Distributed ledger data management system and data management method

The distributed ledger data management system addresses the challenge of centralized private key management by implementing a wallet management ledger for organizations, enabling decentralized and secure key management and transactions.

JP7836274B2Active Publication Date: 2026-03-26HITACHI LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-03-03
Publication Date
2026-03-26

AI Technical Summary

Technical Problem

Conventional distributed ledger systems face challenges in managing private keys when organizations manage wallets, as the management becomes dependent on individuals, and existing technologies do not provide a decentralized solution for key management.

Method used

A distributed ledger data management system is implemented with a wallet management distributed ledger that generates and manages organization-specific private keys in an encrypted state, allowing decentralized key management and secure transactions using interoperability between blockchains.

Benefits of technology

The system enables decentralized management of private keys, ensuring confidentiality and secure transactions without dependency on individuals, while maintaining key secrecy from users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007836274000001
    Figure 0007836274000001
  • Figure 0007836274000002
    Figure 0007836274000002
  • Figure 0007836274000003
    Figure 0007836274000003
Patent Text Reader

Abstract

To non-centralizedly manage a secret key that is required when accessing or moving data to a wallet in the case where an organization manages the wallet in a scattering ledger data system.SOLUTION: A scattering ledger data management system 10 comprises: an asset management scattering ledger 11 of a block chain constructed by including a plurality of asset management scattering ledger nodes and an asset management scattering ledger network; and a plurality of wallet management scattering ledgers and an asset management scattering ledger client for managing a wallet of an individual or an organization user group as users 14 and 15 of a plurality of individual and organization user groups 12 and 13 participating the asset management scattering ledger. A user group system of an organization (a system of the user group 13) issues a transaction to the asset management scattering ledger by using an encrypted secret key of the organization.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a distributed ledger data management system and a data management method, and is suitable for application to a distributed ledger data management system and a data management method for managing data transactions between individuals and organizations participating in the distributed ledger.

Background Art

[0002] In order to realize DFFT (Data Free Flow with Trust) proposed by the Japanese government in 2019, a system in which a plurality of organizations such as countries and enterprises share and utilize data is required. As one of the means for realizing this, there is a distributed ledger technology in which a plurality of organizations can operate the system with the same authority. The distributed ledger technology is a technology that replaces transactions that have been carried out via a central authority (for example, a reliable organization such as a financial institution or the government) with direct P2P (Peer to Peer) transactions between users.

[0003] Regarding distributed ledger technology, various derivative technologies have been proposed and continue to evolve. The main features of the current situation are, first, in transactions between participants in the distributed ledger, the transaction is finalized by consensus formation or approval by (arbitrary or specific) participants instead of a central authority; second, a plurality of transactions are grouped as blocks and recorded in a distributed ledger called a blockchain (BC) in a chain, and by performing hash calculation on consecutive blocks, it is made substantially impossible to falsify; third, all participants share the same ledger data, enabling confirmation of transactions by all participants.

[0004] Due to the characteristics described above, distributed ledger technology using blockchain is being considered for application in a wide range of fields, including finance and manufacturing, as a mechanism for managing and sharing reliable data and executing and managing contractual transactions. Specifically, by using distributed ledger technology such as blockchain (BC), it has become possible to conduct monetary transactions between individuals in a decentralized manner without tampering. As a result, concepts such as Central Bank Digital Currency (CBDC) are progressing, and the digitalization of legal tender in countries around the world is also advancing.

[0005] For example, Patent Document 1 discloses an information disclosure management device that, as a data management technology in a blockchain-based system, receives data to be broadcast from a first user, receives approval for the broadcast of said data from a second user, and receives a disclosure request from a third user, and broadcasts said data if the second user meets predetermined user conditions.

[0006] For example, Patent Document 2 discloses a technology that aims to guarantee security and privacy in blockchain privacy data processing by executing smart contracts in a data confidential state when handling data on a blockchain. [Prior art documents] [Patent Documents]

[0007] [Patent Document 1] Patent No. 7108253 [Patent Document 2] Japanese Patent Publication No. 2021-189431 [Overview of the project] [Problems that the invention aims to solve]

[0008] By the way, in a distributed ledger system using distributed ledger technology (for example, a digital currency system), users of digital currency need to own a wallet to store and manage the private keys required when sending and receiving currency. However, conventional technology has had problems in terms of how to manage these private keys. Specifically, in a wallet in a distributed ledger that manages data including digital currency and assets and their ownership, if an individual manages the wallet, that individual only needs to manage the private keys required for data storage. However, if an organization manages the wallet, there is a problem in that the management of private keys becomes dependent on the individual. The conventional technology described in Patent Document 1 above centrally manages private keys using an information disclosure management device and does not solve the above problem, nor does the conventional technology described in Patent Document 2 disclose a means to solve the above problem.

[0009] This invention has been made in consideration of the above points, and aims to propose a distributed ledger data management system and data management method that enable decentralized management of private keys necessary for accessing or moving data to a wallet when an organization manages a wallet in a distributed ledger system. [Means for solving the problem]

[0010] To solve the above problems, the present invention provides a distributed ledger data management system for managing data exchange between user groups of individuals and organizations participating in a distributed ledger system, comprising: a blockchain distributed ledger system comprising: a plurality of distributed ledger nodes and a network of distributed ledgers constructed by connecting the plurality of distributed ledger nodes to each other; and a plurality of user group systems that manage the wallets of the individual or organizational user group as clients of the plurality of individual and organizational user groups participating in the distributed ledger system, wherein the organizational user group system is The system comprises a wallet management distributed ledger that manages the wallets of the user group of the organization and is connected to the distributed ledger system, and a plurality of wallet management distributed ledger clients, which are operated by users belonging to the user group of the organization and are connected to the wallet management distributed ledger, and when the user group of the organization joins the distributed ledger system, the wallet management distributed ledger is started in response to a startup request from the wallet management distributed ledger client, the wallet management distributed ledger generates and manages the organization's private key in an encrypted state, and the user group of the organization When using the organization's wallet, The aforementioned distributed ledger for wallet managementA distributed ledger data management system is provided, characterized by issuing transactions to the distributed ledger system using the encrypted private key of the organization.

[0011] Furthermore, in order to solve the above problems, the present invention provides a data management method using a distributed ledger data management system that manages the exchange of data between user groups of individuals and organizations participating in a distributed ledger system, wherein the distributed ledger data management system comprises a blockchain distributed ledger system comprising a plurality of distributed ledger nodes and a network of distributed ledgers constructed by connecting the plurality of distributed ledger nodes to each other, and a plurality of user group systems that manage the wallets of the individual or organizational user group as clients of the plurality of individual and organizational user groups participating in the distributed ledger system, wherein the organizational user group system is The system comprises a wallet management distributed ledger that manages the wallets of the user group of the organization and is connected to the distributed ledger system, and a plurality of wallet management distributed ledger clients, which are operated by users belonging to the user group of the organization and are connected to the wallet management distributed ledger, and when the user group of the organization joins the distributed ledger system, the wallet management distributed ledger is started in response to a startup request from the wallet management distributed ledger client, the wallet management distributed ledger generates and manages the organization's private key in an encrypted state, and the user group of the organization When using the organization's wallet, The aforementioned distributed ledger for wallet management A data management method is provided, characterized by issuing transactions to the distributed ledger system using the encrypted private key of the organization. [Effects of the Invention]

[0012] According to the present invention, when an organization manages a wallet in a distributed ledger system, the private keys required to access or move data to the wallet can be managed in a decentralized manner. [Brief explanation of the drawing]

[0013] [Figure 1] This figure shows an example of the overall configuration of a distributed ledger data management system 10 according to one embodiment of the present invention. [Figure 2] This figure shows an example configuration of the distributed asset management ledger 11. [Figure 3] This figure shows an example configuration of the wallet management distributed ledger 17. [Figure 4] This figure shows an example of the hardware configuration of the wallet management distributed ledger node 32. [Figure 5] FIG. 18 is a diagram showing an example of the hardware configuration of the wallet management distributed ledger client 18. [Figure 6] FIG. 19 is a diagram showing an example of key information. [Figure 7] FIG. 20 is a diagram showing an example of user information. [Figure 8] FIG. 21 is a diagram showing an example of workflow information. [Figure 9] FIG. 22 is a diagram showing an example of transaction information. [Figure 10] FIG. 23 is a flowchart showing an example of the processing procedure when the wallet management distributed ledger 17 is started up. [Figure 11] FIG. 24 is a flowchart showing an example of the processing procedure regarding the application of the workflow to the execution of the transaction in the usage group 13 of the organization.

Embodiments for Carrying Out the Invention

[0014] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.

[0015] Note that the following description and drawings are examples for explaining the present invention, and for the sake of clarity of explanation, appropriate omissions and simplifications are made. Also, not all combinations of features described in the embodiments are essential for the solution means of the invention. The present invention is not limited to the embodiments, and all application examples that conform to the idea of the present invention are included in the technical scope of the present invention. Those skilled in the art can make various additions and changes within the scope of the present invention. The present invention can also be implemented in various other forms. Unless otherwise limited, each component may be plural or singular.

[0016] In the following explanation, various types of information may be described using terms such as "table," "list," and "queue," but these types of information may also be represented using other data structures. To indicate independence from data structure, "XX table," "XX list," etc., may be referred to as "XX information." When describing the content of each type of information, terms such as "identification information," "identifier," "name," "ID," and "number" will be used, but these terms are interchangeable.

[0017] Furthermore, in the following explanations, when describing similar elements without distinction, a reference code or a common number in the reference code will be used. When describing similar elements with distinction, the reference code of that element will be used, or the ID assigned to that element will be used instead of the reference code.

[0018] Furthermore, while the following description may include explanations of processes performed by executing a program, the processor may be the primary entity performing the processing, as a program is executed by at least one processor (e.g., a CPU) and performs defined processes using appropriate memory resources (e.g., memory) and / or interface devices (e.g., communication ports). Similarly, the primary entity performing the processing by executing a program may be a controller, device, system, computer, node, storage system, storage device, server, management computer, client, or host having a processor. The primary entity performing the processing by executing a program (e.g., a processor) may include hardware circuits that perform some or all of the processing. For example, the primary entity performing the processing by executing a program may include hardware circuits that perform encryption and decryption, or compression and decompression. The processor operates as a functional unit that realizes predetermined functions by operating according to the program. Devices and systems including a processor are devices and systems including these functional units.

[0019] A program may be installed from its program source into a device such as a computer. The program source may be, for example, a program distribution server or a non-temporary storage medium readable by a computer. If the program source is a program distribution server, the program distribution server includes a processor (e.g., a CPU) and non-temporary storage resources, which may further store the distribution program and the program to be distributed. The processor of the program distribution server may then execute the distribution program, thereby distributing the program to other computers. Furthermore, in the following description, two or more programs may be implemented as a single program, or one program may be implemented as two or more programs.

[0020] Figure 1 shows an example of the overall configuration of a distributed ledger data management system 10 according to one embodiment of the present invention. The distributed ledger data management system 10 is a system that manages the exchange of data between individuals and organizations participating in a distributed ledger system (asset management distributed ledger 11). As shown in Figure 1, the asset management distributed ledger 11 has one or more individual user groups 12 and one or more organizational user groups 13 participating. Each individual user group 12 is used by one user 14 per group, and each organizational user group 13 is used by one organization (multiple users 15 belonging to that organization) per group.

[0021] In individual user group 12, the asset management distributed ledger client 16 manages the individual's wallet, and in response to an operation by a single user 14, the asset management distributed ledger client 16 reads and writes data to the asset management distributed ledger 11.

[0022] In the organization's user group 13, the wallet management distributed ledger 17 manages the organization's wallet, and the wallet management distributed ledger 17 reads and writes data to the asset management distributed ledger 11. In addition, in the organization's user group 13, multiple wallet management distributed ledger clients 18 operated by each user 15 of the organization are connected to the wallet management distributed ledger 17, and in response to operations by the organization's users 15, the wallet management distributed ledger clients 18 read and write data to the wallet management distributed ledger 17.

[0023] Figure 2 shows an example of the configuration of the asset management distributed ledger 11. The asset management distributed ledger 11 is a distributed ledger including a blockchain, configured such that multiple asset management distributed ledger nodes 22 communicate with each other via the asset management distributed ledger network 21.

[0024] The asset management distributed ledger 11 may be a public blockchain and distributed ledger that anyone can participate in, such as Bitcoin® or Ethereum®, or it may be a permissioned blockchain and distributed ledger that only authorized users and organizations can participate in, such as Hyperledger Fabric®. The asset management distributed ledger 11 is configured to be able to handle fungible tokens (FTs), such as cryptocurrencies, as well as non-faguriable tokens (NFTs), such as works of art, real estate, or game characters.

[0025] As shown in Figure 2, the asset management distributed ledger 11 (multiple asset management distributed ledger nodes 22 connected via the asset management distributed ledger network 21) reads and writes data via the asset management distributed ledger clients 16 of the individual user group 12, or the wallet management distributed ledger 17 of the organization user group 13. The number of asset management distributed ledger nodes 22, asset management distributed ledger clients 16, and wallet management distributed ledgers 17 can each be any number.

[0026] When the asset management distributed ledger client 16 reads from or writes to the asset management distributed ledger 11, a wallet containing the private key is required.

[0027] The asset management distributed ledger 11 and the wallet management distributed ledger 17 communicate with each other using interoperability technology that enables mutual communication between blockchains and distributed ledgers, allowing them to read and write to each other.

[0028] Figure 3 shows an example of the configuration of the wallet management distributed ledger 17. The wallet management distributed ledger 17 is a distributed ledger including a blockchain, configured such that multiple wallet management distributed ledger nodes 32 communicate with each other via the wallet management distributed ledger network 31.

[0029] Wallet management distributed ledgers 17 are permission-based blockchains and distributed ledgers, such as Hyperledger Fabric, that allow authorized users and organizations to participate.

[0030] As shown in Figure 3, the wallet management distributed ledger 17 (multiple wallet management distributed ledger nodes 32 connected via the wallet management distributed ledger network 31) reads and writes data via the wallet management distributed ledger clients 18 of the organization's user group 13. The number of wallet management distributed ledger nodes 32 and wallet management distributed ledger clients 18 can be any number.

[0031] Figure 4 shows an example of the hardware configuration of the wallet management distributed ledger node 32. As shown in Figure 4, the wallet management distributed ledger node 32 comprises an auxiliary storage unit 400, an arithmetic unit 430, a main memory unit 440, and a communication unit 450, each unit connected via a bus 460.

[0032] The arithmetic unit 430 is a processor that executes programs from the program unit 410, which are held in the auxiliary storage unit 400, by reading them into the main storage unit 440, and performs overall control of the device (wallet management distributed ledger node 32) itself, as well as performing various judgments, calculations, and control processing. Specifically, it is a CPU (Central Processing Unit).

[0033] Furthermore, the arithmetic unit 430 includes a secure computation unit 431. The secure computation unit 431 uses TEE (Trusted Execution Environment) technology to encrypt a portion of the area of ​​the main memory unit 440, thereby having a secure computation area 441 within the area of ​​the main memory unit 440, and can perform secure computation in the secure computation area 441.

[0034] Furthermore, the secure computation unit 431 and the secure computation area 441 may be a secure computation execution environment configured with secure computation techniques such as secure multi-party computation (MPC) and zero-knowledge proofs.

[0035] The auxiliary storage unit 400 houses the program unit 410 and the information storage unit 420.

[0036] The program unit 410 includes a key pair generation unit 411, a key pair management unit 412, a user management unit 413, a workflow management unit 414, a transaction issuance unit 415, and a wallet management distributed ledger startup unit 416.

[0037] The key pair generation unit 411 is a program that generates a key pair consisting of the private key and public key of the wallet management distributed ledger 17. The private key of the wallet management distributed ledger 17 is the private key required when using the wallet of the organization of user group 13. The key pair management unit 412 is a program that has the function of managing the key pair generated by the key pair generation unit 411. The user management unit 413 is a program that has the function of managing user information and permissions. The workflow management unit 414 is a program that has the function of realizing the business flow such as application and approval related to transaction issuance in the transaction issuance unit 415. The transaction issuance unit 415 is a program that has the function of managing the issuance of transactions. The wallet management distributed ledger startup unit 416 is a program that has the function of constructing the wallet management distributed ledger network 31.

[0038] Of the various programs managed by the program unit 410, all programs except the wallet management distributed ledger startup unit 416 are loaded into the secure computation area 441 in the main memory unit 440 via the bus 460, and are then executed by the secure computation unit 431 of the arithmetic unit 430, and the results are stored in the information storage unit 420.

[0039] The information storage unit 420 includes a distributed ledger 421 and a state database 422.

[0040] A distributed ledger 421 is a blockchain, which is a collection of data that links together transactions called blocks like a string of beads. A distributed ledger 421 includes a user ledger that holds user information, a key ledger that holds key information, a workflow ledger that holds workflow information, and a transaction ledger that holds transaction information.

[0041] The state database 422 is a database for storing the latest table data when a transaction managed in the transaction ledger of the distributed ledger 421 is executed.

[0042] Figure 5 shows an example of the hardware configuration of the wallet management distributed ledger client 18. As shown in Figure 5, the wallet management distributed ledger client 18 comprises an auxiliary storage unit 500, an arithmetic unit 530, a main memory unit 540, and a communication unit 550, each unit connected via a bus 560.

[0043] The arithmetic unit 530 is a processor that executes programs from the program unit 510, which are held in the auxiliary storage unit 500, by reading them into the main storage unit 540, and performs overall control of the device (wallet management distributed ledger client 18) itself, as well as performing various judgments, calculations, and control processing. Specifically, it is a CPU (Central Processing Unit).

[0044] The auxiliary storage unit 500 houses the program unit 510 and the information storage unit 520.

[0045] The program unit 510 includes a workflow application unit 511 and a workflow approval unit 512.

[0046] The workflow application unit 511 is a program that has the function of managing workflow applications from users (users 15). Users read and write data to the workflow management unit 414 of the wallet management distributed ledger node 32 through the workflow application unit 511. The data read and written via the workflow application unit 511 is information related to workflow applications to users with higher authority, such as requests to execute transactions that move assets in the asset management distributed ledger 11, or requests to view data.

[0047] The workflow approval unit 512 is a program that has the function of managing workflow approvals from users (users 15). Users read and write data to the workflow management unit 414 of the wallet management distributed ledger node 32 through the workflow approval unit 512. The data read and written through the workflow approval unit 512 is information regarding workflow approvals for requests to execute or view transactions involving the movement of assets from users with lower authority in the asset management distributed ledger 11. If approval is granted, a request is made to write that fact to the workflow management unit 414.

[0048] The information storage unit 520 holds the private key 521 for the wallet management distributed ledger. The private key 521 for the wallet management distributed ledger is a private key corresponding to the account of a user 15 using the wallet management distributed ledger client 18, and is used during processing between each wallet management distributed ledger client 18 and the wallet management distributed ledger 17, specifically, for example, during the application and approval of a workflow. The method for generating the private key 521 for the wallet management distributed ledger is not particularly limited; for example, when an account is created, the private key 521 for the wallet management distributed ledger for that account is passed from a certification authority (not shown) and stored in the information storage unit 520.

[0049] Figure 6 shows an example of key information. The key information 600 shown in Figure 6 is information about the key used when using the asset management distributed ledger 11, and is stored in the state database 422 of the wallet management distributed ledger node 32. Similar key information is also managed in the key ledger of the distributed ledger on the wallet management distributed ledger node 32.

[0050] Specifically, when a key pair is generated by the key pair generation unit 411 of the wallet management distributed ledger node 32, the key pair management unit 412 writes information about the key pair, including the encrypted key pair, to the distributed ledger 421, and further updates the state database 422 with the latest information (key information 600).

[0051] As shown in Figure 6, the key information 600 uses the key ID 601, which indicates the key identifier, as the key to manage the generated key 602, which is the body of the encrypted key, the generation date 613, which indicates the date and time the key was generated, and the usage 614, which indicates the intended use of the key.

[0052] Figure 7 shows an example of user information. The user information 700 shown in Figure 7 is information about each user (user 15) participating in the organization's user group 13, and is stored in the state database 422 of the wallet management distributed ledger node 32. Similar key information is also managed in the user ledger of the distributed ledger of the wallet management distributed ledger node 32.

[0053] Specifically, when user information is registered or updated by an administrator or other operator of the organization's user group 13, the user management unit 413 writes that information to the distributed ledger 421, and further updates the state database 422 with the latest information (user information 700).

[0054] As shown in Figure 7, the user information 700 uses the user ID 701, which is an identifier for the organization's users (users 15), as a key to manage information such as the username 702, which is the name of the user; the affiliation 703, which is the affiliation of the user within the organization; the position 704, which is the position of the user within the organization; and the approval flow 705, which is the approver of the user's application.

[0055] Figure 8 shows an example of workflow information. The workflow information 800 shown in Figure 8 is information related to the application and approval of a workflow, and is stored in the state database 422 of the wallet management distributed ledger node 32. Similar key information is also managed in the workflow ledger of the wallet management distributed ledger node 32.

[0056] As shown in Figure 8, the workflow information 800 manages information on the requester 802, who is the requester of the application, and the approver 803, who is the approver of the application, using a key 801 that indicates an identifier assigned to each workflow application. In the example in Figure 8, the identifier in key 801 contains the type of transaction that is requested to be executed in that application. For example, key 801 "Transfer 0710" means that a transaction for transfer processing is being requested (0710 is, for example, a serial number). The workflow information 800 is registered and updated by the workflow management unit 414.

[0057] In addition, for approver 803, "ok" is registered for each approver if the application has been approved, and "-" is also registered if the application has not been approved. When the approval status changes, the workflow management unit 414 updates the registration information for approver 803.

[0058] Figure 9 shows an example of transaction information. The transaction information 900 shown in Figure 9 is information regarding the execution (issuance) of a transaction, which becomes executable after the workflow application and approval process, and is stored in the state database 422 of the wallet management distributed ledger node 32. Similar key information is also managed in the transaction ledger of the wallet management distributed ledger node 32.

[0059] As shown in Figure 9, the transaction information 900 manages information on TX execution status 902, which indicates whether the transaction requested in the application can be executed, and TX execution status 903, which indicates the execution status of the transaction, using key 901, which corresponds to key 801 assigned to each workflow application, as the key. Key 901 corresponds to key 801 of the workflow information 800.

[0060] Transaction information 900 is registered and updated by the transaction issuing unit 415 (or workflow management unit 414). For example, when all approvers 803 in the workflow information 800 record corresponding to key 901 have approved (ok), the transaction issuing unit 415 updates the content of TX execution feasibility 902 to "OK," indicating that the transaction for key 901 can be executed. Furthermore, when the transaction for key 901 is issued, the transaction issuing unit 415 updates the content of TX execution 903 to "completed." Alternatively, the workflow management unit 414 may update TX execution feasibility 902 according to the updates in the workflow information 800 and notify the transaction issuing unit 415 when TX execution feasibility 902 becomes "OK."

[0061] The following describes the processes performed by the distributed ledger data management system 10, using the configuration of the distributed ledger data management system 10 and various data examples described above.

[0062] Figure 10 is a flowchart showing an example of the processing procedure when starting up the wallet management distributed ledger 17. The process shown in Figure 10 can also be used for the initialization process of the wallet management distributed ledger 17.

[0063] In Figure 10, first, the organization's administrator performs an operation to start up multiple wallet management distributed ledger nodes 32 (step S11). As a result, the wallet management distributed ledger node 32 sends a startup request to multiple wallet management distributed ledger nodes 32, and the wallet management distributed ledger startup unit 416 of the program unit 410 is started up in the multiple wallet management distributed ledger nodes 32 that receive the request.

[0064] Next, the wallet management distributed ledger startup units 416 in each of the multiple wallet management distributed ledger nodes 32 launched in step S11 connect with each other to construct the wallet management distributed ledger network 31 (step S12).

[0065] Next, one key pair generation unit 411 of the wallet management distributed ledger node 32 generates a key pair (step S13). In step S13, one wallet management distributed ledger node 32 may take the lead in generating the key pair with its key pair generation unit 411, while one or more other wallet management distributed ledger nodes 32 simultaneously execute the same process, generating random number seeds necessary for key pair generation. The leading wallet management distributed ledger node 32 may then confirm that the key pairs generated by the other nodes are identical, thereby reaching an agreement and confirming the use of that key pair.

[0066] Next, the key pair management unit 412 of each wallet management distributed ledger node 32 stores the key pair generated by one of the wallet management distributed ledger nodes 32 in step S13 by writing it to its own distributed ledger 421 and updating the key information 600 in the state database 422 (step S14). Alternatively, in step S14, the key pair management unit 412 of the wallet management distributed ledger node 32 that was the primary entity to generate the key pair in step S13 may store the key pair by writing it to the distributed ledger 421 and updating the key information 600 in the state database 422.

[0067] Next, the key pair management unit 412 registers the public key of the generated key pair in the asset management distributed ledger 11 and makes it possible to write transactions to the asset management distributed ledger 11 using the private key (step S15).

[0068] Finally, the user management unit 413 of the wallet management distributed ledger node 32 performs user registration (step S16), and the startup of the wallet management distributed ledger 17 is completed.

[0069] As described above, when the process shown in Figure 10 is executed, when the organization's user group 13 joins the distributed ledger data management system 10, the wallet management distributed ledger 17, which manages the organization's private key (the private key required when using the organization's wallet), can be launched in a configuration in which multiple nodes (wallet management distributed ledger nodes 32) are interconnected.

[0070] Furthermore, in the above process, the processes of the key pair generation unit 411, the key pair management unit 412, and the user management unit 413 in steps S13 to S15 are all performed using secure computation in the secure computation area 441. Therefore, in the wallet management distributed ledger 17, by using the secure computation function, the processes for generating and managing the organization's key pairs (especially private keys) can be performed in a state of confidentiality to the users 15 belonging to the organization's user group 13, thus avoiding the management of the organization's private keys becoming dependent on individuals.

[0071] Figure 11 is a flowchart showing an example of the processing procedure from workflow application to transaction execution in user group 13 of the organization.

[0072] Figure 11 shows a series of processing steps from when "User A," as shown in the user information 700 in Figure 7, requests (applies to the workflow) a "money transfer" process, when Users B and C (see approval flow 705 in user information 700), who are approvers of User A's request (application), approve it, and after the transaction execution feasibility is determined, the transaction issuing unit 415 executes the money transfer transaction. Users A, B, and C are users 15 belonging to the same organization's user group 13. The money transfer request made by User A is the application for "money transfer 0710" as shown in key 801 of the workflow information 800 in Figure 8.

[0073] In Figure 11, first, user A operates their wallet management distributed ledger client 18 to input a request for "transfer 0710," setting users B and C, as listed in the approval flow 705, as approvers (step S21). In step S21, the wallet management distributed ledger client 18, having received the input of the request from user A, has its workflow application unit 511 send a workflow application corresponding to the request to the workflow management unit 414 of the wallet management distributed ledger node 32. The workflow management unit 414, having received the application, then stores information related to the application in the state database 422 (workflow information 800 and transaction information 900). Furthermore, the workflow management unit 414 may also notify the wallet management distributed ledger clients 18 of users B and C, who are the approvers, of the request for approval of the application.

[0074] Next, users B and C operate the wallet management distributed ledger client 18 to confirm that they have received an approval request (specifically, by referring to the workflow information 800 and transaction information 900 in the state database 422) and write an indication that they approve the request (step S22). When users B and C perform the operation to write the approval in step S22, the workflow approval unit 512 of the wallet management distributed ledger client 18 notifies the workflow management unit 414 of the wallet management distributed ledger node 32 of the approval, and the workflow management unit 414 saves the information regarding the approval in the state database 422 (workflow information 800 and transaction information 900).

[0075] Next, the workflow management unit 414 confirms that approval has been obtained from all approvers (users B and C) (that all approvers 803 in the "Transfer 0710" record in workflow information 800 have turned "ok"), and determines that the "Transfer 0710" transaction is executable. It then writes "OK" to the TX execution status 902 of the "Transfer 0710" record in transaction information 900 (step S23).

[0076] Next, the transaction issuing unit 415 issues a remittance transaction to the asset management distributed ledger 11 (step S24).

[0077] Finally, the transaction issuing unit 415 writes "Completed" to the TX execution 903 of the "Transfer 0710" record in the transaction information 900 (step S25), and terminates the process. In step S25, the transaction issuing unit 415 may also notify the wallet management distributed ledger client 18 to which user A made the request in step S21, and the wallet management distributed ledger client 18 to which the request was approved in step S22, of the completion of the requested transfer process.

[0078] As described above, when the process shown in Figure 11 is executed, the distributed ledger data management system 10 can, when a user 15 belonging to the organization's user group 13 submits a workflow request, issue a transaction corresponding to the request from the wallet management distributed ledger 17 to the asset management distributed ledger 11 using the organization's private key, once the workflow is approved. Subsequently, the transaction is processed in the asset management distributed ledger 11.

[0079] Furthermore, as explained in the process in Figure 10, the organization's private key generated by the key pair generation unit 411 in a confidential state (secure computation) is managed in the key information 600 in a confidential state (still encrypted). In the process in Figure 11, all processes executed by the wallet management distributed ledger node 32 are performed by secure computation in the secure computation area 441, and the wallet management distributed ledger 17 issues transactions to the asset management distributed ledger 11 using this confidential private key. Therefore, when using the organization's wallet, the wallet management distributed ledger 17 can keep the private key used when using the organization's wallet confidential from the user 15 (without the organization's private key becoming personal to the user 15), from the workflow application by the user 15 to the execution of the transaction.

[0080] Furthermore, the processing of requests for remittances and other transactions from individual user group 12 is the same as that used in conventional distributed ledger systems utilizing blockchain technology, so a detailed explanation will be omitted.

[0081] As described above, the distributed ledger data management system 10 according to this embodiment sets up a wallet management distributed ledger 17, which is configured in a way that multiple nodes (wallet management distributed ledger nodes 32) are interconnected via a wallet management distributed ledger network 31, in order to manage the organization's wallet itself, which is necessary for the user group 13 of organizations participating in the asset management distributed ledger 11, a distributed ledger system, to use the asset management distributed ledger 11, and connects the blockchains (asset management distributed ledger 11 and wallet management distributed ledger 17). Furthermore, the wallet management distributed ledger nodes 32 use secure computation technology as a security function of the arithmetic unit 430 (CPU) to generate the key pair (private key and public key) necessary for using the organization's wallet, and manage these keys themselves by encrypting them.

[0082] According to the distributed ledger data management system 10 configured in this way, the keys (especially private keys) necessary for using an organization's wallet can be managed in a decentralized manner, and furthermore, the system can be operated while keeping the contents of the keys secret from users (including users 15 of user group 13). [Explanation of symbols]

[0083] 10. Distributed ledger data management system 11. Distributed ledger for asset management 12,13 User Groups 14,15 users 16 Asset Management Distributed Ledger Client 17. Wallet Management Distributed Ledger 18 Wallet Management Distributed Ledger Client 21 Asset Management Distributed Ledger Network 22 Asset Management Distributed Ledger Nodes 31. Wallet Management Distributed Ledger Network 32 Wallet Management Distributed Ledger Nodes 400,500 Auxiliary storage 410,510 Programming Department 411 Key Pair Generation Unit 412 Key Pair Management Department 413 User Management Department 414 Workflow Management Department 415 Transaction Issuance Department 416 Wallet Management Distributed Ledger Setup Team 420,520 Information storage department 421 Distributed Ledger 422 State Database 430,530 Arithmetic unit 431 Secure calculation operation section 440,540 Main memory 441 Secret Computation Area 450,550 Communications Department 460,560 buses 511 Workflow Application Department 512 Workflow Approval Department 521 Wallet Management Distributed Ledger Private Key 600 Key Information 700 User Information 800 Workflow Information 900 Transaction Information

Claims

1. A distributed ledger data management system that manages the exchange of data between user groups of individuals and organizations participating in a distributed ledger system, A blockchain distributed ledger system comprising multiple distributed ledger nodes and a network of distributed ledgers constructed by connecting the multiple distributed ledger nodes to each other, Multiple user group systems that manage the wallets of multiple individual and organizational user groups participating in the distributed ledger system, as clients of each of the user groups of the said individuals or organizations, Equipped with, The user group system of the said organization comprises a wallet management distributed ledger that manages the wallets of the user groups of the said organization and is connected to the distributed ledger system, and a plurality of wallet management distributed ledger clients, which are terminals operated by users belonging to the user groups of the said organization and are connected to the wallet management distributed ledger. When the user group of the aforementioned organization joins the distributed ledger system, the wallet management distributed ledger is started in response to a startup request from the wallet management distributed ledger client, and the wallet management distributed ledger generates and manages the organization's private key in an encrypted state. When a user group of the said organization uses the said organization's wallet, the wallet management distributed ledger issues a transaction to the distributed ledger system using the encrypted private key of the said organization. A distributed ledger data management system characterized by the following features.

2. The aforementioned distributed ledger for wallet management is Multiple wallet management distributed ledger nodes are launched in response to the launch request from the wallet management distributed ledger client, and when using the organization's wallet, they issue transactions to the distributed ledger system using the organization's encrypted private key. The aforementioned network of wallet management distributed ledger nodes is constructed by connecting with each other, A distributed ledger of a blockchain configured to include, At least one of the plurality of wallet management distributed ledger nodes generates the organization's private key, and each of the plurality of wallet management distributed ledger nodes manages the private key in an encrypted state. The distributed ledger data management system according to feature 1.

3. The aforementioned wallet management distributed ledger node has a secure computation function that performs calculations in a confidential state, and uses the secure computation function to perform processes related to the generation and management of the organization's private keys. The distributed ledger data management system according to feature 2.

4. The wallet management distributed ledger node manages the organization's private key, which was generated in a confidential state, and the public key that is paired with the private key, in a confidential state, and issues transactions to the distributed ledger system using the confidential private key. The distributed ledger data management system according to feature 3.

5. The aforementioned wallet management distributed ledger client is A workflow application unit that performs processing related to an application from the first user of the organization requesting the issuance of a predetermined transaction, A workflow approval unit that performs processing related to the approval of the application by a second user of the same organization, which is different from the first user, This is achieved by executing a program. The aforementioned wallet management distributed ledger node is A workflow management unit manages the workflow from application to approval by exchanging data with the workflow application unit and the workflow approval unit, and when approval of the application is completed, it decides to issue the predetermined transaction. A transaction issuing unit issues the transaction to the distributed ledger system in accordance with the decision to issue the transaction by the workflow management unit, This is achieved through program execution. The distributed ledger data management system according to feature 4.

6. Each wallet management distributed ledger client uses a private key, which is uniquely managed by each wallet management distributed ledger client, to exchange information regarding the application and approval with the wallet management distributed ledger node. The distributed ledger data management system according to feature 5.

7. A data management method using a distributed ledger data management system that manages the exchange of data between user groups of individuals and organizations participating in a distributed ledger system, The distributed ledger data management system comprises a blockchain distributed ledger system comprising a plurality of distributed ledger nodes and a network of distributed ledgers constructed by connecting the plurality of distributed ledger nodes to each other, and a plurality of user group systems that manage the wallets of the individual or organizational user groups as clients of each of the user groups of the plurality of individuals and organizations participating in the distributed ledger system. The user group system of the said organization comprises a wallet management distributed ledger that manages the wallets of the user groups of the said organization and is connected to the distributed ledger system, and a plurality of wallet management distributed ledger clients, which are terminals operated by users belonging to the user groups of the said organization and are connected to the wallet management distributed ledger. When the user group of the aforementioned organization joins the distributed ledger system, the wallet management distributed ledger is started in response to a startup request from the wallet management distributed ledger client, and the wallet management distributed ledger generates and manages the organization's private key in an encrypted state. When a user group of the said organization uses the said organization's wallet, the wallet management distributed ledger issues a transaction to the distributed ledger system using the encrypted private key of the said organization. A data management method characterized by the following features.

Citation Information

Patent Citations

  • Method for processing privacy data of block chain, apparatus, device, and storage medium

    JP2021189431A

  • Information processing program and information processing device

    JP7108253B1

  • Method, apparatus, and computer-readable medium for authentication and authorization of networked data transactions

    US20210377045A1