Information processing device, information processing method, and program

The information processing device securely transmits data by using a decryption key to encrypt and decrypt data through a non-portable relay device, addressing the challenge of secure data transmission on devices users may not always carry.

JP7719985B1Active Publication Date: 2025-08-06JCB CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2025035575
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-08-06
Estimated Expiration
2045-03-06

AI Technical Summary

Technical Problem

Existing secure payment systems rely on tokens stored on devices that users always carry, but future scenarios may require using tokens on devices that users do not always have, posing a security challenge for highly confidential data transmission.

Method used

An information processing device with a memory unit to store decryption keys, a receiving unit to decrypt data encrypted with a user's encryption key, and a transmitting unit to securely transmit decrypted data to a data utilization device via a non-portable relay device.

Benefits of technology

Enables secure data transmission by encrypting and decrypting data through a non-portable device, ensuring confidentiality even when the primary device is not always accessible.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007719985000001_ABST
    Figure 0007719985000001_ABST
Patent Text Reader

Abstract

To provide a technology that enables data to be transmitted securely. [Solution] An information processing device having: a memory unit that stores a decryption key for decrypting data encrypted with a user's encryption key; a receiving unit that receives a decryption request from a data utilization device, the decrypted first data being encrypted with the user's encryption key, wherein the encrypted first data included in the decryption request is transmitted from a first device used by the user and obtained by the data utilization device via a second device different from the first device; a decryption processing unit that decrypts the encrypted first data with the user's decryption key; and a transmitting unit that transmits the decrypted first data to the data utilization device.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing device, an information processing method, and a program. [Background technology]

[0002] Conventionally, token payment, in which payments are made using a token generated based on a payment-dedicated account (e.g., a credit card number, a bank account number, etc.), has been known as one of the technologies for enhancing the security of cashless payments. For example, in the system described in Patent Document 1 below, an inter-company payment agent system generates a token based on a user's credit card number, etc. When a user purchases a product or receives a service, the user hands the token to a merchant. The merchant can process the sales by sending the received token to a credit card payment company. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2022-159160 Summary of the Invention [Problem to be solved by the invention]

[0004] Currently, the above tokens are provided on the premise that they are stored on devices that users always carry, such as smartphones, in order to realize secure payments. However, it is expected that in the future, there will be a need to use tokens on devices that users do not always carry. Similar issues are not limited to tokens, but can occur with any highly confidential data, such as digital certificates.

[0005] Therefore, an object of the present invention is to provide a technique that enables data to be transmitted securely. [Means for solving the problem]

[0006] An information processing device according to one embodiment of the present invention comprises: a memory unit that stores a decryption key for decrypting data encrypted with a user's encryption key; a receiving unit that receives a decryption request from a data utilization device, the decrypted first data being encrypted with the user's encryption key, wherein the encrypted first data included in the decryption request is transmitted from a first device used by the user and acquired by the data utilization device via a second device different from the first device; a decryption processing unit that decrypts the encrypted first data with the user's decryption key; and a transmitting unit that transmits the decrypted first data to the data utilization device. [Effects of the Invention]

[0007] According to the present invention, it is possible to provide a technique that enables data to be transmitted securely. [Brief explanation of the drawings]

[0008] [Figure 1] 1 is a diagram illustrating an example of the configuration of an information processing system according to an embodiment of the present invention. [Figure 2] 1 is a diagram illustrating an example of the hardware configuration of an information processing device, a constantly portable device, a non-portable device, and a data utilization device. [Figure 3] FIG. 2 is a diagram illustrating an example of a functional block configuration of an information processing device. [Figure 4] 10A and 10B are diagrams illustrating examples of always-on device information, non-portable device information, and data utilization device information. [Figure 5] FIG. 2 is a diagram illustrating an example of a functional block configuration of a constantly portable device. [Figure 6] FIG. 2 is a diagram illustrating an example of a functional block configuration of a non-portable device. [Figure 7] FIG. 2 is a diagram illustrating an example of a functional block configuration of a data utilization device. [Figure 8] FIG. 10 is a sequence diagram illustrating an example of a processing procedure for registering an always-on device. [Figure 9] FIG. 10 is a sequence diagram illustrating an example of a processing procedure for registering a non-portable device. [Figure 10] FIG. 10 is a sequence diagram showing an example of a processing procedure when registering a data utilization device. [Figure 11] FIG. 10 is a sequence diagram illustrating an example of a processing procedure when first data is transmitted from the always-on device to the information processing device. [Figure 12] FIG. 10 is a sequence diagram illustrating an example of a processing procedure for registering an always-on device. [Figure 13] FIG. 10 is a sequence diagram illustrating an example of a processing procedure when first data is transmitted from the always-on device to the information processing device. DETAILED DESCRIPTION OF THE INVENTION

[0009] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The present invention will be described with reference to the accompanying drawings, in which the same reference numerals denote the same or similar components.

[0010] <System configuration> FIG. 1 is a diagram illustrating an example of the configuration of an information processing system according to this embodiment. As illustrated in FIG. 1, the information processing system 1 includes an information processing device 10, one or more always-portable devices 20, one or more non-portable devices 30, and one or more data utilization devices 40. The information processing system 1 provides a service (hereinafter referred to as a "data transmission service") for securely transmitting data from the always-portable device 20 to the data utilization device 40 via the non-portable device 30. The data is assumed to be, for example, highly confidential data related to a user, but is not necessarily limited to this and may be any data. In the following description, data transmitted from the always-portable device information 100a to the data utilization device 40 is referred to as "first data." Examples of the first data include attribute information, data generated by the always-portable device 20 (such as location information and operation information), maintenance information, and data related to the user (such as financial transaction information, qualification information, consent history for data processing, and evaluation information).

[0011] The information processing device 10 is configured with one or more servers, etc., and performs various processes required to securely transmit data to the data utilization device 40. The information processing device 10 may be a cloud server. In addition, the information processing device 10 performs a process for registering the always-portable device 20, the non-portable device 30, and the data utilization device 40 for use.

[0012] The information processing device 10 may also store other data associated with the first data and provide the other data to the data utilization device 40. The other data is referred to as "second data." The second data is assumed to be data that is larger in data size than the first data and that would be inefficient to transmit to the data utilization device 40 via the non-portable device 30, but is not limited to this. Examples of the second data include attribute information, data generated by the always-portable device 20 (such as location information and operation information), maintenance information, and data related to the user (such as financial transaction information, qualification information, consent history for data processing, and evaluation information). When the second data is provided, the first data may be short data, such as a character string, that can identify the second data.

[0013] The always-portable device 20 is a device that the user carries with them at all times, and may be, for example, a smartphone, a tablet, a personal computer, a smart watch, a key fob, etc. Note that the always-portable device 20 may be any device that the user can carry with them at all times, regardless of whether the user actually carries it with them at all times.

[0014] The non-portable device 30 is a device that is not intended to be carried by a user at all times, such as an automobile, a drone, a home appliance, or a device owned by another person. In this embodiment, the non-portable device 30 may be any device other than the always-carrying device 20. The non-portable device 30 may also be called a "relay device."

[0015] The data utilization device 40 is a device that utilizes the first data and / or the second data, and is, for example, a store device that accepts payments (a payment device such as a POS (Point Of Sales) device), a parking fee collection system, an EV (electric vehicle) charger, a public power supply spot, a toll collection system for a toll road, an information terminal in a city or facility, a smart display, etc. The data utilization device 40 may be any device that utilizes data related to a user. Furthermore, the data utilization device 40 may utilize the first data and / or the second data itself, or may provide the data to another device for utilization.

[0016] In the information processing system 1, the first data is not transmitted directly from the always-portable device 20 to the data utilization device 40, but is transmitted to the data utilization device 40 via the non-portable device 30. Furthermore, the first data transmitted from the always-portable device 20 to the non-portable device 30 is encrypted, and the non-portable device 30 cannot refer to the contents of the first data. Furthermore, the data utilization device 40 transmits the first data received from the non-portable device 30 to the information processing device 10, and the information processing device 10 transmits the decrypted first data to the data utilization device 40. As a result, the data utilization device 40 can obtain the decrypted first data and can perform processing using the first data.

[0017] In this embodiment, a method in which the encryption key for encrypting the first data is always held by the portable device 20 and the first data is encrypted by the portable device 20 is referred to as an "edge management method" and a "first method." Also, a method in which the encryption key for encrypting the first data is always held by the information processing device 10 and the first data is encrypted by the information processing device 10 is referred to as a "cloud management method" and a "second method."

[0018] (Example) Here, a specific example of a service using the information processing system 1 will be described. For example, the first data is a payment token used for payment. The always-portable device 20 is a smartphone, the non-portable device 30 is a rental car, and the data utilization device 40 is a payment device installed at a drive-through, a power supply spot, or the like. The payment device is capable of mutual communication with a vehicle (here, a rental car) using a communication technology called V2X (Vehicle to X). The always-portable device 20 is also assumed to store an encrypted payment token. The user is also assumed to pay for a product purchased at a drive-through.

[0019] First, the always-carrying device 20 establishes a secure communication path with the non-carrying device 30. Next, the always-carrying device 20 transmits an encrypted payment token to the non-carrying device 30 via the communication path. Next, the non-carrying device 30 establishes a secure communication path with the data utilizing device 40. Next, the non-carrying device 30 transmits the encrypted payment token to the data utilizing device 40 via the communication path. Next, the data utilizing device 40 transmits the encrypted payment token to the information processing device 10. The information processing device 10 decrypts the encrypted payment token using a decryption key and transmits the decrypted payment token to the data utilizing device 40. The data utilizing device 40 performs payment processing for the user by transmitting the payment token to a payment service provider's device.

[0020] According to the above processing procedure, the always-portable device 20 encrypts the payment token rather than passing it in plain text to the non-portable device 30. This makes it possible to pass the payment token to the data utilization device 40 while ensuring security.

[0021] <Hardware configuration> FIG. 2 is a diagram illustrating an example of the hardware configuration of the information processing device 10, the always-portable device 20, the non-portable device 30, and the data utilization device 40. The information processing device 10, the always-portable device 20, the non-portable device 30, and the data utilization device 40 each include a processor 11 such as a central processing unit (CPU) or a graphics processing unit (GPU), a memory (e.g., random access memory (RAM) or read-only memory (ROM)), a hard disk drive (HDD) and / or a solid state drive (SSD), a communication IF (network interface) 13 for wired or wireless communication, an input device 14 for accepting input operations, and an output device 15 for outputting information. The input device 14 is, for example, a keyboard, a touch panel, a mouse, and / or a microphone. The output device 15 is, for example, a display, a touch panel, and / or a speaker. The communication IF 13 may be an interface for short-range wireless communication, cellular communication, V2X communication, wireless LAN, or the like.

[0022] <Function block configuration> (Information processing device) FIG. 3 is a diagram illustrating an example of a functional block configuration of the information processing device 10. The information processing device 10 includes a storage unit 100, a registration unit 101, a receiving unit 102, a decryption processing unit 103, a transmission unit 104, and an encryption processing unit 105. The storage unit 100 can be realized using a storage device 12 included in the information processing device 10. The registration unit 101, the reception unit 102, the decryption processing unit 103, the transmission unit 104, and the encryption processing unit 105 can be realized by the processor 11 of the information processing device 10 executing a program stored in the storage device 12. The program can be stored in a storage medium. The storage medium storing the program may be a non-transitory computer-readable medium. The non-transitory storage medium is not particularly limited, and may be, for example, a storage medium such as a universal serial bus (USB) memory or a compact disc read-only memory (CD-ROM).

[0023] The storage unit 100 stores always-portable device information 100a that stores various information related to the always-portable device 20, non-portable device information 100b that stores various information related to the non-portable device 30, and data utilization device information 100c that stores various information related to the data utilization device 40. The storage unit 100 also stores a decryption key for decrypting data encrypted with a user's encryption key.

[0024] The registration unit 101 performs usage registration of the always-portable device 20, the non-portable device 30, and the data usage device 40 that use the data transmission service. In addition, the registration unit 101 provides a certificate (for example, a digital certificate) indicating that usage registration has been completed to the always-portable device 20 and the non-portable device 30 for which usage registration has been completed.

[0025] Furthermore, when the registration unit 101 receives a registration request from the always-carrying device 20 (first device), it may transmit to the always-carrying device 20 an electronic certificate (first electronic certificate) corresponding to the always-carrying device 20 and a private key corresponding to the electronic certificate, which are used when the always-carrying device 20 communicates with the non-carrying device 30. The always-carrying device 20 may perform authentication processing with the non-carrying device 30 and establish a secure communication path using the public key and private key included in the electronic certificate.

[0026] Furthermore, when the registration unit 101 receives a registration request from the non-portable device 30 (second device), it may transmit to the non-portable device 30 an electronic certificate (second electronic certificate) corresponding to the non-portable device 30 and a private key corresponding to the electronic certificate, which are used when the non-portable device 30 constantly communicates with the portable device 20 or the data utilization device 40. The non-portable device 30 may perform authentication processing with the data utilization device 40 and establish a secure communication path using the public key and private key included in the electronic certificate.

[0027] The receiving unit 102 receives various data (request messages, etc.) from the always-portable device 20, the non-portable device 30, and the data utilizing device 40. For example, the receiving unit 102 receives a decryption request including encrypted first data encrypted with the user's encryption key from the data utilizing device 40. Note that the encrypted first data included in the decryption request is data transmitted from the always-portable device 20 (first device) used by the user and acquired by the data utilizing device 40 via a non-portable device 30 (second device) different from the always-portable device 20 (first device).

[0028] The decryption processing unit 103 performs a process of decrypting the encrypted data using the decryption key. For example, the decryption processing unit 103 decrypts the encrypted first data, which has been encrypted using the user's encryption key, using the user's decryption key.

[0029] The transmitting unit 104 transmits various data (such as a response message) to the always-portable device 20, the non-portable device 30, and the data utilizing device 40. For example, the transmitting unit 104 transmits the first data decoded by the decoding processing unit 103 to the data utilizing device 40.

[0030] The encryption processing unit 105 performs a process of decrypting the encrypted data using a decryption key. For example, the encryption processing unit 105 generates encrypted first data by encrypting first data using a user's encryption key.

[0031] In the edge management system, the transmission unit 104 may be configured to constantly transmit the user's encryption key to the portable device 20 (first device).

[0032] In the case of the cloud management method, the storage unit 100 may store the first data and the user's encryption key. The encryption processing unit 105 may generate encrypted first data by encrypting the first data with the user's encryption key. The transmission unit 104 may constantly transmit the encrypted first data to the portable device 20 (first device).

[0033] In the case of the cloud management method, the storage unit 100 may store the second data in association with the first data. The receiving unit 102 may receive the encrypted first data from the data utilization device 40, and the decryption processing unit 103 may decrypt the encrypted first data with a decryption key. The transmitting unit 104 may transmit the second data corresponding to the first data to the data utilization device 40 when the decrypted first data matches the first data stored in the storage unit 100.

[0034] The storage unit 100 may also store an identifier of the non-portable device 30 (second device). The receiving unit 102 may also receive a decryption request including the encrypted first data and the identifier of the non-portable device 30 from the data utilization device 40. The decryption processing unit 103 may also decrypt the encrypted first data when the received identifier of the non-portable device 30 matches the identifier of the non-portable device 30 stored in the storage unit 100, and may not decrypt the encrypted first data when the received identifier of the non-portable device 30 does not match the identifier of the non-portable device 30 stored in the storage unit 100.

[0035] FIG. 4 is a diagram showing an example of the always-portable device information 100a, the non-portable device information 100b, and the data utilization device information 100c.

[0036] Regarding the always-portable device information 100a, the "always-portable device ID" is an identifier that uniquely identifies the always-portable device 20. The identifier may be an identifier specific to the always-portable device 20, etc. The "device information" is various information related to the always-portable device 20. For example, the device information may include the OS (Operating System) name, the OS version, information about applications installed on the always-portable device 20, information about security areas within the always-portable device 20, user information (user ID, address, name, etc.) of the user who uses the always-portable device 20, etc.

[0037] The "connection certificate" is an electronic certificate used when the always-portable device information 100a communicates with the non-portable device information 100b. The connection certificate is issued to the always-portable device 20 when the usage registration of the always-portable device 20 is completed. Therefore, the connection certificate also serves as a certificate that certifies that the always-portable device 20 is legitimately registered in the information processing device 10. The "connection electronic certificate" may store both a public key and an encryption key according to a public key cryptosystem, or may store only the public key. In the latter case, the private key corresponding to the public key may be passed to the always-portable device 20 and not managed by the information processing device 10.

[0038] The "first data encryption key" is an encryption key used to encrypt the first data. The "first data decryption key" is a decryption key used to decrypt the first data. The first data encryption key and the first data decryption key may be key data according to a public key encryption method, or may be according to another encryption method. If according to a public key encryption method, the encryption key and decryption key may be a public key and a private key, respectively, or vice versa. Furthermore, the other encryption method may be a common key encryption method. In the case of a common key encryption method, the "first data encryption key" and the "first data decryption key" may store the same key data.

[0039] "First data" stores the first data. "Second data" stores the second data related to the first data. If no second data is provided, "first data" and "second data" may be omitted.

[0040] In the non-portable device information 100b, the "non-portable device ID" is an identifier that uniquely identifies the non-portable device 30. The "device information" is various information related to the non-portable device 30. The device information may include the OS name, the OS version, information related to applications installed on the non-portable device 30, information related to security areas within the non-portable device 30, identification information of the system administrator who manages the non-portable device 30, and the like.

[0041] The "connection certificate" is an electronic certificate used when the always-portable device information 100a communicates (connects) with the non-portable device information 100b, and when the non-portable device 30 communicates with the data utilization device 40. The connection certificate is issued to the non-portable device 30 when the usage registration of the non-portable device 30 is completed. Therefore, the connection certificate also serves as a certificate that certifies that the non-portable device 30 is legitimately registered in the information processing device 10. The "connection electronic certificate" may store both a public key and an encryption key according to a public key cryptosystem, or may store only the public key. In the latter case, the private key corresponding to the public key may be passed to the non-portable device 30 and not managed by the information processing device 10.

[0042] In the data utilization device information 100c, the "data utilization device ID" is an identifier that uniquely identifies the data utilization device 40. The "device information" is various information related to the data utilization device 40. The device information may include the OS name, the OS version, information related to applications installed on the data utilization device 40, information related to the security area within the data utilization device 40, identification information of the system administrator who manages the data utilization device 40, etc.

[0043] The "connection certificate" is an electronic certificate used when the non-portable device 30 communicates with the data utilization device 40. The connection certificate is issued to the data utilization device 40 when the utilization registration of the data utilization device 40 is completed. Therefore, the connection certificate also serves as a certificate certifying that the data utilization device 40 is legitimately registered in the information processing device 10. The "connection certificate" may store both a public key and an encryption key according to a public key cryptosystem, or may store only the public key. In the latter case, the private key corresponding to the public key may be passed to the data utilization device 40 and not managed by the information processing device 10. Note that if the data utilization device 40 satisfies certain conditions, such as being guaranteed to be a trustworthy device, the "connection certificate" may be omitted from the data utilization device information 100c.

[0044] (Devices always on hand) FIG. 5 is a diagram showing an example of a functional block configuration of the always-portable device 20. The always-portable device 20 includes a storage unit 200, a registration unit 201, a connection processing unit 202, a transmission unit 203, and a reception unit 204. The storage unit 200 can be realized using the storage unit 12 included in the always-portable device 20. The registration unit 201, the connection processing unit 202, the transmission unit 203, and the reception unit 204 can be realized by the processor 11 of the always-portable device 20 executing a program stored in the storage unit 12. The program can be stored in a storage medium. The storage medium storing the program may be a computer-readable non-transitory storage medium. The non-transitory storage medium is not particularly limited, and may be, for example, a storage medium such as a USB memory or a CD-ROM.

[0045] The storage unit 200 stores a connection certificate 200a. The registration unit 201 requests the information processing device 10 to register the always-portable device 20, receives the connection certificate from the information processing device 10, and stores it in the storage unit 200. The connection processing unit 202 performs connection processing with the non-portable device 30 and establishes a communication path for communicating with the non-portable device 30. The transmission unit 203 transmits data to the information processing device 10 and the non-portable device 30. The reception unit 204 receives data from the information processing device 10 and the non-portable device 30.

[0046] (non-portable device) FIG. 6 is a diagram showing an example of a functional block configuration of the non-portable device 30. The non-portable device 30 includes a storage unit 300, a registration unit 301, a connection processing unit 302, a transmission unit 303, and a reception unit 304. The storage unit 300 can be realized using the storage unit 12 included in the non-portable device 30. The registration unit 301, the connection processing unit 302, the transmission unit 303, and the reception unit 304 can be realized by the processor 11 of the non-portable device 30 executing a program stored in the storage unit 12. The program can be stored in a storage medium. The storage medium storing the program may be a computer-readable non-transitory storage medium. The non-transitory storage medium is not particularly limited, and may be, for example, a storage medium such as a USB memory or a CD-ROM.

[0047] The storage unit 300 stores a connection certificate 300a. The registration unit 301 requests the information processing device 10 to register the non-portable device 30, receives the connection certificate from the information processing device 10, and stores it in the storage unit 300. The connection processing unit 302 performs connection processing between the always-portable device 20 and the data utilization device 40, and establishes a communication path for communicating with the always-portable device 20 and the data utilization device 40. The transmission unit 203 transmits data to the information processing device 10, the always-portable device 20, and the data utilization device 40. The reception unit 204 receives data from the information processing device 10, the always-portable device 20, and the data utilization device 40.

[0048] (Data utilization device) FIG. 7 is a diagram showing an example of a functional block configuration of the data utilization device 40. The data utilization device 40 includes a storage unit 400, a registration unit 401, a connection processing unit 402, a transmission unit 403, and a reception unit 404. The storage unit 300 can be realized using the storage device 12 provided in the data utilization device 40. The registration unit 401, the connection processing unit 402, the transmission unit 403, and the reception unit 404 can be realized by the processor 11 of the data utilization device 40 executing a program stored in the storage device 12. The program can be stored in a storage medium. The storage medium storing the program may be a computer-readable non-transitory storage medium. The non-transitory storage medium is not particularly limited, and may be, for example, a storage medium such as a USB memory or a CD-ROM.

[0049] The storage unit 400 stores a connection certificate 400a. The registration unit 401 requests the information processing device 10 to register the data utilization device 40, receives the connection certificate from the information processing device 10, and stores it in the storage unit 300. The connection processing unit 302 performs connection processing with the non-portable device 30, and establishes a communication path for communicating with the non-portable device 30. The transmission unit 203 transmits data to the information processing device 10 and the non-portable device 30. The reception unit 204 receives data from the information processing device 10 and the non-portable device 30.

[0050] <Processing Procedure> Next, the processing procedures performed by the information processing device 10 will be explained separately for the edge management method and the cloud management method.

[0051] (Edge management method: registration process) FIG. 8 is a sequence diagram showing an example of a processing procedure when the information processing device 10 registers the always-portable device 20. In FIG.

[0052] In step S10, the registration unit 201 of the always-portable device 20 transmits a registration request message to the information processing device 10. At this time, the registration request message may include information to be registered in "device information" of the always-portable device information 100a. Furthermore, when the always-portable device 20 wishes to provide second data to the data utilization device 40, it may transmit the first data and second data included in the registration request message to the information processing device 10. The registration unit 101 of the information processing device 10 associates the second data with the first data and registers the second data in the always-portable device information 100a.

[0053] In step S11, the registration unit 101 of the information processing device 10 registers device information of the always-on device 20 in the always-on device information 100a. At this time, the registration unit 101 generates an always-on device ID, a connection certificate (public key, private key), a first data encryption key, and a first data decryption key.

[0054] In step S12, the registration unit 101 transmits the always-portable device ID, the connection certificate (public key, private key), and the first data encryption key to the always-portable device 20. The registration unit 201 of the always-portable device 20 stores the always-portable device ID, the connection certificate (public key, private key), and the first data encryption key received from the information processing device 10 in the storage unit 200.

[0055] FIG. 9 is a sequence diagram showing an example of a processing procedure when the information processing device 10 registers the non-portable device 30. As shown in FIG.

[0056] In step S20, the registration unit 301 of the non-portable device 30 transmits a registration request message to the information processing device 10. At this time, the registration request message may include information to be registered in the "device information" of the non-portable device information 100b.

[0057] In step S21, the registration unit 101 of the information processing device 10 registers the device information of the non-portable device 30 in the non-portable device information 100b. At this time, the registration unit 101 generates a non-portable device ID and a connection certificate (public key, private key).

[0058] In step S22, the registration unit 101 transmits the non-portable device ID and the connection certificate (public key, private key) to the non-portable device 30. The registration unit 301 of the non-portable device 30 stores the non-portable device ID and the connection certificate (public key, private key) received from the information processing device 10 in the storage unit 300.

[0059] FIG. 10 is a sequence diagram showing an example of a processing procedure when the information processing device 10 registers the data utilization device 40.

[0060] In step S30, the registration unit 401 of the data utilization device 40 transmits a registration request message to the information processing device 10. At this time, the registration request message may include information to be registered in the "device information" of the data utilization device information 100c.

[0061] In step S31, the registration unit 101 of the information processing device 10 registers the device information of the data utilization device 40 in the data utilization device information 100c. At this time, the registration unit 101 generates a connection certificate (public key, private key) for the data utilization device 40.

[0062] In step S32, the registration unit 101 transmits the non-portable device ID and the connection certificate (public key, private key) to the data utilization device 40. The registration unit 401 of the data utilization device 40 stores the data utilization device ID and the connection certificate (public key, private key) received from the information processing device 10 in the storage unit 400.

[0063] Note that the generation of the connection certificate (public key, private key) may be omitted in the processing procedure of step S31. In this case, the transmission of the connection certificate (public key, private key) is omitted in the processing procedure of step S32.

[0064] (Edge management method: first data transmission process) FIG. 11 is a sequence diagram showing an example of a processing procedure when first data is transmitted from the always-portable device 20 to the information processing device 10. It is assumed that the always-portable device 20 has previously acquired from the information processing device 10 and stored therein the non-portable device IDs and connection certificates (public keys) of one or more non-portable devices 30 registered in the information processing device 10. It is also assumed that the non-portable device 30 has previously acquired from the information processing device 10 and stored therein the portable device IDs and connection certificates (public keys) of one or more always-portable devices 20 registered in the information processing device 10. It is also assumed that the data utilization device 40 has previously acquired from the information processing device 10 and stored therein the non-portable device IDs and connection certificates (public keys) of one or more non-portable devices 30 registered in the information processing device 10. It is also assumed that, when a connection certificate (public key, private key) has been generated for the data utilization device 40, the non-portable device 30 has previously acquired from the information processing device 10 and stored therein the data utilization device IDs and connection certificates (public keys) of one or more data utilization devices 40 registered in the information processing device 10. If a connection certificate (public key, private key) is not generated for the data utilization device 40, the non-portable device 30 is assumed to have previously obtained and stored the data utilization device IDs of one or more data utilization devices 40 registered in the information processing device 10 from the information processing device 10.

[0065] In step S40, the encryption processing unit 105 of the always-portable device 20 encrypts the first data to be transmitted to the data utilization device 40 via the non-portable device 30 using the first data encryption key.

[0066] In step S41, when the always-portable device 20 finds a non-portable device 30 with which to communicate, it authenticates the non-portable device 30 and establishes a communication path. For example, the always-portable device 20 transmits an always-portable device ID encrypted using its own private key to the non-portable device 30. The non-portable device 30 also transmits an encrypted non-portable device ID encrypted using its own private key to the always-portable device 20. The connection processing unit 202 of the always-portable device 20 may decrypt the encrypted non-portable device ID using a connection certificate (public key) of the non-portable device 30, and confirm whether the decrypted non-portable device ID matches the stored non-portable device ID, thereby confirming that the non-portable device 30 is a device registered in the information processing device 10. Furthermore, the connection processing unit 302 of the non-portable device 30 may use the connection certificate (public key) of the always-portable device 20 to decrypt the encrypted always-portable device ID and confirm whether the decrypted always-portable device ID matches the stored always-portable device ID, thereby confirming that the always-portable device 20 is a device registered with the information processing device 10. If the always-portable device 20 and the non-portable device 30 confirm that they are both registered with the information processing device 10, they establish a communication path (connect to each other). The communication path may be established using, for example, IPsec or SSL (Secure Sockets Layer). Note that in the processing procedure of step S41, the always-portable device 20 and the non-portable device 30 may confirm that they are both registered with the information processing device 10 by verifying encrypted verification values or predetermined certificate data using a predetermined method, instead of confirming the always-portable device ID or the non-portable device ID.

[0067] In step S42, the transmitting unit 104 of the always-on device 20 transmits to the non-portable device 30 a data transmission message including the encrypted first data and the always-on device ID.

[0068] In step S43, the receiving unit 204 of the non-portable device 30 stores the encrypted first data and the always-portable device ID in the storage unit 200.

[0069] In step S44, when the non-portable device 30 discovers the data utilization device 40 with which it will communicate, it authenticates the data utilization device 40 and establishes a communication path. The method by which the non-portable device 30 discovers the data utilization device 40 is not critical. For example, the non-portable device 30 transmits a non-portable device ID encrypted using its own private key to the data utilization device 40. Furthermore, the connection processing unit 402 of the data utilization device 40 transmits the data utilization device ID encrypted using its own private key to the non-portable device 30. The connection processing unit 302 of the non-portable device 30 may decrypt the encrypted data utilization device ID using the connection certificate (public key) of the data utilization device 40, and confirm whether the decrypted data utilization device ID matches the stored data utilization device ID, thereby confirming that the data utilization device 40 is a device registered in the information processing device 10. Furthermore, the data utilization device 40 may use the connection certificate (public key) of the non-portable device 30 to decrypt the encrypted non-portable device ID, and confirm whether the decrypted non-portable device ID matches the stored non-portable device ID, thereby confirming that the non-portable device 30 is a device registered with the information processing device 10. If the non-portable device 30 and the data utilization device 40 confirm that they are both devices registered with the information processing device 10, they establish a communication path (connect to each other). The communication path may be established using, for example, IPsec or SSL (Secure Sockets Layer), etc.

[0070] Note that if a connection certificate (public key, private key) is not generated for the data utilization device 40, the connection processing unit 402 of the data utilization device 40 may transmit a data utilization device ID to the non-portable device 30. Furthermore, the connection processing unit 302 of the non-portable device 30 may confirm that the data utilization device 40 is a device registered in the information processing device 10 by checking whether the received data utilization device ID matches the stored data utilization device ID. Furthermore, in the processing procedure of step S44, the non-portable device 30 and the data utilization device 40 may verify encrypted verification values or predetermined certificate data by a predetermined method, instead of checking the non-portable device ID or the data utilization device ID, to mutually confirm that they are devices registered in the information processing device 10.

[0071] In step S45, the non-portable device 30 transmits to the data utilizing device 40 a data transmission message including the encrypted first data, the always-on device ID, and the non-portable device ID.

[0072] In step S46, the transmitting unit 403 of the data utilizing device 40 transmits to the information processing device 10 a decryption request message including the encrypted first data, the always-portable device ID, the non-portable device ID, and the data utilizing device ID.

[0073] In step S47, the decryption processing unit 103 of the information processing device 10 acquires a first data decryption key by referring to the always-on device information 100a using the always-on device ID received in the processing procedure of step S46 as a key. Furthermore, the decryption processing unit 103 decrypts the encrypted first data received in the processing procedure of step S46 using the acquired first data decryption key.

[0074] In step S48, the transmission unit 104 of the information processing device 10 transmits the decrypted first data to the data utilizing device 40.

[0075] In step S49, the data utilizing device 40 performs various data processes using the received decrypted first data.

[0076] (Edge management method: Supplementary information regarding the first data transmission process) In the processing procedure described above, the decryption processing unit 103 may be configured to check whether the non-portable device ID received in the processing procedure of step S46 matches the non-portable device ID included in the non-portable device information 100b. If the received non-portable device ID matches the non-portable device ID included in the non-portable device information 100b, the decryption processing unit 103 may be configured to decrypt the encrypted first data. Alternatively, if the received non-portable device ID does not match the non-portable device ID included in the non-portable device information 100b, the decryption processing unit 103 may be configured to send an error message to the data utilization device 40 without decrypting the encrypted first data. This allows the information processing device 10 to check whether the encrypted first data was transmitted via a registered data utilization device 40, thereby improving security.

[0077] Furthermore, in the processing procedure described above, the data utilization device 40 may include a data utilization device ID in the decryption request message of step S46. Furthermore, the decryption processing unit 103 may check whether the non-portable device ID and the data utilization device ID received in the processing procedure of step S46 are included in the non-portable device information 100b and the data utilization device information 100c, respectively. The decryption processing unit 103 may decrypt the encrypted first data if the non-portable device ID and the data utilization device ID are included in the non-portable device information 100b and the data utilization device information 100c. On the other hand, if at least one of the non-portable device ID and the data utilization device ID is not included in the non-portable device information 100b and the data utilization device information 100c, the decryption processing unit 103 may send an error message to the data utilization device 40 without decrypting the encrypted first data. This allows the information processing device 10 to check whether the encrypted first data was transmitted via a registered data utilization device 40 and a registered data utilization device 40, thereby improving security.

[0078] Furthermore, when providing the second data, the information processing device 10 may acquire the first data and second data transmitted from the always-portable device 20 or the first data and second data input in advance by an administrator of the information processing device 10, and store them in the "first data" and "second data" of the always-portable device information 100a. Furthermore, in step S48, the transmitting unit 104 of the information processing device 10 may acquire second data corresponding to the decrypted first data by referring to the always-portable device information 100a, and transmit the acquired second data (or both the decrypted first data and the acquired second data) to the data utilization device 40.

[0079] (Cloud management method: registration process) FIG. 12 is a sequence diagram showing an example of a processing procedure when the information processing device 10 registers the always-portable device 20. In FIG.

[0080] The processing procedures of steps S50 and S51 are the same as the processing procedures of steps S10 and S11 in FIG. 8, respectively, and therefore will not be described again.

[0081] In step S52, the registration unit 101 transmits the always-portable device ID and the connection certificate (public key, private key) to the always-portable device 20. The registration unit 201 of the always-portable device 20 stores the always-portable device ID and the connection certificate (public key, private key) received from the information processing device 10 in the storage unit 200.

[0082] (Cloud management method: first data transmission process) FIG. 13 is a sequence diagram showing an example of a processing procedure when the always-portable device 20 transmits first data to the information processing device 10. As shown in FIG.

[0083] In step S60, the transmitting unit 203 of the always-on device 20 transmits the first data to the information processing device 10.

[0084] In step S61, the receiving unit 102 of the information processing device 10 stores the received first data in the constant portable device information 100a.

[0085] In step S62, the encryption processing unit 105 of the information processing device 10 encrypts the received first data.

[0086] In step S63, the transmitting unit 104 of the information processing device 10 constantly transmits the encrypted first data to the portable device 20.

[0087] The processing procedures of steps S71 to S79 are the same as the processing procedures of steps S41 to S49 in Fig. 11, respectively, and therefore will not be described again. Further, supplementary information regarding the first data transmission processing is also provided in the processing procedures in Fig. 13.

[0088] <Modification> (Variation 1) The registration unit 101 of the information processing device 10 may update the connection certificates of the always-portable device 20, the non-portable device 30, and the data utilization device 40 at predetermined intervals. Furthermore, the registration unit 101 may transmit the updated connection certificates to the always-portable device 20, the non-portable device 30, and the data utilization device 40. This allows the certificates to be updated, thereby improving security.

[0089] (Variation 2) The registration unit 101 of the information processing device 10 may be configured to update the first data encryption key and the first data decryption key of the constantly portable device 20 at a predetermined interval. The predetermined interval may be determined according to the risk level. If the risk level is higher than a predetermined standard, the registration unit 101 may be configured to update the first data encryption key and the first data decryption key every time the first data is transmitted. The registration unit 101 may also transmit the updated first data encryption key to the constantly portable device 20. This allows the encryption key and decryption key to be updated, thereby improving security.

[0090] (Variation 3) In the processing procedure of step S30 in Fig. 10, the data utilization device 40 may include information (e.g., connection information for connecting to the destination device, information for identifying the destination, etc.) related to the device that provides the first data or the second data (hereinafter referred to as "data destination device") in the registration request message. The data destination device is arbitrary, and may be, for example, a device of a payment service provider. Furthermore, the registration unit 101 of the information processing device 10 may register information related to the data destination device in the data utilization device information 100c.

[0091] In addition, after decrypting the encrypted first data in step S47 of Figure 11 (or step S77 of Figure 13), the information processing device 10 may, instead of executing the processing procedure of step S48 (or step S78), directly transmit the first data (or second data associated with the first data) to the data destination device based on information about the data destination device.

[0092] (Variation 4) 11, the data utilization device 40 may transmit information about the data destination device to the non-portable device 30. Furthermore, the non-portable device 30 may transmit a data transmission message including the encrypted first data, the always-portable device ID, the non-portable device ID, and information about the data destination device to the information processing device 10 without executing the processing procedure of step S45.

[0093] In addition, after decrypting the encrypted first data in step S47 of Figure 11 (or step S77 of Figure 13), the information processing device 10 may, instead of executing the processing procedure of step S48 (or step S78), transmit the first data (or second data associated with the first data) to the data destination device based on information about the data destination device.

[0094] <Summary> According to the embodiment described above, when data is transmitted from the always-portable device 20 to the data utilization device 40 via the non-portable device 30, the information processing system 1 transmits encrypted data to the data utilization device 40 via the non-portable device 30. This makes it possible to provide a technology that enables data to be transmitted securely.

[0095] The above-described embodiments are intended to facilitate understanding of the present invention and are not intended to limit the present invention. The flowcharts, sequences, elements included in the embodiments, and their arrangements, materials, conditions, shapes, sizes, etc., described in the embodiments are not limited to those illustrated and can be modified as appropriate. Furthermore, configurations shown in different embodiments can be partially substituted or combined with each other. [Explanation of symbols]

[0096] 1 Information processing system, 10 Information processing device, 11 Processor, 12 Storage device, 13 Communication IF, 14 Input device, 15 Output device, 20 Always-portable device, 30 Non-portable device, 40 Data utilization device, 100 Storage unit, 100a Always-portable device information, 100b Non-portable device information, 100c Data utilization device information, 101 Registration unit, 102 Receiving unit, 103 Decryption processing unit, 104 Transmission unit, 105 Encryption processing unit, 200 Storage unit, 201 Registration unit, 202 Connection processing unit, 203 Transmission unit, 204 Receiving unit, 300 Storage unit, 301 Registration unit, 302 Connection processing unit, 303 Transmission unit, 304 Receiving unit, 343 Transmission unit, 400 Storage unit, 401 Registration unit, 402 Connection processing unit, 403 Transmission unit, 404 Receiving unit

Claims

1. a storage unit that stores a decryption key for decrypting data encrypted with a user's encryption key; a receiving unit that receives a decryption request from a data utilization device, the decryption request including encrypted first data encrypted with the encryption key of the user, the encrypted first data included in the decryption request being transmitted from a first device utilized by the user and being acquired by the data utilization device via a second device different from the first device; a decryption processing unit that decrypts the encrypted first data with the decryption key of the user; a transmitting unit that transmits the decrypted first data to the data utilizing device; An information processing device having the above.

2. the transmitting unit transmits the encryption key of the user to the first device; The information processing device according to claim 1 .

3. the storage unit stores the first data and the encryption key of the user; the information processing device further includes an encryption processing unit that encrypts the first data with the encryption key of the user to generate the encrypted first data; The transmission unit transmits the encrypted first data to the first device. The information processing device according to claim 1 .

4. the storage unit stores the second data in association with the first data; the transmitting unit, when the decrypted first data matches the first data stored in the storage unit, transmits the second data corresponding to the first data to the data utilization device. The information processing device according to claim 1 .

5. the storage unit stores an identifier of the second device; the receiving unit receives the decryption request including the encrypted first data and an identifier of the second device from the data utilization device; the decryption processing unit decrypts the encrypted first data when the received identifier of the second device matches the identifier of the second device stored in the storage unit, and does not decrypt the encrypted first data when the identifier of the second device does not match the identifier of the second device stored in the storage unit. The information processing device according to claim 1 .

6. a registration unit that, when receiving a registration request from the first device, transmits to the first device a first digital certificate corresponding to the first device and a private key corresponding to the first digital certificate, which are used when the first device communicates with the second device; The information processing device according to claim 1 .

7. a registration unit that, when receiving a registration request from the second device, transmits to the second device a second electronic certificate corresponding to the second device and a private key corresponding to the second electronic certificate, which are used when the second device communicates with the first device or the data utilization device; The information processing device according to claim 1 .

8. An information processing method executed by an information processing device, comprising: storing a decryption key in a storage unit for decrypting data encrypted with the user's encryption key; receiving a decryption request from a data utilization device, the decryption request including encrypted first data encrypted with the encryption key of the user, wherein the encrypted first data included in the decryption request is transmitted from a first device utilized by the user and acquired by the data utilization device via a second device different from the first device; decrypting the encrypted first data with the decryption key of the user; transmitting the decrypted first data to the data utilizing device; An information processing method, including:

9. On the computer, storing a decryption key in a storage unit for decrypting data encrypted with the user's encryption key; receiving a decryption request from a data utilization device, the decryption request including encrypted first data encrypted with the encryption key of the user, wherein the encrypted first data included in the decryption request is transmitted from a first device utilized by the user and acquired by the data utilization device via a second device different from the first device; decrypting the encrypted first data with the decryption key of the user; transmitting the decrypted first data to the data utilizing device; A program to execute.

Citation Information

Patent Citations

  • Information convenience store system

    JP2004110534A

  • Contents distribution system, contents distribution method, communication terminal, program and storage medium

    JP2004240655A

  • Method and system for secure transmission of remote notification service messages to mobile devices without secure elements

    JP2019004474A

  • Anytime validation for verification tokens

    US20110173684A1

  • B2b payment agency system

    JP2022159160A