Data protection device, electronic device, method and program

The data protection device addresses the challenge of securely sharing log data by using an encryption process with selective decryption capabilities, ensuring secure and flexible data disclosure between operators and device vendors.

JP7679329B2Active Publication Date: 2025-05-19KK TOSHIBA
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2022044291
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-18
Publication Date
2025-05-19
Estimated Expiration
2042-03-18

AI Technical Summary

Technical Problem

The challenge is to securely share and disclose log data between operators and device vendors while minimizing the risk of confidential data leakage, especially in scenarios where pre-defined agreements are lacking.

Method used

A data protection device that executes an encryption process using a key sequence generated from initial keys and a one-way function, allowing selective decryption of data within a predetermined section of log data, with digital signatures from both entities confirming authenticity for disclosure.

Benefits of technology

This solution enables secure and selective disclosure of log data, reducing the risk of confidential data leakage and allowing flexible response to audits or data mining requirements without pre-defined agreements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007679329000001
    Figure 0007679329000001
  • Figure 0007679329000002
    Figure 0007679329000002
  • Figure 0007679329000003
    Figure 0007679329000003
Patent Text Reader

Abstract

To provide a data protection apparatus, an electronic apparatus, a method, and a program, capable of selectively decoding data included in a predetermined section among a large number of pieces of data included in log data.SOLUTION: A data protection apparatus according to one embodiment includes a processing unit configured to execute encryption processing on log data including a data frame. The processing unit is configured to generate a first initial key and a second initial key that correspond to a data frame including a plurality of pieces of data generated along a time sequence. The processing unit is configured to generate a first key sequence including an encryption key in a forward direction with respect to a time sequence on the basis of the first initial key and a one-way function. The processing unit is configured to generate a second key sequence including an encryption key in a backward direction with respect to the time sequence on the basis of the second initial key and the one-way function. The processing unit is configured to perform multiplex encryption of each of the plurality of pieces of data by means of the encryption key of the first key sequence and the encryption key of the second key sequence.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to a data protection device, an electronic device, a method, and a program.

Background Art

[0002] For example, in information processing systems such as product manufacturing systems, power control systems, and communication systems, various types of data are generated. Among them is log data, which is time-series data. Log data has mainly been used for the maintenance of information processing systems and various devices included in the information processing systems.

[0003] However, with the recent development of IoT (Internet of Things) technology, the value of log data as big data has increased. Log data is not only used for the maintenance of information processing systems and various devices, but has also come to be used for data mining to extract potential problems of these systems and devices and improve the potential problems. While the value of log data as big data has increased in this way, there are issues regarding the right to use the log data.

[0004] Log data includes both the know-how of the operator who operates the information processing system and the know-how of the device vendor who provides the operator with various devices included in the information processing system. Both the operator and the device vendor do not want to disclose log data to others in order to prevent their own know-how from leaking outside, but they want to use the log data themselves for the above-described data mining.

[0005] For example, an operator wants to utilize log data to operate the information processing system more efficiently, but does not want to disclose know-how related to system operation to the outside, so there is a desire not to disclose log data to others including equipment vendors. On the other hand, equipment vendors want to utilize log data to improve and enhance the performance of various devices, but do not want to disclose know-how related to various devices to the outside, so there is a desire not to disclose log data to others including operators.

[0006] Thus, there is a potential conflict of interest between the operator and the equipment vendor. For this reason, it is desirable to share log data in a form that minimizes the external leakage of confidential data related to the know-how of both parties among the large number of data included in the log data between the operator and the equipment vendor, such as by concluding a confidentiality agreement. However, it is difficult to determine all in advance before system operation which data included in the log data corresponds to confidential data. For example, data for which a confidentiality agreement has not been concluded may correspond to confidential data, and there is a possibility that know-how may leak to the outside unintentionally.

[0007] In addition, the operator and the equipment vendor may have to disclose log data to a third party. Audits by customers or third-party institutions correspond to this. Audits may be conducted on the log data of product and information service providing devices, for example, when there are claims from customers regarding the quality of products or information services provided to customers or when there are suspicions of non-compliance with legal standards. In such audits, it is not always possible to know in advance what disclosure of log data is required, so there is also a problem that it is difficult to determine all the agreements regarding responses to audits (that is, the handling of log data during audits) between the operator and the equipment vendor before system operation.

[0008] As described above, it is difficult to determine all the various agreements regarding the handling of log data before system operation. For this reason, even if the various agreements regarding the handling of log data have not been determined before system operation, when data included in a predetermined section among a large number of data included in the log data becomes necessary, it is desired to realize a technology capable of selecting and disclosing the data included in the predetermined section.

Prior Art Documents

Patent Documents

[0009]

Patent Document 1

Non-Patent Documents

[0010]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0011] The problem to be solved by the present invention is to provide a data protection device, an electronic device, a method, and a program capable of executing an encryption process capable of selectively decrypting data included in a predetermined section among a large number of data included in log data.

Means for Solving the Problems

[0012] A data protection device according to an embodiment is a processing unit that executes an encryption process on log data including a data frame and a first public key or a first digital certificate for digital signature verification corresponding to a first entity who is a person concerned with the data frame, a second public key or a second digital certificate for digital signature verification corresponding to a second entity who is a person concerned with the data frame and different from the first entity, a first initial key, and a second initial key, and a storage for storing themIt includes. The processing unit includes the corresponding to a data frame the generate a first initial key and the a second initial key. The processing unit generates a first key sequence based on the first initial key and a one-way function. The first key sequence is a key sequence including encryption keys corresponding to each of the plurality of data, and includes the first initial key and a plurality of first encryption keys generated in the forward direction with respect to the time series of the plurality of data. The processing unit generates a second key sequence based on the second initial key and the one-way function. The second key sequence is a key sequence including encryption keys corresponding to each of the plurality of data, and includes the second initial key and a plurality of second encryption keys generated in the reverse direction with respect to the time series of the plurality of data. The processing unit encrypts each of the plurality of data with the corresponding encryption key among the first initial key and the plurality of first encryption keys included in the first key sequence. The processing unit further encrypts each of the plurality of data encrypted with the encryption key included in the first key sequence with the corresponding encryption key among the second initial key and the plurality of second encryption keys included in the second key sequence. The processing unit receives an input of a disclosure request message that requests disclosure of data included in a predetermined section among a plurality of pieces of data encrypted by the encryption key included in the first key series and the encryption key included in the second key series. The disclosure request message indicates a first number indicating data corresponding to the start position of the predetermined section and a second number indicating data corresponding to the end position of the predetermined section. The disclosure request message is attached with a digital signature of the first entity and a digital signature of the second entity. The processing unit uses the first public key or the first digital certificate to confirm the authenticity of the digital signature of the first entity attached to the disclosure request message. The processing unit uses the second public key or the second digital certificate to confirm the authenticity of the digital signature of the second entity attached to the disclosure request message. When it is confirmed that both the digital signature of the first entity and the digital signature of the second entity are authentic, the processing unit generates, based on the first initial key and the one-way function, the first encryption key corresponding to the data indicated by the first number as a decryption key. The processing unit generates, based on the second initial key and the one-way function, the second encryption key corresponding to the data indicated by the second number as a decryption key. The processing unit transmits the two generated decryption keys to at least one of the first entity and the second entity.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

MODE FOR CARRYING OUT THE INVENTION

[0014] Hereinafter, embodiments will be described with reference to the drawings. First, as a premise of the embodiment, with reference to FIG. 1, encryption processing using a one-way function will be described. FIG. 1 is a diagram for explaining the outline of encryption processing using a one-way function. In the encryption processing using a one-way function, a key sequence including a plurality of encryption keys is generated from one encryption key using the one-way function. The first encryption key included in the key sequence is the encryption key that is the source of the plurality of encryption keys included in the key sequence, and is also referred to as the initial key or the root key. Examples of the one-way function used to generate the key sequence include a hash function, HMAC (Hash-based Message Authentication Code), and the like.

[0015] The key sequence is generated in units of data frames including a plurality of data. In FIG. 1, since it is assumed that the data frame D including N pieces of data D_0 to data D_n-1 is encrypted, a key sequence K including N encryption keys K_0 to encryption key K_n-1 (more specifically, a key sequence K including one initial key K_0 and N-1 encryption keys K_1 to encryption key K_n-1) is generated.

[0016] The encryption key K_1 included in the key sequence K is generated by applying a hash function to the initial key K_0. The encryption key K_2 included in the key sequence K is generated by applying a hash function to the encryption key K_1. Similarly, thereafter, the process of applying a hash function to the upper encryption key to generate a new encryption key is repeatedly executed, whereby a key sequence K including N encryption keys K_0 to encryption key K_n-1 is generated.

[0017] Each of the N pieces of data D_0 to D_n-1 included in the data frame D is encrypted by the corresponding encryption key among the encryption keys K_0 to K_n-1 included in the key series K. For example, data D_0 is encrypted by the initial key K_0 included in the key series K and output as encrypted data Enc(K_0, D_0). Also, data D_1 is encrypted by the encryption key K_1 included in the key series K and output as encrypted data Enc(K_1, D_1). Data D_2 is encrypted by the encryption key K_2 included in the key series K and output as encrypted data Enc(K_2, D_2). Further, data D_n-1 is encrypted by the encryption key K_n-1 included in the key series K and output as encrypted data Enc(K_n-1, D_n-1). In this specification, a data series including the encrypted data Enc(K_0, D_0) to Enc(K_n-1, D_n-1) corresponding to each of the N pieces of data D_0 to D_n-1 included in the data frame D shall be referred to as an encrypted data series Enc(K, D). Encryption algorithms that can be used include various usage modes of the symmetric key block cipher AES, for example, ECB (Electronic Codebook), CBC (Cipher Block Chaining), CCM (Counter with CBC-MAC), and GCM (Galois / Counter Mode). Note that in modes other than ECB such as CBC, CCM, and GCM, there are parameters such as an initial vector IV in addition to the encryption key, and appropriate management of these shall be assumed. Also, when CCM or GCM is used, a forgery verification function for checking the presence or absence of data forgery can be used during data decryption.

[0018] In a key series generated using a one-way function, if a given encryption key included in the key series is known, all encryption keys lower than the given encryption key can be calculated, but there is a characteristic that encryption keys higher than the given encryption key cannot be obtained.

[0019] For example, among the encryption keys K_0 to K_n-1 included in the key series K, if the encryption key K_i (where i satisfies 0 < i < n-1) is known, it is possible to calculate the encryption keys K_i+1 to K_n-1 lower than the encryption key K_i by using a one-way function. That is, if the encryption key K_i is known, not only the encrypted data Enc(K_i, D_i) encrypted by the encryption key K_i, but also the encrypted data Enc(K_i+1, D_i+1) to Enc(K_n-1, D_n-1) encrypted by the encryption keys K_i+1 to K_n-1 lower than the encryption key K_i can be decrypted. On the other hand, even if the encryption key K_i is known, it is not possible to obtain the encryption keys higher than the encryption key K_i, so the encrypted data Enc(K_0, D_0) to Enc(K_i-1, D_i-1) cannot be decrypted.

[0020] In the present embodiment, a data protection device capable of executing an encryption process using a key series having the above characteristics will be described.

[0021] FIG. 2 is a diagram showing a configuration example of an information processing system including the data protection device according to the present embodiment. In the present embodiment, the case where the information processing system is a product manufacturing system will be described, but the present invention is not limited thereto, and the information processing system may be a power control system or a communication system.

[0022] In this specification, a device vendor refers to a person who manufactures a manufacturing device and provides the manufacturing device to an operator (factory). Also, in this specification, an operator refers to a person who manufactures a product using the manufacturing device provided by the device vendor and ships the product to a sales store or the like. For example, the device vendor is a vibration isolation rubber manufacturing device vendor that manufactures a manufacturing device for manufacturing vibration isolation rubber products, and the operator is a chemical manufacturer that manufactures vibration isolation rubber products using the manufacturing device and the raw material of vibration isolation rubber. If it is found that some of the shipped vibration isolation rubber products do not meet the quality standards, the quality standard supervision agency orders the operator to submit log data during the manufacturing and inspection of the product, and an operation is assumed in which the operator submits the log data during the manufacturing and inspection of the product to the supervision agency in agreement with the device vendor.

[0023] As shown in FIG. 2, the device vendor 1 has a vendor terminal 11. The vendor terminal 11 is, for example, a PC, a tablet terminal, a smartphone, etc. that can be operated by the device vendor 1. The vendor terminal 11 is communicably connected to a manufacturing device 21 described later via a first network Nw1. Also, the vendor terminal 11 is communicably connected to an operator terminal 23 described later via a second network Nw2. Note that in FIG. 1, a case where the vendor terminal 11 is communicably connected to the manufacturing device 21 via the first network Nw1 and communicably connected to the operator terminal 23 via the second network Nw2 is illustrated, but the vendor terminal 11 may be communicably connected to both the manufacturing device 21 and the operator terminal 23 via one network.

[0024] The vendor terminal 11 includes a processing unit 111, a communication I / F unit 112, and a storage 113. The processing unit 111 controls the operation of the vendor terminal 11. The communication I / F unit 112 is a communication interface for communicably connecting the vendor terminal 11 to the manufacturing device 21 and the operator terminal 23. A vendor private key used in digital signature described later is stored in the storage 113 at the start of system operation.

[0025] As shown in FIG. 2, the operator 2 has a manufacturing apparatus 21, a storage 22, and an operator terminal 23. The manufacturing apparatus 21 is a manufacturing apparatus provided by the equipment vendor 1. The manufacturing apparatus 21 includes a processing unit 211, a communication I / F unit 212, a product manufacturing unit 213, a log data generation unit 214, and a data protection apparatus 215.

[0026] The processing unit 211 controls the operation of the manufacturing apparatus 21, more specifically, the operations of each part 212 to 214 included in the manufacturing apparatus 21. The processing unit 211 is one or more electronic circuits including a control device and an arithmetic device. The electronic circuit is realized by an analog or digital circuit or the like. For example, a general-purpose processor, a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), an ASIC, an FPGA, and combinations thereof are possible. Further, the functions of the processing unit 211 may be executed by these electronic circuits by software. Although details will be described later, the data protection apparatus 215 has its own processing unit, and its operation is controlled by a processing unit different from the processing unit 211. The communication I / F unit 212 is a communication interface for communicably connecting the manufacturing apparatus 21 and the vendor terminal 11. The product manufacturing unit 213 manufactures a predetermined product.

[0027] The log data generation unit 214 generates various log data related to the operation of the manufacturing apparatus 21 (product manufacturing unit 213). The various log data includes various time-series data related to the manufacturing apparatus 21, such as an operation log, a communication log, and a hardware failure log. The operation log includes, for example, time-series data related to the operating time of the manufacturing apparatus 21, time-series data related to the number of products manufactured per unit time by the manufacturing apparatus 21, time-series data related to the amount of raw materials used per unit time by the manufacturing apparatus 21, and the like. The log data is composed of one or more data frames including a plurality of data.

[0028] The log data generated by the log data generation unit 214 is roughly classified into two types: log data that is always disclosed to both the device vendor 1 and the operator 2, and log data that is not normally disclosed to both the device vendor 1 and the operator 2.

[0029] The log data that is always disclosed to both the device vendor 1 and the operator 2 includes, for example, data necessary for the operation of the product manufacturing system (factory operation), data necessary for the quality control of the products manufactured by the product manufacturing unit 213, data necessary for equipment maintenance when a maintenance contract has been previously concluded between the device vendor 1 and the operator 2, and the like. Since such log data is data that is always disclosed, it may also be referred to as always-disclosed data. The always-disclosed data is uploaded to, for example, a server on the cloud.

[0030] On the other hand, the log data that is not normally disclosed to both the device vendor 1 and the operator 2 includes, for example, data that may be required during an audit by a third-party agency, data that may be required during equipment maintenance when a maintenance contract has not been previously concluded between the device vendor 1 and the operator 2, and the like. Since such log data is data that can be disclosed retrospectively only when special circumstances occur, such as an audit by a third-party agency or a situation where equipment maintenance different from normal equipment maintenance is required, it may also be referred to as retrospectively-disclosed data. The retrospectively-disclosed data is encrypted by the data protection device 215 and stored in the storage 22 as encrypted data.

[0031] Note that what log data corresponds to always-disclosed data or retrospectively-disclosed data can be arbitrarily determined between the device vendor 1 and the operator 2. For example, from the perspective of suppressing the leakage of the know-how of both the device vendor 1 and the operator 2, the minimum data necessary for the operation of the product manufacturing system may be set as always-disclosed data, and all other data may be set as retrospectively-disclosed data.

[0032] The data protection device 215 is a device that encrypts log data generated by the log data generation unit 214 and that corresponds to post-disclosure data, and protects the log data as encrypted data. It is preferable for the data protection device 215 to have obtained authentication, for example, ISO 15408 authentication, from an institution trusted by both the device vendor 1 and the operator 2. Since details of the data protection device 215 will be described later, a detailed explanation thereof is omitted here.

[0033] The storage 22 stores the encrypted data encrypted by the data protection device 215. The storage 22 is a storage device managed by the operator 2, rather than a server on the cloud or the like. The storage 22 may be, for example, a storage connectable to a network like a NAS (Network Attached Storage), or may be a storage not connectable to such a network.

[0034] The operator terminal 23 is, for example, a PC, a tablet terminal, a smartphone, etc. that can be operated by the operator 2. The operator terminal 23 is communicably connected to the vendor terminal 11 via the second network Nw2.

[0035] The operator terminal 23 includes a processing unit 231, a communication I / F unit 232, and a storage 233. The processing unit 231 is a processor that controls the operation of the operator terminal 23. The communication I / F unit 232 is a communication interface for communicably connecting the operator terminal 23 and the vendor terminal 11. The operator's private key used in digital signature described later is stored in the storage 233 at the start of system operation.

[0036] With reference to FIG. 3, the detailed configuration of the data protection device 215 will be described. FIG. 3 is a diagram showing one configuration example of the data protection device 215 according to the present embodiment. As shown in FIG. 3, the data protection device 215 includes a processing unit 215A and a storage 215B. The processing unit 215A realizes each function of the data protection device 215. The processing unit 215A can apply a device similar to the device described in the processing unit 211 (it does not have to be the same device), or the function may be executed by software. As each function of the data protection device 215, for example, there are an initial key generation function 215a, a key sequence generation function 215b, a log data encryption function 215c, an encrypted data disclosure control function 215d, and the like. Each of these functions is realized, for example, by the processing unit 215A executing an encryption program in an environment where neither the device vendor 1 nor the operator 2 can operate (for example, Intel (registered trademark) SGX, AMD (registered trademark) SEV, etc.) (that is, software). However, each of the above functions may be realized by hardware that cannot be operated by both the device vendor 1 and the operator 2, or may be realized by a combination of software and hardware.

[0037] Next, the initial key generation function 215a, the key sequence generation function 215b, the log data encryption function 215c, and the encrypted data disclosure control function 215d of the data protection device 215 realized by the processing unit 215A will be described in order.

[0038] The initial key generation function 215a is a function corresponding to a true random number generator, and generates two initial keys for each data frame to be encrypted. Although details will be described later, one of the two initial keys is an initial key (hereinafter referred to as the forward initial key) for generating a forward key series including a plurality of encryption keys (hereinafter referred to as forward encryption keys) generated in the forward direction with respect to the time series of a plurality of data included in the data frame to be encrypted (that is, the input order of the data). For example, the data D_0 is encrypted by the initial key Kf_0 included in the forward key series Kf. Also, the data D_n-1 is encrypted by the encryption key Kf_n-1 included in the forward key series Kf. The other of the two initial keys is an initial key (hereinafter referred to as the reverse initial key) for generating a reverse key series including a plurality of encryption keys (hereinafter referred to as reverse encryption keys) generated in the reverse direction with respect to the time series of a plurality of data included in the data frame to be encrypted. For the encryption by the reverse key series Kr, the encryption key Kr_n-1 included in the reverse key series Kr is used for encryption with the encrypted data Enc(Kf_0, D_0) as the input data. The data Enc(Kf_n-1, D_n-1) is encrypted by the initial key Kr_0 included in the reverse key series Kr. The two initial keys generated by the initial key generation function 215a are stored in the storage 215B in the data protection device 215.

[0039] The key series generation function 215b generates two key series based on the two initial keys generated by the initial key generation function 215a and a one-way function. More specifically, the key series generation function 215b generates a plurality of encryption keys in the forward direction with respect to the time series of a plurality of data included in the data frame to be encrypted based on the forward initial key generated by the initial key generation function 215a and a one-way function, and generates a forward key series including the forward initial key and the plurality of encryption keys (that is, a plurality of forward encryption keys).

[0040] Also, the key sequence generation function 215b generates a plurality of encryption keys in the reverse direction with respect to the time series of a plurality of data included in the data frame to be encrypted, based on the reverse initial key generated by the initial key generation function 215a and a one-way function, and generates a reverse key sequence including the reverse initial key and the plurality of encryption keys (i.e., a plurality of reverse encryption keys).

[0041] Note that the number of encryption keys including the initial key included in the forward key sequence and the number of encryption keys including the initial key included in the reverse key sequence are the same as the number of data included in the data frame to be encrypted.

[0042] The log data encryption function 215c encrypts each of the plurality of data included in the data frame to be encrypted with the corresponding encryption key among the plurality of encryption keys included in the forward key sequence. Also, the log data encryption function 215c further encrypts each of the encrypted data encrypted by the forward key sequence with the corresponding encryption key among the plurality of encryption keys included in the reverse key sequence. That is, the log data encryption function 215c performs multi-encryption on each of the plurality of data included in the data frame to be encrypted with the encryption key included in the forward key sequence and the encryption key included in the reverse key sequence. The encrypted data encrypted by the log data encryption function 215c is stored in the storage 22 outside the data protection device 215. Note that the order of encryption by the forward key sequence and encryption by the reverse encryption may be interchanged.

[0043] The encrypted data disclosure control function 215d receives an input of a disclosure request message transmitted from the operator terminal 23 and attached with the digital signature of the device vendor 1 and the digital signature of the operator 2 when an agreement is reached regarding the disclosure of the encrypted data included in a predetermined section among the plurality of encrypted data included in the encrypted data series in a human-based negotiation between the device vendor 1 and the operator 2.

[0044] Here, referring to FIG. 4, the data configuration of the disclosure request message will be described. As shown in FIG. 4, the disclosure request message 301 includes a data frame identifier 301-1 and disclosure interval information 301-2. The data frame identifier 301-1 is information for uniquely identifying a data frame corresponding to an encrypted data series including a predetermined interval (data disclosure interval) for which data disclosure is requested. The data frame identifier 301-1 is generated, for example, by combining an identifier for identifying the data protection device 215, a field name of the data frame, a start time of the data frame, and an end time of the data frame. The disclosure interval information 301-2 is information including a data number indicating data corresponding to the start position of the data disclosure interval and a data number indicating data corresponding to the end position of the data disclosure interval. The data disclosure interval can be arbitrarily determined in a human-based negotiation between the device vendor 1 and the operator 2 at any timing after the system operation. As described above, the start request message 301 can be attached with a digital signature of the device vendor 1 and a digital signature of the operator 2.

[0045] Returning to the description of FIG. 3 again. When the encrypted data disclosure control function 215d receives the input of the disclosure request message 301 with the digital signature of the device vendor 1 and the digital signature of the operator 2, it uses the vendor public key and the operator public key pre-stored in the storage 215B in the data protection device 215 to verify the authenticity of the disclosure request message 301. Signature verification algorithms such as RSA and ECDSA can be used for authenticity verification. When it is confirmed that the input disclosure request message 301 is authentic (that is, when it is confirmed that the digital signatures of the device vendor 1 and the operator 2 are authentic), the encrypted data disclosure control function 215d uses the forward encryption key corresponding to the data number indicating the start position of the data disclosure interval indicated by the disclosure interval information 301-2 of the disclosure request message 301, and calculates it based on the forward initial key and the one-way function stored in the storage 215B. Also, the encrypted data disclosure control function 215d calculates the reverse encryption key corresponding to the data of the data number indicating the end position of the data disclosure interval indicated by the disclosure interval information 301-2 of the input disclosure request message 301 based on the reverse initial key and the one-way function stored in the storage 215B.

[0046] The forward encryption key and the reverse encryption key calculated by the encrypted data disclosure function 215d are transmitted to the device vendor 1 (vendor terminal 11) and the operator 2 (operator terminal 23) as decryption keys for decrypting the encrypted data included in the data disclosure interval. The decryption key is encrypted using the vendor public key stored in the storage 215B and then transmitted to the device vendor 1, and encrypted using the operator public key stored in the storage 215B and then transmitted to the operator 2. Alternatively, the decryption key is transmitted to the device vendor 1 using the secure key distribution protocol established between the data protection device 215 and the device vendor 1 (vendor terminal 11), and transmitted to the operator 2 using the secure key distribution protocol established between the data protection device 215 and the operator 2 (operator terminal 23). According to this, it is possible to reduce the risk of the decryption key leaking to a third party other than the device vendor 1 and the operator 2.

[0047] Next, referring to the flowchart of FIG. 5, the encryption process executed by the processing unit 215A of the data protection device 215 will be described. FIG. 5 is a flowchart showing the procedure of the encryption process executed by the data protection device 215 according to the present embodiment.

[0048] First, the processing unit 215A of the data protection device 215 generates a forward initial key Kf_0 and a reverse initial key Kr_0 as two initial keys corresponding to the data frame to be encrypted including N pieces of data D_0 to D_n-1 (step S1).

[0049] Subsequently, the processing unit 215A generates a plurality of forward encryption keys Kf_1 to Kf_n-1 based on the forward initial key Kf_0 generated by the process of step S1 and a one-way function, and generates a forward key sequence Kf including N forward encryption keys Kf_0 to Kf_n-1 including the forward initial key Kf_0 (step S2).

[0050] Furthermore, the processing unit 215A generates a plurality of reverse encryption keys Kr_1 to Kr_n-1 based on the reverse initial key Kr_0 generated by the process of step S1 and a one-way function, and generates a reverse key sequence Kr including N reverse encryption keys Kr_0 to Kr_n-1 including the reverse initial key Kr_0 (step S3).

[0051] Here, the processing unit 215A recognizes the data D_i (where i is any value from 0 to n-1 and increases by 1 in order from 0) among the N pieces of data D_0 to D_n-1 included in the data frame to be encrypted as the data to be encrypted (step S4).

[0052] Then, the processing unit 215A encrypts the data D_i recognized as the data to be encrypted by the process of step S4 with the corresponding forward encryption key Kf_i of the forward key sequence Kf, and outputs it as encrypted data Enc(Kf_i, D_i) (step S5).

[0053] Further, the processing unit 215A encrypts the encrypted data Enc(Kf_i, D_i) encrypted by the process of step S5 with the corresponding reverse encryption key Kr_n-1-i of the reverse key sequence Kr, and outputs it as encrypted data Enc[Kr_n-1-i, Enc(Kf_i, D_i)] (step S6).

[0054] Thereafter, the processing unit 215A determines whether all of the N pieces of data D_0 to D_n-1 included in the data frame to be encrypted have been encrypted (in other words, determines whether i = n-1) (step S7). In the process of step S7, if it is determined that not all of the N pieces of data D_0 to D_n-1 have been encrypted (in other words, if i ≠ n-1) (No in step S7), the processing unit 215A returns to the process of step S4 described above, recognizes the next data D_i+1 as the new data D_i to be encrypted, and then executes the processes of step S5 and subsequent steps described above.

[0055] On the other hand, in the process of step S7, if it is determined that all of the N pieces of data D_0 to D_n-1 have been encrypted (in other words, if i = n-1) (Yes in step S7), the processing unit 215A ends the encryption process for the current data frame and starts the encryption process for the next data frame. Since the forward key Kf_i used for encrypting the data D_i can be easily calculated from Kf_i-1 used for encrypting the previous data D_i-1, it is not necessary to calculate and hold the maximum number N of data frames in advance. Different from the forward direction, the reverse key sequence cannot be calculated from the key used for encrypting the previous data. However, it is not always necessary to calculate all of the maximum number N of data frames in advance. By performing pre-calculation only for the number corresponding to one day's worth of log data and calculating the key sequence for the next day during the maintenance time once a day, the capacity of the storage 215B can be saved.

[0056] Here, with reference to FIG. 6, the encryption process executed by the processing unit 215A of the data protection device 215 will be described in more detail. FIG. 6 is a diagram for explaining a specific example of the encryption process executed by the data protection device 215 according to the present embodiment. Here, it is assumed that the data frame D to be encrypted includes four pieces of data D_0 to D_3.

[0057] First, the processing unit 215A of the data protection device 215 generates a forward initial key Kf_0 and a reverse initial key Kr_0 as two initial keys corresponding to the data frame D to be encrypted, which includes four pieces of data D_0 to D_3.

[0058] Subsequently, the processing unit 215A generates a forward key sequence Kf including four forward encryption keys equal in number to the number of data included in the data frame D including the forward initial key Kf_0, based on the forward initial key Kf_0 and a one-way function. More specifically, the processing unit 215A applies a hash function to the forward initial key Kf_0 to generate a forward encryption key Kf_1, applies a hash function to the forward encryption key Kf_1 to generate a forward encryption key Kf_2, and applies a hash function to the forward encryption key Kf_2 to generate a forward encryption key Kf_3, thereby generating a forward key sequence Kf including four forward encryption keys Kf_0 to Kf_3.

[0059] Furthermore, the processing unit 215A generates a reverse key sequence Kr including four reverse encryption keys equal in number to the number of data included in the data frame D including the reverse initial key Kr_0, based on the reverse initial key Kr_0 and a one-way function. More specifically, the processing unit 215A applies a hash function to the reverse initial key Kr_0 to generate a reverse encryption key Kr_1, applies a hash function to the reverse encryption key Kr_1 to generate a reverse encryption key Kr_2, and applies a hash function to the reverse encryption key Kr_2 to generate a reverse encryption key Kr_3, thereby generating a reverse key sequence Kr including four reverse encryption keys Kr_0 to Kr_3.

[0060] Here, the processing unit 215A recognizes data D_0 among the four pieces of data D_0 to D_3 included in the data frame D to be encrypted as the data to be encrypted. The processing unit 215A encrypts the recognized data D_0 with the corresponding forward encryption key Kf_0 of the forward key sequence Kf, and further encrypts the encrypted data with the corresponding reverse encryption key Kr_3 of the reverse key sequence Kr. According to this, the data D_0 is output as encrypted data Enc[Kr_3, Enc(Kf_0, D_0)].

[0061] Similarly, for the data D_1 to D_3, the processing unit 215A encrypts them with the corresponding forward encryption key of the forward key sequence Kf and the corresponding reverse encryption key of the reverse key sequence. According to this, the data D_1 is output as encrypted data Enc[Kr_2, Enc(Kf_1, D_1)]. Also, the data D_2 is output as encrypted data Enc[Kr_1, Enc(Kf_2, D_2)]. Furthermore, the data D_3 is output as encrypted data Enc[Kr_0, Enc(Kf_3, D_3)].

[0062] As described above, the data protection device 215 according to the present embodiment executes multiple encryption processing using the forward key sequence Kf and the reverse key sequence Kr. Although details will be described later, according to such multiple encryption processing, for example, when it is desired to decrypt the encrypted data corresponding to the data included in a predetermined section of the data frame, as long as there are two encryption keys, namely, the forward encryption key corresponding to the data corresponding to the start position of the predetermined section and the reverse encryption key corresponding to the data corresponding to the end position of the predetermined section, it is possible to decrypt all the encrypted data included in the predetermined section.

[0063] Next, with reference to the sequence chart of FIG. 7, a series of processes executed to select and disclose encrypted data included in a predetermined section among a plurality of encrypted data encrypted by the data protection device 215 will be described. FIG. 7 is a sequence chart for explaining a series of processes realized by the data protection device 215 according to the present embodiment, which is a process of selectively disclosing a part of the encrypted data.

[0064] In a human negotiation between the device vendor 1 and the operator 2, when an agreement is reached on disclosing the encrypted data included in a predetermined section among the plurality of encrypted data included in the encrypted data series, the operator terminal 23 generates a disclosure request message 301 including the data frame identifier 301-1 of the data frame corresponding to the encrypted data series and the disclosure section information 301-2 including the data number of the data corresponding to the start position of the predetermined section and the data number of the data corresponding to the end position of the predetermined section. The operator terminal 23 attaches a digital signature using the operator private key stored in the storage 233 to the generated disclosure request message 301 and transmits this to the vendor terminal 11 (step S11). That is, as shown in FIG. 8, the operator terminal 23 transmits the disclosure request message 301 with the digital signature DS1 (the digital signature of the operator 2) by the operator private key to the vendor terminal 11.

[0065] When the vendor terminal 11 receives the disclosure request message 301 transmitted from the operator terminal 23 and it is confirmed by the device vendor 1 that there is no problem with the content of the received disclosure request message 301, the vendor terminal 11 further attaches a digital signature using the vendor private key stored in the storage 113 to the disclosure request message 301 and returns this to the operator terminal 23 (step S12). That is, as shown in FIG. 9, the vendor terminal 11 returns the disclosure request message 301 with the digital signature DS1 (the digital signature of the operator 2) by the operator private key and the digital signature DS2 (the digital signature of the device vendor 1) by the vendor private key to the operator terminal 23.

[0066] Here, a case where the device vendor 1 and the operator 2 perform a multi-signature on the disclosure request message 301 will be described, but it is not limited thereto. The disclosure request message 301 may be group-signed by the device vendor 1 and the operator 2. In this case, a common group secret key is stored in the storage 113 of the vendor terminal 11 and the storage 233 of the operator terminal 23 before the start of system operation. The device vendor 1 and the operator 2 each perform a group signature on the disclosure request message 301 using the group secret key.

[0067] When the operator terminal 23 receives the disclosure request message 301 transmitted from the vendor terminal 11, it inputs the received disclosure request message 301 to the data protection device 215 (step S13).

[0068] When the processing unit 215A of the data protection device 215 receives the input of the disclosure request message 301 with the digital signature DS1 by the operator secret key and the digital signature DS2 by the vendor secret key, it uses the operator public key pre-stored in the storage 215B to confirm the authenticity of the digital signature DS1 by the operator secret key, and uses the vendor public key pre-stored in the storage 215B to confirm the authenticity of the digital signature DS2 by the vendor secret key (step S14).

[0069] When it is confirmed that the digital signatures attached to the disclosure request message 301 are both authentic, the processing unit 215A generates a decryption key for decrypting the encrypted data included in the data disclosure section indicated by the disclosure section information 301-2 of the disclosure request message 301. Specifically, the processing unit 215A calculates a forward encryption key corresponding to the data of the data number indicating the start position of the data disclosure section indicated by the disclosure section information 301-2 of the disclosure request message 301, based on the forward initial key stored in the storage 215B and a one-way function. Also, the processing unit 215A calculates a reverse encryption key corresponding to the data of the data number indicating the end position of the data disclosure section indicated by the disclosure section information 301-2 of the disclosure request message 301, based on the reverse initial key stored in the storage 215B and a one-way function. The processing unit 215A uses the forward encryption key obtained by the above calculation and the reverse encryption key obtained by the above calculation as the decryption key (step S15).

[0070] After that, the processing unit 215A transmits the decryption key generated by the process of step S15 to the vendor terminal 11 and the operator terminal 23. Also, the processing unit 215A transmits the encrypted data included in the data disclosure section indicated by the disclosure section information 301-2 of the disclosure request message 301 to the vendor terminal 11 and the operator terminal 23 (step S16).

[0071] As described above, since the data protection device 215 according to the present embodiment has the initial key generation function 215a, the key sequence generation function 215b, the log data encryption function 215c, and the encrypted data disclosure control function 215d realized by the processing unit 215A, among the plurality of encrypted data included in the log data (post-disclosure data) that is not normally disclosed to both the device vendor 1 and the operator 2, it is possible to execute an encryption process that can selectively decrypt the encrypted data included in the data disclosure section in which both the device vendor 1 and the operator 2 have agreed to disclose.

[0072] According to this, for example, when defective products are mixed into the products manufactured by the manufacturing apparatus 21 and the disclosure of log data is requested from the destination (a third party) of the products, or when there are doubts such as the quality of the products manufactured by the manufacturing apparatus 21 not meeting the standards defined by laws and regulations, and the disclosure of log data is requested during an audit conducted at that time, etc., it becomes possible to flexibly respond when the disclosure of log data is requested after the system operation. That is, even if all the agreements regarding the handling of log data before the system operation are not determined between the device vendor 1 and the operator 2, it becomes possible to respond to audits by third-party organizations, etc., and it becomes possible to smoothly conduct the contract related to the system operation exchanged between the device vendor 1 and the operator 2.

[0073] Further, since the data protection apparatus 215 according to the present embodiment encrypts log data by using common key encryption in which the encryption key is also used as a decryption key, for example, compared with encryption by attribute-based encryption (CP-ABE: Ciphertext-Policy Attribute-Based Encryption) or the like that can manage the attributes of members who can decrypt and view encrypted data for each data, the processing load is small, and the encryption process can be performed at high speed.

[0074] Furthermore, if the data protection apparatus 215 according to the present embodiment holds two initial keys for one encrypted data frame, it is possible to generate a decryption key corresponding to all the encrypted data included in the data frame.

[0075] In addition, the data protection device 215 according to the present embodiment stores the encrypted data in the storage 22 outside the data protection device 215. Generally, log data is variable-length data generated frequently, and its data size also tends to be large. Therefore, an encryption device for encrypting such log data usually requires a large-capacity storage, and the cost for implementing the encryption device tends to be high. However, the data protection device 215 according to the present embodiment stores the encrypted encrypted data in the storage 22 outside the data protection device 215, and only needs to store two initial keys for each encrypted data frame in the storage 215B inside the device. Therefore, it does not require a large-capacity storage and can reduce the cost for implementing the data protection device 215 to a low cost.

[0076] As described above, two initial keys are stored in the storage 215B of the data protection device 215 according to the present embodiment for each encrypted data frame, and the data size of the data protected by the data protection device 215 can be kept low. Therefore, it is possible to eliminate the garbage collection performed when managing large-capacity data, and reduce the processing load on the data protection device 215. According to this, it is possible to improve the real-time performance of the encryption process executed by the data protection device 215.

[0077] Furthermore, the data protection device 215 according to the present embodiment is provided in the manufacturing device 21, and realizes the various functions 215a to 215d described above by a unique processing unit 215A different from the processing unit 211 of the manufacturing device 21. Therefore, different from a device that realizes various functions by a program stored in a server on the cloud, it is possible to operate locally without depending on the communication environment.

[0078] In the embodiments described above, when the data protection device 215 responds to an audit by a third-party organization, that is, when a part of the log data (post-disclosure data) that is not normally disclosed to both the device vendor 1 and the operator 2 is disclosed to a third party, this has been described. However, the data protection device 215 can also disclose to the operator 2 a part of the log data that is always disclosed to the device vendor 1 and not normally disclosed to the operator 2.

[0079] The log data that is always disclosed to the device vendor 1 and not normally disclosed to the operator 2 includes, for example, data necessary for preventive maintenance by the device vendor 1. Since such log data is data that is always disclosed to a specific person (device vendor 1) who performs preventive maintenance, it may be referred to as specific disclosure data. Note that what log data corresponds to always-disclosed data, post-disclosure data, or specific disclosure data can be arbitrarily determined between the device vendor 1 and the operator 2.

[0080] Preventive maintenance is a maintenance method in which the device vendor 1 collects in real time log data related to equipment maintenance under a maintenance contract with the operator 2, analyzes the log data, detects signs of possible failures that may occur in the manufacturing device 21, and performs equipment maintenance before the manufacturing device 21 fails, thereby preventing failures of the manufacturing device 21.

[0081] The data protection device 215 encrypts the data frames included in the log data corresponding to the specific disclosure data by the encryption process shown in FIGS. 5 and 6. However, in preventive maintenance, since the equipment vendor 1 needs to collect the data frames included in the log data corresponding to the specific disclosure data, which are encrypted data frames (encrypted data series), and sequentially decrypt the data frames, when the data protection device 215 encrypts the data frames included in the log data corresponding to the specific disclosure data, it transmits two initial keys corresponding to the encrypted data frames to the equipment vendor 1 (vendor terminal 11). According to this, the equipment vendor 1 can independently generate a forward key series and a reverse key series based on the two initial keys and the one-way function, and sequentially decrypt the encrypted data frames.

[0082] When the data protection device 215 receives an input of a disclosure request message 301, which is a disclosure request message from the operator terminal 23 (operator 2) asking to disclose a part of the log data corresponding to the specific disclosure data and is digitally signed DS1 with the operator's private key, it uses the operator's public key pre-stored in the storage 215B to confirm the authenticity of the disclosure request message 301. When it is confirmed that the disclosure request message 301 is authentic (that is, when it is confirmed that the digital signature DS1 with the operator's private key is authentic), the data protection device 215 generates, as a decryption key, a forward encryption key corresponding to the data of the data number indicating the start position of the data disclosure section indicated by the disclosure section information 301-2 of the disclosure request message 301 and a reverse encryption key corresponding to the data of the data number indicating the end position of the data disclosure section, and transmits this to the operator terminal 23.

[0083] According to this, the operator 2 can confirm whether the equipment vendor 1 is illegally collecting log data other than the log data corresponding to the specific disclosure data necessary for preventive maintenance. That is, the data protection device 215 according to the present embodiment can respond not only to the audit by the above-mentioned third party institution but also to the extraction inspection by the operator 2. Therefore, the data protection device 215 according to the present embodiment can also function as a deterrent force for suppressing the illegal collection of log data by the equipment vendor 1.

[0084] However, the log data corresponding to the specific disclosure data includes the know-how for detecting failure symptoms, the know-how related to the manufacturing apparatus 21, etc., that is, the know-how of the equipment vendor 1. From the viewpoint of protecting the know-how of the equipment vendor 1, it is desirable to limit the data size of the data included in the data disclosure section and the number of data included in the data disclosure section. Also, it is desirable to limit the operator 2 from making disclosure requests arbitrarily.

[0085] As a method for limiting the data size of the data included in the data disclosure section and the number of data included in the data disclosure section, for example, there is a method that requires the digital signatures of both the equipment vendor 1 and the operator 2 in order to disclose a part of the log data corresponding to the specific disclosure data. According to this, the equipment vendor 1 can confirm the data size of the data included in the data disclosure section requested by the operator 2 and the number of data included in the data disclosure section. When the data size and the number of the data are requested excessively, it is possible to reject the disclosure request from the operator 2 by not performing the digital signature.

[0086] As another method of setting a limit on the data size of the data included in the data disclosure interval or the number of data included in the data disclosure interval, a method is to preset a limit on the data size or the number of the data in the data protection device 215 under the mutual agreement of the device vendor 1 and the operator 2. In this case, the digital signature required to disclose a part of the log data corresponding to the specific disclosure data shall be the digital signature of the operator 2. According to this, in the data protection device 215, it becomes possible to confirm whether the data size of the data included in the data disclosure interval requested by the operator 2 or the number of data included in the data disclosure interval exceeds the preset limit.

[0087] Note that it is assumed that either of the above two methods can be arbitrarily determined by the device vendor 1 and the operator 2.

[0088] In the present embodiment described above, the data protection device 215 generates a plurality of encryption keys such that the number of encryption keys including the initial key included in the key series is the same as the number of data included in the data frame to be encrypted. However, the present invention is not limited to this, and the data protection device 215 may generate a plurality of encryption keys such that the number of encryption keys excluding the initial key included in the key series is the same as the number of data included in the data frame to be encrypted. In this case, the data protection device 215 encrypts the data using an encryption key other than the initial key without using the initial key for encrypting the data included in the data frame to be encrypted.

[0089] So far, the data protection device 215 capable of executing an encryption process that can selectively decrypt the data included in a predetermined interval among a large number of data included in the log data has been described. Hereinafter, a case where such a data protection device 215 further has a forgery verification support function for supporting the forgery verification of encrypted data will be described.

[0090] FIG. 10 is a diagram showing a configuration example of the data protection device 215 according to the present embodiment. The data protection device 215 shown in FIG. 10 is different from the configuration shown in FIG. 3 in that it further has a forgery verification support function 215e as a function realized by the processing unit 215A. Further, the data protection device 215 shown in FIG. 10 is different from the configuration shown in FIG. 3 in that it further stores in the storage 215B a public key pair of a data protection device secret key used in digital signature described later and a data protection device public key which is a key paired with the data protection device secret key. The data protection device public key is also distributed in advance to the vendor terminal 11 and the operator terminal 23 and stored in advance in the storage of each terminal.

[0091] Note that the public key pair of the data protection device secret key and the data protection device public key is generated when the data protection device 215 is manufactured by the device vendor 1, and an X.509 format digital certificate for guaranteeing the correspondence between the data protection device 215 and the data protection device public key is issued by a certification authority (CA: Certificate Authority) for the public key pair.

[0092] The forgery verification support function 215e generates a data frame signature issued for the entire predetermined data frame and a data section signature issued for a predetermined data disclosure section. Here, referring to FIG. 11, a data configuration example of the data frame signature generated by the forgery verification support function 215e will be described. As shown in FIG. 11, the data frame signature 302 is information including a data frame identifier 302-1 of a data frame which is the issuance target of the data frame signature, a hash value 302-2 of the entire data frame (that is, a plaintext hash value), a hash value 302-3 of the entire encrypted data series corresponding to the data frame (that is, a ciphertext hash value), and a digital signature 302-4 by the data protection device secret key (digital signature of the data protection device 215).

[0093] The hash value 302-2 of the entire data frame is calculated by applying a hash function to each of the N pieces of data D_0 to D_n-1 included in the data frame. The hash value 302-3 of the entire encrypted data series is calculated by applying a hash function to each of the N encrypted data encrypted by the encryption process shown in FIG. 5. The digital signature 302-4 by the data protection device secret key is generated using the data protection device secret key stored in the storage 215B. Note that since the data frame identifier 302-1 is the same as the data frame identifier 301-1 shown in FIG. 4, the detailed description thereof is omitted here.

[0094] When all of the N pieces of data included in the data frame to be encrypted are encrypted by the encryption process shown in FIG. 5, the forgery verification support function 215e generates a data frame signature 302 for the data frame. The generated data frame signature 302 is output to the operator terminal 23 and is managed by the operator 2, for example, stored in the storage 233.

[0095] Note that the forgery verification support function 215e may record the generated data frame signature 302 in an external blockchain. According to this, it is possible to leave a trace indicating that the data frame corresponding to the data frame signature 302 existed since the time when the data frame signature 302 was recorded in the blockchain. In addition, since the blockchain is excellent in forgery resistance, by recording the generated data frame signature 302 in the blockchain, it is possible to improve the forgery resistance and enhance the credibility of the audit by a third-party institution.

[0096] Next, with reference to FIG. 12, a data configuration example of the data section signature generated by the forgery verification support function 215e will be described. As shown in FIG. 12, the data section signature 303 includes a data frame identifier 303-1 of a data frame including a data disclosure section that is the issuance target of the data section signature, a hash value 303-2 of data included in the data disclosure section (i.e., a plaintext hash value), a hash value 303-3 of encrypted data included in the data disclosure section (i.e., a ciphertext hash value), disclosure section information 303-4 indicating the data disclosure section, and a digital signature 303-5 by the data protection device private key (the digital signature of the data protection device 215).

[0097] The hash value 303-2 of the data included in the data disclosure section is calculated by applying a hash function to each of one or more data included in the data disclosure section. The hash value 303-3 of the encrypted data included in the data disclosure section is calculated by applying a hash function to each of one or more encrypted data corresponding to one or more data included in the data disclosure section. The digital signature 303-5 by the data protection device private key is generated using the data protection device private key stored in the storage 215B. Since the data frame identifier 303-1 is the same as the data frame identifier 301-1 shown in FIG. 4, the detailed description thereof is omitted here. Since the disclosure section information 303-4 is also the same as the disclosure section information 301-2 shown in FIG. 4, the detailed description thereof is omitted here. However, the disclosure request message 301 itself shown in FIG. 4 may be embedded in the disclosure section information 303-4.

[0098] When the disclosure request message 301 is input from the operator terminal 23, the forgery verification support function 215e generates a data section signature 303 for a predetermined section of the data frame indicated by the disclosure request message 301.

[0099] Next, with reference to the sequence chart of FIG. 13, a series of processes executed to select and disclose encrypted data included in a predetermined section among a plurality of encrypted data encrypted by the data protection device 215 will be described. The series of processes shown in FIG. 13 not only selects and discloses the encrypted data included in the predetermined section, but also differs from the series of processes shown in FIG. 7 in that it also performs forgery verification on the data frame corresponding to the encrypted data, the encrypted data series including the encrypted data, and the encrypted data.

[0100] First, the operator terminal 23 generates a disclosure request message 301 for requesting disclosure of the encrypted data included in a predetermined section among the plurality of encrypted data included in a predetermined encrypted data series. Similar to the case shown in FIG. 8, the generated disclosure request message 301 is attached with a digital signature DS1 using the operator private key.

[0101] The operator terminal 23 inputs the disclosure request message 301 attached with the digital signature DS1 using the operator private key, the data frame signature 302 issued in advance for the data frame identified by the data frame identifier 301-1 included in the disclosure request message 301, and the predetermined encrypted data series stored in the storage 22 to the data protection device 215 (step S21).

[0102] When the processing unit 215A of the data protection device 215 receives the input of the disclosure request message 301, the data frame signature 302, and the predetermined encrypted data series from the operator terminal 23, it executes a series of processes shown in FIG. 14 (step S22).

[0103] FIG. 14 is a flowchart for explaining the process of step S22 shown in FIG. 13 in more detail. First, the processing unit 215A uses the operator public key pre-stored in the storage 215B to confirm the authenticity of the digital signature DS1 using the operator private key attached to the disclosure request message 301 input from the operator terminal 23 (step S22-1).

[0104] When it is confirmed that the digital signature DS1 using the operator's private key attached to the disclosure request message 301 is authentic, the processing unit 215A uses the public key of the data protection device pre-stored in the storage 215B to confirm the authenticity of the digital signature 302-4 using the private key of the data protection device included in the data frame signature 302 input from the operator terminal 23. Further, when it is confirmed that the digital signature DS1 using the operator's private key attached to the disclosure request message 301 is authentic, the processing unit 215A checks whether the data frame identifier 301-1 included in the disclosure request message 301 matches the data frame identifier 302-1 included in the data frame signature 302 (step S22-2).

[0105] When it is confirmed that the digital signature 302-4 using the private key of the data protection device included in the data frame signature 302 is authentic and it is confirmed that the data frame identifier 301-1 included in the disclosure request message 301 matches the data frame identifier 302-1 included in the data frame signature 302, the processing unit 215A calculates the hash value of the entire data frame and the hash value of the entire encrypted data series using the encrypted data series input from the operator terminal 23 (step S22-3). Note that the hash value of the entire data frame is calculated by decrypting the data frame from the encrypted data series using the forward initial key and the reverse initial key stored in the storage 215B.

[0106] Subsequently, the processing unit 215A checks whether the hash value 302-2 of the entire data frame included in the data frame signature 302 matches the hash value of the entire data frame calculated by the process of step S22-3. Further, the processing unit 215A checks whether the hash value 302-3 of the entire encrypted data series included in the data frame signature 302 matches the hash value of the entire encrypted data series calculated by the process of step S22-3 (step S22-4). According to this, it is possible to verify whether the data frame and the encrypted data series corresponding to the data frame have been tampered with.

[0107] When the hash value 302-2 of the entire data frame included in the data frame signature 302 matches the hash value of the entire data frame calculated by the process of step S22-3, and the hash value 302-3 of the entire encrypted data series included in the data frame signature 302 matches the hash value of the entire encrypted data series calculated by the process of step S22-3, and it is confirmed that the data frame and the encrypted data series corresponding to the data frame have not been tampered with, the processing unit 215A generates a data section signature 303 for the data disclosure section indicated by the disclosure section information 301-2 of the disclosure request message 301 input from the operator terminal 23. More specifically, the processing unit 215A calculates the hash value 303-2 of the data included in the data disclosure section and the hash value 303-3 of the encrypted data included in the data disclosure section, and generates a data section signature 303 in the format shown in FIG. 12 (step S22-5).

[0108] Returning again to the description of FIG. 13. The processing unit 215A outputs the data section signature 303 generated by the process of step S22-5 to the operator terminal 23 (step S23).

[0109] When the operator terminal 23 receives the input of the data section signature 303, it transmits the data section signature 303, the disclosure request message 301 with the digital signature DS1 generated by the operator's private key in the process of step S21, and the encrypted data included in the data disclosure section to the vendor terminal 11 (step S24).

[0110] When the vendor terminal 11 receives the input of the data section signature 303, the disclosure request message 301, and the encrypted data included in the data disclosure section from the operator terminal 23, it executes a series of processes shown in FIG. 15 (step S25).

[0111] FIG. 15 is a flowchart for explaining the process of step S25 shown in FIG. 13 in more detail. The vendor terminal 11 uses the operator public key pre-stored in the storage 113 to verify the authenticity of the digital signature DS1 using the operator private key attached to the disclosure request message 301 input from the operator terminal 23 (step S25-1).

[0112] When the vendor terminal 11 verifies that the digital signature DS1 using the operator private key attached to the disclosure request message 301 is authentic, it uses the data protection device public key pre-stored in the storage 113 to verify the authenticity of the digital signature 303-5 using the data protection device private key included in the data section signature 303 input from the operator terminal 23 (step S25-2).

[0113] When the vendor terminal 11 verifies that the digital signature 303-5 using the data protection device private key included in the data section signature 303 is authentic, it calculates the hash value of the encrypted data included in the data disclosure section input from the operator terminal 23 (step S25-3).

[0114] Subsequently, the vendor terminal 11 checks whether the hash value 303-3 of the encrypted data included in the data disclosure section of the data section signature 303 matches the hash value of the encrypted data included in the data disclosure section calculated by the process of step S25-3 (step S25-4). According to this, it is possible to verify whether the encrypted data included in the data disclosure section has been tampered with.

[0115] When the hash value 303-3 of the encrypted data included in the data disclosure section of the data section signature 303 matches the hash value of the encrypted data included in the data disclosure section calculated by the process of step S25-3, and it is verified that the encrypted data included in the data disclosure section has not been tampered with, as shown in FIG. 9, the vendor terminal 11 executes a process of further attaching a digital signature DS2 using the vendor private key to the disclosure request message 301 attached with the digital signature DS1 using the operator private key (step S25-5).

[0116] Return to the description of FIG. 13 again. The vendor terminal 11 transmits the disclosure request message 301 (that is, the disclosure request message 301 with multiple signatures) further appended with the digital signature DS2 by the vendor private key to the operator terminal 23 by the process of step S25-5 (step S26). Hereinafter, since the processes of steps S27 to S30 are the same as the processes of steps S13 to S16 shown in FIG. 7, the detailed description thereof is omitted here.

[0117] As described above, the data protection device 215 according to the present embodiment further has a forgery verification support function 215e realized by the processing unit 215A, issues a data frame signature 302 for the data frame with the completion of the encryption of the data frame, and outputs this to the operator terminal 23. When the data frame signature 302 is input from the operator terminal 23, the data protection device 215 can verify whether the data frame and the encrypted data series corresponding to the data frame are forged using the data frame signature 302. That is, the data protection device 215 does not need to store the hash value for each data frame in the storage 215B for verifying the presence or absence of the above forgery, can keep the data size of the data managed by the data protection device 215 low, and can achieve cost reduction.

[0118] In addition, since the data protection device 215 according to this embodiment can issue a data frame signature 302 including the hash value 302-3 of the entire encrypted data series, it can support the forgery verification of the encrypted data series. For example, when a third-party institution audits the data management system of operator 2, the third-party institution calculates the hash value of the entire encrypted data series provided by operator 2, and checks whether the hash value matches the hash value 302-3 of the entire encrypted data series included in the data frame signature 302, so as to audit the data management system of operator 2. In this case, since the encrypted data series is not decrypted, operator 2 can provide the encrypted data series to the third-party institution without obtaining the consent of device vendor 1, and can smoothly respond to the audit by the third-party institution.

[0119] Furthermore, when a disclosure request message 301 is input from the operator terminal 23, the data protection device 215 according to this embodiment issues a data section signature 303 for the data disclosure section indicated by the disclosure section information 301-2 of the disclosure request message 301, and outputs this to the operator terminal 23. In addition, the operator terminal 23 transmits the data section signature 303 issued by the data protection device 215, the disclosure request message 301, and the encrypted data included in the data disclosure section to the vendor terminal 11. According to this, device vendor 1 can verify whether the encrypted data provided by operator 2 has been forged before attaching the digital signature DS2 using the vendor private key to the disclosure request message 301 (that is, before consenting to the disclosure of the encrypted data included in the data disclosure section). According to this, it is possible to eliminate the concern that operator 2 provides device vendor 1 with deliberately damaged encrypted data and makes false claims such as "the data was damaged due to force majeure. We were also unable to restore the data".

[0120] In the series of processes shown in FIG. 13, it was assumed that the data protection device 215 transmits the decryption key to the vendor terminal 11 and the operator terminal 23. However, as a method for distributing the decryption key, a form in which the data protection device 215 outputs the decryption key to the operator terminal 23 and the operator terminal 23 further transmits the decryption key to the vendor terminal 11 can be considered. In the case of such a decryption key distribution method, for example, a case may occur in which the device vendor 1 cannot obtain the decryption key, such as a communication failure occurring between the device vendor 1 and the operator 2 and the decryption key cannot be normally transmitted, or the operator 2 deliberately does not transmit the decryption key to the device vendor 1.

[0121] However, in the present embodiment, when the process of step S26 shown in FIG. 13 is executed, the device vendor 1 holds the disclosure request message 301 with the digital signature DS1 by the operator private key and the digital signature DS2 by the vendor private key, and the data section signature 303. Therefore, it is possible to prove to a third party that there was an agreement between the device vendor 1 and the operator 2 regarding the disclosure of the encrypted data included in a predetermined section (the third party verifies the existence of the above agreement). For this reason, the device vendor 1 can request the operator 2 to reissue the decryption key, execute the series of processes shown in FIG. 13 again, and receive the reissued decryption key. Even if the operator 2 rejects the decryption key reissue process, it is possible to request (enforce) contract performance through a third party.

[0122] In FIG. 13, a case where the encrypted data series is not disclosed to both the device vendor 1 and the operator 2 is assumed. However, for example, when preventive maintenance is performed by the device vendor 1, that is, even when the encrypted data series (specific disclosure data) is always disclosed to the device vendor 1 and not normally disclosed to the operator 2, it is also applicable.

[0123] If the encrypted data series (specific disclosure data) is always disclosed to equipment vendor 1 for preventive maintenance, since equipment vendor 1 has the forward initial key and the reverse initial key, it is possible for equipment vendor 1 to forge (fabricate) the encrypted data from which the decryption result in the normal data format can be obtained. Even if an encryption method with forgery verification ability such as AES-CCM or AES-GCM is used, since equipment vendor 1 has the correct secret key, it can forge data that passes the forgery verification of AES-CCM or AES-GCM for individual data. However, when the above data frame signature 302 is issued, even if the data is forged (fabricated) by equipment vendor 1, it is possible to detect the forgery of the data by using the hash value 302-2 of the entire data frame included in the data frame signature 302 and the hash value 302-3 of the entire encrypted data series.

[0124] Also, after both equipment vendor 1 and operator 2 are given the decryption key for decrypting a predetermined encrypted data series, both equipment vendor 1 and operator 2 can forge the above data. However, similar to the above case, since it is possible to detect the forgery of the data by using the hash value 302-2 of the entire data frame included in the data frame signature 302 and the hash value 302-3 of the entire encrypted data series, the forgery of the data can be suppressed.

[0125] In addition, even when the encrypted data series (specific disclosure data) is always disclosed to equipment vendor 1 for preventive maintenance and a part of the encrypted data series is requested to be disclosed by operator 2, the forgery verification support function 215e can be applied. However, in this case, since it is sufficient for operator 2 to confirm that the data has not been forged, the issuance of the data section signature 303 and the forgery verification process using the data section signature 303 may be omitted.

[0126] According to the above-described embodiment, it is possible to provide a data protection device 215, an electronic device, a method, and a program that can execute an encryption process capable of selectively decrypting data included in a predetermined section among a large number of data included in log data.

[0127] In the present embodiment, a case where the information processing system is a product manufacturing system and the data protection device 215 is applied to the manufacturing device 21 including the product manufacturing unit 213 and the log data generation unit 214 has been described. However, the present invention is not limited to this. When the information processing system is a power control system, the data protection device 215 can be applied to a power generation device including a power generation unit and a log data generation unit. Alternatively, when the information processing system is a communication system, the data protection device 215 can be applied to a communication device including a communication control unit and a log data generation unit. Note that the above-described manufacturing device 21, power generation device, and communication device (that is, a device including the data protection device 215 and the log data generation unit) may be referred to as an electronic device.

[0128] Also, related parties of the log data generated by the log data generation unit 214, such as the device vendor 1 and the operator 2, may be referred to as entities.

[0129] Although some embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be implemented in various other forms, and various omissions, replacements, and changes can be made without departing from the gist of the invention. These embodiments and their modifications are included in the scope and gist of the invention, and are also included in the invention described in the claims and its equivalent scope.

Description of Reference Numerals

[0130] 1... Machine vendor, 11... Vendor terminal, 2... Operator, 21... Manufacturing device, 213... Product manufacturing department, 214... Log data generation department, 215... Data protection device, 215A... Processing unit, 215a... Initial key generation function, 215b... Key sequence generation function, 215c... Log data encryption function, 215d... Encrypted data disclosure control function, 215e... Tampering verification support function, 215B... Storage, 22... Storage, 23... Operator terminal.

Claims

1. a processing unit that performs an encryption process on log data including a data frame; a storage for storing a first public key or a first digital certificate for verifying a digital signature corresponding to a first entity that is a party to the data frame, a second public key or a second digital certificate for verifying a digital signature corresponding to a second entity that is a party to the data frame and different from the first entity, a first initial key, and a second initial key; The processing unit includes: generating the first initial key and the second initial key corresponding to the data frame including a plurality of data generated in time series; generating a first key sequence based on the first initial key and a one-way function; the first key series is a key series including encryption keys corresponding to the plurality of data items, and includes the first initial key and a plurality of first encryption keys generated in a forward direction with respect to a time series of the plurality of data items; generating a second key sequence based on the second initial key and the one-way function; the second key series is a key series including encryption keys corresponding to the plurality of data, and includes the second initial key and a plurality of second encryption keys generated in a reverse direction with respect to a time series of the plurality of data; encrypting each of the plurality of data items using the first initial key included in the first key sequence and a corresponding encryption key among the plurality of first encryption keys; further encrypting each of the plurality of data encrypted by the encryption key included in the first key series with a corresponding encryption key among the second initial key and the plurality of second encryption keys included in the second key series; accepting an input of a disclosure request message requesting disclosure of data included in a predetermined section among a plurality of pieces of data encrypted with an encryption key included in the first key series and an encryption key included in the second key series; the disclosure request message indicates a first number indicating data corresponding to a start position of the predetermined section, and a second number indicating data corresponding to an end position of the predetermined section, the disclosure request message is affixed with a digital signature of the first entity and a digital signature of the second entity; using the first public key or the first digital certificate to verify the authenticity of the digital signature of the first entity attached to the disclosure request message; using the second public key or the second digital certificate to verify the authenticity of the digital signature of the second entity attached to the disclosure request message; generating, as a decryption key, the first encryption key corresponding to the data indicated by the first number, based on the first initial key and the one-way function when it is confirmed that both the digital signature of the first entity and the digital signature of the second entity are authentic; generating, as a decryption key, the second encryption key corresponding to the data indicated by the second number, based on the second initial key and the one-way function; transmitting the two generated decryption keys to at least one of the first entity and the second entity; Data protection device.

2. The processing unit includes: encrypting each of the plurality of data items with an encryption key included in the first key series and an encryption key included in the second key series, a first signature is generated including a first hash value of an entire data frame including the plurality of data items and a second hash value of an entire encrypted data series including the encrypted plurality of data items; outputting the first signature to the first entity; when receiving an input of the first signature output from the first entity, verifying whether or not the data frame and the encrypted data sequence have been tampered with based on the first signature; generating a second signature including a third hash value of the data included in the predetermined section and a fourth hash value of the encrypted data included in the predetermined section when it is confirmed that the data frame and the encrypted data sequence have not been tampered with; outputting the second signature to the first entity; The second signature is used by the second entity to verify whether or not the data included in the predetermined section and the encrypted data included in the predetermined section have been tampered with. The data protection device of claim 1 .

3. A processing unit that performs an encryption process on log data including a data frame; a storage for storing a first public key or a first digital certificate, a first initial key, and a second initial key in digital signature verification corresponding to a first entity that is a party to the data frame; The processing unit includes: generating the first initial key and the second initial key corresponding to the data frame including a plurality of data generated in time series; the first initial key and the second initial key are shared with a second entity that is a party to the data frame and different from the first entity; generating a first key sequence based on the first initial key and a one-way function; the first key series is a key series including encryption keys corresponding to the plurality of data items, and includes the first initial key and a plurality of first encryption keys generated in a forward direction with respect to a time series of the plurality of data items; generating a second key sequence based on the second initial key and the one-way function; the second key series is a key series including encryption keys corresponding to the plurality of data, and includes the second initial key and a plurality of second encryption keys generated in a reverse direction with respect to a time series of the plurality of data; encrypting each of the plurality of data items using the first initial key included in the first key sequence and a corresponding encryption key among the plurality of first encryption keys; further encrypting each of the plurality of data encrypted by the encryption key included in the first key series with a corresponding encryption key among the second initial key and the plurality of second encryption keys included in the second key series; accepting an input of a disclosure request message requesting disclosure of data included in a predetermined section among a plurality of pieces of data encrypted with an encryption key included in the first key series and an encryption key included in the second key series; the disclosure request message indicates a first number indicating data corresponding to a start position of the predetermined section, and a second number indicating data corresponding to an end position of the predetermined section, The disclosure request message is digitally signed by the first entity; using the first public key or the first digital certificate to verify the authenticity of the digital signature of the first entity attached to the disclosure request message; if it is confirmed that the digital signature of the first entity is authentic, generating, as a decryption key, the first encryption key corresponding to the data indicated by the first number, based on the first initial key and the one-way function; generating, as a decryption key, the second encryption key corresponding to the data indicated by the second number, based on the second initial key and the one-way function; transmitting the two generated decryption keys to the first entity; Data protection device.

4. The processing unit includes: when each of the plurality of data is encrypted with an encryption key included in the first key series and an encryption key included in the second key series, a first signature is generated, the first signature including a first hash value of an entire data frame including the plurality of data and a second hash value of an entire encrypted data series including the encrypted plurality of data; Outputting the first signature to the first entity. The data protection device according to claim 3.

5. The processing unit includes: when receiving an input of the first signature output from the first entity, verifying whether or not the data frame and the encrypted data have been tampered with based on the first signature; The data protection device according to claim 4.

6. The processing unit includes: generating the first initial key and the second initial key using a true random number generating function; The data protection device according to any one of claims 1 to 5.

7. A data protection device according to any one of claims 1 to 6, A log data generating device for generating the log data; An electronic device comprising:

8. A method executed by a data protection device having a processing unit that performs an encryption process on log data including a data frame, and a storage that stores a first public key or a first digital certificate for verifying a digital signature corresponding to a first entity that is a party to the data frame, a second public key or a second digital certificate for verifying a digital signature corresponding to a second entity that is a party to the data frame and different from the first entity, a first initial key, and a second initial key, comprising: generating the first initial key and the second initial key corresponding to the data frame including a plurality of data generated in time series; generating a first key sequence based on the first initial key and a one-way function; the first key series is a key series including encryption keys corresponding to the plurality of data items, and includes the first initial key and a plurality of first encryption keys generated in a forward direction with respect to a time series of the plurality of data items; generating a second key sequence based on the second initial key and the one-way function; the second key series is a key series including encryption keys corresponding to the plurality of data, and includes the second initial key and a plurality of second encryption keys generated in a reverse direction with respect to a time series of the plurality of data; encrypting each of the plurality of data items using the first initial key included in the first key sequence and a corresponding encryption key among the plurality of first encryption keys; further encrypting each of the plurality of data encrypted by the encryption key included in the first key series with a corresponding encryption key among the second initial key and the plurality of second encryption keys included in the second key series; accepting an input of a disclosure request message requesting disclosure of data included in a predetermined section among a plurality of pieces of data encrypted with an encryption key included in the first key series and an encryption key included in the second key series; the disclosure request message indicates a first number indicating data corresponding to a start position of the predetermined section, and a second number indicating data corresponding to an end position of the predetermined section, the disclosure request message is affixed with a digital signature of the first entity and a digital signature of the second entity; using the first public key or the first digital certificate to verify the authenticity of the digital signature of the first entity attached to the disclosure request message; using the second public key or the second digital certificate to verify the authenticity of the digital signature of the second entity attached to the disclosure request message; generating, as a decryption key, the first encryption key corresponding to the data indicated by the first number, based on the first initial key and the one-way function when it is confirmed that both the digital signature of the first entity and the digital signature of the second entity are authentic; generating, as a decryption key, the second encryption key corresponding to the data indicated by the second number, based on the second initial key and the one-way function; transmitting the two generated decryption keys to at least one of the first entity and the second entity; method.

9. A computer of a data protection device comprising: a processing unit that performs an encryption process on log data including a data frame; a first public key or a first digital certificate for verifying a digital signature corresponding to a first entity that is a party to the data frame; a second public key or a second digital certificate for verifying a digital signature corresponding to a second entity that is a party to the data frame and different from the first entity; and storage that stores a first initial key and a second initial key. generating the first initial key and the second initial key corresponding to the data frame including a plurality of data generated in time series; generating a first key sequence based on the first initial key and a one-way function; the first key series is a key series including encryption keys corresponding to the plurality of data items, and includes the first initial key and a plurality of first encryption keys generated in a forward direction with respect to a time series of the plurality of data items; generating a second key sequence based on the second initial key and the one-way function; the second key series is a key series including encryption keys corresponding to the plurality of data, and includes the second initial key and a plurality of second encryption keys generated in a reverse direction with respect to a time series of the plurality of data; encrypting each of the plurality of data items using the first initial key included in the first key series and a corresponding encryption key among the plurality of first encryption keys; further encrypting each of the plurality of data encrypted by the encryption key included in the first key series with a corresponding encryption key among the second initial key and the plurality of second encryption keys included in the second key series; when an input of a disclosure request message is received requesting disclosure of data included in a predetermined section among a plurality of pieces of data encrypted with an encryption key included in the first key series and an encryption key included in the second key series, the disclosure request message indicates a first number indicating data corresponding to a start position of the predetermined section, and a second number indicating data corresponding to an end position of the predetermined section, the disclosure request message is affixed with a digital signature of the first entity and a digital signature of the second entity; Verifying authenticity of a digital signature of the first entity attached to the disclosure request message using the first public key or the first digital certificate; Verifying authenticity of a digital signature of the second entity attached to the disclosure request message using the second public key or the second digital certificate; generating, as a decryption key, the first encryption key corresponding to the data indicated by the first number, based on the first initial key and the one-way function when it is confirmed that both the digital signature of the first entity and the digital signature of the second entity are authentic; generating, as a decryption key, the second encryption key corresponding to the data indicated by the second number, based on the second initial key and the one-way function; transmitting the two generated decryption keys to at least one of the first entity and the second entity; program.

Citation Information

Patent Citations

  • JP1975076110A

  • Content regenerating system, device, and program

    JP2006254204A

  • Message authentication system, message transmitter, message receiver, message transmitting method, message receiving method, and program

    JP2006345408A

  • System and method for proactively detecting software tampering

    JP2006511877A

  • Method and apparatus for accessing stored digital program

    JP2010257475A