Terminal device, management device, information processing method, and program

The system securely recovers private keys in software wallets by generating and encrypting keys with reversible codes, ensuring secure storage and recovery through user authentication, addressing security issues in conventional methods.

JP7850899B2Active Publication Date: 2026-04-24REAZON HOLDINGS INC
View PDF 8 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
REAZON HOLDINGS INC
Filing Date
2023-05-23
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Conventional methods for managing and recovering private keys in software wallets lack security, particularly in cases of key loss, due to reliance on insecure authentication methods and the potential for collusion among virtual servers.

Method used

A terminal device and management device system that generates a private key, encrypts it into a recovery phrase using a decryption code, and securely stores this information, allowing recovery through user authentication and secure transmission.

Benefits of technology

Ensures secure recovery of private keys by using reversible encryption and secure storage, even in cases of key loss, with authentication methods that enhance security and transparency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007850899000001
    Figure 0007850899000001
  • Figure 0007850899000002
    Figure 0007850899000002
  • Figure 0007850899000003
    Figure 0007850899000003
Patent Text Reader

Abstract

To solve the problem that a secret key cannot be securely recovered to a loss or the like of the secret key of a software wallet in the prior arts.SOLUTION: A secret key can be securely recovered to the loss or the like of the secret key of a software wallet by a terminal device 1 including a secret key generation part 133 for generating the secret key of the software wallet, a decryption code generation part 134 for generating a decryption code, a recovery phrase generation part 135 for reversibly encrypting the secret key by the decryption code and generating a recovery phrase, a recovery phrase transmission part 141 for transmitting the recovery phrase to a management device 2 in association with a user identifier, and a use information output part 161 for outputting use information based on the description code.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a terminal device or the like that safely restores the private key of a software wallet.

Background Art

[0002] Conventionally, there has been a technology that divides a private key into multiple parts, stores the divided private keys in a plurality of anonymous nodes on a self-organizing distributed network, and realizes an electronic escrow type storage method and its operation system that has high resistance to data leakage against external hacking (see Patent Document 1). Also, conventionally, as a method for managing the private key of a software wallet, a user has had to write down the private key or a code obtained by encoding the private key into English words on paper. In addition, a server cannot store the private key of a software wallet because it would mean taking over the asset control right of the wallet user. As a solution to the above problems, there has been a method of distributing and depositing the private key in multiple virtual servers. However, the problem with this method is that it relies on authentication methods such as SNS and email addresses for identity verification during restoration, but these authentication methods have often been reported to be hacked and lack security. In addition, there are also problems such as that it cannot be objectively proven that a business operator has deposited in multiple virtual servers, it cannot be said that there is sufficient deposit in multiple virtual servers, and the possibility that multiple virtual servers collude to obtain the private key cannot be completely eliminated. Therefore, in the present invention, for example, when depositing one of the two elements necessary for restoring the private key in a server (management device) and extracting it, for example, authentication such as a phone number, email address, SNS, etc. is used, and the other is stored in the form of an image or the like by the user, in order to provide convenience while ensuring security and transparency.

Prior Art Documents

Patent Documents

[0003] [Patent Document 1] Japanese Patent Publication No. 2020-155911 [Overview of the Initiative] [Problems that the invention aims to solve]

[0004] However, with conventional technology, it was not possible to securely recover a private key in the event of loss of the private key in a software wallet. [Means for solving the problem]

[0005] The terminal device of the first invention comprises a private key generation unit that generates a private key for a software wallet, a decryption code generation unit that generates a decryption code, a recovery phrase generation unit that reversibly encrypts the private key using the decryption code and generates a recovery phrase, a recovery phrase transmission unit that transmits the recovery phrase to a management device in association with a user identifier, and a usage information output unit that outputs usage information based on the decryption code.

[0006] This configuration provides a device that can securely recover private keys in the event of loss of a software wallet's private key.

[0007] Furthermore, the terminal device of the second invention is a terminal device that, in addition to the first invention, further comprises: a recovery instruction transmission unit that transmits a recovery instruction corresponding to a user identifier to a management device; a recovery phrase reception unit that receives a recovery phrase corresponding to a user identifier from the management device in response to the transmission of a recovery instruction; a usage information acquisition unit that acquires usage information; a private key acquisition unit that acquires a private key using the recovery phrase received by the recovery phrase reception unit and a decryption code corresponding to the usage information; and a private key output unit that outputs the private key acquired by the private key acquisition unit.

[0008] This configuration provides a device that can securely recover private keys in the event of loss of a software wallet's private key.

[0009] Furthermore, the management device of this third invention is a management device that, in addition to the first or second invention, comprises a first server receiving unit that receives a recovery phrase from a terminal device in association with a user identifier, a server storage unit that stores the recovery phrase in association with a user identifier, a second server receiving unit that receives a recovery instruction from a terminal device corresponding to a user identifier, a server acquisition unit that acquires a recovery phrase corresponding to a user identifier corresponding to a recovery instruction, and a server transmission unit that transmits the recovery phrase to a terminal device.

[0010] This configuration allows us to provide a server that can securely recover private keys in the event of loss or other issues with a software wallet. [Effects of the Invention]

[0011] According to the terminal device of the present invention, a private key can be securely recovered in the event of loss of the private key of a software wallet. [Brief explanation of the drawing]

[0012] [Figure 1] Conceptual diagram of information system A in Embodiment 1 [Figure 2] Block diagram of information system A [Figure 3] A flowchart illustrating an example of operation of terminal device 1. [Figure 4] A flowchart illustrating an example of the process for generating usage information. [Figure 5] A flowchart illustrating an example of the restoration process. [Figure 6] Flowchart illustrating an example of operation of the management device 2. [Figure 7] Diagram showing the user information management table. [Figure 8] Overview of the computer system [Figure 9] Block diagram of the computer system [Modes for carrying out the invention]

[0013] Hereinafter, embodiments of a terminal device and the like will be described with reference to the drawings. In the embodiments, components denoted by the same reference numerals perform the same operations, and thus the description thereof may be omitted again.

[0014] (Embodiment 1) In the present embodiment, an information system that can safely restore a secret key even when the secret key of a software wallet is lost or the like will be described.

[0015] In this specification, information X being associated with information Y means that information Y can be obtained from information X, or information X can be obtained from information Y, and the method of the association is not limited. Information X and information Y may be linked, may exist in the same buffer, information X may be included in information Y, information Y may be included in information X, or the like.

[0016] FIG. 1 is a conceptual diagram of an information system A in the present embodiment. The information system A includes one or more terminal devices 1 and a management device 2.

[0017] The terminal device 1 is a terminal that can safely restore a secret key in the event of loss of the secret key of a software wallet or the like. The terminal device 1 is, for example, a so-called personal computer, a smartphone, or a tablet terminal, and its type is not limited.

[0018] The management device 2 is a device that manages and associates a restoration phrase, which will be described later, with a user identifier. The management device 2

[0019] Each of the one or more terminal devices 1 and the management device 2 can communicate with each other via a network such as the Internet.

[0020] FIG. 2 is a block diagram of the information system A in the present embodiment.

[0021] Terminal device 1 comprises a storage unit 11, a receiving unit 12, a processing unit 13, a transmission unit 14, a receiving unit 15, and an output unit 16. The storage unit 11 comprises a user information storage unit 111. The processing unit 13 comprises an installation unit 131, an address generation unit 132, a private key generation unit 133, a decryption code generation unit 134, a recovery phrase generation unit 135, a user information acquisition unit 136, and a private key acquisition unit 137. The transmission unit 14 comprises a recovery phrase transmission unit 141 and a recovery instruction transmission unit 142. The receiving unit 15 comprises a recovery phrase receiving unit 151. The output unit 16 comprises a user information output unit 161 and a private key output unit 162.

[0022] The management device 2 comprises a server storage unit 21, a server receiving unit 22, a server processing unit 23, and a server transmission unit 24. The server receiving unit 22 comprises a first server receiving unit 221 and a second server receiving unit 222. The server processing unit 23 comprises a server storage unit 231 and a server acquisition unit 232.

[0023] The storage unit 11, which constitutes the terminal device 1, stores various types of information. These types of information include, for example, a wallet application, usage information (described later), and a user identifier. The storage of a wallet application may also mean that the installer for the wallet application is stored.

[0024] A wallet app is a software wallet application. Here, a wallet app refers, for example, to a software wallet application for cryptocurrencies. However, the term "wallet app" can also refer to any application that manages credit cards, debit cards, shop cards, boarding passes, movie tickets, coupons, loyalty cards, etc., in one place, and is interpreted more broadly.

[0025] A user identifier is information that identifies a user. Examples of user identifiers include email addresses, phone numbers, user IDs, session IDs, or terminal identifiers. A terminal identifier is information that identifies terminal device 1, such as the ID of terminal device 1.

[0026] The usage information storage unit 111 stores usage information. Usage information is information used when recovering the private key. Usage information is information based on the decryption code. Usage information is, for example, image information with the decryption code embedded in it. However, usage information may also be information other than image information, such as a digital watermark or a string of characters. Image information is, for example, a code image. Code images are, for example, two-dimensional codes such as barcodes or QR codes (registered trademarks). Usage information may also be the decryption code itself.

[0027] A decryption code is information used to generate a recovery phrase. Typically, a decryption code is randomly generated information. Ideally, the decryption code should be strong enough to be unpredictable. For example, a decryption code can be obtained by feeding a randomly generated number to a hash function.

[0028] A recovery phrase, in this context, is a phrase used in cases such as the loss of a private key. A phrase is a piece of information. The recovery phrase is generated by reversibly encrypting the encryption key using a decryption code. The recovery phrase is usually a string, but the data type is not limited.

[0029] The reception unit 12 receives various instructions and information. These instructions and information include, for example, installation instructions, management instructions, restoration instructions, and various operations.

[0030] Installation instructions are instructions for installing the wallet application. Management instructions are instructions for outputting usage information for recovering the private key. Management instructions include, for example, a user identifier. Recovery instructions are instructions for recovering the private key. Recovery instructions include, for example, a user identifier. Recovery instructions are associated with, for example, usage information.

[0031] Various operations include, for example, accessing a wallet using a wallet address. However, the content of these operations is not specified.

[0032] Any means of inputting instructions and information is acceptable, such as a touch panel, keyboard, mouse, or menu screen.

[0033] The processing unit 13 performs various processes. These various processes include, for example, the processes performed by the installation unit 131, the address generation unit 132, the private key generation unit 133, the decryption code generation unit 134, the recovery phrase generation unit 135, the usage information acquisition unit 136, and the private key acquisition unit 137.

[0034] Furthermore, the processing unit 13 may, for example, create a data structure for transmitting various instructions and information received by the receiving unit 12. The processing unit 13 may also, for example, create a data structure for outputting information received by the receiving unit 15.

[0035] The installation unit 131 installs the wallet application on the terminal device 1. The installation unit 131 typically installs the wallet application in response to an installation instruction. For example, the installation unit 131 installs the wallet application located in the storage unit 11. If, for example, the wallet application is not present in the storage unit 11, the installation unit 131 obtains the wallet application from the management device 2 or another device (not shown) and installs it.

[0036] The address generation unit 132 generates a wallet address. A wallet address is a string associated with a wallet. The wallet address is a string associated with a blockchain wallet, and it is preferable that it be a randomly generated string. The address generation unit 132 generates a wallet address, for example, when the installation unit 131 installs the wallet application on the terminal device 1. The address generation unit 132 also generates a public key from a private key generated by the private key generation unit 133, which will be described later. In this case, the public key is, for example, the wallet address.

[0037] The private key generation unit 133 generates the private key for the software wallet. This private key is the information needed to access the wallet.

[0038] The decryption code generation unit 134 generates a decryption code. The decryption code generation unit 134 usually generates a decryption code randomly. For example, the decryption code generation unit 134 generates a random number, feeds the random number to a hash function, executes the hash function, and obtains a decryption code.

[0039] The recovery phrase generation unit 135 generates a recovery phrase by reversibly encrypting the secret key using the decryption code. Reversible encryption is a type of encryption that converts data into a reversible form. Since reversible encryption is a well-known process, a detailed explanation is omitted.

[0040] The usage information acquisition unit 136 acquires usage information based on the decrypted code generated by the decrypted code generation unit 134. The usage information acquisition unit 136 generates, for example, image information with the decrypted code embedded. The image information is, for example, a code image. The code image is, for example, a barcode or a two-dimensional code such as a QR code (registered trademark).

[0041] The private key acquisition unit 137 acquires the private key using the recovery phrase received by the recovery phrase receiving unit 151 and the decryption code corresponding to the usage information. Typically, the private key acquisition unit 137 decrypts the decryption code corresponding to the usage information with the recovery phrase received by the recovery phrase receiving unit 151 and acquires the private key. The decryption code corresponding to the usage information is, for example, a decryption code embedded in the usage information or the usage information itself.

[0042] The transmitting unit 14 transmits various information and instructions. The transmitting unit 14 typically transmits various information and instructions to the management device 2. These various information and instructions include, for example, installation instructions, management instructions, restoration instructions, and restoration phrases. A restoration instruction is an instruction for restoring a private key. A restoration instruction includes, for example, a user identifier.

[0043] The recovery phrase transmission unit 141 transmits the recovery phrase generated by the recovery phrase generation unit 135 to the management device 2, associating it with a user identifier.

[0044] The restore instruction transmission unit 142 transmits a restore instruction corresponding to the user identifier to the management device 2. For example, when the receiving unit 12 receives a restore instruction, the restore instruction transmission unit 142 obtains the user identifier contained in the restore instruction or the user identifier of the storage unit 11. Next, the restore instruction transmission unit 142 transmits, for example, a restore instruction having said user identifier to the management device 2.

[0045] The receiving unit 15 receives various types of information. These types of information include, for example, a wallet application and a recovery phrase.

[0046] The recovery phrase receiving unit 151 receives a recovery phrase corresponding to the user identifier from the management device 2 in response to the transmission of a recovery instruction.

[0047] The output unit 16 outputs various types of information. These types of information include, for example, usage information and a secret key.

[0048] The usage information output unit 161 outputs usage information. The usage information output unit 161 outputs usage information based on the decryption code.

[0049] Here, "output" is a concept that includes displaying on a screen, projecting using a projector, printing with a printer, sound output, transmission to an external device, storage on a recording medium, and handing over processing results to other processing devices or other programs.

[0050] The private key output unit 162 outputs the private key acquired by the private key acquisition unit 137. The private key output unit 162, for example, displays the private key. The private key output unit 162, for example, prints the private key. The private key output unit 162, for example, passes the private key to the wallet application.

[0051] The server storage unit 21, which constitutes the management device 2, stores various types of information. These types of information include one or more user information and wallet applications. User information refers to information about the user of the wallet application. User information includes, for example, a user identifier and a recovery phrase.

[0052] The server receiving unit 22 receives various types of information. These types of information include, for example, a recovery phrase, recovery instructions, and installation instructions.

[0053] The first server receiving unit 221 receives a recovery phrase from the terminal device 1, associated with the user identifier.

[0054] The second server receiving unit 222 receives a restore instruction corresponding to the user identifier from the terminal device 1.

[0055] The server processing unit 23 performs various processes. These processes include, for example, those performed by the server storage unit 231 and the server acquisition unit 232.

[0056] The server storage unit 231 stores the recovery phrase received by the first server receiving unit 221, associating it with a user identifier. The server storage unit 231 usually stores user information, which includes the recovery phrase and the user identifier, in the server storage unit 21, but the user information may also be stored in a device not shown.

[0057] The server acquisition unit 232 acquires a user identifier corresponding to the restoration instruction received by the second server receiving unit 222. The server acquisition unit 232 acquires a restoration phrase corresponding to the said user identifier. For example, the server acquisition unit 232 acquires a restoration phrase corresponding to the user identifier corresponding to the restoration instruction received by the second server receiving unit 222 from the server storage unit 21.

[0058] The server transmission unit 24 transmits the recovery phrase acquired by the server acquisition unit 232 to the terminal device 1. The server transmission unit 24 may also transmit the wallet application from the server storage unit 21 to the terminal device 1 in response to receiving an installation instruction sent from the terminal device 1.

[0059] The storage unit 11, the usage information storage unit 111, and the server storage unit 21 are preferably made of non-volatile recording media, but can also be made of volatile recording media.

[0060] The process by which information is stored in the storage unit 11, etc. is not relevant. For example, information may be stored in the storage unit 11, etc. via a recording medium, information transmitted via a communication line, etc. may be stored in the storage unit 11, etc., or information input via an input device may be stored in the storage unit 11, etc.

[0061] The reception unit 12 can be implemented using device drivers for input means such as touch panels and keyboards, or control software for menu screens.

[0062] The processing unit 13, installation unit 131, address generation unit 132, private key generation unit 133, decryption code generation unit 134, recovery phrase generation unit 135, usage information acquisition unit 136, private key acquisition unit 137, server processing unit 23, server storage unit 231, and server acquisition unit 232 can typically be implemented using a processor, memory, etc. The processing procedures of the processing unit 13, etc., are usually implemented in software, and this software is recorded on a recording medium such as ROM. However, it may also be implemented in hardware (dedicated circuitry). The processor can be a CPU, MPU, GPU, etc., and the type is not limited.

[0063] The transmitting unit 14, the recovery phrase transmitting unit 141, the recovery instruction transmitting unit 142, and the server transmitting unit 24 are usually implemented by wireless or wired communication means, but may also be implemented by broadcasting means.

[0064] The receiving unit 15, the recovery phrase receiving unit 151, the server receiving unit 22, the first server receiving unit 221, and the second server receiving unit 222 are usually implemented by wireless or wired communication means, but may also be implemented by means of receiving broadcasts.

[0065] The output unit 16, the usage information output unit 161, and the secret key output unit 162 may or may not be considered to include output devices such as displays and speakers. The output unit 16 can be implemented using driver software for an output device, or driver software for an output device and an output device, etc.

[0066] Next, an example of the operation of terminal device 1 will be explained using the flowchart in Figure 3.

[0067] (Step S301) The reception unit 12 determines whether or not it has received an installation instruction. If it has received an installation instruction, it proceeds to step S302; if it has not received an installation instruction, it proceeds to step S306.

[0068] (Step S302) The installation unit 131 determines whether or not a wallet application exists in the storage unit 11. If the application exists, the process proceeds to step S304; otherwise, the process proceeds to step S303. Note that if a wallet application exists, it usually means that the wallet application installer exists.

[0069] (Step S303) The installation unit 131 obtains the wallet application from the management device 2 or a device not shown.

[0070] (Step S304) The installation unit 131 installs the wallet app from the storage unit 11 or the wallet app obtained in step S303.

[0071] (Step S305) The processing unit 13, etc., performs the usage information generation process. Return to step S301. An example of the usage information generation process will be explained using the flowchart in Figure 4. The usage information generation process is the process of generating and outputting usage information.

[0072] (Step S306) The reception unit 12 determines whether or not it has received the management instruction. If it has received the management instruction, it proceeds to step S305; if it has not received the management instruction, it proceeds to step S307. Note that the usage information generation process is performed after receiving the management instruction if the usage information generation process is not performed automatically in accordance with the installation of the wallet application.

[0073] (Step S307) The reception unit 12 determines whether or not it has received a restore instruction. If it has received a restore instruction, it proceeds to step S308; if it has not received a restore instruction, it proceeds to step S309.

[0074] (Step S308) The private key acquisition unit 137, etc., performs the restoration process. Return to step S301. An example of the restoration process will be explained using the flowchart in Figure 5. Note that the restoration process is the process of recovering the private key.

[0075] (Step S309) The reception unit 12 determines whether or not it has received any other operations. If it has received any other operations, it proceeds to step S310; otherwise, it returns to step S301. Other operations include, for example, operations on the wallet application.

[0076] (Step S310) The processing unit 13, etc., performs processing according to other operations. The process returns to step S301. Note that processing according to other operations is, for example, processing performed by the wallet application.

[0077] In the flowchart in Figure 3, processing is terminated by power-off or processing termination interrupts.

[0078] Next, an example of the usage information generation process in step S305 will be explained using the flowchart in Figure 4.

[0079] (Step S401) The processing unit 13 obtains the user identifier, etc. The user identifier, etc. may be, for example, the user identifier and the identifier of terminal device 1 (for example, the IP address). The user identifier, etc. may be just the user identifier.

[0080] (Step S402) The transmission unit 14 transmits the user identifier and other information obtained in step S401 to the management device 2.

[0081] (Step S404) The secret key generation unit 133 generates a secret key.

[0082] (Step S403) The address generation unit 132 generates a wallet address and stores it at least temporarily in the storage unit 11.

[0083] (Step S405) The decryption code generation unit 134 generates a decryption code.

[0084] (Step S406) The recovery phrase generation unit 135 reversibly encrypts the secret key generated in step S404 using the decryption code generated in step S405, and generates a recovery phrase.

[0085] (Step S407) The recovery phrase transmission unit 141 transmits the recovery phrase generated in step S406 to the management device 2, associating it with the user identifier.

[0086] (Step S408) The usage information acquisition unit 136 acquires usage information based on the decryption code generated in step S405.

[0087] (Step S409) The usage information output unit 161 outputs the usage information acquired in step S408. It returns to the higher-level processing.

[0088] Next, an example of the restoration process in step S308 will be explained using the flowchart in Figure 5.

[0089] (Step S501) The restore instruction transmission unit 142 obtains a user identifier from the storage unit 11.

[0090] (Step S502) The restore instruction transmission unit 142 configures a restore instruction that includes a user identifier.

[0091] (Step S503) The restore instruction transmission unit 142 transmits the restore instruction configured in step S502 to the management device 2.

[0092] (Step S504) The recovery phrase receiving unit 151 determines whether or not it has received a recovery phrase from the management device 2. If a recovery phrase has been received, the process proceeds to step S506; otherwise, the process proceeds to step S505.

[0093] (Step S505) The processing unit 13 determines whether a timeout has occurred. If a timeout has occurred, it returns to the higher-level processing unit; otherwise, it returns to step S504. A timeout occurs when a predetermined amount of time has elapsed since the restore instruction was sent.

[0094] (Step S506) The secret key acquisition unit 137 acquires usage information from the storage unit 11. The usage information is, for example, usage information selected by the user.

[0095] (Step S507) The secret key acquisition unit 137 acquires a decryption code from the usage information acquired in step S506.

[0096] (Step S508) The private key acquisition unit 137 decrypts the decryption code acquired in step S507 using the recovery phrase received in step S504, and acquires the private key.

[0097] (Step S509) The secret key output unit 162 outputs the secret key obtained in step S508. It returns to the higher-level processing unit.

[0098] Next, an example of the operation of the control device 2 will be explained using the flowchart in Figure 6.

[0099] (Step S601) The server receiving unit 22 determines whether or not it has received an installation instruction from the terminal device 1. If an installation instruction is received, the process proceeds to step S602; otherwise, the process proceeds to step S603.

[0100] (Step S602) The server transmission unit 24 transmits the wallet application from the server storage unit 21 to the terminal device 1 that sent the installation instruction. The process returns to step S601. The transmitted wallet application is usually the wallet application installer.

[0101] (Step S603) The server receiving unit 22 determines whether or not it has received a user identifier, etc., from the terminal device 1. If it has received a user identifier, etc., it proceeds to step S604; if it has not received a user identifier, etc., it proceeds to step S607.

[0102] (Step S604) The server storage unit 231 stores the user identifier and other information received in step S603 in the server storage unit 21.

[0103] (Step S605) The first server receiving unit 221 determines whether or not it has received a recovery phrase associated with the user identifier from the terminal device 1. If a recovery phrase is received, the process proceeds to step S606; otherwise, the process returns to step S605.

[0104] (Step S606) The server storage unit 231 stores the recovery phrase received in step S605 in the server storage unit 21, associating it with the user identifier. Return to step S601.

[0105] (Step S607) The second server receiving unit 222 determines whether or not it has received a restore instruction corresponding to the user identifier from the terminal device 1. If a restore instruction is received, the process proceeds to step S608; otherwise, the process returns to step S601.

[0106] (Step S608) The server acquisition unit 232 acquires the user identifier corresponding to the restore instruction received in step S607.

[0107] (Step S609) The server acquisition unit 232 acquires a recovery phrase from the server storage unit 21 that is paired with the user identifier acquired in step S608.

[0108] (Step S610) The server transmission unit 24 transmits the recovery phrase obtained in step S609 to the terminal device 1 that sent the recovery instruction. The process returns to step S601.

[0109] In the flowchart shown in Figure 6, processing is terminated by power-off or processing termination interrupts.

[0110] The specific operation of information system A in this embodiment will be described below. A conceptual diagram of information system A is shown in Figure 1.

[0111] Assume that the server storage unit 21 of the management device 2 stores a user information management table having the structure shown in Figure 7. The user information management table manages one or more records having an "ID," a "user identifier," and a "recovery phrase." The "ID" is information that identifies the record. The "user identifier" is, in this case, an email address or telephone number. The "recovery phrase" is, in this case, a string of characters greater than or equal to a threshold. In this situation, two specific examples will be described below. Specific example 1 is the case of generating usage information. Specific example 2 is the case of recovering a private key.

[0112] (Specific example 1) Assume that the storage unit 11 of user A's terminal device 1 contains an installer for a cryptocurrency software wallet application (wallet app). Then, assume that user A has entered an installation command into terminal device 1.

[0113] Then, the reception unit 12 of terminal device 1 receives the installation instruction. The installation unit 131 executes the installer for the cryptocurrency wallet application in the storage unit 11 and installs the wallet application.

[0114] Upon installation of the cryptocurrency wallet application, the processing unit 13 and other components perform the following usage information generation process. Specifically, the processing unit 13 outputs a screen to the terminal device 1 prompting the user to enter an email address. The user then enters the email address "abc@x.com" on this screen. Next, the transmission unit 14 sends the entered email address "abc@x.com" to the management device 2.

[0115] Next, the server receiving unit 22 of the management device 2 receives the email address "abc@x.com" from the terminal device 1. Then, the server storage unit 231 stores the email address in the user information management table (Figure 7) of the server storage unit 21.

[0116] Furthermore, the address generation unit 132 of terminal device 1 generates the wallet address "address 1". Also, the private key generation unit 133 generates a private key. Furthermore, the decryption code generation unit 134 generates a decryption code. Next, the recovery phrase generation unit 135 reversibly encrypts the private key using the generated decryption code and generates the recovery phrase "XXXyyy0123". Next, the recovery phrase transmission unit 141 associates the generated recovery phrase "XXXyyy0123" with the email address "abc@x.com" and sends it to the management device 2.

[0117] Next, the usage information acquisition unit 136 constructs a QR code with the generated decryption code embedded in it. Then, the usage information output unit 161 stores the acquired QR code in the usage information storage unit 111. The usage information output unit 161 also displays the acquired QR code on the screen of the terminal device 1.

[0118] Furthermore, the first server receiving unit 221 of the management device 2 receives the recovery phrase "XXXyyy0123" from the terminal device 1, associated with the email address "abc@x.com". Next, the server storage unit 231 stores the received recovery phrase "XXXyyy0123" in the user information management table (Figure 7), associated with the email address "abc@x.com". The record stored through the above process is the record with "ID=1" in the user information management table (Figure 7).

[0119] As shown in Example 1 above, when a wallet app is installed, usage information for securely restoring the private key can be automatically obtained. In other words, according to Example 1, even if a user loses their private key, an environment can be provided in which they can securely restore it.

[0120] (Specific example 2) Suppose User A has lost the private key for the wallet app they are using. User A then selects the QR code for the wallet app from one or more QR codes stored in the storage unit 11. User A also enters a recovery instruction, including the email address "abc@x.com", into the terminal device 1. The reception unit 12 of the terminal device 1 then accepts the recovery instruction, including the email address "abc@x.com". The private key acquisition unit 137 then retrieves the QR code from the storage unit 11.

[0121] Next, the recovery instruction transmission unit 142 obtains the entered email address "abc@x.com". Then, the recovery instruction transmission unit 142 constructs a recovery instruction "<Recovery Request>abc@x.com" that includes the said email address. Next, the recovery instruction transmission unit 142 transmits the recovery instruction to the management device 2.

[0122] Next, the second server receiving unit 222 of the management device 2 receives a recovery instruction "<Recovery Request>abc@x.com" from terminal device 1. Next, the server acquisition unit 232 acquires the email address "abc@x.com" included in the received recovery instruction. Next, the server acquisition unit 232 acquires the recovery phrase "XXXyyy0123" which is paired with the acquired email address from the user information management table (Figure 7). Next, the server transmission unit 24 transmits the recovery phrase "XXXyyy0123" to user A's terminal device 1.

[0123] Next, the recovery phrase receiving unit 151 of terminal device 1 receives the recovery phrase "XXXyyy0123" from management device 2.

[0124] Next, the private key acquisition unit 137 acquires the decryption code embedded in the acquired QR code. Then, the private key acquisition unit 137 decrypts the acquired decryption code with the received recovery phrase "XXXyyy0123" and acquires the private key. Next, the private key output unit 162 outputs the acquired private key. The private key output unit 162 temporarily stores the acquired private key in the storage unit 11, for example.

[0125] As shown in Example 2 above, even if a user loses their private key, it can be safely recovered.

[0126] As described above, according to this embodiment, the private key of a software wallet can be securely restored in the event of loss or other issues. More specifically, according to this embodiment, the management device 2 can securely restore the private key without receiving the private key or the elements necessary for restoring the private key. Furthermore, according to this embodiment, two or more elements are required when restoring the private key. These two or more elements are the user identifier, usage information, and the restoration phrase.

[0127] The processing in this embodiment may be implemented in software. This software may be distributed by software download or the like. Alternatively, this software may be recorded on a recording medium such as a CD-ROM and distributed. This also applies to other embodiments in this specification. The software that implements the terminal device 1 in this embodiment is the following program. In other words, this program causes the computer to function as a private key generation unit that generates a private key for a software wallet, a decryption code generation unit that generates a decryption code, a recovery phrase generation unit that reversibly encrypts the private key using the decryption code and generates a recovery phrase, and a recovery phrase transmission unit that transmits the recovery phrase to the management device in association with a user identifier.

[0128] Furthermore, the software that implements the management device 2 in this embodiment is the following program. In other words, this program is a program that causes a computer to function as a first server receiving unit that receives a recovery phrase from a terminal device in association with a user identifier, a server storage unit that stores the recovery phrase in association with the user identifier, a second server receiving unit that receives a recovery instruction from the terminal device corresponding to a user identifier, a server acquisition unit that acquires the recovery phrase corresponding to the user identifier corresponding to the recovery instruction, and a server transmission unit that transmits the recovery phrase to the terminal device.

[0129] Figure 8 also shows the external appearance of a computer that executes the program described herein to realize the terminal device 1 and management device 2 of the various embodiments described above. The embodiments described above can be realized with computer hardware and computer programs executed thereon. Figure 8 is an overview of this computer system 300, and Figure 9 is a block diagram of the system 300.

[0130] In Figure 8, the computer system 300 includes a computer 301 with a CD-ROM drive, a keyboard 302, a mouse 303, and a monitor 304.

[0131] In Figure 9, the computer 301 includes, in addition to the CD-ROM drive 3012, an MPU 3013, a bus 3014 connected to the CD-ROM drive 3012, a ROM 3015 for storing programs such as boot-up programs, a RAM 3016 connected to the MPU 3013 for temporarily storing application program instructions and providing temporary storage space, and a hard disk 3017 for storing application programs, system programs, and data. Although not shown here, the computer 301 may further include a network card for providing connectivity to a LAN.

[0132] The program that causes the computer system 300 to execute the functions of the terminal device 1, etc., as described above, may be stored on the CD-ROM 3101, inserted into the CD-ROM drive 3012, and then transferred to the hard disk 3017. Alternatively, the program may be transmitted to the computer 301 via a network (not shown) and stored on the hard disk 3017. The program is loaded into the RAM 3016 when executed. The program may also be loaded directly from the CD-ROM 3101 or the network.

[0133] The program does not necessarily have to include an operating system (OS) or third-party program that causes the computer 301 to execute functions such as the terminal device 1 of the above-described embodiment. The program only needs to include the instruction portion that calls appropriate functions (modules) in a controlled manner and obtains the desired result. How the computer system 300 operates is well known, so a detailed explanation is omitted.

[0134] In the above program, steps such as sending information and receiving information do not include hardware-based processing, such as processing performed by a modem or interface card in the transmission step (processing that can only be performed by hardware).

[0135] Furthermore, the computer running the above program may be a single computer or multiple computers. In other words, it may perform centralized processing or distributed processing.

[0136] Furthermore, it goes without saying that in each of the above embodiments, two or more communication means present in a single device may be physically implemented in a single medium.

[0137] Furthermore, in each of the above embodiments, each process may be implemented by centralized processing by a single device, or by distributed processing by multiple devices.

[0138] It goes without saying that the present invention is not limited to the embodiments described above, and various modifications are possible, all of which are also included within the scope of the present invention. [Industrial applicability]

[0139] As described above, the terminal device 1 according to the present invention has the effect of securely recovering the private key in the event of loss of the private key of a software wallet, and is useful as a terminal on which a software wallet application for crypto assets operates. [Explanation of symbols]

[0140] A Information Systems 1. Terminal device 2 Management device 11 Storage Unit 12 Reception Department 13 Processing Unit 14. Transmitter 15 Receiving section 16 Output section 21 Server storage unit 22 Server receiving unit 23 Server Processing Unit 24 Server transmission section 111 User Information Storage Unit 131 Installation Section 132 Address Generation Unit 133 Private key generation section 134 Decryption code generation unit 135 Reconstruction Phrase Generation Unit 136 Usage information acquisition department 137 Private key acquisition unit 141 Restoration Phrase Transmission Unit 142 Restoration instruction transmission unit 151 Recovery Phrase Receiver 161 Usage Information Output Unit 162 Private Key Output Section 221 First Server Receiving Unit 222 Second Server Receiving Unit 231 Server Storage Unit 232 Server Acquisition Section

Claims

1. A private key generation unit that generates the private key for the software wallet, An information generation unit that generates usage information including a decryption code, A recovery phrase generation unit generates a recovery phrase by reversibly encrypting the aforementioned private key using the aforementioned decryption code, A recovery phrase transmission unit that transmits the recovery phrase to a management device in association with a user identifier, A usage information output unit that outputs the aforementioned usage information, An information acquisition unit that acquires the usage information output to the usage information output unit in accordance with the user's instructions, A terminal device comprising: a decryption processing unit that decrypts the private key based on the decryption code included in the usage information acquired by the information acquisition unit and the decryption phrase received from the management device by sending a decryption instruction to the management device to decrypt the private key.

2. Restoration instruction transmission unit, The recovery phrase receiving unit, The system further comprises a secret key output unit that outputs the secret key recovered by the recovery processing unit, The restore instruction transmission unit transmits the restore instruction to the management device in association with the user identifier. The recovery phrase receiving unit receives the recovery phrase transmitted from the management device in response to the transmission of the recovery instruction. The terminal device according to claim 1.

3. The usage information output unit outputs the usage information to the storage unit, The information acquisition unit acquires the usage information from the storage unit in response to the user's instructions. The terminal device according to claim 1.

4. The terminal device according to claim 1, wherein the usage information is an image generated by the information generation unit.

5. The terminal device according to claim 1, wherein the usage information is a code image in which the decryption code is embedded.

6. The terminal device according to claim 1, wherein the decoded code is information generated to have randomness.

7. A private key generation unit that generates a private key for a software wallet, An information generation unit that generates usage information including a decryption code, A recovery phrase generation unit generates a recovery phrase by reversibly encrypting the aforementioned private key using the aforementioned decryption code, A recovery phrase transmission unit that transmits the recovery phrase to a management device in association with a user identifier, A usage information output unit that outputs the aforementioned usage information as an image, A recovery processing unit that recovers the private key based on the decryption code contained in the image and the recovery phrase received from the management device by sending a private key recovery instruction to the management device, A terminal device having the following features.

8. A system comprising a management device and a terminal device that are connected to each other via a network, The aforementioned terminal device is A private key generation unit that generates the private key for the software wallet, An information generation unit that generates usage information including a decryption code, A recovery phrase generation unit generates a recovery phrase by reversibly encrypting the aforementioned private key using the aforementioned decryption code, A recovery phrase transmission unit that transmits the recovery phrase to the management device in association with a user identifier, It has, The aforementioned control device is A first server receiving unit receives the recovery phrase from the recovery phrase transmission unit of the terminal device, associated with the user identifier. A server storage unit that stores the recovery phrase in association with the user identifier, It has, Furthermore, the terminal device is A usage information output unit that outputs the aforementioned usage information, An information acquisition unit that acquires the usage information output to the usage information output unit in accordance with the user's instructions, A restore instruction transmission unit that transmits the restore instruction to the management device in association with the user identifier, It has, Furthermore, the management device is A second server receiving unit receives the restore instruction corresponding to the user identifier from the restore instruction transmission unit of the terminal device, A server acquisition unit that acquires the recovery phrase corresponding to the user identifier corresponding to the recovery instruction, A server transmission unit transmits the recovery phrase acquired by the server acquisition unit to the terminal device. It has, Furthermore, the terminal device is The system includes a recovery processing unit that recovers the private key based on the decryption code included in the usage information acquired by the information acquisition unit and the recovery phrase received from the server transmission unit of the management device. system.

9. An information processing method performed by a computer, A private key generation step for generating a private key for a software wallet, An information generation step that generates usage information including a decryption code, A recovery phrase generation step involves reversibly encrypting the aforementioned private key using the aforementioned decryption code and generating a recovery phrase, A recovery phrase transmission step of transmitting the recovery phrase to a management device in association with a user identifier, A usage information output step that outputs the aforementioned usage information, An information acquisition step which acquires the usage information output in the usage information output step according to the user's instructions, A recovery process step in which the private key is recovered based on the decryption code included in the usage information acquired in the information acquisition step and the recovery phrase received from the management device by sending a private key recovery instruction to the management device, An information processing method comprising the following.

10. Computers, A private key generation unit that generates the private key for the software wallet, An information generation unit that generates usage information including a decryption code, A recovery phrase generation unit generates a recovery phrase by reversibly encrypting the aforementioned private key using the aforementioned decryption code, A recovery phrase transmission unit that transmits the recovery phrase to a management device in association with a user identifier, A usage information output unit that outputs the aforementioned usage information, An information acquisition unit that acquires the usage information output to the usage information output unit in accordance with the user's instructions, A restoration processing unit restores the private key based on the decryption code included in the usage information acquired by the information acquisition unit and the restoration phrase received from the management device by sending a private key restoration instruction to the management device. A program to make it work.

Citation Information

Patent Citations

  • Private key storage method and device and related equipment

    CN111431713A

  • Virtual currency system and signature device

    JP2020031268A

  • Electronic tally type storage method and operation system therefor

    JP2020155911A

  • Key management mechanism for cryptocurrency wallet

    KR1020210045326A

  • Method and apparatus for digital currency paper wallet

    US20150254640A1