Information processing method, program, and information processing device

The method addresses the challenge of information leakage in secret sharing techniques by dividing information into aligned dispersion pieces, ensuring secure restoration and preventing unauthorized access.

WO2025094961A1PCT designated stage expired Publication Date: 2025-05-08MINEBEAMITSUMI INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/038599
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-31
Filing Date
2024-10-30
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

Existing information protection methods using secret sharing techniques face challenges in preventing information leakage, particularly when dealing with updated information and dynamic protection requirements.

Method used

The proposed method involves dividing original information into primary and secondary dispersion pieces using secret sharing methods, where some pieces are stored locally and others are stored externally. This setup allows for the restoration of original information only when all necessary pieces are aligned, thereby preventing information leakage.

Benefits of technology

This approach effectively prevents information leakage by ensuring that original information cannot be restored unless all required dispersion pieces are correctly aligned, both locally and externally, thus enhancing data security and protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024038599_08052025_PF_FP_ABST
    Figure JP2024038599_08052025_PF_FP_ABST
Patent Text Reader

Abstract

This information processing method involves causing a computer to execute processing in which the following are stored in a storage unit: a section of a primary shared piece obtained by dividing original information using a secret sharing scheme; and a section of a secondary shared piece obtained by further dividing, using a secret sharing scheme, a remaining section of the primary shared piece which is other than said section of the primary shared piece. The processing further includes: acquiring a remaining secondary shared piece, which is other than the section of the secondary shared piece, from an external storage device that stores the remaining secondary shared piece; and restoring the original information on the basis of the primary shared piece and the secondary shared piece stored in the storage unit and the secondary shared piece acquired from the external storage device.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, program, and information processing device

[0001] The present invention relates to an information processing method, a program, and an information processing device.

[0002] There is a technology for protecting information using a secret sharing scheme. For example, Patent Literature 1 discloses a computer program that uses the secret sharing scheme to distribute secret data into multiple pieces of distributed data and distribute the metadata of a virtual drive that stores the secret data into multiple pieces of distributed metadata, thereby doubly protecting the secret data.

[0003] Japanese Patent Application Laid-Open No. 2017-126321

[0004] In one aspect, an object is to provide an information processing method and the like that can prevent information leakage.

[0005] In one aspect, the information processing method includes storing in a memory unit a portion of primary distribution pieces obtained by dividing original information using a secret sharing method, and a portion of secondary distribution pieces obtained by further dividing the remaining primary distribution pieces other than the portion of primary distribution pieces using a secret sharing method, and acquiring the remaining secondary distribution pieces from an external storage device that stores the remaining secondary distribution pieces other than the portion of secondary distribution pieces, and causing a computer to perform a process of restoring the original information based on the primary distribution pieces and secondary distribution pieces stored in the memory unit and the secondary distribution pieces acquired from the external storage device.

[0006] In one aspect, information leakage can be prevented.

[0007] FIG. 1 is an explanatory diagram showing an example of the configuration of an information processing system. FIG. 2 is a block diagram showing an example of the configuration of a restoration device. FIG. 3 is a block diagram showing an example of the configuration of a management device. FIG. 4 is an explanatory diagram relating to the process of generating distributed pieces. FIG. 5 is an explanatory diagram relating to the process of restoring original information. FIG. 6 is a flowchart showing the procedure of the process of generating distributed pieces. FIG. 7 is a flowchart showing the procedure of the process of restoring original information. FIG. 8 is an explanatory diagram showing an overview of embodiment 2. FIG. 9 is a flowchart showing the procedure of the process of restoring original information relating to embodiment 2. FIG. 10 is an explanatory diagram showing an overview of embodiment 3. FIG. 11 is a flowchart showing the procedure of the process of restoring original information relating to embodiment 3. FIG. 12 is an explanatory diagram showing an overview of embodiment 4. FIG. 13 is a flowchart showing the procedure of the process of restoring original information relating to embodiment 4. FIG. 14 is an explanatory diagram showing an overview of embodiment 5. FIG. 15 is a flowchart showing the procedure of the process of encrypting secondary distributed pieces relating to embodiment 5.

[0008] The present invention will be described in detail below with reference to the drawings showing embodiments. (Embodiment 1) Fig. 1 is an explanatory diagram showing an example of the configuration of an information processing system. In this embodiment, an information processing system is described in which original information to be kept secret is divided into multiple shares using a secret sharing scheme and the multiple shares are combined to restore the original information. The information processing system includes a restoration device 1, a management device 2, and an external storage device 3. The restoration device 1 and the management device 2 are communicatively connected via a network N.

[0009] The restoration device 1 is an information processing device capable of various information processing and information transmission / reception, such as a personal computer, smartphone, or tablet terminal. As described below, the restoration device 1 acquires and stores, in advance from the management device 2, some of the primary shares obtained by dividing the original information using a secret sharing scheme, and some of the secondary shares obtained by further dividing the remaining primary shares using a secret sharing scheme. When an external storage device 3 storing the remaining secondary shares necessary for restoring the original information is connected, the restoration device 1 acquires the secondary shares from the external storage device 3 and restores the original information based on the stored primary shares and secondary shares and the acquired secondary shares. Note that "restoration" in this specification does not mean combining the primary shares and secondary shares themselves (i.e., converting the primary shares and secondary shares into original information), but rather means generating data called "original information" based on the information of the primary shares and secondary shares. Therefore, even after the original information is restored, the data of the primary shares and secondary shares used for the restoration remains.

[0010] The external storage device 3 is a storage device that stores the distributed fragments, such as a USB (Universal Serial Bus) memory. The external storage device 3 is not limited to a USB memory and may be a Secure Drive (SD) card, an Integrated Circuit (IC) card, or the like. The external storage device 3 may also be a device equipped with a processor such as a CPU, such as a smartphone. The external storage device 3 is connected to the management device 2 via a computer (not shown) (or directly), and acquires and stores the secondary distributed fragments from the management device 2. In the following description, unless otherwise specified, the "connection" of the external storage device 3 may refer to an electrical connection or a communication connection. In either case, the external storage device 3 is connected so that data can be downloaded from the management device 2. When the external storage device 3 is connected, the restoration device 1 acquires the secondary distributed fragments from the external storage device 3 and uses them to restore the original information.

[0011] The management device 2 is an information processing device that manages this system, and is, for example, a server computer. The management device 2 generates multiple primary shares by dividing the original information using a secret sharing scheme, and also generates multiple secondary shares by further dividing some of the generated primary shares. The management device 2 stores the primary shares that were not used to generate the secondary shares (i.e., not divided) and some of the secondary shares in the restoration device 1, and stores the remaining secondary shares (secondary shares other than the some of the secondary shares) in the external storage device 3.

[0012] FIG. 2 is a block diagram showing an example configuration of the restoration device 1. The restoration device 1 includes a control unit 11, a main memory unit 12, a communication unit 13, a display unit 14, an operation unit 15, an input / output unit 16, and an auxiliary memory unit 17. The control unit 11 has one or more processors, such as a central processing unit (CPU), a microprocessing unit (MPU), or a graphics processing unit (GPU), and performs various information processing by reading and executing programs stored in the auxiliary memory unit 17. The main memory unit 12 is a temporary storage area, such as a static random access memory (SRAM) or a dynamic random access memory (DRAM), and temporarily stores data necessary for the control unit 11 to execute arithmetic processing. The communication unit 13 is a communication module for performing communication-related processing and transmits and receives information to and from the outside. The display unit 14 is a display screen, such as a liquid crystal display, that displays images. The operation unit 15 is an operation interface, such as a keyboard or a mouse, that accepts operation inputs from a user. The input / output unit 16 is an input / output interface for connecting a portable storage medium (such as the external storage device 3) and accepts connection of the storage medium. The auxiliary storage unit 17 is a non-volatile storage area such as a hard disk, and stores programs (program products) and other data necessary for the control unit 11 to execute processing. The display unit 14 and the operation unit 15 are not essential components. Alternatively, the display unit 14 and the operation unit 15 may be configured as separate devices from the restoration device 1 and connected to the restoration device 1 by wire or wirelessly.

[0013] The restoration device 1 may read and execute a program from a portable storage medium 1a such as a CD (Compact Disk)-ROM or a DVD (Digital Versatile Disk)-ROM.

[0014] 3 is a block diagram showing an example configuration of the management device 2. The management device 2 includes a control unit 21, a main memory unit 22, a communication unit 23, and an auxiliary memory unit 24. The control unit 21 has one or more processors such as CPUs, and performs various information processing by reading and executing programs stored in the auxiliary memory unit 24. The main memory unit 22 is a temporary storage area such as RAM, and temporarily stores data necessary for the control unit 21 to execute arithmetic processing. The communication unit 23 is a communication module for performing communication-related processing, and transmits and receives information to and from the outside. The auxiliary memory unit 24 is a non-volatile storage area such as a large-capacity memory or a hard disk, and stores programs (program products) and other data necessary for the control unit 21 to execute processing.

[0015] The management device 2 may be a multi-computer consisting of a plurality of computers, or may be a virtual machine virtually constructed by software.

[0016] The management device 2 may also be provided with a reading unit that reads a portable storage medium 2a such as a CD-ROM, and may read and execute a program from the portable storage medium 2a.

[0017] 4 is an explanatory diagram of the process of generating shares, and the process of generating a plurality of shares by dividing the original information using the secret sharing scheme will be described with reference to FIG.

[0018] First, the management device 2 generates a plurality of primary shares by dividing the original information using a secret sharing scheme. In the example of Fig. 4, the management device 2 divides the original information into two primary shares X and Y. Note that the management device 2 may divide the original information into three or more shares.

[0019] Furthermore, the management device 2 uses a secret sharing scheme to generate multiple secondary share pieces by dividing a portion of the primary share pieces generated above. In the example of Figure 4, the management device 2 divides the primary share piece Y into two secondary share pieces. Note that the management device 2 may also divide the primary share piece into three or more.

[0020] The management device 2 generates secondary distribution pieces multiple times using different division patterns. The term "division pattern" refers to a combination of the division algorithm and parameters used in the algorithm used to divide primary distribution pieces into secondary distribution pieces. In other words, "division using different division patterns" refers to dividing primary distribution pieces into secondary distribution pieces using different algorithms and / or different parameters. For example, by using random numbers as parameters for dividing primary distribution pieces into secondary distribution pieces, it is possible to easily create different division patterns for each division. By generating secondary distribution pieces multiple times using different division patterns, as shown in FIG. 4, sets of two secondary distribution pieces are generated, such as secondary distribution pieces A and B, C and D, E and F, G and H, etc. Combining secondary distribution pieces from the same set (e.g., secondary distribution pieces A and B) will result in all of the data constituting primary distribution piece Y, making it possible to restore it. In other words, secondary distribution pieces from the same set can be considered "combinations of secondary distribution pieces that can restore a primary distribution piece." On the other hand, even if secondary dispersion piece A is combined with a secondary dispersion piece other than secondary dispersion piece B (such as secondary dispersion piece D), the data constituting primary dispersion piece Y will not be complete because they are divided in different patterns, and primary dispersion piece Y cannot be restored. This is also true when three or more secondary dispersion pieces are used to generate a set; the primary dispersion piece cannot be restored unless all of the secondary dispersion pieces from the same set are collected.

[0021] The management device 2 transmits primary dispersion pieces X that have not been used to generate secondary dispersion pieces to the restoration device 1, and stores them in the auxiliary memory unit 17. The management device 2 also transmits some of the secondary dispersion pieces divided according to a certain division pattern (first division pattern) to the restoration device 1, and stores them in the auxiliary memory unit 17. For example, in Figure 4, the management device 2 stores secondary dispersion piece A, of secondary dispersion pieces A and B that correspond to the first division pattern, in the restoration device 1.

[0022] As described above, the external storage device 3 is also connected to the management device 2. The management device 2 stores in the external storage device 3 secondary distributed pieces B that belong to the same set as secondary distributed pieces A stored in the restoration device 1.

[0023] Furthermore, the management device 2 stores in the external storage device 3 some of the secondary distributed pieces that belong to a set different from the secondary distributed piece B. For example, in Figure 4, the management device 2 stores in the external storage device 3 secondary distributed piece C, out of secondary distributed pieces C and D of the set generated in the second division. As will be described later, the secondary distributed piece C will be used to restore the original information the next time (second time).

[0024] 5 is an explanatory diagram of the process of restoring the original information. The process of restoring the original information from the primary distributed pieces and the secondary distributed pieces will be described with reference to FIG.

[0025] When an external storage device 3 is connected, the restoration device 1 acquires secondary dispersion pieces from the external storage device 3. Specifically, the restoration device 1 acquires secondary dispersion pieces B that can be combined with secondary dispersion pieces A stored in the auxiliary storage unit 17 to restore primary dispersion pieces Y, and secondary dispersion pieces C that have been divided in a pattern different from that of secondary dispersion pieces B and are to be used for the next restoration. Note that the restoration device 1 may simply acquire secondary dispersion pieces B and C without particularly identifying their types. The restoration device 1 may also temporarily store the acquired secondary dispersion pieces B and C in the auxiliary storage unit 17.

[0026] The restoration device 1 restores the original information based on the primary distribution piece X and secondary distribution piece A stored in the auxiliary memory unit 17 and the secondary distribution piece B acquired from the external storage device 3. That is, the restoration device 1 restores the primary distribution piece Y based on the secondary distribution pieces A and B, and restores the original information based on the restored primary distribution piece Y and the primary distribution piece X stored in the auxiliary memory unit 17. Note that during this restoration, the restoration device 1 may attempt restoration using the secondary distribution pieces (B and C) acquired from the external storage device 3 in sequence (i.e., a brute force approach for the acquired secondary distribution pieces). As mentioned above, only secondary distribution piece B can be restored in combination with secondary distribution piece A, so in either case, primary distribution piece Y is restored from secondary distribution pieces A and B.

[0027] For example, if the external storage device 3 is disconnected, the restoration device 1 deletes the secondary distributed pieces A (and B) used for the current restoration from the auxiliary storage unit 17. At this time, the restoration device 1 may also delete the original information. The restoration device 1 also stores the secondary distributed piece C obtained from the external storage device 3 in the auxiliary storage unit 17. Furthermore, the restoration device 1 deletes the secondary distributed pieces B and C from the external storage device 3.

[0028] In addition to the above operations, the secondary distributed pieces stored in the restoration device 1 are deleted when a predetermined condition set in advance is met. The predetermined condition is, for example, the passage of a predetermined time. For example, the restoration device 1 deletes secondary distributed pieces A (and B) from the auxiliary storage unit 17 when a predetermined time has passed since the previous restoration of the original information.

[0029] The condition for deleting the secondary dispersed pieces is not limited to the passage of time. For example, the restoration device 1 may delete the secondary dispersed pieces when a measurement value measured by a predetermined built-in sensor exceeds a threshold value. For example, the restoration device 1 may delete the secondary dispersed pieces when it detects an action such as a fall by comparing the acceleration measured by an acceleration sensor with a threshold value.

[0030] The external storage device 3 is reconnected to the management device 2 by the user. When the external storage device 3 is reconnected, the management device 2 re-stores the secondary distribution pieces in the external storage device 3. For example, the management device 2 stores which secondary distribution pieces were most recently downloaded to the restoration device 1 and the external storage device 3, and stores in the external storage device 3 secondary distribution pieces D that correspond to secondary distribution pieces (here, secondary distribution piece C) that cannot be used for restoration (i.e., do not form a set) among the stored secondary distribution pieces. Alternatively, the management device 2 communicates with the restoration device 1 and stores in the external storage device 3 secondary distribution pieces D that belong to the same set as the secondary distribution piece (here, secondary distribution piece C) stored in the restoration device 1. The management device 2 also stores in the external storage device 3 secondary distribution pieces that belong to a different set from secondary distribution piece D (secondary distribution piece E in the example of Figure 5).

[0031] Here, the management device 2 may reuse a secondary distribution piece (e.g., secondary distribution piece A or B) that has been downloaded to the restoration device 1 or the external storage device 3, as long as it belongs to a different set from secondary distribution piece D, or may not reuse it. If secondary distribution pieces can be reused, for example, the management device 2 may randomly identify a set from among the sets different from secondary distribution piece D to be downloaded to the external storage device 3 this time. In this case, it is sufficient to store one or more, but not all, of the secondary distribution pieces included in the identified set in the external storage device 3. On the other hand, if secondary distribution pieces are not reused, the management device 2 may assign an index to each set of secondary distribution pieces and store the index corresponding to the set of secondary distribution pieces downloaded to the external storage device 3. The management device 2 may then determine the secondary distribution pieces to be downloaded to the external storage device 3 in accordance with the order of the indexes.

[0032] When the external storage device 3 storing the secondary distribution pieces D and E is reconnected, the restoration device 1 retrieves the secondary distribution pieces D and E from the external storage device 3. The subsequent processing is the same as above, and the restoration device 1 restores the original information based on the primary distribution piece X and secondary distribution piece C stored in the auxiliary storage unit 17 and the secondary distribution piece D retrieved from the external storage device 3. When the connection to the external storage device 3 is disconnected, the restoration device 1 deletes the secondary distribution piece C from the auxiliary storage unit 17 and stores the secondary distribution piece E to be used for the next restoration in the auxiliary storage unit 17. The restoration device 1 also deletes the secondary distribution pieces D and E from the external storage device 3.

[0033] In this way, the restoration device 1 obtains the secondary distributed fragments from the external storage device 3 and combines them with the primary distributed fragments and secondary distributed fragments stored in the auxiliary storage unit 17 to restore the original information. As a result, the original information cannot be restored unless the restoration device 1 and the external storage device 3 are present. Furthermore, because the secondary distributed fragments on the restoration device 1 are deleted periodically, even if the restoration device 1 and the external storage device 3 are lost or stolen at the same time, the original information cannot be restored. As a result, information leakage can be prevented.

[0034] 6 is a flowchart showing the procedure for the process of generating shares. The process of generating multiple shares by dividing original information using a secret sharing scheme will be described with reference to FIG. 6. The control unit 21 of the management device 2 generates multiple primary shares by dividing the original information using a secret sharing scheme (step S11). The control unit 21 further divides some of the generated primary shares by using the secret sharing scheme to generate multiple secondary shares (step S12). In step S12, the control unit 21 generates secondary shares multiple times using different division patterns. The management device 2 stores the primary shares and secondary shares generated from the original information.

[0035] The control unit 21 transmits the primary dispersion pieces that were not used to generate the secondary dispersion pieces in step S12, out of the multiple primary dispersion pieces generated in step S11, to the restoration device 1 and stores them (step S13). The control unit 21 transmits a portion of the secondary dispersion pieces divided according to a certain division pattern (first division pattern) to the restoration device 1 and stores them (step S14). The control unit 21 stores the remaining secondary dispersion pieces divided according to that division pattern and a portion of the secondary dispersion pieces divided according to a pattern different from the secondary dispersion pieces in the external storage device 3 (step S15), and ends the series of processes.

[0036] 7 is a flowchart showing the steps of the process for restoring original information. The process performed by the restoration device 1 when restoring original information from distributed pieces will be described with reference to FIG. 7. When the external storage device 3 is connected, the control unit 11 of the restoration device 1 acquires secondary distributed pieces from the external storage device 3 (step S31). Specifically, the control unit 11 acquires, from the external storage device 3, distributed pieces corresponding to the secondary distributed pieces stored in the auxiliary storage unit 17 (i.e., secondary distributed pieces in the same set as the secondary distributed piece), and secondary distributed pieces belonging to a different set from the secondary distributed piece.

[0037] The control unit 11 restores the original information based on the primary distributed pieces and secondary distributed pieces stored in the auxiliary memory unit 17 and the secondary distributed pieces acquired from the external storage device 3 (step S32). That is, the control unit 11 restores the primary distributed pieces based on the secondary distributed pieces stored in the auxiliary memory unit 17 and the secondary distributed pieces acquired from the external storage device 3, and restores the original information based on the restored primary distributed pieces and the primary distributed pieces stored in the auxiliary memory unit 17.

[0038] For example, when the external storage device 3 is disconnected, the control unit 11 deletes the secondary distributed pieces used in the current restoration from the auxiliary storage unit 17 (step S33). The control unit 11 stores the secondary distributed pieces not used in the restoration, among the secondary distributed pieces obtained from the external storage device 3, in the auxiliary storage unit 17 (step S34). The control unit 11 deletes the secondary distributed pieces from the external storage device 3 (step S35), and ends the series of processes. Note that the restoration device 1 may delete the original information either before or after step S35.

[0039] In the above, it is assumed that the restoration device 1 obtains all secondary distributed pieces from the external storage device 3, but this embodiment is not limited to this. For example, the restoration device 1 may send a request to the management device 2 and obtain from the management device 2 the secondary distributed pieces to be used in the next restoration. In this case, the management device 2 sends some of the secondary distributed pieces to be used in the next restoration to the restoration device 1 in response to the request from the restoration device 1. The management device 2 may decide which set of secondary distributed pieces to use in the next restoration in the restoration device 1. In this way, the restoration device 1 only needs to be able to obtain the secondary distributed pieces to be used in the next restoration, and the source of these pieces is not limited to the external storage device 3.

[0040] As described above, according to the first embodiment, it is possible to prevent information leakage.

[0041] (Embodiment 2) In this embodiment, when the original information is updatable data and the original information is updated by reading, writing, etc., a form will be described in which the updated original information (hereinafter referred to as "second original information") is protected. Note that the same reference numerals will be used to designate the same contents as in Embodiment 1, and descriptions thereof will be omitted.

[0042] Fig. 8 is an explanatory diagram showing an outline of embodiment 2. The outline of this embodiment will be described based on Fig. 8. Note that the method of dividing the primary dispersion pieces and secondary dispersion pieces in the example of Fig. 8 is the same as in Fig. 4.

[0043] As in embodiment 1, the restoration device 1 stores primary distributed pieces X, which are obtained by dividing the original information, and secondary distributed pieces A, which are obtained by further dividing the remaining primary distributed pieces Y. When an external storage device 3 is connected, the restoration device 1 acquires secondary distributed pieces B (and C), and combines them with the primary distributed pieces X and secondary distributed pieces A stored in the auxiliary storage unit 17 to restore the original information.

[0044] Now, consider the case where the original information is updatable information (e.g., a document file). In this case, even if the primary and secondary distributed fragments stored in the restoration device 1 are combined with the secondary distributed fragments stored in the external storage device 3, only the original information before the update can be restored, and the second original information after the update cannot be restored. Therefore, in this embodiment, difference information is stored that indicates the difference between the original information when the external storage device 3 is connected (e.g., when mounted) and the second original information when the external storage device 3 is disconnected (e.g., when unmounted), and the second original information is restored based on the original information and the difference information.

[0045] For example, the primary shared piece X includes an encryption key (common key). Note that if the shared pieces split using the secret sharing method include some kind of encryption key (e.g., a common key, a public key, and a private key), the encryption key can only be extracted when the original information is restored from the shared pieces that include that encryption key. This also applies to the following embodiments. When the original information is restored, the restoration device 1 extracts the encryption key included in the primary shared piece X from the restored original information and copies it to the main memory unit 12 (volatile memory area).

[0046] When the external storage device 3 is disconnected, the restoration device 1 encrypts, with an encryption key, difference information D1 between the original information before the update and the second original information after the update. The restoration device 1 stores the encrypted difference information in the auxiliary storage unit 17 and deletes the encryption key from the main storage unit 12.

[0047] When the external storage device 3 is reconnected, the restoration device 1 obtains the secondary distributed pieces D (and E) from the external storage device 3 and combines them with the primary distributed pieces X and secondary distributed pieces C stored in the auxiliary storage unit 17 to restore the original information. The restoration device 1 extracts an encryption key from the restored original information. The restoration device 1 then decrypts the differential information D1 stored in the auxiliary storage unit 17 using the encryption key. The restoration device 1 restores the second original information based on the restored original information and the decrypted differential information D1.

[0048] Similarly, when the external storage device 3 is disconnected, the restoration device 1 encrypts and stores the differential information D2 of the latest update, and uses the differential information D2 to restore the second original information the next time the original information is restored.

[0049] 9 is a flowchart showing the steps of the restoration process of original information according to the second embodiment. After acquiring secondary shared pieces from the external storage device 3 (step S31) and combining them with the primary shared pieces and the secondary shared pieces stored in the auxiliary storage unit 17 to restore the original information (step S32), the restoration device 1 executes the following process. The control unit 11 of the restoration device 1 extracts an encryption key (common key) included in the primary shared pieces from the restored original information and copies it to the main storage unit 12 (step S201). The control unit 11 uses the encryption key to decrypt difference information indicating the difference between the original information and the second shared piece used to previously update the original information (step S202). The control unit 11 restores the second shared piece based on the original information restored in step S32 and the difference information decrypted in step S202 (step S203).

[0050] The control unit 11 updates the second element information in response to an operation input from the user (step S204). The control unit 11 encrypts the difference information obtained at this time of update using the encryption key extracted in step S201 (step S205). The control unit 11 stores the encrypted difference information in the auxiliary storage unit 17 (step S206). The control unit 11 deletes the encryption key from the main storage unit 12 (step S207) and proceeds to step S33.

[0051] As described above, according to the second embodiment, it is possible to prevent information leakage even when the original information is updated.

[0052] Third Embodiment In this embodiment, a description will be given of an embodiment in which the second element information is dynamically protected by dividing the element information every time the element information is updated.

[0053] 10 is an explanatory diagram showing an outline of the third embodiment. The outline of this embodiment will be described with reference to FIG.

[0054] As in the second embodiment, consider a case where the original information can be updated. In this embodiment, when the original information is updated, the restoration device 1 divides the second original information resulting from the update of the original information into at least three or more distributed pieces. The restoration device 1 then stores some of the distributed pieces and stores the remaining distributed pieces in the external storage device 3. When the external storage device 3 is reconnected, the second original information is restored from these distributed pieces.

[0055] For example, as in embodiment 1, the management device 2 stores in the restoration device 1 primary distributed pieces A obtained by dividing the original information and secondary distributed pieces A obtained by further dividing primary distributed pieces Y. The management device 2 also stores in the external storage device 3 secondary distributed pieces B that can be combined with the secondary distributed pieces A stored in the restoration device 1 to restore primary distributed pieces Y. In the example of Figure 10, the management device 2 only needs to generate primary distributed pieces X and Y, and secondary distributed pieces A and B from primary distributed piece Y, among the distributed pieces shown in Figure 4, and may or may not generate secondary distributed pieces from secondary distributed piece C onwards.

[0056] When the external storage device 3 is connected, the restoration device 1 acquires the secondary distributed piece B from the external storage device 3 and restores the original information by combining it with the primary distributed piece X and the secondary distributed piece A stored in the auxiliary storage unit 17. The original information is then updated in accordance with operational input by the user, etc.

[0057] The restoration device 1 divides the updated second original information into multiple primary distributed pieces X' and Y' at a predetermined timing, for example, when the external storage device 3 is disconnected, when the user instructs the external storage device 3 to be disconnected, when the update of the original information is confirmed, or when the file of the updated original information is closed. Furthermore, the restoration device 1 divides the primary distributed piece Y' into multiple secondary distributed pieces A' and B'. The restoration device 1 deletes the primary distributed piece X and the secondary distributed piece A used to restore the original information from the auxiliary storage unit 17, and stores the newly generated primary distributed piece X' and the secondary distributed piece A' in the auxiliary storage unit 17. Furthermore, the restoration device 1 deletes the secondary distributed piece B used to restore the original information from the external storage device 3, and stores the newly generated secondary distributed piece B' in the external storage device 3.

[0058] When the external storage device 3 is reconnected, the restoration device 1 restores the second element information based on the primary distributed piece X' and secondary distributed piece A' stored in the auxiliary storage unit 17 and the secondary distributed piece B' stored in the external storage device 3. In this way, each time the original information is updated, the updated second element information is divided into multiple distributed pieces and stored in the restoration device 1 and the external storage device 3, thereby dynamically protecting the information.

[0059] Figure 11 is a flowchart showing the steps of the restoration process for original information according to embodiment 3. The processing executed by the restoration device 1 will be described with reference to Figure 11. When an external storage device 3 is connected, the control unit 11 of the restoration device 1 acquires from the external storage device 3 secondary distributed pieces that can be combined with the secondary distributed pieces stored in the auxiliary storage unit 17 to restore the primary distributed pieces (step S301). The control unit 11 restores the original information based on the primary distributed pieces and secondary distributed pieces stored in the auxiliary storage unit 17 and the secondary distributed pieces acquired from the external storage device 3 (step S302).

[0060] The control unit 11 updates the raw information to second raw information in response to an operation input from the user or the like (step S303).

[0061] Next, at the predetermined timing described above, the control unit 11 divides the second information into a plurality of primary shared pieces using the secret sharing scheme (step S304), and further divides some of the generated primary shared pieces into a plurality of secondary shared pieces (step S305).

[0062] The control unit 11 deletes the primary distributed pieces and secondary distributed pieces used to restore the original information in step S302 from the auxiliary storage unit 17 (step S306). The control unit 11 stores, in the auxiliary storage unit 17, the primary distributed pieces that were not used to generate the secondary distributed pieces, among the primary distributed pieces generated in step S304, and some of the secondary distributed pieces generated in step S305 (step S307).

[0063] The control unit 11 deletes the secondary dispersion pieces from the external storage device 3 (step S308). The control unit 11 stores in the external storage device 3 the secondary dispersion pieces that can be combined with the secondary dispersion pieces stored in the auxiliary storage unit 17 in step S307 to restore the primary dispersion pieces, from among the secondary dispersion pieces generated in step S305 (step S309), and ends the series of processes.

[0064] As described above, according to the third embodiment, the second element information can be dynamically protected by dividing the second element information one by one.

[0065] Fourth Embodiment In this embodiment, a description will be given of an embodiment in which secondary distributed pieces are encrypted and stored in the restoration device 1, and the secondary distributed pieces are decrypted when the original information is restored.

[0066] Fig. 12 is an explanatory diagram showing an overview of the fourth embodiment. The overview of this embodiment will be described with reference to Fig. 12. The information processing system according to this embodiment includes a mobile terminal 4 in addition to the various devices shown in Fig. 1. The mobile terminal 4 can be realized by, for example, a smartphone.

[0067] As in the first embodiment, the management device 2 stores in the restoration device 1 primary distributed pieces X, which are obtained by dividing the original information, and secondary distributed pieces A, which are obtained by further dividing the primary distributed pieces Y. In this case, the management device 2 encrypts the secondary distributed pieces A using the encryption key (public key) included in the primary distributed piece X, and then stores them in the restoration device 1.

[0068] The "Protection Status" row at the top of Figure 12 shows the state of various data before the external storage device 3 is connected to the restoration device 1. As shown in the figure, secondary distribution piece A is stored in an encrypted state in the restoration device 1, and the external storage device 3 is connected to the restoration device 1 in this state. The "Restoration Status" row at the top of Figure 12 shows the state of various processes and data after the restoration device 1 acquires secondary distribution pieces B (and C) from the external storage device 3. When the external storage device 3 is connected, the restoration device 1 acquires secondary distribution pieces B (and C) from the external storage device 3. Here, the data necessary to restore the original information (primary distribution piece X, secondary distribution pieces A and B) are all present in the restoration device 1, but secondary distribution piece A is in an encrypted state. Therefore, the restoration device 1 decrypts this secondary distribution piece A with a private key. The restoration device 1 according to this embodiment acquires the private key via the mobile terminal 4. Note that the timing of acquiring the private key is not particularly limited. For example, the restoration device 1 may acquire the private key between the time the external storage device 3 is connected and the time before the original information restoration process is performed.

[0069] The portable terminal 4 performs authentication based on authentication information in advance or upon receiving a request from the restoration device 1. Here, the authentication information is, for example, the user's biometric information, location information, etc. In order to enhance security, this authentication is preferably authentication based on two or more pieces of authentication information (multi-factor authentication). Note that the authentication process may be executed by the restoration device 1 instead of the portable terminal 4. Also, the content of the authentication process based on the authentication information may be publicly known. For example, authentication may be performed using a function (face authentication, fingerprint authentication, password authentication, etc.) that is pre-installed as a function of the portable terminal 4 (or the restoration device 1) itself.

[0070] If authentication on the mobile terminal 4 is successful, the mobile terminal 4 obtains a private key corresponding to the public key contained in primary share piece A from the management device 2 (or the cloud). The mobile terminal 4 transmits the obtained private key to the restoration device 1. The restoration device 1 decrypts secondary share piece A using the private key. The restoration device 1 restores the original information based on primary share piece X stored in the auxiliary memory unit 17, the decrypted secondary share piece A, and secondary share piece B obtained from the external storage device 3. The restoration device 1 deletes the private key from the main memory unit 12.

[0071] In this embodiment, the private key is obtained from the management device 2, but the private key may be managed (stored) in a memory unit of the mobile terminal 4, and the mobile terminal 4 may authenticate itself, and if the authentication is successful, send the private key to the restoration device 1.

[0072] The "Restoration Status" row at the bottom of Figure 12 shows the state of the data after secondary share piece A has been decrypted and the original information has been restored. In this state, if the external storage device 3 is disconnected from the restoration device 1, the restoration device 1 deletes secondary share pieces A and B from the auxiliary storage unit 17. Furthermore, at a predetermined timing, such as when the restoration device 1 is disconnected from the external storage device 3, the restoration device 1 extracts the public key from the restored original information and encrypts secondary share piece C, which will be used for the next restoration, with the public key. The "Protection Status" row at the bottom of Figure 12 shows the state of the data after secondary share piece C has been encrypted. The restoration device 1 stores the encrypted secondary share piece C in the auxiliary storage unit 17. The restoration device 1 deletes the public key from the main storage unit 12. The original information may also be deleted at this time.

[0073] The subsequent processing is the same as above, and when the external storage device 3 is reconnected, the restoration device 1 acquires secondary share pieces D and E, decrypts secondary share piece C using the private key obtained from the mobile terminal 4, and restores the original information by combining it with primary share piece X stored in the auxiliary storage unit 17 and secondary share piece D acquired from the external storage device 3. Then, at the predetermined timing mentioned above, secondary share piece E is encrypted using the public key.

[0074] Even if the external storage device 3 is connected, the restoration device 1 may encrypt the secondary distributed pieces if a predetermined condition (for example, the passage of a predetermined time) is met. At this time, the restoration device 1 may also delete the original information. This makes it possible to prevent a third party from viewing the original information, even in cases where the external storage device 3 is left connected for a long period of time.

[0075] As described above, in this embodiment, the secondary distributed pieces are encrypted and stored in the restoration device 1, and the secondary distributed pieces are decrypted when the original information is restored. This makes it possible to more effectively prevent information leakage.

[0076] Fig. 13 is a flowchart showing the steps of the process of restoring original information according to embodiment 4. The process of restoring original information in this embodiment will be described with reference to Fig. 13. When an external storage device 3 is connected, the control unit 11 of the restoration device 1 acquires, from the external storage device 3, secondary distributed pieces that belong to the same set as the secondary distributed pieces stored in the auxiliary storage unit 17, and secondary distributed pieces that belong to a different set from the secondary distributed pieces (step S401).

[0077] If authentication based on the authentication information is successful, the control unit 11 obtains a private key from the management device 2 (step S402). The control unit 11 decrypts the encrypted secondary share pieces stored in the auxiliary memory unit 17 using the private key (step S403). The control unit 11 restores the original information based on the primary share pieces stored in the auxiliary memory unit 17, the secondary share pieces decrypted in step S403, and the secondary share pieces obtained in step S401 (step S404). The control unit 11 deletes the private key from the main memory unit 12 (step S405).

[0078] At a predetermined timing, such as when the external storage device 3 is disconnected, the control unit 11 extracts the public key contained in the primary shared fragment from the restored original information and copies it to the main memory unit 12 (step S406). The control unit 11 uses this copied public key to encrypt the secondary shared fragment to be used in the next restoration (i.e., the secondary shared fragment not used in the current restoration) (step S407). The control unit 11 deletes the secondary shared fragment used in the current restoration from the auxiliary memory unit 17 (step S408). The control unit 11 stores the encrypted secondary shared fragment in the auxiliary memory unit 17 (step S409).

[0079] The control unit 11 deletes the replicated public key from the main storage unit 12 (step S410). The control unit 11 deletes the secondary distributed pieces from the external storage device 3 (step S411), and ends the series of processes.

[0080] As described above, according to the fourth embodiment, information leakage can be prevented more suitably.

[0081] Fifth Embodiment In this embodiment, a form will be described in which, before encrypting secondary distributed pieces, it is confirmed (determined) whether or not the original information can be restored even if it is encrypted.

[0082] 14 is an explanatory diagram showing an outline of the fifth embodiment. The outline of this embodiment will be described with reference to FIG.

[0083] The "Protection Status" row at the top of Figure 14 shows the state of various data before the external storage device 3 is connected to the restoration device 1. As shown in the figure, secondary distribution fragment A is stored in an encrypted state in the restoration device 1, and the external storage device 3 is connected to the restoration device 1 in this state. As in embodiment 4, when the external storage device 3 is connected, the restoration device 1 obtains secondary distribution fragments B and C from the external storage device 3.

[0084] The "Restoration Status" row in Figure 14 shows the state of various processes and data after the restoration device 1 acquires secondary share pieces B and C from the external storage device 3. For example, after connecting the external storage device 3, the restoration device 1 acquires a private key from the mobile terminal 4. As shown in the figure, the mobile terminal 4 acquired this private key in advance from the management device 2 or upon receiving a request from the restoration device 1. The mobile terminal 4 can acquire the private key from the management device 2 in response to the authentication result based on the authentication information (i.e., if authentication is successful). When the restoration device 1 acquires the private key from the mobile terminal 4 and acquires secondary share pieces B and C, it uses the private key to decrypt secondary share piece A. The restoration device 1 then restores the original information based on primary share piece X stored in the auxiliary storage unit 17, the decrypted secondary share piece A, and the acquired secondary share piece B. In this case, as described in embodiment 4, when a predetermined condition (e.g., a predetermined time has passed since the original information was restored) is met, the restoration device 1 encrypts secondary share piece C using the public key included in primary share piece X. At this time, the restoration device 1 may delete the original information.

[0085] In this embodiment, before encrypting the secondary distributed pieces C, the restoration device 1 determines whether or not the original information can be restored even if the secondary distributed pieces C are encrypted. For example, the restoration device 1 determines whether or not it is possible to communicate with the management device 2 that manages the private key, i.e., whether or not it is possible to obtain the private key necessary to decrypt the secondary distributed pieces C.

[0086] If it is determined that the original information can be restored, the restoration device 1 encrypts the secondary distributed piece C. The "Protection Status" row at the bottom of Figure 14 shows the state of the data after encryption of the secondary distributed piece C. If it is determined that the original information can be restored, the secondary distributed pieces A and B may be deleted from the restoration device 1. On the other hand, if it is determined that the original information cannot be restored, the restoration device 1 does not encrypt the secondary distributed piece C, and makes another determination after a certain period of time. This "certain period of time" may be the same as the elapsed time ("predetermined period of time") described above, or it may be different. If it is determined that the original information can be restored as a result of making another determination after the certain period of time, the restoration device 1 encrypts the secondary distributed piece C. The original information may also be deleted at this time.

[0087] As described above, the restoration device 1 checks whether the original information can be restored before encrypting the secondary distributed pieces. This prevents situations such as the expiration date expiring while the Internet is unavailable, such as while on an airplane, making it impossible to access the original information.

[0088] Figure 15 is a flowchart showing the steps of the encryption process for secondary distributed pieces according to embodiment 5. The judgment process when encrypting secondary distributed pieces will be described with reference to Figure 15. The process of this flowchart is executed, for example, when an external storage device 3 is connected to the restoration device 1. The control unit 11 of the restoration device 1 judges whether a predetermined condition set in advance is met (step S501). The predetermined condition is, for example, the passage of a predetermined time since the external storage device 3 was connected to the restoration device 1. If it is determined that the predetermined condition is not met (S501: NO), the control unit 11 puts the process on hold.

[0089] If it is determined that the predetermined conditions are met (S501: YES), the control unit 11 determines whether the original information can be restored (step S502). Specifically, the control unit 11 determines whether it is possible to communicate with the management device 2 that manages the private key. If it is determined that the original information can be restored (S502: YES), the control unit 11 restores the original information, extracts the public key, encrypts the secondary shared pieces using the public key included in the primary shared pieces, and stores them in the auxiliary storage unit 17 (step S503), thereby ending the series of processes. At this time, the original information may be deleted.

[0090] If it is determined that the original information cannot be restored (S502: NO), the control unit 11 determines whether a certain time has elapsed (step S504). If it is determined that the certain time has not elapsed (S504: NO), the control unit 11 puts the processing on hold. If it is determined that the certain time has elapsed (S504: YES), the control unit 11 returns the processing to step S502. In this case, the control unit 11 again determines whether the original information can be restored (step S502), and if it is determined that the original information can be restored, it encrypts the secondary distributed pieces (step S503).

[0091] As described above, according to the fifth embodiment, the encryption of secondary distributed pieces can be suitably performed. Note that the timing of performing the processing of the flowchart shown in FIG. 15 is not limited to the timing when the external storage device 3 is connected. The flowchart shown in FIG. 15 may be performed as appropriate depending on the content of the predetermined condition determined in S501. Furthermore, the various processing shown in FIG. 15 may be performed in parallel with the processing of the restoration device 1 described in the previous drawings and in this specification.

[0092] (Variation 1) In the fifth embodiment, a form has been described in which, when a secondary distributed piece is encrypted by satisfying a predetermined condition (for example, the passage of a predetermined time), it is confirmed whether the original information can be restored. On the other hand, this embodiment may also be applied to a case in which a secondary distributed piece is deleted by satisfying a predetermined condition.

[0093] That is, when the restoration device 1 deletes secondary distributed pieces by satisfying predetermined conditions set in advance, it determines whether the original information can be restored. For example, if an external storage device 3 is connected to the restoration device 1, it determines whether secondary distributed pieces that can be combined with the secondary distributed pieces stored in the auxiliary storage unit 17 to restore the primary distributed pieces can be obtained from the external storage device 3. If it determines that the original information can be restored, the restoration device 1 deletes the secondary distributed pieces stored in the auxiliary storage unit 17.

[0094] On the other hand, if it is determined that the original information cannot be restored, the restoration device 1 does not delete the secondary distributed pieces, and makes another determination after a certain period of time. If it is determined that the original information can be restored as a result of making the determination again after the certain period of time, the restoration device 1 deletes the secondary distributed pieces stored in the auxiliary memory unit 17.

[0095] In this way, the fifth embodiment can also be applied to the case where secondary distributed pieces are deleted. Since this modification is the same as the fifth embodiment except that the secondary distributed pieces are deleted instead of encrypted, detailed explanations of the flowchart and other details will be omitted in this modification.

[0096] (Variation 2) In the fifth embodiment and variation 1, a configuration has been described in which it is confirmed whether the original information can be restored before encrypting or deleting the secondary distributed pieces. This embodiment may also be applied to a configuration in which the original information is updated as described in the second and third embodiments.

[0097] That is, when the restoration device 1 encrypts or deletes secondary distributed pieces by satisfying a predetermined condition, the restoration device 1 may determine whether the second original information (the updated original information) can be restored. If it determines that the second original information can be restored, the restoration device 1 encrypts or deletes the secondary distributed pieces stored in the auxiliary storage unit 17. On the other hand, if it determines that the second original information cannot be restored, the restoration device 1 does not encrypt or delete the secondary distributed pieces, and makes another determination after a certain period of time.

[0098] In this way, the fifth embodiment can also be applied to cases where the original information is updatable information.

[0099] (Variation 3) In embodiment 4, the encryption key may be stored in a device other than the management device 2. The mobile terminal 4 may then obtain the encryption key by communicating with the other device. In this case as well, authentication of the mobile terminal 4 is performed in the mobile terminal 4 and / or the other device. If the authentication is successful, the encryption key is transmitted from the other device to the mobile terminal 4. Similarly, the private key in embodiment 5 may be stored in a device other than the management device 2. The same applies to variations 1 and 2. Note that the other device does not necessarily refer to a single physical device, but may be, for example, cloud storage or the like.

[0100] (Variation 4) In embodiments 4 and 5, the external storage device 3 may be the same device as the mobile terminal 4. In this case, the external storage device 3 may perform authentication to acquire the private key and acquire the private key in advance based on user instructions, etc. Then, when the external storage device 3 connects to the restoration device 1, it may transmit the private key to the restoration device 1 along with the secondary shared pieces (for example, secondary shared pieces B and C in embodiment 4). (Variation 5) Embodiments 4 and 5 can also be applied when the original information is updatable information, as in embodiment 2 or 3. When embodiment 4 or 5 is combined with embodiment 2 or 3, the generation, deletion, and movement of data in the primary shared pieces and secondary shared pieces shall be similar to embodiment 2 or 3. Furthermore, authentication by the mobile terminal 4 and the method of acquiring the private key of the restoration device 1 shall be similar to embodiment 4 or 5. In addition, in the case of embodiment 4 or 5, the secondary distribution fragment that the restoration device 1 encrypts is the secondary distribution fragment obtained from the external storage device 3 that was not used to restore the original information (for example, secondary distribution fragment C in Figure 12 or Figure 14).

[0101] The embodiments disclosed herein are illustrative in all respects and should not be considered limiting. The scope of the present invention is defined by the claims, not by the above meaning, and is intended to include all modifications within the meaning and scope of the claims.

[0102] The matters described in each embodiment can be combined with each other. Furthermore, the independent claims and dependent claims described in the claims can be combined with each other in any combination, regardless of the reference format. Furthermore, the claims use a format in which a claim references two or more other claims (multiple claim format), but this is not limited to this. A multiple claim (multi-multi claim) that references at least one other multiple claim may also be used.

[0103] REFERENCE SIGNS LIST 1 Restoration device 11 Control unit 12 Main memory unit 13 Communication unit 14 Display unit 15 Operation unit 16 Input / output unit 17 Auxiliary memory unit 2 Management device 21 Control unit 22 Main memory unit 23 Communication unit 24 Auxiliary memory unit 3 External storage device 4 Mobile terminal

Claims

1. An information processing method in which a computer executes the following processes: storing in a memory unit a portion of primary shared pieces obtained by dividing original information using a secret sharing method, and a portion of secondary shared pieces obtained by further dividing the remaining primary shared pieces other than the portion of primary shared pieces using a secret sharing method; acquiring the remaining secondary shared pieces from an external storage device that stores the remaining secondary shared pieces other than the portion of secondary shared pieces; and restoring the original information based on the primary shared pieces and secondary shared pieces stored in the memory unit and the secondary shared pieces acquired from the external storage device.

2. The process of dividing the remaining primary distribution pieces into secondary distribution pieces is executed multiple times in different patterns, and if the secondary distribution pieces generated each time are considered to be one set, the remaining primary distribution pieces can be restored when all of the one set of secondary distribution pieces are collected; the external storage device stores secondary distribution pieces of the same set as the secondary distribution pieces stored in the memory unit and some of the secondary distribution pieces of a different set from the secondary distribution pieces; the secondary distribution pieces of the same set and the secondary distribution pieces of the different set are acquired from the external storage device; the secondary distribution pieces of the same set and the secondary distribution pieces of the different set are deleted from the external storage device; after the original information is restored, the secondary distribution pieces used for the restoration are deleted from the memory unit; and the secondary distribution pieces of the different set are stored in the memory unit. An information processing method as described in claim 1.

3. The information processing method according to claim 2, further comprising storing in the external storage device secondary dispersion pieces of the same set as the different set of secondary dispersion pieces stored in the storage unit.

4. An information processing method according to any one of claims 1 to 3, wherein the original information is updatable information, the primary distributed fragments stored in the memory unit include an encryption key, and when the original information is restored, the encryption key is extracted from the restored original information, difference information indicating the difference between the original information before the update and the original information after the update is encrypted using the encryption key, the encrypted difference information is stored in the memory unit, and the extracted encryption key is deleted.

5. The information processing method of claim 4, further comprising the steps of: restoring the original information before the update based on the primary distributed fragments and secondary distributed fragments stored in the memory unit and the secondary distributed fragments obtained from the external storage device; extracting the encryption key contained in the primary distributed fragments from the original information; decrypting the differential information using the encryption key; and restoring the original information after the update from the original information before the update and the decrypted differential information.

6. An information processing method according to any one of claims 1 to 5, wherein the original information is information that can be updated, the updated original information is divided into primary distributed pieces and secondary distributed pieces that are further divided from a portion of the primary distributed pieces, a portion of the primary distributed pieces and a portion of the secondary distributed pieces are stored in the memory unit, a secondary distributed piece that can be combined with the secondary distributed piece stored in the memory unit to restore the primary distributed piece is stored in the external storage device, when the external storage device is reconnected, the secondary distributed piece is obtained from the external storage device, the updated original information is restored based on the primary distributed pieces and secondary distributed pieces stored in the memory unit and the secondary distributed piece obtained from the external storage device, and the secondary distributed piece stored in the external storage device is deleted.

7. The information processing method according to any one of claims 1 to 6, further comprising the step of deleting the secondary dispersion pieces stored in the memory unit when a predetermined condition set in advance is satisfied.

8. The information processing method according to claim 7, wherein when deleting the secondary distributed pieces stored in the memory unit, it is determined whether the original information can be restored, and if it is determined that restoration is possible, the secondary distributed pieces stored in the memory unit are deleted, and if it is determined that restoration is not possible, a determination is made again after a certain period of time.

9. The information processing method according to claim 8, further comprising determining that the original information can be restored if the external storage device is connected.

10. An information processing method according to any one of claims 1 to 9, wherein the secondary distributed pieces are stored in the memory unit after being encrypted with an encryption key, and when restoring the original information, the secondary distributed pieces are decrypted with an encryption key obtained in response to an authentication result based on authentication information to restore the original information.

11. The information processing method according to claim 10, wherein when encrypting the secondary distributed pieces, it is determined whether the original information can be restored, and if it is determined that restoration is possible, the secondary distributed pieces are encrypted, and if it is determined that restoration is not possible, a determination is made again after a certain period of time.

12. The information processing method according to claim 11, further comprising determining that the original information can be restored if communication with a device that manages the encryption key is possible.

13. A program that causes a computer to execute the following process: storing in a memory unit a portion of primary distributed pieces obtained by dividing original information using a secret sharing method, and a portion of secondary distributed pieces obtained by further dividing the remaining primary distributed pieces other than the portion of primary distributed pieces using a secret sharing method; acquiring the remaining secondary distributed pieces from an external storage device that stores the remaining secondary distributed pieces other than the portion of secondary distributed pieces; and restoring the original information based on the primary distributed pieces and secondary distributed pieces stored in the memory unit and the secondary distributed pieces acquired from the external storage device.

14. An information processing device having a control unit, wherein the control unit: stores in a memory unit a portion of primary distribution pieces obtained by dividing original information using a secret sharing method and a portion of secondary distribution pieces obtained by further dividing the remaining primary distribution pieces other than the portion of primary distribution pieces using a secret sharing method; acquires the remaining secondary distribution pieces from an external storage device that stores the remaining secondary distribution pieces other than the portion of secondary distribution pieces; and restores the original information based on the primary distribution pieces and secondary distribution pieces stored in the memory unit and the secondary distribution pieces acquired from the external storage device.

15. An information processing method in which a computer executes the following processes: storing in a memory unit a portion of primary shared pieces obtained by dividing original information using a secret sharing method, and a portion of secondary shared pieces obtained by further dividing the remaining primary shared pieces other than the portion of primary shared pieces using a secret sharing method; acquiring the remaining secondary shared pieces from an external storage device that stores the remaining secondary shared pieces other than the portion of secondary shared pieces; restoring the original information based on the primary shared pieces and secondary shared pieces stored in the memory unit and the secondary shared pieces acquired from the external storage device; determining whether or not the original information can be restored if a predetermined condition is satisfied; deleting the secondary shared pieces stored in the memory unit or encrypting the secondary shared pieces with an encryption key if it is determined that the original information is restored; and making a determination again after a certain period of time if it is determined that the original information is not restored.

16. An information processing method executed by a processor of a management device, comprising: generating primary distribution pieces by dividing original information using a secret sharing method; generating secondary distribution pieces by further dividing a portion of the primary distribution pieces using the secret sharing method; generating the secondary distribution pieces multiple times using different division patterns; storing, among the primary distribution pieces, primary distribution pieces that were not used in generating the secondary distribution pieces in a restoration device; storing, in the restoration device, a portion of the secondary distribution pieces divided using a first division pattern; and storing the remainder of the secondary distribution pieces divided using the first division pattern in an external storage device.

17. The information processing method according to claim 16, further comprising the step of sending a portion of the secondary distributed pieces to be used in the next restoration to said restoration device in response to a request from said restoration device.

18. An information processing method according to claim 16 or 17, wherein, when the external storage device is connected, a portion of the secondary dispersion pieces to be used for the next restoration is stored in the external storage device.

Citation Information

Patent Citations

  • System, method and program for managing information

    JP2008098894A

  • Information processor and information processing system

    JP2012203658A

  • Information processing device, server device, information processing program, and server program

    JP2021086276A

  • Key Generation Using Multiple Sets of Secret Shares

    US20130272521A1