Tamper detection device and tamper detection program
The tampering detection device and program accurately detect data tampering by verifying the consistency of block and data hash values across a network, addressing the limitations of existing methods where tampering goes undetected.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- DENSO CORP
- Filing Date
- 2024-11-21
- Publication Date
- 2026-06-02
Smart Images

Figure 2026090095000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a tampering detection device that detects tampering when data is tampered with, and a tampering detection program.
Background Art
[0002] Patent Document 1 discloses a tampering detection method capable of detecting tampering performed on data stored in a database. The tampering detection method disclosed in Patent Document 1 registers the hash value of the data stored in the database in a blockchain. When data is acquired, the hash value is recalculated from the data and compared with the hash value registered in the blockchain to enable tampering detection. The description of the prior art document is incorporated herein by reference as an explanation of the technical elements in this specification.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, in the tampering detection method disclosed in Patent Document 1, after tampering with the original data stored in the database, the hash value of the tampered original data is calculated, and the hash value recorded in the blockchain is overwritten with the hash value of the tampered original data. If all the hash values that are the connections of the blockchain are also tampered so that they are consistent, the tampering cannot be detected. In that such a case, the technology disclosed in Patent Document 1 cannot detect that the original data has been tampered with, and an improvement in the accuracy of detecting that the original data has been tampered with is desired.
[0005] This disclosure is made in light of these circumstances and aims to provide a data tampering detection device and a data tampering detection program that can accurately detect tampering with the original data. [Means for solving the problem]
[0006] The above objectives are achieved by combinations of features described in the independent claims, and the subordinate claims provide further advantageous specific examples. The reference numerals in parentheses in the claims indicate a correspondence with specific embodiments described later as one aspect, and do not limit the disclosed technical scope.
[0007] One disclosure relating to a tamper detection device for achieving the above objective is: A tampering detection device that detects tampering when the original data stored in the data storage system (10, 310) has been altered, The data storage system is The original data DB (22) is a database that stores the original data, A blockchain node (30) holds a blockchain (31) which contains multiple blocks (40) in which the original data hash value (71), which is a hash value calculated from the original data, Subsequent blocks in the blockchain record the previous block hash value (53), which is the hash value of the previous block. The tampering detection device is A block consistency determination unit (91) calculates a block hash value from the target block, which is the block subject to tampering determination, and compares the calculated block hash value with the previous block hash value recorded in the block immediately following the target block to determine whether the target block and the block immediately following the target block are consistent. A data consistency determination unit (93, 393) identifies the original data corresponding to the original data hash value recorded in the target block from the original data DB, and determines whether the hash value calculated from the identified original data matches the original data hash value. A blockchain consistency determination unit (94) is defined as the local node (30A), identifies a block with the same block number as the latest block held by the local node from other nodes (30B, 30C) that are different from the local node but hold the blockchain, calculates a block hash value from the identified block, and determines whether the calculated block hash value is consistent with the block hash value calculated from the latest block of the local node. Based on the results of the consistency judgments made by the block consistency judgment unit, the original data consistency judgment unit, and the blockchain consistency judgment unit, a tampering judgment unit (95, 395) determines whether or not the original data has been tampered with, It is a tampering detection device that includes [a specific feature / function].
[0008] If the hash value of the block immediately preceding the target block has not been tampered with, the block consistency determination unit can determine that the target block has not been tampered with. Assuming the target block has not been tampered with, the original data consistency determination unit can determine that the original data has not been tampered with. Then, the blockchain consistency determination unit can determine whether or not the blockchain of the current block has been tampered with. If it is determined that the blockchain of the current block has not been tampered with, then it can also be determined that the hash value of the block immediately preceding the target block has not been tampered with. Therefore, based on the consistency determination results of the block consistency determination unit, the original data consistency determination unit, and the blockchain consistency determination unit, the tampering determination unit can accurately determine if the original data has been tampered with. Thus, the tampering detection device can accurately detect tampering with the original data.
[0009] One disclosure relating to a tamper detection program for achieving its objectives is: A data storage system (10, 310) comprising a blockchain node that records a blockchain (31) containing multiple blocks (40) which include a database (22) containing the original data and a block (40) which records the original data hash value (71) calculated from the original data, and for the second and subsequent blocks, a blockchain which records the previous block hash value (53) which is the hash value of the previous block, is used to detect tampering with the original data stored in the system, and a tamper detection program is executed by a processor to detect tampering when the original data stored in the system has been altered. The processor, A block consistency determination unit (91) calculates a block hash value from the target block, which is the block subject to tampering determination, and compares the calculated block hash value with the previous block hash value recorded in the block immediately following the target block to determine whether the target block and the block immediately following the target block are consistent. A data consistency determination unit (93, 393) identifies the original data corresponding to the original data hash value recorded in the target block from the original data DB, and determines whether the hash value calculated from the identified original data matches the original data hash value. A blockchain consistency determination unit (94) is defined as the local node (30A), identifies a block with the same block number as the latest block held by the local node from other nodes (30B, 30C) that are different from the local node but record the blockchain, calculates a hash value from the identified block, and determines whether the calculated hash value is consistent with the hash value calculated from the latest block of the local node. Based on the results of the block consistency determination unit, the original data consistency determination unit, and the blockchain consistency determination unit, a tampering determination unit (95, 395) determines whether or not the original data has been tampered with. This is a tamper detection program designed to function as such. [Brief explanation of the drawing]
[0010] [Figure 1] A diagram showing the configuration of the data storage system according to the first embodiment. [Figure 2] Figure showing components included in the control circuit. [Figure 3] Figure for explaining the blockchain. [Figure 4] Figure showing the data structure of the block. [Figure 5] Figure showing that multiple blockchain nodes are interconnected. [Figure 6] Figure showing the functions executed by the control circuit in the first embodiment. [Figure 7] Figure showing the flow of processing executed by the control circuit in the first embodiment. [Figure 8] Figure showing the flow of processing executed by the control circuit in the second embodiment. [Figure 9] Figure showing the configuration of the data storage system in the third embodiment. [Figure 10] Figure showing the functions executed by the control circuit in the third embodiment. [Figure 11] Figure showing the flow of processing executed by the control circuit in the third embodiment. [Figure 12] Figure showing the flow of processing executed by the control circuit in the fourth embodiment.
Embodiments for Carrying Out the Invention
[0011] <First Embodiment> Hereinafter, embodiments will be described based on the drawings. FIG. 1 shows the configuration of the data storage system 10 of the first embodiment. The data storage system 10 includes a raw data management terminal 20 and a blockchain node 30.
[0012] The raw data management terminal 20 is a terminal for managing raw data. Raw data can also be called original data. Raw data is the data that serves as the basis for calculating the hash value. Raw data only needs to be electronic data, and there are no other restrictions. An example of raw data is various data that can be obtained from a vehicle, for example, the driving distance and the remaining battery level of the in-vehicle battery. Another example of raw data is multimedia data including one or both of video data and audio data.
[0013] The original data management terminal 20 includes a communication circuit 21, an original data DB 22, and a control circuit 23. The communication circuit 21 is a circuit for communicating with the blockchain node 30. Communication by the communication circuit 21 is either wired communication, wireless communication, or both. The original data DB 22 is a database for storing original data in the data storage system 10. The original data DB 22 stores original data grouped into arbitrary units, associated with original data IDs that identify that original data. The original data DB 22 is stored in a storage medium 24. The storage medium 24 is a hardware device. The storage medium 24 is, for example, a hard disk.
[0014] As shown in Figure 2, the control circuit 23 comprises a processor 23a, RAM 23b, and storage 23c. The processor 23a is hardware for arithmetic processing and can execute various programs by accessing RAM 23b. The storage 23c stores programs executed by the processor 23a. The programs stored in storage 23c include a tamper detection program for detecting tampering if the original data stored in the original data DB 22 has been altered. When the processor 23a executes this tamper detection program, the original data management terminal 20 operates as a tamper detection device.
[0015] Furthermore, storage 23c may store data processing programs that perform operations such as adding and deleting original data to the original data DB22, and programs for controlling the communication circuit 21.
[0016] Blockchain node 30 holds blockchain 31. Blockchain node 30 also includes blockchain DB 32, control circuit 33, and communication circuit 34. Blockchain 31 contains multiple blocks 40, as shown in Figure 3. In the example in Figure 3, blockchain 31 has five blocks 40.
[0017] Figure 4 shows the data structure of block 40. Block 40 comprises a block header 50 and a block body 60. The block header 50 contains the block number 51, the Merkle root 52, and the previous block hash value 53.
[0018] Block number 51 is assigned to block 40 to distinguish it from other blocks 40. Merkle root 52 is the hash value of block body 60. More specifically, Merkle root 52 is the hash value calculated when transaction 70 is added to block body 60, based on the hash value of the previous block body 60 and the hash value of the newly added transaction 70. Hash values are calculated using various pre-configured hash functions, such as SHA-256. The previous block hash value 53 is the hash value calculated from the entirety of the previous block 40. Note that the first block 40 does not have a previous block 40. Therefore, the previous block hash value 53 included in the first block 40 is an arbitrary hash value, such as the hash value of the block creation date and time, or the hash value of current events news at that time.
[0019] The block body 60 contains one or more transactions 70. Each transaction 70 contains an original data hash value 71 and an original data ID 72. The original data hash value 71 is a hash value calculated from the original data identified by the original data ID 72.
[0020] Let's return to the explanation in Figure 1. Blockchain DB 32 is a database that stores the original data hash value 71 and original data ID 72 recorded in all blocks 40. Blockchain 31 and Blockchain DB 32 are stored in storage medium 35. Storage medium 35 is a hardware device. The storage medium 35 in which Blockchain 31 is stored and the storage medium 35 in which Blockchain DB 32 is stored may be the same or different.
[0021] The hardware configuration of the control circuit 33 is the same as that of the control circuit 23 in the original data management terminal 20. As shown in Figure 2, the control circuit 33 also includes a processor 33a, RAM 33b, and storage 33c. The storage 33c stores programs that the processor 33a executes. By executing the programs stored in storage 33c, the processor 33a performs updates to the blockchain 31 and blockchain DB 32. The communication circuit 34 is a circuit for communicating with the original data management terminal 20 and other blockchain nodes 30B and 30C shown in Figure 5. Communication by the communication circuit 34 is either wired communication or wireless communication, or both.
[0022] As shown in Figure 5, multiple blockchain nodes 30 can communicate with each other via a communication network 80. In Figure 5, blockchain node 30A is the same blockchain node 30 shown in Figure 1. Therefore, blockchain node 30A is an element of the data storage system 10. Figure 5 shows three blockchain nodes 30A, 30B, and 30C. The number of blockchain nodes 30 is not limited to these; there may be two, four or more. Also, blockchain nodes 30 other than blockchain node 30A may be connected to a source data management terminal 20 different from the source data management terminal 20 to which blockchain node 30A is connected.
[0023] The configuration of blockchain nodes 30B and 30C is the same as that of blockchain node 30A. Therefore, blockchain nodes 30B and 30C also hold blockchain 31.
[0024] In the data storage system 10, the original data hash value 71 calculated from the original data stored in the original data DB 22 is recorded in the blockchain 31. The original data hash value 71 is also recorded in the blockchain DB 32. Therefore, if the original data stored in the original data DB 22 is tampered with, it is easier to detect the tampering. This is because, if the original data is tampered with, the original data hash value 71 calculated from the tampered original data will no longer match the original data hash value 71 recorded in the blockchain 31 or the original data hash value 71 stored in the blockchain DB 32.
[0025] However, if the following occurs, even if the original data is tampered with, the original data hash value 71 calculated from the tampered original data will match the original data hash value 71 recorded in blockchain 31 or blockchain DB 32.
[0026] In other words, after tampering with the original data stored in the original data DB22, the original data hash value 71 is calculated from the tampered original data. The calculated original data hash value 71 is used to overwrite the original data hash value 71 recorded in the blockchain 31 and the original data hash value 71 stored in the blockchain DB32. Furthermore, the previous block hash value 53 recorded in each block 40 of the blockchain 31 is also overwritten. That is, all of the previous block hash values 53, which are the connections of the blockchain 31, are overwritten in a way that makes sense. When this is done, the original data hash value 71 calculated from the original data becomes consistent with the original data hash value 71 recorded in the blockchain 31 or the blockchain DB32. Therefore, in this embodiment, the control circuit 23 executes the function shown in Figure 6.
[0027] Figure 6 shows the functions performed by the control circuit 23. When the processor 23a executes the tamper detection program stored in the storage 23c, the control circuit 23 functions as the block consistency determination unit 91, the original data hash value consistency determination unit 92, the original data consistency determination unit 93, the blockchain consistency determination unit 94, and the tamper detection unit 95 shown in Figure 6.
[0028] The block consistency determination unit 91 determines whether the target block and the block 40 immediately following the target block are consistent. The target block is the block 40 that is subject to tampering determination. The block consistency determination unit 91 sequentially designates all blocks 40 contained in the blockchain 31 as target blocks. For example, the block consistency determination unit 91 designates the first block 40 as a target block in order. The original data hash value consistency determination unit 92 and the original data consistency determination unit 93 also sequentially designate all blocks 40 contained in the blockchain 31 as target blocks.
[0029] The method for determining consistency is explained below. The block consistency determination unit 91 calculates a hash value (hereinafter referred to as the block hash value) from the entire data of the target block. This block hash value is the previous block hash value 53 for the block 40 that follows the target block. The block consistency determination unit 91 determines whether the target block and the block 40 that follows the target block are consistent by comparing the block hash value calculated from the target block with the previous block hash value 53 contained in the block 40 that follows the target block. Consistency may be read as matching.
[0030] The original data hash value consistency determination unit 92 determines whether the original data hash value 71 recorded in the target block and the original data hash value 71 stored in the blockchain DB 32 are consistent. In order to distinguish between the two original data hash values 71, the original data hash value 71 recorded in the target block is designated as the block-side original data hash value, and the original data hash value 71 stored in the blockchain DB 32 is designated as the DB-side original data hash value.
[0031] The original data hash value consistency determination unit 92 identifies the DB-side original data hash value from the blockchain DB 32 that corresponds to the block-side original data hash value recorded in the target block. For this identification, the original data ID 72, which is recorded in transaction 70 along with the block-side original data hash value, is used. The blockchain DB 32 also stores the original data ID 72. Therefore, the DB-side original data hash value corresponding to the block-side original data hash value can be identified using the original data ID 72.
[0032] The original data consistency determination unit 93 determines whether the original data stored in the original data DB 22 is consistent with the original data hash value. The original data hash value is recorded in the blockchain DB 32 and the blockchain node 30. In this embodiment, the consistency between the original data hash value recorded in the blockchain DB 32 and the original data is determined.
[0033] The original data consistency determination unit 93 identifies the DB-side original data hash value corresponding to the block-side original data hash value from the blockchain DB 32 in order to make this consistency determination. Both the blockchain DB 32 and the target block have an original data ID assigned to the original data hash value. Based on this original data ID, the DB-side original data hash value to be used for determining the consistency of the original data is identified from the blockchain DB 32.
[0034] Identifying the DB-side source data hash value used for determining the integrity of the source data in this way can be rephrased as follows: By using the DB-side source data hash value as a basis, the source data corresponding to the DB-side source data hash value is identified from the source data DB22 based on the source data ID. Furthermore, the DB-side source data hash value and the block-side source data hash value correspond via the source data ID 72. Therefore, it can also be said that the source data corresponding to the block-side source data hash value is identified from the source data DB22 based on the source data ID.
[0035] The original data consistency determination unit 93 calculates a hash value from the original data to be determined for consistency. It then determines whether the calculated hash value matches the hash value of the original data on the DB side identified from the blockchain DB 32.
[0036] The blockchain consistency determination unit 94 determines whether the blockchain 31 held by its own node is consistent with the blockchain 31 held by other nodes. "Own node" refers to blockchain node 30A. "Own node" can also be described as blockchain node 30, which holds blockchain 31 containing block 40, which the block consistency determination unit 91 has determined to be consistent. "Other nodes" are blockchain nodes 30B and 30C.
[0037] The blockchain consistency determination unit 94 identifies the same block number as the latest block 40 contained in the blockchain 31 held by its own node, from the blockchain 31 held by other nodes. It then calculates the block hash value of block 40 with the identified block number. It determines whether this block hash value matches the block hash value of the latest block 40 of its own node.
[0038] The tampering detection unit 95 determines whether the original data has been tampered with based on the consistency determination results of the block consistency determination unit 91, the original data hash value consistency determination unit 92, the original data consistency determination unit 93, and the blockchain consistency determination unit 94. Specifically, if the consistency determination result of any of the block consistency determination unit 91, the original data hash value consistency determination unit 92, the original data consistency determination unit 93, or the blockchain consistency determination unit 94 is found to be inconsistent, the tampering detection unit 95 determines that the original data may have been tampered with. On the other hand, if the consistency determination results of all four units—block consistency determination unit 91, original data hash value consistency determination unit 92, original data consistency determination unit 93, and blockchain consistency determination unit 94—are found to be consistent, the tampering detection unit 95 determines that the original data has not been tampered with. Note that, to avoid complicating the diagram, the lines showing the data flow between the tampering detection unit 95 and other elements have been omitted in Figure 6.
[0039] Figure 7 shows the process that the control circuit 23 executes when the processor 23a executes the tamper detection program. The process shown in Figure 7 is executed, for example, at regular intervals.
[0040] S1 is executed by the block consistency determination unit 91. In S1, it is determined whether the connections between the blocks 40 that make up the blockchain 31 are consistent. As explained using Figure 6, a block hash value is calculated from the entire data of the target block, and it is determined whether that block hash value is consistent with the previous block hash value 53 contained in the block 40 immediately following the target block.
[0041] In S1, consistency checks are performed on all blocks 40 that can be checked for consistency. All blocks 40 that can be checked for consistency mean all blocks 40 except the most recent block 40. This is because the most recent block 40 does not have a successor block 40.
[0042] If the block hash value and the previous block hash value do not match for even one target block, the result of S1 will be NO. If the result of S1 is NO, proceed to S5; if the result of S1 is YES, proceed to S2.
[0043] S2 is executed by the original data hash value consistency determination unit 92. S2 determines whether the block-side original data hash value and the DB-side original data hash value are consistent. S2 performs consistency determination on all blocks 40 included in blockchain 31 as target blocks. If even one target block's original data hash value 71 is inconsistent, the result of S2 is NO. If the result of S2 is NO, the process proceeds to S5; if the result of S2 is YES, the process proceeds to S3.
[0044] S3 is executed by the original data consistency determination unit 93. S3 determines whether the original data stored in the original data DB22 is consistent with the DB-side original data hash value. As mentioned above, for this determination, the original data hash value 71 is calculated from the original data stored in the original data DB22. S3 determines whether the DB-side original data hash value corresponding to the block-side original data hash value recorded in all target blocks is consistent with the original data. If even one piece of original data is not consistent with the DB-side original data hash value, the result of S3 is NO. If the result of S3 is NO, proceed to S5; if the result of S3 is YES, proceed to S4.
[0045] S4 is executed by the blockchain consistency determination unit 94. In S4, it is determined whether the latest block 40 of blockchain 31 held by the local node (hereinafter referred to as the local node's latest block) is consistent with the block 40 with the same number as the local node's latest block in blockchain 31 held by other nodes. If the result of S4 is NO, the process proceeds to S5; if the result of S4 is YES, the process proceeds to S6.
[0046] S5 and S6 are executed by the tampering detection unit 95. If the process proceeds to S5, it is determined that the original data may have been tampered with. If it is determined that the data may have been tampered with, this may be indicated on the display unit of the original data management terminal 20. On the other hand, if the process proceeds to S6, it is determined that the original data has not been tampered with.
[0047] In the first embodiment described above, the block consistency determination unit 91 determines the consistency between the blocks 40. If the hash value 53 of the block immediately following the target block has not been tampered with, the block consistency determination unit 91 can determine that the target block has not been tampered with.
[0048] The original data hash value consistency determination unit 92 then determines whether the block-side original data hash value and the DB-side original data hash value are consistent. Assuming that the target block has not been tampered with, the original data hash value consistency determination unit 92 can determine that the blockchain DB 32 has not been tampered with.
[0049] Furthermore, the original data consistency determination unit 93 determines whether the original data stored in the original data DB 22 is consistent with the DB-side original data hash value. Assuming that the blockchain DB 32 has not been tampered with, the original data consistency determination unit 93 can determine that the original data has not been tampered with. Then, the blockchain consistency determination unit 94 determines whether the latest block of the local node is consistent with block 40, which has the same number as the latest block of the local node, in the blockchain 31 held by other nodes. If it is determined that the latest block of the local node has not been tampered with, it can also be determined that the hash value 53 of the block immediately following the target block has not been tampered with.
[0050] Based on the above, the tampering detection unit 95 can accurately determine if the original data has been tampered with, based on the results of the consistency determinations made by the block consistency determination unit 91, the original data hash value consistency determination unit 92, the original data consistency determination unit 93, and the blockchain consistency determination unit 94. Therefore, the original data management terminal 20 can accurately detect tampering with the original data.
[0051] <Second Embodiment> Next, a second embodiment will be described. In this second embodiment and subsequent descriptions, elements having the same reference numerals as those used up to that point are identical to the elements with the same reference numerals in the previous embodiments, unless otherwise specified. Also, when only a part of the configuration is described, the previously described embodiments can be applied to the other parts of the configuration.
[0052] In the second embodiment, the control circuit 23 executes the process shown in Figure 8 instead of the process shown in Figure 7. As shown in Figure 8, the processes from S11 to S14 start from block No. 1 and are executed up to the latest block.
[0053] In S11, it is determined whether or not it is the latest block. If the result of the determination in S11 is YES, S12 is not executed and the process proceeds to S13. If the result of the determination in S11 is NO, the process proceeds to S12. S12 is executed by the block consistency determination unit 91. In S12, it is determined whether the connection between the target block and the next block 40 is consistent. To make this determination, the data of the target block is acquired and a block hash value is calculated from the acquired data. Then, it is determined whether the calculated block hash value matches the previous block hash value 53 recorded in the next block 40. If the result of the determination in S12 is NO, the process proceeds to S15, and if the result of the determination in S12 is YES, the process proceeds to S13.
[0054] S13 is executed by the original data hash value consistency determination unit 92. In S13, the unit retrieves the original data hash value 71 stored in the blockchain DB 32, which is associated with the same original data ID as the original data hash value 71 contained in the transaction 70 of the target block. It then determines whether the original data hash value 71 obtained from the blockchain DB 32 matches the original data hash value 71 contained in the transaction 70 of the target block. In this determination, the original data hash value 71 contained in the transaction 70 of the target block is the value obtained for the determination in S12.
[0055] S14 is executed by the original data consistency determination unit 93. In S14, the unit retrieves original data from the original data DB 22 that has the same original data ID as the original data hash value 71 obtained from the blockchain DB 32 for the determination in S13. It then calculates a hash value from the retrieved original data and determines whether it matches the original data hash value 71 obtained for the determination in S13. If the result of the determination in S14 is NO, the unit proceeds to S15. If the result of the determination in S14 is YES and S14 has been executed up to the latest block, the unit proceeds to S16. If the result of the determination in S14 is YES and S14 has not been executed up to the latest block, the unit executes S11 for the next block 40.
[0056] S16 is the same as S4 in Figure 7. In S16, the blockchain consistency determination unit 94 determines whether the latest block of the local node is consistent with block 40, which has the same number as the latest block of the local node, in the blockchain 31 held by other nodes. If the result of the determination in S16 is NO, proceed to S15; if the result of the determination in S16 is YES, proceed to S17.
[0057] In the second embodiment described above, for each target block, the following are performed: a determination of whether block 40 is consistent (S12), a determination of whether the original data hash values 71 of both the target block and the blockchain DB 32 match (S13), and a determination of whether the original data hash value 71 of the blockchain DB 32 is consistent with the original data (S14). This allows the original data hash value 71 recorded in the target block, which was obtained for the determination in S12, to be used in the determination in S13. Also, the original data hash value 71 obtained from the blockchain DB 32 for the determination in S13 can be used in the determination in S14. Thus, data acquisition for tamper detection can be performed efficiently.
[0058] <Third Embodiment> Figure 9 shows the configuration of the data storage system 310 of the third embodiment. The data storage system 310 differs from the data storage system 10 in that the blockchain node 30 does not have a blockchain DB 32. In addition, some of the functions performed by the control circuit 23 differ from those of the first and second embodiments.
[0059] Figure 10 shows the process executed by the control circuit 23 when the processor 23a executes a tamper detection program in the third embodiment. In the third embodiment, the control circuit 23 also functions as a block consistency determination unit 91 and a blockchain consistency determination unit 94. In addition, in the third embodiment, the control circuit 23 also functions as an original data consistency determination unit 393 and a tamper detection unit 395.
[0060] In the third embodiment, since there is no blockchain DB 32, the original data consistency determination unit 393 uses the original data hash value 71 recorded in the blockchain 31 to determine the consistency of the original data.
[0061] The original data consistency determination unit 393 determines whether the original data stored in the original data DB 22 is consistent with the original data hash value 71 recorded in the blockchain 31. To make this determination, the original data consistency determination unit 393 identifies the original data from the original data DB 22 that corresponds to the original data hash value 71 recorded in the target block. The original data ID is used for this identification. Then, it calculates a hash value from the identified original data. It determines whether this calculated hash value matches the original data hash value 71 identified by the original data ID in the blockchain 31.
[0062] The tampering detection unit 395 determines whether the original data has been tampered with based on the consistency determination results of the block consistency determination unit 91, the original data consistency determination unit 393, and the blockchain consistency determination unit 94. Specifically, if the consistency determination result of any of the block consistency determination unit 91, the original data consistency determination unit 393, or the blockchain consistency determination unit 94 is determined to be inconsistent, the tampering detection unit 395 determines that the original data may have been tampered with. On the other hand, if the consistency determination results of the block consistency determination unit 91, the original data consistency determination unit 393, and the blockchain consistency determination unit 94 are all determined to be consistent, the tampering detection unit 395 determines that the original data has not been tampered with. Note that in Figure 10, the lines showing the data flow between the tampering detection unit 395 and other elements have been omitted.
[0063] Figure 11 shows the process that the control circuit 23 executes in place of Figure 7 in the third embodiment. The control circuit 23 executes the same S1 as in Figure 7. If the result of the judgment in S1 is YES, the process proceeds to S3-1.
[0064] S3-1 is executed by the original data consistency determination unit 393. S3-1 is similar to S3 in Figure 7. S3 determines whether the original data and the original data hash value 71 stored in the blockchain DB 32 are consistent. In S3-1, the original data hash value 71 recorded in block 40 is used as the original data hash value 71 for determining consistency with the original data. Everything else is the same as S3.
[0065] In S3-1, all blocks 40 are selected as target blocks, and it is determined whether the original data hash value 71 recorded in the target blocks matches the hash value calculated from the original data. To make this determination, the original data hash values 71 recorded in all blocks 40 of blockchain 31 are associated with the original data stored in the original data DB 22 based on the original data ID. Then, it is determined whether the hash value calculated from the original data matches the original data hash value 71 associated with that original data. If they match, it is determined that block 40 and the original data are consistent. If the result of the determination in S3-1 is YES, the process proceeds to S4; if the result of the determination in S3-1 is NO, the process proceeds to S5.
[0066] In Figure 11, steps S5 and S6 are executed by the tampering detection unit 395. If the result of any of the decisions in S1, S3-1, or S4 is NO, the process proceeds to S5, and it is determined that the original data may have been tampered with. If the results of all decisions in S1, S3-1, and S4 are YES, the process proceeds to S6, and it is determined that the original data has not been tampered with.
[0067] According to this third embodiment, the original data consistency determination unit 393 determines whether the original data stored in the original data DB 22 is consistent with the original data hash value 71 recorded in block 40. Assuming that block 40 has not been tampered with, the original data consistency determination unit 393 can determine that the original data has not been tampered with.
[0068] If the block consistency determination unit 91 determines that the target block has not been tampered with, and the blockchain consistency determination unit 94 determines that the latest block on the local node has not been tampered with, then the tampering determination unit 395 can determine that the original data has not been tampered with.
[0069] <Fourth Embodiment> In the fourth embodiment, the control circuit 23 executes the process shown in Figure 12 instead of the process shown in Figure 8. The process shown in Figure 12 differs from that in Figure 8 in that it does not include S13 and executes S14-1 instead of S14.
[0070] S14-1 is executed by the original data consistency determination unit 393. In S14-1, the unit retrieves original data from the original data DB 22 that has the same original data ID as the original data hash value 71 contained in the data of the target block obtained for the determination in S12. Then, it calculates a hash value from the retrieved original data and determines whether it matches the original data hash value 71 obtained for the determination in S12. If the result of the determination in S14-1 is NO, the unit proceeds to S15. If the result of the determination in S14-1 is YES and S14-1 has been executed up to the latest block, the unit proceeds to S16. If the result of the determination in S14-1 is YES and S14-1 has not been executed up to the latest block, the unit executes S11 for the next block 40.
[0071] In the fourth embodiment described above, for each target block, a determination is made as to whether block 40 is consistent (S12) and whether the original data hash value 71 recorded in block 40 is consistent with the original data (S14-1). As a result, in the determination in S14-1, the original data hash value 71 recorded in the target block, which was obtained for the determination in S12, can be used. Therefore, data acquisition for tampering detection can be performed efficiently.
[0072] Although embodiments have been described above, the disclosed technology is not limited to the embodiments described above. The following modifications are also included within the scope of disclosure, and further modifications can be made in various ways without departing from the gist of the invention.
[0073] <Example 1> Data storage systems 10 and 310 were equipped with a source data management terminal 20, but data storage systems may also be provided without a source data management terminal 20. In this case, the blockchain node 30 is equipped with the source data DB 22. Furthermore, the functions of the control circuit 23 are performed by the control circuit 33 provided by the blockchain node 30.
[0074] <Modification 2> The order of S1, S2, S3, and S4 shown in Figure 7 may be changed. The process does not proceed to S6 unless all of S1, S2, S3, and S4 result in a positive judgment. Also, S2, S3, and S4 do not require the results of the previous processes. Therefore, S1, S2, S3, and S4 do not need to be in the order shown in Figure 7. Similarly, in Figure 11, the order of S1, S3-1, and S4 may be changed.
[0075] <Variation 3> In the process shown in Figure 8, the processes from S11 onwards were executed starting from block No. 1. However, as long as the processes from S11 onwards are ultimately executed for all blocks 40, it is also acceptable to start with block 40 other than block No. 1 and execute S11 onwards from block 40 other than block No. 1. Even if the processes from S11 onwards are executed starting from block 40 other than block No. 1, the data acquired for the decision in S12 can be used in the decision in S13, and the data acquired for the decision in S13 can be used in the decision in S14. Similarly, in the process shown in Figure 12, S11 may be executed starting from block 40 other than block No. 1. [Explanation of Symbols]
[0076] 10...Data storage system, 22...Original data DB, 30...Blockchain node, 30A...Own node, 30B...Other node, 30C...Other node, 31...Blockchain, 32...Blockchain DB, 40...Block, 53...Previous block hash value, 71...Original data hash value, 91...Block consistency determination unit, 92...Original data hash value consistency determination unit, 93...Original data consistency determination unit, 94...Blockchain consistency determination unit, 95...Tampering determination unit, 310...Data storage system, 393...Original data consistency determination unit, 395...Tampering determination unit
Claims
1. A tampering detection device that detects tampering when the original data stored in the data storage system (10, 310) has been altered, The aforementioned data storage system is The original data DB (22) is a database that stores the aforementioned original data, The system includes a blockchain node (30) that holds a blockchain (31) which contains multiple blocks (40) in which the original data hash value (71), which is a hash value calculated from the original data, is recorded, The second and subsequent blocks of the aforementioned blockchain record the previous block hash value (53), which is the hash value of the previous block. The aforementioned tampering detection device is A block consistency determination unit (91) calculates a block hash value from the target block which is the block subject to the tampering determination, and compares the calculated block hash value with the previous block hash value recorded in the block immediately following the target block to determine whether the target block and the block immediately following the target block are consistent. A data consistency determination unit (93, 393) identifies the original data from the original data DB that corresponds to the original data hash value recorded in the target block, and determines whether the hash value calculated from the identified original data matches the original data hash value. The blockchain consistency determination unit (94) is defined as the local node (30A), and identifies a block with the same block number as the latest block held by the local node from other nodes (30B, 30C) that are different from the local node and hold the blockchain, calculates the block hash value from the identified block, and determines whether the calculated block hash value is consistent with the block hash value calculated from the latest block of the local node. Based on the results of the consistency determinations made by the block consistency determination unit, the original data consistency determination unit, and the blockchain consistency determination unit, a tampering determination unit (95, 395) determines whether or not the original data has been tampered with, A tampering detection device that includes [a specific feature / function].
2. The aforementioned data storage system is The system includes a blockchain DB (32) which is a database in which the aforementioned original data hash values are stored. The aforementioned tampering detection device is The system includes a data hash value consistency determination unit (92) that determines whether the block-side data hash value, which is the original data hash value recorded in the target block, and the DB-side data hash value, which is the original data hash value stored in the blockchain DB and corresponds to the block-side data hash value, are consistent. The original data consistency determination unit identifies the original data from the original data DB using the DB-side original data hash value corresponding to the block-side original data hash value. The tampering determination unit determines whether or not the original data has been tampered with based on the results of the consistency determinations made by the block consistency determination unit, the original data hash value consistency determination unit, the original data consistency determination unit, and the blockchain consistency determination unit. The tampering detection device according to claim 1.
3. The block consistency determination unit acquires the target block for each target block and calculates the block hash value. The original data hash value consistency determination unit, after the block consistency determination unit has determined consistency for one of the target blocks, obtains the block-side original data hash value from the target block obtained by the block consistency determination unit, and obtains the DB-side original data hash value from the blockchain DB, and determines whether the obtained block-side original data hash value and the DB-side original data hash value are consistent. The original data consistency determination unit determines whether the hash value calculated from the original data is consistent with the DB-side original data hash value obtained by the original data hash value consistency determination unit. The tampering detection device according to claim 2.
4. After the block alignment determination unit performs alignment determination on all blocks for which alignment determination is possible, as the target blocks, The original data hash value consistency determination unit determines, for all of the target blocks, whether the block-side original data hash value and the DB-side original data hash value are consistent, and then, The original data consistency determination unit determines whether the DB-side original data hash values corresponding to all of the target blocks are consistent with the hash values calculated from the original data. The tampering detection device according to claim 2.
5. The block consistency determination unit acquires the target block for each target block and calculates the block hash value. The original data consistency determination unit determines whether the hash value calculated from the original data is consistent with the original data hash value recorded in the target block obtained by the block consistency determination unit. The tampering detection device according to claim 1.
6. After the block alignment determination unit performs alignment determination on all blocks for which alignment determination is possible, as the target blocks, The original data consistency determination unit determines whether the hash values of the original data recorded in all of the target blocks are consistent with the hash values calculated from the original data. The tampering detection device according to claim 1.
7. A data storage system (10, 310) comprising a data storage system (10, 310) which includes The aforementioned processor, A block consistency determination unit (91) calculates a block hash value from the target block which is the block subject to the tampering determination, and compares the calculated block hash value with the previous block hash value recorded in the block immediately following the target block to determine whether the target block and the block immediately following the target block are consistent. A data consistency determination unit (93, 393) identifies the original data from the original data DB that corresponds to the original data hash value recorded in the target block, and determines whether the hash value calculated from the identified original data matches the original data hash value. The blockchain node is designated as the local node (30A), and the blockchain consistency determination unit (94) identifies the block with the same block number as the latest block held by the local node from other nodes (30B, 30C) that are different from the local node and record the blockchain, calculates a hash value from the identified block, and determines whether the calculated hash value is consistent with the hash value calculated from the latest block of the local node. Based on the results of the block consistency determination unit, the original data consistency determination unit, and the blockchain consistency determination unit, a tampering determination unit (95, 395) determines whether or not the original data has been tampered with. A tampering detection program designed to function as such.