Data storage system and reward guarantee method

A data distribution method allows low-performance devices to store blockchain data by fragmenting and distributing it across a network, enhancing reliability and enabling rewards for participants.

JP7848928B1Active Publication Date: 2026-04-21DAI NIPPON PRINTING CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
DAI NIPPON PRINTING CO LTD
Filing Date
2025-08-06
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Computers storing blockchains require high computing and memory capabilities for hash calculations and storage due to constant data addition, making it difficult for low-performance devices to participate effectively.

Method used

A data distribution method where devices divide data into fragments, transmitting them to other devices until they meet storage conditions, with a control device managing and rewarding participants.

Benefits of technology

Enables data storage using low-performance computers by distributing data across a network, improving reliability and enabling reward mechanisms for participants.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007848928000001_ABST
    Figure 0007848928000001_ABST
Patent Text Reader

Abstract

This technology provides a new method that utilizes a data distribution storage technique, which allows the use of relatively low-performance computers. [Solution] One aspect of the data storage system of the present disclosure is a data storage system in which a plurality of devices connected via a network store data in a distributed manner, wherein a commissioned device divides data into a plurality of data fragments, transmits each of the divided data fragments to a receiving device, the receiving device further divides the received data fragments if the received data fragments do not satisfy the division termination conditions, transmits each of the divided data fragments to other receiving devices, and stores the received data fragments if the received data fragments satisfy the division termination conditions, and resource-providing devices that are included in the plurality of devices and provided resources for the stored data fragments are guaranteed a reward.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a data storage system and Reward guarantee method law and is related to it.

Background Art

[0002] In recent years, with the improvement of computer performance and the acceleration of network communication speed, various technologies have been researched and developed to improve the reliability and robustness of data storage by storing data using a plurality of computers connected via a network. For example, in the distributed ledger technology called blockchain, a plurality of computers store a database with a structure in which aggregates of data called blocks are linked in a chain, and the use of hash technology makes it difficult to tamper with the data contained in the blocks.

[0003] In Patent Document 1, an electronic trading device that stores transaction data using blockchain technology has been proposed for the purpose of improving the confidentiality of data and the fairness of transactions related to electronic data transactions. This electronic trading device verifies the validity of this electronic data between the terminal on the transmission side and the terminal on the reception side of the electronic data.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] Computers that store blockchains require high computing and memory capabilities because they need to perform calculations such as hash value calculation, solving, and mining on their own, and also need to maintain the coexisting chains at each terminal on the chain. Furthermore, since new blocks are constantly being added to the blockchain, the computer needs a storage device with sufficient capacity to store them all.

[0006] This disclosure is made in light of the above circumstances and aims to provide a new technology that utilizes a data distribution storage method that can be used with relatively low-performance computers. [Means for solving the problem]

[0007] One aspect of the data storage system of the present disclosure is a data storage system in which a plurality of devices connected via a network store data in a distributed manner, wherein a delegated device included in the plurality of devices divides the data into a plurality of data fragments, and each of the divided data fragments The aforementioned multiple The data is transmitted to a receiving device included in the device, and if the received data fragment does not satisfy the division termination condition, the receiving device included in the plurality of devices further divides the received data fragment and each of the divided data fragments The aforementioned multiple The device transmits to other receiving devices included in the device, and if the received data fragment satisfies the division termination condition, the received data fragment is stored. The control device included in the data storage system is a receiving device that stores the received data fragments, and Data fragments included in and stored in the aforementioned plurality of devices At least one of the devices that performed arithmetic processing using Resource provisioning device The commissioned device will be billed Reward Manages settlement data that has been recorded. .

[0008] One aspect of the reward guarantee method of this disclosure is a reward guarantee method performed in a data storage system in which a plurality of devices connected via a network store data in a distributed manner, wherein a commissioned device included in the plurality of devices divides the data into a plurality of data fragments, and each of the divided data fragments The aforementioned multipleThe data is transmitted to a receiving device included in the device, and if the received data fragment does not satisfy the division termination condition, the receiving device included in the plurality of devices further divides the received data fragment and each of the divided data fragments The aforementioned multiple The device transmits to other receiving devices included in the device, and if the received data fragment satisfies the division termination condition, the received data fragment is stored. The control device included in the data storage system is a receiving device that stores the received data fragments, and Data fragments included in and stored in the aforementioned plurality of devices At least one of the devices that performed arithmetic processing using Resource provisioning device The commissioned device will be billed Reward Manages settlement data that has been recorded. . [Effects of the Invention]

[0010] This disclosure provides a new technology that utilizes a data distribution storage method that can be used with relatively low-performance computers. [Brief explanation of the drawing]

[0011] [Figure 1] Figure 1 is a schematic diagram showing an example of the system configuration of the data storage system of the first embodiment. [Figure 2] Figure 2 is a schematic diagram showing an example of the system configuration of the data storage system of the first embodiment. [Figure 3] Figure 3 is a block diagram showing an example of the hardware configuration of the control device according to the first embodiment. [Figure 4] Figure 4 is a block diagram showing an example of the hardware configuration of a node in the first embodiment. [Figure 5] Figure 5 is a block diagram showing an example of the control device and the functional configuration of each node in the first embodiment. [Figure 6] Figure 6 is a sequence diagram showing an example of the key sharing process for a control device and a node using a key sharing scheme based on the secret sharing method of the first embodiment. [Figure 7] Figure 7 shows an example of node control information in the first embodiment. [Figure 8] Figure 8 is an explanatory diagram illustrating an example of the data splitting method for the first embodiment. [Figure 9]FIG. 9 is a diagram showing an example of the data structure of a packet for transmitting a data piece by the node of the first embodiment. [Figure 10] FIG. 10 is an explanatory diagram of an example of a method for dividing data pieces in the first embodiment. [Figure 11] FIG. 11 is a diagram showing an example of the data structure of a packet for transmitting a data piece by the node of the first embodiment. [Figure 12] FIG. 12 is a diagram showing an example of the data structure of a packet for transmitting a data piece by the k-1th diffusion node of the first embodiment. [Figure 13] FIG. 13 is a sequence diagram showing an example of a process for entrusting the distributed storage of original data to other nodes in the first embodiment. [Figure 14] FIG. 14 is a flowchart showing an example of the data transmission process in the first embodiment. [Figure 15] FIG. 15 is a flowchart showing an example of the data piece diffusion process in the first embodiment. [Figure 16] FIG. 16 is a sequence diagram showing an example of a process for restoring original data from distributedly stored data pieces and a reward guarantee process for guaranteeing rewards to nodes storing data pieces in the first embodiment. [Figure 17] FIG. 17 is a flowchart showing an example of the restoration process performed by the node in the first embodiment. [Figure 18] FIG. 18 is a sequence diagram showing an example of a process for transferring distributedly stored data pieces to other nodes in Modification 1. [Figure 19] FIG. 19 is a schematic diagram of an example of the logical network configuration of the data storage system of the second embodiment. [Figure 20] FIG. 20 is a block diagram showing an example of the functional configurations of the control device and each node in the second embodiment. [Figure 21] FIG. 21 is a sequence diagram showing an example of a process for entrusting arithmetic processing to other nodes using the distributed storage method of the second embodiment. [Figure 22]Figure 22 is a sequence diagram showing an example of the outsourcing and acceptance of arithmetic processing programs distributed and stored in the data storage system of the second embodiment. [Figure 23] Figure 23 is a flowchart showing an example of the recruitment advertisement transmission process in the second embodiment. [Figure 24] Figure 24 is a flowchart showing an example of the restoration process performed by the node in the second embodiment. [Figure 25] Figure 25 is a flowchart showing an example of the response processing performed by the node in the second embodiment. [Figure 26] Figure 26 is a sequence diagram showing an example of a process that restores data to be processed, which is distributed and stored in the data storage system of the second embodiment, and performs alternative calculations. [Figure 27] Figure 27 is a sequence diagram showing an example of a process for returning the processing result of an computation to a delegated node using the distributed storage method of the second embodiment, and a reward guarantee process that guarantees a reward to the node that performed the computation on behalf of the other node. [Modes for carrying out the invention]

[0012] The embodiments of this disclosure will be described in detail below with reference to the drawings. However, this disclosure is not limited to the embodiments described below. Furthermore, the embodiments described below can be combined as appropriate.

[0013] (First Embodiment) First, the configuration of the data storage system of the first embodiment will be described.

[0014] Figures 1 and 2 are schematic diagrams showing an example of the system configuration of the data storage system 1 of the first embodiment. Figure 1 schematically shows an example of the physical network configuration of the data storage system 1, and Figure 2 schematically shows an example of the logical network configuration of the data storage system 1.

[0015] As shown in Figure 1, the data storage system 1 comprises a plurality of nodes 20 (an example of a plurality of devices). The data storage system 1 may also include a control device 10. Including the control device 10 facilitates the configuration of a trust space, guarantee of rewards, and the division of program data fragments in a complex manner. The control device may be a single device within the trust space, or it may be a consortium of multiple devices operating in parallel and performing endorsements based on mutual authentication. The data storage system 1 may also include a control device 10. Including the control device 10 facilitates the configuration of a trust space and guarantees of rewards. The control device 10 and the plurality of nodes 20 are connected via a network 2. Network 2 can be implemented by at least one of the following, for example, the Internet, a LAN (Local Area Network), and a mobile phone network. Network 2 may be a wired network, a wireless network, or a mixture of wired and wireless networks.

[0016] Furthermore, as shown in Figure 2, in the data storage system 1, multiple nodes 20 form a peer-to-peer (P2P) network (more specifically, a mesh network) to realize distributed data storage. In the network configuration example shown in Figure 2, the nodes 20 are represented by circular symbols, and the communication paths between the nodes 20 are shown by solid or dashed lines. Although the communication paths between the control device 10 and each node 20 are not shown, the control device 10 is configured to communicate with each node 20.

[0017] In the following explanation, if it is not necessary to distinguish each node 20 individually, they may be simply referred to as "node 20" collectively. Furthermore, if it is necessary to distinguish a node 20 from other nodes 20, it may be described using the symbols shown in parentheses in Figure 2 (e.g., 20-1, 20-2a~20-2c, 20-3a~20-3f, 20-La~20-Lc). Also, for the sake of clarity, the names and functions of each node will be described separately, but each node functions as another node that performs other roles in different contexts. Even in the context of dispersing the same data or data fragments, a single node may perform several functions.

[0018] The control device 10 controls multiple nodes 20 and can be implemented using a computer with slightly higher capabilities than an IoT microcontroller, such as a PC (Personal Computer) or server device. The control device 10 selects nodes with known characteristics (reliable) from among the various nodes present on the network 2 as nodes 20 constituting the data storage system 1 and places them under its control. The space composed of reliable nodes 20 and the control device 10 is called the trust space. Placing something under control means constructing a trust space or causing the nodes 20 to provide responses related to rewards in order to perform its role as the data storage system. As a method for placing something under control, for example, the credentials that serve as the source of the encryption key may be installed in the node's main memory in the initial shipment state, or the node may receive the encryption via an external storage medium such as a SIM card. Of course, it is also possible to place something under control by exchanging encryption over the network. When exchanging encryption, for example, all the contents disclosed in Japanese Patent Publication No. 6863514 can be used. A more robust trust space can be constructed by using the content disclosed in Japanese Patent Publication No. 6863514. In particular, it is desirable to use a key sharing method in which, in addition to the shared information which is the aforementioned encryption, a predetermined generated value is shared between the node 20 and the control device 10, and each uses the generated value to generate a plurality of first distributed information from the shared information using a predetermined encoding method which allows the pre-distribution data to be restored when all or part of the distributed data obtained by distributing the pre-distribution data into multiple parts is available, and one of the plurality of first distributed information or a derived information derived from the first first distributed information is shared as a common key. This method allows the use of a different encryption each time. Furthermore, the data storage system 1 may permit communication with other nodes 20 under its control as communication partners of nodes 20 under its control, but may prohibit communication with other nodes that are not under its control (whose identity is unknown).

[0019] As a result, each node 20's identity is guaranteed by the control device 10, and communication with nodes whose identity is not guaranteed (not under the control of the control device 10) is prohibited, thus guaranteeing that each node 20's communication partners are trustworthy. In this way, the control device 10 constructs a communication space of multiple nodes 20 under its control as a trusted space. More specifically, in the trusted space, connections between peers that have exchanged Zero Trust aircraft mutual authentication manifest as units, and a logical lower layer is formed by creating a mesh / nested trust relationship with multiple partners. On top of this, the control device 10 implements "complete whitelist communication," discarding and blocking all communications from / to (i.e., In / Out) to "nodes other than those in a trusted relationship." Furthermore, all communication packets are protected with an authentication key, signature, and strong encryption for sender identification, and their trustworthiness is checked multiple times. Therefore, no machine outside the trusted space can compromise communications and equipment within the trusted space, and is isolated from cyberattacks. If the control devices are a consortium of multiple machines that operate in parallel and perform endorsements based on mutual authentication, it is desirable that they possess powerful processing capabilities to implement stronger authentication and encryption. Multiple control devices exchange information separately for the operation of the organization, and the method of this exchange may be a normal transmission method or it may be held using the distributed method of the present invention. A control device can function as a node. A node can function as a control device. The role of a control device may be approved by the organization organizer or consortium.

[0020] Node 20 can be any communication device that can connect to network 2. Node 20 can be a variety of information processing devices, from high-performance information processing devices such as PCs, server devices, or game consoles, to low-performance information processing devices known as IoT (Internet of Things) devices, such as sensor devices or actuator devices.

[0021] If node 20 is the issuer of the original data to be stored in distributed storage, it divides the original data into multiple data fragments and sends each of the divided data fragments to other nodes 20 that are different from each other. Node 20 may maintain a list of other nodes with which it has previously exchanged data fragments, i.e., with which it has already established a trust relationship, and may send data fragments only to nodes on that list, or prioritize nodes on that list. Node 20 may also issue a recruitment notice seeking nodes to receive the data fragments and send processing code to nodes that apply. Furthermore, if node 20 is a receiver (receiving device) that receives data fragments from a higher node 20, and the received data fragment does not satisfy the division completion conditions, it may further divide the received data fragment and send each of the divided data fragments to other nodes 20 that are different from each other. When receiving data, node 20 may also act as a restorer (restorer device), checking the idle state of its own control device and main memory, etc., and if it determines that it is possible to execute the program data fragment, it may execute the program data fragment and send the result to the higher node. On the other hand, node 20 stores the received data fragments if they satisfy the partitioning termination conditions. Also, if node 20 is the restorer side that restores the original data, it recovers the distributed data fragments from other nodes 20 to restore the original data. If the original data is program data, the recruitment advertisement may include the computational load based on the Mega Instruction Process Steps (MIPS) and required time, the program size, the amount of memory required, and the amount of received data to be processed.

[0022] As a result, some of the multiple nodes 20 store data fragments of the original data, and the original data is stored in a distributed manner within the data storage system 1. Furthermore, the data fragments stored in the distributed nodes 20 can be retrieved as needed, and the original data can be restored. In the first embodiment, such distributed storage is realized using multiple nodes 20 that are under the control of the control device 10 to establish a trust space. Therefore, the reliability and robustness of data storage can be further improved, and new technologies utilizing the distributed data storage method, such as monetization (rewarding) using the distributed storage method, can be provided.

[0023] The following describes a method for rewarding resources provided for distributed data storage by the data storage system 1. In this description, node 20-1 (an example of a delegation device) is a delegation node (the issuer of the original data) that delegates the distributed storage of the original data, and transmits the original data by dividing it into data fragments. Examples of node 20-1 include surveillance cameras, and examples of original data include video data subject to evidence preservation, but are not limited to these. Nodes 20-2a to 20-2c, 20-3a to 20-3f, 20-La to 20-Lc, etc., are dissemination nodes (receiving sides) that disseminate the data fragments received from the higher-level node 20, and perform further division and storage of the received data fragments.

[0024] In the data storage system 1, the delegation node is predetermined as node 20-1, but the spreading nodes are determined dynamically. When delegating, the receiving candidate may determine whether it can accept the incoming transmission based on the memory of past communication records with the node, or it may transmit the expected role and communication data capacity as pre-negotiation and negotiate whether it will accept or reject the transmission. In other words, for the sake of explanation, nodes 20-2a to 20-2c, 20-3a to 20-3f, and 20-La to 20-Lc are referred to as spreading nodes here, but these are not predetermined and will be determined during the data storage processing. In the following explanation, nodes 20 other than node 20-1 that become spreading nodes may be collectively referred to as node 20' (an example of a receiving device).

[0025] Figure 3 is a block diagram showing an example of the hardware configuration of the control device 10 of the first embodiment. As shown in Figure 3, the control device 10 comprises a control device 11, a main memory 12, an auxiliary memory 13, a communication device 14, and various buses 19. The control device 11, the main memory 12, the auxiliary memory 13, and the communication device 14 are connected via the various buses 19. Thus, the control device 10 of the first embodiment has a general hardware configuration using a normal computer.

[0026] The control device 11 controls the overall operation of the control system 10. The control device 11 may be, for example, at least one of a CPU (Central Processing Unit) and a GPU (Graphics Processing Unit), but is not limited to these. There may be one or more CPUs or GPUs, and they may be single-core or multi-core.

[0027] Examples of main memory 12 include, but are not limited to, ROM (Read Only Memory) and RAM (Random Access Memory). ROM stores various programs, such as a program for controlling the control device 10 and a control program for controlling multiple nodes 20. RAM is used as a workspace when the control device 11 performs various controls based on the programs stored in ROM.

[0028] The auxiliary storage device 13 stores the various programs described above, as well as various data used to control the multiple nodes 20. The various programs described above only need to be stored in at least one of the main storage device 12 and the auxiliary storage device 13. Examples of the auxiliary storage device 13 include, but are not limited to, at least one of existing storage devices capable of magnetic, electrical, or optical storage, such as an HDD (Hard Disk Drive), SSD (Solid State Drive), and DVD (Digital Versatile Disc). The auxiliary storage device 13 may be built into the control device 10 or externally connected to the control device 10 via an interface such as USB (Universal Serial Bus). Furthermore, the auxiliary storage device 13 may be a NAS (Network Attached Storage) connected via a network such as a LAN or WAN (Wide Area Network).

[0029] The communication device 14 is used to communicate with node 20 and other devices via network 2. Examples of the communication device 14 include, but are not limited to, a communication device for a wired LAN or a wireless communication device for a wireless LAN.

[0030] In addition to the above configuration, the control device 10 of the first embodiment may further include hardwired circuits such as ICs (Integrated Circuits), ASICs (Application Specific Integrated Circuits), and FPGAs (Field-Programmable Gate Arrays) specific to the control device 10.

[0031] Figure 4 is a block diagram showing an example of the hardware configuration of node 20 in the first embodiment. As shown in Figure 4, node 20 comprises a control device 21, a main memory 22, an auxiliary storage device 23, a communication device 24, and various buses 29. The control device 21, the main memory 22, the auxiliary storage device 23, and the communication device 24 are connected via the various buses 29. Thus, node 20 in the first embodiment has a general hardware configuration using a normal computer.

[0032] The control device 21 controls the overall operation of each node 20. The implementation method for the control device 21 is the same as for the control device 11, but it may also be implemented by, for example, an MPU (Micro Processing Unit).

[0033] The implementation method for main memory 22 is the same as that for main memory 12, so a detailed explanation will be omitted. The ROM of main memory 22 stores various programs, such as a program for controlling node 20 and a distributed storage / recovery program for distributing data and recovering distributed data.

[0034] The auxiliary storage device 23 stores various data, such as the various programs and data fragments mentioned above. The various programs mentioned above only need to be stored in at least one of the main memory device 22 (ROM) and the auxiliary storage device 23. The implementation method for the auxiliary storage device 23 is the same as that for the auxiliary storage device 13, so a detailed explanation is omitted. The programs may be interpreter language source code or executable binaries.

[0035] The communication device 24 is used to communicate with the control device 10 and other nodes 20 via the network 2. Since the implementation method for the communication device 24 is the same as that for the communication device 14, a detailed explanation is omitted.

[0036] In addition to the above configuration, the node 20 of the first embodiment may further include hardwired circuits such as ICs, ASICs, and FPGAs specific to the node 20.

[0037] Figure 5 is a block diagram showing an example of the functional configuration of the control device 10 and each node 20 in the first embodiment. As shown in Figure 5, the control device 10 includes a key sharing unit 101, a secure communication establishment unit 103, and a control unit 105. The key sharing unit 101, the secure communication establishment unit 103, and the control unit 105 can be realized, for example, by the control device 11, main memory 12, and communication device 14 described in Figure 3.

[0038] The control device 11 reads a control program stored in the main memory 12 (ROM) or auxiliary memory 13, for example, and loads it into the main memory 12 (RAM). The control device 11 implements each of the above-mentioned functional units by executing various processes according to the loaded program. Here, the above-mentioned functional units have been explained using the example of implementation as software, but at least a part of each of the above-mentioned functional units may be implemented as hardware. In this case, the functional unit to be implemented as hardware may be implemented, for example, by the hardwired circuit described above. Alternatively, any of the above-mentioned functional units may be implemented through the cooperation of software and hardware.

[0039] Furthermore, as shown in Figure 5, node 20-1, which is a delegated node (delegated device), includes a key sharing unit 201, a secure communication establishment unit 203, a delegated processing unit 211, and a restoration processing unit 281. Nodes 20' (nodes 20 other than node 20-1), which become spreading nodes (receiving devices), include a key sharing unit 201, a secure communication establishment unit 203, a spreading processing unit 221, and a response processing unit 241.

[0040] The functional configuration of each node 20 shown in Figure 5 is merely an example of the functional units necessary for the role that each node 20 plays, and the functional units included in each node 20 are not limited to these. Therefore, each node 20 may include all of the following: key sharing unit 201, secure communication establishment unit 203, delegation processing unit 211, propagation processing unit 221, response processing unit 241, and restoration processing unit 281.

[0041] Each of the above-mentioned functional units of node 20 can be realized, for example, by the control device 21, main memory 22, and communication device 24 described in Figure 4. The control device 21 reads, for example, a distributed storage and recovery program stored in the main memory 22 (ROM) or auxiliary storage device 23 and expands it into the main memory 22 (RAM). The control device 21 realizes each of the above-mentioned functional units by executing various processes according to the expanded program. Here, the case in which each of the above-mentioned functional units is realized as software has been explained as an example, but at least a part of each of the above-mentioned functional units may be realized as hardware. In this case, the functional unit to be realized as hardware can be realized, for example, by the hardwired circuit described above. Alternatively, any of the above-mentioned functional units may be realized through the cooperation of software and hardware.

[0042] (Trust space building process) First, the process for establishing a communication space with multiple nodes 20 as a trusted space will be explained with reference to the key sharing unit 101, secure communication establishment unit 103, and control unit 105 of the control device 10 described above, as well as the key sharing unit 201 and secure communication establishment unit 203 of the node 20.

[0043] Prior to placing node 20 under its control, control device 10 verifies the identity and location of node 20. If there are no problems with the identity and location of node 20, control device 10 may establish a secure communication (secure communication channel) by sharing a common key with node 20 using a key sharing method based on secret sharing. However, the encryption exchange method described in Patent No. 6863514, as mentioned above, can also be adopted. The encryption exchange method described in Patent No. 6863514 was difficult to implement by dividing and storing existing data fragments, but it became possible due to the existence of control device 10 or a trusted space. Furthermore, the hash value of previously exchanged data may be used as the common key, or the hash value may be used to select which encryption key to use according to Patent No. 6863514.

[0044] Figure 6 is a sequence diagram showing an example of the key sharing process between the control device 10 and node 20 using a key sharing method based on the secret sharing method of the first embodiment.

[0045] First, the key sharing unit 201 of node 20-1 distributes the file (A) it holds into two files (Aa, Ab) using an encryption key (step S101). In this embodiment, file (A) can be of any format. File (A) can be, for example, a file containing a program capable of executing data processing (e.g., source code for an interpreter) that node 20-1 delegates to other nodes 20, or it can be the program itself. However, it is not limited to this, and file (A) can also be a structured document such as JSON (JavaScript Object Notation) or XML (Extensible Markup Language), or a CSV (Comma Separated Values) file.

[0046] Alternatively, instead of the key sharing unit 201 of node 20, the key sharing unit 101 of control device 10 may use the encryption key to distribute the file (A) it holds into two files (Aa, Ab). In this case, file (A) may include, but is not limited to, device-specific information such as the device's serial number, device ID (IDentification), device model number (part number), manufacturer name, device catalog number, or device instruction manual number of the control device 10.

[0047] The file distribution method may be a secret sharing scheme that encrypts the original data using a symmetric-key cryptography scheme and distributes it to multiple distributed files, or it may be a method that encrypts the original data using a symmetric-key cryptography scheme and then divides (fragments) it into multiple data files. The secret sharing scheme is a predetermined encoding method that allows the original data to be restored by obtaining all or part of the distributed data obtained by distributing the original data into multiple files. In the former, encryption and distribution are performed simultaneously, while in the latter, encryption and fragmentation are performed separately. As encryption algorithms, for example, DES (Data Encryption Standard) or AES (Advanced Encryption Standard) can be used. If the file is a program, during distribution, each node may divide the program in a manner similar to how a part of the program is made into a function, and, separate from the hierarchy, each program fragment may have a tree-like identifier that indicates which fragmented program fragment it is and its fragmentation structure. For example, rule-based fragmentation can be used for fragmentation. As another example, fragmentation may be performed by an AI trained by machine learning. Fractionation may be performed by the control device 10. Fractionation by an AI trained by machine learning can handle complex configurations. When using the control device 10, the load on low-performance nodes is reduced. Existing methods such as deep learning are used as appropriate for machine learning.

[0048] The accepting device notifies the commissioning device of its identity and its "acceptance" of data processing. The accepting device receives the commissioning device ID or data ID or segmented branch number structure or appendix number of the target device to be processed, and the final recovery key of the assigned program from the commissioning device. At this time, the commissioning device ID or data ID or segmented branch number structure or appendix number may be included in the advertisement, and the exchange of data IDs may be carried out by this. The accepting device feeds the specified data to be processed into the reproducible independent miniature program and obtains the calculation result. The accepting device attaches the data ID to the calculation result and disseminates it using its own derived key. At this time, the current communication key with the requester may be used as the secret sharing decryption key.

[0049] By distributing the files, even if file (A) is leaked or illegally obtained, the attacker will not know the encryption key or distribution algorithm, thus preventing them from guessing the two files (Aa and Ab).

[0050] Next, the key sharing unit 201 of node 20 or the nodes 20 exchanging files send one of the two files (A-a, A-b) (here, file (A-a), an example of shared information) to the control device 10 for sharing (step S103). The following description assumes that the control device 10 is the other party. In the case of exchange between nodes 20, appropriately replace node 20 with one node 20 and control device 10 with the other node 20. The key sharing unit 101 of the control device 10 receives file (A-a) and holds it in the auxiliary storage device 13. As a result, the control device 10 and node 20 share file (A-a).

[0051] It is also possible not to share file (A) as shared information. In this case, by sharing file (Aa) as shared information, even if file (Aa) is leaked or illegally obtained, two different files (Aa', Ab') can be generated again using file (A). Therefore, the control device 10 and node 20 can each generate different common keys as described later, and the impact of the leakage or illegal acquisition of shared information can be reduced.

[0052] Next, the key sharing unit 101 of the control device 10 sends an authentication request to the node 20 (step S105).

[0053] Next, the key sharing unit 201 of node 20 generates a random number (R) (an example of a generated value) (step S107), and transmits the generated random number (R) to the control device 10 to share the random number (R) (step S109). The key sharing unit 201 of node 20 can store the generated random number (R) in the auxiliary storage device 23, and the key sharing unit 101 of the control device 10 can store the received random number (R) in the auxiliary storage device 13.

[0054] Next, the key sharing unit 201 of node 20 distributes file (Aa) into n+1 files (Aaa, Aa1, ..., Aan) using a random number (R) as the encryption key (step S111). The file distribution here can use the method exemplified in step S101. The key sharing unit 201 of node 20 can store the generated files (Aaa, Aa1, ..., Aan) in the auxiliary storage device 23.

[0055] Next, the key sharing unit 101 of the control device 10, like the node 20, uses a random number (R) as the encryption key to distribute file (Aa) into n+1 files (Aaa, Aa1, ..., Aan) (step S113). The method illustrated in step S101 can also be used for distributing the files here. The key sharing unit 101 of the control device 10 can store the generated files (Aaa, Aa1, ..., Aan) in the auxiliary storage device 13.

[0056] Furthermore, the control device 10 and node 20 may use a derived value (R') derived from the random number (R) as the encryption key instead of the random number (R). Also, each time the random number (R) is shared between the control device 10 and node 20, the random number (R) generated by the key sharing unit 201 of node 20 may be a different value.

[0057] Next, the key sharing unit 101 of the control device 10 sends one of the n+1 files (Aaa, Aa1, ..., Aan) (in the example shown in the figure, file (Aaa)) to node 20 as distributed information for authentication (step S115).

[0058] Next, the key sharing unit 201 of node 20 authenticates the control device 10 by comparing the received file (Aaa) with the file (Aaa) it holds (Step S117). Specifically, if the received file (Aaa) and the file (Aaa) held by node 20 match, the key sharing unit 201 of node 20 determines that the control device 10 is a legitimate device and that authentication is successful. In this case, the key sharing unit 201 of node 20 sends a notification of authentication completion to the control device 10 (Step S119). Note that if the received file (Aaa) and the file (Aaa) held by node 20 do not match, the key sharing unit 201 of node 20 can stop processing, determining that authentication is not possible.

[0059] Next, the key sharing unit 201 of node 20 generates a shared key (in this case, shared key F1 from file (Aa1)) from one of the n files (Aa1, ..., Aan) if authentication is successful (step S121). The shared key can be generated using a key derivation algorithm that applies a HASH function or the like to the file. Alternatively, the file itself or a part of the file used in the previous communication may be used as the shared key.

[0060] Next, the key sharing unit 101 of the control device 10, like the node 20, generates a common key (in this case, a common key F2 from file (Aa2)) from one of the n files (Aa1, ..., Aan) (step S123).

[0061] From this point onward, the secure communication establishment unit 103 of the control device 10 and the secure communication establishment unit 203 of the node 20 establish secure communication using a double symmetric key with common keys F1 and F2 (step S125), and the required data can be double-encrypted and decrypted using the common key.

[0062] Specifically, the key sharing unit 101 of the control device 10 not only generates a common key F1 from file (Aa1) among the n files (Aa1, ..., Aan), but also generates a common key (for example, a common key Fn from file (Aan)) for establishing secure communication to notify node 20 of the common key F1. Similarly, the key sharing unit 201 of node 20 not only generates a common key F2 from file (Aa2) among the n files (Aa1, ..., Aan), but also generates a common key (for example, a common key Fn from file (Aan)) for establishing secure communication to notify control device 10 of the common key F2. As a result, the secure communication establishment unit 103 of the control device 10 and the secure communication establishment unit 203 of node 20 establish secure communication using a single common key with the common key Fn. The secure communication establishment unit 103 of the control device 10 notifies node 20 of the common key F1 in this single-key secure communication, and the secure communication establishment unit 203 of node 20 notifies the common key F2 in this single-key secure communication to the control device 10. As a result, both the control device 10 and node 20 can agree to use common keys F1 and F2 for double-key secure communication, and can establish double-key secure communication using the common keys F1 and F2 described above.

[0063] Furthermore, the sharing of two common keys (F1, F2) between the control device 10 and node 20 may be implemented not by secure communication using a single common key with the common key Fn, but by using a common random number generator and sharing a common key for the two random numbers (numbers) generated by this generator. Alternatively, it may be implemented by applying a hash function to the previous messages between the control device 10 and node 20 and sharing a common key for the two values ​​(numbers) derived from this hash function.

[0064] Furthermore, the secure communication using a dual symmetric key by the control device 10 and node 20 may be configured to change the symmetric key used for each session. In this case, one of the n files (Aa1, ..., Aan) that is not used to generate the symmetric key may be considered as file (Aa), and the processing from step S105 onwards in the flowchart shown in Figure 6 may be performed to generate the next generation of n+1 files for key generation and generate a new symmetric key.

[0065] Through the above process, the secure communication establishment unit 103 of the control device 10 establishes secure communication with node 20. The control unit 105 of the control device 10 issues a node ID that is unique in the trusted space and credentials that guarantee that node 20 is a trusted terminal to node 20 with whom secure communication has been established. Examples of credentials include, but are not limited to, a public key certificate that associates a public key with a certificate that verifies the identity of the issued node 20. The control unit 105 of the control device 10 may also send a private key corresponding to the public key to node 20 via secure communication and store the private key in the auxiliary storage device 23 of node 20.

[0066] The control device 10 performs the above-described process for each node 20 under its control, establishing secure communication for each node 20 and issuing credentials specific to that node. In other words, the control unit 105 of the control device 10 issues credentials for each node 20 to manage the identity of that node 20 based on the establishment of encrypted communication. The control unit 105 of the control device 10 manages the control information used for controlling the nodes 20 under its control on the auxiliary storage device 13.

[0067] Figure 7 shows an example of control information for node 20 in the first embodiment, where each node 20 is managed in association with its node ID (an example of device identification information). Credentials and location may also be managed in association. Location refers to the location of node 20 on network 2, and is not limited to address information such as an IP address. The control unit 105 of the control device 10 uses this control information to manage and control the communication partners of each node 20, thereby constructing a communication space of multiple nodes 20 under the control of the control device 10 as a trusted space. Note that if the IP address is IPv6, it is possible to communicate with unregistered addresses, so the above-described trusted space mechanism can prevent communication with addresses that are not in a trusted relationship. Also, if the IP address is IPv4 and the IP address of the communication partner is floating (the IP address is not fixed and changes dynamically), the communication partner can prevent its location from becoming unknown by providing the control device 10 with its current IP address and, if necessary, the port number in a timely manner based on its own key ID.

[0068] The above describes an example of the trust space construction process in the first embodiment. Note that the method for establishing secure communication between the control device 10 and the node 20 is not limited to the method described above; for example, all the contents disclosed in Japanese Patent Publication No. 6863514 can be used.

[0069] (Distributed memory processing) Next, the distributed storage processing of the first embodiment will be described with reference to the key sharing unit 201, the delegation processing unit 211 of node 20-1, and the diffusion processing unit 221 of node 20'.

[0070] First, let me explain about delegated nodes.

[0071] As mentioned above, node 20-1 is a delegation node that entrusts the distributed storage of the original data, and it divides the original data into data fragments and sends each of the divided data fragments to different nodes 20'. The original data is, for example, stored in the auxiliary storage device 23 of node 20-1.

[0072] The key sharing unit 201 of node 20-1 generates an encryption key, which is a shared key for encrypting the original data, when necessary, such as when a trust space has not been established or when stronger security is required. If the exchange is between nodes that have previously exchanged keys, the exchange of keys may be omitted by reusing the previous key or its derived key. For example, the key sharing unit 201 can generate an encryption key (an example of a first shared key) from an unused file (an example of a first distributed information file) among the n+1 files (examples of A aa, A a1, ..., A an, and multiple first distributed information files) generated in the trust space construction process described above. Alternatively, the key sharing unit 201 can generate an encryption key from an unused file among the next generation of n+1 files for key generation described above.

[0073] The consignment processing unit 211 of node 20-1 performs a process to generate a data ID for unique identification within the data storage system 1 for the source data to be consigned. The consignment processing unit 211 can generate a data ID by, for example, combining a predetermined device ID for node 20-1 with the date and time information at that time. In the following explanation, we will assume that an ID of "XYZ" has been generated as the data ID.

[0074] The delegation processing unit 211 of node 20-1 encrypts the original data to be delegated using the encryption key generated by the key sharing unit 201 and divides it into data fragments. The encryption and division of the original data may be done using the secret sharing method described above, or by encrypting the original data with a symmetric-key encryption method and then dividing (fragmenting) it into multiple data fragments. As for the encryption algorithm, for example, DES or AES can be used.

[0075] The number of divisions of the original data may be a predetermined fixed number, or it may be variable depending on the communication status, etc. Furthermore, an upper limit may be set for the number of divisions. Note that whether the number of divisions of the original data is fixed or variable may differ for each of the 20 nodes.

[0076] The delegated processing unit 211 of node 20-1 may, for example, specify the node ID of node 20-1 and query the control device 10 for a node 20' suitable for communication with node 20-1. A node 20' suitable for communication may be, for example, a node 20' with a short communication path distance (number of hops) to node 20-1, but is not limited to these. The delegated processing unit 211 may also communicate with the node 20' that the control device 10 has responded with and check the available capacity of the auxiliary storage device 23 of that node 20' and the communication speed with node 20-1.

[0077] If the number of divisions of the original data is fixed, the outsourcing processing unit 211 sets the number of nodes 20' that satisfy the conditions for communication partners from among the nodes 20' confirmed in this way as destinations for sending the divided data fragments. If the number of divisions of the original data is variable, the outsourcing processing unit 211 determines the number of divisions to be the number of nodes 20' that satisfy the conditions for communication partners and is less than or equal to the upper limit from among the nodes 20' confirmed in this way, and sets the number of nodes 20' less than or equal to the upper limit as destinations for sending the divided data fragments.

[0078] In the first embodiment, we will explain using the example where the number of data fragments divided by the delegated processing unit 211 of node 20-1 is 3, and the destination nodes 20 are nodes 20-2a to 20-2c. In this case, the delegated processing unit 211 divides the encrypted original data into data fragments 1 to 3, as shown in Figure 8. Figure 8 is an explanatory diagram of an example of the original data division method in the first embodiment. However, the number of data fragments and the destination nodes 20 are not limited to these.

[0079] The delegation processing unit 211 of node 20-1 generates packets for sending the divided data fragments 1 to 3 to nodes 20-2a to 20-2c. Figure 9 shows an example of the data structure of a packet sent by node 20-1 in the first embodiment. As shown in Figure 9, the data structure of the primary propagation packet by node 20-1, which is the delegation node (issuer), includes an owner data header, a payload, and an owner signature.

[0080] The owner data header corresponds to the data header of the primary propagation packet and includes the owner ID, data ID, and sub-number. The owner ID is the node ID "20-1" of node 20-1, which is the source (issuer) of the original data. The data ID is the original data ID "XYZ" mentioned above. The sub-number is the sub-number of the divided data fragment, and in the example shown in Figure 9, it is "1 / 3". The denominator indicates the number of divisions, and the numerator indicates which data fragment it corresponds to among the divided data fragments.

[0081] The payload includes a branched data fragment and an error correction code. The branched data fragment is the actual data fragment 1 indicated by the branched number in the owner data header. The error correction code is an error correction code (parity) that provides redundancy to the data fragment, and is data that allows the original data to be restored even if any of the data fragments are missing during the restoration of the original data. Various code generation methods such as Hamming codes, cyclic codes, or convolutional codes may be employed for the error correction code.

[0082] The owner signature may include the issue time and the digital signature. The issue time is the time the packet was issued. The digital signature is the hash value of the payload and the issue time encrypted with the private key of the owner node 20-1. As mentioned above, the private key of node 20-1 is stored, for example, in the auxiliary storage device 23 of node 20-1.

[0083] The delegated processing unit 211 of node 20-1 generates packets with the data structure shown in Figure 9 for each of the divided data pieces 1 to 3, and sends, for example, the packet for data piece 1 to node 20-2a, the packet for data piece 2 to node 20-2b, and the packet for data piece 3 to node 20-2c. In other words, each packet has the ID of the original data assigned to the data piece.

[0084] Next, we will explain diffusion nodes.

[0085] As mentioned above, node 20' is a spreading node (receiving device) that spreads data fragments received from the higher-level node 20, and performs further division and storage of the received data fragments. Below, we will describe an example in which node 20-2a further divides and spreads the received data fragments, and node 20-3a stores the received data fragments.

[0086] When node 20's spreading processing unit 221 receives a data fragment packet from node 20-1, it checks whether the data fragment contained in the received packet satisfies the partitioning termination condition. The partitioning termination condition is, but is not limited to, that the data size of the data fragment is smaller than a predetermined threshold. If node 20's spreading processing unit 221 determines that the data size of the data fragment is greater than or equal to the threshold and does not satisfy the partitioning termination condition, it further partitions the data fragment and sends each of the partitioned data fragments to other different nodes 20'. If it determines that the data size of the data fragment is smaller than the threshold and satisfies the partitioning termination condition, it stores the received packet (received data) in node 20's auxiliary storage device 23.

[0087] When the spreading processing unit 221 of node 20-2a receives a packet of data fragments shown in Figure 9 from node 20-1, it determines that the data size of data fragment 1 with the error correction code added is greater than or equal to a threshold, and therefore the partitioning termination condition is not met. In this case, the spreading processing unit 221 of node 20-2a considers data fragment 1 with the error correction code added to be a data fragment to be repartitioned and divides it into further data fragments.

[0088] The partitioning method used by the spreading processing unit 221 of node 20-2a is the same as the partitioning method used by the delegated processing unit 211 of node 20-1, except that encryption is not performed.

[0089] In the first embodiment, we will explain using the example where the number of data fragment divisions by the diffusion processing unit 221 of node 20-2a is 2, and the destination (diffusion destination) nodes 20 are nodes 20-3a to 20-3b. In this case, as shown in Figure 10, the diffusion processing unit 221 divides data fragment 1, to which the error correction code has been added, into data fragments 1-1 and 1-2. Figure 10 is an explanatory diagram of an example of the data fragment division method of the first embodiment. However, the number of data fragment divisions and the destination (diffusion destination) nodes 20 are not limited to these.

[0090] The propagation processing unit 221 of node 20-2a generates packets for transmitting (spreading) the divided data fragments 1-1 and 1-2 to nodes 20-3a and 20-3b. Figure 11 shows an example of the data structure of a packet for transmitting data fragments by node 20-2a in the first embodiment. As shown in Figure 11, the data structure of the packet for secondary propagation by node 20-2a, which is the primary propagation node, may include an owner data header, a secondary data header, a payload, and a primary signature.

[0091] The owner data header is the same as the owner data header in Figure 9. The secondary data header corresponds to the data header of the packet for secondary propagation and includes the primary ID and the sub-number. The primary ID is the node ID "20-2a" of node 20-2a, which is the primary propagation node of the received data fragment. The sub-number is the sub-number of the divided data fragment, and in the example shown in Figure 11, it is "1 / 2". The denominator indicates the number of divisions, and the numerator indicates which data fragment of the divided data fragment it corresponds to.

[0092] The payload includes a branched data fragment and an error correction code. The branched data fragment is the actual data fragment 1-1 indicated by the branched number in the secondary data header. The error correction code is an error correction code (parity) used to provide redundancy to the data fragment.

[0093] The primary signature may include the issuance time and the digital signature. The issuance time is the time the packet was issued. The digital signature is the hash value of the payload and the issuance time encrypted with the secret key of node 20-2a, which is the primary spreading node. As mentioned above, the secret key of node 20-2a is stored, for example, in the auxiliary storage device 23 of node 20-2a.

[0094] The spreading processing unit 221 of node 20-2a generates packets with the data structure shown in Figure 11 for each of the divided data pieces 1-1 and 1-2, and transmits (spreads) the packet of data piece 1-1 to node 20-3a and the packet of data piece 1-2 to node 20-3b. Although a detailed explanation is omitted, nodes 20-2b and 2c each divide the received data pieces 2 and 3 into two data pieces, and node 20-2b transmits (spreads) them to nodes 20-3c and 3d, and node 20-2c transmits them to nodes 20-3e and 3f.

[0095] For reference, Figure 12 shows the data structure of a packet for k-th order propagation by node 20', which is a k-1-th order propagation node. Figure 12 is a diagram showing an example of the data structure of a packet that transmits a data fragment by node 20', which is a k-1-th order propagation node in the first embodiment. As shown in Figure 12, the data structure of a packet for k-th order propagation by node 20', which is a k-1-th order propagation node, includes an owner data header, a secondary data header, ...k-th order data header, a payload, and a k-1-th order signature.

[0096] When the spreading processing unit 221 of node 20-3a receives a packet of data fragments shown in Figure 11 from node 20-2a, it determines that the data size of data fragment 1-1 with the error correction code added is smaller than the threshold and that the splitting termination condition is met. In this case, the spreading processing unit 221 of node 20-3a stores the received packet (received data) in the auxiliary storage device 23 of node 20-3a. Although a detailed explanation is omitted, nodes 20-3b to 3f also store the received data fragments. In other words, if the received data fragment satisfies the splitting termination condition, the spreading processing unit 221 of node 20' stores the received data fragment in association with a data ID.

[0097] In this way, the divided data fragments propagate through the network and are re-divided at each node 20', and finally, the multiple divided data fragments are stored at multiple nodes 20' that determine that the division termination conditions are met.

[0098] (Restoration process) Next, the recovery process for recovering data fragments (packets or transaction messages) distributed and stored in the data storage system 1 of the first embodiment and restoring the original data will be described with reference to the recovery processing unit 281 of node 20-1 and the response processing unit 241 of node 20'. Node 20' is a receiving device in relation to node 20-1 as a consignment device, and subsequent consignment devices that received program data fragments before node 20-M.

[0099] In the first embodiment, an example is described in which node 20-1, the data source, retrieves data fragments and performs the process of restoring the original data. However, the retrieval of data fragments and the restoration of the original data may be performed by a device other than node 20-1, or it may be performed in cooperation with a device other than node 20-1. Also, in the first embodiment, as described in the "distributed storage processing" above, it is assumed that nodes 20-3a to 20-3f store the received data fragments.

[0100] The recovery processing unit 281 of node 20-1 sends a recovery advertisement to node 20' specifying the data ID "XYZ" of the original data in order to recover the data fragment. The recovery advertisement may be a message that includes, for example, a command instructing that a response be sent if the data fragment with the specified data ID is stored, the data ID specifying the target data, and the node ID of the node 20-1 to which the response will be sent. The recovery advertisement may also include information that the receiving node can use to determine that the received program data fragment is executable, such as the computational load due to the megainstruction process steps (MIPS) and the time required, the program size, the amount of memory required, and the amount of received processing data. The recovery processing unit 281 of node 20-1 sends a recovery advertisement to nodes 20-La to 20-Lc, for example.

[0101] The response processing unit 241 of node 20', which received the retrieval advertisement, determines whether it has stored the data fragment (packet) with the data ID specified in the retrieval advertisement. If it determines that it has stored it, it sends a response message to node 20-1, the source of the retrieval advertisement, notifying it that it has stored the specified data fragment. The response message includes the sub-numbers of each data header contained in the stored packet (the packet containing the data fragment with the specified data ID) and the node ID of node 20'. For example, the response message may include information indicating that it is a response to the retrieval advertisement, as well as the sub-numbers of each data header and the node ID of node 20'.

[0102] Furthermore, the response processing unit 241 of node 20 that received the retrieval advertisement determines whether it holds the program data fragment (packet) with the data ID specified in the retrieval advertisement. If it determines that it does not hold the fragment, it forwards the retrieval advertisement to another node 20. If it determines that it does hold the fragment, it may also forward the retrieval advertisement to another node 20. In this way, the retrieval advertisement is transmitted to each node 20 included in the data storage system 1, and finally, the retrieval advertisement is received by node 20' that stores the data fragment. The response processing unit 241 of node 20' that stores the data fragment sends the above-described response message in response to the receipt of the retrieval advertisement.

[0103] In the first embodiment, as described above, since nodes 20-3a to 3f store data fragments, when the response processing unit 241 of nodes 20-3a to 3f receives a retrieval advertisement, it sends a response message to node 20-1, the source of the retrieval advertisement. This allows the restoration processing unit 281 of node 20-1 to collect the branch number of each data header indicating the data fragment and the node ID of the node 20' that stores the data fragment. The response message may be sent directly from the source nodes 20-3a to 3f to the destination node 20-1, or it may be sent from nodes 20-3a to 3f to node 20-1 via another node 20.

[0104] In the data storage system 1 according to the first embodiment, error correction codes are assigned to the data fragments. Therefore, even if some of the multiple data fragments obtained by dividing the original data are missing and not all data fragments are available, the original data can be restored if a certain number of data fragments are available. The restoration processing unit 281 of node 20-1, which sent the retrieval advertisement, receives a response message from node 20' which stores the data fragments, and when it has collected the branch numbers of each data header and the node ID for a number of data fragments that can be used to restore the data, it performs data restoration processing using this information.

[0105] The number of data fragments required to restore the original data may depend on the bit length and algorithm of the error correction code. The restoration processing unit 281 of node 20-1 performs data restoration when it has collected the branch number of each data header and the node ID for a predetermined number of data fragments (for example, 85% of the total). However, since restoration may not be possible with the information collected at this point, the restoration processing unit 281 of node 20-1 may use any additional information collected afterward for data restoration.

[0106] The restoration processing unit 281 of node 20-1 determines whether it is possible to restore the original data using the data fragments whose location is known at that time, based on the branch number of each collected data header. Specifically, the restoration processing unit 281 of node 20-1 examines the branch number of each collected data header and checks how complete the data fragments divided in the final stage of division are, thereby determining whether the data fragments in this final stage can be restored to the data fragments of the previous stage. Next, the restoration processing unit 281 of node 20-1 examines the branch number of each data header related to the data fragments that it has determined can be restored to the previous stage and checks how complete the data fragments divided in this stage are, thereby determining whether the data fragments in this stage can be restored to the data fragments of the previous stage. The restoration processing unit 281 of node 20-1 determines the feasibility of restoration by working backward from the final stage, and finally determines whether it is possible to restore the original data. If it is determined that it is impossible to restore the original data, the restoration processing unit 281 of node 20-1 waits until it receives additional information.

[0107] If it is determined that the original data can be restored, the restoration processing unit 281 of node 20-1 queries the control device 10 for the location of node 20' corresponding to the given node ID along with the branch number of the data header, and requests that node 20' to send the data fragment. At this time, the restoration processing unit 281 of node 20-1 sends a message to node 20' requesting the transmission of the data fragment specifying the data ID. This transmission request message may be sent directly from node 20-1 to node 20', or it may be sent indirectly via another node 20.

[0108] The response processing unit 241 of node 20', which stores data fragments, receives a transmission request message from node 20-1, reads the data fragment with the data ID specified in the received transmission request message from the auxiliary storage device 23, and sends it to the requesting node 20-1. In this way, the data fragment is retrieved based on the data ID. In the first embodiment, the response processing units 241 of the six nodes 20-3a to 3f send data fragments to node 20-1. These data fragments may be sent directly from nodes 20-3a to 3f to node 20-1, or they may be sent indirectly via other nodes 20.

[0109] The restoration processing unit 281 of node 20-1, upon receiving the data fragments, restores the data fragments to the original data based on the branch numbers of each data header. Data restoration is performed sequentially from the final data fragment to the previous data fragment, similar to the determination of whether restoration is possible as described above, until it is finally restored to the original single data. In each stage of restoration, the restoration processing unit 281 of node 20-1 combines the multiple data fragments in the order indicated by the branch numbers of each data header and performs error correction using error correction codes as necessary to restore the data fragments before splitting. Finally, the restoration processing unit 281 of node 20-1 restores the encrypted original data using the encryption key used for encryption. This allows node 20-1 to obtain the original data. When the restoration processing unit 281 of node 20-1 retrieves the data fragments to be processed, node 20-1 recruits nodes that have the first-stage data fragment of the data fragment (packet) to be processed with the specified data ID. However, for subsequent recruitment advertisements, it is desirable for each node to issue a recruitment advertisement seeking nodes that have performed a division one level deeper than the data fragment stage for which it wishes to aggregate.

[0110] If the original data is, for example, video data subject to evidence preservation as mentioned above, the original video data can be obtained at the necessary time by performing a restoration process at the time of submission of the evidence to the court, etc.

[0111] Here, each node 20' that stores a data fragment and notifies node 20-1 of the data fragment resulting from resource provision becomes a resource provider that provided resources for the stored data fragment, and is therefore guaranteed a reward. For this reason, when the restoration processing unit 281 of node 20-1 restores the original data, it notifies each node 20' that collected the data fragment of the reward, and each node 20' that has been notified of the reward requests the control device 10 for the reward. As a result, the control device 10 records the amount of reward that each node 20' requests from node 20-1 in the settlement ledger and settles the reward at a predetermined time. In addition, when the restoration processing unit 281 of node 20-1 restores the original data, it sends a termination advertisement specifying the data ID "XYZ" of the original data to node 20' and propagates it to each node 20'. As a result, the recovery of the original data with data ID "XYZ" is completed, and each node 20' is notified that the data fragment of the original data will be deleted. The reward can be implemented while ensuring its reliability through the existence of a control device, the establishment of a trust space, or the issuance of credentials that manage the identity of the device. By managing the reward, the probability of collecting reliable data edges is improved, and this improved probability makes it easier to recover missing data. While implementation is possible in embodiments other than this one, it is desirable for a control device to exist in order to properly respond to reward requests. In that case, it is desirable for the node to request the reward at the time of applying to the recruitment advertisement, such as at the start or end of applying to the recruitment advertisement. By having the node send a request for reward to the control device at the time of applying to the recruitment advertisement, the node and the control device can communicate directly, and the expansion of data fragment size can be prevented. The authenticity is also ensured by having the reward request made when the node applies to the recruitment advertisement. Furthermore, if the data fragment is a program data fragment, each node 20' that performs calculations using the program data fragment also becomes a resource provider device, and a reward is promised.

[0112] Next, the operation of the data storage system of the first embodiment will be described.

[0113] Figure 13 is a sequence diagram showing an example of the process for entrusting the distributed storage of the original data in the first embodiment to another node 20. Prior to this process, it is assumed that the trust space construction process by the control device 10 has been completed.

[0114] First, the delegated node, node 20-1, performs a data transmission process in which it divides the original data into data fragments and sends them (step S201).

[0115] Figure 14 is a flowchart showing an example of the data transmission process in the first embodiment.

[0116] First, the key sharing unit 201 of node 20-1 generates an encryption key, which is a shared key for encrypting the original data (step S301). For example, the key sharing unit 201 can generate an encryption key from an unused file among the n+1 files (A aa, A a1, ..., A an) generated in the trust space construction process described above. Alternatively, the key sharing unit 201 can generate an encryption key from an unused file among the next generation of n+1 files for key generation described above.

[0117] Next, the delegation processing unit 211 of node 20-1 searches for a node 20' suitable for communication with node 20-1. If a trust space has been established or if data exchange has been confirmed with the node in question in the trust space, the data may be distributed without selecting which node to hand it over to. Node 20 may also designate a specific node 20 to receive the data fragment. When designating a node, past acceptance records may be used as a basis. In this case, the node may also search for other nodes 20' that can communicate with node 20-1 by querying the control device 10, having the control device 10 do so on its behalf, querying the control device 10, or checking the available capacity of the auxiliary storage device 23 of node 20' as answered by the control device 10, the communication speed with node 20-1, etc. (step S303).

[0118] Next, the delegated processing unit 211 of node 20-1 determines the number of divisions for the original data (step S305).

[0119] Next, the delegated processing unit 211 of node 20-1 generates a data ID for the original data to be uniquely identified within the data storage system 1 (step S307).

[0120] Next, the delegated processing unit 211 of node 20-1 encrypts the original data using the encryption key generated by the key sharing unit 201 (step S309), and divides it into the determined number of data fragments (step S311).

[0121] Next, the delegated processing unit 211 of node 20-1 generates packets to send each of the divided data fragments to different nodes 20' (step S313).

[0122] Next, the delegated processing unit 211 of node 20-1 sends each of the generated packets to a different node 20' (step S315).

[0123] Returning to Figure 13, node 20', which is a diffusion node, then performs a data fragment diffusion process, which involves further dividing and spreading the data fragments received from the higher-level node 20, or storing the received data fragments (step S203).

[0124] Figure 15 is a flowchart showing an example of data fragment diffusion processing according to the first embodiment.

[0125] First, the spreading processing unit 221 of node 20' waits to receive a data fragment packet from the higher-level node 20 (No in step S401), and when it receives a data fragment packet (Yes in step S401), it checks whether the data fragment contained in the received packet satisfies the splitting termination condition (step S403).

[0126] If the diffusion processing unit 221 of node 20' determines that the data size of the data fragment is greater than or equal to a threshold and does not satisfy the division termination condition (No in step S403), it determines the number of divisions for the data fragment (step S405).

[0127] Next, the diffusion processing unit 221 of node 20' divides the received data fragment into a determined number of data fragments (step S407).

[0128] Next, the spreading processing unit 221 of node 20' generates packets to send each of the divided data fragments to different nodes 20' (step S409).

[0129] Next, the propagation processing unit 221 of node 20' sends each of the generated packets to a different node 20' (step S411).

[0130] On the other hand, if the spreading processing unit 221 of node 20' determines that the data size of the data fragments contained in the received packet is less than a threshold and that the splitting termination condition is met (Yes in step S403), it stores the received packet (step S413).

[0131] Returning to Figure 13, the divided data fragments propagate through the network, undergoing further division at each node 20', and are ultimately stored at multiple nodes 20' that determine that the multiple divided data fragments satisfy the division completion conditions.

[0132] Figure 16 is a sequence diagram showing an example of a restoration process in the first embodiment, which restores the original data from distributed stored data fragments, and a reward guarantee process that guarantees a reward to the node 20' that stored the data fragments.

[0133] First, the recovery processing unit 281 of node 20-1 sends a recovery advertisement to node 20' specifying the data ID "XYZ" of the original data in order to recover the data fragment (step S221). If there is no node with an existing transaction, the control unit may be asked to act on behalf of the node. The control unit may also communicate which node should be entrusted with the task.

[0134] Next, the response processing unit 241 of node 20' waits for the reception of a retrieval advertisement from the higher node 20 (No in step S223), and upon receiving the retrieval advertisement (Yes in step S223), it forwards it to the other node 20 (step S225). In this way, the retrieval advertisement is transmitted to each node 20 included in the data storage system 1.

[0135] Next, the response processing unit 241 of node 20' determines whether or not it has stored the data fragment (packet) with the data ID specified in the retrieval advertisement (step S227).

[0136] If the response processing unit 241 of node 20' determines that it has stored a data fragment (packet) with the specified data ID (Yes in step S227), it notifies the control device 10 of the consigning node ID, which is the node ID of node 20-1 included in the retrieval advertisement, in order to inquire with the control device 10 about the location of node 20-1, the source of the retrieval advertisement (step S229).

[0137] Next, the control unit 105 of the control device 10 refers to the control information to confirm the location of node 20-1, which has been notified of the commissioning node ID, and notifies the source node 20' of the location of node 20-1, which is the commissioning node, and the credentials of the control device 10 (step S231).

[0138] Next, the response processing unit 241 of node 20' sends a response message to node 20-1 informing it that it has stored the specified data fragment, based on the location of node 20-1 that was notified (step S233).

[0139] Next, the restoration processing unit 281 of node 20-1 performs a restoration process to restore the original data (step S235).

[0140] Figure 17 is a flowchart showing an example of the restoration process performed by node 20-1 in the first embodiment.

[0141] First, the recovery processing unit 281 of node 20-1 waits to receive a response message from node 20' which stores the data fragments in response to the recovery advertisement sent in step S221 (No in step S501). When it receives a response message (Yes in step S501), it determines whether the number of data fragments whose location has been determined by the response messages received so far exceeds a predetermined threshold (step S503).

[0142] If the number of data points does not exceed the threshold (No in step S503), wait for a response message from node 20' storing the data fragments (No in step S501).

[0143] On the other hand, if the number of data exceeds a threshold (Yes in step S503), the restoration processing unit 281 of node 20-1 queries the control device 10 for the location of node 20' with the given node ID along with the branch numbers of the data headers received so far, and requests that node 20' to send a data fragment. Upon receiving the data fragment, the restoration processing unit 281 of node 20-1 restores the data fragment to the original data based on the branch numbers of each data header (step S505).

[0144] Next, the restoration processing unit 281 of node 20-1 restores the finally restored encrypted original data into a program for arithmetic processing using the encryption key used for encryption (step S507). This allows the restoration processing unit 281 of node 20-1 to obtain the original data.

[0145] Returning to Figure 16, the restoration processing unit 281 of node 20-1, upon successful restoration of the original data, notifies each node 20' that recovered the data fragments of a reward (reward claim right) for having distributed and stored the data fragments (step S237).

[0146] Next, the response processing unit 241 of node 20' requests the notified reward (reward claim right) from the control device 10 (step S239). The request data may also be stored in distributed storage as data fragments. In this case, an ID and hash signature may be attached.

[0147] Next, the control unit 105 of the control device 10 records in the settlement ledger the reward from node 20-1, the client node, to each node 20' that was storing the data fragments in a distributed storage manner (step S241). In other words, the control unit 105 of the control device 10 guarantees the reward from node 20-1 to each node 20' based on a claim made using the reward claim right of each node 20' that was storing the data fragments in a distributed storage manner. Based on this settlement ledger, the control unit 105 of the control device 10 makes the payment of the reward to each node 20' that was storing the data fragments in a distributed storage manner at the appropriate time.

[0148] If node 20' does not have a data fragment (packet) with the data ID specified in the retrieval advertisement (No in step S227), then steps S229, S231, S233, S237, and S239 will not be performed at node 20'.

[0149] Next, the restoration processing unit 281 of node 20-1 sends a termination notice to node 20' specifying the original data ID "XYZ" in order to complete the retrieval of the data fragments (step S243).

[0150] Next, the response processing unit 241 of node 20' waits to receive a termination advertisement from the higher-level node 20 (No in step S245), and upon receiving the termination advertisement (Yes in step S245), forwards it to the other node 20 (step S247). In this way, the termination advertisement is transmitted to each node 20 included in the data storage system 1.

[0151] Next, the response processing unit 241 of node 20' determines whether or not it has stored the data fragment (packet) with the data ID specified in the termination advertisement (step S249).

[0152] If the response processing unit 241 of node 20' determines that it has stored a data fragment (packet) with the specified data ID (Yes in step S249), it deletes the stored data fragment (step S251).

[0153] As described above, in this implementation, the control device 10 constructs a communication space of multiple nodes 20 under the control of the control device 10 as a trusted space. Therefore, distributed storage of data becomes possible among the nodes 20 whose origins are guaranteed by the control device 10, and monetization associated with this distributed storage becomes possible. Specifically, because the control device 10 is aware of the origins of each node 20, it can manage and guarantee the payment obligations of the requesting node and the right of the receiving node to receive rewards that arise from distributed storage.

[0154] (modified version) Next, a modified example of the first embodiment will be described. In each of the following modified examples, the parts that differ from the first embodiment will be mainly described, and the parts that are the same as the first embodiment will not be described.

[0155] (Variation 1) In the first embodiment described above, the node 20' that was storing the data fragments in a distributed storage manner may transfer the stored data fragments to other nodes 20'. In this way, the storage location of the distributed data fragments changes dynamically, thereby further enhancing the security of the distributed storage by the data storage system 1.

[0156] Furthermore, when node 20', which was storing the data fragments in a distributed manner, hands over the stored data fragments to other nodes 20', it may choose to delete the data fragments it is storing, or it may choose to retain them. If it retains them, the data fragments will be stored in a mirrored manner, increasing the redundancy of the data fragments and making it easier to restore the original data.

[0157] Figure 18 is a sequence diagram showing an example of the process of transferring distributed data fragments in Modification 1 to another node 20'. In the example shown in Figure 18, we will explain using the case in the above embodiment where node 20-3a transfers the packet of data fragment 1-1 shown in Figure 11, which is stored in distributed storage, to node 20-La. However, the transfer of data fragments is not limited to this and is performed dynamically, and in addition, data fragments that have already been transferred may be transferred again.

[0158] First, the propagation processing unit 221 of node 20-3a, which is storing the data fragment 1-1 packets in a distributed storage manner, specifies its own node ID and queries the control device 10 for the node 20' to which the data fragment 1-1 packets will be delivered (step S601).

[0159] Next, the control unit 105 of the control device 10 notifies node 20-3a of the location of node 20-La, which is a node 20' suitable for communication with node 20-3a, to be the destination node 20' to which the data fragment 1-1 packet will be delivered (step S603).

[0160] Furthermore, the diffusion processing unit 221 of node 20-3a may communicate with node 20-La, which has responded to the control device 10, to check the available capacity of the auxiliary storage device 23 of node 20-La, the communication speed with node 20-3a, and so on.

[0161] Next, the spreading processing unit 221 of node 20-3a duplicates the packet of data fragment 1-1, notifies node 20-La of the duplicated data fragment 1-1 packet (step S605), and has node 20-La store it.

[0162] Next, the spreading processing unit 221 of node 20-3a notifies node 20-1 of the data ID (XYZ) and branch number (1 / 3-1 / 2) of the data fragment 1-1 packet that was delivered to node 20-La (step S607).

[0163] As a result, node 20-1, which is the client for the distributed storage of the original data, can understand that node 20-3a has handed over data fragment 1-1, which node 20-3a had been storing in distributed storage, to another node 20' (node ​​20-La). Here, node 20-3a, which notified that it had handed over data fragment 1-1 to node 20-La as a result of providing resources, becomes a resource provider that provided resources for the stored data fragment, and is therefore guaranteed a reward. For this reason, node 20-1 can also notify node 20-3a, which changed the distributed storage destination of data fragment 1-1, of the reward based on this information. For example, node 20-1 may notify node 20-3a, which handed over data fragment 1-1, of the reward at the timing of notifying each node 20' that retrieved the data fragment, as described in the first embodiment above.

[0164] Next, the spreading processing unit 221 of node 20-3a discards the data fragment 1-1 packets that it has handed over to node 20-La, if necessary (step S609).

[0165] As described above, Modification 1 allows for the dynamic change of the storage location of the distributed original data, thereby enhancing security. Furthermore, Modification 1 guarantees rewards not only to the node 20' that stored the data fragments of the distributed original data, but also to the node 20' whose security has been enhanced by dynamically changing the storage location of the distributed original data. This is expected to encourage the expansion of the nodes 20' that are eligible for monetization, and to activate the dynamic changes in the storage location of the original data for the purpose of monetization.

[0166] (Modification 2) In the first embodiment described above, the notification of the data fragment to node 20-1, the source of the original data, and the notification of the reward to node 20', which notified the data fragment, were performed via bilateral communication between node 20-1 and node 20'. However, this may also be done by propagating it among the nodes 20', similar to collection advertisements and termination advertisements. In this case, the node 20' that propagated the reward notification may be given the right to receive a portion of the reward. For example, when node 20', which received the reward notification from node 20-1, requests the reward from the control device 10, it may also notify the control device 10 of the information of the node 20' that relayed the notification, and distribute a portion of the reward. In this case, the node 20' that relayed the notification higher up may receive a higher reward than the node 20' that relayed the notification lower down.

[0167] (Second Embodiment) In the second embodiment, the source data is a program for arithmetic processing, and a method is described in which one node 20 distributes storage of this program and delegates the arithmetic processing to other nodes 20. In the second embodiment, the parts that differ from the first embodiment will be mainly described, and the parts that are the same as in the first embodiment will be omitted from the explanation.

[0168] Figure 19 is a schematic diagram of a logical network configuration example of the data storage system 1 of the second embodiment. The data storage system 1 of the second embodiment shown in Figure 19 differs from the first embodiment in that it further includes nodes 20-M and 20-N. Hereinafter, node 20-1 is assumed to be a delegation node that delegates arithmetic processing and transmits the arithmetic processing program by dividing it into data fragments. Node 20-M is assumed to be a receiving node that accepts the delegated arithmetic processing, recovers the dispersed program data fragments to restore the arithmetic processing program, and executes the arithmetic processing using the restored program. Node 20-N is assumed to be a node that provides the data to be processed for arithmetic processing.

[0169] In data storage system 1, the commissioning node and the providing node are predetermined as node 20-1 and node 20-N, respectively, but the diffusion node and the receiving node are determined dynamically. In other words, for the sake of explanation, nodes 20-2a to 20-2c, 20-3a to 20-3f, and 20-La to 20-Lc are designated as diffusion nodes, and node 20-M is designated as the receiving node, but these are not predetermined and will be determined during the data storage processing. In the following explanation, nodes 20 that become diffusion nodes other than nodes 20-1, 20-M, and 20-N may be collectively referred to as node 20'. However, these are merely settings for the sake of explanation, and in reality, any of the commissioning node, diffusion node, receiving node, and providing node can be a commissioning node, diffusion node, receiving node, or providing node in the same data or data fragment diffusion / retrieval scenario, or in different scenarios.

[0170] Furthermore, while the example shown in Figure 19 illustrates one entrusted node, node 20-M, the number of entrusted nodes is not limited to this and may be multiple nodes.

[0171] Figure 20 is a block diagram showing an example of the functional configuration of the control device 10 and each node 20 in the second embodiment. In the second embodiment shown in Figure 19, node 20-1, which is the entrusted node, differs from the first embodiment in that it includes a receiving processing unit 291 instead of a restoration processing unit 281. Furthermore, node 20-M, which is the receiving node, includes a key sharing unit 201, a secure communication establishment unit 203, an entrusted processing unit 231, a processing execution unit 261, and a result processing unit 271. Furthermore, node 20-N, which is the providing node, includes a key sharing unit 201, a secure communication establishment unit 203, and a providing processing unit 251. When entrusting, the receiving candidate may self-determine whether it can accept the incoming message based on the memory of past communication history with the node, or it may transmit the expected role and communication data capacity as pre-negotiation and negotiate whether to accept or reject it. Depending on the data fragment, or depending on the division situation even with the same data fragment, the entrusted node may also be a receiving node. A entrusted node can also be a delegated node depending on the data fragment, or even depending on the partitioning of the same data fragment. Therefore, each component can be included in any node 20.

[0172] The trust space construction process is the same as in the first embodiment, except that nodes 20-M and 20-N are also included.

[0173] Furthermore, the distributed storage processing is the same as in the first embodiment, except that the original data is a program for arithmetic processing. However, after the data fragments obtained by dividing the program for arithmetic processing are stored in multiple nodes 20' that have determined that the division termination condition is met, node 20-1 issues a recruitment advertisement soliciting nodes 20 to undertake the arithmetic processing, and node 20-M responds to this recruitment advertisement, undertakes the arithmetic processing, and recovers the program data fragments distributed and stored in the data storage system 1 to restore the program for arithmetic processing. As will be described in detail later, node 20-M establishes secure communication with node 20-1 and obtains the encryption key used to encrypt the program for arithmetic processing and the data ID "XYZ" of the program for arithmetic processing from node 20-1.

[0174] Furthermore, the restoration process is the same as in the first embodiment, except that it is performed by the entrusted processing unit 231 of node 20-M instead of the restoration processing unit 281 of node 20-1. Node 20-M can obtain the arithmetic processing program through the restoration process, and thereby the processing execution unit 261 of node 20-1 can execute the arithmetic processing based on the arithmetic processing program, on behalf of the entrusted node. The data to be processed by the arithmetic processing is provided by the providing processing unit 251 of node 20-N. However, the providing processing unit 251 of node 20-N may apply the explanation of "distributed storage processing" to the data to be processed, divide the data to be processed into multiple data fragments, similar to the arithmetic processing program, send each of the divided data fragments to different nodes 20' for distributed storage in the data storage system 1, and the entrusted processing unit 231 of node 20-M may apply the explanation of "restoration processing" to the data fragments of the data to be processed, and recover the data fragments to restore the data to be processed, similar to the arithmetic processing program, thereby obtaining the data to be processed. If the receiving device determines that the received program data fragment is not executable by itself, it functions as a spreading node, which is another form of receiving device.

[0175] Furthermore, the processing results from the processing execution unit 261 of node 20-M are provided to node 20-1. However, the result processing unit 271 of node 20-M may apply the explanation of "distributed storage processing" to the processing result data, divide the data processing result data into multiple processing result data fragments, and transmit each of the divided processing result data fragments to different nodes 20' to distribute and store them in the data storage system 1. The receiving processing unit 291 of node 20-1 may then apply the explanation of "restoration processing" to the processing result data fragments, and, similar to the arithmetic processing program, retrieve the processing result data fragments to restore the processing result data, thereby obtaining the processing result data.

[0176] Furthermore, in the second embodiment, the case where there is only one node 20, node 20-M, which acts as the entrusted node was explained as an example, but multiple nodes 20 may be prepared to act as entrusted nodes. In this case, each of the multiple nodes 20 acting as entrusted nodes recovers program data fragments of the program for its own device, restores the program for its own device, and uses the restored program for its own device to execute data processing in parallel. The program for arithmetic processing (the program for its own device) may be different or the same for each entrusted node. The data processing executed in parallel can be, for example, machine learning processing. Here, for example, if the program for arithmetic processing is a machine learning program, pipeline-type machine learning processing using massive computing can be realized.

[0177] Figure 21 is a sequence diagram showing an example of a process for delegating computation processing to another node 20 using the distributed storage method of the second embodiment. Prior to this process, it is assumed that the trust space construction process by the control device 10 has been completed.

[0178] First, node 20-1, which is a delegated node (delegated device), performs a data transmission process in which it divides the program (program data) of the arithmetic processing to be delegated into program data fragments and transmits them (step S1201). Examples of the arithmetic processing program include, but are not limited to, a JAR (Java Archive) file that executes some minor process.

[0179] Here, by replacing the original data with a program for calculation processing and the data fragments with program data fragments, the flowchart of the data transmission process shown in Figure 14 can also be applied to the data transmission process by the delegated processing unit 211 of node 20-1.

[0180] Next, node 20', which is a spreading node (a receiving device, and may also be a contracted device), performs data fragment spreading processing, which involves further dividing and spreading the program data fragments received from the higher-level node 20, or storing the received program data fragments (step S1203).

[0181] Here, by replacing "data fragments" with "program data fragments," the flowchart of the data fragment diffusion process shown in Figure 15 can also be applied to the data fragment diffusion process of the program data fragments by the diffusion processing unit 221 of node 20'.

[0182] In this way, the divided program data fragments propagate through the network and are re-divided at each node 20', and finally, the multiple divided program data fragments are stored at multiple nodes 20' that determine that the division termination conditions are met.

[0183] Next, the data provisioning node, node 20-N, performs a data transmission process in which it divides the data to be processed for calculation (processing target data) into processing target data fragments and transmits them (step S1211).

[0184] Here, by replacing node 20-1 with node 20-N, the commissioned processing unit 211 with the providing processing unit 251, the original data with the data to be processed, and the data fragment with the data fragment to be processed, the flowchart of the data transmission process shown in Figure 14 can also be applied to the data transmission process by the providing processing unit 251 of node 20-N.

[0185] Next, node 20', which is a diffusion node, performs data fragment diffusion processing, which involves further dividing and distributing the data fragments to be processed received from the higher-level node 20, or storing the received data fragments to be processed (step S1213).

[0186] Here, by replacing "data fragment" with "data fragment to be processed," the explanation of the data fragment diffusion process flowchart shown in Figure 15 can also be applied to the data fragment diffusion process of the data fragment by the diffusion processing unit 221 of node 20'.

[0187] In this way, the divided data fragments to be processed propagate through the network and are re-divided at each node 20', and finally the multiple divided program data fragments are stored at multiple nodes 20' that determine that the division completion conditions are met. When delegating, the receiving candidate may determine whether it can accept the incoming message based on its memory of past communication history with the node, or it may send the expected role and communication data capacity as pre-negotiation and negotiate whether it will accept or reject the message. A delegating node may also be a receiving node depending on the data fragment, or depending on the division situation of the same data fragment. A receiving node may also be a delegating node depending on the data fragment, or depending on the division situation of the same data fragment. Therefore, each component can be included in any node 20.

[0188] Figure 22 is a sequence diagram showing an example of the outsourcing and acceptance of arithmetic processing programs distributed and stored in the data storage system 1 of the second embodiment.

[0189] First, the delegation processing unit 211 of node 20-1 sends a recruitment advertisement (an example of delegation request information) to node 20' for delegating computation processing to another node (step S1221). The recruitment advertisement can be a message that includes, for example, the node ID of node 20-1, which is the delegating node, the communication and processing load associated with the computation processing, and the reward for taking over the computation processing.

[0190] Next, the response processing unit 241 of node 20' performs recruitment advertisement transmission processing to transmit the recruitment advertisement to other nodes 20 (step S1223).

[0191] Figure 23 is a flowchart showing an example of the recruitment advertisement transmission process in the second embodiment.

[0192] First, the response processing unit 241 of node 20' waits to receive a recruitment advertisement from the higher-level node 20 (No in step S1501), and when it receives a recruitment advertisement (Yes in step S1501), it forwards it to the other node 20 (step S1503). In this way, the recruitment advertisement is transmitted to each node 20 included in the data storage system 1.

[0193] Next, the response processing unit 241 of node 20' determines whether or not to apply for the received recruitment advertisement (step S1505). For example, if the response processing unit 241 of node 20' determines that its primary function is idle, that the estimated "communication and processing load" in the recruitment advertisement can be adequately covered by its own surplus capacity, and that the operational cost (resources) for this exceeds the offered reward, then it applies for the recruitment advertisement.

[0194] Returning to Figure 22, we assume that Node 20-M, which will be the entrusted node, has decided to apply for the recruitment advertisement. The entrusted processing unit 231 of Node 20-M notifies the control device 10 of the node ID of Node 20-1, which is the entrusted node included in the recruitment advertisement (entrusted node ID), its own node ID (entrusted node ID), and the common key of Node 20-M for establishing secure communication with Node 20-1 (entrusted common key) (step S1225). This notification is made via the secure communication between Node 20-M and the control device 10 using the dual common key described above.

[0195] Here, the common key for node 20-M can be generated, for example, by the key sharing unit 201 of node 20-M from an unused file among the n+1 files (A aa, A a1, ..., A an) generated in the trust space construction process described above. Alternatively, for example, the key sharing unit 201 can generate the key from an unused file among the next generation of n+1 files for key generation described above.

[0196] Next, the control unit 105 of the control device 10 verifies the authenticity of node 20-M using control information and other data, based on the credentials of node 20-M associated with the node ID of the submitted node 20-M (step S1227).

[0197] Next, the control unit 105 of the control device 10 notifies the receiving node ID (consignee node ID) and the common key (consignee common key) of node 20-M of node 20-M to node 20-1, which is the entrusted node (step S1229). This notification is made via secure communication using the dual common key between node 20-1 and the control device 10 as described above. In this way, node 20-M shares its common key with node 20-1 via the control device 10 through encrypted communication based on the shared information of the control device 10.

[0198] Next, the delegation processing unit 211 of node 20-1 notifies the control device 10 of the common key of node 20-1 (delegation-side common key) (step S1231). This notification is also performed via secure communication using the dual common key between node 20-1 and the control device 10 as described above.

[0199] Here, the common key for node 20-1 can be generated, for example, by the key sharing unit 201 of node 20-1 from an unused file among the n+1 files (A aa, A a1, ..., A an) generated in the trust space construction process described above. Alternatively, for example, the key sharing unit 201 can generate the key from an unused file among the next generation of n+1 files for key generation described above.

[0200] Next, the control unit 105 of the control device 10 notifies node 20-M of the common key (commissioning side common key) of node 20-1 that it has received (step S1233). This notification is also performed using the double common key secure communication between node 20-M and the control device 10 as described above. In this way, node 20-1 shares its common key with node 20-M via the control device 10 through encrypted communication based on the shared information of the control device 10.

[0201] As a result, both Node 20-1 and Node 20-M can agree to use Node 20-1's common key (client-side common key) and Node 20-M's common key (recipient-side common key) for secure communication using dual common keys, and Node 20-1 and Node 20-M establish secure communication using dual common keys as described above (Step S1235). In this way, the control device 10 mediates the sharing of Node 20-1's common key (client-side common key) and Node 20-M's common key (recipient-side common key) between Node 20-1 and Node 20-M based on Node ID of Node 20-1 and Node 20-M's Node ID.

[0202] Next, the delegation processing unit 211 of node 20-1 transmits the data ID (XYZ) of the delegated arithmetic processing program, the encryption key used to encrypt the arithmetic processing program, and a power of attorney for the restoration of the arithmetic processing program (recovery of program data fragments) to node 20-M via secure communication using a dual symmetric key between node 20-1 and node 20-M (step S1237).

[0203] Next, the entrusted processing unit 231 of node 20-M performs a restoration process to restore the program for the calculation process (step S1239).

[0204] Figure 24 is a flowchart showing an example of the restoration process performed by node 20-M in the second embodiment.

[0205] First, the entrusted processing unit 231 of node 20-M checks its idle state and, if it determines that it can execute the arithmetic processing and acts as an accepting node (accepting device), and if it determines that there is no shortage of program data fragments for executing the arithmetic processing, it executes the arithmetic processing. If node 20-M determines that it can execute the arithmetic processing and acts as an accepting node (accepting device), and if it determines that there is a shortage of program data fragments for executing the arithmetic processing, it sends a retrieval advertisement to node 20' specifying the data ID "XYZ" of the arithmetic processing program and attaching a power of attorney from node 20-1 in order to retrieve the program data fragments (step S1601).

[0206] If node 20-M determines that it is unable to perform computational processing due to its idle state, it may cease acting as a entrusted node (accepting device) and issue a recruitment advertisement to solicit the next receiving device.

[0207] Next, the entrusted processing unit 231 of node 20-M waits to receive a response message from node 20' which stores the program data fragments (No in step S1603). When it receives a response message (Yes in step S1603), it determines whether the number of program data fragments whose location has been determined from the response messages received so far exceeds a predetermined threshold (step S1605).

[0208] If the number of data points does not exceed the threshold (No in step S1605), the system waits for a response message from node 20' storing the program data fragments (No in step S1603).

[0209] On the other hand, if the number of data exceeds a threshold (Yes in step S1605), the entrusted processing unit 231 of node 20-M queries the control device 10 for the location of node 20' with the given node ID, along with the branch numbers of the data headers received so far, and requests that node 20' to send a program data fragment. Upon receiving the program data fragment, the entrusted processing unit 231 of node 20-M restores the program data fragment into a program for arithmetic processing based on the branch numbers of each data header (step S1607).

[0210] Next, the entrusted processing unit 231 of node 20-M restores the encrypted arithmetic processing program, which has been finally recovered, using the encryption key used for encryption (step S1609). As a result, the processing execution unit 261 of node 20-M can obtain the arithmetic processing program and execute the arithmetic processing based on the arithmetic processing program on behalf of the entrusted node. When the entrusted processing unit 231 of node 20-M retrieves the data fragments to be processed, node 20-M recruits nodes that have the data fragments from the first division of the data fragments (packets) to be processed with the specified data ID. However, for subsequent recruitment advertisements, it is desirable for each node to issue recruitment advertisements that recruit nodes that can perform a division one level deeper than the data fragments it possesses.

[0211] Figure 25 is a flowchart showing an example of the response processing performed by node 20' in the second embodiment.

[0212] First, it is determined whether or not the program data fragment (packet) with the data ID specified in the retrieval advertisement is stored. If it is determined that it is not stored, the response processing unit 241 of node 20' waits for the retrieval advertisement to be received from the higher-level node 20 (No in step S1701). When the retrieval advertisement is received (Yes in step S1701), it forwards it to another node 20 (step S1703). If it is determined that it is stored, this retrieval advertisement may also be forwarded to yet another node 20. In this way, the retrieval advertisement is transmitted to each node 20 included in the data storage system 1.

[0213] Next, the response processing unit 241 of node 20' determines whether or not it has stored the program data fragment (packet) with the data ID specified in the retrieval advertisement (step S1705). If it determines that it has stored it (Yes in step S1705), it sends a response message to node 20-M, the source of the retrieval advertisement, notifying it that it has stored the specified program data fragment (step S1707).

[0214] As a result, the processing execution unit 261 of node 20-M can obtain a program for arithmetic processing and, instead of the delegated node, can execute arithmetic processing based on the program.

[0215] Figure 26 is a sequence diagram showing an example of a process that restores data to be processed, which is distributed and stored in the data storage system 1 of the second embodiment, and performs alternative calculations.

[0216] First, the provision processing unit 251 of node 20-N sends a provision advertisement to node 20' to provide the data to be processed to other nodes (step S1241). The provision advertisement can be, for example, a message containing the node ID of node 20-N, which is the providing node.

[0217] Next, the response processing unit 241 of node 20' performs an advertisement transmission process to transmit the advertisement to other nodes 20 (step S1243).

[0218] Here, by replacing the recruitment advertisement with a service advertisement, the flowchart of the recruitment advertisement transmission process shown in Figure 23 can also be applied to the service advertisement transmission process by the service processing unit 251 of node 20-N. Whether or not to apply for a service advertisement depends on factors such as whether or not the calculation processing program has been restored, but is not limited to these.

[0219] Here, it is assumed that node 20-M, which will be the receiving node, has decided to apply for the offer advertisement. If the receiving device determines that the program to be executed, which is estimated from the received advertisement content, is executable by itself, it functions as an accepting node (accepting device). As material for determining that the received program data fragment is executable by itself, the calculation load due to the Mega Instruction Process Steps (MIPS) and required time, program size, required memory amount, and amount of received processing data present in the recruitment advertisement may be referred to. The receiving processing unit 231 of node 20-M notifies the control device 10 of the node ID of node 20-N, which is the providing node included in the offer advertisement (provider node ID), its own node ID (receiving node ID), and the common key of node 20-M for establishing secure communication with node 20-N (receiving common key) in order to apply for the offer advertisement (step S1245). This notification is made via the secure communication between node 20-M and the control device 10 using the double common key described above.

[0220] Here, the common key for node 20-M can be generated, for example, by the key sharing unit 201 of node 20-M from an unused file among the n+1 files (A aa, A a1, ..., A an) generated in the trust space construction process described above. Alternatively, for example, the key sharing unit 201 can generate the key from an unused file among the next generation of n+1 files for key generation described above.

[0221] Next, the control unit 105 of the control device 10 verifies the authenticity of node 20-M using control information and other data, based on the credentials of node 20-M associated with the node ID of the submitted node 20-M (step S1247).

[0222] Next, the control unit 105 of the control device 10 notifies the receiving node 20-M's node ID (consignee node ID) and node 20-M's common key (consignee common key) to the providing node, node 20-N (step S1249). This notification is made via secure communication using a dual common key between node 20-N and the control device 10, as described above.

[0223] Next, the delegated processing unit 211 of node 20-N notifies the control device 10 of the common key of node 20-N (provider-side common key) (step S1251). This notification is also performed via secure communication using the dual common key between node 20-N and the control device 10 as described above.

[0224] Here, the common key for nodes 20-N can be generated, for example, by the key sharing unit 201 of node 20-1 from an unused file among the n+1 files (A aa, A a1, ..., A an) generated in the trust space construction process described above. Alternatively, for example, the key sharing unit 201 can generate the key from an unused file among the next generation of n+1 files for key generation described above.

[0225] Next, the control unit 105 of the control device 10 notifies node 20-M of the common key (provider common key) of node 20-N that it has received (step S1253). This notification is also performed via secure communication using the dual common key between node 20-M and the control device 10, as described above.

[0226] As a result, both Node 20-N and Node 20-M can agree to use Node 20-N's common key (provider's common key) and Node 20-M's common key (recipient's common key) for secure communication using dual common keys, and Node 20-N and Node 20-M establish secure communication using dual common keys as described above (Step S1255).

[0227] Next, the provision processing unit 251 of node 20-N transmits the data ID of the data to be processed, the encryption key used to encrypt the data to be processed, and a power of attorney for the restoration of the data to be processed (recovery of data fragments) to node 20-M via secure communication using a dual symmetric key between node 20-N and node 20-M (step S1257).

[0228] Next, the entrusted processing unit 231 of node 20-M performs a restoration process to recover the data to be processed (step S1259).

[0229] Here, by replacing node 20-1 with node 20-N, the program for arithmetic processing with the data to be processed, and the program data fragments with the data fragments to be processed, the flowchart explanation of the restoration process shown in Figure 24 can be applied to the data restoration process performed by node 20-M, and the flowchart explanation of the response process shown in Figure 25 can be applied to the response processing performed by node 20'.

[0230] Next, the processing execution unit 261 of node 20-M performs the calculation processing of the restored data to be processed using the restored calculation processing program (step S1261). Furthermore, during the calculation processing of the program, data from another distributed third party or client may be used, and a recruitment advertisement for this data may be issued. In this case, it is assumed that the data is distributed under different IDs. Alternatively, the user may use their own data.

[0231] Figure 27 is a sequence diagram showing an example of a process for returning the processing result of the computation process to the delegated node 20-1 using the distributed storage method of the second embodiment, and a reward guarantee process that guarantees a reward to the node 20-M that substituted the computation process.

[0232] First, node 20-M, the contracted node, performs a data transmission process in which it divides the processing result data to be returned into processing result data fragments and sends them (step S1271). Here, the processing result data is divided into processing result data fragments that include the invoice for the compensation for performing the calculation on behalf of the client. In this way, when node 20-1, the commissioned node, restores the processing result data, the invoice is also restored.

[0233] Here, by replacing node 20-1 with node 20-M, the delegated processing unit 211 with the result processing unit 271, the original data with the processed result data, and the data fragment with the processed result data fragment, the flowchart explanation of the data transmission process shown in Figure 14 can also be applied to the data transmission process by the result processing unit 271 of node 20-M.

[0234] Next, node 20', which is a diffusion node, performs data diffusion processing, such as further dividing and distributing the data fragments of the processing result received from the higher-level node 20, or storing the received data fragments of the processing result (step S1273).

[0235] Here, by replacing the data fragments with the processed data fragments, the flowchart of the data fragment diffusion process shown in Figure 15 can also be applied to the data transmission process by the diffusion processing unit 221 of node 20'.

[0236] In this way, the divided data fragments of the processing result propagate through the network and are re-divided at each node 20', and finally, the multiple divided data fragments of the processing result are stored at multiple nodes 20' that determine that the division termination condition is met.

[0237] Next, the result processing unit 271 of node 20-M transmits the data ID of the processing result, the encryption key used to encrypt the data of the processing result, and a power of attorney for the restoration of the data of the processing result (recovery of the data fragments of the processing result) to node 20-1 via secure communication using a dual symmetric key between node 20-1 and node 20-M (step S1275).

[0238] Next, the receiving processing unit 291 of node 20-1 performs a restoration process to restore the processing result data (step S1277).

[0239] Here, by replacing node 20-M with node 20-1, the arithmetic processing program with the processing result data, and the program data fragments with the processing result data fragments, the explanation of the restoration process flowchart shown in Figure 24 can be applied to the data restoration process of the processing result performed by node 20-1, and the explanation of the response process flowchart shown in Figure 25 can be applied to the response processing performed by node 20'.

[0240] As a result, node 20-1 can receive the processing result of the computation entrusted to node 20-M. Here, node 20-M, which recovered the data fragment, restored the computation program, performed the computation on its behalf, and notified node 20-1 of the processing result of the computation which is the result of providing resources, becomes a resource provider that provided resources for the stored data fragment, and is therefore guaranteed a reward.

[0241] Next, if the receiving processing unit 291 of node 20-1 successfully restores the processing result data, it notifies node 20-M, which performed the calculation processing on behalf of the node, of the payment (payment claim right) based on the invoice (step S1279).

[0242] Next, the result processing unit 271 of node 20-M requests the notified reward (reward claim right) from the control device 10 (step S1281).

[0243] Next, the control unit 105 of the control device 10 records in the settlement ledger the reward from node 20-1, the client node, to node 20-M, which substituted the computation processing (step S1283). Based on this settlement ledger, the control unit 105 of the control device 10 makes the payment of the reward to node 20-M, which substituted the computation processing, at the appropriate time.

[0244] As described above, according to the second embodiment, a delegating node can delegate computational processing to a receiving node, and the receiving node can take over the computational processing. In particular, according to the second embodiment, a large number of receiving nodes can be prepared, enabling pipeline-type parallel processing using massive computing, and it is also possible to delegate processing that requires a large amount of resources, such as machine learning processing.

[0245] Furthermore, according to the second implementation configuration, the control device 10 constructs a communication space of multiple nodes 20 under its control as a trusted space. This enables secure communication between nodes 20 whose identities are guaranteed by the control device 10, allowing for the safe exchange of highly confidential data necessary for processing delegation and guaranteeing that the delegation of computational processing is carried out securely.

[0246] Furthermore, according to the second implementation model, rewards can be guaranteed for nodes that perform computational processing, and it is expected that the substitution of computational processing will be actively promoted for the purpose of monetization.

[0247] (program) The programs executed by the devices and nodes of the above embodiments and each of the above modifications are provided as installable or executable files stored on a computer-readable storage medium such as a CD-ROM, CD-R, memory card, DVD, or flexible disk (FD).

[0248] Furthermore, the programs executed by the devices and nodes of the above embodiments and their respective modifications may be stored on a computer connected to a network such as the Internet and provided by allowing downloads via the network. Alternatively, the programs executed by the devices and nodes of the above embodiments and their respective modifications may be provided or distributed via a network such as the Internet. Furthermore, the programs executed by the devices and nodes of the above embodiments and their respective modifications may be pre-installed in ROM or the like and provided.

[0249] The programs executed in the above embodiments and the devices and nodes of each of the above modifications are configured as modules for realizing the above-described parts on a computer. In actual hardware, for example, the CPU reads the program from the HDD into RAM and executes it, thereby realizing the above-described parts on the computer.

[0250] The above embodiments and their respective modifications are merely examples of how this disclosure may be implemented, and they do not restrict the technical scope of this disclosure. Therefore, this disclosure can be implemented in various ways without departing from its essence or its main features. For example, the above embodiments and their respective modifications may be combined as appropriate on a component basis. Also, for example, some components may be removed from the total components in the above embodiments and their respective modifications.

[0251] This disclosure also includes the following aspects:

[0252] (1) A data storage system in which multiple devices connected via a network store data in a distributed manner, The aforementioned multiple devices each have a different entrusted device, The data is divided into multiple data fragments, and each of the divided data fragments is transmitted to a receiving device included in one or more devices. The receiving device included in the aforementioned plurality of devices is, If the received data fragment does not satisfy the division termination condition, the received data fragment is further divided, and each divided data fragment is transmitted to other receiving devices included in one or more devices. If the received data fragment satisfies the division termination condition, the received data fragment is stored. A resource-providing device included in the aforementioned plurality of devices, which provides resources for stored data fragments, is guaranteed a reward. Data storage system.

[0253] (2) The control device included in the data storage system is The characteristics of each of the aforementioned multiple devices are managed, The resource providing device is, The results of providing the aforementioned resources are notified to the contracted device. The aforementioned control device, Based on the notification from the commissioned device, the resource providing device is guaranteed the remuneration from the commissioned device. The data storage system described in (1) above.

[0254] (3) The control device, Each of the aforementioned devices shares a generated value generated by a predetermined method and shared information specific to the control device. Each of the above devices generates multiple distributed pieces of data from the shared information using the generated values ​​in a predetermined encoding method that allows the pre-distributed data to be restored when all or part of the distributed data obtained by distributing the pre-distributed data into multiple pieces is available. For each of the aforementioned devices, encrypted communication is constructed based on at least one of the plurality of distributed information, For each of the aforementioned devices, based on the establishment of the encrypted communication, a credential for managing the identity of the device is issued. The data storage system described in (2) above.

[0255] (4) The entrusted device is The resource provision device is notified of its right to claim remuneration, The aforementioned control device, Based on a claim made by the resource-providing device using the right to claim remuneration, the resource-providing device is guaranteed remuneration from the commissioned device. The data storage system described in (2) above.

[0256] (5) The resource providing device shall The receiving device stores the received data fragments and, in response to a retrieval request from the contracted device, returns the data fragments to the contracted device. The data storage system described in (1) above.

[0257] (6) The resource providing device shall This is a receiving device that stores the received data fragment and passes that data fragment to another receiving device. The data storage system described in (1) above.

[0258] (7) The data is a program capable of performing data processing, The resource providing device is, A trustee device that retrieves data pieces stored in one or more receiving devices to restore the program, executes the data processing using the restored program, and returns the execution result to the entrusting device. The data storage system according to (1) above.

[0259] (8) The control device included in the data storage system For each device, share a generated value generated by a predetermined method and shared information unique to the control device. For each device, use the generated value to generate a plurality of first distributed information from the shared information by a predetermined encoding method in which all or part of the distributed data obtained by dispersing the pre-dispersed data into a plurality can be used to restore the pre-dispersed data. For each device, share, as a common key, one of the plurality of first distributed information or derived information derived from the one first distributed information. The data storage system according to (1) above.

[0260] (9) The resource providing device Divide the claim data using the claim right into a plurality of claim data pieces, and transmit each of the divided claim data pieces to a receiving device included in one or more devices. The receiving devices included in the plurality of devices If the received claim data piece does not satisfy the division end condition, further divide the received claim data piece, and transmit each of the divided claim data pieces to other receiving devices included in one or more devices. If the received claim data piece satisfies the division end condition, store the received claim data piece. The control device Retrieve the claim data pieces stored in one or more receiving devices and restore the claim data using the claim right of the processing result. The data storage system according to (4) above.

[0261] (10) The control device included in the data storage system Includes some or all of the plurality of devices Having at least one of the following roles: building a trusted space that guarantees communication with a reliable partner for the plurality of devices, guaranteeing compensation for the resource providing device, and providing a complex partitioning scheme for the data fragments, The data storage system described in (1) above.

[0262] (11) A reward guarantee method performed in a data storage system in which multiple devices connected via a network store data in a distributed manner, The aforementioned multiple devices each have a different entrusted device, The data is divided into multiple data fragments, and each of the divided data fragments is transmitted to a receiving device included in one or more devices. The receiving device included in the aforementioned plurality of devices is, If the received data fragment does not satisfy the division termination condition, the received data fragment is further divided, and each divided data fragment is transmitted to other receiving devices included in one or more devices. If the received data fragment satisfies the division termination condition, the received data fragment is stored. A resource-providing device included in the aforementioned plurality of devices, which provides resources for stored data fragments, is guaranteed a reward. Method of guaranteeing compensation.

[0263] (12) If the received data fragment does not satisfy the division termination condition, the received data fragment is further divided, and each of the divided data fragments is transmitted to other receiving devices included in one or more devices. If the received data fragment satisfies the division termination condition, the received data fragment is stored. We received a retrieval request information to recover the data fragments. To claim compensation, Receiving device.

[0264] This disclosure also includes the following aspects:

[0265] (13) The receiving device, It maintains a list of other receiving devices that have already communicated, and prioritizes using those other receiving devices listed as destinations for the divided program data fragments. The data storage system described in (1) above.

[0266] (14) The data is a program capable of performing data processing, The aforementioned data fragment is a program data fragment, The aforementioned contracted equipment is If the idle state is confirmed and the resources necessary for retrieving and restoring program data fragments can be secured, the program data fragments stored in one or more receiving devices are retrieved to restore the program, and the data processing is performed using the restored program. The data storage system described in (7) above.

[0267] (15) The entrusted device is Information requesting retrieval of a specified data fragment is transmitted to a receiving device included in one or more devices. The receiving device included in the aforementioned plurality of devices is, The received retrieval request information is transmitted to other receiving devices included in one or more devices. The resource providing device is, Upon receiving the aforementioned retrieval request information, and based on the received retrieval request information, apply to retrieve the predetermined data fragment. The aforementioned consignment device, Based on the resource providing device's application to collect the predetermined data fragment, the right to claim compensation is notified to the resource providing device. The data storage system described in (4) above.

[0268] (16) The data is a program capable of performing data processing, The aforementioned data fragment is a program data fragment, The aforementioned consignment device, The outsourcing request information requesting the outsourcing of the aforementioned data processing is transmitted to a receiving device included in one or more devices. The receiving device included in the aforementioned plurality of devices is, If it is possible to secure the resources necessary for the recovery and restoration of program data pieces based on the resource information necessary for the execution of the data processing included in the received委托 request information, as the受托 device, recover the program data pieces stored in one or more receiving-side devices and restore the program, and execute the data processing using the restored program. The data storage system according to (7) above.

[0269] (17) The data is a program capable of executing data processing. The data piece is a program data piece. The受托 device Execute the data processing of the data to be processed using the restored program. The data to be processed is data held by the受托 device or data restored by recovering the data pieces to be processed stored in one or more receiving-side devices by the受托 device. The data storage system according to (7) above.

[0270] (18) The委托 device or the receiving-side device Based on the communication record with other receiving-side devices that have completed communication or the negotiation with other receiving-side devices that are candidates for the transmission destination, determine another receiving-side device that is the transmission destination of the divided program data pieces. The data storage system according to (1) above.

[0271] (19) The control device included in the data storage system For each device, share the generated value generated by a predetermined method and the shared information unique to the control device. For each device, use the generated value in a predetermined encoding method in which all or part of the distributed data obtained by dispersing the pre-distribution data into a plurality can restore the pre-distribution data, and generate a plurality of first distributed information from the shared information. For each of the aforementioned devices, one of the multiple first distributed pieces of information is shared as a common key, or the first first distributed piece of information is used to select a derived piece of information from among multiple derived pieces of information derived from the first first distributed piece of information to be used as a common key. The data storage system described in (1) above.

[0272] (20) A data storage system in which multiple devices connected via a network store data in a distributed manner, The aforementioned multiple devices each have a different entrusted device, The outsourcing request information, including the device identification information of the outsourced device, which requests the outsourcing of data processing, is transmitted to one or more receiving devices included in the device. The receiving device included in the aforementioned plurality of devices is, The received request information is transmitted to other receiving devices included in one or more devices. The contracted equipment included in the aforementioned plurality of devices is, The system receives the aforementioned outsourcing request information and, based on the received outsourcing request information, applies to the outsourcing device for the data processing to be performed. The aforementioned consignment device, Based on the application from the contracted equipment, a program capable of executing the data processing is sent to the contracted equipment. Data storage system. [Explanation of symbols]

[0273] 1. Data storage system 2 Network 10 Control equipment 20 (20-1, 20-2a~20-2c, 20-3a~20-3f, 20-La~20-Lc, 20-M, 20-N) Multiple nodes 101 Key sharing part 103 Secure Communication Establishment Unit 105 Control Department 201 Key sharing part 203 Secure Communication Establishment Unit 211 Outsourced Processing Unit 221 Diffusion Processing Unit 231 Contract Processing Unit 241 Response Processing Unit 251 Processing Unit 261 Processing Execution Unit 271 Result Processing Unit 281 Restoration Processing Unit 291 Receiving Processing Unit

Claims

1. A data storage system in which multiple devices connected via a network store data in a distributed manner, The aforementioned multiple devices each have a different entrusted device, The data is divided into multiple data fragments, and each of the divided data fragments is transmitted to a receiving device included in the multiple devices. The receiving device included in the aforementioned plurality of devices is, If the received data fragment does not satisfy the division termination condition, the received data fragment is further divided, and each divided data fragment is transmitted to another receiving device included in the plurality of devices. If the received data fragment satisfies the division termination condition, the received data fragment is stored. The control device included in the data storage system is, A receiving device that stores received data fragments, and a resource providing device which is at least one of the devices included in the plurality of devices that performed calculation processing using the stored data fragments, manage settlement data that records the remuneration that the resource providing device bills to the commissioning device. Data storage system.

2. The aforementioned control device, Each of the aforementioned devices is managed to ensure that it is a reliable device. The resource providing device is, The entrusted device is notified that the data fragment has been stored or that the calculation process has been performed. The aforementioned control device, Based on the notification from the outsourced device, the resource providing device records the remuneration it requests from the outsourced device as settlement data. The data storage system according to claim 1.

3. The aforementioned control device, Each of the aforementioned devices shares a generated value generated by a predetermined method and shared information specific to the control device. Each of the above devices generates multiple distributed pieces of data from the shared information using the generated values ​​in a predetermined encoding method that allows the pre-distributed data to be restored when all or part of the distributed data obtained by distributing the pre-distributed data into multiple pieces is available. For each of the aforementioned devices, encrypted communication is constructed based on at least one of the plurality of distributed information, For each of the aforementioned devices, based on the establishment of the encrypted communication, a credential is issued to guarantee that the device is a reliable device. The data storage system according to claim 2.

4. The aforementioned consignment device, The resource provision device is notified of its right to claim remuneration, The aforementioned control device, Based on the claim made by the resource-providing device using the right to claim remuneration, the remuneration that the resource-providing device claims from the commissioning device is recorded as settlement data. The data storage system according to claim 2.

5. The resource providing device is, The receiving device stores the received data fragments and, in response to a retrieval request from the contracted device, returns the data fragments to the contracted device. The data storage system according to claim 1.

6. The resource providing device is, This is a receiving device that stores the received data fragment and passes that data fragment to another receiving device. The data storage system according to claim 1.

7. The aforementioned data is a program capable of performing data processing, The resource providing device is, This is a contracted device that retrieves data fragments stored in one or more receiving devices, restores the program, performs the data processing using the restored program, and returns the execution results to the contracted device. The data storage system according to claim 1.

8. The aforementioned control device, Each of the aforementioned devices shares a generated value generated by a predetermined method and shared information specific to the control device. Each of the above devices generates a plurality of first distributed information from the shared information using the generated value in a predetermined encoding method that allows the pre-distributed data to be restored when all or part of the distributed data obtained by distributing the pre-distributed data into multiple parts is available. Each of the above devices shares one of the plurality of first distributed information or derived information derived from the one first distributed information as a common key. The data storage system according to claim 2.

9. The resource providing device is, The data of the claim using the aforementioned right to claim remuneration is divided into multiple claim data fragments, and each of the divided claim data fragments is transmitted to a receiving device included in the multiple devices. The receiving device included in the aforementioned plurality of devices is, If the received billing data fragment does not satisfy the division termination condition, the received billing data fragment is further divided, and each of the divided billing data fragments is transmitted to other receiving devices included in the plurality of devices. If the received billing data fragment satisfies the division termination condition, the received billing data fragment is stored. The aforementioned control device, The system retrieves claim data fragments stored in one or more receiving devices and restores the data of the claim using the aforementioned right to claim remuneration as a processing result. The data storage system according to claim 4.

10. The aforementioned control device, Including some or all of the aforementioned multiple devices, Having at least one of the following roles: building a trusted space that guarantees communication with a reliable partner for the plurality of devices, guaranteeing compensation for the resource providing device, and providing a complex partitioning scheme for the data fragments. The data storage system according to claim 1.

11. A reward guarantee method implemented in a data storage system in which multiple devices connected via a network store data in a distributed manner, The aforementioned multiple devices each have a different entrusted device, The data is divided into multiple data fragments, and each of the divided data fragments is transmitted to a receiving device included in the multiple devices. The receiving device included in the aforementioned plurality of devices is, If the received data fragment does not satisfy the division termination condition, the received data fragment is further divided, and each divided data fragment is transmitted to another receiving device included in the plurality of devices. If the received data fragment satisfies the division termination condition, the received data fragment is stored. The control device included in the data storage system is, A receiving device that stores received data fragments, and a resource providing device which is at least one of the devices included in the plurality of devices that performed calculation processing using the stored data fragments, manage settlement data that records the remuneration that the resource providing device bills to the commissioning device. Method of guaranteeing compensation.

Citation Information

Patent Citations

  • Data storage system, data storage device, computer program, and data storage method

    JP2021105680A

  • The method and system for providing cloud service including saas based blockchain

    KR102361207B1

  • System and method for virtual currency management

    WO2020039494A1

  • Electronic transaction apparatus, electronic transaction method, and program

    JP2019106639A