Information processing device, information processing method, information processing program, and information processing system

The information processing device addresses authentication risks and evidence gaps by dividing input data into blocks with time-varying identifiers, ensuring secure and traceable irreversible processes through dynamic role assignment and evidence recording.

JP7896833B1Active Publication Date: 2026-07-29竹内祐树 +1
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
竹内祐树
Filing Date
2026-02-25
Publication Date
2026-07-29

AI Technical Summary

Technical Problem

Conventional information processing systems face risks of fixed authentication information leakage, complexity in managing multiple authentication methods, lack of evidence for determination processing success or failure, and information leakage prior to final confirmation, with existing technologies like OTP and multi-factor authentication failing to maintain causal relationships and dynamic role assignment for input data.

Method used

An information processing device that divides input data into blocks and assigns short-term identifiers through lottery for each time window, requiring both identifiers to meet conditions for processing execution, records execution states as evidence, and invalidates identifiers upon time expiration, ensuring secure and traceable irreversible confirmation processes.

Benefits of technology

This approach reduces the risk of authentication leakage and misuse by eliminating fixed IDs/passwords, simplifies user management, and provides objective evidence of processing execution states, enhancing security and accountability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007896833000001_ABST
    Figure 0007896833000001_ABST
Patent Text Reader

Abstract

This provides suitable safety control and evidence-gathering technologies for determining whether irreversible definitive processing can be performed. [Solution] The information processing device of this disclosure controls whether or not an irreversible confirmation process based on an external request can be executed. Input data included in the request is divided to generate multiple input blocks, and a role for generating a short-term first identifier and a short-term second identifier is assigned to each input block by lottery at predetermined time windows, and the short-term first identifier and the short-term second identifier are generated based on the assignment result. Processing by the confirmation processing interface is executed only when the combination of the short-term first identifier and the short-term second identifier satisfies the conditions for establishment, which are predetermined matching criteria, and the point is set as established. If the conditions are not met, the point is set as an unestablished final point. Whether it is an established point or an unestablished final point is associated with base identification information, location identification information, transit information, and time information to generate evidence and record it in a chain, and external output data is automatically generated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus, an information processing method, an information processing program, and an information processing system for controlling the executability of irreversible determination processing based on an external request.

Background Art

[0002] In a conventional information processing system, in order to control the executability of determination processing (for example, irreversible processing such as money transfer processing, application processing, approval processing, registration processing, device operation determination processing, etc.) based on an external request, a combination of a fixed identifier (such as a user ID) and fixed authentication information (such as a password, PIN, etc.) has been widely used. However, this method has the following problems.

[0003] First, there is a risk of leakage of fixed authentication information. There is a risk that the fixed authentication information may be leaked to a third party due to phishing attacks, keyloggers, database intrusions, etc. And once the leaked fixed authentication information remains valid unless it is changed, a third party can impersonate a legitimate user and execute the determination processing illegally. [[ID=1十七]] ID=18]]

[0004] Second, there is the complexity of managing fixed authentication information. It is recommended to use different fixed authentication information for multiple services and change it regularly, but this places a heavy burden on users in terms of memorization and management. As a result, security vulnerabilities such as reusing the same fixed authentication information or using simple strings that are easy to guess may occur.

[0005] Third, there is a lack of evidence regarding the success or failure of the determination processing. In the conventional system, the basis for determining whether the determination processing has been reached is scattered各处 as reception logs and processing logs, and the determination of establishment or non - establishment is likely to depend on human interpretation. In particular, it has been difficult to objectively prove afterwards the fact that the determination processing was not executed (that is, it was not established).

[0006] Fourthly, there is the risk of information leakage in the stages prior to the final confirmation process. Even if there are input errors or fraudulent requests, the input information is temporarily stored or transmitted in the stages prior to the final confirmation process, which can lead to the risk of incorrect confirmation or information leakage.

[0007] To address these issues, technologies such as one-time password (OTP), multi-factor authentication, and token-based authentication have been proposed. Log management and audit trail technologies have also been developed to record the success or failure of processes. Furthermore, a technology has been proposed that dynamically generates a unique identifier for each transaction and attaches this identifier to the access command, thereby identifying the application that issued the command and preventing access from unauthorized applications (see, for example, Patent Document 2).

[0008] For example, OTP technology generates a temporarily valid password for authentication, so it does not generate information that remains valid for a long period of time, like fixed personal identification information. However, OTP technology does not have a mechanism to determine over time which parts of the input data are used to generate temporary information and how, nor does it incorporate a mechanism to record the fact that a final process is performed or not performed as a chain of evidence with a fixed causal relationship. [Prior art documents] [Patent Documents]

[0009] [Patent Document 1] Japanese Patent Publication No. 2014-85919 [Patent Document 2] Japanese Patent Publication No. 2008-97652 [Overview of the project] [Problems that the invention aims to solve]

[0010] In conventional information processing systems, for example, OTP technology uses temporary passwords, so while the risk of long-term leakage like that of fixed PINs is low, there is a risk of reuse attacks within the password validity period. Furthermore, there is no mechanism to maintain a causal relationship as evidence between the generation of the OTP and the execution of the confirmation process. In addition, the technology described in Patent Document 2 generates a unique identifier for each transaction and attaches it to the access command to prevent unauthorized applications from accessing the same data file. However, in the technology described in Patent Document 2, the unique identifier is uniformly generated at the start of the transaction, and there is no mechanism to dynamically assign different roles to each part of the input data for each time window. Furthermore, no mechanism is disclosed to record the fact of execution or non-execution of the confirmation process as a chain of evidence causally associated with the processing route information and time information.

[0011] On the other hand, while multi-factor authentication improves security by combining multiple authentication factors, it complicates the authentication process and increases the burden on users. For example, according to the technology described in Patent Document 1, users must pre-register a procedure for launching desired applications in a desired order and reproduce the same procedure during authentication. Thus, although the risk of leakage of fixed PIN information is reduced, the memory burden on users remains. Furthermore, while the technology described in Patent Document 2 prevents access from unauthorized applications by dynamically generating a unique identifier for each transaction, it does not have a mechanism to assign different roles to each component of the input data for each time window. As the same unique identifier is used throughout the entire transaction period, there remains a risk of reuse if the identifier is intercepted during the transaction period. In addition, none of the conventional technologies have a mechanism to record whether or not a confirmation process was executed as a chain of evidence causally associated with the path information and time information through which the process took. Thus, there is still room for improvement in the security control and evidence-taking technologies for confirmation processes.

[0012] The purpose of this disclosure is to provide suitable safety control and evidence-gathering technologies related to the feasibility of performing irreversible deterministic processes. [Means for solving the problem]

[0013] One of the first aspects of this disclosure is an information processing device that controls whether or not an irreversible confirmation process can be executed based on an external request. This information processing device receives the request, divides the input data included in the request into item units including address elements, contact elements, date elements, attribute elements, or monetary elements to generate a plurality of data units, which are input blocks, and for each predetermined time window, assigns a short-term first identifier role, which is to be used as source data for generating a short-term first identifier, to at least a portion of the input blocks, which are first blocks, by lottery based on a predetermined decision rule, for each predetermined time window, assigns a short-term second identifier role, which is to be used as source data for generating a short-term second identifier, to at least a portion of the input blocks, which are second blocks different from the first blocks, by lottery based on the decision rule, and generates the short-term first identifier and the short-term second identifier based on the assignment results of the short-term first identifier role and the short-term second identifier role. The control unit performs the following actions: to determine whether the conditions are met; if the conditions are met, to execute processing by a confirmation processing interface for executing the irreversible confirmation process, and to confirm the execution state of the irreversible confirmation process as the point at which the execution of processing by the confirmation processing interface is completed; if the conditions are not met, to confirm the execution state of the irreversible confirmation process as the final point of non-confirmation where processing by the confirmation processing interface has not been executed; to generate an audit trail by associating the confirmed state of the irreversible confirmation process at the point of confirmation or the final point of non-confirmation with base identification information that identifies the base from which the request originated; to identify location identification information that identifies a section, device or service within the base; to record the audit trail as a chain in which the sequence of events can be verified; and to automatically generate external output data based on the audit trail.The control unit then invalidates the short-term first identifier and the short-term second identifier upon the elapsed time window or upon determination of the state based on the established point or the final unestablished point for the irreversible determination process.

[0014] Furthermore, in the information processing device in the first aspect of this disclosure, the role assigned to each block of input data can be re-randomized each time the time window is updated. Therefore, even with the same input data, different roles may be assigned depending on the time window. This enables zero-fixed confidentiality control that controls whether or not confirmation processing can be performed without using a fixed ID or fixed password, thereby reducing the risk of leakage or misuse of password information.

[0015] Furthermore, in the information processing apparatus according to the first aspect of this disclosure, the determinative processing interface may be configured to include at least one of a software API, a control interface, a control signal, an open / close signal, or an actuator command, and to include a function for irreversibly determining the state of the device or processing system. This realizes a general-purpose structure that can be applied not only to software processing systems but also to processing systems that involve device control.

[0016] Furthermore, in the information processing apparatus according to the first aspect of this disclosure, the control unit maintains the fact that the processing by the confirmation processing interface was not executed, causally associating it with the transit information and the time information, and a third party can verify that the irreversible confirmation processing state is the final point of non-completion. In this way, by causally associating the above fact with the transit information and time information and recording it in a chain, subsequent verification and explanation become easier.

[0017] Furthermore, in the information processing apparatus according to the first aspect of this disclosure, the external output data includes a summary section and an evidence section, and the control unit can progressively change the granularity of the base identification information, location identification information, or transit information included in the summary section according to the destination of the external output data. This makes it possible to reduce the risk of information leakage while fulfilling accountability with the minimum necessary information.

[0018] The second aspect of the present disclosure is an information processing method executed by the information processing apparatus according to the first aspect.

[0019] The third aspect of the present disclosure is an information processing program executed by the information processing apparatus according to the first aspect.

[0020] The fourth aspect of the present disclosure is an information processing system including the information processing apparatus according to the first aspect.

Advantages of the Invention

[0021] According to the present disclosure, it is possible to provide a suitable security control technology and a traceability technology regarding the executability of irreversible determination processing.

Brief Description of the Drawings

[0022] [Figure 1] It is a diagram showing a schematic configuration of the information processing system in the first embodiment. [Figure 2] It is a diagram showing more details of the components of the server included in the information processing system in the first embodiment, and showing the components of the user terminal communicating with the server. [Figure 3] It is a diagram exemplifying the flow of operations of the information processing system in the first embodiment. [Figure 4] It is a schematic diagram exemplifying the chain structure of traces in the fourth embodiment.

Modes for Carrying Out the Invention

[0023] Hereinafter, embodiments of the present disclosure will be described based on the drawings. The configurations of the following embodiments are examples, and the present disclosure is not limited to the configurations of the embodiments.

[0024] <Term Definitions> First, terms used in the following embodiments will be defined. (1) “Deterministic processing interface” means an interface called to perform irreversible deterministic processing, and may include a software API, a control interface, a control signal, an open / close signal, or an actuator command. (2) “Software API” means an interface for accessing software functions or data in accordance with a programmatic calling convention. (3) "Internal API (Internal Application Programming Interface)" refers to an interface used within an information processing system to transfer processing between different functional units of a control unit or between software modules within a server. (4) "Point of completion" means the state in which the execution of processing by the confirmation processing interface has been completed, and the completion of the irreversible confirmation processing has been confirmed. (5) "Final point of non-establishment" refers to a state in which processing by the interface for finalization processing has not been executed and the process has ended. (6) An "input block" is a data unit obtained by dividing the input data included in an external request into item units (address element, contact element, date element, attribute element, etc.). (7) "Time window" means a predetermined time window that defines the determination of the conditions for establishment and the scope of validity of the short-term first identifier and the short-term second identifier. (8) “Lottery” means a lottery based on a decision rule for determining the assignment of roles to input blocks for each time window, and the “decision rule” may include rules based on pseudorandom numbers, randomized functions, or similar. (9) "Time-varying role assignment" refers to the process of updating the role of an input block in accordance with the update of the time window, based on a lottery. (10) “Short-term first identifier” means identification information that is valid only within a time window and becomes invalid upon the passage of the time window or the determination of the final point of establishment or non-establishment. (11) "Short-term second identifier" means information for determining identification that is valid only within a time window and becomes invalid upon the passage of the time window or the determination of the final point of establishment or non-establishment. (12) "Matcher" means a key for matching with external records, which does not contain information that can directly identify an individual and is generated from time information or location identification information. (13) “External output data” means a data structure for external submission consisting of a summary section including the type of final destination, base, route, time and verifier, and an evidence section including a chained record of evidence.

[0025] <First Embodiment> (Overview of the Information Processing System) The outline of the information processing system in the first embodiment will be described with reference to Figure 1. Figure 1 is a diagram showing the schematic configuration of the information processing system in this embodiment. The information processing system 100 according to this embodiment is composed of a network 200, a server 300, and a user terminal 400. The information processing system disclosed herein controls whether or not irreversible confirmation processing based on external requests can be executed by time-varying role assignment based on a lottery for each time window, and records the distinction between the final point of completion and the final point of non-completion as evidence, with the control of whether or not irreversible confirmation processing can be executed being performed by the server 300. Here, the above-mentioned irreversible confirmation processing includes, for example, remittance processing in finance, application processing in government administration, approval processing in medical care, and operation confirmation processing for vehicles and industrial machinery.

[0026] This embodiment is characterized by not using a fixed ID and fixed password, assigning roles to blocks of input data in a time-varying manner, and controlling whether or not the confirmation process can be executed based on conditions that are met based on a combination of a short-term first identifier and a short-term second identifier.

[0027] In this embodiment, a combination of a short-term first identifier and a short-term second identifier is required as a condition for establishment. Specifically, (a) for each input block obtained by dividing the input data into item units, a short-term first identifier role or a short-term second identifier role is assigned by lottery for each predetermined time window, and (b) processing by the confirmation processing interface is executed only if the short-term first identifier and short-term second identifier generated based on the assignment result satisfy the establishment condition within the time window.

[0028] Here, the first short-term identifier is identification information valid only within the time window and is not permanently maintained like a fixed ID. The second short-term identifier is identification determination information valid only within the time window and is not meant to be permanently memorized like a fixed PIN. Both the first and second short-term identifiers expire upon the passage of the time window or upon the determination of the final point of completion or non-completion.

[0029] In this embodiment, the confirmation process is executed only when both the short-term first identifier and the short-term second identifier satisfy the conditions within the time window. This eliminates the need for a fixed ID / fixed password combination, making it difficult to reuse attacks or guess attacks in the event of a data breach.

[0030] (Functional configuration of information processing systems) Here, network 200 is, for example, an IP network. Network 200 can be wireless, wired, or a combination of both, as long as it is an IP network. For example, in the case of wireless communication, user terminal 400 may access a wireless LAN access point (not shown) and communicate with server 300 via LAN or WAN. Furthermore, network 200 is not limited to these examples and may also be, for example, a public switched telephone network, an optical fiber line, an ADSL line, or a satellite communication network.

[0031] Server 300 is connected to user terminals 400 via network 200. Note that in Figure 1, for simplicity of explanation, one server 300 and four user terminals 400 are shown, but it goes without saying that the configuration is not limited to these.

[0032] Server 300 can be any electronic computer equipment with processing capabilities for computational and processing operations such as data acquisition, generation, and updating. For example, it may be a personal computer, server, mainframe, or other electronic device. In other words, Server 300 can be configured as a computer having a processor such as a CPU or GPU, main memory such as RAM or ROM, and auxiliary storage such as an EPROM, hard disk drive, or removable media. The removable media may be, for example, a USB memory stick or a disk recording medium such as a CD or DVD. The auxiliary storage device stores the operating system (OS), various programs, various tables, etc.

[0033] Furthermore, the server 300 may use SaaS (Software as a Service), PaaS (Platform as a Service), or IaaS (Infrastructure as a Service) via a cloud server as appropriate, without providing dedicated software, hardware, or OS for the information processing system 100 according to this embodiment.

[0034] The user terminal 400 can be any electronic device used by a user of the information processing system 100 to send requests, such as a mobile terminal, tablet terminal, smartphone, wearable device, personal computer, or other terminal device. Alternatively, the user terminal 400 may be a control terminal for industrial machinery or vehicles.

[0035] Next, a detailed explanation of the components of the server 300 will be given based on Figure 2. Figure 2 shows in more detail the components of the server 300 included in the information processing system 100 in the first embodiment, as well as the components of the user terminal 400 that communicates with the server 300.

[0036] The server 300 has a communication unit 301, a storage unit 302, and a control unit 303 as functional units. It loads a program stored in the auxiliary storage device into the working area of ​​the main memory and executes it. Through the execution of the program, each functional unit is controlled, thereby enabling each functional unit to perform its respective function according to its predetermined purpose. However, some or all of the functions may be implemented by hardware circuits such as ASICs or FPGAs.

[0037] Here, the communication unit 301 is a communication interface for connecting the server 300 to the network 200. The communication unit 301 consists of, for example, a network interface board and a wireless communication circuit for wireless communication. The server 300 is connected to a user terminal 400 and other external devices for communication via the communication unit 301.

[0038] The storage unit 302 comprises a main memory and an auxiliary storage device. The main memory is the memory where programs executed by the control unit 303 and the data used by those programs are stored. The auxiliary storage device is the device where programs executed by the control unit 303 and the data used by those programs are stored. The storage unit 302 also stores data transmitted from the user terminal 400, etc., and the storage unit 302 stores input data included in user requests. The server 300 acquires data transmitted from the user terminal 400, etc., via the communication unit 301.

[0039] The control unit 303 is a functional unit that manages the control performed by the server 300. The control unit 303 can be implemented by a processing unit such as a CPU. The control unit 303 is further composed of four functional units: a receiving / input splitting unit 3031, a time-varying role assignment / generation unit 3032, a quarantine / determination unit 3033, and an evidence / recording unit 3034. Each functional unit may be implemented by executing a stored program using the CPU.

[0040] The receiving / input splitting unit 3031 receives an external request and divides the input data included in the received request into item units to generate multiple input blocks. The received request includes data transmitted from the user terminal 400 via the communication unit 301. The input blocks can be divided into any item units such as address elements, contact elements, date elements, attribute elements, and amount elements.

[0041] In this embodiment, the user terminal 400 has a communication unit 401, an input / output unit 402, and a storage unit 403 as functional units. The communication unit 401 is a communication interface for connecting the user terminal 400 to the network 200, and is configured to include, for example, a network interface board and a wireless communication circuit for wireless communication. The input / output unit 402 is a functional unit for displaying information transmitted from the outside via the communication unit 401, and for inputting information when transmitting information to the outside via the communication unit 401. The storage unit 403 is configured to include a main memory and an auxiliary memory, similar to the storage unit 302 of the server 300.

[0042] The input / output unit 402 further includes a display unit 4021, an operation input unit 4022, and an image / audio input / output unit 4023. The display unit 4021 has the function of displaying various information and is implemented by, for example, an LCD (Liquid Crystal Display) display, an LED (Light Emitting Diode) display, or an OLED (Organic Light Emitting Diode) display. The operation input unit 4022 has the function of receiving operation input from the user and is specifically implemented by soft keys such as a touch panel or hard keys. The image / audio input / output unit 4023 has the function of receiving image input such as still images and videos and is specifically implemented by a camera using an image sensor such as Charged-Coupled Devices (CCD), Metal-oxide-semiconductor (MOS), or Complementary Metal-Oxide-Semiconductor (CMOS). The image / audio input / output unit 4023 also has the function of receiving audio input and output and is specifically implemented by a microphone or speaker.

[0043] The user can use the user terminal 400 configured in this way to send a request containing input data to the server 300.

[0044] The time-varying role assignment and generation unit 3032 assigns the role of short-term first identifier to at least a portion of the input blocks, specifically to first blocks, by lottery for each predetermined time window. The time-varying role assignment and generation unit 3032 also assigns the role of short-term second identifier to at least a portion of the input blocks, specifically to second blocks, which are different from the first blocks, by lottery for each predetermined time window. The lottery is performed based on a decision rule that may include rules based on pseudo-random numbers, randomized functions, or similar methods. The assignment results are used consistently within the same time window, and a re-lottery is performed when the time window is updated. The short-term first identifier role serves as the source data for generating the short-term first identifier, and the short-term second identifier role serves as the source data for generating the short-term second identifier. The time-varying role assignment and generation unit 3032 then generates the short-term first identifier and the short-term second identifier based on the assignment results. The generated short-term first identifier and short-term second identifier are not retained as fixed identifiers or fixed password information, and expire upon the passage of the time window or the determination of the final point of completion or non-completion.

[0045] The quarantine / determination unit 3033 determines whether the short-term first identifier and the short-term second identifier satisfy the conditions for success within the time window. The determination of the conditions for success is performed before the execution of processing by the confirmation processing interface, and if the conditions for success are not met, processing by the confirmation processing interface is not executed. Only if the conditions for success are met, the quarantine / determination unit 3033 executes processing by the confirmation processing interface as the success point, and confirms that irreversible confirmation processing has been performed upon completion of the execution of processing by the confirmation processing interface. On the other hand, if the conditions for success are not met, the quarantine / determination unit 3033 confirms the execution status of irreversible confirmation processing as the final point of non-success without executing processing by the confirmation processing interface.

[0046] The trail / recording unit 3034 generates evidence by associating whether the final point is established or not, base identification information, location identification information, transit information, and time information. Here, the base identification information identifies a facility or logical base, and the location identification information identifies a section, device, or service within the base. The transit information may include the processing sequence or processing path identifier that was passed through from reception in the receiving / input splitting unit 3031 to the determination of the irreversible final processing state. The trail / recording unit 3034 then records the generated evidence as a chain whose context can be verified. Chain recording can be implemented, for example, by a hash chain, but is not limited to a specific implementation method as long as the verifiability of the context is ensured. Furthermore, the trail / recording unit 3034 automatically generates external output data based on the chained evidence. The external output data consists of a summary unit including the type of irreversible final processing state, base, transit, time, and verifier, and an evidence unit including the chained evidence.

[0047] Furthermore, the control unit 303 functions as the control unit according to this disclosure by executing the processing of the receiving / input splitting unit 3031, the time-varying role assignment / generation unit 3032, the quarantine / determination unit 3033, and the evidence / recording unit 3034.

[0048] Here, the operation flow of the information processing system 100 in this embodiment will be described. Figure 3 is a diagram illustrating the operation flow of the information processing system 100 in this embodiment. Figure 3 describes the operation flow between each component in the information processing system 100 in this embodiment, and the processing performed by each component.

[0049] In this embodiment, first, a request is sent from the user terminal 400 of a user who intends to perform a confirmation process (for example, a remittance process in finance, an application process in government administration, an approval process in medical care, or a confirmation process for the operation of a vehicle or industrial machinery). When the user inputs request information at the user terminal 400 (S101), the receiving / input splitting unit 3031 of the server 300 receives information regarding this request via the communication unit 301 (S102).

[0050] The server 300 does not immediately proceed to processing the received request using the confirmation processing interface, but instead divides the input data into item units in the receiving / input splitting unit 3031 to generate multiple input blocks (S103).

[0051] Next, the time-variable role assignment / generation unit 3032 performs a lottery for each predetermined time window and assigns the short-term first identifier role to the first block included in the input block and the short-term second identifier role to the second block (S104). Then, it generates the short-term first identifier and the short-term second identifier based on the assignment results (S105). At this time, the time-variable role assignment / generation unit 3032 determines the current time window. Here, the time window may be set based on the reception time in the reception / input division unit 3031. The time window may also be set as a fixed-length period, or as a variable-length period depending on the load, frequency, requirement characteristics, etc. Then, the time-variable role assignment / generation unit 3032 assigns the short-term first identifier role and the short-term second identifier role by performing a lottery based on a determination rule that may include rules based on pseudorandom numbers, randomized functions, or similar. At this time, the time-variable role assignment / generation unit 3032 may restrict the assignment so that the same input block does not play the same role in consecutive time windows. In other words, the assignment of the short-term first identifier role and the short-term second identifier role may be restricted so that the same input block does not play the same role in consecutive time windows before and after the time window update. This update restriction makes it difficult for an attacker to learn and reuse the role of a particular input block. Furthermore, with this processing, the user does not need to constantly remember a fixed identifier or a fixed password, because the conditions for fulfillment are determined only when deciding whether or not to execute the confirmation processing interface based on the combination of the short-term first identifier and the short-term second identifier.

[0052] Furthermore, at least a portion of the input block, the first short-term identifier, and the second short-term identifier may be obtained manually. However, such manual input is used only as part of the conditions for fulfillment and is invalidated after the state is determined by the fulfillment point or the final point of non-fulfillment. This eliminates the risk of manually entered information remaining and being reused after determination.

[0053] Furthermore, even if a fixed identifier or password is entered for compatibility with existing systems, the execution of the confirmation process via the confirmation interface is determined by the conditions for success based on the short-term first identifier and short-term second identifier. In other words, even if a fixed identifier or password is entered, confirmation processing will not be executed based on that alone.

[0054] Next, the quarantine and determination unit 3033 determines whether the short-term first identifier and the short-term second identifier satisfy the conditions for establishment within the time window (S106).

[0055] Here, we will explain a specific example of determining the conditions for success. The conditions for success are whether or not the combination of the short-term first identifier and the short-term second identifier satisfies a predetermined matching criterion within the time window. For example, considering a money transfer transaction in finance, suppose a user requests a money transfer from user terminal 400, and four items are sent as input data: "recipient account number," "sender account number," "transfer amount," and "transfer date." The receiving / input splitting unit 3031 generates these as input blocks B1 (recipient), B2 (sender), B3 (amount), and B4 (date), respectively.

[0056] Next, the time-varying role assignment and generation unit 3032 performs a lottery in the current time window T1 (for example, 30 seconds from the time of receipt) and assigns, for example, the short-term first identifier role to B1 (recipient) and the short-term second identifier role to B3 (amount). Here, B2 (sender) and B4 (date) are not assigned a role in this time window. The time-varying role assignment and generation unit 3032 generates the short-term first identifier SI based on the value of B1 to which the short-term first identifier role has been assigned, and generates the short-term second identifier S2 based on the value of B3 to which the short-term second identifier role has been assigned. For example, SI is a hash value calculated by a one-way hash function using the value of B1 and the start time of the time window T1 as inputs, and S2 is a hash value calculated by the same or different one-way hash function using the value of B3 and the start time of the time window T1 as inputs.

[0057] The quarantine / determination unit 3033 determines whether the combination of SI and S2 satisfies a predetermined matching criterion. One example of a matching criterion is a method in which the value of the upper N bits of SI and the value of the upper N bits of S2 are subjected to a predetermined operation (e.g., exclusive OR), and the unit determines whether the result of the operation is within a predetermined threshold. As a specific example of a case where the condition for success is met, suppose the upper 8 bits of SI are "0x3A", the upper 8 bits of S2 are "0x35", and their exclusive OR is "0x0F" (15 in decimal). If the threshold for matching is set to "20 or less", the operation result 15 satisfies the threshold of 20 or less, so the condition for success is met. In this case, the quarantine / determination unit 3033 executes the processing of the confirmation processing interface and confirms the execution state of the irreversible confirmation processing as the success point.

[0058] On the other hand, as a concrete example of a case where the conditions for success are not met, suppose the upper 8 bits of SI are "0x3A", the upper 8 bits of S2 are "0xF2", and the exclusive OR is "0xC8" (200 in decimal). Since the calculation result of 200 exceeds the threshold of 20, the conditions for success are not met. In this case, the quarantine / determination unit 3033 does not execute the processing of the confirmation processing interface, and the execution state of the irreversible confirmation processing is confirmed as the final point of non-success.

[0059] Furthermore, once time window T1 has elapsed, SI and S2 will expire. If a draw is conducted again in the next time window T2, even with the same input data, different roles may be assigned to different input blocks, and therefore the generated values ​​of SI and S2 will also change. As a result, it becomes extremely difficult for a third party who intercepts the short-term first identifier and short-term second identifier in a particular time window to reuse that information in another time window to satisfy the conditions for success.

[0060] If the result in S106 is positive, the server 300 proceeds to process S107; if the result in S106 is negative, the server 300 proceeds to process S108.

[0061] If a positive determination is made in S106, the quarantine / determination unit 3033 then performs processing using the confirmation processing interface in S107. This performs irreversible confirmation processing, and the state is confirmed as established (S108).

[0062] On the other hand, if a negative determination is made in S106, the quarantine / determination unit 3033 then determines the state as the final unfulfilled state in S109 without executing processing by the confirmation processing interface. In this case, confirmation processing is not executed, and if the user is a third party with fraudulent intentions, fraudulent confirmation processing by this third party can be deterred. Furthermore, if the conditions for fulfillment are not met because neither the short-term first identifier role nor the short-term second identifier role is assigned within the time window, the execution state of the irreversible confirmation processing may also be determined as the final unfulfilled state.

[0063] The quarantine and determination unit 3033 may also transfer the request to an isolated environment separated from the production execution environment that performs the irreversible finalization process, and execute a predetermined inspection process in the isolated environment. Here, the inspection process involves verifying the legitimacy of the request and determining in advance whether or not the irreversible finalization process can be executed. The results of the processing in such an isolated environment are controlled so as not to be reflected in the production finalization process. In this way, fraudulent requests are inspected without affecting the finalization process.

[0064] Next, the evidence recording unit 3034 generates evidence including whether it is a point of completion or the final point of non-completion, and records the evidence as a chain in which the sequence of events can be verified (S110). Then, the evidence recording unit 3034 automatically generates external output data based on the chained recorded evidence (S111).

[0065] More specifically, the trail / recording unit 3034 acquires site identification information, location identification information, route information, and time information. Site identification information and location identification information may be expressed as a hierarchy of sites, areas, and devices or services. Route information may include at least one of the call sequence or processing route identifiers of internal APIs. This information makes it possible to consistently understand where a request originated, what route it took, and where it was completed or not completed.

[0066] The evidence / recording unit 3034 then records the fact that processing by the confirmation processing interface was not performed, causally associating it with transit information and time information. This makes it possible for a third party to verify that the final state was not established. Thus, a feature of this embodiment is that not only the fact that confirmation processing was performed (establishment point) but also the fact that confirmation processing was not performed (final state of not being established) is documented in a verifiable evidence.

[0067] Furthermore, the evidence / recording unit 3034 generates a verifier that does not contain information that can directly identify an individual, and includes it in the evidence and external output data. The verifier is generated from at least a portion of the time information and location identification information report. The verifier is used for matching with external records or as a key for case identification.

[0068] The external output data includes a summary section and an evidence section. The summary section is verifiable as being based on the evidence section. Depending on the recipient, the granularity of the base identification information, location identification information, or transit information included in the summary section may be changed in stages. The granularity may include at least coarse, medium, and fine levels. Here, time information is included at all levels of granularity. For example, coarse level includes time information, base identification information, and whether the final destination is a completed or uncompleted point; medium level includes location identification information in addition to the above; and fine level may include transit information and verifiers in addition to the above.

[0069] For example, in a financial application, when a user requests a money transfer from a user terminal 400, the input data is divided into input blocks consisting of items such as recipient, sender, amount, and date. The time-variable role assignment / generation unit 3032 performs a lottery within the time window and assigns, for example, the short-term first identifier role to the recipient block and the short-term second identifier role to the amount block. The time-variable role assignment / generation unit 3032 generates the short-term first identifier and short-term second identifier from the assignment results, and the quarantine / determination unit 3033 determines the conditions for completion. If the conditions for completion are met, the money transfer process is executed as a completed transaction; otherwise, it is determined as an uncompleted transaction. In either case, evidence is generated and chained together.

[0070] In this case, the summary section included in the external output data, at a coarse level, only discloses which facility the processing took place at and whether it was completed or not. It does not include which counter or terminal within the branch processed the transaction, or which internal route the processing took. This allows for accountability with the minimum necessary information for recipients who do not require individual processing details, such as for transaction count aggregations and statistical reports. On the other hand, at a medium level, the data is hierarchically disclosed down to which section (2nd floor corporate counter) within the base, which device (terminal LC-03), and which service (remittance processing service) processed the transaction. This makes it possible to track the physical and logical location where a particular transaction was completed, enabling internal control verification and responding to individual inquiries from supervisory authorities. However, it does not include the internal route the processing took. At a detailed level, the internal API call order (the order in which each functional unit was called) and processing route identifiers are included as transit information. In addition, a verifier (a key that does not contain information that directly identifies an individual) is included, enabling matching with external records. Furthermore, time information is recorded down to the second. This allows for verification in fraud investigations and internal audits that the process followed the legitimate route, and enables comparison with external transaction records using a verifier.

[0071] Furthermore, in vehicle applications, when a user requests engine start from the user terminal 400, the confirmation processing interface is configured as a control signal. Engine start is executed only when the conditions for success are met; otherwise, the engine does not start and the final point of failure is confirmed. In either case, evidence is generated and recorded in a chain, allowing for objective verification of whether or not the engine started afterward.

[0072] In this case, the summary section of the external output data, at a coarse level, only records the fact that engine starting was refused and which facility it occurred at. It does not include details about the vehicle or the internal processing that led to the refusal to start, so it is limited to the minimum information required for a daily operational management record. On the other hand, at a medium level, it is hierarchically identified which vehicle in which section was refused to start its engine. This includes sufficient information for the safety management department to track the history of engine starting refusals for specific vehicles and to report to insurance companies that the vehicle was under normal control. At a detailed level, the fact that the control signal (confirmation processing interface) was not executed is explicitly stated as transit information. The accident investigation committee can verify from the transit information that engine starting was refused by proper safety control, and can also cross-reference it with the vehicle's logs using a verifier.

[0073] Furthermore, correlations between multiple requests may be identified based on the matcher or request feature information. Here, the request feature information includes at least one of the request's repeatability, order, formal deviation, or anomalous parameter features. Notifications are made according to the results of the correlation identification, and the notification content includes whether it is a successful point or an unsuccessful final point, but does not contain personal information. As a result, events determined as unsuccessful final points are managed cumulatively based on the matcher or request feature information. This cumulative management can then be used as auxiliary information for the determination conditions of successful point control.

[0074] For example, considering a scenario involving a remittance in finance, suppose that four requests with the same base identification information and location identification information are sent consecutively within approximately 90 seconds, and all are determined to be unsuccessful final destinations. The evidence / record unit 3034 detects common matchers in these requests based on the repetition of the request characteristic information and correlates them to identify that requests with the same characteristics are repeatedly reaching unsuccessful final destinations in a short period of time. Based on the results of this correlation identification, a notification is issued that includes the number of detected cases, whether they are successful or unsuccessful final destinations, the detection period, and base identification information, but does not include information that can directly identify an individual. This allows the possibility of exploratory attempts by an unauthorized third party to be communicated to the administrator without including personal information.

[0075] Furthermore, for example, consider a scenario in administrative application processing where three requests with the same verifier are sent. Two of these requests are determined to be unsuccessful because the order in which the input blocks are received differs from the usual pattern, while the remaining request is entered in the usual order and determined to be successful. The evidence / record unit 3034 correlates and identifies the transition pattern in the request characteristic information, where the system reached the successful point after multiple attempts with varying input orders. Since the notification includes both successful and unsuccessful final points, the administrator has an opportunity to retrospectively verify the validity of successful processes.

[0076] Furthermore, for example, consider the scenario of engine start control in a vehicle management system. Suppose that requests containing format deviations such as invalid strings, non-standard field lengths, or negative values ​​in the input block are sporadically sent from different vehicles (different location identification information) within the same location, and all are determined to be unfulfilled final destinations. The evidence / recording unit 3034 detects common matchers for requests that share the common characteristics of being from the same location, at similar time periods, and having format deviations, based on the format deviation characteristics among the request characteristic information, and correlates and identifies structural anomalies spanning multiple locations. This allows administrators to be notified of the possibility of organized unauthorized access attempts or communication failures without identifying individual vehicles or drivers.

[0077] Furthermore, for example, considering a scenario in the operation confirmation of industrial machinery control in a factory, suppose requests with numerical parameters that significantly deviate from the past normal range, such as a pressure specification value more than three times the normal range and a speed specification value approximately three times the normal range, are intermittently transmitted from a press machine on the same processing line. Most of these will be determined as unfulfilled final points, but requests with relatively small deviations from the normal range may satisfy the conditions for fulfillment and be determined as fulfilled points. The evidence / recording unit 3034 correlates and identifies repeated deviations from the normal range within a series of requests having the same matcher, based on the abnormal parameter features in the request characteristic information. Since the notification also includes requests that have been determined as fulfilled points, the administrator can grasp the parameter drift trend caused by equipment aging or sensor malfunctions at an early stage.

[0078] The user terminal 400 then obtains information regarding the results of the confirmation process (S112). This allows the user to confirm that, for example, the execution of a remittance process, application process, approval process, or device operation confirmation process has been completed.

[0079] As described above, this embodiment does not rely on fixed IDs and fixed passwords, but generates short-term first and second identifiers through time-varying role assignment based on a lottery for each time window, and controls whether the confirmation processing interface can be executed based on the conditions for their establishment. The final point of establishment or non-establishment is then documented in association with base, location, route, and time, recorded as a chain with verifiable cause and effect, and external output data is automatically generated. Here, due to the combination of time-varying role assignment and evidence chain recording, the short-term first and second identifiers generated from the input data expire upon the passage or confirmation of the time window, so the fact of execution or non-execution of the confirmation process is causally documented based only on the information that was valid within the time window. Such synergistic effects cannot be achieved by using any of the conventional OTP technology, multi-factor authentication technology, or unique identifier generation technology alone or in combination.

[0080] According to the information processing system 100 described above, suitable safety control technology and evidence-gathering technology can be provided regarding the feasibility of executing irreversible definitive processing.

[0081] <Second Embodiment> The information processing system 100 in the second embodiment will now be described. The deterministic processing interface in this embodiment can be applied to a wide range of processing systems, including not only software processing systems but also device control systems.

[0082] In this embodiment, the confirmation processing interface is not limited to a software API, but may include a control interface, control signal, switch signal, or actuator command for irreversibly determining the state of the device or processing system. Therefore, confirmation processing can be abstractly treated as confirmation of information processing, confirmation of device operation, confirmation of state transitions, or irreversible processing similar thereto.

[0083] In Figure 3 described in the description of the first embodiment, if the S106 process is positive, in this embodiment, one of the four: a software API, a control signal, an open / close signal, and an actuator command can be executed as the interface for confirmation processing. On the other hand, if the S106 process is negative, in this embodiment, the confirmation processing is not executed and the device or processing system can be kept in a safe state.

[0084] For example, in financial applications, the confirmation processing interface is configured as a software API, and the transaction is considered complete upon the completion of the API call for remittance processing. On the other hand, in automotive applications, the confirmation processing interface is configured as a control signal, and the transaction is considered complete upon the completion of the transmission of the engine start signal. Furthermore, in industrial machinery applications, it is configured as an actuator command, and the transaction is considered complete upon the completion of the transmission of the heavy machinery start command.

[0085] Thus, regardless of the type of confirmation processing interface, the quarantine / determination unit 3033 determines that irreversible confirmation processing has been performed upon completion of processing by the confirmation processing interface. If the conditions for this determination are not met, processing by the confirmation processing interface is not performed, and the device or processing system is maintained in a safe state.

[0086] <Third Embodiment> The information processing system 100 in the third embodiment will now be described. In this embodiment, the server 300 ensures safe behavior in the event of a processing system failure or exception, and independence of the audit trail for simultaneous requests.

[0087] In this embodiment, if a failure or exception occurs in the processing system, and the confirmation processing interface is not executed, the request is confirmed as an unfulfilled final point. This prevents irreversible confirmation processing from being mistakenly executed in the event of a failure. Furthermore, the occurrence of the failure or exception itself is recorded as evidence.

[0088] For example, consider a scenario involving money transfer processing in finance. Suppose a user requests a money transfer from user terminal 400. After the receiving / input splitting unit 3031 generates an input block and the time-varying role assignment / generation unit 3032 generates a short-term first identifier and a short-term second identifier, the server 300 process terminates abnormally while the quarantine / determination unit 3033 is executing the determination process for the conditions of success. In this case, since processing by the confirmation processing interface (money transfer processing API) is not executed, the state based on the request is determined to be an unsuccessful final point. The evidence / recording unit 3034 records the fact of the failure as evidence, associating it with the time of the failure, transit information (that processing was interrupted), and location identification information. This ensures that the fact that the money transfer was not executed is documented along with the fact of the failure, preventing duplicate transfers after the failure is resolved.

[0089] Furthermore, for example, consider a scenario involving vehicle engine start control. Suppose a user requests engine start from user terminal 400, the conditions for fulfillment are determined, and the transmission of the confirmation processing interface (engine start control signal) begins. However, if a communication interruption in the in-vehicle network is detected before the transmission of the control signal is completed, the execution of processing by the confirmation processing interface is not completed because the transmission of the control signal is not finished. The state based on the request is then determined to be an unfulfilled final state. The evidence records the time the communication interruption was detected and the fact that the control signal was not completed. This prevents the engine from being started in an uncertain state during a communication interruption and allows for objective confirmation afterward that the engine did not start.

[0090] Furthermore, this embodiment ensures the independence of the evidence trail for simultaneous requests.

[0091] For more details, consider a scenario in financial remittance processing where three remittance requests (Request A, Request B, Request C) are sent at approximately the same time from three different user terminals 400 through different teller terminals at branch B of bank A. Server 300 sets an independent time window (Time Window A, Time Window B, Time Window C) for each request and independently performs a lottery within each time window to assign roles to input blocks. For example, in Request A, the recipient block may be assigned the role of short-term first identifier, and in Request B, the same recipient block may be assigned the role of short-term second identifier. Thus, even for the same item, different roles may be assigned to each request. The short-term first identifier and short-term second identifier generated for each request are also independent of each other, and the result of the determination of the fulfillment condition for Request A does not affect the determination result for Request B or Request C. As a result, for example, if Request A is determined to be fulfilled and Requests B and C are determined to be unfulfilled, the evidence for each request is independently chained and recorded as evidence chain A, evidence chain B, and evidence chain C. This ensures that the fact of fulfillment of requirement A and the fact of non-fulfillment of requirements B and C are managed as verifiable chains of evidence, respectively. This prevents the evidence from becoming mixed up between simultaneous requirements.

[0092] <Fourth Embodiment> The information processing system 100 in the fourth embodiment will be described with reference to Figure 4. In this embodiment, the server 300 performs processing related to long-term storage, regeneration, and re-verification of the evidence trail.

[0093] Here, Figure 4 is a schematic diagram illustrating the chain structure of evidence in this embodiment.

[0094] Figure 4 shows a chain structure at the top in which evidence A, evidence B, evidence C, and evidence N are sequentially connected by arrows. This chain structure represents that each piece of evidence is related to the preceding and succeeding evidence, and that the sequence is verifiable. Below the chain structure, three management operations for the chained evidence are shown. On the left is retention period management, stating that when the retention period expires, the fact of deletion is recorded as a new piece of evidence. In the center is package regeneration, stating that external output data can be regenerated from the same piece of evidence and that modifications can be detected. On the right is long-term preservation format, stating that consistency with the original evidence is maintained while retaining the information necessary for verification.

[0095] The retention period for chained evidence may be set according to the requirements of the processing system or operational policies. Even if evidence is deleted due to the expiration of the retention period, the fact of deletion and the time of deletion are recorded as new evidence. This makes it possible to verify the history of the existence and disappearance of evidence at a later date.

[0096] Regarding the management of retention periods, for example, considering a scenario involving remittance processing in finance, suppose that in the information processing system 100 of Bank A, evidence A, evidence B, ..., evidence N related to remittance requests processed from April to June 2025 are recorded in a chain. If the operational policy stipulates that the retention period for evidence is 5 years, then in July 2030, the deletion process is performed for evidence A, whose retention period has expired. At this time, the evidence / record unit 3034 removes the content of evidence A itself from the chain, but adds the fact of deletion, "evidence A was deleted on July 1, 2030," and the deletion time as a new evidence (evidence D1) in the chain record. Evidence D1 retains the position of evidence A in the chain before deletion (its chronological relationship with evidence B). As a result, the content of evidence A can no longer be referenced, but the fact that evidence A existed and the time of deletion are maintained in a verifiable state in the chain record. If a supervisory authority were to subsequently inquire about transactions in April 2025, the administrator could explain, based on evidence D1, that "evidence for that period existed but was deleted due to the expiration of the retention period."

[0097] Furthermore, the external output data may be regenerated based on the same chained recorded evidence. The regenerated external output data can be verified in correspondence with the evidence section, and arbitrary alterations can be detected.

[0098] Regarding the regeneration of external output data, for example, considering an application processing scenario in government administration, suppose that for an application request processed in July 2025, the evidence / record unit 3034 chain-recorded the evidence and generated and submitted medium-granular external output data P1 to the supervisory authority in July of the same year. Subsequently, if the fraud investigation agency requests detailed-granular data regarding the same application processing in February 2026, the evidence / record unit 3034 regenerates detailed-granular external output data P2 based on the same chain-recorded evidence. The evidence section of the regenerated P2 is based on the same chain-record as the evidence section of the previously submitted P1, and the correspondence between the evidence sections of P1 and P2 can be verified. In other words, even if P2 is regenerated after the submission of P1, the content of the evidence section does not change arbitrarily. If part of the chain-record has been altered, the alteration can be detected by verifying the sequence of events in the chain structure.

[0099] Furthermore, regarding the conversion to a long-term storage format, for example, considering the scenario of industrial machine control, suppose that in the factory's information processing system 100, evidence related to the confirmation of press machine operation is routinely recorded in a chain. After several years have passed since the start of operation, if the amount of accumulated evidence data increases, the evidence / recording unit 3034 converts the evidence to a long-term storage format in order to improve the efficiency of the storage area. The evidence in the long-term storage format retains the minimum information necessary for verifying the completion point or the final location of the incomplete completion, namely, base identification information, location identification information, route information, time information, and the type of final location, while supplementary information that is not directly related to whether or not the confirmation processing interface has been executed is stored separately. The converted evidence maintains consistency with the original evidence, and it is possible to regenerate external output data from the evidence converted to the long-term storage format.

[0100] <Fifth Embodiment> The information processing system 100 in the fifth embodiment will be described. In this embodiment, the categorization of unfulfilled final points, safe side control, and response to attack attempts will be described.

[0101] The final point where a condition is not met is determined by the non-execution of processing by the confirmation processing interface, but it may be classified into multiple types depending on the cause. These types may include, for example, failure to meet the conditions for fulfillment, rejection of the judgment in the observation environment, input block mismatch, exceeding the time window, or a combination thereof.

[0102] If the conditions for fulfillment are not met, the processing by the confirmation interface is not executed, and the device or processing system is maintained in a safe state. This safe state is recorded in the evidence as the last point where fulfillment was not achieved. This prevents irreversible confirmation processing from being mistakenly executed in the event of a failure or abnormality.

[0103] Even if an incorrect input, incorrect operation, or interruption occurs, the request will be finalized as an unfulfilled request unless processing by the confirmation interface is executed. This prevents incorrect operations from affecting irreversible confirmation processing.

[0104] A request that has been determined as an unfulfilled final point will not transition to a fulfilled point after such determination. Furthermore, after a fulfilled point or an unfulfilled final point has been determined, the determination result is not re-evaluated. If re-evaluation is necessary, it will be processed as a new request from the receiving / input splitting unit 3031.

[0105] Even if unauthorized external attempts, exploratory attempts, or consecutive attempts that do not meet the conditions for success are made, all such attempts will be determined as unsuccessful final points unless processing is performed by the confirmation processing interface. Furthermore, events determined as unsuccessful final points may be managed cumulatively based on the verifier or request feature information.

[0106] <Sixth Embodiment> The information processing system 100 in the sixth embodiment will be described. In this embodiment, the multi-stage determination of the successful point, the expansion of the determination conditions, and the consistency of the confirmed result will be described.

[0107] This disclosure is also applicable to multi-stage processing systems in which the point of success is determined through multiple stages of processing. In this case, a part of the conditions for success may be determined at each stage, and the point of success or the final point of failure may be determined at the final stage.

[0108] The conditions for success may include not only matching of the first short-term identifier and the second short-term identifier, but also consistency within the time window, consistency of role assignments, or consistency of requested feature information. Here, the matching criteria used to determine the conditions for success may include, for example, matching hash values, determining whether a predetermined calculation result is within a threshold, or determining whether it matches a predetermined pattern. This allows the conditions for determining success to be flexibly extended according to the characteristics of the processing system.

[0109] Even if multiple conditions for fulfillment are met simultaneously, the point of fulfillment is uniquely determined. The time of determination of the point of fulfillment is recorded as the completion time of the interface for determination processing. Furthermore, the determination of the point of fulfillment does not depend on the evaluation order of the conditions for fulfillment.

[0110] The determination of whether a condition is met is not dependent on the state of an external system or external judgment, but is based on the internal conditions for meeting the condition and whether the confirmation processing interface is executed. This prevents inconsistencies in the determination of the condition being met due to external factors.

[0111] When processing is performed based on the same conditions for achieving a goal, the determination of the final point where the goal is achieved or not achieved will be consistently the same. This prevents different achievement judgments from being made under the same conditions.

[0112] Even when machine learning or inference processing is used to determine whether the conditions for fulfillment are met, the determination of the final point where the conditions are met or not is based on the decisive fact of whether or not processing is performed by the confirmation interface. This prevents the uncertainty of the AI ​​judgment from directly affecting the determination of the points where the conditions are met. Furthermore, the determination of the final point where the conditions are met or not is not changed later by the AI's learning results or model updates.

[0113] <Seventh Embodiment> The information processing system 100 in the seventh embodiment will be described. In this embodiment, distributed arrangement of establishment point control, network separation, and joint operation by multiple entities will be described.

[0114] The quarantine / determination unit 3033, the evidence / recording unit 3034, or parts of these processes do not need to be consolidated on a single computer, but may be distributed across multiple computers, virtual computers, or logically separated processing units. Even in this case, the determination of the final point of success or failure is consistently maintained by chain records.

[0115] The processing system relating to this disclosure may be configured to span multiple network boundaries. Even when spanning network boundaries, the determination of the final point of completion or non-completion is consistently recorded as evidence in a chain.

[0116] The processing system relating to this disclosure may be jointly operated in an environment involving multiple entities. Even in this case, the determination of the final point of completion or non-completion and the chain recording of evidence trails will be performed uniquely. The authority involved in controlling the point of completion and the authority involved in viewing or submitting evidence trails may be separated.

[0117] This disclosure is also applicable to configurations in which some of the conditions for achieving a goal are evaluated in multiple processing units, and when predetermined agreement conditions are met, goal point control is executed. In such configurations as well, the determination result of the goal point or the final point of non-achievement is uniquely documented.

[0118] <Eighth Embodiment> The information processing system 100 in the eighth embodiment will be described. In this embodiment, minimizing the impact on processing performance, resilience to changes in the processing system, and phased implementation will be described.

[0119] Evidence generation and chain recording may be performed as processes independent of the execution of processing by the confirmation processing interface. This allows for the realization of the evidence-gathering function of this disclosure while minimizing the impact on the main processing performance of the processing system.

[0120] Even if the processing system configuration is changed, updated, or expanded, the system can manage the evidence before and after the update by linking it based on the base identification information, location identification information, transit information, and verifiers. This makes it possible to verify past successful or unsuccessful transactions even after the processing system has been changed.

[0121] Even if the processing order changes due to a change in the system configuration, the actual order of execution can be reconstructed later based on the transit information and chain records. This ensures that changes in the processing flow do not affect the validity of the evidence.

[0122] The length of the time window, the frequency of the lottery, or the update cycle of the role assignment may be adjusted according to the load on the processing system, the frequency of requests, or safety requirements. Even if such adjustments are made, the basic structure of this disclosure, which is time-varying role assignment and establishment point control based on time window lottery, will be maintained.

[0123] This disclosure does not need to be implemented across the entire processing system at once, but may be implemented gradually in some processes or functions of the processing system. Even with gradual implementation, the evidentiary function for the point of establishment and the final point of non-establishment will function effectively within the scope of implementation.

[0124] Even if the processing system is stopped or interrupted, if processing by the confirmation processing interface is not executed, the state based on the request will be confirmed as an unfulfilled final state. This prevents irreversible confirmation processing from being mistakenly executed when the system is stopped.

[0125] <Ninth Embodiment> The information processing system 100 in the ninth embodiment will be described. In this embodiment, the clarification of responsibility boundaries and legal supplementation will be described.

[0126] This disclosure does not involve actively intruding into or manipulating external processing systems, terminals, or communication paths. This disclosure determines and records evidence of the final point of completion or non-completion within a processing system under its own control, and does not involve any unauthorized interference with external parties.

[0127] This system provides an evidence structure aimed at verifying the point of completion or the final point of non-completion, and does not automatically determine the appropriateness of the processing content or the correctness of the business judgment. While the judgment of whether or not the processing is appropriate is left to the operational policy, the facts of completion or non-completion and their causal relationships are objectively preserved as evidence.

[0128] Even if evidence or external output data is provided to a third party, this disclosure is intended to document the facts at the point of completion or the final point of non-completion, and does not automatically determine any judgment or liability based on those facts.

[0129] This disclosure does not require integration with external systems, and the points of achievement and the final points of non-achievement can be completed and documented within the processing system under its own control. Even if external integration is performed, such integration will occur after the points of achievement or the final points of non-achievement have been determined, and the success or failure of the integration will not affect the determination of the points of achievement.

[0130] <Other variations> The embodiments described above are merely examples, and this disclosure may be modified as appropriate without departing from its essence. For example, the processes and means described in this disclosure can be freely combined and implemented as long as no technical inconsistencies arise.

[0131] Furthermore, processes described as being performed by a single device may be divided and executed by multiple devices. For example, the quarantine / determination unit 3033 may be formed in a separate processing unit from the server 300. In this case, the separate processing unit is configured to cooperate suitably with the server 300. Also, processes described as being performed by different devices may be executed by a single device. In a computer system, the hardware configuration (server configuration) by which each function is implemented can be flexibly changed.

[0132] The present disclosure can also be realized by supplying a computer program implementing the functions described in the embodiments above to a computer, and having one or more processors in the computer read and execute the program. Such a computer program may be provided to the computer by a non-temporary computer-readable storage medium that can be connected to the computer's system bus, or it may be provided to the computer via a network. Non-temporary computer-readable storage mediums include, for example, any type of disk such as magnetic disks (floppy disks, hard disk drives (HDDs), etc.), optical disks (CD-ROMs, DVDs, Blu-ray discs, etc.), read-only memory (ROM), random access memory (RAM), EPROM, EEPROM, magnetic cards, flash memory, optical cards, and any type of medium suitable for storing electronic instructions.

[0133] In the present invention, the specific methods for generating, determining, or invalidating time window lotteries, time-varying role assignments, short-term first identifiers, or short-term second identifiers are not limited to the examples provided. Such methods are included within the technical scope of this disclosure as long as they have the effect of forming a condition valid only within a time window and expiring after the determination of the point of fulfillment or the final point of non-fulfillment.

[0134] Each term used herein may be replaced by other expressions that are synonymous or have substantially the same function. For example, expressions such as "lottery," "allocation," and "selection" may be used interchangeably as long as they indicate the same function of determining the conditions for success within a time window.

[0135] The embodiments described herein are for the purpose of aiding the understanding of this disclosure and do not limit the technical scope of the inventions described in the claims. Configurations that produce substantially the same effects as those produced by the configurations described in the claims may fall within the technical scope of this disclosure. [Explanation of Symbols]

[0136] 100... Information Processing Systems 200 Network 300 servers 301... Communications Department 302...Storage section 303... Control Unit 400...User terminals

Claims

1. An information processing device that controls whether or not an irreversible definitive process based on an external request can be executed, Receiving the aforementioned request, The input data included in the aforementioned request is divided into item units including address elements, contact elements, date elements, attribute elements, or monetary elements to generate multiple data units, which are input blocks. At each predetermined time window, a lottery based on predetermined decision rules assigns a short-term first identifier role, which serves as the source data for generating a short-term first identifier, to at least a portion of the input blocks, the first block. For each of the aforementioned time windows, a lottery based on the aforementioned decision rule assigns a role to a second block, which is at least a part of the input block and different from the first block, to serve as the source data for generating the second short-term identifier, and Based on the assignment results of the short-term first identifier role and the short-term second identifier role, the short-term first identifier and the short-term second identifier are generated. Within the aforementioned time window, it is determined whether the combination of the short-term first identifier and the short-term second identifier satisfies the conditions for the irreversible determination process to be completed. If the aforementioned conditions for fulfillment are met, the processing by the confirmation processing interface for executing the irreversible confirmation process is executed, and the execution state of the irreversible confirmation process is confirmed as the point at which the execution of the processing by the confirmation processing interface is completed. If the aforementioned conditions for fulfillment are not met, the execution state of the irreversible finalization process is determined to be the final point of non-fulfillment, where the process by the finalization interface is not executed. An evidence trail is generated by associating the confirmed state at the point of completion or the final point of non-completion for the irreversible confirmation process, location identification information identifying the location from which the request originated, location identification information identifying a section, device, or service within the location, transit information indicating the processing path taken from the receipt of the request to the confirmation of the state of the irreversible confirmation process, and time information, and the sequence of events of the evidence trail is recorded as a verifiable chain. The system automatically generates external output data based on the aforementioned evidence, It includes a control unit that performs the following: The control unit, The short-term first identifier and the short-term second identifier are invalidated upon the passage of the time window, or upon determination of the state based on the established point or the final unestablished point for the irreversible determination process. Information processing device.

2. The confirmation processing interface is characterized by including at least one of a software API, a control interface, a control signal, an open / close signal, or an actuator command, and by including a function for irreversibly determining the state of the device or processing system. The information processing apparatus according to claim 1.

3. The control unit, The fact that the processing by the aforementioned confirmation processing interface was not executed is maintained in causal association with the transit information and the time information, and the state of the irreversible confirmation processing is such that a third party can verify that it is the final point of non-completion. The information processing apparatus according to claim 1.

4. The control unit, Each time the time window is updated, the assignment of the short-term first identifier role and the short-term second identifier role is re-drawn, and when the time window is updated, the short-term first identifier and the short-term second identifier that were generated before the time window was updated are further invalidated. The information processing apparatus according to claim 1.

5. The control unit, Furthermore, the assignment of the short-term first identifier role and the short-term second identifier role is restricted so that the same input block does not play the same role in consecutive time windows before and after the update of the time window. The information processing apparatus according to claim 4.

6. The aforementioned conditions for fulfillment are determined not by a permanently stored fixed identifier or fixed password, but by a combination of the short-term first identifier and the short-term second identifier. The information processing apparatus according to claim 1.

7. At least a portion of the input block, the short-term first identifier, and the short-term second identifier are obtained by user input, and are invalidated after the execution state of the irreversible confirmation process is determined as the fulfillment point or the final unfulfilled point. The information processing apparatus according to claim 1.

8. Even when a fixed identifier or fixed password information is entered by the user for compatibility with existing systems, the execution of the processing by the confirmation processing interface is determined by the conditions for success based on the short-term first identifier and the short-term second identifier. The information processing apparatus according to claim 1.

9. The control unit, The request is transferred to an isolated environment separated from the execution environment for the irreversible final processing, and a predetermined inspection process is performed in the isolated environment. The information processing apparatus according to claim 1.

10. The control unit, Further, the system generates a qualifier that does not contain information that directly identifies the user, and includes it in the external output data. The information processing apparatus according to claim 1.

11. The aforementioned verifier is characterized by being generated including the time information or the location identification information. The information processing apparatus according to claim 10.

12. The aforementioned external output data is characterized by including a summary section and an evidence section. The information processing apparatus according to claim 1.

13. The control unit, The granularity of the base identification information, location identification information, or transit information included in the summarization unit is further changed in stages depending on the output destination of the external output data. The information processing apparatus according to claim 12.

14. The information particle size stage is characterized by including at least coarse particle size, medium particle size, and fine particle size. The information processing apparatus according to claim 13.

15. The control unit, Further, the system identifies correlations between multiple requests based on the aforementioned matcher or request feature information representing the characteristics of the request. The information processing apparatus according to claim 10.

16. The aforementioned requirement feature information is characterized by including at least one of the repeatability, order, formal deviation, and anomalous parameter features of the requirement. The information processing apparatus according to claim 15.

17. The control unit, A notification is given in accordance with the identification result of the correlation, and the notification includes information regarding the execution status of the irreversible final processing, but does not include personal information. The information processing apparatus according to claim 15.

18. The aforementioned base identification information and the aforementioned location identification information are characterized by being represented hierarchically. The information processing apparatus according to claim 1.

19. The aforementioned routing information is characterized by including at least one of the call sequence and processing path identifier of the internal application programming interface. The information processing apparatus according to claim 1.

20. The control unit, The completion of the processing by the aforementioned confirmation processing interface confirms that the irreversible confirmation process has been executed. The information processing apparatus according to claim 1.

21. The control unit, If neither the short-term first identifier role nor the short-term second identifier role is assigned within the aforementioned time window, and the conditions for fulfillment are not met, the execution state of the irreversible confirmation process is determined as the final point of non-fulfillment. The information processing apparatus according to claim 1.

22. An information processing method executed by an information processing device that controls whether or not an irreversible definitive processing based on an external request can be performed, The control unit of the information processing device, The step of receiving the aforementioned request, The steps include: dividing the input data included in the request into item units including address elements, contact elements, date elements, attribute elements, or monetary elements to generate input blocks which are multiple data units; The steps include: assigning a short-term first identifier role, which serves as source data for generating a short-term first identifier, to at least a portion of the input blocks by lottery based on predetermined decision rules for each predetermined time window; For each of the aforementioned time windows, the step of assigning a short-term second identifier role, which serves as the source data for generating a short-term second identifier, to a second block that is at least a part of the input block and different from the first block, by lottery based on the decision rule, The steps include generating the first short-term identifier and the second short-term identifier based on the assignment results of the first short-term identifier role and the second short-term identifier role, Within the aforementioned time window, a step of determining whether the combination of the short-term first identifier and the short-term second identifier satisfies the conditions for the irreversible determination process to be completed, If the aforementioned conditions for fulfillment are met, the process is executed by the confirmation processing interface for executing the irreversible confirmation process, and the execution state of the irreversible confirmation process is confirmed as the point at which the execution of the process by the confirmation processing interface is completed. If the aforementioned conditions for fulfillment are not met, the execution state of the irreversible finalization process is determined to be an unfulfilled final point where the process by the finalization process interface is not executed. A step of generating evidence by associating the confirmed state at the point of completion or the final point of non-completion for the irreversible confirmation process, location identification information identifying the location from which the request originated, location identification information identifying a section, device, or service within the location, transit information indicating the processing path taken from the receipt of the request to the confirmation of the state of the irreversible confirmation process, and time information, and recording the evidence as a chain in which the sequence of events can be verified, The steps include: automatically generating external output data based on the aforementioned evidence; Execute, The control unit performs the action of invalidating the short-term first identifier and the short-term second identifier upon the elapsed time window or upon determination of the state based on the established point or the final unestablished point for the irreversible determination process. Information processing methods.

23. An information processing program executed by an information processing device that controls whether or not an irreversible definitive processing based on an external request can be performed, The control unit of the aforementioned information processing device, The step of receiving the aforementioned request, The steps include: dividing the input data included in the request into item units including address elements, contact elements, date elements, attribute elements, or monetary elements to generate input blocks which are multiple data units; The steps include: assigning a short-term first identifier role, which serves as source data for generating a short-term first identifier, to at least a portion of the input blocks by lottery based on predetermined decision rules for each predetermined time window; For each of the aforementioned time windows, the step of assigning a short-term second identifier role, which serves as the source data for generating a short-term second identifier, to a second block that is at least a part of the input block and different from the first block, by lottery based on the decision rule, The steps include generating the first short-term identifier and the second short-term identifier based on the assignment results of the first short-term identifier role and the second short-term identifier role, Within the aforementioned time window, a step of determining whether the combination of the short-term first identifier and the short-term second identifier satisfies the conditions for the irreversible determination process to be completed, If the aforementioned conditions for fulfillment are met, the process is executed by the confirmation processing interface for executing the irreversible confirmation process, and the execution state of the irreversible confirmation process is confirmed as the point at which the execution of the process by the confirmation processing interface is completed. If the aforementioned conditions for fulfillment are not met, the execution state of the irreversible finalization process is determined to be an unfulfilled final point where the process by the finalization process interface is not executed. A step of generating evidence by associating the confirmed state at the point of completion or the final point of non-completion for the irreversible confirmation process, location identification information identifying the location from which the request originated, location identification information identifying a section, device, or service within the location, transit information indicating the processing path taken from the receipt of the request to the confirmation of the state of the irreversible confirmation process, and time information, and recording the evidence as a chain in which the sequence of events can be verified, The steps include: automatically generating external output data based on the aforementioned evidence; Make it run, The control unit is instructed to invalidate the short-term first identifier and the short-term second identifier upon the passage of the time window, or upon determination of the state based on the established point or the final unestablished point for the irreversible determination process. Information processing program.

24. An information processing system comprising an information processing device according to any one of claims 1 to 21.