Confidential information processing device, method for operating same, and data transmission / reception system

JPWO2024070153A5Pending Publication Date: 2025-06-06
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024549778
Authority / Receiving Office
JP · JP
Patent Type
Applications
Filing Date
2025-02-21
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

In consortium-type blockchain networks, the lack of uniform IT literacy among node administrators and the absence of a centralized management organization pose challenges in maintaining system integrity and security, particularly when failures occur, as sensitive information may be inadvertently leaked during log data transmission and analysis.

Method used

A confidential information processing device and method that detects and converts sensitive information in log data using specific character recognition and conversion processes, ensuring that only non-identifiable information is transmitted across the network for system maintenance, thereby preventing information leakage.

Benefits of technology

Enables secure system maintenance across organizations by identifying and converting sensitive information in log data, ensuring that only necessary information is shared, thus maintaining the integrity and reliability of blockchain nodes.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

Provided are: a confidential information processing device with which it is possible, while preventing leakage of sensitive information in a blockchain, to perform system maintenance extending across organizations; a method for operating said confidential information processing device; and a data transmission / reception system. A confidential information processing device (13) according to the present invention comprises a processor, the processor: acquiring log data that propagates between devices constituting a blockchain network; identifying a character string of log data; setting, to a marker, a specific character that is based on a preliminary setting; detecting, from the log data, a character string of log data as sensitive information on the basis of the specific character; and performing a conversion process to convert the character string of sensitive information to a different character or a signal.
Need to check novelty before this filing date? Find Prior Art

Description

Confidential information processing device, its operating method, and data transmission / reception system

[0001] The present invention relates to a confidential information processing device, an operating method thereof, and a data transmission / reception system.

[0002] In a blockchain network, there is no central administrator, and each node has independent authority and constitutes the network. In addition, when transmitting log data to the network, personal information and confidential information must be protected.

[0003] Patent Document 1 describes how the contents of the encrypted portions of a source program are protected so that they are difficult to guess, and Patent Document 2 describes how, when medical data is shared between hospitals using a P2P database, personal information is identified using a classifier, and the personal information is depersonalized before being transmitted.

[0004] JP 2019-53146 A International Publication No. 2019 / 244949

[0005] On the other hand, especially in consortium-type blockchain networks spanning multiple industries, it is rare for the administrators of each node to have the same level of IT (information technology) literacy, and there is often an organization that effectively manages the entire network. However, even in such cases, each node has independent authority, so the management organization cannot directly handle issues or feature updates.

[0006] To recover from a failure, the management organization can request log data from the network's constituent organizations, analyze it, and troubleshoot the problem, but there is a risk that the log data may contain sensitive information such as key information, passwords, and raw data.If sensitive information is included in the log data, it could be leaked to the network's constituent organizations, which could lead to a decrease in the tamper-resistance of the node and a loss of reliability.On the other hand, if data containing sensitive information is not uploaded, system maintenance such as recovery work cannot be performed if a problem occurs with the log data storage.

[0007] The present invention aims to provide a confidential information processing device that enables system maintenance across organizations while preventing the leakage of sensitive information in a blockchain, a method for operating the same, and a data transmission and reception system.

[0008] The confidential information processing device of the present invention is equipped with a processor, which acquires log data to be transmitted between devices that make up a blockchain network, discriminates character strings in the log data, sets specific characters based on pre-settings as markers, detects the character strings in the log data as sensitive information based on the specific characters in the log data, and performs a conversion process to convert the character strings of sensitive information into different characters or symbols.

[0009] In the log data, it is preferable to detect character strings containing specific characters as sensitive information.

[0010] In the log data, it is preferable to detect a character string sandwiched between specific characters or character strings containing specific characters as sensitive information.

[0011] It is preferable to use a dictionary function to distinguish character strings in the log data, and to detect character strings that cannot be distinguished based on the dictionary function as sensitive information.

[0012] It is preferable to detect, as sensitive information, a character string that is sandwiched between character strings that could not be determined based on the dictionary function.

[0013] It is preferable to determine the character string after conversion processing depending on the type of sensitive information.

[0014] In the presetting, it is preferable to apply a rule listing specific characters, a rule classifying the type of sensitive information, and a rule determining the conversion range to the conversion process.

[0015] In the presetting, it is preferable to apply statistical data of past conversion processes on sensitive information to the conversion process.

[0016] It is preferable to transmit the converted log data to another device that constitutes the blockchain network, and obtain feedback data containing the analysis results of the converted log data from the other device.

[0017] In the pre-setting, it is preferable to accept updates of the detection target of sensitive information based on the analysis result.

[0018] It is preferable to perform conversion processing and transmission for each line of log data in response to a command operation by another device that constitutes the blockchain network.

[0019] When performing conversion processing in response to a command operation, it is preferable to determine prohibited operations, including operations for obtaining sensitive information by another device.

[0020] The prohibited operations preferably include any of the operations of viewing, creating, editing, and deleting directories that are not related to system maintenance, in addition to editing and deleting character strings in the log data.

[0021] It is preferable that the data transmission / reception system has a confidential information processing device.

[0022] The method of operating the confidential information processing device of the present invention includes the steps of acquiring log data to be transmitted between devices constituting a blockchain network, determining a character string in the log data, setting a specific character based on a pre-setting as a marker, detecting the character string in the log data as sensitive information based on the specific character in the log data, and performing a conversion process to convert the character string of the sensitive information into a different character or symbol.

[0023] According to the present invention, system maintenance across organizations becomes possible while preventing the leakage of sensitive information in the blockchain.

[0024] FIG. 1 is a schematic diagram of a data transmission and reception system. FIG. 1 is a block diagram showing the functions of devices constituting a node 11 and a confidential information processing device. FIG. 2 is a block diagram showing the functions of a sensitive information detection unit in the confidential information processing device. FIG. 3 is an explanatory diagram showing log data exchange between two organizations. FIG. 4 is an explanatory diagram showing a case where log data is automatically transmitted. FIG. 5 is a flowchart showing a series of flows for log data conversion processing and transmission. FIG. 6 is an explanatory diagram showing a case where log data is transmitted by a command operation in a second embodiment.

[0025] [First Embodiment] As shown in Fig. 1, a data transmission and reception system 10 is a blockchain network configured by a plurality of nodes 11, and each node 11 is managed by a constituent organization with independent authority. The node 11 includes a device 12 and a confidential information processing device 13. The device 12 is an information processing terminal equipped with a storage medium and a processor and capable of transmitting and receiving information, and stores ledger data including log data using the blockchain network. When the device 12 transmits information such as log data to another node 11, the confidential information processing device 13 detects sensitive information such as key information, passwords, and raw data and performs conversion processing.

[0026] The log data may be received by the device 12, while the log data may be transmitted from the confidential information processing device 13 that performed the conversion process, or the confidential information processing device may transmit the converted log data via the device 12 that constitutes the same node 11. The functions of the device 12 and the confidential information processing device 13 may be realized by a single device, that is, the confidential information processing device.

[0027] The blockchain network is, for example, a consortium type in which a limited number of companies participate. In this case, the participating companies may be from different industries. Node 11 handles all of its own organization's log data in order to automatically or manually transmit log data used for recovery in the event of a system failure. Normal transmission and reception of log data to node 11 of another organization is performed automatically, but can also be performed manually when recovering from a system failure.

[0028] Furthermore, when the converted log data is received, the receiving organization can use the device 12 to analyze it and obtain the analysis result of the conversion processing status of the log data for sensitive information. The analysis result can also be sent as feedback data to the device 12 of the sending organization. The device 12 that receives the feedback data may reflect the feedback data in the confidential information processing device 13 belonging to the same organization.

[0029] The format of the log data may differ for each node 11, and it is preferable that the confidential information processing device 13 or the program that realizes the functions of the confidential information processing device 13 that each node 11 has be compatible with each other.

[0030] A node 11 constituting the data transmission / reception system 10 with another organization includes a device 12 and a confidential information processing device 13. The device 12 and the confidential information processing device 13 are connected, and when the device 12 transmits information such as log data to another organization in the data transmission / reception system 10, the information is transmitted via the confidential information processing device 13.

[0031] 2, the device 12 realizes the functions of a receiving unit 20, an analyzing unit 21, a saving unit 22, an output unit 23, and an input accepting unit 24. The confidential information processing device 13 realizes the functions of a data acquiring unit 30, a sensitive information detecting unit 31, a conversion processing unit 32, a data output unit 33, and an input accepting unit 34. The device 12 and the confidential information processing device 13 are computers such as personal computers or workstations on which application programs for realizing predetermined functions are installed. The computers are equipped with a processor such as a CPU (Central Processing Unit), memory, storage, etc., and realize various functions using programs, etc., stored in the storage.

[0032] The receiving unit 20 acquires log data received from a node 11 of another organization and log data of related devices of its own organization. The log data acquired from a node 11 of another organization is sent to the analyzing unit, and the log data of its own organization is sent to the storing unit. It also accepts instructions to output log data.

[0033] The analysis unit 21 analyzes the log data received from another organization and determines the information and type of information contained in the log data. It is also preferable to determine whether conversion processing has been performed and the converted parts so that they can be searched for, for example, by tagging them. The analysis results may be output in text format, for example. The conversion processing will be described later. After analysis and tagging, the log data is sent to the storage unit. The analysis results of the log data from another organization are sent to the source node as feedback data.

[0034] The storage unit 22 stores log data related information such as the log data of the organization itself and other organizations, and the analysis results created by the analysis unit. The log data of the organization itself is transmitted to and shared with the node 11 of the other organization in the blockchain network unless otherwise specified. The log data of the other organization is output during system maintenance.

[0035] The output unit 23 outputs the log data of its own organization or another organization in response to the log data output instruction. When outputting the log data of its own organization, it transmits it to the confidential information processing device 13, and when outputting the log data or feedback data of another organization, it transmits it to the source node 11.

[0036] The input receiving unit 24 can receive input from a user such as an administrator of the organization to which the node 11 belongs via a user interface (UI) or the like. The input is performed via a user interface (not shown) such as a mouse operation or a keyboard operation. The input includes instructions regarding the output of log data and instructions for controlling the confidential information processing device 13.

[0037] The specific functions of the data acquisition unit 30, sensitive information detection unit 31, conversion processing unit 32, data output unit 33, and input reception unit 34 included in the confidential information processing device 13 will be described below.

[0038] The data acquisition unit 30 acquires log data to be transmitted to the node 11 of another organization from the device 12. The acquired log data is all log data to be transmitted, and is sent to the sensitive information detection unit 31.

[0039] The sensitive information detection unit 31 detects sensitive information contained in the log data, classifies the type of sensitive information, and determines the range of character strings to be converted by the conversion processing unit 32. Based on the contents of the pre-settings, character strings containing specific characters and character strings sandwiched between specific characters or character strings containing specific characters are detected as sensitive information from the log data.

[0040] The conversion processing unit 32 performs a conversion process on the log data for a conversion range determined in accordance with a preset setting. The conversion process changes the character string in the conversion range in the log data so that the original character string, which is sensitive information, cannot be identified, while the converted character string is data used for recovery in the event of a system failure, etc., so that the type of sensitive information can be identified from the converted character string. Therefore, the characters, character strings, or symbols converted by the conversion process are determined depending on the type of sensitive information. The conversion process also includes a masking process that masks the characters in the conversion range by blacking them out, etc.

[0041] For example, a string detected as sensitive information is converted into a hash value using a hash function, and a string that can identify only the type of sensitive information is added before and after the hash value. Alternatively, each type of sensitive information is converted into a specific string. The converted string may have a pattern that repeats the same characters or characters, such as "AAAA" or "ABAB." Furthermore, to make the type of converted string easily identifiable, it may be converted into a string such as "--PASSWORD--" or "--PRIVATE_KEY--." By using a conversion process that can identify the type of sensitive information, organizations that receive the converted log data (converted log data) can retain the minimum information necessary for system maintenance, such as the type of sensitive information, while preventing the viewing of confidential information and personal information.

[0042] The data output unit 33 outputs the converted log data, in which the sensitive information has been converted by the conversion process, from the confidential information processing device 13 to the node 11 of the other organization.

[0043] The input receiving unit 34 receives instructions from administrators of each organization and input of feedback data, which will be described later.

[0044] In normal operation, various data is accumulated in the nodes 11 managed by each organization. When participating in a blockchain network, log data and other data are exchanged and stored with each other. At that time, a conversion process is performed to convert sensitive information, and the receiving side receives and stores the converted log data.

[0045] As shown in Figure 3, the sensitive information detection unit 31 has a preset management unit 40 which further has the functions of a preset storage unit 41 and a preset update unit 42, a specific character recognition unit 43, a character string discrimination unit 44, a sensitive information classification unit 45, and a conversion range determination unit 46, and the specific functions are described below.

[0046] The preset management unit 40 manages presets, which are pre-defined rules for detecting sensitive information, classifying the types of sensitive information, and the range of conversion. Each rule is updated using statistical data in addition to the pre-defined rules. The presets are stored in the preset storage unit 41, and are updated by manual settings by an administrator via the preset update unit 42 or by receiving feedback data.

[0047] The pre-settings applied to the detection and conversion of sensitive information include at least a rule listing specific characters that serve as markers for detecting sensitive information, a rule for classifying the type of sensitive information according to the determined character string, and a rule for determining the conversion range according to the type of sensitive information. In addition, statistical data of past conversion processes for sensitive information is also used in the pre-settings. Rules for performing conversion processes according to the type of sensitive information may also be set.

[0048] The preset storage unit 41 has a function of writing and reading from a storage area and stores presets. The stored presets are referenced when detecting and classifying sensitive information, and when determining the conversion range and conversion processing method. The presets are also referenced from the storage area when updating the contents of the presets via the preset update unit 42.

[0049] The preset update unit 42 updates the presets based on user operations or received feedback data. The update involves adding or changing rules and statistical data, and the updated content is stored in the preset storage unit 41. The updated presets are used for future sensitive information detection. The update operation is performed, for example, to change or add rules for character strings that would be undetected or erroneously detected by the dictionary function or natural language processing described below, thereby enabling more accurate conversion processing of sensitive information. When automatically updating the presets, it is preferable to use statistical data that includes multiple examples, rather than a single example of undetection or erroneous detection.

[0050] The statistical data used for pre-settings is the relationship between the information before and after the conversion and the string of sensitive information, which is difficult to set using rules but is often used. By using sensitive information statistical data and individual definitions, it is possible to prevent sensitive information from being overlooked.

[0051] The specific character recognition unit 43 recognizes specific characters that are likely to be sensitive information based on a preset setting. The specific characters are single characters or multiple characters used in a fixed combination, and are used to determine whether or not the information is sensitive. The recognized specific characters are tagged, etc.

[0052] Specific characters are characters or symbols used in specific expressions, such as the at sign (@), colon (:), hyphen (-), and period (.). In addition, a specific character may not be a single character, but a combination of multiple characters that exist in a specific order within a certain range. For example, curly brackets ({}) and quotation marks ("") are symbols that enclose characters or strings of characters.

[0053] The character string discrimination unit 44 discriminates character strings such as words from the acquired log data. Specifically, it uses a dictionary function registered in advance for the log data and performs named entity extraction using natural language processing to discriminate the log data for names, numbers, or character strings with some meaning. As a result, the log data is divided into discriminated character strings and undiscriminated character strings.

[0054] Character strings that can be identified using the dictionary function are character strings that have some meaning, such as words, and the dictionary function may be used to classify the character strings according to their meanings. In particular, these are expressions of time, expressions of monetary amounts, telephone numbers, and proper nouns such as people's names and place names, and proper nouns are particularly likely to be sensitive information.

[0055] Character strings that cannot be identified using the dictionary function, especially those with a large number of digits, may be passwords or private keys. Therefore, character strings with a certain number of characters or more, for example, eight characters or more, that cannot be identified using the dictionary function are detected as sensitive information. Meanwhile, passwords or private keys with particularly many characters may contain words if they were manually entered by someone with low IT literacy or by chance. Therefore, even if a word is detected in a character string, if a certain percentage, for example, more than half, of the characters cannot be identified using the dictionary function, the character string is detected as sensitive information.

[0056] By presetting the system, it can identify combinations of character strings and character strings that contain specific characters that are likely to contain sensitive information within a certain range. For example, it can identify "http: / / " or "https: / / " that indicate a uniform resource locator (URL), company names such as "Ltd.", "Corp.", and "Inc.", and honorifics such as "Mr.", "Ms.", and "Mrs.". It can also identify character strings that combine characters or words, such as "-----BEGIN PRIVATE KEY-----" and "-----END PRIVATE KEY-----," which indicate the start and end of a private key.

[0057] Natural language processing, for example, performs character string discrimination processing on log data using previously learned content. The character string discrimination unit 44 has the function of a trained model required for the character string discrimination processing. In other words, the character string discrimination unit 44 is a computer algorithm consisting of a neural network that performs machine learning, and determines whether or not meaningful character strings exist in the input log data according to the learned content, and if meaningful character strings exist, performs specific inference regarding the type of character string, and obtains a discrimination result. The discrimination result obtains information such as the determined meaningful character string, its type, and its position in the log data. The discrimination result is used to detect sensitive information.

[0058] The sensitive information classification unit 45 detects sensitive information and classifies the type of sensitive information from the specific characters or character strings set as markers by the specific character recognition unit 43 and the character string determination unit 44. The sensitive information is determined by referring to the preset settings stored in the preset storage unit 41.

[0059] A proper noun consisting of multiple words may be considered sensitive information, along with a string containing specific characters and the string immediately preceding or following it. Therefore, when a string containing specific characters is detected based on a predefined rule, a certain range of characters is detected as sensitive information. For example, the strings "Ltd.," "Corp.," and "Inc." used in company names are detected as sensitive information, along with the string immediately preceding them, while the strings "Mr.," "Ms.," and "Mrs." are detected as sensitive information, along with the string immediately following them. Because proper nouns in log data rarely continue across line breaks, the range of characters detected along with a string containing specific characters is limited to the same line, i.e., up to the line break. Natural language processing and named entity extraction are preferably used to determine the extent of the string immediately preceding or following the string to be detected as sensitive information. Meanwhile, long proper nouns frequently used by organizations are preferably added to the predefined settings as sensitive information.

[0060] The conversion range determination unit 46 determines the range in which conversion processing for each piece of sensitive information is performed, depending on the type of sensitive information classified by the sensitive information classification unit. The determined conversion range information is linked to each piece of log data and transmitted to the conversion processing unit 32. Based on pre-settings, the specific characters recognized by the specific character recognition unit 43 and the character strings determined by the character string determination unit 44 are set as markers, and the range of character strings in the log data in which conversion processing is performed is determined. The determination of the range in which conversion processing is performed corresponds to the detection of sensitive information. The range in which conversion processing is performed varies depending on the classification results by the sensitive information classification unit 45. The log data in which the range in which conversion processing is performed is determined to be sensitive information and has parts detected as sensitive information is transmitted to the conversion processing unit 32.

[0061] The detection of sensitive information, such as a user ID and password used for basic authentication, will be described. For example, if a user ID and password pair is output to log data in the format "https: / / userid:password@example.com," the specific character recognition unit 43 recognizes a colon (:) and an at sign (@), and the character string discrimination unit 44 discriminates the character string "https: / / ." The sensitive information classification unit 45 detects the area between "https: / / " and "@" on a single line, without spaces or line breaks, as sensitive information and classifies the type as a "pair of ID and password." Furthermore, the colon (:) within the enclosed area may be used as a starting point to further classify the first half as a "user ID" and the second half as a "password." In this case, the reliability of the sensitive information is higher than that of a "pair of ID and password." The conversion range determination unit 46 considers the entire range classified as a "pair of ID and password" as a conversion range, and if the range is divided into "user ID" and "password," each is considered a separate conversion range.

[0062] The detection of sensitive information, which is a private key, will be described. For example, if the character strings "-----BEGIN PRIVATE KEY-----" and "-----END PRIVATE KEY-----" are output as private key log data, the specific character recognition unit 43 recognizes a hyphen (-), and the character string discrimination unit 44 discriminates the character strings "BEGIN PRIVATE KEY" and "END PRIVATE KEY". The sensitive information classification unit 45 detects the area between "-----BEGIN PRIVATE KEY-----" and "-----END PRIVATE KEY-----" as sensitive information and classifies the type as "private key". The enclosed area may contain spaces or line breaks. In other words, this indicates that "-----BEGIN PRIVATE KEY-----" immediately precedes the "private key" and "-----END PRIVATE KEY-----" immediately follows the "private key". The conversion range determination unit 46 considers the entire range classified as "private key" to be the conversion range.

[0063] The information to be converted may be information that is not normally treated as log data, may not be written to the blockchain, and may not be necessary for recovery in the event of a failure. For example, documents in XML, JSON, and YAML formats may be converted as sensitive information.

[0064] The detection of documents in XML, JSON, and YAML formats will be described. Document format detection involves first detecting a character string representing a start point and a character string representing an end point, as defined in the rules for each document format, from character strings included in log data, and estimating the corresponding document format. Next, the area between the start point and the end point is determined to be a valid character string for each estimated document format, thereby detecting whether the character string between the start point and the end point is sensitive information. Character string rules corresponding to each document format are stored in advance as presets.

[0065] In the case of XML format, the specific character recognition unit 43 and the string determination unit 44 identify "<xxx>" and "< / xxx>" when any alphanumeric character is represented by x. The sensitive information classification unit 45 detects the entire area between "<xxx>" at the start of the document and "< / xxx>" at the end of the document as sensitive information, and estimates the type as an "XML format document." After estimation, it determines whether the enclosed area is valid as a pre-registered XML format. If it is determined to be valid, it is classified as an "XML document" in sensitive information. If it is determined to be invalid, it detects and classifies whether it is a different type of sensitive information.

[0066] In the case of the JSON format, the specific character recognition unit 43 recognizes an opening curly brace ({) and a closing curly brace (}). The sensitive information classification unit 45 detects the entire area enclosed by the opening curly brace ({) at the beginning of any line of the log data and the closing curly brace (}) at the end of any line after the line containing the opening curly brace ({) as sensitive information, and estimates the type as a "JSON format document." After estimation, it determines whether the enclosed area is valid as a pre-registered JSON format. If it is determined to be valid, it is classified as a "JSON document" in sensitive information. If it is determined to be invalid, it detects and classifies whether it is a different type of sensitive information.

[0067] In the case of the YAML format, the specific character recognition unit 43 recognizes a colon (:). If an arbitrary character is designated as y, the sensitive information classification unit 45 recognizes the area beginning with "yyy:" followed by zero or more spaces or tabs at the beginning of any line of the log data as sensitive information, and detects the area up to the area valid in the YAML format as sensitive information, and classifies it as a "YAML document."

[0068] 4, the following describes the transmission of log data between a node 11a managed by organization A and a node 11b managed by organization B among multiple nodes constituting a data transmission / reception system 10 such as a blockchain network. The node 11a is equipped with a device 12a and a confidential information processing device 13a, and the node 11b is equipped with a device 12b and a confidential information processing device 13b. Before outputting the log data in the node 11a, the log data held by the device 12a is transmitted to the confidential information processing device 13a.

[0069] The confidential information processing device 13a performs sensitive information detection and conversion processing on the acquired log data based on preset settings. The specific character recognition unit 43 recognizes specific characters that serve as markers of sensitive information based on preset settings. The character string discrimination unit 44 discriminates character strings that serve as markers of sensitive information, including specific characters. The sensitive information classification unit 45 detects character strings within a certain range from the character or character string set as the marker as sensitive information and identifies the type of sensitive information. The conversion range determination unit 46 determines the range of conversion processing to convert each type into a different character string. The conversion processing unit 32 performs conversion processing on the log data for the determined range and converts it into converted log data.

[0070] The node 11a transmits the converted log data to the device 12b in the node 11b. The device 12b analyzes the acquired converted log data and stores it together with the analysis results. The log data that the confidential information processing device 13a converts is all of the log data that is transmitted from the node 11a to the node 11b, but it is preferable to perform the conversion process on each line of the log data.

[0071] The receiving device 12b, to which the converted log data has been transmitted, analyzes the converted log data. The device analyzes the information contained in the acquired converted log data. For example, natural language processing is performed on the unconverted portion of the log data to extract meaningful character strings. The extracted character strings are used to obtain the nature, type, and information contained in the log data as analysis results. If there is a converted portion, any data obtained from the converted character strings is also used in the analysis. It is preferable to include unconverted character strings that are likely to contain sensitive information as omitted data in the feedback data. The type of log data containing the converted sensitive information is determined. For example, this may include user IDs and passwords, private keys, documents, contact information, etc. The node 11a acquires feedback data containing the analysis results of the converted log data from the receiving node 11b. The node 11a references the analysis results contained in the acquired feedback data, and if there are any deficiencies, such as omitted conversion of sensitive information, the node 11a accepts an update to the pre-defined sensitive information detection targets based on the analysis results.

[0072] Similarly, in node 11b, log data output by device 12b is converted by confidential information processing device 13b into converted log data and transmitted to node 11a. Data exchange is performed between the respective nodes 11 constituting data transmission / reception system 10. Note that log data exchange during normal operation is performed automatically.

[0073] Next, we will explain the operation when a system failure occurs in the data transmission and reception system 10 and recovery is performed. To investigate the cause of the system failure and recover, converted log data is transmitted from at least one of the nodes 11, and the node 11 that receives the converted log data analyzes the converted log data and provides feedback using the analysis results. Log data transmission and feedback for investigating the cause of the system failure may be performed randomly between the nodes 11, or may be performed between specific nodes 11 by narrowing down candidate nodes 11 that are likely to be able to identify the cause. If the feedback produces results that lead to cause investigation, recovery work is performed based on those results. If no results that lead to cause investigation are obtained, data exchange is repeated.

[0074] The analysis result is sent to node 11a as feedback indicating whether the analysis was performed normally, whether there were any unnatural analysis results, or the results of a comparison between the analyzed converted log data and the same analysis content saved during normal operation. The transmitted log data is the entire log data of node 11a. Node 11a responds to the system failure based on the received feedback.

[0075] A series of operations for log exchange by the confidential information processing device 13 of this embodiment will be described with reference to the flowchart shown in FIG. 6. The confidential information processing device 13 acquires log data transmitted from devices 12 belonging to the same node 11 among devices constituting the blockchain network (step ST110). From the acquired log data, specific characters that serve as markers of sensitive information are recognized based on pre-settings (step ST120). Furthermore, from the acquired log data, character strings that serve as markers of sensitive information are determined based on pre-settings (step ST130). Character strings within a certain range from the character or character strings set as markers are detected as sensitive information, and the type of sensitive information is classified (step ST140). A conversion process is performed to convert the detected sensitive information into different character strings for each type (step ST150). The node 11 transmits the converted log data to another organization (step ST160).

[0076] The other organization to which the log data is transmitted analyzes the converted log data. Node 11 acquires feedback data including the analysis results (step ST170). If the analysis results of the feedback data indicate a defect in the conversion process for sensitive information (Y in step ST180), the node updates the pre-settings to resolve the defect in the conversion process and terminates the transmission of the log data (step ST190). If the feedback does not identify any defect in the conversion process (Y in step ST180), the node does not change the pre-settings and terminates the transmission of the log data.

[0077] As described above, by detecting sensitive information in log data and performing conversion processing, log data can be exchanged between organizations while preventing leakage of sensitive information.

[0078] [Second Embodiment] In the second embodiment, instead of the data output instruction by the administrator of the sending organization in the first embodiment, the transmission of log data is executed by a command operation by the administrator of the receiving organization, etc. The command operation may be issued by operating the device 12, or may be issued by operating the confidential information processing device 13 that also has the functions of the device 12. The rest is the same as in the first embodiment.

[0079] For example, if a problem such as a system failure occurs in organization A, log data is transmitted between organization A and organization B for system maintenance to investigate the cause and recover. The administrator of organization B recognizes the notification of an abnormality in its own organization by the administrator Ha of organization A and the warning message issued from node 11a, and performs command operations such as an instruction to provide data from organization B to node 11a of organization A.

[0080] As shown in Figure 7, when acquiring log data from organization A, the administrator Hb of organization B transmits a command to node 11a by command operation. In response to the command, node 11a transmits log data converted by the confidential information processing device 13a to another organization, organization B. It is preferable that device 12b, which receives the converted log data, performs an analysis process and provides feedback on the analysis results of the log data. Administrator Ha refers to the feedback of the analysis results acquired by device 12a of node 11a. Note that administrator Hb of organization B, who is involved in investigating the cause of and recovering from a system failure, is, for example, the actual administrator of the entire data transmission / reception system 10.

[0081] When organization B, which is the recipient of the log data, acquires the log data by command operation, an administrator Hb of organization B performs a command operation to cause device 12b to output a command requesting log data from organization A. The command issued from device 12b in node 11b is transmitted to device 12a storing the log data via confidential information processing device 13a in node 11 of organization A. Because organization B indirectly accesses device 12a of organization A through command operation and commands, confidential information processing device 13a limits the commands it accepts.

[0082] The specific command contains information such as the amount of log data required and the destination of the log data, and includes only the minimum instructions necessary to transmit the log data. The confidential information processing device 13a, which accepts commands from organization B, determines operations that are unrelated or only slightly related to log data acquisition or system maintenance as prohibited operations and does not accept them from nodes 11 belonging to a different organization. Specifically, only commands highly related to log data acquisition are allowed to be input, and other operations, particularly operations that may acquire or identify sensitive information, are restricted as prohibited operations. Prohibited operations include editing and deleting strings in log data, as well as viewing, creating, editing, and deleting directories that are not related to system maintenance.

[0083] When transmitting log data in real time from node 11a of organization A to node 11b of organization B, it is possible to convert and transmit small amounts of log data, for example, one line at a time, rather than outputting all of the log data at once. When log data is transmitted by command operation on the receiving side, outputting all of the log data at once takes time, increasing the wait time on the command operation side. Furthermore, in the event of a system failure, identifying a general anomaly may be prioritized over identifying a detailed anomaly. Therefore, transmitting log data one line at a time allows for efficient response to system failures, etc. Note that one line of log data does not refer to a "wraparound" that may be changed by the display or other features of each node, but rather refers to the range up to the line break code set for each document format.

[0084] In the second embodiment, because sensitive information is detected and converted line by line, the maximum conversion range for one conversion process is one line of log data. However, if the log data includes documents, sensitive information may be detected across lines, so it is preferable to retain information about the character string at the start of each document format in the log data so that conversion can be performed continuously.

[0085] In the above embodiment, the hardware structure of the processing units that execute various processes, such as the central control unit (not shown), data acquisition unit 30, sensitive information detection unit 31, conversion processing unit 32, data output unit 33, and input reception unit 34, is the following various processors: The various processors include a CPU (Central Processing Unit), which is a general-purpose processor that executes software (programs) and functions as various processing units, a programmable logic device (PLD), such as an FPGA (Field Programmable Gate Array), whose circuit configuration can be changed after manufacture, and a dedicated electrical circuit, which is a processor with a circuit configuration designed specifically for executing various processes.

[0086] A single processing unit may be configured with one of these various processors, or may be configured with a combination of two or more processors of the same or different types (e.g., multiple FPGAs or a combination of a CPU and an FPGA). Multiple processing units may also be configured with a single processor. Examples of multiple processing units configured with a single processor include: a first configuration, as typified by client or server computers, in which a single processor is configured with a combination of one or more CPUs and software, and this processor functions as multiple processing units; and a second configuration, as typified by system-on-chip (SoC), in which a processor is used to realize the functions of an entire system including multiple processing units on a single IC (Integrated Circuit) chip. In this way, the various processing units are configured with one or more of the above-mentioned various processors as a hardware structure.

[0087] Furthermore, the hardware structure of these various processors is, more specifically, an electric circuit formed by combining circuit elements such as semiconductor elements, and the hardware structure of the memory unit is a storage device such as a hard disk drive (HDD) or a solid state drive (SSD).

[0088] 10 Data transmission / reception system 11 Node 11a Node 11b Node 12 Device 12a Device 12b Device 13 Confidential information processing device 13a Confidential information processing device 13b Confidential information processing device 20 Receiving unit 21 Analysis unit 22 Storage unit 23 Output unit 24 Input receiving unit 30 Data acquisition unit 31 Sensitive information detection unit 32 Conversion processing unit 33 Data output unit 34 Input receiving unit 40 Presetting management unit 41 Presetting storage unit 42 Presetting update unit 43 Specific character recognition unit 44 Character string discrimination unit 45 Sensitive information classification unit 46 Conversion range determination unit Ha Administrator Hb Administrator

Claims

1. A processor is provided. The processor Acquire log data transmitted between devices that make up the blockchain network, Identifying a character string of the log data; Detecting, as sensitive information, a character string in the log data based on a specific character set as a marker in advance and a character string in the log data that cannot be determined based on a dictionary function for determining a meaningful character string; A confidential information processing device that performs a conversion process to convert the character string of the sensitive information into a different character or symbol.

2. The processor, The confidential information processing device according to claim 1 , wherein a character string including the specific character is detected as the sensitive information in the log data.

3. The processor, The confidential information processing device according to claim 1 , wherein a character string sandwiched between the specific character or a character string including the specific character in the log data is detected as the sensitive information.

4. The processor, A dictionary function is used to distinguish character strings in the log data; 2. The confidential information processing device according to claim 1, wherein a character string enclosed by character strings that could not be determined based on the dictionary function is detected as the sensitive information.

5. The processor, The confidential information processing device according to claim 1 , wherein the character string converted by the conversion process is determined according to the type of the sensitive information.

6. The processor, 2 . The confidential information processing device according to claim 1 , wherein in the presetting, a rule that lists the specific characters, a rule that classifies the types of the sensitive information, and a rule that determines a conversion range are applied to the conversion process.

7. The processor, The confidential information processing device according to claim 6 , wherein in the presetting, statistical data of past conversion processes on the sensitive information is applied to the conversion process.

8. The processor, Transmitting the converted log data to another device constituting the blockchain network; The confidential information processing device according to claim 1 , further comprising: a processor configured to receive, from the other device, feedback data having an analysis result of the converted log data.

9. The processor, The confidential information processing device according to claim 8 , wherein the presetting accepts an update of the detection target of the sensitive information based on the analysis result.

10. The processor, The confidential information processing device according to claim 1 , wherein the conversion processing and transmission are performed for each line of the log data in response to a command operation by another device constituting the block chain network.

11. The processor, The confidential information processing device according to claim 10 , wherein when the conversion process is performed in response to the command operation, a prohibited operation including an operation of acquiring the sensitive information by the other device is determined.

12. The confidential information processing device according to claim 11 , wherein the prohibited operations include any of browsing, creating, editing, and deleting operations for a directory that is not related to system maintenance, in addition to editing and deleting character strings of the log data.

13. 13. A data transmission / reception system comprising the confidential information processing device according to claim 1.

14. A step of acquiring log data to be transmitted between devices constituting a blockchain network; determining a character string of the log data; detecting, as sensitive information, a character string in the log data based on a specific character set as a marker in advance and a character string in the log data that cannot be identified based on a dictionary function for identifying a meaningful character string; and performing a conversion process for converting the character string of the sensitive information into a different character or symbol.