes of each base belonging to each of the distributed file management groups, detecting multiple sub-component file servers on which the large file data linked to the information of the conservation point that was sorted by the file data conservation point association sorting means in the encrypted and divided state recorded as the second index information and managed in a black box environment by the conservation point information management means, extracting file data recorded on the sub-component file servers from the multiple sub-component file servers, combining the extracted multiple file data, and restoring the large file data linked to the information of the conservation point that was sorted by the file data conservation point association sorting means in the original encrypted and divided state and managed in a black box environment by the conservation point information management means.
53. The real-time backup and restoration type digital asset guard service providing system of claim 1, characterized in that the file data real-time backup system further has a period-recording amount check means that, if the file data uploaded by a customer who wishes to back up file data and distributedly recorded on each location node belonging to each of the distributed file management groups and on recording devices at multiple locations connected to the location nodes via a network exceeds the maximum file data recording amount within a specified period, requests the customer to re-apply for a file data backup service contract, and if the customer does not go through the re-application procedure, treats it as an error.
54. At any one of the bases belonging to each of the distributed file management groups, there is a node or a recording device that is in a stopped state and not connected to the Internet, The real-time backup and restoration type digital asset guard service providing system of claim 1, characterized in that the node or recording device in a stopped state at the relevant base is configured to receive and record encrypted and divided file data recorded on a node or recording device in an operating state at another base when it is restarted.
55. a data destruction attack detection means for detecting an attack (or the existence of data destruction due to equipment failure, etc.) on encrypted and divided file data recorded on the planet (or on a node or recording device at any of the bases constituting the planet), and determining that a data destruction attack is taking place when destruction of multiple file data managed within a certain period of time (e.g., 30 minutes, 8 hours, 24 hours, etc.) is detected; and an automatic data evacuation means at the time of attack configured to, when the data destruction attack detection means detects an attack on the file data in the encrypted and divided state, suspend the nodes at each base constituting the planet and the recording devices at multiple bases connected to the nodes at the base via a network, or forcibly cut off the internet connection path, and to set up a separate network to automatically evacuate the encrypted and divided file data that has been distributed and recorded in the nodes at the base that have not been attacked or the recording devices at multiple bases connected to the nodes at the base via a network, to the nodes at each base constituting another planet where an attack on the encrypted and divided file data by the data destruction attack detection means has not been detected, and to the recording devices at multiple bases connected to the nodes at the base via a network.
2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
56. The real-time backup and restoration type digital asset guard service providing system of claim 55, characterized in that it has a communication switching control means configured to, when the data destruction attack detection means detects an attack on the encrypted and divided file data, maintain the stopped node and the recording devices at multiple locations connected to the node at the location via a network in a stopped state with their Internet connection cut off, and switch to a connection with a communication means other than the Internet (such as LTE).
57. The real-time backup and restoration type digital asset guard service providing system described in claim 55, characterized in that when the data destruction attack detection means detects an attack on the file data in an encrypted and divided state, the automatic data backup means in the event of an attack is configured to automatically backup the encrypted and divided file data, which is distributed and recorded on the nodes of a base that is not attacked and which constitutes the planet and on recording devices of multiple bases that are network-connected to the nodes of the base, via a communication means other than the Internet (such as LTE), to the nodes of each base that constitutes another planet that is not attacked on the file data in an encrypted and divided state and on recording devices of multiple bases that are network-connected to the nodes of the base.
58. The real-time backup and restoration type digital asset guard service providing system described in claim 1, characterized in that the file data constituting the digital assets (information of some high value) to be protected are tokens, customer information of existing business systems, asset information, source code and modules, confidential information, design documents, parameters such as settings, digital contracts, rights, designs, and any other data that can be expressed digitally.
59. The real-time backup and restoration type digital asset guard service providing system of claim 41, characterized in that the data backup service contract application procedure acceptance means further accepts from the customer, at the time of accepting the data backup service contract application procedure, specifications of the guarantee level of the file data desired to be saved, the nodes of each of the locations that make up each of the planets, recording devices at multiple locations that are network-connected to the nodes of the locations, and the level of the file data real-time backup and restoration system configuration required for the file data real-time backup system and the file data real-time restoration system to operate.
60. The real-time backup and restoration type digital asset guard service provision system described in claim 1, characterized in that the nodes of each base that make up each distributed file management group and the recording devices of multiple bases that are connected to the nodes of that base via a network have different operating hours and are in a mixture of operating and stopped states, and all nodes of the bases and the recording devices of multiple bases that are connected to the nodes of that base via a network are in operation 24 hours a day, and at a given point in time, at least one node of the bases or at least one recording device of the bases that is connected to the nodes of that base via a network is in operation within each distributed file management group.
61. The nodes at each base that make up each of the distributed file management groups and the recording devices at multiple bases that are connected to the base nodes via a network operate only during nighttime hours using waste electricity generated during nighttime hours, and at a given point in time, at least one of the base nodes or at least one of the base recording devices connected to the base nodes via a network is operating within each of the distributed file management groups, and when the base node or the base recording device connected to the base node via a network changes from a stopped state to an operating state, the base node or the base recording device is configured to automatically correct information such as stored file data to the latest information within each of the distributed file management groups.
62. The real-time evacuation and restoration type digital asset guard service provision system described in claim 1, characterized in that the node at each base and the recording devices at multiple bases connected to the node at that base via a network have a container or housing equipped with a renewable energy generator such as solar power, a file server / CPU, a 5G communication device and a battery.
63. The real-time evacuation and restoration type digital asset guard service provision system described in claim 1, characterized in that the node at each location and the recording devices at multiple locations connected to the node at that location via a network have a container or housing equipped with a file server / CPU, 5G communication equipment, a battery (capable of withstanding short-term operation), a cooling device, etc.
64. The real-time evacuation and restoration type digital asset guard service providing system according to claim 1, characterized in that it is configured to: primarily use a closed blockchain such as the private type or the consortium type that forms the distributed ledger structure; offset the file data recording capacity provided at nodes owned by node holders participating in multiple chains that may include the distributed ledger group, public blockchains, etc., with the file data recording capacity used by the node holders; calculate the difference between the total file data recording capacity and the provided file data recording capacity; and collect and allocate an amount based on the difference from each node holder.
65. a customer registration information designation receiving means for receiving, from a customer who desires to save file data, a customer ID and designation of terminal information (fixed IP address) to be used for saving and restoring file data; a customer registration smart contract (or server application) that has a function of encrypting and recording the customer ID and terminal information (fixed IP address) used for saving and restoring file data accepted by the customer registration information designation accepting means in a node group at a specific location in the distributed ledger structure; and Further having 2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
66. The real-time backup and restoration type digital asset guard service providing system of claim 1, further comprising a first parameter designation receiving and recording means for receiving the designation of the first parameter from the customer who wishes to back up file data and recording the first parameter that has been designated to an offline recording medium.
67. The real-time backup and restoration type digital asset guard service providing system described in claim 1, further comprising a second parameter designation receiving and setting means for receiving the designation of the second parameter from the digital asset guard service operator and setting the second parameter whose designation has been received in a predetermined processing means that performs the corresponding processing or in the source code of a smart contract (or server application) to modularize it.
68. The index information creating means, the index information recording means, the encrypted index information extracting means, and the index information decrypting means are configured separately on the user (customer and data manager) side and on the digital asset guard service operation manager side, The index information creation means includes a user (customer and data manager) side index information creation program (wallet function) (or smart contract) that operates on the side of the user (customer and data manager) who desires to save file data, and a digital asset guard service operator-side index information creation smart contract (or server application) that operates on the digital asset guard service operator-side, The user (customer and data manager) side index information creation program (or smart contract) has a function of creating user (customer and data manager) side index information having the original file name, upload date information, and storage date of the file data to be saved when uploaded to the first temporary storage area using the upload means, The digital asset guard service operator-side index information creation smart contract (or server application) has a function of creating digital asset guard service operator-side index information that includes information on the (renamed) file name of each of the file data that is linked to the information on the preservation points that are distributed and recorded by each of the distributed recording means or the distributed recording smart contract (or server application), sorted by the file data preservation point association sorting means, and managed in a black box environment by the preservation point information management means, (encrypted) corresponding recording destination information, etc.; The index information recording means includes a user (customer and data manager) side index information recording program (or smart contract) that runs on the side of the user (customer and data manager) who wishes to save file data, and a digital asset guard service operator side index information recording smart contract (or server application) that runs on the digital asset guard service operator side, The user (customer and data manager) side index information recording program (or smart contract) has a function of encrypting and recording the user (customer and data manager) side index information created by the user (customer and data manager) side index information creation program (or smart contract) in a group of nodes at a specific location in the distributed ledger structure when approval is given using a first private key for blockchain access generated based on a first private key (first offline decryption key) created by each of the customer and the data manager, The digital asset guard service operator-side index information recording smart contract has a function of encrypting and recording the digital asset guard service operator-side index information created by the digital asset guard service operator-side index information creation smart contract (or server application) in a group of nodes at a specific location in the distributed ledger structure when approval is given using a second blockchain access private key generated based on a second private key (second decryption key) created by the digital asset guard service operator, The encrypted index information extraction means includes a user (customer and data manager)-side encrypted index information extraction smart contract (or server application) that operates on the side of the user (customer and data manager) who desires to restore the file data, and a digital asset guard service operator-side encrypted index information extraction smart contract (or server application) that operates on the digital asset guard service operator-side, The user (customer and data administrator) side encrypted index information extraction smart contract (or server application) extracts the encrypted index information of the user (customer and data administrator) side, when authorization is given using a first private key for blockchain access generated based on a first private key (first offline decryption key) created by each of the customer and the data administrator, the user (customer and data administrator) side encrypted index information extraction smart contract (or server application) extracts the encrypted index information of the user (customer and data administrator) side encrypted index information acquired by the data restoration processing agreement information acquisition means, which is associated with the file data to be extracted and accepted by the customer data restoration instruction acceptance means, for each group of file data associated with the information of each of the conservation points managed in a black box environment by the conservation point information management means. The system has a function of extracting encrypted user (customer and data manager)-side index information recorded in a node group at a specific location in the distributed ledger structure by the user (customer and data manager)-side encrypted index information recording smart contract (or server application) based on key information (or the first parameter and the second parameter included in the key information) formed using the first authenticator ID information and the second authenticator ID information required for data restoration in agreement information between the first authenticator and the second authenticator regarding the restoration process of the data to be restored for the customer, The smart contract (or server application) for extracting encrypted index information on the digital asset guard service operator side has a function of extracting encrypted digital asset guard service operator-side index information recorded in a group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording encrypted index information on the digital asset guard service operator side, when authorization is made using a second private key for accessing the blockchain generated based on a second private key (second decryption key) created by the digital asset guard service operator, for each group of file data linked to information on each of the conservation points managed in a black-box environment by the conservation point information management means, based on key information (or the first parameter and the second parameter included in the key information) made up of the first authenticator ID information and the second authenticator ID information necessary for data restoration in agreement information between the first authenticator and the second authenticator regarding the restoration process of the data to be restored for the customer, which is associated with file data to be extracted and acquired by the data restoration process agreement information acquisition means, and which is associated with file data to be extracted and accepted by the customer data restoration instruction acceptance means; The index information decryption means includes a user (customer and data manager)-side index information decryption smart contract (or server application) that operates on the side of the user (customer and data manager) who desires to restore the file data, and a digital asset guard service operator-side index information decryption smart contract (or server application) that operates on the digital asset guard service operator-side, The user (customer and data manager) side index information decryption smart contract (or server application) has a function of decrypting the encrypted user (customer and data manager) side index information extracted by the user (customer and data manager) side encrypted index information extraction smart contract (or server application) based on a first private key (first offline decryption key) created by each of the customer and the data manager, The digital asset guard service operator-side index information decryption smart contract (or server application) has a function of decrypting the encrypted digital asset guard service operator-side index information extracted by the digital asset guard service operator-side encrypted index information extraction smart contract (or server application) based on a second private key (second decryption key) created by the digital asset guard service operator.
2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
69. 2. The real-time backup and restoration type digital asset guard service providing system according to claim 1, wherein the group of nodes at a specific location in the distributed ledger structure is configured to record, in encrypted form, the following as configuration information for the customer and the data manager: IP addresses and user IDs as respective configuration information for the customer and the data manager; agreement information between the first authenticator and the second authenticator (or the first parameter included in the agreement information) regarding the backup processing of the data to be backed up for the customer, acquired by the data backup processing agreement information acquisition means; a smart contract address on the digital asset guard service operator side that can reference the respective configuration information for the customer and the data manager; the file name and file data capacity, processing date and time, and storage date when the file data was backed up as index information for the customer; configuration information for a smart contract (or server application) running on the digital asset guard service operator side to back up the customer's file data; and information on the renamed file names of each of the file data that has been distributedly recorded by each of the distributed recording means or the distributed recording smart contract (or server application), as index information on the digital asset guard service operator side.
70. The real-time backup and restoration type digital asset guard service provision system described in claim 1, characterized in that the recording devices at multiple locations that are network-connected to the nodes at each location are made up of nodes that constitute the same blockchain network as the nodes at the location, or are made up of devices that do not belong to the blockchain network constituted by the nodes at the location but can be connected in a state that allows them to access the nodes at the location.
71. A real-time backup and restoration type digital asset guard service providing system as described in claim 1, characterized in that the recording devices at multiple locations connected to the nodes at each location via a network are devices that constitute a different network from the nodes at the respective locations.
72. The real-time backup and restoration type digital asset guard service providing system described in claim 1, characterized in that the distributed file management group allocation means or the smart contract (or server application) for distributed file management group allocation, the encrypted / split file data extraction means or the smart contract (or server application) for encrypted / split file data extraction each have a second parameter specified by the digital asset guard service operator hard-coded internally.
73. The real-time evacuation and restoration type digital asset guard service providing system according to claim 1, characterized in that the distributed ledger structure is constructed using a private or consortium type blockchain.
74. The real-time evacuation and restoration type digital asset guard service providing system described in claim 73, characterized in that the private type or the consortium type etc. blockchain is constructed with a planet consisting of a group of nodes combining multiple virtual nodes at one base.
75. The digital asset guard service operator-side file data real-time evacuation system includes a smart contract (or server application) for real-time file data evacuation on the digital asset guard service operator side, which is configured by incorporating the functions of the distributed file management group allocation means or the smart contract (or server application) for distributed file management group allocation, the distributed recording means or the smart contract (or server application) for distributed recording, the smart contract (or server application) for server index information creation, and the smart contract (or server application) for server index information recording, The real-time backup and restoration type digital asset guard service providing system described in claim 2, characterized in that the digital asset guard service operator side file data real-time restoration system has a smart contract (or server application) for real-time file data restoration on the digital asset guard service operator side that is configured by incorporating the functions of the smart contract (or server application) for extracting encrypted server index information, the smart contract (or server application) for decrypting server index information, and the encrypted / split file data extraction means or the smart contract (or server application) for extracting encrypted / split file data.
76. The real-time backup and restoration type digital asset guard service providing system described in claim 75, characterized in that the smart contract (or server application) for real-time backup of file data on the digital asset guard service operator side has a second parameter specified by the digital asset guard service operator hard-coded internally.
77. 76. The real-time backup and restoration type digital asset guard service providing system of claim 75, wherein the smart contract (or server application) for real-time file data restoration on the digital asset guard service operator side has a second parameter specified by the digital asset guard service operator or a second composite parameter (composed of a pair of a second decryption parameter specified by the digital asset guard service operator and managed offline (which is incorporated and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) and a second encryption parameter automatically generated from the second decryption parameter (which is incorporated and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing)) hard-coded internally.
78. The smart contract (or server application) for real-time file data evacuation on the digital asset guard service operator side is: a function of creating a renaming and encryption key using agreement information between the first authenticator and the second authenticator regarding the evacuation process of the data to be evacuated for the customer, acquired by the data evacuation process agreement information acquisition means (or the first parameter specified by the customer who desires to evacuate file data and the second parameter hard-coded internally, which are included in the agreement information), encrypting and dividing the file data into multiple pieces by the file data encryption / division means, uploading the file data to the first temporary storage area by the upload means, sorting the file data by the file data conservation point association sorting means, and managing the file data in a black box environment by the conservation point information management means, using the renaming and encryption key to change the file name of each file data linked to the information of the conservation point, encrypting the file data, and allocating it to multiple distributed file management groups; a function of creating server index information including information on the renamed file name of each of the distributed and recorded file data, which is associated with information on each of the conservation points sorted by the file data conservation point correspondence sorting means and managed in a black box environment by the conservation point information management means, and address information of the nodes and recording devices that will store the file data in each of the distributed file management groups to which each of the file data will be allocated, and before encrypting and recording the information on the node group at a specific location in the distributed ledger structure, changing the information on the renamed file name and the address information of the node and recording device that will store the file data to a name that is further different from the renamed file name (based on the second parameter hard-coded internally), to create new server index information, and encrypting and recording the created new server index information to the node group at a specific location in the distributed ledger structure, and then erasing the information on the renamed file name of each of the original distributed and recorded file data, and the address information of the node and recording device that will store the file data in each of the distributed file management groups to which each of the file data will be allocated; have 77. The system for providing real-time saving and restoring digital asset guard services according to claim 76.
79. 79. The real-time backup and restoration type digital asset guard service providing system of claim 78, wherein the smart contract (or server application) for real-time backup of file data on the digital asset guard service operator side further has the function of changing the name of the file data to a name that is different from the converted file name (based on the second parameter hard-coded internally), and then adding dummy file information to the information of the changed file name and the address information of the node and recording device where the file data will be stored, to create new server index information, encrypting the created new server index information and recording it on a group of nodes at a specific location in the distributed ledger structure, and then erasing the information of the changed file name of each of the original distributedly recorded file data and the address information of the node and recording device where the file data will be stored in each of the distributed file management groups to which each file data will be allocated.
80. The smart contract (or server application) for real-time file data restoration on the digital asset guard service operator side is: Agreement information between the first authenticator and the second authenticator regarding the backup processing of the data to be backed up for the customer, acquired by the data backup processing agreement information acquisition means (or the first parameter specified by the customer, or a first composite parameter (composed of a pair of a first decryption parameter specified by the customer and managed offline and a first encryption parameter automatically generated from the first decryption parameter, included in the agreement information), and A name recovery and decryption key is created using a second parameter designated by the digital asset guard service administrator, which is hard-coded internally, or a second composite parameter (a pair consisting of a second decryption parameter designated and managed offline by the digital asset guard service administrator (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) and a second encryption parameter automatically generated from the second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing)); The server index information management means has a function of extracting encrypted server index information (recorded in a node group at a specific location in the distributed ledger structure) for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means, restoring the information to a new server index information state in which the name has been changed to a name that is further different from the name-converted file name (based on the second parameter or the second composite parameter hard-coded inside), then restoring the changed name to the information of the name-converted file name, and then restoring the information of the file name before the name change of each of the distributedly recorded file data based on the name restoration and decryption key.
79. The system for providing real-time saving and restoring digital asset guard services according to claim 78.
81. The smart contract (or server application) for real-time file data restoration on the digital asset guard service operator side is: Agreement information between the first authenticator and the second authenticator regarding the backup processing of the data to be backed up for the customer, acquired by the data backup processing agreement information acquisition means (or the first parameter specified by the customer, or a first composite parameter (composed of a pair of a first decryption parameter specified by the customer and managed offline and a first encryption parameter automatically generated from the first decryption parameter, included in the agreement information), and A name recovery and decryption key is created using a second parameter designated by the digital asset guard service administrator, which is hard-coded internally, or a second composite parameter (a pair consisting of a second decryption parameter designated and managed offline by the digital asset guard service administrator (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) and a second encryption parameter automatically generated from the second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing)); The server index information management means has a function of extracting, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means, encrypted server index information recorded in a node group at a specific location in the distributed ledger structure, excluding dummy file information (based on the second parameter or the second composite parameter hard-coded therein), then restoring the state of new server index information changed to a name that is further different from the name-converted file name, then restoring the changed name to the name-converted file name information, and then restoring the distributedly recorded file data to the name-converted file name information based on the name restoration and decryption key.
80. The system for providing real-time saving and restoring digital asset guard services according to claim 79.
82. A real-time evacuation and restoration type digital asset guard service providing system for guarding digital assets from high-level cyber-attacks, which is constructed with a distributed ledger in distributed ledger technology and a server application for performing predetermined processing using data managed in the distributed ledger, A distributed ledger system, such as a private or consortium system, constructed with multiple planets (each a unit of a distributed ledger system) consisting of a group of nodes combining nodes from multiple locations in different regions around the world; a first authenticator information management means for managing first authenticator authentication information required for authenticating a first authenticator who is one of a customer and a data manager who manages customer data, and first authenticator ID information and key information required for saving and restoring data, etc.; a second authenticator information management means for managing second authenticator authentication information required for authenticating a second authenticator who is the other of the customers and the data administrator who manages the customer data, and second authenticator ID information and key information required for saving and restoring data, etc.; an external first authenticator authentication system that authenticates the first authenticator; an external second authenticator authentication system that authenticates the second authenticator; A file data real-time evacuation system, Real-time file data recovery system and Each node in each location connects to recording devices in multiple locations around the world via a network to create a distributed file management group. The file data real-time saving system includes: a data saving process agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding a process of saving data to be saved for the client; a customer data evacuation instruction means for instructing the evacuation of the customer's data based on the agreement information when the data evacuation processing agreement information acquisition means acquires agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the customer's data to be saved; a program having a plurality of encryption and division algorithms with different encryption and division processing methods for file data; an encryption / division algorithm selection receiving means for receiving a selection of a program having a predetermined encryption / division algorithm based on the agreement information between the first authenticator and the second authenticator (or a first parameter specified by the customer who desires to save file data, which is included in the agreement information) regarding the saving process of the data to be saved for the customer, acquired by the data saving process agreement information acquisition means; a customer data evacuation instruction receiving means for receiving an instruction to evacuate the customer's data from the customer data evacuation instruction means; a file data encryption / division means for encrypting and dividing the customer data to be saved, which has been accepted by the customer data saving instruction accepting means, into a plurality of file data using a program having the encryption / division algorithm accepted by the encryption / division algorithm selection accepting means; an uploading means for uploading each of the file data encrypted and divided by the file data encryption / division means to a first temporary storage area; a file data security point associating and sorting means for associating each of the file data encrypted and divided by the file data encryption and division means and uploaded to the first temporary storage area by the upload means with one of at least two security points for managing the file data; a security point information management means for managing, in a black box environment, information on the security points for managing the file data sorted by the file data security point association sorting means; a distributed file management group allocation means provided in each planet, which has the function of allocating, on the digital asset guard service operator's side according to conditions specified by the customer, each of the file data associated with the information of the conservation point managed in a black box environment by the conservation point information management means, which is sorted by the file data conservation point matching sorting means based on the agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer acquired by the data evacuation processing agreement information acquisition means (or the first parameter included in the agreement information and the second parameter specified by the digital asset guard service operator), to a plurality of the distributed file management groups constructed by the respective base nodes constituting the planet corresponding to the conservation point and recording devices at a plurality of bases connected to the base nodes via a network; a distributed recording means provided in each planet, which has a function of distributively recording the file data associated with the information of each of the conservation points that has been allocated by the distributed file management group allocation means, sorted by the file data conservation point association sorting means, and managed in a black box environment by the conservation point information management means, in each of the base nodes belonging to the corresponding distributed file management groups and in recording devices at multiple bases connected to the base nodes via a network; a system setting information creation and recording means having a function of creating system setting information including terminal information (information identifying the other party, such as a fixed IP address) for uploading to the first temporary storage area using the upload means, the number of a predetermined processing means that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and information on the file server groups (in the node of a predetermined base and in recording devices at multiple bases that are networked to the node of the base) that make up the distributed file management group, encrypting the information, and recording it in the node group at a specific base in the distributed ledgers of the private type or the consortium type, etc.; a server index information creation means for creating server index information including: key information using the first authenticator ID information and the second authenticator ID information required for data evacuation, which are included in the agreement information between the first authenticator and the second authenticator regarding the evacuation process of the data to be evacuated for the client acquired by the data evacuation process agreement information acquisition means; file name information of each of the file data linked to the information of the conservation point sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means, which are distributed and recorded by each of the distributed recording means; and configuration information of each of the distributed file management groups to which each of the file data is allocated; a server index information recording means having a function of encrypting the server index information created by the server index information creation means and recording it in a node group at a specific location in the distributed ledgers of the private type, the consortium type, or the like; customer setting information creation means (or a program having a wallet function) having a function to create customer setting information including agreement information between the first authenticator and the second authenticator (or setting information of the first parameter included in the agreement information) regarding the evacuation process of the data to be evacuated for the customer, which is acquired by the data evacuation process agreement information acquisition means, and which is linked to a program having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means; a customer index information creating means (or a program having a wallet function) having a function of creating customer index information including information on the original file name and upload date of the customer's file data to be saved; a customer index information recording means having a function of encrypting the customer index information created by the customer index information creation means (or a program having a wallet function) and recording it in a node group at a specific location in the distributed ledgers of the private type, the consortium type, or the like; a first data erasure means for erasing each file data uploaded to the first temporary storage area after the server index information recording means encrypts the server index information and records it in a node group at a specific location in the distributed ledgers of the private type, the consortium type, or the like; and The data saving process agreement information acquisition means a data evacuation process request instruction means for issuing an instruction to request evacuation process of data to be evacuated by the customer via the first authenticator; a data evacuation processing request instruction receiving means for receiving a request instruction for evacuation processing of the data to be evacuated from the data evacuation processing request instruction means; a data saving processing request instruction receiving first authenticator authentication requesting means for, when the data saving processing request instruction receiving means receives a request instruction for saving processing of the data to be saved by the customer, acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information managing means, providing the information to an external first authenticator authentication system, and requesting authentication of the first authenticator; a data saving first authenticated person ID information and key information receiving means for receiving the first authenticated person ID information and key information required for saving data from the first authenticated person information managing means when the first authenticated person is authenticated by the external first authenticated person authentication system; a first information notification means for notifying the second authenticator of information that the first authenticator has issued a request instruction for a data evacuation process for the data to be saved by the customer and information urging the second authenticator to issue an approval instruction for the data evacuation process for the data to be saved by the customer, when the first authenticator ID information and key information receiving means for data evacuation has received the first authenticator ID information and key information necessary for data evacuation; a data evacuation process approval instruction means for instructing approval of the evacuation process of the data to be evacuated for the client via the second authenticator who has received the notification from the first information notification means; a data evacuation processing approval instruction receiving means for receiving an approval instruction for the evacuation processing of the data to be evacuated from the data evacuation processing approval instruction means; a data saving processing approval instruction receiving second authenticator authentication requesting means for, when the data saving processing approval instruction receiving means receives an instruction to approve the saving processing of the data to be saved by the customer, acquiring second authenticator authentication information required for authenticating the second authenticator from the second authenticator information managing means, providing the second authenticator authentication information to an external second authenticator authentication system, and requesting authentication of the second authenticator; a data saving second authenticated person ID information and key information receiving means for receiving the second authenticated person ID information and key information required for saving data from the second authenticated person information managing means when the second authenticated person is authenticated by the external second authenticated person authentication system; a second information notification means for notifying the first authenticator of information that the second authenticator has issued an approval instruction for the evacuation process of the data to be saved by the customer and information urging the first authenticator to issue a request instruction for the evacuation process of the data to be saved by the customer, when the second authenticator ID information and key information receiving means for data evacuation has received the second authenticator ID information and key information necessary for data evacuation; a data evacuation process request instruction means for instructing a request for evacuation process of the data to be evacuated for the client via the first authenticator who has received the notification from the second information notification means; a data evacuation processing request instruction receiving means for receiving a request instruction for evacuation processing of the data to be evacuated from the data evacuation processing request instruction means; a data saving process agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the saving process of the client's data, using the first authenticator ID information and key information required for data saving received by the data saving first authenticator ID information and key information receiving means and the second authenticator ID information and key information required for data saving received by the data saving second authenticator ID information and key information receiving means, when the data saving process request instruction receiving means receives an instruction to request saving process of the client's data to be saved; and The file data real-time restoration system includes: a data restoration processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding restoration processing of the data to be restored for the customer; a customer data restoration instruction means for instructing the restoration of the customer's data based on the agreement information when the data restoration processing agreement information acquisition means acquires agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer; a program having a plurality of decryption and joining algorithms with different methods for decrypting and joining file data, each of which is associated with a program having the encryption and division algorithm; customer data restoration instruction receiving means for receiving an instruction to restore data to be restored for the customer from the customer data restoration instruction means; The data restoration instruction receiving means is provided for each planet, and for each group of file data linked to the information of each of the security points managed in a black box environment by the security point information management means in the planet corresponding to the security point, the data restoration instruction receiving means receives, linked to the file data to be extracted, the data restoration instruction receiving means receives, and the data restoration instruction receiving means receives, key information (or the first parameter included in the key information) using the first certifier ID information and the second certifier ID information required for data restoration in the agreement information between the first certifier and the second certifier regarding the restoration process of the data to be restored for the customer acquired by the data restoration process agreement information acquisition means. an encrypted server index information extraction means having a function of extracting encrypted server index information (recorded by the server index information recording means in a node group at a specific location in the distributed ledgers of the private type, the consortium type, etc.) based on a first composite parameter (composed of a pair of a first encryption parameter and a second decryption parameter designated by the digital asset guard service administrator and managed offline (modularized and incorporated in a predetermined processing means that performs the relevant processing) and a second encryption parameter automatically generated from the second decryption parameter (modularized and incorporated in a predetermined processing means that performs the relevant processing)); a server index information decryption means provided in each planet and having a function of decrypting the encrypted server index information extracted by the encrypted server index information extraction means for each group of file data associated with the information of each of the security points managed in a black box environment by the security point information management means in the planet corresponding to the security point; an encrypted and divided file data extraction means provided in each planet, which has a function of extracting, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point, from any of the nodes at each base belonging to each of the distributed file management groups and the recording devices at multiple bases connected to the nodes at each of the distributed file management groups via a network, each of the encrypted and divided file data being allocated to each of the distributed file management groups by the distributed file management group allocation means using server index information decrypted by the server index information decryption means, and distributed and recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in each of the recording devices at multiple bases connected to the nodes at each of the distributed file management groups via a network; downloading means provided in each planet for downloading, to a second temporary storage area, each of the file data in an encrypted and divided state extracted by the encrypted and divided file data extraction means for each group of file data associated with the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point; a file data restoration means provided in each planet, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point, for decrypting and combining all of the file data linked across the information of all of the conservation points in an encrypted and divided state that has been extracted by the encrypted and divided file data extraction means and downloaded to the second temporary storage area by the download means, using a program having the decryption and combination algorithm that is linked to a program having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means, to restore the data of the client before it was saved; a second data erasing means for erasing each of the encrypted and divided file data downloaded to the second temporary storage area after the file data restoration means has restored the data of the client to the state before the backup; and The data restoration processing agreement information acquisition means a data restoration processing request instruction means for instructing a request for restoration processing of data to be restored by the customer via the first authenticator; a data restoration processing request instruction receiving means for receiving a request instruction for restoration processing of the data to be restored from the data restoration processing request instruction means; a data restoration processing request instruction receiving first authenticator authentication requesting means for, when the data restoration processing request instruction receiving means receives a request instruction for restoration processing of data to be restored by the customer, acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information managing means, providing the information to an external first authenticator authentication system, and requesting authentication of the first authenticator; a first authenticator ID information and key information receiving means for data restoration, which receives the first authenticator ID information and key information required for data restoration from the first authenticator information managing means when the first authenticator is authenticated by the external first authenticator authentication system; a third information notifying means for notifying the second certifier of information that the first certifier has issued a request instruction for restoration of the data to be restored by the first certifier and information that prompts the second certifier to issue an approval instruction for the restoration of the data to be restored by the first certifier when the first certifier ID information and key information receiving means for data restoration receives the first certifier ID information and key information necessary for data restoration; a data restoration process approval instruction means for instructing approval of restoration process of the data to be restored for the customer via the second authenticator who has received notification from the third information notification means; a data restoration processing approval instruction receiving means for receiving an approval instruction for the restoration processing of the data to be restored for the customer from the data restoration processing approval instruction means; a data restoration processing approval instruction acceptance second authenticator authentication requesting means for, when the data restoration processing approval instruction accepting means accepts an approval instruction for the restoration processing of the data to be restored for the customer, acquiring second authenticator authentication information required for authenticating the second authenticator from the second authenticator information managing means, providing the second authenticator authentication information to an external second authenticator authentication system, and requesting authentication of the second authenticator; a data restoration second authenticator ID information and key information receiving means for receiving second authenticator ID information and key information required for data restoration from said second authenticator information management means when said second authenticator is authenticated by said external second authenticator authentication system; a fourth information notifying means for notifying the first authenticator of information that the second authenticator has instructed to approve the restoration process of the data to be restored by the customer and information that prompts the first authenticator to instruct to request the restoration process of the data to be restored by the second authenticator when the second authenticator ID information and key information receiving means for data restoration receives the second authenticator ID information and key information necessary for data restoration; a data restoration processing request instruction means for instructing a request for restoration processing of the data to be restored for the customer via the first authenticator who has received the notification from the fourth information notification means; a data restoration processing request instruction receiving means for receiving a request instruction for restoration processing of the data to be restored from the data restoration processing request instruction means; a data restoration processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer, by combining the first authenticator ID information and key information required for data restoration received by the first authenticator ID information and key information receiving means for data restoration and the second authenticator ID information and key information required for data restoration received by the second authenticator ID information and key information receiving means for data restoration, when the data restoration processing request instruction receiving means receives an instruction to request restoration processing of the data to be restored for the customer; have A real-time evacuation and restoration type digital asset guard service providing system.
83. The file data real-time saving system comprises a user-side file data real-time saving system that operates on the side of a user (customer or data manager) who desires to save file data, and a digital asset guard service operator-side file data real-time saving system that operates on the side of the digital asset guard service operator, The user-side file data real-time saving system comprises the data saving processing agreement information acquisition means, the customer data saving instruction means, a program having a plurality of the encryption / division algorithms, the encryption / division algorithm selection receiving means, the customer data saving instruction receiving means, the file data encryption / division means, the uploading means, the file data preservation point association sorting means, and the preservation point information management means, the digital asset guard service administrator-side file data real-time backup system comprises the distributed file management group allocation means, the distributed recording means, the server index information creation means, the server index information recording means, and the first data erasure means; The file data real-time restoration system comprises a user-side file data real-time restoration system that operates on the side of a user (customer or data manager) who desires to restore saved file data, and a digital asset guard service operator-side file data real-time restoration system that operates on the side of the digital asset guard service operator, the user-side file data real-time restoration system comprises the data restoration processing agreement information acquisition means, the customer data restoration instruction means, a program including a plurality of the decryption and combination algorithms, the download means, the file data restoration means, and the second data erasure means; The digital asset guard service administrator-side file data real-time restoration system includes the customer data restoration instruction receiving means, the encrypted server index information extracting means, the server index information decrypting means, and the encrypted and divided file data extracting means.
83. The system for providing real-time saving and restoring digital asset guard services according to claim 82.
84. A real-time evacuation and restoration type digital asset guard service providing system as described in any one of claims 1, 3 and 6, characterized in that the at least two conservation points are at least two addresses in one blockchain.
85. A real-time evacuation and restoration type digital asset guard service providing system as described in any one of claims 1, 3 and 6, characterized in that the at least two conservation points are at least one address in each of at least two blockchains.
86. The real-time evacuation and restoration type digital asset guard service providing system of claim 83, characterized in that the at least two conservation points are at least two addresses in one distributed ledger group.
87. The real-time evacuation and restoration type digital asset guard service providing system described in claim 83, characterized in that the at least two conservation points are at least one address in each of at least two distributed ledgers.
88. The file data real-time restoration system includes: a restoration processing time period setting accepting means for accepting settings such as a time period for performing file data restoration processing, an IP address for restoration, and a restoration period from a client who desires file data restoration; a file data restoration processing operation control means for controlling the customer data restoration instruction receiving means, the smart contract (or server application) for extracting encrypted server index information, the smart contract (or server application) for decrypting server index information, the smart contract (or server application) for extracting encrypted and divided file data, the download means, the file data restoration means, and the second data erasure means to operate only during the time period for which the restoration processing time period setting receiving means has received settings; Further having 2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
89. The file data real-time restoration system includes: The system further includes an authorization code setting receiving means for receiving an authorization (license) code setting from a customer who desires to restore file data, The file data restoration process operation control means controls the customer data restoration instruction receiving means, the encrypted server index information extraction smart contract (or server application), the server index information decryption smart contract (or server application), the encrypted and divided file data extraction smart contract (or server application), the download means, the file data restoration means, and the second data erasure means to operate only during the time period for which the restoration process time period setting receiving means has received a setting, and only when the approval code for which the approval code setting receiving means has received a setting has been approved by the digital asset guard service administrator.
89. The system for providing real-time saving and restoring digital asset guard services according to claim 88.
90. the approval code set in the approval code setting receiving means is a code received by the customer who desires to restore the file data from the digital asset guard service operation manager, The file data restoration processing operation control means is configured to grant an operation license for a program (or smart contract) having the decryption and combination algorithm linked to a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means when the approval code accepted by the approval code setting acceptance means is approved by the digital asset guard service operation manager and the customer's identity is confirmed systematically by multi-step authentication, biometric authentication, one-time passcode, or the like registered on the customer's smartphone.
90. The system for providing real-time saving and restoring digital asset guard services according to claim 89.
91. Each divided file data recorded in each base node belonging to each distributed file management group and in recording devices at multiple bases connected to the base node via a network is managed in an encrypted state, and index information such as a hash of each file data and the distributed file group to which the recorded file data is assigned is recorded in a block, and the blocks are linked by a chain in which time data is incorporated into the hash, The file data real-time saving system includes: a smart contract (or server application) for setting a storage period, which has a function of setting a storage period for the block on a planet-by-planet basis when each file data is distributedly recorded by each smart contract (or server application) for distributed recording, based on information on the storage period of the file data that the customer wishes to evacuate, which information is recorded in a node group at a specific location in the distributed ledger structure by the smart contract (or server application) for recording data evacuation service contract application acceptance information; a smart contract (or server application) for disconnecting a chain, which has a function of disconnecting a chain of blocks whose storage period set by the smart contract (or server application) for setting the storage period has elapsed; Further having 42. The system for providing real-time saving and restoring digital asset guard services according to claim 41.
92. The real-time backup and restoration type digital asset guard service providing system described in claim 91, characterized in that the file data real-time backup system further has a block deletion smart contract (or server application) that has the function of deleting unnecessary blocks that have been separated through the chain separation smart contract (or server application).
93. 92. The real-time backup and restoration type digital asset guard service providing system of claim 91, wherein the file data real-time backup system has the function of sending a notification to the customer to confirm whether or not the unnecessary blocks separated via the chain separation smart contract (or server application) can be deleted via the block deletion smart contract (or server application), and if there is no reply from the customer, notifying the digital asset guard service operator and confirming whether or not the unnecessary blocks can be deleted; and even if it is confirmed that the unnecessary blocks can be deleted, further having an unnecessary block data backup means configured to provisionally record each of the encrypted and divided file data as backup data via a predetermined recording medium disconnected from the network, and erase the provisionally recorded backup data after a certain period of time has passed.
94. The real-time backup and restoration type digital asset guard service providing system of claim 93, characterized in that when the unnecessary block data backup means sends a notification to the customer to confirm whether the unnecessary blocks can be deleted and it is confirmed that the customer wishes to extend the storage period of the file data, it provisionally records each of the encrypted and divided file data as backup data via a specified recording medium disconnected from the network, and at the same time selects a new planet that meets the conditions of the extended storage period of the file data desired by the customer, automatically backups the corresponding file data to the nodes of each base that constitute the selected planet and to recording devices of multiple bases connected to the nodes of the base through a network, and updates the server index information, and after the update, erases the provisionally recorded backup data after a certain period of time.
95. 92. The real-time backup and restoration type digital asset guard service providing system of claim 91, further comprising a rollover smart contract (or server application) having the function of: setting a new planet and distributed file management group, inheriting the management number of the old server index information and changing it to a new management number, creating new server index information, re-recording the file data in each base node belonging to the new distributed file management group and in multiple base recording devices connected to the base node via a network, and then deleting the file data and the old server index information for the file data recorded in each base node belonging to the original distributed file management group and in multiple base recording devices connected to the base node via a network, in order to extend the storage period of each file data that has been encrypted and divided into multiple pieces and that is recorded as the block in each base node belonging to each of the distributed file management groups and in multiple base recording devices connected to the base node via a network before the expiration of the storage period of the block set by the storage period setting smart contract (or server application).
96. a small amount of file data provisional recording means for recording a small amount of file data to be saved in a predetermined confidential blockchain in real time within the range of block capacity; a file data integration means configured to integrate the small amounts of file data recorded in the specified confidential blockchain by the small amount file data temporary recording means into one integrated file data through batch processing several times a day, and to use the integrated file data for evacuation processing such as splitting and encrypting the file data by the file data real-time evacuation system and distributing the data to nodes at each base belonging to the distributed file management group and to recording devices at multiple bases connected to the base nodes via a network; a small amount of file data erasure means for, after the file data real-time backup system has completed the backup process for the integrated file data, cutting a chain of a block in the predetermined confidential blockchain that records the small amount of file data, and erasing the file data recorded in the block; Further having 2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
97. The file data integration means integrates the small amounts of file data recorded in the specified confidential blockchain by the small amount file data temporary recording means into one integrated file data in batch processing several times a day, and passes the integrated file data to a smart contract (or server application) in the file data real-time backup system that has the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means, and controls the backup process to be carried out from splitting / encrypting the file data to nodes at each location belonging to a distributed file management group and distributed recording to recording devices at multiple locations connected to the nodes at the location via a network.
98. The small amount of file data erasing means A function of setting a provisional storage period of a predetermined number of days (for example, about 7 days) for file data that has been integrated into one integrated file data by the file data integration means, among the file data recorded in the predetermined confidential blockchain by the small amount of file data provisional recording means, and for which the file data real-time backup system has completed the backup process for the integrated file data; The real-time backup and restoration type digital asset guard service providing system of claim 96, characterized in that it has a function of cutting the chain of the corresponding block in the specified confidential blockchain after the provisional storage period has elapsed and erasing the file data recorded in the corresponding block.
99. a second file data real-time deletion system; The second file data real-time deletion system includes: a data deletion processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding a deletion processing of data to be deleted for the customer; a customer data deletion instruction means for instructing the deletion of the data to be deleted for the customer based on the agreement information when the data deletion processing agreement information acquisition means acquires agreement information between the first authenticated person and the second authenticated person regarding the deletion processing of the data to be deleted for the customer; a customer data deletion instruction receiving means for receiving an instruction to delete data to be deleted from the customer data deletion instruction means; a file data preservation point information deletion means for deleting information on the preservation points associated with the file data to be deleted that is received by the customer data deletion instruction receiving means and that is managed in a black box environment by the preservation point information management means; and The data deletion processing agreement information acquisition means a data deletion process request instruction means for issuing an instruction to request deletion of data to be deleted from the customer via the first authenticator; a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of the data to be deleted from the data deletion processing request instruction means; a data deletion processing request instruction receiving first authenticator authentication requesting means for, when the data deletion processing request instruction receiving means receives a request instruction for deletion processing of data to be deleted by the customer, acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information managing means, providing the information to an external first authenticator authentication system, and requesting authentication of the first authenticator; a data deletion first authenticated person ID information and key information receiving means for receiving the first authenticated person ID information and key information required for data deletion from the first authenticated person information management means when the first authenticated person is authenticated by the external first authenticated person authentication system; a fifth information notifying means for notifying the second authenticator of information that the first authenticator has issued a request instruction for deletion of the data to be deleted from the customer and information that prompts the second authenticator to issue an approval instruction for the deletion of the data to be deleted from the customer, when the first authenticator ID information and key information receiving means for data deletion has received the first authenticator ID information and key information necessary for data deletion; a data deletion process approval instruction means for instructing approval of a deletion process of the data to be deleted of the customer via the second authenticator who has received a notification from the fifth information notification means; a data deletion processing approval instruction receiving means for receiving an approval instruction for the deletion processing of the data to be deleted from the data deletion processing approval instruction means; a data deletion processing approval instruction acceptance second authenticator authentication request means for, when the data deletion processing approval instruction acceptance means accepts an approval instruction for the deletion processing of the data to be deleted from the customer, acquiring second authenticator authentication information required for authenticating the second authenticator from the second authenticator information management means, providing the second authenticator authentication information to an external second authenticator authentication system, and requesting authentication of the second authenticator; a data deletion second authenticated person ID information and key information receiving means for receiving second authenticated person ID information and key information required for data deletion from said second authenticated person information managing means when said second authenticated person is authenticated by said external second authenticated person authentication system; a sixth information notifying means for notifying the first authenticator of information that the second authenticator has instructed to approve the deletion of the data to be deleted by the customer and information that prompts the customer to instruct to request the deletion of the data to be deleted by the second authenticator when the data deletion second authenticator ID information and key information receiving means has received the second authenticator ID information and key information necessary for deleting data; a data deletion process request instruction means for instructing, via the first authenticated person notified by the sixth information notification means, to request a deletion process of the data to be deleted of the customer; a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of the data to be deleted from the data deletion processing request instruction means; a data deletion processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the deletion processing of the data to be deleted for the customer, using the first authenticator ID information and key information required for data deletion received by the first authenticator ID information and key information receiving means for data deletion and the second authenticator ID information and key information required for data deletion received by the second authenticator ID information and key information receiving means for data deletion, when the data deletion processing request instruction receiving means receives a request instruction for deletion processing of the data to be deleted for the customer; have 2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
100. The second file data real-time deletion system comprises a user-side second file data real-time deletion system that operates on the side of a user (customer and data manager) who desires to delete file data, and a digital asset guard service operator-side second file data real-time deletion system that operates on the side of the digital asset guard service operator- the user-side second file data real-time deletion system includes the data deletion processing agreement information acquisition means and the customer data deletion instruction means, The second file data real-time deletion system on the digital asset guard service operator side includes the customer data deletion instruction receiving means and the file data preservation point information deletion means. The real-time saving and restoring type digital asset guard service providing system according to claim 99.
101. A second file data real-time update (saving and deleting) system is provided, The second file data real-time update (saving and deleting) system comprises: a data update (saving and deletion) processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of the data to be updated (saved and deleted) for the customer, between the first authenticator and the second authenticator; a customer data update (saving and deletion) instruction means for instructing the updating (saving and deletion) of the data to be updated (saved and deleted) for the customer based on the agreement information when the data update (saving and deletion) processing agreement information acquisition means acquires agreement information between the first authenticated person and the second authenticated person regarding the updating (saved and deletion) processing of the data to be updated (saved and deleted) for the customer; A program (or smart contract) having a plurality of encryption and division algorithms that have different encryption and division processing methods for file data; an update (saving and deletion) processing encryption / division algorithm selection receiving means for receiving a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on agreement information between the first authenticator and the second authenticator regarding the saving processing of the data to be saved for the customer, which has been acquired by the data update (saving and deletion) processing agreement information acquisition means; a customer data evacuation instruction receiving means for receiving an instruction to evacuate data to be evacuated from the customer data update (evacuation and deletion) instruction means; an update (saving and deletion) processing time file data encryption / division means for encrypting and dividing the customer data to be saved, which has been accepted by the update (saving and deletion) processing time customer data saving instruction accepting means, into a plurality of file data using a program (or smart contract) having the encryption / division algorithm accepted by the update (saving and deletion) processing time encryption / division algorithm selection accepting means; an update (saving and deleting) processing time uploading means for uploading each of the file data encrypted and divided into a plurality of pieces by the update (saving and deleting) processing time file data encryption / division means to a first temporary storage area; an update (saving and deletion) processing time file data conservation point associating and sorting means for associating each of the file data encrypted and divided into a plurality of pieces by the update (saving and deletion) processing time file data encryption / division means and uploaded to the first temporary storage area by the update (saving and deletion) processing time upload means with one of the conservation points corresponding to at least two planets for managing the file data; an update (saving and deletion) processing time preservation point information management means for managing, in a black box environment, information on the preservation points for managing the file data sorted by the update (saving and deletion) processing time file data preservation point association sorting means; a smart contract (or server application) for allocating distributed file management groups during update (evacuation and deletion) processing, which is provided in each planet and has a function of allocating each of the file data associated with the information of the conservation points managed in a black box environment by the conservation point information management means during update (evacuation and deletion) processing, which is sorted by the file data conservation point association sorting means based on agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer, acquired by the data update (evacuation and deletion) processing agreement information acquisition means (or a first parameter included in the agreement information and a second parameter specified by the digital asset guard service operator); and the smart contract (or server application) for allocating each of the file data associated with the information of the conservation points managed in a black box environment by the conservation point information management means during update (evacuation and deletion) processing, to a plurality of distributed file management groups, which are configured by the digital asset guard service operator according to conditions specified by the customer and which are composed of nodes at each base constituting the planet corresponding to the conservation points and recording devices at multiple bases connected to the nodes at each base via a network; a smart contract (or server application) for distributed recording during update (evacuation and deletion) processing, which is provided on each planet and has a function of distributing and recording each of the file data associated with the information of each of the conservation points sorted by the file data conservation point association sorting means during update (evacuation and deletion) processing and managed in a black box environment by the conservation point information management means during update (evacuation and deletion) processing, which has been allocated by the smart contract (or server application) for distributed file management group allocation during update (evacuation and deletion) processing, in each of the base nodes belonging to the corresponding distributed file management group and in recording devices at multiple bases connected to the base nodes via a network; a smart contract (or server application) for creating and recording system setting information during update (backup and deletion) processing, which has the function of creating system setting information including terminal information (information identifying the other party, such as a fixed IP address) for uploading to the first temporary storage area using the upload means during update (backup and deletion) processing, the number of the predetermined processing means that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and information on the file server groups (in the node at a predetermined base and in recording devices at multiple bases that are networked to the node at that base) that make up the distributed file management group, encrypting the information, and recording it in the node group at a specific base in the distributed ledger structure; and a smart contract (or server application) for creating server index information during update (saving and deletion) processing, the smart contract having a function of creating server index information including: key information using the first authenticator ID information and the second authenticator ID information required for data evacuation, which are included in agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer, acquired by the data update (saving and deletion) processing agreement information acquisition means; file name information of each of the file data linked to the information of the conservation point, which is sorted by the file data conservation point association sorting means during update (saving and deletion) processing and managed in a black box environment by the conservation point information management means during update (saving and deletion) processing, and configuration information of each of the distributed file management groups to which each of the file data is allocated; and a smart contract (or server application) for recording server index information during update (backup and deletion) processing, which has a function of encrypting the server index information created by the smart contract (or server application) for creating server index information during update (backup and deletion) processing and recording it in a group of nodes at a specific location in the distributed ledger structure; and a smart contract (or a program having a wallet function) for creating customer setting information during update (saving and deletion) processing, the smart contract having a function for creating customer setting information including agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer, which has been acquired by the data update (saving and deletion) processing agreement information acquisition means linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means during update (saving and deletion) processing; a smart contract (or a program with a wallet function) for creating customer index information during update (saving and deletion) processing, which has a function of creating customer index information including information on the original file name and upload date of the customer's file data to be saved during update (saving and deletion) processing; a smart contract (or a server application) for recording customer index information during update (backup and deletion) processing, which has a function of encrypting the customer index information created by the smart contract (or a program having a wallet function) for creating customer index information during update (backup and deletion) processing and recording it in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means during the update (backup and deletion) processing, which erases each file data uploaded to the first temporary storage area after the server index information is encrypted and recorded in a node group at a specific location in the distributed ledger structure by a smart contract (or a server application) for recording server index information during the update (backup and deletion) processing; a customer data deletion instruction receiving means for receiving an instruction to delete data to be deleted from the update (saving and deleting) instruction means during update (saving and deleting) processing; a file data preservation point information deletion means for deleting information on preservation points associated with file data to be deleted, which is managed in a black box environment by the preservation point information management means for update (saving and deleting), and which is accepted by the customer data deletion instruction accepting means for update (saving and deleting); and The data update (saving and deletion) processing agreement information acquisition means a data update (saving and deletion) processing request instructing means for instructing a request for processing to update (saving and deletion) data to be updated (saved and deleted) for the customer via the first authenticator; a data update (saving and deletion) processing request instruction receiving means for receiving a request instruction for updating (saving and deleting) the data to be updated (saving and deleted) by the customer from the data update (saving and deletion) processing request instruction means; a data update (saving and deletion) processing request instruction receiving means for acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means when the data update (saving and deletion) processing request instruction receiving means receives a request instruction for updating (saving and deleting) data to be updated (saving and deleting) by the customer, and providing the information to an external first authenticator authentication system to request authentication of the first authenticator; a data updating (saving and deleting) first authenticated person ID information and key information receiving means for receiving the first authenticated person ID information and key information required for updating (saving and deleting) data from the first authenticated person information managing means when the first authenticated person is authenticated by the external first authenticated person authentication system; seventh information notifying means for notifying the second authenticator of information that the first authenticator has issued a request instruction for updating (saving and deleting) the data to be updated (saving and deleting) by the customer and information urging the second authenticator to issue an approval instruction for updating (saving and deleting) the data to be updated (saving and deleting) by the customer, when the first authenticator ID information and key information receiving means for data update (saving and deletion) has received the first authenticator ID information and key information necessary for updating (saving and deleting) the data; a data update (saving and deletion) processing approval instruction means for instructing approval of the update (saving and deletion) processing of the data to be updated (saved and deleted) by the customer via the second authenticator who has received the notification from the seventh information notification means; a data update (saving and deletion) processing approval instruction receiving means for receiving an approval instruction for updating (saving and deletion) the data to be updated (saving and deletion) by the customer from the data update (saving and deletion) processing approval instruction means; a data update (saving and deletion) processing approval instruction receiving second authenticator authentication requesting means for, when the data update (saving and deletion) processing approval instruction receiving means receives an approval instruction for updating (saving and deleting) processing of the data to be updated (saving and deletion) for the customer, acquiring second authenticator authentication information required for authenticating the second authenticator from the second authenticator information managing means, providing the second authenticator authentication information to an external second authenticator authentication system, and requesting authentication of the second authenticator; a data updating (saving and deleting) second authenticator ID information and key information receiving means for receiving the second authenticator ID information and key information required for updating (saving and deleting) data from the second authenticator information managing means when the second authenticator is authenticated by the external second authenticator authentication system; an eighth information notification means for notifying the first authenticator of information that the second authenticator has given an approval instruction for the update (saving and deletion) process of the data to be updated (saving and deletion) of the customer and information that prompts the first authenticator to give a request instruction for the update (saving and deletion) process of the data to be updated (saving and deletion) of the customer, when the second authenticator ID information and key information receiving means for data update (saving and deletion) has received the second authenticator ID information and key information necessary for data update (saving and deletion); a data update (saving and deletion) processing request instruction means for instructing a request for processing to update (saving and deletion) data to be updated (saved and deleted) for the customer via the first authenticated person who has received the notification from the eighth information notification means; a data update (saving and deletion) processing request instruction receiving means for receiving a request instruction for updating (saving and deleting) the data to be updated (saving and deleted) by the customer from the data update (saving and deletion) processing request instruction means; a data update (saving and deletion) processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer, using the first authenticator ID information and key information required for the data update (saving and deletion) received by the first authenticator ID information and key information receiving means for data update (saving and deletion) and the second authenticator ID information and key information required for the data update (saving and deletion) received by the second authenticator ID information and key information receiving means for data update (saving and deletion), when the data update (saving and deletion) processing request instruction receiving means receives an instruction to request the processing of updating (saving and deletion) of the data to be updated (saving and deletion) for the customer; have 2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.
102. The second file data real-time update (saving and deletion) system comprises a user-side second file data real-time update (saving and deletion) system that operates on the side of a user (customer or data manager) who desires to update (saving and deleting) file data, and a digital asset guard service operator-side second file data real-time update (saving and deletion) system that operates on the side of the digital asset guard service operator, The user-side second file data real-time update (saving and deletion) system comprises the data update (saving and deletion) processing agreement information acquisition means, the customer data update (saving and deletion) instruction means, a program (or smart contract) having a plurality of the encryption and division algorithms, an encryption and division algorithm selection acceptance means for the update (saving and deletion) processing, a customer data evacuation instruction acceptance means for the update (saving and deletion) processing, a file data encryption and division means for the update (saving and deletion) processing, an upload means for the update (saving and deletion) processing, a file data conservation point association and sorting means for the update (saving and deletion) processing, and a conservation point information management means for the update (saving and deletion) processing, The second file data real-time update (saving and deletion) system on the digital asset guard service operator side includes a smart contract (or server application) for allocating distributed file management groups during the update (saving and deletion) processing, a smart contract (or server application) for distributed recording during the update (saving and deletion) processing, a smart contract (or server application) for creating server index information during the update (saving and deletion) processing, a smart contract (or server application) for recording server index information during the update (saving and deletion) processing, a first data erasure means during the update (saving and deletion) processing, a customer data deletion instruction acceptance means during the update (saving and deletion) processing, and a file data preservation point information deletion means during the update (saving and deletion) processing; have The real-time saving and restoring type digital asset guard service providing system according to claim 101.
103. A real-time evacuation and restoration type digital asset guard service provision system for guarding digital assets from high-level cyber attacks, constructed with a distributed ledger in distributed ledger technology such as blockchain, and a smart contract or server application for performing predetermined processing using the data managed in the distributed ledger, or a system for handling data that is difficult to manage through systems, such as personal information, primarily on-chain in two configurations: one in which the information is managed by a company, and one in which the information is managed by an individual, and which serves as a base system for managing the personal information directly on-chain in both configurations, or for separating the personal information section based on the information and utilizing it as personal attribute information for big data analysis, etc., At least one distributed ledger structure consisting of multiple chains that may include distributed ledgers, public blockchains, etc., and is primarily a private or consortium type closed blockchain, constructed with multiple planets (a unit that combines blockchains, distributed file management functions, etc., and forms one unit that constitutes a system for providing services that implement distributed smart contracts, server applications, etc.) that are made up of a group of nodes that combine nodes from multiple locations in different regions around the world; a first user information management means for managing first user ID information required for saving and restoring data of a first user who is one of a customer and a data manager who manages the customer's data; a second user information management means for managing second user ID information required for saving and restoring data of a second user who is the other of the customer and the data manager who manages the customer's data; A file data real-time evacuation system, Real-time file data recovery system and Each node in each location connects to recording devices in multiple locations around the world via a network to create a distributed file management group. The file data real-time saving system includes: a data evacuation processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding the evacuation processing of the data to be evacuated for the customer; a customer data evacuation instruction means for instructing the evacuation of the customer's data to be evacuated based on the agreement information when the data evacuation processing agreement information acquisition means acquires agreement information between the first user and the second user regarding the evacuation processing of the customer's data to be evacuated; A program (or smart contract) with multiple encryption and division algorithms that have different methods for encrypting and dividing file data, an encryption / division algorithm selection receiving means for receiving a selection of a program (or a smart contract) having a predetermined encryption / division algorithm based on the agreement information between the first user and the second user (or a first parameter specified by the customer who desires to evacuate file data, which is included in the agreement information) regarding the evacuation process of the data to be evacuated by the customer, acquired by the data evacuation process agreement information acquisition means; a customer data evacuation instruction receiving means for receiving an instruction to evacuate data to be evacuated from the customer data evacuation instruction means; a file data encryption / division means for encrypting and dividing the customer data to be saved, which has been accepted by the customer data saving instruction accepting means, into a plurality of file data using a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection accepting means; an uploading means for uploading each of the file data encrypted and divided by the file data encryption / division means to a first temporary storage area; a file data security point associating and sorting means for associating each of the file data encrypted and divided by the file data encryption and division means and uploaded to the first temporary storage area by the upload means with one of at least two security points for managing the file data; a security point information management means for managing, in a black box environment, information on the security points for managing the file data sorted by the file data security point association sorting means; a distributed file management group allocation means or a smart contract (or server application) for distributed file management group allocation, which is provided in each planet and has a function of allocating the file data associated with the information of the conservation point managed in a black box environment by the conservation point information management means, which is sorted by the file data conservation point association sorting means based on the agreement information between the first user and the second user (or the first parameter included in the agreement information and the second parameter specified by the digital asset guard service operator) regarding the evacuation process of the data to be evacuated by the customer, which is set by the digital asset guard service operator according to conditions specified by the customer, to a plurality of distributed file management groups, which are configured by the digital asset guard service operator according to conditions specified by the customer and which are constituted by nodes at each base constituting the planet corresponding to the conservation point and recording devices at multiple bases connected to the nodes at each base via a network; a distributed recording means or a smart contract for distributed recording (or a server application) that is provided on each planet and has a function of distributing and recording each of the file data associated with the information of each of the conservation points that has been sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means, which has been sorted by the distributed file management group sorting means or the smart contract for distributed file management group sorting (or a server application), in each of the base nodes belonging to the corresponding distributed file management group and in recording devices at multiple bases that are connected to the base nodes via a network; a smart contract (or server application) for creating and recording system setting information that has the function of creating system setting information including terminal information (information identifying the other party, such as a fixed IP address) for uploading to the first temporary storage area using the upload means, the number of a predetermined processing means or smart contract (or server application) that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and information on the file server groups (in the node at a predetermined base and in recording devices at multiple bases that are networked to the node at that base) that make up the distributed file management group, encrypting the information, and recording it in the node group at a specific base in the distributed ledger structure; a smart contract (or server application) for creating server index information having: key information using the first user ID information and the second user ID information required for data evacuation, which are included in the agreement information between the first user and the second user regarding the evacuation process of the data to be evacuated for the customer acquired by the data evacuation process agreement information acquisition means; file name information of each of the file data that is distributed and recorded by each of the distributed recording means or the distributed recording smart contract (or server application) and that is linked to the information of the conservation point that is sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means; and configuration information of each of the distributed file management groups to which each of the file data is allocated; a server index information recording smart contract (or server application) that has a function of encrypting the server index information created by the server index information creation smart contract (or server application) and recording it in a node group at a specific location in the distributed ledger structure; and a smart contract (or a program having a wallet function) for creating customer setting information that has a function of creating customer setting information that includes agreement information between the first user and the second user (or setting information of the first parameter included in the agreement information) regarding the evacuation process of the data to be evacuated for the customer, which is acquired by the data evacuation process agreement information acquisition means, and that is linked to a program (or smart contract) that includes the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means; A smart contract (or a program with a wallet function) for creating customer index information that has a function to create customer index information containing information on the original file name and upload date of the customer's file data to be saved; a smart contract (or a server application) for recording customer index information, which has a function of encrypting the customer index information created by the smart contract for creating customer index information (or a program having a wallet function) and recording the encrypted customer index information in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means for erasing each file data uploaded to the first temporary storage area after the server index information is encrypted and recorded in a node group at a specific location in the distributed ledger structure by the server index information recording smart contract (or server application); and The data saving process agreement information acquisition means a data evacuation processing request instruction means for issuing an instruction via the first user to request evacuation processing of the data to be evacuated by the client; a data evacuation processing request instruction receiving means for receiving a request instruction for evacuation processing of the data to be evacuated from the data evacuation processing request instruction means; a data saving first user ID information receiving means for receiving the first user ID information required for saving data from the first user information management means when the data saving process request instruction receiving means receives a request instruction for saving data to be saved by the customer; a first information notification means for notifying the second user, when the first user ID information receiving means for data evacuation receives the first user ID information required for data evacuation, of information that the first user has issued a request instruction for evacuation processing of the data to be evacuated for the customer and information urging the second user to issue an approval instruction for the evacuation processing of the data to be evacuated for the customer; a data evacuation process approval instruction means for instructing approval of the evacuation process of the data to be evacuated for the customer via the second user who has received the notification from the first information notification means; a data evacuation processing approval instruction receiving means for receiving an approval instruction for the evacuation processing of the data to be evacuated from the data evacuation processing approval instruction means; a data evacuation second user ID information receiving means for receiving the second user ID information required for data evacuation from the second user information management means when the data evacuation processing approval instruction receiving means receives an approval instruction for the evacuation processing of the data to be evacuated for the customer; a second information notification means for notifying the first user, when the second user ID information receiving means for data evacuation receives the second user ID information necessary for data evacuation, of information that the second user has given an approval instruction for the evacuation process of the data to be evacuated for the customer and information that urges the first user to give an instruction to request the evacuation process of the data to be evacuated for the customer; a data evacuation processing request instruction means for instructing a request for evacuation processing of the data to be evacuated for the client via the first user who has received the notification from the second information notification means; a data evacuation processing request instruction receiving means for receiving a request instruction for evacuation processing of the data to be evacuated from the data evacuation processing request instruction means; a data evacuation processing agreement information creation means for creating agreement information between the first user and the second user regarding the evacuation processing of the data to be evacuated for the customer, using the first user ID information required for data evacuation and key information managed by the first user, which are received by the first user ID information receiving means for data evacuation, and the second user ID information required for data evacuation and key information managed by the second user, which are received by the second user ID information receiving means for data evacuation; and The file data real-time restoration system includes: a data restoration processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding restoration processing of the data to be restored for the customer; a customer data restoration instruction means for instructing the restoration of the data to be restored for the customer based on the agreement information when the data restoration processing agreement information acquisition means acquires agreement information between the first user and the second user regarding the restoration processing of the data to be restored for the customer; A program (or smart contract) having a plurality of decryption and combination algorithms with different methods for decrypting and combining file data, each of which is linked to a program (or smart contract) having the encryption and division algorithm; customer data restoration instruction receiving means for receiving an instruction to restore data to be restored for the customer from the customer data restoration instruction means; The data restoration instruction receiving means is provided for each planet, and for each group of file data linked to the information of each of the security points managed in a black box environment by the security point information management means in the planet corresponding to the security point, the data restoration instruction receiving means receives, for each group of file data linked to the information of each of the security points managed in a black box environment by the security point information management means, key information formed using the first user ID information and the second user ID information required for data restoration in the agreement information between the first user and the second user for the restoration process of the data to be restored for the customer acquired by the data restoration process agreement information acquisition means, which is linked to the file data to be extracted and accepted by the customer data restoration instruction accepting means (or the first parameter included in the key information, or a first composite parameter (composed of a pair of a first decryption parameter designated by the customer and managed offline and a first encryption parameter automatically generated from the first decryption parameter) and the second parameter a smart contract (or server application) for extracting encrypted server index information that has a function of extracting encrypted server index information (recorded in a group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on a meter or (a second composite parameter that is a pair of a second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) designated by the digital asset guard service operator and managed offline, and a second encryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter); a server index information decryption smart contract (or server application) that is provided in each planet and has a function of decrypting the encrypted server index information extracted by the encrypted server index information extraction smart contract (or server application) for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point; an encrypted and divided file data extraction means or a smart contract (or server application) for extracting encrypted and divided file data, which is provided in each planet and has a function of extracting, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point, from any of the nodes at each base belonging to each of the distributed file management groups and any of the recording devices at each of the multiple bases connected to the nodes at each of the multiple bases via a network, each of the encrypted and divided file data being allocated to each of the distributed file management groups by the distributed file management group allocation means or the smart contract (or server application) for allocating the file data using server index information decrypted by the smart contract (or server application) for decrypting server index information, and distributed and recorded in each of the nodes at each of the multiple bases belonging to each of the distributed file management groups and any of the recording devices at each of the multiple bases connected to the nodes at each of the multiple bases via a network; a downloading means provided in each planet, which downloads, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point, each of the encrypted and divided file data extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data, into a second temporary storage area; a file data restoration means provided in each planet, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point, for which the file data is extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data and downloaded to the second temporary storage area by the download means, and which decrypts and combines all of the file data linked across the information of all of the conservation points in an encrypted and divided state into one file data using a program (or smart contract) having the decryption and combination algorithm linked to a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means, thereby restoring the data of the client before evacuation; a second data erasing means for erasing each of the encrypted and divided file data downloaded to the second temporary storage area after the file data restoration means has restored the data of the client to the state before the backup; and The data restoration processing agreement information acquisition means a data restoration processing request instruction means for instructing, via the first user, a request for restoration processing of the data to be restored for the customer; a data restoration processing request instruction receiving means for receiving a request instruction for restoration processing of the data to be restored from the data restoration processing request instruction means; a first user ID information receiving means for data restoration that receives the first user ID information required for data restoration from the first user information management means when the data restoration processing request instruction receiving means receives a request instruction for restoration processing of the data to be restored for the customer; a third information notification means for notifying the second user, when the first user ID information receiving means for data restoration receives the first user ID information necessary for data restoration, of information that the first user has issued a request instruction for restoration processing of the data to be restored for the customer and information that urges the second user to issue an approval instruction for the restoration processing of the data to be restored for the customer; a data restoration process approval instruction means for instructing approval of the restoration process of the data to be restored of the customer via the second user who has received the notification from the third information notification means; a data restoration processing approval instruction receiving means for receiving an approval instruction for the restoration processing of the data to be restored for the customer from the data restoration processing approval instruction means; a data restoration second user ID information receiving means for receiving the second user ID information required for restoring the data from the second user information management means when the data restoration processing approval instruction receiving means receives an approval instruction for the restoration processing of the data to be restored for the customer; a fourth information notification means for notifying the first user, when the second user ID information receiving means for data restoration receives the second user ID information necessary for data restoration, of information that the second user has given an approval instruction for the restoration process of the data to be restored for the customer and information that urges the first user to give an instruction to request the restoration process of the data to be restored for the customer; a data restoration processing request instruction means for instructing, via the first user who has received the notification from the fourth information notification means, to request restoration processing of the data to be restored for the customer; a data restoration processing request instruction receiving means for receiving a request instruction for restoration processing of the data to be restored from the data restoration processing request instruction means; a data restoration processing agreement information creating means for creating agreement information between the first user and the second user regarding the restoration processing of the data to be restored for the customer, using the first user ID information required for data restoration and key information managed by the first user, which are received by the first user ID information receiving means for data restoration, and the second user ID information required for data restoration and key information managed by the second user, which are received by the second user ID information receiving means for data restoration; have A real-time evacuation and restoration type digital asset guard service providing system.
104. The file data real-time saving system comprises a user-side file data real-time saving system that operates on the side of a user (customer or data manager) who desires to save file data, and a digital asset guard service operator-side file data real-time saving system that operates on the side of the digital asset guard service operator, The user-side file data real-time saving system comprises the data saving processing agreement information acquisition means, the customer data saving instruction means, a program (or smart contract) having a plurality of the encryption / division algorithms, the encryption / division algorithm selection acceptance means, the customer data saving instruction acceptance means, the file data encryption / division means, the upload means, the file data conservation point association sorting means, and the conservation point information management means, The digital asset guard service operator-side file data real-time backup system comprises the distributed file management group allocation means or the distributed file management group allocation smart contract (or server application), the distributed recording means or the distributed recording smart contract (or server application), the server index information creation smart contract (or server application), the server index information recording smart contract (or server application), and the first data erasure means, The file data real-time restoration system comprises a user-side file data real-time restoration system that operates on the side of a user (customer or data manager) who desires to restore saved file data, and a digital asset guard service operator-side file data real-time restoration system that operates on the side of the digital asset guard service operator, the user-side file data real-time restoration system comprises the data restoration processing agreement information acquisition means, the customer data restoration instruction means, a program (or smart contract) having a plurality of the decryption and combination algorithms, the download means, the file data restoration means, and the second data erasure means; The digital asset guard service administrator-side file data real-time restoration system includes the customer data restoration instruction receiving means, the encrypted server index information extraction smart contract (or server application), the server index information decryption smart contract (or server application), and the encrypted and divided file data extraction means or the encrypted and divided file data extraction smart contract (or server application). The real-time saving and restoring type digital asset guard service providing system according to claim 103.
105. It has a file data real-time deletion system, The file data real-time deletion system includes: a data deletion processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding the deletion processing of the data to be deleted for the customer; a customer data deletion instruction means for instructing the deletion of the data to be deleted for the customer based on the agreement information when the data deletion processing agreement information acquisition means acquires agreement information between the first user and the second user regarding the deletion processing of the data to be deleted for the customer; a customer data deletion instruction receiving means for receiving an instruction to delete data to be deleted from the customer data deletion instruction means; The data deletion instruction receiving means is provided for each planet, and for each group of file data linked to the information of each of the security points managed in a black box environment by the security point information management means in the planet corresponding to the security point, the data deletion instruction receiving means receives, for each group of file data linked to the information of each of the security points managed in a black box environment by the security point information management means, key information (or the first parameter included in the key information or a first composite parameter (composed of a pair of a first decryption parameter designated by the customer and managed offline and a first encryption parameter automatically generated from the first decryption parameter) using the first user ID information and the second user ID information required for data deletion in the agreement information between the first user and the second user regarding the deletion process of the data to be deleted of the customer acquired by the data deletion process agreement information acquisition means, which is linked to the file data to be deleted accepted by the customer data deletion instruction accepting means, and a smart contract (or server application) for extracting encrypted server index information to be deleted, which has a function of extracting encrypted server index information (recorded in a group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on the data or (a second composite parameter consisting of a pair of a second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) designated by the digital asset guard service operator and managed offline, and a second encryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter); a smart contract (or server application) for decrypting server index information to be deleted, which is provided in each planet and has a function of decrypting the encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information to be deleted, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point; a smart contract (or server application) for deleting encrypted and divided file data that is provided in each planet and has a function of deleting, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point, each of the encrypted and divided file data to be deleted, which has been allocated to each of the distributed file management groups by the distributed file management group allocation means using server index information decrypted by the smart contract (or server application) for decrypting server index information to be deleted, and which has been distributed and recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in recording devices of multiple bases connected to the base nodes via a network; The data deletion processing agreement information acquisition means a data deletion process request instruction means for issuing an instruction to request deletion of data to be deleted from the customer via the first user; a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of the data to be deleted from the data deletion processing request instruction means; a data deletion first user ID information receiving means for receiving the first user ID information required for deleting data from the first user information management means when the data deletion processing request instruction receiving means receives a request instruction for deleting data to be deleted from the customer; a fifth information notification means for notifying the second user of information that the first user has issued a request instruction for deletion of the data to be deleted of the customer and information urging the second user to issue an approval instruction for the deletion of the data to be deleted of the customer, when the first user ID information receiving means for data deletion has received the first user ID information necessary for data deletion; a data deletion process approval instruction means for instructing approval of the deletion process of the data to be deleted of the customer via the second user who has received the notification from the fifth information notification means; a data deletion processing approval instruction receiving means for receiving an approval instruction for the deletion processing of the data to be deleted from the data deletion processing approval instruction means; a data deletion second user ID information receiving means for receiving the second user ID information required for deleting data from the second user information management means when the data deletion processing approval instruction receiving means receives an approval instruction for the deletion processing of the data to be deleted by the customer; a sixth information notification means for notifying the first user, when the second user ID information receiving means for data deletion receives the second user ID information necessary for deleting data, of information that the second user has given an approval instruction for the deletion process of the data to be deleted of the customer and information that urges the first user to give an instruction to request the deletion process of the data to be deleted of the customer; a data deletion processing request instruction means for instructing, via the first user who has received the notification from the sixth information notification means, to request a deletion processing of the data to be deleted of the customer; a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of the data to be deleted from the data deletion processing request instruction means; a data deletion processing agreement information creation means for creating agreement information between the first user and the second user regarding the deletion processing of the data to be deleted for the customer, using the first user ID information required for data deletion and key information managed by the first user, which are received by the first user ID information receiving means for data deletion, and the second user ID information required for data deletion and key information managed by the second user, which are received by the second user ID information receiving means for data deletion, when the data deletion processing request instruction receiving means receives a request instruction for deletion processing of the data to be deleted for the customer; have The real-time saving and restoring type digital asset guard service providing system according to claim 103.
106. The file data real-time deletion system comprises a user-side file data real-time deletion system that operates on the side of a user (customer or data manager) who desires to delete file data, and a digital asset guard service operator-side file data real-time deletion system that operates on the side of the digital asset guard service operator, The user-side file data real-time deletion system comprises the data deletion processing agreement information acquisition means and the customer data deletion instruction means, The digital asset guard service administrator-side file data real-time deletion system includes the customer data deletion instruction receiving means, a smart contract (or server application) for extracting the encrypted server index information to be deleted, a smart contract (or server application) for decrypting the server index information to be deleted, and a smart contract (or server application) for deleting the encrypted and divided file data. The real-time saving and restoring type digital asset guard service providing system according to claim 105.
107. It has a file data real-time update (backup and deletion) system, The file data real-time update (saving and deleting) system includes: a data update (saving and deletion) processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer between the first user and the second user; a customer data update (saving and deletion) instruction means for instructing the updating (saving and deletion) of the data to be updated (saved and deleted) for the customer based on the agreement information when the data update (saving and deletion) processing agreement information acquisition means acquires agreement information between the first user and the second user regarding the updating (saved and deleted) processing of the data to be updated (saved and deleted) for the customer; A program (or smart contract) having a plurality of encryption and division algorithms that have different encryption and division processing methods for file data; an update (saving and deletion) processing encryption / division algorithm selection receiving means for receiving a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on agreement information between the first user and the second user regarding the saving processing of the data to be saved by the customer, which has been acquired by the data update (saving and deletion) processing agreement information acquisition means; a customer data evacuation instruction receiving means for receiving an instruction to evacuate data to be evacuated from the customer data update (evacuation and deletion) instruction means; an update (saving and deletion) processing time file data encryption / division means for encrypting and dividing the customer data to be saved, which has been accepted by the update (saving and deletion) processing time customer data saving instruction accepting means, into a plurality of file data using a program (or smart contract) having the encryption / division algorithm accepted by the update (saving and deletion) processing time encryption / division algorithm selection accepting means; an update (saving and deleting) processing time uploading means for uploading each of the file data encrypted and divided into a plurality of pieces by the update (saving and deleting) processing time file data encryption / division means to a first temporary storage area; an update (saving and deletion) processing time file data conservation point associating and sorting means for associating each of the file data encrypted and divided into a plurality of pieces by the update (saving and deletion) processing time file data encryption / division means and uploaded to the first temporary storage area by the update (saving and deletion) processing time upload means with one of the conservation points corresponding to at least two planets for managing the file data; an update (saving and deletion) processing time preservation point information management means for managing, in a black box environment, information on the preservation points for managing the file data sorted by the update (saving and deletion) processing time file data preservation point association sorting means; an update (evacuation and deletion) processing time distributed file management group allocation means provided in each planet, which has the function of allocating each of the file data associated with the information of the conservation points managed in a black box environment by the update (evacuation and deletion) processing time conservation point information management means, which is sorted by the update (evacuation and deletion) processing time file data conservation point matching sorting means based on agreement information between the first user and the second user (or a first parameter included in the agreement information and a second parameter specified by the digital asset guard service operations manager) regarding the evacuation processing of the data to be evacuated by the customer, acquired by the data update (evacuation and deletion) processing agreement information acquisition means, to a plurality of the distributed file management groups, which are set by the digital asset guard service operations manager according to conditions specified by the customer and are constituted by the nodes of each base constituting the planet corresponding to the conservation points and recording devices of multiple bases connected to the nodes of the bases via a network; an update (saving and deletion) processing time distributed recording means provided in each planet, which has a function of distributively recording the file data associated with the information of each of the conservation points that has been sorted by the update (saving and deletion) processing time file data conservation point association sorting means and managed in a black box environment by the update (saving and deletion) processing time conservation point information management means, in the nodes of each base belonging to the corresponding distributed file management group and in recording devices of multiple bases connected to the base nodes via a network; a smart contract (or server application) for creating and recording system setting information during update (backup and deletion) processing, which has the function of creating system setting information including terminal information (information identifying the other party, such as a fixed IP address) for uploading to the first temporary storage area using the upload means during update (backup and deletion) processing, the number of the predetermined processing means that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and information on the file server groups (in the node at a predetermined base and in recording devices at multiple bases that are networked to the node at that base) that make up the distributed file management group, encrypting the information, and recording it in the node group at a specific base in the distributed ledger structure; and a smart contract (or server application) for creating server index information during update (saving and deletion) processing, the smart contract having a function for creating server index information including: key information using the first user ID information and the second user ID information required for data evacuation, which are included in the agreement information between the first user and the second user regarding the evacuation processing of the data to be evacuated for the customer acquired by the data update (saving and deletion) processing agreement information acquisition means; file name information of each of the file data linked to the information of the conservation point sorted by the file data conservation point association sorting means during update (saving and deletion) processing and managed in a black box environment by the conservation point information management means during update (saving and deletion) processing; and configuration information of each of the distributed file management groups to which each of the file data is allocated; a smart contract (or server application) for recording server index information during update (backup and deletion) processing, which has a function of encrypting the server index information created by the smart contract (or server application) for creating server index information during update (backup and deletion) processing and recording it in a group of nodes at a specific location in the distributed ledger structure; and a smart contract (or a program having a wallet function) for creating customer setting information during update (saving and deletion) processing, the smart contract having a function for creating customer setting information including agreement information between the first user and the second user regarding the evacuation processing of the data to be evacuated for the customer, which has been acquired by the data update (saving and deletion) processing agreement information acquisition means linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means during update (saving and deletion) processing; a smart contract (or a program with a wallet function) for creating customer index information during update (saving and deletion) processing, which has a function of creating customer index information including information on the original file name and upload date of the customer's file data to be saved during update (saving and deletion) processing; a smart contract (or a server application) for recording customer index information during update (backup and deletion) processing, which has a function of encrypting the customer index information created by the smart contract (or a program having a wallet function) for creating customer index information during update (backup and deletion) processing and recording it in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means during the update (backup and deletion) processing, which erases each file data uploaded to the first temporary storage area after the server index information is encrypted and recorded in a node group at a specific location in the distributed ledger structure by a smart contract (or a server application) for recording server index information during the update (backup and deletion) processing; a customer data deletion instruction receiving means for receiving an instruction to delete data to be deleted from the update (saving and deletion) instruction means during update (saving and deletion) processing; and a data update (saving and deletion) processing agreement information acquisition means for acquiring a first composite parameter (a first parameter included in the key information or a first composite parameter (a first decryption parameter designated by the customer and managed offline, and a first encryption parameter automatically generated from the first decryption parameter, as a pair)) for each group of file data linked to information of each of the security points managed in a black box environment by the update (saving and deletion) processing time security point information management means in the planet corresponding to the security point. a smart contract (or server application) for extracting encrypted server index information to be deleted during update (backup and deletion) processing, which has a function of extracting encrypted server index information (recorded in a group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on the second parameter or a second composite parameter (composed of a pair of a second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) designated and managed offline by the digital asset guard service operator), and a second encryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter); a smart contract (or server application) for decrypting server index information to be deleted during update (saving and deletion) processing, which is provided in each planet and has a function of decrypting encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information to be deleted during update (saving and deletion) processing, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means during update (saving and deletion) processing in the planet corresponding to the conservation point; a smart contract (or server application) for deleting encrypted and divided file data during update (evacuation and deletion) processing, which is provided in each planet and has a function of deleting, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means during update (evacuation and deletion) processing, from each of the base nodes belonging to each of the distributed file management groups and from all of the base node storage devices connected to the base node via a network, each of the encrypted and divided file data to be deleted, which has been allocated to each of the distributed file management groups by the distributed file management group allocation means using server index information decrypted by the smart contract (or server application) for decrypting server index information to be deleted during update (evacuation and deletion) processing, and which has been distributed and recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in multiple base node storage devices connected to the base node via a network; The data update (saving and deletion) processing agreement information acquisition means a data update (saving and deletion) processing request instruction means for instructing, via the first user, a request for processing to update (saving and deletion) data to be updated (saved and deleted) by the customer; a data update (saving and deletion) processing request instruction receiving means for receiving a request instruction for updating (saving and deleting) the data to be updated (saving and deleted) by the customer from the data update (saving and deletion) processing request instruction means; a first user ID information receiving means for data update (saving and deletion) that receives the first user ID information required for updating (saving and deleting) data from the first user information management means when the data update (saving and deletion) processing request instruction receiving means receives a request instruction for updating (saving and deleting) data of the customer; a seventh information notification means for notifying the second user, when the first user ID information receiving means for data update (saving and deletion) receives the first user ID information necessary for updating (saving and deleting) data, of information that the first user has issued a request instruction for updating (saving and deleting) the data to be updated (saving and deletion) for the customer, and information urging the second user to issue an approval instruction for updating (saving and deleting) the data to be updated (saving and deletion) for the customer; a data update (saving and deletion) processing approval instruction means for instructing approval of the update (saving and deletion) processing of the data to be updated (saved and deleted) by the customer via the second user who has received the notification from the seventh information notification means; a data update (saving and deletion) processing approval instruction receiving means for receiving an approval instruction for updating (saving and deletion) the data to be updated (saving and deletion) by the customer from the data update (saving and deletion) processing approval instruction means; a data update (saving and deletion) second user ID information receiving means for receiving the second user ID information required for updating (saving and deleting) data from the second user information management means when the data update (saving and deletion) processing approval instruction receiving means receives an approval instruction for updating (saving and deleting) data to be updated (saving and deleted) by the customer; an eighth information notification means for notifying the first user, when the second user ID information receiving means for data update (saving and deletion) receives the second user ID information necessary for updating (saving and deleting) data, of information that the second user has given an approval instruction for the update (saving and deletion) process of the data to be updated (saving and deletion) by the customer and information that urges the first user to give a request instruction for the update (saving and deletion) process of the data to be updated (saving and deletion) by the customer; a data update (saving and deletion) processing request instruction means for instructing, via the first user who has received the notification from the eighth information notification means, a request for processing to update (saving and deletion) the data to be updated (saved and deleted) for the customer; a data update (saving and deletion) processing request instruction receiving means for receiving a request instruction for updating (saving and deleting) the data to be updated (saving and deleted) by the customer from the data update (saving and deletion) processing request instruction means; a data update (saving and deletion) processing agreement information creating means for creating agreement information between the first user and the second user regarding the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer, using the first user ID information required for the data update (saving and deletion) and key information managed by the first user and the second user ID information required for the data update (saving and deletion) and received by the first user ID information receiving means for data update (saving and deletion), and key information managed by the second user, when the data update (saving and deletion) processing request instruction receiving means receives an instruction to request the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer; have The real-time saving and restoring type digital asset guard service providing system according to claim 103.
108. The file data real-time update (saving and deletion) system comprises a user-side file data real-time update (saving and deletion) system that operates on the side of a user (customer or data manager) who desires to update (saving and deleting) file data, and a digital asset guard service operator-side file data real-time update (saving and deletion) system that operates on the side of the digital asset guard service operator, The user-side file data real-time update (saving and deletion) system comprises the data update (saving and deletion) processing agreement information acquisition means, the customer data update (saving and deletion) instruction means, a program (or smart contract) having a plurality of the encryption and division algorithms, an encryption and division algorithm selection acceptance means for the update (saving and deletion) processing, a customer data evacuation instruction acceptance means for the update (saving and deletion) processing, a file data encryption and division means for the update (saving and deletion) processing, an upload means for the update (saving and deletion) processing, a file data conservation point association and sorting means for the update (saving and deletion) processing, and a conservation point information management means for the update (saving and deletion) processing, The digital asset guard service operator-side file data real-time update (saving and deletion) system includes: a distributed file management group allocation means during the update (saving and deletion) processing; a distributed recording means during the update (saving and deletion) processing; a smart contract (or server application) for creating server index information during the update (saving and deletion) processing; a smart contract (or server application) for recording server index information during the update (saving and deletion) processing; a first data erasure means during the update (saving and deletion) processing; a customer data deletion instruction receiving means during the update (saving and deletion) processing; a smart contract (or server application) for extracting encrypted server index information to be deleted during the update (saving and deletion) processing; a smart contract (or server application) for decrypting server index information to be deleted during the update (saving and deletion) processing; and a smart contract (or server application) for deleting encrypted and divided file data during the update (saving and deletion) processing. The real-time saving and restoring type digital asset guard service providing system according to claim 107.
109. a second file data real-time deletion system; The second file data real-time deletion system includes: a data deletion processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding the deletion processing of the data to be deleted for the customer; a customer data deletion instruction means for instructing the deletion of the data to be deleted for the customer based on the agreement information when the data deletion processing agreement information acquisition means acquires agreement information between the first user and the second user regarding the deletion processing of the data to be deleted for the customer; a customer data deletion instruction receiving means for receiving an instruction to delete data to be deleted from the customer data deletion instruction means; a file data preservation point information deletion means for deleting information on the preservation points associated with the file data to be deleted that is received by the customer data deletion instruction receiving means and that is managed in a black box environment by the preservation point information management means; and The data deletion processing agreement information acquisition means a data deletion process request instruction means for issuing an instruction to request deletion of data to be deleted from the customer via the first user; a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of the data to be deleted from the data deletion processing request instruction means; a data deletion first user ID information receiving means for receiving the first user ID information required for deleting data from the first user information management means when the data deletion processing request instruction receiving means receives a request instruction for deleting data to be deleted from the customer; a fifth information notification means for notifying the second user of information that the first user has issued a request instruction for deletion of the data to be deleted of the customer and information urging the second user to issue an approval instruction for the deletion of the data to be deleted of the customer, when the first user ID information receiving means for data deletion has received the first user ID information necessary for data deletion; a data deletion process approval instruction means for instructing approval of the deletion process of the data to be deleted of the customer via the second user who has received the notification from the fifth information notification means; a data deletion processing approval instruction receiving means for receiving an approval instruction for the deletion processing of the data to be deleted from the data deletion processing approval instruction means; a data deletion second user ID information receiving means for receiving the second user ID information required for deleting data from the second user information management means when the data deletion processing approval instruction receiving means receives an approval instruction for the deletion processing of the data to be deleted by the customer; a sixth information notification means for notifying the first user, when the second user ID information receiving means for data deletion receives the second user ID information necessary for deleting data, of information that the second user has given an approval instruction for the deletion process of the data to be deleted of the customer and information that urges the first user to give an instruction to request the deletion process of the data to be deleted of the customer; a data deletion processing request instruction means for instructing, via the first user who has received the notification from the sixth information notification means, to request a deletion processing of the data to be deleted of the customer; a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of the data to be deleted from the data deletion processing request instruction means; a data deletion processing agreement information creation means for creating agreement information between the first user and the second user regarding the deletion processing of the data to be deleted for the customer, using the first user ID information required for data deletion and key information managed by the first user, which are received by the first user ID information receiving means for data deletion, and the second user ID information required for data deletion and key information managed by the second user, which are received by the second user ID information receiving means for data deletion, when the data deletion processing request instruction receiving means receives a request instruction for deletion processing of the data to be deleted for the customer; have The real-time saving and restoring type digital asset guard service providing system according to claim 103.
110. The second file data real-time deletion system comprises a user-side second file data real-time deletion system that operates on the side of a user (customer and data manager) who desires to delete file data, and a digital asset guard service operator-side second file data real-time deletion system that operates on the side of the digital asset guard service operator- the user-side second file data real-time deletion system includes the data deletion processing agreement information acquisition means and the customer data deletion instruction means, The second file data real-time deletion system on the digital asset guard service operator side includes the customer data deletion instruction receiving means and the file data preservation point information deletion means. The real-time saving and restoring type digital asset guard service providing system according to claim 109.
111. A second file data real-time update (saving and deleting) system is provided, The second file data real-time update (saving and deleting) system comprises: a data update (saving and deletion) processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer between the first user and the second user; a customer data update (saving and deletion) instruction means for instructing the updating (saving and deletion) of the data to be updated (saved and deleted) for the customer based on the agreement information when the data update (saving and deletion) processing agreement information acquisition means acquires agreement information between the first user and the second user regarding the updating (saved and deleted) processing of the data to be updated (saved and deleted) for the customer; A program (or smart contract) having a plurality of encryption and division algorithms that have different encryption and division processing methods for file data; an update (saving and deletion) processing encryption / division algorithm selection receiving means for receiving a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on agreement information between the first user and the second user regarding the saving processing of the data to be saved by the customer, which has been acquired by the data update (saving and deletion) processing agreement information acquisition means; a customer data evacuation instruction receiving means for receiving an instruction to evacuate data to be evacuated from the customer data update (evacuation and deletion) instruction means; an update (saving and deletion) processing time file data encryption / division means for encrypting and dividing the customer data to be saved, which has been accepted by the update (saving and deletion) processing time customer data saving instruction accepting means, into a plurality of file data using a program (or smart contract) having the encryption / division algorithm accepted by the update (saving and deletion) processing time encryption / division algorithm selection accepting means; an update (saving and deleting) processing time uploading means for uploading each of the file data encrypted and divided into a plurality of pieces by the update (saving and deleting) processing time file data encryption / division means to a first temporary storage area; an update (saving and deletion) processing time file data conservation point associating and sorting means for associating each of the file data encrypted and divided into a plurality of pieces by the update (saving and deletion) processing time file data encryption / division means and uploaded to the first temporary storage area by the update (saving and deletion) processing time upload means with one of the conservation points corresponding to at least two planets for managing the file data; an update (saving and deletion) processing time preservation point information management means for managing, in a black box environment, information on the preservation points for managing the file data sorted by the update (saving and deletion) processing time file data preservation point association sorting means; a smart contract (or server application) for allocating distributed file management groups during update (evacuation and deletion) processing, which is provided in each planet and has a function of allocating each of the file data associated with the information of the conservation points managed in a black box environment by the conservation point information management means during update (evacuation and deletion) processing, which is sorted by the file data conservation point association sorting means based on agreement information between the first user and the second user (or a first parameter included in the agreement information and a second parameter specified by the digital asset guard service administrator) regarding the evacuation processing of the data to be evacuated by the customer, acquired by the data update (evacuation and deletion) processing agreement information acquisition means, to a plurality of distributed file management groups, which are set by the digital asset guard service administrator according to conditions specified by the customer and are constituted by nodes at each base constituting the planet corresponding to the conservation points and recording devices at multiple bases connected to the nodes at each base via a network; a smart contract (or server application) for distributed recording during update (evacuation and deletion) processing, which is provided on each planet and has a function of distributing and recording each of the file data associated with the information of each of the conservation points sorted by the file data conservation point association sorting means during update (evacuation and deletion) processing and managed in a black box environment by the conservation point information management means during update (evacuation and deletion) processing, which has been allocated by the smart contract (or server application) for distributed file management group allocation during update (evacuation and deletion) processing, in each of the base nodes belonging to the corresponding distributed file management group and in recording devices at multiple bases connected to the base nodes via a network; a smart contract (or server application) for creating and recording system setting information during update (backup and deletion) processing, which has the function of creating system setting information including terminal information (information identifying the other party, such as a fixed IP address) for uploading to the first temporary storage area using the upload means during update (backup and deletion) processing, the number of the predetermined processing means that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and information on the file server groups (in the node at a predetermined base and in recording devices at multiple bases that are networked to the node at that base) that make up the distributed file management group, encrypting the information, and recording it in the node group at a specific base in the distributed ledger structure; and a smart contract (or server application) for creating server index information during update (saving and deletion) processing, the smart contract having a function for creating server index information including: key information using the first user ID information and the second user ID information required for data evacuation, which are included in the agreement information between the first user and the second user regarding the evacuation processing of the data to be evacuated for the customer acquired by the data update (saving and deletion) processing agreement information acquisition means; file name information of each of the file data linked to the information of the conservation point sorted by the file data conservation point association sorting means during update (saving and deletion) processing and managed in a black box environment by the conservation point information management means during update (saving and deletion) processing; and configuration information of each of the distributed file management groups to which each of the file data is allocated; a smart contract (or server application) for recording server index information during update (backup and deletion) processing, which has a function of encrypting the server index information created by the smart contract (or server application) for creating server index information during update (backup and deletion) processing and recording it in a group of nodes at a specific location in the distributed ledger structure; and a smart contract (or a program having a wallet function) for creating customer setting information during update (saving and deletion) processing, the smart contract having a function for creating customer setting information including agreement information between the first user and the second user regarding the evacuation processing of the data to be evacuated for the customer, which has been acquired by the data update (saving and deletion) processing agreement information acquisition means linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means during update (saving and deletion) processing; a smart contract (or a program with a wallet function) for creating customer index information during update (saving and deletion) processing, which has a function of creating customer index information including information on the original file name and upload date of the customer's file data to be saved during update (saving and deletion) processing; a smart contract (or a server application) for recording customer index information during update (backup and deletion) processing, which has a function of encrypting the customer index information created by the smart contract (or a program having a wallet function) for creating customer index information during update (backup and deletion) processing and recording it in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means during the update (backup and deletion) processing, which erases each file data uploaded to the first temporary storage area after the server index information is encrypted and recorded in a node group at a specific location in the distributed ledger structure by a smart contract (or a server application) for recording server index information during the update (backup and deletion) processing; a customer data deletion instruction receiving means for receiving an instruction to delete data to be deleted from the update (saving and deleting) instruction means during update (saving and deleting) processing; a file data preservation point information deletion means for deleting information on preservation points associated with file data to be deleted, which is managed in a black box environment by the preservation point information management means for update (saving and deleting), and which is accepted by the customer data deletion instruction accepting means for update (saving and deleting); and The data update (saving and deletion) processing agreement information acquisition means a data update (saving and deletion) processing request instruction means for instructing, via the first user, a request for processing to update (saving and deletion) data to be updated (saved and deleted) by the customer; a data update (saving and deletion) processing request instruction receiving means for receiving a request instruction for updating (saving and deleting) the data to be updated (saving and deleted) by the customer from the data update (saving and deletion) processing request instruction means; a first user ID information receiving means for data update (saving and deletion) that receives the first user ID information required for updating (saving and deleting) data from the first user information management means when the data update (saving and deletion) processing request instruction receiving means receives a request instruction for updating (saving and deleting) data of the customer; a seventh information notification means for notifying the second user, when the first user ID information receiving means for data update (saving and deletion) receives the first user ID information necessary for updating (saving and deleting) data, of information that the first user has issued a request instruction for updating (saving and deleting) the data to be updated (saving and deletion) for the customer, and information urging the second user to issue an approval instruction for updating (saving and deleting) the data to be updated (saving and deletion) for the customer; a data update (saving and deletion) processing approval instruction means for instructing approval of the update (saving and deletion) processing of the data to be updated (saved and deleted) by the customer via the second user who has received the notification from the seventh information notification means; a data update (saving and deletion) processing approval instruction receiving means for receiving an approval instruction for updating (saving and deletion) the data to be updated (saving and deletion) by the customer from the data update (saving and deletion) processing approval instruction means; a data update (saving and deletion) second user ID information receiving means for receiving the second user ID information required for updating (saving and deleting) data from the second user information management means when the data update (saving and deletion) processing approval instruction receiving means receives an approval instruction for updating (saving and deleting) data to be updated (saving and deleted) by the customer; an eighth information notification means for notifying the first user, when the second user ID information receiving means for data update (saving and deletion) receives the second user ID information necessary for updating (saving and deleting) data, of information that the second user has given an approval instruction for the update (saving and deletion) process of the data to be updated (saving and deletion) by the customer and information that urges the first user to give a request instruction for the update (saving and deletion) process of the data to be updated (saving and deletion) by the customer; a data update (saving and deletion) processing request instruction means for instructing, via the first user who has received the notification from the eighth information notification means, a request for processing to update (saving and deletion) the data to be updated (saved and deleted) for the customer; a data update (saving and deletion) processing request instruction receiving means for receiving a request instruction for updating (saving and deleting) the data to be updated (saving and deleted) by the customer from the data update (saving and deletion) processing request instruction means; a data update (saving and deletion) processing agreement information creating means for creating agreement information between the first user and the second user regarding the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer, using the first user ID information required for the data update (saving and deletion) and key information managed by the first user and the second user ID information required for the data update (saving and deletion) and received by the first user ID information receiving means for data update (saving and deletion), and key information managed by the second user, when the data update (saving and deletion) processing request instruction receiving means receives an instruction to request the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer; have The real-time saving and restoring type digital asset guard service providing system according to claim 103.
112. The second file data real-time update (saving and deletion) system comprises a user-side second file data real-time update (saving and deletion) system that operates on the side of a user (customer or data manager) who desires to update (saving and deleting) file data, and a digital asset guard service operator-side second file data real-time update (saving and deletion) system that operates on the side of the digital asset guard service operator, The user-side second file data real-time update (saving and deletion) system comprises the data update (saving and deletion) processing agreement information acquisition means, the customer data update (saving and deletion) instruction means, a program (or smart contract) having a plurality of the encryption and division algorithms, an encryption and division algorithm selection acceptance means for the update (saving and deletion) processing, a customer data evacuation instruction acceptance means for the update (saving and deletion) processing, a file data encryption and division means for the update (saving and deletion) processing, an upload means for the update (saving and deletion) processing, a file data conservation point association and sorting means for the update (saving and deletion) processing, and a conservation point information management means for the update (saving and deletion) processing, The second file data real-time update (saving and deletion) system on the digital asset guard service operator side includes a smart contract (or server application) for allocating distributed file management groups during the update (saving and deletion) processing, a smart contract (or server application) for distributed recording during the update (saving and deletion) processing, a smart contract (or server application) for creating server index information during the update (saving and deletion) processing, a smart contract (or server application) for recording server index information during the update (saving and deletion) processing, a first data erasure means during the update (saving and deletion) processing, a customer data deletion instruction acceptance means during the update (saving and deletion) processing, and a file data preservation point information deletion means during the update (saving and deletion) processing; have The real-time saving and restoring type digital asset guard service providing system according to claim 111.
113. Cold wallets and A registration means for registering a list of destination addresses (whitelist) of digital assets in the cold wallet; a transaction destination address check means for comparing a destination address of the transaction with a destination address in a whitelist registered in the cold wallet before approval of the transaction for the evacuation processing of the data to be evacuated of the customer when the data evacuation processing agreement information creation means creates agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated of the customer, and determining that the transaction is correct if the destination address of the transaction is included in the whitelist registered in the cold wallet, and determining that the transaction is incorrect if the destination address is not included in the whitelist; 2. The real-time save / restore digital asset guard service providing system according to claim 1, further comprising a save transaction approval processing control means for, if the transaction destination address check means determines that the transaction is incorrect, notifying the first authenticator and the second authenticator that the destination address is invalid and halting the creation of agreement information between the first authenticator and the second authenticator by the data save processing agreement information creation means.
114. Cold wallets and A registration means for registering a list of destination addresses (whitelist) for digital assets in the cold wallet; a transaction recipient address check means for comparing a recipient address of the transaction with a recipient address in a whitelist registered in the cold wallet before approval of the transaction for the restoration processing of the data to be restored for the customer when the data restoration processing agreement information creation means creates agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer, and determining that the transaction is correct if the recipient address of the transaction is included in the whitelist registered in the cold wallet, and determining that the transaction is incorrect if the recipient address is not included in the whitelist; 2. The real-time save / restore type digital asset guard service providing system according to claim 1, further comprising a restoration transaction approval processing control means for, if the transaction recipient address check means determines that the transaction is incorrect, notifying the first authenticator and the second authenticator that the recipient address is invalid and halting the creation of agreement information between the first authenticator and the second authenticator by the data restoration processing agreement information creation means.
115. Cold wallets and A registration means for registering a list of destination addresses (whitelist) of digital assets in the cold wallet; transaction destination address check means for comparing a destination address of the transaction with a destination address in a whitelist registered in the cold wallet before approval of the transaction for the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer when the data update (saving and deletion) processing agreement information creation means creates agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer by the data update (saving and deletion) processing agreement information creation means, and determining that the transaction is correct if the destination address of the transaction is included in the whitelist registered in the cold wallet, and determining that the transaction is incorrect if the destination address is not included in the whitelist; 7. The real-time save / restore type digital asset guard service providing system according to claim 6, further comprising an update (saving and deletion) transaction approval processing control means which, if the transaction destination address check means determines that the transaction is incorrect, notifies the first authenticator and the second authenticator that the destination address is invalid and stops the data update (saving and deletion) processing agreement information creation means from creating agreement information between the first authenticator and the second authenticator.