Information exchange system
The information exchange system addresses security vulnerabilities by separating encrypted information and encryption key management, ensuring secure transfer through distinct units and authorized access, with self-erasing encryption processes.
Patent Information
- Application Number
- JP2024109811
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-08
- Publication Date
- 2026-01-21
AI Technical Summary
Existing information exchange systems lack security as encrypted information and encryption keys are managed on the same server, leading to potential leaks.
An information exchange system that separates the management of encrypted information and encryption keys, using distinct units for asset and instruction information, with a key management unit that discriminates and provides encryption keys only to authorized parties based on associations, and performs self-erasing encryption processes.
Enhances security by ensuring that neither encrypted information nor encryption keys are leaked during exchange, providing secure and reliable information transfer.
Smart Images

Figure 2026009728000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information exchange system for exchanging asset information. [Background technology]
[0002] In recent years, with the development of information processing technology, confidential information such as personal information, trade secrets, and wills has come to be processed as digitized asset information using encryption technology. For example, a will management system has been proposed in which will information entered by a depositor is encrypted with an encryption key, and the encrypted will information and the encryption key for decrypting the encrypted will information are managed by a will management server (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2006-059283 Summary of the Invention [Problem to be solved by the invention]
[0004] However, in the management system described above, the encrypted information and the encryption key for decrypting the information are exchanged on the same server, which means that the security of the information exchange is lacking.
[0005] An object of the present invention is to provide an information exchange system that provides high security in the exchange of encrypted information and an encryption key for decrypting the information. [Means for solving the problem]
[0006] That is, the present invention includes the following inventions. (1) An information transfer system for transferring information between at least two parties, a trustor who creates plaintext asset information on assets and plaintext instruction information on instructions regarding the asset information, a trustee who receives instructions from the trustor based on the instruction information, and a recipient who receives the asset information, the trustor and the trustee or the recipient, the information transfer system including an asset information encryption processing unit that encrypts the asset information into ciphertext asset encrypted information, an instruction information encryption processing unit that encrypts the instruction information into ciphertext instruction encrypted information, an asset information decryption processing unit that decrypts the asset encrypted information into the asset information, an instruction information decryption processing unit that decrypts the instruction encrypted information into the instruction information, encryption in the asset information encryption processing unit and the instruction information encryption processing unit, and a decryption processing unit that decrypts the instruction encrypted information into the instruction information. an information transfer system comprising: a key management unit that manages an encryption key used for decryption in the instruction information decryption processing unit; and a ciphertext memory unit that stores the asset encryption information and the instruction encryption information, wherein the key management unit includes a discrimination unit that discriminates whether the person requesting acquisition of the encryption key is the trustee or the recipient, and when the discrimination unit discriminates that the person is the trustee, the encryption key is provided from the key management unit to the instruction information decryption processing unit, and the instruction information decryption processing unit uses the encryption key to decrypt the instruction encryption information obtained from the ciphertext memory unit into the instruction information, and when the discrimination unit discriminates that the person is the recipient, the encryption key is provided from the key management unit to the asset information decryption processing unit, and the asset information decryption processing unit uses the encryption key to decrypt the asset encryption information obtained from the ciphertext memory unit into the asset information.
[0007] According to the configuration of this information exchange system, instructions such as the client's comments, personal information, trade secrets, asset information such as wills, and instructions to the trustee, as well as encryption keys for decrypting this encrypted information, are all managed separately. Therefore, when information is exchanged, neither the encrypted information nor the encryption key is leaked, making it possible to provide an information exchange system with improved security.
[0008] (2) The information transfer system described in (1) further includes an information update unit that updates the asset information and instruction information by the trustor, wherein the determination unit further determines whether the person requesting acquisition of the encryption key is the trustor, and when the determination unit determines that the person is the trustor, the encryption key is provided from the key management unit to the asset information encryption processing unit and the instruction information encryption processing unit, the asset information encryption processing unit uses the encryption key to encrypt the asset information updated by the information update unit into the asset encryption information, the instruction information encryption processing unit uses the encryption key to encrypt the instruction information updated by the information update unit into the instruction encryption information, and the ciphertext memory unit stores the asset encryption information and the instruction encryption information, which are the information updated by the information update unit.
[0009] With this configuration, the client can independently update the asset information and instruction information using the information update unit. Furthermore, the encryption processing unit re-encrypts the updated asset information and instruction information using an encryption key.
[0010] (3) An information exchange system described in (1) or (2), in which the instruction information encryption processing unit performs a self-erasing encryption process in which the instruction encryption information self-deletes when the instruction encryption information is decrypted without using the encryption key or with an encryption key other than the encryption key.
[0011] According to this configuration, even if the instruction encryption information is accidentally leaked, when an attempt is made to decrypt or decode it at the destination, the instruction encryption information will be self-deleted, thereby increasing the security of information transmission.
[0012] (4) The information exchange system described in (3), wherein the encryption key is generated based on the association between the trustor and the trustee who accepts the instruction information, the key management unit manages the encryption key as an instruction information encryption key, and the discrimination unit determines that the person requesting acquisition of the instruction information encryption key is the trustor or the trustee based on the association between the trustor and the trustee who accepts the instruction information, and the instruction information encryption key is provided from the key management unit to the instruction information decryption processing unit or the instruction information encryption processing unit.
[0013] With this configuration, the key management unit manages the instruction information encryption key associated with the trustor and the trustee, and the key management unit grants the instruction information encryption key only to the trustor and the trustee, thereby preventing the instruction information encryption key from being leaked to anyone other than the trustor and the trustee.
[0014] (5) The asset information encryption processing unit performs a self-erasing encryption process in which the asset encryption information is self-erased when the asset encryption information is decrypted without using the encryption key or with an encryption key other than the encryption key. An information exchange system as described in (1) or (2).
[0015] With this configuration, even if the asset encryption information is accidentally leaked, if an attempt is made to decrypt or decode it at the destination, the asset encryption information will be self-deleted, thereby increasing the security of information transfer.
[0016] (6) The information transfer system described in (5), wherein the encryption key is generated based on the association between the trustor and the recipient who receives the asset information, the key management unit manages the encryption key as an asset information encryption key, the determination unit determines whether the person requesting acquisition of the asset information encryption key is the trustor or the recipient based on the association between the trustor and the recipient who receives the asset information, and the asset information encryption key is provided from the key management unit to the asset information decryption processing unit or the asset information encryption processing unit.
[0017] With this configuration, the key management unit manages the asset information encryption key associated with the trustor and the recipient, and the key management unit grants the asset information encryption key only to the trustor and the recipient, thereby preventing the asset information encryption key from being leaked to anyone other than the trustor and the recipient. [Effects of the Invention]
[0018] The present invention provides an information exchange system that allows highly secure information exchange, since encrypted information and the encryption key for decrypting the information are managed separately, and neither the encrypted information nor the encryption key is leaked when information is exchanged. [Brief explanation of the drawings]
[0019] [Figure 1] 1 is a block diagram showing an information exchange system 1 according to an embodiment of the present invention. [Figure 2] 2 is an explanatory diagram showing encryption keys K1 and K2 and association information G1 and G2 stored in an encryption key storage unit 43 of the key management server 4 shown in FIG. 1; [Figure 3] 2 is a flowchart showing an example of a flow on the side of a client I in the information transfer system 1 shown in FIG. [Figure 4] 2 is a flowchart showing an example of a flow on the side of a trustee J in the information transfer system 1 shown in FIG. [Figure 5] 2 is a flowchart showing an example of a flow on the receiver U1 side in the information exchange system 1 shown in FIG. DETAILED DESCRIPTION OF THE INVENTION
[0020] An embodiment of the present invention will be described below with reference to the drawings. As shown in Fig. 1, in an information transfer system 1, information is transferred via a network N between a terminal device 2 owned by a trustor I, a trustee J, and a recipient U, a key management server 4 serving as a key management unit, and an information management server 6 serving as a ciphertext storage unit.
[0021] The terminal device 2 may be any device capable of transmitting and receiving information, and is preferably a personal computer or a tablet terminal, and more preferably a mobile terminal such as a smartphone in terms of portability. The terminal device 2 is equipped with a terminal input / output unit 21, a terminal processing unit 23, and a terminal communication unit 25.
[0022] The terminal input / output unit 21 is a touch panel that accepts operations such as creating information, encrypting and decrypting information, and displays the information. In the case of the terminal device 2 owned by the trustor I, the terminal input / output unit 21 accepts operations for creating plaintext asset information 100 related to assets and plaintext instruction information 300 related to instructions regarding the asset information 100, and for encrypting such information. In the case of the terminal devices 2 owned by the trustee J and the recipient U, the terminal input / output unit 21 accepts operations for decrypting the encrypted asset information 100 and instruction information 300.
[0023] The terminal processing unit 23 is a calculation device such as a CPU (Central Processing Unit). In the case of the terminal device 2 owned by the entrustor I, the terminal processing unit 23 performs a setting process to set the recipient U who will grant the asset information 100 and the trustee J who will grant the instruction information 300, and an encryption process to encrypt the asset information 100 and the instruction information 300, respectively. The terminal processing unit 23 includes a user authentication unit 230, a target setting unit 231, an information creation unit 232, an asset information encryption processing unit 233, and an instruction information encryption processing unit 235. In the case of the terminal device 2 owned by the recipient U, the terminal processing unit 23 decrypts the asset encryption information 110 encrypted by the terminal device 2 owned by the entrustor I. The terminal processing unit 23 includes a user authentication unit 230 and an asset information decryption processing unit 234. In the case of the terminal device 2 owned by the trustee J, the terminal processing unit 23 decrypts the instruction encryption information 310 encrypted by the terminal device 2 owned by the entrustor I. The terminal processing unit 23 includes a user authentication unit 230 and an instruction information decryption processing unit 236. The terminal processing units 23 of the terminal devices 2 owned by the trustee J and the recipient U each further include an information acquisition unit 238 that requests and acquires the encryption key K from the key management server 4, and requests and acquires at least one of the asset encryption information 110 and the instruction encryption information 310 from the information management server 6.
[0024] The terminal communication unit 25 transmits and receives information between the terminal device 2 and the key management server 4 or the information management server 6 via the network N. The network N may be any of various communication means, such as the Internet, public telephone lines, a mobile communication network, a LAN (Local Area Network), or WIFI (registered trademark), or may be a combination of these communication means, and may be configured as a wired or wireless network, or a combination of wired and wireless networks.
[0025] The user authentication unit 230 authenticates whether the person exchanging information via the terminal device 2 is the entrustor I, the trustee J, or the recipient U. The user authentication unit 230 preferably performs authentication using knowledge authentication such as a preset ID / password or PIN code. In addition to knowledge authentication, the user authentication unit 230 may also perform possession authentication by reading an electronic key or a contactless IC card, or biometric authentication by recognizing physical features such as a face or fingerprint. Alternatively, authentication may be performed using multi-factor authentication that combines two or more of these authentication methods. It is sufficient for the user authentication unit 230 to be able to authenticate that the person using the terminal device 2 is the entrustor I, the trustee J, or the recipient U.
[0026] The target setting unit 231 sets a recipient U as a target to which the asset information 100 is to be assigned via the terminal input / output unit 21. The target setting unit 231 also sets a trustee J as a target to which the instruction information 300 is to be assigned via the terminal input / output unit 21. The setting information set by the target setting unit 231 is transmitted to the key management server 4 by the terminal communication unit 25.
[0027] The information creation unit 232 creates plaintext asset information 100 relating to assets and plaintext instruction information 300 relating to instructions for the asset information 100 via the terminal input / output unit 21 .
[0028] The asset information encryption processing unit 233 acquires an encryption key K1 (described below) from the key management server 4 and uses the encryption key K1 to encrypt the asset information 100 into ciphertext asset encryption information 110. The instruction information encryption processing unit 235 acquires an encryption key K2 (described below) that is different from the encryption key K1 that encrypted the asset information 100 from the key management server 4 and uses the encryption key K2 to encrypt the instruction information 300 into ciphertext instruction encryption information 310. The asset encryption information 110 encrypted by the asset information encryption processing unit 233 and the instruction encryption information 310 encrypted by the instruction information encryption processing unit 235 are transmitted by the terminal communication unit 25 to the information management server 6, and the information management server 6 stores the asset encryption information 110 and the instruction encryption information 310.
[0029] The asset information decryption processing unit 234 acquires asset encryption information 110 from the information management server 6, acquires encryption key K1 from the key management server 4, and uses encryption key K1 to decrypt the asset encryption information 110 into asset information 100. The instruction information decryption processing unit 236 acquires instruction encryption information 310 from the information management server 6, and uses encryption key K2 acquired from the key management server 4 to decrypt the instruction encryption information 310 into instruction information 300.
[0030] The key management server 4 is configured as a server device comprising an encryption key processing unit 41, an encryption key communication unit 42, and an encryption key storage unit 43. The encryption key processing unit 41 is a calculation device such as a CPU. The encryption key communication unit 42 transmits and receives data to and from the terminal device 2 via the network N. The encryption key storage unit 43 stores a program for implementing the information transfer system 1 in the key management server 4. The encryption key processing unit 41 executes the program stored in the encryption key storage unit 43, thereby causing an association unit 411, a key generation unit 412, and a determination unit 413 to function as information processing in the key management server 4.
[0031] The associating unit 411 associates the trustor I with the recipient U, or the trustor I with the trustee J, based on the setting information of the target setting unit 231 transmitted from the terminal device 2 of the trustor I. The association by the associating unit 411 is preferably based on authentication information authenticated by the user authentication unit 230, but may also be based on the terminal devices 2 owned by the trustor I, the recipient U, and the trustee J.
[0032] The key generation unit 412 generates an encryption key K based on the association information G of the association unit 411. The key generation unit 412 generates an encryption key K made up of binary data in a random format. The encryption key K generated by the key generation unit 412 is given to a person corresponding to the association information G of the association unit 411, and is also stored in the encryption key storage unit 43.
[0033] The key generation unit 412 generates an encryption key K1 as an asset information encryption key for encrypting the asset information 100 into asset encrypted information 110, based on the association information G1 in which the association unit 411 associates the settlor I with the recipient U. The encryption key K1 generated by the key generation unit 412 is provided to the asset information encryption processing unit 233 of the terminal device 2 owned by the settlor I via the encryption key communication unit 42, and is also stored in the encryption key storage unit 43. The key generation unit 412 also generates an encryption key K2 as an asset information encryption key for encrypting the instruction information 300 into instruction encrypted information 310, based on the association information G2 in which the association unit 411 associates the settlor I with the trustee J. The encryption key K2 generated by the key generation unit 412 is provided to the instruction information encryption processing unit 235 of the terminal device 2 owned by the settlor I via the encryption key communication unit 42, and is also stored in the encryption key storage unit 43.
[0034] The encryption keys K1 and K2 generated by the key generation unit 412 are of a common key encryption system (symmetric key encryption system). Therefore, the encryption key K1 is used not only when encrypting the asset information 100 into the asset encrypted information 110, but also when decrypting the asset encrypted information 110 into the asset information 100. Furthermore, the encryption key K2 is used not only when encrypting the command information 300 into the command encrypted information 310, but also when decrypting the command encrypted information 310 into the command information 300.
[0035] The encryption key storage unit 43 is configured with a storage medium such as a RAM, a ROM, or a hard disk, and functions as a memory or storage. As shown in Fig. 2, the encryption key storage unit 43 stores the encryption key K1 and the encryption key K2, as well as association information G1 that associates the trustor I with the recipient U, and association information G2 that associates the trustor I with the trustee J.
[0036] The determination unit 413 determines whether the person requesting acquisition of the encryption key K1 is the recipient U, based on the association information G1 stored in the encryption key storage unit 43. If the determination unit 413 determines that the person requesting acquisition of the encryption key K1 is the recipient U, the determination unit 413 assigns the encryption key K1 stored in the encryption key storage unit 43 to the asset information decryption processing unit 234 of the terminal device 2 owned by the recipient U via the encryption key communication unit 42.
[0037] Furthermore, the determination unit 413 determines whether the person requesting acquisition of the encryption key K2 is the trustee J, based on the association information G2 stored in the encryption key storage unit 43. If the determination unit 413 determines that the person requesting acquisition of the encryption key K2 is the trustee J, the determination unit 413 transfers the encryption key K2 stored in the encryption key storage unit 43 to the instruction information decryption processing unit 236 of the terminal device 2 owned by the trustee J via the encryption key communication unit 42.
[0038] The information management server 6 is a server device comprising an information communication unit 61, an information processing unit 62, and an information storage unit 63. The information communication unit 61 transmits and receives data to and from the terminal device 2 via the network N. The information communication unit 61 receives the asset cryptographic information 110 and the instruction cryptographic information 310 encrypted by the terminal device 2 owned by the entrustor I. The information processing unit 62 is a computing device such as a CPU. The information storage unit 63 is comprised of a storage medium such as a RAM, a ROM, or a hard disk, and functions as a memory or storage. The information storage unit 63 stores the asset cryptographic information 110 and the instruction cryptographic information 310 transmitted from the terminal device 2 owned by the entrustor I. The information storage unit 63 also stores a program for implementing the information transfer system 1 in the information management server 6. The information processing unit 62 executes the program stored in the information storage unit 63, thereby causing the information storage unit 621, the acquisition notification unit 622, and the acquisition identification unit 623 to function as information processing in the information management server 6.
[0039] The information saving unit 621 stores the asset crypto information 110 and the instruction crypto information 310 received by the information communication unit 61 in the information storage unit 63 based on the setting information set by the target setting unit 231. The acquisition notifying unit 622 notifies the trustee J that the asset crypto information 110 and the instruction crypto information 310 will be acquired, and notifies the recipient U that the asset crypto information 110 will be acquired. The acquisition identifying unit 623 identifies the person requesting acquisition of the information stored in the information storage unit 63 based on authentication by the user authentication unit 230 of the terminal device 2. When the acquisition identifying unit 623 identifies that the person requesting acquisition of the information is the recipient U, it grants the asset crypto information 110 to the recipient U via the information communication unit 61. When the acquisition identifying unit 623 identifies that the person requesting acquisition of the information is the trustee J, it grants the instruction crypto information 310 to the trustee J via the information communication unit 61.
[0040] Furthermore, an information update unit 237 also functions as the terminal processing unit 23 in the terminal device 2 owned by the entrustor I. When the entrustor I creates at least one of asset information 100N (not shown) and instruction information 300N (not shown) to be newly updated using the terminal input / output unit 21, the information update unit 237 encrypts the created information into at least one of asset crypto information 110N and instruction crypto information 310N via at least one of the corresponding asset information encryption processing unit 233 and instruction information encryption processing unit 235. The information update unit 237 generates update information including at least one of the asset crypto information 110N and instruction crypto information 310N and transmits it to the information management server 6.
[0041] When the information communication unit 61 of the information management server 6 receives the update information, the information storage unit 621 deletes at least one of the asset crypto information 110 and the instruction crypto information 310 stored in the information storage unit 63 of the information management server 6 based on the update information, and stores at least one of the asset crypto information 110N and the instruction crypto information 310N corresponding thereto, thereby updating the information stored in the information storage unit 63. The processing of the information storage unit 621 based on the update information of the information update unit 237 preferably deletes the pre-update information stored in the information storage unit 63 and replaces it with the post-update information. The processing of the information storage unit 621 may also update the information by overwriting the pre-update information stored in the information storage unit 63, as long as it does not affect the post-update information.
[0042] The acquisition notification unit 622 of the information management server 6 notifies the trustee J that at least one of the asset cryptographic information 110 and the instruction cryptographic information 310 has been updated. Upon receiving the notification, the trustee J deletes the asset cryptographic information 110 and the instruction cryptographic information 310 before the update that he / she has stored, and acquires the updated asset cryptographic information 110 and the instruction cryptographic information 310 from the information transfer system 1.
[0043] In the information transfer system 1 according to this embodiment, the asset encryption information 110, the instruction encryption information 310, the encryption key K1, and the encryption key K2 are managed by the key management server 4 and the information management server 6. Therefore, it is not necessary to change the encryption keys K1 and K2 in response to updates to the asset information 100 and the instruction information 300, and the entrustor I can easily update the asset information 100 and the instruction information 300 via the information update unit 237.
[0044] Furthermore, when encrypting the asset information 100 into the asset cryptographic information 110, the asset information encryption processing unit 233 performs a self-erasing encryption process in which the asset cryptographic information 110 self-deletes when the asset cryptographic information 110 is decrypted without using the encryption key K1 or with an encryption key other than the encryption key K1. By performing the self-erasing encryption process on the asset information 100, the asset information encryption processing unit 233 makes it possible to decrypt the asset cryptographic information 110 into the asset information 100 only with the encryption key K1. Because the encryption key K1 is generated based on the association information G1, no one other than the settlor I and the recipient U can obtain the encryption key K1, improving security in the exchange of information.
[0045] Furthermore, when encrypting the command information 300 into the command encrypted information 310, the command information encryption processing unit 235 performs a self-erasing encryption process in which the command encrypted information 310 self-deletes when the command encrypted information 310 is decrypted without using the encryption key K2 or with an encryption key other than the encryption key K2. By performing the self-erasing encryption process on the command information 300, the command encrypted information 310 can only be decrypted into the command information 300 using the encryption key K2. Because the encryption key K2 is generated based on the association information G2, only the settlor I and the trustee J can obtain the encryption key K2, improving the security of information exchange.
[0046] The flow of the information transfer system 1 according to an embodiment of the present invention will be described with reference to FIGS. 3 to 5. To facilitate the explanation of the information transfer system 1, the transfer of the following information will be described as an example. The information is will information created in electronic data by the settlor I, who is the deceased. The will information includes asset information 100 and instruction information 300. The asset information 100 is information about assets owned by the settlor I, including financial assets such as cash and deposits, fixed assets such as land and buildings, and commemorative assets such as photographs and souvenirs. The instruction information 300 is information about instructions to a trustee, such as a data trust company, on how to have the asset information 100 inherited by the recipient U, who is the heir.
[0047] First, the flow on the entrustor I side in the information transfer system 1 will be described. As shown in FIG. 3, the user authentication unit 230 authenticates whether the person transferring information via the terminal device 2 is the entrustor I (step S301). The user authentication unit 230 authenticates that the user is the entrustor I, for example, by inputting an ID and password that the entrustor I registered in advance. For example, knowledge authentication using an ID and password is used as a means for authenticating the user. If the user is not authenticated as the entrustor I (Y in step S301), the user cannot proceed to the next step, and if the number of authentication failures reaches a predetermined threshold, it is preferable that the user cannot use, for example, an application of the information transfer system 1 for a certain period of time.
[0048] The terminal input / output unit 21 of the terminal device 2 accepts an input operation from the trustor I (step S302). The terminal input / output unit 21 accepts an input operation from the trustor I to set at least one of the recipient U and the trustee J, and an input operation to create the asset information 100 and the instruction information 300. The input information accepted by the terminal input / output unit 21 is processed by the target setting unit 231 and the information creation unit 232 as applications, which set at least one of the recipient U and the trustee J, and create the asset information 100 and the instruction information 300. At this time, it is preferable that information for authenticating the recipient U and the trustee J set by the trustor I has been input.
[0049] If multiple recipients U are set by the settlor I, asset information 100 is created for each recipient U. Furthermore, if multiple trustees J are set by the settlor I, instruction information 300 is created for each trustee J. In the following explanation, three recipients U1, U2, and U3 are set by the settlor I. Asset information 101 to be received by recipient U1, asset information 102 to be received by recipient U2, and asset information 103 to be received by recipient U3 are created for each recipient U1, U2, and U3.
[0050] The terminal communication unit 25 transmits the setting information set by the target setting unit 231 to the key management server 4 (step S303). The terminal device 2 transmits the setting information set by the target setting unit 231 to the key management server 4 via the terminal communication unit 25. The setting information includes information that the asset information 100 is to be granted to recipients U1, U2, and U3, and that the instruction information 300 is to be granted to trustee J.
[0051] When the encryption key communication unit 42 receives the setting information from the terminal device 2 (step S304), the association unit 411 associates the trustor I with each grantee based on the setting information (step S305). Specifically, the association unit 411 associates the trustor I with each of the recipients U1, U2, U3, and trustee J based on the setting information. The association between the trustor I and recipient U1 is stored as association information G11, the association between the trustor I and recipient U2 is stored as association information G12, and the association between the trustor I and recipient U3 is stored as association information G13 in the encryption key storage unit 43. In addition, the association between the trustor I and trustee J is stored as association information G2 in the encryption key storage unit 43.
[0052] The key generation unit 412 generates an encryption key K based on each piece of association information G (step S306), and the encryption key communication unit 42 transmits the encryption key K to the terminal device 2 (step S307). Specifically, the key generation unit 412 generates an encryption key K11 as an asset information encryption key for encrypting the asset information 101 into asset cryptographic information 111 based on the association information G11. The key generation unit 412 also generates an encryption key K12 as an asset information encryption key for encrypting the asset information 102 into asset cryptographic information 112 based on the association information G12. The key generation unit 412 also generates an encryption key K13 as an asset information encryption key for encrypting the asset information 103 into asset cryptographic information 113 based on the association information G13. The key generation unit 412 also generates an encryption key K2 as an instruction information encryption key for encrypting the instruction information 300 into instruction cryptographic information 310 based on the association information G2. The encryption keys K11, K12, K13 and the encryption key K2 generated by the key generating unit 412 are transmitted by the encryption key communicating unit 42 to the terminal device 2 that transmitted the setting information, and are stored in the encryption key storage unit 43.
[0053] The terminal communication unit 25 receives the encryption keys K11, K12, K13 and the encryption key K2 transmitted from the key management server 4 (step S308). The terminal processing unit 23 encrypts the asset information 101, 102, 103 and the instruction information 300 into asset encryption information 111, 112, 113 and instruction encryption information 310 (step S309).
[0054] Specifically, the asset information encryption processing unit 233 encrypts the asset information 101, 102, and 103 into asset cryptographic information 111, 112, and 113 using encryption keys K11, K12, and K13. The command information encryption processing unit 235 encrypts the command information 300 into command cryptographic information 310 using encryption key K2. It is preferable that the asset information encryption processing unit 233 and the command information encryption processing unit 235 encrypt the asset information 101, 102, and 103 and the command information 300 using self-deleting encryption processing. The asset cryptographic information 111, 112, and 113 encrypted by the asset information encryption processing unit 233 and the command cryptographic information 310 encrypted by the command information encryption processing unit 235 are transmitted to the information management server 6 by the terminal communication unit 25 (step S310).
[0055] The information communication unit 61 receives the asset crypto information 111, 112, 113 and the instruction crypto information 310 (step S311), and the information processing unit 62 stores the asset crypto information 111, 112, 113 and the instruction crypto information 310 in the information storage unit 63 (step S312). The information saving unit 621 of the information processing unit 62 stores the asset crypto information 111, 112, 113 and the instruction crypto information 310 in the information storage unit 63, based on the setting information set by the target setting unit 231.
[0056] The information processing unit 62 issues a notification to the trustee J urging him to acquire the asset information 100 and the instruction information 300 (step S313). The acquisition notification unit 622 of the information processing unit 62 notifies the trustee J via the information communication unit 61 to acquire the asset information 100 (asset encryption information 110) and instruction information 300 (instruction encryption information 310) created by the trustee I. The acquisition notification unit 622 may use any known means to notify the trustee J. For example, it is sufficient if the notification from the information transfer system 1 can be received by the terminal device 2 owned by the trustee J, such as a short message or email. If the trustee I is unable to set up information about the trustee J in advance, it is preferable to notify the trustee J by a notification email including a one-time authentication URL. This marks the end of the flow on the trustee I side in the information transfer system 1.
[0057] Next, we will explain the flow on the trustee J side in the information transfer system 1. As shown in Fig. 4, the terminal device 2 authenticates whether the person transferring information is the trustee J (step S401). The user authentication unit 230 authenticates that the user is the trustee J, for example, by inputting an ID and password that the trustee J registered in advance.
[0058] The information acquisition unit 238 requests the information management server 6 to acquire the asset crypto information 110 and the instruction crypto information 310 via the terminal communication unit 25 (step S402). When the information communication unit 61 of the information management server 6 receives the request from the terminal device 2 (step S403), the acquisition identification unit 623 identifies the person requesting acquisition of the information stored in the information storage unit 63 based on authentication by the user authentication unit 230 of the terminal device 2 (step S404). When the acquisition identification unit 623 identifies that the person requesting acquisition of the information is trustee J (Y in step S404), the asset crypto information 110 and the instruction crypto information 310 are transmitted to the terminal device 2 of trustee J via the information communication unit 61 (step S405). Note that the asset crypto information 110 and the instruction crypto information 310 transmitted to the terminal device 2 of trustee J are preferably deleted from the information storage unit 63 to improve security. The asset crypto information 110 and the instruction crypto information 310 may remain stored in the information storage unit 63 even after being sent to the trustee J's terminal device 2 in case the trustor I checks the asset information 100 (asset crypto information 110) and the instruction information 300 (instruction crypto information 310) or the trustee J loses the asset information 100 (asset crypto information 110) and the instruction information 300 (instruction crypto information 310).
[0059] When the information acquisition unit 238 acquires the asset encryption information 110 and the instruction encryption information 310 (step S406), the information acquisition unit 238 requests the key management server 4 via the terminal communication unit 25 to acquire the encryption key K2 for decrypting the instruction encryption information 310 (step S407). When the encryption key communication unit 42 of the key management server 4 receives the request from the terminal device 2 (step S408), the discrimination unit 413 discriminates the person requesting the acquisition of the encryption key K2 based on the association information G2 stored in the encryption key storage unit 43 (step S409). When the discrimination unit 413 identifies the person requesting the acquisition of the encryption key K2 as trustee J (Y in step S409), the encryption key K2 is transmitted to the terminal device 2 of trustee J via the encryption key communication unit 42 (step S410).
[0060] The information acquisition unit 238 acquires the encryption key K2 (step S411), and the instruction information decryption processing unit 236 uses the encryption key K2 to decrypt the instruction encrypted information 310 into instruction information 300 (step S412). The decrypted instruction information 300 is displayed on the terminal input / output unit 21 of the terminal device 2 of the trustee J. The trustee J stores the asset encrypted information 110 and executes it in accordance with the instructions displayed on the terminal input / output unit 21 by the instruction information 300. This completes the flow on the trustee J's side in the information transfer system 1.
[0061] Next, we will explain the flow on the side of the receiver U1 who receives the asset cryptographic information 111 in the information transfer system 1. Even if there are multiple receivers U, the flow of information transfer is the same, so we will omit explanation of the flow on the side of the receivers U2 and U3 who receive the asset cryptographic information 112 and 113. Note that, as a premise for the explanation, the trustee J performs the above steps S301 to S313 based on the instructions from the settlor I. That is, at an appropriate time specified in the instructions from the settlor I, the asset cryptographic information 111 stored by the trustee J is further encrypted, i.e., double-encrypted, with the encryption key K31 newly generated based on the association information G31, and a notification is sent to the receiver U1 urging him to obtain the asset information 101.
[0062] 5, the terminal device 2 authenticates whether the person exchanging information is the recipient U1 (step S501). The user authentication unit 230 authenticates that the user is the recipient U1 by having the recipient U1 input an ID and password that the recipient U1 registered in advance, for example, based on a notification from the trustee J.
[0063] The information acquisition unit 238 requests the information management server 6 to acquire the asset crypto information 111 via the terminal communication unit 25 (step S502). When the information communication unit 61 of the information management server 6 receives the request from the terminal device 2 (step S503), the acquisition identification unit 623 identifies the person requesting acquisition of the information stored in the information storage unit 63 based on authentication by the user authentication unit 230 of the terminal device 2 (step S504). When the acquisition identification unit 623 identifies that the person requesting acquisition of the information is recipient U1 (Y in step S504), the asset crypto information 111 is transmitted to the terminal device 2 of recipient U1 via the information communication unit 61 (step S505).
[0064] When the information acquisition unit 238 acquires the asset encryption information 111 (step S506), the information acquisition unit 238 requests the key management server 4 via the terminal communication unit 25 to acquire the encryption keys K11 and K31 for decrypting the asset encryption information 111 (step S507). When the encryption key communication unit 42 of the key management server 4 receives the request from the terminal device 2 (step S508), the discrimination unit 413 discriminates the person requesting the acquisition of the encryption keys K11 and K31 based on the association information G11 and G31 stored in the encryption key storage unit 43 (step S509). When the discrimination unit 413 identifies the person requesting the acquisition of the encryption keys K11 and K31 as the recipient U11 (Y in step S509), the encryption keys K11 and K31 are transmitted to the terminal device 2 of the recipient U1 via the encryption key communication unit 42 (step S510).
[0065] The information acquisition unit 238 acquires the encryption keys K11 and K31 (step S511), and decrypts the asset encryption information 111 into asset information 100 using the encryption keys K11 and K31 (step S512). The decrypted asset information 100 is displayed on the terminal input / output unit 21 of the terminal device 2 of the recipient U11. This completes the flow on the recipient U11 side in the information transfer system 1.
[0066] In the flow on the trustee J side in the information transfer system 1 described above, the encryption key K2 is acquired after the instruction encryption information 310 is acquired, but the encryption key K2 may be acquired before the instruction encryption information 310 is acquired, or the instruction encryption information 310 and the encryption key K2 may be acquired simultaneously. Similarly, in the flow on the receiver U11 side in the information transfer system 1 described above, the encryption keys K11 and K31 may be acquired before the asset encryption information 111 (110) is acquired, or the asset encryption information 111 (110) and the encryption keys K11 and K31 may be acquired simultaneously.
[0067] In the above-described information transfer system 1, the recipient U is notified to acquire the asset information 100 via the trustee J, but in some cases, the recipient U may be notified to acquire the asset information 100 without going through the trustee J. In this case, in the above-described step S313, the information processing unit 62 of the information management server 6 notifies the recipient U to prompt the recipient U to acquire the asset information 100. Based on the notification from the information processing unit 62, the information acquisition unit 238 of the terminal device 2 can request the information management server 6 to acquire the asset encryption information 111 via the terminal communication unit 25.
[0068] As can be seen from the flow of the information transfer system 1 according to an embodiment of the present invention, when the asset cryptographic information 110 and the instruction cryptographic information 310 are acquired, they are identified based on authentication by the user authentication unit 230 and settings by the target setting unit 231, whereas when the encryption keys K1 and K2 are acquired, they are identified based on the association information G1 and G2. In other words, direct information communication is avoided between the device storing the asset cryptographic information 110 and the instruction cryptographic information 310 and the device storing the encryption keys K1 and K2 used to encrypt and decrypt this information. As a result, even if an inappropriate person such as the trustee J or the recipient U acquires the asset cryptographic information 110 and the instruction cryptographic information 310 from the information management server 6, or even if the trustee J or the recipient U acquires the asset cryptographic information 110 and the instruction cryptographic information 310 from the information management server 6 at an inappropriate time, the asset cryptographic information 110 and the instruction cryptographic information 310 cannot be easily decrypted because the encryption keys K1 and K2 cannot be acquired.
[0069] In the above-described embodiment, from the viewpoint of security in information exchange, information processing such as creation, encryption, and decryption of the asset information 100 and instruction information 300 is performed by the terminal device 2, but this is not limited to this. A separate processing server (not shown) that performs this information processing on the asset information 100 and instruction information 300 and that is accessed by each terminal device 2 may be provided, and the processing may be performed by the processing server. It is sufficient that information is not directly communicated between the device that stores the asset information 100 and instruction information 300 and the device that stores the encryption key K that encrypts and decrypts this information. Furthermore, the information exchange system 1 according to other embodiments of the present invention may be used only for the exchange of asset cryptographic information 110 and instruction cryptographic information 310 between the settlor I and the trustee J, or only for the exchange of asset cryptographic information 110 between the trustee J and the recipient U.
[0070] Although the embodiments of the present invention have been described above, the present invention is not limited to these examples, and it goes without saying that the present invention can be embodied in various forms without departing from the spirit of the present invention. [Explanation of symbols]
[0071] 1. Information exchange system 2. Terminal Device 4. Key Management Server 6 Information Management Server 21 Terminal input / output section 23 Terminal processing section 25 Terminal communication unit 41 Encryption key processing unit 42 Encryption key communication unit 43 Encryption key storage unit 61 Ministry of Information and Communications 62 Information Processing Department 63 Information storage section 100,101,102,103 Asset Information 110,111,112,113 Asset Crypto Information 230 User authentication unit 231 Target Setting Section 232 Information Creation Department 233 Asset information encryption processing unit 234 Asset information decryption processing unit 235 Instruction information encryption processing unit 236 Instruction information decoding processing unit 237 Information Update Department 238 Information Acquisition Department 300 Instruction information 310 Instruction cipher information 411 Association section 412 Key generation section 413 Discrimination part 621 Information Storage Department 622 Acquisition Notification Department 623 Acquisition and Identification Unit G,G1,G2,G11,G12,G13,G31 Association information I Consignor J Trustee K, K1, K2, K11, K12, K13, K31 encryption keys N Network U,U1,U2,U3 recipients
Claims
1. An information transfer system for transferring information between at least two parties, namely, a trustor who creates plaintext asset information on assets and plaintext instruction information on instructions regarding the asset information, a trustee who receives instructions from the trustor based on the instruction information, and a recipient who receives the asset information, the trustor and the trustee or the recipient, an asset information encryption processing unit that encrypts the asset information into ciphertext asset cipher information; an instruction information encryption processing unit that encrypts the instruction information into instruction encryption information of ciphertext; an asset information decryption processing unit that decrypts the asset encryption information into the asset information; an instruction information decryption processing unit that decrypts the instruction encrypted information into the instruction information; a key management unit that manages encryption keys used for encryption in the asset information encryption processing unit and the instruction information encryption processing unit, and for decryption in the asset information decryption processing unit and the instruction information decryption processing unit; a ciphertext storage unit that stores the asset ciphertext information and the instruction ciphertext information, the key management unit includes a determination unit that determines whether a party requesting acquisition of the encryption key is the trustee or the recipient; When the determination unit determines that the person is the trustee, the encryption key is provided from the key management unit to the instruction information decryption processing unit, and the instruction information decryption processing unit decrypts the instruction encrypted information acquired from the ciphertext storage unit using the encryption key into the instruction information, When the discrimination unit determines that the recipient is the recipient, the encryption key is provided from the key management unit to the asset information decryption processing unit, and the asset information decryption processing unit uses the encryption key to decrypt the asset encryption information obtained from the ciphertext storage unit into the asset information.
2. an information updating unit that updates the asset information and the instruction information by the trustor; The determination unit further determines whether the person requesting acquisition of the encryption key is the entrustor, When the determination unit determines that the person is the entrustor, the encryption key is provided from the key management unit to the asset information encryption processing unit and the instruction information encryption processing unit, the asset information encryption processing unit encrypts the asset information updated by the information update unit using the encryption key into asset encryption information; the instruction information encryption processing unit encrypts the instruction information updated by the information updating unit using the encryption key into the instruction encryption information; 2. The information transfer system according to claim 1, wherein the ciphertext storage unit stores the asset cipher information and the instruction cipher information, which are information updated by the information update unit.
3. The information exchange system described in claim 1 or 2, wherein the instruction information encryption processing unit performs a self-erasing encryption process in which the instruction encryption information self-deletes when the instruction encryption information is decrypted without using the encryption key or with an encryption key other than the encryption key.
4. the encryption key is generated based on an association between the entrustor and the trustee who receives the instruction information; the key management unit manages the encryption key as an instruction information encryption key; The information exchange system described in claim 3, wherein the discrimination unit determines that the person requesting acquisition of the instruction information encryption key is the entrustor or the trustee based on the association between the entrustor and the trustee who accepts the instruction information, and the instruction information encryption key is provided from the key management unit to the instruction information decryption processing unit or the instruction information encryption processing unit.
5. The information exchange system described in claim 1 or 2, wherein the asset information encryption processing unit performs a self-erasing encryption process in which the asset encryption information is self-erased when the asset encryption information is decrypted without using the encryption key or with an encryption key other than the encryption key.
6. the encryption key is generated based on an association between the trustor and the recipient who receives the asset information; the key management unit manages the encryption key as an asset information encryption key; The information transfer system described in claim 5, wherein the determination unit determines that the person requesting acquisition of the asset information encryption key is the trustor or the recipient based on the association between the trustor and the recipient who receives the asset information, and the asset information encryption key is provided from the key management unit to the asset information decryption processing unit or the asset information encryption processing unit.
Citation Information
Patent Citations
Testament document management system
JP2006059283A