Digital Asset Guard Service Provisioning System

The digital asset guard service provision system uses a distributed ledger and consortium blockchain to protect and restore sensitive information from quantum computer and EMP attacks, addressing inefficiencies in existing systems.

JP2026091191APending Publication Date: 2026-06-03西本 一也 +2

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
西本 一也
Filing Date
2024-11-22
Publication Date
2026-06-03

AI Technical Summary

Technical Problem

Current systems fail to effectively guard digital assets against high-level cyberattacks, such as those using quantum computers and EMP attacks, and do not efficiently manage and restore sensitive information like confidential and personal data in the face of such threats.

Method used

A digital asset guard service provision system utilizing a distributed ledger in blockchain technology, smart contracts, and a consortium-type blockchain with nodes worldwide, performs encryption, distribution, and management of data to protect and restore digital assets efficiently, even in the face of cyberattacks.

Benefits of technology

The system provides robust protection and efficient restoration of confidential and personal information from high-level cyberattacks and physical destruction, ensuring data integrity and usability even if backup information is destroyed or compromised.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026091191000001_ABST
    Figure 2026091191000001_ABST
Patent Text Reader

Abstract

To provide a system that powerfully and efficiently protects sensitive information such as confidential and personal data from high-level cyberattacks and physical destruction, and that can quickly detect and restore backup information used to preserve sensitive information even if it is destroyed. [Solution] The system includes a data portion discrepancy check means 20 that periodically checks for discrepancies in data portions with identical date and time information by comparing the maintenance data with date and time information created by the maintenance data creation means 11, which is used as a comparison standard, with the data portion with identical date and time information stored by the comparison standard maintenance data storage means 12, via the control of the maintenance data creation control means 19. If a discrepancy is found, the system includes a maintenance data extraction function contamination notification means 21 that notifies the user and the consortium that the data extraction function for information to be preserved is contaminated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a digital asset guard service providing system that guards digital assets (primarily aiming to protect from destruction) against risks such as high-level cyberattacks beyond normal levels, intense natural disasters, or physical attacks that are expected in the future. In addition, the "system" in the specification of this application means a computer system that specifically realizes software-based information processing using hardware resources, which is composed of elements such as computers, other electronic devices, software, communication networks, and data.

Background Art

[0002] Conventionally, as a protection measure for data against general cyberattacks, encryption technologies such as blockchain have been used. However, in the future, high-level cyberattacks beyond normal levels such as cryptographic analysis by quantum computers and EMP attacks, etc. are expected. These high-level cyberattacks aim at leakage, alteration, deletion, and destruction of digital assets (confidential information such as personal information and security-related information, control modules for important functions, currencies such as stablecoins, rights such as contracts). Therefore, it has become important to guard digital assets from high-level cyberattacks.

[0003] Digital assets that are targets of high-level cyberattacks Digital assets targeted by high-level cyberattacks are considered to cover a wide range, including personal information (account information) and personal asset information held by financial institutions, confidential information such as personal information and security-related information held by large enterprises and government agencies, important contracts, designs, control modules and data, and those related to lifelines. Conventionally, no service has been provided to guard high-level cyberattacks with a high degree of accuracy (especially for civilian use).

[0004] High-level cyberattack High-level cyberattacks primarily include cryptographic analysis using quantum computers (often referred to as Y2Q (Years To Quantum)) and EMP attacks.

[0005] Cryptography using quantum computers Quantum computer-based cryptography is a cyberattack that uses public keys from SSL (Secure Sockets Layer) and blockchains to decrypt private keys, thereby bypassing cryptographic guards, stealing important information, and destroying systems. If quantum computers are misused, even if digital assets are protected by storing private keys in cold wallets isolated from the system, there is a high risk that cryptographic analysis will be performed using public keys to decrypt private keys. Cryptographic analysis using quantum computers is a cyberattack that bypasses current basic security measures known as cryptography. Furthermore, it is expected that when combined with various other attacks, it could develop into unforeseen attacks with far-reaching implications.

[0006] EMP attack An EMP attack is a cyberattack that uses strong electromagnetic waves generated by a nuclear explosion at high altitude (stratosphere) to destroy electronic devices, systems, and magnetically recorded digital assets. An EMP attack could potentially destroy evacuated digital assets or modules in the system used to evacuate those digital assets. Additionally, although not an EMP attack, large-scale solar flares occur periodically. The strong magnetic field generated by solar flares can cause physical destruction equivalent to or greater than that of an EMP attack.

[0007] Current measures being considered against high-level cyberattacks Quantum cryptography and other related technologies are being researched as countermeasures against cryptographic analysis using quantum computers. However, considering the timeframe for general implementation and the costs involved, quantum cryptography has not yet reached a practical level. Furthermore, as a countermeasure against EMP attacks, data centers (including cloud facilities) that meet U.S. EMP resistance standards have implemented measures such as the installation of magnetic shielding mesh. However, magnetic shielding mesh is only installed in a portion of data centers in Japan as a whole, or the countermeasures do not meet sufficient standards.

[0008] Another possible strategy is to use the cloud to back up data to overseas regions (independent areas where data centers are located). However, cloud computing carries risks, such as insufficient user management, and financial institutions (especially large ones) are refraining from using it. More specifically, most domestic cloud services are currently operated by overseas service providers, and there is a risk that they could easily withdraw if any problems arise in Japan. In addition, incorrect cloud configuration can create security vulnerabilities, potentially leading to system destruction through even simple attacks. Furthermore, even with domestic cloud services, backing up digital assets using only one provider's cloud service carries risks, such as the inability to access backed-up data in the event of a cloud system failure. Even backing up digital assets using two different cloud providers requires the creation of separate management functions for each provider, which generally increases the complexity and makes it less user-friendly.

[0009] In particular, countermeasures for cyberattacks that simultaneously employ cryptographic analysis using quantum computers and EMP attacks are currently complex and costly, and have not yet reached a level where they can be generally put into practical use.

[0010] Other grades Furthermore, the system's ability to back up digital assets, including personal information and confidential corporate information, is subject to extremely strict limitations. For example, if someone other than the individual manages their digital assets, the consent of the individual who wishes for data management is required. However, obtaining consent for all digital assets that could potentially be managed is difficult. This complicates the management of digital assets. Furthermore, when using decentralized technology to back up digital assets, blockchains such as public chains cannot break the chain connecting the blocks. Therefore, even if it becomes necessary to delete data that is unnecessary for management or to erase digital data at the customer's request, the digital data cannot be deleted. Also, because the block size is relatively small, it is not possible to record an amount of digital data exceeding the block size. Furthermore, even if it were possible to create a function similar to the safekeeping of digital assets using distributed technology by combining public blockchains and freeware, the responsibility for public blockchains and freeware is not clearly defined. In a digital asset safekeeping service that is not guaranteed in principle, it is undesirable to handle important information or personal information due to its reliability and other factors.

[0011] However, the inventors of this case have developed a digital asset guard service provision system that can strongly and efficiently protect important information such as confidential information and personal information from high-level cyberattacks and physical destruction, and can restore important information without it being stolen by a third party even if it is subjected to cryptographic analysis by a quantum computer or an EMP attack (Patent Document 1).

[0012] The digital asset guard service provision system described in Patent Document 1 is configured such that the user's system performs encryption and partitioning to render the data to be protected meaningless, the consortium's system performs further transformation processing, and the data is managed in a distributed manner worldwide. The user's system and the consortium's system are independent, and both manage the data by encrypting it, so neither can interfere with the area in which the other manages the data. Furthermore, decrypting and restoring the data distributed and managed by the consortium requires bidirectional agreement between the user and the consortium. [Prior art documents] [Patent Documents]

[0013] [Patent Document 1] Patent No. 7503778 [Overview of the project] [Problems that the invention aims to solve]

[0014] Upon further consideration and examination of the derived digital asset guarding service provision system, the inventors of this case found that the following challenges remain regarding defense against cyberattacks. Recent cyberattacks not only access and destroy backup information, but also hijack the backup creation process itself, destroying and invalidating all backup information without the user's knowledge. When faced with such cyberattacks, the backup information created becomes meaningless, and even with a digital asset guarding service system, there is a risk that sensitive information such as confidential and personal information cannot be protected.

[0015] Furthermore, the current digital asset guard service provision system manages in a distributed manner the information that has been rendered meaningless by cryptographic distribution on the user's system (meaningless protected data and index information of protected data), which has been further transformed on the consortium's system. This makes it impossible for the user's system to grasp the relationship between the index information of the information rendered meaningless by cryptographic distribution and the index information managed in a distributed manner on the consortium's system. This makes it difficult for a malicious third party to recover the user's original information even if they steal the consortium's information. However, it has been found that if the index information on the user's system is destroyed, the user will not be able to identify the protected data that could be recovered, and will not be able to select and recover only the desired protected data from the list of protected data recorded in the index information on the user's system. Instead, all protected data must be recovered, which is inconvenient.

[0016] The present invention has been made in view of the above problems, and strongly and efficiently protects important information such as confidential information and personal information from high-level cyberattacks and physical destruction. In addition to restoring important information without being stolen by a third party even when subjected to cryptographic analysis by a quantum computer or an EMP attack, it promptly detects and recovers in case the backup information for preserving important information such as confidential information and personal information is destroyed. Furthermore, even if the index information of the preservation target information managed by the user side is destroyed, it is an object to provide a digital asset guard service providing system capable of efficiently restoring the desired preservation target information.

Means for Solving the Problems

[0017] To achieve the above objective, the digital asset guard service provision system according to the present invention is a digital asset guard service provision system for guarding digital assets from high-level cyberattacks, constructed with a distributed ledger in blockchain or other distributed ledger technology, and a smart contract or server application for performing predetermined processing using data managed in the distributed ledger, and has a consortium-type blockchain constructed with multiple planets that form one unit constituting the blockchain, each consisting of a group of nodes combining nodes in multiple locations in different regions around the world, and has a means for creating protected target data that extracts information to be protected from original information with date and time information recorded in a relational database managed by the user and creates protected target data with date and time information, a means for receiving instructions to back up protected target data from a user who wishes to back up protected target data, and based on the protected target data back-up instructions from the user using the primary key or other primary conversion information received by the protected target data back-up instruction receiving means A user-side backup system having: a means for demeaning preserved data by performing a predetermined encryption process on preserved data with date and time information created by the preserved data creation means to convert it into demeaning preserved data; a means for storing the demeaning preserved data converted by the preserved data demeaning means in a predetermined memory; a means for uploading the demeaning preserved data stored in the predetermined memory by the demeaning preserved data memory storage means to a first provisional storage area; a distributed file management group distribution means for distributing the demeaning preserved data uploaded to the first provisional storage area by the demeaning preserved data upload means to multiple distributed file management groups constructed by the nodes of each base that constitute the planet set up by the consortium and recording devices of multiple bases that are network-connected to the nodes of said bases, using the secondary key of the consortium and other secondary conversion information; and a means for modifying the data distributed by the distributed file management group distribution means.The consortium-side backup system includes: a modification and distributed recording means that distributes and records data not exceeding the block size to multiple nodes of a distributed file group established on the blockchain, and data exceeding the block size to multiple nodes of a distributed file management group separate from the blockchain; a distributed recording data index information creation, encryption, and recording means that creates and encrypts index information of the data distributed and recorded by the modification and distributed recording means and records it on a specific node of the blockchain in a black box environment; and an upload meaningless preservation target data erasure means that erases the meaningless preservation target data uploaded to a first provisional storage area after the index information of the data distributed and recorded by the modification and distributed recording means has been recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption, and recording means. The user-side backup system further includes: A comparison reference data creation means that decodes the meaningless data to be preserved stored in a predetermined memory by the meaningless data to be preserved memory storage means to create preserved data with date and time information to serve as a comparison reference; a comparison reference data storage means that stores the preserved data with date and time information to serve as a comparison reference created by the comparison reference data creation means; a memory-stored meaningless data erasure means that erases the meaningless data to be preserved stored in a predetermined memory by the meaningless data to be preserved memory storage means after the preserved data with date and time information to serve as a comparison reference has been stored by the comparison reference data storage means; a check-type preserved data creation control means that periodically instructs the preserved data creation means to extract information to be preserved from original information with date and time information recorded in a relational database managed by a user and create check-type preserved data with date and time information; and, through the control of the check-type preserved data creation control means, compares the check-type preserved data with date and time information created by the preserved data creation means with the data portion with the same date and time information in the preserved data with date and time information to serve as a comparison reference stored by the comparison reference data storage means.Check for the presence or absence of a deviation in the data portion with the same date and time information between the preservation target data with the date and time information for checking and the preservation target data with the date and time information serving as the comparison criterion, i.e., the preservation target data same date and time information attached data portion deviation presence / absence check means, and as a result of the check by the preservation target data same date and time information attached data portion deviation presence / absence check means, when it is recognized that there is a deviation in the data portion with the same date and time information between the preservation target data with the date and time information for checking and the preservation target data with the date and time information serving as the comparison criterion, determine that the extraction function of the information to be preserved in the preservation target data creation means is contaminated, and notify the user and the consortium that the extraction function of the information to be preserved in the preservation target data creation means is contaminated, i.e., the preservation target data extraction function contamination notification means, characterized by having these.

[0018] Also, in the digital asset guard service providing system of the present invention, the preservation target data same date and time information attached data portion deviation presence / absence check means preferably calculates the hash values of the data portions with the same date and time information in the preservation target data with the date and time information for checking and the preservation target data with the date and time information serving as the comparison criterion, respectively, and compares the calculated hash values with each other to check for the presence or absence of a deviation in the data portion with the same date and time information between the preservation target data with the date and time information for checking and the preservation target data with the date and time information serving as the comparison criterion.

[0019] Furthermore, the digital asset guard service provision system of the present invention further comprises: a first hash value calculation means for calculating the hash value of the data portion other than the date and time information in the reference data to be protected with date and time information that serves as the comparison standard, which is stored in the reference data to be protected data storage means, as a first hash value; a first hash value storage means for storing the first hash value calculated by the first hash value calculation means; and a second hash value calculation means for calculating the hash value of the data portion of the data to be protected with date and time information for checking that has the same date and time information as the reference data to be protected with date and time information that serves as the comparison standard, as a second hash value. The data portion discrepancy check means for data to be protected with the same date and time information preferably checks for discrepancies in the data portion of data to be protected with the same date and time information between the data to be protected with the reference data to be protected with date and time information for checking and the data to be protected with date and time information that serves as the comparison standard, by comparing the second hash value calculated by the second hash value calculation means with the first hash value stored in the first hash value storage means.

[0020] Furthermore, in the digital asset guard service provision system of the present invention, the means for rendering the protected data meaningless is configured to perform a predetermined encryption process and primary decomposition process on the protected data with date and time information created by the protected data creation means, based on a backup instruction for the protected data from a user using a primary key or other primary conversion information received by the protected data backup instruction receiving means, thereby converting it into a plurality of meaningless protected data; the means for storing the meaningless protected data meaningless converted by the means for rendering the protected data meaningless is configured to store each of the meaningless protected data meaningless converted by the means for rendering the protected data meaningless in a predetermined memory; the means for uploading the meaningless protected data meaningless converted into a predetermined memory is configured to upload each of the meaningless protected data meaningless converted into a predetermined memory by the means for storing the meaningless protected data meaningless in a predetermined memory to a first provisional storage area; and the means for distributing the distributed file management group uploads the meaningless protected data meaningless converted into a first provisional storage area by the means for distributing the meaningless protected data meaningless converted into a first provisional storage area. Preferably, the data to be rendered meaningless and preserved is decomposed secondarily using the consortium's secondary key and other secondary transformation information, and distributed to multiple distributed file management groups constructed by the nodes of each location that constitute the planet set up by the consortium and recording devices of multiple locations that are network-connected to the nodes of said locations; the means for erasing uploaded meaningless and preserved data is configured to erase the data to be rendered meaningless and preserved that has been uploaded to the first provisional storage area after the index information of the data distributed and recorded by the modification and distributed recording means has been recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption and recording means; and the means for creating comparison standard preserved data is preferably configured to decode and combine the data to be rendered meaningless and preserved that has been stored in a predetermined memory by the meaningless and preserved data memory storage means to create preserved data with date and time information that serves as a comparison standard.

[0021] Furthermore, in the digital asset guard service provision system of the present invention, the system includes: a means for receiving instructions to restore protected data from users who wish to restore protected data; an encrypted index information extraction means that extracts encrypted index information recorded in a black box environment on a group of nodes at a specific location on the blockchain by the distributed record data index information creation, encryption, and recording means, based on the primary key and other primary transformation information from the user associated with the protected data with date and time information to be restored, and the secondary key and other secondary transformation information of the consortium; an index information decryption means that decrypts the encrypted index information extracted by the encrypted index information extraction means; and, using the index information decrypted by the index information decryption means, the distributed file management group distribution means distributes the data to each of the distributed file management groups, and the respective nodes at each location belonging to each of the distributed file management groups are recorded by the respective modification and distributed recording means. A user-side recovery system comprising: data extraction means for extracting data distributed and recorded in multiple recording devices at multiple locations connected to a node from either the node of each location belonging to the respective distributed file management group or from the multiple recording devices at multiple locations connected to the node of that location; download means for downloading the data extracted by the data extraction means to a second provisional storage area; data recovery means for restoring the data extracted by the data extraction means and downloaded to the second provisional storage area by the download means to data to be preserved with date and time information before backup; and download data erasure means for erasing the data downloaded to the second provisional storage area after it has been restored to data to be preserved with date and time information before backup by the data recovery means; and further comprising: data recovery instruction receiving means, download means, data recovery means, and download data erasure means; and encryption index information extraction means, index information decryption means, and data extraction means.It is preferable to have a consortium-side restoration system that has the following:

[0022] Furthermore, in the digital asset guard service provision system of the present invention, a means for receiving instructions to delete protected data from users who wish to delete protected data, a means for extracting encrypted index information at the time of deletion based on a primary key and other primary transformation information from the user associated with the protected data to be deleted, which has date and time information to be deleted, and a secondary key and other secondary transformation information from the consortium, the distributed record data index information creation, encryption, and recording means for extracting encrypted index information recorded in a group of nodes at a specific location on the blockchain in a black box environment, the deleted record data index information creation, encryption, and recording means for decrypting the encrypted index information extracted by the deleted record data index information extraction means, and the distributed file management group distribution means for distributing the decrypted index information to each of the distributed file management groups, and each of the Preferably, the system includes: a user-side deletion system having the means for receiving instructions to delete data

[0023] Furthermore, the digital asset guard service provision system according to the present invention is a digital asset guard service provision system for guarding digital assets from high-level cyberattacks, constructed with a distributed ledger in blockchain or other distributed ledger technology, and a smart contract or server application for performing predetermined processing using data managed in the distributed ledger, and has a consortium-type blockchain constructed with multiple planets that form one unit constituting the blockchain, each consisting of a group of nodes combining nodes in multiple locations in different regions around the world, and has a means for creating protected target data that extracts information to be protected from original information with date and time information recorded in a relational database managed by the user and creates protected target data with date and time information, a means for receiving instructions to back up protected target data from a user who wishes to back up protected target data, and based on the protected target data back-up instruction from the user using a first primary public key or other first primary public conversion information received by the protected target data back-up instruction reception means, the protected Meansless means for demeaning data to be preserved, which is created by a target data creation means and has date and time information attached to it, by performing a predetermined encryption process on the data to be preserved with date and time information attached to it, and converting it into meaningless data to be preserved; Meansless data to be preserved memory storage means for storing the meaningless data to be preserved converted by the meansless means for being preserved; Meansless data to be preserved upload means for uploading the meaningless data to be preserved stored in the predetermined memory by the meaningless data to be preserved memory storage means to a first provisional storage area; means for creating data to be preserved index information, which is having file name and upload date information for the data to be preserved with date and time information attached to it, created by the meansless means for being preserved; Meansless means for demeaning data to be preserved index information, which is created by performing a predetermined encryption process on the data to be preserved index information, which is created by the meansless means for being preserved index information, by using a second primary public key and other second primary public conversion information from the user received by the meansless means for being preserved backup instruction;A user-side backup system having a means for uploading meaningless data index information converted by the means for semanticizing data index information to be preserved to a first provisional storage area; a distributed file management group distribution means for distributing the meaningless data and meaningless data index information uploaded to the first provisional storage area by the means for uploading meaningless data and meaningless data index information to a multiple distributed file management group constructed by nodes at each location configured for the planet set up by the consortium and recording devices at multiple locations connected to the nodes at said locations via a network, using the secondary key and other secondary conversion information of the consortium; modifying the data distributed by the distributed file management group distribution means, and distributing the data that does not exceed the block size to multiple nodes of the distributed management file group provided on the blockchain, and the data that exceeds the block size to the block The consortium-side backup system includes: a modification and distributed recording means that distributes and records data to multiple nodes of a distributed file management group separate from the chain; a distributed recording data index information creation, encryption, and recording means that creates and encrypts index information of the data distributed and recorded by the modification and distributed recording means and records it on a specific node of the blockchain in a black box environment; and an upload meaningless preservation target data and meaningless preservation target data index information erasure means that erases the meaningless preservation target data and meaningless preservation target data index information that have been uploaded to a first provisional storage area after the index information of the data distributed and recorded by the modification and distributed recording means has been recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption, and recording means; and the user-side backup system further includes a comparison reference preservation target data creation means that decrypts the meaningless preservation target data stored in a predetermined memory by the meaningless preservation target data memory storage means and creates preservation target data with date and time information that serves as a comparison reference.A comparison standard data storage means for storing data to be preserved with date and time information that serves as a comparison standard, created by the comparison standard data creation means; a memory-stored meaningless data erasure means for erasing meaningless data to be preserved stored in a predetermined memory by the meaningless data memory storage means after the data to be preserved with date and time information that serves as a comparison standard has been stored by the comparison standard data storage means; a check data creation control means for periodically instructing the data to be preserved creation means to extract information to be preserved from original information with date and time information recorded in a relational database managed by the user, and to create data to be preserved with date and time information for checking; and, via the control of the check data creation control means, the data to be preserved with date and time information for checking created by the data to be preserved creation means is erased from the comparison standard data storage means. The system is characterized by comprising: a means for checking whether there is a discrepancy in the data portion with the same date and time information of the data to be preserved, which is used for checking, when the data to be preserved, which is used for checking, is found to have used, and the data to be preserved, when the data to be preserved, which is used

[0024] Furthermore, in the digital asset guard service provision system of the present invention, the original information with date and time information is assigned a data type for management according to the retention period set by the user, the data protection target creation means extracts the information to be protected from the original information with date and time information to which the data type has been assigned, automatically assigns a counter to each of the extracted information to be protected, and adds a user code to distinguish the user, thereby creating data to be protected with date and time information, and the meaningless data protection target upload means creates a first upload ID to the first provisional storage area of ​​the meaningless data protection target using the information to which the user code has been assigned and which has a counter automatically assigned to each piece of information to be protected, based on the data type, and the first primary public key and other first primary public conversion information from the user, and uploads the created first upload Preferably, the load ID is attached to the data to be preserved and meaningless and uploaded to the first provisional storage area; the data to be preserved index information creation means creates data to be preserved index information which includes a user code attached and information which has a counter that is automatically assigned for each piece of information to be preserved, based on the data type; the data to be preserved index information upload means creates a second upload ID for the data to be preserved index information to the first provisional storage area using the information which includes a user code attached and information which has a counter that is automatically assigned for each piece of information to be preserved, based on the data type, and a second primary public key or other second primary public conversion information from the user; and the created second upload ID is attached to the data to be preserved index information and uploaded to the first provisional storage area.

[0025] Furthermore, in the digital asset guard service provision system of the present invention, the system includes: a data type to be restored specification reception means that receives a user code and data type specification from a user who wishes to restore data to be restored; a data index information download instruction means that instructs the download of all meaningless data to be restored index information corresponding to the user code and type, which is distributed and managed in the consortium-side backup system, using a second upload ID created using information that has a user code attached to it and has a counter automatically assigned for each piece of information to be restored, based on the data type to be restored, and a second primary public key and other second primary public conversion information from the user; and the distributed recording data index information creation, encryption, and recording based on the second primary private key and other second primary secret conversion information from the user associated with the data to be restored with date and time information to be downloaded based on the download instruction by the data index information download instruction means, and the consortium's secondary key and other secondary conversion information. A first encrypted data index information extraction means for extracting encrypted data index information to be preserved and rendered meaningless, recorded in a group of nodes at a specific location on the blockchain under a black box environment; a first encrypted data index information decryption means for decrypting the encrypted data index information to be preserved and rendered meaningless, extracted by the first encrypted data index information extraction means; a data index information download means for downloading the data index information to be preserved and rendered meaningless, decrypted by the first encrypted data index information decryption means to a second provisional storage area; and a data index information restoration means for restoring the data index information to be preserved by performing semantic processing on the data index information to be preserved and rendered meaningless, downloaded to the second provisional storage area by the data index information download means, based on a second primary secret key and other second primary secret transformation information from the user.Preferably, the system further includes: an uploaded data restoration candidate data restoration list creation means that rearranges the data restoration index information restored by the data restoration index information means in a predetermined order on a counter to create a list of uploaded data restoration candidates; and an uploaded data restoration candidate data restoration list display means that displays the list of uploaded data restoration candidates created by the uploaded data restoration candidate data restoration list creation means to the user.

[0026] Furthermore, in the digital asset guard service provision system of the present invention, a means for receiving a request to restore protected data from a user who wishes to restore protected data, by receiving a request to restore protected data selection / designation acceptance means for receiving a request to restore protected data from a list of uploaded protected data that constitute restoration candidates displayed by the Uploaded Restoration Candidate Protected Data List Display Means, and a means for instructing the download of protected data corresponding to the user code and type, which is distributed and managed in the consortium-side backup system, using a first upload ID created using a first primary public key and other first primary public conversion information from the user, which has a user code attached to the protected data to be restored received by the request to restore protected data selection / designation acceptance means, and which has a counter that is automatically numbered for each piece of information to be protected on a data type basis, and a first primary private key and other first primary public conversion information from the user, which are distributed and managed in the consortium-side backup system, and a first primary private key and other first primary private conversion information from the user that are linked to the protected data with date and time information that is to be downloaded based on the download instruction from the protected data download instruction means. Based on the primary secret transformation information of 1 and the secondary key and other secondary transformation information of the consortium, a second encrypted data index information extraction means extracts encrypted data index information to be preserved for meaninglessness that is recorded in a black box environment on a group of nodes at a specific location on the blockchain by the distributed recording data index information creation, encryption, and recording means; a second encrypted data index information decryption means decrypts the encrypted data index information to be preserved for meaninglessness extracted by the second encrypted data index information extraction means; and using the data index information to be preserved for meaninglessness that has been decrypted by the second encrypted data index information decryption means, the distributed file management group distribution means distributes it to each of the distributed file management groups, and the respective nodes at each location belonging to each of the distributed file management groups and the recording devices at multiple locations connected to the nodes at those locations via a network are distributed and recorded by each of the modification and distributed recording means.The system further comprises: a means for extracting meaningless data to be preserved, which extracts each meaningless data to be preserved from either the node of each location belonging to each of the distributed file management groups or the recording devices of multiple locations connected to the node of said location via a network; a means for downloading meaningless data to be preserved, which extracts each meaningless data to be preserved, which is extracted by the meaningless data to be preserved, which is downloaded by the meaningless data to be preserved, which is downloaded by the meaningless data to be preserved, which is then preserved with the date and time information from before the backup; and a means for erasing meaningless data to be preserved and meaningless data to be preserved, which is then downloaded to the second provisional storage area after the data has been restored to its original state with the date and time information from before the backup by the preserved data to be preserved. It is preferable to have a user-side recovery system having a reception means, a means for instructing the download of the meaningless preserved data index information, a means for restoring the preserved data index information, a means for creating a list of uploaded preserved data candidates for restoration, a means for displaying the list of uploaded preserved data candidates for restoration, a means for receiving the desired preserved data selection / designation, a means for instructing the download of the preserved data, a means for restoring the preserved data, and a means for erasing the downloaded meaningless preserved data and meaningless preserved data index information; and a consortium-side recovery system having a first means for extracting encrypted meaningless preserved data index information, a first means for decrypting encrypted meaningless preserved data index information, a means for downloading meaningless preserved data index information, a second means for extracting encrypted meaningless preserved data index information, a second means for decrypting encrypted meaningless preserved data index information, a means for extracting meaningless preserved data, and a means for downloading meaningless preserved data. [Effects of the Invention]

[0027] According to the present invention, a digital asset guard service provision system is obtained that can strongly and efficiently protect important information such as confidential information and personal information from high-level cyberattacks and physical destruction, restore important information without it being stolen by a third party even if it is subjected to cryptographic analysis by a quantum computer or EMP attack, quickly detect and restore backup information for protecting important information such as confidential information and personal information even if it is destroyed, and efficiently restore the desired protected information even if the index information of the protected information managed by the user is destroyed. [Brief explanation of the drawing]

[0028] [Figure 1] This is a schematic diagram illustrating an example of the overall configuration of a digital asset guard service provision system according to the first embodiment of the present invention. [Figure 2] This is a schematic diagram illustrating an example of the configuration of a means for creating data to be protected, which is provided in the user-side evacuation system in the digital asset guard service provision system according to the first embodiment. [Figure 3] This is a schematic diagram illustrating an example of the configuration of a data backup instruction receiving means for protected data, which is provided in the user-side backup system of the digital asset guard service provision system according to the first embodiment. [Figure 4] This is a schematic diagram illustrating an example of the configuration of a means for rendering protected data meaningless in the user-side evacuation system of the digital asset guard service provision system according to the first embodiment. [Figure 5] This is a schematic diagram illustrating an example of the configuration of a data memory storage means for data to be rendered meaningless, provided in the user-side evacuation system of the digital asset guard service provision system according to the first embodiment. [Figure 6] This is a schematic diagram illustrating an example of the configuration of a data upload means for data to be rendered meaningless, provided in the user-side evacuation system of the digital asset guard service provision system according to the first embodiment. [Figure 7]This is a schematic diagram illustrating an example of the configuration of a distributed file management group distribution means provided in the consortium-side backup system in the digital asset guard service provision system according to the first embodiment. [Figure 8] This is a schematic diagram illustrating an example of the configuration of the modification and distributed recording means provided in the consortium-side evacuation system in the digital asset guard service provision system according to the first embodiment. [Figure 9] This is a schematic diagram illustrating an example of the configuration of a distributed record data index information creation, encryption, and recording means provided in the consortium-side evacuation system of the digital asset guard service provision system according to the first embodiment. [Figure 10] This is a schematic diagram illustrating an example of the configuration of the data erasure means for data to be erased by rendering it meaningless when uploaded, which is provided in the consortium-side backup system in the digital asset guard service provision system according to the first embodiment. [Figure 11] This is a schematic diagram illustrating an example of the configuration of a means for creating comparative reference protection target data, which is provided in the user-side evacuation system of the digital asset guard service provision system according to the first embodiment. [Figure 12] This is a schematic diagram illustrating an example of the configuration of a comparative reference data storage means provided in the user-side evacuation system of the digital asset guard service provision system according to the first embodiment. [Figure 13] This is a schematic diagram illustrating an example of the configuration of a means for erasing data to be stored in memory and preserved in a user-side evacuation system in a digital asset guard service provision system according to the first embodiment. [Figure 14] This is a schematic diagram illustrating an example of the configuration of a control means for creating maintenance target data for checking, which is provided in the user-side evacuation system of the digital asset guard service provision system according to the first embodiment. [Figure 15] This is a schematic diagram illustrating an example of the configuration of a means for checking for partial data misalignment of data with identical date and time information in the user-side evacuation system of the digital asset guard service provision system according to the first embodiment. [Figure 16] This is a schematic diagram illustrating an example of the configuration of a data protection target extraction function contamination notification means provided in the user-side evacuation system of the digital asset guard service provision system according to the first embodiment. [Figure 17] This is a schematic diagram illustrating an example of the overall configuration of a digital asset guard service provision system according to a second embodiment of the present invention. [Figure 18] This is a schematic diagram illustrating an example of the configuration of a means for checking for partial data misalignment of data with identical date and time information in the user-side evacuation system of the digital asset guard service provision system according to the second embodiment. [Figure 19] This is a schematic diagram illustrating an example of the overall configuration of a digital asset guard service provision system according to a third embodiment of the present invention. [Figure 20] This is a schematic diagram illustrating an example of the configuration of the first hash value calculation means provided in the user-side evacuation system in the digital asset guard service provision system according to the third embodiment. [Figure 21] This is a schematic diagram illustrating an example of the configuration of the first hash value storage means provided in the user-side evacuation system in the digital asset guard service provision system according to the third embodiment. [Figure 22] This is a schematic diagram illustrating an example of the configuration of a second hash value calculation means provided in the user-side evacuation system in the digital asset guard service provision system according to the third embodiment. [Figure 23] This is a schematic diagram illustrating an example of the configuration of a means for checking for partial data misalignment of data with identical date and time information in the user-side evacuation system of the digital asset guard service provision system according to the third embodiment. [Figure 24] This is an explanatory diagram illustrating a schematic example of the overall configuration of a digital asset guard service provision system according to a fourth embodiment of the present invention. [Figure 25]This is a schematic diagram illustrating an example of the configuration of a means for rendering protected data meaningless in the user-side evacuation system of the digital asset guard service provision system according to the fourth embodiment. [Figure 26] This is a schematic diagram illustrating an example of the configuration of a data memory storage means for data to be rendered meaningless, provided in the user-side evacuation system of the digital asset guard service provision system according to the fourth embodiment. [Figure 27] This is a schematic diagram illustrating an example of the configuration of a data upload means for meaningless preservation in the user-side evacuation system of the digital asset guard service provision system according to the fourth embodiment. [Figure 28] This is a schematic diagram illustrating an example of the configuration of a distributed file management group distribution means provided in the consortium-side backup system in the digital asset guard service provision system according to the fourth embodiment. [Figure 29] This is a schematic diagram illustrating an example of the configuration of the data deletion means for data to be erased by rendering it meaningless when uploaded, which is provided in the consortium-side backup system in the digital asset guard service provision system according to the fourth embodiment. [Figure 30] This is a schematic diagram illustrating an example of the configuration of a means for creating comparative reference protection target data in the user-side evacuation system of the digital asset guard service provision system according to the fourth embodiment. [Figure 31] This is a schematic diagram illustrating an example of the overall configuration of a user-side restoration system, which is another common component in the digital asset guard service provision system according to the first to fourth embodiments of the present invention. [Figure 32] This is a schematic diagram illustrating an example of the configuration of a means for receiving instructions to restore data to be preserved, which is provided in the user-side restoration system of the digital asset guard service provision system according to the first to fourth embodiments. [Figure 33] This is a schematic diagram illustrating an example of the configuration of a download means included in the user-side restoration system of the digital asset guard service provision system according to the first to fourth embodiments. [Figure 34]This is a schematic diagram illustrating an example of the configuration of a data recovery means for protected data included in the user-side recovery system of the digital asset guard service provision system according to the first to fourth embodiments. [Figure 35] This is a schematic diagram illustrating an example of the configuration of a downloaded data erasure means included in the user-side restoration system of the digital asset guard service provision system according to the first to fourth embodiments. [Figure 36] This is a schematic diagram illustrating an example of the overall configuration of the consortium-side restoration system, which is another common component in the digital asset guard service provision system according to each embodiment of the first to fourth inventions. [Figure 37] This is a schematic diagram illustrating an example of the configuration of the encrypted index information extraction means provided in the consortium-side recovery system in the digital asset guard service provision system according to the first to fourth embodiments. [Figure 38] This is a schematic diagram illustrating an example of the configuration of an index information decoding means provided in the consortium-side restoration system in the digital asset guard service provision system according to the first to fourth embodiments. [Figure 39] This is a schematic diagram illustrating an example of the configuration of a data extraction means provided in the consortium-side restoration system in the digital asset guard service provision system according to the first to fourth embodiments. [Figure 40] This is a schematic diagram illustrating an example of the overall configuration of a user-side deletion system, which is another common component in the digital asset guard service provision system according to the first to fourth embodiments of the present invention. [Figure 41] This is a schematic diagram illustrating an example of the configuration of a means for receiving instructions to delete preservation data, which is included in the user-side deletion system of the digital asset guard service provision system according to the first to fourth embodiments. [Figure 42] This is a schematic diagram illustrating an example of the overall configuration of a consortium-side deletion system, which is another common component in the digital asset guard service provision system according to the first to fourth embodiments of the present invention. [Figure 43] This is a schematic diagram illustrating an example of the configuration of the encryption index information extraction means during deletion processing, which is provided in the consortium-side deletion system in the digital asset guard service provision system according to the first to fourth embodiments. [Figure 44] This is a schematic diagram illustrating an example of the configuration of the index information decoding means during deletion processing, which is provided in the consortium-side deletion system in the digital asset guard service provision system according to the first to fourth embodiments. [Figure 45] This is a schematic diagram illustrating an example of the configuration of a file data deletion means provided in the consortium-side deletion system in the digital asset guard service provision system according to the first to fourth embodiments. [Figure 46] This is a schematic diagram illustrating an example of the configuration of a second file data deletion means provided in the consortium-side deletion system in the digital asset guard service provision system according to the first to fourth embodiments. [Figure 47] This is an explanatory diagram showing a part of the basic processing flow - maintenance processing flow - as an example of the processing flow using the digital asset guard service provision system according to the first embodiment. [Figure 48] This is an explanatory diagram showing the basic processing flow - maintenance processing flow and other parts of the processing flow using the digital asset guard service provision system according to the first embodiment. [Figure 49] This is an explanatory diagram showing the basic processing flow - maintenance processing flow - as an example of the processing flow using the digital asset guard service provision system according to the first embodiment. [Figure 50] This is an explanatory diagram showing the basic processing flow unique to the present invention - the maintenance processing flow - as an example of the processing flow using the digital asset guard service provision system according to the first embodiment. [Figure 51] This diagram illustrates the processing flow using the digital asset guard service provision system according to the first embodiment, specifically the periodic processing flow and the processing flow for checking for contamination of data to be protected. [Figure 52]This diagram illustrates the processing flow specific to the digital asset guard service provision system according to the second embodiment, specifically showing the periodic processing flow and the processing flow for checking whether or not the data to be protected is contaminated. [Figure 53] This diagram illustrates the processing flow specific to the digital asset guard service provision system according to the third embodiment, specifically showing the periodic processing flow and the processing flow for checking whether or not the data to be protected is contaminated. [Figure 54] This is an explanatory diagram showing a part of the basic processing flow in the maintenance processing, which is specific to the digital asset guard service provision system according to the fourth embodiment. [Figure 55] This diagram illustrates the processing flow specific to the digital asset guard service provision system according to the fourth embodiment, showing the basic processing flow - an explanatory diagram showing other parts of the processing flow in the maintenance processing. [Figure 56] This is an explanatory diagram showing the basic processing flow unique to the present invention—the maintenance processing flow—as a processing flow specific to the digital asset guard service provision system according to the fourth embodiment. [Figure 57] This is an explanatory diagram showing a part of the data recovery process for protected data, as it represents other processing flows common to the digital asset guard service provision system 1 of the first to fourth embodiments. [Figure 58] This is an explanatory diagram showing other parts of the data recovery process for protected data, which is a common process flow for the digital asset guard service provision system 1 of the first to fourth embodiments. [Figure 59] This is an explanatory diagram showing other parts of the data recovery process for protected data, which is a common process flow for the digital asset guard service provision system 1 of the first to fourth embodiments. [Figure 60] This is an explanatory diagram showing a part of the data deletion process for protected data, which is a common process flow for the digital asset guard service provision system 1 of the first to fourth embodiments. [Figure 61]This is an explanatory diagram showing other parts of the data deletion process, which is common to the digital asset guard service provision system 1 of the first to fourth embodiments. [Figure 62] This is an explanatory diagram illustrating a schematic example of the overall configuration of a digital asset guard service provision system according to a fifth embodiment of the present invention. [Figure 63] This is a schematic diagram illustrating an example of the configuration of a means for rendering protected data meaningless in the user-side evacuation system of the digital asset guard service provision system according to the fifth embodiment. [Figure 64] This is a schematic diagram illustrating an example of the configuration of a means for creating data index information to be protected, which is provided in the user-side evacuation system in the digital asset guard service provision system according to the fifth embodiment. [Figure 65] This is a schematic diagram illustrating an example of the configuration of a means for rendering data index information of protected data meaningless, which is provided in the user-side evacuation system of the digital asset guard service provision system according to the fifth embodiment. [Figure 66] This is a schematic diagram illustrating an example of the configuration of a means for uploading meaningless data index information to be preserved in the user-side evacuation system of the digital asset guard service provision system according to the fifth embodiment. [Figure 67] This is a schematic diagram illustrating an example of the configuration of a distributed file management group distribution means provided in the consortium-side evacuation system in the digital asset guard service provision system according to the fifth embodiment. [Figure 68] This is a schematic diagram illustrating an example of the configuration of the means for erasing uploaded data to be rendered meaningless and data index information to be rendered meaningless, which is provided in the consortium-side backup system of the digital asset guard service provision system according to the fifth embodiment. [Figure 69] This is a schematic diagram illustrating an example of the data structure of original information with date and time information in the digital asset guard service provision system according to the fifth embodiment. [Figure 70]This is a schematic diagram illustrating an example of the configuration of a means for creating data to be protected, which is provided in the user-side evacuation system in the digital asset guard service provision system according to the fifth embodiment. [Figure 71] This is a schematic diagram illustrating an example of the configuration of a data upload means for data to be rendered meaningless, provided in the user-side evacuation system of the digital asset guard service provision system according to the fifth embodiment. [Figure 72] This is a schematic diagram illustrating an example of the configuration of a means for creating data index information to be protected, which is provided in the user-side evacuation system in the digital asset guard service provision system according to the fifth embodiment. [Figure 73] This is a schematic diagram illustrating an example of the configuration of a means for uploading meaningless data index information to be preserved in the user-side evacuation system of the digital asset guard service provision system according to the fifth embodiment. [Figure 74] This is a schematic diagram illustrating an example of the overall configuration of a user-side restoration system in a digital asset guard service provision system according to a fifth embodiment of the present invention. [Figure 75] This is a schematic diagram illustrating an example of the configuration of a data type to be restored receiving means in the user-side restoration system of the digital asset guard service provision system according to the fifth embodiment. [Figure 76] This is a schematic diagram illustrating an example of the configuration of a means for instructing the download of meaningless data index information in the user-side restoration system of the digital asset guard service provision system according to the fifth embodiment. [Figure 77] This is a schematic diagram illustrating an example of the configuration of a data index information restoration means for protected data, which is provided in the user-side restoration system of the digital asset guard service provision system according to the fifth embodiment. [Figure 78] This is a schematic diagram illustrating an example of the configuration of a means for creating a list of uploaded data to be preserved as a candidate for restoration, which is included in the user-side restoration system of the digital asset guard service provision system according to the fifth embodiment. [Figure 79]This is a schematic diagram illustrating an example of the configuration of a means for displaying a list of uploaded data to be preserved as a restoration candidate, which is provided in the user-side restoration system of the digital asset guard service provision system according to the fifth embodiment. [Figure 80] This is a schematic diagram illustrating an example of the configuration of a data selection and designation receiving means for data to be restored and preserved, which is included in the user-side restoration system of the digital asset guard service provision system according to the fifth embodiment. [Figure 81] This is a schematic diagram illustrating an example of the configuration of a data download instruction means for protected data included in the user-side restoration system of the digital asset guard service provision system according to the fifth embodiment. [Figure 82] This is a schematic diagram illustrating an example of the configuration of a data recovery means for protected data included in the user-side recovery system of the digital asset guard service provision system according to the fifth embodiment. [Figure 83] This is a schematic diagram illustrating an example of the configuration of the means for erasing downloadable data to be rendered meaningless and data index information of the user-side restoration system in the digital asset guard service provision system according to the fifth embodiment. [Figure 84] This is a schematic diagram illustrating an example of the overall configuration of the consortium-side restoration system in the digital asset guard service provision system according to the fifth embodiment of the present invention. [Figure 85] This is a schematic diagram illustrating an example of the configuration of the first encryption-decryption-preservation target data index information extraction means provided in the consortium-side restoration system in the digital asset guard service provision system according to the fifth embodiment. [Figure 86] This is a schematic diagram illustrating an example of the configuration of the first encryption-decryption-preservation-target data index information decryption means provided in the consortium-side restoration system in the digital asset guard service provision system according to the fifth embodiment. [Figure 87]This is a schematic diagram illustrating an example of the configuration of a means for downloading meaningless data index information in the consortium-side restoration system of the digital asset guard service provision system according to the fifth embodiment. [Figure 88] This is a schematic diagram illustrating an example of the configuration of a second encryption-decryption-preservation target data index information extraction means provided in the consortium-side restoration system in the digital asset guard service provision system according to the fifth embodiment. [Figure 89] This is a schematic diagram illustrating an example of the configuration of a second encryption-decryption-preservation-target data index information decryption means provided in the consortium-side restoration system in the digital asset guard service provision system according to the fifth embodiment. [Figure 90] This is a schematic diagram illustrating an example of the configuration of the data extraction means for data to be rendered meaningless, which is provided in the consortium-side restoration system in the digital asset guard service provision system according to the fifth embodiment. [Figure 91] This is a schematic diagram illustrating an example of the configuration of a data download means for data to be rendered meaningless, which is provided in the consortium-side restoration system in the digital asset guard service provision system according to the fifth embodiment. [Figure 92] This is an explanatory diagram showing a part of the basic processing flow - maintenance processing flow - which is specific to the digital asset guard service provision system according to the fifth embodiment. [Figure 93] This is an explanatory diagram showing the basic processing flow - maintenance processing flow, as a processing flow specific to the digital asset guard service provision system according to the fifth embodiment. [Figure 94] This diagram illustrates a part of the basic processing flow - maintenance processing flow - which is specific to the digital asset guard service provision system according to the fifth embodiment. [Figure 95] This is an explanatory diagram showing a part of the basic processing flow - restoration processing flow, which is specific to the digital asset guard service provision system according to the fifth embodiment. [Figure 96]This is an explanatory diagram showing the basic processing flow - restoration processing flow, as a processing flow specific to the digital asset guard service provision system according to the fifth embodiment. [Figure 97] This diagram illustrates a part of the basic processing flow - restoration processing flow, which is specific to the digital asset guard service provision system according to the fifth embodiment. [Figure 98] This diagram illustrates a part of the basic processing flow - restoration processing flow, which is specific to the digital asset guard service provision system according to the fifth embodiment. [Figure 99] This diagram illustrates a part of the basic processing flow - restoration processing flow, which is specific to the digital asset guard service provision system according to the fifth embodiment. [Figure 100] This diagram illustrates a part of the basic processing flow - restoration processing flow, which is specific to the digital asset guard service provision system according to the fifth embodiment. [Figure 101] This is a schematic diagram illustrating the overall flow of the contamination check process for the data extraction function in the maintenance process using the asset guard service provision system of the first embodiment. [Figure 102] This is a schematic diagram illustrating the flow of processing from the creation of data to be protected to the uploading of data to be protected in the maintenance process using the asset guard service provision system of the fifth embodiment. [Figure 103] This is a schematic diagram illustrating the processing flow from receiving the specification of the data type to be restored to displaying the list of data to be restored as a candidate for preservation in the restoration process using the asset guard service provision system of the fifth embodiment. [Figure 104] This is a schematic diagram illustrating the process flow from selecting and specifying the data to be restored to the restoration of the data in the restoration process using the asset guard service provision system of the fifth embodiment. [Modes for carrying out the invention]

[0029] Before describing the embodiments, we will explain the circumstances that led to the invention and the effects of the invention.

[0030] Recent attacks Recent cyberattacks have been the dominant type of attack during times of crisis. Cyberattacks during emergencies are based on the premise of destroying backups. The "backup measures" in a "standard BCP" are based on the concept of recovery from a major disaster, and are less effective in a "cyber BCP."

[0031] Cyber ​​BCP A cyber business continuity plan (BCP) is a plan for responding to emergencies that threaten the survival of a business due to cyberattacks. While typical BCPs (IT-BCPs) are designed to handle natural disasters (such as backups), there is a growing need to incorporate BCPs specifically tailored to cyberattacks.

[0032] Since June 2024, various ministries and agencies have been leading the development of "business continuity plans (BCPs) that anticipate cyberattacks," also known as "cyber BCP concepts." However, these concepts do not focus on defensive measures, which have been the emphasis in cybersecurity until now, but rather on how to deal with cyberattacks after they have occurred, assuming that defense is impossible.

[0033] The key point is proactive measures against cyberattacks by state actors during times of crisis. These attacks by state actors aim not at information leakage, but at system destruction.

[0034] Anticipated State Actor Attacks In the event of a crisis, the following types of attacks by state actors are anticipated: • Cutting of submarine cables • Naval blockade by military force (suspension of exports and imports) • Cyberattacks (Zero-day cyberattacks are basically impossible to defend against on servers) • EMP (high magnetic field) attack using balloons Currently, cyber insurance policies exclude coverage for state actor factors. In effect, cyber insurance is not available to financial institutions and similar entities. Furthermore, in the case of an EMP attack, it has been pointed out that in addition to short-circuiting the electronic circuits, there is also a possibility that the information on the backup cartridge itself may be corrupted. While mainframe systems are resistant to cyberattacks, they cannot withstand EMP attacks.

[0035] The following two points are examples of information that should be preserved: • Company's important information: Contracts / Research and patent details / System designs and source code • Service information: Personal and corporate information (credit / rights / assets / transactions, etc.) Furthermore, under the revised Personal Information Protection Act, all forms of personal information, including encrypted and distributed versions, as well as backups, are considered personal information, and their transfer overseas is restricted.

[0036] Cyber ​​BCP for "State-Actor-Type Attacks" in Times of Crisis (1) Commonly considered desk measures While cyberattacks are difficult to completely prevent due to their complexity and destructive power, it is believed that damage can be mitigated through multi-layered defenses, continuous vulnerability management, and rapid incident response. Furthermore, to enable rapid recovery after an attack, it is considered important to manage backups, rebuild systems, conduct forensic investigations, and design systems with resilience in mind.

[0037] (2) Cyberattacks in times of crisis Cyberattacks during emergencies are different in scale from what is anticipated, and in reality, the following countermeasures are likely necessary. The primary threat is zero-day attacks, and although countermeasures are being considered and researched due to the existence of real-world examples, defense is virtually impossible. In the near future, cryptography using quantum computers and EMP (electromagnetic pulse) attacks are recognized as important threats, particularly in the United States, and countermeasures are being taken. If such an attack were to occur domestically, it would pose a particularly serious threat to critical infrastructure and the financial sector. It has been pointed out that if an EMP attack occurs, electronic devices and infrastructure could be destroyed on a large scale, potentially bringing critical infrastructure and financial systems to a standstill. It is difficult to defend against the above attacks in advance, and it is necessary to consider restoring the system under the assumption that it has been severely damaged. In other words, computer shelter (data preservation) measures like those used in Europe and the United States are considered effective.

[0038] Matters that require special consideration in "Cyber ​​BCP" While ransomware is likely already embedded in systems, the latest security technologies allow for a certain degree of detection. Although these countermeasures are being implemented, the real threat lies in unknown attacks that haven't surfaced. In such cases, the fundamental concept of cyber business continuity planning (BCP) is to assume that defense is impossible and take appropriate measures. At the very least, defending against the next attack will be difficult. (1) Zero-day attacks: These particularly target network vulnerabilities, and the Huawei issue in the US is complex. They have already secured undisclosed halls. (2) EMP: A strong electromagnetic wave attack caused by a nuclear explosion in the stratosphere, recognized by the United Nations as a cyberattack. It is virtually impossible to defend against attacks that involve mobile balloons controlled by satellites. (3) Quantum computer cryptography: The practical application of 10,000-qubit gate-type quantum computers is imminent. As mentioned above, cyberattacks are cutting-edge, and countermeasures using older technologies are insufficient.

[0039] Cyber ​​BCP plan for particularly troublesome EMP attacks The following are some cyber BCP (Business Continuity Plan) proposals for particularly troublesome EMP (Electromagnetic Pulse) attacks: (1) Infrastructure hardening The equipment is physically protected from the effects of electromagnetic waves by introducing shielded rooms and adopting EMP-resistant equipment. For example, a computer shelter deep underground would be one such example. (2) Data redundancy and off-site information backup Off-site data backup: To prevent data loss, data is regularly backed up to an off-site location and stored in a physically and geographically isolated location that is not affected by EMP attacks. Utilizing cloud backup: By storing financial system data in cloud-based storage (across multiple regions), data loss due to physical server damage is prevented. Furthermore, in the case of foreign-owned cloud services, cloud risks exist, so measures to render the information to be evacuated meaningless are considered essential.

[0040] However, the above practical solutions require very high costs and time. However, according to the digital asset guard service provision system derived by the inventor of this case, it is believed that important information can be protected against foreign cloud companies by rendering the information to be backed up to a cryptographic distributed service meaningless (+PQC).

[0041] Digital Asset Guard Service Provisioning System The digital asset guarding service provision system developed by the inventor is configured to render the information to be evacuated meaningless and distribute it globally (utilizing overseas cloud regions). The anonymized information will be protected using multivariate polynomial cryptography that is resistant to cryptographic cracking by quantum computers. Furthermore, personal information can be anonymized and stored overseas. Generally, blockchains cannot manage personal information because the block chain is unbreakable, thus failing to meet the requirements for invalidating personal information, and they cannot manage information exceeding the block size. However, according to the digital asset guard service provision system, it is possible to invalidate meaningless personal information recorded on the blockchain by deleting the index information of meaningless personal information, and information exceeding the block size can be managed by distributing and recording it on nodes separate from the blockchain. The information management in the digital asset guard service provision system utilizes blockchain (a type with data management functionality, not ledger functionality), but its structure is based on a password (two-way agreement) method. If you don't want to hand over sensitive information to a foreign cloud provider, rendering the information meaningless can be an effective solution. The Digital Asset Guard Service Provisioning System provides a cryptographic distributed data preservation service with a consortium-type planetary system configuration. The inventors of this invention believe that, globally, the Digital Asset Guard Service Provisioning System is currently the only system providing a service in this manner. Users can recover their preserved information even if their system's data management environment is completely destroyed, provided they reliably protect their digital key (RSA or next-generation type selected during initial setup). The digital keys are expected to be stored in fireproof safes or through security services provided by security companies. Thus, while blockchain is used for token management, the digital asset guard service provision system puts into practical use a decentralized DMP (Data Management Platform), an open data management structure that is still in the research stage globally. The digital asset guarding service provision system has the following features: (1) it divides the original data into multiple meaningless data and stores them, and (2) if the required number of meaningless data are available from the multiple divided meaningless data, the original data can be restored.

[0042] Security Concepts for Digital Asset Guard Service Provisioning Systems As described above, the digital asset guard service provision system renders the original data meaningless on the user's side. This is then further decomposed into secondary data and distributed globally, with each index managed accordingly. However, as long as the "digital key" of the primary information is not lost or destroyed, the system is configured to allow decomposition even if the primary information is stolen or the environment is destroyed. Since the secondary decomposition side involves a globally dispersed physical environment, it is considered extremely difficult to destroy the entire environment. Deconstructing multiple meaningless data sets to restore the original data requires both primary information (primary key) and secondary decomposition information (secondary key). Furthermore, even if both pieces of information are obtained, decomposition requires specialized processing, and it is considered that there are basically no methods of attacking the system through the theft of both pieces of information and environmental destruction.

[0043] Countermeasures against backup disablement attacks Cyberattacks are fundamentally based on the destruction of system backups. In cases where large-scale damage has occurred, cyberattacks are now emerging that not only access and destroy backup data, but also hijack the backup creation process itself, disabling all backup creation processes without the user's knowledge. When faced with such cyberattacks, the backup information created becomes meaningless, and even with a digital asset guarding service system, there is a risk that sensitive information such as confidential and personal information cannot be protected.

[0044] Improvements to the data recovery process in the event that the user's environment is destroyed. Furthermore, the current digital asset guard service provision system manages in a distributed manner the information that has been rendered meaningless by cryptographic distribution on the user's system (meaningless protected data and index information of protected data), which has been further transformed on the consortium's system. This makes it impossible for the user's system to grasp the relationship between the index information of the information rendered meaningless by cryptographic distribution and the index information managed in a distributed manner on the consortium's system. This makes it difficult for a malicious third party to recover the user's original information even if they steal the consortium's information. However, it has been found that if the index information on the user's system is destroyed, the user will not be able to identify the protected data that could be recovered, and will not be able to select and recover only the desired protected data from the list of protected data recorded in the index information on the user's system. Instead, all protected data must be recovered, which is inconvenient.

[0045] The inventors of this case have organized the strategies and issues derived from the above considerations and studies, and after further consideration and studies, have developed a digital asset guard service provision system that can strongly and efficiently protect important information such as confidential information and personal information from high-level cyberattacks and physical destruction, restore important information without it being stolen by third parties even if it is subjected to cryptographic analysis by quantum computers or EMP attacks, quickly detect and restore backup information used to preserve important information such as confidential information and personal information even if it is destroyed, and efficiently restore the desired protected information even if the index information of the protected information managed by the user is destroyed.

[0046] The present invention provides a digital asset guard service system for protecting digital assets from high-level cyberattacks, comprising a distributed ledger in blockchain or other distributed ledger technology, and a smart contract or server application for performing predetermined processing using data managed in the distributed ledger, and having a consortium-type blockchain constructed with multiple planets that constitute a single unit of the blockchain, each consisting of a group of nodes combining nodes in multiple locations in different regions around the world, and includes a means for creating protected target data that extracts information to be protected from original information with date and time information recorded in a relational database managed by the user and creates protected target data with date and time information, a means for receiving instructions to back up protected target data from a user who wishes to back up protected target data, and a means for receiving instructions to back up protected target data based on the instructions received by the protected target data back-up instruction reception means using a primary key or other primary conversion information from the user, the protected target A user-side backup system having: a means for demeaning data to be preserved by applying a predetermined encryption process to data to be preserved with date and time information created by a data creation means to convert it into data to be preserved that has been demeaned; a means for storing the data to be preserved that has been converted by the means for demeaning data to be preserved by a predetermined memory; a means for uploading the data to be preserved that has been demeaned that has been stored in the predetermined memory by the means for demeaning data to be preserved by a predetermined memory to a first provisional storage area; a distributed file management group distribution means for distributing the data to be preserved that has been uploaded to the first provisional storage area by the means for demeaning data to be preserved by a means for distributing it to a plurality of distributed file management groups constructed by the nodes of each base that constitute the planet set up by the consortium and recording devices of multiple bases that are network-connected to the nodes of said bases, using the secondary key of the consortium and other secondary conversion information; and a means for modifying the data distributed by the distributed file management group distribution means.The consortium-side backup system includes: a modification and distributed recording means that distributes and records data not exceeding the block size to multiple nodes of a distributed management file group established on the blockchain, and data exceeding the block size to multiple nodes of a distributed file management group separate from the blockchain; a distributed recording data index information creation, encryption, and recording means that creates and encrypts index information of the data distributed and recorded by the modification and distributed recording means and records it on a specific node of the blockchain in a black box environment; and an upload meaningless preservation target data erasure means that erases the meaningless preservation target data uploaded to a first provisional storage area after the index information of the data distributed and recorded by the modification and distributed recording means has been recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption, and recording means. The user-side backup system further decrypts the meaningless preservation target data stored in a predetermined memory by the meaningless preservation target data memory storage means and preserves it with date and time information that serves as a comparison standard. A comparison standard data creation means for creating data; a comparison standard data storage means for storing data to be preserved with date and time information that serves as a comparison standard, created by the comparison standard data creation means; a memory-stored meaningless data erasure means for erasing meaningless data stored in a predetermined memory by the meaningless data memory storage means after the data to be preserved with date and time information that serves as a comparison standard has been stored by the comparison standard data storage means; a check data creation control means for periodically instructing the data creation means to extract information to be preserved from source information with date and time information recorded in a relational database managed by a user, and to create check data with date and time information; and, through the control of the check data creation control means, comparing the check data creation means with the data portion with the same date and time information in the data to be preserved with date and time information that serves as a comparison standard and is stored by the comparison standard data storage means.The system comprises: a means for checking whether there is a discrepancy in the data portion with the same date and time information between the data to be preserved with the date and time information for checking and the data to be preserved with the date and time information used as a comparison standard; and a means for notifying the user and the consortium that the data extraction function for information to be preserved in the data to be preserved is contaminated, when, as a result of the check by the means for checking whether there is a discrepancy in the data portion with the same date and time information between the data to be preserved with the date and time information for checking and the data to be preserved with the date and time information used as a comparison standard; and a means for notifying the user and the consortium that the data extraction function for information to be preserved in the data to be preserved in the data to be preserved is contaminated.

[0047] The present invention provides a digital asset guard service system that includes a consortium-type blockchain constructed with multiple planets, each planet being a single unit constituting a blockchain, and which extracts information to be protected from original information with date and time information recorded in a relational database managed by the user, and creates protected data with date and time information; a protected data backup instruction receiving means that receives backup instructions for protected data from users who wish to back up protected data; a protected data de-meaningfulness means that performs a predetermined encryption process on the protected data with date and time information created by the protected data creation means based on the backup instructions from the user using a primary key or other primary conversion information received by the protected data backup instruction receiving means, and converts it into de-meaningful protected data; a de-meaningful protected data memory storage means that stores the de-meaningful protected data converted by the protected data de-meaningfulness means in a predetermined memory; and the de-meaningful protected data A user-side backup system having a data upload means for uploading data to be rendered meaningless, stored in a predetermined memory by a data storage means, to a first provisional storage area; a distributed file management group distribution means for distributing the data to be rendered meaningless, uploaded to the first provisional storage area by the data upload means for being rendered meaningless, to multiple distributed file management groups constructed by nodes at each location that constitute the planet set up by the consortium and recording devices at multiple locations that are network-connected to the nodes at said locations, using the consortium's secondary key and other secondary transformation information; a modification and distributed recording means for modifying the data distributed by the distributed file management group distribution means and distributing the data that does not exceed the block size to multiple nodes of a distributed management file group provided on the blockchain, and distributing the data that exceeds the block size to multiple nodes of a distributed file management group separate from the blockchain; and an index information for the data distributed and recorded by the modification and distributed recording means,If a consortium-side backup system is configured with a means for creating, encrypting, and recording distributed record data index information recorded on a specific node of the blockchain in a black box environment, and an upload meaningless data erasure means for erasing meaningless data to be preserved after the index information of the data distributed and recorded by the said modification and distributed recording means has been recorded on a specific node of the blockchain by the said distributed record data index information creation, encryption, and recording means, then if the user-side backup system renders the data to be preserved meaningless using a primary key and other primary transformation information, and the consortium-side backup system further distributes the meaningless data to nodes around the world using a secondary key and other secondary transformation information, modifies and distributes the recorded data, and creates, encrypts, and manages the index information of the distributed data, then, as long as the user-side primary key and other primary transformation information are not lost or destroyed, it becomes possible to restore the preserved data even if the primary key and other primary transformation information are stolen or the environment of the user-side backup system is destroyed. Furthermore, the consortium's evacuation system has a globally distributed physical environment, making it extremely difficult for state actors or other entities to destroy the entire environment even if they attack, thus enabling the protection of data necessary for restoration. Furthermore, by requiring both the primary key and other primary transformation information, as well as the secondary key and other secondary transformation information, for data recovery, it becomes possible to prevent data leakage by malicious third parties.

[0048] Furthermore, as in the digital asset guard service provision system of the present invention, "the user-side evacuation system further includes a comparison reference protected target data creation means that decodes the meaningless protected target data stored in a predetermined memory by the meaningless protected target data memory storage means to create protected target data with date and time information that serves as a comparison reference; a comparison reference protected target data storage means that stores the protected target data with date and time information that serves as a comparison reference created by the comparison reference protected target data creation means; and a check protected target data creation means that periodically causes the protected target data creation means to extract information to be protected from the original information with date and time information recorded in the relational database managed by the user to create protected target data with date and time information for checking. If the system is configured to include a "preservation target data identical date and time information data portion deviation check means" that, through the control of the data creation control means and the check-use preservation target data creation control means, compares the preservation target data with date and time information created by the preservation target data creation means with the data portion with the same date and time information in the comparison standard preservation target data with date and time information stored by the comparison standard preservation target data storage means, and checks whether there is a discrepancy in the data portion with the same date and time information between the check-use preservation target data with date and time information and the comparison standard preservation target data with date and time information, it becomes possible to check whether the function of extracting information to be preserved from the original information and creating preservation target data is contaminated.

[0049] Furthermore, if the digital asset guard service provision system of the present invention is configured to include "a data extraction function contamination notification means for data to be protected, which, as a result of a check by the data to be protected data with identical date and time information data portion deviation check means, determines that the data to be protected extraction function in the data to be protected

[0050] Furthermore, if the system is configured as the digital asset guard service provision system of the present invention, including "a memory-stored meaningless protected data erasure means that erases meaningless protected data stored in a predetermined memory by the meaningless protected data memory storage means after protected data with date and time information serving as a comparison standard has been stored by the comparison standard protected data storage means," the time that meaningless protected data remains in memory on the user's system can be made extremely short, making it easier to prevent malicious third parties from analyzing and leaking the data.

[0051] Furthermore, in the digital asset guard service provision system of the present invention, preferably, the means for checking whether there is a discrepancy in the data portion with identical date and time information of the protected data is configured to check whether there is a discrepancy in the data portion with identical date and time information between the protected data with date and time information for checking and the protected data with date and time information that serves as a comparison standard, by calculating the hash values ​​of the data portions with identical date and time information in the protected data with date and time information for checking and the protected data with date and time information that serves as a comparison standard, and comparing the calculated hash values. By using this method of comparing hash values, it becomes easier to determine whether or not there are discrepancies in the data portion.

[0052] Furthermore, the digital asset guard service provision system of the present invention preferably further comprises: a first hash value calculation means for calculating the hash value of the data portion other than the date and time information in the reference data to be protected with date and time information that serves as the comparison standard, which is stored in the reference data to be protected data storage means, as a first hash value; a first hash value storage means for storing the first hash value calculated by the first hash value calculation means; and a second hash value calculation means for calculating the hash value of the data portion of the data to be protected with date and time information for checking that has the same date and time information as the reference data to be protected with date and time information, as a second hash value; and the data portion discrepancy check means for data to be protected with the same date and time information that serves as the comparison standard is configured to check whether there is a discrepancy in the data portion with the same date and time information that serves as the comparison standard between the data to be protected with date and time information that serves as the comparison standard and the data to be protected with check.

[0053] In the digital asset guard service provision system of the present invention, if the second hash value calculated by the second hash value calculation means is compared with the first hash value stored by the first hash value storage means, it is not necessary to calculate the hash value of the data portion other than the date and time information in the data to be protected with date and time information attached for checking, which is stored in the comparison reference data to be protected, each time a comparison is made with the hash value of the data portion other than the date and time information attached to the data to be protected with check date and time information attached, and the comparison process can be made more efficient.

[0054] Furthermore, in the digital asset guard service provision system of the present invention, preferably, the means for rendering the protected data meaningless is configured to perform a predetermined encryption process and primary decomposition process on the protected data with date and time information created by the protected data creation means, based on a backup instruction for the protected data using a primary key or other primary conversion information received by the protected data backup instruction receiving means from a user, thereby converting it into a plurality of meaningless protected data; the means for storing the meaningless protected data meaningless is configured to store each of the meaningless protected data meaningless converted by the means for rendering the protected data meaningless in a predetermined memory; the means for uploading the meaningless protected data meaningless is configured to upload each of the meaningless protected data meaningless stored in the predetermined memory by the means for storing the meaningless protected data meaningless is configured to upload to a first provisional storage area; and the distributed file management group distribution means uploads to the first provisional storage area by the meaningless protected data upload means. Each uploaded data subject to be rendered meaningless and preserved is decomposed secondarily using the consortium's secondary key and other secondary transformation information, and distributed to multiple distributed file management groups constructed by the nodes of each location that constitute the planet set up by the consortium and recording devices of multiple locations that are network-connected to the nodes of said locations. The means for erasing uploaded data subject to be rendered meaningless and preserved is configured to erase each data subject to be rendered meaningless and preserved that has been uploaded to the first provisional storage area after the index information of the data distributed and recorded by the modification and distributed recording means has been recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption and recording means. The means for creating comparison reference data subject to be preserved is configured to decode and combine each data subject to be rendered meaningless and preserved stored in a predetermined memory by the meaningless data subject to be preserved memory storage means to create data subject to be preserved with date and time information that serves as a comparison reference. By configuring the system in such a way that the encrypted data to be protected is further decomposed on the user's side, it becomes more difficult for malicious third parties to analyze and leak the data.

[0055] Furthermore, in the digital asset guard service provision system of the present invention, preferably, a means for receiving instructions to restore protected data from users who wish to restore protected data; an encrypted index information extraction means for extracting encrypted index information recorded in a black box environment on a group of nodes at a specific location on the blockchain by the distributed record data index information creation, encryption, and recording means, based on a primary key and other primary transformation information from the user associated with the protected data with date and time information to be restored, and a secondary key and other secondary transformation information of the consortium; an index information decryption means for decrypting the encrypted index information extracted by the encrypted index information extraction means; and using the index information decrypted by the index information decryption means, the distributed file management group distribution means distributes the data to each of the distributed file management groups, and the respective nodes at each location belonging to each of the distributed file management groups are recorded by the respective modification and distributed recording means. A user-side recovery system comprising: data extraction means for extracting data distributed and recorded on multiple recording devices at multiple locations connected to a node at a base from either the node at each base belonging to the respective distributed file management group or from the multiple recording devices at multiple locations connected to the node at that base; download means for downloading the data extracted by the data extraction means to a second provisional storage area; data recovery means for restoring the data extracted by the data extraction means and downloaded to the second provisional storage area by the download means to data to be preserved with date and time information before backup; and download data erasure means for erasing the data downloaded to the second provisional storage area after it has been restored to data to be preserved with date and time information before backup by the data recovery means; and a user-side recovery system comprising: data recovery instruction receiving means, download means, data recovery means, and download data erasure means; and encryption index information extraction means, index information decryption means, and data extraction means.It is configured to include a consortium-side restoration system having [a certain feature]. With this configuration, as long as the primary key and other primary conversion information on the user's side are not lost or destroyed, it becomes possible to restore the preserved data even if the primary key and other primary conversion information are stolen or the environment of the user's backup system is destroyed.

[0056] Furthermore, in the digital asset guard service provision system of the present invention, preferably, a means for receiving instructions to delete protected data from users who wish to delete protected data; a means for extracting encrypted index information at the time of deletion, based on a primary key and other primary transformation information from the user associated with the protected data to be deleted, which has date and time information to be deleted, and a secondary key and other secondary transformation information from the consortium, by the distributed record data index information creation, encryption, and recording means; a means for decrypting the encrypted index information extracted by the encrypted index information extraction means; and a means for decrypting the index information at the time of deletion, which uses the decrypted index information by the decryption means to distribute it to each of the distributed file management groups by the distributed file management group distribution means, and each The system comprises a user-side deletion system having the aforementioned data deletion instruction receiving means, and a consortium-side deletion system having the aforementioned modification and distributed recording means, which are distributed and recorded on the nodes of each location belonging to each of the distributed file management groups and on recording devices at multiple locations connected to the nodes of those locations via a network, and which delete file data prior to a predetermined generation; a second file data deletion means that deletes encrypted index information recorded on a group of nodes at a specific location in the blockchain under a black box environment by the aforementioned distributed recording data index information creation, encryption, and recording means, based on the primary key and other primary conversion information from the user associated with the data to be deleted with date and time information received by the data deletion instruction receiving means, and the secondary key and other secondary conversion information of the consortium; and a second file data deletion means. With this configuration, it is possible to delete the meaningless data that is being managed in a distributed manner by the consortium's backup system. Furthermore, even if the meaningless data is recorded on the blockchain, deleting the index information makes it impossible to extract the meaningless data that has been distributed and recorded on the blockchain, thus achieving an effect equivalent to its effective deletion.

[0057] Furthermore, the present invention provides a digital asset guard service provision system for guarding digital assets from high-level cyberattacks, comprising a distributed ledger in blockchain or other distributed ledger technology, and a smart contract or server application for performing predetermined processing using data managed in the distributed ledger, and having a consortium-type blockchain constructed with multiple planets that constitute a single unit of the blockchain, each consisting of a group of nodes combining nodes in multiple locations in different regions around the world, and includes a means for creating protected target data that extracts information to be protected from original information with date and time information recorded in a relational database managed by the user and creates protected target data with date and time information, a means for receiving instructions to back up protected target data from a user who wishes to back up protected target data, and a means for receiving instructions to back up protected target data based on the instructions received by the protected target data back up instruction reception means using a first primary public key or other first primary public conversion information from the user, the protected target Meansless means for protecting data to be protected, which performs a predetermined encryption process on the data to be protected with date and time information created by the data creation means to convert it into meaningless data to be protected; Meansless data memory storage means for storing the meaningless data to be protected converted by the meansless means to be protected in a predetermined memory; Meansless data upload means for uploading the meaningless data to be protected stored in a predetermined memory by the meansless data memory storage means to a first provisional storage area; Meansless data index information creation means for creating data index information for protected data which has file name and upload date information in the data to be protected with date and time information created by the data creation means to be protected; Meansless data index information meaningless means for performing a predetermined encryption process on the data index information for protected data which is protected by the meansless means to be protected in meaningless data index information, which uses a second primary public key and other second primary public conversion information from the user received by the data backup instruction receiving means to be protected;A user-side backup system having a means for uploading meaningless data index information converted by the means for semanticizing data index information to be preserved to a first provisional storage area; a distributed file management group distribution means for distributing the meaningless data and meaningless data index information uploaded to the first provisional storage area by the means for uploading meaningless data and meaningless data index information to a multiple distributed file management group constructed by nodes at each location configured for the planet set up by the consortium and recording devices at multiple locations connected to the nodes at said locations via a network, using the secondary key and other secondary conversion information of the consortium; modifying the data distributed by the distributed file management group distribution means, and distributing the data that does not exceed the block size to multiple nodes of the distributed management file group provided on the blockchain, and the data that exceeds the block size to the block The consortium-side backup system includes: a modification and distributed recording means that distributes and records data to multiple nodes of a distributed file management group separate from the chain; a distributed recording data index information creation, encryption, and recording means that creates and encrypts index information of the data distributed and recorded by the modification and distributed recording means and records it on a specific node of the blockchain in a black box environment; and an upload meaningless preservation target data and meaningless preservation target data index information erasure means that erases the meaningless preservation target data and meaningless preservation target data index information that have been uploaded to a first provisional storage area after the index information of the data distributed and recorded by the modification and distributed recording means has been recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption, and recording means; and the user-side backup system further includes a comparison reference preservation target data creation means that decrypts the meaningless preservation target data stored in a predetermined memory by the meaningless preservation target data memory storage means and creates preservation target data with date and time information that serves as a comparison reference.A comparison standard data storage means for storing data to be preserved with date and time information that serves as a comparison standard, created by the comparison standard data creation means; a memory-stored meaningless data erasure means for erasing meaningless data to be preserved that is stored in a predetermined memory by the meaningless data memory storage means after the data to be preserved with date and time information that serves as a comparison standard has been stored by the comparison standard data storage means; a check data creation control means for periodically instructing the data to be preserved to extract information to be preserved from original information with date and time information recorded in a relational database managed by the user, and to create data to be preserved with date and time information for checking; and a comparison standard data storage means for storing data to be preserved with date and time information for checking that has been created by the data to be preserved, via the control of the check data creation control means. The system comprises: a means for checking whether there is a discrepancy in the data portion with the same date and time information of the data to be preserved, which is attached to a reference date and time information for comparison, and the data portion with the same date and time information of the data to be preserved, which is attached to a reference date and time information for comparison, and the means for notifying the user and the consortium that the data extraction function for information to be preserved in the data to be preserved is contaminated, when, as a result of the check by the means for checking whether there is a discrepancy in the data portion with the same date and time information of the data to be preserved, which is attached to a reference date and time information for comparison, the data to be preserved, which is attached to a data to be preserved, is contaminated, and the means for notifying the user and the consortium that the data extraction function for information to be preserved in the data to be preserved in the data to be preserved is contaminated.

[0058] As in the digital asset guard service provision system of the present invention, the user-side backup system includes: a means for creating a data to be protected index information which has file name and upload date information for the data to be protected with date and time information created by the data to be protected creation means; a means for demeaning the data to be protected index information which performs a predetermined encryption process on the data to be protected index information created by the data to be protected index information creation means using a second primary public key and other second primary public conversion information received from the user by the data to be protected backup instruction receiving means to convert it into demeaning the data to be protected index information; and a means for demeaning the data to be protected data which uploads the demeaning the data to be protected index information converted by the data to be protected index information to a first provisional storage area. The system has a "data index information upload means," and the distributed file management group distribution means of the consortium-side backup system is configured to "distribute the meaningless data to be preserved index information to multiple distributed file management groups along with the meaningless data to be preserved uploaded to the first provisional storage area" for distributed management. In cases where a user wishes to restore specific data from among the data to be preserved that are distributed and managed by the consortium-side backup system, even if the environment of the user-side backup system is destroyed, the system can extract the index information of the data to be preserved managed by the consortium-side backup system, restore it in the user-side restoration system, and display it in a list. This allows the user to select and restore specific data to be preserved from the index information of the data to be preserved that is displayed in the list.

[0059] Furthermore, in the digital asset guard service provision system of the present invention, preferably, the original information with date and time information is accompanied by data types for management according to the retention period set by the user, the data protection target creation means extracts the information to be protected from the original information with date and time information accompanied by data types, automatically assigns a counter to each data type of the extracted information to be protected, and adds a user code to distinguish the user, thereby creating data to be protected with date and time information, and the meaningless data protection target upload means creates a first upload ID to the first provisional storage area of ​​the meaningless data protection target using the information which has a user code attached and has a counter that is automatically assigned to each piece of information to be protected on a data type basis, and the first primary public key or other first primary public conversion information from the user, and the created first upload The system is configured to upload the data to be preserved by adding a Proload ID to the data to be preserved and uploading it to a first provisional storage area, the data to be preserved index information creation means creates data to be preserved index information which includes a user code and information which has a counter that is automatically assigned for each piece of information to be preserved, based on the data type, the data to be preserved index information upload means creates a second upload ID for the data to be preserved index information to the first provisional storage area using the information which includes a user code and information which has a counter that is automatically assigned for each piece of information to be preserved, based on the data type, and a second primary public key or other second primary public conversion information from the user, and to add the created second upload ID to the data to be preserved index information and upload it to the first provisional storage area.

[0060] With this configuration, users can restore index information of the data to be preserved, which has been backed up in the consortium's backup system, for each specific data type they wish to restore. This information can then be displayed as a list on the user's restoration system, and the user can select the specific data to be preserved from the displayed index information.

[0061] Furthermore, in the digital asset guard service provision system of the present invention, preferably, a means for receiving a user code and data type specification from a user who wishes to restore data to be protected; a means for instructing the download of all meaningless protected data index information corresponding to the user code and type, which is distributed and managed in the consortium-side backup system, using a second upload ID created using information that has a user code attached to it and has a counter automatically assigned for each piece of information to be protected, based on the data type, and a second primary public key or other second primary public conversion information from the user, which is received by the means for receiving a user code and a unit of data type; and a means for instructing the download of all meaningless protected data index information corresponding to the user code and type, which is distributed and managed in the consortium-side backup system; and based on the second primary secret key or other second primary secret conversion information from the user associated with the protected data with date and time information to be downloaded based on the download instruction by the means for downloading the meaningless protected data index information download, the distributed record data index information creation and encryption. - A first encrypted data index information extraction means for extracting encrypted data index information to be preserved and rendered meaningless, recorded in a black box environment on a group of nodes at a specific location in the blockchain using recording means; a first encrypted data index information decryption means for decrypting the encrypted data index information to be preserved and rendered meaningless, extracted by the first encrypted data index information extraction means; a data index information download means for downloading the data index information to be preserved and rendered meaningless, decrypted by the first encrypted data index information decryption means to a second provisional storage area; and a data index information restoration means for restoring the data index information to be preserved by performing semantic processing on the data index information to be preserved and rendered meaningless, downloaded to the second provisional storage area by the data index information download means, based on a second primary secret key and other second primary secret transformation information from the user.The system further comprises: an uploaded data restoration candidate data restoration list creation means that rearranges the data restoration index information restored by the data restoration index information means in a predetermined order on a counter to create a list of uploaded data restoration candidates; and an uploaded data restoration candidate data restoration list display means that displays the list of uploaded data restoration candidates created by the uploaded data restoration candidate data restoration list creation means to the user.

[0062] With this configuration, it becomes possible to restore index information of the data to be preserved, which has been backed up in the consortium's backup system, for each specific data type that the user wishes to restore, and display it as a list in the user's restoration system. From the displayed index information, it becomes possible to select the specific data to be preserved that the user wishes to restore.

[0063] Furthermore, in the digital asset guard service provision system of the present invention, preferably, a means for receiving selection and specification of data to be restored by a user who wishes to restore data to be restored, from a list of uploaded data to be restored that are candidates for restoration, as displayed by the Uploaded Restoration Candidate Data to be Restored List Display Means; a means for instructing the download of data to be restored that corresponds to the user code and type, which is distributed and managed in the consortium-side backup system, using a first upload ID created using information that has a user code attached to the data to be restored that the Restoration Desired Data to be Restored Selection and Specification Reception Means have, and which has a counter that is automatically numbered for each piece of information to be restored, with respect to the data type, and a first primary public key and other first primary public conversion information from the user; and a means for instructing the download of data to be restored that corresponds to the user code and type, which is distributed and managed in the consortium-side backup system, using a first primary private key from the user that is linked to the data to be restored that has date and time information, which is the data to be downloaded based on the download instruction from the means for the data to be restored. A second encryption data index information extraction means extracts encrypted data index information to be destroyed and preserved, which is recorded in a black box environment on a group of nodes at a specific location in the blockchain, based on other first primary secret transformation information and the consortium's secondary key and other secondary transformation information; a second encryption data index information decryption means decrypts the encrypted data index information to be destroyed and preserved, which is extracted by the second encryption data index information extraction means; and the data index information to be destroyed and preserved, which is decrypted by the second encryption data index information decryption means and distributed to each of the distributed file management groups by the distributed file management group distribution means, and distributed and recorded by each of the nodes at each location belonging to each of the distributed file management groups and recording devices at multiple locations connected to the nodes at said locations via a network, respectively.The system further comprises: a means for extracting meaningless data to be preserved, which extracts each meaningless data to be preserved from either the node of each location belonging to each of the distributed file management groups or the recording devices of multiple locations connected to the node of said location via a network; a means for downloading meaningless data to be preserved, which extracts each meaningless data to be preserved, which is extracted by the meaningless data to be preserved, which is downloaded by the meaningless data to be preserved, which is downloaded by the meaningless data to be preserved, which is then preserved with the date and time information from before the backup; and a means for erasing meaningless data to be preserved and meaningless data to be preserved, which is then downloaded to the second provisional storage area after the data has been restored to its original state with the date and time information from before the backup by the preserved data to be preserved. The system comprises: a user-side recovery system having a reception means, a means for instructing the download of the meaningless preserved data index information, a means for restoring the preserved data index information, a means for creating a list of uploaded preserved data candidates for restoration, a means for displaying the list of uploaded preserved data candidates for restoration, a means for receiving the desired preserved data selection / designation, a means for instructing the download of the preserved data, a means for restoring the preserved data, and a means for erasing the downloaded meaningless preserved data and meaningless preserved data index information; and a consortium-side recovery system having a first means for extracting encrypted meaningless preserved data index information, a first means for decrypting encrypted meaningless preserved data index information, a means for downloading meaningless preserved data index information, a second means for extracting encrypted meaningless preserved data index information, a second means for decrypting encrypted meaningless preserved data index information, a means for extracting meaningless preserved data, and a means for downloading meaningless preserved data.

[0064] With this configuration, it becomes possible to restore, for each specific data type that a user wishes to restore, the index information of the data to be preserved, which has been backed up in the consortium's backup system, and then, from the index information displayed in the user's restoration system, select the specific data to be preserved that the user wishes to restore, thereby restoring the data to be preserved that is managed in a distributed manner in the consortium's backup system.

[0065] Therefore, the digital asset guard service provision system of the present invention provides a digital asset guard service provision system that can strongly and efficiently protect important information such as confidential information and personal information from high-level cyberattacks and physical destruction, restore important information without it being stolen by a third party even if it is subjected to cryptographic analysis by a quantum computer or an EMP attack, quickly detect and restore backup information for protecting important information such as confidential information and personal information even if it is destroyed, and efficiently restore the desired protected information even if the index information of the protected information managed by the user is destroyed. The embodiments for carrying out the present invention will be described below with reference to the drawings.

[0066] First Embodiment Figure 1 is a schematic diagram illustrating an example of the overall configuration of a digital asset guard service provision system according to the first embodiment of the present invention. Figure 2 is a schematic diagram illustrating an example of the configuration of a means for creating data to be protected in the digital asset guard service provision system according to the first embodiment. Figure 3 is a schematic diagram illustrating an example of the configuration of a means for receiving instructions to back up data to be protected in the digital asset guard service provision system according to the first embodiment. Figure 4 is a schematic diagram illustrating an example of a means for rendering data to be protected meaningless in the digital asset guard service provision system according to the first embodiment. Figure 5 is a schematic diagram illustrating an example of a means for storing meaningless data to be protected in memory in the digital asset guard service provision system according to the first embodiment. Figure 6 is a schematic diagram illustrating an example of a means for uploading meaningless data to be protected in the user-side back-up system in the digital asset guard service provision system according to the first embodiment. Figure 7 is a schematic diagram illustrating an example of a means for distributing distributed file management groups in the consortium-side back-up system in the digital asset guard service provision system according to the first embodiment. Figure 8 is a schematic diagram illustrating an example of the configuration of the modification and distributed recording means provided in the consortium-side backup system of the digital asset guard service provision system according to the first embodiment. Figure 9 is a schematic diagram illustrating an example of the configuration of the distributed recording data index information creation, encryption, and recording means provided in the consortium-side backup system of the digital asset guard service provision system according to the first embodiment. Figure 10 is a schematic diagram illustrating an example of the configuration of the upload meaningless data preservation target data erasure means provided in the consortium-side backup system of the digital asset guard service provision system according to the first embodiment. Figure 11 is a schematic diagram illustrating an example of the configuration of the comparison standard preservation target data creation means provided in the user-side backup system of the digital asset guard service provision system according to the first embodiment. Figure 12 is a schematic diagram illustrating an example of the configuration of the comparison standard preservation data storage means provided in the user-side backup system of the digital asset guard service provision system according to the first embodiment.Figure 13 is a schematic diagram illustrating an example of the configuration of a means for erasing data to be stored in memory and rendered meaningless, provided in the user-side evacuation system of the digital asset guard service provision system according to the first embodiment. Figure 14 is a schematic diagram illustrating an example of the configuration of a means for creating data to be checked, provided in the user-side evacuation system of the digital asset guard service provision system according to the first embodiment. Figure 15 is a schematic diagram illustrating an example of the configuration of a means for checking whether there is a partial shift in data with identical date and time information for data to be stored, provided in the user-side evacuation system of the digital asset guard service provision system according to the first embodiment. Figure 16 is a schematic diagram illustrating an example of the configuration of a means for notifying contamination of data to be extracted, provided in the user-side evacuation system of the digital asset guard service provision system according to the first embodiment.

[0067] The first embodiment of the digital asset guard service provision system 1 is constructed with a distributed ledger in blockchain or other distributed ledger technology, and a smart contract or server application for performing predetermined processing using data managed in the distributed ledger. It has a consortium-type blockchain constructed with multiple planets, which are units that make up the blockchain, each consisting of a group of nodes combining nodes in multiple locations in different regions around the world. For example, as shown in Figure 1, it has a user-side evacuation system 10 and a consortium-side evacuation system 50.

[0068] User-side evacuation system 10 As shown in Figure 1, the user-side evacuation system 10 is configured to include a means for creating data to be preserved 11, a means for receiving instructions to evacuate data to be preserved 12, a means for rendering data to be preserved meaningless 13, a means for storing rendered data to be preserved in memory 14, and a means for uploading rendered data to be preserved meaningless 15.

[0069] Data creation method 11 for data to be preserved The data preservation target creation means 11 is configured, for example as shown in Figure 2, to extract information to be preserved from original information with date and time information recorded in a relational database managed by the user, and to create data to be preserved with date and time information.

[0070] Data to be preserved: Data evacuation instruction receiving means 12 The data backup instruction receiving means 12 is configured to receive backup instructions for data to be backed up from users who wish to back up data to be backed up, for example, as shown in Figure 3.

[0071] Means for rendering data to be preserved meaningless 13 The data to be preserved and rendered meaningless means 13 is configured, for example as shown in Figure 4, to perform a predetermined encryption process on the data to be preserved and with date and time information created by the data to be preserved and rendered meaningless, based on a data to be preserved and saved instruction from a user using a primary key or other primary conversion information received by the data to be preserved and saved instruction receiving means 12, and to convert it into meaningless data to be preserved and saved.

[0072] Meaningless data storage memory means 14 The data storage means 14 for data to be rendered meaningless and preserved is configured to store the data to be rendered meaningless and preserved, which has been transformed by the data to be preserved meaningless means 13, in a predetermined memory, as shown in Figure 5, for example.

[0073] Means of uploading data to be preserved by rendering it meaningless 15 The data to be preserved for meaninglessness upload means 15 is configured to upload the data to be preserved for meaninglessness, which is stored in a predetermined memory by the data to be preserved for meaninglessness memory storage means 14, to a first provisional storage area, as shown in Figure 6, for example.

[0074] Consortium-side evacuation system 50 As shown in Figure 1, the consortium-side evacuation system 50 is configured to include a distributed file management group distribution means 51, a modification and distributed recording means 52, a distributed recording data index information creation, encryption and recording means 53, and an upload-invalidation and preservation target data deletion means 54.

[0075] Distributed file management group distribution means 51 The distributed file management group distribution means 51 is configured, for example as shown in Figure 7, to distribute the data to be preserved for meaninglessness, which has been uploaded to the first provisional storage area by the data to be preserved for meaninglessness upload means 15, to multiple distributed file management groups, which are constructed using the nodes of each location that constitute a planet set up by the consortium and recording devices at multiple locations that are network-connected to the nodes of those locations, using the secondary key of the consortium and other secondary transformation information.

[0076] Modification / distributed recording means 52 The modification and distributed recording means 52 is configured, for example as shown in Figure 8, to modify the data distributed by the distributed file management group distribution means 51 and to distribute and record data that does not exceed the block size to multiple nodes of a distributed management file group established on the blockchain, and data that exceeds the block size to multiple nodes of a distributed file management group separate from the blockchain.

[0077] Distributed recording data index information creation, encryption, and recording means 53 The distributed recording data index information creation, encryption, and recording means 53 is configured, for example as shown in Figure 9, to create and encrypt index information for data distributed and recorded by the modification and distributed recording means 52, and to record it on a specific node of the blockchain in a black box environment.

[0078] Means of erasing data to be preserved by rendering the upload meaningless 54 The data erasure means 54 for data to be erased after the index information of the data to be recorded in a distributed manner by the modification and distributed recording means 52 has been recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption and recording means 53, as shown in Figure 10, is erased from the data to be erased after it has been uploaded to the first provisional storage area.

[0079] Here, in the digital asset guard service provision system 1 of the first embodiment, the user-side evacuation system 10 is further configured to include, as shown in Figure 1, a comparison standard data preservation target creation means 16, a comparison standard data preservation target storage means 17, a memory-stored meaningless preservation target data deletion means 18, a check preservation target data creation control means 19, a data partial shift presence or absence check means 20 for data preservation target data with same date and time information, and a preservation target data extraction function contamination notification means 21.

[0080] Comparison standard maintenance target data creation method 16 The comparison reference data creation means 16 is configured, for example as shown in Figure 11, to decode the meaningless data to be preserved stored in a predetermined memory by the meaningless data to be preserved memory storage means 15, and to create data to be preserved with date and time information that will serve as a comparison reference.

[0081] Data storage means 17 for data subject to comparison and preservation. The comparison standard preservation target data storage means 17 is configured to store preservation target data with date and time information that serves as a comparison standard, created by the comparison standard preservation target data creation means 16, as shown in Figure 12, for example.

[0082] Memory-stored data deletion means 18 The memory-stored meaningless data erasure means 18 is configured, for example as shown in Figure 13, to erase meaningless data stored in a predetermined memory by the meaningless data memory storage means 15 after the data to be preserved with date and time information that serves as a comparison standard has been stored by the comparison standard data storage means 17.

[0083] Maintenance data creation control means 19 for checking The maintenance target data creation control means 19 is configured, for example as shown in Figure 14, to periodically instruct the maintenance target data creation means 11 to extract information to be maintained from the original information with date and time information recorded in the relational database managed by the user, and to create maintenance target data with date and time information for checking. In this context, "regularly" could refer to things like daily or once a week.

[0084] Data to be preserved with same date and time information data partial discrepancy check method 20 The data portion discrepancy check means 20, for example as shown in Figure 15, checks for discrepancies in the data portion with identical date and time information of the data to be preserved, by having the data to be preserved with check date and time information created by the data to be preserved, via the control means 19 for creating the data to be preserved for checking, and comparing it with the data portion with identical date and time information of the data to be preserved, which is a reference data to be preserved, stored by the reference data to be preserved, and checking for discrepancies in the data portion with identical date and time information between the data to be preserved with check date and time information and the reference data to be preserved, which is a reference data to be preserved.

[0085] Contamination notification means 21 for data extraction function to protect data The data preservation target extraction function contamination notification means 21 is configured to notify users and the consortium that the data preservation target extraction function in the data preservation target creation means 11 is contaminated, for example, as shown in Figure 16, when, as a result of a check by the data preservation target data identical date and time information data portion shift check means 20, it is determined that there is a shift in the data portion with identical date and time information when the data preservation target data with date and time information used for checking is compared with the data preservation target data with date and time information used as a comparison standard.

[0086] Second Embodiment Figure 17 is a schematic diagram illustrating an example of the overall configuration of a digital asset guard service provision system according to a second embodiment of the present invention. Figure 18 is a schematic diagram illustrating an example of the configuration of a data partial misalignment check means for data with identical date and time information of data to be protected, provided in the user-side evacuation system of the digital asset guard service provision system according to the second embodiment.

[0087] The digital asset guard service provision system 1 of the second embodiment includes, for example, a means 20' for checking whether there is a partial data misalignment with the same date and time information of the data to be protected, as shown in Figure 17. The other configurations are substantially the same as those of the digital asset guard service provision system of the first embodiment.

[0088] Data to be preserved with same date and time information data partial discrepancy check method 20' The data portion discrepancy check means 20' for data to be preserved, for example as shown in Figure 18, calculates the hash values ​​of the data portions with the same date and time information in the data to be preserved with date and time information for checking and the data to be preserved with date and time information that serves as a comparison standard, and compares the calculated hash values ​​to check whether there is a discrepancy in the data portions with the same date and time information between the data to be preserved with date and time information for checking and the data to be preserved with date and time information that serves as a comparison standard.

[0089] Third Embodiment Figure 19 is a schematic diagram illustrating an example of the overall configuration of a digital asset guard service provision system according to a third embodiment of the present invention. Figure 20 is a schematic diagram illustrating an example of the configuration of a first hash value calculation means provided in the user-side backup system of the digital asset guard service provision system according to the third embodiment. Figure 21 is a schematic diagram illustrating an example of the configuration of a first hash value storage means provided in the user-side backup system of the digital asset guard service provision system according to the third embodiment. Figure 22 is a schematic diagram illustrating an example of the configuration of a second hash value calculation means provided in the user-side backup system of the digital asset guard service provision system according to the third embodiment. Figure 23 is a schematic diagram illustrating an example of the configuration of a data partial misalignment check means provided in the user-side backup system of the data to be protected with same date and time information.

[0090] The third embodiment of the digital asset guard service provision system 1 further includes, for example, a first hash value calculation means 22, a first hash value storage means 23, and a second hash value calculation means 24, as well as a means 20 for checking whether there is a data partial misalignment with same date and time information for the data to be protected. The other configurations are substantially the same as those of the digital asset guard service provision system of the first embodiment.

[0091] First hash value calculation means 22 The first hash value calculation means 22 is configured, for example as shown in Figure 20, to calculate the hash value of the data portion other than the date and time information in the data to be preserved with date and time information that serves as a comparison standard, which is stored by the data storage means 17, as the first hash value.

[0092] First hash value storage means 23 The first hash value storage means 23 is configured to store the first hash value calculated by the first hash value calculation means 21, for example, as shown in Figure 21.

[0093] Second hash value calculation means 24 The second hash value calculation means 24 is configured, for example as shown in Figure 22, to calculate the hash value of the portion of the data with the same date and time information as the reference date and time information of the data to be preserved with date and time information for checking, as the second hash value.

[0094] Data to be preserved with same date and time information data partial discrepancy check method 20” The data portion discrepancy check means 20 for data with identical date and time information attached to the data to be preserved is configured to check for discrepancies in the data portion with identical date and time information between the data to be preserved with date and time information attached to the comparison standard, as shown in Figure 23, for example.

[0095] Fourth Embodiment Figure 24 is a schematic diagram illustrating an example of the overall configuration of a digital asset guard service provision system according to the fourth embodiment of the present invention. Figure 25 is a schematic diagram illustrating an example of the configuration of a means for rendering protected data meaningless in the user-side backup system of the digital asset guard service provision system according to the fourth embodiment. Figure 26 is a schematic diagram illustrating an example of the configuration of a memory storage means for rendering protected data meaningless in the user-side backup system of the digital asset guard service provision system according to the fourth embodiment. Figure 27 is a schematic diagram illustrating an example of the configuration of an upload means for rendering protected data meaningless in the user-side backup system of the digital asset guard service provision system according to the fourth embodiment. Figure 28 is a schematic diagram illustrating an example of the configuration of a distributed file management group distribution means for the consortium-side backup system of the digital asset guard service provision system according to the fourth embodiment. Figure 29 is a schematic diagram illustrating an example of the configuration of an upload data meaningless protected data erasure means for the consortium-side backup system of the digital asset guard service provision system according to the fourth embodiment.

[0096] The fourth embodiment of the digital asset guard service provision system 1 includes, for example, a means for rendering the data to be preserved meaningless 13', a means for storing the rendered data to be preserved in memory 14', a means for uploading the rendered data to be preserved meaningless 15', a means for distributing the distributed file management group 51', a means for erasing the uploaded data to be rendered meaningless 54', and a means for creating comparison reference data to be preserved 16'. The other configurations are substantially the same as those of the digital asset guard service provision system of the first embodiment.

[0097] Means of rendering protected data meaningless 13' The data to be preserved demeaning means 13' is configured, for example as shown in Figure 25, to perform a predetermined encryption process and primary decomposition process on the data to be preserved with date and time information created by the data to be preserved creation means 11, based on a backup instruction for the data to be preserved from a user using a primary key or other primary conversion information received by the data to be preserved backup instruction receiving means 12, thereby converting it into multiple demeaning data to be preserved.

[0098] Meaningless Preservation Target Data Memory Storage Means 14' The data storage means 14' for data to be rendered meaningless and preserved is configured to store each piece of data to be rendered meaningless and preserved, which has been transformed by the data to be preserved meaningless means, in a predetermined memory, as shown in Figure 26, for example.

[0099] Meaningless data preservation target data upload method 15' The data to be preserved for meaninglessness upload means 15' is configured to upload each data to be preserved for meaninglessness, which is stored in a predetermined memory by the data to be preserved for meaninglessness memory storage means 14', to a first provisional storage area, as shown in Figure 27, for example.

[0100] Distributed file management group distribution means 51' The distributed file management group distribution means 51' is configured, for example as shown in Figure 28, to decompose each piece of data to be demeaning and preserved, uploaded to the first provisional storage area by the data to be demeaning and preserved by the data to be demeaning and preserved by the data upload means 15' into secondary decomposition using the consortium's secondary key and other secondary transformation information, and to distribute it to multiple distributed file management groups constructed by the nodes of each location that constitute the planet set up by the consortium and the recording devices of multiple locations that are network-connected to the nodes of those locations.

[0101] Upload meaningless data preservation target data deletion means 54' The data erasure means 54' for uploading data to be rendered meaningless is configured to erase each piece of data to be rendered meaningless after the index information of the data distributed and recorded by the modification and distributed recording means 52 has been recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption and recording means 53, as shown in Figure 29.

[0102] Comparison standard maintenance target data creation means 16' The comparison reference data creation means 16' is configured, for example as shown in Figure 30, to decode and combine each of the meaningless data to be preserved stored in a predetermined memory by the meaningless data to be preserved memory storage means 14' to create data to be preserved with date and time information that will serve as a comparison reference.

[0103] Other configurations common to the digital asset guard service provision system according to the first to fourth embodiments of the present invention In addition, the digital asset guard service provision system 1 according to the first to fourth embodiments is further configured to include a user-side restoration system 30, a consortium-side restoration system 60, a user-side deletion system 40, and a consortium-side deletion system 70, as shown in Figure 1.

[0104] User-side recovery system 30 The user-side recovery system 30 is configured, for example, as shown in Figure 31, to include a data recovery instruction receiving means 31, a download means 32, a data recovery means 33, and a downloaded data deletion means 34.

[0105] Data recovery instruction receiving means 31 The data restoration instruction receiving means 31 is configured to receive instructions for the restoration of data to be preserved from users who wish to have the data to be preserved restored, as shown in Figure 32, for example.

[0106] Download method 32 The download means 32 is configured to download each piece of data extracted by the data extraction means 63 to a second provisional storage area, as shown in Figure 33, for example.

[0107] Data recovery means 33 for data to be preserved The data recovery means 33 is configured to restore each piece of data extracted by the data extraction means 63 and downloaded to the second temporary storage area by the download means 32, as shown in Figure 34, to the data to be recovered with the date and time information before backup.

[0108] Download data deletion method 34 The downloaded data erasure means 34 is configured to erase each of the data that has been downloaded to the second provisional storage area after being restored to the data to be preserved with the date and time information before backup by the data to be preserved means 33, as shown in Figure 35.

[0109] Consortium-side restoration system 60 The consortium-side recovery system 60 is configured, for example, as shown in Figure 36, to include an encrypted index information extraction means 61, an index information decryption means 62, and a data extraction means 63.

[0110] Encryption index information extraction means 61 The encrypted index information extraction means 61 is configured, for example as shown in Figure 37, to extract encrypted index information recorded in a black-box environment on a group of nodes at a specific location in the blockchain by the distributed record data index information creation, encryption, and recording means 53, based on the primary key and other primary transformation information from the user associated with the data to be restored, which has date and time information to be restored and has been received by the data restoration instruction receiving means 31, and the consortium's secondary key and other secondary transformation information.

[0111] Index information decoding means 62 The index information decryption means 62 is configured to decrypt the encrypted index information extracted by the encrypted index information extraction means 61, for example, as shown in Figure 38.

[0112] Data extraction means 63 The data extraction means 63 is configured to extract data from either the node at each location belonging to each distributed file management group or the recording device at multiple locations connected to the node at each location, which is distributed and recorded by the respective modification and distributed recording means 52, using the index information decoded by the index information decoding means 62, for example as shown in Figure 39. The data is distributed and recorded by the respective modification and distributed recording means 52, which is distributed to the nodes at each location belonging to each distributed file management group and to recording devices at multiple locations connected to the nodes at each location.

[0113] User-side deletion system 40 The user-side deletion system 40 is configured to include, for example, a means 41 for receiving instructions to delete data to be preserved, as shown in Figure 40.

[0114] Data Deletion Instruction Reception Means 41 The data deletion instruction receiving means 41 is configured to receive instructions from users who wish to delete data to be preserved, for example, as shown in Figure 41.

[0115] Consortium-side deletion system 70 The consortium-side deletion system 70 is configured, for example, as shown in Figure 42, to include a means for extracting encrypted index information during deletion processing 71, a means for decrypting index information during deletion processing 72, a means for deleting file data 73, and a second means for deleting file data 74.

[0116] Deletion process encryption index information extraction means 71 The encryption index information extraction means 71 during deletion processing is configured, for example as shown in Figure 43, to extract encrypted index information recorded in a black-box environment on a group of nodes at a specific location in the blockchain by the distributed record data index information creation, encryption, and recording means 53, based on the primary key and other primary transformation information from the user associated with the data to be deleted, which has date and time information to be received by the data deletion instruction receiving means 41, and the secondary key and other secondary transformation information from the consortium.

[0117] Deletion process index information decryption means 72 The decryption of index information during deletion, as shown in Figure 44, for example, is configured to decrypt the encrypted index information extracted by the encrypted index information extraction means 71 during deletion.

[0118] File data deletion means 73 The file data deletion means 73 is configured to delete file data from a predetermined generation or earlier, for example, as shown in Figure 45, which is distributed to each distributed file management group by the distributed file management group distribution means 51 using the index information decoded by the deletion process

[0119] Second file data deletion means 74 The second file data deletion means 74 is configured, for example as shown in Figure 46, to delete encrypted index information, which is recorded in a black box environment on a group of nodes at a specific location in the blockchain by the distributed record data index information creation, encryption, and recording means 53, based on the primary key and other primary transformation information from the user associated with the data to be deleted, which has date and time information to be deleted and has been received by the data to be deleted instruction receiving means 41, and the secondary key and other secondary transformation information from the consortium.

[0120] The processing flow and other details using the digital asset guard service provision system 1 configured in this way will be explained with reference to the drawings as appropriate. For convenience, the processing flow using the digital asset guard service provision system 1 of the first embodiment will be explained here, and the digital asset guard service provision system 1 of the second to fourth embodiments will be explained as appropriate when specific processing occurs.

[0121] (S1) Basic processing flow - Maintenance processing (Figures 47-49) (S1-1) Receipt of instructions to back up data to be preserved (Figure 47) The data backup instruction receiving means 12 receives backup instructions for data to be backed up from users who wish to back up the data to be backed up.

[0122] (S1-2) Creation of data to be preserved (Figure 47) The data preservation target creation means 11 extracts information to be preserved from the original information with date and time information recorded in the relational database managed by the user, and creates data to be preserved with date and time information.

[0123] (S1-3) De-emphasizing the meaning of data to be preserved (Figure 47) The data to be preserved is rendered meaningless by the means 13, based on a backup instruction for the data to be preserved from a user using a primary key or other primary conversion information received by the data to be preserved backup instruction receiving means 12, by performing a predetermined encryption process on the data to be preserved with date and time information created by the data to be preserved creation means 11, thereby converting it into meaningless data to be preserved.

[0124] (S1-4) Memory storage of data to be preserved by rendering it meaningless (Figure 47) The data to be preserved and rendered meaningless memory storage means 14 stores the data to be preserved and rendered meaningless, which has been converted by the data to be preserved and rendered meaningless means 13, in a predetermined memory.

[0125] (S1-5) Uploading data to be preserved by rendering it meaningless (Figure 47) The data to be preserved for meaninglessness upload means 15 uploads the data to be preserved for meaninglessness, which is stored in a predetermined memory by the data to be preserved for meaninglessness memory storage means 14, to a first provisional storage area.

[0126] (S1-6) Distribution to distributed file management groups (Figure 48) The distributed file management group distribution means 51 distributes the data to be preserved for meaninglessness, which has been uploaded to the first provisional storage area by the data to be preserved for meaninglessness upload means 15, to multiple distributed file management groups, which are constructed using the consortium's secondary key and other secondary transformation information, and consist of nodes at each location that constitute a planet set up by the consortium and recording devices at multiple locations that are network-connected to the nodes at said locations.

[0127] (S1-7) Modified and distributed records (Figure 48) The modification and distributed recording means 52 modifies the data distributed by the distributed file management group distribution means 51, and distributes and records the data that does not exceed the block size to multiple nodes of the distributed management file group established on the blockchain, and the data that exceeds the block size to multiple nodes of a distributed file management group separate from the blockchain.

[0128] (S1-7) Creation, encryption, and recording of distributed record data index information (Figure 48) The distributed recording data index information creation, encryption, and recording means 53 creates and encrypts index information for data distributed and recorded by the modification and distributed recording means 52, and records it on a specific node of the blockchain in a black box environment.

[0129] (S1-8) Deletion of data to be preserved by rendering the upload meaningless (Figure 49) The data erasure means 54 for data to be erased for uploading after the index information of the data to be recorded in a distributed manner by the modification and distributed recording means 52 has been recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption and recording means 53 has been erased from the data to be erased for uploading after it has been uploaded to the first provisional storage area.

[0130] (S2) Basic processing flow specific to the present invention - Maintenance processing (Figure 50) In each embodiment of the present invention, the digital asset guard service provision system 1 performs the following processing in parallel with the process from memory storage of data to be preserved by rendering it meaningless (Figure 47) to uploading the data to be preserved by rendering it meaningless (Figure 47).

[0131] (S2-1) Creation of comparative standard maintenance target data (Figure 50) The comparison reference data creation means 16 decodes the meaningless data to be preserved stored in a predetermined memory by the meaningless data to be preserved memory storage means 15, and creates data to be preserved with date and time information that will serve as a comparison reference.

[0132] (S2-2) Storage of data subject to comparative standard preservation (Figure 50) The comparison standard data storage means 17 stores the data to be preserved, which includes date and time information and serves as a comparison standard, created by the comparison standard data creation means 16.

[0133] (S2-3) Deletion of data to be preserved by rendering it meaningless in memory (Figure 50) The data erasure means 18 for data to be erased from memory after the data to be erased from memory has been stored by the comparison reference data storage means 17, and the data to be erased from memory has been erased by the data to be erased from memory 15.

[0134] (S3) Periodic processing flow - Contamination check process for data extraction target to be preserved (Figure 51) (S3-1) Control of creation of maintenance target data for checking (Figure 51) The maintenance target data creation control means 19 periodically causes the maintenance target data creation means 11 to extract information to be maintained from the original information with date and time information recorded in the relational database managed by the user, and to create maintenance target data with date and time information for checking.

[0135] (S3-2) Checking for discrepancies in the data portion with same date and time information for the data subject to preservation (Figure 51) The data portion discrepancy check means 20, via the control of the data creation control means 19 for checking the data to be preserved, compares the data portion with the same date and time information in the data to be preserved that has been created by the data creation means 11 for checking the data to be preserved, with the data portion with the same date and time information in the data to be preserved that has

[0136] (S3-3) Contamination notification function for data to be preserved (Figure 51) The data extraction function contamination notification means 21 determines that the data extraction function for data to be preserved in the data creation means 11 is contaminated when, as a result of the check by the data portion shift check means 20 for data portion shift with identical date and time information for data to be preserved is found to be shifted when the data to be preserved with date and time information used for checking is compared with the data to be preserved with date and time information used as a comparison standard. The means 21 notifies the user and the consortium that the data extraction function for data to be preserved in the data creation means 11 is contaminated. Figure 101 shows an overall flow diagram of the contamination check process for the data to be preserved in the preservation process using the asset guard service provision system 1 of the first embodiment.

[0137] (S4) Processing flow specific to the digital asset guard service provision system 1 of the second embodiment (Figure 52) In the digital asset guard service providing system 1 of the second embodiment, the check for deviation in the data portion with the same date and time information of the data to be protected in the check process for the presence or absence of contamination in the regular processing flow - data extraction function for the data to be protected is performed as follows.

[0138] (S4-1) Checking for discrepancies in the data portion with the same date and time information for the data to be preserved (Figure 52) The means 20' for checking the deviation in the data portion with the same date and time information of the data to be protected calculates the hash values of the data portions with the same date and time information in the data to be protected with date and time information for checking and the data to be protected with date and time information as the comparison reference respectively, and checks the presence or absence of deviation in the data portion with the same date and time information between the data to be protected with date and time information for checking and the data to be protected with date and time information as the comparison reference by comparing the calculated hash values. The creation control of the data to be protected for checking and the contamination notification of the data extraction function for the data to be protected are substantially the same as the processes in the regular processing flow - check process for the presence or absence of contamination in the data extraction function for the data to be protected (Fig. 51) of the digital asset guard service providing system 1 of the first embodiment. The flow of other processes is substantially the same as the flow of the basic processes (Figs. 47 to 50) of the digital asset guard service providing system 1 of the first embodiment.

[0139] (S5) Processing flow specific to the digital asset guard service provision system 1 of the third embodiment (Figure 53) In the digital asset guard service providing system 1 of the third embodiment, the check process for the presence or absence of contamination in the regular processing flow - data extraction function for the data to be protected is performed as follows.

[0140] (S5-1) Calculation of the first hash value (Figure 53) The first hash value calculation means 22 calculates the hash value of the data portion other than the date and time information in the data to be protected with date and time information as the comparison reference stored by the comparison reference data to be protected storage means 17 as the first hash value.

[0141] (S5-2) Storage of the first hash value (Figure 53) The first hash value storage means 23 stores the first hash value calculated by the first hash value calculation means 21.

[0142] (S5-3) Calculation of the second hash value (Figure 53) The second hash value calculation means 24 calculates, as the second hash value, the hash value of the data portion with the same date and time information as the preservation target data with date and time information for comparison in the preservation target data with date and time information for checking.

[0143] (S5-4) Checking for discrepancies in the data portion with same date and time information for the data to be preserved (Figure 53) The means 20” for checking the presence or absence of deviation in the data portion with the same date and time information of the preservation target data checks the presence or absence of deviation in the data portion with the same date and time information between the preservation target data with date and time information for comparison in the preservation target data with date and time information for checking and the preservation target data with date and time information for comparison by comparing the second hash value calculated by the second hash value calculation means 23 with the first hash value stored by the first hash value storage means 22. The creation control of the preservation target data for checking and the contamination notification of the preservation target data extraction function are substantially the same as the processes in the process flow - check for the presence or absence of contamination of the preservation target data extraction function (Fig. 51) of the digital asset guard service providing system 1 of the first embodiment. The flow of other processes is substantially the same as the basic process flow (Figs. 47 to 50) of the digital asset guard service providing system 1 of the first embodiment.

[0144] (S6) Processing flow in the digital asset guard service provision system 1 of the fourth embodiment (Figures 54-55) In the digital asset guard service providing system 1 of the fourth embodiment, the process in the basic process flow - preservation process is performed as follows.

[0145] (S6-1) De-empowering data to be preserved (Figure 54) The data to be preserved is rendered meaningless by means of means 13', based on a backup instruction for data to be preserved from a user using a primary key or other primary conversion information received by the data to be preserved backup instruction receiving means 12, by performing a predetermined encryption process and primary decomposition process on the data to be preserved with date and time information created by the data to be preserved creation means 11, thereby converting it into multiple meaningless data to be preserved.

[0146] (S6-2) Memory storage of data to be preserved by rendering it meaningless (Figure 54) The data to be preserved and rendered meaningless memory storage means 14' stores each of the data to be preserved and rendered meaningless, which has been converted by the data to be preserved and rendered meaningless, in a predetermined memory.

[0147] (S6-3) Uploading data to be preserved by rendering it meaningless (Figure 54) The data to be preserved for meaninglessness upload means 15' uploads each data to be preserved for meaninglessness, which is stored in a predetermined memory by the data to be preserved for meaninglessness memory storage means 14', to the first provisional storage area.

[0148] (S6-4) Distribution to distributed file management groups (Figure 55) The distributed file management group distribution means 51' decomposes each piece of data to be demeaning and preserved, uploaded to the first provisional storage area by the data to be demeaning and preserved upload means 15', using the consortium's secondary key and other secondary transformation information, and distributes it to multiple distributed file management groups, which are constructed by the nodes of each location that constitute the planet set up by the consortium and the recording devices of multiple locations that are network-connected to the nodes of those locations.

[0149] (S6-5) Deletion of data to be preserved by rendering the upload meaningless (Figure 55) The data erasure means 54' for data to be erased after the index information of the data to be recorded in a distributed manner by the modification and distributed recording means 52 has been recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption and recording means 53, has been erased from the first provisional storage area. The flow of other basic processes - The flow of processes in the preservation process is substantially the same as the flow of processes (Figs. 47 to 49) in the digital asset guard service providing system 1 of the first embodiment. Also, the flow of other periodic processes is substantially the same as the flow of periodic processes (Fig. 51) in the digital asset guard service providing system 1 of the first embodiment.

[0150] (S7) Processing flow specific to the digital asset guard service provision system 1 of the fourth embodiment (Figure 56) Also, in the digital asset guard service providing system 1 of the fourth embodiment, the flow of basic processes - preservation processes unique to the present invention is performed as follows.

[0151] (S7-1) Creation of comparative standard maintenance target data (Figure 56) The comparison criterion preservation target data creation means 16' decrypts and combines each meaningless preservation target data stored in a predetermined memory by the meaningless preservation target data memory storage means 14' to create preservation target data with date and time information serving as a comparison criterion. The flow of other basic processes - the flow of processes in the preservation process unique to the present invention is substantially the same as the flow of processes (Y4) in the digital asset guard service providing system 1 of the first embodiment.

[0152] (S8) Other processing flow common to the digital asset guard service provision system 1 of the first to fourth embodiments (Figures 57 to 61) (S8A) Data recovery process for data to be preserved (Figures 57-59) (S8A-1) Receipt of instructions for data restoration target (Figure 57) The preservation target data restoration instruction reception means 31 receives a restoration instruction for the preservation target data from a user who desires the restoration of the preservation target data.

[0153] (S8A-2) Extraction of encrypted index information (Figure 58) The encrypted index information extraction means 61 extracts encrypted index information recorded in a black-box environment on a group of nodes at a specific location on the blockchain by the distributed record data index information creation, encryption, and recording means 53, based on the primary key and other primary transformation information from the user associated with the data to be restored, which has date and time information to be restored and has been received by the data restoration instruction receiving means 31, and the secondary key and other secondary transformation information from the consortium.

[0154] (S8A-3) Decoding of index information (Figure 58) The index information decryption means 62 decrypts the encrypted index information extracted by the encrypted index information extraction means 61.

[0155] (S8A-4) Data extraction (Figure 58) The data extraction means 63 uses the index information decoded by

[0156] (S8A-5) Download (Figure 59) The download means 32 downloads each piece of data extracted by the data extraction means 63 to a second provisional memory area.

[0157] (S8A-6) Restoration of data to be preserved (Figure 59) The data recovery means 33 restores each of the data extracted by the data extraction means 63 and downloaded to the second provisional storage area by the download means 32 to the data to be recovered with the date and time information from before the backup.

[0158] (S8A-7) Deleting downloaded data (Figure 59) The downloaded data erasure means 34 erases each of the data that was downloaded to the second provisional storage area after being restored to the data to be preserved with the date and time information before backup by the data to be preserved data restoration means 33.

[0159] (S8B) Data deletion process for data to be preserved (Figures 60-61) (S8B-1) Receipt of instruction to delete data subject to preservation (Figure 60) The data deletion instruction receiving means 41 receives instructions from users who wish to delete data subject to preservation.

[0160] (S8B-2) Extraction of encrypted index information during deletion process (Figure 61) The deletion-processing encrypted index information extraction means 71 extracts encrypted index information, which is recorded in a black-box environment on a group of nodes at a specific location in the blockchain, by the distributed record data index information creation, encryption, and recording means 53, based on the primary key and other primary transformation information from the user associated with the data to be deleted with date and time information received by the data deletion instruction receiving means 41, and the secondary key and other secondary transformation information from the consortium.

[0161] (S8B-3) Decryption of index information during deletion process (Figure 61) The decryption-time index information decryption means 72 decrypts the encrypted index information extracted by the decryption-time encrypted index information extraction means 71.

[0162] (S8B-4) Deleting file data (Figure 61) The file data deletion means 73 uses the index information decoded by the deletion process index information decoded by the deletion process index information decoded by the 72 to delete file data of a predetermined generation or earlier, which has been distributed to each distributed file management group by the distributed file management group distribution means 51, and has been distributed and recorded by each modification and distributed recording means 52 to the nodes of each location belonging to each distributed file management group and to recording devices at multiple locations connected to the nodes of those locations via a network.

[0163] (S8B-5) Deletion of the second file data (Figure 61) The second file data deletion means 74 deletes the encrypted index information, which is recorded in a black box environment on a group of nodes at a specific location on the blockchain, by the distributed record data index information creation, encryption, and recording means 53, based on the primary key and other primary transformation information from the user associated with the data to be deleted with date and time information received by the data deletion instruction receiving means 41, and the secondary key and other secondary transformation information from the consortium.

[0164] Fifth Embodiment Figure 62 is a schematic diagram illustrating an example of the overall configuration of a digital asset guard service provision system according to the fifth embodiment of the present invention. Figure 63 is a schematic diagram illustrating an example of the configuration of a means for rendering protected data meaningless in the user-side backup system of the digital asset guard service provision system according to the fifth embodiment. Figure 64 is a schematic diagram illustrating an example of the configuration of a means for creating protected data index information in the user-side backup system of the digital asset guard service provision system according to the fifth embodiment. Figure 65 is a schematic diagram illustrating an example of the configuration of a means for rendering protected data index information meaningless in the user-side backup system of the digital asset guard service provision system according to the fifth embodiment. Figure 66 is a schematic diagram illustrating an example of the configuration of a means for uploading meaningless protected data index information in the user-side backup system of the digital asset guard service provision system according to the fifth embodiment. Figure 67 is a schematic diagram illustrating an example of the configuration of a distributed file management group distribution means in the consortium-side backup system of the digital asset guard service provision system according to the fifth embodiment. Figure 68 is a schematic diagram illustrating an example of the configuration of the means for erasing the meaningless data to be preserved and the meaningless data to be preserved index information in the consortium-side backup system of the digital asset guard service provision system according to the fifth embodiment. Figure 69 is a schematic diagram illustrating an example of the data structure of the original information with date and time information in the digital asset guard service provision system according to the fifth embodiment. Figure 70 is a schematic diagram illustrating an example of the configuration of the means for creating data to be preserved in the user-side backup system of the digital asset guard service provision system according to the fifth embodiment. Figure 71 is a schematic diagram illustrating an example of the configuration of the means for uploading meaningless data to be preserved in the user-side backup system of the digital asset guard service provision system according to the fifth embodiment. Figure 72 is a schematic diagram illustrating an example of the configuration of the means for creating data to be preserved index information in the user-side backup system of the digital asset guard service provision system according to the fifth embodiment.Figure 73 is a schematic diagram illustrating an example of the configuration of the data index information upload means for meaningless data to be preserved, provided in the user-side evacuation system of the digital asset guard service provision system according to the fifth embodiment. Figure 74 is a schematic diagram illustrating an example of the overall configuration of the user-side restoration system of the digital asset guard service provision system according to the fifth embodiment of the present invention. Figure 75 is a schematic diagram illustrating an example of the configuration of the data type to be restored receiving means for the user-side restoration system of the digital asset guard service provision system according to the fifth embodiment. Figure 76 is a schematic diagram illustrating an example of the configuration of the data index information download instruction means for meaningless data to be preserved, provided in the user-side restoration system of the digital asset guard service provision system according to the fifth embodiment. Figure 77 is a schematic diagram illustrating an example of the configuration of the data index information restoration means for the user-side restoration system of the digital asset guard service provision system according to the fifth embodiment. Figure 78 is a schematic diagram illustrating an example of the configuration of the uploaded data restoration candidate data list creation means for the user-side restoration system of the digital asset guard service provision system according to the fifth embodiment. Figure 79 is a schematic diagram illustrating an example of the configuration of an uploaded data recovery candidate data recovery list display means in the user-side recovery system of the digital asset guard service provision system according to the fifth embodiment. Figure 80 is a schematic diagram illustrating an example of the configuration of a data recovery desired data selection / designation reception means in the user-side recovery system of the digital asset guard service provision system according to the fifth embodiment. Figure 81 is a schematic diagram illustrating an example of the configuration of a data recovery instruction means in the user-side recovery system of the digital asset guard service provision system according to the fifth embodiment. Figure 82 is a schematic diagram illustrating an example of the configuration of a data recovery means in the user-side recovery system of the digital asset guard service provision system according to the fifth embodiment.Figure 83 is a schematic diagram illustrating an example of the configuration of the downloadable data to be rendered meaningless and protected, and the data index information erasure means provided in the user-side restoration system of the digital asset guard service provision system according to the fifth embodiment. Figure 84 is a schematic diagram illustrating an example of the overall configuration of the consortium-side restoration system of the digital asset guard service provision system according to the fifth embodiment of the present invention. Figure 85 is a schematic diagram illustrating an example of the configuration of the first encrypted data to be rendered meaningless and protected data index information extraction means provided in the consortium-side restoration system of the digital asset guard service provision system according to the fifth embodiment. Figure 86 is a schematic diagram illustrating an example of the configuration of the first encrypted data to be rendered meaningless and protected data index information decryption means provided in the consortium-side restoration system of the digital asset guard service provision system according to the fifth embodiment. Figure 87 is a schematic diagram illustrating an example of the configuration of the data to be rendered meaningless and protected data index information download means provided in the consortium-side restoration system of the digital asset guard service provision system according to the fifth embodiment. Figure 88 is a schematic diagram illustrating an example of the configuration of a second encryption-decryption-preservation-target data index information extraction means provided in the consortium-side restoration system in the digital asset guard service provision system according to the fifth embodiment. Figure 89 is a schematic diagram illustrating an example of the configuration of a second encryption-decryption-preservation-target data index information decryption means provided in the consortium-side restoration system in the digital asset guard service provision system according to the fifth embodiment. Figure 90 is a schematic diagram illustrating an example of the configuration of a data extraction means for meaningless data preservation-target data provided in the consortium-side restoration system in the digital asset guard service provision system according to the fifth embodiment. Figure 91 is a schematic diagram illustrating an example of the configuration of a data download means for meaningless data preservation-target data provided in the consortium-side restoration system in the digital asset guard service provision system according to the fifth embodiment.

[0165] The digital asset guard service provision system 1 according to the fifth embodiment is configured to include, for example, a user-side evacuation system 110, a consortium-side evacuation system 150, a user-side restoration system 130, and a consortium-side restoration system 160, as shown in Figure 62.

[0166] The user-side evacuation system 110 is configured to include a means for creating data to be preserved 11, a means for receiving instructions to evacuate data to be preserved 12, a means for rendering data to be preserved meaningless 113, a means for storing rendered data to be preserved in memory 14, a means for uploading rendered data to be preserved meaningless 15, a means for creating data index information to be preserved 125, a means for rendering data index information to be preserved meaningless 126, and a means for uploading rendered data index information to be preserved meaningless 127.

[0167] Means for rendering data to be preserved meaningless 113 The data to be preserved and rendered meaningless means 113 is configured, for example as shown in Figure 63, to perform a predetermined encryption process on the data to be preserved with date and time information created by the data to be preserved and rendered meaningless, based on a data to be preserved and saved instruction from a user using a first primary public key or other first primary public conversion information received by the data to be preserved and saved instruction receiving means 12, and to convert it into meaningless data to be preserved and saved.

[0168] Data index information creation means 125 for data to be preserved The data to be preserved index information creation means 125 is configured to create data to be preserved index information that includes the file name and upload date information of the data to be preserved with date and time information created by the data to be preserved creation means 11, for example, as shown in Figure 64.

[0169] Means for rendering meaningless data index information of data to be preserved 126 The data index information de-meaninglessness means 126 is configured, for example as shown in Figure 65, to convert the data index information to be preserved created by the data index information creation means 11 into de-meaningless data index information by performing a predetermined encryption process using a second primary public key and other second primary public conversion information received by the data backup instruction receiving means 12 from the user.

[0170] Meansless preservation target data index information upload means 127 The meaningless data to be preserved data index information upload means 127 is configured to upload the meaningless data to be preserved data index information converted by the preserved data index information semantics means 126 to a first provisional storage area, as shown in Figure 66, for example.

[0171] The consortium-side evacuation system 150 is configured to include a distributed file management group allocation means 151, a modification and distributed recording means 52, a distributed recording data index information creation, encryption and recording means 53, and an upload meaningless data preservation target data meaningless data preservation target data deletion means 154.

[0172] Distributed file management group distribution means 151 The distributed file management group distribution means 151 is configured, for example as shown in Figure 67, to distribute the data to be preserved for meaninglessness and the index information of the data to be preserved for meaninglessness, which have been uploaded to the first provisional storage area by the data to be preserved for meaninglessness and the data index information of the data to be preserved for meaninglessness, to multiple distributed file management groups constructed by the nodes of each location that constitute a planet set up by the consortium and the recording devices of multiple locations that are network-connected to the nodes of those locations, using the secondary key of the consortium and other secondary transformation information.

[0173] Means for erasing uploaded data and index information of data to be erased The upload meaningless data preservation target data and meaningless data preservation target data index information erasure means 154 is configured to erase the meaningless data preservation target data and meaningless data preservation target data index information that have been uploaded to the first provisional storage area, after the index information of the data distributed and recorded by the modification and distributed recording means 52 has been recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption and recording means 53, as shown in Figure 68, for example.

[0174] As shown in Figure 62, the user-side evacuation system 110 is further configured in substantially the same manner as the user-side evacuation system 10 in the first embodiment of the digital asset guard service provision system 1, comprising: comparison standard data preservation target creation means 16; comparison standard data preservation target storage means 17; memory-stored meaningless preservation target data deletion means 18; check preservation target data creation control means 19; preservation target data data with same date and time information data partial shift presence or absence check means 20; and preservation target data extraction function contamination notification means 21.

[0175] Furthermore, in the digital asset guard service provision system 1 according to the fifth embodiment, for example, as shown in Figure 69, the original information with date and time information is configured with data types added for management according to the retention period set by the user.

[0176] The data preservation target creation means 11 is configured to extract information to be preserved from the original information with date and time information and data type added, as shown in Figure 70, automatically assign a counter to each data type of the extracted information to be preserved, and add a user code to distinguish users, thereby creating data to be preserved with date and time information.

[0177] Furthermore, the data upload means 15 for meaningless data preservation is configured to create a first upload ID for the data to be meaningless data to be preservation to a first provisional storage area, using, for example, as shown in Figure 71, information having a user code attached and a counter automatically assigned to each piece of information to be preserved based on the data type, and a first primary public key or other first primary public conversion information from the user, and to attach the created first upload ID to the data to be meaningless data preservation and upload it to the first provisional storage area.

[0178] Furthermore, the data index information creation means 25 is configured to create the data index information to be preserved, which includes, for example, as shown in Figure 72, information to which a user code is added and which has a counter that is automatically numbered for each piece of information to be preserved, based on the data type.

[0179] Furthermore, the data index information upload means 126 is configured to create a second upload ID for the data index information to be demeaning-preserved to a first provisional storage area, using, for example, as shown in Figure 73, information to which a user code is attached and which has a counter automatically assigned for each piece of information to be preserved, based on the data type, and a second primary public key or other second primary public conversion information from the user, and to attach the created second upload ID to the data index information to be demeaning-preserved to a first provisional storage area and upload it to the first provisional storage area.

[0180] User-side recovery system 130 The user-side restoration system 130 is configured, for example, as shown in Figure 74, to include a data type to be restored, a data type specification receiving means 131, a data index information download instruction means 132, a data index information restoration means 133, an uploaded data restoration candidate data list creation means 134, an uploaded data restoration candidate data list display means 135, a data restoration desired for restoration selection and specification receiving means 136, a data restoration data download instruction means 137, a data restoration means 138, and a data meaningless data / data index information deletion means 139.

[0181] Data type to be restored specification receiving means 131 The data type specification receiving means 131 is configured to receive, for example, the user code and data type specification from a user who wishes to have data to be preserved restored, as shown in Figure 75.

[0182] Means 132 for instructing the download of data index information for data to be preserved for meaninglessness. The data index information download instruction means 132 is configured to instruct the download of all data index information to be preserved that corresponds to the user code and type, which is managed in a distributed manner on the consortium side backup system 150. This is done using, for example, as shown in Figure 76, information that has a user code attached to it and has a counter that is automatically assigned for each piece of information to be preserved, based on the data type, and a second upload ID created using a second primary public key and other second primary public conversion information from the user.

[0183] Data index information recovery means 133 for data to be preserved The data index information restoration means 133 is configured to restore the data index information by performing a semanticization process on the meaningless data index information downloaded to the second provisional storage area by the meaningless data index information download means 163, for example, as shown in Figure 77, based on a second primary secret key and other second primary secret conversion information from the user.

[0184] Uploaded data candidate data preservation target data list creation method 134 The Uploaded Restoration Candidate Preservation Target Data List Creation Means 134 is configured, for example as shown in Figure 78, to rearrange the Preservation Target Data Index Information Restored by the Preservation Target Data Index Information Restores Means 133 in a predetermined order on a counter to create a list of Uploaded Preservation Target Data that constitute restoration candidates.

[0185] Uploaded data recovery candidate data preservation target list display means 135 The Uploaded Restoration Candidate Preservation Target Data List Display Means 135 is configured to display to the user a list of preserved data that constitutes a restoration candidate, which has been uploaded and created by the Uploaded Restoration Candidate Preservation Target Data List Creation Means 134, for example, as shown in Figure 79.

[0186] Data to be restored and preserved: Selection and designation acceptance method 136 The data restoration request selection / designation receiving means 136 is configured, for example as shown in Figure 80, to accept the selection and designation of data to be restored by a user who wishes to restore data to be restored, from a list of uploaded data that constitutes restoration candidates, displayed by the uploaded data restoration candidate list display means 135.

[0187] Data to be preserved download instruction means 137 The data to be preserved download instruction means 137 is configured to instruct the download of data to be preserved that corresponds to the user code and type, which are distributed and managed in the consortium-side backup system. This is done using, for example, as shown in Figure 81, information that has a counter automatically assigned to each piece of information to be preserved, based on the data type, and a first upload ID created using a first primary public key and other first primary public conversion information from the user.

[0188] Data recovery means 138 for data to be preserved The data preservation target restoration means 138 is configured to restore each of the meaningless data preservation target data, which has been extracted by the meaningless data preservation target extraction means 166 and downloaded to a second provisional storage area by the meaningless data preservation target download means 167, to the preservation target data with date and time information from before the backup, as shown in Figure 82, for example.

[0189] Download Meaningless Preservation Target Data / Meaningless Preservation Target Data Index Information Deletion Method 139 The means 139 for erasing the meaningless data to be preserved and the meaningless data to be preserved index information is configured to erase the respective meaningless data to be preserved and the meaningless data to be preserved index information, which were downloaded to the second provisional storage area after being restored to the preserved data with the date and time information before backup by the preserved data restoration means 138, for example, as shown in Figure 83.

[0190] Consortium-side restoration system 160 The consortium-side recovery system 160 is configured, for example, as shown in Figure 84, to include a first encryption-decryption-preservation target data index information extraction means 161, a first encryption-decryption-preservation target data index information decryption means 162, a decryption-preservation target data index information download means 163, a second encryption-decryption-preservation target data index information extraction means 164, a second encryption-decryption-preservation target data index information decryption means 165, a decryption-preservation target data extraction means 166, and a decryption-preservation target data download means 167.

[0191] First encryption-decryption-preservation target data index information extraction means 161 The first encryption-decryption-preservation-target data index information extraction means 161 is configured, for example as shown in Figure 85, to extract encrypted-statement-preservation-target data index information recorded in a black-box environment on a group of nodes at a specific location in the blockchain by the distributed recording data index information creation, encryption, and recording means 53, based on a second primary secret key and other second primary secret transformation information from the user associated with the preservation-target data with date and time information to be downloaded based on a download instruction by the decryption-preservation-target data index information download instruction means 132, and the consortium's secondary key and other secondary transformation information.

[0192] First encryption-decryption-preservation data index information decryption means 162 The first encryption-decryption-preservation-target data index information decryption means 162 is configured to decrypt the encrypted data index information extracted by the first encryption-decryption-preservation-target data index information extraction means 161, as shown in Figure 86, for example.

[0193] Meaningless Preservation Target Data Index Information Download Method 163 The data index information download means 163 is configured to download the data index information to be decrypted by the first encrypted data index information decryption means 164 to a second provisional storage area, as shown in Figure 87, for example.

[0194] Second encryption-decryption-preservation data index information extraction means 164 The second encryption-decryption-preservation-target data index information extraction means 164 is configured, for example as shown in Figure 88, to extract encrypted-decryption-preservation-target data index information recorded in a black-box environment on a group of nodes at a specific location in the blockchain by the distributed recording data index information creation, encryption, and recording means 53, based on the first primary secret key and other first primary secret transformation information from the user associated with the preservation-target data with date and time information to be downloaded based on a download instruction by the preservation-target data download instruction means 137, and the consortium's secondary key and other secondary transformation information.

[0195] Second encryption-decryption-preservation data index information decryption means 165 The second encryption-decryption-preservation-target data index information decryption means 165 is configured to decrypt the encrypted-statement-preservation-target data index information extracted by the second encryption-decryption-preservation-target data index information extraction means 164, as shown in Figure 89, for example.

[0196] Meaningless data preservation target extraction means 166 The data extraction means 166 for meaningless data preservation is configured to extract each data to be meaningless data preservation from either the node of

[0197] Data download method 167 for data to be rendered meaningless and preserved. The data download means 167 for data to be preserved for meaninglessness is configured to download each piece of data to be preserved for meaninglessness, extracted by the data extraction means 166, to a second provisional storage area, as shown in Figure 91, for example.

[0198] The processing flow and other details using the digital asset guard service provision system 1 of the fifth embodiment configured in this way will be explained with reference to the drawings as appropriate.

[0199] (S8) Basic processing flow - Maintenance processing (Figures 92-94) (S8-1) De-empowering data to be preserved (Figure 92) The data to be preserved and rendered meaningless means 113 performs a predetermined encryption process on the data to be preserved with date and time information created by the data to be preserved and rendered meaningless, based on a backup instruction for the data to be preserved and rendered meaningless, from a user using a first primary public key and other first primary public conversion information received by the data to be preserved and rendered meaningless.

[0200] (S8-2) Creation of data index information for data to be preserved (Figure 92) The data to be preserved index information creation means 125 creates data to be preserved index information which includes the file name and upload date information of the data to be preserved with date and time information created by the data to be preserved creation means 11.

[0201] (S8-3) De-emphasizing the meaninglessness of the data index information to be preserved (Figure 92) The data index information demeaning means 126 demeans the data index information to be preserved by the data index information creation means 11 by applying a predetermined encryption process using a second primary public key and other second primary public conversion information from the user received by the data backup instruction receiving means 12, thereby converting it into demeaning data index information to be preserved.

[0202] (S8-4) Uploading data index information for data to be preserved by rendering it meaningless (Figure 92) The meaningless data index information upload means 127 uploads the meaningless data index information converted by the data index information semantics means 126 to the first provisional storage area.

[0203] (S8-5) Distribution to distributed file management groups (Figure 93) The distributed file management group distribution means 151 distributes the data to be preserved for meaninglessness and the index information of the data to be preserved for meaninglessness, which have been uploaded to the first provisional storage area by the data to be preserved for meaninglessness and the data index information of the data to be preserved for meaninglessness, to multiple distributed file management groups constructed by the nodes of each location that constitute a planet set up by the consortium and recording devices at multiple locations that are network-connected to the nodes of said locations, using the secondary key and other secondary transformation information of the consortium.

[0204] (S8-6) Deletion of data to be preserved by rendering it meaningless when uploaded, and deletion of index information for data to be preserved by rendering it meaningless (Figure 94) The upload meaningless data preservation target data and meaningless data preservation target data index information erasure means 154 erases the meaningless data preservation target data and meaningless data preservation target data index information that have been uploaded to the first provisional storage area after the index information of the data distributed and recorded by the modification and distributed recording means 52 has been recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption and recording means 53. Figure 102 shows an image of the processing flow from the creation of data to be protected to the uploading of data to be protected in the maintenance process using the asset guard service provision system 1 of the fifth embodiment.

[0205] (S9) Basic processing flow specific to the present invention - Maintenance processing (not shown) The processing flow in the creation of comparative reference data, storage of comparative reference data, and deletion of data to be rendered meaningless in memory in the Digital Asset Guard Service Provision System 1 of the fifth embodiment is substantially the same as the processing flow in the Digital Asset Guard Service Provision System 1 of the first embodiment.

[0206] (S10) Basic processing flow specific to the Digital Asset Guard Service Provisioning System 1 of the Fifth Embodiment - Restoration Process (Figures 95-100) (S10-1) Acceptance of data type to be restored (Figure 95) The data type specification receiving means 131 accepts user codes and data type specifications from users who wish to have data to be preserved restored.

[0207] (S10-2) Instruction to download data index information for data to be preserved by rendering it meaningless (Figure 95) The data index information download instruction means 132 instructs the download of all data index information to be preserved that corresponds to the user code and type, which is distributed and managed in the consortium-side backup system 150. This is done using the second upload ID created using the second primary public key and other second primary public conversion information from the user, which has been received by the data type designation acceptance means 131 to which the user code has been added and which has a counter that has been automatically assigned for each piece of information to be preserved, based on the data type, and the second primary public conversion information from the user.

[0208] (S10-3) Extraction of the first encryption-decryption-preservation target data index information (Figure 95) The first encryption-decryption-preservation-target data index information extraction means 161 extracts encrypted-state decryption-preservation-target data index information recorded in a black-box environment on a group of nodes at a specific location in the blockchain by the distributed recording data index information creation, encryption, and recording means 53, based on a second primary secret key and other second primary secret transformation information from the user associated with the preserved data with date and time information to be downloaded based on a download instruction from the decryption-preservation-target data index information download instruction means 132, and the consortium's secondary key and other secondary transformation information.

[0209] (S10-4) Decryption of the first encryption-decrypted data index information (Figure 95) The first encryption-decryption-preservation-target data index information decryption means 162 decrypts the encrypted data index information extracted by the first encryption-decryption-preservation-target data index information extraction means 161.

[0210] (S10-5) Download of data index information for data to be preserved by rendering it meaningless (Figure 95) The data index information download means 163 downloads the data index information to be preserved for meaninglessness, which has been decrypted by the first encrypted data index information decryption means 164, to the second provisional storage area.

[0211] (S10-6) Restoration of data index information for data to be preserved (Figure 96) The data index information restoration means 133 restores the data index information by performing a semanticization process on the meaningless data index information downloaded to the second provisional storage area by the meaningless data index information download means 163, based on the second primary secret key and other second primary secret conversion information from the user.

[0212] (S10-7) Creation of a list of uploaded data to be preserved as candidates for restoration (Figure 96) The Uploaded Restoration Candidate Preservation Target Data List Creation Means 134 rearranges the Preservation Target Data Index Information restored by the Preservation Target Data Index Information Restoration Means 133 in a predetermined order of counters to create a list of uploaded preservation target data that constitute restoration candidates.

[0213] (S10-8) Display of the list of uploaded data to be preserved as candidates for restoration (Figure 96) The Uploaded Restoration Candidate Preservation Target Data List Display Means 135 displays to the user a list of uploaded restoration candidate preservation target data created by the Uploaded Restoration Candidate Preservation Target Data List Creation Means 134. Figure 103 shows an image of the processing flow from receiving the specification of the data type to be restored to displaying the list of data to be restored as a candidate for preservation in the restoration process using the asset guard service provision system 1 of the fifth embodiment.

[0214] (S10-9) Acceptance of selection and designation of data to be restored and preserved (Figure 97) The data restoration request selection / designation acceptance means 136 accepts the selection and designation of data to be restored by a user who wishes to restore data to be restored, from the list of uploaded data to be restored candidates displayed by the uploaded data restoration candidate list display means 135.

[0215] (S10-10) Instruction to download data to be preserved (Figure 97) The data to be preserved download instruction means 137 instructs the download of data to be preserved that corresponds to the user code and type, which is distributed and managed in the consortium-side backup system. This is done using information that has a counter automatically assigned to each piece of information to be preserved, based on the data type, and a first upload ID created using the first primary public key and other first primary public conversion information from the user. The data to be preserved that is to be preserved has been received by the data to be restored selection / designation acceptance means 136 and to which the user code has been attached.

[0216] (S10-11) Extraction of the second encryption-decryption and meaningless data index information (Figure 98) The second encryption-decryption-preservation-target data index information extraction means 164 extracts encrypted-decryption-preservation-target data index information recorded in a black-box environment on a group of nodes at a specific location in the blockchain by the distributed recording data index information creation, encryption, and recording means 53, based on the first primary secret key and other first primary secret transformation information from the user associated with the preservation-target data with date and time information to be downloaded based on the download instruction by the preservation-target data download instruction means 137, and the consortium's secondary key and other secondary transformation information.

[0217] (S10-12) Decryption of the second encryption-decrypted data index information (Figure 98) The second encryption-decryption-preservation-target data index information decryption means 165 decrypts the encrypted-state data index information to be preserved, which was extracted by the second encryption-decryption-preservation-target data index information extraction means 164.

[0218] (S10-13) Extraction of data to be preserved by rendering it meaningless (Figure 99) The data extraction means 166 extracts the data to be preserved for meaninglessness from either the node of

[0219] (S10-14) Download of data to be preserved by rendering it meaningless (Figure 99) The data download means 167 for data to be preserved for meaninglessness downloads each piece of data to be preserved for meaninglessness, extracted by the data extraction means 166 for data to be preserved for meaninglessness, to a second provisional memory area.

[0220] (S10-15) Restoration of data to be preserved (Figure 100) The data preservation target restoration means 138 restores each piece of data that has been extracted by the data de-meaningless data preservation target extraction means 166 and downloaded to the second provisional storage area by the data de-meaningless data preservation target download means 167 back to the data preservation target with date and time information from before the backup.

[0221] (S10-16) Deletion of data to be devalued and preserved, and deletion of index information for data to be devalued and preserved (Figure 100) The data to be deleted from download and preserved, and the data to be deleted and preserved index information deletion means 139 deletes the respective data to be deleted and preserved, and the data to be deleted and preserved index information, which were downloaded to the second provisional storage area after being restored to the data to be deleted with the date and time information before backup by the data to be deleted means 138. Figure 104 shows an image of the processing flow from the selection and specification of data to be restored to the restoration of data in the restoration process using the asset guard service provision system 1 of the fifth embodiment.

[0222] Furthermore, the configuration and processing flow of the deletion system on the user side and the consortium side are substantially the same as those of the Digital Asset Guard Service Provision System 1 in the first to fourth embodiments, so a detailed explanation will be omitted.

[0223] Effects of the Digital Asset Guard Service Provisioning System in Each Embodiment According to the first embodiment of the digital asset guard service provision system 1, "It has a consortium-type blockchain constructed with multiple planets that form a single unit constituting the blockchain, each consisting of a group of nodes combining nodes from multiple locations in different regions around the world, and a data protection target creation means 11 that extracts information to be protected from original information with date and time information recorded in a relational database managed by the user and creates data protection target with date and time information, a data protection target backup instruction receiving means 12 that receives backup instructions for data protection target from users who wish to back up the data protection target, a data protection target data meaninglessness means 13 that performs a predetermined encryption process on the data protection target with date and time information created by the data protection target creation means 11 based on the backup instructions for data protection target from the user using a primary key or other primary conversion information received by the data protection target data backup instruction receiving means 12, and converts it into meaningless data protection target, a meaningless data protection target memory storage means 14 that stores the meaningless data protection target converted by the data protection target data meaninglessness means 13 in a predetermined memory, and meaningless data protection target A user-side backup system 10 having a data-to-meaning-preservation-target data upload means 15 that uploads data to be preserved for meaninglessness stored in a predetermined memory by a data memory storage means 14 to a first provisional storage area; a distributed file management group distribution means 51 that distributes the data to be preserved for meaninglessness uploaded to the first provisional storage area by the data-to-meaning-preservation-target data upload means 15 to multiple distributed file management groups constructed by nodes at each location that constitute a planet set up by the consortium and recording devices at multiple locations that are network-connected to the nodes at said locations, using the secondary key of the consortium and other secondary transformation information; a modification and distributed recording means 52 that modifies the data distributed by the distributed file management group distribution means 51 and distributes and records the data that does not exceed the block size to multiple nodes of the distributed management file group provided on the blockchain, and the data that exceeds the block size to multiple nodes of a distributed file management group separate from the blockchain; and an index information of the data distributed and recorded by the modification and distributed recording means 52 that creates and encrypts index information of the data distributed and recorded by the modification and distributed recording means 52.The system is configured with a "consortium-side backup system 50" which includes a means 53 for creating, encrypting, and recording distributed recording data index information, and a means 52 for modifying and distributing the data, and an upload meaningless data erasure means 54 for erasing the meaningless data to be preserved, which has been uploaded to a first provisional storage area after the index information of the data distributed and recorded by the distributed recording data index information creation, encryption, and recording means 53 has been recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption, and recording means 53. Therefore, the user-side backup system 10 renders the data to be preserved meaningless using a primary key and other primary transformation information, and the consortium-side backup system 50 distributes the meaningless data to be preserved to nodes around the world using a secondary key and other secondary transformation information, modifies and distributes the data, and creates, encrypts, and manages the index information of the distributed data. As long as the user-side primary key and other primary transformation information are not lost or destroyed, the preserved data can be restored even if the primary key and other primary transformation information are stolen or the environment of the user-side backup system is destroyed. Furthermore, the consortium's evacuation system 50 has a globally distributed physical environment, making it extremely difficult for national actors or other entities to destroy the entire environment even if they attack, thus protecting the data necessary for restoration. Furthermore, by requiring both the primary key and other primary transformation information, as well as the secondary key and other secondary transformation information, when restoring data, it is possible to prevent data leakage by malicious third parties.

[0224] Furthermore, according to the first embodiment of the digital asset guard service provision system 1, "The user-side evacuation system 10 further includes a comparison reference preserved target data creation means 16 that decodes the meaningless preserved target data stored in a predetermined memory by the meaningless preserved target data memory storage means 14 to create preserved target data with date and time information that serves as a comparison reference, a comparison reference preserved target data storage means 17 that stores the preserved target data with date and time information that serves as a comparison reference created by the comparison reference preserved target data creation means 16, and periodically instructs the preserved target data creation means 11 to extract information to be preserved from the original information with date and time information recorded in the relational database managed by the user to create preserved target data with date and time information for checking, The system is configured to include a data creation control means 19 and a data creation control means 19 for checking the data to be preserved, which is created by the data creation means 11 via the control of the data creation means 19 for checking the data to be preserved, and a data portion with the same date and time information in the data portion with the same date and time information in the data to be preserved that is stored in the reference data storage means 17, which is a reference data to be preserved that is stored in the reference data to be preserved that is stored in the reference data to be preserved that is stored in the reference data to be preserved that is stored in the reference data to be preserved that is stored in the reference data storage means 17. This configuration includes a data creation control means 19 and a data creation control means 19 for checking the data to be preserved, which is created by the data creation means 11 via the control of the data creation means 19 for checking the data to be preserved, and a data portion with the same date and time information in the data portion with the same date and time information in the data to be preserved that is stored in the reference storage means 17. This configuration allows checking whether the function of extracting the information to be preserved from the original information and creating the data to be preserved is contaminated.

[0225] Furthermore, according to the digital asset guard service provision system 1 of the first embodiment, the system is configured to include "a data extraction function contamination notification means 21 that, as a result of a check by the data extraction function 20 for checking whether there is a discrepancy in the data portion with the same date and time information, when the data extraction function with date and time information for checking is found to be a discrepancy in the data portion with the same date and time information when compared with the data extraction function with date and time information that serves as a comparison standard, determines that the data extraction function for information to be protected in the data extraction function 11 for data to be protected is contaminated, and notifies the user and the consortium that the data extraction function for information to be protected in the data extraction function 11 for data to be protected is contaminated." Therefore, if the function for extracting information to be protected from the original information and creating data to be protected is contaminated, the user and the consortium can recognize this, minimizing damage and enabling rapid recovery.

[0226] Furthermore, according to the first embodiment of the digital asset guard service provision system 1, it is configured to have "memory-stored meaningless protected data erasure means 18 that erases meaningless protected data stored in a predetermined memory by the meaningless protected data memory storage means 14 after protected data with date and time information that serves as a comparison standard has been stored by the comparison standard protected data storage means 17," so that the time that meaningless protected data remains in memory on the user's system can be made extremely short, making it easier to prevent malicious third parties from analyzing and leaking the data.

[0227] Furthermore, according to the digital asset guard service provision system 1 of the second embodiment, the means 20' for checking whether there is a discrepancy in the data portion with identical date and time information of the protected data is configured to "calculate hash values ​​for the data portions with identical date and time information in the protected data with date and time information for checking and the protected data with date and time information that serves as a comparison standard, and by comparing the calculated hash values, check whether there is a discrepancy in the data portion with identical date and time information between the protected data with date and time information for checking and the protected data with date and time information that serves as a comparison standard," making it easier to determine whether there is a discrepancy in the data portion.

[0228] Furthermore, according to the digital asset guard service provision system of the third embodiment, it further comprises: a first hash value calculation means 22 that calculates the hash value of the data portion other than the date and time information in the data to be protected with date and time information that serves as a comparison standard and is stored by the comparison standard data to be protected data storage means 17 as the first hash value; a first hash value storage means 23 that stores the first hash value calculated by the first hash value calculation means 22; and a second hash value calculation means 24 that calculates the hash value of the data portion of the data to be protected with date and time information for checking that has the same date and time information as the data to be protected with date and time information that serves as a comparison standard, as the second hash value, and checks whether there is a discrepancy in the data portion with the same date and time information of the data to be protected. The checking means 20 is configured to check whether there is a discrepancy in the data portion with the same date and time information between the data to be preserved with date and time information that serves as a comparison standard and the data to be preserved with date and time information that serves as a comparison standard, by comparing the second hash value calculated by the second hash value calculation means 24 with the first hash value stored by the first hash value storage means 23. Therefore, each time the hash value of the data portion other than the date and time information in the data to be preserved with date and time information for checking is compared, it is not necessary to calculate the hash value of the data portion other than the date and time information in the data to be preserved with date and time information that serves as a comparison standard and is stored by the data to be preserved with date and time information that serves as a comparison standard, and the comparison process can be made more efficient.

[0229] Furthermore, according to the digital asset guard service provision system 1 of the fourth embodiment, the means for rendering the protected data meaningless 13' is configured to "perform a predetermined encryption process and primary decomposition process on the protected data with date and time information created by the protected data creation means 11, based on a backup instruction for the protected data using a primary key or other primary conversion information received by the protected data backup instruction receiving means 12 from a user, and convert it into multiple meaningless protected data," and the means for storing the meaningless protected data memory 14' is configured to "perform a predetermined encryption process and primary decomposition process on the protected data with date and time information created by the protected data creation means 11, and convert it into multiple meaningless protected data," and the means for storing the meaningless protected data memory 14' is configured to "perform a predetermined encryption process and primary decomposition process on the protected data meaningless The system is configured to store each of the meaningless data to be preserved after being converted by step 13' in a predetermined memory, and the meaningless data to be preserved upload means 15' is configured to upload each of the meaningless data to be preserved after being stored in a predetermined memory by the meaningless data to be preserved memory storage means 14' to a first provisional storage area, and the distributed file management group distribution means 51' is configured to distribute each of the meaningless data to be preserved after being uploaded to the first provisional storage area by the meaningless data to be preserved to two consortiums. The system is configured to "decompose the data using the next key and other secondary transformation information, and distribute it to multiple distributed file management groups constructed with nodes at each location that make up a planet set up by the consortium and recording devices at multiple locations that are network-connected to the nodes at those locations," and the upload meaningless data preservation target erasure means 54' is configured to "delete each meaningless data preservation target that has been uploaded to the first provisional storage area after the index information of the data distributed and recorded by the modification and distributed recording means 52 has been recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption and recording means 53," and the comparison standard preservation target data creation means 16' is configured to "decode and combine each meaningless data preservation target stored in a predetermined memory by the meaningless data preservation target data memory storage means to create preservation target data with date and time information that will serve as a comparison standard," thereby further decomposing the preservation target data encrypted on the user side, making it more difficult for malicious third parties to analyze and leak the data.

[0230] Furthermore, according to the first to fourth embodiments of the digital asset guard service provision system 1, "a means 31 for receiving instructions to restore protected data from users who wish to restore protected data, an encrypted index information extraction means 61 that extracts encrypted index information recorded in a black box environment on a group of nodes at a specific location on the blockchain by a distributed record data index information creation, encryption, and recording means 53 based on the primary key and other primary transformation information from the user associated with the protected data with date and time information to be restored, and the secondary key and other secondary transformation information of the consortium, an index information decryption means 62 that decrypts the encrypted index information extracted by the encrypted index information extraction means 61, and uses the index information decrypted by the index information decryption means 62 to distribute to each distributed file management group by the distributed file management group distribution means 51, and each modification and distributed recording means 52 to record the respective locations belonging to each distributed file management group Data extraction means 63 extracts data that is distributed and recorded on a node and multiple recording devices at multiple locations connected to the node of the said location from either the node of the said location belonging to the respective distributed file management group or from the multiple recording devices at multiple locations connected to the node of the said location; download means 32 downloads the data extracted by data extraction means 63 to a second provisional storage area; and the data extracted by data extraction means 63 and downloaded to the second provisional storage area by download means 32 The system further comprises a data recovery means 33 for restoring data to the state before backup with date and time information, and a downloaded data erasure means 34 for erasing each of the data downloaded to a second provisional storage area after being restored to the state before backup with date and time information by the data recovery means 33, and a user-side recovery system 30 having a data recovery instruction receiving means 31, a download means 32, a data recovery means 33, and a downloaded data erasure means 34, and an encrypted index information extraction means 61 and an index information decryption means 62.The system is configured to include a "consortium-side recovery system 60" with a "data extraction means 63." Therefore, as long as the user-side primary key and other primary conversion information are not lost or destroyed, it becomes possible to recover the preserved data even if the primary key and other primary conversion information are stolen or the user-side backup system environment is destroyed.

[0231] Furthermore, according to the first to fourth embodiments of the digital asset guard service provision system 1, "a means 41 for receiving instructions to delete protected data from users who wish to delete protected data, a means 71 for extracting encrypted index information recorded in a black box environment on a group of nodes at a specific location on the blockchain by a distributed recording data index information creation, encryption, and recording means, based on the primary key and other primary transformation information from the user associated with the protected data to be deleted with date and time information received by the means 41, and the secondary key and other secondary transformation information of the consortium, a means 72 for decrypting the encrypted index information extracted by the means 71 for decrypting the index information, and a means 51 for distributing the decrypted index information to each distributed file management group, and each distributed file management group for modifying and recording the respective distributed file management information by the respective modification and distributed recording means 52." The system comprises a user-side deletion system 40 having a data deletion instruction receiving means 41, and a consortium-side deletion system 70 having a means 71 for extracting encrypted index information during deletion processing, a means 72 for decrypting index information during deletion processing, a means 73 for decrypting file data of a predetermined generation or earlier, which is distributed and recorded on the nodes of each base belonging to the management group and on recording devices of multiple bases network-connected to the nodes of those bases; a second file data deletion means 74 that deletes encrypted index information recorded on the node group of a specific base in the blockchain under a black box environment by a distributed recording data index information creation, encryption, and recording means 53, based on a primary key and other primary conversion information from the user associated with the data to be deleted with date and time information to be deleted, received by a data deletion instruction receiving means 41, and a secondary key and other secondary conversion information from the consortium; and a consortium-side deletion system 70 having a means 71 for extracting encrypted index information during deletion processing, a means 72 for decrypting index information during deletion processing, a file data deletion means 73, and a second file data deletion means 74. Therefore, it is possible to delete meaningless data that is distributed and managed by the consortium-side backup system 50.Furthermore, even if meaningless data is recorded on the blockchain, deleting the index information makes it impossible to extract the meaningless data that has been distributed and recorded on the blockchain, effectively achieving the same effect as if it had been deleted.

[0232] Furthermore, according to the Digital Asset Guard Service Provision System 1 of the fifth embodiment, the user-side evacuation system 110 is configured as follows: "A means for creating data to be preserved index information 125 that creates data to be preserved index information having file name and upload date information for data to be preserved with date and time information created by the data to be preserved creation means 11; a means for demeaning data to be preserved index information 126 that performs a predetermined encryption process on the data to be preserved index information created by the data to be preserved index information creation means 125 using a second primary public key and other second primary public conversion information received by the data to be preserved evacuation instruction reception means 12 to convert it into demeaning data to be preserved index information; and a means for demeaning data to be preserved index information converted by the data to be preserved index information semantically converted by the data to be preserved index information 126 to upload the demeaning data to be preserved index information to a first provisional storage area." The system is configured to include an index information upload means 127, and the distributed file management group distribution means 151 of the consortium-side backup system 150 is configured to distribute the index information of the data to be preserved for meaningless purposes, along with the data to be preserved for meaningless purposes uploaded to the first temporary storage area, to multiple distributed file management groups for distributed management. Therefore, if a user wishes to restore specific data to be preserved from among the data to be preserved that is distributed and managed by the consortium-side backup system 150, even if the environment of the user-side backup system 130 is destroyed, the index information of the data to be preserved managed by the consortium-side backup system 150 is extracted, restored by the user-side restoration system 130, and displayed in a list. This allows the user to select and restore specific data to be preserved from the index information of the data to be preserved that is displayed in the list.

[0233] Furthermore, according to the digital asset guard service provision system 1 of the fifth embodiment, the original information with date and time information is configured to have "data types added for management according to the storage period set by the user", the data to be preserved creation means 11 is configured to "extract information to be preserved from the original information with date and time information to which data types have been added, automatically assign counters to the extracted information to be preserved for each data type, and add a user code to distinguish users to create data to be preserved with date and time information", the meaningless data to be preserved upload means 15 is configured to "create a first upload ID to the first provisional storage area of ​​the meaningless data to be preserved using information to which a user code has been added and which has a counter automatically assigned for each piece of information to be preserved, based on the data type, and a first primary public key or other first primary public conversion information from the user, and add the created first upload ID to the meaningless data to be preserved and upload it to the first provisional storage area", and the data to be preserved index information creation means 125 is configured to "user code The system is configured to "create a data index information to be preserved, which includes information with a code attached and a counter automatically assigned to each piece of information to be preserved, based on the data type," and the meaningless data index information upload means 127 is configured to "create a second upload ID to the first provisional storage area of ​​the meaningless data index information to be preserved using information with a user code attached and a counter automatically assigned to each piece of information to be preserved, based on the data type, and a second primary public key or other second primary public conversion information from the user, and then attach the created second upload ID to the meaningless data index information to be preserved and upload it to the first provisional storage area," so that the user can restore the index information of the data to be preserved that has been backed up in the consortium-side backup system 150 for each specific data type they wish to restore, display it as a list in the user-side restoration system 130, and select the specific data to be preserved that they wish to restore from the index information displayed in the list.

[0234] Furthermore, according to the Digital Asset Guard Service Provision System 1 of the fifth embodiment, "a data type to be restored specification reception means 131 that receives the user code and data type specification from a user who wishes to restore the data to be restored; a data type to be restored specification reception means 131 that receives the user code and has a counter that is automatically assigned for each piece of information to be restored, with the data type to be restored as a unit, and a second upload ID created using the second primary public key and other second primary public conversion information from the user, and manages in a distributed manner in the consortium-side backup system 150, and instructs the download of all meaningless data to be restored index information corresponding to the user code and type, which is managed in a distributed manner in the consortium-side backup system 150; and a second primary secret key and other second primary secret conversion information from the user associated with the data to be restored with date and time information to be downloaded based on the download instruction by the data type to be restored specification reception means 131, and the consortium's secondary key and other secondary conversion information, which are distributed A first encrypted data index information extraction means 161 extracts encrypted data index information to be preserved for meaninglessness from a group of nodes at a specific location on the blockchain under a black box environment using a data index information creation, encryption, and recording means 53; a first encrypted data index information decryption means 162 decrypts the encrypted data index information to be preserved for meaninglessness extracted by the first encrypted data index information extraction means 161; a data index information download means 163 downloads the data index information to be preserved for meaninglessness decrypted by the first encrypted data index information decryption means 162 to a second provisional storage area; and performs semantic processing on the data index information to be preserved for meaninglessness downloaded to the second provisional storage area by the data index information download means 163, based on a second primary secret key and other second primary secret conversion information from the user.The system further comprises a data preservation target index information restoration means 133 for restoring data preservation target index information, an uploaded data preservation target list creation means 134 for rearranging the data preservation target index information restored by the data preservation target index information restoration means 133 in a predetermined order on a counter to create a list of uploaded data preservation target data that are candidates for restoration, and an uploaded data preservation target list display means 135 for displaying the list of uploaded data preservation target data that are candidates for restoration created by the uploaded data preservation target list creation means 134 to the user. Therefore, for each specific data type that the user wishes to restore, the index information of the data preservation target data backed up in the consortium-side backup system 150 can be restored and displayed in a list on the user-side restoration system 130, and the user can select the specific data preservation target data they wish to restore from the displayed index information.

[0235] Furthermore, according to the Digital Asset Guard Service Provision System 1 of the fifth embodiment, "a means 136 for receiving the selection and specification of data to be restored by a user who wishes to restore data to be restored from a list of uploaded data to be restored that are candidates for restoration, displayed by the Uploaded Restoration Candidate Data to be Restored List Display Means 135; a means 137 for instructing the download of data to be restored that corresponds to the user code and type, which is distributed and managed in the consortium-side backup system, using a first upload ID created using information that has a user code attached to the data to be restored that the user wishes to restore, and which has a counter that is automatically assigned for each piece of information to be restored, based on the data type, and a first primary public key and other first primary public conversion information from the user; and a means 137 for instructing the download of data to be restored that corresponds to the user code and type, which is distributed and managed in the consortium-side backup system, using information that has a user code attached to the data to be restored that the user wishes to restore, and which has a counter that is automatically assigned for each piece of information to be restored, based on the data type, and a first primary private key from the user that is linked to the data to be restored that corresponds to the date and time information to be downloaded based on the download instruction from the means 137 for data to be restored; and a means 137 for instructing the download of data to be restored that corresponds to the user's first primary private key and other first primary public conversion information from the user. Based on other first primary secret transformation information and the consortium's secondary key and other secondary transformation information, a second encrypted meaningless preservation target data index information extraction means 164 extracts encrypted meaningless preservation target data index information recorded in a black box environment on a group of nodes at a specific location in the blockchain by a distributed recording data index information creation / encryption / recording means 53; a second encrypted meaningless preservation target data index information decryption means 165 decrypts the encrypted meaningless preservation target data index information extracted by the second encrypted meaningless preservation target data index information extraction means 164; and using the meaningless preservation target data index information decrypted by the second encrypted meaningless preservation target data index information decryption means 165, it is distributed to each distributed file management group by a distributed file management group distribution means 151 and distributed and recorded by each modification / distributed recording means 52 on the nodes at each location belonging to each distributed file management group and on recording devices at multiple locations that are network-connected to the nodes at said locations.Meaningless data extraction means 166 extracts each meaningless data to be preserved from either the node of each location belonging to each distributed file management group or the recording devices of multiple locations connected to the node of said location via a network; Meaningless data download means 167 downloads each meaningless data extracted by the meaningless data extraction means 166 to a second provisional storage area; and the meaningless data extracted by the meaningless data extraction means 166 and downloaded by the meaningless data download means 167 to the second The system further comprises: a data restoration means 138 that restores each data subject to be demeaning and preserved, downloaded to a temporary storage area, to the data subject to be preserved with the date and time information before backup; and a download data demeaning and preserved data / data demeaning and preserved data index information erasure means 139 that erases each data subject to be demeaning and preserved, and the data subject to be demeaning and preserved, downloaded to a second temporary storage area, after they have been restored to the data subject to be preserved with the date and time information before backup by the data restoration means 138; and a data type specification receiving means 13 A user-side restoration system 130 having: 1, a means 132 for instructing the download of meaningless data to be preserved index information, a means 133 for restoring data index information, a means 134 for creating a list of uploaded restoration candidate data to be preserved, a means 135 for displaying the list of uploaded restoration candidate data to be preserved, a means 136 for receiving the selection / designation of data to be restored, a means 137 for instructing the download of data to be preserved, a means 138 for restoring data to be preserved, and a means 139 for erasing downloaded meaningless data to be preserved and meaningless data to be preserved index information. The system is configured to include a consortium-side recovery system 160 having a first encryption-decryption-preservation target data index information extraction means 161, a first encryption-decryption-preservation target data index information decryption means 162, a decryption-preservation target data index information download means 163, a second encryption-decryption-preservation target data index information extraction means 164, a second encryption-decryption-preservation target data index information decryption means 165, a decryption-preservation target data extraction means 166, and a decryption-preservation target data download means 167.For each specific data type that a user wishes to restore, the system can restore the index information of the data to be preserved that has been backed up in the consortium's backup system 150. The user can then select the specific data to be preserved from the index information displayed in the list on the user's restoration system 130, and restore the data to be preserved that is managed in a distributed manner in the consortium's backup system 150.

[0236] Accordingly, according to the digital asset guard service provision system 1 of each embodiment of the present invention, a digital asset guard service provision system is obtained that can strongly and efficiently protect important information such as confidential information and personal information from high-level cyberattacks and physical destruction, restore important information without it being stolen by a third party even if it is subjected to cryptographic analysis by a quantum computer or EMP attack, quickly detect and restore backup information for preserving important information such as confidential information and personal information even if it is destroyed, and furthermore, efficiently restore the desired protected information even if the index information of the protected information managed by the user is destroyed.

[0237] Although preferred embodiments of the present invention have been described in detail above, the present invention is not limited to the embodiments described above, and various modifications and substitutions can be made to the embodiments described above within the scope of the specification and drawings without departing from the scope of the present invention.

[0238] supplementary explanation In the data to be protected with date and time information handled by the digital asset guard service provision system of the present invention, the date and time information is set as a basic setting, but additionally, data extraction information from the original information at the time of creation of the data to be protected may also be added to the configuration.

[0239] Furthermore, while we have described above a configuration for verifying the accuracy of the information to be preserved by a user-side system that renders the information meaningless, it is also possible to construct a configuration for verifying the meaningless data to be preserved by a consortium-side system that preserves the data.

[0240] The digital asset guard service provision system is constructed with two independent systems: a meaninglessness processing side (user-side system) and a data preservation side (consortium-side system). The function to verify the accuracy of the information to be preserved is performed on the meaninglessness processing side (user-side system) via the control of the check-preservation target data creation control means. This involves calculating a hash value (1) from the data portion with the same date and time information in the check-preservation target data with date and time information created by the preservation target data creation means (preservation target data created by a separate system of preservation target data generation function similar to the actual data with date and time information that serves as a comparison standard) using a hash function, and comparing it with the preservation target data with date and time information that serves as a comparison standard (preservation data). If the data creation means extracts information to be preserved from the original information using a data extraction function to create data to be preserved, the data to be preserved means performs meaningless processing, and the meaningless preserved data memory storage means decodes the meaningless preserved data stored in a predetermined memory, and the hash values ​​(2) calculated using the same hash function for the data portions with the same date and time information match, then the information stored in memory (meaningless preserved data) becomes the data to be preserved on the actual data preservation side (consortium system). Therefore, if these two hash values ​​(1) and (2) match, the data processed by the original data to be preserved means is considered to be in the correct state. A similar verification function may be implemented on the data preservation side (consortium system) as follows.

[0241] On the meaninglessness processing side (user-side system), a hash value (3) is calculated by a hash function from the data obtained by aggregating the multiple generated meaninglessness information (data to be preserved for meaninglessness), and this hash value is generated from the information stored in memory (data to be preserved for meaninglessness) and uploaded. On the data preservation side (consortium-side system), the multiple meaninglessness information (data to be preserved for meaninglessness) received from the meaninglessness processing side (user-side system) is aggregated, and the aggregated information is calculated using the same hash function as the meaninglessness processing side (user-side system) to obtain a hash value (4). The calculated hash value (4) is then compared with the hash value (3) of the information in memory (data to be preserved for meaninglessness) before it is sent to the data preservation side. By doing so, if the hash value (4) matches the hash value (3), it becomes possible to confirm that the meaninglessness data being transferred from the meaninglessness processing side (user-side system) to the data preservation side (consortium-side system) is normal information that has not been tampered with.

[0242] Furthermore, on the data preservation side (consortium system), multiple pieces of meaningless information (data to be preserved for meaninglessness) received from the meaninglessness processing side (user system) are further decomposed and distributed for recording. Before recording the distributed information as an index, like a distributed map, on the blockchain, the distributed information recorded in each wide-area location is referenced and retrieved. The retrieved pieces of information are combined to create the information before decomposition. The sum of the created information is then calculated using the same hash function to obtain a hash value (5). This calculated hash value (5) is then compared with the hash value (4) calculated when the multiple pieces of meaningless information were received from the meaninglessness processing side (user system). By doing so, if the two hash values ​​(4) and (5) match, it becomes possible to confirm that the decomposed and distributed information to be preserved has also been recorded correctly.

[0243] Furthermore, this information can be periodically verified by the data preservation side (consortium system). The hash values ​​(3) and (4) are stored separately on a blockchain or similar (tamper-proof), and periodically the information of the same group in the index is retrieved. The data preservation side (consortium system) then creates information by decomposing it back into meaningless information, and the sum of the created information is calculated using the same hash function to obtain a hash value (6). The calculated hash value (6) is then periodically compared with hash value (4) or hash value (5). In this way, the data preservation side (consortium system) can verify that the preserved information is correct. [Industrial applicability]

[0244] The digital asset guard service provision system of the present invention is useful in fields that handle confidential information such as personal information and security-related information, control modules for important functions, currencies such as stablecoins, rights such as contracts, and other important information as digital assets. [Explanation of Symbols]

[0245] 1. Digital Asset Guard Service Provisioning System 10. User-side evacuation system 11. Means for creating data to be preserved 12. Method for receiving instructions to back up data to be preserved. 13, 13' Means of rendering data subject to preservation meaningless 14, 14' Meaningless Preservation Target Data Memory Storage Means 15, 15' Means of uploading data to be preserved by rendering it meaningless 16, 16' Method for creating comparative standard maintenance target data 17. Data storage method for data subject to comparative standard preservation. 18. Means for erasing data stored in memory by rendering it meaningless. 19. Control means for creating maintenance target data for checking. 20, 20', 20" Data Preservation Target Data with Same Date and Time Information Data Partial Discrepancy Check Method 21 Contamination notification means for data extraction function targeting data 22 First hash value calculation means 23. First hash value storage means 24. Second hash value calculation method 30. User-side recovery system 31. Data Restoration Instruction Reception Method for Data to be Preserved 32 Download Methods 33. Data recovery means for data to be preserved 34. Method for Deleting Downloaded Data 40. User-side deletion system 41. Means for receiving instructions to delete data subject to preservation. 50 Consortium-side evacuation system 51, 51' Distributed file management group distribution means 52 Modified and Distributed Recording Means 53. Distributed recording data index information creation, encryption, and recording methods 54, 54' Means of erasing data that is being preserved by rendering the upload meaningless. 60 Consortium-side recovery system 61. Encryption Index Information Extraction Method 62 Index information decoding means 63 Data Extraction Method 70. Consortium-side deletion system 71. Means for extracting encrypted index information during deletion process 72. Means for decrypting index information during deletion process 73. File Data Deletion Methods 74. Second method for deleting file data 110 User-side evacuation system 113 Means of rendering data subject to preservation meaningless 125 Means for creating data index information of data to be preserved 126 Means for rendering meaningless data index information of data to be preserved 127 Means of uploading data index information for data to be preserved by rendering it meaningless 130 User-side recovery system 131 Reception method for specifying the type of data to be restored 132 Means for instructing the download of data index information for data to be preserved by rendering it meaningless. 133 Data index information recovery means for data to be preserved 134. Method for creating a list of uploaded data that can be restored and preserved. 135 Display method for the list of uploaded data to be preserved as a candidate for restoration. 136 Method for selecting and designating data to be restored and preserved 137 Data download instruction means for data to be preserved 138 Data recovery means for data to be preserved 139 Downloadable data to be rendered meaningless and protected / Data index information erasure method for data to be rendered meaningless and protected 150 Consortium-side evacuation system 151 Distributed file management group allocation means 154 Means of erasing data and index information of data to be preserved by rendering it meaningless when uploaded. 155 Method for selecting and designating data to be restored and preserved. 160 Consortium-side recovery system 161 First encryption-decryption-preservation target data index information extraction means 162 First encryption-decryption and meaninglessness-preserving data index information decryption means 163 Means of downloading index information for data to be preserved by rendering it meaningless 164 Second encryption-decryption-preservation data index information extraction means 165 Second encryption-decryption and preservation target data index information decryption means 166 Means for extracting data to be preserved by rendering it meaningless 167 Means of downloading data to be preserved by rendering it meaningless

Claims

1. A digital asset guard service provision system for protecting digital assets from high-level cyberattacks, which is constructed with a distributed ledger in blockchain or other distributed ledger technology, and a smart contract or server application for performing predetermined processing using data managed in said distributed ledger, It has a consortium-type blockchain built on multiple planets, which are units that make up the blockchain, each consisting of a group of nodes combining nodes from multiple locations in different regions around the world. A means for creating data to be preserved, which extracts information to be preserved from original information with date and time information recorded in a relational database managed by the user, and creates data to be preserved with date and time information. A means for receiving instructions to back up protected data from users who wish to back up protected data. Based on a data backup instruction from a user using a primary key or other primary conversion information received by the data backup instruction receiving means, the data de-meaningfulness means performs a predetermined encryption process on the data backup data with date and time information created by the data backup creation means, thereby converting it into meaningless data. Meaningless data storage means for storing the meaningless data to be preserved, which has been converted by the means for rendering the data to be preserved meaningless, in a predetermined memory. Meaningless data to be preserved upload means uploading meaningless data to be preserved stored in a predetermined memory by the meaningless data to be preserved memory storage means to a first provisional storage area. A user-side evacuation system having, Distributed file management group distribution means distributes the data to be preserved and rendered, which has been uploaded to the first provisional storage area by the data to be preserved and rendered meaningless, to multiple distributed file management groups constructed by the consortium's secondary key and other secondary transformation information, which consists of nodes at each location that constitute the planet set up by the consortium and recording devices at multiple locations that are network-connected to the nodes at said locations. A modification and distributed recording means that modifies the data distributed by the aforementioned distributed file management group distribution means, and distributes and records data that does not exceed the block size to multiple nodes of a distributed file management group established on the blockchain, and data that exceeds the block size to multiple nodes of a distributed file management group separate from the blockchain. A distributed recording data index information creation, encryption, and recording means that creates and encrypts index information of data distributed and recorded by the aforementioned modification and distributed recording means, and records it on a specific node of the blockchain in a black box environment. After the index information of the data distributed and recorded by the modification and distributed recording means is recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption, and recording means, the uploaded meaningless data to be preserved is deleted by the upload meaningless data deletion means. A consortium-side evacuation system having, It has, The aforementioned user evacuation system further includes: A comparison reference data creation means decodes the meaningless data to be preserved stored in a predetermined memory by the meaningless data to be preserved memory storage means and creates preserved data with date and time information to be used as a comparison reference, A comparison standard preservation target data storage means that stores preservation target data with date and time information that serves as a comparison standard, created by the comparison standard preservation target data creation means, After the data to be preserved with date and time information that serves as a comparison standard is stored in the comparison standard data storage means, the meaningless data to be preserved is deleted from the memory-stored meaningless data to be preserved that is stored in a predetermined memory by the meaningless data to be preserved memory storage means. A check-type maintenance target data creation control means periodically instructs the aforementioned maintenance target data creation means to extract information to be maintained from the original information with date and time information recorded in the relational database managed by the user, and to create maintenance target data with date and time information for checking purposes. A data preservation target data identical date and time information discrepancy check means checks whether there is a discrepancy in the data portion with identical date and time information between the data preservation target data with date and time information for checking, which has been created by the data preservation target data creation means via the control of the data preservation target data creation means for checking, and the data preservation target data with date and time information for checking which has date and time information, which has been created by the data preservation target data creation means for checking, and checks whether there is a discrepancy in the data portion with identical date and time information between the data preservation target data with date and time information for checking which has date and time information and the data preservation target data with date and time information which has been created by the data preservation target data creation means for comparison, via the control of the data preservation target data creation means for checking, data preservation target data creation means, which checks whether there is a discrepancy in the data portion with identical date and time information between the data preservation target data with date and time information for checking. If, as a result of the check by the data subject data with identical date and time information data discrepancy check means, the data subject data with date and time information for checking is found to have a discrepancy in the data portion with identical date and time information compared with the data subject data with date and time information that serves as the comparison standard, the data subject data creation means determines that the data extraction function for information subject to preservation in the data subject data creation means is contaminated, and the data subject data extraction function contamination notification means notifies the user and the consortium that the data extraction function for information subject to preservation in the data subject data creation means is contaminated. A digital asset guard service provision system characterized by having the following features.

2. The digital asset guard service provision system according to claim 1, characterized in that the means for checking whether there is a discrepancy in the data portion with the same date and time information of the data to be protected is to calculate the hash values ​​of the data portions with the same date and time information in the data to be protected with the date and time information for checking and the data to be protected with the date and time information that serves as a comparison standard, and to check whether there is a discrepancy in the data portion with the same date and time information between the data to be protected with the date and time information for checking and the data to be protected with the date and time information that serves as a comparison standard by comparing the calculated hash values.

3. A first hash value calculation means calculates the hash value of the data portion other than the date and time information in the data to be preserved with date and time information that serves as the comparison standard, which is stored in the comparison standard data storage means, as a first hash value. A first hash value storage means for storing the first hash value calculated by the first hash value calculation means, A second hash value calculation means calculates a second hash value from the data portion of the data subject to be preserved with date and time information for checking that has the same date and time information as the data subject to be preserved with date and time information that serves as the comparison standard, It further possesses, The digital asset guard service provision system according to claim 1, characterized in that the means for checking whether there is a discrepancy in the data portion with the same date and time information of the data to be protected, with respect to the data to be protected with date and time information that serves as the comparison standard, is checked by comparing the second hash value calculated by the second hash value calculation means with the first hash value stored by the first hash value storage means.

4. The means for rendering the data to be preserved meaningless is configured to perform a predetermined encryption process and a primary decomposition process on the data to be preserved with date and time information created by the means for creating the data to be preserved, based on a backup instruction for the data to be preserved from a user using a primary key or other primary conversion information received by the means for receiving backup instructions for the data to be preserved, thereby converting it into a plurality of meaningless data to be preserved. The aforementioned data memory storage means for meaningless data to be preserved is configured to store each of the meaningless data to be preserved that has been converted by the data meaningless data to be preserved in a predetermined memory. The meaningless data preservation data upload means is configured to upload each meaningless data preservation data stored in a predetermined memory by the meaningless data preservation data memory storage means to a first provisional storage area. The distributed file management group distribution means is configured to decompose each piece of data to be demeaning and preserved, uploaded to the first provisional storage area by the data to be demeaning and preserved The aforementioned data erasure means for data to be erased from uploads is configured to erase each data to be erased from uploads to the first provisional storage area after the index information of the data distributed and recorded by the modification and distributed recording means has been recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption, and recording means. The comparison reference data creation means is configured to decode and combine each of the meaningless data stored in a predetermined memory by the meaningless data storage means to create data to be preserved with date and time information that serves as a comparison reference. The digital asset guard service provision system according to feature 1.

5. A means for receiving instructions for the restoration of protected data from users who wish to restore protected data, Based on the primary key and other primary transformation information from the user associated with the data to be restored, which has date and time information to be restored and has been received by the data restoration instruction receiving means, and the secondary key and other secondary transformation information from the consortium, the encrypted index information extraction means extracts the encrypted index information recorded in a black box environment on a group of nodes at a specific location on the blockchain by the distributed record data index information creation, encryption, and recording means. An index information decryption means for decrypting the encrypted index information extracted by the aforementioned encrypted index information extraction means, A data extraction means for extracting data from either the node of the respective location belonging to, A download means for downloading each of the data extracted by the aforementioned data extraction means to a second provisional storage area, A data recovery means for restoring each of the data extracted by the data extraction means and downloaded to the second provisional storage area by the download means to data to be preserved with date and time information before backup, After the data to be preserved has been restored to its original state with date and time information before backup by the data to be preserved data restoration means, the data downloaded to the second provisional storage area is deleted by the data to be preserved data erasure means, It further possesses, A user-side recovery system having the means for receiving instructions to recover data to be preserved, the means for downloading, the means for recovering data to be preserved, and the means for erasing downloaded data, A consortium-side recovery system having the encryption index information extraction means, the index information decryption means, and the data extraction means, A digital asset guard service provision system according to claim 1, characterized by having the following features.

6. A means for receiving instructions to delete protected data from users who wish to delete protected data, Based on the primary key and other primary transformation information from the user associated with the data to be deleted, which has date and time information to be deleted and has been received by the data deletion instruction receiving means, and the secondary key and other secondary transformation information from the consortium, the encrypted index information extraction means for deletion processing extracts the encrypted index information recorded in a black box environment on a group of nodes at a specific location in the blockchain by the distributed record data index information creation, encryption, and recording means. Deletion process index information decryption means for decrypting the encrypted index information extracted by the deletion process encryption index information extraction means, A file data deletion means deletes file data from a predetermined generation or earlier, which is distributed to each of the distributed file management groups by the distributed file management group distribution means using the index information decoded by the deletion process index information decoded by the aforementioned deletion process index information decoded by the aforementioned deletion process index information decoded by the aforementioned distributed file management group distribution means, and distributed and recorded by each of the respective modification and distributed recording means to the nodes of each location belonging to each of the distributed file management groups and to recording devices at multiple locations connected to the nodes of those locations via a network, A second file data deletion means deletes encrypted index information, which is recorded in a black box environment on a group of nodes in the blockchain, based on the primary key and other primary transformation information from the user associated with the data to be deleted, which has date and time information to be deleted and has been received by the aforementioned data deletion instruction receiving means, and the secondary key and other secondary transformation information of the consortium, by the aforementioned distributed record data index information creation, encryption, and recording means. It further possesses, A user-side deletion system having means for receiving instructions to delete data to be preserved, and a consortium-side deletion system having means for extracting encrypted index information during deletion processing, means for decrypting index information during deletion processing, means for deleting file data, and means for deleting second file data. A digital asset guard service provision system according to claim 1, characterized by having the following features.

7. A digital asset guard service provision system for protecting digital assets from high-level cyberattacks, which is constructed with a distributed ledger in blockchain or other distributed ledger technology, and a smart contract or server application for performing predetermined processing using data managed in said distributed ledger, It has a consortium-type blockchain built on multiple planets, which are units that make up the blockchain, each consisting of a group of nodes combining nodes from multiple locations in different regions around the world. A means for creating data to be preserved, which extracts information to be preserved from original information with date and time information recorded in a relational database managed by the user, and creates data to be preserved with date and time information. A means for receiving instructions to back up protected data from users who wish to back up protected data. Based on a data backup instruction receiving means for data to be preserved from a user using a first primary public key or other first primary public conversion information, the data to be preserved data de-meaningful means performs a predetermined encryption process on the data to be preserved with date and time information created by the data to be preserved creation means, thereby converting it into meaningless data to be preserved. Meaningless data storage means for storing the meaningless data to be preserved, which has been converted by the means for rendering the data to be preserved meaningless, in a predetermined memory. Meaningless data to be preserved upload means uploading meaningless data to be preserved stored in a predetermined memory by the meaningless data to be preserved memory storage means to a first provisional storage area. A means for creating a data to be preserved index information, which has file name and upload date information for the data to be preserved with date and time information created by the aforementioned data to be preserved creation means. Meaningless Data Index Information De-meaningless means for converting the data index information created by the data index information creation means into meaningless data index information by performing a predetermined encryption process using a second primary public key and other second primary public conversion information received from the user by the data backup instruction receiving means. Meaningless data index information upload means uploading meaningless data index information converted by the aforementioned data index information semantics means to a first provisional storage area. A user-side evacuation system having, Distributed file management group distribution means distributes the data to be preserved and the index information of the data to be preserved and the data to be preserved, which have been uploaded to the first provisional storage area by the data to be preserved and the index information of the data to be preserved and the data to be preserved and the data to be preserved, which have been uploaded to the first provisional storage area by the data to be preserved and the data to be preserved and the data to be preserved, which have been uploaded by index information of the data to be preserved and the data to be preserved, which have been uploaded by the data to be preserved and the data to be preserved, to a plurality of distributed file management groups constructed by the nodes of each base that constitute the planet set by the consortium and the recording devices of multiple bases that are network-connected to the nodes of said bases, using the secondary key of the consortium and other secondary transformation information. A modification and distributed recording means that modifies the data distributed by the aforementioned distributed file management group distribution means, and distributes and records data that does not exceed the block size to multiple nodes of a distributed file management group established on the blockchain, and data that exceeds the block size to multiple nodes of a distributed file management group separate from the blockchain. A distributed recording data index information creation, encryption, and recording means that creates and encrypts index information of data distributed and recorded by the aforementioned modification and distributed recording means, and records it on a specific node of the blockchain in a black box environment. The index information of the data distributed and recorded by the modification and distributed recording means is recorded on a specific node of the blockchain by the distributed recording data index information creation, encryption, and recording means, and then the uploaded meaningless data and meaningless data index information are deleted by the upload meaningless data and meaningless data index information deletion means. A consortium-side evacuation system having, It has, The aforementioned user evacuation system further includes: A comparison reference data creation means decodes the meaningless data to be preserved stored in a predetermined memory by the meaningless data to be preserved memory storage means and creates preserved data with date and time information to be used as a comparison reference, A comparison standard preservation target data storage means that stores preservation target data with date and time information that serves as a comparison standard, created by the comparison standard preservation target data creation means, After the data to be preserved with date and time information that serves as a comparison standard is stored in the comparison standard data storage means, the meaningless data to be preserved is deleted from the memory-stored meaningless data to be preserved that is stored in a predetermined memory by the meaningless data to be preserved memory storage means. A check-type maintenance target data creation control means periodically instructs the aforementioned maintenance target data creation means to extract information to be maintained from the original information with date and time information recorded in the relational database managed by the user, and to create maintenance target data with date and time information for checking purposes. A data preservation target data identical date and time information discrepancy check means checks whether there is a discrepancy in the data portion with identical date and time information between the data preservation target data with date and time information for checking, which has been created by the data preservation target data creation means via the control of the data preservation target data creation means for checking, and the data preservation target data with date and time information for checking which has date and time information, which has been created by the data preservation target data creation means for checking, and checks whether there is a discrepancy in the data portion with identical date and time information between the data preservation target data with date and time information for checking which has date and time information and the data preservation target data with date and time information which has been created by the data preservation target data creation means for comparison, via the control of the data preservation target data creation means for checking, data preservation target data creation means, which checks whether there is a discrepancy in the data portion with identical date and time information between the data preservation target data with date and time information for checking. If, as a result of the check by the data subject data with identical date and time information data discrepancy check means, the data subject data with date and time information for checking is found to have a discrepancy in the data portion with identical date and time information compared with the data subject data with date and time information that serves as the comparison standard, the data subject data creation means determines that the data extraction function for information subject to preservation in the data subject data creation means is contaminated, and the data subject data extraction function contamination notification means notifies the user and the consortium that the data extraction function for information subject to preservation in the data subject data creation means is contaminated. A digital asset guard service provision system characterized by having the following features.

8. The aforementioned source data with date and time information is further modified to include data types for management according to the retention period set by the user. The aforementioned data preservation target creation means extracts information to be preserved from the original information with date and time information to which the data type has been added, automatically assigns a counter to each of the extracted information to be preserved, and adds a user code to distinguish users, thereby creating data to be preserved with date and time information. The aforementioned data upload means for data to be demeaning-preserved creates a first upload ID for the data to be demeaning-preserved to a first provisional storage area using information to which a user code is attached and a counter is automatically assigned for each piece of information to be preserved, based on the data type, and a first primary public key or other first primary public conversion information from the user, and attaches the created first upload ID to the data to be demeaning-preserved and uploads it to the first provisional storage area. The means for creating the data index information to be preserved creates the data index information to be preserved, which includes information to which a user code is added and which has a counter that is automatically numbered for each piece of information to be preserved, with the data type as the unit. The means for uploading the meaningless data index information to be preserved creates a second upload ID for the meaningless data index information to be preserved to a first provisional storage area using information to which a user code has been added and a counter has been automatically assigned for each piece of information to be preserved, based on the data type, and a second primary public key and other second primary public conversion information from the user, and adds the created second upload ID to the meaningless data index information to be preserved and uploads it to the first provisional storage area. The digital asset guard service provision system according to feature 7.

9. A means for receiving the specification of the data type to be restored, which accepts the user code and data type specification from a user who wishes to restore the data to be preserved, A data index information download instruction means for meaningless data to be preserved, which is distributed and managed in the consortium-side backup system, instructs the download of all meaningless data to be preserved index information corresponding to the user code and type, using the information that has a user code attached to it and has a counter that is automatically assigned to each piece of information to be preserved, based on the data type, and the second upload ID created using the second primary public key and other second primary public conversion information from the user, which is received by the data type to be restored instruction means. A first encrypted data index information extraction means for extracting encrypted data index information for data to be preserved, which is recorded in a black box environment on a group of nodes in a blockchain, by the distributed recording data index information creation, encryption, and recording means, based on a second primary secret key and other second primary secret transformation information from a user associated with the data to be preserved with date and time information to be downloaded based on a download instruction by the aforementioned data index information download instruction means, and the consortium's secondary key and other secondary transformation information, A first encryption-decryption-preservation-target-data-index-information-decryption means for decrypting the encrypted data-decryption-preservation-target-data-index-information-decryption means extracted by the first encryption-decryption-preservation-target-data-index-information-extraction means, A data index information download means for downloading the data index information to be preserved for meaninglessness, which has been decrypted by the first encryption-decryption-preservation data index information decryption means, to a second provisional storage area, A data index information restoration means for restoring data index information to be preserved by performing semantic processing on the data index information to be preserved, which has been downloaded to the second provisional storage area by the data index information to be preserved, based on a second primary secret key and other second primary secret conversion information from the user, A means for creating an uploaded restoration candidate for preserved data, which rearranges the preserved data index information restored by the preserved data index information restoration means in a predetermined order on a counter to create a list of preserved data that are uploaded as restoration candidates, A means for displaying an uploaded list of data to be preserved that constitutes a candidate for restoration, which is created by the means for creating an uploaded list of data to be preserved that constitutes a candidate for restoration, and The digital asset guard service provision system according to claim 8, further comprising the above.

10. A means for receiving requests for the selection and specification of data to be restored, which accepts the selection and specification of data to be restored from a list of uploaded data that are candidates for restoration, as displayed by the means for displaying the list of uploaded data that are candidates for restoration, by a user who wishes to restore data to be restored. A data download instruction means for data to be preserved, which is distributed and managed in the consortium's backup system, instructs the download of data to be preserved that corresponds to the user code and type, using information that has a counter automatically assigned for each piece of information to be preserved, based on the data type, and a first upload ID created using a first primary public key and other first primary public conversion information from the user, the data to be preserved that is to be preserved that is to be preserved, which is to be preserved, as received by the data to be preserved selection and designation acceptance means. A second encryption-decryption-decryption-preservation-target-data-index-information-extraction means extracts encrypted-state-decryption-preservation-target-data-index-information-extraction means that extracts encrypted-state-decryption-preservation-target-data-index-information-extracted by the distributed-record-data-index-information-creation-encryption-and-recording means from a group of nodes at a specific location in the blockchain under a black box environment, based on a first primary secret key and other first primary secret transformation information from a user associated with the preservation-target-target-data-to-be-downloaded data with date and time information to be downloaded based on a download instruction by the aforementioned preservation-target-target-data-download instruction means, and a second encryption-decryption-decryption-preservation-target-data-index-information-extraction means that extracts encrypted-state-decryption-decryption-preservation-target-data-index-information-extracted means that is recorded in A second encryption-decryption-preservation-target-data-index-information-decryption means for decrypting the encrypted data-decryption-preservation-target-data-index-information-decryption means extracted by the second encryption-decryption-preservation-target-data-index-information-extraction means, Meaninglessness-preservation-target-data extraction means extracts each meaninglessness-preservation-target-data from either the node of A data download means for downloading each of the data to be preserved for meaninglessness, extracted by the aforementioned data extraction means for meaninglessness preservation, to a second provisional storage area. A data preservation target restoration means for restoring each of the data preservation target data extracted by the data preservation target extraction means and downloaded to the second provisional storage area by the data preservation target download means to the data preservation target data with date and time information before backup, After the data to be preserved has been restored to its original state with the date and time information before backup by the data to be preserved data restoration means, the respective data to be rendered meaningless and the data to be rendered meaningless, which have been downloaded to the second provisional storage area, are to be erased by the download data to be preserved data and the data to be rendered meaningless, It further possesses, A user-side restoration system comprising: a means for receiving the type of data to be restored; a means for instructing the download of index information of data to be rendered meaningless and preserved; a means for restoring the index information of data to be preserved; a means for creating a list of uploaded data to be restored as a candidate for preservation; a means for displaying the list of uploaded data to be restored as a candidate for preservation; a means for receiving the selection and specification of data to be restored as desired; a means for instructing the download of data to be preserved; a means for restoring data to be preserved as meaningless and deleting the index information of downloaded data to be rendered meaningless and preserved; A consortium-side recovery system having the following: a first encryption-decryption-preservation data index information extraction means, a first encryption-decryption-preservation data index information decryption means, a data-decryption-preservation data index information download means, a second encryption-decryption-preservation data index information extraction means, a second encryption-decryption-preservation data index information decryption means, a data-decryption-preservation data extraction means, and a data-decryption-preservation data download means. The digital asset guard service provision system according to claim 9, characterized by having the following features.