Information processing apparatus, information processing method, and information processing program

The information processing apparatus optimizes zero-knowledge proof verification in blockchain transactions by limiting hash value calculations and avoiding direct proof association, ensuring rapid and secure service provision with maintained anonymity.

JP7711714B2Active Publication Date: 2025-07-23SONY GROUP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2022561813
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-11-10
Filing Date
2021-10-28
Publication Date
2025-07-23
Estimated Expiration
2041-10-28

AI Technical Summary

Technical Problem

Anonymizing transaction information in a blockchain using zero-knowledge proof is challenging due to the time-consuming computation required, which hinders quick service provision, especially in face-to-face transactions.

Method used

An information processing apparatus and method that utilizes a first recording unit to record viewing authority information in a blockchain, a verification unit to verify zero-knowledge proofs, and a second recording unit to record verification results, optimizing the proof verification process by limiting hash value calculations to once and avoiding direct association of proof information with viewing authority records.

Benefits of technology

Enables rapid service provision while maintaining anonymity, enhancing system availability and security by reducing computation time and preventing proof reuse.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007711714000001
    Figure 0007711714000001
  • Figure 0007711714000002
    Figure 0007711714000002
  • Figure 0007711714000003
    Figure 0007711714000003
Patent Text Reader

Abstract

This information processing device (30) comprises a first recording unit (331), a verification unit (332), and a second recording unit (333). The first recording unit (331), in response to a request from an information management device (20) that manages data, records information about browsing permission for the data onto blockchain. The verification unit (332), on the basis of the information about the browsing permission written onto the blockchain, verifies a proof of a zero-knowledge proof for authenticating a valid user to whom the browsing permission has been applied. The second recording unit (333) records information about the proof verification result onto the blockchain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information processing apparatus, an information processing method, and an information processing program.

Background Art

[0002] A distributed ledger system, also referred to as a blockchain system, is used for managing various transaction information exchanged through a network. For example, Patent Document 1 proposes a technique in which an auditing apparatus executes auditing and tracing of virtual currency transaction information (such as a remitter, a recipient, and an amount) described on a distributed ledger.

[0003] Also, in the above-described technique, in order to anonymize transaction information, a transaction (transaction information) with a zero-knowledge proof is used. For example, "zk-snarks" and the like are known as techniques based on zero-knowledge proofs.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, when anonymizing transaction information recorded in a blockchain by means of a zero-knowledge proof, there is a problem that it is difficult to provide a service quickly. This is due to the fact that it takes a fair amount of time until the processing of the zero-knowledge proof is completed.

[0006] Therefore, the present disclosure proposes an information processing apparatus, an information processing method, and an information processing program that can realize quick service provision while ensuring anonymity.

Means for Solving the Problems

[0007] To solve the above problems, an information processing apparatus according to one aspect of the present disclosure includes a first recording unit, a verification unit, and a second recording unit. The first recording unit records information regarding the viewing authority of data in a blockchain in response to a request from an information management apparatus that manages the data. The verification unit verifies a proof of zero-knowledge proof for proving that the user is a legitimate user granted the viewing authority based on the information regarding the viewing authority written in the blockchain. The second recording unit records information regarding the verification result of the proof in the blockchain.

Brief Description of Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Embodiments for Carrying Out the Invention

[0009] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In the following embodiments, the same parts may be denoted by the same numbers or symbols to omit redundant explanations. Also, in this specification and the drawings, a plurality of components having substantially the same functional configuration may be distinguished by attaching different numbers or symbols after the same number or symbol.

[0010] Also, the present disclosure will be described in accordance with the following item order. 1. Introduction 2. System Configuration Example 3. Overview of Information Processing 4. Device Configuration Example 5. Processing Procedure Example 6. Variation Example 7. Others 8. Hardware Configuration Example 9. Conclusion

[0011] <<1. Introduction>> <1-1. Background> A blockchain (decentralized ledger system) has the property that it can track the history of transaction information such as virtual currency (transaction history) through blockchain addresses uniquely assigned to each piece of data recorded in the blockchain. On the other hand, it is not practical to erase the transaction history recorded in the blockchain, and there are privacy issues.

[0012] In view of this privacy issue, it is also conceivable to completely anonymize the transaction information recorded on the blockchain by encrypting it. However, if the transaction information is completely anonymized, the legitimacy of the transaction history cannot be verified, and the security of the distributed ledger will be compromised. Therefore, zero-knowledge proof (ZKP) has attracted attention as a method that ensures privacy without sacrificing the verifiability of the distributed ledger.

[0013] Zero-knowledge proof is a protocol for convincing that something is correct (the proposition is true). By using zero-knowledge proof, it is possible to prove that one knows something without disclosing the information that one does not want to be known. Therefore, by recording the transaction history using zero-knowledge proof on the blockchain, it is possible to ensure privacy without sacrificing the verifiability of the distributed ledger.

[0014] <1-2. Existing Technology> Hereinafter, as an example of a technology for realizing zero-knowledge proof used for anonymizing transaction information such as virtual currency, the "Merkle Tree" used in "zk-snarks" will be described.

[0015] In virtual currency transactions, the anonymity to be ensured includes "anonimity" and "unlikability". "Anonimity" means that it is unknown which user is conducting a particular transaction. "Unlikability" means that it is impossible to determine whether the same user is involved in two transactions. In virtual currency transactions, by satisfying the above two types of anonymity, it is possible to conduct financial transactions while keeping secret "who transacted with whom, when, and for how much".

[0016] In order to satisfy the above two types of anonymity in a distributed ledger, it is necessary not to write information identifying users in the transaction history on the blockchain and to make it impossible to determine which record was accessed using whose access rights.

[0017] The "Merkle Tree" can indicate that there is a record of one's own authority among all transaction histories without identifying one's own record. Therefore, by creating a zero-knowledge proof using the "Merkle Tree", the above two anonymities are satisfied. FIG. 12 is a diagram showing an overview of the zero-knowledge proof using the "Merkle Tree".

[0018] "H(Y0)" to "H(Y3)" in FIG. 12 indicate the hash values written to the blockchain. "a" 0,0 ", "a" 0,1 ", "A0", "A1", "auth0", "auth1", "R0" respectively indicate the nodes constituting the tree structure of the "Merkle Tree".

[0019] By using the "Merkle Tree", the proposition of the zero-knowledge proof can be whether the value of the node "R0", which is the root of the tree structure created using all the hash values "H(Y0)" to "H(Y3)", is correctly calculated. For example, let "auth0" and "auth1" be the secret information (values) exchanged between the verifier and the prover. As a result, only those who can know the secret information (value) can correctly calculate the value of the node "R0", which is the root of the tree structure. In this way, it is possible to prove that one's own hash value is included in the blockchain without disclosing the information for identifying one's own hash value recorded in the blockchain.

[0020] As described above, zero-knowledge proof using a "Merkle Tree" realizes high anonymity, but the amount of computation for zero-knowledge proof is large, and it may take time to verify a proposition. For example, when creating a tree structure as illustrated in FIG. 12, the larger the number of levels until reaching the root node, the greater the amount of computation. Therefore, when anonymizing transaction information recorded in a blockchain by zero-knowledge proof, there is a problem that it is difficult to provide a service quickly. This problem is particularly problematic in services that conduct face-to-face transactions, for example. Therefore, the present disclosure proposes an information processing apparatus, an information processing method, and an information processing program that can realize quick service provision while ensuring anonymity.

[0021] <<2. System configuration example>> Hereinafter, a configuration example of an information processing system according to an embodiment of the present disclosure will be described. FIG. 1 is a schematic diagram showing a system configuration example according to an embodiment of the present disclosure. As shown in FIG. 1, the information processing system 1 according to an embodiment of the present disclosure includes a user terminal 10, a service providing apparatus 20, a BC client apparatus 30, a BC system 40, and a data user apparatus 50. The configuration of the information processing system 1 does not necessarily have to be particularly limited to the example shown in FIG. 1, and may include more user terminals 10, service providing apparatuses 20, BC client apparatuses 30, BC systems 40, and data user apparatuses 50 than those shown in FIG. 1.

[0022] The user terminal 10, the service providing apparatus 20, the BC client apparatus 30, the BC system 40, and the data user apparatus 50 are connected to the network N by wire or wirelessly. The network N includes a LAN (Local Area Network), a WAN (Wide Area Network), a telephone network (such as a mobile phone network and a fixed telephone network), a regional IP (Internet Protocol) network, the Internet, and the like.

[0023] In addition, the user terminal 10 and the service providing device 20 can communicate with each other via the network N. Also, the service providing device 20 and the BC client device 30 can communicate with each other via the network N. Also, the service providing device 20 and the data user device 50 can communicate with each other via the network N. Also, the BC client device 30 and the BC system 40 can communicate with each other via the network N.

[0024] The user terminal 10 is, for example, an information processing device used by a user who deposits personal information with the service providing device 20. The user terminal 10 can be realized by a smartphone, a tablet terminal, a notebook PC (Personal Computer), a desktop PC, a mobile phone, a PDA (Personal Digital Assistant), or the like.

[0025] The service providing device 20 (an example of an information management device) is an information processing device that manages personal information uploaded by the user of the user terminal 10 using the user terminal 10. Also, the service providing device 20 grants, for example, a viewing right to personal information to the user of the data user device 50 who is the data requester of the personal information. Also, the service providing device 20 receives a zero-knowledge proof from the user of the data user device 50 who is the data requester of the personal information, and provides the personal information based on the verification result of the received proof. The service providing device 20 can be realized by a server or the like.

[0026] The BC client device 30 is an information processing device that records data with respect to the BC system 40 in response to a request from the service providing device 20. The BC client device 30 may be physically or functionally integrated with the BC system 40 described later. Also, the BC client device 30 may be distributed from the BC system 40. The BC client device 30 can be realized by a server or the like. The processing of the BC client device 30 will be described later.

[0027] The BC system 40 is an information processing device that manages, as a blockchain, each block that aggregates data such as information regarding the viewing authority of personal information and information regarding the verification result of proof accompanying a request for personal information, arranged in the order of processing. The BC system 40 is configured by, for example, a plurality of information processing devices (nodes) that execute various processes such as block generation and blockchain sharing. Each node of the BC system 40 includes, for example, a communication unit realized by a NIC (Network Interface Card), a communication circuit, etc., and is connected to the network N by wire or wirelessly. The BC system 40 assumes a permission type blockchain that can be used by the service providing device 20 and the data user device 50, but any configuration may be used as long as the processes according to the embodiments of the present disclosure can be realized.

[0028] The data user device 50 is an information processing device used by a user who acquires personal information managed by the service providing device 20. The data user device 50 can be realized by a smartphone, a tablet terminal, a notebook PC, a desktop PC, a mobile phone, a PDA, etc. The data user device 50 generates a proof of zero-knowledge proof to prove that it is a legitimate user granted the viewing authority of personal information from the service providing device 20. The data user device 50 transmits a data request for personal information to the service providing device 20 together with the generated proof, and thereby acquires the desired personal information from the service providing device 20.

[0029] <<3. Outline of Information Processing>> <3-1. Example of Information Processing> Hereinafter, an example of information processing by the information processing system according to the embodiment of the present disclosure will be described. FIG. 2 is a schematic diagram showing an example of information processing according to the embodiment of the present disclosure.

[0030] As shown in FIG. 2, the user terminal 10 transmits personal information to the service providing device 20 (step S11). The service providing device 20 manages the personal information received from the user terminal 10 in a local environment (step 12).

[0031] The data user device 50 sends a request to the service providing device 20 to obtain the viewing right for viewing personal information (step S13). When the service providing device 20 receives the request for obtaining the viewing right from the data user device 50, it sends a recording request for the viewing right to the BC client device 30 (step S14).

[0032] The BC client device 30 records information regarding the viewing right in the BC system 40 in response to the request from the service providing device 20 (step S15). Here, the information regarding the viewing right recorded by the BC client device 30 in the BC system 40 is information indicating that the viewing of personal information by the user of the data user device 50 is permitted, and it can be composed of an arbitrary character string or the like. Also, the BC client device 30 can record in the BC system 40 not the information regarding the viewing right as it is, but the hash value obtained by hashing the information regarding the viewing right.

[0033] After the BC client device 30 records the viewing right, the service providing device 20 grants the viewing right to the data user device 50 (step S16). The service providing device 20 provides the data user device 50 with the secret value (such as a random number) incorporated when hashing the viewing right, together with the information regarding the viewing right. The secret value may be a nonce.

[0034] When the data user device 50 is granted the viewing right by the service providing device 20, it generates a zero-knowledge proof to prove that it is a legitimate user granted the viewing right of personal information (step S17). As the proof created by the data user device 50, evidence that can produce the same hash value as the hash value recorded by the BC client device 30 in the BC system 40 in response to a request from the service providing device 20 is assumed. For example, the data user device 50 may present the hash value itself generated using the secret value granted by the service providing device 20 as the proof to the service providing device 20. Then, the data user device 50 transmits a data request for personal information to the service providing device 20 together with the generated proof (step S18).

[0035] When the service providing device 20 receives a data request from the data user device 50, it transmits a proof confirmation request to the BC client device 30 (step S19). The BC client device 30 executes proof verification in response to the proof confirmation request received from the service providing device 20 (step S20). Specifically, the BC client device 30 compares the hash value of the information regarding the viewing record recorded in the BC system 40 with the hash value based on the proof obtained from the service providing device 20 to determine whether they match.

[0036] The BC client device 30 records the proof verification result in the BC system 40 as a usage history (step S21). Specifically, the BC client device 30 records information regarding the proof verification result indicating whether the proof obtained from the data user device 50 is legitimate in the BC system 40. At this time, when verifying the proof, the BC client device 30 records the usage history excluding the record position of the viewing right so that the record position of the viewing right information recorded in the BC system 40 is not associated with the proof generated in the data user device 50. Also, the BC client device 30 transmits the proof verification result to the service providing device 20 as a determination result (step S22).

[0037] Based on the verification result of the proof received from the BC client device 30, the service providing device 20 provides the personal information corresponding to the data request (see step S18) received from the data user device 50 to the data user device 50 (step S23).

[0038] As described above, the BC client device 30 verifies the proof by comparing the information (hash value) regarding the viewing authority recorded in the BC system 40 in advance with the hash value based on the proof generated in the data user device 50. In the zero-knowledge proof using "Merkle Tree", it is necessary to acquire all the data required for calculating the hash value from the block data recorded in the blockchain and repeatedly calculate the hash value until reaching the root node using the acquired data. However, in the zero-knowledge proof in the embodiment of the present disclosure, the calculation of the hash value only needs to be performed once in the data user device 50, and it only needs to compare the generated hash value with the recorded hash value. Thereby, rapid service provision (provision of personal information) becomes possible.

[0039] Also, when recording the verification result in the BC system 40, the BC client device 30 does not record the information (hash value) regarding the viewing authority on the BC system 40 used during the verification of the proof and the information associating the proof generated in the data user device 50. Thereby, in the BC system 40 (blockchain), anonymity equivalent to that of "Merkle Tree" can be realized. From such a fact, according to the embodiment of the present disclosure, it is possible to realize rapid service provision while ensuring anonymity.

[0040] <3-2. Service Example> An example of the service form realized by the information processing system according to the embodiment of the present disclosure will be described with reference to FIGS. 3 and 4. FIGS. 3 and 4 are schematic diagrams showing the outline of the service form according to the embodiment of the present disclosure.

[0041] Figure 3 shows the service form provided by medical service α to doctors, medical institutions, etc. (data users) regarding the biometric information and medical data of the users it manages. The users shown in Figure 3 correspond to the users of the user terminal 10 shown in Figures 1 and 2. The medical service α shown in Figure 3 corresponds to the service providing device 20 shown in Figures 1 and 2. The blockchain shown in Figure 3 corresponds to the BC client device 30 and BC system 40 shown in Figures 1 and 2. The data users shown in Figure 3 correspond to the users of the data user device 50 shown in Figures 1 and 2.

[0042] The user uploads and pre-registers biometric information (vital signs) that can be measured by a predetermined measuring device such as an electrocardiogram, heart rate, blood pressure, body temperature, etc., and medical data such as medical records and health diagnosis results in medical institutions to medical service α.

[0043] Medical service α registers and manages the biometric information and medical data uploaded by the user as personal information. When registering biometric information and medical data, medical service α asks whether the user agrees to provide the data to doctors and medical institutions. Medical service α may permit the registration of personal information on the condition that the user agrees to provide the data. Medical service α records information regarding the viewing permission of personal information on the blockchain in response to a request from the data user, and grants the viewing permission to the data user.

[0044] The data user generates a proof of zero-knowledge proof based on the viewing permission, and sends a data request to medical service α together with the generated proof.

[0045] Based on the verification result of the proof included in the data request received from the data user, medical service α obtains the personal information corresponding to the data request and provides the obtained personal information to the data user. In addition, medical service α records the usage history of the viewing permission on the blockchain.

[0046] Figure 4 shows a service form in which data sharing service X provides personal information and the like that it manages to data users and the like. The user shown in Figure 4 corresponds to the user of the user terminal 10 shown in Figures 1 and 2. The data sharing services X, Y, and Z shown in Figure 4 correspond to the service providing device 20 shown in Figures 1 and 2. The blockchain shown in Figure 4 corresponds to the BC client device 30 and the BC system 40 shown in Figures 1 and 2. The data users shown in Figure 4 correspond to the users of the data user devices 50 shown in Figures 1 and 2. Note that the data sharing services X, Y, and Z shown in Figure 4 have the same functions. Hereinafter, an example of a service executed via data sharing service X will be described.

[0047] The user uploads and pre-registers data such as information on demographic attributes such as age, gender, and sex, location information, and application usage history to the data sharing service X.

[0048] The data sharing service X registers and manages the personal information uploaded by the user. When registering personal information, the data sharing service X asks whether the user agrees to provide the data to the data user. The data sharing service X may permit the registration of personal information on the condition that the user agrees to provide the data. The data sharing service X records information regarding the viewing authority of personal information in the blockchain in response to a request from the data user and grants the viewing authority to the data user.

[0049] The data user generates a proof of zero-knowledge proof based on the viewing authority and sends a data request to the data sharing service X together with the generated proof.

[0050] Data sharing service X obtains personal information corresponding to a data request based on the verification result of the proof included in the data request received from a data user, and provides the obtained personal information to the data user. Further, data sharing service X records the usage history of personal information on the blockchain. Also, when data sharing service X grants a reward to a user according to the use of personal information, information regarding the reward may be recorded on the blockchain accordingly.

[0051] As described above, the information processing system 1 according to the embodiment of the present disclosure is applicable to various services related to the provision of personal information as described above.

[0052] <<4. Example of Device Configuration>> Hereinafter, the configuration of the BC client device 30 according to the embodiment of the present disclosure will be described. FIG. 5 is a block diagram showing a configuration example of the BC client device according to the embodiment of the present disclosure.

[0053] The BC client device 30 is an information processing device that executes data recording on the blockchain and the like in response to a request from the service providing device 20. The BC client device 30 may be one of the information processing devices constituting the BC system 40, or may be an information processing device independent of the BC system 40.

[0054] As shown in FIG. 5, the BC client device 30 includes a communication unit 31, a storage unit 32, and a control unit 33.

[0055] The communication unit 31 is realized by a NIC (Network Interface Card), various communication modems, etc. The communication unit 31 communicates with the service providing device 20 via the network N and transmits and receives various information.

[0056] The storage unit 32 is realized by, for example, a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as a hard disk or an optical disk. The storage unit 32 can store, for example, programs and data for realizing various processing functions executed by the control unit 33. The programs stored in the storage unit 32 include programs for realizing processing functions corresponding to each part of the control unit 33. The programs stored in the storage unit 32 include an OS (Operating System) and various application programs.

[0057] The control unit 33 includes a first recording unit 331, a verification unit 332, a second recording unit 333, and a transmission unit 334. Each functional unit included in the control unit 33 is realized by a control circuit including a processor and a memory. Each functional unit included in the control unit 33 is realized, for example, by instructions described in a program read from an internal memory by a processor being executed with the internal memory as a work area. The programs read by the processor from the internal memory include an OS (Operating System) and application programs. Also, each functional unit included in the control unit 33 may be realized by an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array).

[0058] Also, the main storage device and the auxiliary storage device that function as the aforementioned internal memory are realized by, for example, a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as a hard disk or an optical disk.

[0059] The first recording unit 331 records information regarding the viewing authority of data in the BC system 40 in response to a request from the service providing device 20 that manages the data. For example, when the first recording unit 331 receives a recording request for the viewing authority from the service providing device 20, it writes and records the hash value included in the recording request in the BC system 40. The hash value generated by the service providing device 20 is generated using "HMAC (Hash-based Message Authentication Code)", the information regarding the viewing authority granted by the service providing device 20 to the source of the viewing authority request, a secret value that is shared limitedly between the service providing device 20 and the source of the viewing authority request, and the public key provided by the source of the viewing authority request. In addition, as the hash function used when generating the hash value, in addition to "HMAC (Hash-based Message Authentication Code)", any hash function such as "SHA-256 (Secure Hash Algorithm 256-bit)" or "Pedersen Commitment" can be used.

[0060] The verification unit 332 verifies a zero-knowledge proof to prove that the user is a legitimate user with the viewing authority based on the information regarding the viewing authority written in the blockchain. Specifically, when the verification unit 332 receives a proof confirmation request from the service providing device 20, it acquires the keyed hash value of the information regarding the viewing authority from the BC system 40 based on the writing position (record position) of the viewing authority included in the confirmation request. The verification unit 332 verifies the proof by comparing the acquired keyed hash value with the keyed hash value generated based on the proof included in the confirmation request. If the hash values are the same, the verification unit 332 determines that the user is a legitimate user with the viewing authority.

[0061] The second recording unit 333 records information regarding the proof verification result by the verification unit 332 in the BC system 40. When recording information regarding the proof verification result in the BC system 40, the second recording unit 333 does not record information associating the proof with the information regarding the viewing authority. For example, the second recording unit 333 writes in the BC system 40 information other than the writing position (record position) of the information regarding the viewing authority used for the proof verification among the information regarding the proof verification.

[0062] The transmission unit 334 transmits the determination result as to whether or not the data requester is a legitimate user having the viewing authority to the service providing apparatus 20.

[0063] <<5. Example of processing procedure>> <5-1. Flow of processing according to the comparative example> Using FIG. 6, as an example of the processing procedure according to the comparative example, an example of the processing procedure when using "Merkle Tree" as the proof of zero-knowledge proof will be described. FIG. 6 is a sequence diagram showing an example of the processing procedure according to the comparative example.

[0064] As shown in FIG. 6, the user terminal 10EX transmits personal information to the service providing apparatus 20EX (step S101). The service providing apparatus 20EX writes and records in the BC system 40EX that it has the ownership of the personal information (step S102).

[0065] Also, the data user apparatus 50EX transmits a request for acquiring the viewing authority of the personal information to the service providing apparatus 20EX (step S103).

[0066] The service providing apparatus 20EX confirms the content of the request for acquiring the viewing authority (step S104), and executes the recording of the viewing authority in the BC system 40EX (step S105). Then, the service providing apparatus 20EX grants the viewing authority to the data user apparatus 50EX (step S106).

[0067] The data user device 50EX sends a request for the records to be used in the "Merkle Tree" to the BC system 40EX (step S107). In response to the request from the data user device 50EX, the BC system 40EX passes the records to be used in the "Merkle Tree" to the data user device 50EX (step S108).

[0068] The data user device 50EX creates a zero-knowledge proof of the viewing right incorporating the "Merkle Tree" (step S109). Then, the data user device 50EX sends the proof of the zero-knowledge proof together with the data request for personal information to the service providing device 20EX (step S110).

[0069] The service providing device 20EX verifies the proof of the zero-knowledge proof (step S111), writes and records the usage history in the BC system 40 (step S112). Then, when the user of the data user device 50EX has a legitimate viewing right, the service providing device 20EX provides the personal information corresponding to the data request to the user of the data user device 50EX (step S113).

[0070] <5-2. Example of the processing procedure according to the embodiment of the present disclosure> An example of the processing procedure according to the embodiment of the present disclosure will be described with reference to FIG. 7. FIG. 7 is a sequence diagram showing an example of the processing procedure according to the embodiment of the present disclosure.

[0071] As shown in FIG. 7, the user terminal 10 sends personal information to the service providing device 20 (step S201). The service providing device 20 sends a recording request for the ownership of the personal information to the BC client device 30 (step S202). In response to the request from the service providing device 20, the BC client device 30 writes and records in the BC system 40 that it has the ownership of the personal information (step S203).

[0072] In addition, the data user device 50 transmits a request for obtaining the viewing right of personal information to the service providing device 20 (step S204). Note that the data user device 50 creates a key pair of a public key and a private key in advance, and provides the public key to the service providing device 20 when requesting to obtain the viewing right for the service providing device 20.

[0073] The service providing device 20 confirms the content of the request for obtaining the viewing right (step S205), and transmits a request for recording the viewing right to the BC client device 30 (step S206). The service providing device 20 generates a hash value of the information regarding the viewing right, and transmits it included in the request for recording the viewing right. This hash value is generated using the secret value: "r" that is shared limitedly between the information regarding the viewing right and the data user device 50 that is the requester of the viewing right, and the public key provided from the data user device 50 that is the requester of the viewing right.

[0074] The BC client device 30 writes and records the information (hash value) regarding the viewing right in the BC system 40 in response to the request from the service providing device 20 (step S207). Then, the BC client device 30 returns the writing position (record position) of the information regarding the viewing right to the service providing device 20 (step S208).

[0075] The service providing device 20 grants the viewing right to the data user device 50 (step S209). The service providing device 20 provides the data user device 50 with the secret value: "r" and the writing position (record position) of the hash value of the information regarding the viewing right in the BC system 40 as the viewing right.

[0076] The data user device 50 creates a zero-knowledge proof of the viewing right (step S210). Specifically, the data user device 50 inputs the secret key paired with the public key provided to the service providing device 20 into the public key generation function to generate a public key. The data user device 50 creates a proof of zero-knowledge proof that generates a hash value from the hash function based on the generated public key, the secret value "r" provided from the service providing device 20, and the information regarding the viewing right. Then, the data user device 50 transmits the proof of zero-knowledge proof and the writing position (record position) of the viewing right to the service providing device 20 together with the data request for personal information (step S211).

[0077] The service providing device 20 transmits a proof confirmation request to the BC client device 30 (step S212). The BC client device 30 verifies the proof of the data user device 50 in response to the request from the service providing device 20 (step S213). Specifically, the BC client device 30 obtains the hash value recorded at the viewing information writing position (record position) included in the data request transmitted from the data user device 50 to the service providing device 20 from the BC system 40. The BC client device 30 verifies the proof of the data user device 50 by comparing the hash value obtained from the BC system 40 with the hash value created based on the proof of the data user device 50.

[0078] The BC client device 30 writes and records the information regarding the proof verification result in the BC system 40 as a usage history (step S214). At this time, the BC client device 30 does not record in the BC system 40 the information that associates the hash value on the BC system 40 used for the proof verification and the hash value generated based on the proof among the information regarding the proof verification result. Then, the BC client device 30 returns to the service providing device 20 the determination result as to whether the user of the data user device 50 has a legitimate viewing right (step S215).

[0079] Based on the determination result obtained from the BC client device 30, when the user of the data user device 50 has a legitimate viewing right, the service providing device 20 passes the personal information corresponding to the data request to the data user device 50 (step S216).

[0080] In the processing procedure according to the above-described comparative example (see FIG. 6), since the "Merkle Tree" is used to prove by zero-knowledge proof that the user of the data user device 50EX has a legitimate viewing right, the amount of calculation increases, and the processing until the provision of personal information may be delayed. For example, it may take time to obtain the block data recorded in the blockchain in the above-described step S107 or step S108, to create a proof in the above-described step 109, and to create a tree structure in the above-described step S111.

[0081] On the other hand, in the processing procedure according to the embodiment of the present disclosure (see FIG. 7), the BC client device 30 verifies a zero-knowledge proof for proving that the user of the data user device 50 has a legitimate viewing right. This proof incorporates a hash value generated using a secret value "r" that is shared limitedly between the service providing device 20 and the data user device 50. Thereby, when the BC client device 30 verifies the proof, time required for acquiring block data necessary for verifying the proof from the blockchain and time required for calculating hash values repeatedly executed until reaching the root node are unnecessary, and the processing can be accelerated compared to using a "Merkle Tree". Also, in the processing procedure according to the embodiment of the present disclosure (see FIG. 7), when the BC client device 30 records information regarding the verification result of the proof on the blockchain, it does not record information associating the proof with information regarding the viewing right. Thereby, anonymity equivalent to that of a "Merkle Tree" can be realized on the blockchain. By arranging the BC client device 30 between the service providing device 20 and the BC system 40, even when there is a new entry to the blockchain operated by the BC system 40, the availability of the information processing system 1 can be enhanced. That is, when the service providing device 20 directly participates in the blockchain, communication with other participants is required to perform the function of the distributed ledger. In contrast, by performing communication with the blockchain via the BC client device 30 as in the embodiment of the present disclosure, even if the service providing device 20 goes down, the BC client device 30 disconnects the dependency relationship with the service providing device 20, and other blockchain participants can continue to provide the service.

[0082] <<6. Modification Example>> <6-1. Update of Viewing Right> In the above embodiment, each time the verification unit 332 verifies the proof, the second recording unit 333 may update the information regarding the viewing authority and record it in the BC system 40. In this way, by limiting the number of times of use of the proof generated in the data user device 50 and used for zero-knowledge proof to only once, it is possible to prevent the reuse of the proof by intercepting the data. Hereinafter, with reference to FIG. 8, the flow of the process regarding the update of the viewing authority will be described. FIG. 8 is a sequence diagram showing an example of a processing procedure according to a modification of the present disclosure. Among the processes shown in FIG. 8, the processes of step S310, step S311, step S314, and step S316 are different from the processes shown in FIG. 7.

[0083] As shown in FIG. 8, the user terminal 10 transmits personal information to the service providing device 20 (step S301). The service providing device 20 transmits a recording request for the ownership of the personal information to the BC client device 30 (step S302). The BC client device 30 writes and records in the BC system 40 that it has the ownership of the personal information in response to the request from the service providing device 20 (step S303).

[0084] Also, the data user device 50 transmits a request for obtaining the viewing authority of the personal information to the service providing device 20 (step S304). The service providing device 20 confirms the content of the request for obtaining the viewing authority (step S305), and transmits a recording request for the viewing authority to the BC client device 30 (step S306).

[0085] The BC client device 30 writes and records the information (hash value) regarding the viewing authority in the BC system 40 in response to the request from the service providing device 20 (step S307). Then, the BC client device 30 returns the writing position (record position) of the information regarding the viewing authority to the service providing device 20 (step S308). The service providing device 20 grants the viewing authority to the data user device 50 (step S309).

[0086] The data user device 50 creates a zero-knowledge proof of viewing permission and creates a new secret value and a new hash value based on the new secret value (step S310). Then, the data user device 50 transmits, together with the data request for personal information, the proof of zero-knowledge proof, the writing position (record position) of the viewing permission, and the new hash value to the service providing device 20 (step S311). By transmitting the hash value based on the new secret value instead of the new secret value, the security against man-in-the-middle attacks can be ensured.

[0087] The service providing device 20 transmits a proof confirmation request to the BC client device 30 (step S312). Also, the service providing device 20 sends the new hash value received from the data user device 50 to the BC client device 30 together with the proof confirmation request.

[0088] The BC client device 30 verifies the proof of the data user device 50 in response to the request from the service providing device 20 (step S313). Also, the BC client device 30 writes and records information regarding the verification result of the proof in the BC system 40 as a usage history, and updates the viewing permission with the new hash value received from the service providing device 20 (step S314). As a result, at the time of the next data usage, a data request using an old proof will not be accepted.

[0089] Then, the BC client device 30 returns to the service providing device 20 the determination result as to whether the user of the data user device 50 has a legitimate viewing permission (step S315). At this time, the BC client device 30 sends the writing position (record position) of the information (new hash value) regarding the updated viewing permission to the service providing device 20.

[0090] Based on the determination result obtained from the BC client device 30, when the user of the data user device 50 has a legitimate viewing right, the service providing device 20 passes the writing position (record position) of the information regarding the updated viewing right to the data user device 50 together with the personal information corresponding to the data request (step S316).

[0091] In addition, when the data user device 50 acquires the data again, it uses the new secret value created in step S310 that is the basis of the new hash value transmitted to the service providing device 20 in step S311. The BC client device 30 always uses the latest hash value and rejects proofs based on old hash values.

[0092] <6-2. Invalidation of viewing right> In the above embodiment, the BC client device 30 may record a revocation list enumerating the targets of revocation of the viewing right in the BC system 40. FIG. 9 is a block diagram showing a configuration example of the BC client device according to a modification of the present disclosure. The BC client device 30 according to the modification is different from the above embodiment in that it has an update unit 335.

[0093] The update unit 335 updates the revocation list recorded in the BC system 40 in response to a request from the service providing device 20. The verification unit 332 verifies whether the prover of the proof is included in the revocation list prior to verifying the proof.

[0094] Hereinafter, with reference to FIG. 10, the flow of the process regarding the invalidation of the viewing right will be described. FIG. 10 is a sequence diagram showing an example of the processing procedure according to a modification of the present disclosure. Note that FIG. 10 shows an example of the flow of the process when the user of the data user device 50 is the target of revocation of the viewing right (revoke target).

[0095] As shown in FIG. 10, the user terminal 10 transmits a revocation request to the service providing apparatus 20 (step S401). The service providing apparatus 20 transfers the revocation request to the BC client apparatus 30 (step S402).

[0096] In response to the revocation request received from the service providing apparatus 20, the BC client apparatus 30 updates the revocation list recorded in the BC system 40 (step S403).

[0097] The data user apparatus 50 transmits, together with a data request for personal information, a zero-knowledge proof, a writing position (record position) of the viewing right, and a new secret value to the service providing apparatus 20 (step S404).

[0098] The service providing apparatus 20 transmits a proof confirmation request to the BC client apparatus 30 (step S405).

[0099] When the BC client apparatus 30 receives a proof confirmation request from the service providing apparatus 20, it executes confirmation of the revocation list and verification of the proof (step S406). If the user of the data user apparatus 50 is subject to revocation in the revocation list, the BC client apparatus 30 does not execute verification of the proof. Specifically, the BC client apparatus 30 refers to the revocation list recorded in the BC system 40 and checks whether the prover of the proof (the user of the data user apparatus 50) is subject to revocation. If the prover of the proof is subject to revocation, the BC client apparatus 30 does not execute verification of the proof and returns rejection (indicating that it is subject to revocation) as a determination result to the service providing apparatus 20 (step S407). If the prover of the proof does not fall within the scope of revocation in the revocation list, the BC client apparatus 30 executes verification of the proof in the same manner as in the above embodiment.

[0100] Based on the verification result received from the BC client device 30, the service providing device 20 notifies the user of the data user device 50 that it has been rejected (step S408).

[0101] <<7. Others>> The BC client device 30 according to the embodiments and modifications of the present disclosure may be realized by a dedicated computer system or a general-purpose computer system.

[0102] Also, various programs for realizing the information processing method executed by the BC client device 30 according to the embodiments and modifications of the present disclosure may be stored and distributed in a computer-readable recording medium such as an optical disk, a semiconductor memory, a magnetic tape, a flexible disk, etc. At this time, the BC client device 30 according to the embodiments and modifications of the present disclosure can realize the information processing method according to the embodiments and modifications of the present disclosure by installing and executing various programs on a computer.

[0103] Also, various programs for realizing the information processing method executed by the BC client device 30 according to the embodiments and modifications of the present disclosure may be stored in a disk device provided in a server on a network such as the Internet so that they can be downloaded to a computer. Further, the functions provided by various programs for realizing the information processing method executed by the BC client device 30 according to the embodiments and modifications of the present disclosure may be realized by the cooperation of the OS and an application program. In this case, the part other than the OS may be stored and distributed in a medium, or the part other than the OS may be stored in an application server so that it can be downloaded to a computer.

[0104] In addition, among the processes described in the embodiments and variations of the present disclosure, all or part of the processes described as being automatically performed can be manually performed, or all or part of the processes described as being manually performed can be automatically performed by a known method. Additionally, regarding the processing procedures, specific names, and information including various data and parameters shown in the above documents and drawings, they can be arbitrarily changed unless otherwise specified. For example, the various information shown in each figure is not limited to the illustrated information.

[0105] Moreover, each component of the BC client device 30 according to the embodiments and variations of the present disclosure is a functional concept and does not necessarily need to be physically configured as shown in the drawings. That is, the specific form of the distribution and integration of each device is not limited to that shown, and all or part of it can be functionally or physically distributed and integrated in any unit according to various loads and usage situations. For example, the verification unit 332 and the second recording unit 333 included in the control unit 33 of the BC client device 30 may be functionally integrated.

[0106] Also, the embodiments and variations of the present disclosure can be appropriately combined within a range that does not conflict with the processing content. Further, the order of each step shown in the flowchart according to the embodiments of the present disclosure can be appropriately changed.

[0107] As described above, the embodiments and variations of the present disclosure have been explained. However, the technical scope of the present disclosure is not limited to the above-described embodiments and variations, and various changes are possible without departing from the gist of the present disclosure. Also, components from different embodiments and variations may be appropriately combined.

[0108] <<8. Hardware Configuration Example>> Using FIG. 11, a hardware configuration example of a computer capable of realizing the BC client device 30 according to the embodiments and modifications of the present disclosure will be described. FIG. 11 is a block diagram showing a hardware configuration example of a computer capable of realizing the BC client device according to the embodiments and modifications of the present disclosure. Note that FIG. 11 shows an example of a computer, and the configuration shown in FIG. 11 is not necessarily limited thereto.

[0109] As shown in FIG. 11, the BC client device 30 according to the embodiments and modifications of the present disclosure can be realized by, for example, a computer 1000 having a processor 1001, a memory 1002, and a communication module 1003.

[0110] The processor 1001 is typically a CPU (Central Processing Unit), a DSP (Digital Signal Processor), a SoC (System-on-a-Chip), a system LSI (Large Scale Integration), or the like.

[0111] The memory 1002 is typically a volatile or non-volatile semiconductor memory such as a RAM (Random Access Memory), a ROM (Read Only Memory), a flash memory, or a magnetic disk. The storage unit 32 included in the BC client device 30 is realized by the memory 1002.

[0112] The communication module 1003 is typically a communication card for a wired or wireless LAN (Local Area Network), LTE (Long Term Evolution), Bluetooth (registered trademark), WUSB (Wireless USB), a router for optical communication, various communication modems, or the like. The function of the communication unit 31 of the BC client device 30 according to the above embodiment is realized by the communication module 1003.

[0113] Processor 1001 functions as, for example, an arithmetic processing unit or a control unit, and controls the overall operation or a part of the operation of each component based on various programs recorded in memory 1002. Each functional unit (first recording unit 331, verification unit 332, second recording unit 333, transmission unit 334, and update unit 335) included in BC client device 30 is realized by processor 1001 reading and executing an information processing program in which instructions for operating as each functional unit are described from memory 1002.

[0114] That is, processor 1001 and memory 1002 realize information processing by each functional unit included in BC client device 30 in cooperation with software (the information processing program stored in memory 1002).

[0115] <<9. Conclusion>> BC client device 30 (an example of an information processing device) according to an embodiment of the present disclosure includes a first recording unit 331, a verification unit 332, and a second recording unit 333. The first recording unit 331 records information regarding the viewing right of data (for example, personal information) in BC system 40 (an example of a blockchain) in response to a request from service providing device 20 (an example of an information management device) that manages data. The verification unit 332 verifies a zero-knowledge proof to prove that the user is a legitimate user granted the viewing right based on the information regarding the viewing right written in BC system 40. The second recording unit 333 records information regarding the verification result of the proof in BC system 40. From this, BC client device 30 can realize rapid service provision while ensuring anonymity.

[0116] Further, the first recording unit 331 records in BC system 40 a hash value (for example, a keyed hash value) obtained by hashing information regarding the viewing right (for example, an arbitrary character string) using secret information (for example, secret information: "r") shared between the data requester (for example, the user of data utilization device 50) that requests the data and service providing device 20. Thereby, it becomes possible to trace the usage history without directly recording personal information on the blockchain.

[0117] Also, when the second recording unit 333 records information regarding the verification result of the proof in the blockchain, it does not record information associating the proof with information regarding the viewing authority. Thereby, in the BC system 40 (blockchain), anonymity equivalent to that of a "Merkle Tree" can be realized.

[0118] Also, each time the verification by the verification unit 332 is performed, the second recording unit 333 updates the information regarding the viewing authority and records it in the BC system 40. Thereby, it is possible to prevent the reuse of the proof due to the interception of data.

[0119] Also, the BC client device 30 further includes an update unit 335 that updates the revocation list recorded in the BC system 40 in response to a request from the service providing device 20. Also, prior to verifying the proof, the verification unit 332 verifies whether the prover of the proof is included in the revocation list. Thereby, it is possible to avoid verifying the proof of a data user who does not wish to disclose personal information by the user.

[0120] Also, the effects described in this specification are merely illustrative or exemplary and not restrictive. That is, the technology of the present disclosure may exhibit other effects apparent to those skilled in the art from the description of this specification, together with or instead of the above effects.

[0121] Note that the technology of the present disclosure can also have the following configurations as belonging to the technical scope of the present disclosure. (1) A first recording unit that records information regarding the viewing authority of the data in a blockchain in response to a request from an information management device that manages the data, A verification unit that verifies a proof of zero-knowledge proof for proving that a user is a legitimate user granted the viewing authority based on the information regarding the viewing authority written in the blockchain, A second recording unit that records information regarding the verification result of the proof in the blockchain An information processing apparatus having the same. (2) The first recording unit Using secret information shared between the data requester who requests the data and the information management apparatus, records, in the blockchain, a hash value obtained by hashing the information regarding the viewing authority The information processing apparatus according to (1) above. (3) The second recording unit When recording information regarding the verification result of the proof in the blockchain, does not record information associating the proof with the information regarding the viewing authority The information processing apparatus according to (1) or (2) above. (4) The second recording unit Each time the verification by the verification unit is performed, updates the information regarding the viewing authority and records it in the blockchain The information processing apparatus according to any one of (1) to (3) above. (5) An update unit that updates the revocation list recorded in the blockchain in response to a request from the information management apparatus Further comprising The verification unit Before verifying the proof, verifies whether the prover of the proof is included in the revocation list The information processing apparatus according to (1) above. (6) A processor In response to a request from an information management apparatus that manages data, records information regarding the viewing authority of the data in the blockchain, Based on the information regarding the viewing authority written in the blockchain, verifies a proof of zero-knowledge proof for proving that the user is a legitimate user granted the viewing authority, Records information regarding the verification result of the viewing authority in the blockchain Information processing method. (7) Cause a processor to in response to a request from an information management device that manages data, record information regarding the viewing right of the data in a blockchain, verify a proof of zero-knowledge proof for proving that it is a legitimate user granted the viewing right based on the information regarding the viewing right written in the blockchain, record information regarding the verification result of the viewing right in the blockchain Information processing program.

Explanation of symbols

[0122] 1 Information processing system 10 User terminal 20 Service providing device 30 BC client device 31 Communication unit 32 Storage unit 33 Control unit 40 BC system 50 Data user device 331 First recording unit 332 Verification unit 333 Second recording unit 334 Transmission unit 335 Update unit

Claims

1. A first recording unit that records information regarding the viewing authority of the data on a blockchain in response to a request from an information management device that manages the data; A verification unit that verifies a proof of zero-knowledge proof for proving that the user is a legitimate user granted the viewing authority based on the information regarding the viewing authority written on the blockchain; A second recording unit that records information regarding the verification result of the proof on the blockchain An information processing apparatus having the above.

2. The first recording unit records, on the blockchain, a hash value obtained by hashing the information regarding the viewing authority using secret information shared between the data requester who requests the data and the information management device. The information processing apparatus according to Claim 1.

3. The second recording unit does not record information associating the proof with the information regarding the viewing authority when recording the information regarding the verification result of the proof on the blockchain. The information processing apparatus according to Claim 2.

4. The second recording unit updates the information regarding the viewing authority each time the verification by the verification unit is performed, and records it on the blockchain. The information processing apparatus according to Claim 3.

5. An update unit that updates a revocation list recorded on the blockchain in response to a request from the information management device further provided, The verification unit verifies whether the prover of the proof is included in the revocation list prior to the verification of the proof. The information processing apparatus according to Claim 1.

6. A processor records information regarding the viewing authority of the data on a blockchain in response to a request from an information management device that manages the data, verifies a proof of zero-knowledge proof for proving that the user is a legitimate user granted the viewing authority based on the information regarding the viewing authority written on the blockchain, records information regarding the verification result of the proof on the blockchain An information processing method.

7. Causing a processor to record information regarding the viewing authority of the data on a blockchain in response to a request from an information management device that manages the data, to verify a proof of zero-knowledge proof for proving that the user is a legitimate user granted the viewing authority based on the information regarding the viewing authority written on the blockchain, Cause information regarding the verification result of the proof to be recorded in the blockchain Information processing program.

Citation Information

Patent Citations

  • Inspection device, anonymous remittance method with inspection function, and program

    JP2018007168A

  • Distributed medical information sharing system, medical information provision server, and program

    JP2020010267A