Electronic data management device, electronic data management system, program therefor, and recording medium

The electronic data management system addresses slow processing and information leakage by dispersing files across volatile and non-volatile storage in kernel mode, ensuring secure and high-speed data access without leaving decipherable data on the computer.

JP7710672B2Active Publication Date: 2025-07-22SCI PARK CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2021030857
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-02-26
Publication Date
2025-07-22
Estimated Expiration
2041-02-26

AI Technical Summary

Technical Problem

Existing electronic data management systems using secret sharing technology face issues with slow processing speeds and potential information leakage when reading and restoring fragmented files on electronic computers, especially when network connectivity is unavailable.

Method used

An electronic data management system that operates in kernel mode to disperse and store fragmented files in volatile and non-volatile storage, using secret sharing to ensure high-speed processing and secure data protection, with files erased from volatile storage upon power off or program termination.

Benefits of technology

The system provides secure, high-speed data management by dispersing files across multiple storage means, ensuring data is not left in a decipherable format on the computer, thereby preventing information leakage and enabling seamless data access without awareness of secret distribution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007710672000004
    Figure 0007710672000004
  • Figure 0007710672000005
    Figure 0007710672000005
  • Figure 0007710672000006
    Figure 0007710672000006
Patent Text Reader

Abstract

To provide an electronic data management apparatus configured to prevent leakage of user data without saving the user data in process on an electronic computer, an electronic data management system, a program therefor, and a recording medium.SOLUTION: In an electronic data management system 1, a memory area of a part of a main memory device of a user terminal 2 is used as a RAM disk 11. User data in process is secretly shared. Generated fragmented files are stored in a distribution folder 12 of the RAM disk 11, then transferred to a network storage 3, a mobile terminal 6, and a local auxiliary storage device 14. Using a driverware technology, secret sharing of user data, restoration thereof, transfer of fragmented files are performed in the electronic computer in a kernel mode.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an electronic data management device, an electronic data management system, a program therefor, and a recording medium. More specifically, the present invention relates to an electronic data management device, an electronic data management system, a program therefor, and a recording medium for storing and using electronic data in a volatile storage means by an electronic computer and preventing and managing leakage of the electronic data from the electronic computer by dispersedly holding (storing) the electronic data by a secret dispersion means.

Background Art

[0002] Electronic data is stored in auxiliary storage devices of electronic computers such as HDDs and SSDs, recording media such as CDs and flash memories, and network storage on a network. A user accesses this electronic data using the operating electronic computer and performs processes such as viewing, editing, newly creating, and deleting files of the electronic data. This electronic data is a broad concept including still image data, moving image data, audio data, text documents, electronic documents in a specific format, and the like.

[0003] Electronic data consisting of data such as personal information and business know-how is data having confidentiality. It is necessary to take measures such as management of access rights to this electronic data, protection, and prevention of leakage to the outside. The electronic computer mentioned here is equipped with a central processing unit, a main storage device, input / output means, a power supply means, etc., and examples thereof include any computer such as a desktop personal computer, a notebook personal computer, a tablet, a smartphone, and a server.

[0004] Users are taking various measures so as not to leak electronic data to the outside. Controlling the electronic computer so that the electronic data cannot be used for purposes other than the intended purpose is important from the viewpoint of preventing leakage of electronic data, particularly confidential data. Usually, a user encrypts electronic data and stores it in the electronic computer and also in an external auxiliary storage device, for example.

[0005] In recent years, it has become increasingly common to connect a computer to a network, store electronic data in network storage on the network, and download and use the electronic data from the network storage to the computer. When electronic data is stored in a network folder of network storage in this way, there is no need to store the electronic data in the auxiliary storage device of the computer, resulting in a so-called data-less use of the computer. However, the electronic data downloaded and used from network storage is often stored and used in the auxiliary storage device of the computer, etc.

[0006] When electronic data is stored in a computer or a recording medium, there is a risk of leakage to the outside through various routes. For example, when electronic data is stored in an auxiliary storage device such as a flash memory connected to a computer, there is a risk of leakage to the outside (a third party) due to the loss of this auxiliary storage device, etc. Also, due to the loss, theft, etc. of the computer, the electronic data being used may be lost or leaked to an external third party. At this time, even if the electronic data is encrypted, it may be decrypted.

[0007] Preventive measures against such information leakage have been carried out and proposed in various forms. For example, when storing electronic data in an auxiliary storage device connected to a computer, measures such as encrypting the electronic data or authenticating the auxiliary storage device are taken (for example, Patent Document 1). The program of the data management system disclosed in Patent Document 1 controls the computer so that the user data of the client stored in the non-volatile memory cannot be used by the computer that is processing it for purposes other than the intended ones.

[0008] In this system, user data is recorded only in non-volatile memory approved by the computer, and the computer is further controlled by other means so that it cannot be taken out externally. When the user accesses the auxiliary storage device of the computer, electronic data can be saved in a folder on the network by using the redirect function that transfers it to a pre-set address on the network. In particular, in the context of the increasing trend towards data-less computers, there is a need for a mechanism that does not leave the electronic data on the computer even when working with electronic data on the computer.

[0009] This computer has conventionally used part of the main memory as a pseudo-auxiliary storage device for data-less operation, which is called a virtual disk or the like. Writing data to the auxiliary storage device of the computer is prohibited, and data is redirected to be written to the virtual disk and written to the virtual disk on the network (Patent Document 2). By using this function, data is not left on the local disk of the computer but is saved on network storage (virtual drive) on the network.

[0010] There is also a technology that uses secret sharing technology, which is one of the encryption technologies, to disperse electronic data into multiple fragment files and store each in a different storage device. Secret sharing is a concept independently proposed by Adi Shamir and George Blakley in 1979, and has since been intensively studied, with various methods proposed and even becoming an international standard (ISO / IEC 19592-2:2017). Representative examples of secret sharing methods include the threshold scheme, the verifiable secret sharing (VSS) scheme, the general secret sharing method, and the threshold cryptography method.

[0011] Secret sharing involves reading the electronic data from its fragment files from respective recording devices, restoring it using secret sharing technology to create the original file that can be decoded, and using this on an electronic computer. With this secret sharing technology, it is impossible to decrypt the content using only the fragment files. Among these multiple fragment files, the original file can be restored and its content can be decoded using a preset number of fragment files.

[0012] There is a technology that disperses electronic data into multiple fragment files using secret sharing technology and, when using it, restores the fragment files onto the main memory device of an electronic computer for use. According to the secret sharing technology, the electronic data with decipherable meaning exists only on the main memory device of the electronic computer. When the power of the electronic computer is turned off, all the data stored in the main memory device disappears, and thus the electronic data also disappears. This reduces the risk of leakage of electronic data that can be decoded from the electronic computer.

Prior Art Documents

Patent Documents

[0013]

Patent Document 1

Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0014] However, when using electronic data on an electronic computer and taking measures against data leakage using secret sharing technology and the main memory device, the following problems exist. First, when reading electronic data from multiple recording devices, processing it within the electronic computer, and restoring it onto the main memory device, and also when secret-sharing working files to generate fragment files, there is a problem that the processing speed of the electronic computer becomes slow. Furthermore, when using electronic data on an electronic computer, there remains room for information leakage of the restored original file via a recording medium or the like.

[0015] From the user's perspective, there is a desire to use the electronic data smoothly without being aware of the secret distribution of the electronic data. The fragmented files are recorded on a plurality of recording media such as network storage and recording media connected to an electronic computer. It is important for the user to use these fragmented files without being aware of them as much as possible. In particular, when changing the electronic computer for work, when the working electronic computer cannot be connected to the network, when using work files externally such as on a business trip, etc., the user desires to use the distributed fragmented files smoothly with little awareness.

[0016] The present invention has been made based on the above technical background and achieves the following objectives. An object of the present invention is to provide an electronic data management device, an electronic data management system, a program therefor, and a recording medium that securely protect the electronic data of an electronic computer and prevent information leakage by dispersedly storing electronic data using a secret distribution means and using the electronic data in the volatile storage means of the electronic computer.

[0017] Another object of the present invention is to provide an electronic data management device, an electronic data management system, a program therefor, and a recording medium that realize a data-less electronic computer that does not store electronic data that can be decoded by the electronic computer.

Means for Solving the Problems

[0018] To achieve the above object, the present invention adopts the following means. The present invention relates to an electronic data management device, an electronic data management system, a program therefor, and a recording medium. The electronic data management device of the first aspect of the present invention is It operates in kernel mode where all instructions of the operating system can be executed, and has common interface means for providing a common interface for communication between device drivers for directly controlling devices connected to the following electronic computer, or for communication between the device driver and an application program. It consists of an electronic computer connectable to a network, and is an electronic data management device having an electronic data leakage prevention function for preventing and controlling leakage of user data from the electronic computer to the outside. Dispersion means for secretly dispersing a file to generate n fragments Restoration means for synthesizing m of the fragments to restore the original file Drive creation means that operates in the kernel mode to create volatile storage means in the electronic computer Fragment file generation means for secretly dispersing a working file by the dispersion means to generate the n fragment files and storing them in the volatile storage means First transfer means for transferring the n fragment files stored in the volatile storage means to a plurality of non-volatile storage means and storing them in the kernel mode Second transfer means for transferring m or more of the n fragment files stored in the plurality of non-volatile storage means to the volatile storage means in the kernel mode, and Working file restoration means for acquiring the m or more fragment files stored in the volatile storage means by the second transfer means and generating the original working file by the restoration means, and storing it in the volatile storage means When the transfer of the n fragment files by the first transfer means is completed and the application program ends, it has deletion means for deleting one or more of the working file, the volatile storage means, the working drive, and the working folder and The fragment file that cannot be transferred to the non-volatile storage means among the n fragment files is encrypted and transferred and stored in the non-volatile storage means built in or connected to the electronic computer.

[0019] The electronic data management device of the second aspect of the present invention is the electronic data management device of the first aspect of the present invention, wherein the dispersion means and the restoration means operate in the kernel mode, the fragmented file generation means acquires the working file in the kernel mode, passes it to the dispersion means in the kernel mode, and performs the secret dispersion, the working file restoration means acquires the n number of the fragmented files in the kernel mode, passes them to the restoration means in the kernel mode, and restores the working file.

[0020] The electronic data management device of the third aspect of the present invention is the electronic data management device of the first aspect of the present invention, wherein the dispersion means and the restoration means with the execution of some instructions restricted operate in the user mode, the fragmented file generation means acquires the working file in the kernel mode, passes it to the dispersion means in the user mode, and performs the secret dispersion, the working file restoration means acquires the n number of the fragmented files in the kernel mode, passes them to the restoration means in the user mode, and restores the working file.

[0021] The electronic data management device of the fourth aspect of the present invention is the electronic data management device of the first aspect of the present invention, wherein the first transfer means acquires the n fragmented files stored in the volatile storage means in the kernel mode, with the execution of some instructions restricted transfers them to the plurality of non-volatile storage means in the user mode, the second transfer means acquires the n fragmented files stored in the plurality of non-volatile storage means in the user mode, transfers the n fragmented files in the kernel mode, and stores them in the volatile storage means.

[0022] The electronic data management device of the present invention 5 is the electronic data management device of the present inventions 1 to 4, Each of the working file and the n fragment files is stored in a working drive or a working folder having the same directory structure.

[0023] The electronic data management device of the present invention 6 is the electronic data management device of the present invention 1, When the electronic computer is started, the fragment files for which the transfer has not been completed are transmitted to the volatile storage means.

[0024] The electronic data management device of the present invention 7 is the electronic data management device of the present inventions 1 to 4, When the electronic computer is started, it is confirmed whether or not the fragment files obtained by secret sharing of the working file are stored in all the corresponding volatile storage means. If they are not stored in all the volatile storage means, the working file is restored from the readable fragment files, and then the newly restored working file is secretly shared to create a plurality of fragment files, which are transferred to the volatile storage means.

[0025] The electronic data management device of the present invention 8 is the electronic data management device of the present inventions 1 to 4, The volatile storage means is encrypted. The electronic data management device of the present invention 9 is the electronic data management device of the present inventions 1 to 4, The non-volatile storage means is encrypted. The electronic data management device of the present invention 10 is the electronic data management device of the present inventions 1 to 4, The non-volatile storage means is two or more selected from network storage, cloud folder for online storage service, built-in auxiliary storage means, external auxiliary storage means, network drive, USB device, USB medium, portable device, synchronization drive, and virtual drive.

[0026] The electronic data management system of the present invention 1 a network, network storage connected to the network for storing user data, a computer connected to the network, operating in kernel mode where all instructions of the operating system can be executed, and providing a common interface for communication between device drivers for directly controlling devices connected to the computer or for communication between the device driver and an application program, comprising common interface means, In an electronic data management system having an electronic data leakage prevention function for preventing and controlling leakage of the user data from the computer to the outside, dispersion means for secretly dispersing a file to generate n fragments, restoring means for synthesizing m of the fragments to restore the original file, drive creation means for operating in the kernel mode to create volatile storage means in the computer, fragment file generation means for secretly dispersing a working file by the dispersion means to generate the n fragment files and storing them in the volatile storage means, for secret sharing first transfer means for transferring and storing the n fragment files stored in the volatile storage means to a plurality of non-volatile storage means including the network storage in the kernel mode, for restoring the said file second transfer means for transferring and storing m or more of the n fragment files stored in the plurality of non-volatile storage means to the volatile storage means in the kernel mode, and the n fragment files stored in the volatile storage means by the second transfer means are acquired, and the original working file is generated by the restoring means and stored in the volatile storage means, comprising working file restoration means and When the transfer of the n fragment files by the first transfer means is completed and the application program ends, there is a deletion means for deleting one or more of the working file, the volatile storage means, the working drive, and the working folder. and Among the n fragment files, the fragment files that cannot be transferred to the non-volatile storage means are encrypted and transferred and stored in the non-volatile storage means built in or connected to the electronic computer.

[0027] The electronic data management system of the second invention is the electronic data management system of the first invention, The dispersion means and the restoration means operate in the kernel mode, The fragment file generation means acquires the working file in the kernel mode, passes it to the dispersion means in the kernel mode, and performs the secret dispersion, The working file restoration means is in the kernel mode for the n acquires the n fragment files, passes them to the restoration means in the kernel mode, and restores the working file.

[0028] The electronic data management system of the third invention is the electronic data management system of the first invention, The dispersion means and the restoration means with the execution of some instructions restricted operate in the user mode, The fragment file generation means acquires the working file in the kernel mode, passes it to the dispersion means in the user mode, and performs the secret dispersion, The working file restoration means is in the kernel mode for the n acquires one or more of the fragment files, passes them to the restoration means in the user mode, and restores the working file.

[0029] The electronic data management system of the fourth invention is the electronic data management system of the first invention, The first transfer means acquires the n fragment files stored in the volatile storage means in the kernel mode, with the execution of some instructions restricted transfers them to the plurality of non-volatile storage means in the user mode, The second transfer means acquires the n fragment files stored in the plurality of non-volatile storage means in the user mode, and transfers the n fragment files in the kernel mode and stores them in the volatile storage means.

[0030] The electronic data management system according to Invention 5 is the electronic data management system according to Inventions 1 to 4, wherein each of the working file and the n fragment files is stored in a working drive or a working folder having the same directory structure.

[0031] The electronic data management system according to Invention 6 is the electronic data management system according to Invention 1, when the electronic computer is started, the fragment files for which the transfer is not completed are transmitted to the volatile storage means.

[0032] The electronic data management system according to Invention 7 is the electronic data management system according to Inventions 1 to 4, when the electronic computer is started, it is confirmed whether or not the fragment files obtained by secret sharing of the working file are stored in all the volatile storage means. If they are not stored in all the volatile storage means, the working file is restored from the readable fragment files, and then the newly restored working file is secretly shared to create a plurality of fragment files, which are transferred to the volatile storage means.

[0033] The electronic data management system according to Invention 8 is the electronic data management system according to Inventions 1 to 4, wherein the volatile storage means is encrypted. In the electronic data management system of the present invention 9, in the present inventions 1 to 4, The non-volatile storage means is characterized by being encrypted.

[0034] In the electronic data management system of the present invention 10, in the electronic data management system of the present inventions 1 to 4, The non-volatile storage means is characterized by being two or more selected from network storage, a cloud folder for an online storage service, built-in auxiliary storage means, external auxiliary storage means, a network drive, a USB device, a USB medium, a portable device, a synchronization drive, and a virtual drive.

[0035] The program for an electronic data management device of the present invention 1 It operates in kernel mode capable of executing all instructions of the operating system, and has common interface means for providing a common interface for communication between device drivers for directly controlling devices connected to the following electronic computer, or for communication between the device driver and an application program. It consists of an electronic computer connectable to a network, and in an electronic data management device having an electronic data leakage prevention function for preventing and controlling leakage of user data from the electronic computer to the outside. A drive creation step of creating volatile storage means in the electronic computer by drive creation means operating in the kernel mode, and creating a plurality of distributed folders in the created volatile storage means. A fragment file generation step of secretly distributing the work files stored in the volatile storage means by a distribution means to generate n fragment files and storing them in the volatile storage means. For secret distribution, a first transfer step of transferring and storing the n fragment files stored in the volatile storage means to a plurality of non-volatile storage means in the kernel mode. For restoring the file, a second transfer step of transferring the n fragment files stored in the plurality of non-volatile storage means to the volatile storage means in the kernel mode and storing them in the volatile storage means, and the second step acquiring the fragment files stored in the volatile storage means by the above and generating the original working file by a restoring means, and storing it in the volatile storage means, which consists of a working file restoration step, n and the first transfer step has a deletion step of deleting one or more of the working file, the volatile storage means, the working drive, and the working folder when the transfer of the n fragment files is completed and the application program ends. The step consists of encrypting the fragment files among the n fragment files that cannot be transferred to the non-volatile storage means and transferring and storing them in the non-volatile storage means built in or connected to the electronic computer.

[0036] The program for an electronic data management device according to the second aspect of the present invention is the program for an electronic data management device according to the first aspect of the present invention, wherein the dispersing means and the restoring means operate in the kernel mode, the fragment file generation step consists of a step of acquiring the working file in the kernel mode and a step of passing the acquired working file to the dispersing means in the kernel mode, the working file restoration step consists of a step of acquiring the n fragment files in the kernel mode and a step of passing the acquired fragment files to the restoring means in the kernel mode.

[0037] The program for an electronic data management device according to the third aspect of the present invention is the program for an electronic data management device according to the first aspect of the present invention, wherein the dispersing means and the restoring means with the execution of some instructions restricted operate in the user mode, The fragment file generation step includes the step of obtaining the working file in the kernel mode and the step of passing the obtained working file to the dispersion means. The working file restoration step is to obtain the n individual fragment files in the kernel mode and pass the obtained fragment files to the restoration means.

[0038] The program for an electronic data management device according to the fourth aspect of the present invention is the program for an electronic data management device according to the first aspect of the present invention, The first transfer step includes the step of obtaining the n fragment files stored in the volatile storage means in the kernel mode and with the execution of some instructions restricted transferring the obtained n fragment files to the plurality of non-volatile storage means in the user mode. The second transfer step includes the step of obtaining the n fragment files stored in the plurality of non-volatile storage means in the user mode and the step of transferring the obtained n fragment files to the volatile storage means in the kernel mode and storing them therein.

[0039] The program for an electronic data management device according to the fifth aspect of the present invention is the program for an electronic data management device according to the first to fourth aspects of the present invention, Each of the working file and the n fragment files is stored in a working drive or a working folder having the same directory structure.

[0040] The program for an electronic data management device according to the sixth aspect of the present invention is the program for an electronic data management device according to the first to fourth aspects of the present invention, The first transfer step has a deletion step of deleting one or more of the working file, the volatile storage means, the working drive, and the working folder when the transfer of the n fragment files is completed and the application program ends.

[0041] The program for an electronic data management device according to the seventh aspect of the present invention is the program for an electronic data management device according to the first aspect of the present invention, characterized by comprising a step of transmitting, to the volatile storage means, the fragmented file for which transfer has not been completed when the electronic computer is started.

[0042] The program for an electronic data management device according to the eighth aspect of the present invention is the program for an electronic data management device according to the first to fourth aspects of the present invention, characterized by comprising a step of checking, when the electronic computer is started, whether or not all of the volatile storage means in which the fragmented file obtained by secret sharing of the working file is stored; when not all of the plurality of fragmented files are stored in all of the volatile storage means, a step of restoring the working file from the readable fragmented files; a step of performing secret sharing on the working file to create a plurality of fragmented files; and a step of transferring the created plurality of fragmented files to the volatile storage means.

[0043] The program for an electronic data management device according to the ninth aspect of the present invention is the program for an electronic data management device according to the first to fourth aspects of the present invention, characterized by comprising a step of encrypting the volatile storage means. The program for an electronic data management device according to the tenth aspect of the present invention is the program for an electronic data management device according to the first to fourth aspects of the present invention, characterized by comprising a step of encrypting the non-volatile storage means. The program for an electronic data management device according to the eleventh aspect of the present invention is the program for an electronic data management device according to the first to fourth aspects of the present invention, The non-volatile memory means is characterized by being two or more selected from network storage, a cloud folder for online storage service, built-in auxiliary memory means, externally attached auxiliary memory means, network drive, USB device, USB medium, portable device, synchronization drive, and virtual drive. The recording medium recording the program for the electronic data management device of the first invention records the programs for the electronic data management devices of the first to fourth inventions.

Effect of the Invention

[0044] According to the present invention, the following effects are achieved. The present invention uses the volatile memory means of an electronic computer as a working folder, disperses and stores fragmented files of electronic data in a secret manner in local auxiliary memory means, network storage, portable auxiliary memory means, etc., and when the operation of the application program ends or the power of the electronic computer is turned off, all the decipherable user data used can be erased. Therefore, the electronic data of the electronic computer can be reliably protected and information leakage can be prevented.

[0045] The present invention realizes the secret sharing means in the kernel mode of the electronic computer, transfers the secretly shared fragmented files in the kernel mode, and stores these fragmented files in the auxiliary memory means, thereby realizing high-speed distribution processing, storage processing and high security and preventing information leakage.

Brief Description of the Drawings

[0046]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

[0047] Hereinafter, embodiments of the present invention will be described with reference to the drawings. [First Embodiment of the Present Invention] Hereinafter, the electronic data management system 1 according to the first embodiment of the present invention will be described with reference to the drawings. FIG. 1 is a block diagram showing an overview of the electronic data management system 1 according to the first embodiment of the present invention.

[0048] When using electronic data with an electronic computer, the electronic data management system 1 restores the original file from fragmented files of a secretly shared file such as user data described later, and the restored file is stored in volatile storage means for use. When saving a file, the electronic data management system 1 secretly shares it to generate a plurality of fragmented files, and stores these fragmented files in a plurality of storage means. The file in the volatile storage means is erased when the power of the electronic computer is turned off or deleted after use. As a result, the file is no longer stored in the electronic computer in a decipherable format, preventing leakage of electronic data.

[0049] When using electronic data that is subject to information leakage prevention, the electronic data management system 1 stores and uses files in a decryptable format in the volatile memory means of the electronic computer. When storing in non-volatile memory means, it generates a plurality of fragment files that cannot be decrypted alone and stores them in different storage means. For example, it stores the fragment files in the built-in auxiliary storage means of the electronic computer, the auxiliary storage means externally attached to the electronic computer, the storage means of portable devices connected to the electronic computer, the network storage means connected to the electronic computer, etc. Accordingly, when the power of the electronic computer is turned off, etc., the volatile memory means disappears, and at the same time, the file in a decryptable format disappears and does not remain in the electronic computer.

[0050] The electronic data management system 1 controls the device driver in kernel mode, and the restoration of a file in a decryptable format from fragment files, the generation of fragment files from a file, the transmission of fragment files to each storage medium, and the reading of fragment files from each storage means are performed in kernel mode. In this way, by performing the main processing in kernel mode, high-speed processing, high-level security, and data transmission between different device drivers can be realized.

[0051] When using the electronic computer, the user works using the files stored in the volatile memory means without being aware of the secret dispersion and restoration of the files, and the storage and transfer of the fragment files to the storage medium. For an application program that operates on the electronic computer and uses files, as in the past, it will handle the files in the main auxiliary storage device and operate without being affected by the secret dispersion and restoration of the files and the storage of the fragment files.

[0052] These are advanced technologies by the technology of driverware (registered trademark) that controls the device driver in kernel mode. In particular, the electronic data management system 1 disperses and stores the fragment files in the built-in auxiliary storage device of the electronic computer, the network storage on the network, the portable storage means connected to the electronic computer, etc.

[0053] In the present invention, any known secret sharing method such as the above-mentioned threshold method, verifiable secret sharing method, general secret sharing method, threshold cryptography method, secret sharing method defined in ISO / IEC 19592-2:2017, etc. is used. Since the gist of the present invention is not the invention of the secret sharing method itself, the details of the secret sharing method are left to relevant textbooks, standards, and papers, and detailed explanations are omitted.

[0054] Hereinafter, the structure and operation procedure of the electronic data management system 1 will be specifically described. The electronic data management system 1 shown in FIG. 1 includes a user terminal 2, a network storage 3, a network 4, a portable storage means 5, etc. Examples of the portable storage means 5 include a portable terminal 6 such as a smartphone, a tablet, a wearable device, etc., and a non-volatile storage means 7 such as a USB memory and a flash memory. The network storage 3 is a storage means connected to the user terminal 2 and a communication network such as the network 4.

[0055] The network storage 3 is a concept including auxiliary storage devices on the network 4, remote storage means such as cloud storage, etc. The user terminal 2 and the network storage 3 are connected to a network 4 such as a LAN, WAN, or the Internet. The user terminal 2 acquires the electronic data stored therein from the network storage 3 via the network 4, and transmits and stores the electronic data in the network storage 3.

[0056] User data includes the electronic data stored in the user terminal 2, the network storage 3, and the portable storage means 5, the electronic data created by derivation from this electronic data, the newly created electronic data, etc. Hereinafter, these data will be simply referred to as "user data". The network storage 3 is for storing user data. The network storage 3 is a storage device of a web server or a file server (not shown), in other words, a non-volatile auxiliary storage device.

[0057] The network storage 3 is a storage device connected to user terminals 2, mobile terminals 6, etc. via a network 4, such as a storage device installed in a dedicated server, distributedly managed network storage, storage of cloud services (cloud storage), etc. In the present embodiment, the network storage 3 means any storage device as long as it stores user data, including cloud storage. The network 4 is any known wired or wireless communication network, preferably a local area network (LAN) or the Internet.

[0058] In the present embodiment, the network 4 will be described as the Internet. The user terminal 2 is an electronic computer for the user to operate and use (details will be described later). The user terminal 2 can be directly connected to the network 4, but can also be connected to the network 4 via a communication mediation means 8 like the user terminal 2a. It is common for the user terminal 2a to be connected and used via a communication mediation means 8 such as a wireless gateway, proxy server, router, wireless access point, etc.

[0059] The electronic data management system 1 shall include these communication mediation means 8. In the present embodiment, since the means for connecting the user terminal 2 to the network 4 is not the gist of the present invention, its detailed description will be omitted. The data communication between the user terminal 2 and the network storage 3 encrypts the electronic data to be communicated and transmits and receives it to and from each other according to a predetermined communication protocol. Any communication protocol can be used as the communication protocol, but a protocol compliant with the ISO reference model, particularly a general-purpose protocol used in the Internet such as TCP / IP, is preferable.

[0060] In the user terminal 2, the file 10 is stored and used in the RAM disk 11 on the main memory device (RAM: Random Access Memory) of the user terminal 2. This RAM disk 11 serves as a working drive for the application programs operating on the user terminal 2. A plurality of distributed folders 12 are created in the RAM disk 11. These plurality of distributed folders 12 are folders for storing each of the plurality of fragment files generated by secretly distributing the file 10. The number of distributed folders 12 is preferably equal to the number of times the file 10 is secretly distributed, in other words, equal to the number of generated fragment files.

[0061] Each of the distributed folders 12 corresponds to a non-volatile storage means for finally storing the fragment file. For example, one distributed folder 12 corresponds to the network folder 13 of the network storage 3. Another distributed folder 12 corresponds to the local folder 15 of the auxiliary storage device 14 built into the user terminal 2. Still another distributed folder 12 corresponds to the portable storage means 5 (portable terminal 6 or non-volatile storage means 7) connected to the user terminal 2.

[0062] In this way, each of the plurality of distributed folders 12 corresponds to a plurality of storage means, and the fragment file stored in the distributed folder 12 is transferred to the storage means corresponding to that folder. In the user terminal 2, the fragment file is sent and stored in the network storage 3, the auxiliary storage device 14, and the portable storage means 5 as it is or encrypted. The user terminal 2 acquires the fragment file stored therein from the network storage 3 via the network 4, or sends the fragment file stored in the distributed folder 12 to the network storage 3.

[0063] This communication flow is schematically illustrated by a dashed line in FIG. 1. When the user terminal 2 transmits and stores the data in the distributed folder 12 to the network storage 3, the auxiliary storage device 14, the portable storage means 5, etc., a schedule can be set for each distributed folder 12. For example, the schedule is set to transmit fragmented files in the distributed folder 12 when a predetermined time arrives, when there is a request from an application program or a service of an operating system, or when there is an instruction from the user.

[0064] The user terminal 2 transmits all the contents of the distributed folder 12 or the difference from the previous transmission, which is appropriately determined by the communication speed, the size of the file (electronic data) to be transmitted, etc. The main storage device (RAM: Random Access Memory) of the user terminal 2 is a volatile memory, and when the power supply is cut off, the data stored on the main storage device volatilizes, in other words, disappears. Due to this feature, when the power of the user terminal 2 is turned off, all the electronic data in the main storage device disappears, and thus the contents of the RAM disk 11 that uses a part of the main storage device also disappear.

[0065] The RAM disk 11 is a drive, but it resides in a part of the memory area of the main storage device and disappears when the power is turned off, so it can be called pseudo-auxiliary storage means, pseudo-auxiliary storage device, pseudo-drive, virtual drive, etc. In the present embodiment, the RAM disk 11 uses a virtual drive created on the main storage device, but a virtual drive created on the auxiliary storage device 14 can also be used. The auxiliary storage device 14 is a non-volatile auxiliary storage means built into the user terminal 2 such as an HDD (Hard disk drive), an SSD (Solid State Drive), etc. Generally, in an electronic computer, application programs and user data are stored in a non-volatile auxiliary storage device such as the auxiliary storage device 14.

[0066] During the operation of a computer, an application program has its program code read from a storage device where it is stored, stored in the main memory device, and executed. Then, data required for the application program is read from the storage device and processed. In contrast, in this example, the decryptable user data (File 10) is not stored in the storage device 14. The user data is secret-shared to generate a plurality of fragmented files, which are stored in different storage means. One of the fragmented files is stored in the storage device 14, but it is impossible to decrypt meaningful information with only one fragmented file stored in the storage device 14.

[0067] When using File 10 of the user data, a plurality of fragmented files are retrieved from each storage device where they are stored and restored, and File 10 is restored. The user terminal 2 stores the restored File 10 in the RAM disk 11. Therefore, in this embodiment, the RAM disk 11 functions as a working drive, and the distributed folder 12 in the RAM disk 11 functions as a working folder. The working File 10 is stored in the RAM disk 11. As a result, the decryptable file disappears when the power of the computer is turned off, eliminating the information leakage of the decryptable File 10 (user data) and improving security.

[0068] [Specific Example of Secret Sharing] Figures 2 and 6 illustrate an example in which File 10 is secret-shared to generate three fragmented files 10n, 10h, and 10m, which are stored in three different storage means respectively. A RAM disk 11 is generated in a part of the main memory device of the user terminal 2 and recognized as a virtual drive by the operating system. In the example of Figure 2, the portable storage means 5 is described by taking the portable terminal 6 as an example. In the RAM disk 11, a working folder 16 is created, and File 10 is stored in this folder.

[0069] File 10 can be stored within the RAM disk 11, within a folder, or without a folder. Hereafter, the case where File 10 is stored within a specific folder will be used as an example for explanation. Also, dispersion folders 12 for storing fragmented files 10n, 10h, and 10m of File 10 are created in number corresponding to the number of fragmented files. In this example, network dispersion folder 12n, mobile dispersion folder 12m, and local dispersion folder 12h are respectively created within the RAM disk 11.

[0070] Network dispersion folder 12n is a folder used to transfer and store fragmented file 10n stored therein to network storage 3, specifically to network folder 13. In other words, network dispersion folder 12n is set to correspond to network folder 13. Local dispersion folder 12h is a folder used to transfer and store fragmented file 10h stored therein to local folder 15 of auxiliary storage device 14 built in user terminal 2.

[0071] Local dispersion folder 12h corresponds to local folder 15. Mobile dispersion folder 12m is a folder used to transfer and store fragmented file 10m stored therein to auxiliary storage means within portable terminal 6 connected to user terminal 2 by communication means. Fragmented file 10n obtained from network storage 3 is stored in network dispersion folder 12n. Similarly, fragmented file 10h obtained from auxiliary storage device 14 is stored in local dispersion folder 12h, and fragmented file 10m obtained from portable terminal 6 is stored in mobile dispersion folder 12m.

[0072] Fragmented files 10n, 10h, and 10m stored in network dispersion folder 12n, mobile dispersion folder 12m, and local dispersion folder 12h are used by restoration means for restoring the original File 10, and the restored original File 10 is stored in working folder 16. An application program or the like acquires File 10 from within working folder 16 and performs operations such as display and editing.

[0073] The fragment files 10n, 10h, and 10m used for restoring the file 10 are deleted under various timings and conditions. For example, after the original file 10 is restored, the fragment files 10n, 10h, and 10m used for it are deleted from the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h. Another example is that after the original file 10 is restored, the physical entities of the fragment files 10n, 10h, and 10m used for it are deleted from the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h, and only the names or only the links can be displayed.

[0074] Still another example is that after the original file 10 is restored, the fragment files 10n, 10h, and 10m used for it are not deleted and are kept as they are until the use of the original file 10 ends, and when the original file 10 is updated, they can be overwritten with the newly generated fragment files 10n, 10h, and 10m. Still another example is that after the original file 10 is restored, the fragment files 10n, 10h, and 10m used for it are deleted after the use of the original file 10 ends.

[0075] The updated file 10 and the newly created file 10 stored in the working folder 16 are subjected to secret sharing processing to create fragment files 10n, 10h, and 10m, and the fragment files 10n, 10h, and 10m are respectively stored in the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h. The fragment file 10n stored in the network distributed folder 12n is transmitted (transferred) to the network storage 3 via the network 4 and stored in the network folder 13.

[0076] Similarly, the fragmented file 10m stored in the mobile distributed folder 12m is transmitted (transferred) to the mobile terminal 6, and the fragmented file 10h stored in the local distributed folder 12h is transmitted (transferred) to and stored in the auxiliary storage device 14. At the user terminal 2, the fragmented files 10n, 10h, and 10m that have been transmitted (transferred) and for which the transmission (transfer) has succeeded are deleted from the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h.

[0077] 〔Hardware Configuration of User Terminal 2〕 The user terminal 2 is a general-purpose electronic computer equipped with a central processing means, a main storage means, an input means, an output means, a data transmission means, etc. The block diagram in FIG. 3 illustrates an example of the configuration of the user terminal 2. As shown in FIG. 3, the user terminal 2 includes a central processing unit (CPU) 21, a main storage device 22, an input interface 23, an output interface 24, an auxiliary storage device 14, a bus 25, an input device 26, an output device 27, a power supply unit 28, etc., stored in the main body 20.

[0078] The main body 20 is a main board (not shown) on which a central processing unit 21, a main storage device 22, an input interface 23, an output interface 24, a bus 25, etc. are mounted, and a housing incorporating an auxiliary storage device 14, a power supply unit 28, etc. The power supply unit 28 is for supplying power to each component and device of the user terminal 2 and consists of a battery or a commercial power adapter, etc., but these are well-known technologies and their detailed description is omitted.

[0079] The input device 26, output device 27, etc. are peripheral devices connected to and used with the main body 20. However, in the case of an integrated electronic computer such as a notebook-type electronic computer, they can be incorporated into or integrally configured with the main body 20. A touch panel having input and output functions can also be used as both the input device 27 and the output device 28. The user terminal 2 includes, as auxiliary storage means, a built-in auxiliary storage device 14, an external auxiliary storage device (not shown), etc. Hereinafter, the auxiliary storage device 14 will be described as an example.

[0080] Further, the central processing unit 21, the main memory device 22, the input interface 23, and the output interface 24 are connected to each other by a bus 25, and data is transmitted and received between them via this bus 25. Although the user terminal 2 can be provided with signal processing means for performing specific signal processing such as image processing, encryption processing, and authentication processing as an example, a detailed description thereof is omitted because it is not the gist of the present invention. The central processing unit 21 controls the operation of the user terminal 2, and controls the operation of the user terminal 2 while sequentially processing and executing the instructions of the program according to the program stored in the main memory device 22.

[0081] The main memory device 22 is a volatile storage means. The RAM disk 11 uses a part of the memory area of the main memory device 22. Input devices 26 such as a mouse and a keyboard are connected to the input interface 23. The auxiliary storage device 14 is a non-volatile storage means such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive). The auxiliary storage device 14 stores the code of the operating system, the code of the application program, electronic data, and the like. The application program is usually called from the auxiliary storage device 14 or the like, expanded in the main memory device 22, and operates.

[0082] The user terminal 2 is provided with a number of built-in devices such as a network card, a sound card, a graphics card, and a speaker. However, since the present invention is not intended for an interface, a detailed description thereof is omitted. The user terminal 2 includes a network card 41 (see FIG. 4) for connecting to the network 4 and a communication adapter 42 (see FIG. 4) for connecting to a portable device, and the description thereof will be given later.

[0083] 〔Software Configuration of User Terminal 2〕 FIG. 4 is a block diagram illustrating an overview of software and devices operating on the user terminal 2. In the user terminal 2, an operating system 30 operates, and software such as an application program 33 operates on a platform provided by the operating system 30. As illustrated in FIG. 4, the user terminal 2 includes devices 40 such as internally connected devices and externally connected devices.

[0084] Examples of the device 40 include a network card 41, a RAM disk 11, an auxiliary storage device 14, and a communication adapter 42. The user terminal 2 includes a device driver 50 for controlling each of these devices 40. In FIG. 4, as the device driver 50, a network driver 54, a RAM disk driver 52, a disk driver 53, a file system driver 51, and a communication driver 55 are illustrated.

[0085] The device driver 50 utilizes the input / output functions of the operating system 30 to communicate with each other and with the application program 33. In the present embodiment, it has driverware 60 as control means for controlling the device driver 50, and this is provided between the device driver 50 and the operating system 30. The driverware 60 controls the control of the device driver 50, the communication between the device drivers 50, and the communication between the device driver 50 and the operating system 30.

[0086] The operating system 30 has two types of operation modes: a kernel mode 31 in which all instructions provided by the operating system 30 can be executed, and a user mode 32 in which the execution of some instructions is restricted. The application program 33 basically operates in the user mode 32, and uses the input / output functions of the operating system 30 to transmit data to the device 40 via the device driver 50 and also to acquire data from the device 40.

[0087] Driverware 60 operates in the kernel mode 31 of the operating system 30. The driverware 60 controls the device driver 50 in the kernel mode 31 and realizes communication between the device drivers 50 in the kernel mode 31 (details will be described later). The cloud communication unit 34 is an application program that operates in the user mode 32 and transfers or receives data to / from a storage means such as the network storage 3. The cloud communication unit 34 reads and writes the fragmented file 10n in the network storage 3. A dedicated API (Application Programming Interface) is prepared for each network storage 3.

[0088] The driverware 60 includes a control unit 61, a dispersion unit 62, a restoration unit 63, an encryption unit 64, a decryption unit 65, etc. The RAM disk 11 does not physically exist independently but is a virtual storage device or a virtual device that operates software by using a part of the physical memory in the main storage device 22. Each device 40 is controlled by its respective device driver 50. Specifically, the network card 41 is controlled by the network driver 54, the auxiliary storage device 14 is controlled by the disk driver 53, and the communication adapter 42 is controlled by the communication driver 55.

[0089] Also, the RAM disk 11 is controlled by the RAM disk driver 52. The file system driver 51 controls the device drivers 50 for storage devices such as the disk driver 53 and the RAM disk driver 52. As a result, the file system driver 51 becomes the window of the input / output function (I / O function) of the operating system 30 for auxiliary storage devices such as the auxiliary storage device 14 and the RAM disk 11 and controls them. The operating system 30 originally controls the device 40 with the device driver 50 through its input / output function (I / O function).

[0090] The application program 33 operating on the user terminal 2 operates in user mode 32. Although there are some application programs 33 that operate in kernel mode 31, these are limited to special programs that directly access system resources. General-purpose application programs, especially object-oriented application programs, basically operate in user mode 32 and utilize functions such as input / output functions provided by the operating system 30 when accessing kernel mode 31.

[0091] In the present invention, the driver ware 60 located between the operating system 30 and the device driver 50 controls the input / output functions of the operating system 30 and the device driver 50. The configuration and functions of the driver ware 60 will be described in detail later. The auxiliary storage device 14 includes one or more electronic computers such as the user terminal 2. Hereinafter, the description will be given taking only one auxiliary storage device 14 as an example.

[0092] The auxiliary storage device 14 stores the code of the operating system 30, various application programs 33 such as program codes necessary for the operation of the user terminal 2, and source codes of modules, etc. (hereinafter simply referred to as the operating system 30, application programs 33, modules, etc.). In addition, the auxiliary storage device 14 can store electronic data such as user data. The user data is stored in the auxiliary storage device 14 either encrypted or unencrypted according to the needs such as user requests, specifications or requirements of the application program 33. In the present embodiment, the user data is electronic data used by the application program 33 or the user.

[0093] User data is not particularly limited, but includes text files, still image files, video files, audio files, document files in various formats (such as Word, pdf, etc.), computer program code files, executable files (.exe files), communication histories, operation histories of application programs, backup files of operating systems or application programs, various temporary files, files in any format such as the contents of memory, and backup files thereof. Also, user data is broadly interpreted to include data that requires data management, such as secret sharing codes, their restoration codes, encryption codes, decryption codes, identification numbers, passwords, personal information, customer data, business know-how, information on confidential data, and their documents, etc.

[0094] As described above, the user data used in the user terminal 2 is described as the file 10 or the working file 10. The device driver 50 is located between the operating system 30 and the device 40 and performs data transmission and reception therebetween. The operating system 30 uses its I / O function to control the device 40 via the device driver 50. The I / O function is a function for performing data input and output between the operating system 30 and the device 40, but performs data input and output with the device 40 via the device driver 50.

[0095] Although not shown in the figure, the user terminal 2 is provided with a hardware abstraction layer (HAL) located between software and hardware. The user terminal 2 includes input / output devices such as a keyboard 17 connected to the keyboard port 43, a mouse 18 connected to the mouse port 44, and a display (not shown). Although not shown in the figure, the user terminal 2 has a connector for connecting to peripheral devices, and the connector is preferably a serial port such as SATA, RS-232C, IrDA, USB, IEEE1394, or a parallel port such as IEEE1284, SCSI, IDE.

[0096] In addition, the user terminal 2 communicates with other devices via these connectors using a communication standard such as BLUETOOTH (registered trademark). The keyboard port 43 and the mouse port 44 are one of the connectors. The user terminal 2 can be equipped with peripheral devices such as a scanner and a printer, which are connected to the connectors. The application program 33 operating on the user terminal 2 performs input / output from / to the input / output devices and necessary processing using the functions provided by the operating system 30.

[0097] The application program 33 is, for example, software for creating and editing documents such as word processing software and text editors, and software for viewing, creating, and editing files in a specific format such as pdf format files. The operating system 30 is software that provides input / output functions from / to input / output devices such as input from the keyboard 17, input from the mouse 18, and screen output, and basic functions such as management of the storage device and memory, and operates and manages the entire user terminal 2.

[0098] The operating system 30 is also called basic software. The operating system 30 is composed of a number of executable programs to realize the functions it provides. There are many books about the operating system 30, especially the Windows-based operating system used in the embodiments of the present invention, and some of them will be introduced. In order to reproduce the present invention, the technical knowledge described in these published books, especially the knowledge related to device driver development, is required.

[0099] List of books on the internal configuration and operation of the Windows-based operating system: - Inside Windows NT by Helen Custer (Microsoft Press, 1992) - Inside the Windows NT File System by Helen Custer (Microsoft Press, 1994) - Inside Microsoft Windows 2000, Third Edition by David A. Solomon, Mark E. Russinovich (Microsoft Press, 2000).

[0100] List of books on the basics of device drivers and knowledge related to their development: - Programming the Microsoft Windows Driver Model by Walter Oney (Microsoft Press, 1999) - Programming the Microsoft Windows Driver Model, Second Edition by Walter Oney (Microsoft Press, 2002).

[0101] Here, an overview will be given of typical components within the operating system 30. The operating system 30 (see Figure 4) is composed of a kernel, an executive, subsystems, device drivers 50, a HAL, etc. The subsystems are services provided in the user mode 32 of the operating system 30. The executive provides basic services of the operating system 30 such as memory management, process and thread management, security, I / O (input / output), networking, and inter-process communication.

[0102] The kernel provides low-level functions such as thread scheduling, interrupts, exception notification, and multiprocessor synchronization. The kernel also provides a set of routines and basic objects used inside the executive. The device driver 50 is usually created for each piece of hardware connected to the user terminal 2 and directly controls the device 40 via the HAL. The device driver 50 is a service that converts input / output function requests (I / O call requests) from the application program 33 and the operating system 30 into input / output function requests (I / O requests) for a specific device 40, and provides system services such as file systems and network drivers.

[0103] The HAL is a code layer for separating and abstracting the kernel, device driver 50, and executive from platform-specific hardware functions. The HAL absorbs differences in hardware models and types, such as built-in devices of the user terminal 2 and external devices connected to the user terminal 2, and provides abstracted services for each service of the operating system 30.

[0104] The various services that make up the operating system 30 can access the hardware without being aware of differences in hardware models and types. As described above, the typical configuration and functions of the operating system 30 have been explained. For details, please refer to relevant books, web sources, etc., and the details will be omitted.

[0105] 〔Application Platform Program 35〕 The application platform program 35 (see Fig. 4) is application software that operates in the user mode 32 of the operating system 30. The application platform program 35 is located between the application program 33 and the operating system 30 and is an application program for mediating and controlling the transmission and reception of instructions and data between them.

[0106] The application platform program 35 has a function of monitoring the startup of the application program 33 and the startup of the associated processes, and acquiring their attribute information. The application platform program 35 provides a user interface for accessing the file system from the operating system 30. The application platform program 35 operates in cooperation with the driver ware 60, transmits the communication data acquired in the user mode 32 to the driver ware 60, and controls the application program 33 and the operating system 30 according to the instructions of the driver ware 60.

[0107] The application platform unit 35 allocates the RAM disk 11 as a working drive, holds data related to settings that can be changed according to the system configuration such as the dispersion number of secret sharing and the target folders for secret sharing (network dispersion folder 12n, mobile dispersion folder 12m, local dispersion folder 12h, network folder 13, mobile terminal 6, auxiliary storage device 15), etc., and instructs the control unit 61.

[0108] [Cloud communication unit 34] The cloud communication unit 34 is a dedicated application program or module for communicating with the network storage 3 (see FIG. 1), and operates in the user mode 32. The cloud communication unit 34 operates in cooperation with the driver ware 60 and is for transmitting and receiving (transferring) data between the network dispersion folder 12n and the network storage 3. The cloud communication unit 34 acquires the user data in the network dispersion folder 12n via the file system driver 51 and the driver ware 60.

[0109] The cloud communication unit 34 transmits the acquired user data to the network storage 3 via the driver ware 60, the network driver 54, and the network card 41. Conversely, the cloud communication unit 34 acquires user data from the network storage 3 via the network card 41, the network driver 54, and the driver ware 60, and stores it in the network distributed folder 12n via the driver ware 60 and the file system driver 51 (see FIG. 2). General-purpose services that provide cloud storage such as the network storage 3 basically provide an interface (I / F) in the user mode 32.

[0110] To access such an interface of the cloud storage, it is accessed by the cloud communication unit 34 operating in the user mode 32. To obtain the access right to the cloud storage, especially when connecting to the cloud storage, the interface (I / F) provided as a standard function with the account (ID and password) of the cloud storage is used for access in the user mode 32. When the access to the cloud storage is authenticated, the necessary access is controlled by the driver ware 60.

[0111] 〔Description of Driver Ware 60〕 FIG. 5 illustrates an overview of the software operating on the user terminal 2 including the driver ware 60. While referring to this figure, the operating system 30, the driver ware 60, etc. operating on the user terminal 2 will be described. In the present embodiment, the operating system 30 will be described by taking Windows as an example, especially including Windows 10 after Windows XP (registered trademark) of Microsoft Corporation, a U.S. corporation.

[0112] However, this does not limit the types of operating systems 30 that can be used in the present invention. Any operating system can be utilized as long as the same functions can be achieved. The user terminal 2 includes an operating system 30 that operates as software, driver ware 60, etc., and as hardware (device 40), it has a network card 41, an auxiliary storage device 14, a keyboard port 43, a mouse port 44, etc. in the main body 20.

[0113] The driver ware 60 is for realizing the transmission and reception of data between device drivers 50 in the kernel mode 31. When transferring data between device drivers 50 in the kernel mode 31, the data transfer can be performed at high speed and the security of the data can be ensured. Therefore, the driver ware 60 has the advantage of transferring a large amount of data at high speed in a short time. The driver ware 60 provides a common interface when accessing from the application program 33 to the device driver 50 and when transmitting data from the device driver 50 to the application program 33.

[0114] The driver ware 60 operates in the kernel mode 31 of the operating system 30. The driver ware 60 includes a dispersion unit 62 for dispersing electronic data and generating fragmented files, and a restoration unit 63 for restoring the original file (electronic data) using the fragmented files. The driver ware 60 has an interface unit 70 for receiving instructions, data, etc. from the application program 33 and transmitting data to the application program 33. The driver ware 60 has a control unit 61 for controlling the overall operation of the driver ware 60.

[0115] It also has a log acquisition unit 66 for acquiring the operation history of the driver software 60. The driver software 60 has an encryption unit 64 for encrypting data to be communicated and a decryption unit 65 for decrypting the encrypted data. The control unit 61 controls and monitors other parts of the driver software 60 such as the distribution unit 62, the restoration unit 63, the device driver control unit 67 for controlling each device driver 50, the interface unit 70, the log acquisition unit 66, the encryption unit 64, and the decryption unit 65. It is the core part of the driver software 60.

[0116] The device driver control unit 67 is composed of control units 71 - 74 for controlling each device driver 50. For example, it includes a network control unit 71 for controlling the network driver 54, a file system control unit 72 for controlling the file system driver 51, a communication control unit 73 for controlling the communication driver 55, and an input control unit 74 for controlling the keyboard driver 56 and the mouse driver 57, etc.

[0117] The device driver 50 includes those provided as an attachment to the operating system 30 and those created as needed by the device provider, etc., and installed on the user terminal 2. In this embodiment, the device driver 50 is described as being attached to the operating system 30. The network driver 54 is a device driver for controlling the network card 41.

[0118] The file system driver 51 manages information regarding files (electronic data) and folders stored in the auxiliary storage device 14, and provides access to the files and folders stored in the auxiliary storage device 14. In this example, the file system driver 51 provides access to storage devices compliant with standards such as IDE (Integrated Drive Electronics), ATA (Advanced Technology Attachment), SATA (Serial ATA), SCSI (Small Computer System Interface), USB (Universal Serial Bus), and their derivative standards, which are connected to the user terminal 2.

[0119] Since the present invention does not pertain to an invention mainly concerned with hardware standards, the detailed description thereof is left to the specification documents of each standard, and further explanation is omitted. Thus, the driverware 60 has an interface unit 70 for receiving instructions and / or data output from the application program 33 and transmitting the execution result of these instructions and / or the received data received from the device driver 50 to the application program 33.

[0120] Also, the driverware 60 has a device driver control unit 67 for transmitting these instructions and / or data to the device driver 50 and receiving the execution result of the instructions and / or the received data from the device driver 50. Furthermore, the driverware 60 has a control unit 61 for processing these instructions and / or data, generating output data, and controlling the data. The driverware 60 has a dispersion unit 62 for dispersing electronic data and a restoration unit 63 for generating the original file from the fragmented files with the secret dispersed.

[0121] The driver software 60 has an encryption unit 64 for encrypting data to create encrypted data, and a decryption unit 65 for decrypting the encrypted data to create the original data. The encryption unit 64 and the decryption unit 65 not only encrypt and decrypt data to the external device connected to the user terminal 2 and the network 4, but also encrypt and decrypt data stored in the storage means built in or connected to the user terminal 2 as necessary. Furthermore, it has a log acquisition unit 66 for acquiring and storing the history of the operation of the driver software 60.

[0122] In particular, the log acquisition unit 66 acquires and records the history of the operation of the control unit 61. Each control unit 71 to 74 of the device driver control unit 67 is controlled by the control unit 61, or receives instructions or data from the control unit 61 and transmits or transfers this to the device driver 50. The device driver control unit 67 receives data as a result of executing the above-described instructions from the device driver 50 and transmits it to the control unit 61. In this way, the driver software 60 is a core unit that controls the user terminal 2, particularly controls the operation of each device of the user terminal 2.

[0123] [Directory Structure] FIG. 6 illustrates an example of the directory structure of the RAM disk 11. Sub-folders and files are stored in a hierarchical structure in the working folder 16. For example, as illustrated in FIG. 6, sub-folders such as folder 16a and folder 16b are created in the working folder 16, and the file 10 is stored therein. For example, the file 10 is stored alongside the folder 16a in the working folder 16, or is stored in the folder 16a.

[0124] The network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h have the same hierarchical structure as the working folder 16, and store the fragment files 10n, 10m, 10h of the file 10 respectively. For example, as shown in FIG. 6, sub-folders such as folder 16an and folder 16bn are created in the network distributed folder 12n, and the fragment file 10n is stored therein. The fragment file 10n is stored side by side with the sub-folders in the working folder 12n or stored in these sub-folders.

[0125] In the mobile distributed folder 12m, sub-folders such as folder 16am and folder 16bm are created, and the fragment file 10m is stored side by side with or in these sub-folders. In the local distributed folder 12h, sub-folders such as folder 16ah and 16bh are also created, and the fragment file 10h is stored side by side with or in these sub-folders. In the present embodiment, the working file 10 used by the application program 33 is stored in the working folder 16 or in a sub-folder in the working folder 16, and operations such as editing are performed.

[0126] When the file 10 is stored in the working folder 16, secret sharing processing is performed to generate a plurality of fragment files 10n, 10m, 10h, and the generated fragment files 10n, 10m, 10h are stored in the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h in the same directory structure as the working folder 16. The network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h store data transmitted and received from the network storage 3, the mobile device 6, and the auxiliary storage device 14 respectively. These directory structures are synchronized.

[0127] Specifically, the directory structures in the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h are synchronized with the network storage 3, the mobile device 6, and the auxiliary storage device 14 in the same directory structure. The fragmented files in the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h are synchronized with or transferred to the network storage 3, the mobile device 6, and the auxiliary storage device 14 in the same directory structure.

[0128] In this embodiment, the file 10 in the work folder 16 refers to the file 10 stored in the work folder 16 and the file 10 stored in the subfolder in the work folder 16. In other words, the file 10 in the work folder 16 refers to the file stored in any folder of the directory structure of the work folder 16. The same applies to the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h. However, the file 10 and the fragmented files 10n, 10m, 10h generated by secret sharing of this file 10 are stored in folders with the same directory structure.

[0129] [Overview of the Operation of the User Terminal 2] FIG. 7 is a flowchart showing an overview of the operation of the user terminal 2 of the electronic data management system 1 according to the first embodiment of the present invention. First, the user terminal 2 is powered on and activated (steps 1 and 2). The operating system 30 is activated on the user terminal 2, performs initial processing, etc., and then the driver software 60 is activated (step 3).

[0130] To create the RAM disk 11, the file system control unit 72 secures an area for the RAM disk 11 on the main memory device 22, and settings for the RAM disk 11 are made in the operating system 30 and the driver software 60 (step 4). The area required for the RAM disk 11, that is, the memory size resident on the main memory device 22, is preset as a standard size such as 500 MB, 1 GB, 10 GB, etc., but can be specified by the user.

[0131] Since the driver software 60 controls the device driver 50, it controls the file system driver 51, etc., and makes settings to operate the RAM disk 11 as the main auxiliary storage device. First, the RAM disk 11 is registered in the I / O function of the operating system 30 as an auxiliary storage device. Also, the RAM disk driver 52 is loaded, and the file system control unit 72 issues a mount request, thereby cooperating with the file system driver 51. As a result, the RAM disk 11 is recognized by the file system driver 51 and the operating system 30 as a normal auxiliary storage device.

[0132] Next, the formatting process of the RAM disk 11 is performed. At this time, the partition information (MBR format, GPT format, etc.) of the RAM disk 11 is set and formatted. As a result, the application program 33, the operating system 30, etc. can access the RAM disk 11. Here, as an example, the Windows API functions used for formatting the RAM disk 11 are shown. This formatting process is performed from the application platform program 35 using, for example, the following functions.

Table 1

[0133] Next, in the RAM disk 11, a working folder 16, a network distributed folder 12n, a mobile distributed folder 12m, and a local distributed folder 12h are created (step 5). Then, the program of the cloud communication unit 34 is started, and the setting of the network distributed folder 12n is performed by the operating system 30, driver ware 60, application platform program 35, etc. (step 6). Then, the user terminal 2 connects to the network 4 (see FIG. 1) and connects to the network storage 3 (step 6).

[0134] In other words, the user terminal 2 establishes a communication link with the network storage 3. The user terminal 2 requests a connection to the network storage 3, and after the user's approval, it connects, or connects based on preset data. Next, the driver ware 60 performs processing necessary for connection to the mobile terminal 6 (step 7). The user terminal 2 requests a connection to the mobile terminal 6, and after the user's approval, it connects, or connects based on preset data. The mobile distributed folder 12m registers with the I / O function of the operating system 30 to connect to the mobile terminal 6.

[0135] The driver ware 60 issues a connection request to the mobile terminal 6 and waits for the user to activate and connect the mobile terminal 6. When the user gives permission to connect from the mobile terminal 6 to the user terminal 2, the driver ware 60 receives this, authenticates the mobile terminal 6, and establishes a communication link between the mobile terminal 6 and the mobile distributed folder 12m (step 7). The driver ware 60 sets the local distributed folder 12h to connect to the auxiliary storage device 14 (step 8).

[0136] Next, directory structures are set up for the working folder 16, the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h. Here, the driver ware 60 reads out the directory structures of the folders set from each of the storage devices of the network storage 3, the mobile terminal 6, and the auxiliary storage device 14, and sets the same directory structure for the working folder 16, the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h.

[0137] At this time, only the directory structures of the network folder 13 of the network storage 3, the folder of the mobile terminal 6, and the local folder 15 of the auxiliary storage device 14, and the file names of the files stored in their sub-folders are acquired and set for the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h. Therefore, directory structures for each folder are created in the working folder 16, the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h, and file names are stored therein.

[0138] To the user, this makes it appear as if the file 10 actually exists. In other words, it pseudo-displays the file 10. In this pseudo-display, the restored working file 10 displays its file name as if it actually exists, and when there is an access request to the working file 10 from the application program 33 or the like, the working file 10 is restored from the fragment files 10n, 10m, 10h. This prepares the user terminal 2 for use by the user. The files in the working folder 16 appear to be stored in the auxiliary storage device 14.

[0139] That is, the driverware 60 controls the input / output functions of the operating system 30 and the device driver 50, redirects access to files, and switches file access to the auxiliary storage device 14 to access to the RAM disk 11. From the perspective of the application program 33, the working folder 16 appears as a mid-document of the auxiliary storage device 14 and like a folder therein. The application program 33 operates on the user terminal 2 to perform data processing and the like (step 8).

[0140] The application program 33 operates on the user terminal 2 and operates according to a request or instruction from the user, another application program, or a service of the operating system 30. The application program 33 issues a request to read a file (step 9). At this time, the application program 33 basically selects an appropriate folder and an appropriate file stored in the auxiliary storage device 14 and issues a request to read them. Although this appropriate folder and appropriate file are supposed to be read and written in the auxiliary storage device 14 for the user or the application program 33, their actual entities are in the working folder 16.

[0141] Using the redirect function of the driverware 60, the read / write requests to the auxiliary storage device 14 are redirected to the working folder 16 for control. The driverware 60 receives a request from the application program 33. The driverware 60 requests the corresponding fragmented files from the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h for the requested file, and restores the file 10 (step 10).

[0142] When there are corresponding fragment files 10n, 10m, 10h in the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h, the driver ware 60 acquires them, passes them to the restoration unit 63, and restores the file 10. The restoration unit 63 receives the fragment files 10n, 10m, 10h, performs appropriate restoration processing on them, and restores the original file 10. Then, the restoration unit 63 passes the restored original file 10 to the control unit 61. First, the control unit 61 stores this restored file 10 in the work folder 16.

[0143] Then, the control unit 61 reads the file 10 from the work folder 16 and passes it to the application program 33 via the interface unit 70. The application program 33 receives this and starts using the file 10 (step 11). When there are no required fragment files 10n, 10m, 10h in the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h, the driver ware 60 acquires them from each storage device of the network storage 3, the mobile terminal 6, and the auxiliary storage device 14, and stores them in the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h.

[0144] Then, the driver ware 60 performs the above restoration process. When receiving a file from the network storage 3, the driver ware 60 takes the following two methods. The first method is that when receiving a file from the network storage 3, it sends a file read request to the cloud communication unit 34. The cloud communication unit 34 reads the file from the network storage 3 via the network driver 54 according to the connection settings of the network storage 3 and passes it to the driver ware 60.

[0145] The second method is that when receiving a file from the network storage 3, a read request for the file is sent to the network storage 3 via the network control unit 71, the network driver 54, etc., and the file sent from the network storage 3 is received. In this method, the operation of reading a file from the network storage 3 can be realized only in the kernel mode 31 without passing through the user mode 32.

[0146] When using an application program 33 operating in the user mode 32 as in the first method, since the driverware 60 receives the setting function, setting values, etc. when setting these network folders 13, it can be sent to the network folder 13 as a request from the cloud communication unit 34. From the perspective of the network storage 3, the file read request from the cloud communication unit 34 and the file read request sent from the driverware 60 are the same, and the same processing is performed to send the requested file.

[0147] The application program 33 uses the file 10 to perform operations such as browsing and editing, and issues a request to save this (step 11, step 12). The save destination of the request issued by the application program 33 is the auxiliary storage device 14. The driverware 60 detects the save request issued by the application program 33. Then, the driverware 60 redirects this save operation and saves the file 10 to the working folder 16. And when the file 10 is saved in this way, the driverware 60 detects the end of the save operation and starts the process of secret sharing the working file 10 (step 13).

[0148] At this time, the control unit 61 reads the work file 10, passes it to the dispersion unit 62, and causes the secret dispersion process to be performed (step 13). The dispersion unit 62 receives the work file 10, secretly disperses it, and generates fragment files 10n, 10m, and 10h. The dispersion unit 62 passes the generated fragment files 10n, 10m, and 10h to the control unit 61, and the control unit 61 stores the fragment files 10n, 10m, and 10h in the network dispersion folder 12n, the mobile dispersion folder 12m, and the local dispersion folder 12h (step 14).

[0149] When the storage of the fragment files 10n, 10m, and 10h is completed, the driverware 60 transfers the fragment files 10n, 10m, and 10h to the respective storage devices 3, 6, and 14 (step 15). The fragment file 10n stored in the network dispersion folder 12n is transmitted by the driverware 60 to the cloud communication unit 34 and finally stored in the network storage 3. The fragment file 10m in the mobile dispersion folder 12m is read by the file system control 12 and finally stored in the mobile terminal 6 via the communication control unit 73 and the communication driver 55.

[0150] The fragment file 10h in the local dispersion folder 12h is read by the file system control unit 12 and stored in the auxiliary storage device 14 via the file system control unit 72, the file system driver 51, and the disk driver 53. When the transfer of the fragment files 10n, 10m, and 10h stored in the network dispersion folder 12n, the mobile dispersion folder 12m, and the local dispersion folder 12h is completed, the transferred fragment files 10n, 10m, and 10h are deleted from these respective dispersion folders 12.

[0151] When deleting, instructions are issued from the control unit 61 to delete the fragment files 10n, 10m, and 10h and the operation is executed. The driver software 60 constantly monitors whether the use of the working file 10 has ended. When the use ends, the working file 10 in the working folder 16 is deleted. It is finally confirmed whether the working file 10 has been secret-shared. If it has not been secret-shared at the last save of the working file 10, the processes of steps 13 to 15 described above are performed, secret-sharing is performed to generate the fragment files 10n, 10m, and 10h, and these are transferred to the final storage destination.

[0152] The end of the use of the working file 10 is realized by monitoring whether the application program 33 has ended or whether the application program 33 closes the working file 10. When the working file 10 is open, in the settings of the operating system 30, a setting is made to prohibit overwriting and saving the working file 10 with other application programs, etc. A temporary file of the working file 10 is created, and the temporary file is periodically updated by the application program 33.

[0153] The driver software 60 constantly monitors the setting to prohibit overwriting and saving, the command to close the file issued by the application program 33, the existence of the temporary file, the update of the temporary file, etc. By this monitoring, the state of the working file 10 is obtained, and necessary processes such as the process of secret-sharing the working file 10 and the process of deleting the working file 10 are performed (step 16). When the application program 33 ends or when the application program 33 closes the working file 10 and ends the use of the working file 10, the working file 10 is secret-shared and the fragment files 10n, 10m, and 10h are transferred (step 16).

[0154] Then, the working file 10 is finally deleted from the working folder 16, and the process proceeds to the next process (Steps 18 and 19). When the power of the user terminal 2 is turned off, the content of the main memory device 22 is erased, and thus the content of the RAM disk 11 is also erased. Along with this, the fragmented files and the like stored in the working folder 16, the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h are erased, so that the decipherable user data associated with the working file 10 does not remain in the user terminal 2.

[0155] The fragmented file 10h is stored in the auxiliary storage device 14 of the user terminal 2, but the original file 10 cannot be restored using only the fragmented file 10h, and meaningful content cannot be obtained by analyzing only the fragmented file 10h. Therefore, user data does not leak from the user terminal 2, and confidentiality can be ensured. As described above, since the secret sharing and restoration processes are performed in the kernel mode 31, the working file 10 can be secretly shared or restored at high speed. The transfer of the fragmented file is also basically performed in the kernel mode 31 by controlling the device driver 50, so that the process is not passed to the user mode 32 or file data is not passed in the user mode 32, enabling high-speed transfer and reducing information leakage.

[0156] [Operation of the Management Program] Hereinafter, an operation example of the driverware 60 will be described with reference to the flowchart illustrated in FIG. 8. The driverware 60 is provided as a management program together with the application platform program 35 and the cloud communication unit 34. The management program is stored in the network storage 3 on the network 4 or other file servers and application providing sites, and is downloaded and installed on the user terminal 2 (Step 30).

[0157] In addition, the management program is provided by being stored in a recording medium or the like. In this way, the management program is provided by any method. The management program is installed and started on the user terminal 2, and license authentication of the management program, terminal authentication of the user terminal 2, and user authentication are performed in a predetermined procedure (step 31). After all these authentications are successfully completed, the user terminal 2 is ready to use the management program and user data. At this time, in the user terminal 2, a RAM disk 11 is set in the main storage device 22.

[0158] In this example, the setting of the RAM disk 11 is performed by a file system control unit 72 built into the driverware 60 (see FIG. 5). Since the method of this setting has been described above, a detailed explanation is omitted. Then, a working folder 16, a network distributed folder 12n, a mobile distributed folder 12m, and a local distributed folder 12h are created, and the directory structure is set.

[0159] The management program (driverware 60) has a control mode for controlling the installed user terminal 2. Here, when the management program controls the user terminal 2 to prevent leakage of user data, it is said that the control mode is effective or the control mode is turned on. Conversely, when the management program is not controlling the user terminal, it is said that the control mode is invalid or the control mode is turned off.

[0160] When the control mode is turned off, the installed management program does not control the computer, and the user terminal 2 operates as usual. At this time, since the management program is installed, started, and operating on the user terminal 2, the operation of the user terminal 2 can be monitored, and its log can be acquired and saved. When the control mode of the management program is turned on, the control of the user terminal 2 is started (step 32). The instruction to turn on this control mode is given from the application platform program 35 of the user terminal 2.

[0161] Alternatively, when the application program 33 or the user accesses the file 10 to be controlled, the driverware 60 detects this and turns on the control mode. Therefore, the management program checks the auxiliary storage device 14, the RAM disk 11, etc. connected to the user terminal 2 (step 33). Also, each distributed folder 12 is checked. This check is made by determining whether the RAM disk 11 and the network distributed folder 12n are included in the auxiliary storage device recognized by the operating system 30.

[0162] Set the writing to the auxiliary storage device 14 built into the user terminal 2 to be prohibited (step 34). At this time, storage devices such as USB memories, removable drives, flexible disk drives, and external auxiliary storage devices are set to prohibit writing. In other words, the recording of user data is restricted for recording means that can take out user data from the user terminal 2. Even if there are recording means other than the storage devices exemplified in the above-described storage devices, they shall fall within the scope of the present invention. At this time, the RAM disk 11 is not prohibited from access such as writing.

[0163] Also, the auxiliary storage device 14 in which the operating system 30 is installed is necessary for the operation of the operating system 30 and is not subject to access restrictions such as prohibiting writing. Therefore, when the application program 33 or the operating system 30 attempts to write user data to the storage device that is subject to the recording restriction of these user data, the driverware 60 detects this and controls the writing operation. The management program sets the communication port for communicating with the network 4 (step 35).

[0164] As for communication with Network 4, it includes wired or wireless communication to the Internet, LAN, etc. via Network Card 41, and wired or wireless communication between computers. In this setting, only the necessary communication ports of User Terminal 2 are permitted to be used, and unnecessary ports are prohibited from communicating. This is something that can be selected and set by the user, administrator, etc. When the management program is installed, or when its control mode is turned on, it can be preset or selected by the user. Interfaces other than the above communication ports of the user terminal are set to be prohibited from use.

[0165] For example, interfaces of USB, SCSI, IDE, and RS-232C standards are set to be prohibited from use (Step 36). Furthermore, the management program prohibits the use of copy & paste, the use of the clipboard, network functions, and screen capture (Step 37). However, if the user, administrator, etc. want to use all or some of these, they do not prohibit their use. Finally, the management program designates the processes necessary for the normal operation of Operating System 30 and makes exception settings (Step 38). For example, the System process, etc. necessary for the operation of Operating System 30 is made operable.

[0166] The various confirmations and settings from Step 33 to Step 38 after the management program turns on the control mode do not necessarily have to be performed in this order and can be freely combined according to the situation. When these settings are completed, the management program sets up the RAM disk 11. The network distributed folder 12n can be set as the virtual storage device of Network Storage 3. At this time, paths are set for the application program 33, operating system 30, etc.

[0167] When accessing this path, the physical data is downloaded from the network storage 3 and stored in the RAM disk 11. Therefore, in the settings of the RAM disk 11, settings are made to map the RAM disk 11 to the network distributed folder 12n. Also, various settings are made when transferring the user data stored in the RAM disk 11 to the network storage 3. For example, regarding the user data, settings such as the encryption key for encryption, the timing of transfer (specific time, interval, etc.), the communication speed, the priority, etc. are set, and the administrator can select these settings as needed.

[0168] The management program acquires the process name and process ID of the running process (step 38). The management program saves the acquired process name and process ID in the process control list (refer to Table 1) (step 39). In the process control list, as a condition for the file path, the storage destination or the working folder 16 is specified. In this example, "Application 1" sets "e:\". A network drive is assigned to the network storage 3, a drive name such as "e:" is assigned, and any folder in the network storage 3 can be freely read and written to by accessing this drive.

[0169] Thereby, the application program 33 is started, work is performed on the user terminal 2, and the reading and writing of user data are controlled while being monitored by the management program (driver ware 60). Therefore, the processing results of the application program 33 and the operating system 30 and the processed user data are secretly distributed and stored in different storage devices. The control mode of the management program continues unless this is intentionally set to OFF. When the control mode of the management program is set to OFF by the administrator or a preset condition, all or part of the above settings are released.

Table 2

[0170] [Operation of the Control Unit] When the driver software 60 is instructed to turn on the control mode, the control unit 61 receives this instruction and sends an instruction to prohibit all file accesses to the control means for controlling storage devices such as the network control unit 71, the file system control unit 72, the communication control unit 73, and the input control unit 74, and performs monitoring and setting. The settings of the control process described above, the prohibition of network use, the prohibition of clipboard use, the prohibition of screen capture use, the prohibition of copy and paste functions, etc. are performed according to the instructions issued from the control unit 61.

[0171] The process manager of the operating system 30's executive manages all processes running on the user terminal 2. Here, by registering a callback function (using the kernel's API), events for starting and ending processes are obtained. For the start and end events of the processes to be executed, a callback function is set so that the start and end of the application program 33 can be detected. When the application platform program 35 is operating, the application program 33 starts.

[0172] The application platform program 35 detects the start of the application program 33. The process of the application program 33 is started in the SUSPEND mode of CreateProcess, and the application platform program 35 obtains the handle and process ID of this process. When the process is started in the suspend mode of CreateProcess, it is in a suspended state and will not be executed until it is resumed. The handle is the process handle returned from CreateProcess.

[0173] The application platform program 35 transmits the acquired handle and process ID to the control unit 61. When the process is started, it executes the callback function in the file system control unit 72 and notifies the control unit 61 of the start of control. The control unit 61 acquires the handle and process ID. The detailed operation of this acquisition will be described later. The control unit 61 transmits the handle and process ID to the file system control unit 72, refers to the management table using the process ID, and performs settings to permit file access according to the values in the management table.

[0174] The items set to permit file access are the process ID, process name, file name, folder name, and file operation. The setting specified for the file operation is to permit either read-only or read / write. After these series of settings are completed, the suspended process is resumed using the acquired handle. The application program 33 operates. Then, the control unit 61 waits for an end event, which is a notification issued from the operating system 30 when the application program 33 ends.

[0175] When the application program 33 ends, it executes the callback function in the file system control unit 72 and notifies the control unit 61 of the release of control. The file system control unit 72 releases the control that was being performed by the process control list (refer to Table 1), and thereafter, does not control this application program 33. Of course, when this application program 33 accesses user data, the control is resumed.

[0176] When the application program 33 ends, an end event is generated. The application platform program 35 acquires the process ID of the end event. The application platform program 35 transmits the process ID of the end event to the control unit 61. The control unit 61 acquires the process ID of the end event. The control unit 61 acquires the user data used by the application program 33 stored in the RAM disk 11.

[0177] This user data is stored in the distributed folder 12. On the user terminal 2, it is necessary to operate the minimum execution files and processes required for the operation of the operating system 30 without restrictions. For example, as processes, System, Kernel.exe, and explorer.exe can be exemplified. The control process name and control directory are registered in the process control list. The control unit 61 acquires access from the system process to the auxiliary storage device 14 and replaces it with access to the corresponding folder of the RAM disk 11, in other words, redirects it.

[0178] To acquire the process name, use the ZwQueryInformationProcess function to acquire the image path of the running process, and acquire the process name from the file name of the executable file exe of this. To acquire the process ID, use the PsGetCurrentProcessId() function to acquire the ID of the current process. To acquire the file name, acquire the file name from the file object referenced from the input / output (I / O) request (IRP) regarding the I / O request of the file.

[0179] Event detection is performed as follows. The I / O requests in the kernel of the operating system 30 are performed in the form of IRP (IO Request Packet). Regarding file access, the IRP shown in Table 2 below is used. When this IRP is requested to the file system 51, monitor passing through the control unit 61 to perform event detection.

Table 3

[0180] User data is basically called from the application program 33 and deployed and used in the main memory device 22. When an action to call user data is performed, the application program 33 issues an access request to read the file 10 from the auxiliary storage device 14. The actual form of the file 10 is the distributed folder 12, and the actual forms of the fragmented files 10n, 10m, and 10h of the file 10 are stored in the network storage 3, the auxiliary storage device 14, the mobile terminal 6, etc. at their transfer destinations.

[0181] When this request is issued, the fragmented files 10n, 10m, and 10h are downloaded from the network storage 3, the auxiliary storage device 14, the mobile terminal 6, etc., stored in the distributed folder 12, and the original file 10 is restored from the fragmented files 10n, 10m, and 10h and stored in the working folder 16. The restored file 10 is passed to the application program 33 to perform operations.

[0182] Then, when the operation of the application program 33 is completed and the working file 10 is to be saved, similarly, a request to save it in the working folder 16 is output to the auxiliary storage device 14, but this is redirected, the working file 10 is stored in the working folder 16, and then the secretly distributed fragmented files 10n, 10m, and 10h are stored in the distributed folder 12. Then, the fragmented files 10n, 10m, and 10h are transferred from the distributed folder 12. The fragmented files 10n, 10m, and 10h are transferred and stored in the storage devices 4, 6, and 14 at each transfer destination, and if the storage fails, a retry is performed.

[0183] [Encryption and Decryption] Figure 9 illustrates the process of using the fragmented files 10n, 10m, and 10h encrypted on the user terminal 2. The basic process is the same as the flowchart in Figure 7 described above. Here, the different parts will be explained. The driver ware 60 has an encryption unit 64 for encrypting electronic data and a decryption unit 65 for decrypting the encrypted electronic data. When the control unit 61 receives the encrypted fragmented files 10n, 10m, and 10h, it passes them to the decryption unit 65 for decryption (step 9).

[0184] The decryption unit 65 decrypts the encrypted fragmented files 10n, 10m, and 10h received from the control unit 61 using a predetermined decryption key and passes the result to the control unit 61 (step 9a). The control unit 61 stores the decrypted fragmented files 10n, 10m, and 10h in the respective distributed folders 12n, 12m, and 12h. Thereafter, the restoration unit 63 restores the original file 10 using the fragmented files 10n, 10m, and 10h (step 9a). Here, the control unit 61 may directly pass the decrypted fragmented files 10n, 10m, and 10h received from the decryption unit 65 to the restoration unit 63 for restoration processing.

[0185] Since the restoration process is performed using two or more fragmented files 10n, 10m, and 10h, after one fragmented file is decrypted, it can be stored and wait in either the working folder 16 or the distributed folder 12 on the main memory device 22 until the other fragmented files are decrypted. When the restoration unit 63 receives the required number of fragmented files 10n, 10m, and 10h for restoration, it performs the restoration process, passes the generated original file 10 to the control unit 61, and the control unit 61 stores it in the working folder 16 via the file system control unit 72.

[0186] When the control unit 61 receives the fragmented files 10n, 10m, and 10h generated by secret sharing in the distribution unit 62, it passes them to the encryption unit 64 for encryption (step 14a). The encryption unit 64 encrypts the fragmented files 10n, 10m, and 10h received from the control unit 61 using a predetermined encryption key and passes the result to the control unit 61 (step 14a). When the control unit 61 receives the encrypted fragmented files 10n, 10m, and 10h, it stores them in the distributed folder 12 and then transfers them to each of the storage devices 3, 6, and 14. When the control unit 61 receives the encrypted fragmented files 10n, 10m, and 10h, it can directly perform transfer processing to each of the storage devices 3, 6, and 14.

[0187] [Usage form] FIG. 10 and FIG. 11 illustrate other examples of using the secretly shared user data in the present embodiment. The user terminal is operated, the operating system 30 is started for initial settings, and the driver software 60 is also started for initial settings (steps 50, 51, 52). The RAM disk 11 is set by the driver software 60, and the distributed folder 12 is set (steps 53, 54). Here, the driver software 60 sets the control mode to ON, performs various settings, and identifies the environment for using the user terminal 2.

[0188] For example, the user terminal 2 identifies whether it is in the environment for normal use. For example, the environment for normal use can include an office, home, etc., where the user terminal 2 is used daily. The environment for using the user terminal 2 is determined by the network address when the user terminal 2 is connected to the network 4, the wireless access point, the network address when the user terminal 2 is connected to the mobile terminal 6, the network address of the mobile terminal 6, the location information by the location identification means built-in or externally connected to the user terminal 2, the location information measured by the location identification means of the mobile terminal 6, etc. In this example, the office is taken as an example to explain the environment where the user terminal 2 is used daily.

[0189] When the user terminal 2 is in the office, the use of the user terminal 2 is normal. For example, the use is carried out as per the flowchart of FIG. 7 and its description above (step 55 → step 56). When the user terminal 2 is not in the office, in other words, when it is not in a normal usage environment, the user terminal 2 is connected to the network 4 and checks whether the network storage 3 can be used (step 57). This check is determined by whether the user terminal 2 is connected to the network 4 and whether the necessary security and data communication speed are ensured.

[0190] In the determination of step 57, if the network storage 3 can be used, basically the mobile terminal 6 can be used, so the user terminal 2 is used as normal (step 57 → step 56). In the determination of step 57, if the network storage 3 cannot be used, it is checked whether the mobile terminal 6 is connected (step 57 → step 58). When the mobile terminal 6 is connected and has been authenticated normally, the use of the user terminal 2 is started (step 58 → step 61).

[0191] When the mobile terminal 6 is not connected, or even if it is connected but not authenticated normally, it is determined that the use of the user terminal 2 is unavailable, a screen for instructing the reconnection of the mobile terminal 6 is displayed, and the next process is awaited (step 58 → step 59). The user reconnects the mobile terminal 6 to the user terminal 2 and performs authentication, etc., until the mobile terminal 6 is normally connected to the user terminal 2 (step 60 → step 58). The mobile terminal 6 is reconnected to the user terminal 2 and user authentication is performed.

[0192] If it cannot be normally connected a predetermined number of times, or if it cannot be normally connected within a predetermined period, the use of the mobile terminal 6 is not permitted, and the user cannot use the user data on the user terminal 2. In step 61, when the use of the user terminal 2 starts, the application program 33 issues a request to read the file 10, and this is monitored and controlled by the driver ware 60 (step 62).

[0193] Specifically, the fragment files 10m and 10h of the file 10 for which a read request has been made are acquired, and the original file 10 is restored using these, and the restored file 10 is stored in the working folder 16 and passed to the application program 33 (steps 63 to 65). The application program 33 uses the working file 10. The application program 33 issues a request to save the working file 10 (steps 65, step 66). The working file 10 is stored in the working folder 16, secret-shared, and the fragment files 10n, 10m, and 10h are generated (step 67).

[0194] The generated fragment files 10n, 10m, and 10h are stored in the distributed folder 12 and transferred (steps 68, step 70). At this time, since the network storage 3 is not available, the fragment file 10n is not transferred. If necessary, the fragment files 10n, 10m, and 10h are encrypted (step 69). It is confirmed whether the application program 33 has ended (step 71). If the application program 33 has not ended and the working file 10 is to be continuously used, the above operations are repeated (step 71 → step 65).

[0195] When the application program 33 has ended, the transfer of the fragment files 10n, 10m, and 10h is finally confirmed (step 71 → step 72). If there is a fragment file 10n or a fragment file 10m that has not been transferred, this is transferred. However, if it cannot be used in a situation such as a communication failure between the network 3 and the mobile terminal 6 etc., the fragment file 10n or the fragment file 10m that has not been transferred is transferred to and stored in another storage medium (step 73). Here, the fragment file 10h is stored in the auxiliary storage device 14 without problems when the user terminal 2 is operating normally.

[0196] Since the fragmented file 10m is connected to the mobile terminal 6 and is normally authenticated at the start of use of the user terminal 2, it can be transferred normally as long as this situation continues. In this way, when the two fragmented files 10m and 10h are stored in the non-volatile storage medium, the original file 10 can be restored from these two. Therefore, the fragmented file 10n can be deleted without being transferred to the network storage 3. Or, the fragmented file 10n can be encrypted and stored in the auxiliary storage device 14, the mobile terminal 6, another storage medium, etc.

[0197] In this way, when the fragmented file 10n cannot be transferred to the network storage 3, the user can choose to encrypt the fragmented file 10n and store it in the auxiliary storage device 14, the mobile terminal 6, another storage medium, etc. Or, it is performed according to the preset pointer. When the fragmented file 10n or 10m cannot be transferred, it is encrypted and stored in the auxiliary storage device 14, etc., or stored in a folder that can be accessed only by the driver ware 60.

[0198] This storage destination folder is preferably a hidden folder that is not visible to the user during normal access. The encryption key for encryption is preferably different from the encryption key and authentication key when accessing the distributed folder 12, the network storage 3, and the mobile terminal 6, although it is not limited. After the transfer of the fragmented files 10n, 10m, and 10h, the fragmented files 10n, 10m, and 10h in the working file 10 and the distributed folder 12 are deleted (step 74). Then, move on to the next operation (step 75).

[0199] FIG. 12 illustrates a flowchart of an example of using fragmented files. When using the user terminal 2, after startup, the usage form of the user terminal 2 is confirmed, and it is checked whether it is normal usage (steps 90, 91). For example, an example is shown in step 55 of the flowchart in FIG. 10. If it is not normal usage of the user terminal 2, the process moves to the steps after step 57 of the flowchart in FIG. 10 and the work is performed (step 91 → step 92). In the case of normal usage of the user terminal 2, it is checked whether there are fragmented files 10n, 10m, 10h that have not been transferred into the user terminal 2 (step 91 → step 93).

[0200] For example, in step 73 of the flowchart in FIG. 11, due to a communication failure with the network 3, the mobile terminal 6, etc., the existence of fragmented files 10n, 10m, 10h that have not been transferred is confirmed. At this time, first, the fragmented files of each drive are checked (step 91 → step 93). For example, it is checked whether there are files stored in a preset folder. If there are fragmented files that have not been transferred, an appropriate storage means 3, 6 is connected, and this fragmented file is transferred (step 94 → step 95).

[0201] When the transfer of the fragmented files is completed, the use of the user terminal is started (step 96). If there are no fragmented files that have not been transferred, normal use is started (step 94 → step 96). If, in the flowchart 123 in FIG. 11, the fragmented file n that has not been transferred is deleted, the original file 10 is restored from the other two fragmented files 10m and the fragmented file 10h, and the fragmented files 10n, 10m, 10h are generated again. Then, these generated fragmented files 10n, 10m, 10h are transferred to each storage device.

[0202] [Second Embodiment] FIG. 13 is a block diagram showing an overview of the electronic data management system 1 according to the second embodiment of the present invention. The electronic data management system 1 according to the second embodiment of the present invention has basically the same configuration and the same functions as the electronic data management system 1 according to the first embodiment of the present invention described above. Here, only the different parts will be described.

[0203] The electronic data management system 1 according to the second embodiment of the present invention uses a USB memory 7 as the portable storage means 5. FIG. 14 is a flowchart showing an overview of the operation of the user terminal 2 of the electronic data management system 1 according to the second embodiment of the present invention. Here, the same parts as those shown in FIG. 7 are omitted, and the different parts will be described. The USB memory 7 is a non-volatile memory that is connected to the user terminal 2 in accordance with the USB standard.

[0204] The user terminal 2, the operating system 30, the driver software 60, etc. are sequentially started, and initial processing and the like are performed (steps 100 to 104). In particular, a RAM disk 11 is created, and initial settings of the RAM disk 11 are performed (step 104). A connection is made to the network storage 3, and authentication processing is performed (step 105). Thereafter, a connection with the USB memory 7 is confirmed, and recognition processing is performed (step 106). If the USB memory 7 is not connected to or recognized by the user terminal 2, the system waits until the USB memory 7 is connected and recognized.

[0205] When the user connects an appropriate USB memory 7 to the user terminal 2, the USB memory 7 is automatically recognized by the user terminal 2 with the PnP function. The USB memory 7 is recognized by the driver software 60, and initialization processing, that is, processing to make a specific area in the USB memory 7 recognizable to the operating system 30, processing to decrypt and recognize it if it is encrypted, etc. are performed. A work folder 16, a network distributed folder 12n, a mobile distributed folder 12m and a local distributed folder 12h are created in the USB memory 7, and a directory structure is created and set (step 107).

[0206] The application program 33 issues a request to read the working file 10 and starts using the working file 10 (step 108). At this time, as described in the flowchart of FIG. 7, the fragment file 10m of the working file 10 is read from the USB memory 7, stored in the mobile distributed folder 12m, and used for restoring the original file 10 (step 109). The application program 33 performs operations such as browsing and editing using the file 10 and issues a request to save it (step 110, step 111).

[0207] When the working file 10 is saved in the working folder 16, it is secretly distributed, and the generated fragment files 10n, 10m, 10h are stored in the distributed folder 12 such as the mobile media distributed folder 12m (step 112, step 113). When the storage of the fragment files 10n, 10m, 10h is completed, the driver software 60 transfers the fragment files 10n, 10m, 10h to each storage device such as the USB memory 7 (step 114).

[0208] When the application program 33 ends, or when the application program 33 closes the working file 10 and ends the use of the working file 10, the working file 10 is secretly distributed, and when the fragment files 10n, 10m, 10h stored in the mobile media distributed folder 12m etc. are transferred, they are deleted (step 115 → step 116, step 117). Then, it moves on to the next operation (step 118). When the application program 33 continues without ending, steps 110 to 114 are repeatedly performed (step 115 → step 110).

[0209] As described above, by using the USB memory 7, user authentication is performed with the USB memory 7, and user data is used in a secret sharing manner. When using portable storage means such as the USB memory 7, the user can use the electronic data management system 1 just by carrying the USB memory 7. Also, the USB memory 7 can be backed up and replicated for use. By replicating the USB memory 7, multiple users can simultaneously use the fragmented files 10m (secret sharing files) of the same content.

[0210] Of course, at this time, it is necessary to be able to access the network storage 3 and for each user to have access rights thereto. By replicating the USB memory 7 and passing it to other users, the receiving user can access the USB memory 7 and the network storage 3 and use the secretly shared user data. Also, when the user is using user data on the user terminal 2 and wants to use it at another location or on another terminal, if the user can access the network storage 3 by simply bringing the USB memory 7, the user data can be used.

[0211] When storage media such as the USB memory 7 and the user terminal 2 that store fragmented files are lost (including stolen, lost, cracked, etc.), meaningful information cannot be obtained from only the fragmented files therein. However, if necessary, the original file 10 can be restored from two other fragmented files that are paired with the lost fragmented file, the fragmented file can be generated again, and saved to an appropriate non-volatile storage medium.

[0212] When the saving of the newly generated fragmented file is completed, the fragmented file paired with the lost fragmented file is deleted. This process can be performed according to instructions from the user, administrator, etc., but can also be automatically confirmed and performed by the management program (driverware 60). In particular, it is possible to determine whether to regenerate the fragmented file depending on cases such as when the USB memory 7 storing the fragmented file has not been used for a predetermined period.

[0213] [Third Embodiment] The third embodiment of the present invention will be described. The third embodiment of the present invention is basically the same as the first and second embodiments of the present invention, and only the different parts will be described. As shown in FIG. 15, the user terminal 2 includes an online storage service program 80 for an online storage service. This online storage service is a service that provides a place for storing files on a network such as the Internet.

[0214] The above-described network storage can be used as a place for storing files provided by the online storage service. Representative online storage services include "OneDrive" (registered trademark) of Microsoft Corporation (USA), "Google Drive" (registered trademark) of Google Inc., "iCloud" (registered trademark) of Apple Inc., "Amazon Drive" (registered trademark) of Amazon.com, Inc., and the like. The online storage service program 80 is an application program installed in the user terminal 2 to provide such an online storage service.

[0215] The online storage service program 80 is a dedicated API for the online storage service. In addition, the online storage service program 80 includes a dedicated API that has become one of the standard functions (services) of the operating system 30, such as "OneDrive". As long as there is an environment where the Internet can be accessed, the online storage service can store and manage data in one place even on mobile terminals such as a remote location or multiple personal computers and smartphones.

[0216] In addition, by assigning a "key" (such as an ID, password, or authority), data can be shared with or downloaded by others, and its use in business is increasing. Online storage services basically provide an interface (I / F) in user mode 32. The online storage service program 80 operates in user mode 31 of the operating system 30. In this embodiment, the network storage 3 will be described as being storage on the cloud of an online storage service.

[0217] The online storage service program 80 transmits and stores user data in the network storage 3. When user data is requested from an application program 33 or the like, the online storage service program 80 downloads and delivers it from the network storage 3. As described above, the cloud communication unit 34 is attached to the management program and operates in cooperation with the driverware 60, and is a dedicated application program or module for communicating with the network storage 3.

[0218] In this embodiment, the cloud communication unit 34 operates in cooperation with the driverware 60 and transmits and receives (transfers) files between the network distributed folder 12n and the network storage 3 via the online storage service program 80. The online storage service program 80 transmits to the network storage 3 via the driverware 60, the network driver 54, and the network card 41. Conversely, the online storage service program 80 acquires user data from the network storage 3 via the network card 41, the network driver 54, and the driverware 60.

[0219] The user data acquired by the online storage service program 80 is acquired by the cloud communication unit 34 and stored in the network distributed folder 12n via the driver ware 60 and the file system driver 51. In order to access the network storage 3 provided by the online storage service in this way, the interface of the online storage service program 80 operating in the user mode 32 is accessed by the cloud communication unit 34.

[0220] In order to obtain the access right to the network storage 3, the account (ID and password) of the online storage service is required and is performed via the online storage service program 80. When the access to the online storage service is authenticated, the necessary access is controlled by the cloud communication unit 34 and the driver ware 60. In the present embodiment, the network storage 3 of the online storage service is accessed by the online storage service program 80, and this access is controlled by the cloud communication unit 34. Other operations are the same as those in the above-described first and second embodiments.

[0221] [Fourth Embodiment] The fourth embodiment of the present invention will be described. The fourth embodiment of the present invention is basically the same as the first and second embodiments of the present invention, and only the different parts will be described. As illustrated in FIG. 16, the user terminal 2 includes a secret sharing unit 90 that operates in the user mode 32. The secret sharing unit 90 includes a sharing unit 91 for sharing a file secretly to generate a plurality of fragmented files, and a restoring unit 92 for restoring the original file from the plurality of fragmented files.

[0222] The secret sharing unit 90 is an application program that operates in the user mode 32. The secret sharing unit 90 receives a file from another application program 33 or the like, secretly shares it, and returns the fragmented files. Or, it receives a plurality of fragmented files, performs a restoration process on them, restores the original file, and returns it.

[0223] In the present embodiment, the secret sharing unit 90 is called and operated from the driver software 60. The secret sharing unit 90 is controlled by the application platform program 35, receives a file, and outputs a processing result. When there is a file that needs to be secretly shared or a fragment file that needs to be restored, the driver software 60 instructs from the control unit 61 and passes the file information of the file such as the file name and folder name, or the file information of the fragment file such as the file name and folder name of the fragment file to the secret sharing unit 90 via the interface unit 70 and the application platform program 35. The result is received via the application platform program 35 and the interface unit 70.

[0224] FIG. 17 is a flowchart showing an operation example of the user terminal 2 in the fourth embodiment. First, the user terminal 2 operates, the driver software 60 is started, and initial settings are performed (steps 20201 to 203). The RAM disk 11 is created, and settings such as formatting are performed (step 204). Next, in the RAM disk 11, a work folder 16, a network distributed folder 12n, a mobile distributed folder 12m, and a local distributed folder 12h are created (step 205).

[0225] Connection processing with each storage device is performed so that the distributed folder 12 corresponds to the network storage 3, the mobile terminal 6, the auxiliary storage device 14, etc. (steps 206 to 208). The application program 33 operates on the user terminal 2 and operates according to the requests or instructions of the user, other application programs, or the services of the operating system 30. The application program 33 issues a request to select and read an appropriate folder and an appropriate file stored in the auxiliary storage device 14 (step 209).

[0226] The driver software 60 receives a request from the application program 33. The driver software 60 reads out the corresponding fragmented files from the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h for the requested file (step 210). The read fragmented files are transmitted to the secret sharing unit 90 via the interface unit 70 and the application platform program 35 according to the instruction of the control unit 61 (step 211).

[0227] The secret sharing unit 90 receives the fragmented files, processes them by the restoration unit 92, and restores the original file (step 212). Then, the secret sharing unit 90 returns the restored original file to the application platform program 35. The original file is stored in the working folder 16 of the RAM disk 11 via the interface unit 70, the file system control unit 72, the file system driver 51, and the RAM disk driver 53 according to the instruction of the control unit 61 (step 213).

[0228] Then, the control unit 61 reads out the file 10 from the working folder 16 and passes it to the application program 33 via the interface unit 70 (step 214). The application program 33 receives this and starts using the file 10 (step 215). If the requested fragmented files 10n, 10m, 10h are not in the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h, the driver software 60 obtains them from each storage device of the network storage 3, the mobile terminal 6, and the auxiliary storage device 14 and stores them in the network distributed folder 12n, the mobile distributed folder 12m, and the local distributed folder 12h.

[0229] Then, the driver software 60 acquires this and transmits it to the secret sharing unit 90 for the above-mentioned restoration process. The application program 33 uses the file 10 to perform operations such as browsing and editing, and issues a request to save this (step 216). The save destination of the request issued by the application program 33 is the auxiliary storage device 14. The driver software 60 detects the save request issued by the application program 33, redirects this save operation, and saves the file 10 in the working folder 16 (step 217).

[0230] When the file 10 is saved, the driver software 60 detects the end of the save operation and starts the process of secretly sharing the working file 10. At this time, the control unit 61 reads the working file 10 and passes it to the secret sharing unit 90 via the interface unit 70 and the application platform program 35 (step 218). When the secret sharing unit 90 receives the working file 10, it secretly shares this by the sharing unit 91 to generate a plurality of fragment files (step 219). The generated plurality of fragment files are passed to the application platform program 35.

[0231] The control unit 61 stores the fragment files in the distributed folder 12 on the RAM disk 11 (step 220). When the storage of the fragment files is completed, the driver software 60 transfers the fragment files to each storage device 3, 6, and 14 (step 221). When the fragment files are transferred, the fragment files in the distributed folder 12 may be deleted, or may remain stored until the end of the use of the working file 10. If the application program 33 continues to use the working file 10, the operations of the above steps 215 to 221 are repeated (step 222 → step 215).

[0232] When the application program 33 ends, or when the application program 33 closes the working file 10 and terminates the use of the working file 10, the working file 10 is secretly distributed and the fragment file is transferred (step 222 → step 223). Then, if the transfer is successful, the working file 10 and the fragment file are deleted (step 224). Then, the process proceeds to the next operation (step 225).

Explanation of Signs

[0233] 1 Electronic data management system 2,2a User terminal 3 Network storage 4 Network 5 Portable storage means 6 Portable terminal 7 Non-volatile storage means 8 Communication mediation means 9 USB memory 10 File 11 RAM disk 12 Distributed folder 12n Network distributed folder 12m Mobile distributed folder 12h Local distributed folder 13 Network folder 14 Auxiliary storage device 15 Local folder 16 Working folder 17 Keyboard 18 Mouse 20 Main body 21 Central processing unit (CPU) 22 Main memory device 23 Input interface 24 Output interface 25 Bus 26 Input device 27 Output device 28 Power supply unit 30 Operating system 31 Kernel mode 32 User mode 33 Application Program 34 Cloud Communication Unit 35 Application Platform Program 40 Device 41 Network Card 42 Communication Adapter 43 Keyboard Port 44 Mouse Port 50 Device Driver 51 File System Driver 52 RAM Disk Driver 53 Disk Driver 54 Network Driver 55 Communication Driver 56 Keyboard Driver 57 Mouse Driver 60 Driverware 61 Control Unit 62 Distributed Information Generation Unit 63 Restoration Unit 64 Encryption Unit 65 Decryption Unit 66 Log Acquisition Unit 67 Device Driver Control Unit 70 Interface Unit 71 Network Control Unit 72 File System Control Unit 73 Communication Control Unit 74 Input Control Unit 80 Online Storage Service Program 90 Secret Sharing Unit 91 Distribution Unit 92 Restoration Unit

Claims

1. An electronic data management device that operates in kernel mode where all instructions of an operating system can be executed, and that has a common interface means for providing a common interface for communication between device drivers that directly control devices connected to the following electronic computer, or for communication between the device driver and an application program. The electronic data management device is connected to a network and has an electronic data leakage prevention function for preventing and controlling leakage of user data from the electronic computer to the outside. In the device: Dispersion means for secretly dispersing a file and generating n fragments; Restoration means for synthesizing the n fragments and restoring the original file; Drive creation means that operates in the kernel mode to create volatile storage means in the electronic computer; Fragment file generation means for secretly dispersing a working file by the dispersion means to generate the n fragment files and storing them in the volatile storage means; First transfer means for transferring the n fragment files stored in the volatile storage means to a plurality of non-volatile storage means in the kernel mode and storing them for secret dispersion; Second transfer means for transferring the n fragment files stored in the plurality of non-volatile storage means to the volatile storage means in the kernel mode for restoration of the file, and Working file restoration means for acquiring the n fragment files stored in the volatile storage means by the second transfer means, generating the original working file by the restoration means, and storing it in the volatile storage means; Deletion means for deleting one or more of the working file, the volatile storage means, the working drive, and the working folder when the transfer of the n fragment files by the first transfer means is completed and the application program ends; Among the n fragment files, those that cannot be transferred to the non-volatile storage means are encrypted and transferred and stored in the non-volatile storage means built in or connected to the electronic computer. An electronic data management device characterized by the above.

2. In the electronic data management device according to Claim 1, The dispersion means and the restoration means operate in the kernel mode, The fragment file generation means acquires the working file in the kernel mode, passes it to the dispersion means in the kernel mode, and secretly disperses it. The working file restoration means acquires the n fragment files in the kernel mode and passes them to the restoration means in the kernel mode to restore the working file. An electronic data management device characterized by the above.

3. In the electronic data management device according to claim 1, the dispersion means and the restoration means operate in a user mode in which the execution of some instructions is restricted, the fragment file generation means acquires the working file in the kernel mode, passes it to the dispersion means in the user mode to perform secret dispersion, the working file restoration means acquires the n fragment files in the kernel mode and passes them to the restoration means in the user mode to restore the working file. An electronic data management device characterized by the above.

4. In the electronic data management device according to claim 1, the first transfer means acquires the n fragment files stored in the volatile storage means in the kernel mode and transfers them to the plurality of non-volatile storage means in a user mode in which the execution of some instructions is restricted, the second transfer means acquires the n fragment files stored in the plurality of non-volatile storage means in the user mode, transfers the n fragment files in the kernel mode, and stores them in the volatile storage means. An electronic data management device characterized by the above.

5. In the electronic data management device according to any one of claims 1 to 4, each of the working file and the n fragment files is stored in a working drive or a working folder having the same directory structure. An electronic data management device characterized by the above.

6. In the electronic data management device according to claim 1, when the electronic computer is started, the fragment files for which the transfer has not been completed are transmitted to the volatile storage means. An electronic data management device characterized by the above.

7. In the electronic data management device according to any one of claims 1 to 4, when the electronic computer is started, it is confirmed whether or not the fragment files obtained by secretly dispersing the working file are stored in all the volatile storage means corresponding thereto. If they are not stored in all the volatile storage means, the working file is restored from the readable fragment files, and then the newly restored working file is secretly dispersed to create a plurality of fragment files, which are transferred to the volatile storage means. An electronic data management device characterized by the following.

8. In the electronic data management device according to one item selected from Claims 1 to 4, the volatile storage means is encrypted An electronic data management device characterized by the following.

9. In the electronic data management device according to one item selected from Claims 1 to 4, the non-volatile storage means is encrypted An electronic data management device characterized by the following.

10. In the electronic data management device according to one item selected from Claims 1 to 4, the non-volatile storage means is two or more selected from network storage, cloud folders for online storage services, built-in auxiliary storage means, external auxiliary storage means, network drives, USB devices, USB media, portable devices, synchronization drives, and virtual drives An electronic data management device characterized by the following.

11. A network, network storage connected to the network for storing user data, a computer connected to the network, Common interface means for providing a common interface for communication between device drivers that operate in kernel mode where all instructions of the operating system can be executed and directly control devices connected to the computer, or for communication between the device driver and an application program, In an electronic data management system having an electronic data leakage prevention function for preventing control of leakage of the user data from the computer to the outside, Dispersion means for secretly dispersing a file to generate n fragments, Restoration means for synthesizing the n fragments to restore the original file, Drive creation means that operates in the kernel mode to create volatile storage means in the computer, Fragment file generation means for secretly dispersing a working file by the dispersion means to generate the n fragment files and storing them in the volatile storage means, First transfer means for transferring and storing the n fragment files stored in the volatile storage means to a plurality of non-volatile storage means including the network storage in the kernel mode for secret dispersion, Second transfer means for transferring and storing the n fragment files stored in the plurality of non-volatile storage means to the volatile storage means in the kernel mode for restoration of the file, and The working file restoration means includes acquiring the n fragment files stored in the volatile memory means by the second transfer means, causing the restoration means to generate the original working file, and storing the generated file in the volatile memory means. When the transfer of the n fragment files by the first transfer means is completed and the application program ends, there is deletion means for deleting one or more of the working file, the volatile memory means, the working drive, and the working folder. Among the n fragment files, the fragment files that cannot be transferred to the non-volatile memory means are encrypted and transferred and stored in the non-volatile memory means built in or connected to the electronic computer. An electronic data management system characterized by the above.

12. In the electronic data management system according to claim 11, the dispersion means and the restoration means operate in the kernel mode, the fragment file generation means acquires the working file in the kernel mode, passes it to the dispersion means in the kernel mode, and performs the secret dispersion, the working file restoration means acquires the n fragment files in the kernel mode, passes them to the restoration means in the kernel mode, and restores the working file. An electronic data management system characterized by the above.

13. In the electronic data management system according to claim 11, the dispersion means and the restoration means operate in a user mode in which the execution of some instructions is restricted, the fragment file generation means acquires the working file in the kernel mode, passes it to the dispersion means in the user mode, and performs the secret dispersion, the working file restoration means acquires the n fragment files in the kernel mode, passes them to the restoration means in the user mode, and restores the working file. An electronic data management system characterized by the above.

14. In the electronic data management system according to claim 11, the first transfer means acquires the n fragment files stored in the volatile memory means in the kernel mode, and transfers them to the plurality of non-volatile memory means in a user mode in which the execution of some instructions is restricted, the second transfer means acquires the n fragment files stored in the plurality of non-volatile memory means in the user mode, and transfers the n fragment files in the kernel mode and stores them in the volatile memory means. An electronic data management system characterized by the following.

15. In the electronic data management system according to one of claims 11 to 14, each of the working file and the n fragment files is stored in a working drive or a working folder having the same directory structure An electronic data management system characterized by the following.

16. In the electronic data management system according to claim 11, when the electronic computer is started, the fragment files for which the transfer is not completed are transmitted to the volatile storage means An electronic data management system characterized by the following.

17. In the electronic data management system according to one of claims 11 to 14, when the electronic computer is started, it is confirmed whether or not the fragment files obtained by secret sharing of the working file are stored in all the corresponding volatile storage means. If they are not stored in all the volatile storage means, the working file is restored from the readable fragment files, and then the newly restored working file is secretly shared to create a plurality of fragment files, which are transferred to the volatile storage means An electronic data management system characterized by the following.

18. In the electronic data management system according to one of claims 11 to 14, the volatile storage means is encrypted An electronic data management system characterized by the following.

19. In the electronic data management system according to one of claims 11 to 14, the non-volatile storage means is encrypted An electronic data management system characterized by the following.

20. In the electronic data management system according to one of claims 11 to 14, the non-volatile storage means is two or more selected from network storage, cloud folder for online storage service, built-in auxiliary storage means, external auxiliary storage means, network drive, USB device, USB medium, portable device, synchronization drive, and virtual drive An electronic data management system characterized by the following.

21. An electronic data management device, which is a network - connectable electronic computer equipped with common interface means for providing a common interface for communication between device drivers that operate in kernel mode capable of executing all instructions of an operating system and directly controlling devices connected to the following electronic computer, or for communication between the device drivers and application programs, and has an electronic data leakage prevention function for preventing and controlling the leakage of user data from the electronic computer to the outside. A drive creation step of creating a volatile storage means in the electronic computer by drive creation means operating in the kernel mode, and creating a plurality of distributed folders in the created volatile storage means. A fragment file generation step of secretly distributing a working file stored in the volatile storage means by distribution means, generating n fragment files, and storing them in the volatile storage means. A first transfer step of transferring and storing the n fragment files stored in the volatile storage means to a plurality of non - volatile storage means in the kernel mode for secret distribution. A second transfer step of transferring and storing the n fragment files stored in the plurality of non - volatile storage means to the volatile storage means in the kernel mode for file restoration, and A working file restoration step of obtaining the n fragment files stored in the volatile storage means by the second transfer step, generating the original working file by restoration means, and storing it in the volatile storage means. The first transfer step has a deletion step of deleting one or more of the working file, the volatile storage means, the working drive, and the working folder when the transfer of the n fragment files is completed and the application program ends. A step of encrypting the fragment files among the n fragment files that cannot be transferred to the non - volatile storage means and transferring and storing them in the non - volatile storage means built - in or connected to the electronic computer. Characterized by comprising the above steps, a program for an electronic data management device.

22. In the program for an electronic data management device according to Claim 21, The distribution means and the restoration means operate in the kernel mode. The fragment file generation step includes the step of obtaining the working file in the kernel mode and the step of passing the obtained working file to the dispersion means in the kernel mode. The working file restoration step includes the step of obtaining the n fragment files in the kernel mode and the step of passing the obtained fragment files to the restoration means in the kernel mode. A program for an electronic data management device, characterized by the above.

23. In the program for an electronic data management device according to claim 21, the dispersion means and the restoration means operate in user mode with the execution of some instructions restricted. The fragment file generation step includes the step of obtaining the working file in the kernel mode and the step of passing the obtained working file to the dispersion means. The working file restoration step includes the step of obtaining the n fragment files in the kernel mode and the step of passing the obtained fragment files to the restoration means. A program for an electronic data management device, characterized by the above.

24. In the program for an electronic data management device according to claim 21, the first transfer step includes the step of obtaining the n fragment files stored in the volatile storage means in the kernel mode and the step of transferring the obtained n fragment files to the plurality of non-volatile storage means in user mode with the execution of some instructions restricted. The second transfer step includes the step of obtaining the n fragment files stored in the plurality of non-volatile storage means in user mode and the step of transferring the obtained n fragment files in the kernel mode and storing them in the volatile storage means. A program for an electronic data management device, characterized by the above.

25. In the program for an electronic data management device according to any one of claims 21 to 24, each of the working file and the n fragment files is stored in a working drive or a working folder having the same directory structure. A program for an electronic data management device, characterized by the above.

26. In the program for an electronic data management device according to any one of claims 21 to 24, The first transfer step includes a deletion step of deleting one or more of the working file, the volatile storage means, the working drive, and the working folder when the transfer of the n fragmented files is completed and the application program ends. A program for an electronic data management device, characterized by the above.

27. In the program for an electronic data management device according to claim 21, When the electronic computer is started, a step of transmitting the fragmented files whose transfer is not completed to the volatile storage means A program for an electronic data management device, characterized by comprising the above.

28. In the program for an electronic data management device according to any one of claims 21 to 24, When the electronic computer is started, a step of checking whether the fragmented files obtained by secret sharing of the working file are stored in all the volatile storage means; When all the fragmented files are not stored in all the volatile storage means, a step of restoring the working file from the readable fragmented files; A step of secret-sharing the working file to create a plurality of fragmented files; A program for an electronic data management device, characterized by comprising a step of transferring the created plurality of fragmented files to the volatile storage means.

29. In the program for an electronic data management device according to any one of claims 21 to 24, A step of encrypting the volatile storage means A program for an electronic data management device, characterized by comprising the above.

30. In the program for an electronic data management device according to any one of claims 21 to 24, A step of encrypting the non-volatile storage means A program for an electronic data management device, characterized by comprising the above.

31. In the program for an electronic data management device according to any one of claims 21 to 24, The non-volatile storage means is two or more selected from network storage, cloud folders for online storage services, built-in auxiliary storage means, external auxiliary storage means, network drives, USB devices, USB media, portable devices, synchronization drives, and virtual drives. A program for an electronic data management device, characterized by the above.

32. A recording medium for an electronic data management device program that records the program for an electronic data management device according to one item selected from claims 21 to 24.

Citation Information

Patent Citations

  • Authentication system

    JP2007241371A

  • Data processing control method, information processor and data processing control system

    JP2011008813A

  • Data management device, data management method and data management program

    JP2017010424A

  • Computer program, secret management method, and system

    JP2017126314A

  • Electronic data management device, electronic data management system, program therefor, and recording medium

    WO2020144961A1