Information processing apparatus, information processing method, and program
The system addresses the authenticity issue in private key management by distributing confidential data across servers and blockchains with digital signatures, ensuring secure and authentic storage.
Patent Information
- Application Number
- JP2024128155
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-08-02
- Publication Date
- 2026-02-16
AI Technical Summary
Existing private key management systems fail to ensure the authenticity of data fragments if they are tampered with, posing a risk to the protection of highly confidential information.
A system that performs secret sharing of confidential information into multiple shares, registering one share on a data server, another on a blockchain, and a third share on a computer-readable medium, with additional digital signatures and link information for authentication.
Ensures the authenticity and secure storage of highly confidential information by distributing shares across different storage locations, enhancing data integrity and protection.
Smart Images

Figure 2026025410000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device, an information processing method, and a program. [Background technology]
[0002] In recent years, various technologies have been proposed for appropriately protecting highly confidential information. For example, Patent Document 1 discloses a simplified private key management system that can strongly and efficiently protect important information from cyberterrorism and reliably recover important information in the event of a data attack. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2023-107165 Summary of the Invention [Problem to be solved by the invention]
[0004] However, in the private key management simplification system described in Patent Document 1, only the data fragment storage location information is broadcast on the blockchain, so if the data fragment itself is tampered with, there is a risk that the authenticity of the data cannot be guaranteed, and this is still insufficient from the perspective of appropriately protecting highly confidential information.
[0005] The present invention has been made to solve the above-mentioned problems, and has as its object to provide an information processing device, an information processing method, and a program that are capable of appropriately protecting highly confidential information. [Means for solving the problem]
[0006] An information processing device according to a first aspect of the present invention comprises: a management information acquisition unit that acquires highly confidential management information to be managed; a secret sharing processing unit that performs secret sharing processing on the management information acquired by the management information acquisition unit to generate a plurality of shares from the management information; a data registration unit that registers a first share among the plurality of shares generated by the secret sharing processing unit in a data server and registers a second share different from the first share in a data block on a blockchain; The data registration unit registers link information indicating the storage location of the first distributed fragment in the data server together with the second distributed fragment in a data block on the blockchain. It is characterized by:
[0007] In addition, in the information processing device according to the above aspect, The data registration unit registers a third share fragment, which is different from the first share fragment and the second share fragment, among the plurality of share fragments generated by the secret sharing processing unit, in a computer-readable recording medium together with specific information for identifying the blockchain and the data block in which the second share fragment is registered. It is characterized by:
[0008] In addition, in the search device according to the above aspect, a third fragment acquisition unit that acquires the specific information together with the third fragment from the computer-readable recording medium; A second fragment acquisition unit that acquires the link information together with the second fragment from the blockchain and the data block identified by the identification information acquired by the third fragment acquisition unit; a first distribution piece acquisition unit that acquires the first distribution piece from a storage location of the data server indicated by the link information acquired by the second distribution piece acquisition unit; a data restoration unit that restores the management information based on the fragments acquired by the first fragment acquisition unit, the second fragment acquisition unit, and the third fragment acquisition unit; The device is characterized by further comprising:
[0009] In addition, in the search device according to the above aspect, The data registration unit adds a digital signature of an administrator who manages the management information to the third fragment, and registers the third fragment together with specific information for identifying the blockchain in which the second fragment is registered and the data block in a computer-readable recording medium. It is characterized by:
[0010] An information processing method according to a second aspect of the present invention comprises: An information processing method by an information processing device, a management information acquisition step of acquiring highly confidential management information to be managed; a secret sharing processing step of generating a plurality of shares from the management information by performing secret sharing processing on the management information acquired in the management information acquisition step; a data registration step of registering a first share among the plurality of shares generated in the secret sharing processing step in a data server, and registering a second share different from the first share in a data block on a blockchain; In the data registration step, link information indicating the storage location of the first distributed fragment in the data server is registered together with the second distributed fragment in a data block on the blockchain. It is characterized by:
[0011] A program according to a third aspect of the present invention comprises: Computer, a management information acquisition unit that acquires highly confidential management information to be managed; a secret sharing processing unit that performs secret sharing processing on the management information acquired by the management information acquisition unit to generate a plurality of shares from the management information; a data registration unit that registers a first share among the plurality of shares generated by the secret sharing processing unit in a data server and registers a second share different from the first share in a data block on a blockchain; The data registration unit registers link information indicating the storage location of the first distributed fragment in the data server together with the second distributed fragment in a data block on the blockchain. It is characterized by:
[0012] The program may be recorded on a non-transitory recording medium. The non-transitory recording medium can be distributed or sold independently of the computer. Here, a non-transitory recording medium refers to a tangible recording medium. Examples of non-transitory recording media include compact discs, flexible disks, hard disks, magneto-optical disks, digital video disks, magnetic tapes, and semiconductor memories. A transitory recording medium refers to the transmission medium (propagation signal) itself. Examples of transitory recording media include electrical signals, optical signals, and electromagnetic waves. A temporary storage area is an area for temporarily storing data and programs, such as volatile memory such as RAM (Random Access Memory). [Effects of the Invention]
[0013] According to the present invention, it is possible to provide an information processing device, an information processing method, and a program that are capable of appropriately protecting highly confidential information. [Brief explanation of the drawings]
[0014] [Figure 1] FIG. 2 is a diagram illustrating the relationship between an information processing device, a data server, and each node. [Figure 2] FIG. 1 is a block diagram illustrating an example of an information processing device. [Figure 3] 10 is a flowchart illustrating an example of an information management process. [Figure 4] FIG. 1 is an explanatory diagram showing an example of secret sharing. [Figure 5] FIG. 1 is an explanatory diagram illustrating an example of a blockchain. [Figure 6] 10 is a flowchart illustrating an example of a data restoration process. [Figure 7] FIG. 10 is an explanatory diagram illustrating an example of data restoration. DETAILED DESCRIPTION OF THE INVENTION
[0015] (Overall composition) An information processing device, an information processing method, and a program according to an embodiment of the present invention will be described in detail with reference to the drawings. In the drawings, identical or corresponding parts are denoted by the same reference numerals. As shown in FIG. 1, an information processing system 1 according to this embodiment comprises an information processing device 100, a blockchain 200 made up of multiple nodes 200, and a data server 300, all of which are communicatively connected via a computer communication network 400 such as the Internet.
[0016] The information processing device 100 is an information terminal (so-called computer) such as a PC (Personal Computer), tablet, or smartphone for appropriately protecting highly confidential information, and is capable of communicating with the blockchain 200 and the data server 300 via a computer communication network 400. The information processing device 100 registers (stores) common data in each of the nodes 200a to 200g, thereby registering data in a data block of the blockchain 200. The information processing device 100 in this embodiment has a function of performing secret sharing processing on highly confidential information, i.e., management information. In the secret sharing processing, data may be simply shared among multiple pieces, or a threshold secret sharing scheme may be used. In this example, for ease of understanding, the following description will be given using an example in which management information is shared among three pieces, share 1 to share 3, in the secret sharing processing. The information processing device 100 has the following functions: to register fragment 3, which is part of the management information obtained by secret sharing processing, in the data server 300; to register link information in the data server 300 for fragments 1 and 3 in the blockchain 200; and to store fragment 2, for example, in a computer-readable recording medium (flexible disk, CD (Compact Disc)-ROM, DVD (Digital Versatile Disc)-ROM, MO (Magneto-Optical Disc), memory card, USB memory, etc.). Note that fragment 2 may be registered not in a computer-readable recording medium, but in, for example, a digital wallet, which is an electronic information storage service that guarantees information security such as data integrity, reliability, and availability.
[0017] As shown in Fig. 1, the blockchain 200 is composed of multiple nodes including nodes 200a to 200g. Each node is an information terminal (so-called computer) such as a PC, and can communicate with the information processing device 100 via a computer communication network 400. As described above, in the blockchain 200, link information in the data server 300 of distributed pieces 1 and 3 is registered in the data block by the function of the information processing device 100.
[0018] The data server 300 is a server in which the share fragments 3, which are part of the management information obtained by the secret sharing process, are registered, and is capable of communicating with the information processing device 100 via a computer communication network 400.
[0019] (Functional configuration of information processing device) Next, the configuration of the information processing device 100 will be described with reference to FIG.
[0020] As shown in FIG. 2, the information processing device 100 includes a storage unit 110, a control unit 120, an input / output unit 130, a communication unit 140, and a system bus (not shown) that interconnects these units.
[0021] The storage unit 110 includes a ROM (Read Only Memory), a RAM (Random Access Memory), etc. The ROM stores a program 111 to be executed by the control unit 120 and various data (not shown) required in advance for executing the program 111.
[0022] The program 111 is a program for executing information management processing and data restoration processing, which will be described later, and is stored in the storage unit 110 in advance.
[0023] The control unit 120 is configured with a CPU (Central Processing Unit), an ASIC (Application Specific Integrated Circuit), etc. The control unit 120 operates in accordance with a program 111 stored in the storage unit 110, and executes processing in accordance with the program 111. The control unit 120 includes a management information acquisition unit 121, a secret sharing processing unit 122, a data registration unit 123, a link information acquisition unit 124, and a data restoration unit 125 as main functional units provided by the program 111 stored in the storage unit 110.
[0024] The management information acquisition unit 121 is a functional unit that acquires management information, which is highly confidential information to be managed. Specifically, the management information acquisition unit 121 is a functional unit that acquires management information based on a user's operation on the input / output unit 130. The management information may be information stored in the storage unit 110, or may be acquired from an external device via the computer communication network 400. Alternatively, the management information may be acquired by reading the information from a computer-readable recording medium.
[0025] The secret sharing processing unit 122 is a functional unit that performs secret sharing processing on the management information acquired by the management information acquisition unit 121. Specifically, the secret sharing processing unit 122 is a functional unit that distributes the management information into multiple shares using a secret sharing technique such as a threshold sharing method or an AONT (All Or Nothing Transform) method, and generates multiple secret shared data for the management information, which is the original data. For example, if the management information, which is the original data, is 100 MB of data, the secret sharing processing unit 122 in this embodiment generates three shares: a 2 KB share 1, a 2 KB share 2, and a 99.996 MB share 3. Although the management information is distributed into three shares, share 1 to share 3, the number of shares to which the management information is distributed may be two, four or more.
[0026] The data registration unit 123 is a functional unit that registers (stores) each share piece, which is management information distributed by the secret sharing processing unit 122, in the data server 300, the block chain 200, and a computer-readable recording medium. Specifically, the data registration unit 123 registers (stores) share piece 3, which is the share piece with the largest data capacity among the share pieces distributed by the secret sharing processing unit 122, in the data server 300. The data registration unit 123 also registers (stores) share piece 1 in the block chain 200 together with link information indicating the storage location of share piece 3 in the data server 300. The data registration unit 123 then registers (stores) share piece 2 in a computer-readable recording medium. For example, if there are multiple blockchains 200, the blockchain identification information indicating which blockchain 200 the distributed piece 1 corresponding to the distributed piece 2 was registered in is associated with a unique transaction ID issued when the distributed piece 1 is registered in the blockchain 200, and stored together with the distributed piece 2 on a computer-readable recording medium.
[0027] The link information acquisition unit 124 is a functional unit that acquires link information indicating the storage location in the data server 300 of the dispersed piece 3 registered in the data server 300 by the data registration unit 123. Specifically, the link information acquisition unit 124 acquires the storage location in the data server 300 of the dispersed piece 3 stored by the data registration unit 123 from the data server 300 as link information. Note that the link information may be acquired by the function of the data registration unit 123 when the dispersed piece 3 is stored in the data server 300 by the data registration unit 123.
[0028] The data restoration unit 125 is a functional unit that restores management information based on each shared piece registered by the data registration unit 123. Specifically, the data restoration unit 125 acquires a shared piece 2 stored on a computer-readable recording medium, identifies the blockchain 200 based on the blockchain identification information and transaction ID stored together with the shared piece 2, and acquires link information between the shared piece 1 corresponding to the shared piece 2 and the shared piece 3 corresponding thereto. Then, it acquires the shared piece 3 from the data server 300 based on the link information. The data restoration unit 125 restores the original data, which is the management information, based on the corresponding shared pieces 1 to 3 thus acquired.
[0029] The input / output unit 130 is a device that is configured with a keyboard, a mouse, a camera, a microphone, a liquid crystal display, an organic EL (Electro-Luminescence) display, and the like, and is used to input and output various types of data.
[0030] The communication unit 140 is a device that enables the information terminal 200 to communicate with other information terminals such as the block chain 200 (nodes 200a to 200g included in the block chain 200) and the data server 300 via the computer communication network 400. The above is the configuration of the information processing device 100.
[0031] (operation) Next, the operation of the information processing device 100 will be described with reference to Figures 3 to 7. Figure 3 is a flowchart showing an example of information management processing in the information processing device 100. Execution of the information management processing starts when a user operates the input / output unit 130.
[0032] When the information management process starts, the control unit 120 first acquires management information using the function of the management information acquisition unit 121 (step S11). Specifically, in the process of step S11, the management information acquisition unit 121 acquires management information based on a user's operation on the input / output unit 130. Note that the management information acquired in the process of step S11 may be information stored in the storage unit 110, or may be acquired from an external device via the computer communication network 400. Alternatively, the information may be read and acquired from a computer-readable recording medium.
[0033] After executing the process of step S11, the control unit 120 performs secret sharing processing on the management information acquired in the process of step S11 using the function of the secret sharing processing unit 122 (step S12). Specifically, in the process of step S12 in this embodiment, when the management information acquired in the process of step S11 is 100 MB of data, the secret sharing processing unit 122 generates three share pieces: share piece 1 of 2 KB, share piece 2 of 2 KB, and share piece 3 of 99.996 MB, as shown in Fig. 4.
[0034] Returning to FIG. 3, after executing the processing of step S12, the control unit 120 uses the function of the data registration unit 123 to register the distributed piece 3 generated in the processing of step S12 in the data server 300 (step S13). Specifically, in the processing of step S13, the data registration unit 123 records the distributed piece with the largest data capacity among the multiple distributed pieces generated in the processing of step S12 in a predetermined area in the data server 300. For example, as shown in FIG. 4, if the management information acquired in the processing of step S11 is 100 MB of data, and three distributed pieces, 2 KB distributed piece 1, 2 KB distributed piece 2, and 99.996 MB distributed piece 3, are generated in the processing of step S12, the data registration unit 123 records the 99.996 MB distributed piece 3 in a predetermined area in the data server 300 in the processing of step S13.
[0035] Returning to FIG. 3, after executing the processing of step S13, the control unit 120 uses the function of the link information acquisition unit 124 to acquire link information indicating the storage location in the data server 300 of the dispersed piece 3 (step S14). Specifically, in the processing of step S14, the link information acquisition unit 124 acquires the storage location in the data server 300 of the dispersed piece 3 stored by the data registration unit 123 from the data server 300 as link information. Note that this link information may be acquired by the function of the data registration unit 123 when the dispersed piece 3 is stored in the data server 300 by the data registration unit 123, i.e., in the processing of step S13. Furthermore, dispersed piece 3 corresponds to the first dispersed piece.
[0036] After executing the process of step S14, the control unit 120, using the function of the data registration unit 123, registers the shared fragment 1 generated in the process of step S12 in the blockchain 200 together with the link information acquired in the process of step S14 (step S15). Specifically, in the process of step S15, the data registration unit 123 stores the shared fragment 1 generated in the process of step S12 together with the link information acquired in the process of step S14 as transaction data in data block L, which is the data block following data block L-1, which is the previous data block, as shown in FIG. 5. Note that the hash value of data block L-1 is also stored in the data block L. Furthermore, each data block is shared by each node (nodes 200a to 200g) constituting the blockchain 200, and data verification is performed at each node. Furthermore, shared fragment 1 corresponds to the second shared fragment.
[0037] Returning to FIG. 3, after executing the processing of step S15, the control unit 120 uses the function of the data registration unit 123 to register the shared piece 2 generated in the processing of step S12 in a computer-readable recording medium (step S16), and terminates the information management processing. Specifically, in the processing of step S16, if there are multiple blockchains 200, for example, the data registration unit 123 associates blockchain identification information indicating in which blockchain 200 the shared piece 1 corresponding to the shared piece 2 has been registered with a unique transaction ID issued when the shared piece 1 is registered in the blockchain 200, and stores this information together with the shared piece 2 in a computer-readable recording medium. The blockchain identification information and transaction ID may be obtained by registration in the blockchain 200 in the processing of step S15. Note that the blockchain identification information and transaction ID correspond to specific information. Furthermore, the shared piece 2 corresponds to the third shared piece.
[0038] In this way, by performing information management processing in the information processing device 100, management information, which is highly confidential information, becomes multiple distributed fragments and is registered in different areas, such as the blockchain 200, the data server 300, and a computer-readable recording medium, thereby making it possible to appropriately protect the highly confidential information. Also, by storing distributed fragments 1 in the blockchain 200, it is possible to ensure the existence and authenticity of the management information. Furthermore, data that cannot be stored in the blockchain 200 due to its large capacity can also be stored in the blockchain 200.
[0039] Next, the operation of the information processing device 100 when restoring the shares 1 to 3 to management information, which is data before the secret sharing process, will be described, that is, the data restoration process. Fig. 6 is a flowchart showing an example of the data restoration process in the information processing device 100. The data restoration process starts when a user operates the input / output unit 130.
[0040] When the data restoration process starts, the control unit 120 first acquires the distributed fragment 2 recorded on a computer-readable recording medium using the function of the data restoration unit 125 (step S21). Specifically, in the processing of step S21, the data restoration unit 125 acquires the distributed fragment 2 recorded on a computer-readable recording medium, and also acquires blockchain identification information and a transaction ID to identify the blockchain and data block where the distributed fragment 1 corresponding to the distributed fragment 2 is stored.
[0041] After executing the processing of step S21, the control unit 120, using the function of the data restoration unit 125, acquires link information indicating the storage location of the distributed piece 3 corresponding to the acquired distributed piece 2 and the distributed piece 1 corresponding to the distributed piece 2 from the blockchain 200 (step S22). Specifically, in the processing of step S22, the data restoration unit 125 acquires link information indicating the storage location of the distributed piece 3 corresponding to the distributed piece 2 and the distributed piece 1 corresponding to the distributed piece 2 from the data block indicated by the transaction ID in the blockchain 200 indicated by the blockchain identification information acquired in the processing of step S21.
[0042] After executing the process of step S22, the control unit 120 acquires the fragment 3 from the data server 300 using the function of the data restoration unit 125 (step S23). Specifically, in the process of step S23, the data restoration unit 125 acquires the fragment 3 corresponding to the acquired fragment 1 and fragment 2 from the storage location of the data server 300 indicated by the link information acquired in the process of step S22.
[0043] After executing the process of step S23, the control unit 120 restores the management information based on the shares 1 to 3 acquired in the processes of steps S21 to S23 using the function of the data restoration unit 125 (step S24), and ends the data restoration process. Specifically, in the process of step S24, the data restoration unit 125 restores the management information, which is the original data, by performing the reverse process of the secret sharing process performed in the process of step S12 in Fig. 3 on the acquired shares 1 to 3, as shown in Fig. 7.
[0044] In this way, the management information, which is highly confidential information that has been divided into multiple fragments in the information management process, is restored by performing the data restoration process in the information processing device 100. Therefore, in order to restore the management information, it is necessary to obtain fragments 1 to 3, which are registered separately, and data security can be ensured.
[0045] (Variation) It should be noted that the present invention is not limited to the above-described embodiments, and various modifications and applications are possible. For example, the information processing device 100, the blockchain 200, and the data server 300 according to the above-described embodiments do not necessarily have all of the technical features described above, and may have some of the configurations described in the above-described embodiments so as to solve at least one problem in the prior art. Furthermore, at least a portion of each of the following modifications may be combined.
[0046] In the above embodiment, for ease of understanding, an example was shown in which management information is distributed into three pieces, namely, pieces 1 to 3, in the processing of step S12 shown in FIG. 3, but this is just one example. Alternatively, the management information may be distributed into four or more pieces, such as pieces 4 and 5. In this case, for example, in the processing of step S15, piece 4 and the blockchain identification information and transaction ID of the blockchain that stores piece 1 may be stored in a data block of a blockchain different from piece 1. Then, in the processing of step S16, the blockchain identification information indicating which blockchain 200 piece 4 is registered in and the unique transaction ID issued when piece 4 is registered in the blockchain 200 are associated with each other, and stored together with piece 5 in a computer-readable recording medium that is different from the recording medium that stores piece 2. This can further improve security.
[0047] Alternatively, the management information may be distributed to two pieces, a piece 1 and a piece 2. In this case, in the processing of step S13 in FIG. 3, one piece is registered in the data server 200, and the other piece is registered in the blockchain 200 together with link information indicating the storage destination of the piece registered in the data server 200. Then, the blockchain identification information and transaction ID of the blockchain 200 in which this piece is registered are associated with each other and stored in the memory unit 110.
[0048] In the above embodiment, in the processing of step S12 in Fig. 3, for example, when the management information acquired in the processing of step S11 is 100MB of data, an example is shown in which 2KB distributed piece 1, 2KB distributed piece 2, and 99.996MB distributed piece 3 are generated, but this is just an example. The data capacity of each distributed piece generated in the processing of step S12 is not limited to this and can be changed as desired.
[0049] In the above embodiment, the example of recording the fragment with the largest data capacity in a predetermined area in the data server 300 by the processing of step S13 shown in Figure 3 is shown, but this is just one example. The fragment recorded in a predetermined area in the data server 300 is not limited to the fragment with the largest data capacity. Which fragment is recorded (stored) in which can be changed arbitrarily.
[0050] Furthermore, in the above embodiment, an example was shown in which fragment 2 is stored on a computer-readable recording medium, but for example, fragment 2 may be added with a digital signature of a manager of the management information, such as the owner or rights holder of the original data (management information), before being stored on a computer-readable recording medium. This makes it possible to prove ownership and rights of the management information. Note that the digital signature may be added not necessarily to fragment 2, but to either fragment 1 or fragment 3.
[0051] The information processing device 100, the blockchain 200, and the data server 300 according to the above-described embodiments can be realized using a normal computer, without using dedicated devices. For example, the information terminal 200 that executes the above-described processes may be configured by installing a program for executing any of the above-described processes on a computer from a recording medium storing the program on the computer. Also, a single information processing device 100, the blockchain 200, and the data server 300 may be configured by multiple computers operating in cooperation with each other.
[0052] Furthermore, when the above-mentioned functions are realized by sharing the functions between an OS (Operating System) and an application, or by cooperation between the OS and the application, only the parts other than the OS may be stored on the medium.
[0053] It is also possible to superimpose the program on a carrier wave and distribute it via a communication network. For example, the program may be posted on a bulletin board system (BBS) on the communication network and distributed via the network. These programs may then be started and run under the control of an operating system in the same way as other application programs, thereby enabling the above-mentioned processing to be performed.
[0054] The present disclosure allows various embodiments and modifications without departing from the broad spirit and scope of the present disclosure. Furthermore, the above-described embodiments are intended to illustrate the present disclosure and do not limit the scope of the present disclosure. That is, the scope of the present disclosure is defined by the claims, not the embodiments. Various modifications made within the scope of the claims and the meaning of equivalent disclosures are considered to be within the scope of the present disclosure. [Industrial Applicability]
[0055] According to the present invention, it is possible to provide an information processing device, an information processing method, and a program that are capable of appropriately protecting highly confidential information. [Explanation of symbols]
[0056] 1. Information Processing Systems 100 Information processing device 110 Storage section 111 Program 120 control section 121 Management information acquisition department 122 Secret Sharing Processing Unit 123 Data Registration Department 124 Link Information Acquisition Unit 125 Data Recovery Department 130 Input / output section 140 Communications Department 200 Blockchain 200a~200g nodes 300 Data Server 400 Computer Network
Claims
1. a management information acquisition unit that acquires highly confidential management information to be managed; a secret sharing processing unit that performs secret sharing processing on the management information acquired by the management information acquisition unit to generate a plurality of shares from the management information; a data registration unit that registers a first share among the plurality of shares generated by the secret sharing processing unit in a data server and registers a second share different from the first share in a data block on a blockchain; The data registration unit registers link information indicating a storage location of the first distributed piece in the data server together with the second distributed piece in a data block on the blockchain.
1. An information processing device comprising:
2. The data registration unit registers a third share fragment, which is different from the first share fragment and the second share fragment, among the plurality of share fragments generated by the secret sharing processing unit, in a computer-readable recording medium together with specific information for identifying the blockchain and the data block in which the second share fragment is registered.
2. The information processing apparatus according to claim 1, wherein:
3. a third fragment acquisition unit that acquires the specific information together with the third fragment from the computer-readable recording medium; a second fragment acquisition unit that acquires the link information together with the second fragment from the blockchain and the data block identified by the identification information acquired by the third fragment acquisition unit; a first distribution piece acquisition unit that acquires the first distribution piece from a storage location of the data server indicated by the link information acquired by the second distribution piece acquisition unit; a data restoration unit that restores the management information based on the fragments acquired by the first fragment acquisition unit, the second fragment acquisition unit, and the third fragment acquisition unit; 3. The information processing apparatus according to claim 2, further comprising:
4. The data registration unit adds a digital signature of an administrator who manages the management information to the third distributed fragment, and registers the third distributed fragment together with specific information for identifying the blockchain in which the second distributed fragment is registered and the data block in a computer-readable recording medium.
4. The information processing apparatus according to claim 2, wherein the information processing apparatus is a computer.
5. An information processing method by an information processing device, a management information acquisition step of acquiring highly confidential management information to be managed; a secret sharing processing step of generating a plurality of shares from the management information by performing secret sharing processing on the management information acquired in the management information acquisition step; a data registration step of registering a first share among the plurality of shares generated in the secret sharing processing step in a data server, and registering a second share different from the first share in a data block on a blockchain; In the data registration step, link information indicating a storage location of the first distributed piece in the data server is registered together with the second distributed piece in a data block on the blockchain.
1. An information processing method comprising:
6. Computer, a management information acquisition unit that acquires highly confidential management information to be managed; a secret sharing processing unit that performs secret sharing processing on the management information acquired by the management information acquisition unit to generate a plurality of shares from the management information; a data registration unit that registers a first share among the plurality of shares generated by the secret sharing processing unit in a data server and registers a second share different from the first share in a data block on a blockchain; The data registration unit registers link information indicating a storage location of the first distributed piece in the data server together with the second distributed piece in a data block on the blockchain. A program characterized by:
Citation Information
Patent Citations
Data backup system
JP2023107165A