Information Processing Method, Information Processing System, Information Processing Apparatus, and Information Processing Program
The information processing method and system enhance data security by encoding target data and storing it separately from a blockchain network, addressing the risk of illegal data restoration and leakage in existing distributed data storage systems.
Patent Information
- Application Number
- JP2021061797
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-03-31
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-03-31
AI Technical Summary
The existing system for distributed data storage, as described in Patent Document 1, faces a significant risk of illegal data restoration and leakage due to unauthorized acquisition of distributed data and information from shareholders, necessitating enhanced data security measures.
The proposed solution involves an information processing method and system that utilizes a blockchain network to securely store and manage data. This is achieved by generating encoding information to specify an algorithm for encoding target data, creating encoded data based on this algorithm, and storing the encoded data separately from the blockchain network while connecting a block with the encoding information to the blockchain.
This approach significantly enhances the security of stored data by making it difficult to steal the secretly stored target data, as the encoded information and data are stored separately, thereby reducing the risk of illegal data restoration and leakage.
Smart Images

Figure 0007684072000001 
Figure 0007684072000002 
Figure 0007684072000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to an information processing method, an information processing system, an information processing apparatus, and an information processing program.
Background Art
[0002] Conventionally, a system is known in which a main controller distributes data processing to generate distributed data and stores the distributed data in a distributed manner. For example, Patent Document 1 discloses a system in which distributed information used for restoring distributed data is stored in a shareholder in association with the distributed data.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In the system described in Patent Document 1, there is an increased risk that the original data is illegally restored and leaked due to the illegal acquisition of distributed data and distributed information from each shareholder. Improvement in data security is required.
[0005] In view of such circumstances, an object of the present disclosure is to enhance the security of stored data.
Means for Solving the Problems
[0006] An information processing method according to an embodiment of the present disclosure is executed by an information processing system including a plurality of information processing devices each functioning as a peer of a network constituting a blockchain network. The information processing method includes: generating encoding information for specifying an algorithm for encoding target data; generating encoded data obtained by encoding the target data based on the algorithm specified by the encoding information; storing the encoded data separately from the blockchain network in a first information processing device belonging to a first channel among the plurality of information processing devices; and connecting a block including the encoding information to a blockchain recorded in the blockchain network.
[0007] An information processing system according to an embodiment of the present disclosure includes a plurality of information processing devices each functioning as a peer of a network constituting a blockchain network. At least one of the plurality of information processing devices generates encoding information for specifying an algorithm for encoding target data, and generates encoded data obtained by encoding the target data based on the algorithm specified by the encoding information. A first information processing device belonging to a first channel among the plurality of information processing devices stores the encoded data separately from the blockchain network. Each of the information processing devices connects a block including the encoding information to a blockchain recorded in the blockchain network.
[0008] An information processing apparatus according to an embodiment of the present disclosure functions as a peer that constitutes a blockchain network, together with at least a first information processing apparatus belonging to a first channel. The information processing apparatus generates encoding information that specifies an algorithm for encoding target data, generates encoded data obtained by encoding the target data based on the algorithm specified by the encoding information, outputs the encoded data to the first information processing apparatus so that the first information processing apparatus stores the encoded data separately from the blockchain network, and concatenates a block including the encoding information to a blockchain recorded in the blockchain network.
[0009] An information processing program according to an embodiment of the present disclosure is executed by an information processing apparatus that functions as a peer that constitutes a blockchain network, together with at least a first information processing apparatus belonging to a first channel. The information processing program causes the information processing apparatus to execute steps of generating encoding information that specifies an algorithm for encoding target data, generating encoded data obtained by encoding the target data based on the algorithm specified by the encoding information, outputting the encoded data to the first information processing apparatus so that the first information processing apparatus stores the encoded data separately from the blockchain network, and concatenating a block including the encoding information to a blockchain recorded in the blockchain network.
Advantages of the Invention
[0010] According to an information processing method, an information processing system, an information processing apparatus, and an information processing program according to an embodiment of the present disclosure, the security of stored data is enhanced.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Mode for Carrying Out the Invention
[0012] (Overview of Information Processing System 1) An information processing system 1 according to an embodiment (see FIG. 1) can store target data in a concealed manner. The data to be concealed is also referred to as target data. Specifically, the information processing system 1 encodes the target data based on a predetermined algorithm. The predetermined algorithm is also referred to as encoding information. The encoding information may include the program itself for encoding the target data. The program for encoding the target data is also referred to as a smart contract. The encoded data is also referred to as encoded data. The information processing system 1 distributes and stores the encoded data in a plurality of information processing devices 2 (see FIG. 1). Further, the information processing system 1 records the encoding information in a blockchain managed by the plurality of information processing devices 2. By doing so, when storing the target data in a concealed manner, the security of the stored target data can be enhanced. Hereinafter, a configuration example and an operation example of the information processing system 1 will be described.
[0013] (Configuration example of information processing system 1) As shown in FIG. 1, an information processing system 1 according to an embodiment includes information processing devices 2A to 2G. When there is no need to distinguish between the information processing devices 2A to 2G, they are simply referred to as information processing devices 2. The number of information processing devices 2 is not limited to 7, and may be 6 or less or 8 or more. The information processing devices 2 are communicably connected to each other via a network 10. The network 10 may be, for example, the Internet or an intranet. Each information processing device 2 functions as a peer of the network 10 that constitutes a blockchain network. It can also be said that the information processing system 1 includes a plurality of information processing devices 2 each functioning as a peer of the network 10 that constitutes a blockchain network.
[0014] In this embodiment, it is assumed that the blockchain network is a consortium-type blockchain, but it may be of other forms. The information processing devices 2 are connected to each other by P2P (Peer to Peer) communication, but may be connected by other communication methods. The information processing device 2 is also referred to as a node in P2P communication.
[0015] As shown in FIG. 2, the information processing apparatus 2 includes a control unit 21, a storage unit 22, a communication unit 23, an output unit 24, and an input unit 25.
[0016] The control unit 21 may be configured to include one or more processors, one or more programmable circuits, one or more dedicated circuits, or a combination thereof. The processor may be, for example, a general-purpose processor such as a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit), or a dedicated processor specialized for a predetermined process, but is not limited thereto. The programmable circuit may be, for example, an FPGA (Field-Programmable Gate Array), but is not limited thereto. The dedicated circuit may be, for example, an ASIC (Application Specific Integrated Circuit), but is not limited thereto.
[0017] The storage unit 22 may be configured to include one or more memories. The memory may include, for example, a semiconductor memory, a magnetic memory, or an optical memory, etc., but is not limited thereto. The storage unit 22 may be configured to include an electromagnetic storage medium such as a magnetic disk. The storage unit 22 may function as, for example, a main storage device, an auxiliary storage device, or a cache memory of the control unit 21. The storage unit 22 stores any information used for the operation of the information processing apparatus 2. For example, the storage unit 22 may store a system program, an application program, etc.
[0018] The communication unit 23 may be configured to include one or more communication interfaces for communicating with other information processing apparatuses 2 via the network 10. The communication interface may be configured to be communicable based on various communication standards such as a mobile communication standard such as 4G (4th Generation) or 5G (5th Generation), a wired LAN (Local Area Network) standard, or a wireless LAN standard.
[0019] The output unit 24 may be configured to include one or more output devices that output information so that it can be recognized by the user. The output device may include, for example, a display that displays information as an image, character, symbol, etc., or a speaker that outputs information as sound. The output device is not limited to these and may include various other devices.
[0020] The input unit 25 may be configured to include one or more input devices that receive user operation inputs in the information processing apparatus 2. The input device may include, for example, physical keys, capacitive keys, a touch screen provided integrally with the display of the output unit 24, a microphone that receives voice input, or a camera, etc. The input device is not limited to these and may include various other devices.
[0021] The information processing system 1 further includes a storage device 5. The storage device 5 may be configured to include an electromagnetic storage medium such as a magnetic disk. The storage device 5 may be configured to include one or more memories. The memory may be configured to be the same as or similar to the storage unit 22 of the information processing apparatus 2. The storage device 5 may be configured integrally with the storage unit 22 of the information processing apparatus 2, or may be configured separately from the storage unit 22. The storage unit 22 of the information processing apparatus 2 may implement the functions of the storage device 5.
[0022] The information processing apparatus 2 is connected to the storage device 5. The information processing apparatus 2 stores information related to the blockchain in the storage device 5. For example, as shown in FIG. 3, the storage device 5 stores information on blocks 4A to 4C connected to the blockchain as information related to the blockchain. When it is not necessary to distinguish between blocks 4A to 4C, they are simply referred to as block 4.
[0023] The memory device 5 may have a first memory area 51 and a second memory area 52. The first memory area 51 and the second memory area 52 may be physically separated areas within the memory device 5, or may be logically separated areas. When the memory device 5 is configured to include a plurality of memories or media, the first memory area 51 and the second memory area 52 may be associated with different memories or media respectively. In the present embodiment, the memory device 5 stores the information of block 4 in the first memory area 51 and stores the encoded data described later in the second memory area 52. That is, in the present embodiment, the memory device 5 separates the areas for storing the information of block 4 and the encoded data respectively. The memory device 5 does not necessarily need to separate the areas for storing the information of block 4 and the encoded data.
[0024] In the information processing system 1, each information processing device 2 stores the information of block 4 as information related to the blockchain in the memory device 5 of each information processing device 2. When each information processing device 2 connects a new block 4D to blocks 4A to 4C stored in the memory device 5 as shown in FIG. 3, each information processing device 2 approves the connection of the new block 4D to each other by calculating the hash value of the block 4D. In addition, each information processing device 2 confirms that the information of each block 4 has not been tampered with by calculating the hash value of each block 4 stored in the memory device 5. By operating as described above, each information processing device 2 functions as a blockchain network that manages the blockchain.
[0025] (Operation example of information processing system 1) The information processing system 1 executes a storage operation of storing encoded data obtained by encoding target data, and a read operation of decoding and reading out the stored encoded data.
[0026] <Configuration example of storage operation> The information processing system 1 may store target data and enhance the security of the stored target data by executing each procedure of the information processing method shown as a flowchart in FIG. 4, for example. The information processing method may be realized as an information processing program executed by the control unit 21 of each information processing device 2. The information processing program may be stored in a non-transitory computer-readable medium.
[0027] The information processing device 2A of the information processing system 1 receives, via the input unit 25, an operation regarding an instruction to secretly store target data from an operator 8 (see FIG. 1). The control unit 21 of the information processing device 2A generates encoding information to be used for encoding the target data (step S1). Specifically, the encoding information corresponds to information specifying an algorithm used by the control unit 21 to encode the target data and enhance the confidentiality of the target data. That is, the control unit 21 generates an algorithm to be used for encoding the target data. The algorithm used for encoding the target data is also referred to as an encoding algorithm.
[0028] The encoding algorithm may include various types of algorithms capable of enhancing the confidentiality of the target data. The encoding algorithm may include, for example, an algorithm for dividing the target data. The encoding algorithm may include, for example, an algorithm for masking the target data with predetermined mask data. The encoding algorithm may include, for example, an algorithm for encrypting the target data. The algorithm for encrypting the target data may include key data used for encryption.
[0029] The control unit 21 may randomly generate an encoding algorithm. For example, the control unit 21 may randomly generate the algorithm itself. The control unit 21 may randomly generate an encoding algorithm by randomly determining which algorithm to adopt from among predetermined algorithms. Also, in the algorithm of each method, the control unit 21 may randomly determine the specific rules for encoding the target data. When the encoding algorithm includes an algorithm for encrypting the target data, the control unit 21 may randomly determine the key data used for encryption.
[0030] The control unit 21 may generate a pseudo-random number and randomly determine an encoding algorithm based on the pseudo-random number. The control unit 21 may randomly determine an encoding algorithm based on a random number generated by a random number generator based on thermal noise or the like.
[0031] The control unit 21 of the information processing apparatus 2A encodes the target data based on the generated encoded information (step S2). The encoded target data is also referred to as encoded data. When the target data is divided, the encoded data includes the divided data obtained by dividing the target data. The number of divided data may be two or more.
[0032] When the target data is masked with predetermined mask data, the encoded data includes the masked data and the masked data. The number of mask data may be one or two or more.
[0033] When the target data is encrypted, the encoded data includes the encrypted data. The encrypted data may be one or two or more. The encoded data may include a part of the key data used for encryption. At least a part of the key data used for encryption may be included in the encoded information.
[0034] In the information processing system 1, each information processing device 2 functions not only as a peer in the blockchain network but also as a storage for storing encoded data. The control unit 21 of the information processing device 2A sets a channel 3 as a unit for storing encoded data in the information processing system 1 (step S3). The number of channels 3 set by the control unit 21 is the same as or more than the number of encoded data generated by encoding the target data. For example, when the encoded data includes first encoded data and second encoded data, the control unit 21 sets a first channel 3A to which the information processing device 2 storing the first encoded data belongs and a second channel 3B to which the information processing device 2 storing the second encoded data belongs. The information processing device 2 belonging to the first channel 3A is also referred to as the first information processing device. The information processing device 2 belonging to the second channel 3B is also referred to as the second information processing device.
[0035] The control unit 21 of the information processing device 2A determines the belonging of the information processing device 2 to each channel 3 (step S4). The number of information processing devices 2 belonging to each channel 3 may be one or two or more. As will be described later, the number of information processing devices 2 belonging to each channel 3 may be an odd number of three or more. The control unit 21 may assign the information processing device 2 including the control unit 21 itself to the channel 3, or may not assign the information processing device 2 including the control unit 21 itself to the channel 3. In the configuration illustrated in FIG. 1, the information processing devices 2B, 2C, and 2D belong to the first channel 3A. The information processing devices 2E, 2F, and 2G belong to the second channel 3B. The combination of the information processing devices 2 belonging to each channel 3 is not limited to the combination illustrated in FIG. 1 and may be various other combinations.
[0036] The control unit 21 of the information processing apparatus 2A outputs the encoded data to the information processing apparatuses 2 belonging to each channel 3 (step S5). Each information processing apparatus 2 stores the acquired encoded data in the storage device 5. The storage device 5 stores the encoded data in the second storage area 52. When the block 4 of the blockchain is stored in the first storage area 51, it can be said that the information processing apparatus 2 stores the encoded data in the storage device 5 separately from the blockchain network.
[0037] The control unit 21 of the information processing apparatus 2A records the encoded information in the blockchain (step S6). Specifically, the control unit 21 generates a block 4 for recording the encoded information and outputs it to each information processing apparatus 2. For example, when blocks 4A, 4B, and 4C shown in FIG. 3 are connected to the blockchain, the control unit 21 generates a new block 4D for recording the encoded information and outputs it to each information processing apparatus 2. Each information processing apparatus 2 including the information processing apparatus 2A connects the block 4D to the block 4C. The storage device 5 of each information processing apparatus 2 stores the block 4D in the first storage area 51 and connects the block 4D to the blockchain. By connecting the block 4D in which the encoded information is recorded to the blockchain, the encoded information is recorded in the blockchain. After the completion of the procedure in step S6, the control unit 21 ends the execution of the procedure of the flowchart in FIG. 4.
[0038] By the control unit 21 of the information processing apparatus 2A executing the procedure up to step S6 of the flowchart in FIG. 4, the information processing system 1 can encode the target data, disperse and store the encoded data in the channel 3, and record the encoded information in the blockchain. That is, each procedure of the flowchart in FIG. 4 corresponds to the procedure until the target data is encoded and stored.
[0039] In the information processing system 1, the number of information processing devices 2 assigned to channel 3 may be an odd number of 3 or more. By setting the number of information processing devices 2 to an odd number of 3 or more, each information processing device 2 storing the encoded data can check whether the encoded data is correctly stored. The control unit 21 of each information processing device 2 may check the encoded data stored in the storage device 5 by executing an information processing method including the procedure shown in the flowchart of FIG. 5, for example.
[0040] The control unit 21 of each information processing device 2 belonging to the same channel 3 acquires the encoded data from the information processing device 2A and stores it in the storage device 5 (step S11). The storage device 5 stores the encoded data in the second storage area 52.
[0041] The control unit 21 of each information processing device 2 belonging to the same channel 3 determines whether the encoded data stored in the storage device 5 of each information processing device 2 within the same channel 3 matches (step S12). If the encoded data matches within the same channel 3 (step S12: YES), the control unit 21 of each information processing device 2 repeats the determination procedure of step S12. If the encoded data does not match within the same channel 3 (step S12: NO), the control unit 21 of each information processing device 2 determines whether the information processing device 2 itself is included in the majority group when the information processing devices 2 storing the matching encoded data are grouped together (step S13). Specifically, the control unit 21 of each information processing device 2 calculates the number of other information processing devices 2 with matching encoded data and the number of other information processing devices 2 with non-matching encoded data. The control unit 21 of each information processing device 2 determines that the information processing device 2 itself is in the majority if the number obtained by adding the information processing device 2 itself to the number of other information processing devices 2 with matching encoded data is greater than the number of other information processing devices 2 with non-matching encoded data.
[0042] When the control unit 21 of each information processing device 2 is included in a majority group (step 13: YES), it returns to step S12 and repeats the determination procedure. When the control unit 21 of each information processing device 2 is not included in a majority group (step S13: NO), it acquires encoded data from the majority information processing devices 2 and stores the acquired encoded data in the storage device 5 (step S14). After executing the procedure of step S14, the control unit 21 returns to step S12 and repeats the determination procedure.
[0043] While the storage device 5 stores encoded data, the control unit 21 of each information processing device 2 may repeat the procedures from step S12 to S14.
[0044] <Configuration example of decoding operation> At least one information processing device 2 of the information processing system 1 can acquire target data by acquiring and decoding the encoded data stored in the storage device 5 of each information processing device 2 of the information processing system 1. The control unit 21 of at least one information processing device 2 can acquire target data by executing each procedure of the information processing method shown as a flowchart in FIG. 6, for example. The information processing device 2 that acquires the target data may be an information processing device 2 peer to the information processing system 1. Hereinafter, a configuration example in which the information processing device 2A acquires the target data will be described.
[0045] The information processing device 2A receives an operation regarding an instruction to acquire target data from the operator 8 (see FIG. 1) by the input unit 25. The control unit 21 of the information processing device 2A acquires the encoded information recorded on the blockchain (step S21). The control unit 21 specifies the encoded information used for encoding the target data to be acquired based on the instruction from the operator 8. Conversely, when the operator 8 instructs to acquire the target data, it is necessary to input information that can specify the encoded information corresponding to the target data.
[0046] In order to decrypt the target data, the control unit 21 of the information processing apparatus 2A needs to acquire the encoded data from each information processing apparatus 2. The encoded data is configured such that the relationship with the encoding information is not known by itself. On the other hand, each information processing apparatus 2 associates data for identifying the encoded data with the encoded data so that, in response to a request to acquire the encoded data, the requested encoded data can be specified and output. The data for identifying the encoded data is also referred to as identification data.
[0047] The control unit 21 of the information processing apparatus 2A generates identification data of the encoded data necessary to decrypt the target data instructed by the operator 8 to acquire, and notifies each information processing apparatus 2 (step S22). The control unit 21 of each information processing apparatus 2 checks whether the encoded data associated with the notified identification data is stored in the storage device 5. When the encoded data associated with the identification data is stored in the storage device 5, the control unit 21 of each information processing apparatus 2 reads out the encoded data from the storage device 5 and outputs it to the information processing apparatus 2A. In other words, the information processing apparatus 2 that recognizes the identification data outputs the encoded data corresponding to the identification data.
[0048] The control unit 21 of the information processing apparatus 2A acquires the encoded data from the information processing apparatus 2 that has recognized the identification data (step S23). When the control unit 21 acquires the same encoded data from a plurality of information processing apparatuses 2 belonging to each channel 3, based on the encoded data acquired from each information processing apparatus 2 belonging to one channel 3, the encoded data of that channel 3 is acquired. If the encoded data acquired from some of the information processing apparatuses 2 belonging to one channel 3 is different from that of other information processing apparatuses 2, the control unit 21 may adopt the encoded data acquired from a large number of information processing apparatuses 2 as the encoded data of that channel 3. The control unit 21 may discard the encoded data acquired from a small number of information processing apparatuses 2.
[0049] The control unit 21 of the information processing apparatus 2A decrypts the target data based on the encoded information and the encoded data acquired from each information processing apparatus 2 (step S24). Specifically, the control unit 21 generates an algorithm for decrypting the target data based on the encoding algorithm specified by the encoded information. The control unit 21 may analyze the smart contract included in the encoded information to generate a program for decrypting the target data. The control unit 21 decrypts the target data based on the decryption algorithm and the encoded data acquired from each information processing apparatus 2. After executing the procedure of step S24, the control unit 21 ends the execution of the procedure of the flowchart in FIG. 6.
[0050] In step S22 of the flowchart in FIG. 6, the control unit 21 of each information processing apparatus 2 to which the control unit 21 of the information processing apparatus 2A notified the identification data may execute the procedure of the flowchart in FIG. 7. The control unit 21 of each information processing apparatus 2 acquires the identification data (step S31). The control unit 21 of each information processing apparatus 2 determines whether the encoded data corresponding to the identification data is stored in the storage device 5 (step S32). If the encoded data corresponding to the identification data is not stored in the storage device 5 (step S32: NO), the control unit 21 of each information processing apparatus 2 ends the execution of the procedure of the flowchart in FIG. 7 without outputting the encoded data to the information processing apparatus 2A. If the encoded data corresponding to the identification data is stored in the storage device 5 (step S32: YES), the control unit 21 of each information processing apparatus 2 reads out the encoded data corresponding to the identification data from the storage device 5 and outputs it to the information processing apparatus 2A (step S33). After ending the procedure of step S33, the control unit 21 of each information processing apparatus 2 ends the execution of the procedure of the flowchart in FIG. 7.
[0051] <Parentheses> As described above, the information processing system 1 can store the target data secretly by encoding the target data, distributing and storing it in each information processing device 2, and recording the encoded information on the blockchain. Further, the information processing system 1 can decrypt the secretly stored target data by notifying each information processing device 2 of the identification data based on the encoded information and acquiring the encoded data corresponding to the identification data from each information processing device 2. Since the encoded information and the encoded data are stored separately, it becomes difficult to steal the secretly stored target data. That is, the security of the secretly stored target data can be enhanced.
[0052] (Other embodiments) Hereinafter, various other embodiments of the information processing system 1 will be described.
[0053] <Configuration example of Channel 3> When storing one target data, the information processing system 1 sets Channel 3 and distributes and stores the encoded data in each Channel 3. When storing another target data, the information processing system 1 may set Channel 3 differently.
[0054] For example, when the information processing system 1 stores the first target data, as illustrated in FIG. 1, it is assumed that the information processing devices 2B, 2C, and 2D belong to the first Channel 3A, and the information processing devices 2E, 2F, and 2G belong to the second Channel 3B. On the other hand, when the information processing system 1 stores the second target data, as illustrated in FIG. 8, it may be assumed that the information processing devices 2A, 2B, and 2G belong to the third Channel 3C, and the information processing devices 2C, 2D, and 2E belong to the fourth Channel 3D. That is, the setting of Channel 3 may be different for each target data.
[0055] As illustrated in FIGS. 1 and 8, the combination of information processing apparatuses 2 belonging to the same channel 3 may be different for each target data. Specifically, the information processing apparatus 2C belongs to the first channel 3A set for the first target data while belonging to the second channel 3B set for the second target data. The information processing system 1 may appropriately determine the combination of information processing apparatuses 2 belonging to each channel 3 set for each target data.
[0056] <Configuration example of dividing target data> As described above, as encoding of the target data, the information processing system 1 may generate divided data obtained by dividing the target data and store the divided data distributed to each channel 3. When the information processing apparatus 2A encodes the target data, the control unit 21 of the information processing apparatus 2A generates division information for specifying an algorithm for dividing the target data. The division information is included in the encoding information. The control unit 21 divides the target data by the algorithm specified by the division information and generates divided data. The divided data is included in the encoded data. In this configuration example, the control unit 21 divides the target data into first divided data and second divided data.
[0057] The control unit 21 of the information processing apparatus 2A sets a first channel 3A for storing the first divided data and a second channel 3B for storing the second divided data. The control unit 21 allocates at least one information processing apparatus 2 to each channel 3. That is, at least one information processing apparatus 2 belongs to each channel 3. The control unit 21 stores the first divided data in the information processing apparatus 2 belonging to the first channel 3A and stores the second divided data in the information processing apparatus 2 belonging to the second channel 3B.
[0058] The control unit 21 of the information processing apparatus 2A records the division information as encoding information on the blockchain. Specifically, the control unit 21 newly generates a block 4 in which the division information is recorded and connects it to the existing block 4 of the blockchain.
[0059] The segmentation information may include information specifying in which channel 3 each of the segmented data is stored. When restoring the target data, each information processing device 2 can acquire the segmented data from each channel 3 based on the segmentation information.
[0060] The segmentation information may include information specifying only the channel 3 that stores one of the plurality of segmented data. In this case, the information specifying the channel 3 that stores the next segmented data is included in one segmented data. When restoring the target data, each information processing device 2 can acquire the first segmented data based on the segmentation information and acquire the second and subsequent segmented data in a chained manner.
[0061] The segmentation information is not limited to these examples, and may specify the channel 3 in which the segmented data is stored in various manners.
[0062] The control unit 21 of the information processing device 2A may split the bit string of the target data randomly, for example, as if shredding it. The control unit 21 may split the bit string of the target data in a predetermined pattern such as a matrix. The control unit 21 may split the target data into packets. The control unit 21 is not limited to these examples and may split the target data in various other patterns. The control unit 21 may randomly determine the splitting pattern.
[0063] <Movement of Encoded Data> The information processing system 1 may be attacked from the outside to steal the target data. In order to reduce the success rate of an external attack, the information processing system 1 may change the information processing device 2 that is the storage destination of the encoded data. That is, the information processing system 1 may move the encoded data stored distributedly in each information processing device 2 among the information processing devices 2 without continuously storing it in the same information processing device 2.
[0064] At least one information processing apparatus 2 of the information processing system 1 may change the setting of channel 3 and move the encoded data to the changed channel 3 by executing each procedure of the information processing method shown as a flowchart in FIG. 9, for example. The information processing apparatus 2 of the information processing system 1 peer may execute the change of the setting of channel 3 and the movement of the encoded data. Hereinafter, a configuration example in which the information processing apparatus 2A executes the change of the setting of channel 3 and the movement of the encoded data will be described.
[0065] The control unit 21 of the information processing apparatus 2A changes the information processing apparatus 2 belonging to each channel 3 (step S41). In other words, the control unit 21 assigns different information processing apparatuses 2 to each channel 3. For example, before the change, as illustrated in FIG. 1, it is assumed that the information processing apparatuses 2B, 2C, and 2D belong to the first channel 3A, and the information processing apparatuses 2E, 2F, and 2G belong to the second channel 3B. In this case, in the procedure of step S41, the control unit 21 may assign the information processing apparatuses 2E, 2F, and 2G to the first channel 3A and assign the information processing apparatuses 2B, 2C, and 2D to the second channel 3B. That is, the control unit 21 may change the information processing apparatus 2 belonging to the first channel 3A to the information processing apparatuses 2E, 2F, and 2G, and change the information processing apparatus 2 belonging to the second channel 3B to the information processing apparatuses 2B, 2C, and 2D. The information processing apparatus 2B, 2C, or 2D that belonged to the first channel 3A is also referred to as the first information processing apparatus as described above. The information processing apparatuses 2E, 2F, or 2G that the control unit 21 newly causes to belong to the first channel 3A are also referred to as the third information processing apparatus. Therefore, it can be said that the control unit 21 causes the third information processing apparatus to belong to the first channel 3A instead of the first information processing apparatus.
[0066] The control unit 21 of the information processing apparatus 2A moves the encoded data in the information processing apparatus 2 before and after the change of the belonging of each channel 3 (step S42). Specifically, the control unit 21 of the information processing apparatus 2A acquires the first encoded data from the information processing apparatuses 2B, 2C, and 2D that belonged to the first channel 3A before the change of the belonging, and outputs it to the information processing apparatuses 2E, 2F, and 2G that belong to the first channel 3A after the change of the belonging. The information processing apparatuses 2E, 2F, and 2G store the first encoded data in the storage device 5. Also, the control unit 21 of the information processing apparatus 2A acquires the second encoded data from the information processing apparatuses 2E, 2F, and 2G that belonged to the second channel 3B before the change of the belonging, and outputs it to the information processing apparatuses 2B, 2C, and 2D that belong to the second channel 3B after the change of the belonging. The information processing apparatuses 2B, 2C, and 2D store the second encoded data in the storage device 5. By doing so, the control unit 21 of the information processing apparatus 2A can move the encoded data in the information processing apparatus 2 before and after the change of the belonging. It can also be said that the control unit 21 moves the encoded data from the first information processing apparatus to the third information processing apparatus.
[0067] The control unit 21 of the information processing apparatus 2A updates the encoded information (step S43). Specifically, the control unit 21 updates the information for specifying the information processing apparatus 2 belonging to the channel 3 in the encoded information. The control unit 21 of the information processing apparatus 2A records the updated encoded information in the blockchain (step S44). After executing the procedure of step S44, the control unit 21 of the information processing apparatus 2A ends the execution of the procedure of the flowchart in FIG. 9.
[0068] In the procedure of step S41, the control unit 21 of the information processing apparatus 2A selects, as the information processing apparatus 2 belonging to each channel 3 after the change of the belonging, from those other than the information processing apparatus 2 that belonged to each channel 3 before the change of the belonging. The control unit 21 may cause a part of the information processing apparatus 2 that belonged to each channel 3 before the change of the belonging to also belong to the same channel 3 after the change of the belonging. For example, the control unit 21 may cause the information processing apparatus 2B that belonged to the first channel 3A before the change of the belonging to also belong to the first channel 3A after the change of the belonging.
[0069] As described above, the information processing system 1 can move the encoded data. When the information processing system 1 detects an illegal operation such as an external attack, it may reduce the possibility of the target data being stolen by moving the encoded data before the target data is stolen. As a result, the security of the stored target data is enhanced.
[0070] <Re-encoding of Target Data> After encoding the target data, the information processing system 1 may restore the target data once and then re-encode it. By doing so, the security of the target data against illegal operations attempting to steal the target data can be enhanced. The information processing device 2 of the information processing system 1 peer may execute the re-encoding of the target data. Hereinafter, a configuration example in which the information processing device 2A executes the re-encoding of the target data will be described.
[0071] The control unit 21 of the information processing device 2A restores the target data by executing the procedure of the flowchart in FIG. 6 described above. The control unit 21 of the information processing device 2A re-encodes the target data by executing the procedure of the flowchart in FIG. 4 described above. The data obtained by re-encoding the target data is also referred to as re-encoded data.
[0072] The control unit 21 of the information processing device 2A is assumed to make the number of encoded data before re-encoding different from the number of re-encoded data. The control unit 21 newly sets channel 3 based on the number of re-encoded data and assigns at least one information processing device 2 to each newly set channel 3. That is, at least one information processing device 2 belongs to each newly set channel 3. The control unit 21 of the information processing device 2A stores the re-encoded data in each newly set channel 3.
[0073] The control unit 21 of the information processing apparatus 2A may distinguish between the information processing apparatus 2 belonging to the first channel 3A set before re-encoding and the information processing apparatus 2 belonging to the first channel 3A newly set during re-encoding. That is, the control unit 21 may replace the information processing apparatus 2 belonging to the first channel 3A with another information processing apparatus 2.
[0074] As described above, the information processing system 1 may once decrypt the target data and then re-encode it. When the information processing system 1 detects an unauthorized operation such as an external attack, it may reduce the possibility of the target data being stolen by executing re-encoding before the target data is stolen. As a result, the security of the stored target data is enhanced.
[0075] Before re-encoding the target data, the information processing system 1 may change the content of the target data and then re-encode it.
[0076] <Configuration example for restricting reading of encoded information> The information processing system 1 records the encoded information in the blockchain. Although the blockchain is generally configured so that the recorded information is difficult to be tampered with, it is not configured so that the recorded information is difficult to be read. By adopting means for restricting the reading of the information recorded in the blockchain, the information processing system 1 can reduce the success rate of unauthorized operations such as external attacks on the information processing system 1.
[0077] For example, the information processing system 1 may encrypt the encoded information and record it in the blockchain. By doing so, even if the encrypted encoded information is stolen by an unauthorized operation such as an external attack, the start of the theft of the encoded data is delayed by at least the time required to decrypt the encoded information. The information processing system 1 can detect an unauthorized operation while gaining time and prevent the theft of the encoded data by moving the encoded data as described later.
[0078] For example, the information processing system 1 may encode the encoded information itself and record it on the blockchain. For example, the information processing system 1 may divide the encoded information and record it in a distributed manner in a plurality of blocks 4. By doing so, it becomes difficult for the encoded information to be stolen by unauthorized operations such as external attacks.
[0079] <<Approval function>> For example, the information processing system 1 may be configured such that approval is required to read information from the blockchain. For example, at least some of the information processing devices 2 may have a function of approving the reading of information. The information processing device 2 having the function of approving the reading of information is also referred to as an approval device. It is assumed that the information processing device 2 attempting to read information from the blockchain sends a request to read information to the approval device and can read information from the blockchain when approved by the approval device. The approval device rejects the request to read information if the request to read information is an unauthorized request such as a request based on an external attack. The approval device may be composed of a plurality of information processing devices 2. The approval device may, for example, determine by majority vote whether the request to read information is an unauthorized request. The approval device may, for example, determine that the request to read information is an unauthorized request when it is determined that the request to read information is an unauthorized request in a predetermined ratio or more of the approval devices, such as one-third.
[0080] Specifically, it is assumed that the information processing device 2A reads the encoded information from the blockchain. In this case, when at least one of the other information processing devices 2B to 2G functions as an approval device and approves the reading of the encoded information by the information processing device 2A, the information processing device 2A may be configured to be able to read the encoded information.
[0081] When the information processing device 2A requests to read the encoded information from the blockchain, the other information processing devices 2B to 2G of the information processing system 1 determine which information processing device 2 approves the request from the information processing device 2A. The information processing device 2A that requests to read the encoded information from the blockchain is also referred to as the fourth information processing device. The information processing device 2 that approves the request from the fourth information processing device is also referred to as the fifth information processing device.
[0082] The fifth information processing device determines whether the request from the fourth information processing device is a request based on an unauthorized operation such as an external attack. If the fifth information processing device determines that the request from the fourth information processing device is a request based on an unauthorized operation, it rejects the request. If the fifth information processing device determines that the request from the fourth information processing device is not a request based on an unauthorized operation, it approves the request.
[0083] The number of the fifth information processing devices may be one or two or more. When the fifth information processing device is composed of a plurality of information processing devices 2, it may approve the request from the fourth information processing device by a majority vote.
[0084] As described above, the information processing system 1 can reduce the possibility of the target data being stolen by determining whether the request for reading the encoded information is a request based on an unauthorized operation. As a result, the security of the stored target data is enhanced.
[0085] The information processing system 1 is not limited to these examples, and may limit the reading of the encoded information from the blockchain by each information processing device 2 by various other means.
[0086] Each information processing device 2 may be configured to accept only operations from the operator 8 who has been authenticated after authenticating the operator 8. For example, each information processing device 2 may authenticate the operator 8 by inputting a password, inputting biometric information, or collating location information, etc. The information processing system 1 may manage, in association with each operator 8 to be authenticated, authority information that specifies items for granting operation authorities. Each information processing device 2 may accept an input of an operation from the operator 8 based on the authority information. Further, when an operator 8 inputs an operation to restore target data in one information processing device 2, another information processing device 2 may determine whether to approve a request to read encoded information to restore the target data based on the authority information of the operator 8.
[0087] Although the present disclosure has been described based on the drawings and embodiments, it should be noted that those skilled in the art may make various modifications and alterations based on the present disclosure. Therefore, it should be noted that these modifications and alterations are included in the scope of the present disclosure. For example, functions included in each component or each step, etc. can be rearranged so as not to be logically contradictory, and a plurality of components or steps, etc. can be combined into one or divided.
[0088] Also, for example, an embodiment in which a general-purpose computer functions as the information processing device 2 according to the above-described embodiment is also possible. Specifically, a program describing the processing content for realizing each function of the information processing device 2 according to the above-described embodiment is stored in the memory of a general-purpose computer, and the program is read and executed by a processor. Therefore, the invention according to the present embodiment can also be realized as a program executable by a processor or a non-temporary computer-readable medium storing the program.
[0089] In the present disclosure, descriptions such as "first" and "second" are identifiers for distinguishing the relevant configurations. The configurations distinguished by descriptions such as "first" and "second" in the present disclosure can have their numbers in the configuration exchanged. For example, the first information processing apparatus can exchange the identifiers "first" and "second" with the second information processing apparatus. The exchange of identifiers is performed simultaneously. The configurations are still distinguishable after the exchange of identifiers. The identifiers may be deleted. The configurations with the identifiers deleted are distinguished by symbols. Based only on the descriptions of identifiers such as "first" and "second" in the present disclosure, the order of the configurations should not be interpreted, nor should it be used as a basis for the existence of an identifier with a smaller number.
Explanation of Signs
[0090] 1 Information processing system 2, 2A to 2G Information processing apparatus (21: Control unit, 22: Storage unit, 23: Communication unit, 24: Output unit, 25: Input unit) 3 Channel (3A to 3D: First to fourth channels) 4, 4A to 4D Blocks 5 Storage device (51: First storage area, 52: Second storage area) 6 Encoded data 8 Operator 10 Network
Claims
1. An information processing method executed by an information processing system including a plurality of information processing devices each functioning as a peer of a network that constitutes a blockchain network, comprising: generating encoding information for specifying an algorithm for encoding target data; generating encoded data obtained by encoding the target data based on the algorithm specified by the encoding information; storing the encoded data separately from the blockchain network by associating the encoded data with identification data for the first information processing device to identify the encoded data in the first information processing device belonging to the first channel among the plurality of information processing devices; connecting a block including the encoding information to a blockchain recorded in the blockchain network; and the encoded data is configured such that the relationship with the encoding information is not known. An information processing method.
2. The information processing method according to claim 1, wherein the encoded data is configured such that the first information processing device can output the encoded data associated with the identification data obtained from the information processing device that is the source of the notification of the identification data to the source information processing device.
3. The information processing method according to claim 1 or 2, further comprising restricting reading of the encoding information.
4. In the step of generating the encoding information, generating division information for specifying an algorithm for dividing the target data as the encoding information; In the step of generating the encoded data, dividing the target data into at least first divided data and second divided data based on the algorithm specified by the division information as the encoded data; In the step of storing the encoded data, storing the first divided data separately from the blockchain network in the first information processing device, and storing the second divided data separately from the blockchain network in the second information processing device belonging to the second channel among the plurality of information processing devices. The information processing method according to any one of claims 1 to 3.
5. The number of the first information processing devices is an odd number of 3 or more. When at least a part of the encoded data stored in each of the first information processing devices is different, further including the step of updating the encoded data stored in a small number of the first information processing devices with the encoded data stored in a large number of the first information processing devices, the information processing method according to any one of claims 1 to 4.
6. The method further includes the step of causing a third information processing device to belong to the first channel instead of the first information processing device, moving the encoded data from the first information processing device to the third information processing device, and updating the encoded information, the information processing method according to any one of claims 1 to 5.
7. The step of reading the encoded information from the blockchain, The step of obtaining the encoded data based on the encoded information, The step of restoring the target data based on the encoded data and further including, the information processing method according to any one of claims 1 to 6.
8. In the step of reading the encoded information, the fourth information processing device approved to read the encoded information among the plurality of information processing devices reads the encoded information, the information processing method according to claim 7.
9. The method further includes the step of approving, by a fifth information processing device different from the fourth information processing device among the plurality of information processing devices, the fourth information processing device to read the encoded information, the information processing method according to claim 8.
10. In the step of obtaining the encoded data, identification data for specifying the encoded data based on the encoded information is generated, the identification data is output to each information processing device, and the encoded data is obtained from the information processing device that has recognized the identification data, the information processing method according to any one of claims 7 to 9.
11. The step of generating re-encoded data by updating and re-encoding the content of the target data restored by executing the information processing method according to any one of claims 6 to 10, The step of replacing the information processing device belonging to the first channel from the first information processing device with another information processing device, The step of storing the re-encoded data in the information processing device belonging to the first channel and including, an information processing method.
12. An information processing system including a plurality of information processing apparatuses each functioning as a peer that constitutes a blockchain network, wherein at least one of the plurality of information processing apparatuses generates encoding information for specifying an algorithm for encoding target data, and generates encoded data obtained by encoding the target data based on the algorithm specified by the encoding information, wherein a first information processing apparatus belonging to a first channel among the plurality of information processing apparatuses stores the encoded data separately from the blockchain network by associating identification data for the first information processing apparatus to identify the encoded data with the encoded data, wherein each of the information processing apparatuses concatenates a block including the encoding information to a blockchain recorded on the blockchain network, wherein the encoded data is configured such that the relationship with the encoding information is not known, the information processing system.
13. An information processing apparatus that functions as a peer that constitutes a blockchain network, together with at least a first information processing apparatus belonging to a first channel, generates encoding information for specifying an algorithm for encoding target data, generates encoded data obtained by encoding the target data based on the algorithm specified by the encoding information, outputs the encoded data to the first information processing apparatus by associating identification data for the first information processing apparatus to identify the encoded data with the encoded data so that the first information processing apparatus stores the encoded data separately from the blockchain network, concatenates a block including the encoding information to a blockchain recorded on the blockchain network, wherein the encoded data is configured such that the relationship with the encoding information is not known, the information processing apparatus.
14. An information processing program to be executed by an information processing apparatus that functions as a peer that constitutes a blockchain network, together with at least a first information processing apparatus belonging to a first channel, the step of generating encoding information for specifying an algorithm for encoding target data, the step of generating encoded data obtained by encoding the target data based on the algorithm specified by the encoding information, The step of associating the encoded data with identification data for the first information processing apparatus to identify the encoded data in the encoded data and outputting the encoded data to the first information processing apparatus so that the first information processing apparatus stores the encoded data separately from the blockchain network; The step of linking a block including the encoded information to a blockchain recorded in the blockchain network; Causing the information processing apparatus to execute; An information processing program in which the encoded data is configured such that the relationship with the encoded information is unknown.
Citation Information
Patent Citations
Method and system for fault tolerance
JP1991015946A
IC card system and IC card
JP1998065663A
Data backup device, data backup method and program
JP2007102672A
Information processor having information dispersion function
JP2007304962A
Network distributed duplication exclusion file storage system
JP2018190227A