Memory system and information processing system

The memory system addresses the challenges of cost and security in content sharing by implementing a key pair system for secure access logging, enabling efficient and transparent management of digital content among group members.

JP2026035986APending Publication Date: 2026-03-05KIOXIA CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024138479
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-20
Publication Date
2026-03-05

AI Technical Summary

Technical Problem

Existing memory systems face challenges in efficiently managing digital content sharing among group members, particularly in terms of implementation costs and security of content lending, with current methods either requiring expensive server infrastructure or relying on insecure manual management of storage media.

Method used

A memory system equipped with a non-volatile memory and a controller that manages content access and usage through a key pair system, enabling secure communication and logging of access logs among group members, allowing for centralized yet decentralized content management without the need for a server.

Benefits of technology

Facilitates secure, efficient, and cost-effective sharing of digital content among group members by ensuring secure access control and transparent usage tracking, reducing the risk of loss or unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026035986000001_ABST
    Figure 2026035986000001_ABST
Patent Text Reader

Abstract

To provide a memory system capable of easily managing the use of contents by members belonging to a group.SOLUTION: According to an embodiment, a memory system includes a controller used by a first user belonging to a group. The controller manages a first key pair including a first secret key and a first public key, and stores one or more pieces of content information each including one or more pieces of content in the nonvolatile memory. The controller is configured to generate a first access log related to the use of the first content, generate first signature data for the first access log using a first secret key, store the first access log and the first signature data in a non-volatile memory, and transmit the first access log and the first signature data to one or more other memory systems used by one or more users belonging to a group other than the first user.SELECTED DRAWING: Figure 12
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] FIELD Embodiments of the present invention relate to a memory system and an information processing system including a nonvolatile memory. [Background technology]

[0002] In recent years, memory systems equipped with non-volatile memory have become widespread. One such memory system is the solid-state drive (SSD) equipped with NAND flash memory. SSDs are used as the main storage of various computing devices.

[0003] Digital content (hereinafter also simply referred to as content) may be shared and used among multiple members belonging to one group.

[0004] One method for managing such content is to centrally manage the content on a server. In this method, the content is stored in, for example, a memory system built into or connected to the server. Members can use the managed content by accessing the server. However, this method requires, for example, purchasing a server, building an access management system on the server, and operating the access management system, resulting in high implementation costs.

[0005] Another management method that does not use a server is Digital Versatile Disc (DVD). TM ) or SD TMOne method for sharing content is to store it on a storage medium such as a memory card. Compared to memory systems (e.g., SSDs), such storage media have a smaller storage capacity. Therefore, multiple storage media are used to share content. Furthermore, it is necessary to manage lending of shared content to members by associating the content with the storage media on which it is stored. A common management method for this is for members to voluntarily enter the name of the member borrowing the content in a lending list when the content (i.e., the storage media on which the content is stored) is lent. Managing lending by voluntarily entering the name makes it unclear which member currently has the content borrowed, which raises the risk of the content (storage media) being lost or leaked to a third party. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] US Patent Application Publication No. 2016 / 0057117 [Patent Document 2] US Patent Application Publication No. 2005 / 0152542 [Patent Document 3] US Patent Application Publication No. 2020 / 0162439 Summary of the Invention [Problem to be solved by the invention]

[0007] One embodiment provides a memory system and an information processing system that can easily manage the use of content by members belonging to a group. [Means for solving the problem]

[0008] According to an embodiment, a memory system is used by a first user belonging to a group. The memory system includes a non-volatile memory and a controller. The controller is electrically connected to the non-volatile memory. The controller is capable of communicating with one or more other memory systems each used by one or more users belonging to the group other than the first user. The controller manages a first key pair including a first private key and a first public key. The controller stores one or more pieces of content information, each of which includes one or more pieces of content, in the non-volatile memory. When a first user requests use of a first content among the one or more pieces of content, the controller generates a first access log related to the use. The controller generates first signature data for the first access log using the first private key. The controller stores the first access log and the first signature data in the non-volatile memory. The controller transmits the first access log and the first signature data to one or more other memory systems. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is a block diagram showing an example of the configuration of an information processing system including a memory system according to an embodiment. [Figure 2] FIG. 1 is a block diagram showing an example of the configuration of a memory system according to an embodiment. [Figure 3] FIG. 2 is a diagram showing an example of the configuration of a group public key management table used in the memory system according to the embodiment. [Figure 4] FIG. 2 is a diagram showing an example of the configuration of a content information management table used in the memory system according to the embodiment. [Figure 5] FIG. 2 is a diagram showing an example of the configuration of a content usage record management table used in the memory system according to the embodiment. [Figure 6] FIG. 10 is a diagram showing an example of a public key registration operation in an information processing system including a memory system according to an embodiment. [Figure 7] 10 is a diagram showing an example of a public key exchange and registration operation when exchanging a public key with another memory system in the memory system according to the embodiment. FIG. [Figure 8] 10 is a diagram showing an example of a public key verification and registration operation in the memory system according to the embodiment when public key information is received from a plurality of other memory systems. FIG. [Figure 9] FIG. 10 is a diagram showing an example of a content registration operation in an information processing system including a memory system according to an embodiment. [Figure 10] 10A and 10B are diagrams showing an example of content registration and transmission operations when content information is received from a host in the memory system according to the embodiment. [Figure 11] 10 is a diagram showing an example of a content reception and registration operation in the memory system according to the embodiment when content information is received from another memory system. FIG. [Figure 12] 10A and 10B are diagrams showing an example of a usage start information recording operation in an information processing system including a memory system according to an embodiment. [Figure 13] 10 is a diagram showing an example of a usage control and start information recording operation when content usage is requested in the memory system according to the embodiment. FIG. [Figure 14] 10 is a diagram showing an example of start information receiving and recording operations in the memory system according to the embodiment when use start information indicating the start of use of content is received from another memory system. FIG. [Figure 15] 10A and 10B are diagrams showing an example of a usage completion information recording operation in an information processing system including a memory system according to an embodiment. [Figure 16] 10A and 10B are diagrams showing an example of a completion detection and completion information recording operation when content usage is completed in the memory system according to the embodiment. [Figure 17] 10 is a diagram showing an example of a completion information receiving and recording operation in the memory system according to the embodiment when usage completion information indicating completion of content usage is received from another memory system. FIG. [Figure 18] 10 is a flowchart showing an example of a procedure of a public key registration process executed in the memory system according to the embodiment. [Figure 19] 10 is a flowchart showing an example of the procedure of a public key verification and registration process executed in the memory system according to the embodiment. [Figure 20]10 is a flowchart showing an example of the procedure of a usage control and start information recording process executed in the memory system according to the embodiment. [Figure 21] 10 is a flowchart showing an example of a procedure of a completion information recording process executed in the memory system according to the embodiment. [Figure 22] 10 is a flowchart showing an example of the procedure of a usage record verification and registration process executed in the memory system according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0010] Hereinafter, embodiments will be described with reference to the drawings.

[0011] First, referring to FIG. 1, an example configuration of an information processing system 1 including a memory system according to an embodiment will be described. The information processing system 1 is a system for multiple users belonging to one group 7 to share and use digital content (content). The information processing system 1 manages the use (e.g., viewing or browsing) of the shared content. The group 7 is, for example, a small community. Users belonging to the group 7 are also referred to as members or group members. Content is various data that members desire to share. Content includes, for example, video data created by members, e-book data purchased by members, or minutes data, audio data, and video data related to meetings held among members.

[0012] The information processing system 1 includes a plurality of memory systems 3. The plurality of memory systems 3 are, for example, memory systems used by a plurality of members, respectively. The plurality of memory systems 3 are, for example, n memory systems 3-1, 3-2, ..., and 3-n, where n is an integer equal to or greater than 2. The n memory systems 3-1, 3-2, ..., and 3-n are referred to as the first memory system 3-1, the second memory system 3-2, ..., and the nth memory system 3-n, respectively. Note that an unspecified memory system among the n memory systems 3-1, 3-2, ..., and 3-n is also referred to as the memory system 3.

[0013] The information processing system 1 may further include a plurality of host devices 2 (hereinafter referred to as hosts 2). The plurality of hosts 2 are terminals respectively corresponding to the plurality of memory systems 3. The plurality of hosts 2 are, for example, n hosts 2-1, 2-2, ..., and 2-n. The n hosts 2-1, 2-2, ..., and 2-n are referred to as the first host 2-1, the second host 2-2, ..., and the n-th host 2-n, respectively. Note that an unspecified host among the n hosts 2-1, 2-2, ..., and 2-n is also referred to as the host 2.

[0014] The host 2 can use the corresponding memory system 3 as storage. The host 2 may be connected to the corresponding memory system 3 via a cable or a network, or may have the corresponding memory system 3 built in. The host 2 includes an input device that allows a user to input information (data). The input device is, for example, a keyboard and a pointing device such as a mouse or a touchscreen display.

[0015] The memory system 3 is a storage device configured to write data to and read data from a nonvolatile memory. The nonvolatile memory is, for example, a NAND flash memory. The memory system 3 is also called a storage device or a semiconductor storage device. The memory system 3 is realized, for example, as a solid-state drive (SSD) or a hard disk drive (HDD) equipped with a NAND flash memory. The following mainly illustrates the case where the memory system 3 is an SSD.

[0016] FIG. 2 is a block diagram showing an example of the configuration of the memory system 3. As shown in FIG.

[0017] The memory system 3 includes, for example, a nonvolatile memory 4 and a controller 6. The memory system 3 may further include a DRAM 5.

[0018] The nonvolatile memory 4 includes a plurality of blocks. Each of the plurality of blocks functions as the smallest unit of a data erase operation. A block is also called an erase block or a physical block. Each of the plurality of blocks includes a plurality of pages. Each of the plurality of pages includes a plurality of memory cells connected to a single word line. Each of the plurality of pages functions as a unit of a data write operation and a data read operation. Note that one word line may also function as a unit of a data write operation and a data read operation.

[0019] There is an upper limit to the number of program / erase cycles (P / E cycles) for each block, called the maximum number of P / E cycles. One P / E cycle for a block includes a data erase operation to erase all memory cells in the block, and a data program operation to write data to each page of the block.

[0020] The nonvolatile memory 4 stores, for example, a private key 411, a public key 412, a group public key management table 413, a content information management table 414, and one or more content usage record management tables 415.

[0021] The private key 411 and the public key 412 are a key pair corresponding to a member who uses the memory system 3. The private key 411 is used to encrypt data and to decrypt data encrypted using the public key 412. The private key 411 cannot be read from outside the memory system 3 and is not leaked to the outside. The public key 412 is used to encrypt data and to decrypt data encrypted using the private key 411.

[0022] The group public key management table 413 is data for managing the public keys 412 corresponding to each member belonging to one group 7. The group public key management table 413 may be temporarily read from the non-volatile memory 4 to the DRAM 5 (i.e., may be cached in the DRAM 5).

[0023] The content information management table 414 is data for managing one or more pieces of content stored in the nonvolatile memory 4. The one or more pieces of content can be used by members belonging to the group 7. The content information management table 414 may be temporarily read from the nonvolatile memory 4 to the DRAM 5.

[0024] One or more content usage record management tables 415 are associated with one or more pieces of content stored in the non-volatile memory 4. Each of the one or more content usage record management tables 415 is data for managing the usage of the corresponding content. For example, one content usage record management table 415 is generated in response to one piece of content being stored in the non-volatile memory 4. The content usage record management table 415 may be temporarily read from the non-volatile memory 4 to the DRAM 5.

[0025] Group public key management table 413, content information management table 414, and one or more content usage record management tables 415 will be described with reference to FIGS.

[0026] (Group Public Key Management Table 413) 3 shows an example of the configuration of group public key management table 413. Group public key management table 413 includes, for example, multiple entries corresponding to multiple members, each of which includes a member name field, a public key field, a signature member name field, and a signature data field.

[0027] The member name field indicates the name of the corresponding member (member name). The member name is information that can uniquely identify the corresponding member. For example, a character string representing the member name is set in the member name field.

[0028] The public key field indicates the corresponding member's public key 412. The member's public key 412 is a public key that is generated and managed in the memory system 3 used by the member. In the public key field, for example, the public key 412 in Privacy-Enhanced Mail (PEM) format is set.

[0029] The signature member name field and the signature data field are a pair of fields.

[0030] The signature member name field indicates the name of the member who created the signature data for the public key 412 set in the public key field. More specifically, the member who created the signature data is the member who uses the memory system 3 in which the signature data was generated. In the signature member name field, for example, a character string representing the name of the member who created the signature data is set.

[0031] The signature data field indicates signature data for the public key 412 set in the public key field. This signature data is generated in the memory system 3 used by the member set in the signature member name field.

[0032] Each entry may include multiple pairs of signing member name fields and signature data fields. Specifically, each entry may include multiple pairs, such as a pair of a first signing member name field and a first signature data field, and a pair of a second signing member name field and a second signature data field. The number of pairs of signing member name fields and signature data fields included in each entry can be set arbitrarily based on, for example, the number of members belonging to group 7.

[0033] In the example shown in Figure 3, the public key "keyA" of member "A" is associated with the signature data "keysigB" by member "B." This means that the authenticity of the public key "keyA" of member "A" is guaranteed by the signature data "keysigB" by member "B."

[0034] With the above-described configuration of the group public key management table 413, the memory system 3 can securely manage the public keys 412 corresponding to each member.

[0035] (Content Information Management Table 414) 4 shows an example of the configuration of content information management table 414. Content information management table 414 includes one or more entries each corresponding to one or more pieces of content. Each of the one or more entries includes, for example, a content ID field, a content name field, a content body field, and a simultaneous user limit field.

[0036] The content ID field indicates information that can uniquely identify the corresponding content (hereinafter referred to as content ID). As the content ID, for example, a universally unique identifier (UUID) is used.

[0037] The content name field indicates the name of the corresponding content (hereinafter referred to as the content name). The content name is, for example, a character string given by the user who provided (for example, created) the content.

[0038] The content body field indicates the data of the corresponding content itself. For example, if the content is video data, the video data is stored in the content body field.

[0039] The simultaneous user limit field indicates information regarding the limit on the number of people who can simultaneously use the corresponding content. Specifically, the simultaneous user limit field indicates whether there is a limit on the number of people who can simultaneously use the corresponding content, and if there is a limit on the number of people who can simultaneously use the content, indicates that number. If there is no limit on the number of people who can simultaneously use the content, for example, 0 is set in the simultaneous user limit field. If there is a limit on the number of people who can simultaneously use the content, for example, a numerical value indicating that number is set in the simultaneous user limit field.

[0040] Note that content information management table 414 may further include a field indicating the conditions under which the corresponding content can be used (hereinafter referred to as usage conditions) instead of or in addition to the simultaneous user limit field.

[0041] In the example shown in FIG. 4, a limit of five simultaneous users is set for content "dataA" having a content ID of "AAAA" and a content name of "contentA."

[0042] With the above-described configuration of the content information management table 414, the memory system 3 can manage information for members to use content.

[0043] (Content Usage Record Management Table 415) FIG. 5 shows an example configuration of one or more content usage record management tables 415. Each of the one or more content usage record management tables 415 is associated with one or more pieces of content. For example, the one or more content usage record management tables 415 include content usage record management tables 415A, 415B, ..., 415M. Content usage record management table 415A is associated with content having a content ID of "AAAA". Content usage record management table 415B is associated with content having a content ID of "BBBB". Content usage record management table 415M is associated with content having a content ID of "MMMM".

[0044] Each of the one or more content usage record management tables 415 includes a plurality of entries corresponding to a plurality of members, each of which includes, for example, a member name field, an access log field, a usage status field, and a signature data field.

[0045] Here, each field will be explained using as an example the content usage record management table 415A associated with content having a content ID of "AAAA" (hereinafter referred to as content A).

[0046] The member name field indicates the name of the corresponding member (member name).

[0047] The access log field indicates log data (i.e., an access log) related to the use of content A by the corresponding member. The access log includes information indicating, for example, the access date and time, the member name, and the content ID. Specifically, for example, in the case of access to content A by member "A," the access date and time indicates, for example, the date and time when member "A" started or completed using content A. The member name indicates member "A." The content ID indicates content ID "AAAA." The access log may further include other information related to the use of content A.

[0048] The usage status field indicates the usage status of the content A by the corresponding member. In the usage status field, for example, a value (information) indicating unused or completed usage, or a value indicating start of usage is set.

[0049] Unused means that the corresponding member has not yet used content A. Completed use means that the corresponding member has completed (ended) use of content A. In other words, unusable or completed use means that the corresponding member is not currently using content A. As a value indicating unusable or completed use, for example, "0" is set in the usage status field. Note that the usage status field can be set with any information indicating unusable or completed use, not limited to "0".

[0050] The start of use means that the corresponding member has started using content A. In other words, the start of use means that the corresponding member is currently using content A. As a value indicating the start of use, for example, "1" is set in the usage status field. Note that the usage status field is not limited to "1" and any information indicating the start of use can be set.

[0051] Therefore, by counting the total number of entries in the content usage record management table 415A in which "1" is set in the usage status field, the number of people currently using content A can be obtained.

[0052] The signature data field indicates the signature data for the access log set in the access log field. The signature data is used to verify the authenticity of the access log. Specifically, the authenticity of the access log can be verified using the signature data and the corresponding member's public key 412.

[0053] The example of content usage record management table 415A shown in FIG. 5 indicates that member "A" is currently using content A (usage status "1"), and manages an access log "logA" related to member "A's" use of content A and signature data "logsigA" for the access log "logA". Also, it indicates that member "B" is not using content A (usage status "0"), and manages an access log "logB" related to member "B's" use of content A and signature data "logsigB" for the access log "logB". Furthermore, it indicates that member "C" is currently using content A (usage status "1"), and manages an access log "logC" related to member "C's" use of content A and signature data "logsigC" for the access log "logC". In this case, the number of people currently using content A is two.

[0054] With the above-described configuration of content usage record management table 415A, memory system 3 can securely manage the usage status of content A by each member belonging to group 7. Note that content usage record management tables 415B, ..., and 415M each have the same configuration as content usage record management table 415A described above. Therefore, memory system 3 can securely manage the usage status of one or more pieces of content by each member belonging to group 7.

[0055] Return to Figure 2.

[0056] The DRAM 5 is a volatile memory and is provided with a storage area for firmware (FW) 51, for example.

[0057] The FW 51 is a program for controlling the operation of the controller 6. The FW 51 is loaded from the nonvolatile memory 4 to the DRAM 5, for example.

[0058] The controller 6 may be realized by a circuit such as a system-on-a-chip (SoC). The controller 6 is configured to control the nonvolatile memory 4. The functions of each unit in the controller 6 may be realized by dedicated hardware in the controller 6, or may be realized by a processor (e.g., CPU 16) that executes the FW 51.

[0059] The controller 6 may function as a flash translation layer (FTL) configured to perform data management and block management of the nonvolatile memory 4. The data management performed by the FTL includes (1) management of mapping information indicating the correspondence between each logical address and each physical address of the nonvolatile memory 4, and (2) processing for concealing the difference between page-based data read / write operations and block-based data erase operations. The block management includes bad block management, wear leveling, and garbage collection.

[0060] The logical address is used by the host 2 to address a storage area in the memory system 3. The logical address is, for example, a logical block address (LBA).

[0061] The management of the mapping between each logical address and each physical address is performed using, for example, a logical-physical address conversion table. The controller 6 uses the logical-physical address conversion table to manage the mapping between each logical address and each physical address in specific management size units. A physical address corresponding to a certain logical address indicates a physical storage location in the nonvolatile memory 4 to which data at this logical address is written. The controller 6 uses the logical-physical address conversion table to manage multiple storage areas obtained by logically dividing the storage area of ​​the nonvolatile memory 4. These multiple storage areas correspond to multiple logical addresses, respectively. In other words, each of these multiple storage areas is identified by a single logical address. The logical-physical address conversion table may be loaded from the nonvolatile memory 4 to the DRAM 5 when the memory system 3 is started up.

[0062] Data can be written to one page only once per P / E cycle. Therefore, the controller 6 writes updated data corresponding to a certain logical address to a different physical storage location, rather than to the physical storage location where the previous data corresponding to this logical address is stored. The controller 6 then invalidates the previous data by updating the logical-physical address translation table so that the logical address is associated with this different physical storage location. Data referenced by the logical-physical address translation table (i.e., data associated with a logical address) is called valid data. Data not associated with any logical address is called invalid data. Valid data is data that may be read by the host 2 later. Invalid data is data that may no longer be read by the host 2.

[0063] The controller 6 may include, for example, a data communication interface circuit (data communication I / F) 11, a peer-to-peer communication interface circuit (P2P communication I / F) 12, a close-proximity communication interface circuit (close-proximity communication I / F) 13, a memory interface circuit (memory I / F) 14, a DRAM interface circuit (DRAM I / F) 15, and a CPU 16. The data communication I / F 11, the P2P communication I / F 12, the close-proximity communication I / F 13, the memory I / F 14, the DRAM I / F 15, and the CPU 16 may be connected via a bus 10.

[0064] The data communication I / F 11 functions as a circuit that performs data communication with the outside (for example, the host 2). Specifically, the data communication I / F 11 functions as a circuit that receives various commands and data from the outside. The commands include, for example, input / output (I / O) commands and control commands. The I / O commands are, for example, read commands or write commands. The control commands are, for example, flush commands. The data communication I / F 11 also functions as a circuit that transmits responses to commands and data to the outside. When the data communication I / F 11 functions as a circuit that performs communication with the host 2, it is also called a host interface circuit (host I / F). The interface circuit for connecting the memory system 3 and the host 2 is a PCI Express TM (PCIe TM ), Ethernet TM , Fiber channel, NVM Express TM (NVMe TM ) etc. When the memory system 3 is built into the host 2, the data communication I / F 11 can function as a circuit that communicates with any of the components in the host 2.

[0065] The P2P communication I / F 12 functions as a circuit that performs P2P communication with the outside (e.g., another memory system 3). P2P communication is, for example, communication in which data is exchanged directly between two devices without going through a server. Specifically, the P2P communication I / F 12 establishes a P2P connection between the memory system 3 and another memory system 3 without going through a server. The P2P communication I / F 12 functions as a circuit configured to transmit data to the other memory system 3 and receive data from the other memory system 3 in the established P2P connection. The P2P communication I / F 12 complies with standards such as Ethernet and Transmission Control Protocol / Internet Protocol (TCP / IP). In this case, the P2P communication I / F 12 performs P2P communication using, for example, an IP address assigned to each memory system 3. Note that if the memory system 3 is built into the host 2, the P2P communication I / F 12 may perform P2P communication using an IP address assigned to the host 2.

[0066] The proximity communication I / F 13 functions as a circuit that performs proximity communication with the outside (for example, another memory system 3). Proximity communication is communication in which data is exchanged between two devices that are in close proximity. In other words, two devices performing proximity communication are within a range (distance) in which the proximity communication is possible. Proximity communication is performed using, for example, Bluetooth TM In this case, the proximity communication I / F 13 complies with the Bluetooth standard. Specifically, the proximity communication I / F 13 establishes a Bluetooth connection between the memory system 3 and another memory system 3, for example. The proximity communication I / F 13 functions as a circuit configured to transmit data to the other memory system 3 and receive data from the other memory system 3 in the established Bluetooth connection.

[0067] When the memory system 3 is built into the host 2, at least one of the P2P communication I / F 12 and the proximity communication I / F 13 may be provided as a component of the host 2 (i.e., an external component of the memory system 3). In this case, the memory system 3 can communicate with the outside via the P2P communication I / F 12 or the proximity communication I / F 13 provided in the host 2.

[0068] The memory I / F 14 electrically connects the controller 6 and the nonvolatile memory 4. The memory I / F 14 supports interface standards such as Toggle DDR and Open NAND Flash Interface (ONFI).

[0069] The memory I / F 14 functions as a memory control circuit configured to control the nonvolatile memory 4. The memory I / F 14 may be connected to multiple nonvolatile memory chips in the nonvolatile memory 4 via multiple channels. By driving the multiple nonvolatile memory chips in parallel, the bandwidth for accessing the entire nonvolatile memory 4 can be increased.

[0070] The DRAM I / F 15 functions as a DRAM control circuit configured to control access to the DRAM 5 .

[0071] The CPU 16 is a processor configured to control the data communication I / F 11, the P2P communication I / F 12, the proximity communication I / F 13, the memory I / F 14, and the DRAM I / F 15. The CPU 16 performs various processes by executing the FW 51 loaded from the non-volatile memory 4 to the DRAM 5. The FW 51 is a control program including a group of instructions for causing the CPU 16 to perform various processes. The CPU 16 may execute command processing, etc., for processing various commands from the host 2. The operation of the CPU 16 is controlled by the FW 51 executed by the CPU 16.

[0072] The CPU 16 functions as, for example, a key pair generation management unit 160, a public key transmission / reception unit 161, a public key management unit 162, a content management unit 163, a content transmission / reception unit 164, a content usage control unit 165, a usage record management unit 166, a usage record transmission / reception unit 167, a signature unit 168, and a signature verification unit 169. The CPU 16 functions as each of these units by, for example, executing the FW 51.

[0073] The key pair generation management unit 160 generates a key pair corresponding to a member (hereinafter, a first target member) who uses the memory system 3, and manages the generated key pair. The generated key pair is a pair of a private key 411 and a public key 412. The key pair generation management unit 160 generates a key pair in response to, for example, the first target member inputting, via the host 2, the member name and information about the group 7 to which the first target member belongs. The input member name is the name of the first target member. The input information about the group 7 is information that can uniquely identify the group 7 to which the first target member belongs. The key pair generation management unit 160 stores the generated key pair, for example, in the non-volatile memory 4.

[0074] The public key transmitting / receiving unit 161 is configured to transmit information about the public key 412 of the first target member to another memory system 3, and to receive information about the public key 412 of another member belonging to the group 7 from another memory system 3. Specifically, the public key transmitting / receiving unit 161 transmits information about the public key 412 of the first target member to another memory system 3 via either the proximity communication I / F 13 or the P2P communication I / F 12. In addition, the public key transmitting / receiving unit 161 receives information about the public key 412 of another member from another memory system 3 via either the proximity communication I / F 13 or the P2P communication I / F 12.

[0075] The public key management unit 162 manages the public key 412 of each member using the group public key management table 413. Specifically, the public key management unit 162 registers (stores) information about the public key 412 of another member in the group public key management table 413. That is, the public key management unit 162 adds an entry including information about the public key 412 of the other member to the group public key management table 413. Alternatively, the public key management unit 162 updates the entry in the group public key management table 413 corresponding to the other member by using at least a part of the information about the other member's public key 412. Note that the public key management unit 162 may also register information about the public key 412 of the first target member in the group public key management table 413.

[0076] The content management unit 163 manages one or more pieces of content using the content information management table 414. Specifically, the content management unit 163 receives, for example, information about the content input in response to an operation by the first target member (hereinafter, content information) from the host 2 via the data communication I / F 11. Alternatively, the content management unit 163 may receive the content information from the content transmission / reception unit 164. The content information includes, for example, a content ID, a content name, the content (i.e., the content itself), and usage conditions. The content management unit 163 registers (stores) the received content information in the content information management table 414. The content management unit 163 sends the content information received from the host 2 via the data communication I / F 11 and registered in the content information management table 414 to the content transmission / reception unit 164.

[0077] The content transmitting / receiving unit 164 is configured to transmit content information to another memory system 3 and receive content information from another memory system 3. Specifically, the content transmitting / receiving unit 164 transmits the content information received from the content management unit 163 to the other memory system 3 via the P2P communication I / F 12. As a result, the content information is registered in the content information management table 414 in the other memory system 3. In addition, the content transmitting / receiving unit 164 transmits the content information received from the other memory system 3 via the P2P communication I / F 12 to the content management unit 163. The transmitted content information is registered in the content information management table 414 by the content management unit 163.

[0078] The content usage control unit 165 controls the use of each content by the first target member. Specifically, when the host 2 requests the first target member to use content (hereinafter, target content), the content usage control unit 165 controls the use of the target content using the content information management table 414. If the usage conditions of the target content are met, the content usage control unit 165 transmits the target content to the host 2 via the data communication I / F 11 and generates an access log regarding the use of the target content by the first target member. This allows the first target member to use the target content. On the other hand, if the usage conditions of the target content are not met, the content usage control unit 165 notifies the host 2 via the data communication I / F 11 that the target content cannot be used. Therefore, the first target member cannot use the target content.

[0079] The content usage control unit 165 also detects that the first target member has completed using the target content. The content usage control unit 165 determines that the use of the content is complete when, for example, a threshold time has elapsed since the start of use of the target content, which is the time required to play the entire target content plus a certain time. For example, if the time required to play the entire target content is one hour and the certain time is one hour, the threshold time is two hours. Alternatively, the content usage control unit 165 may determine that the use of the target content is complete when, after the start of use of the target content, a period of time during which a request to read at least a portion of the target content data from the non-volatile memory 4 (e.g., a read command) has not been received from the host 2 exceeds a threshold (i.e., a timeout).

[0080] The usage record management unit 166 uses the content usage record management table 415 to manage the start and end of content usage by group members.

[0081] Specifically, the usage record management unit 166 stores (registers) information indicating that the first target member has started using the target content (hereinafter referred to as usage start information) in the content usage record management table 415 in the non-volatile memory 4. The usage start information includes, for example, an access log, a value indicating the start of usage, and signature data for the access log. The usage record management unit 166 works in conjunction with the signature unit 168 (described later) to generate signature data for the access log using the private key 411. The usage record management unit 166 sends the usage start information to the usage record transmission / reception unit 167.

[0082] Furthermore, the usage record management unit 166 stores information indicating that the first target member has completed using the target content (hereinafter referred to as usage completion information) in the content usage record management table 415 in the non-volatile memory 4. The usage completion information includes, for example, an access log, a value indicating completion of use, and signature data for the access log. The usage record management unit 166 sends the usage completion information to the usage record transmission / reception unit 167.

[0083] The usage record transmitting / receiving unit 167 is configured to transmit usage start information or usage completion information to the memory systems 3 used by other group members, and to receive usage start information or usage completion information from the memory systems 3 used by other group members, via the P2P communication I / F 12. The other group members are members other than the first target member who belongs to the group 7. Specifically, the usage record transmitting / receiving unit 167 transmits the usage start information or usage completion information received from the usage record management unit 166 to the memory systems 3 used by other group members. In the memory system 3 that receives the usage start information or usage completion information, the information can be registered in the content usage record management table 415. In addition, the usage record transmitting / receiving unit 167 receives the usage start information or usage completion information from the memory systems 3 used by other group members. The usage record transmitting / receiving unit 167 sends the received usage start information or usage completion information to the usage record management unit 166.

[0084] The usage record management unit 166 receives usage start information or usage completion information from the usage record transmission / reception unit 167. If the authenticity of the access log included in the received usage start information or usage completion information is confirmed, the usage record management unit 166 stores (registers) the usage start information or usage completion information in the content usage record management table 415. The usage record management unit 166 cooperates with the signature verification unit 169, which will be described later, to obtain the verification result of the authenticity of the access log.

[0085] Signature unit 168 uses private key 411 to generate signature data for specific data. The specific data is, for example, public key 412 or an access log. Specifically, signature unit 168 calculates a hash value of the specific data using a specific hash function. The specific hash function is, for example, a hash function defined in advance in information processing system 1. Signature unit 168 then generates signature data by encrypting the calculated hash value using private key 411.

[0086] The signature verification unit 169 verifies the authenticity of specific data using a public key 412 (hereinafter referred to as verification public key 412) and signature data for that data. The specific data is, for example, a public key 412 different from the verification public key 412, or an access log. The verification public key 412 is a public key 412 that is presumed to be paired with the private key 411 that is presumed to have been used to generate the signature data. In other words, the verification public key 412 is a public key 412 that corresponds to the member that is presumed to have generated the signature data.

[0087] Specifically, the signature verification unit 169 generates a hash value by decrypting the signature data using the verification public key 412. The signature verification unit 169 calculates a hash value of the data to be verified for authenticity using a specific hash function. If these two hash values ​​match, the signature verification unit 169 determines that the authenticity of the data has been confirmed. The signature verification unit 169 may generate (output) a verification result indicating that the authenticity of the data has been confirmed. On the other hand, if these two hash values ​​do not match, the signature verification unit 169 determines that the authenticity of the data has not been confirmed. The signature verification unit 169 may generate a verification result indicating that the authenticity of the data has not been confirmed.

[0088] With the above configuration, the memory system 3 manages the use of content by each member.

[0089] Next, a more detailed description will be given of the operations in the information processing system 1. The operations in the information processing system 1 include, for example, a public key registration operation, a content registration operation, a usage start information recording operation, and a usage completion information recording operation.

[0090] (Public key registration operation) 6 shows an example of a public key registration operation in the information processing system 1. The public key registration operation is an operation for registering a member's public key 412 together with signature data for that public key 412 in a group public key management table 413 in a plurality of memory systems 3 used by the plurality of members. The public key registration operation is performed, for example, when public keys 412 are exchanged between two adjacent memory systems 3.

[0091] Here, the public key registration operation in the first memory system 3-1, the second memory system 3-2, and the third memory system 3-3 will be illustrated. The first memory system 3-1 and the second memory system 3-2 are assumed to be located within a range where close-proximity communication is possible.

[0092] The first memory system 3-1 is used by the first member 9-1. The first memory system 3-1 is, for example, built into the first host (first terminal) 2-1. The first memory system 3-1 may be provided outside the first host 2-1 and connected to the first host 2-1. The first memory system 3-1 manages the group public key management table 413-1.

[0093] The second memory system 3-2 is used by the second member 9-2. The second memory system 3-2 is, for example, built into the second host (second terminal) 2-2. The second memory system 3-2 may be provided outside the second host 2-2 and connected to the second host 2-2. The second memory system 3-2 manages the group public key management table 413-2.

[0094] The third memory system 3-3 is used by the third member 9-3. The third memory system 3-3 is, for example, built into the third host (third terminal) 2-3. The third memory system 3-3 may be provided outside the third host 2-3 and connected to the third host 2-3. The third memory system 3-3 manages a group public key management table 413-3.

[0095] The first member 9-1, the second member 9-2, and the third member 9-3 belong to one group 7.

[0096] A specific example of the public key registration operation will be described below.

[0097] First, the first memory system 3-1 receives the owner information of the first memory system 3-1 and information on the group 7 to which the first member 9-1 belongs (hereinafter referred to as group information) input to the first host 2-1 in response to an operation by the first member 9-1 ((1) in FIG. 6). The owner information is the member name of the first member 9-1 (hereinafter referred to as the first member name). The group information is information that can uniquely identify the corresponding group. More specifically, the first member 9-1 performs an operation to input the owner information and group information, for example, using an input device provided in the first host 2-1. The first memory system 3-1 receives the input owner information and group information from the first host 2-1 via the data communication I / F 11.

[0098] In response to receiving the owner information and group information, the first memory system 3-1 generates a key pair including a first secret key 411-1 and a first public key 412-1 ((2) in FIG. 6). The first secret key 411-1 and the first public key 412-1 are a key pair corresponding to the first member 9-1. The first memory system 3-1 may add an entry including the first member name and the first public key 412-1 to the group public key management table 413-1.

[0099] 6 is also performed in the second memory system 3-2. That is, in response to receiving the owner information (second member name) and group information regarding the second member 9-2 from the second host 2-2, the second memory system 3-2 generates a key pair including a second secret key 411-2 and a second public key 412-2. The second secret key 411-2 and the second public key 412-2 are the key pair corresponding to the second member 9-2.

[0100] 6 is also performed in the third memory system 3-3. In response to receiving the owner information (third member name) and group information related to the third member 9-3 from the third host 2-3, the third memory system 3-3 generates a key pair including a third private key 411-3 and a third public key 412-3. The third private key 411-3 and the third public key 412-3 are the key pair corresponding to the third member 9-3.

[0101] Next, the first memory system 3-1 and the second memory system 3-2, which are located within a proximity communication range, exchange the first public key 412-1 and the second public key 412-2 through proximity communication ((3) in FIG. 6). In other words, the first member 9-1 and the second member 9-2 confirm each other's identities in person and then have the first memory system 3-1 and the second memory system 3-2 exchange the first public key 412-1 and the second public key 412-2. More specifically, the first memory system 3-1 transmits the first member name and the first public key 412-1 to the second memory system 3-2 via the proximity communication I / F 13, and receives the second member name and the second public key 412-2 from the second memory system 3-2. In addition, the second memory system 3-2 transmits the second member name and the second public key 412-2 to the first memory system 3-1 via the proximity communication I / F 13, and receives the first member name and the first public key 412-1 from the first memory system 3-1.

[0102] The first memory system 3-1 generates signature data (hereinafter, signature data A) for the received second public key 412-2 using the first private key 411-1 ((4) in FIG. 6). Specifically, the first memory system 3-1 calculates a hash value of the second public key 412-2 using, for example, a specific hash function. The first memory system 3-1 generates signature data A by encrypting the calculated hash value using the first private key 411-1.

[0103] Next, the first memory system 3-1 stores (registers) information about the second public key 412-2 (hereinafter, second public key information) in the group public key management table 413-1 in the non-volatile memory 4 ((5) in FIG. 6). The second public key information includes, for example, the second member name, the second public key 412-2, the first member name, and signature data A. Specifically, the first memory system 3-1 adds, for example, an entry including the second public key information to the group public key management table 413-1. Note that if an entry including the second member name and the second public key 412-2 already exists in the group public key management table 413-1, the first memory system 3-1 adds, for example, part of the second public key information to that entry. The part of the second public key information is, for example, the first member name and signature data A.

[0104] Hereinafter, adding an entry including information about public key 412 (hereinafter referred to as public key information) to group public key management table 413, or adding part of the public key information to an entry in group public key management table 413, is also referred to as registering public key information in group public key management table 413. The public key information includes, for example, public key 412, the member name corresponding to public key 412, signature data for public key 412, and the name of the member who generated the signature data (more specifically, the member name corresponding to private key 411 used to generate the signature data). The part of the public key information is, for example, the signature data for public key 412 and the name of the member who generated the signature data.

[0105] 6 is also performed in the second memory system 3-2. That is, the second memory system 3-2 generates signature data (hereinafter, signature data B) for the first public key 412-1 using the second secret key 411-2. Then, the second memory system 3-2 registers the first public key 412-1 together with the signature data B in the group public key management table 413-2.

[0106] Next, the first memory system 3-1 transmits the second public key information registered in the group public key management table 413-1 to the memory systems 3 used by group members other than the second member 9-2 via P2P communication ((6-1) in FIG. 6). Specifically, the first memory system 3-1 transmits the second public key information to the memory systems 3 used by group members other than the first member 9-1 and the second member 9-2 (the third memory system 3-3 in FIG. 6) via, for example, the P2P communication I / F 12. The first memory system 3-1 may, for example, have previously acquired information for performing P2P communication with the other memory systems 3 used by the group members.

[0107] Furthermore, the second memory system 3-2 transmits information about the first public key 412-1 registered in the group public key management table 413-2 (hereinafter referred to as first public key information) to the memory systems 3 used by group members other than the first member 9-1 via P2P communication ((6-2) in FIG. 6). The first public key information includes, for example, the first member name, the first public key 412-1, the second member name, and signature data B. Specifically, the second memory system 3-2 transmits the first public key information to the memory systems 3 used by group members other than the first member 9-1 and the second member 9-2 (the third memory system 3-3 in FIG. 6) via, for example, the P2P communication I / F 12. The second memory system 3-2 may, for example, have previously acquired information for P2P communication with the memory systems 3 used by the group members.

[0108] The third memory system 3-3 receives the second public key information from the first memory system 3-1 via the P2P communication I / F 12. The third memory system 3-3 also receives the first public key information from the second memory system 3-2 via the P2P communication I / F 12.

[0109] The third memory system 3-3 verifies the authenticity of the first public key 412-1 and the authenticity of the second public key 412-2 using the received first public key information and second public key information ((7) in FIG. 6). Specifically, the third memory system 3-3 verifies the authenticity of the first public key 412-1 using the second public key 412-2 included in the second public key information and the signature data B included in the first public key information. The third memory system 3-3 also verifies the authenticity of the second public key 412-2 using the first public key 412-1 included in the first public key information and the signature data A included in the second public key information.

[0110] The following describes a method in which the third memory system 3-3 verifies the authenticity of the first public key 412-1 using the second public key 412-2 and the signature data B. The third memory system 3-3 generates a hash value by decrypting the signature data B using the second public key 412-2. The third memory system 3-3 calculates the hash value of the first public key 412-1 using a specific hash function. If these two hash values ​​match, the third memory system 3-3 determines that the authenticity of the first public key 412-1 has been confirmed. If these two hash values ​​differ, the third memory system 3-3 determines that the authenticity of the first public key 412-1 has not been confirmed.

[0111] The following describes a method in which the third memory system 3-3 verifies the authenticity of the second public key 412-2 using the first public key 412-1 and the signature data A. The third memory system 3-3 generates a hash value by decrypting the signature data A using the first public key 412-1. The third memory system 3-3 calculates the hash value of the second public key 412-2 using a specific hash function. If these two hash values ​​match, the third memory system 3-3 determines that the authenticity of the second public key 412-2 has been confirmed. If these two hash values ​​differ, the third memory system 3-3 determines that the authenticity of the second public key 412-2 has not been confirmed.

[0112] Here, it is assumed that the authenticity of first public key 412-1 and second public key 412-2 has been confirmed.

[0113] The third memory system 3-3 updates the group public key management table 413-3 with information about the first public key 412-1 and second public key 412-2 whose authenticity has been confirmed (i.e., the first public key information and the second public key information) ((7) in Figure 6).

[0114] Specifically, the third memory system 3-3 uses the first public key information to add (store) to the group public key management table 413-3, for example, an entry including the first member name, the first public key 412-1, the second member name, and the signature data B. Note that if an entry including the first member name and the first public key 412-1 already exists in the group public key management table 413-3, the third memory system 3-3 adds, for example, the second member name and the signature data B to that entry.

[0115] Furthermore, the third memory system 3-3 uses the second public key information to add, for example, an entry including the second member name, the second public key 412-2, the first member name, and the signature data A to the group public key management table 413-3. Note that if an entry including the second member name and the second public key 412-2 already exists in the group public key management table 413-3, the third memory system 3-3 adds, for example, the first member name and the signature data A to that entry.

[0116] By the above public key registration operation, the member's public key 412 can be registered in the group public key management table 413 in the memory system 3 together with the signature data for that public key 412 .

[0117] Specifically, the first memory system 3-1 registers the second public key 412-2 of the second member 9-2 in the group public key management table 413-1 together with signature data A by the first member 9-1 for the second public key 412-2. The second memory system 3-2 registers the first public key 412-1 of the first member 9-1 in the group public key management table 413-2 together with signature data B by the second member 9-2 for the first public key 412-1. The first memory system 3-1 and the second memory system 3-2 exchange the first public key 412-1 and the second public key 412-2 through near-field communication (i.e., the first member 9-1 and the second member 9-2 face-to-face). Therefore, the authenticity of second public key 412-2 can be guaranteed in group public key management table 413-1, and the authenticity of first public key 412-1 can be guaranteed in group public key management table 413-2.

[0118] Furthermore, the third memory system 3-3 registers the first public key 412-1 of the first member 9-1 in the group public key management table 413-3 together with the signature data B used to verify the authenticity of the first public key 412-1. The third memory system 3-3 registers the second public key 412-2 of the second member 9-2 in the group public key management table 413-3 together with the signature data A used to verify the authenticity of the second public key 412-2. Therefore, in the group public key management table 413-3, the authenticity of the first public key 412-1 can be guaranteed by the signature data B, and the authenticity of the second public key 412-2 can be guaranteed by the signature data A.

[0119] With reference to FIGS. 7 and 8, the internal operation of each memory system 3 will be described in more detail regarding the public key registration operation.

[0120] FIG. 7 shows an example of a public key exchange and registration operation in a memory system 3 when exchanging a public key with another memory system 3. Here, the public key exchange and registration operation in the first memory system 3-1 is illustrated when the first memory system 3-1 exchanges a public key 412 with the second memory system 3-2. While exchanging the public key 412, the first memory system 3-1 and the second memory system 3-2 are located within a range where proximity communication is possible. In the first memory system 3-1 shown in FIG. 7, the data communication I / F 11, P2P communication I / F 12, proximity communication I / F 13, key pair generation management unit 160, public key transmission / reception unit 161, public key management unit 162, signature unit 168, which are related to the public key exchange and registration operation, as well as the first private key 411-1, first public key 412-1, and group public key management table 413-1 in the nonvolatile memory 4 are shown.

[0121] In the first memory system 3-1, the public key transmission / reception unit 161 and the public key management unit 162 receive the first member name and group information from the host 2 via the data communication I / F 11 ((1) in FIG. 7). The first member name and group information may be provided to other units in the first memory system 3-1.

[0122] For example, in response to receiving the first member name and group information from the host 2, the key pair generation management unit 160 generates a key pair including a first secret key 411-1 and a first public key 412-1 ((2) in FIG. 7). The key pair generation management unit 160 stores the first secret key 411-1 and the first public key 412-1 in the non-volatile memory 4.

[0123] When the first memory system 3-1 exchanges public keys 412 with the second memory system 3-2, the public key transceiver 161 reads the first public key 412-1 from the nonvolatile memory 4 ((3) in FIG. 7). Then, the public key transceiver 161 transmits the first member name and the first public key 412-1 to the second memory system 3-2 via the proximity communication I / F 13 ((4) in FIG. 7). As a result, in the second memory system 3-2, the first public key 412-1 associated with the first member name is registered in the group public key management table 413-2.

[0124] Furthermore, the public key transmitting / receiving unit 161 receives the second member name and the second public key 412-2 from the second memory system 3-2 via the proximity communication I / F 13 ((5) in FIG. 7). Note that the public key transmitting / receiving unit 161 may transmit the first member name and the first public key 412-1 to the second memory system 3-2 after receiving the second member name and the second public key 412-2 from the second memory system 3-2. The public key transmitting / receiving unit 161 sends the received second member name and second public key 412-2 to the public key management unit 162 ((6) in FIG. 7).

[0125] Public key management unit 162 receives the second member name and second public key 412-2 from public key transmission / reception unit 161, and sends second public key 412-2 to signature unit 168 ((7) in FIG. 7).

[0126] In response to receiving second public key 412-2 from public key management unit 162, signing unit 168 reads first secret key 411-1 from non-volatile memory 4 ((8) in FIG. 7). Signing unit 168 generates signature data A for second public key 412-2 using first secret key 411-1, and sends signature data A to public key management unit 162 ((9) in FIG. 7).

[0127] The public key management unit 162 registers the second public key information, including the second member name, second public key 412-2, first member name, and signature data A, in the group public key management table 413-1 ((10) in FIG. 7). Then, the public key management unit 162 sends the second public key information to the public key transmission / reception unit 161 ((11) in FIG. 7).

[0128] The public key transmitting / receiving unit 161 transmits the second public key information received from the public key managing unit 162 to the third memory system 3-3 via the P2P communication I / F 12 ((12) in FIG. 7). As a result, in the third memory system 3-3, the group public key management table 413-3 is updated using the second public key information.

[0129] As a result of the above public key exchange and registration operation in the first memory system 3-1, the second public key 412-2 (second public key information) is registered in the group public key management table 413-1 in the first memory system 3-1. Also, the first public key 412-1 (first public key information) is registered in the group public key management table 413-2 in the second memory system 3-2. Furthermore, the second public key 412-2 (second public key information) is registered in the group public key management table 413-3 in the third memory system 3-3.

[0130] Note that, in other memory systems 3 than the first memory system 3-1, when exchanging public keys 412 with other memory systems 3 through near field communication, a similar public key exchange and registration operation is performed.

[0131] 8 shows an example of public key verification and registration operations in a memory system 3 when public key information is received from a plurality of other memory systems 3. Here, an example is shown of public key verification and registration operations in a third memory system 3-3 when public key information is received from a first memory system 3-1 and a second memory system 3-2. In the third memory system 3-3 shown in FIG. 8, the P2P communication I / F 12, public key transmission / reception unit 161, public key management unit 162, signature verification unit 169, and group public key management table 413-3 in non-volatile memory 4, which are related to the public key verification and registration operations, are shown.

[0132] In the third memory system 3-3, the public key transmitting / receiving unit 161 receives second public key information from the first memory system 3-1 via the P2P communication I / F 12 ((1) in FIG. 8). The second public key information includes the second member name, the second public key 412-2, the first member name, and signature data A. The public key transmitting / receiving unit 161 also receives first public key information from the second memory system 3-2 via the P2P communication I / F 12 ((2) in FIG. 8). The first public key information includes the first member name, the first public key 412-1, the second member name, and signature data B. The public key transmitting / receiving unit 161 may receive the first public key information and the second public key information in any order. The public key transmitting / receiving unit 161 sends the first public key information and the second public key information to the public key management unit 162 ((3) in FIG. 8).

[0133] The public key management unit 162 sends the first public key 412-1 and signature data B included in the first public key information, and the second public key 412-2 included in the second public key information to the signature verification unit 169 ((4) in FIG. 8). The signature verification unit 169 verifies the authenticity of the first public key 412-1 using the signature data B and the second public key 412-2, and sends the verification result to the public key management unit 162 ((5) in FIG. 8). Then, if the verification result indicates that the authenticity of the first public key 412-1 has been confirmed, the public key management unit 162 registers the first public key information in the group public key management table 413-3 ((6) in FIG. 8).

[0134] Furthermore, the public key management unit 162 sends the second public key 412-2 and signature data A included in the second public key information, and the first public key 412-1 included in the first public key information to the signature verification unit 169 ((7) in FIG. 8). The signature verification unit 169 verifies the authenticity of the second public key 412-2 using the signature data A and the first public key 412-1, and sends the verification result to the public key management unit 162 ((8) in FIG. 8). Then, if the verification result indicates that the authenticity of the second public key 412-2 has been confirmed, the public key management unit 162 registers the second public key information in the group public key management table 413-3 ((9) in FIG. 8).

[0135] Public key management unit 162 and signature verification unit 169 may perform operations (4), (5), and (6) after performing operations (7), (8), and (9) in Fig. 8. Alternatively, public key management unit 162 and signature verification unit 169 may perform operations (4) and (5) and operations (7) and (8) in Fig. 8 before performing operations (6) and (9).

[0136] Through the above public key verification and registration operation in the third memory system 3-3, information (first public key information) regarding the first public key 412-1 whose authenticity has been confirmed, and information (second public key information) regarding the second public key 412-2 whose authenticity has been confirmed can be registered in the group public key management table 413-3 within the third memory system 3-3.

[0137] It should be noted that in other memory systems 3 than the third memory system 3-3, when public key information is received from each of the other memory systems 3 through P2P communication, a similar public key verification and registration operation is performed.

[0138] (Content registration operation) In the information processing system 1, content is shared and used by multiple members belonging to a group 7. Therefore, content registered (stored) in the memory system 3 used by one member is also registered in the memory systems 3 used by other members.

[0139] 9 shows an example of a content registration operation in the information processing system 1. The content registration operation is an operation for registering content and information related to the content in the content information management table 414 in multiple memory systems 3 used by multiple members, respectively.

[0140] Here, content registration operations in the first memory system 3-1, the second memory system 3-2, and the third memory system 3-3 are illustrated. The first memory system 3-1 manages a content information management table 414-1. The second memory system 3-2 manages a content information management table 414-2. The third memory system 3-3 manages a content information management table 414-3.

[0141] A specific example of the content registration operation will be described below.

[0142] First, the first memory system 3-1 receives content information input to the first host 2-1 in response to an operation by the user 9-L ((1) in FIG. 9). The user 9-L may be the same user as the first member 9-1, or a different user. The content information includes, for example, a content ID, a content name, the content itself, and information indicating the usage conditions of the content. The information indicating the usage conditions of the content indicates, for example, a limit on the number of simultaneous users of the content. Specifically, the user 9-L performs an operation to input content information using, for example, an input device provided in the first host 2-1. The first memory system 3-1 receives the input content information from the first host 2-1 via the data communication I / F 11.

[0143] The first memory system 3-1 stores (registers) the received content information in the content information management table 414-1 in the non-volatile memory 4 ((2) in FIG. 9). That is, the first memory system 3-1 adds an entry including the content ID, content name, content body, and usage conditions (e.g., limit on the number of simultaneous users) to the content information management table 414-1 based on the content information.

[0144] Next, the first memory system 3-1 transmits the content information to the memory systems 3 used by the other group members via P2P communication ((3) in FIG. 9). Specifically, the first memory system 3-1 transmits the content information to the second memory system 3-2 via the P2P communication I / F 12. The first memory system 3-1 also transmits the content information to the third memory system 3-3 via the P2P communication I / F 12.

[0145] The second memory system 3-2 registers the content information received from the first memory system 3-1 in the content information management table 414-2 ((4-1) in FIG. 9). Also, the third memory system 3-3 registers the content information received from the first memory system 3-1 in the content information management table 414-2 ((4-2) in FIG. 9).

[0146] Through the above content registration operation, the first memory system 3-1 can register the content information input to the first memory system 3-1 from the first host 2-1 in the content information management table 414-1 within the first memory system 3-1. Furthermore, the first memory system 3-1 can also register the same content information in the content information management table 414-2 within the second memory system 3-2 and the content information management table 414-3 within the third memory system 3-3, which are used by other group members.

[0147] In addition, in the case where content information is input from the second host 2-2 to the second memory system 3-2, and in the case where content information is input from the third host 2-3 to the third memory system 3-3, the content information can be registered in the content information management table 414 not only in the memory system 3 to which the content information was input, but also in the content information management table 414 in the memory system 3 used by other group members.

[0148] 10 and 11, the internal operation of each memory system 3 will be described in more detail regarding the content registration operation.

[0149] 10 shows an example of content registration and transmission operations in the memory system 3 when content information is received from the host 2. Here, the content registration and transmission operations in the first memory system 3-1 when content information is received from the first host 2-1 are illustrated. In the first memory system 3-1 shown in FIG. 10, the data communication I / F 11, P2P communication I / F 12, content management unit 163, content transmission / reception unit 164, and content information management table 414-1 in the non-volatile memory 4, which are related to the content registration and transmission operations, are shown.

[0150] In the first memory system 3-1, the content management unit 163 receives content information from the first host 2-1 via the data communication I / F 11 ((1) in FIG. 10). The content management unit 163 registers the content information in the content information management table 414-1 ((2) in FIG. 10). That is, the content management unit 163 adds an entry including the content ID, content name, content body, and usage conditions to the content information management table 414-1. Then, the content management unit 163 sends the content information to the content transmission / reception unit 164 ((3) in FIG. 10).

[0151] The content transmitting / receiving unit 164 transmits the content information received from the content managing unit 163 to the second memory system 3-2 and the third memory system 3-3 via the P2P communication I / F 12 ((4) in FIG. 10).

[0152] By the above content registration and transmission operations in the first memory system 3-1, the content information is registered in the content information management table 414-1 in the first memory system 3-1. In addition, the content information transmitted by the first memory system 3-1 is registered in the content information management table 414-2 in the second memory system 3-2 and the content information management table 414-3 in the third memory system 3-3.

[0153] It should be noted that in other memory systems 3 than the first memory system 3-1, when receiving content information from the corresponding host 2, similar content registration and transmission operations are performed.

[0154] 11 shows an example of content reception and registration operations in a memory system 3 when content information is received from another memory system 3. Here, the content reception and registration operations in a second memory system 3-2 when content information is received from a first memory system 3-1 are illustrated. In the second memory system 3-2 shown in FIG. 11, the P2P communication I / F 12, content management unit 163, content transmission / reception unit 164, and content information management table 414-2 in non-volatile memory 4, which are related to the content reception and registration operations, are shown.

[0155] In the second memory system 3-2, the content transmitting / receiving unit 164 receives content information from the first memory system 3-1 via the P2P communication I / F 12 ((1) in FIG. 11). The content transmitting / receiving unit 164 sends the received content information to the content management unit 163 ((2) in FIG. 11).

[0156] The content management unit 163 registers the content information received from the content transmission / reception unit 164 in the content information management table 414-2 ((3) in FIG. 11). That is, the content management unit 163 adds an entry including the content ID, content name, content body, and usage conditions to the content information management table 414-2.

[0157] By the above content receiving and registering operation in the second memory system 3-2, the content information is registered in the content information management table 414-2 in the second memory system 3-2. Note that a similar content receiving and registering operation is also performed in other memory systems 3 other than the second memory system 3-2 when receiving content information from another memory system 3.

[0158] (Use start information recording operation) 12 shows an example of a usage start information recording operation in the information processing system 1. The usage start information recording operation is an operation for controlling the use of content by members and for recording information (usage start information) indicating that a member has started using content in the content usage record management table 415 in multiple memory systems 3 used by each of the multiple members. The usage start information recording operation is performed when a member requests the memory system 3 to use content via the host 2. Here, an example of the usage start information recording operation in the first memory system 3-1, the second memory system 3-2, and the third memory system 3-3 will be shown.

[0159] The first memory system 3-1 receives a request to use content (target content) generated by the first host 2-1 in response to an operation by the first member 9-1 ((1) in FIG. 12). The request to use the target content is, for example, an initial read access request (e.g., a read command) for reading the target content from the non-volatile memory 4 of the first memory system 3-1. More specifically, the first member 9-1 performs an operation to request use of the target content, for example, using an input device provided in the first host 2-1. The first memory system 3-1 receives the request to use the target content generated in response to this operation from the first host 2-1 via the data communication I / F 11.

[0160] In response to receiving a usage request for the target content, the first memory system 3-1 determines whether the usage conditions for the target content are met ((2) in FIG. 12). Specifically, for example, the first memory system 3-1 obtains the limit on the number of simultaneous users of the target content from the content information management table 414-1. The first memory system 3-1 obtains the number of people currently using the target content from the content usage record management table 415-1. Then, the first memory system 3-1 determines whether the number of people currently using the target content is less than the limit on the number of simultaneous users.

[0161] Here, it is assumed that the number of people currently using the target content is less than the limit on the number of simultaneous users (i.e., the usage conditions for the target content are met). In this case, the first memory system 3-1 provides the target content to the first member 9-1 by reading at least a portion of the target content from the content information management table 414-1 (non-volatile memory 4) and transmitting it to the first host 2-1 ((3) in FIG. 12). Note that the first memory system 3-1 may, for example, read the entire data of the target content from the content information management table 414-1 and transmit it to the first host 2-1. Alternatively, the first memory system 3-1 may sequentially read multiple data portions that make up the target content from the content information management table 414-1 and transmit them to the first host 2-1.

[0162] The first memory system 3-1 generates an access log regarding the use of the target content by the first member 9-1, and generates signature data for the access log using the first private key 411-1 ((4) in FIG. 12). Then, the first memory system 3-1 records usage start information indicating the start of use of the target content by the first member 9-1 in the content usage record management table 415-1 ((5) in FIG. 12). The usage start information includes, for example, the access log, a value indicating the start of use (for example, 1), and signature data. Specifically, the first memory system 3-1 adds an entry based on the usage start information to the content usage record management table 415-1 associated with the target content. Note that if the content usage record management table 415-1 associated with the target content already has an entry including the first member's name, the first memory system 3-1 updates that entry using the usage start information, for example. In the following, adding an entry based on the usage start information to the content usage record management table 415 associated with the target content, or updating an entry in the content usage record management table 415 associated with the target content using the usage start information, is also referred to as recording the usage start information in the content usage record management table 415.

[0163] Next, the first memory system 3-1 transmits the usage start information via P2P communication to the other memory systems 3 used by group members other than the first member 9-1 ((6) in FIG. 12). Specifically, the first memory system 3-1 transmits the usage start information to the second memory system 3-2 via the P2P communication I / F 12. The first memory system 3-1 also transmits the usage start information to the third memory system 3-3 via the P2P communication I / F 12.

[0164] In response to receiving the use start information from the first memory system 3-1, the second memory system 3-2 verifies the authenticity of the access log using the first public key 412-1 and the signature data ((7-1) in FIG. 12). Specifically, when an entry (i.e., public key information) indicating the first member 9-1 (first member name), the first public key 412-1, and the signature data for the first public key 412-1 is stored in the group public key management table 413-2 in the non-volatile memory 4, the second memory system 3-2 obtains the first public key 412-1 corresponding to the first member 9-1 from the group public key management table 413-2 based on the first member name included in the access log. The second memory system 3-2 verifies the authenticity of the access log included in the use start information using the obtained first public key 412-1 and the signature data included in the use start information.

[0165] Here, it is assumed that the authenticity of the access log included in the usage start information is confirmed. In this case, the second memory system 3-2 records the usage start information in the content usage record management table 415-2 ((8-1) in FIG. 12).

[0166] Similarly, upon receiving the usage start information from the first memory system 3-1, the third memory system 3-3 verifies the authenticity of the access log using the first public key 412-1 and the signature data ((7-2) in FIG. 12). Specifically, the third memory system 3-3 obtains the first public key 412-1 corresponding to the first member 9-1 from the group public key management table 413-3 based on the first member name included in the access log. The third memory system 3-3 verifies the authenticity of the access log included in the usage start information using the obtained first public key 412-1 and the signature data included in the usage start information.

[0167] Here, it is assumed that the authenticity of the access log included in the usage start information is confirmed. In this case, the third memory system 3-3 records the usage start information in the content usage record management table 415-3 ((8-2) in FIG. 12).

[0168] By the above-described usage start information recording operation, the information processing system 1 controls the use of content by members, and the usage start information is recorded in the content usage record management table 415 in the multiple memory systems 3 used by the multiple members. This allows each memory system 3 to securely and easily manage the use of content by members belonging to the group 7. Specifically, each memory system 3 can use the content usage record management table 415 to manage, for example, which member is currently using each piece of content and the number of people currently using each piece of content.

[0169] Furthermore, the first memory system 3-1 records the access log in the content usage record management table 415-1 together with signature data that can verify the authenticity of the access log. Therefore, in the content usage record management table 415-1, the authenticity of the access log can be guaranteed by the signature data.

[0170] Furthermore, the second memory system 3-2 records the access log in the content usage record management table 415-2 together with the signature data used to verify the authenticity of the access log. Therefore, the content usage record management table 415-2 can guarantee the authenticity of the access log by the signature data. The same applies to the third memory system 3-3.

[0171] 13 and 14, the internal operation of each memory system 3 will be described in more detail regarding the use start information recording operation.

[0172] FIG. 13 shows an example of usage control and start information recording operations in the memory system 3 when content usage is requested. Here, the usage control and start information recording operations in the first memory system 3-1 are illustrated when the first host 2-1 requests the use of content (target content). It is also assumed that the usage conditions for the target content include a limit on the number of simultaneous users. The first memory system 3-1 shown in FIG. 13 includes the data communication I / F 11, P2P communication I / F 12, content usage control unit 165, usage record management unit 166, usage record transmission / reception unit 167, and signature unit 168, which are related to the usage control and start information recording operations, as well as the first secret key 411-1, content information management table 414-1, and content usage record management table 415-1 in the nonvolatile memory 4.

[0173] In the first memory system 3-1, the content usage control unit 165 receives a usage request for the target content from the first host 2-1 via the data communication I / F 11 ((1) in FIG. 13). In response to receiving the usage request, the content usage control unit 165 obtains the limit on the number of simultaneous users of the target content from the content information management table 414-1 ((2) in FIG. 13). In addition, the content usage control unit 165 obtains the number of people currently using the target content using the content usage record management table 415-1 ((3) in FIG. 13).

[0174] If the number of people currently using the target content is equal to or greater than the simultaneous user limit, the content usage control unit 165 notifies the first host 2-1 via the data communication I / F 11 that the target content cannot be used ((4) in FIG. 13). In other words, the first member 9-1 cannot use the target content until the number of people currently using the target content falls below the simultaneous user limit.

[0175] On the other hand, if the number of people currently using the target content is less than the simultaneous user limit, the content usage control unit 165 reads out at least a portion of the target content from the content information management table 414-1 ((5) in FIG. 13). The content usage control unit 165 transmits the read target content to the first host 2-1 via the data communication I / F 11 ((6) in FIG. 13). This allows the first member 9-1 to use the target content. The content usage control unit 165 then generates an access log for the target content and a value indicating the start of use, and sends these to the usage record management unit 166 ((7) in FIG. 13).

[0176] The usage record management unit 166 receives the access log and a value indicating the start of usage from the content usage control unit 165, and sends the access log to the signature unit 168 ((8) in FIG. 13).

[0177] In response to receiving the access log from usage record management unit 166, signature unit 168 reads first secret key 411-1 from non-volatile memory 4 ((9) in FIG. 13). Signature unit 168 generates signature data for the access log using first secret key 411-1 and sends the signature data to usage record management unit 166 ((10) in FIG. 13).

[0178] The usage record management unit 166 records the access log, the value indicating the start of usage, and the usage start information including the signature data in the content usage record management table 415-1 ((11) in FIG. 13). Then, the usage record management unit 166 sends the usage start information to the usage record transmission / reception unit 167 ((12) in FIG. 13).

[0179] The usage record transmitting / receiving unit 167 transmits the usage start information received from the usage record management unit 166 to the second memory system 3-2 and the third memory system 3-3 via the P2P communication I / F 12 ((13) in FIG. 13). As a result, in the second memory system 3-2, the usage start information is recorded in the content usage record management table 415-2. Also, in the third memory system 3-3, the usage start information is recorded in the content usage record management table 415-3.

[0180] The use of the target content by the first member 9-1 is controlled by the above-described usage control and start information recording operation in the first memory system 3-1. When the target content is used, the usage start information is recorded in the content usage record management table 415-1 in the first memory system 3-1. The usage start information is also recorded in the content usage record management table 415-2 in the second memory system 3-2 and the content usage record management table 415-3 in the third memory system 3-3.

[0181] It should be noted that in other memory systems 3 than the first memory system 3-1, when a request for use of content is made by the corresponding host 2, a similar use control and start information recording operation is performed.

[0182] 14 shows an example of start information receiving and recording operations in a memory system 3 when usage start information is received from another memory system 3. Here, the start information receiving and recording operations in a second memory system 3-2 when usage start information is received from a first memory system 3-1 are illustrated. In the second memory system 3-2 shown in FIG. 14, the P2P communication I / F 12, usage record management unit 166, usage record transmission / reception unit 167, signature verification unit 169, as well as group public key management table 413-2 and content usage record management table 415-2 in non-volatile memory 4, which are related to the start information receiving and recording operations, are shown.

[0183] In the second memory system 3-2, the usage record transmitting / receiving unit 167 receives usage start information from the first memory system 3-1 via the P2P communication I / F 12 ((1) in FIG. 14). The usage start information includes the first member name, the access log, a value indicating the start of usage, and signature data. The usage record transmitting / receiving unit 167 sends the received usage start information to the usage record management unit 166 ((2) in FIG. 14).

[0184] In response to receiving the usage start information, the usage record management unit 166 acquires the first public key 412-1 from the group public key management table 413-2 ((3) in FIG. 14). Specifically, the usage record management unit 166 acquires the first member name included in the access log. The usage record management unit 166 identifies an entry in the group public key management table 413-2 that includes the acquired first member name. The usage record management unit 166 acquires the first public key 412-1 from the identified entry. Then, the usage record management unit 166 sends the acquired first public key 412-1, the access log and signature data included in the usage start information to the signature verification unit 169 ((4) in FIG. 14).

[0185] The signature verification unit 169 verifies the authenticity of the access log using the signature data and the first public key 412-1, and sends the verification result to the usage record management unit 166 ((5) in FIG. 14).

[0186] If the verification result indicates that the authenticity of the access log has been confirmed, the usage record management unit 166 records the usage start information in the content usage record management table 415-2 ((6) in FIG. 14).

[0187] By the above-described start information receiving and recording operation in the second memory system 3-2, it is possible to record the usage start information including the access log whose authenticity has been confirmed in the content usage record management table 415-2. Note that a similar start information receiving and recording operation is also performed in other memory systems 3 other than the second memory system 3-2 when receiving usage start information from another memory system 3 via P2P communication.

[0188] (Usage completion information recording operation) 15 shows an example of a usage completion information recording operation in the information processing system 1. The usage completion information recording operation is an operation for detecting that a member has completed use of content (target content) and for recording information (usage completion information) indicating that use of the target content has been completed in the content usage record management table 415 in the multiple memory systems 3 used by the multiple members. The usage completion information recording operation is performed after a member has started using the target content (more specifically, after the host 2 has started read access to the target content). Here, an example of the usage completion information recording operation in the first memory system 3-1, the second memory system 3-2, and the third memory system 3-3 is shown.

[0189] The first memory system 3-1 detects that the first member 9-1 has completed using the target content ((1) in FIG. 15). In response to detecting that the first member 9-1 has completed using the target content, the first memory system 3-1 generates an access log regarding the first member 9-1's use of the target content and generates signature data for the access log using the first private key 411-1 ((2) in FIG. 15).

[0190] Then, the first memory system 3-1 records usage completion information indicating the completion of use of the target content by the first member 9-1 in the content usage record management table 415-1 ((3) in FIG. 15). The usage completion information includes, for example, the first member's name, an access log, a value indicating completion of use (for example, 0), and signature data. Specifically, the first memory system 3-1 adds an entry including the usage completion information to the content usage record management table 415-1 associated with the target content. Note that if the content usage record management table 415-1 associated with the target content already has an entry including the first member's name, the first memory system 3-1 updates that entry, for example, using part of the usage completion information. The part of the usage completion information is, for example, the access log, a value indicating completion of use, and signature data. In the following, adding an entry including usage completion information to the content usage record management table 415 associated with the target content, or updating an entry in the content usage record management table 415 associated with the target content using part of the usage completion information, is also referred to as recording usage completion information in the content usage record management table 415.

[0191] The subsequent operations (4), (5-1), (6-1), (5-2), and (6-2) in Figure 15 correspond to operations (6), (7-1), (8-1), (7-2), and (8-2) of the start-of-use information recording operation described above with reference to Figure 12, in which the start-of-use information is replaced with completion-of-use information.

[0192] Through the above-described usage completion information recording operation, the information processing system 1 detects that a member has completed using the content, and records the usage completion information in the content usage record management table 415 in each of the multiple memory systems 3 used by the multiple members. This allows each memory system 3 to securely and easily manage the use of content by members belonging to the group 7. Specifically, each memory system 3 can use the content usage record management table 415 to manage, for example, which member is currently using each piece of content and the number of people currently using each piece of content.

[0193] Furthermore, the first memory system 3-1 records the access log in the content usage record management table 415-1 together with signature data that can verify the authenticity of the access log. Therefore, in the content usage record management table 415-1, the authenticity of the access log can be guaranteed by the signature data.

[0194] Furthermore, the second memory system 3-2 records the access log in the content usage record management table 415-2 together with the signature data used to verify the authenticity of the access log. Therefore, the content usage record management table 415-2 can guarantee the authenticity of the access log by the signature data. The same applies to the third memory system 3-3.

[0195] With reference to FIGS. 16 and 17, the internal operation of each memory system 3 with respect to the usage completion information recording operation will be described in more detail.

[0196] 16 shows an example of the completion detection and completion information recording operation in the memory system 3 when the host 2 has completed access to the content. Here, the completion detection and completion information recording operation in the first memory system 3-1 is illustrated when detecting the completion of the use of the content (target content) by the first host 2-1. In the first memory system 3-1 shown in FIG. 16, the data communication I / F 11, P2P communication I / F 12, content usage control unit 165, usage record management unit 166, usage record transmission / reception unit 167, signature unit 168, as well as the first secret key 411-1 and content usage record management table 415-1 in the non-volatile memory 4, which are related to the completion detection and completion information recording operation, are shown.

[0197] In the first memory system 3-1, when the content usage control unit 165 detects that the first host 2-1 has completed using the target content, it generates an access log for the target content and a value indicating completion of use, and sends them to the usage record management unit 166 ((1) in Figure 16).

[0198] The subsequent operations (2) to (7) in Figure 16 correspond to the operations (8) to (13) of the usage control / start information recording operation described above with reference to Figure 13, in which the usage start information is replaced with usage completion information.

[0199] The completion of use of the target content by the first member 9-1 is detected by the above completion detection and completion information recording operations in the first memory system 3-1. When the completion of use of the target content is detected, usage completion information is recorded in the content usage record management table 415-1 in the first memory system 3-1. The usage completion information is also recorded in the content usage record management table 415-2 in the second memory system 3-2 and the content usage record management table 415-3 in the third memory system 3-3.

[0200] In addition, in other memory systems 3 than the first memory system 3-1, when the completion of the use of the content by the corresponding host 2 is detected, a similar completion detection and completion information recording operation is performed.

[0201] 17 shows an example of completion information receiving and recording operations in memory system 3 when usage completion information indicating completion of content usage is received from another memory system. Here, the completion information receiving and recording operations in second memory system 3-2 when usage completion information is received from first memory system 3-1 are illustrated. In second memory system 3-2 shown in FIG. 17, the P2P communication I / F 12, usage record transmitting / receiving unit 167, usage record management unit 166, signature verification unit 169, as well as group public key management table 413-2 and content usage record management table 415-2 in non-volatile memory 4, which are related to the completion information receiving and recording operations, are shown.

[0202] In the second memory system 3-2, the usage record transmitting / receiving unit 167 receives usage completion information from the first memory system 3-1 via the P2P communication I / F 12 ((1) in FIG. 17). The usage completion information includes the first member name, the access log, a value indicating usage completion, and signature data. The usage record transmitting / receiving unit 167 sends the received usage completion information to the usage record management unit 166 ((2) in FIG. 17).

[0203] The subsequent operations (3) to (6) in Figure 17 correspond to operations (3) to (6) of the start information receiving and recording operation described above with reference to Figure 14, in which the usage start information is replaced with usage completion information.

[0204] By the above-described completion information receiving and recording operation in the second memory system 3-2, the usage completion information including the access log whose authenticity has been confirmed can be recorded in the content usage record management table 415-2. Note that a memory system 3 other than the second memory system 3-2 also performs a similar completion information receiving and recording operation when receiving usage completion information from another memory system 3 via P2P communication.

[0205] Next, the procedure of the process executed in the memory system 3 will be described with reference to the flowcharts shown in FIGS.

[0206] (Public key registration process) 18 is a flowchart showing an example of the procedure of public key registration processing executed by the CPU 16 of the memory system 3. The public key registration processing is processing for exchanging a public key 412 with another memory system 3 through near-field communication and registering the public key 412 obtained through the exchange in the group public key management table 413. The CPU 16 executes the public key registration processing, for example, in response to receiving a specific operation from a member using the memory system 3. The specific operation is an operation that instructs the execution of the public key registration processing. For example, a member using the memory system 3 performs the specific operation when attempting to exchange public keys through near-field communication with a memory system 3 used by another member.

[0207] Here, an example is shown in which the public key registration process is executed in the first memory system 3-1. The memory system 3 with which the first memory system 3-1 exchanges public keys is assumed to be the second memory system 3-2. The first memory system 3-1 and the second memory system 3-2 are located within a range where close proximity communication is possible. In the first memory system 3-1, a key pair including a first secret key 411-1 and a first public key 412-1 is stored in the nonvolatile memory 4. In the second memory system 3-2, a key pair including a second secret key 411-2 and a second public key 412-2 is stored in the nonvolatile memory 4.

[0208] First, the CPU 16 of the first memory system 3-1 exchanges the first public key 412-1 of the first memory system 3-1 with the second public key 412-2 of the second memory system 3-2 through near field communication (step S101). Specifically, the CPU 16 transmits the first public key 412-1 to the second memory system 3-2 and receives the second public key 412-2 from the second memory system 3-2 via the near field communication I / F 13.

[0209] CPU 16 calculates a hash value of second public key 412-2 (hereinafter referred to as first hash value) using a specific hash function (step S102). CPU 16 generates signature data A by encrypting the first hash value using first private key 411-1 (step S103).

[0210] Next, the CPU 16 determines whether or not the group public key management table 413-1 includes an entry corresponding to the second member 9-2 using the second memory system 3-2 (ie, an entry including the second member name) (step S104).

[0211] If group public key management table 413-1 includes an entry corresponding to second member 9-2 (YES in step S104), CPU 16 adds first member 9-1 and signature data A to that entry (step S105), and proceeds to step S107. Specifically, CPU 16 identifies an x-th signature member name field and an x-th signature data field in which values ​​have not yet been set in the entry corresponding to second member 9-2. Then, CPU 16 sets the name of first member 9-1 (first member name) in the identified x-th signature member name field, and sets signature data A in the x-th signature data field.

[0212] If group public key management table 413-1 does not include an entry corresponding to second member 9-2 (NO in step S104), CPU 16 adds an entry indicating second member 9-2, second public key 412-2, first member 9-1, and signature data A to group public key management table 413-1 (step S106), and proceeds to step S107. Specifically, CPU 16 adds an entry to group public key management table 413-1, in which the name of second member 9-2 (second member name), second public key 412-2, first member name, and signature data A are set in the member name field, public key field, first signature member name field, and first signature data field, respectively.

[0213] Then, the CPU 16 transmits information (second public key information) indicating the second member 9-2, the second public key 412-2, the first member 9-1, and the signature data A to a memory system 3 (e.g., the third memory system 3-3) used by a group member other than the first member 9-1 and the second member 9-2 via the P2P communication I / F 12 (step S107), and terminates the public key registration process.

[0214] Through the above public key registration process, the CPU 16 of the first memory system 3-1 exchanges the public key 412 with the second memory system 3-2 and can register the second public key 412-2 obtained through the exchange in the group public key management table 413-1 together with the signature data A. The CPU 16 also transmits second public key information indicating the second member 9-2, the second public key 412-2, the first member 9-1, and the signature data A to the memory systems 3 used by group members other than the first member 9-1 and the second member 9-2. The signature data A for the second public key 412-2 is signature data generated using the first private key 411-1. Therefore, the memory system 3 that receives the second public key information can verify the authenticity of the second public key 412-2 using the first public key 412-1 and the signature data A.

[0215] In the above explanation, an example was given of the public key registration process when the first memory system 3-1 exchanges the public key 412 with the second memory system 3-2 via close proximity communication, but a similar public key registration process is also performed when the public key 412 is exchanged between two other memory systems 3 via close proximity communication.

[0216] (Public key verification and registration processing) 19 is a flowchart showing an example of the procedure of public key verification and registration processing executed by the CPU 16 of the memory system 3. The public key verification and registration processing is processing for verifying the authenticity of the public key 412 included in public key information received from another memory system 3, and registering the public key 412 whose authenticity has been confirmed in the group public key management table 413. The CPU 16 executes the public key verification and registration processing in response to receiving public key information from each of the other two memory systems 3, for example.

[0217] Here, an example will be given of a case where the public key verification and registration process is executed in the third memory system 3-3. The third memory system 3-3 is assumed to have received public key information from each of the first memory system 3-1 and the second memory system 3-2. The public key information (first public key information) received from the second memory system 3-2 is information indicating the first member 9-1, the first public key 412-1, the second member 9-2, and signature data B. The signature data B is signature data for the first public key 412-1. The public key information (second public key information) received from the first memory system 3-1 is information indicating the second member 9-2, the second public key 412-2, the first member 9-1, and signature data A. The signature data A is signature data for the second public key 412-2.

[0218] First, the CPU 16 of the third memory system 3-3 uses a specific hash function to calculate a hash value (hereinafter referred to as the second hash value) of the first public key 412-1 included in the first public key information (step S201). The CPU 16 generates a hash value (hereinafter referred to as the third hash value) by decrypting the signature data B using the second public key 412-2 included in the second public key information (step S202). The CPU 16 then determines whether the second hash value and the third hash value are equal (step S203). The fact that the second hash value and the third hash value are equal means that the authenticity of the first public key 412-1 has been confirmed based on the second public key 412-2 and the signature data B.

[0219] If the second hash value and the third hash value are different (NO in step S203), the process by CPU 16 proceeds to step S207. That is, since the authenticity of first public key 412-1 has not been confirmed, CPU 16 proceeds to the process of verifying the authenticity of second public key 412-2 without registering the first public key information in group public key management table 413-3.

[0220] If the second hash value and the third hash value are equal (YES in step S203), the CPU 16 determines whether the group public key management table 413-3 contains an entry corresponding to the first member 9-1 using the first memory system 3-1 (i.e., an entry with the first member name set in the member name field) (step S204).

[0221] If group public key management table 413-3 includes an entry corresponding to first member 9-1 (YES in step S204), CPU 16 adds second member 9-2 and signature data B to the entry corresponding to first member 9-1 (step S205), and proceeds to step 207. Specifically, CPU 16 identifies an x-th signature member name field and an x-th signature data field in which values ​​have not yet been set in the entry corresponding to first member 9-1. Then, CPU 16 sets the name of second member 9-2 (second member name) in the identified x-th signature member name field, and sets signature data B in the x-th signature data field.

[0222] If group public key management table 413-3 does not include an entry corresponding to first member 9-1 (NO in step S204), CPU 16 adds an entry indicating first member 9-1, first public key 412-1, second member 9-2, and signature data B to group public key management table 413-3 (step S206), and proceeds to step S207. Specifically, CPU 16 adds an entry to group public key management table 413-3, in which the first member name, first public key 412-1, second member name, and signature data B are set in the member name field, public key field, first signature member name field, and first signature data field, respectively.

[0223] Next, CPU 16 calculates a hash value (hereinafter, referred to as a fourth hash value) of second public key 412-2 using a specific hash function (step S207). CPU 16 generates a hash value (hereinafter, referred to as a fifth hash value) by decrypting signature data A using first public key 412-1 (step S208). CPU 16 then determines whether the fourth hash value and the fifth hash value are equal (step S209). If the fourth hash value and the fifth hash value are equal, this means that the authenticity of second public key 412-2 has been confirmed based on first public key 412-1 and signature data A.

[0224] If the fourth hash value and the fifth hash value are different (NO in step S209), CPU 16 ends the public key verification and registration process. In other words, since the authenticity of second public key 412-2 has not been confirmed, CPU 16 ends the public key verification and registration process without registering the second public key information in group public key management table 413-3.

[0225] If the fourth hash value and the fifth hash value are equal (YES in step S209), the CPU 16 determines whether the group public key management table 413-3 contains an entry corresponding to the second member 9-2 using the second memory system 3-2 (i.e., an entry with the second member name set in the member name field) (step S210).

[0226] If the group public key management table 413-3 contains an entry corresponding to the second member 9-2 (YES in step S210), the CPU 16 adds the first member 9-1 and signature data A to the entry corresponding to the second member 9-2 (step S211), and terminates the public key verification and registration process.

[0227] If the group public key management table 413-1 does not contain an entry corresponding to the second member 9-2 (NO in step S210), the CPU 16 adds an entry indicating the second member 9-2, the second public key 412-2, the first member 9-1, and the signature data A to the group public key management table 413-3 (step S212), and terminates the public key verification and registration process.

[0228] Through the above public key verification and registration process, the CPU 16 of the third memory system 3-3 can verify the authenticity of each of the first public key 412-1 and the second public key 412-2 using the first public key information received from the second memory system 3-2 and the second public key information received from the first memory system 3-1. Then, the CPU 16 can register information about the first public key 412-1 and the second public key 412-2, whose authenticity has been confirmed, in the group public key management table 413-3.

[0229] Note that CPU 16 may execute the processes from steps S201 to S206 relating to the verification and registration of first public key 412-1 after the processes from steps S207 to S212 relating to the verification and registration of second public key 412-2. Alternatively, the processes from steps S201 to S206 relating to the verification and registration of first public key 412-1 and the processes from steps S207 to S212 relating to the verification and registration of second public key 412-2 may be executed in parallel.

[0230] In addition, the above explanation illustrates the public key verification and registration process when the third memory system 3-3 receives public key information from each of the first memory system 3-1 and the second memory system 3-2, but a similar public key verification and registration process is also performed when a certain memory system 3 receives public key information from each of two other memory systems 3.

[0231] (Usage control and start information recording processing) 20 is a flowchart showing an example of the procedure for usage control and start information recording processing executed by the CPU 16 of the memory system 3. The usage control and start information recording processing is processing for controlling access to content by a member and registering usage start information indicating that access to the content has started in the content usage record management table 415. The CPU 16 executes the usage control and start information recording processing in response to, for example, a request for access to content by a member.

[0232] Here, an example will be given in which the usage control / start information recording process is executed in the first memory system 3-1. In this case, for example, access to content by the first member 9-1 is requested by the host 2 via the data communication I / F 11.

[0233] First, the CPU 16 of the first memory system 3-1 acquires the simultaneous user limit corresponding to the content (target content) requested for use by the first member 9-1 from the content information management table 414-1 (step S301). Specifically, the CPU 16 identifies, for example, an entry in the content information management table 414-1 that includes the content ID of the target content. Then, the CPU 16 acquires the value set in the simultaneous user limit field of the identified entry as the simultaneous user limit corresponding to the target content.

[0234] The CPU 16 determines whether or not there is a limit on the number of simultaneous users for use of the target content (step S302). Specifically, the CPU 16 determines, for example, whether or not the acquired value of the limit on the number of simultaneous users is greater than 0. If the value of the limit on the number of simultaneous users is 0, the CPU 16 determines that there is no limit on the number of simultaneous users for use of the target content. If the value of the limit on the number of simultaneous users is greater than 0, the CPU 16 determines that there is a limit on the number of simultaneous users.

[0235] If there is no limit on the number of simultaneous users for the use of the target content (NO in step S302), the processing by the CPU 16 proceeds to step S305.

[0236] If the target content has a limit on the number of simultaneous users (YES in step S302), CPU 16 refers to content usage record management table 415-1 to calculate the number of people currently using the target content (step S303). Specifically, CPU 16 identifies a content usage record management table 415-1 associated with the content ID of the target content from, for example, one or more content usage record management tables 415A, 415B, ..., and 415M corresponding to one or more pieces of content stored in non-volatile memory 4. CPU 16 counts the number of entries in the identified content usage record management table 415-1 whose usage status field is set to a value indicating the start of use (e.g., 1). In this way, CPU 16 obtains the number of people currently using the target content.

[0237] Next, CPU 16 determines whether the number of people currently using the target content is less than the simultaneous user limit corresponding to the target content (step S304). Note that the determination in step S304 is not limited to the condition that the number of people currently using the target content is less than the simultaneous user limit, and any condition for determining whether the target content can be used may be used.

[0238] If the number of people currently using the target content is less than the simultaneous user limit corresponding to the target content (YES in step S304), the processing by the CPU 16 proceeds to step S305.

[0239] In step S305, the CPU 16 generates an access log indicating that the first member 9-1 has started accessing the target content. The generated access log includes, for example, the date and time when the access started, the member name of the first member 9-1, and the content ID of the target content.

[0240] The CPU 16 calculates a hash value of the generated access log using a specific hash function (step S306), and generates signature data for the access log by encrypting the calculated hash value using the first secret-key 411-1 (step S307).

[0241] Next, CPU 16 updates content usage record management table 415-1 associated with the target content using usage start information indicating the access log, usage start, and signature data (step S308). Specifically, CPU 16 identifies an entry including the member name of first member 9-1 in content usage record management table 415-1 associated with the target content (e.g., the content ID of the target content). Then, CPU 16 sets the access log, a value indicating usage start (e.g., 1), and signature data in the access log field, usage status field, and signature data field of the identified entry, respectively.

[0242] The CPU 16 transmits the usage start information to the memory systems 3 used by group members other than the first member 9-1 via the P2P communication I / F 12 (step S309), and ends the usage control and start information recording process.

[0243] Furthermore, if the number of people currently using the target content is equal to or greater than the simultaneous user limit for the target content (NO in step S304), the CPU 16 notifies the host 2-1 that the target content cannot be used (step S310), and terminates the usage control / start information recording process.

[0244] Through the above usage control and start information recording process, the CPU 16 of the first memory system 3-1 can control access to the target content by the first member 9-1 depending on whether a specific condition (for example, the condition that the number of simultaneous users is less than the limit) is met. If the specific condition is met, the CPU 16 can register usage start information indicating that access to the target content has started in the content usage record management table 415-1.

[0245] Furthermore, the CPU 16 transmits usage start information to the memory systems 3 used by group members other than the first member 9-1. The usage start information includes an access log and signature data for the access log generated using the first private key 411-1. Therefore, the memory systems 3 that receive the usage start information can verify the authenticity of the access log using the first public key 412-1 and the signature data.

[0246] In the above explanation, the usage control and start information recording process when access to content is requested from the first memory system 3-1 is exemplified, but similar usage control and start information recording process is also performed when access to content is requested from each of the other memory systems 3.

[0247] (Completion information recording process) 21 is a flowchart showing an example of the procedure of completion information recording processing executed by the CPU 16 of the memory system 3. The completion information recording processing is processing for registering usage completion information indicating that the member's usage of the content has been completed (ended) in the content usage record management table 415. The CPU 16 executes the completion information recording processing, for example, in response to the member's completion of usage of the content.

[0248] Here, a case where the completion information recording process is executed in the first memory system 3-1 will be illustrated. In this case, the CPU 16 of the first memory system 3-1 executes the completion information recording process in response to the completion of access by the first member 9-1 to the content (target content).

[0249] First, the CPU 16 generates an access log indicating that the first member 9-1 has completed access to the target content (step S401). The generated access log includes, for example, the date and time when the access was completed, the member name of the first member 9-1, and the content ID of the target content.

[0250] The CPU 16 calculates a hash value of the generated access log using a specific hash function (step S402), and generates signature data for the access log by encrypting the calculated hash value using the first secret-key 411-1 (step S403).

[0251] Next, CPU 16 updates content usage record management table 415-1 associated with the target content with usage completion information indicating the access log, usage completion, and signature data (step S404). Specifically, CPU 16 identifies an entry including the member name of first member 9-1 in content usage record management table 415-1 associated with the target content. Then, CPU 16 sets the access log, a value indicating usage completion (e.g., 0), and signature data in the access log field, usage status field, and signature data field of the identified entry, respectively.

[0252] The CPU 16 transmits the usage completion information to the memory systems 3 used by the group members other than the first member 9-1 via the P2P communication I / F 12 (step S405), and ends the completion information recording process.

[0253] By the above completion information recording process, the CPU 16 of the first memory system 3-1 can register usage completion information indicating that access to the content has been completed in the content usage record management table 415-1.

[0254] Furthermore, the CPU 16 transmits usage completion information to the memory systems 3 used by group members other than the first member 9-1. The usage completion information includes the access log and signature data for the access log generated using the first private key 411-1. Therefore, the memory systems 3 that receive the usage completion information can verify the authenticity of the access log using the first public key 412-1 and the signature data.

[0255] In the above explanation, the usage control and start information recording process when access to content is completed in the first memory system 3-1 is exemplified, but a similar completion information recording process is also performed when access to content is completed in each of the other memory systems 3.

[0256] (Usage record verification and registration processing) FIG. 22 is a flowchart showing an example of the procedure for usage record verification and registration processing executed by the CPU 16 of the memory system 3. The usage record verification and registration processing is processing for verifying the authenticity of an access log included in usage record information received from another memory system 3 and registering the access log whose authenticity has been confirmed in the content usage record management table 415. The usage record information is either usage start information indicating that access to content has started or usage completion information indicating that access to content has been completed. The usage record information includes an access log, a value indicating the start or completion of usage, and signature data for the access log. The CPU 16 executes the usage record verification and registration processing, for example, in response to receiving usage record information from another memory system 3.

[0257] Here, a case where the second memory system 3-2 receives usage record information from another memory system 3 will be exemplified.

[0258] First, the CPU 16 of the second memory system 3-2 uses a specific hash function to calculate a hash value (hereinafter, a sixth hash value) of the access log included in the usage record information (step S501). Based on the member name included in the access log, the CPU 16 obtains the public key 412 corresponding to that member (hereinafter, a second target member) from the group public key management table 413-2 (step S502). The CPU 16 uses the obtained public key 412 to decrypt the signature data included in the usage record information, thereby generating a hash value (hereinafter, a seventh hash value) (step S503). The CPU 16 then determines whether the sixth hash value and the seventh hash value are equal (step S504). If the sixth hash value and the seventh hash value are equal, this means that the authenticity of the access log has been confirmed.

[0259] If the sixth hash value and the seventh hash value are different (NO in step S504), CPU 16 ends the usage record verification and registration process. In other words, since the authenticity of the access log has not been confirmed, CPU 16 ends the usage record verification and registration process without registering the usage record information in content usage record management table 415-2.

[0260] If the sixth hash value and the seventh hash value are equal (YES in step S504), the CPU 16 updates the content usage record management table 415-2 associated with the content ID included in the access log using the usage record information (step S505), and terminates the usage record verification and registration process. Specifically, the CPU 16 identifies the content usage record management table 415-2 associated with the content ID included in the access log from, for example, one or more content usage record management tables 415A, 415B, ..., and 415M corresponding to one or more contents stored in the non-volatile memory 4. The CPU 16 identifies an entry in the identified content usage record management table 415-2 that includes the member name of the second target member. The CPU 16 then sets the access log, a value indicating the start or completion of usage, and signature data, which are included in the usage record information, in the access log field, usage status field, and signature data field of the identified entry, respectively.

[0261] Through the above usage record verification and registration process, the CPU 16 of the second memory system 3-2 verifies the authenticity of the access log included in the usage record information received from another memory system 3. Then, the CPU 16 registers the usage record information including the access log whose authenticity has been confirmed in the content usage record management table 415-2. In other words, the CPU 16 can update the content usage record management table 415-2 with the usage record information including the access log whose authenticity has been confirmed.

[0262] In the above explanation, an example was given of the usage record verification and registration process when the second memory system 3-2 receives usage record information from another memory system 3, but a similar usage record verification and registration process is also performed when each of the other memory systems 3 receives usage record information from another memory system 3.

[0263] As described above, according to this embodiment, content usage by members belonging to a group can be easily managed. The memory system 3 is used by a first user belonging to the group 7. The controller 6 (e.g., the P2P communication I / F 12 or the proximity communication I / F 13) can communicate with one or more other memory systems 3 used by one or more users belonging to the group 7 other than the first user. The key pair generation management unit 160 manages a first key pair including a first secret key 411 and a first public key 412. The content management unit 163 stores one or more pieces of content information, each of which includes one or more pieces of content, in the non-volatile memory 4. When the first user requests use of a first content among the one or more pieces of content, the content usage control unit 165 generates a first access log related to the usage. The usage record management unit 166 and the signature unit 168 generate first signature data for the first access log using the first secret key 411. The usage record management unit 166 stores the first access log and the first signature data in the nonvolatile memory 4 (for example, the content usage record management table 415). The usage record transmission / reception unit 167 transmits the first access log and the first signature data to one or more other memory systems 3.

[0264] As a result, the first access log and the first signature data are stored in the non-volatile memory 4 of each of the one or more other memory systems 3. That is, the first access log and the first signature data are shared among the multiple memory systems 3 used by the multiple members belonging to the group 7. Therefore, each memory system 3 can easily manage the use of content by the members belonging to the group 7.

[0265] Furthermore, each memory system 3 can verify the authenticity of the first access log using the first signature data. Therefore, each memory system 3 can securely manage the use of content by members belonging to group 7 using an access log whose authenticity has been confirmed (i.e., a highly reliable access log).

[0266] Each of the various functions described in this embodiment may be realized by a circuit (processing circuit). An example of a processing circuit includes a programmed processor, such as a central processing unit (CPU). This processor performs each of the described functions by executing a computer program (a set of instructions) stored in a memory. This processor may be a microprocessor including electrical circuits. Examples of processing circuits also include digital signal processors (DSPs), application specific integrated circuits (ASICs), microcontrollers, controllers, and other electrical circuit components. Each of the components other than the CPU described in this embodiment may also be realized by a processing circuit.

[0267] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, and are also included in the scope of the invention and its equivalents as defined in the claims. [Explanation of symbols]

[0268] 1...information processing system, 2...host (terminal), 3...memory system, 3-1...first memory system, 3-2...second memory system, 3-3...third memory system, 3-n...nth memory system, 4...non-volatile memory, 5...DRAM, 6...controller, 7...group, 11...data communication I / F, 12...P2P communication I / F, 13...proximity communication I / F, 14...memory I / F, 15...DRAM I / F, 16...CPU, 160...key pair generation management unit, 161...public key transmission / reception unit, 162...public key management unit, 163...content management unit, 164...content transmission / reception unit, 165...content usage control unit, 166...usage record management unit, 167...usage record transmission / reception unit, 168...signature unit, 169...signature verification unit, 411...private key, 412...public key, 413...group public key management table, 414...content information management table, 415...content usage record management table.

Claims

1. A memory system used by a first user belonging to a group, comprising: a non-volatile memory; a controller electrically connected to the non-volatile memory and capable of communicating with one or more other memory systems respectively used by one or more users belonging to the group other than the first user; The controller managing a first key pair including a first private key and a first public key; storing one or more pieces of content information each including one or more pieces of content in the non-volatile memory; When a first content of the one or more pieces of content is requested to be used by the first user, generating a first access log relating to the use; generating first signature data for the first access log using the first private key; storing the first access log and the first signature data in the nonvolatile memory; configured to transmit the first access log and the first signature data to the one or more other memory systems. Memory system.

2. the one or more pieces of content information include first content information; the first content information includes the first content and information indicating a first condition under which the first content can be used; The controller, when the use is requested, if the first condition is satisfied, generating the first access log; generating the first signature data; storing the first access log and the first signature data in the nonvolatile memory; configured to transmit the first access log and the first signature data to the one or more other memory systems.

10. The memory system of claim 1.

3. the one or more other memory systems include a second memory system; the second memory system used by a second one of the one or more users; managing a second key pair including a second private key and a second public key; The controller further comprises: transmitting the first public key to the second memory system and receiving the second public key from the second memory system; generating second signature data for the second public key using the first private key; configured to transmit second public key information indicating the second user, the second public key, the first user, and the second signature data to the one or more other memory systems other than the second memory system; 3. The memory system according to claim 1.

4. The controller further comprises: configured to store the second public key information in the non-volatile memory; 4. The memory system of claim 3.

5. The controller transmitting the first public key to the second memory system and receiving the second public key from the second memory system via a first interface circuit that performs near-field communication; configured to transmit the second public key information to the one or more other memory systems other than the second memory system via a second interface circuit; 4. The memory system of claim 3.

6. The controller further comprises: receiving second content information including second content from the host; storing the second content information in the nonvolatile memory; configured to transmit the second content information to the one or more other memory systems.

4. The memory system of claim 3.

7. The controller transmitting the first public key to the second memory system and receiving the second public key from the second memory system via a first interface circuit that performs near-field communication; configured to transmit the second public key information to the one or more other memory systems other than the second memory system via a second interface circuit; 7. The memory system of claim 6.

8. the controller is configured to transmit the first access log and the first signature data to the one or more other memory systems via the second interface circuit; 8. The memory system of claim 7.

9. The controller receiving the second content information from the host via a third interface circuit; configured to transmit the second content information to the one or more other memory systems via the second interface circuit; 9. The memory system of claim 8.

10. A memory system used by a first user belonging to a group, comprising: a non-volatile memory; a controller electrically connected to the non-volatile memory and capable of communicating with one or more other memory systems respectively used by one or more users belonging to the group other than the first user; the one or more other memory systems include a second memory system; the second memory system is used by a second one of the one or more users; The controller managing a first key pair including a first private key and a first public key; storing one or more pieces of content information each including one or more pieces of content in the non-volatile memory; receiving, from the second memory system, a first access log relating to the second user's use of a first content among the one or more contents and first signature data for the first access log; When second public key information indicating the second user, a second public key, and second signature data for the second public key is stored in the nonvolatile memory, the authenticity of the first access log is verified using the second public key and the first signature data. Memory system.

11. the controller is further configured to store the first access log and the second signature data in the non-volatile memory when authenticity of the first access log is confirmed. The memory system of claim 10.

12. the one or more other memory systems further include a third memory system; the third memory system is used by a third user of the one or more users; The controller further comprises: receiving, from the second memory system, information indicating the third user, a third public key, the second user, and third signature data for the third public key; receiving, from the third memory system, information indicating the second user, the second public key, the third user, and the second signature data; and performing at least one of verifying authenticity of the second public key using the third public key and the second signature data, and verifying authenticity of the third public key using the second public key and the third signature data.

12. The memory system according to claim 10 or 11.

13. The controller further comprises: If the authenticity of the second public key is confirmed, the second public key information indicating the second user, the second public key, the third user, and the second signature data is stored in the nonvolatile memory; When the authenticity of the third public key is confirmed, third public key information indicating the third user, the third public key, the second user, and the third signature data is stored in the nonvolatile memory.

13. The memory system of claim 12.

14. The controller further comprises: transmitting the first public key to the second memory system and receiving the second public key from the second memory system; generating the second signature data for the second public key using the first private key; configured to store the second public key information indicating the second user, the second public key, the first user, and the second signature data in the non-volatile memory; The memory system of claim 10.

15. The controller transmitting the first public key to the second memory system and receiving the second public key from the second memory system via a first interface circuit that performs near-field communication; configured to receive the first access log and the first signature data from the second memory system via a second interface circuit; 15. The memory system of claim 14.

16. The controller further comprises: configured to transmit the second public key information to the one or more other memory systems other than the second memory system; 15. The memory system of claim 14.

17. The controller transmitting the first public key to the second memory system and receiving the second public key from the second memory system via a first interface circuit that performs near-field communication; transmitting the second public key information to the one or more other memory systems other than the second memory system via a second interface circuit; configured to receive the first access log and the first signature data from the second memory system via the second interface circuit; 17. The memory system of claim 16.

18. The controller further comprises: receiving second content information from the second memory system, the second content information including second content; configured to store the second content information in the non-volatile memory; 15. The memory system of claim 14.

19. The controller transmitting the first public key to the second memory system and receiving the second public key from the second memory system via a first interface circuit that performs near-field communication; configured to receive the second content information from the second memory system via a second interface circuit; 20. The memory system of claim 18.

20. An information processing system including a plurality of memory systems each used by a plurality of users belonging to a group, the plurality of memory systems includes a first memory system and a second memory system; the first memory system is used by a first user of the plurality of users; the second memory system is used by a second user of the plurality of users; the first memory system managing a first key pair including a first private key and a first public key; storing one or more pieces of content information, each of which includes one or more pieces of content, in a non-volatile memory in the first memory system; When a first content of the one or more pieces of content is requested to be used by the first user, generating a first access log relating to the use; generating first signature data for the first access log using the first private key; storing the first access log and the first signature data in the nonvolatile memory; configured to transmit the first access log and the first signature data to at least the second memory system; the second memory system receiving the first access log and the first signature data from the first memory system; When first public key information indicating the first user, the first public key, and second signature data for the first public key is stored in a non-volatile memory in the second memory system, the authenticity of the first access log is verified using the first public key and the first signature data. Information processing system.

Citation Information

Patent Citations

  • Public key encryption for groups

    US20050152542A1

  • System and method for managing secure communications in an ad-hoc network

    US20160057117A1

  • End-to-end encryption for personal communication nodes

    US20200162439A1