Distribution server, distribution system, distribution method, and program

The distribution system encrypts and splits cyber drill data into a package and beacon, ensuring secure decryption and tamper-evident checks, addressing data theft and misuse risks in wireless environments.

JP2026084974AActive Publication Date: 2026-05-22CHIEF OF DEFENSE EQUIP DEPT +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
CHIEF OF DEFENSE EQUIP DEPT
Filing Date
2024-11-12
Publication Date
2026-05-22

AI Technical Summary

Technical Problem

Cyber drill data, including malware, is vulnerable to theft and misuse in wireless communication environments, posing risks of unintended damage and unauthorized simulation of cyberattacks.

Method used

A distribution system that encrypts and splits cyber drill data into a distribution package and a secure beacon, using a hash value to ensure tamper-evident checks and limits unauthorized decryption, with separate distribution of decryption keys to secure terminals.

Benefits of technology

Guarantees security by making it difficult to misuse stolen data, limits unintended malware behavior, and ensures tamper-evident checks even in unstable communication environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026084974000001_ABST
    Figure 2026084974000001_ABST
Patent Text Reader

Abstract

We provide a mechanism to ensure security even if the distributed data falls into the hands of a third party. [Solution] The distribution server includes means for creating converted data by converting distribution data and check data, creating a beacon containing the hash value of the check data, splitting the beacon to create a first beacon and a second beacon, creating a distribution package containing the converted data and the first beacon, and means for transmitting the distribution package.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a distribution server, a distribution system, a distribution method, and a program.

Background Art

[0002] With the expansion of the use of communication networks, security measures such as cyberattacks have become increasingly important. In response, private companies are training personnel through cyber drills. In general cyber drills, a drill environment equipped with a high-quality network or the like is prepared, and a management server that manages the content of the cyber drill often advances the drill while sequentially controlling the execution of simulated cyberattacks on the drill terminals.

[0003] In order to conduct effective and practical drills, it is preferable to conduct cyber drills using the environment that users normally use as it is, rather than a pseudo environment prepared for the drills. In this case, cyber drill data is distributed from the management server to the user terminals to conduct cyber drills. In recent years, due to the wide penetration of mobile communication and wireless communication, when conducting cyber drills in the user environment, data will be distributed using mobile communication or the like. However, in a wireless communication environment, there is a possibility that data will be stolen during data distribution. Cyber drill data includes malware that has the ability to simulate cyberattacks. If these are stolen and fall into the hands of a third party, they may be misused. In addition, if malware malfunctions in an unintended environment, unexpected damage may occur. When conducting cyber drills in a wireless communication environment, even if communication with the management server is interrupted and it is in an uncontrollable state, it must be possible to control so that unintended cyberattacks are not simulated.

[0004] Patent Document 1 discloses a decryption device that reduces the risk of data being improperly decrypted using a leaked decryption key when the decryption key for encrypted data may be leaked to an external party during the transfer of the decryption key. This decryption device generates a time-limited key by combining the decryption key with time information, verifies the validity of the time-limited key based on the difference between the time attached to the key and the current time, and decrypts the data using the decryption key if it is valid. However, even if a mechanism is in place to decrypt a program that executes a simulated cyberattack using such a time-limited decryption key, if it is decrypted with the decryption key within the time limit, it may be misused or malfunction. [Prior art documents] [Patent Documents]

[0005] [Patent Document 1] Japanese Patent Publication No. 2016-19120 [Overview of the Initiative] [Problems that the invention aims to solve]

[0006] A system is needed that can guarantee security even if data distributed for cyber exercises is stolen.

[0007] Therefore, this invention aims to provide a distribution server, distribution system, distribution method, and program that solve the above-mentioned problems. [Means for solving the problem]

[0008] According to one aspect of the present invention, the distribution server includes means for creating converted data by converting distribution data and check data, creating a beacon containing the hash value of the check data, dividing the beacon to create a first beacon and a second beacon, and creating a distribution package containing the converted data and the first beacon; and means for transmitting the distribution package.

[0009] According to one aspect of the present invention, the distribution system comprises the distribution server and the user terminal, the user terminal comprising means for receiving the distribution package, means for storing the second beacon and a restoration key for restoring the converted data, and means for generating the beacon by combining the first beacon included in the distribution package received by the receiving means and the second beacon stored by the storing means, and for reading the restoration key stored by the storing means and restoring the converted data using the read restoration key.

[0010] According to one aspect of the present invention, the distribution method includes the steps of: creating converted data by converting distribution data and check data; creating a beacon that includes the hash value of the check data; dividing the beacon to create a first beacon and a second beacon; creating a distribution package that includes the converted data and the first beacon; and transmitting the distribution package.

[0011] According to one aspect of the present invention, the program causes a computer to perform the steps of: creating converted data by converting distribution data and check data; creating a beacon that includes the hash value of the check data; dividing the beacon to create a first beacon and a second beacon; creating a distribution package that includes the converted data and the first beacon; and transmitting the distribution package. [Effects of the Invention]

[0012] According to the present invention, security can be guaranteed even if the distributed data is stolen. [Brief explanation of the drawing]

[0013] [Figure 1] This is a block diagram of the cyber exercise system according to the embodiment. [Figure 2]This figure shows an example of the operation of the cyber exercise system according to the embodiment. [Figure 3A] This flowchart shows an example of the distribution package creation process according to the embodiment. [Figure 3B] This diagram illustrates the distribution package creation process according to the embodiment. [Figure 4A] This flowchart shows an example of the distribution package deployment process according to the embodiment. [Figure 4B] This diagram illustrates the distribution package deployment process according to the embodiment. [Figure 5] This is a block diagram showing the configuration of a distribution server with a minimum setup. [Figure 6] This flowchart shows the processing of a distribution server with a minimal configuration. [Figure 7] This figure shows an example of the hardware configuration of the cyber exercise system according to the embodiment. [Modes for carrying out the invention]

[0014] <Embodiment> A cyber exercise system according to one embodiment of the present invention will be described below with reference to the drawings. In the drawings used in the following description, the configuration of parts not related to the present invention may be omitted from the description and not shown.

[0015] (System Configuration) Figure 1 is a block diagram of a cyber exercise system according to an embodiment. As shown in FIG. 1, the cyber exercise system 1 includes a management server 10, a distribution server 20, and user terminals 30a, 30b, and 30c. The management server 10 instructs the distribution server 20 to distribute data used in cyber exercises executed on the user terminals 30a to 30c, or instructs the user terminals 30a to 30c to start a cyber exercise. The distribution server 20 encrypts and packages the data used in the cyber exercise, and distributes it to the user terminals 30a to 30c. The encrypted and packaged data distributed by the distribution server 20 is called a distribution package, and the data before encryption and packaging is called distribution data. The user terminals 30a to 30c unpack and decrypt the distribution package distributed from the distribution server 20, and perform a cyber exercise using the distribution data. The user terminals 30a to 30c are terminal devices normally used by participants in cyber exercises for business and the like. For example, the user terminals 30a to 30c are personal computers (PCs), tablet terminals, mobile terminals such as smartphones, etc. The management server 10, the distribution server 20, and the user terminals 30a to 30c are communicably connected via a network NW. The network NW may use a line that is prone to unstable communication situations such as narrow bandwidth, communication delay, or interrupted communication.

[0016] The management server 10 includes an input reception unit 11, a control unit 12, a display unit 13, a storage unit 14, and a communication unit 15. The input reception unit 11 is configured to include an input device such as a touch panel or a keyboard, receives an operation performed by the user using the input device, generates information corresponding to the operation, and outputs the generated information to the control unit 12. The control unit 12 controls the operation of the management server 10 based on the operation received by the input reception unit 11. For example, the control unit 12 performs display control of the display unit 13 and communication control using the communication unit 15. The control unit 12 uses the communication unit 15 to transmit a distribution instruction for a distribution package, an execution instruction for a cyber exercise, and to perform transmission and reception of a secure beacon described later. The display unit 13 is configured to include a display device such as a liquid crystal display. The display unit 13 displays various information based on the instructions of the control unit 12. The storage unit 14 is composed of storage media such as RAM (Random Access Memory), ROM (Read Only Memory), EEPROM (Electrically Erasable Programmable Read Only Memory), HDD (Hard Disk Drive), SSD (Solid State Drive), etc., and stores various information. The communication unit 15 is configured using a communication module and communicates with other devices such as the distribution server 20 and user terminals 30a to 30c.

[0017] The distribution server 20 includes an input reception unit 21, a control unit 22, a display unit 23, a storage unit 24, and a communication unit 25. The input reception unit 21 is configured to include an input device such as a touch panel or a keyboard, receives an operation performed by the user using the input device, generates information corresponding to the operation, and outputs the generated information to the control unit 22. The control unit 22 controls the operation of the distribution server 20 based on the operation received by the input reception unit 21 and the instruction information received from the management server 10. For example, the control unit 22 performs display control of the display unit 23 and communication control using the communication unit 25. The control unit 22 includes a package creation unit 221. The package creation unit 221 encrypts and packages distribution data to create a distribution package. Also, the package creation unit 221 creates a secure beacon. The secure beacon is used for tampering check of the distribution package. The control unit 22 uses the communication unit 25 to transmit the distribution package to user terminals 30a to 30c. Also, the control unit 22 uses the communication unit 25 to transmit the secure beacon to the management server 10. The display unit 23 is configured to include a display device such as a liquid crystal display. The display unit 23 displays various information based on the instructions of the control unit 22. The storage unit 24 is composed of storage media such as RAM, ROM, EEPROM, HDD, SSD, etc., and stores various information. The communication unit 25 is configured using a communication module and communicates with other devices such as the management server 10 and user terminals 30a to 30c.

[0018] The user terminal 30a comprises an input receiving unit 31a, a control unit 32a, a display unit 33a, a storage unit 34a, and a communication unit 35a. The input receiving unit 31a includes input devices such as a touch panel and a keyboard, and receives operations performed by exercise participants using these input devices, generates information corresponding to the operations, and outputs the generated information to the control unit 32a. The control unit 32a controls the operation of the user terminal 30a based on operations received by the input reception unit 31a and instruction information received from the management server 10. The control unit 32a includes a package management unit 321a, a beacon monitoring unit 322a, and an exercise scenario control unit 323a. The package management unit 321a saves, unpacks, and decrypts distribution packages distributed from the distribution server 20. The beacon monitoring unit 322a logs the contents of secure beacons distributed from the management server 10. The beacon monitoring unit 322a also disables secure beacons recorded in the log according to usage restriction information sent from the management server 10 or set by the user. The exercise scenario control unit 323a controls the execution of exercise scenarios and malware that simulate cyberattacks included in the distribution package. The exercise scenarios include information such as the timing and conditions for executing malware to simulate cyberattacks, and the exercise scenario control unit 323a executes simulated malware based on the exercise scenarios. Furthermore, the distributed simulated malware is configured so that it can only be executed by the exercise scenario control unit 323a. For example, the simulated malware may be created in a data format that can only be executed by the exercise scenario control unit 323a, or it may be configured so that it cannot be executed unless it communicates with the exercise scenario control unit 323a at startup and is authenticated by a predetermined check process.

[0019] The display unit 33a includes a display device such as a liquid crystal display. The display unit 33a displays information based on instructions from the control unit 32a. The memory unit 34a is composed of storage media such as RAM, ROM, EEPROM, HDD, and SSD, and stores various information such as exercise scenarios. The communication unit 35a is configured using a communication module and communicates with other devices such as the management server 10, the distribution server 20, and user terminals 30b to 30c.

[0020] The configurations of user terminals 30b and 30c are the same as those of user terminal 30a, so their illustrations and descriptions are omitted. Hereafter, unless it is necessary to distinguish between user terminals 30a to 30c, they will be referred to as user terminal 30, and each functional unit will be referred to as input reception unit 31, control unit 32, package management unit 321, beacon monitoring unit 322, exercise scenario control unit 323, display unit 33, storage unit 34, communication unit 35, etc. In the cyber exercise system 1 shown in Figure 1, there are three user terminals, but there may be two or fewer user terminals 30, or four or more. In addition, the cyber exercise system 1 may have multiple management servers 10 or distribution servers 20.

[0021] (operation) <Overall processing flow> Next, referring to Figure 2, we will explain the process flow in the cyber exercise system 1, from the creation and distribution of the distribution package to the deployment of the distribution package on the user terminal 30 that received the distribution package and the execution of the cyber exercise. Figure 2 shows an example of the operation of the cyber exercise system according to the embodiment. As a premise, it is assumed that the storage unit 24 of the distribution server 20 stores the distribution data. The distribution data includes data subject to encryption, such as exercise scenarios and malware, as well as data not subject to encryption, such as an exercise environment construction program that performs processing to build the exercise environment, such as deploying the exercise scenarios and malware after deployment and decryption to the appropriate location, and a recovery program that performs processing to restore the operating environment of the user terminal 30 to the same state as before the exercise, such as deleting the exercise scenarios and malware after the exercise.

[0022] The administrator of the cyber exercise performs an operation to instruct the creation and distribution of the distribution package. On the management server 10, the input reception unit 11 receives this operation, and the control unit 12 uses the communication unit 15 to send instruction information instructing the creation and distribution of the distribution package (step S1). For example, the instruction information includes information specifying the contents of the distribution package and the distribution destination. On the distribution server 20, the communication unit 25 receives the instruction information and outputs the received instruction information to the control unit 22. The control unit 22 instructs the distribution package creation unit 221 to create the distribution package. The distribution package creation unit 221 reads the distribution data from the storage unit 24 and creates the distribution package and secure beacon (step S2). Details of the distribution package creation process will be explained later using Figures 3A to 3B. Once the distribution package and secure beacon are created, the control unit 22 uses the communication unit 25 to send the distribution package to the specified distribution destination (step S3). In the user terminal 30, the communication unit 35 receives the distribution package, and the control unit 32 records and saves the distribution package in the storage unit 34 (step S4).

[0023] Furthermore, the control unit 22 uses the communication unit 25 to send a secure beacon to the management server 10 (step S5). At the management server 10, the communication unit 15 receives the secure beacon, and the control unit 12 stores the secure beacon in the storage unit 14 (step S6). The secure beacon is, for example, text data composed of letters and numbers. The transmission order of the distribution package and the secure beacon may be reversed.

[0024] Next, based on the administrator's instructions, the control unit 12 of the management server 10 uses the communication unit 15 to send the secure beacon and usage restriction information to the user terminal 30 (step S7). At the user terminal 30, the communication unit 35 receives the secure beacon and usage restriction information and outputs it to the beacon monitoring unit 322. The beacon monitoring unit 322 registers the secure beacon in a dedicated log (step S8). For example, if the secure beacon is a 10-digit string, the beacon monitoring unit 322 records this string in a dedicated log file, associates it with the previously distributed distribution package, and saves this log file in the storage unit 34. The beacon monitoring unit 322 also saves the usage restriction information in the storage unit 34 and monitors the validity status of the received secure beacon based on the usage restriction information (step S9). If the expiration condition is met, the beacon monitoring unit 322 performs the process of deactivating the secure beacon. Usage restriction information is, for example, the expiration date. The expiration condition is that the expiration date has passed. The beacon monitoring unit 322 performs a deactivation process for secure beacons when the set expiration date and time have passed. For example, the beacon monitoring unit 322 may perform the deactivation process by recording information indicating that the secure beacon has been deactivated in a deactivation log file separate from the log file in which the deactivated secure beacon was registered. When a secure beacon is received, the beacon monitoring unit 322 determines whether the secure beacon is valid or invalid at predetermined time intervals until the secure beacon is deactivated, and if it is invalid, it performs the deactivation process described above. In this example, usage restriction information is sent from the management server 10 to the user terminal 30, but since there is a risk of false usage restriction information being sent, the usage restriction information may be transmitted to the user on the user terminal 30 by another means, and the usage restriction information may be set for each user terminal 30 when building the environment for the exercise.

[0025] Furthermore, in cases where the communication status between the management server 10 and the user terminal 30 is poor, or for the purpose of ensuring greater security, instead of sending secure beacons etc. from the management server 10 to the user terminal 30, the secure beacon and usage restriction information may be verbally transmitted to the user on the user terminal 30 using telephone or other means. In this case, the user inputs the contents of the transmitted secure beacon and usage restriction information into the user terminal 30. The input receiving unit 31 receives this input and outputs the input secure beacon and usage restriction information to the beacon monitoring unit 322. When the beacon monitoring unit 322 receives the secure beacon and usage restriction information, it registers the secure beacon in the log and saves the usage restriction information in the storage unit 34. The beacon monitoring unit 322 then monitors whether the secure beacon is valid or not until the secure beacon is deactivated, and if the deactivation conditions are met, it performs the secure beacon deactivation process described above. In this case, the usage restriction information may be the number of times it is limited. The limit refers to the number of times the user attempts to input the secure beacon, which was verbally communicated to them, into the user terminal 30 (the number of times the beacon monitoring unit 322 registers the secure beacon in the log). If the user attempts to input the secure beacon multiple times, it is determined that some kind of fraud is suspected, and the number of input attempts is limited. In this case, the condition for expiration is that the number of input attempts exceeds the limit.

[0026] Next, based on the administrator's instructions, the control unit 12 of the management server 10 uses the communication unit 15 to send instruction information to the user terminal 30 to instruct it to start the cyber exercise (step S10). At the user terminal 30, the communication unit 35 receives the instruction information to start the cyber exercise, and the control unit 32 outputs to the display unit 33 that an instruction to start the cyber exercise has been received. The user performs an operation on the user terminal 30 to instruct it to unpack the package saved in step S4. The input reception unit 31 receives this operation and notifies the control unit 32 that it has received an operation to instruct it to unpack the package. The control unit 32 instructs the package management unit 321 to unpack the distribution package. The package management unit 321 reads the distribution package from the storage unit 34 and performs unpacking, decryption, etc. (step S11). Details of the distribution package unpacking process will be explained later using Figures 4A to 4B. Once the distribution package is unpacked, the user performs an operation on the user terminal 30 to instruct it to execute the cyber exercise. When the input receiving unit 31 receives this operation, the exercise scenario control unit 323 reads the exercise scenario from the memory unit 34 and executes the exercise scenario. This executes the cyber exercise (step S12). In the above explanation, the cyber exercise is initiated upon receiving the instruction information sent in step S10, but instead, the cyber exercise may be initiated in step S8 when the user terminal 30 receives a secure beacon.

[0027] <Creating a distribution package> Next, referring to Figures 3A and 3B, the process of creating the distribution package and secure beacon in step S2 will be explained. Figure 3A is a flowchart of an example of the distribution package creation process. First, the package creation unit 221 of the distribution server 20 encrypts the distribution data to be encrypted (step S21). Figure 3B shows the details of the encryption process in S21. The package creation unit 221 reads the distribution data to be encrypted D211, the distribution data not to be encrypted D212, and the operational condition data D213 from the storage unit 34. The distribution data to be encrypted D211 is malware that executes exercise scenarios and simulated cyberattacks. This data is encrypted because it is highly dangerous. The distribution data not to be encrypted D212 is the exercise environment construction program and recovery program, and these are not encrypted. The operational condition data D213 is an arbitrary value used for tampering checks. The operational condition data D213 is registered in the storage unit 24 in advance and can be changed at any time. The package creation unit 221 encrypts the distribution data D211 to be encrypted and the operational condition data D213 together to create encrypted distribution data D214 (S211). The encryption key (e.g., public key) used for encryption is distributed to the distribution server 20 by secure means and stored in the storage unit 24 in advance. The decryption key (e.g., private key) used to decrypt the encrypted distribution data D214 is distributed to the user terminal 30 in advance via a route other than the network NW, from the standpoint of ensuring security, and stored in the storage unit 34 of the user terminal 30.

[0028] Next, the package creation unit 221 creates a secure beacon (step S22). Figure 3B shows the details of the secure beacon creation process in S22. The package creation unit 221 calculates the hash value D221 of the operational condition data D213. The hash value D221 is set as a parameter for detecting tampering with the distributed data. The package creation unit 221 also encrypts the hash value D221 using the AES encryption key D223 to calculate beacon D224 (S222). The AES encryption key D223 is stored in the storage unit 24 beforehand. Next, the package creation unit 221 divides beacon D224 to calculate beacon A (D225) and beacon B (D226) (S223). The resulting beacon A (D225) is stored in the distribution package, and beacon B (D226) is sent to the management server as the secure beacon described in Figure 2.

[0029] Next, the package creation unit 221 creates a distribution package (step S23). Figure 3B shows the details of the distribution package creation process in S23. The package creation unit 221 packages the encrypted distribution data D214, the AES encryption key D223, beacon A (D225), and the non-encrypted distribution data D212 into a single file. For example, the package creation unit 221 may archive these files in tar format, or it may further compress them and archive them in tar.gz format. The archived file is the distribution package D231. The distribution package D231 is sent to the user terminal 30 by the distribution server 20.

[0030] <Deployment of distribution package> Next, we will refer to Figures 4A and 4B to explain the distribution package deployment process in step S11. Figure 4A is a flowchart showing an example of the distribution package deployment process. As a prerequisite, the memory unit 34 stores the distribution package D231 and beacon B (D226) (secure beacon). When a user initiates an operation to deploy the distribution package, the beacon monitoring unit 322 retrieves a log from the storage unit 34 indicating that the secure beacon has been registered (step S111) and determines whether the secure beacon is within the usage limits (step S112). For example, if the invalidation log file contains information indicating that the secure beacon has been invalidated, the beacon monitoring unit 322 determines that the usage limits have been exceeded; otherwise (for example, if the log contains an expiration date for a future date), it determines that the beacon is within the usage limits. The beacon monitoring unit 322 notifies the control unit 32 of this determination result. If the beacon is not within the usage limits (step S112; No), the control unit 32 displays an error message (step S119). For example, the control unit 32 outputs a message to the display unit 33 such as, "The expiration date has passed. The distribution package cannot be deployed." In this case, the flowchart in Figure 4A ends.

[0031] If the usage restrictions are met (Step S112; Yes), the control unit 32 instructs the package management unit 321 to deploy the distribution package. Based on this instruction, the package management unit 321 performs the following processing.

[0032] The package management unit 321 reads the distribution package D231 from the storage unit 34 and unpacks it (step S113). Figure 4B shows the details of the unpacking process in S113. When the distribution package D231 is unpacked (S1131), encrypted distribution data D214, AES encryption key D223, beacon A (D225), and non-encrypted distribution data D212 are output.

[0033] Next, the package management unit 321 decrypts beacon D224 (step S114). Figure 4B shows the details of the beacon decryption process in S114. The package management unit 321 combines the decrypted beacon A (D225) and beacon B (D226) stored in the storage unit 34 to generate beacon D224 (S1141). The package management unit 321 decrypts the generated beacon D224 using the decrypted AES encryption key D223 (S1142). This decryption outputs the movable condition hash value D221.

[0034] Next, the package management unit 321 decrypts the encrypted distribution data (step S115). Figure 4B shows the details of the encrypted distribution data decryption process in S115. The package management unit 321 reads a decryption key (e.g., a secret key) that was previously stored in the storage unit 34, and decrypts the encrypted distribution data D214 obtained by unpacking the distribution package using the read decryption key (S1151). This decryption yields the encrypted distribution data D211 and the operational condition data D213.

[0035] Next, the package management unit 321 performs a tamper-evident check on the distribution data (step S116). Figure 4B shows the details of the tamper-evident check in S116. Based on the operational condition data D213 obtained by decrypting the encrypted distribution data D214, the package management unit 321 calculates the hash value D221-2 in the same manner as the processing in step S221 by the package creation unit 221 (S1161). The package management unit 321 compares the operational condition hash value D221 obtained by decrypting the beacon D224 with the calculated hash value D221-2 (S1162). If the operational condition hash value D221 and the hash value D221-2 match, the package management unit 321 determines that there has been no tampering. If the operational condition hash value D221 and the hash value D221-2 do not match, the package management unit 321 determines that there has been tampering. The package management unit 321 notifies the control unit 32 of this determination result.

[0036] If it is determined that there has been no tampering (step S117; Yes), the control unit 32 outputs the distribution data (step S118). For example, the control unit 32 displays the message "Distribution package deployment is complete" on the display unit 33, copies the encrypted distribution data D211 and the non-encrypted distribution data D212 to a predetermined path, and executes the environment setup program contained in the non-encrypted distribution data D212. As a result, the exercise scenarios and malware contained in the encrypted distribution data D211 are deployed to the predetermined location (path), and an environment in which the exercise scenarios can be executed is created.

[0037] If tampering is detected (step S117; No), the control unit 32 performs error processing (step S120). For example, the control unit 32 may display the message "Failed to unpack the distribution package" on the display unit 33 and delete the encrypted distribution data D211 and the non-encrypted distribution data D212 generated in steps S113 to S115. In this case, the flowchart in Figure 4A is terminated.

[0038] (effect) As explained above, according to the cyber exercise system 1 of this embodiment, the data used for cyber exercises is distributed in two parts: a distribution package and a secure beacon. In addition, the decryption key (e.g., a private key) necessary for decrypting malware, etc., contained in the distribution package is distributed to the user terminal 30 in advance via a secure route. Therefore, malware, etc., cannot be decrypted unless all of the distribution package D231, the secure beacon, and the decryption key (e.g., a private key) are obtained. Thus, even if the distribution package D231 is stolen during distribution, security can be guaranteed. Furthermore, the distribution package D231 includes the movable condition data D213, and the secure beacon includes the hash value D221 of the movable condition data D213. After decrypting the distribution package D231, a hash value can be calculated from the movable condition data D213 contained in the distribution package D231, and tampering can be checked by comparing the calculated value with the hash value D221 included in the secure beacon. This allows for the detection of tampering with distribution package D231, preventing damage caused by data tampering. Furthermore, when creating a secure beacon, the hash value D221 is encrypted, the encrypted data is split, one portion is used to create the secure beacon, and the remaining encrypted data and its decryption key (AES encryption key D223) are included in distribution package D231. Therefore, without obtaining both distribution package D231 and the secure beacon, it is impossible to combine and restore beacon A and beacon B, and the tampering check cannot be performed correctly, thus guaranteeing the legitimacy of the tampering check. Additionally, without a separately distributed decryption key (e.g., a private key), the encrypted distribution data D214 cannot be decrypted, making malware recovery difficult and thus ensuring security. Moreover, usage restrictions such as an expiration date can be set for beacon B (D226), increasing the difficulty of malware recovery and improving security.

[0039] In the actual system configuration, secure beacons and usage restriction information are transmitted from the management server 10. However, for example, the management server 10 may send instruction information to the distribution server 20 to instruct it to transmit secure beacons, etc., and the distribution server 20, upon receiving this instruction information, may transmit secure beacons and usage restriction information to the user terminal 30. In the actual system configuration, encrypted distribution data D211, etc., are encrypted to create encrypted distribution data D214. However, instead of this, or in addition to this, in order to improve the difficulty of decryption if the distribution package is stolen, for example, the target data (e.g., encrypted distribution data D214 or encrypted distribution data D211) may be partially transformed (bit-replaced) or entirely transformed (bit-replaced), and information indicating how it has been modified may be included in the secure beacon. When the package is unpacked, the information indicating how it has been modified may be extracted from the secure beacon, and the transformed data may be corrected based on the extracted information to restore it to the data before bit replacement. The information indicating how it has been modified from the secure beacon is an example of a restoration key. Furthermore, the decryption key (e.g., a private key) used to decrypt the encrypted distribution data D214 is an example of a recovery key.

[0040] Furthermore, in order to conduct effective cyber exercises, it is desirable to conduct them using the environment that participants normally use, rather than using a pre-prepared simulated exercise environment. However, in recent years, network environments that are not necessarily of high quality, such as wireless communication and mobile communication, have been expanding, and there is a risk of theft during data distribution. When conducting cyber exercises in a wireless communication environment, even if communication with the management server 10 that controls the exercise is interrupted and control becomes impossible, it is necessary to control the malware so that it does not behave unintentionally. As explained above, according to this embodiment, it is difficult to recover the malware, and the period during which recovery is possible is limited, so the opportunity for the malware to behave unintentionally can be limited. Moreover, even if the malware can be recovered, the mechanism is such that only the exercise scenario control unit 323 can execute a simulated attack by the malware, thus reducing the possibility of the malware behaving unintentionally in an unintended environment.

[0041] (Minimum configuration) Figure 5 is a block diagram showing the configuration of a distribution server with a minimum setup. The distribution server 40 includes a package creation means 41 and a transmission means 42. The package creation means 41 creates converted data (for example, encrypted data, bit-substituted data, or data obtained by converting the original data by both encryption and bit substitution) obtained by converting the distribution data and the check data, and a beacon containing the hash value of the check data, divides the beacon to create a first beacon and a second beacon, and creates a distribution package containing the converted data and the first beacon. The transmission means 42 transmits the distribution package created by the package creation means 41.

[0042] Figure 6 is a flowchart showing the processing of a distribution server with a minimal configuration. The package creation means 41 creates converted data (encrypted distribution data D214) by converting the distribution data (encrypted distribution data D211) and the check data (operational condition data D213) (step S31). The package creation means 41 creates an encrypted beacon (D224) that includes the hash value of the check data (operational condition hash value D221) (step S32). The package creation means 41 splits the beacon (D224) (step S33) to create a first beacon (D225) and a second beacon (D226). The package creation means 41 creates a distribution package (D231) that includes the converted data (D214), the first beacon (D225), and a decryption key (AES encryption key D223) for decrypting the encrypted beacon (step S34). The transmission means 42 transmits the distribution package (step S35).

[0043] Figure 7 shows an example of the hardware configuration of the cyber exercise system according to the embodiment. Computer 900 is, for example, a PC (Personal Computer) or server terminal device equipped with a CPU 901, main memory 902, auxiliary memory 903, input / output interface 904, and communication interface 905. The management server 10, distribution server 20, and user terminal 30 mentioned above are implemented in computer 900. The above-mentioned processes are stored in auxiliary memory 903 in the form of programs. The CPU 901 reads the program from auxiliary memory 903, expands it into main memory 902, and executes the above processes according to the program. The CPU 901 also allocates memory space in main memory 902 according to the program. The CPU 901 also allocates memory space in auxiliary memory 903 to store data being processed according to the program.

[0044] In at least one embodiment, the auxiliary storage device 903 is an example of a non-temporary tangible medium. Other examples of non-temporary tangible media include magnetic disks, magneto-optical disks, CD-ROMs, DVD-ROMs, semiconductor memory, etc., connected via the input / output interface 904. Furthermore, if this program is distributed to the computer 900 via a communication line, the computer 900 that receives the program may expand it into the main memory 902 and execute the above processing. The program may also be for the purpose of realizing some of the functions described above. Moreover, the program may be a so-called differential file (differential program) that realizes the above-mentioned functions in combination with other programs already stored in the auxiliary storage device 903.

[0045] Although one embodiment of this invention has been described in detail above with reference to the drawings, the specific configuration is not limited to that described above, and various design changes can be made without departing from the spirit of this invention. Furthermore, one aspect of the present invention can be modified in various ways within the scope of the claims, and embodiments obtained by appropriately combining the technical means disclosed in different embodiments are also included in the technical scope of the present invention. In addition, configurations in which elements described in the above embodiments and modifications are replaced with elements that produce similar effects are also included.

[0046] Some or all of the above embodiments may be described as follows, but are not limited to the following:

[0047] (Note 1) A distribution server comprising means for creating converted data by converting distribution data and check data, creating a beacon containing the hash value of the check data, splitting the beacon to create a first beacon and a second beacon, and creating a distribution package containing the converted data and the first beacon; and means for transmitting the distribution package.

[0048] (Note 2) The means for transmission is the distribution server described in Appendix 1, which transmits the second beacon separately from the distribution package.

[0049] (Note 3) The means for creating the distribution package is a distribution server as described in Appendix 1 or Appendix 2, which creates the distribution package including a decryption key for decrypting the encrypted beacon, the converted data, and the first beacon.

[0050] (Note 4) The aforementioned second beacon has an expiration date set for the distribution server listed in any one of the appendices 1 to 3.

[0051] (Note 5) The aforementioned distribution data includes malware and is distributed to any of the distribution servers listed in Appendix 1 to Appendix 4.

[0052] (Note 6) A distribution system comprising a distribution server described in any one of Appendix 1 to Appendix 5, and a user terminal, wherein the user terminal comprises means for receiving the distribution package, means for storing the second beacon and a restoration key for restoring the converted data, and means for generating the beacon by combining the first beacon included in the distribution package received by the receiving means and the second beacon stored by the storing means, and for reading the restoration key stored by the storing means and restoring the converted data using the read restoration key.

[0053] (Note 7) The distribution system described in Appendix 6, wherein the means for restoration involves extracting the check data from the restored converted data, calculating a hash value, and comparing the calculated hash value with the hash value contained in the beacon to determine whether or not the distribution package has been tampered with.

[0054] (Note 8) The distribution system as described in Appendix 6 or Appendix 7, wherein the user terminal further comprises means for determining whether the second beacon is valid based on predetermined expiration conditions, and if the determining means determines that the second beacon is not valid, the restoration means does not restore the converted data.

[0055] (Note 9) A distribution method comprising the steps of: creating converted data by converting distribution data and check data; creating a beacon containing the hash value of the check data; dividing the beacon to create a first beacon and a second beacon; creating a distribution package containing the converted data and the first beacon; and transmitting the distribution package.

[0056] (Note 10) A program that causes a computer to perform the following steps: create converted data by converting distribution data and check data; create a beacon containing the hash value of the check data; divide the beacon to create a first beacon and a second beacon; create a distribution package containing the converted data and the first beacon; and transmit the distribution package. [Explanation of Symbols]

[0057] 1. Cyber ​​Exercise System 10. Management Server 11. Input Reception Section 12. Control Unit 13...Display section 14...Storage section 15. Communications Department 20...Distribution Server 21...Input Reception Section 22.. Control Unit 221...Package Creation Department 221 23...Display section 24...Storage section 25. Communications Department 30, 30a, 30b, 30c... User terminals 31,31a...Input reception section 32,32a..., control unit 321,321a...Package Management Department 322,322a...Beacon Monitoring Unit 323,323a...Exercise Scenario Control Unit 33,33a...Display section 34,34a...Storage section 35,35a...Communication Department 900... Computer 901···CPU 902...Main memory 903...Auxiliary storage device 904... Input / Output Interface 905...Communication Interface

Claims

1. Means for creating converted data by converting distribution data and check data, creating a beacon containing the hash value of the check data, splitting the beacon to create a first beacon and a second beacon, and creating a distribution package containing the converted data and the first beacon, means for transmitting the aforementioned distribution package, A distribution server equipped with the necessary features.

2. The means for transmitting transmits the second beacon separately from the distribution package. The distribution server according to claim 1.

3. The means for creating the distribution package creates the distribution package which includes a decryption key for decrypting the encrypted beacon, the converted data, and the first beacon. The distribution server according to claim 1 or claim 2.

4. The aforementioned second beacon has an expiration date set. The distribution server according to claim 1 or claim 2.

5. The aforementioned distribution data contains malware, The distribution server according to claim 1 or claim 2.

6. A distribution server according to claim 1 or claim 2, A user terminal is provided, The aforementioned user terminal is means for receiving the aforementioned distribution package, A means for storing the second beacon and a recovery key for restoring the converted data, A means for generating a beacon by combining the first beacon contained in the distribution package received by the receiving means and the second beacon stored by the storing means, and for reading the recovery key stored by the storing means and recovering the converted data using the recovered recovery key, A distribution system equipped with these features.

7. The restoration means extracts the check data from the restored converted data, calculates a hash value, and compares the calculated hash value with the hash value contained in the beacon to determine whether or not the distribution package has been tampered with. The distribution system according to claim 6.

8. The aforementioned user terminal is Means for determining whether the second beacon is valid or not based on predetermined expiration conditions, Furthermore, If the means for making the determination determines that the second beacon is not valid, The means for restoration does not perform the restoration of the converted data. The distribution system according to claim 6.

9. The steps include creating converted data by converting the distribution data and the data for checking, The steps include creating a beacon that includes the hash value of the aforementioned check data, The steps include dividing the aforementioned beacon to create a first beacon and a second beacon, A step of creating a distribution package that includes the converted data and the first beacon, The steps include sending the aforementioned distribution package, Packaging distribution method.

10. On the computer, The steps include creating converted data by converting the distribution data and the data for checking, The steps include creating a beacon that includes the hash value of the aforementioned check data, The steps include dividing the aforementioned beacon to create a first beacon and a second beacon, A step of creating a distribution package that includes the converted data and the first beacon, The steps include sending the aforementioned distribution package, A program that executes the command.