Information management method and information management system
The method and system use homomorphic encryption to securely aggregate information across a supply chain, addressing the reluctance of traders to disclose data, enabling comprehensive supply chain information management while maintaining confidentiality.
Patent Information
- Application Number
- JP2024558691
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-11-17
- Filing Date
- 2023-10-11
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2043-10-11
AI Technical Summary
Individual traders in a supply chain are reluctant to disclose their information, making it difficult to obtain comprehensive information about the entire supply chain using conventional cryptographic systems.
An information management method and system utilizing homomorphic encryption to securely share and calculate item-related information among traders, ensuring that only cumulative results are decrypted, maintaining confidentiality of individual trader data.
Enables the aggregation of information across the supply chain while keeping individual trader data confidential, allowing for the calculation of carbon footprints and other item-related information without disclosing sensitive details.
Smart Images

Figure 0007772253000002 
Figure 0007772253000003 
Figure 0007772253000004
Abstract
Description
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application is based on Patent Application No. 2022-184387 filed in Japan on November 17, 2022, and the contents of the original application are incorporated by reference in their entirety. [Technical Field]
[0002] TECHNICAL FIELD This disclosure relates to the art of information management. [Background technology]
[0003] Patent Document 1 discloses a supply chain management method for managing transaction records between multiple traders in a supply chain constructed including multiple traders.
[0004] Furthermore, Patent Document 2 discloses an encryption system that performs homomorphic operations on encrypted data encrypted with a user public key and is capable of decrypting the results of the homomorphic operations using a master private key. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] International Publication No. 2021 / 002226 [Patent Document 2] Japanese Patent Application Publication No. 2018-36418 Summary of the Invention
[0006] Individual traders who build a supply chain such as that disclosed in Patent Document 1 generally do not want to disclose information to the outside. Therefore, it can be difficult to obtain information about the entire supply chain by receiving information from all traders. Therefore, it has been considered to obtain information about the entire supply chain by using homomorphic operations such as those used in the encryption system of Patent Document 2.
[0007] However, simply using the conventional cryptographic system disclosed in Patent Document 2 for supply chain information management makes it difficult to prevent individual traders from disclosing their information to the outside world and to obtain information about the entire supply chain.
[0008] The present disclosure aims to provide an information management method and information management system that can obtain information about the entire supply chain while keeping information about individual traders confidential.
[0009] In order to achieve the above-mentioned object, one disclosed aspect is an information management method that is implemented by a computer and manages information linked to each of multiple traders that make up a supply chain, and includes the steps of: preparing a private key and a public key based on homomorphic encryption, sharing the public key among multiple traders, obtaining acquired cryptographic information encrypted using the public key at a front-side trader that is a front-side trader that supplies the delivery items, preparing generated cryptographic information that is encrypted using the public key to obtain item-related information related to the action to be taken on the delivery items, and providing the secret calculation result obtained by secret calculation using the acquired cryptographic information and the generated cryptographic information as information to be provided to a back-side trader that is a next-side trader that provides the shipping items.
[0010] Another disclosed aspect is an information management system that manages information linked to each of multiple traders that make up a supply chain, and includes a key generation unit that prepares a private key and a public key based on homomorphic encryption and shares the public key among the multiple traders, an information acquisition unit that acquires acquired cryptographic information encrypted using the public key by a previous trader that is a previous process trader that supplies the delivery items, an information generation unit that prepares generated cryptographic information that is encrypted using the public key from item-related information related to the treatment to be performed on the delivery items, and an information provision unit that provides the secret calculation result obtained by secret calculation using the acquired cryptographic information and the generated cryptographic information as information to be provided to a subsequent trader that is a next process trader that provides the shipping items.
[0011] In these embodiments, acquired cryptographic information encrypted by the earlier transactor providing the delivery item and generated cryptographic information encrypted with item-related information related to the action to be taken on the delivery item are used in a secret computation to calculate a secret computation result. The secret computation result is then provided to the later transactor to which the shipping item is supplied. As described above, even if the later transactor holds the private key, the acquired cryptographic information and generated cryptographic information encrypted by the earlier transactor are not provided to the later transactor, so the item-related information of the earlier transactor and the item-related information of the current transactor are not disclosed to the later transactor. In addition, as the transaction progresses, the generated cryptographic information of each transactor is added to the secret computation result, so the holder of the private key can obtain information about the entire supply chain by decrypting the cumulative secret computation results.
[0012] Therefore, information on the entire supply chain can be obtained while keeping information on individual traders confidential.
[0013] It should be noted that the reference numerals in parentheses in the claims merely indicate examples of correspondence with specific configurations in the embodiments described below, and do not limit the technical scope in any way. Furthermore, claims not explicitly stated in the claims may be combined together unless there is a particular problem with the combination. [Brief explanation of the drawings]
[0014] [Figure 1] FIG. 2 is a diagram for explaining the operation of public keys and private keys in a supply chain in the first embodiment of the present disclosure. [Figure 2] FIG. 1 is a diagram showing an overview of a supply chain management system. [Figure 3] 10 is a flowchart showing details of a key sharing process in which a public key generated in a process is provided to a transactor in a previous process. [Figure 4] 10 is a flowchart showing details of a key sharing process in which a public key acquired from a subsequent process is provided to a transactor in a previous process. [Figure 5]10 is a flowchart showing details of a secure computation process for calculating cumulative carbon emissions by secure computation. [Figure 6] 10 is a flowchart showing the details of a decoding and summing process for decoding the cumulative carbon emission amount up to the previous process and adding the carbon emission amount in the current process. [Figure 7] 10 is a flowchart showing details of the process of registering information acquired from a trader terminal, among the management server processes performed by the information management server. [Figure 8] 10 is a flowchart showing details of a process of providing registration information to an information browsing server, which is part of the management server process; [Figure 9] FIG. 10 is a diagram showing details of a browsing server process performed by the information browsing server. [Figure 10] FIG. 10 is a diagram for explaining the operation of public keys and private keys in a supply chain in a second embodiment of the present disclosure. [Figure 11] FIG. 1 is a diagram showing an overview of a supply chain management system. DETAILED DESCRIPTION OF THE INVENTION
[0015] Hereinafter, multiple embodiments of the present disclosure will be described with reference to the drawings. Note that corresponding components in each embodiment are designated by the same reference numerals, and redundant description may be omitted. When only a portion of a configuration is described in each embodiment, the configuration of another previously described embodiment may be applied to the remaining portions of the configuration. Furthermore, in addition to the combinations of configurations explicitly stated in the description of each embodiment, configurations of multiple embodiments may be partially combined together even if not explicitly stated, provided that there is no particular problem with the combination. Furthermore, combinations of configurations described in multiple embodiments and modified examples that are not explicitly stated are also considered to be disclosed by the following description.
[0016] (First embodiment) The supply chain SC shown in Figure 1 is a connection between traders TR for delivering industrial products, agricultural products, marine products, etc. to end users. The supply chain SC is constructed by a large number of traders TR (see Companies A to F in Figure 1). The final products supplied by the supply chain SC may be various goods, such as automobiles, batteries, semiconductors, fresh produce, marine products, food, flowers, pharmaceuticals, and chemicals.
[0017] A supply chain management system according to a first embodiment of the present disclosure manages transaction records of items traded between traders TR in a supply chain SC as information linked to each trader TR. The transaction records are historical information that realizes traceability of items traded between traders TR, and include a large amount of information indicating the time and place where the transaction occurred.
[0018] In addition to transaction records, the supply chain management system also manages item-related information related to the items being traded. For example, information related to raw materials, information related to processing and assembly, and information related to distribution are managed as item-related information. Furthermore, the supply chain management system collects and stores information related to the amount of greenhouse gas emissions (hereinafter referred to as carbon release) emitted during each process of the item's manufacturing and distribution, as part of the item-related information.
[0019] The supply chain management system can obtain the total amount of carbon released by each trader TR and present it as a carbon footprint to end users and supervisory authorities, such as the SA. The carbon footprint may include the amount of carbon released in processes such as mining and recycling of the item's raw materials, as well as the amount of carbon released in processes related to the disposal of the item, such as incineration and landfilling. Furthermore, the carbon footprint may further include the amount of carbon released in the transportation process and the amount of carbon released from offices and other places not directly involved in manufacturing.
[0020] The greenhouse gases whose emissions are recorded may be carbon dioxide only, or may include greenhouse gases other than carbon dioxide, specifically methane, nitrous oxide, hydrofluorocarbons, perfluorocarbons, sulfur hexafluoride, etc. In this case, the emissions of greenhouse gases other than carbon dioxide are converted into carbon dioxide emissions and included in the presented carbon footprint value.
[0021] Here, the carbon release amount is often a trade secret of each trader TR. This is because the takt time and manufacturing method related to manufacturing can be inferred from the carbon release amount. As a result, many companies do not want to disclose their carbon release amount to other traders TR. In response to this background, the supply chain management system accumulates the carbon release amount of each trader TR without disclosing it, and obtains only the carbon footprint of the final product. The details of the supply chain management system are explained below with reference to Figures 1 and 2.
[0022] The supply chain management system is composed of a large number of trader terminals 50, an information management server 100s, an application distribution server 100a, an information browsing server 110, etc. Each element constituting the supply chain management system is connected to the network as a node and can communicate with each other.
[0023] <Trader TR and Trader Terminal 50> The trader terminal 50 is an information processing device operated by each trader TR. For example, a smartphone, tablet terminal, or personal computer can be used as the trader terminal 50. The trader terminal 50 is linked to each of companies A to F (see Figure 1). The trader terminal 50 is used by each trader TR to collect and store transaction records and item-related information. The trader terminal 50 records delivery information, such as from which trader TR raw materials or parts are purchased and when they were acquired, as well as shipping information, such as to which trader TR they were shipped to and when, as transaction records. Furthermore, the trader terminal 50 records at least information related to costs and carbon release amounts as item-related information.
[0024] The trader terminal 50 is mainly configured with a processing circuit 50c. The processing circuit 50c includes a processor 51, a RAM (Random Access Memory) 52, a storage unit 53, an input / output interface, and a bus connecting these components, and functions as a computer that performs arithmetic processing. The processor 51 is hardware for arithmetic processing that is coupled to the RAM 52. The storage unit 53 stores an application program (information management application APT) that causes the processing circuit 50c to execute the information management method according to the present disclosure. A display, a code reader (or camera), a printer, and the like are electrically connected to the input / output interface. The display, code reader, and printer may be integrated with the trader terminal 50, or may be electrically connected to the trader terminal 50 via wire or wireless.
[0025] The trader terminal 50 has functional units such as a key management unit 61, an information acquisition unit 62, an information calculation unit 63, an information provision unit 64, and a code output unit 65, by the processor 51 executing the information management application APT stored in the memory unit 53.
[0026] The key management unit 61 manages a private key sk and a public key pk based on homomorphic encryption. While a transactor TR typically only possesses a public key pk, a transactor TR primarily responsible for managing carbon release amounts may also possess a private key sk. The private key sk and public key pk are used to encrypt and decrypt item-related information equivalent to a trade secret when providing the item-related information to the transactor terminal 50 of another transactor TR. Homomorphic encryption is an encryption method that allows encrypted data to be processed without decrypting it. The key management unit 61 uses fully homomorphic encryption, such as FHE (Fully Homomorphic Encryption), as one type of homomorphic encryption. Fully homomorphic encryption enables addition, subtraction, multiplication, and division while the data remains encrypted. Alternatively to fully homomorphic encryption, multiplicative homomorphic encryption, such as RSA encryption and EI Gamal encryption, and additive homomorphic encryption, such as Goldwasser-Micali encryption and Paillier encryption, can be used depending on the content of the secure computation described below.
[0027] To further explain secure computation using homomorphic encryption, the key management unit 61 uses a key generation function KeyGen to generate a shared public key pk and a private key sk with decryption authority. If M is a message space, C is a cryptographic space, Enc is a probabilistic encryption function, and Dec is a deterministic decryption function, then for a message m∈M, encryption is c←Enc(m,pk) and decryption is m←Dec(c,sk). Furthermore, being able to process data in its encrypted state means that, as shown in the following formula 1, for messages m1, m2∈M,
number
[0028] The key management unit 61 performs a key sharing process (see Figures 3 and 4) in which a public key pk is shared among multiple traders TR. The content of the key sharing process changes depending on the attributes of the trader TR that operates the trader terminal 50. In more detail, the multiple traders TR include reporter TRs that are obligated to report item-related information (carbon footprints) to the supervisory authority SA that oversees the supply chain SC, and non-reporters TRn that are not obligated to report. Traders TRs that supply final products and traders TRs that supply specific finished products to the supply chain SC are pre-selected as reporter TRs.
[0029] The key management unit 61 of the trader terminal 50 operated by the reporter TRs (see companies C, D, and F in Figure 1) performs a key sharing process (S10 in Figure 3) to share the generated public key pk with the previous trader TR (previous trader). In the key sharing process, the key management unit 61 prepares a pair of a private key sk and a public key pk based on fully homomorphic encryption by generating them using the key generation function described above (S11). The key management unit 61 stores the generated private key sk (see private key Cskc, private key Dskd, and private key Fskf in Figure 1) so that it is not leaked to the outside (S12).
[0030] The key management unit 61 determines the recipient of the generated public key pk (see public key Cpkc, public key Dpkd, and public key Fpkf in Figure 1) (S13). The recipient of the public key pk is determined based on the nature of the connections between the traders TR in the supply chain SC. Specifically, the previous trader who is the provider of the items delivered (supplied) to the company (hereinafter referred to as delivery items) is selected as the recipient of the public key pk. If multiple traders TR deliver items to the company, multiple previous traders are set as recipients of the public key pk. The key management unit 61 provides the public key pk to the determined recipient (S14). The key management unit 61 shares the public key pk with the key management unit 61 of the trader terminal 50 linked to the previous trader via a network, using secure communication.
[0031] The key management unit 61 of the trader terminal 50 operated by the non-reporting party TRn (see companies A, B, and E in Figure 1) performs a key sharing process (Figure 4, S20) to share the public key pk obtained from the next-step trader TR (later-side trader) with the earlier-side trader. The key management unit 61 stores the public key pk obtained from the later-side trader (S21). The key management unit 61 determines the recipient of the obtained public key pk (S22). In this case, as in the above process (see Figure 3, S13), one or more earlier-side traders who are the providers of the delivery items are selected as the recipients of the public key pk.
[0032] The key management unit 61 determines whether there is a recipient of the public key pk (S23). If the company is the trader TR that is the starting point of the supply chain SC and there is no recipient of the public key pk (S23: NO), the key management unit 61 ends the key sharing process. On the other hand, if there is a previous trader that will be a recipient (S23: YES), the key management unit 61 provides the public key pk obtained from the subsequent trader to the identified recipient via secure communication (S24).
[0033] By performing the above key sharing process at each trader terminal 50, the public key pk is passed along the supply chain SC in the opposite direction (upstream) from the item. As a result, a unique public key pk is shared among multiple related traders TR before they start storing item-related information.
[0034] As a specific example, in a supply chain SC made up of companies A to F (see FIG. 1), public keys Cpkc, Dpkd, and Fpkf are shared among related companies. That is, in company C, a private key Cskc is created, and a public key Cpkc corresponding to the private key Cskc is also created. The public key Cpkc is shared among companies A to C. Similarly, in company D, a private key Dskd is created, and a public key Dpkd corresponding to the private key Dskd is also created. The public key Dpkd is shared among companies C and D. Furthermore, in company F, a private key Fskf is created, and a public key Fpkf corresponding to the private key Fskf is also created. The public key Fpkf is shared among companies D to F. The sharing of the public key pk through each key sharing process may be performed via the information management server 100s.
[0035] The information acquisition unit 62 acquires the identification information of the delivery item read by the code reader. The item identification information is at least one of a unique identification ID (hereinafter referred to as UID) issued by the information management server 100s and a hash value generated from the transaction record and item-related information. The identification information, including at least one of the UID and the hash value, is recorded in a one-dimensional code or two-dimensional code (e.g., QR code, registered trademark) attached to the delivery item in a state that can be read by a code reader or the like.
[0036] The information acquisition unit 62 acquires item transaction records and item-related information. The item-related information includes information related to the treatment (e.g., processing, assembly, transportation, storage, etc.) that the trader TR performs on the delivered item, as well as information regarding the amount of carbon released described above. The information acquisition unit 62 may automatically acquire the transaction records and item-related information from another server device installed at the trader TR's base, or may acquire data that is manually input according to a predefined management process as the transaction records and item-related information.
[0037] The information acquisition unit 62 acquires UIDs attached to items shipped (provided) by the company (hereinafter, "shipped items") by receiving them from the information management server 100s. In a configuration in which hash values are used to identify items, the information acquisition unit 62 acquires hash values generated by the information calculation unit 63. The information acquisition unit 62 stores transaction records and item-related information in the user database DB2, linked to the UIDs (or hash values) of the delivery items and the shipped items. The information acquisition unit 62 uses the UIDs or hash values as search keys to extract transaction records and item-related information associated with the UIDs (or hash values) from the data stored in the user database DB2. The user database DB2 may be a local storage device installed at the base of the trader TR, or may be cloud storage.
[0038] The information calculation unit 63 performs various calculations related to transaction records and item-related information. The information calculation unit 63 generates the above-mentioned hash value by inputting the transaction records and item-related information linked to the item into a predetermined hash function. Furthermore, the information calculation unit 63 performs a process of encrypting the item-related information using the public key pk and a process of performing secret calculations on the encrypted information.
[0039] The information providing unit 64 provides the information collected by the trader terminal 50 to the information management server 100s. The information providing unit 64 links the hash value generated by the information calculation unit 63 to the UID and transmits it to the information management server 100s (the information receiving unit 31 described below). The hash value may be generated by the information management server 100s and issued to the trader terminal 50 in the same way as the UID. In this embodiment, the information providing unit 64 transmits to the information management server 100s information that does not correspond to a trade secret among the transaction records and item-related information acquired by the information acquisition unit 62. The information management server 100s generates a hash value based on the received information and issues the generated hash value to the information acquisition unit 62.
[0040] The code output unit 65 is connected to a printer. The code output unit 65 causes the printer to output a label on which a two-dimensional code or the like is printed. The two-dimensional code records a UID or hash value issued by the information management server 100s (the information issuing unit 33 described below). The label is attached to the shipped item and distributed together with the shipped item to the trader TR in the next process. The two-dimensional code may be laser engraved or printed directly on the item. In this case, a laser marker, inkjet printer, or the like can be used as an output device instead of a printer.
[0041] [Secure computation and decryption / summing process] The information acquisition unit 62, information calculation unit 63, and information provision unit 64 described so far perform the secret calculation process (see Figure 5) or the decryption and summation process (see Figure 6). The secret calculation process and the decryption and summation process are continuously and repeatedly performed by the trader terminal 50. The secret calculation process is performed by the trader terminal 50 operated by the non-reporter TRn (see companies A, B, and E in Figure 1). In the secret calculation process, the carbon release amount is summed while remaining encrypted. On the other hand, the decryption and summation process is performed by the trader terminal 50 operated by the reporter TRs (see companies C, D, and F in Figure 1). In the decryption and summation process, the carbon release amount is summed and the public key pk used for encryption is switched.
[0042] In the secure computation process (see FIG. 5), the information acquisition unit 62 determines whether or not there is a previous transactor (S41), and if there is a previous transactor (S41: YES), acquires information related to the amount of carbon released up to the previous process (S42). Specifically, the information acquisition unit 62 acquires information on the amount of carbon released (hereinafter, the amount of cryptographic other company released) encrypted using the public key pk by the previous transactor providing the delivery item. In addition, the information acquisition unit 62 also acquires information such as the UID or hash value described above that identifies the delivery item. The information acquisition unit 62 stores the acquired information on the amount of cryptographic other company released in a variable (S43). The information acquisition unit 62 determines whether or not there is another previous transactor (S44), and if there is another previous transactor (S44: YES), repeats the acquisition and storage of the amount of cryptographic other company released, etc.
[0043] Here, the information acquisition unit 62 acquires the cryptocurrency company release amount by receiving it from the information management server 100s. Specifically, the information acquisition unit 62 acquires the cryptocurrency company release amount linked to the delivery item from the information management server 100s (the information delivery unit 33 described below) by making a provision request to the information management server 100s using the UID or hash value of the delivery item. When multiple delivery items are used in the company's shipping items, the information acquisition unit 62 acquires multiple cryptocurrency company release amounts from the information management server 100s. Note that the information acquisition unit 62 may also acquire the cryptocurrency company release amount directly from the trader terminal 50 linked to the front-side trader.
[0044] When the information acquisition unit 62 acquires the cryptocurrency release amounts of all the front-end traders (S44: NO), it acquires information indicating the carbon release amount in its own process (hereinafter, its own process) (S45). The information acquisition unit 62 determines whether the cryptocurrency release amounts of other companies, the carbon release amount of its own process, and all other necessary input items have been acquired (S46). If the necessary information has not been acquired (S46: NO), corresponding abnormality processing is carried out (S53). On the other hand, if all the necessary information has been acquired (S46: YES), the information acquisition unit 62 determines whether the carbon release amount of its own process is equal to or greater than a predetermined value (S47). The predetermined value is determined, for example, by the information management server 100s (administrator ADM). If the carbon release amount of its own process is less than the predetermined value (S47: NO), corresponding abnormality processing is carried out (S53).
[0045] As described above, the information acquisition unit 62 verifies whether the calculation of the carbon release amount for its own process has been omitted (S46) and whether the carbon release amount for its own process has been underestimated (S47). As described above, when processing is performed using secret calculation to add up the carbon release amounts for its own process, the information acquisition unit 62 detects the occurrence of this fraudulent processing.
[0046] If the amount of carbon release in the process itself is equal to or greater than a predetermined value (S47: YES), the information calculation unit 63 determines whether or not there is a public key pk for encryption (see S21 in FIG. 4) (S48). If there is no public key pk for encryption (S48: NO), the corresponding abnormality processing is carried out (S53). On the other hand, if there is a public key pk for encryption (S48: YES), the information calculation unit 63 encrypts the amount of carbon release in the process itself using the stored public key pk and prepares an amount of encrypted data released by the company itself (S49). Furthermore, the information calculation unit 63 adds the amount of carbon release in the process itself to the amount of carbon release up to the previous process while keeping it encrypted, by secret calculation using one or more amounts of encrypted data released by other companies and the amount of encrypted data released by the company itself (S50).
[0047] The information calculation unit 63 calculates the cumulative carbon release amount (hereinafter referred to as the cumulative cryptographic release amount) through secure calculation. At this time, the information calculation unit 63 can perform not only simple addition but also secure calculations such as multiplication and division, depending on the type of process performed in-house, such as an addition process, an integration process, and a branching process. For example, if the cryptographic other company release amount corresponds to the carbon release amount for one lot, the information calculation unit 63 can divide the cryptographic other company release amount by the number of items included in one lot to calculate the carbon release amount for one item.
[0048] The information calculation unit 63 calculates a hash value of the information management application APT (S51). The information providing unit 64 provides the cumulative encrypted release amount obtained as a result of the secret calculation to the subsequent transactor, and uploads the information to the information management server 100s by linking it to the UID or hash value of the shipping item (S52). Specifically, the information providing unit 64 transmits a data registration request to the information management server 100s. The information providing unit 64 transmits, as data to be registered, information related to the previous process, input items entered in the current process, the in-house encrypted release amount, the cumulative encrypted release amount, the hash value of the information management application APT, the public key pk used for encryption, and the like to the information management server 100s.
[0049] Note that information related to the preceding process includes, for example, a UID or hash value read from the two-dimensional code of the delivery item. Furthermore, when the trader TR, which is the starting point of the supply chain SC, performs the secure computation process, since there is no preceding trader, the amount of encrypted company release may be uploaded to the information management server 100s as the cumulative encrypted company release amount (provided information). The cumulative encrypted company release amount or the amount of encrypted company release uploaded to the information management server 100s is provided to the information acquisition unit 62 as the amount of encrypted company release based on a provision request from the trader terminal 50 in the secure computation process or decryption summation process performed by the succeeding trader.
[0050] In the decryption and summation process (see FIG. 6), the information acquisition unit 62 acquires the amount of cryptographic other company released, which indicates the amount of carbon released up to the previous process, and information such as a UID or hash value that identifies the delivery item (S61). The information acquisition unit 62 stores the amount of cryptographic other company released in a variable (S62). The information acquisition unit 62 determines whether there are other previous transactors (S63), and if there are other previous transactors (S63: YES), repeats the acquisition and storage of the amount of cryptographic other company released, etc.
[0051] When the cryptographic company release amounts of all previous transactors have been acquired (S63: NO), the information calculation unit 63 decrypts the acquired cryptographic company release amounts using the stored private key sk (see S12 in Fig. 3). As a result, the information calculation unit 63 acquires (prepares) the plaintext carbon release amounts up to the previous process (hereinafter referred to as the plaintext carbon release amounts) (S64). Furthermore, the information acquisition unit 62 acquires information indicating the carbon release amounts in its own process (S65).
[0052] The information acquisition unit 62 verifies whether the calculation of the carbon release amount for its own process has been omitted (S66) and whether the carbon release amount for its own process has been underestimated (S67) using a method similar to that of the secure computation process (see FIG. 5). As described above, if an unauthorized process is performed in the secure computation that totals the carbon release amounts for its own process, the information acquisition unit 62 detects the occurrence of this unauthorized process.
[0053] The information acquisition unit 62 determines whether the encryption company release amount, the carbon release amount of the current process, and all other required input items have been acquired (S66). If the required information has not been acquired (S66: NO), the corresponding abnormality processing is performed (S73). On the other hand, if all the required information has been acquired (S66: YES), the information acquisition unit 62 determines whether the cumulative carbon release amount up to the decrypted previous process and the carbon release amount of the current process are equal to or greater than a predetermined value (S67). Each predetermined value is determined, for example, by the information management server 100s (administrator ADM). If at least one of the carbon release amounts is less than a predetermined value (S67: NO), the corresponding abnormality processing is performed (S73). On the other hand, if both carbon release amounts are equal to or greater than a predetermined value (S67: YES), the presence or absence of an encryption public key pk (see S21 in FIG. 4) is determined (S68). If the encryption public key pk does not exist (S68: NO), the corresponding abnormality processing is performed (S73).
[0054] If the encryption public key pk is available (S68: YES), the information calculation unit 63 adds up the carbon release amount in the current process and the carbon release amount up to the previous process to calculate the cumulative carbon release amount up to the current process (hereinafter referred to as the cumulative plaintext release amount) (S69).The information calculation unit 63 encrypts the cumulative plaintext release amount using the stored public key pk, and calculates the encrypted cumulative release amount (S70).
[0055] The information calculation unit 63 calculates a hash value of the information management application APT (S71). The information providing unit 64 includes the encrypted encrypted cumulative release amount in information to be provided to the subsequent transactor, links it to the UID or hash value of the shipping item, and uploads it to the information management server 100s (S72). In the decryption and summation process, the information providing unit 64 also sends a data registration request to the information management server 100s. Then, information related to the previous process, input items entered in the current process, the encrypted cumulative release amount, the hash value of the information management application APT, the public key pk used for encryption, and the like are sent to the information management server 100s. The information providing unit 64 may generate an encrypted in-house release amount by encrypting the carbon release amount in the current process, and further transmit the generated encrypted in-house release amount to the information management server 100s.
[0056] The carbon release amount of each trader TR is added up by performing the above-mentioned secure computation process and decryption and summing process at each trader terminal 50. As a result, the carbon footprint associated with the final product supplied by the supply chain SC can be obtained by the trader TR of the final product and the supervisory authority SA.
[0057] As a specific example, in a supply chain SC consisting of companies A to F (see Figure 1), the carbon release amount acquired by company A is encrypted with public key pkc and provided to company B. Next, the carbon release amount acquired by company B is encrypted with public key pkc, added to the encrypted carbon release amount (encrypted third-party release amount) acquired from company A, and provided to company C.
[0058] Furthermore, the carbon release amount acquired by company C is added to the carbon release amount up to company B (plaintext release amount to other companies) decrypted with private key skc. The added carbon release amount is encrypted with public key pkd and provided to company D. Next, the carbon release amount acquired by company D is added to the carbon release amount up to company C decrypted with private key skd. The added carbon release amount is encrypted with public key pkf and provided to company E.
[0059] Then, the carbon release amount of company E is encrypted with the public key pkf, added to the encrypted carbon release amount obtained from company D, and provided to company F. Next, the carbon release amount of company F is added to the carbon release amount up to company E, which has been decrypted with the private key skf. As a result, the carbon footprint of the final product provided by company F can be obtained.
[0060] <Administrator ADM and information management server 100s, etc.> The information management server 100s and the application distribution server 100a are server devices operated by an administrator ADM of the supply chain SC. The administrator ADM is, for example, an agent entrusted with management work by a provider (finished product manufacturer) of the final product supplied by the supply chain SC. The administrator ADM may also be an agent entrusted with management and audit work by a supervisory authority SA that has supervisory authority over the category to which the final product belongs. The information management server 100s and the application distribution server 100a may be configured as on-premises servers physically managed by the administrator ADM or a system supplier, or may be configured as virtual servers installed on the cloud.
[0061] The information management server 100s is an information processing device mainly composed of a processing circuit 100c. The processing circuit 100c includes a processor 11, a RAM 12, a storage unit 13, an input / output interface, and a bus connecting these, and functions as a computer that performs arithmetic processing. The processor 11 is hardware for arithmetic processing that is coupled to the RAM 12, and executes programs stored in the storage unit 13.
[0062] The information management server 100s is an information management device on the administrator ADM side that manages transaction records and item-related information. The memory unit 13 stores an application program (information management application APS) that causes the processing circuit 100c to implement the information management method according to the present disclosure. The information management server 100s has functional units such as an information receiving unit 31, an information storage unit 32, an information delivery unit 33, and an information disclosure unit 34, as a result of the processor 11 executing the information management application APS. The information management server 100s continuously and repeatedly performs the management server process (see FIGS. 7 and 8), which will be described later, through cooperation between the functional units.
[0063] The information receiving unit 31 receives a request to register data transmitted from the trader terminal 50 and a request to view data transmitted from the information viewing server 110. When the information receiving unit 31 receives a request to register data, it receives and acquires the transaction record and item-related information transmitted from the trader terminal 50.
[0064] Based on a data registration request, the information storage unit 32 stores the transaction records and item-related information acquired by the information receiving unit 31 in the administrator database DB1, linking them to a UID or a hash value. The administrator database DB1 stores data to be stored, such as transaction records and item-related information, in a substantially tamper-proof state using blockchain BC technology. The administrator database DB1 stores the acquired data to be stored as transactions in blocks of a private blockchain BC. The administrator database DB1 hashes information stored in one block and stores it in the next block, making it difficult to tamper with the data to be stored stored in each block. The administrator database DB1 may also make it substantially impossible to tamper with the data to be stored by storing hash values generated from the data to be stored in blocks of a consortium or public blockchain BC.
[0065] The information issuing unit 33 issues a UID or hash value for identifying an item to each trader TR. The information issuing unit 33 provides the cumulative encrypted release amount up to the previous process to the information acquiring unit 62 of the trader terminal 50, which executes the secret calculation process (see FIG. 5) or the decryption and summation process (see FIG. 6). The information issuing unit 33 transmits a return value indicating the success or failure of the process based on the data registration request to the trader terminal 50. The information issuing unit 33 transmits a return value indicating the success or failure of the process based on the data viewing request to the information viewing server 110.
[0066] Based on a data browsing request, the information disclosure unit 34 extracts information linked to the UID or hash value to be browsed from a large amount of information stored in the administrator database DB1. The information disclosure unit 34 generates data to be provided based on the information extracted from the administrator database DB1, and provides the generated data to be provided to the information browsing server 110 that made the request.
[0067] The application distribution server 100a functions as a server device that distributes application programs related to traceability management (hereinafter referred to as traceability applications). The application distribution server 100a distributes information management applications APS and APT and an information browsing application APR as traceability applications. The application distribution server 100a may also distribute the above-mentioned key generation function KeyGen. The information management application APS is a traceability application for the administrator ADM. The information management application APS is distributed to the information management server 100s and installed on the information management server 100s. The information management application APT is a traceability application for the trader TR. The information management application APT is distributed to the trader terminal 50 and installed on the processing circuit 50c. The information browsing application APR is a traceability application for the supervisory authority SA. The information browsing application APR is distributed to the information browsing server 110 and installed on the processing circuit 100c of the information browsing server 110. Each application (APS, APT, APR) and the key generation function (KeyGen) are updated periodically to maintain security in traceability management.
[0068] The application distribution server 100a may be configured to be operated by a platformer of an operating system that runs the trader terminal 50 or each server 100s, 110. In this configuration, the latest application program is provided to the platformer by the administrator ADM, and is distributed to the trader terminal 50 or each server 100s, 110 from a server device operated by the platformer.
[0069] <Supervisory Authority SA and Information Viewing Server 110> The information browsing server 110 is a server device operated by a supervisory authority SA. The information browsing server 110 may be an on-premise configuration physically managed by the supervisory authority SA, or a virtual server configuration provided on the cloud. The information browsing server 110 is an information processing device mainly including a processing circuit 100c. The memory unit 53 stores an application program (information browsing application APR) for causing the processing circuit 100c to execute the information management method according to the present disclosure. A display, an input device, etc. are connected to the input / output interface of the processing circuit 100c. The information browsing server 110 continuously and repeatedly performs the audit server processing (see FIG. 9) described below by executing the information browsing application APR stored in the memory unit 13 using the processor 11.
[0070] The information browsing server 110 holds a master private key skM (private key M in Figure 1). The master private key skM is a decryption key separate from the private key sk held by the trader TR. The master private key skM is an upgraded version of the private key Fskf held by the trader TR (see company F in Figure 1) that supplies the final product, and can at least decrypt data encrypted with the public key Fpkf. The master private key skM may also be capable of decrypting data encrypted with the public key Cpkc or the public key Dpkd. The information browsing server 110 may hold another master private key skM that can decrypt data encrypted with the public key Cpkc or the public key Dpkd.
[0071] [Administration server processing and audit server processing] Next, the management server process (see FIGS. 7 and 8) performed by the information management server 100s and the audit server process (see FIG. 9) performed by the information browsing server 110 will be described in detail.
[0072] In the management server process (see FIG. 7), the information receiving unit 31 receives requests from the trader terminal 50 and the information browsing server 110. The information receiving unit 31 determines the content of the received request (S81). When a data registration request is received from the trader terminal 50 (S81: YES), the information receiving unit 31 receives and acquires the transaction record and item-related information transmitted from the trader terminal 50 (S82). Specifically, the information receiving unit 31 acquires, as the transaction record, information related to the previous process (delivery item), and the UID or hash value associated with the shipped item (see S52 in FIG. 5 and S72 in FIG. 6). In addition, the information receiving unit 31 acquires, as item-related information, the items entered in the current process, each encrypted carbon release amount, the hash value of the information management application APT, the public key pk, and the like.
[0073] If unauthorized processing is performed using secure computation, the information receiving unit 31 detects the occurrence of this unauthorized processing. The information receiving unit 31 determines the validity of the encrypted carbon release amount without decrypting it. The information receiving unit 31 determines whether or not the information on the internally released amount of encrypted carbon and the cumulative released amount of encrypted carbon has been acquired (S83). If the necessary information has been acquired (S83: YES), the information receiving unit 31 further determines whether or not the hash value of the information management application APT is identical to the hash value of a released valid application (S84). That is, based on a comparison of the hash values, the information receiving unit 31 determines whether or not the correct information management application APT is running on the trader terminal 50.
[0074] If the acquired hash value matches the correct value (S84: YES), the information receiving unit 31 compares the cumulative cryptographic release amount acquired from the trader terminal 50 in the previous process with the cumulative cryptographic release amount acquired from the trader terminal 50 in the current process (S85). If the two cumulative cryptographic release amounts are the same (S85: NO), the information receiving unit 31 presumes that the carbon release addition in the current process has been omitted. On the other hand, if the two cumulative cryptographic release amounts are the same (S85: YES), the information storage unit 32 presumes that the addition was performed correctly and stores the acquired transaction record and item-related information in the administrator database DB1, linking them to the UID or hash value (S86). In this case, the information issuing unit 33 sends a return value notifying the trader terminal 50 of normal processing (S87). On the other hand, if there is insufficient information (S83: NO), if the hash value does not match the normal value (S84: NO), or if the cumulative released amount of encryption has not changed (S85: NO), the information delivery unit 33 sends the return value of the abnormal processing to the trader terminal 50 (S88).
[0075] In the management server process (see FIG. 8), when the information accepting unit 31 accepts a data browsing request from the information browsing server 110 (S81: NO), the information disclosing unit 34 generates data to be provided. Specifically, the information disclosing unit 34 searches for the target ID to be acquired from the information browsing server 110 along with the data browsing request from the information stored in the administrator database DB1 (S91), and determines whether the target ID exists in the accumulated data (S92). If the target ID does not exist (S92: NO), the information disclosing unit 34 transmits an error value notifying that the target ID does not exist to the information browsing server 110 that made the request (S93).
[0076] If the target ID exists (S92: YES), the information disclosing unit 34 searches for all data (transaction records, etc.) related to the target ID (S94). If data related to the target ID does not exist in the information stored in the administrator database DB1 (S94: NO), the information disclosing unit 34 transmits an error value notifying the requesting information browsing server 110 that the data does not exist (S96). On the other hand, if data related to the target ID exists (S94: YES), the information disclosing unit 34 transmits provision data generated from the searched data to the requesting information browsing server 110 (S97). The information disclosing unit 34 provides the provision data to the information browsing server 110, which includes at least the encrypted cumulative release amount and information indicating the public key pk used to encrypt this encrypted cumulative release amount.
[0077] In the audit server process (see FIG. 9), the information browsing server 110 acquires the identification information (UID or hash value) of the final product or specific finished product whose carbon footprint is to be viewed as the target ID (S101). The target ID may be read from a two-dimensional code using a camera or code reader, or may be read from pre-prepared data. The information browsing server 110 sends a data viewing request together with the read target ID to the information management server 100s, thereby inquiring about the carbon footprint (S102).
[0078] The information browsing server 110 determines whether or not data linked to the target ID exists (S103). If a value indicating the occurrence of an error (see S93 or S96 in FIG. 8) is received, the information browsing server 110 determines that data linked to the target ID does not exist (S103: NO) and displays an error message using a display or the like (S104). On the other hand, if data to be provided (see S97 in FIG. 8) is returned, the information browsing server 110 determines that data linked to the target ID exists (S103: YES). In this case, the information browsing server 110 acquires the cumulative released amount of encryption provided as the data to be provided (S105).
[0079] The information browsing server 110 determines whether it holds a private key sk (master private key skM) that can decrypt the acquired encrypted cumulative release amount (S106). If it does not hold the private key sk (S106: NO), the information browsing server 110 displays an error message on a display or the like (S104). On the other hand, if it holds the private key sk (S106: YES), the information browsing server 110 decrypts the encrypted cumulative release amount using the private key sk and acquires the carbon footprint in plain text (S107). The information browsing server 110 displays the acquired carbon footprint value on a display or the like (S108).
[0080] In the above audit server process, not only the UID of the final product but also the UID of a specific finished product manufactured in the middle of the supply chain SC can be set as the target ID. Therefore, it becomes possible to inquire about the cumulative carbon release amount registered by reporter TRs for a specific finished product, in other words, the carbon footprint value of a specific finished product.
[0081] <Summary of the First Embodiment> In the first embodiment described above, the encrypted third-party release amount encrypted by the front-side transactor that provides the delivery item and the encrypted first-party release amount, which is the carbon release amount related to the processing performed on the delivery item, are used for the secure calculation. Then, the encrypted cumulative release amount is calculated as the result of the secure calculation, and this encrypted cumulative release amount is provided to the back-side transactor that supplies the delivery item.
[0082] According to the above, even if the later transactor holds the private key sk, the encrypted carbon footprints of other transactors and the carbon footprints of the former transactor are not provided to the later transactor. Therefore, the former transactor's item-related information and the current carbon footprint of the transactor's own process are not disclosed to the later transactor. In addition, as the transaction progresses, the former transactor's own carbon footprint is added to the cumulative carbon footprint of each transactor TR, so the holder of the private key sk can obtain the carbon footprint of the entire supply chain SC by decrypting the cumulative carbon footprint. Therefore, it is possible to obtain information about the entire supply chain SC while keeping the information of each transactor TR confidential.
[0083] Additionally, in the first embodiment, a pair of private key skc and public key pkc and a pair of private key skd and public key pkd are prepared by different transactors TR. Then, a reporter TR (company C) that holds the private key skc provides the public key pkc to the previous transactor (company B) and obtains the public key pkd from the subsequent transactor (company D).
[0084] Furthermore, the reporter TRs' trader terminal 50 prepares the plaintext other company release amount by decrypting the encrypted other company release amount using the private key skc. The plaintext cumulative release amount obtained by calculation using the plaintext other company release amount and the carbon release amount related to the processing that the reporter TRs performs on the delivery item in its own process is then encrypted using the public key pkd and included in the information provided to the subsequent trader.
[0085] According to the above key management, the number of traders TR that share one public key pk is limited to only a portion of the multiple traders TR that make up the supply chain SC. Therefore, even if the private key sk is leaked from the reporter TRs, the information that can be decrypted using the leaked private key sk is limited to information encrypted by a portion of the traders TRs. As a result, it is possible to further increase the security level against leaks of the private key sk.
[0086] Furthermore, in the first embodiment, the information viewing server 110 at the supervisory authority SA of the supply chain SC holds a master private key skM that is separate from the private key sk held by the trader TR. The information viewing server 110 then decrypts the encrypted cumulative release amount using the master private key skM. In this way, by holding the master private key skM in the information viewing server 110, it is possible to avoid a situation in which the encrypted cumulative release amount cannot be decrypted even if the private key sk is lost at the reporter TRs.
[0087] Furthermore, in the first embodiment, each trader terminal 50 and the information management server 100s detects unauthorized processing through secret calculation. Therefore, even if information is exchanged in an encrypted state, the carbon release amount emitted in each trader TR's process can be correctly added to the encrypted cumulative release amount. As a result, even if the information of each trader TR is not disclosed, the accuracy of information in the entire supply chain SC can be guaranteed.
[0088] Additionally, in the first embodiment, in the step of sharing the public key pk, the public key pk obtained from the subsequent transactor is provided to at least one previous transactor. In this way, if the public key pk is handed over in a manner tracing back upstream in the supply chain SC, it becomes possible for transactors TR with no direct transactions to share the public key pk while keeping their transaction relationship confidential.
[0089] In the first embodiment, the carbon release amount associated with a delivery item is encrypted using the public key pk in a previous process and acquired as the encrypted third-party release amount. Additionally, the carbon release amount associated with the process performed on the delivery item in the current process is encrypted using the public key pk and acquired as the encrypted first-party release amount. Then, a cryptographic cumulative release amount is generated by adding up each carbon release amount while keeping it encrypted, using secure computation. As described above, by using secure computation to accumulate the carbon release amount in the supply chain SC, the carbon footprint of the final product can be ascertained without forcing each trader TR to disclose information. As a result, it becomes possible to lower the barrier to introducing a system for disclosing carbon footprints.
[0090] Furthermore, in the first embodiment, a private key sk and a public key pk based on fully homomorphic encryption are prepared. Therefore, addition, subtraction, multiplication, and division can be performed in a secure manner while the data remains encrypted. As a result, secure computations corresponding to various processes performed by each transactor TR can be performed. As a result, even if the form of connection between transactors TR is complex, it is possible to calculate secure computation results with guaranteed accuracy.
[0091] In the first embodiment, the key management unit 61 corresponds to the "key generation unit," the information calculation unit 63 corresponds to the "information generation unit," the processing circuit 50c and the processing circuit 100c correspond to the "computer," and the supply chain management system corresponds to the "information management system." The supervisory authority SA corresponds to the "supervisor," the reporter TRs corresponds to the "key holder," the private key Cskc corresponds to the "first private key," the public key Cpkc corresponds to the "first public key," the private key Dskd corresponds to the "second private key," and the public key Dpkd corresponds to the "second public key." Furthermore, the amount of encryption released by other companies corresponds to "acquired encryption information," the amount of plaintext released by other companies corresponds to "acquired plaintext information," and the amount of encryption released by one company corresponds to "generated encryption information." The cumulative encryption release amount corresponds to the "secret computation result" and the "encryption computation result," the cumulative plaintext release amount corresponds to the "plaintext computation result," and the carbon release amount corresponds to "emissions information."
[0092] Second Embodiment 10 and 11 is a modified example of the first embodiment. In the second embodiment, the private key sk and the public key pk are not generated by the key management unit 61 of the trader terminal 50. On the other hand, the information browsing server 110 is provided with a key generation unit 236 as a functional unit based on the information browsing application APR.
[0093] The key generation unit 236 performs key sharing processing (see FIG. 3) on behalf of the key management unit 61, and generates a private key sk and a public key pk (private key Z, public key Z in FIG. 10) based on fully homomorphic encryption (S11). The key generation unit 236 stores the generated private key sk (S12). Furthermore, the key generation unit 236 identifies a trader TR (see Company F in FIG. 10) that supplies a final product in the supply chain SC as a recipient of the prepared public key pk (S13), and provides the public key pk to the trader terminal 50 of this trader TR (S14). Each trader terminal 50 performs key sharing processing (see FIG. 4) to sequentially deliver the public key pk to upstream traders TRs up the supply chain SC. Through this cooperation between the key generation unit 236 and each key management unit 61, the public key pk designated by the supervisory authority SA is shared among each trader TR (see Companies A to F in FIG. 10).
[0094] Each trader terminal 50 performs a secure calculation process (see FIG. 5) to add the amount of encrypted data released by the previous trader to the amount of encrypted data released by the previous trader, which corresponds to the amount of carbon released in its own process. As a result, the trader TR that provides the final product uses secure calculation to calculate the cumulative amount of encrypted data released, including information on the carbon footprint of the final product. In the second embodiment, the cumulative amount of encrypted data released by each trader terminal 50 is also registered in the administrator database DB1 of the information management server 100s.
[0095] As a specific example, in a supply chain SC consisting of companies A to F, the carbon release amount acquired by company A is encrypted with public key pk and provided to company B. Next, the carbon release amount acquired by company B is encrypted with public key pk, added to the encrypted carbon release amount (cryptographically released by other companies) acquired from company A, and provided to company C. Furthermore, the carbon release amount acquired by company C is also encrypted with public key pk, added to the cryptographically released by other companies acquired from company B (cryptographically accumulated released amount), and provided to company D. Similarly, companies D to F also encrypt the carbon release amount with public key pk and add it to the cryptographically accumulated released amount. As a result, the carbon footprint of the final product provided by company F can be obtained.
[0096] The information browsing server 110 executes the audit server process (see FIG. 9) to acquire the encrypted cumulative release amount associated with the final product or a specific finished product from the information management server 100s (S105). The information browsing server 110 decrypts the acquired encrypted cumulative release amount using the private key sk stored in the key generation unit 236, and acquires the carbon footprint (S107).
[0097] The second embodiment described so far also achieves the same effect as the first embodiment, and since the amount of carbon released by each transactor TR is not provided to subsequent transactors, the amount of carbon released in the process is not disclosed to subsequent transactors. On the other hand, since the amount of carbon released by each transactor TR is added to the cumulative amount of carbon released by secret calculation, the supervisory authority SA, which holds the private key sk, can obtain the carbon footprint by decrypting the cumulative amount of carbon released. Therefore, information about the entire supply chain SC can be obtained while keeping the information about each transactor TR confidential.
[0098] Additionally, in the second embodiment, a private key sk and a public key pk are prepared in the information browsing server 110 of the supervisory authority SA, and this public key pk is shared among each trader TR. Then, the information browsing server 110 acquires the encrypted cumulative release amount associated with the final product or a specific finished product, and the carbon footprint is acquired by decrypting the encrypted cumulative release amount using the private key sk. As described above, by managing the private key sk in the information browsing server 110, the risk of leakage of the private key sk can be reduced. As a result, a supply chain management system with a high level of security can be realized.
[0099] In the second embodiment, the final product and the specific finished product correspond to the "supply item", and the carbon footprint corresponds to the "decoding calculation result".
[0100] (Other embodiments) Although several embodiments of the present disclosure have been described above, the present disclosure should not be construed as being limited to the above-described embodiments, and can be applied to various embodiments and combinations within the scope that does not deviate from the gist of the present disclosure.
[0101] In a first modification of the above embodiment, instead of the carbon release amount for each process, information on the usage of electricity or energy resources used in connection with the processing performed on the item in each process is collected as item-related information. Specifically, the usage information indicating the usage of electricity and energy resources is information for calculating the carbon release amount. The electricity usage information is linked to type information indicating the power generation method, such as hydroelectric power, thermal power, wind power, geothermal power, nuclear power, and solar power. Similarly, the energy resource usage information is linked to information indicating the type of fuel, such as crude oil, coal, natural gas, and hydrogen.
[0102] The acquired encryption information acquired in the secure computation process of Modification 1 (see FIG. 5) is information obtained by encrypting the usage information for each type of power or energy resource associated with the delivery item using the public key pk (S42). Then, the usage information associated with the process performed in the current process is encrypted for each type of power or energy resource using the public key pk (S49). Furthermore, a secure computation result is generated by adding up the usage information for each type while it remains encrypted using secure computation (S50). This secure computation result is generated for each type of power or energy resource, and is encrypted information of the value obtained by individually accumulating each piece of usage information. The secure computation result for each type is uploaded to the information management server 100s as information to be provided to the next process (S52).
[0103] In Modifications 2 and 3 of the above embodiment, the information management method according to the present disclosure is applied to the accumulation of item-related information other than the carbon release amount. Specifically, in Modification 2, the amount of rare metal used is accumulated for each type of rare metal. As a result, a secret calculation result that can be decrypted into information indicating the total amount of rare metal used in the supply item can be obtained for each type of rare metal. Furthermore, in Modification 3, the amount of generation of specific hazardous substances that are subject to regulation is accumulated for each type of hazardous substance. As a result, a secret calculation result that can be decrypted into information indicating the total amount of hazardous substances generated by the manufacture or distribution of the supply item can be obtained for each type of hazardous substance.
[0104] The information management method according to the present disclosure is particularly suitable for storing information that is required to be recorded by law, as in the above-described variations 1 to 3. Note that the item-related information to be recorded is not limited to the carbon release amount and the like, and may be changed as appropriate.
[0105] In the fourth modification of the first embodiment, the information viewing server 110 does not hold the master private key skM. The information viewing server 110 receives the private key sk from each reporter TRs. Even with this key operation, the information viewing server 110 can obtain information on the entire supply chain SC. It is desirable that the private key sk be provided directly to the information viewing server 110 without being relayed through the information management server 100s.
[0106] In the above embodiment, detection of fraudulent processing using secret calculation was performed at each trader terminal 50 and the information management server 100s. However, detection of fraudulent processing may be performed only in some configurations. For example, in variant 5, detection of fraudulent processing is performed by each trader terminal 50, while detection of fraudulent processing by the information management server 100s is omitted. Furthermore, in variant 6, detection of fraudulent processing is performed by the information management server 100s, while detection of fraudulent processing by each trader terminal 50 is omitted.
[0107] Furthermore, in Variation 7, detection of fraudulent processing is carried out only at some trader terminals 50. Specifically, detection of fraudulent processing is carried out at the trader terminal 50 of the reporter TRs, while detection of fraudulent processing is not carried out at the trader terminal 50 of the non-reporter TRn. Also, in Variation 8, the secure computation of the previous process is checked for fraudulent processing, rather than the secure computation of the current process.
[0108] In the above embodiment, the administrator ADM and the supervisory authority SA exist as separate organizations. However, in a ninth modification of the above embodiment, the supervisory authority SA also serves as the administrator ADM. In this ninth modification, the functions of the processing circuit 100c may be integrated into the information browsing server 110.
[0109] In the above embodiment, a server device is used as the information management server 100s and the information browsing server 110. However, similar to the trader terminal 50, a smartphone, a tablet terminal, a personal computer, or the like may be used as the information management server 100s or the information browsing server 110.
[0110] In a tenth modification of the above embodiment, RFID (radio frequency identifier) technology is used to attach a UID or hash value to an item. In this tenth modification, an RFID tag is used as the data recording medium instead of a paper medium on which a two-dimensional code is printed. By using such RFID technology, it becomes possible to read the UID remotely, even when the RFID tag is not directly visible. In the tenth modification, instead of a code reader or camera, a reader capable of reading an RFID tag is connected to the trader terminal 50 by wire or wirelessly.
[0111] In the above embodiment, the functions provided by the information management server 100s and the information browsing server 110 can be provided by software and hardware that executes the software, software alone, hardware alone, or a combination of these. Similarly, the functions provided by the trader terminal 50 can be provided by software and hardware that executes the software, software alone, hardware alone, or a combination of these. When such functions are provided by electronic circuits as hardware, each function can also be provided by digital circuits including multiple logic circuits or analog circuits. Furthermore, the software for realizing such functions may include, at least in part, code automatically generated by a neural network or language model trained using learning data.
[0112] Each of the processors 11 and 51 in the above embodiments may include at least one arithmetic core such as a CPU (Central Processing Unit) and a GPU (Graphics Processing Unit).Furthermore, the processor may further include an FPGA (Field-Programmable Gate Array) and an IP core with other dedicated functions.
[0113] The form of the storage medium employed as each storage unit in the above-described embodiments and storing each program related to realizing the information management method of the present disclosure may be changed as appropriate. For example, the storage medium is not limited to a configuration mounted on a circuit board, but may be provided in the form of a memory card or the like, inserted into a slot, and electrically connected to a computer bus. Furthermore, the storage medium may be an optical disk, hard disk drive, solid state drive, or the like used as a source from which programs are copied or distributed to a computer.
[0114] The controller and methods described herein may be implemented by a special-purpose computer comprising a processor programmed to perform one or more functions embodied in a computer program. Alternatively, the apparatus and methods described herein may be implemented by special-purpose hardware logic circuitry. Alternatively, the apparatus and methods described herein may be implemented by one or more special-purpose computers comprising a processor executing a computer program in combination with one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by a computer on a computer-readable non-transitory storage medium.
[0115] (Disclosure of technical ideas) This specification discloses multiple technical ideas described in the following multiple clauses. Some clauses may be written in a multiple dependent form, with the subsequent clause referring to the preceding clause as an alternative. Furthermore, some clauses may be written in a multiple dependent form, referring to another multiple dependent clause. These multiple dependent clauses define multiple technical ideas. (Technical thought 1) An information management method implemented by a computer (50c, 100c) for managing information associated with each of a plurality of traders (TR) constituting a supply chain (SC), comprising: The process executed by at least one processor (11, 51) A private key (sk) and a public key (pk) based on homomorphic encryption are prepared, and the public key is shared among the multiple transactors (S10, S20); The upstream transaction party, which is the transaction party in the upstream process that supplies the delivery item, obtains the obtained encryption information encrypted using the public key (S42). preparing generated encryption information by encrypting item-related information relating to the process to be performed on the delivery item using the public key (S49); A secret calculation result obtained by secret calculation using the acquired encryption information and the generated encryption information is set as information to be provided to the subsequent transactor, who is the transactor in the next process that provides the shipping item (S52). An information management method comprising the steps of: (Technical thought 2) In the step of sharing the public key, As the private key and the public key, a first private key (skc) and a first public key (pkc) and a second private key (skd) and a second public key (pkd) are prepared by different transactors, A key holder (TR) as the transactor who holds the first private key provides the first public key to the first transactor and obtains the second public key from the second transactor (S14, S21); The key holder: Prepare acquired plaintext information by decrypting the acquired encrypted information using the first private key (S64); encrypting, with the second public key, a plaintext calculation result obtained by calculation using the acquired plaintext information and the item-related information related to the action that the key holder will take on the delivery item (S70); The encrypted cryptographic calculation result is included in the provided information (S72). The information management method according to Technical Idea 1 further includes the step of: (Technical Thought 3) A supervisor (SA) that supervises the supply chain decrypts the secure computation result using a master private key (skM) that is different from the private key held by the trader (S107). The information management method according to Technical Idea 2 further includes the step of: (Technical Thought 4) In the step of sharing the public key, the private key and the public key are prepared by a supervisor (SA) that supervises the supply chain; The supervisor, Obtaining the secure computation result associated with the supply item provided by the supply chain (S105); The secret calculation result is decrypted using the private key to obtain a decryption calculation result (S107). The information management method according to Technical Idea 1 further includes the step of: (Technical Thought 5) The information management method according to any one of Technical Ideas 1 to 4 further includes the step of detecting whether an unauthorized process has been performed in the secure computation (S46, S47, S66, S67, S83 to S85). (Technical Thought 6) An information management method described in any one of technical ideas 1 to 5, wherein in the step of sharing the public key, the public key obtained from the subsequent transaction party is provided to at least one of the previous transaction parties (S24). (Technical Thought 7) In the step of acquiring the acquired cryptographic information, the acquired cryptographic information is obtained by encrypting greenhouse gas emission information associated with the delivery item using the public key; In the step of preparing generated encryption information, the emission amount information associated with the treatment to be performed on the delivery item is encrypted using the public key; An information management method described in any one of Technical Ideas 1 to 6, wherein in the step of obtaining the secret calculation result, the secret calculation result obtained by adding up the emission information while keeping it encrypted by the secret calculation is used as the provided information. (Technical Thought 8) In the step of acquiring the acquired encryption information, the acquired encryption information is acquired by encrypting usage information for each type of power or energy resource associated with the delivery item using the public key; In the step of preparing generated encryption information, the usage amount information associated with the process to be performed on the delivery item is encrypted for each type using the public key; An information management method according to any one of Technical Ideas 1 to 6, wherein in the step of obtaining the secret calculation result, the secret calculation result obtained by adding up the usage information for each type while keeping it encrypted by the secret calculation is used as the provided information. (Technical Thought 9) The information management method according to any one of Technical Ideas 1 to 8, wherein in the step of sharing the public key, the private key and the public key based on fully homomorphic encryption are prepared (S11).
Claims
1. An information management method that is implemented by a computer (50c, 100c) and manages information associated with each of a plurality of traders (TRs) that make up a supply chain (SC), comprising: The process executed by at least one processor (11, 51) A private key (sk) and a public key (pk) based on homomorphic encryption are prepared, and the public key is shared by the multiple transactors (S10, S20); The upstream transaction party, which is the transaction party in the upstream process that supplies the delivery item, obtains the acquisition encryption information encrypted using the public key (S42). Prepare generated encryption information by encrypting item-related information related to the process to be performed on the delivery item using the public key (S49); A secret calculation result obtained by secret calculation using the acquired encryption information and the generated encryption information is used as information to be provided to the subsequent transactor, who is the transactor in the next process that provides the shipping item (S52). An information management method comprising the steps of:
2. In the step of sharing the public key, As the private key and the public key, a first private key (skc) and a first public key (pkc) and a second private key (skd) and a second public key (pkd) are prepared by different transactors, A key holder (TRs) as the transactor who holds the first private key provides the first public key to the first transactor and obtains the second public key from the second transactor (S14, S21); The key holder: Prepare acquired plaintext information by decrypting the acquired encrypted information using the first secret key (S64); a plaintext calculation result obtained by calculation using the acquired plaintext information and the item-related information related to the action that the key holder will take on the delivery item is encrypted using the second public key (S70); The encrypted cryptographic calculation result is included in the provided information (S72).
2. The information management method according to claim 1, further comprising the step of:
3. The supervisor (SA) that supervises the supply chain decrypts the secret calculation result using a master private key (skM) that is different from the private key held by the trader (S107).
3. The information management method according to claim 2, further comprising the step of:
4. In the step of sharing the public key, the private key and the public key are prepared by a supervisor (SA) that supervises the supply chain; The supervisor, Acquire the secure computation result associated with the supply item supplied by the supply chain (S105); The secret calculation result is decrypted using the private key to obtain a decryption calculation result (S107).
2. The information management method according to claim 1, further comprising the step of:
5. 5. The information management method according to claim 1, further comprising the step of detecting whether an unauthorized process has been performed in the secure computation (S46, S47, S66, S67, S83 to S85).
6. An information management method described in any one of claims 1 to 4, wherein in the step of sharing the public key, the public key obtained from the subsequent transaction party is provided to at least one of the previous transaction parties (S24).
7. In the step of acquiring the acquired cryptographic information, the acquired cryptographic information is obtained by encrypting greenhouse gas emission information associated with the delivery item using the public key; In the step of preparing generated encryption information, the emission amount information associated with the treatment to be performed on the delivery item is encrypted using the public key; 5. The information management method according to claim 1, wherein in the step of obtaining the secret calculation result, the secret calculation result obtained by adding up the emission information while keeping it encrypted by the secret calculation is used as the provided information.
8. In the step of acquiring the acquired encryption information, the acquired encryption information is acquired by encrypting usage information for each type of power or energy resource associated with the delivery item using the public key; In the step of preparing generated encryption information, the usage amount information associated with the process to be performed on the delivery item is encrypted for each type using the public key; The information management method according to any one of claims 1 to 4, wherein in the step of obtaining the secret calculation result, the secret calculation result obtained by adding up the usage information for each type while keeping it encrypted by the secret calculation is used as the provided information.
9. 5. The information management method according to claim 1, wherein in the step of sharing the public key, the private key and the public key based on fully homomorphic encryption are prepared (S11).
10. An information management system that manages information associated with each of a plurality of traders (TRs) that make up a supply chain (SC), a key generation unit (61, 236) that prepares a secret key (sk) and a public key (pk) based on homomorphic encryption and shares the public key among the multiple transactors; an information acquisition unit (62) that acquires acquired encryption information encrypted using the public key by a previous transaction party that is a transaction party in a previous process that supplies a delivery item; an information generating unit (63) that prepares generated encrypted information by encrypting item-related information related to the treatment to be performed on the delivery item using the public key; an information providing unit (64) that provides a secret calculation result obtained by secret calculation using the acquired encryption information and the generated encryption information to a subsequent transactor, who is the transactor in the next process that provides a shipping item; An information management system comprising:
Citation Information
Patent Citations
Device, method and program for simulating environmental load
JP2011204217A
Encryption system, encryption method, and encryption program
JP2018036418A
Supply chain management method, supply chain management program, supply chain management system, and transaction record display program
WO2021002226A1
Information management method and information provision method
WO2022149501A1