Information acquisition device, information acquisition system, information acquisition method, and program
Patent Information
- Application Number
- JP2025509404
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Filing Date
- 2025-09-17
- Publication Date
- 2025-12-05
AI Technical Summary
Existing systems cannot provide product information to customers while keeping information of other customers confidential, as they rely on known product identification numbers, which vendors cannot obtain, and cannot transmit product information across systems.
An information acquisition system that includes a data acquisition unit to decrypt customer product information using individual product numbers and encryption keys, ensuring only relevant product information is displayed, keeping other customers' data confidential.
Enables the provision of customer-specific product information while maintaining confidentiality of other customers' data, allowing vendors to manage and transmit product information securely.
Abstract
Description
Information acquisition device, information acquisition system, information acquisition method, and recording medium
[0001] The present disclosure relates to an information acquisition device, an information acquisition system, an information acquisition method, and a recording medium.
[0002] There is technology that links product inspection results with individual product identification numbers and manages them.
[0003] For example, Patent Document 1 discloses a technology for managing stored information related to the production of products, parts, equipment, workers, etc. by linking it to the product's production lot number or identification number, etc., and extracting a specified production lot number or individual identification number and the value of the information item related to that production.
[0004] JP 2010-182284 A
[0005] However, the invention described in the above-mentioned Patent Document 1 is based on the premise that the identification number of the product used by the customer is known in advance. However, the vendor that provides the product usually cannot obtain the individual number of the product sold to the customer. Furthermore, product information provided to a specific customer cannot be passed on to other customers.
[0006] An example of an objective of the present disclosure is to provide an information acquisition system that can provide product information of a customer while concealing product information of other customers.
[0007] An information acquisition device in one aspect of the present disclosure includes a data acquisition means for acquiring encrypted data of management information regarding products shipped by a vendor to multiple customers, a number acquisition means for acquiring individual numbers of customer products held by the customers, an extraction means having an encryption key and extracting customer product information regarding the customer products from the encrypted data that has been decrypted using the individual numbers and the encryption key, and a display means for displaying the extracted customer product information.
[0008] An information acquisition system in one aspect of the present disclosure is an information acquisition system having an information management device and the information acquisition device described above, wherein the information management device is equipped with an encryption means for encrypting management information regarding products shipped to multiple customers.
[0009] In one aspect of the present disclosure, an information acquisition method includes a computer acquiring encrypted data of management information regarding products shipped by a vendor to multiple customers, acquiring individual numbers of customer products owned by the customers, extracting customer product information regarding the customer products from the encrypted data that has been decrypted using the individual numbers and an encryption key, and displaying the extracted customer product information.
[0010] In one aspect of the present disclosure, a recording medium stores a program that causes a computer to obtain encrypted data of management information regarding products shipped by a vendor to multiple customers, obtain individual numbers of customer products owned by the customers, extract customer product information regarding the customer products from the encrypted data that has been decrypted using the individual numbers and encryption keys, and display the extracted customer product information.
[0011] One example of the effect of the present disclosure is that it is possible to provide an information acquisition system that can provide product information of a customer while concealing product information of other customers.
[0012] FIG. 1 is a block diagram showing the configuration of an information management device according to the present disclosure. FIG. 2 is a block diagram showing the configuration of an information acquisition device according to the present disclosure. FIG. 3 is a diagram showing a hardware configuration in which the information management device and information acquisition device according to the present disclosure are realized by a computer device and its peripheral devices. FIG. 4 is a diagram showing the configuration of a customer's internal network including an information acquisition device according to the present disclosure. FIG. 5 is an example of a screen displaying extracted customer product information according to the present disclosure. FIG. 6 is a flowchart showing the information acquisition operation according to the present disclosure. FIG. 7 is a block diagram showing the configuration of an information acquisition system according to the present disclosure. FIG. 8 is a flowchart showing the information acquisition operation according to the present disclosure.
[0013] Next, an embodiment will be described in detail with reference to the drawings. In this embodiment, a case where the product is a device will be described as an example, but the product in the present disclosure is not limited to a device.
[0014] [First Embodiment] Fig. 1 is a block diagram of an information management device 100 according to the present disclosure. Fig. 2 is a block diagram of an information acquisition device 200 according to the present disclosure. The information management device 100 is, for example, a server owned by a vendor that sells products, and stores management information related to the products up until the vendor ships them. The information acquisition device 200 is a server owned by each customer that purchases products from the vendor, and is used to acquire information related to customer products owned by the customer. The information management device 100 and the information acquisition device 200 according to the present disclosure will be described in detail below.
[0015] 3 is a diagram illustrating an example of a hardware configuration in which the information management device 100 and the information acquisition device 200 according to the first embodiment of the present disclosure are realized by a computer device 500 including a processor. As shown in FIG. 3, the information acquisition system 10 includes a CPU (Central Processing Unit) 501, memories such as a ROM (Read Only Memory) 502 and a RAM (Random Access Memory) 503, a storage device 505 such as a hard disk for storing a program 504, a communication interface 508 for network connection, and an input / output interface 511 for inputting and outputting data. In the first embodiment, each component of the information management device 100 and the information acquisition device 200 is connected to each other via a bus 512.
[0016] The CPU 501 runs an operating system to control the information management device 100 and the information acquisition device 200 according to the first embodiment of the present disclosure. The CPU 501 also reads programs and data into memory from a recording medium 506 mounted in, for example, a drive device 507. The CPU 501 also functions as each component of the information management device 100 and the information acquisition device 200 or as part of these components, and executes processing or commands in the flowcharts shown in Figures 6 and 8 (described later) based on the program.
[0017] The recording medium 506 is, for example, an optical disk, a flexible disk, a magneto-optical disk, an external hard disk, or a semiconductor memory. A part of the recording medium in the storage device is a non-volatile storage device, and the program is recorded therein. The program may also be downloaded from an external computer (not shown) connected to a communication network.
[0018] The input device 509 is realized by, for example, a mouse, a keyboard, built-in key buttons, etc., and is used for input operations. The input device 509 is not limited to a mouse, a keyboard, or built-in key buttons, and may be, for example, a touch panel. The output device 510 is realized by, for example, a display, and is used to check output.
[0019] As described above, the first embodiment shown in Figures 1 and 2 is realized by the computer hardware shown in Figure 3. However, the means for realizing each component of the information management device 100 in Figure 1 and the information acquisition device 200 in Figure 2 are not limited to the configurations described in this specification. Furthermore, the information management device 100 and the information acquisition device 200 may each be realized by a single physically coupled device, or by two or more physically separated devices connected by wire or wirelessly. For example, the input device 509 and the output device 510 may be connected to the computer device 500 via a network.
[0020] (Information Management Device 100) First, the information management device 100 will be described. As shown in FIG. 1, the information management device 100 includes an encryption unit 101. Furthermore, the storage device 505 of the information management device 100 stores product management information up until the vendor ships the product. The management information is, for example, product inspection information up until the product is shipped. If the product is a device, the inspection information includes whether or not information on authenticity inspection at the time of factory shipment has been performed, whether or not the device status has been confirmed, and the like. Authenticity refers to confirming that no unauthorized hardware or programs have been installed in the device. The authenticity of hardware is confirmed, for example, by checking that the hardware has not been counterfeited or replaced. The authenticity of programs is confirmed, for example, by checking whether or not a program can be executed when the device is started up using secure boot.
[0021] The management information may contain dummy data, which is used to conceal the amount of data in the management information and is created by a known method and mixed with the real management information.
[0022] The encryption unit 101 encrypts management information related to products shipped to multiple customers. The encryption unit 101 encrypts the management information using, for example, an encryption key enclosed by the manufacturer of the information acquisition system 10. The encryption unit 101 may encrypt the management information periodically at predetermined intervals. The encryption unit 101 stores, for example, encrypted data of the encrypted management information on a recording medium 506 attached to a drive device 507 or the like.
[0023] (Information Acquisition Device 200) Next, the information acquisition device 200 will be described. As shown in FIG. 2, the information acquisition device 200 includes a data acquisition unit 201, a number acquisition unit 202, an extraction unit 203, and a display unit 204. FIG. 4 is a diagram showing the configuration of a customer's internal network including the information acquisition device 200 in the present disclosure. As shown in FIG. 4, the information acquisition device 200 is connected to customer products purchased by the customer from a vendor on the internal network N. Note that each customer product is not connected to an external network.
[0024] The data acquisition unit 201 acquires the encrypted data of the management information and outputs it to the extraction unit 203. The data acquisition unit 201 acquires the encrypted data from, for example, a storage medium or the like in which the encrypted data is stored.
[0025] The number acquisition unit 202 acquires the individual number of a customer product owned by a customer. The individual number is a number used to identify a product, such as a serial number. The number acquisition unit 202 acquires data including the individual number from information stored in the customer product, for example.
[0026] The number acquisition unit 202 may verify the acquired individual number. Specifically, the number acquisition unit 202 verifies the individual number by verifying a digital signature for data including the individual number using a certificate enclosed with each customer product. This certificate is, for example, an IEEE802.1AR (IDevID: Initial Device Identifier), and the key in the certificate cannot be extracted to the outside. Furthermore, the number acquisition unit 202 may instruct the CPU of the customer product to assign a nonce to the verified digital signature. The assigned nonce is a unique value, which prevents the individual number from being swapped.
[0027] The extraction unit 203 is provided with an encryption key and extracts customer product information related to the customer product decrypted using the individual number and the encryption key. The encryption key is, for example, an encryption key stored in a tamper-resistant storage area. The tamper-resistant storage area may be configured, for example, as a TPM (Trusted Platform Module), but is not limited to this as long as it has a tamper-resistant configuration. The extraction unit 203 may also be configured to obfuscate the encryption key information so that the information cannot be extracted from outside. For example, the encryption key may be incorporated by the manufacturer of the information acquisition system 10 in a pair with an encryption key for encrypting the management information.
[0028] The extraction unit 203 uses the individual number and encryption key to extract customer product information related to the decrypted customer product from the encrypted data. In this embodiment, "extraction" refers to retrieving the decrypted customer product information from the extraction unit 203. The extraction unit 203 may decrypt all encrypted data using the encryption key and extract customer product information from the decrypted management information using the individual number. Alternatively, the extraction unit 203 may decrypt only the encrypted data related to the customer product from the encrypted data and extract the decrypted customer product information. In this case, an encryption key for decrypting only the encrypted data related to a specific individual number is used. An example of this encryption key is a derived key generated by limiting the data to be decrypted from a master key that decrypts all encrypted data. The extraction unit 203 outputs the extracted customer product information to the display unit 204. After extracting the customer product information, the extraction unit 203 may delete management information related to products other than the customer product.
[0029] The display unit 204 displays the decrypted customer product information. The display unit 204 displays the decrypted customer product information in a customer product list, for example. That is, the customer products displayed by the display unit 204 may not include product information. The display unit 204 outputs the customer product information to the output device 510 or the like. FIG. 5 shows an example of displaying the inspection history of a device before shipment as customer product information. As shown in FIG. 5, the inspection history associates each inspection result regarding the quality and authenticity of the product with the inspection time information. In FIG. 5, "◯" indicates that the product has been inspected, and "×" indicates that the product has not been inspected. This allows the customer product manager to confirm the product's quality and security reliability before shipping. Note that the display example of the inspection history in this embodiment is not limited to the example shown in FIG. 5. Furthermore, the display unit 204 may transmit information to another device using an API (Application Programming Interface) or the like, without displaying it on the output device 510.
[0030] 6 is a flowchart showing an outline of the operation of the information acquisition device 200 according to the first embodiment. Note that the processing according to this flowchart may be executed based on program control by the processor described above.
[0031] As shown in Fig. 6, first, the data acquisition unit 201 acquires encrypted data of management information related to products shipped by a vendor to multiple customers (step S101). Next, the number acquisition unit 202 acquires the individual numbers of customer products owned by the customers (step S102). The extraction unit 203 extracts customer product information related to the customer products decrypted from the encrypted data using the individual numbers and encryption keys (step S103). Finally, the display unit 204 displays the extracted customer product information (step S104).
[0032] In the information acquisition device 200 of this embodiment, the extraction unit 203 extracts customer product information about a customer product decrypted from the encrypted data using the individual product number and encryption key, and the display unit 204 displays the customer product information. With this configuration, a customer who extracted the customer product information cannot extract information about products that the vendor has shipped to other customers. Therefore, it is possible to provide customer product information from management information about products shipped by the vendor to multiple customers while concealing product information about other customers.
[0033] (Information Acquisition System 10) Next, the information acquisition system 10 of this embodiment will be described. Fig. 7 is a block diagram showing the configuration of the information acquisition system 10 in the first embodiment. Referring to Fig. 7, the information acquisition system 10 has an information management device 100 and an information acquisition device 200. The configurations of the information management device 100 and the information acquisition device 200 are similar to the configurations shown in Figs. 1 and 2, respectively.
[0034] In the information acquisition system 10, the information management device 100 transmits encrypted data of the management information encrypted by the encryption unit 101 to the information acquisition device 200, and the data acquisition unit 201 of the information acquisition device 200 receives the encrypted data of the management information. Note that transmission and reception of encrypted data between the information management device 100 and the information acquisition device 200 is performed via the communication interface 508 of each device. Furthermore, the encryption unit 101 may encrypt the management information stored in the storage device 505 in response to a request from the information acquisition device 200 to transmit information related to the customer product.
[0035] The operation of the information acquisition system 10 configured as above will be described with reference to the flowchart of FIG.
[0036] 8 is a flowchart showing an outline of the operation of the information acquisition system 10 according to the first embodiment. Note that the processing according to this flowchart may be executed based on program control by the processor described above.
[0037] As shown in FIG. 8 , first, the encryption unit 101 in the information management device 100 encrypts management information related to products shipped to multiple customers (step S111) and transmits the encrypted information to the information acquisition device 200 (step S112). Next, in the information acquisition device 200, the data acquisition unit 201 acquires the encrypted data (step S113). Next, the number acquisition unit 202 acquires the individual numbers of the customer products owned by the customers (step S114). The extraction unit 203 extracts customer product information related to the customer products decrypted from the encrypted data using the individual numbers and encryption keys (step S115). Finally, the display unit 204 displays the extracted customer product information (step S116). This completes the operation of the information acquisition system 10.
[0038] In the information acquisition system 10 of the first embodiment, the information management device 100 encrypts management information related to products shipped to multiple customers, and in the information acquisition device 200, the extraction unit 203 extracts customer product information related to the customer product decrypted from the encrypted data using the individual product number and encryption key, and the display unit 204 displays the customer product information. With this configuration, a customer who extracted the customer product information cannot extract information related to products shipped by the vendor to other customers. Therefore, it is possible to provide customer product information from the management information related to products shipped by the vendor to multiple customers while concealing the product information of other customers.
[0039] Furthermore, even when a vendor receives a request for inspection information on a customer's product from a customer who has purchased the product, the factory is unable to identify which product the customer purchased. Furthermore, even when a customer who has purchased a product requests information on the customer's product from the vendor, there are issues such as the product ID number operating within the customer system being unable to be transmitted outside the customer system, and the product ID number of a product sold to a customer being unable to be obtained from a sales system or the like that manages product information shipped by the vendor to the customer. In response to these issues, the information acquisition system 10 disclosed herein allows the number acquisition unit 202 of the information acquisition device 200 to acquire the product ID number of the customer's product owned by the customer. Therefore, while solving the above-mentioned issues, it is possible to provide customer product information while concealing product information of other customers from management information regarding products shipped by the vendor to multiple customers. Furthermore, the information acquisition system 10 disclosed herein allows providing customer product information while concealing the production or shipment quantity of the product.
[0040] <Application Example> Another use case of the information acquisition system 10 of the present disclosure is device license management. When a commercial product such as a network device is equipped with multiple functions, the customer must purchase licenses from the vendor to enable the corresponding functions. The customer enables the corresponding functions by inputting the license data purchased from the vendor into the information acquisition device 200. The information acquisition device 200 is pre-implemented with all functions that can be enabled, and the device is controlled so that only functions whose usage rights are confirmed by the license data are operational.
[0041] The presently disclosed invention can be applied to the above-described information acquisition device 200 when only functions for which licenses have been purchased are activated. Specifically, the encryption unit 101 of the information management device 100 encrypts control information for controlling all functions. The number acquisition unit 202 of the information acquisition device 200 acquires specific information identifying the activated functions to be activated on the customer's device, and the extraction unit 203 extracts control information for the activated functions decrypted from the encrypted data using the specific information and the encryption key. This allows the control information for functions for which the customer does not have the right to use to be provided while concealing the control information for functions for which the customer does not have the right to use. This enables device function control through license acquisition.
[0042] Another application example is information regarding the traceability of agricultural products, etc. In this case, the information management device 100 manages information such as the place of origin, shipping volume, production volume, and distribution volume of the agricultural products, and provides the information regarding the place of origin to the information acquisition device 200 while concealing information other than the place of origin.
[0043] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention.
[0044] For example, although multiple operations are described in a sequential order in the form of a flowchart, the order of description does not limit the order in which the multiple operations are performed. Therefore, when implementing each embodiment, the order of the multiple operations can be changed within the scope that does not affect the content.
[0045] Some or all of the above-described embodiments can be described as follows: However, some or all of the above-described embodiments are not limited to the following.
[0046] (Supplementary Note 1) An information acquisition device comprising: a data acquisition means for acquiring encrypted data of management information relating to products shipped by a vendor to multiple customers; a number acquisition means for acquiring individual numbers of customer products held by the customers; an extraction means having an encryption key and extracting customer product information relating to the customer products from the encrypted data that has been decrypted using the individual numbers and the encryption key; and a display means for displaying the extracted customer product information.
[0047] (Supplementary Note 2) The information acquisition device according to Supplementary Note 1, wherein the extraction means decrypts all of the encrypted data and extracts the customer product information from the decrypted management information.
[0048] (Supplementary Note 3) The information acquisition device according to Supplementary Note 1, wherein the extraction means decrypts only encrypted data relating to the customer product among the encrypted data, and extracts the customer product information.
[0049] (Supplementary Note 4) The information acquisition device according to any one of Supplementary Notes 1 to 3, wherein the number acquisition means verifies the individual number by verifying a digital signature for data including the individual number.
[0050] (Supplementary Note 5) The information acquisition device according to any one of Supplementary Notes 1 to 4, wherein the management information includes dummy data.
[0051] (Supplementary Note 6) The information acquisition device according to any one of Supplementary Notes 1 to 5, wherein the extraction means deletes management information relating to products other than the customer product after extracting the customer product information.
[0052] (Supplementary Note 7) The information acquisition device according to any one of Supplementary Notes 1 to 6, wherein the management information is a pre-shipment inspection history of devices shipped to multiple customers.
[0053] (Supplementary Note 8) An information acquisition system having an information management device and an information acquisition device according to any one of Supplementary Notes 1 to 7, wherein the information management device is provided with an encryption means for encrypting management information relating to products shipped to multiple customers.
[0054] (Appendix 9) An information acquisition system as described in Appendix 8, wherein the management information is control information for activating multiple functions installed in a specific product, the encryption means encrypts the control information for controlling all functions, the number acquisition means acquires specific information that identifies the activation function to be activated in the customer's product, and the extraction means extracts the control information of the activation function from the encrypted data decrypted using the specific information and the encryption key.
[0055] (Supplementary Note 10) An information acquisition method in which a computer acquires encrypted data of management information regarding products shipped by a vendor to multiple customers, acquires individual numbers of customer products owned by the customers, extracts customer product information regarding the customer products from the encrypted data decrypted using the individual numbers and an encryption key, and displays the extracted customer product information.
[0056] (Supplementary Note 11) A recording medium storing a program that causes a computer to execute the following operations: acquiring encrypted data of management information regarding products shipped by a vendor to multiple customers; acquiring individual numbers of customer products held by the customers; extracting customer product information regarding the customer products from the encrypted data that has been decrypted using the individual numbers and an encryption key; and displaying the extracted customer product information.
[0057] 10 Information acquisition system 100 Information management device 101 Encryption unit 200 Information acquisition device 201 Data acquisition unit 202 Number acquisition unit 203 Extraction unit 204 Display unit
Claims
1. a data acquisition means for acquiring encrypted data of management information relating to products shipped by a vendor to a plurality of customers; a number acquisition means for acquiring the individual number of a customer product held by a customer; an extracting means for extracting customer product information related to the customer product from the encrypted data, the customer product information being provided with an encryption key and decrypted using the individual number and the encryption key; and a display means for displaying the extracted customer product information.
2. 2. The information acquisition device according to claim 1, wherein said extracting means decrypts all of said encrypted data and extracts said customer product information from the decrypted management information.
3. 2. The information acquisition device according to claim 1, wherein the extracting means decrypts only the encrypted data relating to the customer product from the encrypted data, and extracts the customer product information.
4. The information acquisition device according to claim 1 , wherein the number acquisition means verifies the individual number by verifying a digital signature for data including the individual number.
5. 2. The information acquisition device according to claim 1, wherein said extracting means, after extracting said customer product information, deletes management information relating to products other than said customer product.
6. The information acquisition device according to claim 1 , wherein the management information is a pre-shipment inspection history of devices shipped to a plurality of customers.
7. An information acquisition system having an information management device and the information acquisition device according to any one of claims 1 to 6, The information management device includes an encryption unit that encrypts management information related to products shipped to multiple customers.
8. the management information is control information for enabling a plurality of functions installed in a specific product, the encryption means encrypts control information for controlling all functions, The number acquisition means acquires specific information that identifies an activation function to be activated in the customer's product, 8. The information acquisition system according to claim 7, wherein the extracting means extracts the control information of the activation function decrypted using the specific information and the encryption key from the encrypted data.
9. The computer Obtaining encrypted data of management information regarding products shipped by a vendor to multiple customers; Obtain the individual number of the customer product held by the customer, extracting customer product information regarding the customer product decrypted using the individual number and encryption key from the encrypted data; and displaying the extracted customer product information.
10. Obtaining encrypted data of management information regarding products shipped by a vendor to multiple customers; Obtain the individual number of the customer product held by the customer, extracting customer product information regarding the customer product decrypted using the individual number and encryption key from the encrypted data; and displaying the extracted customer product information.