Data acquisition device and program

The NTFS file system-based data acquisition device simplifies data tampering detection by storing hash values in invisible areas, facilitating easy comparison and preventing fraud without encryption.

JP7731738B2Active Publication Date: 2025-09-01TOSHIBA TEC KK
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2021143711
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-03
Publication Date
2025-09-01
Estimated Expiration
2041-09-03

AI Technical Summary

Technical Problem

Existing data tampering detection methods require encryption of hash values, necessitating the creation of private and public keys, which are time-consuming and complex.

Method used

A data acquisition device and program that utilizes the NTFS file system to store data and tampering judgment information in separate streams, allowing for easy detection of data tampering by comparing hash values without encryption.

Benefits of technology

Enables efficient and straightforward detection of data tampering by comparing hash values stored in visible and invisible areas of files, preventing fraud and reducing complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007731738000001
    Figure 0007731738000001
  • Figure 0007731738000002
    Figure 0007731738000002
  • Figure 0007731738000003
    Figure 0007731738000003
Patent Text Reader

Abstract

To provide a data providing device, a data acquisition device, and a program that allow an easy detection of data falsification.SOLUTION: In a data providing device (settlement management server), a control unit includes: a management unit that manages data; an extraction unit that extracts, from the data managed by the management unit, provision data that is to be provided to an external device; a determination information generation unit that generates falsification determination information for determining whether the provision data has been falsified, based on the provision data extracted by the extraction unit; an integrated data generation unit that makes the falsification determination information generated by the determination information generation unit invisible and generates integrated data by integrating it with the provision data; and an output unit that outputs the integrated data generated by the integrated data generation unit, to the external device.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] An embodiment of the present invention comprises: Data Acquisition Equipment and regarding the program. [Background technology]

[0002] Conventionally, technologies have been adopted to detect tampering of electronic data (hereinafter simply referred to as "data"). For example, a known technology uses hash values ​​to detect tampering in order to confirm that data has not been tampered with in the process in which a data user obtains the data from a provider.

[0003] According to this conventional technology, the provider generates a hash value based on the data to be provided, encrypts the hash value with a private key, and transmits the data and the hash value to the user. The user decrypts the received hash value with a public key and generates a hash value based on the received data. The decrypted hash value is then compared with the generated hash value, and if the two match, it is determined that the data has not been tampered with. The encrypted hash value is used to prevent the hash value from being tampered with along with the data during the process of the user obtaining the data.

[0004] However, in the above-mentioned conventional technology, since the hash value is encrypted, it is necessary to create a private key for encryption and a public key for decryption. In addition, the public key must be provided to the user in advance. Therefore, the above-mentioned conventional technology is time-consuming, and there is a need for an easy method of detecting data tampering. Summary of the Invention [Problem to be solved by the invention]

[0005] The problem that the present invention aims to solve is to provide a system that can easily detect data tampering. Data Acquisition Equipment and to provide programs. [Means for solving the problem]

[0007] The data acquisition device according to the embodiment includes: a communication unit that communicates with an external device; Stored in the mainstream NTFS file system Provided data and information for determining whether the provided data has been tampered with, By storing the data in an alternate data stream of the NTFS file system that is different from the main stream, the first tampering judgment information that has been made invisible is matched with the second tampering judgment information generated by the judgment information generation unit; a data acquisition unit that acquires the provided data when the first tampering judgment information matches the second tampering judgment information generated by the judgment information generation unit as a result of the judgment by the judgment unit; and an error information transmission unit that transmits error information to the external device when the first tampering judgment information does not match the second tampering judgment information as a result of the judgment by the judgment unit. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 is a diagram illustrating an outline of a data tampering prevention system according to an embodiment. [Figure 2] FIG. 2 is a diagram illustrating the data structure of the integrated data according to the embodiment. [Figure 3] FIG. 3 is a block diagram illustrating a hardware configuration of the data providing device according to the embodiment. [Figure 4] FIG. 4 is a block diagram illustrating a functional configuration of the control unit of the data providing device according to the embodiment. [Figure 5] FIG. 5 is a block diagram illustrating a hardware configuration of the data acquisition device according to the embodiment. [Figure 6] FIG. 6 is a block diagram illustrating a functional configuration of the control unit of the data acquisition device according to the embodiment. [Figure 7] FIG. 7 is a flowchart showing the flow of the output process by the control unit of the data providing device according to the embodiment. [Figure 8]FIG. 8 is a flowchart showing the flow of the import process performed by the control unit of the data acquisition device according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0009] Hereinafter, a data providing device, a data acquiring device, and a program according to an embodiment will be described with reference to the drawings. Note that the present invention is not limited to the embodiments described below. For example, in the embodiments described below, an example will be described in which the data providing device is a payment management server installed in a payment center and the data acquiring device is a sales management server installed in a shopping center operating company (hereinafter simply referred to as "operating company"), but the present invention is not limited to this. The data providing device and data acquiring device can be widely used in other fields.

[0010] 1 is a diagram showing an outline of a tampering prevention system including a data providing device and a data acquiring device. The tampering prevention system 1 of the embodiment is applied to an operating company of a shopping center in which multiple stores are located and a payment center that processes cashless payments for transactions at each store in the shopping center.

[0011] The tampering prevention system 1 comprises a payment management server 2, a download PC (Personal Computer) 3, an upload PC 4, and a sales management server 5. The payment management server 2 is installed in the payment center of a payment company. The download PC 3, upload PC 4, and sales management server 5 are installed in an operating company.

[0012] The payment management server 2 is connected to payment terminals 6 provided in each store in the shopping center via a network such as the Internet. Based on information from each payment terminal 6, the payment management server 2 executes payment processing related to cashless payments using electronic money, two-dimensional codes, credit cards, etc., and manages information related to the executed payment processing. Note that the payment management server 2 may also be configured to only manage information related to payment processing without executing the payment processing.

[0013] The payment management server 2 is also connected to the download PC 3 via a network such as the Internet. In response to a request from the download PC 3, the payment management server 2 transmits (provides) payment data related to the operating company that manages the download PC 3 to the download PC 3. In this embodiment, the payment management server 2 provides the payment data to the download PC 3 via a network, but the data may also be provided using a storage medium. The payment management server 2 is an example of a data providing device.

[0014] The download PC 3 transmits a request to output payment data to the payment management server 2 and downloads the payment data from the payment management server 2 .

[0015] The upload PC 4 is connected to the sales management server 5 via a dedicated line and, together with the sales management server 5, constitutes a sales management system within the operating company. The upload PC 4 is a PC dedicated to the sales management system and is installed in an environment isolated from public lines such as the Internet. The upload PC 4 acquires the payment data received by the download PC 3 from the payment management server 2 via, for example, a USB (Universal Serial Bus) memory, and uploads it to the sales management server 5.

[0016] The sales management server 5 manages the sales of each store in the shopping center. The sales management server 5 acquires payment data related to cashless payments from the upload PC 4, and also acquires payment data for cash payments separately. The sales management server 5 manages the sales data of each store in the shopping center based on the acquired payment data. The sales management server 5 is an example of a data acquisition device.

[0017] The operating company performs various processes based on the sales data managed by the sales management server 5. For example, the operating company checks the sales amounts reported separately from each store based on the sales data managed by the sales management server 5. The operating company also calculates the rent for each store opening in the shopping center based on the sales data managed by the sales management server 5.

[0018] In the tampering prevention system 1, when the payment management server 2 receives a request for payment data from the download PC 3, it extracts payment data related to the operating company that manages the download PC 3. In other words, the payment management server 2 extracts, from the payment data it manages, payment data for each store in the shopping center operated by the operating company that requested the payment data. The extracted payment data is an example of provided data that the data providing device provides to an external device.

[0019] The payment management server 2 generates a hash value of the extracted payment data. The hash value is generated using a hash function. The generated hash value is an example of tampering determination information. The hash value generated by the payment management server 2 constitutes first tampering determination information. In the following description, the hash value generated by the payment management server 2 may be referred to as the "first hash value." The payment management server 2 integrates the payment data and the first hash value into a single file and sends it to the download PC 3. The file containing the payment data and the hash value is an example of integrated data.

[0020] A file is a unit of data management in a computer. Files are managed by a file system, which is part of a computer's operating system (OS).

[0021] The file sent to the download PC 3 has payment data written (stored) in the visible area and the first hash value written in the invisible area. The data written in the visible area can be displayed by normal computer operation. In contrast, the data written in the invisible area is not displayed by normal computer operation, but can be displayed by executing a special command.

[0022] The visible area of ​​a file corresponds to the main stream in an NTFS (registered trademark) file system, for example, and the invisible area of ​​a file corresponds to an alternate data stream in an NTFS file system, for example.

[0023] Figure 2 shows the data structure of the integrated data. In this embodiment, the NTFS file system is used. The integrated data is composed of one file, with payment data stored in the main stream, which is the visible area, and a first hash value generated by the payment management server 2 stored in the alternative data stream, which is the invisible area.

[0024] The download PC 3 downloads a file containing the payment data and the first hash value. An employee of the operating company stores the downloaded file on a USB memory stick and transfers the data to the upload PC 4. The upload PC 4 reads the file from the USB memory stick and uploads it to the sales management server 5. At this time, the upload PC 4 can display the payment data but not the first hash value.

[0025] The sales management server 5 reads the first hash value from the invisible area of ​​the uploaded file. The sales management server 5 also reads the payment data from the visible area of ​​the uploaded file and creates a hash value of the payment data using a hash function. The hash value generated by the sales management server 5 constitutes second tampering determination information. In the following description, the hash value generated by the sales management server 5 may be referred to as the "second hash value." Note that the hash function used by the sales management server 5 to generate the second hash value is the same as the hash function used by the payment management server 2 to generate the first hash value. Therefore, if the payment data is the same, the first hash value generated by the payment management server 2 and the second hash value generated by the sales management server 5 will be the same.

[0026] The sales management server 5 compares the first tampering determination information, i.e., the first hash value written in the file, with the second tampering information, i.e., the second hash value generated by the sales management server 5 based on the payment data written in the file. This allows the sales management server 5 to determine whether the uploaded payment data is payment data downloaded from the payment management server 2 that has been tampered with.

[0027] If the first hash value and the second hash value match, the sales management server 5 determines that the payment data downloaded from the payment management server 2 has not been tampered with, and imports the payment data into the sales data management file 512 (see FIG. 5) that it manages. If the first hash value and the second hash value do not match, the sales management server 5 determines that the payment data downloaded from the payment management server 2 has been tampered with or corrupted, and does not import the payment data. The sales management server 5 then sends an error message to, for example, the upload PC 4. Preventing the import of tampered payment data can prevent fraud, for example, through collaboration between some employees of the operating company and stores.

[0028] Next, the configuration and functions of the payment management server 2 will be described in detail. Fig. 3 is a block diagram showing the main hardware configuration of the payment management server 2. The payment management server 2 includes a control unit 20, a memory unit 21, a display unit 22, an operation input unit 23, and a communication unit 24. The control unit 20, the memory unit 21, the display unit 22, the operation input unit 23, and the communication unit 24 are connected to each other via a bus 25 or the like.

[0029] The control unit 20 is configured as a computer including a CPU (Central Processing Unit) 201, a ROM (Read Only Memory) 202, and a RAM (Random Access Memory) 203. The CPU 201, the ROM 202, and the RAM 203 are connected to each other via a bus 25.

[0030] The CPU 201 controls the overall operation of the payment management server 2. The ROM 202 stores various programs and various data, such as programs used to drive the CPU 201. The RAM 203 is used as a work area for the CPU 201, and loads various programs and data stored in the ROM 202 and the memory unit 21. The control unit 20 executes various control processes of the payment management server 2 by the CPU 201 operating in accordance with the control programs stored in the ROM 202 and the memory unit 21 and loaded in the RAM 203.

[0031] The memory unit 21 is configured with a storage medium such as a hard disk drive (HDD) or flash memory, and maintains its stored contents even when the power is cut off. The memory unit 21 stores a control program 211 and a payment data management file 212.

[0032] The control program 211 includes a program for executing payment processing based on information received from the store's payment terminal 6, a program for managing payment data, a program for generating hash values ​​and generating integrated data, and other programs that cause the payment management server 2 to function as a data providing device.

[0033] The payment data management file 212 is a file that manages payment data related to cashless payments processed using information from the payment terminal 6 of each store. The payment data management file 212 stores, for example, for each transaction, information indicating the store, the shopping center to which the store belongs, the product to be transacted, the total amount, the payment method, etc., in association with each other. Note that the memory unit 21 may be an external memory accessible by the payment management server 2.

[0034] The display unit 22 is configured with a liquid crystal panel or the like, and displays various information. For example, the display unit 22 displays an input screen for inputting various information.

[0035] The operation input unit 23 is composed of a keyboard and a touch panel provided on the surface of the display unit 22. The operation input unit 23 inputs various information to the control unit 20 based on operations by the operator.

[0036] The communication unit 24 is an interface for communicating with external devices such as the download PC 3 and the payment terminal 6. The control unit 20 is connected to the external devices via the communication unit 24, thereby enabling transmission and reception of information (data) with the external devices.

[0037] Next, the functional configuration of the control unit 20 of the payment management server 2 will be described. Fig. 4 is a block diagram showing the main functional configuration of the control unit 20 of the payment management server 2. The control unit 20 functions as a reception unit 2001, a management unit 2002, an extraction unit 2003, a first determination information generation unit 2004, an integrated data generation unit 2005, and an output unit 2006, as a result of the CPU 201 operating in accordance with a control program stored in the ROM 202 or memory unit 21. Note that each of these functions may be configured using hardware such as a dedicated circuit.

[0038] The reception unit 2001 receives a request for payment data from the download PC 3. The request for payment data includes information identifying the download PC 3, information identifying the operating company, information identifying the shopping center operated by the operating company, and information indicating the period for the requested payment data. The reception unit 2001 also receives a request for payment processing from the payment terminal 6 of each store. The request for payment processing includes customer information such as credit information, information indicating the total amount of one transaction, information indicating the transaction store, and information indicating the payment method. Note that if the payment management server 2 does not execute the payment processing, the reception unit 2001 receives payment information from the payment device that executed the payment processing.

[0039] The management unit 2002 manages data. Specifically, the management unit 2002 updates the payment data management file 212 based on payment information related to a payment processed in response to a payment processing request accepted by the acceptance unit 2001. Furthermore, if the payment management server 2 does not execute the payment processing, the management unit 2002 updates the payment data management file 212 based on the payment information accepted by the acceptance unit 2001.

[0040] The extraction unit 2003 extracts data to be provided to an external device from the data managed by the management unit 2002. Specifically, the extraction unit 2003 extracts payment data from the payment data management file 212 based on a payment data output request received by the reception unit 2001 from the download PC 3. The extraction unit 2003 extracts, from the payment data management file 212, payment data related to the shopping center specified in the payment data output request, which corresponds to the period specified in the output request. Note that the payment data output request may include information specifying the store instead of information specifying the shopping center. In this case, the extraction unit 2003 can extract payment data from the payment data management file 212 using the store as a key. The payment data extracted by the extraction unit 2003 is provided to the sales management server 5, an external device, via the download PC 3, upload PC 4, etc.

[0041] The first judgment information generation unit 2004 generates tampering judgment information for judging whether the provided data has been tampered with, based on the provided data extracted by the extraction unit 2003. Specifically, the first judgment information generation unit 2004 generates a first hash value using a hash function for the payment data extracted by the extraction unit 2003. The generation of the hash value using the hash function is performed by a known method.

[0042] The integrated data generation unit 2005 converts the tampering judgment information generated by the judgment information generation unit (first judgment information generation unit 2004) into invisible data and integrates it with the provided data to generate integrated data. Specifically, the integrated data generation unit 2005 writes the first hash value generated by the first judgment information generation unit 2004 into an alternative data stream of the file that is the integrated data, thereby converting the first hash value into invisible data. The integrated data generation unit 2005 also writes the payment data extracted by the extraction unit 2003 into the main stream of the file. As a result, the payment data is written in the visible area, and the first hash value is written in the invisible area, generating an output file that is the integrated data.

[0043] The output unit 2006 outputs to an external device the integrated data generated by the integrated data generation unit 2005. Specifically, the output unit 2006 transmits to the download PC 3 a file generated by the integrated data generation unit 2005, the file including the payment data and the first hash value requested by the download PC 3.

[0044] Next, the configuration and functions of the sales management server 5 will be described in detail. Figure 5 is a block diagram showing the main hardware configuration of the sales management server 5. The sales management server 5 comprises a control unit 50, a memory unit 51, a display unit 52, an operation input unit 53, and a communication unit 54. The control unit 50, the memory unit 51, the display unit 52, the operation input unit 53, and the communication unit 54 are connected to each other via a bus 55 or the like.

[0045] The control unit 50 is configured by a computer including a CPU 501, a ROM 502, and a RAM 503. The CPU 501, the ROM 502, and the RAM 503 are connected to one another via a bus 55.

[0046] The CPU 501 controls the overall operation of the sales management server 5. The ROM 502 stores various programs and various data, such as programs used to drive the CPU 501. The RAM 503 is used as a work area for the CPU 501, and expands the various programs and data stored in the ROM 502 and the memory unit 51. The control unit 50 executes various control processes of the sales management server 5 by the CPU 501 operating in accordance with the control programs stored in the ROM 502 and the memory unit 51 and expanded in the RAM 503.

[0047] The memory unit 51 is configured with a storage medium such as a HDD or flash memory, and maintains its stored contents even when the power is turned off. The memory unit 51 stores a control program 511 and a sales data management file 512.

[0048] The control program 511 includes a program for reading hash values ​​and payment data from files sent from the upload PC 4, a program for generating hash values ​​of the read payment data, and other programs that cause the sales management server 5 to function as a data acquisition device.

[0049] The sales data management file 512 is a file that manages sales at each store in a shopping center operated by the operating company. The sales data management file 512 is updated based on payment data related to cashless payments obtained from the payment management server 2 and payment data related to cash payments obtained separately. The sales data management file 512 stores information indicating, for example, the store, date, daily sales amount, etc. in association with each other. The memory unit 51 may also be an external memory accessible by the sales management server 5.

[0050] The display unit 52 is configured with a liquid crystal panel or the like and displays various information. For example, the display unit 52 displays payment data read from a file received from the upload PC 4. The display unit 52 also displays an input screen for inputting various information.

[0051] The operation input unit 53 is composed of a keyboard and a touch panel provided on the surface of the display unit 52. The operation input unit 53 inputs various information to the control unit 50 based on operations by the operator.

[0052] The communication unit 54 is an interface for communicating with an external device such as the upload PC 4. By connecting the control unit 50 to an external device via the communication unit 54, the control unit 50 can send and receive information (data) to and from the external device.

[0053] Next, we will explain the functional configuration of the control unit 50 of the sales management server 5. Figure 6 is a block diagram showing the main functional configuration of the control unit 50 of the sales management server 5. The control unit 50 functions as an acquisition unit 5001, a second determination information generation unit 5002, a determination unit 5003, and a data acquisition unit 5004, as the CPU 501 operates in accordance with a control program stored in the ROM 502 or memory unit 51. Note that each of these functions may be configured using hardware such as a dedicated circuit.

[0054] The acquisition unit 5001 acquires integrated data that integrates provided data and first tampering determination information that is information for determining whether the provided data has been tampered with and that has been made invisible. Specifically, the acquisition unit 5001 acquires a file that is output from the payment management server 2 and that integrates payment data and a first hash value that is a hash value of the payment data. The file acquired by the acquisition unit 5001 is a file configured in NTFS format in which payment data is stored in the main stream, which is a visible area, and the first hash value is stored in the alternative data stream, which is an invisible area.

[0055] The second determination information generation unit 5002 generates second tampering determination information for determining whether the provided data has been tampered with, based on the provided data acquired by the acquisition unit 5001. Specifically, the second determination information generation unit 5002 reads payment data from the file acquired by the acquisition unit 5001 from the upload PC 4, and generates a second hash value. The second determination information generation unit 5002 generates the second hash value by using a hash function on the payment data read from the file.

[0056] The determination unit 5003 reads the first tampering determination information that has been made invisible, and determines whether it matches the second tampering determination information generated by the determination information generation unit. Specifically, the determination unit 5003 reads the first hash value generated by the payment management server 2 from the alternative data stream of the file acquired by the acquisition unit 5001. Then, the determination unit 5003 compares the first hash value read from the file with the second hash value generated by the second determination information generation unit 5002, and determines whether they match.

[0057] The data import unit 5004 imports the provided data when the determination unit 5003 determines that the first tampering determination information and the second tampering determination information match. Specifically, the data import unit 5004 determines that the payment data output from the payment management server 2 has not been tampered with when the first hash value read from the file matches the second hash value generated by the second determination information generation unit 5002. The data import unit 5004 then updates the sales data management file 512 based on the payment data included in the file. The data import unit 5004 also updates the sales data management file 512 based on the payment data related to cash payments separately acquired by the acquisition unit 5001.

[0058] Next, a description will be given of the processing of the control unit 20 of the payment management server 2. Fig. 7 is a flowchart showing the flow of output processing by the control unit 20 of the payment management server 2.

[0059] First, the accepting unit 2001 accepts a payment data request from the download PC 3 (step S1). The extracting unit 2003 extracts payment data corresponding to the shopping center and period specified in the payment data request from the payment data management file 212 (step S2).

[0060] The first determination information generation unit 2004 generates a first hash value based on the extracted payment data (step S3). Subsequently, the integrated data generation unit 2005 writes the payment data extracted by the extraction unit 2003 into the main stream, which is the visible area of ​​the output file (step S4).

[0061] Furthermore, the integrated data generation unit 2005 writes the first hash value generated by the first determination information generation unit 2004 to an alternative data stream, which is an invisible area of ​​the output file (step S5). Through the processing of steps S4 and S5, an output file is generated in which the payment data and the first hash value are integrated.

[0062] Next, the output unit 2006 transmits the output file generated by the integrated data generation unit 2005 to the download PC 3 that transmitted the output request for the payment data (step S6). Then, the control unit 20 ends the output process.

[0063] The above-described output process of the payment management server 2 allows the download PC 3 to obtain a file storing the payment data and the first hash value. At this time, the first hash value is written in an invisible area and is therefore not normally displayed on the download PC 3. This prevents an operator of the download PC 3 (such as an employee of the operating company) from noticing the first hash value and rewriting it.

[0064] Therefore, it is possible to prevent tampering of the first hash value in conjunction with tampering of the payment data. In other words, even if the payment data is tampered with, it is possible to prevent the first hash value from being rewritten with a hash value corresponding to the rewritten payment data, thereby making it possible to detect tampering of the payment data. Moreover, by utilizing the invisible area of ​​the file, there is no need to use encryption technology, making it easy to detect data tampering.

[0065] Next, a description will be given of the processing performed by the control unit 50 of the sales management server 5. Fig. 8 is a flowchart showing the flow of the import processing performed by the control unit 50 of the sales management server 5.

[0066] First, the acquiring unit 5001 acquires a file from the upload PC 4 (step S11). The acquiring unit 5001 receives from the upload PC 4 the file output by the payment management server 2, that is, the file storing the payment data and the first hash value.

[0067] The second determination information generating unit 5002 reads the payment data from the main stream, which is the visible area of ​​the file acquired by the acquiring unit 5001 (step S12), and generates a second hash value based on the read payment data (step S13). The second hash value is generated using the same hash function as the hash function used by the payment management server 2 when generating the first hash value.

[0068] Next, the determination unit 5003 reads the first hash value from the alternative data stream, which is the invisible area of ​​the file acquired by the acquisition unit 5001 (step S14).The determination unit 5003 then compares the first hash value with the second hash value (step S15) and determines whether the two hash values ​​match (step S16).

[0069] If the first hash value and the second hash value match (Y in step S16), the data import unit 5004 imports the payment data read from the file (step S17). That is, the sales data management file 512 is updated based on the payment data read from the file. Then, the control unit 50 ends the import process.

[0070] If the first hash value and the second hash value do not match (N in step S16), the control unit 50 sends error information to the upload PC 4 (step S18). The error information sent to the upload PC 4 indicates that the uploaded payment data has been tampered with or corrupted and is therefore inappropriate. The control unit 50 ends the import process once the error transmission is complete.

[0071] By the above-mentioned import process, the sales management server 5 can import the payment data output by the payment management server 2, and can prevent the import of tampered or damaged payment data.

[0072] As described above, the data providing device of the above embodiment comprises a management unit 2002 that manages data, an extraction unit 2003 that extracts provided data to be provided to an external device from the data managed by the management unit 2002, a judgment information generation unit (first judgment information generation unit 2004) that generates tampering judgment information for determining whether the provided data has been tampered with based on the provided data extracted by the extraction unit 2003, an integrated data generation unit 2005 that converts the tampering judgment information generated by the judgment information generation unit into invisible data and integrates it with the provided data to generate integrated data, and an output unit 2006 that outputs the integrated data generated by the integrated data generation unit 2005 to an external device (sales management server 5).

[0073] This prevents the tampering determination information from being rewritten by the data recipient. Therefore, by using the data providing device of the above embodiment, tampering of the provided data can be easily detected without using encryption technology or the like.

[0074] Furthermore, the integrated data generating unit 2005 of the data providing device of the above embodiment generates a file that stores the provided data in the visible area and stores the tampering determination information in the invisible area.

[0075] This makes it possible to detect tampering with the provided data by utilizing the invisible area of ​​the file, making it easier to detect tampering with the provided data.

[0076] In addition, the data acquisition device of the above embodiment includes an acquisition unit 5001 that acquires integrated data that integrates provided data and first tampering judgment information that is information for determining whether the provided data has been tampered with and that has been made invisible, a judgment information generation unit (second judgment information generation unit) that generates second tampering judgment information for determining whether the provided data has been tampered with based on the provided data acquired by the acquisition unit 5001, and a judgment unit 5003 that reads the first tampering judgment information that has been made invisible and determines whether it matches the second tampering judgment information generated by the judgment information generation unit.

[0077] This allows the data acquisition device to easily detect tampering with the provided data without using encryption technology or the like.

[0078] In addition, the data acquisition device of the above embodiment further includes a data acquisition unit 5004 that acquires the provided data when the determination unit 5003 determines that the first tampering determination information and the second tampering determination information match.

[0079] This allows the data acquisition device to acquire the provided data on the condition that the provided data has not been tampered with, thereby preventing the acquisition of tampered provided data.

[0080] In the above embodiment, the control programs executed by the payment management server 2, which is the data providing device, and the sales management server 5, which is the data acquiring device, may be configured to be recorded on a computer-readable recording medium such as a CD-ROM and provided. Also, the control programs executed by the payment management server 2 and the sales management server 5 in the above embodiment may be configured to be stored on a computer connected to a network such as the Internet and provided by being downloaded via the network, or may be configured to be provided via a network such as the Internet.

[0081] Although the embodiment of the present invention has been described above, this embodiment is presented as an example and is not intended to limit the scope of the invention. This embodiment can be implemented in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. [Explanation of symbols]

[0082] 2. Payment management server (data provider) 5. Sales management server (data acquisition device) 2002 Management Department 2003 Extraction part 2004 First judgment information generation unit (judgment information generation unit) 2005 Integrated Data Generation Department 2006 Output section 5001 Acquisition Department 5002 Second judgment information generation unit (judgment information generation unit) 5003 Judgment section 5004 Data Acquisition Unit [Prior art documents] [Patent documents]

[0083] [Patent Document 1] Japanese Patent Application Laid-Open No. 2008-269544

Claims

1. a communication unit for communicating with an external device; an acquisition unit that acquires from the external device integrated data that integrates provided data stored in a main stream of an NTFS file system and first tampering determination information, which is information for determining whether the provided data has been tampered with and is made invisible by being stored in an alternative data stream of the NTFS file system that is different from the main stream; a determination information generating unit that generates second tampering determination information for determining whether or not the provided data has been tampered with, based on the provided data acquired by the acquiring unit; a determination unit that reads the first tampering determination information that has been made invisible and determines whether it matches the second tampering determination information generated by the determination information generation unit; a data acquisition unit that acquires the provided data when the first tampering determination information and the second tampering determination information match as a result of the determination by the determination unit; an error information transmitting unit that transmits error information to the external device when the first tampering determination information and the second tampering determination information do not match as a result of the determination by the determining unit; A data acquisition device comprising:

2. A program for controlling a computer of a data acquisition device having a communication unit that communicates with an external device, The computer an acquisition unit that acquires from the external device integrated data that integrates provided data stored in a main stream of an NTFS file system and first tampering determination information, which is information for determining whether the provided data has been tampered with and is made invisible by being stored in an alternative data stream of the NTFS file system that is different from the main stream; a determination information generating unit that generates second tampering determination information for determining whether or not the provided data has been tampered with, based on the provided data acquired by the acquiring unit; a determination unit that reads the first tampering determination information that has been made invisible and determines whether it matches the second tampering determination information generated by the determination information generation unit; a data acquisition unit that acquires the provided data when the first tampering determination information and the second tampering determination information match as a result of the determination by the determination unit; an error information transmitting unit that transmits error information to the external device when the first tampering determination information and the second tampering determination information do not match as a result of the determination by the determining unit; A program to make it function as such.

Citation Information

Patent Citations

  • Document distribution method and document management method

    JP2008219875A

  • Using object information management device, using object information management method, and program therefor

    JP2008269544A

  • Digital watermark generating apparatus, electronic-watermark verifying apparatus, method of generating digital watermark, and method of verifying digital watermark

    JP2011155323A

  • Information management terminal equipment

    JP2018156633A

  • Alternate data stream cache for file classification

    US20110099152A1