Information processing method, program, and information processing device

The information processing method addresses the challenge of preventing information leakage by dividing updated source information into dispersion pieces and restoring it only when the external storage device is connected, ensuring secure storage and deletion of secondary dispersion pieces.

WO2025094965A1PCT designated stage expired Publication Date: 2025-05-08MINEBEAMITSUMI INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/038603
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-31
Filing Date
2024-10-30
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

Existing information protection methods using secret sharing techniques do not effectively prevent information leakage, especially when source information is updated or when external storage devices are disconnected.

Method used

The method involves dividing updated source information into primary and secondary dispersion pieces, storing parts in a storage unit and external storage device, and restoring the original information by combining the stored pieces when the external storage device is connected, while ensuring that the secondary dispersion pieces are deleted from the external storage device to prevent information leakage.

Benefits of technology

This approach effectively prevents information leakage by ensuring that the secondary dispersion pieces are only temporarily stored on the external storage device and are deleted after use, thus maintaining the security of the original information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024038603_08052025_PF_FP_ABST
    Figure JP2024038603_08052025_PF_FP_ABST
Patent Text Reader

Abstract

In this information processing method, a computer executes processing for: dividing second original information, which is information obtained by updating original information which has been restored from split pieces divided via a secret splitting scheme, into primary split pieces and secondary split pieces obtained by further dividing some of the primary split pieces; storing some of the primary split pieces and some of the secondary split pieces in a storage unit; storing the remaining secondary split pieces other than those stored in the storage unit in an external storage device; and, when the external storage device is connected, acquiring the secondary split pieces from the external storage device, restoring the second original information on the basis of the primary split pieces and the secondary split pieces stored in the storage unit and the secondary split pieces acquired from the external storage device, and deleting the secondary split pieces stored on the external storage device.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, program, and information processing device

[0001] The present invention relates to an information processing method, a program, and an information processing device.

[0002] There is a technology for protecting information using a secret sharing scheme. For example, Patent Literature 1 discloses a computer program that uses the secret sharing scheme to distribute secret data into multiple pieces of distributed data and distribute the metadata of a virtual drive that stores the secret data into multiple pieces of distributed metadata, thereby doubly protecting the secret data.

[0003] Japanese Patent Application Laid-Open No. 2017-126321

[0004] In one aspect, an object is to provide an information processing method and the like that can prevent information leakage.

[0005] In one aspect, the information processing method divides second original information, which is information obtained by updating original information restored from distributed fragments divided by a secret sharing method, into primary distributed fragments and secondary distributed fragments obtained by further dividing a portion of the primary distributed fragments, stores a portion of the primary distributed fragments and a portion of the secondary distributed fragments in a memory unit, stores the remaining secondary distributed fragments other than the secondary distributed fragments stored in the memory unit in an external storage device, and when the external storage device is connected, acquires the secondary distributed fragments from the external storage device, restores the second original information based on the primary distributed fragments and secondary distributed fragments stored in the memory unit and the secondary distributed fragments acquired from the external storage device, and deletes the secondary distributed fragments stored in the external storage device, all of which are executed by a computer.

[0006] In one aspect, information leakage can be prevented.

[0007] FIG. 1 is an explanatory diagram showing an example of the configuration of an information processing system. FIG. 2 is a block diagram showing an example of the configuration of a restoration device. FIG. 3 is a block diagram showing an example of the configuration of a management device. FIG. 4 is an explanatory diagram relating to the process of generating distributed pieces. FIG. 5 is an explanatory diagram relating to the process of restoring original information. FIG. 6 is a flowchart showing the procedure of the process of generating distributed pieces. FIG. 7 is a flowchart showing the procedure of the process of restoring original information. FIG. 8 is an explanatory diagram showing an overview of embodiment 2. FIG. 9 is a flowchart showing the procedure of the process of restoring original information relating to embodiment 2. FIG. 10 is an explanatory diagram showing an overview of embodiment 3. FIG. 11 is a flowchart showing the procedure of the process of restoring original information relating to embodiment 3. FIG. 12 is an explanatory diagram showing an overview of embodiment 4. FIG. 13 is a flowchart showing the procedure of the process of restoring original information relating to embodiment 4. FIG. 14 is an explanatory diagram showing an overview of embodiment 5. FIG. 15 is a flowchart showing the procedure of the process of encrypting secondary distributed pieces relating to embodiment 5.

[0008] The present invention will be described in detail below with reference to the drawings showing embodiments. (Embodiment 1) Fig. 1 is an explanatory diagram showing an example of the configuration of an information processing system. In this embodiment, an information processing system is described in which original information to be kept secret is divided into multiple shares using a secret sharing scheme and the multiple shares are combined to restore the original information. The information processing system includes a restoration device 1, a management device 2, and an external storage device 3. The restoration device 1 and the management device 2 are communicatively connected via a network N.

[0009] The restoration device 1 is an information processing device capable of various information processing and information transmission / reception, such as a personal computer, smartphone, or tablet terminal. As described below, the restoration device 1 acquires and stores, in advance from the management device 2, some of the primary shares obtained by dividing the original information using a secret sharing scheme, and some of the secondary shares obtained by further dividing the remaining primary shares using a secret sharing scheme. When an external storage device 3 storing the remaining secondary shares necessary for restoring the original information is connected, the restoration device 1 acquires the secondary shares from the external storage device 3 and restores the original information based on the stored primary shares and secondary shares and the acquired secondary shares. Note that "restoration" in this specification does not mean combining the primary shares and secondary shares themselves (i.e., converting the primary shares and secondary shares into original information), but rather means generating data called "original information" based on the information of the primary shares and secondary shares. Therefore, even after the original information is restored, the data of the primary shares and secondary shares used for the restoration remains.

[0010] The external storage device 3 is a storage device that stores the distributed fragments, such as a USB (Universal Serial Bus) memory. The external storage device 3 is not limited to a USB memory and may be a Secure Drive (SD) card, an Integrated Circuit (IC) card, or the like. The external storage device 3 may also be a device equipped with a processor such as a CPU, such as a smartphone. The external storage device 3 is connected to the management device 2 via a computer (not shown) (or directly), and acquires and stores the secondary distributed fragments from the management device 2. In the following description, unless otherwise specified, the "connection" of the external storage device 3 may refer to an electrical connection or a communication connection. In either case, the external storage device 3 is connected so that data can be downloaded from the management device 2. When the external storage device 3 is connected, the restoration device 1 acquires the secondary distributed fragments from the external storage device 3 and uses them to restore the original information.

[0011] The management device 2 is an information processing device that manages this system, and is, for example, a server computer. The management device 2 generates multiple primary shares by dividing the original information using a secret sharing scheme, and also generates multiple secondary shares by further dividing some of the generated primary shares. The management device 2 stores the primary shares that were not used to generate the secondary shares (i.e., not divided) and some of the secondary shares in the restoration device 1, and stores the remaining secondary shares (secondary shares other than the some of the secondary shares) in the external storage device 3.

[0012] FIG. 2 is a block diagram showing an example configuration of the restoration device 1. The restoration device 1 includes a control unit 11, a main memory unit 12, a communication unit 13, a display unit 14, an operation unit 15, an input / output unit 16, and an auxiliary memory unit 17. The control unit 11 has one or more processors, such as a central processing unit (CPU), a microprocessing unit (MPU), or a graphics processing unit (GPU), and performs various information processing by reading and executing programs stored in the auxiliary memory unit 17. The main memory unit 12 is a temporary storage area, such as a static random access memory (SRAM) or a dynamic random access memory (DRAM), and temporarily stores data necessary for the control unit 11 to execute arithmetic processing. The communication unit 13 is a communication module for performing communication-related processing and transmits and receives information to and from the outside. The display unit 14 is a display screen, such as a liquid crystal display, that displays images. The operation unit 15 is an operation interface, such as a keyboard or a mouse, that accepts operation inputs from a user. The input / output unit 16 is an input / output interface for connecting a portable storage medium (such as the external storage device 3) and accepts connection of the storage medium. The auxiliary storage unit 17 is a non-volatile storage area such as a hard disk, and stores programs (program products) and other data necessary for the control unit 11 to execute processing. The display unit 14 and the operation unit 15 are not essential components. Alternatively, the display unit 14 and the operation unit 15 may be configured as separate devices from the restoration device 1 and connected to the restoration device 1 by wire or wirelessly.

[0013] The restoration device 1 may read and execute a program from a portable storage medium 1a such as a CD (Compact Disk)-ROM or a DVD (Digital Versatile Disk)-ROM.

[0014] 3 is a block diagram showing an example configuration of the management device 2. The management device 2 includes a control unit 21, a main memory unit 22, a communication unit 23, and an auxiliary memory unit 24. The control unit 21 has one or more processors such as CPUs, and performs various information processing by reading and executing programs stored in the auxiliary memory unit 24. The main memory unit 22 is a temporary storage area such as RAM, and temporarily stores data necessary for the control unit 21 to execute arithmetic processing. The communication unit 23 is a communication module for performing communication-related processing, and transmits and receives information to and from the outside. The auxiliary memory unit 24 is a non-volatile storage area such as a large-capacity memory or a hard disk, and stores programs (program products) and other data necessary for the control unit 21 to execute processing.

[0015] The management device 2 may be a multi-computer consisting of a plurality of computers, or may be a virtual machine virtually constructed by software.

[0016] The management device 2 may also be provided with a reading unit that reads a portable storage medium 2a such as a CD-ROM, and may read and execute a program from the portable storage medium 2a.

[0017] 4 is an explanatory diagram of the process of generating shares, and the process of generating a plurality of shares by dividing the original information using the secret sharing scheme will be described with reference to FIG.

[0018] First, the management device 2 generates a plurality of primary shares by dividing the original information using a secret sharing scheme. In the example of Fig. 4, the management device 2 divides the original information into two primary shares X and Y. Note that the management device 2 may divide the original information into three or more shares.

[0019] Furthermore, the management device 2 uses a secret sharing scheme to generate multiple secondary share pieces by dividing a portion of the primary share pieces generated above. In the example of Figure 4, the management device 2 divides the primary share piece Y into two secondary share pieces. Note that the management device 2 may also divide the primary share piece into three or more.

[0020] The management device 2 generates secondary distribution pieces multiple times using different division patterns. The term "division pattern" refers to a combination of the division algorithm and parameters used in the algorithm used to divide primary distribution pieces into secondary distribution pieces. In other words, "division using different division patterns" refers to dividing primary distribution pieces into secondary distribution pieces using different algorithms and / or different parameters. For example, by using random numbers as parameters for dividing primary distribution pieces into secondary distribution pieces, it is possible to easily create different division patterns for each division. By generating secondary distribution pieces multiple times using different division patterns, as shown in FIG. 4, sets of two secondary distribution pieces are generated, such as secondary distribution pieces A and B, C and D, E and F, G and H, etc. Combining secondary distribution pieces from the same set (e.g., secondary distribution pieces A and B) will result in all of the data constituting primary distribution piece Y, making it possible to restore it. In other words, secondary distribution pieces from the same set can be considered "combinations of secondary distribution pieces that can restore a primary distribution piece." On the other hand, even if secondary dispersion piece A is combined with a secondary dispersion piece other than secondary dispersion piece B (such as secondary dispersion piece D), the data constituting primary dispersion piece Y will not be complete because they are divided in different patterns, and primary dispersion piece Y cannot be restored. This is also true when three or more secondary dispersion pieces are used to generate a set; the primary dispersion piece cannot be restored unless all of the secondary dispersion pieces from the same set are collected.

[0021] The management device 2 transmits primary dispersion pieces X that have not been used to generate secondary dispersion pieces to the restoration device 1, and stores them in the auxiliary memory unit 17. The management device 2 also transmits some of the secondary dispersion pieces divided according to a certain division pattern (first division pattern) to the restoration device 1, and stores them in the auxiliary memory unit 17. For example, in Figure 4, the management device 2 stores secondary dispersion piece A, of secondary dispersion pieces A and B that correspond to the first division pattern, in the restoration device 1.

[0022] As described above, the external storage device 3 is also connected to the management device 2. The management device 2 stores in the external storage device 3 secondary distributed pieces B that belong to the same set as secondary distributed pieces A stored in the restoration device 1.

[0023] Furthermore, the management device 2 stores in the external storage device 3 some of the secondary distributed pieces that belong to a set different from the secondary distributed piece B. For example, in Figure 4, the management device 2 stores in the external storage device 3 secondary distributed piece C, out of secondary distributed pieces C and D of the set generated in the second division. As will be described later, the secondary distributed piece C will be used to restore the original information the next time (second time).

[0024] 5 is an explanatory diagram of the process of restoring the original information. The process of restoring the original information from the primary distributed pieces and the secondary distributed pieces will be described with reference to FIG.

[0025] When an external storage device 3 is connected, the restoration device 1 acquires secondary dispersion pieces from the external storage device 3. Specifically, the restoration device 1 acquires secondary dispersion pieces B that can be combined with secondary dispersion pieces A stored in the auxiliary storage unit 17 to restore primary dispersion pieces Y, and secondary dispersion pieces C that have been divided in a pattern different from that of secondary dispersion pieces B and are to be used for the next restoration. Note that the restoration device 1 may simply acquire secondary dispersion pieces B and C without particularly identifying their types. The restoration device 1 may also temporarily store the acquired secondary dispersion pieces B and C in the auxiliary storage unit 17.

[0026] The restoration device 1 restores the original information based on the primary distribution piece X and secondary distribution piece A stored in the auxiliary memory unit 17 and the secondary distribution piece B acquired from the external storage device 3. That is, the restoration device 1 restores the primary distribution piece Y based on the secondary distribution pieces A and B, and restores the original information based on the restored primary distribution piece Y and the primary distribution piece X stored in the auxiliary memory unit 17. Note that during this restoration, the restoration device 1 may attempt restoration using the secondary distribution pieces (B and C) acquired from the external storage device 3 in sequence (i.e., a brute force approach for the acquired secondary distribution pieces). As mentioned above, only secondary distribution piece B can be restored in combination with secondary distribution piece A, so in either case, primary distribution piece Y is restored from secondary distribution pieces A and B.

[0027] For example, if the external storage device 3 is disconnected, the restoration device 1 deletes the secondary distributed pieces A (and B) used for the current restoration from the auxiliary storage unit 17. At this time, the restoration device 1 may also delete the original information. The restoration device 1 also stores the secondary distributed piece C obtained from the external storage device 3 in the auxiliary storage unit 17. Furthermore, the restoration device 1 deletes the secondary distributed pieces B and C from the external storage device 3.

[0028] In addition to the above operations, the secondary distributed pieces stored in the restoration device 1 are deleted when a predetermined condition set in advance is met. The predetermined condition is, for example, the passage of a predetermined time. For example, the restoration device 1 deletes secondary distributed pieces A (and B) from the auxiliary storage unit 17 when a predetermined time has passed since the previous restoration of the original information.

[0029] The condition for deleting the secondary dispersed pieces is not limited to the passage of time. For example, the restoration device 1 may delete the secondary dispersed pieces when a measurement value measured by a predetermined built-in sensor exceeds a threshold value. For example, the restoration device 1 may delete the secondary dispersed pieces when it detects an action such as a fall by comparing the acceleration measured by an acceleration sensor with a threshold value.

[0030] The external storage device 3 is reconnected to the management device 2 by the user. When the external storage device 3 is reconnected, the management device 2 re-stores the secondary distribution pieces in the external storage device 3. For example, the management device 2 stores which secondary distribution pieces were most recently downloaded to the restoration device 1 and the external storage device 3, and stores in the external storage device 3 secondary distribution pieces D that correspond to secondary distribution pieces (here, secondary distribution piece C) that cannot be used for restoration (i.e., do not form a set) among the stored secondary distribution pieces. Alternatively, the management device 2 communicates with the restoration device 1 and stores in the external storage device 3 secondary distribution pieces D that belong to the same set as the secondary distribution piece (here, secondary distribution piece C) stored in the restoration device 1. The management device 2 also stores in the external storage device 3 secondary distribution pieces that belong to a different set from secondary distribution piece D (secondary distribution piece E in the example of Figure 5).

[0031] Here, the management device 2 may reuse a secondary distribution piece (e.g., secondary distribution piece A or B) that has been downloaded to the restoration device 1 or the external storage device 3, as long as it belongs to a different set from secondary distribution piece D, or may not reuse it. If secondary distribution pieces can be reused, for example, the management device 2 may randomly identify a set from among the sets different from secondary distribution piece D to be downloaded to the external storage device 3 this time. In this case, it is sufficient to store one or more, but not all, of the secondary distribution pieces included in the identified set in the external storage device 3. On the other hand, if secondary distribution pieces are not reused, the management device 2 may assign an index to each set of secondary distribution pieces and store the index corresponding to the set of secondary distribution pieces downloaded to the external storage device 3. The management device 2 may then determine the secondary distribution pieces to be downloaded to the external storage device 3 in accordance with the order of the indexes.

[0032] When the external storage device 3 storing the secondary distribution pieces D and E is reconnected, the restoration device 1 retrieves the secondary distribution pieces D and E from the external storage device 3. The subsequent processing is the same as above, and the restoration device 1 restores the original information based on the primary distribution piece X and secondary distribution piece C stored in the auxiliary storage unit 17 and the secondary distribution piece D retrieved from the external storage device 3. When the connection to the external storage device 3 is disconnected, the restoration device 1 deletes the secondary distribution piece C from the auxiliary storage unit 17 and stores the secondary distribution piece E to be used for the next restoration in the auxiliary storage unit 17. The restoration device 1 also deletes the secondary distribution pieces D and E from the external storage device 3.

[0033] In this way, the restoration device 1 obtains the secondary distributed fragments from the external storage device 3 and combines them with the primary distributed fragments and secondary distributed fragments stored in the auxiliary storage unit 17 to restore the original information. As a result, the original information cannot be restored unless the restoration device 1 and the external storage device 3 are present. Furthermore, because the secondary distributed fragments on the restoration device 1 are deleted periodically, even if the restoration device 1 and the external storage device 3 are lost or stolen at the same time, the original information cannot be restored. As a result, information leakage can be prevented.

[0034] 6 is a flowchart showing the procedure for the process of generating shares. The process of generating multiple shares by dividing original information using a secret sharing scheme will be described with reference to FIG. 6. The control unit 21 of the management device 2 generates multiple primary shares by dividing the original information using a secret sharing scheme (step S11). The control unit 21 further divides some of the generated primary shares by using the secret sharing scheme to generate multiple secondary shares (step S12). In step S12, the control unit 21 generates secondary shares multiple times using different division patterns. The management device 2 stores the primary shares and secondary shares generated from the original information.

[0035] The control unit 21 transmits the primary dispersion pieces that were not used to generate the secondary dispersion pieces in step S12, out of the multiple primary dispersion pieces generated in step S11, to the restoration device 1 and stores them (step S13). The control unit 21 transmits a portion of the secondary dispersion pieces divided according to a certain division pattern (first division pattern) to the restoration device 1 and stores them (step S14). The control unit 21 stores the remaining secondary dispersion pieces divided according to that division pattern and a portion of the secondary dispersion pieces divided according to a pattern different from the secondary dispersion pieces in the external storage device 3 (step S15), and ends the series of processes.

[0036] 7 is a flowchart showing the steps of the process for restoring original information. The process performed by the restoration device 1 when restoring original information from distributed pieces will be described with reference to FIG. 7. When the external storage device 3 is connected, the control unit 11 of the restoration device 1 acquires secondary distributed pieces from the external storage device 3 (step S31). Specifically, the control unit 11 acquires, from the external storage device 3, distributed pieces corresponding to the secondary distributed pieces stored in the auxiliary storage unit 17 (i.e., secondary distributed pieces in the same set as the secondary distributed piece), and secondary distributed pieces belonging to a different set from the secondary distributed piece.

[0037] The control unit 11 restores the original information based on the primary distributed pieces and secondary distributed pieces stored in the auxiliary memory unit 17 and the secondary distributed pieces acquired from the external storage device 3 (step S32). That is, the control unit 11 restores the primary distributed pieces based on the secondary distributed pieces stored in the auxiliary memory unit 17 and the secondary distributed pieces acquired from the external storage device 3, and restores the original information based on the restored primary distributed pieces and the primary distributed pieces stored in the auxiliary memory unit 17.

[0038] For example, when the external storage device 3 is disconnected, the control unit 11 deletes the secondary distributed pieces used in the current restoration from the auxiliary storage unit 17 (step S33). The control unit 11 stores the secondary distributed pieces not used in the restoration, among the secondary distributed pieces obtained from the external storage device 3, in the auxiliary storage unit 17 (step S34). The control unit 11 deletes the secondary distributed pieces from the external storage device 3 (step S35), and ends the series of processes. Note that the restoration device 1 may delete the original information either before or after step S35.

[0039] In the above, it is assumed that the restoration device 1 obtains all secondary distributed pieces from the external storage device 3, but this embodiment is not limited to this. For example, the restoration device 1 may send a request to the management device 2 and obtain from the management device 2 the secondary distributed pieces to be used in the next restoration. In this case, the management device 2 sends some of the secondary distributed pieces to be used in the next restoration to the restoration device 1 in response to the request from the restoration device 1. The management device 2 may decide which set of secondary distributed pieces to use in the next restoration in the restoration device 1. In this way, the restoration device 1 only needs to be able to obtain the secondary distributed pieces to be used in the next restoration, and the source of these pieces is not limited to the external storage device 3.

[0040] As described above, according to the first embodiment, it is possible to prevent information leakage.

[0041] (Embodiment 2) In this embodiment, when the original information is updatable data and the original information is updated by reading, writing, etc., a form will be described in which the updated original information (hereinafter referred to as "second original information") is protected. Note that the same reference numerals will be used to designate the same contents as in Embodiment 1, and descriptions thereof will be omitted.

[0042] Fig. 8 is an explanatory diagram showing an outline of embodiment 2. The outline of this embodiment will be described based on Fig. 8. Note that the method of dividing the primary dispersion pieces and secondary dispersion pieces in the example of Fig. 8 is the same as in Fig. 4.

[0043] As in embodiment 1, the restoration device 1 stores primary distributed pieces X, which are obtained by dividing the original information, and secondary distributed pieces A, which are obtained by further dividing the remaining primary distributed pieces Y. When an external storage device 3 is connected, the restoration device 1 acquires secondary distributed pieces B (and C), and combines them with the primary distributed pieces X and secondary distributed pieces A stored in the auxiliary storage unit 17 to restore the original information.

[0044] Now, consider the case where the original information is updatable information (e.g., a document file). In this case, even if the primary and secondary distributed fragments stored in the restoration device 1 are combined with the secondary distributed fragments stored in the external storage device 3, only the original information before the update can be restored, and the second original information after the update cannot be restored. Therefore, in this embodiment, difference information is stored that indicates the difference between the original information when the external storage device 3 is connected (e.g., when mounted) and the second original information when the external storage device 3 is disconnected (e.g., when unmounted), and the second original information is restored based on the original information and the difference information.

[0045] For example, the primary shared piece X includes an encryption key (common key). Note that if the shared pieces split using the secret sharing method include some kind of encryption key (e.g., a common key, a public key, and a private key), the encryption key can only be extracted when the original information is restored from the shared pieces that include that encryption key. This also applies to the following embodiments. When the original information is restored, the restoration device 1 extracts the encryption key included in the primary shared piece X from the restored original information and copies it to the main memory unit 12 (volatile memory area).

[0046] When the external storage device 3 is disconnected, the restoration device 1 encrypts, with an encryption key, difference information D1 between the original information before the update and the second original information after the update. The restoration device 1 stores the encrypted difference information in the auxiliary storage unit 17 and deletes the encryption key from the main storage unit 12.

[0047] When the external storage device 3 is reconnected, the restoration device 1 obtains the secondary distributed pieces D (and E) from the external storage device 3 and combines them with the primary distributed pieces X and secondary distributed pieces C stored in the auxiliary storage unit 17 to restore the original information. The restoration device 1 extracts an encryption key from the restored original information. The restoration device 1 then decrypts the differential information D1 stored in the auxiliary storage unit 17 using the encryption key. The restoration device 1 restores the second original information based on the restored original information and the decrypted differential information D1.

[0048] Similarly, when the external storage device 3 is disconnected, the restoration device 1 encrypts and stores the differential information D2 of the latest update, and uses the differential information D2 to restore the second original information the next time the original information is restored.

[0049] 9 is a flowchart showing the steps of the restoration process of original information according to the second embodiment. After acquiring secondary shared pieces from the external storage device 3 (step S31) and combining them with the primary shared pieces and the secondary shared pieces stored in the auxiliary storage unit 17 to restore the original information (step S32), the restoration device 1 executes the following process. The control unit 11 of the restoration device 1 extracts an encryption key (common key) included in the primary shared pieces from the restored original information and copies it to the main storage unit 12 (step S201). The control unit 11 uses the encryption key to decrypt difference information indicating the difference between the original information and the second shared piece used to previously update the original information (step S202). The control unit 11 restores the second shared piece based on the original information restored in step S32 and the difference information decrypted in step S202 (step S203).

[0050] The control unit 11 updates the second element information in response to an operation input from the user (step S204). The control unit 11 encrypts the difference information obtained at this time of update using the encryption key extracted in step S201 (step S205). The control unit 11 stores the encrypted difference information in the auxiliary storage unit 17 (step S206). The control unit 11 deletes the encryption key from the main storage unit 12 (step S207) and proceeds to step S33.

[0051] As described above, according to the second embodiment, it is possible to prevent information leakage even when the original information is updated.

[0052] Third Embodiment In this embodiment, a description will be given of an embodiment in which the second element information is dynamically protected by dividing the element information every time the element information is updated.

[0053] 10 is an explanatory diagram showing an outline of the third embodiment. The outline of this embodiment will be described with reference to FIG.

[0054] As in the second embodiment, consider a case where the original information can be updated. In this embodiment, when the original information is updated, the restoration device 1 divides the second original information resulting from the update of the original information into at least three or more distributed pieces. The restoration device 1 then stores some of the distributed pieces and stores the remaining distributed pieces in the external storage device 3. When the external storage device 3 is reconnected, the second original information is restored from these distributed pieces.

[0055] For example, as in embodiment 1, the management device 2 stores in the restoration device 1 primary distributed pieces A obtained by dividing the original information and secondary distributed pieces A obtained by further dividing primary distributed pieces Y. The management device 2 also stores in the external storage device 3 secondary distributed pieces B that can be combined with the secondary distributed pieces A stored in the restoration device 1 to restore primary distributed pieces Y. In the example of Figure 10, the management device 2 only needs to generate primary distributed pieces X and Y, and secondary distributed pieces A and B from primary distributed piece Y, among the distributed pieces shown in Figure 4, and may or may not generate secondary distributed pieces from secondary distributed piece C onwards.

[0056] When the external storage device 3 is connected, the restoration device 1 acquires the secondary distributed piece B from the external storage device 3 and restores the original information by combining it with the primary distributed piece X and the secondary distributed piece A stored in the auxiliary storage unit 17. The original information is then updated in accordance with operational input by the user, etc.

[0057] The restoration device 1 divides the updated second original information into multiple primary distributed pieces X' and Y' at a predetermined timing, for example, when the external storage device 3 is disconnected, when the user instructs the external storage device 3 to be disconnected, when the update of the original information is confirmed, or when the file of the updated original information is closed. Furthermore, the restoration device 1 divides the primary distributed piece Y' into multiple secondary distributed pieces A' and B'. The restoration device 1 deletes the primary distributed piece X and the secondary distributed piece A used to restore the original information from the auxiliary storage unit 17, and stores the newly generated primary distributed piece X' and the secondary distributed piece A' in the auxiliary storage unit 17. Furthermore, the restoration device 1 deletes the secondary distributed piece B used to restore the original information from the external storage device 3, and stores the newly generated secondary distributed piece B' in the external storage device 3.

[0058] When the external storage device 3 is reconnected, the restoration device 1 restores the second element information based on the primary distributed piece X' and secondary distributed piece A' stored in the auxiliary storage unit 17 and the secondary distributed piece B' stored in the external storage device 3. In this way, each time the original information is updated, the updated second element information is divided into multiple distributed pieces and stored in the restoration device 1 and the external storage device 3, thereby dynamically protecting the information.

[0059] Figure 11 is a flowchart showing the steps of the restoration process for original information according to embodiment 3. The processing executed by the restoration device 1 will be described with reference to Figure 11. When an external storage device 3 is connected, the control unit 11 of the restoration device 1 acquires from the external storage device 3 secondary distributed pieces that can be combined with the secondary distributed pieces stored in the auxiliary storage unit 17 to restore the primary distributed pieces (step S301). The control unit 11 restores the original information based on the primary distributed pieces and secondary distributed pieces stored in the auxiliary storage unit 17 and the secondary distributed pieces acquired from the external storage device 3 (step S302).

[0060] The control unit 11 updates the raw information to second raw information in response to an operation input from the user or the like (step S303).

[0061] Next, at the predetermined timing described above, the control unit 11 divides the second information into a plurality of primary shared pieces using the secret sharing scheme (step S304), and further divides some of the generated primary shared pieces into a plurality of secondary shared pieces (step S305).

[0062] The control unit 11 deletes the primary distributed pieces and secondary distributed pieces used to restore the original information in step S302 from the auxiliary storage unit 17 (step S306). The control unit 11 stores, in the auxiliary storage unit 17, the primary distributed pieces that were not used to generate the secondary distributed pieces, among the primary distributed pieces generated in step S304, and some of the secondary distributed pieces generated in step S305 (step S307).

[0063] The control unit 11 deletes the secondary dispersion pieces from the external storage device 3 (step S308). The control unit 11 stores in the external storage device 3 the secondary dispersion pieces that can be combined with the secondary dispersion pieces stored in the auxiliary storage unit 17 in step S307 to restore the primary dispersion pieces, from among the secondary dispersion pieces generated in step S305 (step S309), and ends the series of processes.

[0064] As described above, according to the third embodiment, the second element information can be dynamically protected by dividing the second element information one by one.

[0065] Fourth Embodiment In this embodiment, a description will be given of an embodiment in which secondary distributed pieces are encrypted and stored in the restoration device 1, and the secondary distributed pieces are decrypted when the original information is restored.

[0066] Fig. 12 is an explanatory diagram showing an overview of the fourth embodiment. The overview of this embodiment will be described with reference to Fig. 12. The information processing system according to this embodiment includes a mobile terminal 4 in addition to the various devices shown in Fig. 1. The mobile terminal 4 can be realized by, for example, a smartphone.

[0067] As in the first embodiment, the management device 2 stores in the restoration device 1 primary distributed pieces X, which are obtained by dividing the original information, and secondary distributed pieces A, which are obtained by further dividing the primary distributed pieces Y. In this case, the management device 2 encrypts the secondary distributed pieces A using the encryption key (public key) included in the primary distributed piece X, and then stores them in the restoration device 1.

[0068] The "Protection Status" row at the top of Figure 12 shows the state of various data before the external storage device 3 is connected to the restoration device 1. As shown in the figure, secondary distribution piece A is stored in an encrypted state in the restoration device 1, and the external storage device 3 is connected to the restoration device 1 in this state. The "Restoration Status" row at the top of Figure 12 shows the state of various processes and data after the restoration device 1 acquires secondary distribution pieces B (and C) from the external storage device 3. When the external storage device 3 is connected, the restoration device 1 acquires secondary distribution pieces B (and C) from the external storage device 3. Here, the data necessary to restore the original information (primary distribution piece X, secondary distribution pieces A and B) are all present in the restoration device 1, but secondary distribution piece A is in an encrypted state. Therefore, the restoration device 1 decrypts this secondary distribution piece A with a private key. The restoration device 1 according to this embodiment acquires the private key via the mobile terminal 4. Note that the timing of acquiring the private key is not particularly limited. For example, the restoration device 1 may acquire the private key between the time the external storage device 3 is connected and the time before the original information restoration process is performed.

[0069] The portable terminal 4 performs authentication based on authentication information in advance or upon receiving a request from the restoration device 1. Here, the authentication information is, for example, the user's biometric information, location information, etc. In order to enhance security, this authentication is preferably authentication based on two or more pieces of authentication information (multi-factor authentication). Note that the authentication process may be executed by the restoration device 1 instead of the portable terminal 4. Also, the content of the authentication process based on the authentication information may be publicly known. For example, authentication may be performed using a function (face authentication, fingerprint authentication, password authentication, etc.) that is pre-installed as a function of the portable terminal 4 (or the restoration device 1) itself.

[0070] If authentication on the mobile terminal 4 is successful, the mobile terminal 4 obtains a private key corresponding to the public key contained in primary share piece A from the management device 2 (or the cloud). The mobile terminal 4 transmits the obtained private key to the restoration device 1. The restoration device 1 decrypts secondary share piece A using the private key. The restoration device 1 restores the original information based on primary share piece X stored in the auxiliary memory unit 17, the decrypted secondary share piece A, and secondary share piece B obtained from the external storage device 3. The restoration device 1 deletes the private key from the main memory unit 12.

[0071] In this embodiment, the private key is obtained from the management device 2, but the private key may be managed (stored) in a memory unit of the mobile terminal 4, and the mobile terminal 4 may authenticate itself, and if the authentication is successful, send the private key to the restoration device 1.

[0072] The "Restoration Status" row at the bottom of Figure 12 shows the state of the data after secondary share piece A has been decrypted and the original information has been restored. In this state, if the external storage device 3 is disconnected from the restoration device 1, the restoration device 1 deletes secondary share pieces A and B from the auxiliary storage unit 17. Furthermore, at a predetermined timing, such as when the restoration device 1 is disconnected from the external storage device 3, the restoration device 1 extracts the public key from the restored original information and encrypts secondary share piece C, which will be used for the next restoration, with the public key. The "Protection Status" row at the bottom of Figure 12 shows the state of the data after secondary share piece C has been encrypted. The restoration device 1 stores the encrypted secondary share piece C in the auxiliary storage unit 17. The restoration device 1 deletes the public key from the main storage unit 12. The original information may also be deleted at this time.

[0073] The subsequent processing is the same as above, and when the external storage device 3 is reconnected, the restoration device 1 acquires secondary share pieces D and E, decrypts secondary share piece C using the private key obtained from the mobile terminal 4, and restores the original information by combining it with primary share piece X stored in the auxiliary storage unit 17 and secondary share piece D acquired from the external storage device 3. Then, at the predetermined timing mentioned above, secondary share piece E is encrypted using the public key.

[0074] Even if the external storage device 3 is connected, the restoration device 1 may encrypt the secondary distributed pieces if a predetermined condition (for example, the passage of a predetermined time) is met. At this time, the restoration device 1 may also delete the original information. This makes it possible to prevent a third party from viewing the original information, even in cases where the external storage device 3 is left connected for a long period of time.

[0075] As described above, in this embodiment, the secondary distributed pieces are encrypted and stored in the restoration device 1, and the secondary distributed pieces are decrypted when the original information is restored. This makes it possible to more effectively prevent information leakage.

[0076] Fig. 13 is a flowchart showing the steps of the process of restoring original information according to embodiment 4. The process of restoring original information in this embodiment will be described with reference to Fig. 13. When an external storage device 3 is connected, the control unit 11 of the restoration device 1 acquires, from the external storage device 3, secondary distributed pieces that belong to the same set as the secondary distributed pieces stored in the auxiliary storage unit 17, and secondary distributed pieces that belong to a different set from the secondary distributed pieces (step S401).

[0077] If authentication based on the authentication information is successful, the control unit 11 obtains a private key from the management device 2 (step S402). The control unit 11 decrypts the encrypted secondary share pieces stored in the auxiliary memory unit 17 using the private key (step S403). The control unit 11 restores the original information based on the primary share pieces stored in the auxiliary memory unit 17, the secondary share pieces decrypted in step S403, and the secondary share pieces obtained in step S401 (step S404). The control unit 11 deletes the private key from the main memory unit 12 (step S405).

[0078] At a predetermined timing, such as when the external storage device 3 is disconnected, the control unit 11 extracts the public key contained in the primary shared fragment from the restored original information and copies it to the main memory unit 12 (step S406). The control unit 11 uses this copied public key to encrypt the secondary shared fragment to be used in the next restoration (i.e., the secondary shared fragment not used in the current restoration) (step S407). The control unit 11 deletes the secondary shared fragment used in the current restoration from the auxiliary memory unit 17 (step S408). The control unit 11 stores the encrypted secondary shared fragment in the auxiliary memory unit 17 (step S409).

[0079] The control unit 11 deletes the replicated public key from the main storage unit 12 (step S410). The control unit 11 deletes the secondary distributed pieces from the external storage device 3 (step S411), and ends the series of processes.

[0080] As described above, according to the fourth embodiment, information leakage can be prevented more suitably.

[0081] Fifth Embodiment In this embodiment, a form will be described in which, before encrypting secondary distributed pieces, it is confirmed (determined) whether or not the original information can be restored even if it is encrypted.

[0082] 14 is an explanatory diagram showing an outline of the fifth embodiment. The outline of this embodiment will be described with reference to FIG.

[0083] The "Protection Status" row at the top of Figure 14 shows the state of various data before the external storage device 3 is connected to the restoration device 1. As shown in the figure, secondary distribution fragment A is stored in an encrypted state in the restoration device 1, and the external storage device 3 is connected to the restoration device 1 in this state. As in embodiment 4, when the external storage device 3 is connected, the restoration device 1 obtains secondary distribution fragments B and C from the external storage device 3.

[0084] The "Restoration Status" row in Figure 14 shows the state of various processes and data after the restoration device 1 acquires secondary share pieces B and C from the external storage device 3. For example, after connecting the external storage device 3, the restoration device 1 acquires a private key from the mobile terminal 4. As shown in the figure, the mobile terminal 4 acquired this private key in advance from the management device 2 or upon receiving a request from the restoration device 1. The mobile terminal 4 can acquire the private key from the management device 2 in response to the authentication result based on the authentication information (i.e., if authentication is successful). When the restoration device 1 acquires the private key from the mobile terminal 4 and acquires secondary share pieces B and C, it uses the private key to decrypt secondary share piece A. The restoration device 1 then restores the original information based on primary share piece X stored in the auxiliary storage unit 17, the decrypted secondary share piece A, and the acquired secondary share piece B. In this case, as described in embodiment 4, when a predetermined condition (e.g., a predetermined time has passed since the original information was restored) is met, the restoration device 1 encrypts secondary share piece C using the public key included in primary share piece X. At this time, the restoration device 1 may delete the original information.

[0085] In this embodiment, before encrypting the secondary distributed pieces C, the restoration device 1 determines whether or not the original information can be restored even if the secondary distributed pieces C are encrypted. For example, the restoration device 1 determines whether or not it is possible to communicate with the management device 2 that manages the private key, i.e., whether or not it is possible to obtain the private key necessary to decrypt the secondary distributed pieces C.

[0086] If it is determined that the original information can be restored, the restoration device 1 encrypts the secondary distributed piece C. The "Protection Status" row at the bottom of Figure 14 shows the state of the data after encryption of the secondary distributed piece C. If it is determined that the original information can be restored, the secondary distributed pieces A and B may be deleted from the restoration device 1. On the other hand, if it is determined that the original information cannot be restored, the restoration device 1 does not encrypt the secondary distributed piece C, and makes another determination after a certain period of time. This "certain period of time" may be the same as the elapsed time ("predetermined period of time") described above, or it may be different. If it is determined that the original information can be restored as a result of making another determination after the certain period of time, the restoration device 1 encrypts the secondary distributed piece C. The original information may also be deleted at this time.

[0087] As described above, the restoration device 1 checks whether the original information can be restored before encrypting the secondary distributed pieces. This prevents situations such as the expiration date expiring while the Internet is unavailable, such as while on an airplane, making it impossible to access the original information.

[0088] Figure 15 is a flowchart showing the steps of the encryption process for secondary distributed pieces according to embodiment 5. The judgment process when encrypting secondary distributed pieces will be described with reference to Figure 15. The process of this flowchart is executed, for example, when an external storage device 3 is connected to the restoration device 1. The control unit 11 of the restoration device 1 judges whether a predetermined condition set in advance is met (step S501). The predetermined condition is, for example, the passage of a predetermined time since the external storage device 3 was connected to the restoration device 1. If it is determined that the predetermined condition is not met (S501: NO), the control unit 11 puts the process on hold.

[0089] If it is determined that the predetermined conditions are met (S501: YES), the control unit 11 determines whether the original information can be restored (step S502). Specifically, the control unit 11 determines whether it is possible to communicate with the management device 2 that manages the private key. If it is determined that the original information can be restored (S502: YES), the control unit 11 restores the original information, extracts the public key, encrypts the secondary shared pieces using the public key included in the primary shared pieces, and stores them in the auxiliary storage unit 17 (step S503), thereby ending the series of processes. At this time, the original information may be deleted.

[0090] If it is determined that the original information cannot be restored (S502: NO), the control unit 11 determines whether a certain time has elapsed (step S504). If it is determined that the certain time has not elapsed (S504: NO), the control unit 11 puts the processing on hold. If it is determined that the certain time has elapsed (S504: YES), the control unit 11 returns the processing to step S502. In this case, the control unit 11 again determines whether the original information can be restored (step S502), and if it is determined that the original information can be restored, it encrypts the secondary distributed pieces (step S503).

[0091] As described above, according to the fifth embodiment, the encryption of secondary distributed pieces can be suitably performed. Note that the timing of performing the processing of the flowchart shown in FIG. 15 is not limited to the timing when the external storage device 3 is connected. The flowchart shown in FIG. 15 may be performed as appropriate depending on the content of the predetermined condition determined in S501. Furthermore, the various processing shown in FIG. 15 may be performed in parallel with the processing of the restoration device 1 described in the previous drawings and in this specification.

[0092] (Variation 1) In the fifth embodiment, a form has been described in which, when a secondary distributed piece is encrypted by satisfying a predetermined condition (for example, the passage of a predetermined time), it is confirmed whether the original information can be restored. On the other hand, this embodiment may also be applied to a case in which a secondary distributed piece is deleted by satisfying a predetermined condition.

[0093] That is, when the restoration device 1 deletes secondary distributed pieces by satisfying predetermined conditions set in advance, it determines whether the original information can be restored. For example, if an external storage device 3 is connected to the restoration device 1, it determines whether secondary distributed pieces that can be combined with the secondary distributed pieces stored in the auxiliary storage unit 17 to restore the primary distributed pieces can be obtained from the external storage device 3. If it determines that the original information can be restored, the restoration device 1 deletes the secondary distributed pieces stored in the auxiliary storage unit 17.

[0094] On the other hand, if it is determined that the original information cannot be restored, the restoration device 1 does not delete the secondary distributed pieces, and makes another determination after a certain period of time. If it is determined that the original information can be restored as a result of making the determination again after the certain period of time, the restoration device 1 deletes the secondary distributed pieces stored in the auxiliary memory unit 17.

[0095] In this way, the fifth embodiment can also be applied to the case where secondary distributed pieces are deleted. Since this modification is the same as the fifth embodiment except that the secondary distributed pieces are deleted instead of encrypted, detailed explanations of the flowchart and other details will be omitted in this modification.

[0096] (Variation 2) In the fifth embodiment and the first variation, a configuration has been described in which it is confirmed whether the original information can be restored before encrypting or deleting the secondary distributed pieces. This embodiment may also be applied to a configuration in which the original information is updated as described in the second and third embodiments.

[0097] That is, when the restoration device 1 encrypts or deletes secondary distributed pieces by satisfying a predetermined condition, the restoration device 1 may determine whether the second original information (the updated original information) can be restored. If it determines that the second original information can be restored, the restoration device 1 encrypts or deletes the secondary distributed pieces stored in the auxiliary storage unit 17. On the other hand, if it determines that the second original information cannot be restored, the restoration device 1 does not encrypt or delete the secondary distributed pieces, and makes another determination after a certain period of time.

[0098] In this way, the fifth embodiment can also be applied to cases where the original information is updatable information.

[0099] (Variation 3) In embodiment 4, the encryption key may be stored in a device other than the management device 2. The mobile terminal 4 may then obtain the encryption key by communicating with the other device. In this case as well, authentication of the mobile terminal 4 is performed in the mobile terminal 4 and / or the other device. If the authentication is successful, the encryption key is transmitted from the other device to the mobile terminal 4. Similarly, the private key in embodiment 5 may be stored in a device other than the management device 2. The same applies to variations 1 and 2. Note that the other device does not necessarily refer to a single physical device, but may be, for example, cloud storage or the like.

[0100] (Variation 4) In embodiments 4 and 5, the external storage device 3 may be the same device as the mobile terminal 4. In this case, the external storage device 3 may perform authentication to acquire the private key and acquire the private key in advance based on user instructions, etc. Then, when the external storage device 3 connects to the restoration device 1, it may transmit the private key to the restoration device 1 along with the secondary shared pieces (for example, secondary shared pieces B and C in embodiment 4). (Variation 5) Embodiments 4 and 5 can also be applied when the original information is updatable information, as in embodiment 2 or 3. When embodiment 4 or 5 is combined with embodiment 2 or 3, the generation, deletion, and movement of data in the primary shared pieces and secondary shared pieces shall be similar to embodiment 2 or 3. Furthermore, authentication by the mobile terminal 4 and the method of acquiring the private key of the restoration device 1 shall be similar to embodiment 4 or 5. In addition, in the case of embodiment 4 or 5, the secondary distribution fragment that the restoration device 1 encrypts is the secondary distribution fragment obtained from the external storage device 3 that was not used to restore the original information (for example, secondary distribution fragment C in Figure 12 or Figure 14).

[0101] The embodiments disclosed herein are illustrative in all respects and should not be considered limiting. The scope of the present invention is defined by the claims, not by the above meaning, and is intended to include all modifications within the meaning and scope of the claims.

[0102] The matters described in each embodiment can be combined with each other. Furthermore, the independent claims and dependent claims described in the claims can be combined with each other in any combination, regardless of the reference format. Furthermore, the claims use a format in which a claim references two or more other claims (multiple claim format), but this is not limited to this. A multiple claim (multi-multi claim) that references at least one other multiple claim may also be used.

[0103] REFERENCE SIGNS LIST 1 Restoration device 11 Control unit 12 Main memory unit 13 Communication unit 14 Display unit 15 Operation unit 16 Input / output unit 17 Auxiliary memory unit 2 Management device 21 Control unit 22 Main memory unit 23 Communication unit 24 Auxiliary memory unit 3 External storage device 4 Mobile terminal

Claims

1. An information processing method in which a computer executes the processes of: dividing second element information, which is information obtained by updating original information restored from distributed pieces divided by a secret sharing scheme, into primary distributed pieces and secondary distributed pieces obtained by further dividing a part of the primary distributed pieces; storing a part of the primary distributed pieces and a part of the secondary distributed pieces in a memory unit; storing the remaining secondary distributed pieces other than the secondary distributed pieces stored in the memory unit in an external storage device; acquiring the secondary distributed pieces from the external storage device when the external storage device is connected; restoring the second element information based on the primary distributed pieces and secondary distributed pieces stored in the memory unit and the secondary distributed pieces acquired from the external storage device; and deleting the secondary distributed pieces stored in the external storage device.

2. The information processing method according to claim 1, further comprising the step of deleting the secondary dispersion pieces stored in the memory unit when a predetermined condition set in advance is satisfied.

3. The information processing method according to claim 2, wherein when deleting the secondary distributed pieces stored in the memory unit, it is determined whether or not the second original information can be restored, and if it is determined that restoration is possible, the secondary distributed pieces are deleted, and if it is determined that restoration is not possible, a determination is made again after a certain period of time.

4. An information processing method according to any one of claims 1 to 3, wherein the secondary distributed pieces are encrypted using an encryption key and then stored in the memory unit, and when restoring the second elemental information, the secondary distributed pieces are decrypted using the encryption key to restore the second elemental information.

5. The information processing method described in claim 4, further comprising the steps of: encrypting the secondary distributed fragment using a public key contained in the primary distributed fragment; and, when restoring the second original information, decrypting the secondary distributed fragment using a private key obtained in response to an authentication result based on authentication information.

6. An information processing method according to claim 4 or 5, wherein when encrypting the secondary distributed pieces, it is determined whether the original information can be restored, and if it is determined that restoration is possible, the secondary distributed pieces are encrypted, and if it is determined that restoration is not possible, a determination is made again after a certain period of time.

7. A program that causes a computer to execute the following processes: dividing second element information, which is information obtained by updating original information restored from distributed pieces divided by a secret sharing scheme, into primary distributed pieces and secondary distributed pieces obtained by further dividing a part of the primary distributed pieces; storing a part of the primary distributed pieces and a part of the secondary distributed pieces in a memory unit; storing the remaining secondary distributed pieces other than the secondary distributed pieces stored in the memory unit in an external storage device; acquiring the secondary distributed pieces from the external storage device when the external storage device is connected; restoring the second element information based on the primary distributed pieces and secondary distributed pieces stored in the memory unit and the secondary distributed pieces acquired from the external storage device; and deleting the secondary distributed pieces stored in the external storage device.

8. An information processing device having a control unit, wherein the control unit: divides second element information, which is information obtained by updating original information restored from distributed pieces divided by a secret sharing scheme, into primary distributed pieces and multiple secondary distributed pieces obtained by further dividing a part of the primary distributed pieces; stores a part of the primary distributed pieces and a part of the secondary distributed pieces in a memory unit; stores the remaining secondary distributed pieces other than the secondary distributed pieces stored in the memory unit in an external storage device; acquires the secondary distributed pieces from the external storage device when the external storage device is connected; restores the second element information based on the primary distributed pieces and secondary distributed pieces stored in the memory unit and the secondary distributed pieces acquired from the external storage device; and deletes the secondary distributed pieces stored in the external storage device.

Citation Information

Patent Citations

  • System, method and program for managing information

    JP2008098894A

  • Information processor and information processing system

    JP2012203658A

  • Information processing device, server device, information processing program, and server program

    JP2021086276A

  • Key Generation Using Multiple Sets of Secret Shares

    US20130272521A1