Access control system, registration device, reference device, access control method, and access control program

The access control system addresses high-speed access control for shared content among multiple members by encrypting content identifiers with a group common key, facilitating efficient file sharing and management in decentralized systems.

WO2025141712A1PCT designated stage expired Publication Date: 2025-07-03MITSUBISHI ELECTRIC CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2023/046730
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-26
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

Existing technologies face challenges in enabling high-speed access control for content shared among multiple members, particularly in decentralized systems, and do not effectively manage file sharing by groups, leading to slower encryption/decryption processes due to increased key information files with data division.

Method used

An access control system that encrypts a content identifier using a group common key for a group of permitted members, registers the encrypted identifier, and facilitates decryption and acquisition using a content acquisition unit, leveraging a blockchain for distributed management.

Benefits of technology

Enables high-speed access control for content shared by multiple members, allowing efficient file sharing and management in decentralized systems with reduced resource usage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2023046730_03072025_PF_FP_ABST
    Figure JP2023046730_03072025_PF_FP_ABST
Patent Text Reader

Abstract

This registration device encrypts a content identifier for identifying content by using a group common key for a group composed of a plurality of members permitted to access the content, and registers the encrypted content identifier. This reference device acquires the encrypted content identifier, decrypts the content identifier from the encrypted content identifier by using the group common key, and acquires the content by using the content identifier.
Need to check novelty before this filing date? Find Prior Art

Description

Access control system, registration device, reference device, access control method and access control program

[0001] The present disclosure relates to a technique for sharing content among multiple members.

[0002] Patent Literature 1 discloses a technology for quickly concealing the contents of a file. This technology achieves the concealment of distributed data by encrypting a key information file required to restore the divided data. This technology enables the concealment of files in a shorter time than encrypting the data itself.

[0003] The technology of Patent Document 1 divides files, making it possible to decentralize and manage data in a decentralized information system. However, the data size of the key information file to be encrypted increases in proportion to the number of data segments. Therefore, the encryption and decryption process slows down in proportion to the number of data segments. Furthermore, the technology of Patent Document 1 does not take into account file sharing by a group (multiple people).

[0004] Japanese Patent Application Laid-Open No. 2019-61574

[0005] The present disclosure aims to enable high-speed access control for content shared by multiple members.

[0006] The access control system of the present disclosure includes a content registration unit that encrypts a content identifier that identifies content using a group common key for a group consisting of multiple members who are permitted to access the content, and registers the encrypted content identifier; and a content acquisition unit that acquires the encrypted content identifier, decrypts the content identifier from the encrypted content identifier using the group common key, and acquires the content using the content identifier.

[0007] According to the present disclosure, high-speed access control for content shared by multiple members becomes possible.

[0008] 1 is a configuration diagram of an access control system 200 according to the first embodiment. A configuration diagram of a terminal device 100 according to the first embodiment. A flowchart of key management processing according to the first embodiment. A flowchart of group registration processing according to the first embodiment. A flowchart of content registration processing according to the first embodiment. A flowchart of content acquisition processing according to the first embodiment. A diagram showing an example of the access control system 200 according to the first embodiment. A diagram showing an example of a blockchain 170 according to the first embodiment. A diagram showing an example of a blockchain 170 according to the first embodiment. A diagram showing an example of a distributed file system 180 according to the first embodiment. A configuration diagram of a terminal device 100 according to the second embodiment. A flowchart of group management processing according to the second embodiment. A flowchart of content registration processing according to the second embodiment. A flowchart of content acquisition processing according to the second embodiment. A diagram showing an example of an access control system 200 according to the second embodiment. A diagram showing an example of a blockchain 170 according to the second embodiment. A diagram showing an example of a distributed file system 180 according to the second embodiment. A hardware configuration diagram of a terminal device 100 according to the embodiments.

[0009] In the embodiments and drawings, the same or corresponding elements are denoted by the same reference numerals. The description of elements denoted by the same reference numerals as those already described will be omitted or simplified as appropriate. Arrows in the drawings primarily indicate the flow of data or the flow of processing.

[0010] First Embodiment An access control system 200 will be described with reference to FIGS.

[0011] *** Description of Configuration *** The configuration of the access control system 200 will be described based on Fig. 1. The access control system 200 includes multiple terminal devices 100. The multiple terminal devices 100 communicate with each other via a network. At least one terminal device 100 operates as a registration device. At least one terminal device 100 operates as a reference device.

[0012] The configuration of the terminal device 100 will be described with reference to Fig. 2. The terminal device 100 is a computer that includes hardware such as a processor 101, a memory 102, an auxiliary storage device 103, a communication device 104, and an input / output interface 105. These pieces of hardware are connected to each other via signal lines.

[0013] The processor 101 is an IC that performs arithmetic processing and controls other hardware. For example, the processor 101 is a CPU. IC is an abbreviation for Integrated Circuit. CPU is an abbreviation for Central Processing Unit.

[0014] The memory 102 is a volatile or non-volatile storage device. The memory 102 is also called a primary storage device or a main memory. For example, the memory 102 is a RAM. Data stored in the memory 102 is saved in the secondary storage device 103 as needed. RAM is an abbreviation for Random Access Memory.

[0015] The auxiliary storage device 103 is a non-volatile storage device. The auxiliary storage device 103 is also called storage. For example, the auxiliary storage device 103 is a ROM, a HDD, a flash memory, or a combination of these. Data stored in the auxiliary storage device 103 is loaded into the memory 102 as needed. ROM is an abbreviation for Read Only Memory. HDD is an abbreviation for Hard Disk Drive.

[0016] The communication device 104 is a receiver and a transmitter. For example, the communication device 104 is a communication chip or a NIC. The communication of the terminal device 100 is performed using the communication device 104. NIC is an abbreviation for Network Interface Card.

[0017] The input / output interface 105 is a port to which an input device and an output device are connected. For example, the input / output interface 105 is a USB terminal, the input devices are a keyboard and a mouse, and the output device is a display. Input and output of the terminal device 100 is performed using the input / output interface 105. USB is an abbreviation for Universal Serial Bus.

[0018] The terminal device 100 includes at least one of elements such as a key management unit 110, a group registration unit 120, a content registration unit 130, and a content acquisition unit 140. These elements are realized by software. The terminal device 100 that operates as a registration device includes the key management unit 110 and at least one of the group registration unit 120 and the content registration unit 130. The terminal device 100 that operates as a reference device includes the key management unit 110 and the content acquisition unit 140.

[0019] The auxiliary storage device 103 stores an access control program for causing the computer to function as a key management unit 110, a group registration unit 120, a content registration unit 130, and a content acquisition unit 140. The access control program is loaded into the memory 102 and executed by the processor 101. The auxiliary storage device 103 also stores an OS. At least a portion of the OS is loaded into the memory 102 and executed by the processor 101. The processor 101 executes the access control program while running the OS. OS is an abbreviation for Operating System.

[0020] Input and output data of the access control program is stored in the storage unit 190. The auxiliary storage device 103 functions as the storage unit 190. However, storage devices such as the memory 102, a register in the processor 101, and a cache memory in the processor 101 may function as the storage unit 190 instead of or together with the auxiliary storage device 103.

[0021] The access control program can be recorded (stored) in a computer-readable manner on a non-volatile recording medium such as an optical disk or flash memory. The access control program includes a key management program, a registration program, and a reference program. The key management program causes a computer to function as a key management unit 110. The registration program causes a computer to function as at least one of a group registration unit 120 and a content registration unit 130. The reference program causes a computer to function as a content acquisition unit 140.

[0022] The auxiliary storage device 103 functions as storage for the blockchain 170 and the distributed file system 180. Although the blockchain 170 and the distributed file system 180 are stored in the auxiliary storage device 103, the blockchain 170 and the distributed file system 180 utilize the respective functions of the processor 101, memory 102, and auxiliary storage device 103. The blockchain 170 of each terminal device 100 forms a network with the blockchains 170 of other terminal devices 100 and manages the same data as the blockchains 170 of the other terminal devices 100. The distributed file system 180 of each terminal device 100 forms a network with the distributed file systems 180 of the other terminal devices 100 and manages registered content and content obtained from the other terminal devices 100. In the distributed file system 180, for example, each content is managed in a fragmented form.

[0023] ***Explanation of Operation*** The operation procedure of the access control system 200 corresponds to an access control method. Also, the operation procedure of the access control system 200 corresponds to a processing procedure by an access control program.

[0024] A user identifier is set in advance for each terminal device 100. The user identifier identifies a user who uses the access control system 200. For example, the user identifier identifies an organization that owns the terminal device 100.

[0025] The key management process of the access control method will be described with reference to Fig. 3. The key management process is executed for each terminal device 100.

[0026] In step S111, the key management unit 110 generates a key pair for public key cryptography, thereby obtaining a key pair consisting of a private key and a public key.

[0027] In step S112 , the key management unit 110 stores the key pair in the storage unit 190 .

[0028] In step S113, the key management unit 110 registers the public key in association with the user identifier in the blockchain 170. The registered public key is shared among the multiple terminal devices 100 through the blockchain 170 of each terminal device 100.

[0029] The group registration process of the access control method will be described with reference to Fig. 4. The group registration process is executed for each terminal device 100 that operates as a (group) registration device.

[0030] Registered group information is stored in memory 102. The registered group information indicates users (members) who are registered in a group among users registered in the blockchain. A group is made up of multiple members who are permitted to access specific content. A member is a user who is registered in a group and belongs to the group. The user identifier of a user who is a member is called a member identifier. The registered group information includes a group identifier and one or more member identifiers.

[0031] In step S121, the group registration unit 120 generates a key for a common key cryptosystem, thereby obtaining a common key.

[0032] The obtained common key is called a group common key, and is used as a common key for the registered group.

[0033] In step S122 , the group registration unit 120 stores the group common key in the storage unit 190 .

[0034] In step S123, the group registration unit 120 selects one unselected member from the group to be registered. Specifically, the group registration unit 120 selects one unselected member identifier from the registered group information.

[0035] In step S124, the group registration unit 120 obtains the public key of the selected member from the blockchain 170. Specifically, the group registration unit 120 obtains from the blockchain 170 the public key associated with the user identifier that is the same as the member identifier of the selected member.

[0036] In step S125, the group registration unit 120 encrypts the group common key using the public key of the selected member, thereby obtaining the encrypted group common key of the selected member.

[0037] In step S126, the group registration unit 120 determines whether any unselected members remain. If any unselected members remain, the process proceeds to step S123. If no unselected members remain, the process proceeds to step S127.

[0038] In step S127, the group registration unit 120 registers the encrypted group common key of each member in the blockchain 170. Specifically, the group registration unit 120 associates the member identifier and the encrypted group common key for each member with the group identifier and registers them in the blockchain 170. The registered encrypted group common key is shared by multiple terminal devices 100 through the blockchain 170 of each terminal device 100.

[0039] The content registration process of the access control method will be described with reference to Fig. 5. The content registration process is executed for each terminal device 100 that operates as a (content) registration device.

[0040] One or more pieces of content to be registered are designated in advance and stored in the storage unit 190. Information on one or more pieces of content to be registered in the blockchain 170 (registered content information) is stored in the memory 102. The content is various data accessed by a specific group. The registered content information includes a group identifier and one or more content identifiers.

[0041] A member who registers content in a group that is permitted to access the registered content is called a “registered member.” In other words, a registered member is a user who uses the terminal device 100 that executes the content registration process.

[0042] In step S131, the content registration unit 130 acquires, from the blockchain 170, an encrypted group common key of a registered member from among multiple encrypted group common keys of a group that is permitted to access one or more pieces of content to be registered. Specifically, the content registration unit 130 acquires, from the blockchain 170, an encrypted group common key that is associated with the same group identifier as the group identifier included in the registered content information and that is associated with the same member identifier as the user identifier of the registered member.

[0043] In step S132, the content registration unit 130 obtains the private key of the registered member from the storage unit 190. Then, the content registration unit 130 uses the private key of the registered member to decrypt the group common key from the encrypted group common key of the registered member.

[0044] In step S133, the content registration unit 130 selects one unselected piece of content from the one or more pieces of content to be registered. Specifically, the content registration unit 130 selects one unselected content identifier from the registered content information.

[0045] In step S134, the content registration unit 130 acquires an identifier for the selected content. The content identifier is information for identifying the content.

[0046] Specifically, the content registration unit 130 calculates a hash value of the selected content, and the calculated hash value becomes the content identifier.

[0047] In step S135, the content registration unit 130 registers the selected content in the distributed file system 180. Specifically, the content registration unit 130 registers the selected content in the distributed file system 180 in association with a content identifier.

[0048] In step S136, the content registration unit 130 encrypts the content identifier using the group common key, thereby obtaining an encrypted content identifier.

[0049] In step S137, the content registration unit 130 determines whether any unselected content remains. If any unselected content remains, the process proceeds to step S133. If no unselected content remains, the process proceeds to step S138.

[0050] In step S138, the content registration unit 130 registers the encrypted content identifier of each content in the blockchain 170. Specifically, the content registration unit 130 registers the encrypted content identifier for each content in the blockchain 170 in association with the same group identifier as the group identifier included in the registered content information. The registered encrypted content identifier is shared among multiple terminal devices 100 through the blockchain 170 of each terminal device 100.

[0051] The content acquisition process of the access control method will be described with reference to Fig. 6. The content acquisition process is executed by each terminal device 100 operating as a reference device.

[0052] A user selects one or more pieces of content to reference, and information about the selected one or more pieces of content (reference content information) is stored in memory 102. The reference content information includes one or more encrypted content identifiers.

[0053] A member who references content is called a “referring member.” In other words, a “referring member” is a user who uses a terminal device 100 that executes content acquisition processing.

[0054] In step S141, the content acquisition unit 140 selects one unselected piece of content from one or more pieces of referenced content. Specifically, the content acquisition unit 140 selects one unselected encrypted content identifier from the reference content information.

[0055] In step S142, the content acquisition unit 140 acquires from the blockchain 170 the encrypted group common key of the reference member from among the multiple encrypted group common keys of the group that is permitted to access the selected content.

[0056] The encrypted group common key is obtained as follows: First, the content acquisition unit 140 acquires a group identifier associated with the encrypted content identifier of the selected content from the blockchain 170. Then, the content acquisition unit 140 acquires from the blockchain 170 an encrypted group common key associated with the same group identifier as the acquired group identifier and associated with the same member identifier as the user identifier of the reference member.

[0057] In step S143, the content acquisition unit 140 decrypts the group common key from the encrypted group common key of the reference member using the private key of the reference member. The private key of the reference member is acquired from the storage unit 190.

[0058] In step S144, the content acquisition unit 140 decrypts the encrypted content identifier using the group common key to obtain the content identifier.

[0059] In step S145, the content acquisition unit 140 acquires the content using the content identifier. Specifically, the content acquisition unit 140 inputs the content identifier to the distributed file system 180 and acquires the content from the distributed file system 180.

[0060] The distributed file system 180 outputs the content associated with the same content identifier as the input content identifier. If the corresponding content is not stored, the distributed file system 180 receives the corresponding content from the distributed file system 180 of another terminal device 100 and outputs the received content. The distributed file system 180 also stores the received content in association with the input content identifier.

[0061] In step S146, the content acquisition unit 140 determines whether any unselected content remains. If any unselected content remains, the process proceeds to step S141. If no unselected content remains, the process ends.

[0062] ***Description of the Embodiment*** An embodiment of the access control system 200 will be described with reference to Figures 7 to 10. Figure 7 shows the configuration of the access control system 200. The users of the access control system 200 are Company A, Company B, and Company C. Each of Company A, Company B, and Company C owns a terminal device 100. Company A's terminal device 100 stores a private key for Company A, Company B's terminal device 100 stores a private key for Company B, and Company C's terminal device 100 stores a private key for Company C.

[0063] 8 and 9 show the configuration of the blockchain 170. The blockchain 170 has a public key list, a group list, and a content list. The public keys of companies A, B, and C are registered in the public key list (see FIG. 8).

[0064] Three groups (Gp1, Gp2, Gp3) are registered in the group list (see FIG. 8). One or more users belong to each group. For example, companies A and B belong to group Gp1. Specifically, the group list registers a user identifier and an encrypted group common key for each user (member) in association with each group name. Each user's encrypted group common key is obtained by encrypting the group common key using the user's public key. For example, in group Gp1, company A's encrypted group common key is obtained by encrypting the group common key for group Gp1 using company A's public key.

[0065] A plurality of encrypted content identifiers are registered in the content list (see FIG. 9). The encrypted content identifier is obtained by encrypting the content identifier (hash value of the content) using the group common key of the group that is permitted to access the content. For example, the encrypted content identifier for group Gp1 is obtained by encrypting the content identifier using the group common key of group Gp1. Specifically, the content list registers a registered user identifier, group identifier, encrypted content identifier, content name, and timestamp for each piece of content. The registered user identifier indicates the user who registered the content. The timestamp indicates the date and time when the content was registered.

[0066] FIG. 10 shows the configuration of the distributed file system 180. Multiple pieces of content are registered in the distributed file system 180. Each piece of content is managed by the distributed file system 180 and accessed using a content identifier. In other words, the content cannot be accessed without knowing the content identifier. Specifically, each piece of content is registered in the distributed file system 180 in association with a content identifier. The content identifier is obtained by decrypting the encrypted content identifier using the group common key of the group that is permitted to access the content. The group common key is obtained for each user by decrypting the user's encrypted group common key using the user's private key. For example, the group common key for group Gp1 is obtained by decrypting Company A's encrypted group common key for group Gp1 using Company A's private key. The content ID of the content in group Gp1 is obtained by decrypting the encrypted content ID for group Gp1 using the group common key for group Gp1. The distributed file system 180 accepts an input content identifier and outputs content associated with the same content identifier as the input content identifier. For example, when a content identifier (Qm9Ed+ . . . ) is input, the distributed file system 180 outputs the content associated with the content identifier (Qm9Ed+ . . . ).

[0067] ***Effects of First Embodiment*** The first embodiment can be applied to a distributed information system, and realizes access control to distributed data faster and with fewer resources. Specifically, in the first embodiment, the hash value (approximately 64 bytes) of the content is encrypted and decrypted. This realizes processing faster and with fewer resources than when the content itself or the key information file is encrypted and decrypted.

[0068] The first embodiment realizes access control that enables information sharing among groups. Specifically, in the first embodiment, in order to share content within a group, a group common key is encrypted using a public key. Also, a content identifier that serves as an index of the content is encrypted. This allows each user (registered user) to freely set the disclosure range (group) and share the content. A user (registered user) who registers content simply creates a group common key, encrypts the group common key using the public keys of each user in the disclosure range, and registers the encrypted group common key.

[0069] Second Embodiment A second embodiment in which the encrypted group common key is not managed by a blockchain will be described, focusing mainly on the differences from the first embodiment, with reference to Figs. 11 to 17 .

[0070] ***Description of Configuration*** The configuration of the access control system 200 is the same as that in the first embodiment.

[0071] The configuration of the terminal device 100 will be described with reference to Fig. 11. The terminal device 100 includes elements such as a group management unit 150, a content registration unit 130, and a content acquisition unit 140. A terminal device 100 that operates as a registration device (or a group management device) includes the group management unit 150. A terminal device 100 that operates as a registration device includes the content registration unit 130. A terminal device 100 that operates as a reference device includes the content acquisition unit 140. An access control program causes a computer to function as the group management unit 150, the content registration unit 130, and the content acquisition unit 140.

[0072] ***Description of Operation*** The group management process of the access control method will be described with reference to Fig. 12. The group management process is executed for each terminal device 100 operating as a registration device (or group management device).

[0073] Information about the group to be managed (managed group information) is specified in advance and stored in the storage unit 190. The managed group information includes a group identifier and one or more pieces of member information. The member information includes information (e.g., addresses) for communicating with the terminal devices 100 that will become members.

[0074] In step S251, the group management unit 150 generates a key for the common key cryptosystem, thereby obtaining a group common key. The process in step S251 is the same as step S121 in the first embodiment.

[0075] In step S252, the group management unit 150 stores the group common key in the storage unit 190. The process in step S252 is the same as step S122 in the first embodiment.

[0076] In step S253, the group management unit 150 transmits the group common key to each member. Specifically, the group management unit 150 refers to the managed group information and transmits the group common key to each member in association with the group identifier.

[0077] In each member's terminal device 100, the group management unit 150 receives the group common key and stores it.

[0078] The content registration process of the access control method will be described with reference to Fig. 13. In step S231, the content registration unit 130 selects one unselected piece of content from one or more pieces of content to be registered. Step S231 is the same as step S133 in the first embodiment.

[0079] In step S232, the content registration unit 130 acquires the content identifier of the selected content. Step S232 is the same as step S134 in the first embodiment.

[0080] In step S233, the content registration unit 130 registers the selected content in the distributed file system 180. Step S233 is the same as step S135 in the first embodiment.

[0081] In step S234, the content registration unit 130 encrypts the content identifier using the group common key. This results in an encrypted content identifier. Step S234 is the same as step S136 in the first embodiment. However, the group common key is obtained from the storage unit 190.

[0082] In step S235, the content registration unit 130 determines whether any unselected content remains. If any unselected content remains, the process proceeds to step S231. If no unselected content remains, the process proceeds to step S236.

[0083] In step S236, the content registration unit 130 registers the encrypted content identifier of each content in the block chain 170. Step S236 is the same as step S138 in the first embodiment.

[0084] The content acquisition process of the access control method will be described with reference to Fig. 14. In step S241, the content acquisition unit 140 selects one unselected piece of content from one or more pieces of referenced content. Step S241 is the same as step S141 in the first embodiment.

[0085] In step S242, the content acquisition unit 140 decrypts the encrypted content identifier using the group common key to obtain a content identifier. Step S242 is the same as step S144 in the first embodiment. However, the group common key is acquired from the storage unit 190.

[0086] In step S243, the content acquisition unit 140 acquires the content using the content identifier. Step S243 is the same as step S145 in the first embodiment.

[0087] In step S244, the content acquisition unit 140 determines whether any unselected content remains. If any unselected content remains, the process proceeds to step S241. If no unselected content remains, the process ends.

[0088] ***Description of the Embodiment*** An embodiment of the access control system 200 will be described with reference to Figs. 15 to 17. Fig. 15 shows the configuration of the access control system 200. The users of the access control system 200 are company A, company B, and company C. Each of company A, company B, and company C owns a terminal device 100. Company A belongs to group Gp1 and group Gp2, and the terminal device 100 of company A stores the group common key for group Gp1 and the group common key for group Gp2. Company B belongs to group Gp1 and group Gp3, and the terminal device 100 of company B stores the group common key for group Gp1 and the group common key for group Gp3. Company C belongs to group Gp2 and group Gp3, and the terminal device 100 of company C stores the group common key for group Gp2 and the group common key for group Gp3. For example, the terminal device 100 of company A generates and stores a group common key for group Gp1, and transmits the group common key for group Gp1 to the terminal device 100 of company B. Then, the terminal device 100 of company B receives and stores the group common key for group Gp1.

[0089] 16 shows the configuration of the blockchain 170. The blockchain 170 has a content list. A plurality of encrypted content identifiers are registered in the content list. Specifically, the content list registers a registered user identifier, a group identifier, an encrypted content identifier, a content name, and a timestamp for each piece of content.

[0090] FIG. 17 shows the configuration of the distributed file system 180. The distributed file system 180 manages a single piece of content by dividing it into multiple pieces of data. For example, a content identifier (Qm9Ed+...) is formed from three pieces of data: content identifiers (Qm8c2..., QmdeA6..., QmBxd7...). Multiple pieces of content are registered in the distributed file system 180. Specifically, each piece of content is registered in the distributed file system 180 in association with its corresponding content identifier. The distributed file system 180 accepts an input content identifier and outputs content associated with the same content identifier as the input content identifier. For example, when a content identifier (Qm9Ed+...) is input, the distributed file system 180 outputs content associated with the content identifier (Qm9Ed+...). If the referenced content is content in group Gp1, the content ID is obtained by decrypting the encrypted content identifier of group Gp1 using the group common key of group Gp1.

[0091] ***Effects of the Second Embodiment*** The second embodiment can be applied to a distributed information system, and realizes access control to distributed data faster and with fewer resources. Specifically, in the second embodiment, the hash value (approximately 64 bytes) of the content is encrypted and decrypted. This realizes processing faster and with fewer resources than when the content itself or the key information file is encrypted and decrypted.

[0092] *** Supplementary Information about the Embodiment *** The hardware configuration of the terminal device 100 will be described with reference to Fig. 18. The terminal device 100 includes a processing circuit 109. The processing circuit 109 is hardware that realizes a key management unit 110, a group registration unit 120, a content registration unit 130, a content acquisition unit 140, and a group management unit 150. The processing circuit 109 may be dedicated hardware, or may be a processor 101 that executes a program stored in memory 102.

[0093] When the processing circuit 109 is dedicated hardware, the processing circuit 109 may be, for example, a single circuit, a multiple circuit, a programmed processor, a parallel programmed processor, an ASIC, an FPGA, or a combination thereof. ASIC is an abbreviation for Application Specific Integrated Circuit. FPGA is an abbreviation for Field Programmable Gate Array.

[0094] The terminal device 100 may include a plurality of processing circuits that replace the processing circuit 109 .

[0095] In the processing circuit 109, some functions may be realized by dedicated hardware, and the remaining functions may be realized by software or firmware.

[0096] In this way, the functions of the terminal device 100 can be realized by hardware, software, firmware, or a combination of these.

[0097] Each embodiment is an example of a preferred embodiment and is not intended to limit the technical scope of the present disclosure. Each embodiment may be implemented in part or in combination with other embodiments. Procedures described using flowcharts, etc. may be modified as appropriate.

[0098] The "part" of each element of the terminal device 100 may be read as a "process," a "step," a "circuit," or a "circuitry."

[0099] 100 Terminal device, 101 Processor, 102 Memory, 103 Auxiliary storage device, 104 Communication device, 105 Input / output interface, 109 Processing circuit, 110 Key management unit, 120 Group registration unit, 130 Content registration unit, 140 Content acquisition unit, 150 Group management unit, 170 Blockchain, 180 Distributed file system, 190 Storage unit, 200 Access control system.

Claims

1. A content registration unit that encrypts a content identifier for identifying content using a group common key for a group composed of a plurality of members to whom access to the content is permitted, and registers an encrypted content identifier; and a content acquisition unit that acquires the encrypted content identifier, decrypts the content identifier from the encrypted content identifier using the group common key, and acquires the content using the content identifier. An access control system comprising:

2. The access control system according to claim 1, wherein the content registration unit registers the content in a distributed file system, and the content acquisition unit inputs the content identifier into the distributed file system and acquires the content from the distributed file system.

3. The access control system according to claim 1 or claim 2, wherein the content registration unit encrypts a hash value of the content as the content identifier.

4. The access control system includes: a group registration unit that generates the group common key, encrypts the group common key using the public key of each member of the group, and registers an encrypted group common key for each member of the group; the content registration unit acquires the encrypted group common key of a registered member who is any one of the members of the group, decrypts the group common key from the encrypted group common key of the registered member using the secret key corresponding to the public key of the registered member, encrypts the content identifier using the group common key, and registers the encrypted content identifier; the content acquisition unit acquires the encrypted content identifier and the encrypted group common key of a reference member who is any one of the members of the group, decrypts the group common key from the encrypted group common key of the reference member using the secret key corresponding to the public key of the reference member, decrypts the content identifier from the encrypted content identifier using the group common key, and acquires the content using the content identifier. The access control system according to any one of claims 1 to 3.

5. The group registration unit registers the encrypted group common key of each member in the blockchain, the content registration unit registers the encrypted content identifier in the blockchain, and the content acquisition unit acquires the encrypted content identifier and the encrypted group common key of the reference member from the blockchain. The access control system according to claim 4.

6. A registration device including the group registration unit and used in the access control system according to claim 4 or 5.

7. A registration device including the content registration unit and used in the access control system according to any one of claims 1 to 5.

8. A reference device including the content acquisition unit and used in the access control system according to any one of claims 1 to 5.

9. An access control method in which a registration device encrypts a content identifier for identifying content using a group common key for a group composed of a plurality of members to whom access to the content is permitted, registers an encrypted content identifier, a reference device acquires the encrypted content identifier, decrypts the content identifier from the encrypted content identifier using the group common key, and acquires the content using the content identifier.

10. An access control program for causing a computer operating as a registration device to execute a content registration process of encrypting a content identifier for identifying content using a group common key for a group composed of a plurality of members to whom access to the content is permitted and registering an encrypted content identifier, and causing a computer operating as a reference device to execute a content acquisition process of acquiring the encrypted content identifier, decrypting the content identifier from the encrypted content identifier using the group common key, and acquiring the content using the content identifier.

Citation Information

Patent Citations

  • Group subordinate terminal, group administrative terminal, server, key updating system and key updating method thereof

    JP2009033721A

  • Content management method and program, and content use terminal

    JP2011187017A

  • Litz wire cable

    KR1020220135582A

  • System and method to provide a secure communication of information

    US10686592B1

  • Method and System for Data Transmission

    US20100268840A1