File decryption device, file decryption method, and computer program

The file decryption device uses volatile memory to securely output decrypted data directly, addressing confidentiality issues by preventing storage of decrypted data, thereby enhancing security and enabling decryption of large files.

JP2026081604APending Publication Date: 2026-05-19COOLY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
COOLY CO LTD
Filing Date
2024-11-05
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing file decryption technologies do not adequately enhance the confidentiality of encrypted files, leaving decrypted data vulnerable to unauthorized access.

Method used

A file decryption device and method that utilizes a volatile memory to store and output decrypted data directly to an output unit, bypassing storage, and a decryption processing means to decrypt and store data in volatile memory only when necessary, ensuring no decrypted data remains in storage.

Benefits of technology

This approach enhances the confidentiality and security of encrypted files by preventing decrypted data from being stored in non-volatile memory, thus reducing the risk of unauthorized access and supporting decryption of large files.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026081604000001_ABST
    Figure 2026081604000001_ABST
Patent Text Reader

Abstract

To enhance the confidentiality of encrypted files. [Solution] When the receiving terminal 30 receives a password to decrypt encrypted content and then receives a display instruction to the display unit 33 via an external operation, the display processing unit 41 outputs a decryption request to the decryption processing unit 42. When the decryption processing unit 42 receives the decryption request, it decrypts the portion of the encrypted content stored in the HDD 34 that corresponds to the display instruction and stores it in the memory 35. The decrypted data stored in the memory 35 is then output to the display processing unit 41 without going through the HDD 34, and the display processing unit 41 outputs the contents of the decrypted file from the display unit 33 based on the decrypted data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a technology for decrypting files.

Background Art

[0002] Conventionally, a number of technologies for decrypting encrypted files have been disclosed (for example, Patent Document 1, etc.).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] An object of the present invention is to further enhance the confidentiality of encrypted files.

Means for Solving the Problems

[0005] To solve the above problems, a first aspect of the present invention includes a storage means for storing an encrypted file, a volatile memory, and output processing means for outputting the content of the decrypted file to an output unit when there is an output instruction to the output unit by an external operation after a password for decrypting the decrypted file is input, and decryption processing means for decrypting the decrypted file. The output processing means outputs a decryption request to the decryption processing means when there is an output instruction to the output unit by an external operation after a password for decrypting the decrypted file is input. The decryption processing means decrypts a portion of the file stored in the storage means related to the output instruction and holds it in the volatile memory when the decryption request is input, and outputs the decrypted data held in the volatile memory to the output processing means without passing through the storage means. The output processing means is a file decryption device that outputs the content of the decrypted file from the output unit based on the decrypted data.

[0006] In a second aspect of the present invention, it is preferable that the decryption processing means decrypts a file whose data size is larger than the storage capacity of the volatile memory.

[0007] To solve the aforementioned problems, a third aspect of the present invention is a file decryption method in a file decryption device having an output processing means and a decryption processing means, comprising: a decryption request step in which the output processing means outputs a decryption request when an output instruction is received to the output unit by an external operation after a password for decrypting a decrypted file has been entered; a decryption data output step in which the decryption processing means, upon receiving a decryption request, decrypts the portion of the file stored in the storage means that corresponds to the output instruction, stores it in volatile memory, and outputs the decrypted data stored in volatile memory without going through the storage means; and a file content output step in which the output processing means outputs the contents of the decrypted file from the output unit based on the decryption data.

[0008] To solve the aforementioned problems, a fourth aspect of the present invention is a computer program for a file decryption device having an output processing means and a decryption processing means, wherein the output processing means performs a decryption request step in which, after a password for decrypting a decrypted file is entered and an output instruction is received to the output unit by an external operation, the output processing means outputs a decryption request; the decryption data output step in which, upon receiving a decryption request, the decryption processing means decrypts the portion of the file stored in the storage means that corresponds to the output instruction, stores it in volatile memory, and outputs the decrypted data stored in volatile memory without going through the storage means; and the output processing means performs a file content output step in which, based on the decrypted data, the contents of the decrypted file are output from the output unit. [Effects of the Invention]

[0009] According to the first, third, and fourth aspects of the present invention, the file decryption device decrypts an encrypted file stored in the storage means, stores the decrypted composite data in volatile memory, and outputs the composite data stored in volatile memory to the output unit without storing it in the storage means. As a result, the file decryption device does not leave any decrypted data in the storage means. This prevents the decrypted data from being obtained or viewed by a third party, and consequently increases the confidentiality and security of the encrypted file.

[0010] According to the second aspect of the present invention, the file decryption device decrypts the portion of the file corresponding to the output instruction in volatile memory, and therefore can decrypt files whose data size is larger than the storage capacity of the volatile memory. [Brief explanation of the drawing]

[0011] [Figure 1] Figure 1 is a block diagram showing an example configuration of a file transfer system. [Figure 2] Figure 2 is a block diagram showing an example configuration of a sending server. [Figure 3] Figure 3 is a block diagram showing an example configuration of a file transfer system, including file exchange. [Figure 4] Figure 4 is a block diagram showing an example configuration of the receiving terminal. [Figure 5] Figure 5 is a block diagram showing an example configuration of the terminal-side processing unit. [Figure 6] Figure 6 is a flowchart showing an example of the display process. [Figure 7] Figure 7 shows an example of a screen used to display content when an application is launched. [Figure 8] Figure 8 is a flowchart showing an example of the decoding process. [Modes for carrying out the invention]

[0012] Embodiments of the present invention will be described with reference to the drawings. In this embodiment, a file transmission system is exemplified.

[0013] (Configuration) FIG. 1 is a block diagram showing a configuration example of a file transmission system 1.

[0014] As shown in FIG. 1, the file transmission system 1 includes a transmission server 10, a plurality of transmission-side terminals 20, and a plurality of reception-side terminals 30. Here, the transmission server 10, the transmission-side terminals 20, and the reception-side terminals 30 are capable of communicating with each other via communication means NW. The communication means NW is a communication network such as a LAN or an Internet line that can be connected by wire or wirelessly.

[0015] In this file transmission system 1, when the transmission-side terminal 20 uploads content to the transmission server 10, the transmission server 10 encrypts the uploaded content using the password set by the transmission-side terminal 20. Furthermore, the transmission server 10 issues a URL (hereinafter referred to as a download URL) for downloading the encrypted content (hereinafter referred to as encrypted content). On the reception-side terminal 30, the encrypted content is downloaded based on the download URL. Then, on the reception-side terminal 30, the encrypted content is decrypted using the password set by the transmission-side terminal 20. Hereinafter, each configuration will be described.

[0016] The transmission-side terminal 20 is a personal computer or the like. In the transmission-side terminal 20, for example, PDF files, text files, video files, audio files, etc. are stored as content to be transmitted. When the user of the transmission-side terminal 20 transmits the content to be transmitted, the user opens a WEB page of the file transmission service provided by the transmission server 10 (hereinafter referred to as the file transmission service WEB page). Then, the user of the transmission-side terminal 20 uploads the content to be transmitted to the file transmission service WEB page and inputs a password for encrypting the content to be transmitted to the file transmission service WEB page.

[0017] FIG. 2 is a block diagram showing a configuration example of the transmission server 10.

[0018] As shown in FIG. 2, the transmission server 10 has a communication unit 11, a storage unit 12, and a processing unit (hereinafter referred to as the server-side processing unit) 13. Here, the communication unit 11 communicates with other devices such as the transmission-side terminal 20 and the reception-side terminal 30 via the communication means NW. The storage unit 12 is an HDD (Hard Disk Drive) or the like, and stores various data and various programs. The server-side processing unit 13 executes various processes in the transmission server 10. The server-side processing unit 13 includes, for example, a microcomputer and its peripheral circuits, and is configured by, for example, a CPU, a ROM, a RAM, etc. The server-side processing unit 13 executes various processes according to various data and various programs 12a stored in the storage unit 12 as necessary. In the present embodiment, the server-side processing unit 13 encrypts the content uploaded from the transmission-side terminal 20.

[0019] FIG. 3 is a block diagram showing a configuration example of the file transmission system 1 including the file exchange.

[0020] As shown in FIG. 3, the server-side processing unit 13 encrypts the content uploaded from the transmission-side terminal 20 with the password input from the transmission-side terminal 20 and stores it in the storage unit 12. At this time, the server-side processing unit 13 generates management information and control information, also encrypts the management information, adds these information to the encrypted content (encrypted file), and stores it in the storage unit 12. For example, the server-side processing unit 13 encrypts by adopting the AES (Advanced Encryption Standard) method.

[0021] Here, management information is the information necessary to decrypt encrypted content. Management information includes information about the content file, such as the file name and data size of the encrypted content. Control information includes information such as the watermark attached to the content for content protection, the viewing period for the encrypted content, the password used for encryption, and the deletion period for the encrypted content. Control information can be structured in HTML, Javascript, XML, JSON, etc. Watermark parameters include the string to be displayed, font size, string tilt, font color, and string spacing. For example, the watermark parameters are pre-configured on the sending server 10.

[0022] Once the server-side processing unit 13 has encrypted the content as described above, it issues a download URL for the encrypted content (displaying the download URL on the file transfer service web page). The user on the sending terminal 20 communicates the issued download URL to the user on the receiving terminal 30 using a means of communication such as email. The user on the receiving terminal 30 then downloads the encrypted content from the download URL. This encrypted content includes management information and control information.

[0023] The receiving terminal 30 is also a personal computer, similar to the transmitting terminal 20. Figure 4 is a block diagram showing an example configuration of the receiving terminal 30.

[0024] As shown in Figure 4, the transmitting terminal 20 has a communication unit 31, an operation unit 32, a display unit 33, an HDD (Hard Disk Drive) 34, a memory 35, and a processing unit (hereinafter referred to as the terminal-side processing unit) 40. Here, the communication unit 31 communicates with other devices such as the transmitting server 10 via a communication means NW. The operation unit 32 is a touch panel, mouse, keyboard, etc., operated by the user to input data. The display unit 33 is a touch panel, monitor, etc. Encrypted content, etc., is stored in the HDD 34 as shown in Figure 3. The memory 35 is a volatile memory such as RAM. The terminal-side processing unit 40 executes various processes in the receiving terminal 30. The terminal-side processing unit 40 is equipped with, for example, a microcomputer and its peripheral circuits, and is composed of, for example, a CPU, ROM, RAM, etc. The terminal-side processing unit 40 executes various processes according to the various data and various programs 34a stored in the HDD 34 as needed.

[0025] Figure 5 is a block diagram showing an example configuration of the terminal-side processing unit 40.

[0026] As shown in Figure 5, the terminal-side processing unit 40 has a display processing unit 41 and a decryption processing unit 42. The display processing unit 41 and the decryption processing unit 42 are implemented, for example, as functions of a program stored in the HDD 34. That is, for example, the display processing unit 41 and the decryption processing unit 42 are implemented by an application program downloaded to the receiving terminal 30. The display processing unit 41 performs display processing to display encrypted content on the display unit 33 upon request from the user of the receiving terminal 30. The decryption processing unit 42 performs decryption processing to decrypt the encrypted file stored in the HDD 34 and output the decrypted data to the decryption processing unit 42 upon request from the display processing unit 41. For example, the decryption processing unit 42 functions as a data distribution server by program in the receiving terminal 30. More specifically, for example, the decryption processing unit 42 buffers the decrypted data in memory 35 in combination with the data distribution server and the decryption processing library.

[0027] Figure 6 is a flowchart showing an example of the display process.

[0028] As shown in Figure 6, first, as part of step S1, the display processing unit 41 displays the content display screen on the display unit 33. For example, when an application program for viewing encrypted files is launched on the receiving terminal 30, the display processing unit 41 displays the content display screen on the display unit 33. This example describes the case where the content is a PDF file.

[0029] Figure 7 shows an example of a screen used to display content when an application is launched.

[0030] As shown in Figure 7, the content display screen shows the files that can be displayed. All of these displayable files are encrypted.

[0031] In the subsequent step S2, the display processing unit 41 determines whether the user has entered a password into the content display screen by operating the operation unit 32 of the receiving terminal 30. For example, as shown in Figure 7, when a file displayed on the content display screen is selected (clicked) by the user by operating the operation unit 32 of the receiving terminal 30, the display processing unit 41 displays an input window on the content display screen for entering a password. The display processing unit 41 determines whether a password has been entered into the input window. If the display processing unit 41 determines that a password has been entered into the content display screen, it proceeds to step S3.

[0032] As part of step S3, the display processing unit 41 outputs a request to decrypt the management information to the decryption processing unit 42. At this time, the display processing unit 41 adds the password obtained in step S2 to the request to decrypt the management information.

[0033] In the subsequent step S4, the display processing unit 41 determines whether or not there is a request from the decryption processing unit 42 to re-enter the password. If the display processing unit 41 determines that there is no request from the decryption processing unit 42 to re-enter the password, it proceeds to step S5. On the other hand, if the display processing unit 41 determines that there is a request from the decryption processing unit 42 to re-enter the password, it resumes execution from step S2.

[0034] As part of step S5, the display processing unit 41 determines whether or not it has obtained the decrypted data decrypted by the decryption processing unit 42. If the display processing unit 41 determines that it has obtained the decrypted data decrypted by the decryption processing unit 42, it proceeds to step S6.

[0035] As part of the process in step S6, the display processing unit 41 displays the decrypted content, i.e., the initial display portion (for example, the beginning display portion) of the encrypted content on the display unit 33, based on the decrypted data obtained in the process in step S5. In this example, since the content is a PDF file, the display processing unit 41 displays the first part of the text, such as the first page. At this time, the display processing unit 41 controls the display based on the control information attached to the decrypted data. That is, if the control information includes HTML display control information, the display processing unit 41 treats the decrypted data as HTML data and controls the display. Also, if the control information includes WaterMark display control information, the display processing unit 41 composites a semi-transparent image onto the content displayed on the display unit 33 based on the WaterMark parameters included in the control information.

[0036] In the subsequent step S7, the display processing unit 41 determines whether or not to terminate the display on the display unit 33. For example, the display processing unit 41 determines that the display on the display unit 33 will terminate if the operation unit 32 of the receiving terminal 30 is used to close the content displayed on the display unit 33. If the display processing unit 41 determines that the display on the display unit 33 will terminate, it terminates the display process. On the other hand, if the display processing unit 41 determines that the display on the display unit 33 will not terminate, it proceeds to the process in step S8.

[0037] As part of step S8, the display processing unit 41 determines whether or not a display request has been made by the user to display content on the display unit 33 by operating the operation unit 32 of the receiving terminal 30. In this example, since the content is a PDF file, if the user performs an operation such as scrolling to change the part of the display unit 33 that is displayed on the display unit 33, the display processing unit 41 determines that a display request has been made. If the display processing unit 41 determines that a display request has been made by the user, it proceeds to step S9. On the other hand, if the display processing unit 41 determines that there is no display request from the user, it resumes execution from step S7.

[0038] As part of the processing in step S9, the display processing unit 41 outputs a display request (content request) to the decoding processing unit 42. At this time, the display processing unit 41 adds information about the operations performed by the user in the processing of step S8 (hereinafter referred to as operation information) to the display request.

[0039] In the subsequent step S10, the display processing unit 41 determines whether or not it has obtained the decoded data decoded by the decoded processing unit 42. This decoded data corresponds to the display request output to the decoded processing unit 42 in step S9. If the display processing unit 41 determines that it has obtained the decoded data decoded by the decoded processing unit 42, it proceeds to step S11.

[0040] In step S11, the display processing unit 41 displays the decoded content on the display unit 33 based on the decoded data acquired in step S10. That is, for example, the display processing unit 41 displays the continuation of text or other content corresponding to scrolling operations on the display unit 33. At this time, the display processing unit 41 controls the display based on the control information attached to the decoded data, similar to the process in step S6. After that, the display processing unit 41 resumes execution from step S7.

[0041] As described above, through the display process, the display processing unit 41 displays the content display screen on the display unit 33. When it determines that the operation unit 32 of the receiving terminal 30 has been operated and a password has been entered by the user on the content display screen, it outputs a request to decrypt the management information with the password added to the decryption processing unit 42. Then, when the display processing unit 41 determines that there is no request from the decryption processing unit 42 to re-enter the password and that it has obtained the decrypted data decrypted by the decryption processing unit 42, it displays the initial display portion of the decrypted content on the display unit 33 based on that decrypted data. Subsequently, when the display processing unit 41 determines that the operation unit 32 of the receiving terminal 30 has been operated by the user and a display request has been made to display the content on the display unit 33, it outputs a display request (content request) with operation information added to the decryption processing unit 42. In response, when the display processing unit 41 determines that it has obtained the decrypted data decrypted by the decryption processing unit 42, it displays the decrypted content on the display unit 33 based on the obtained decrypted data. Then, the display processing unit 41 displays the decoded content on the display unit 33 based on the decoded data decoded by the decoded processing unit 42, in response to a display request from the user to the operation unit 32 of the receiving terminal 30 to display content on the display unit 33. That is, for example, the display processing unit 41 displays chapters, etc., on the display unit 33 in response to continuous scrolling operations.

[0042] Figure 8 is a flowchart showing an example of the decoding process.

[0043] As shown in Figure 8, first, in step S21, the decryption processing unit 42 determines whether or not it has obtained the password from the display processing unit 41. If the decryption processing unit 42 determines that it has obtained the password from the display processing unit 41, it proceeds to step S22.

[0044] In step S22, the decryption processing unit 42 determines whether the passwords match. Specifically, the decryption processing unit 42 determines that the passwords match if the password obtained in step S21 is the same as the password in the control information attached to the encrypted content. If the decryption processing unit 42 determines that the passwords match, it proceeds to step S24. On the other hand, if the decryption processing unit 42 determines that the passwords do not match, it proceeds to step S23.

[0045] As part of step S23, the decryption processing unit 42 outputs a password re-entry request to the display processing unit 41. Then, the decryption processing unit 42 terminates the decryption process.

[0046] Meanwhile, as part of step S24, the decryption processing unit 42 decrypts and stores the management information attached to the encrypted content stored in the HDD 34. Here, the management information is, as mentioned above, information for decrypting the encrypted content.

[0047] In the subsequent step S25, the decryption processing unit 42 decrypts the initial display portion of the encrypted content stored on the HDD 34 based on the decrypted management information and stores it in the memory 35.

[0048] In the subsequent step S26, the decoding processing unit 42 outputs the decoded data decoded in step S25 to the display processing unit 41. At this time, the decoding processing unit 42 adds control information to the decoded data and outputs it to the display processing unit 41.

[0049] In the subsequent step S27, the decoding processing unit 42 determines whether or not to terminate the display on the display unit 33. For example, similar to the display processing unit 41, the decoding processing unit 42 determines that the display on the display unit 33 will terminate when the operation unit 32 of the receiving terminal 30 closes the content displayed on the display unit 33. If the decoding processing unit 42 determines that the display on the display unit 33 will terminate, it terminates the decoding process. On the other hand, if the decoding processing unit 42 determines that the display on the display unit 33 will not terminate, it proceeds to the process in step S28.

[0050] As part of step S28, the decoding processing unit 42 determines whether or not there is a display request from the display processing unit 41. If the decoding processing unit 42 determines that there is a display request from the display processing unit 41, it proceeds to step S29.

[0051] As part of the process in step S29, the decryption processing unit 42, based on the decrypted management information, decrypts the encrypted content stored in the HDD 34 if the portion corresponding to the display request is not held in memory 35, and holds it in memory 35. Here, the decryption processing unit 42 adds the decryption time to the decrypted data and holds it in memory 35. As a result, the decryption processing unit 42 compares the decryption time attached to the decrypted data already held in memory 35 with the current time, frees up the area of ​​the decrypted data that has been decrypted for a certain period of time since the decryption time, reuses it, and holds the newly decrypted data in memory 35. This allows the decryption processing unit 42 to decrypt large data files while minimizing the memory area of ​​memory 35. At this time, for the data to be decrypted, the decryption processing unit 42 decrypts the portion of the encrypted content that should be displayed in the display unit 33, such as text, based on the operation information attached to the display request. For example, if the operation information is a scroll operation, the decryption processing unit 42 decrypts the portion of the text that should be displayed by that scroll operation.

[0052] In the subsequent step S30, the decoding processing unit 42 outputs the decoded data decoded in step S29 to the display processing unit 41. After that, the decoding processing unit 42 resumes execution from step S27.

[0053] As described above, through the decryption process, the decryption processing unit 42 obtains a password from the display processing unit 41. If it determines that the password does not match, it outputs a request for password re-entry to the display processing unit 41. On the other hand, if the decryption processing unit 42 determines that the password matches, it decrypts the management information attached to the encrypted content stored in the HDD 34 and stores it in memory 35. Based on this management information, it decrypts the initial display portion of the encrypted content stored in the HDD 34 and stores it in memory 35. Then, the decryption processing unit 42 outputs the decrypted data to the display processing unit 41. Subsequently, if the decryption processing unit 42 determines that there is a display request from the display processing unit 41, it decrypts the portion of the encrypted content stored in the HDD 34 corresponding to the display request based on the management information and the operation information attached to the display request and stores it in memory 35. The decryption data stored in memory 35 has the decryption time attached to it, and by releasing the old data storage area and reusing the memory area, the decryption processing unit 42 can decrypt large data files with a small amount of memory. Then, the decryption processing unit 42 outputs the decrypted data to the display processing unit 41. Then, until it determines that it has finished displaying the content on the display unit 33, the decryption processing unit 42 outputs the decrypted data obtained by decrypting the encrypted content to the display processing unit 41 in response to a display request from the user to the display unit 33, which is operated by the user on the operation unit 32 of the receiving terminal 30.

[0054] Furthermore, the decryption processing unit 42 or the display processing unit 41 prevents the viewing of encrypted content once the viewing period specified in the control information has expired, prevents the viewing of encrypted content once the viewing period has expired, and deletes encrypted content once the deletion period specified in the control information has expired.

[0055] (action, action, etc.) Next, we will describe an example of the operation and function of the file transmission system 1.

[0056] In the file transmission system 1, the user of the sending terminal 20 uploads the content to be transmitted to the file transmission service web page and also enters a password on the file transmission service web page to encrypt the content to be transmitted.

[0057] In the file transmission system 1, the server-side processing unit 13 encrypts the content uploaded from the sending terminal 20 using a password entered by the sending terminal 20, and stores the encrypted content in the storage unit 12. At this time, the server-side processing unit 13 generates management information and control information, encrypts the management information as well, and adds this information to the encrypted content before storing it in the storage unit 12. The server-side processing unit 13 then issues a download URL for the encrypted content. The user of the receiving terminal 30, having received the download URL for the encrypted content from the user of the sending terminal 20, downloads the encrypted content from the download URL on the receiving terminal 30.

[0058] Subsequently, when the application software for displaying content is launched, the display processing unit 41 of the receiving terminal 30 displays a content display screen showing the encrypted content file on the display unit 33. Then, when the operation unit 32 of the receiving terminal 30 is operated and the user selects the encrypted content file, and a password is entered on the content display screen, the display processing unit 41 adds the password and outputs a request to the decryption processing unit 42 for decryption of the management information.

[0059] The decryption processing unit 42 obtains a password from the display processing unit 41, and if the password does not match, it outputs a password re-entry request to the display processing unit 41. When the display processing unit 41 receives a password re-entry request from the decryption processing unit 42, it prompts the user on the receiving terminal 30 to enter the password. On the other hand, if the password matches, the decryption processing unit 42 decrypts the management information attached to the encrypted content stored in the HDD 34, and based on that management information, decrypts the initial display portion of the encrypted content stored in the HDD 34 and stores it in memory 35, and outputs the decrypted data stored in memory 35 to the display processing unit 41.

[0060] When the display processing unit 41 receives decrypted data from the decryption processing unit 42, it displays the initial display portion of the decrypted content on the display unit 33 based on that decrypted data.

[0061] Subsequently, when the display processing unit 41 receives a display request from the user to display content on the display unit 33 by operating the operation unit 32 of the receiving terminal 30, it outputs a display request (content request) with operation information added to it to the decoding processing unit 42.

[0062] When the decryption processing unit 42 receives a display request from the display processing unit 41, it decrypts the portion of the encrypted content stored in the HDD 34 that corresponds to the display request based on the management information and the operation information attached to the display request, stores it in memory 35, and outputs the decrypted data stored in memory 35 to the display processing unit 41.

[0063] When the display processing unit 41 receives decrypted data from the decryption processing unit 42, it displays the decrypted content on the display unit 33 based on that decrypted data.

[0064] (Effects of this embodiment) (1) The receiving terminal 30 decrypts the encrypted content stored in the HDD 34, stores the decrypted data in the memory 35, and outputs the decrypted data stored in the memory 35 to the display processing unit 41 without passing through the HDD 34, that is, without storing it in the HDD 34. As a result, the receiving terminal 30 does not leave any decrypted data on the HDD 34. This prevents the decrypted data from being obtained or viewed by a third party, and as a result the confidentiality and security of the encrypted content are further enhanced.

[0065] (2) The receiving terminal 30 decrypts the portion of the file that corresponds to the display request in memory 35, so it can decrypt files whose data size is larger than the storage capacity of memory 35.

[0066] (Modifications of this embodiment, etc.) As another example of the above embodiment, the target of decryption is not limited to downloaded encrypted content, but can also be encrypted content stored on HDD34, regardless of the acquisition route of the encrypted content.

[0067] Furthermore, as another example of the above embodiment, the transmitting server 10 can also attach unencrypted files to the encrypted content and store them, and then send those files to the receiving terminal 30 upon request from the receiving terminal 30.

[0068] Furthermore, as another example of the above embodiment, the encrypted file is not limited to a PDF file, but can also be a text file, image file, video file, audio file, etc.

[0069] Furthermore, as another example of the above embodiment, if the data size of the file to be decrypted is smaller than the storage capacity of the memory 35, the receiving terminal 30 may decrypt the entire file to be decrypted instead of partially decrypting it and store it in the memory 35. In this case, for example, if the display processing unit 41 determines that the data size of the file to be decrypted is smaller than the storage capacity of the memory 35, it outputs a decryption request to the decryption processing unit 42 to decrypt the entire file to be decrypted, and the decryption processing unit 42 decrypts the entire file to be decrypted based on that decryption request and stores the decrypted data in the memory 35.

[0070] Furthermore, in the above embodiment, the HDD 34 constitutes, for example, a storage means. The display unit 33 constitutes, for example, an output unit. The display processing unit 41 constitutes, for example, an output processing means. The decoding processing unit 42 constitutes, for example, a decoding processing means.

[0071] Furthermore, in the above embodiment, the file decryption device includes a storage means for storing encrypted files, a volatile memory, an output processing means that outputs the contents of the decrypted file to the output unit when an output instruction is received from an external operation after a password for decrypting the decrypted file has been input, and a decryption processing means for decrypting the decrypted file. The output processing means outputs a decryption request to the decryption processing means when an output instruction is received from an external operation after a password for decrypting the decrypted file has been input, and when the decryption processing means receives the decryption request, it decrypts the portion of the file stored in the storage means that corresponds to the output instruction and stores it in the volatile memory, outputs the decrypted data stored in the volatile memory to the output processing means without going through the storage means, and the output processing means outputs the contents of the decrypted file from the output unit based on the decrypted data.

[0072] Furthermore, the above embodiment provides a file decryption method in a file decryption device having an output processing means and a decryption processing means, comprising: a decryption request step in which the output processing means outputs a decryption request when an output instruction is received to the output unit by an external operation after a password for decrypting a decrypted file has been entered; a decryption data output step in which, when a decryption request is entered, the decryption processing means decrypts the portion of the file stored in the storage means that corresponds to the output instruction, stores it in volatile memory, and outputs the decrypted data held in volatile memory without going through the storage means; and a file content output step in which the output processing means outputs the contents of the decrypted file from the output unit based on the decrypted data.

[0073] Furthermore, the above embodiment provides a computer program for a file decryption device having an output processing means and a decryption processing means, which causes the output processing means to output a decryption request step when an output instruction is received to the output unit via external operation after a password for decrypting a decrypted file has been entered; a decryption data output step when the decryption processing means receives a decryption request, decrypts the portion of the file stored in the storage means that corresponds to the output instruction, stores it in volatile memory, and outputs the decrypted data held in volatile memory without going through the storage means; and a file content output step when the output processing means outputs the contents of the decrypted file from the output unit based on the decrypted data.

[0074] Furthermore, while embodiments of the present invention have been disclosed, it will be apparent to those skilled in the art that modifications can be made without departing from the scope of the invention. All such modifications and equivalents are intended to be included in the following claims. [Explanation of Symbols]

[0075] 1 File transmission system, 10 Transmission server, 20 Sending terminal, 30 Receiving terminal, 33 Display unit, 34 HDD, 35 Memory, 40 Terminal-side processing unit, 41 Display processing unit, 42 Decryption processing unit

Claims

1. A storage means on which encrypted files are stored, Volatile memory and After the password for decrypting the decrypted file is entered, and an output instruction is given to the output unit via external operation, the output processing means outputs the contents of the decrypted file to the output unit. Decryption processing means for decrypting the aforementioned decrypted file, It has, After the password for decrypting the decrypted file is entered, the output processing means, upon receiving an output instruction to the output unit via external operation, outputs a decryption request to the decryption processing means. When the decoding request is input, the decoding processing means decodes the portion of the file stored in the storage means that corresponds to the output instruction and stores it in the volatile memory, and outputs the decoded data stored in the volatile memory to the output processing means without passing it through the storage means. The output processing means is a file decryption device that outputs the contents of the decrypted file from the output unit based on the decrypted data.

2. The file decryption device according to claim 1, wherein the decryption processing means decrypts a file whose data size is larger than the storage capacity of the volatile memory.

3. A file decoding method in a file decoding device having output processing means and decoding processing means, The output processing means, after receiving a password for decrypting the decrypted file and receiving an output instruction to the output unit via an external operation, performs a decryption request step that outputs a decryption request. The decryption processing means, upon receiving a decryption request, decrypts the portion of the file stored in the storage means that corresponds to the output instruction, stores it in volatile memory, and outputs the decrypted data stored in volatile memory without passing through the storage means in a decryption data output step. The output processing means includes a file content output step in which the contents of the decoded file are output from the output unit based on the decoded data, A file decryption method having the following characteristics.

4. A computer program for a file decryption device having output processing means and decryption processing means, The output processing means, after receiving a password for decrypting the decrypted file and receiving an output instruction to the output unit via an external operation, performs a decryption request step that outputs a decryption request. The decryption processing means, upon receiving a decryption request, decrypts the portion of the file stored in the storage means that corresponds to the output instruction, stores it in volatile memory, and outputs the decrypted data stored in volatile memory without passing through the storage means in a decryption data output step. The output processing means includes a file content output step in which the contents of the decoded file are output from the output unit based on the decoded data, A computer program that executes an action.