Realtime backup / restoration type digital asset safeguarding service-providing system

The digital asset guard service system addresses the challenge of protecting small data volumes from high-level cyberattacks and physical destruction by employing a distributed ledger network with smart contracts, ensuring secure management and real-time restoration.

WO2025211431A1PCT designated stage Publication Date: 2025-10-09NISHIMOTO KAZUYA +2
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/013695
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-03
Filing Date
2025-04-03
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

Current systems lack effective protection against high-level cyberattacks, such as quantum computer cryptanalysis and EMP attacks, and are inadequate for managing and evacuating small volumes of data linked to personal information in real-time, especially in the context of strict legal regulations and complex data management requirements.

Method used

A real-time evacuation and restoration type digital asset guard service system utilizing a distributed ledger technology with smart contracts, authenticators, and a network of nodes across multiple regions to securely encrypt, divide, and manage small data volumes, ensuring protection and restoration against cyberattacks and physical destruction.

Benefits of technology

The system provides robust protection and efficient restoration of small data volumes linked to personal information, safeguarding against quantum computer cryptanalysis and EMP attacks, while adhering to legal regulations and ensuring data integrity and availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025013695_09102025_PF_FP_ABST
    Figure JP2025013695_09102025_PF_FP_ABST
Patent Text Reader

Abstract

[Problem] To provide a system that is capable of: preserving, in real time, digital assets comprising small-capacity data associated with personal information; strongly protecting important information from encryption analysis by a quantum computer, EMP attack, etc.; and restoring said important information. [Solution] Regarding the backup of data, the present invention involves: acquiring information on agreement between both a first authenticator and a second authenticator; encrypting and dividing the data into a plurality of items on the basis of the information on agreement; classifying the data items by being associated with a plurality of preservation points so as to manage the data items under a black box environment, and allocating the data items, which are associated with information on the preservation points and are to be managed, to a plurality of sets of distributed file management groups comprising node groups at a plurality of bases in various regions around the world formed for a planet; and recording said data items in a distributed manner across nodes of the respective bases that belong to the distributed file management groups, and also creating and encrypting index information of each data item that is recorded in a distributed manner and recording the same in a node group of a specific base.
Need to check novelty before this filing date? Find Prior Art

Description

Real-time evacuation and restoration type digital asset guard service provision system

[0001] The present invention relates to a real-time backup and restoration type digital asset guard service providing system that protects digital assets consisting of small amounts of data linked to important information such as personal information in real time (focusing on protecting not only from information leakage but also from information destruction) from anticipated future risks such as high-level cyber attacks that exceed normal levels, severe natural disasters, or physical attacks. Note that in this specification, "system" means a computer system that specifically realizes software-based information processing using hardware resources, and is configured by combining elements such as computers and other electronic devices, software, communication networks, and data.

[0002] Traditionally, distributed encryption technologies such as blockchain have been used as a means of protecting data from general cyberattacks. However, in the future, we can expect to see more sophisticated cyberattacks (perpetrated by state actors or actors combining state and non-state actors) that exceed the standard level, such as quantum computer-based cryptography and EMP attacks, as described below. These sophisticated cyberattacks aim to leak, alter, erase, or destroy digital assets (confidential information such as personal information and national security-related information, control modules for critical functions, currencies such as stablecoins, digital currencies, and digital securities, and rights such as contracts). For this reason, it is becoming increasingly important to protect digital assets from sophisticated cyberattacks.

[0003] Digital assets that are subject to high-level cyber attacks are thought to cover a wide range of digital assets, including personal information (account information) and personal asset information held by financial institutions, confidential information such as personal information and national security-related information held by large corporations and government agencies, confidential internal information, important contracts and designs, control modules and data, and information related to lifelines. To date, there have been no services (especially for private use) that can provide a high degree of protection against high-level cyber attacks, and in fact, no services that are resistant to quantum computer cryptanalysis (such as PQC (Post-Quantum Cryptography)) have been put into practical use.

[0004] High-level cyber attacks High-level cyber attacks mainly include cryptoanalysis using quantum computers (often expressed as Y2Q (Years To Quantum)) and EMP attacks.

[0005] Quantum Computer Cryptanalysis Quantum computer cryptanalysis is a cyberattack that uses public keys, such as SSL (Secure Sockets Layer) and blockchain, to decrypt private keys and RSA cryptography, thereby breaching cryptographic defenses and stealing critical information and disrupting systems. If quantum computers are misused, even if digital assets are protected by storing private keys in cold wallets isolated from the system, there is a high risk that private keys could be decrypted using public keys. Quantum computer cryptanalysis is a cyberattack that breaches current basic security known as encryption. It is expected that combining it with various other attacks will lead to unexpected attacks with far-reaching impacts. Quantum computers are expected to be practically usable around 2025, and with improved performance, current general encryption methods are expected to be decrypted by around 2030. Furthermore, even if sensitive information is currently difficult to decrypt, it is likely that it will be decrypted by quantum computers in the near future. Therefore, it is important to make the information more resistant to quantum computer cryptanalysis than is currently possible.

[0006] EMP Attacks An EMP attack is a cyberattack that uses strong electromagnetic waves generated by a nuclear explosion at high altitudes (stratosphere) to destroy electronic devices, systems, and magnetically recorded digital assets. An EMP attack could potentially destroy evacuated digital assets and the system modules that store them. While not an EMP attack, large solar flares occur periodically. The strong magnetic field caused by solar flares can cause physical destruction equal to or greater than that of an EMP attack. In recent years, reports have suggested that a direct hit from a large solar flare on the far side of the sun, if directed toward Earth, could cause considerable damage. Furthermore, the risk of a Nankai Trough earthquake occurring by 2030 is a growing concern in Japan. Data centers are concentrated in the Tokyo-Osaka region, which is within the expected damage range of such an earthquake, and similar system destruction damage is expected.

[0007] Current Measures to Counter High-Level Cyberattacks Quantum cryptography and other technologies are being researched as a countermeasure against cryptanalysis using quantum computers. However, considering the timing of general adoption and the cost of quantum cryptography, it is not yet ready for practical use. Similarly, research is being conducted into the practical application of quantum computer cryptanalysis resistance (PQC (Post-Quantum Cryptography)), but it has not yet been put into practical use. Furthermore, as a countermeasure against EMP attacks, data centers (including cloud services) that meet US EMP resistance standards have implemented measures such as the installation of anti-magnetic mesh. However, only a portion of data centers in Japan have implemented anti-magnetic mesh, or the countermeasures do not meet the standards. Regarding equipment destruction, Japan faces the risk of a Nankai Trough earthquake, and the fact that approximately 90% of data centers are located in areas expected to be affected by the earthquake also poses a significant risk.

[0008] Another option is to use the cloud to evacuate data to overseas regions (independent regions with data centers). However, financial institutions (especially large financial institutions) are reluctant to use cloud services due to risks associated with the cloud itself, the risk of cloud backups being corrupted, and inadequate user management. Most domestic cloud services currently operate through overseas service providers, which could easily withdraw if a problem occurs in Japan. Furthermore, contracts stipulate that lawsuits in the event of a problem will be conducted overseas. Furthermore, incorrect cloud configurations could create security holes, exposing important information to the public or even causing the system to be destroyed by a simple attack. Even with domestic cloud services, evacuating digital assets using only one cloud provider poses the risk of the evacuated data becoming unusable in the event of a cloud system failure.

[0009] In particular, measures to deal with cyber-attacks that simultaneously use quantum computer-based cryptanalysis, EMP attacks, and more advanced artificial intelligence, etc., are currently complex and costly, and have not yet reached a level at which they can be put to practical use. In fact, even in light of current cases of cyber-attacks, there are limitations to how much can be done to counter cyber-attacks on the front end, and since in many cases attacks are actually initiated via human users, it is recognized that there are limitations to how much can be done to defend against cyber-attacks on the front end.

[0010] Other Issues: The system's ability to evacuate digital assets, including personal information, confidential corporate information, and state-level classified information, is subject to strict restrictions. For example, if a business entity other than the individual manages digital assets, the individual's consent is required. However, it is difficult to obtain consent for all digital assets that could potentially be managed. This limits and complicates digital asset management. Furthermore, when using distributed cryptography to evacuate digital assets, public blockchains and other blockchains cannot sever the chain of blocks. This prevents the deletion of unnecessary data or the erasure of digital data for customer convenience. Furthermore, because block sizes are relatively small, digital data exceeding the block size cannot be recorded. This limits the amount of information that can be stored on blockchains. Furthermore, managing personal information on public chains is impossible. Even if a function similar to the evacuation of digital assets using distributed ledger technology could be created by combining public chains and freeware, the responsibility for public chains and freeware is unclear. It is not advisable to handle important information or personal information with a digital asset evacuation service that is fundamentally unguaranteed, given its reliability. While current attacks on blockchains involve the theft of private keys, in the future, cryptographic analysis of addresses will become the main method. Therefore, even if technology is developed to defend against attacks that steal private keys on current blockchains, it is not reassuring.

[0011] Therefore, the present inventors first considered and examined measures to strongly and efficiently protect important information such as secret / classified information and personal information from high-level cyber attacks and physical destruction, and to restore important information without it being stolen by third parties even if it is subjected to cryptographic analysis using a quantum computer or an EMP attack, or measures to make it impossible for third parties to analyze the management information even if it is stolen by a third party, by first targeting the maintenance processing of backup data for internal systems, etc., which is performed in batches on a regular basis.

[0012] However, among the data that constitutes digital assets that need to be preserved, there is a huge amount of small-volume data linked to personal information. Unlike backup data held by corporate systems, small-volume data linked to personal information often requires real-time data preservation from the perspective of convenience (in the event of system destruction, in order to quickly restore the system, even a backup structure that allows for database-like processing is desirable, in other words, a function that realizes storage-like processing with data preservation functionality is desirable).

[0013] Furthermore, personal information is subject to strict legal regulations from the perspective of protection, and there is a strong need to further strengthen defenses against external cyber attacks in order to preserve small amounts of data linked to personal information.

[0014] Furthermore, there are many different types of data linked to personal information, and it is desirable to preserve that data in a variety of forms. Small units of data linked to personal information that do not exceed the block size can be evacuated to a blockchain, but as mentioned above, blockchains such as public chains cannot cut the chains that connect the blocks. When evacuating data to a blockchain, even if the data itself is subjected to a cyberattack, or, as an application of this, information that exceeds the blockchain's block size is transferred to a distributed file function and only the management information is recorded on the block side, it is necessary to manage this data as meaningless data that is not recognized as personal information (including important information) and cannot be restored to the original personal information as is, even if the data itself is subjected to a cyberattack.

[0015] The present invention has been made in consideration of the above-mentioned problems, and aims to provide a real-time evacuation and restoration type digital asset guard service provision system that can preserve digital assets consisting of (basically) small amounts of data linked to personal information in real time, strongly and efficiently protect important information such as confidential information and personal information from high-level cyber attacks and physical destruction, and restore important information without it being stolen by third parties even if it is subjected to cryptographic analysis using a quantum computer or an EMP attack, or make it impossible for a third party to restore the management information even if it is stolen by a third party.

[0016] In order to achieve the above object, a real-time evacuation and restoration type digital asset guard service provision system according to a first aspect of the present invention is a real-time evacuation and restoration type digital asset guard service provision system for guarding digital assets from high-level cyber attacks, constructed with a distributed ledger in distributed ledger technology such as blockchain, and a smart contract or server application for performing predetermined processing using the data managed in the distributed ledger, or a system for handling data that is difficult to manage in a system, such as personal information, mainly on-chain in two configurations, one in which the information is managed by a company, and one in which the information is managed by an individual, and is a base system for managing the personal information directly on-chain in both configurations, or for separating the personal information part based on the information and utilizing it as personal attribute information for big data analysis, etc., and is composed of a group of nodes combining nodes at multiple locations in different regions around the world (a unit that combines blockchain, file distributed management functions, etc., and is a distributed smart and a distributed ledger structure constructed of a plurality of chains that may include a distributed ledger group, a public blockchain, etc., and that is primarily a closed blockchain such as a private or consortium blockchain, and that is constructed having a plurality of planets (each forming a unit constituting a system for providing services that implement a blockchain contract, a server application, etc.); a first authenticator information management means that manages first authenticator authentication information required to authenticate a first authenticator who is one of the data managers that manages customers and customer data, first authenticator ID information and key information required for data evacuation, restoration, etc.; a second authenticator information management means that manages second authenticator authentication information required to authenticate a second authenticator who is the other of the data managers that manages customers and customer data, second authenticator ID information and key information required for data evacuation, restoration, etc.; an external first authenticator authentication system that authenticates the first authenticator; an external second authenticator authentication system that authenticates the second authenticator; a file data real-time evacuation system; and a file data real-time restoration system, wherein the nodes at each base area data saving process agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the saving process of the data to be saved for the customer, a customer data saving instruction means for issuing an instruction to save the data to be saved for the customer based on the agreement information when the agreement information between the first authenticator and the second authenticator regarding the saving process of the data to be saved for the customer is acquired by the data saving process agreement information acquisition means; a program (or smart contract) having a plurality of encryption / division algorithms for encrypting and dividing file data differently; and a program (or smart contract) having a predetermined encryption / division algorithm based on the agreement information between the first authenticator and the second authenticator regarding the saving process of the data to be saved for the customer acquired by the data saving process agreement information acquisition means (or a first parameter specified by the customer who desires to save file data, which is included in the agreement information). a file data encryption / division means for encrypting and dividing the customer data to be saved received by the customer data saving instruction receiving means into a plurality of file data using a program (or a smart contract) having the encryption / division algorithm received by the encryption / division algorithm selection receiving means; an upload means for uploading each of the file data encrypted and divided into a plurality of pieces by the file data encryption / division means to a first temporary storage area; and a file data security point association sorting means for associating each of the file data encrypted and divided into a plurality of pieces by the file data encryption / division means and uploaded to the first temporary storage area by the upload means with one of at least two security points for managing the file data.a storage point information management means for managing, in a black box environment, information on the storage points for managing the file data sorted by the file data storage point association sorting means; and a distributed file management group sorting means or a distributed file management group sorting smart contract (or service) provided for each planet, which has a function of sorting, based on agreement information between the first authenticator and the second authenticator (or the first parameter included in the agreement information and a second parameter specified by the digital asset guard service administrator) regarding the evacuation processing of the data to be evacuated for the customer, into a plurality of distributed file management groups, the distributed file management group sorting means or a distributed file management group sorting smart contract (or service) having a function of sorting, based on agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer acquired by the data evacuation processing agreement information acquisition means, the file data associated with the information on the storage points sorted by the file data storage point association sorting means and managed in a black box environment by the storage point information management means, into a plurality of distributed file management groups, the distributed file management group sorting means or a distributed file management group sorting smart contract (or service) having a function of sorting, based on agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer acquired by the data evacuation processing agreement information acquisition ... a distributed recording means or a distributed recording smart contract (or server application) that is provided on each planet and has the function of distributing and recording each of the file data associated with the information of each of the conservation points that has been sorted by the distributed file management group sorting means or the distributed file management group sorting smart contract (or server application) and that is managed in a black box environment by the conservation point information management means, to each of the base nodes belonging to the corresponding distributed file management group and to recording devices at multiple bases that are connected to the base nodes via a network; terminal information (information that identifies the other party, such as a fixed IP address) for uploading to the first temporary storage area using the upload means; and the number of a predetermined processing means or smart contract (or server application) that performs the corresponding processing of the recording destination of the customer's file data;a smart contract (or server application) for creating and recording system setting information that has a function of creating system setting information including information on the planet to which the file data is recorded, information on a group of file servers (in a node at a specified location and in recording devices at multiple locations that are networked to the node at that location) that constitute a distributed file management group, encrypting the information, and recording it in a group of nodes at a specific location in the distributed ledger structure; key information that uses the first authenticator ID information and the second authenticator ID information that are included in the agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer that is acquired by the data evacuation processing agreement information acquisition means; information on the file name of each of the file data that is distributedly recorded by each of the distributed recording means or the smart contract (or server application) for distributed recording and that is linked to the information on the conservation point that is sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means; a smart contract (or server application) for creating server index information, which has a function of creating server index information having configuration information of each of the distributed file management groups to which file data will be allocated; a smart contract (or server application) for recording server index information, which has a function of encrypting the server index information created by the smart contract (or server application) for creating server index information and recording it in a node group at a specific location in the distributed ledger structure; and a smart contract (or program with a wallet function) for creating customer setting information, which is linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means, and which has a function of creating customer setting information having agreement information between the first authenticator and the second authenticator (or setting information of the first parameter included in the agreement information) regarding the evacuation processing of the data to be evacuated for the customer, which is acquired by the data evacuation processing agreement information acquisition means;a customer index information creating smart contract (or a program with a wallet function) having a function of creating customer index information having information on the original file name and upload date of the customer's file data to be saved; a customer index information recording smart contract (or a server application) having a function of encrypting the customer index information created by the customer index information creating smart contract (or the program with a wallet function) and recording it in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means for erasing each file data uploaded to the first temporary storage area after the server index information has been encrypted and recorded in the group of nodes at a specific location in the distributed ledger structure by the server index information recording smart contract (or server application); The data saving process agreement information acquisition means includes a data saving process request instruction means for instructing, via the first authenticator, a request for saving process of the data to be saved of the customer, a data saving process request instruction acceptance means for accepting a request instruction for saving process of the data to be saved of the customer from the data saving process request instruction means, and a data saving process request instruction acceptance means for acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means when the data saving process request instruction acceptance means accepts a request instruction for saving process of the data to be saved of the customer, and providing the information to an external first authenticator authentication system, and requesting authentication of the first authenticator. an authenticator authentication requesting means; a first authenticator ID information and key information receiving means for data evacuation, which receives the first authenticator ID information and key information required for data evacuation from the first authenticator information managing means when the first authenticator is authenticated by the external first authenticator authentication system; and a first information notifying means, when the first authenticator ID information and key information receiving means for data evacuation has received the first authenticator ID information and key information required for data evacuation, notifying the second authenticator of information that the first authenticator has issued a request instruction for evacuation processing of the data to be saved for the customer and information urging the second authenticator to issue an approval instruction for the evacuation processing of the data to be saved for the customer.a data saving process approval instruction means for instructing approval of a process for saving data to be saved for the customer via the second authenticator notified by the first information notification means; a data saving process approval instruction receiving means for receiving an instruction to approve the process for saving data to be saved for the customer from the data saving process approval instruction means; and a data saving process approval instruction receiving means for receiving an instruction to approve the process for saving data to be saved for the customer from the data saving process approval instruction means when the data saving process approval instruction receiving means receives an instruction to approve the process for saving data to be saved for the customer, the data saving process approval instruction receiving means for receiving second authenticator authentication information required for authenticating the second authenticator from the second authenticator information management means and transmitting the second authenticator authentication information to an external second authenticator. a second authenticator authentication requesting means for requesting authentication of the second authenticator when receiving a data saving processing approval instruction, which provides the second authenticator with the second authenticator authentication system and requests authentication of the second authenticator; a second authenticator ID information and key information receiving means for data saving, which receives the second authenticator ID information and key information required for saving data from the second authenticator information managing means when the second authenticator is authenticated by the external second authenticator authentication system; and a second authenticator ID information and key information receiving means for data saving, which receives the second authenticator ID information and key information required for saving data from the second authenticator information managing means when the second authenticator ID information and key information receiving means for data saving receives the second authenticator ID information and key information required for saving data. a second information notification means for notifying the first authenticated person of information that an approval instruction for the evacuation process of the data to be saved of the customer has been given by the first authenticated person and information urging the first authenticated person to request an instruction for the evacuation process of the data to be saved of the customer; a data evacuation process request instruction means for instructing a request for the evacuation process of the data to be saved of the customer via the first authenticated person who has received the notification from the second information notification means; a data evacuation process request instruction receiving means for receiving an instruction to request the evacuation process of the data to be saved of the customer from the data evacuation process request instruction means; and a data saving process agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the saving process of the data to be saved for the client, using the first authenticator ID information and key information required for data saving received by the first authenticator ID information and key information receiving means for data saving and the second authenticator ID information and key information required for data saving received by the second authenticator ID information and key information receiving means for data saving, when the request instruction receiving means receives an instruction to request saving process of the data to be saved for the client,The file data real-time restoration system includes: a data restoration processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer, between the first authenticator and the second authenticator; a customer data restoration instruction means for instructing the restoration of the data to be restored for the customer based on the agreement information when the agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer is acquired by the data restoration processing agreement information acquisition means; a program (or smart contract) having a plurality of decryption and combination algorithms with different file data decryption and combination processing methods, linked to a program (or smart contract) having each of the encryption and division algorithms; a customer data restoration instruction acceptance means for accepting an instruction to restore the data to be restored for the customer from the customer data restoration instruction means; and a protection point information management means provided on each planet, which manages the protection point information on the planet corresponding to the protection point. for each group of file data linked to the information of each of the conservation points managed in a black-box environment by the means, key information (or the first parameter included in the key information or a first composite parameter (composed of a pair of a first decryption parameter designated and managed offline by the customer and a first encryption parameter automatically generated from the first decryption parameter) using the first authenticator ID information and the second authenticator ID information required for data restoration in the agreement information between the first authenticator and the second authenticator regarding the restoration process of the data to be restored for the customer, which is linked to the file data to be extracted and received by the customer data restoration instruction receiving means and acquired by the data restoration process agreement information acquisition means, and the second parameter or a second decryption parameter (designated and managed offline by the digital asset guard service administrator and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant process),a smart contract (or server application) for extracting encrypted server index information that has a function of extracting encrypted server index information (recorded in a group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on a second composite parameter (composed of a pair of a second encryption parameter incorporated and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter; and a smart contract (or server application) for extracting encrypted server index information that is provided in each planet and that, for each group of file data linked to information on each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point, extracts the encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information. a server index information decryption smart contract (or server application) having a function of decrypting server index information, the server index information being provided in each planet, and for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point, the server index information being decrypted by the server index information decryption smart contract (or server application), the file data being allocated to each of the distributed file management groups by the distributed file management group allocation means or the distributed file management group allocation smart contract (or server application), and the file data being distributed and recorded by each of the distributed recording means or the distributed recording smart contract (or server application) in a node at each base belonging to each of the distributed file management groups and in recording devices at multiple bases connected to the node at each base via a network;an encrypted and divided file data extraction means or a smart contract (or server application) for extracting encrypted and divided file data having a function of extracting each of the file data in an encrypted and divided state from any of the nodes of each base belonging to each of the distributed file management groups and recording devices of multiple bases connected to the nodes of the base via a network; a download means provided in each planet for downloading each of the file data in an encrypted and divided state extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data for each group of the file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point; a file data restoration means for decrypting and combining all of the file data associated with information of all of the conservation points in an encrypted and divided state, which is extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data and downloaded to the second temporary storage area by the download means, into one file data to restore the client's data before it was saved, using a program (or smart contract) having the decryption and combination algorithm linked to a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means; and a second data erasure means for erasing each of the file data in an encrypted and divided state, which was downloaded to the second temporary storage area after being restored to the client's data before it was saved by the file data restoration means, via the first authenticator;a data restoration processing request instruction means for instructing a request for restoration processing of data to be restored for the customer; a data restoration processing request instruction receiving means for receiving a request instruction for restoration processing of data to be restored for the customer from the data restoration processing request instruction means; and when the data restoration processing request instruction receiving means receives a request instruction for restoration processing of data to be restored for the customer, acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means and providing the information to an external first authenticator authentication system to request authentication of the first authenticator. a first authenticator authentication requesting means for requesting data restoration processing when receiving a data restoration processing request instruction for the first authenticator to authenticate the first authenticator by the external first authenticator authentication system; a first authenticator ID information and key information receiving means for data restoration that receives the first authenticator ID information and key information necessary for data restoration from the first authenticator information managing means when the first authenticator ID information and key information receiving means for data restoration receives the first authenticator ID information and key information necessary for data restoration; a third information notifying means for notifying the second authenticator of information that the first authenticator has issued a request instruction for restoration processing of the data to be restored of the customer and information urging the second authenticator to give an instruction to approve the restoration processing of the data to be restored of the customer when the first authenticator ID information and key information receiving means for data restoration receives the first authenticator ID information and key information necessary for data restoration; a data restoration processing approval instruction means for instructing approval of the restoration processing of the data to be restored of the customer via the second authenticator that has received the notification from the third information notifying means; a data restoration processing approval instruction receiving means for receiving an instruction to approve the restoration processing of the data to be restored of the customer from the data restoration processing approval instruction means; a data restoration processing approval instruction receiving second authenticator authentication requesting means for, when receiving an instruction to approve the restoration processing, acquiring second authenticator authentication information required to authenticate the second authenticator from the second authenticator information managing means, providing the information to an external second authenticator authentication system, and requesting authentication of the second authenticator; and a data restoration second authenticator ID information and key information receiving means for, when the second authenticator is authenticated by the external second authenticator authentication system, receiving the second authenticator ID information and key information required to restore the data from the second authenticator information managing means.a fourth information notifying means for notifying the first authenticator of information that the second authenticator has instructed to approve the restoration of the data to be restored by the customer and information urging the first authenticator to instruct a request for the restoration of the data to be restored by the customer when the second authenticator ID information and key information receiving means for data restoration receives the second authenticator ID information and key information necessary for data restoration; a data restoration processing request instructing means for instructing the first authenticator to request the restoration of the data to be restored by the customer via the first authenticator that has received the notice from the fourth information notifying means; and a data restoration processing request instructing means for receiving an instruction to request the restoration of the data to be restored by the data restoration processing request instructing means. and a data restoration processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer, using the first authenticator ID information and key information required for data restoration received by the first authenticator ID information and key information receiving means for data restoration and the second authenticator ID information and key information required for data restoration received by the second authenticator ID information and key information receiving means for data restoration, when the data restoration processing request instruction receiving means accepts a request instruction for restoration processing of the data to be restored for the customer.

[0017] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the file data real-time save system comprises a user-side file data real-time save system that operates on the side of a user (customer and data manager) who desires to save file data, and a digital asset guard service operator-side file data real-time save system that operates on the side of the digital asset guard service operator, and the user-side file data real-time save system comprises the data save processing agreement information acquisition means, the customer data save instruction means, a program (or smart contract) comprising a plurality of the encryption / division algorithms, the encryption / division algorithm selection acceptance means, the customer data save instruction acceptance means, the file data encryption / division means, the upload means, the file data preservation point association sorting means, and the preservation point information management means, and the digital asset guard service operator-side file data real-time save system comprises the distributed file management group allocation means or the distributed file management group allocation means. the file data real-time restoration system comprises a user-side file data real-time restoration system operated on the side of a user (customer or data manager) who desires to restore saved file data, and a digital asset guard service operator-side file data real-time restoration system operated on the side of the digital asset guard service operator, the user-side file data real-time restoration system comprising the data restoration processing agreement information acquisition means, the customer data restoration instruction means, a program (or smart contract) having a plurality of the decryption and combination algorithms, the downloading means, the file data restoration means, and the second data erasure means;The digital asset guard service operator-side file data real-time restoration system preferably comprises the customer data restoration instruction receiving means, the encrypted server index information extraction smart contract (or server application), the server index information decryption smart contract (or server application), and the encrypted and divided file data extraction means or the encrypted and divided file data extraction smart contract (or server application).

[0018] Furthermore, the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention has a file data real-time deletion system, the file data real-time deletion system including: data deletion processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the deletion processing of data to be deleted for the customer, customer data deletion instruction means for issuing an instruction to delete the data to be deleted for the customer based on the agreement information when the agreement information acquisition means has acquired agreement information between the first authenticator and the second authenticator regarding the deletion processing of data to be deleted for the customer, customer data deletion instruction receiving means for receiving an instruction to delete the data to be deleted for the customer from the customer data deletion instruction means, and a customer data deletion instruction receiving means provided in each planet, for each group of file data linked to information of each of the protection points managed in a black box environment by the protection point information management means in the planet corresponding to the protection point. key information formed using the first authenticator ID information and the second authenticator ID information required for data deletion in agreement information between the first authenticator and the second authenticator regarding the deletion process of the data to be deleted for the customer acquired by the data deletion process agreement information acquisition means, which is linked to the file data to be deleted received by the attachment means (or the first parameter included in the key information or a first composite parameter (composed of a pair of a first decryption parameter designated and managed offline by the customer and a first encryption parameter automatically generated from the first decryption parameter); the second parameter or a second decryption parameter (designated and managed offline by the digital asset guard service administrator and incorporated and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing), and a second encryption parameter automatically generated from the second decryption parameter (embedded and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing);a smart contract (or server application) for extracting encrypted server index information to be deleted, which has a function of extracting encrypted server index information (recorded in a node group at a specific site in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on a second composite parameter (composed of a pair of parameters, each of which is a parameter consisting of a first composite parameter and a second composite parameter consisting of a first composite parameter and a second composite parameter), a smart contract (or server application) for decrypting server index information to be deleted, which is provided in each planet, and has a function of decrypting the encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information to be deleted, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point; and a smart contract (or server application) for deleting encrypted and divided file data that has a function of deleting, for each group of file data linked to information of each of the conservation points managed in a black-box environment, from each of the base nodes belonging to each of the distributed file management groups and from all of the base node recording devices connected to the base nodes via a network, the encrypted and divided file data being allocated to each of the distributed file management groups by the distributed file management group allocation means using server index information decrypted by the smart contract (or server application) for decrypting server index information to be deleted, and being distributedly recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in all of the base node recording devices connected to the base nodes via a network, the encrypted and divided file data being allocated to each of the distributed file management groups by the distributed file management group allocation means using server index information decrypted by the smart contract (or server application) for decrypting server index information to be deleted, the distributed recording means distributively recording the encrypted and divided file data being targeted for deletion from each of the base nodes belonging to each of the distributed file management groups and from all of the base node recording devices connected to the base nodes via a network, the data deletion processing agreement information acquisition means comprising: a data deletion processing request instruction means for instructing a request for deletion processing of the data targeted for deletion of the customer via the first authenticator;a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of data to be deleted from the data deletion processing request instruction means; a data deletion processing request instruction receiving first authenticator authentication request means for, when the data deletion processing request instruction receiving means receives a request instruction for deletion processing of data to be deleted from the customer, acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means and providing the information to an external first authenticator authentication system to request authentication of the first authenticator; and a data deletion processing request instruction receiving first authenticator authentication request means for receiving a request instruction for deletion processing of data to be deleted from the external first authenticator authentication system. a data deletion first authenticator ID information and key information receiving means for receiving the first authenticator ID information and key information required for deleting data from the first authenticator information management means when the first authenticator is authenticated by the data deletion first authenticator ID information and key information receiving means for receiving the first authenticator ID information and key information required for deleting data when the data deletion first authenticator ID information and key information receiving means receives the first authenticator ID information and key information required for deleting data, and transmits to the second authenticator information that the first authenticator has issued a request instruction for deletion processing of the data to be deleted for the customer and information prompting the customer to issue an approval instruction for deletion processing of the data to be deleted a data deletion process approval instruction means for instructing approval of a deletion process of data to be deleted for the customer via the second certifier notified from the fifth information notification means; a data deletion process approval instruction receiving means for receiving an instruction to approve the deletion process of data to be deleted for the customer from the data deletion process approval instruction means; and a second certifier authentication information management means for receiving second certifier authentication information required for authenticating the second certifier from the second certifier information management means when the data deletion process approval instruction receiving means receives an instruction to approve the deletion process of data to be deleted for the customer. a second authenticator authentication requesting means for receiving a data deletion processing approval instruction, which acquires information and provides it to an external second authenticator authentication system to request authentication of the second authenticator; a second authenticator ID information and key information receiving means for data deletion, which receives second authenticator ID information and key information necessary for data deletion from the second authenticator information managing means when the second authenticator is authenticated by the external second authenticator authentication system; and a second authenticator ID information and key information receiving means for data deletion, which receives the second authenticator ID information and key information necessary for data deletion from the second authenticator information managing means when the second authenticator ID information and key information necessary for data deletion is receiveda sixth information notification means for notifying the first authenticated person of information that the second authenticated person has given an approval instruction for the deletion process of the data to be deleted of the customer and information urging the first authenticated person to give an instruction to request the deletion process of the data to be deleted of the customer; a data deletion process request instruction means for instructing the first authenticated person who has received the notification from the sixth information notification means to request the deletion process of the data to be deleted of the customer, a data deletion process request instruction receiving means for receiving an instruction to request the deletion process of the data to be deleted of the customer from the data deletion process request instruction means; It is preferable to have a data deletion processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the deletion processing of the data to be deleted for the customer, using the first authenticator ID information and key information required for data deletion received by the first authenticator ID information and key information receiving means for data deletion and the second authenticator ID information and key information required for data deletion received by the second authenticator ID information and key information receiving means for data deletion, when the request instruction receiving means receives a request instruction for deletion processing of the data to be deleted for the customer.

[0019] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, the file data real-time deletion system comprises a user-side file data real-time deletion system operating on the side of the user (customer and data manager) who wishes to delete file data, and a digital asset guard service operator-side file data real-time deletion system operating on the side of the digital asset guard service operator-side, and the user-side file data real-time deletion system has the data deletion processing agreement information acquisition means and the customer data deletion instruction means, and the digital asset guard service operator-side file data real-time deletion system has the customer data deletion instruction acceptance means, a smart contract (or server application) for extracting the encrypted server index information to be deleted, a smart contract (or server application) for decrypting the server index information to be deleted, and a smart contract (or server application) for deleting the encrypted / split file data.

[0020] In addition, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the data deletion processing request instruction means is configured to be able to change the setting of the generation of the file data to be deleted.

[0021] Furthermore, the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention has a file data real-time update (saving and deletion) system, the file data real-time update (saving and deletion) system including: data update (saving and deletion) processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer between the first authenticator and the second authenticator; customer data update (saving and deletion) instruction means for instructing the update (saving and deletion) of the data to be updated (saving and deletion) for the customer based on the agreement information when agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer is acquired by the data update (saving and deletion) processing agreement information acquisition means; a program (or smart contract) having a plurality of encryption / division algorithms that differ in file data encryption and division processing methods; and an update (saving and deletion) processing time encryption / division algorithm selection receiving means for receiving a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer acquired by the update (saving and deletion) processing agreement information acquisition means; an update (saving and deletion) processing time customer data evacuation instruction receiving means for receiving an instruction to evacuate the data to be evacuated for the customer from the customer data update (saving and deletion) instruction means; an update (saving and deletion) processing time file data encryption / division means for encrypting and dividing the customer data to be evacuated, which has been accepted by the update (saving and deletion) processing time customer data evacuation instruction accepting means, into a plurality of file data using a program (or smart contract) having the encryption / division algorithm accepted by the update (saving and deletion) processing time encryption / division algorithm selection accepting means; and each of the file data encrypted and divided into a plurality of file data by the update (saving and deletion) processing time file data encryption / division means,an update (saving and deletion) processing time uploading means for uploading to a first temporary storage area; an update (saving and deletion) processing time file data conservation point associating and sorting each piece of file data encrypted and divided by the update (saving and deletion) processing time file data encryption / division means and uploaded to the first temporary storage area by the update (saving and deletion) processing time uploading means, by associating the file data with one of the conservation points corresponding to at least two planets for managing the file data; and an update (saving and deletion) processing time conservation point information management means for managing, in a black box environment, information on the conservation points for managing the file data sorted by the update (saving and deletion) processing time file data conservation point associating and sorting means; The file data update (saving and deletion) processing time file data protection point associating and sorting means is provided in each planet and is sorted based on agreement information between the first authenticator and the second authenticator (or a first parameter included in the agreement information and a second parameter designated by the digital asset guard service operation manager) regarding the saving process of the data to be saved for the customer, which is acquired by the data update (saving and deletion) processing agreement information acquisition means, and each file data associated with the information of the protection point managed in a black box environment by the update (saving and deletion) processing time protection point information management means. The data is set by the digital asset guard service administrator in accordance with conditions designated by the customer, and the data is sorted by a file data preservation point associating means for update (saving and deleting) processing at distributed file management groups, the file data being configured by nodes at each base constituting the planet corresponding to the preservation point and recording devices at multiple bases connected to the nodes at each base via a network, and the file data is sorted by a file data preservation point associating means for update (saving and deleting) processing at distributed file management groups, the file data being sorted by the ...a distributed recording means for update (backup and deletion) processing that has a function of distributing and recording each of the file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means for update (backup and deletion) processing in the nodes of each base belonging to the corresponding distributed file management group and in recording devices of multiple bases connected to the nodes of the base via a network; and a system setting means for update (backup and deletion) processing that has a function of creating system setting information including terminal information (information specifying the other party such as a fixed IP address) for uploading to the first temporary storage area using the upload means for update (backup and deletion) processing, the number of a predetermined processing means that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and information on a group of file servers (in the node of a predetermined base and in recording devices of multiple bases connected to the node of the base via a network) that constitute the distributed file management group, encrypting the information, and recording it in a group of nodes of a specific base in the distributed ledger structure. a smart contract (or server application) for creating server index information during update (saving and deletion) processing, the smart contract (or server application) having a function of creating server index information including: key information using the first authenticator ID information and the second authenticator ID information required for data evacuation, which are included in agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer acquired by the data update (saving and deletion) processing agreement information acquisition means; file name information of each of the file data linked to the information of the conservation point sorted by the file data conservation point association sorting means during update (saving and deletion) processing and managed in a black box environment by the conservation point information management means during update (saving and deletion) processing, which has been distributed and recorded by each of the distributed recording means during update (saving and deletion) processing; and configuration information of each of the distributed file management groups to which each of the file data is allocated;a smart contract (or server application) for recording server index information during update (saving and deletion) processing, which has a function of encrypting and recording server index information created by the smart contract (or server application) for creating server index information during update (saving and deletion) processing in a group of nodes at a specific location in the distributed ledger structure; a smart contract (or program with a wallet function) for creating customer setting information during update (saving and deletion) processing, which has a function of creating customer setting information including agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer, which is acquired by the data update (saving and deletion) processing agreement information acquisition means linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means during update (saving and deletion) processing; and a smart contract (or a program with a wallet function) for creating customer index information during update (saving and deletion) processing, which has a function of creating customer index information having information on a file name and an upload date; a smart contract (or a server application) for recording customer index information during update (saving and deletion) processing, which has a function of encrypting the customer index information created by the smart contract (or the program with a wallet function) for creating customer index information during update (saving and deletion) processing and recording it in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means (or server application) for updating (saving and deletion) processing, which erases each file data uploaded to the first temporary storage area after the server index information has been encrypted and recorded in the group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information during update (saving and deletion) processing; a means for accepting a deletion instruction for the data to be deleted from the update (saving and deletion) instruction means during the update (saving and deletion) processing; and a means for accepting a deletion instruction for the data to be deleted from the customer from the update (saving and deletion) instruction means, the means being provided on each planet;In the planet corresponding to the security point, for each group of file data linked to information on each of the security points managed in a black box environment by the update (saving and deletion) processing time security point information management means, key information (or the first parameter included in the key information or a first composite parameter (composed of a pair of a first decryption parameter designated and managed offline by the customer and a first encryption parameter automatically generated from the first decryption parameter) using the first authenticator ID information and the second authenticator ID information required for data deletion in agreement information between the first authenticator and the second authenticator regarding deletion processing of the data to be deleted for the customer acquired by the data update (saving and deletion) processing agreement information acquisition means, which is linked to file data to be deleted accepted by the update (saving and deletion) processing time customer data deletion instruction acceptance means, and the second parameter (designated by the digital asset guard service operation manager and managed offline (by a predetermined processing means or screen for performing the relevant processing) a smart contract (or server application) for extracting encrypted server index information to be deleted during update (backup and deletion) processing, which has a function of extracting encrypted server index information (recorded in a node group at a specific location in the distributed ledger structure by the server index information recording smart contract (or server application)) based on a second composite parameter (composed of a pair of second decryption parameters (embedded and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) and a second encryption parameter (embedded and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameters; and a smart contract (or server application) for extracting encrypted server index information to be deleted during update (backup and deletion) processing, which is provided in each planet and, in the planet corresponding to the conservation point, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means during update (backup and deletion) processing,a smart contract (or server application) for decrypting server index information to be deleted during update (saving and deletion) processing, which has a function of decrypting the encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information to be deleted during update (saving and deletion) processing; and a smart contract (or server application) for decrypting server index information to be deleted during update (saving and deletion) processing, which is provided in each planet and manages, in the planet corresponding to the maintenance point, for each group of file data associated with the information of each of the maintenance points managed in a black box environment by the maintenance point information management means during update (saving and deletion) processing. and a smart contract (or server application) for deleting encrypted and divided file data during update (saving and deletion) processing, which has a function of deleting each of the encrypted and divided file data to be deleted from each of the base nodes belonging to each of the distributed file management groups and from all of the base node recording devices connected to the base node via a network, the file data being allocated to each of the distributed file management groups by the distributed file management group allocation means and distributedly recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in all of the base node recording devices connected to the base node via a network, using server index information decrypted by the distributed file management group allocation means (or server application), The data update (saving and deletion) processing agreement information acquisition means includes a data update (saving and deletion) processing request instruction means that instructs, via the first authenticator, a request for processing to update (saving and deletion) data that is to be updated (saving and deletion) for the customer, a data update (saving and deletion) processing request instruction acceptance means that accepts, from the data update (saving and deletion) processing request instruction means, an instruction to request processing to update (saving and deletion) data that is to be updated (saving and deletion) for the customer, and when the data update (saving and deletion) processing request instruction acceptance means accepts the instruction to request processing to update (saving and deletion) data that is to be updated (saving and deletion) for the customer,a first authenticated person authentication requesting means for receiving a data update (saving and deleting) processing request instruction, which acquires first authenticated person authentication information required for authenticating the first authenticated person from the first authenticated person information managing means, provides the acquired information to an external first authenticated person authentication system, and requests authentication of the first authenticated person; and a first authenticated person ID information and key information receiving means for data update (saving and deleting) which receives the first authenticated person ID information and key information required for updating (saving and deleting) data from the first authenticated person information managing means when the first authenticated person is authenticated by the external first authenticated person authentication system. a seventh information notification means for notifying the second authenticator of information that the first authenticator has issued a request instruction for updating (saving and deleting) the data to be updated (saving and deleting) for the customer when the first authenticator ID information and key information receiving means for data update (saving and deletion) has received the first authenticator ID information and key information necessary for updating (saving and deleting) the data, and information urging the second authenticator to issue an approval instruction for updating (saving and deleting) the data to be updated (saving and delete) for the customer; and a data update (saving and deletion) processing approval instruction means for instructing approval of the update (saving and deletion) processing of the data to be updated (saved and deleted) by the customer via the data update (saving and deletion) processing approval instruction means; a data update (saving and deletion) processing approval instruction receiving means for receiving an approval instruction for the update (saving and deletion) processing of the data to be updated (saved and deleted) by the customer from the data update (saving and deletion) processing approval instruction means; and a data update (saving and deletion) processing approval instruction receiving means for receiving an approval instruction for the update (saved and deletion) processing of the data to be updated (saved and deleted) by the customer when the data update (saving and deletion) processing approval instruction receiving means receives an approval instruction for the update (saved and deletion) processing of the data to be updated (saved and deleted) by the customer. a second authenticated person authentication requesting means for receiving a data update (saving and deleting) processing approval instruction, which acquires second authenticated person authentication information required for authenticating the second authenticated person from the second authenticated person information managing means, provides the acquired information to an external second authenticated person authentication system, and requests authentication of the second authenticated person; and a second authenticated person ID information and key information receiving means for data update (saving and deleting), which receives the second authenticated person ID information and key information required for updating (saving and deleting) data from the second authenticated person information managing means when the second authenticated person is authenticated by the external second authenticated person authentication system.an eighth information notifying means for, when the second authenticator ID information and key information receiving means for data update (saving and deletion) receives the second authenticator ID information and key information necessary for data update (saving and deletion), notifying the first authenticator of information that the second authenticator has issued an approval instruction for the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer and information urging the first authenticator to issue a request instruction for the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer; a data update (saving and deletion) processing request instructing means for instructing a request for the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer via the first authenticator notified from the eighth information notifying means; and It is preferable to have a data update (saving and deletion) processing request instruction receiving means for receiving a request instruction, and a data update (saving and deletion) processing agreement information creating means for, when the data update (saving and deletion) processing request instruction receiving means receives a request instruction for processing to update (saving and deletion) data to be updated (saving and deletion) for the customer, creating agreement information between the first authenticator and the second authenticator regarding the processing to update (saving and deletion) data to be updated (saving and deletion) for the customer, using the first authenticator ID information and key information required for data update (saving and deletion) received by the first authenticator ID information and key information receiving means for data update (saving and deletion) and the second authenticator ID information and key information required for data update (saving and deletion) received by the second authenticator ID information and key information receiving means for data update (saving and deletion).

[0022] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the file data real-time update (saving and deletion) system comprises a user-side file data real-time update (saving and deletion) system that operates on the side of a user (customer or data manager) who desires to update (saving and deleting) file data, and a digital asset guard service operator-side file data real-time update (saving and deletion) system that operates on the side of the digital asset guard service operator, and the user-side file data real-time update (saving and deletion) system comprises the data update (saving and deletion) processing agreement information acquisition means, the customer data update (saving and deletion) instruction means, a program (or smart contract) having a plurality of the encryption and division algorithms, an encryption and division algorithm selection acceptance means at the time of the update (saving and deletion) processing, a customer data save instruction acceptance means at the time of the update (saving and deletion) processing, the file data encryption and division means at the time of the update (saving and deletion) processing, and an upload at the time of the update (saving and deletion) processing. means, the file data preservation point correspondence sorting means at the time of update (saving and deletion) processing, and the preservation point information management means at the time of update (saving and deletion) processing, and the digital asset guard service operator side file data real-time update (saving and deletion) system comprises the distributed file management group allocation means at the time of update (saving and deletion) processing, the distributed recording means at the time of update (saving and deletion) processing, a smart contract (or server application) for creating server index information at the time of update (saving and deletion) processing, a smart contract (or server application) for recording server index information at the time of update (saving and deletion) processing, a first data erasure means at the time of update (saving and deletion) processing, a customer data deletion instruction receiving means at the time of update (saving and deletion) processing, a smart contract (or server application) for extracting encrypted server index information to be deleted at the time of update (saving and deletion) processing, and a smart contract (or server application) for decrypting server index information to be deleted at the time of update (saving and deletion) processing,and a smart contract (or server application) for deleting encrypted and divided file data during the update (saving and deletion) process.

[0023] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the data update (backup and deletion) processing request instruction means automatically sets all of the client's past generation file data as file data to be deleted.

[0024] Furthermore, in the first aspect of the real-time backup / restore type digital asset guard service providing system of the present invention, it is preferable that the data update (backup and deletion) processing request instruction means is configured to be able to change the setting of the generation of the file data to be deleted.

[0025] In the real-time save / restore type digital asset guard service providing system according to the first aspect of the present invention, the distributed file management group allocation means or the distributed file management group allocation smart contract (or server application) is configured to encrypt and split the file data associated with the information of the conservation points sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means before sorting the file data into the plurality of distributed file management groups, and to upload the first temporary file data to the plurality of distributed file management groups. It is preferable that the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data further has a function of converting the file format and name of each file data uploaded to the fixed storage area into a predetermined file format and name, and that after extracting each of the encrypted and divided file data for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means, converting the file format and name of each of the extracted file data into the original file format and name.

[0026] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the agreement information (or the first parameter included in the agreement information) between the first authenticator and the second authenticator regarding the save processing of the customer's data acquired by the data save processing agreement information acquisition means has a file division code and a file storage code, the encryption / division algorithm selection receiving means receives a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on the file division code, the distributed file management group allocation means or the distributed file management group allocation smart contract (or server application) is encrypted and divided into multiple pieces by the file data encryption / division means, uploaded to the first temporary storage area by the uploading means, sorted by the file data conservation point association sorting means, and each of the files linked to information of the conservation point managed in a black box environment by the conservation point information management means. For file data, based on the file storage code (or the file storage code and the second parameter), the file format and name of the file data are converted into a predetermined file format and name, and at the same time, the file data is encrypted and distributed to a plurality of distributed file management groups configured by the digital asset guard service administrator side according to conditions specified by the customer, the plurality of base nodes constituting the planet corresponding to the conservation point, and the plurality of base nodes and the recording devices connected to the base nodes via a network, and each of the distributed recording means or the distributed recording smart contract (or server application) has a function of sorting the file data associated with the information of each of the conservation points sorted by the distributed file management group sorting means or the distributed file management group sorting smart contract (or server application) and managed in a black box environment by the conservation point information management means,The encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data has a function of distributing and recording to the nodes of each base that belong to each of the corresponding distributed file management groups and to recording devices of multiple bases that are connected to the nodes of the base via a network, and the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data is allocated to each distributed file management group by the distributed file management group allocation means or the smart contract (or server application) for distributing and recording to each distributed file management group by each of the distributed recording means or the smart contract (or server application) for distributed recording to the nodes of each base that belong to each of the distributed file management groups and to recording devices of multiple bases that are connected to the nodes of the base via a network. and a file data recovery means for recovering the file data from the node of each base belonging to each of the distributed file management groups and from any of the recording devices of multiple bases connected to the node of the base via a network, based on the file storage code (or the file storage code and the second parameter), and decrypting the extracted file data, and at the same time converting the file format and name of the file data to the original file format and name; and the file data recovery means has a function of recovering the file data from the node of each of the bases belonging to each of the distributed file management groups and from any of the recording devices of multiple bases connected to the node of the base via a network, based on the file storage code (or the file storage code and the second parameter), and decrypting the extracted file data, and at the same time converting the file format and name of the file data to the original file format and name; and the file data recovery means recovers the file data from the node of each of the bases belonging to each of the distributed file management groups and from any of the recording devices of multiple bases connected to the node of the base via a network, based on the file storage code (or the file storage code and the second parameter), and for each group of the file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means, based on the file division code, recovering all of the file data linked across the information of all of the conservation points in an encrypted and divided state that has been extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data and downloaded to the second temporary storage area by the download means, based on the file division code,It is preferable that the encryption / division algorithm selection receiving means has a function of using a program (or smart contract) having the decryption / combining algorithm linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection receiving means to decrypt and combine the data into one file data and restore the file data to the state before saving.

[0027] Furthermore, in the real-time save / restore type digital asset guard service providing system according to the first aspect of the present invention, the customer data to be saved, which has been accepted by the customer data save instruction accepting means, is divided into a plurality of pieces using a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection accepting means, and each of the divided file data is encrypted based on a first public key (first encryption key) created by each of the customer and the data manager, and the file data restoring means performs an encryption / division file data extraction using the encrypted / division file data extracting means or the encrypted / division file data extracting means for each group of the file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information managing means. It is preferable that all of the file data linked across the information of all of the conservation points in an encrypted and divided state, which has been extracted by the output smart contract (or server application) and downloaded to the second temporary storage area by the downloading means, is decrypted based on a first private key (first offline decryption key) created by each of the customer and the data manager, and that all of the file data linked across the decrypted information of all of the conservation points is combined into one file data using a program (or smart contract) having the decryption and combination algorithm that is linked to a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection accepting means.

[0028] Furthermore, in the real-time save / restore type digital asset guard service providing system according to the first aspect of the present invention, the file data encryption / division means encrypts the customer data to be saved that is accepted by the customer data save instruction acceptance means based on a first public key (first encryption key) created by the customer and the data manager, and divides the encrypted file data into a plurality of pieces using a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means, and the file data restoration means extracts the encrypted / division file data for each group of the file data linked to the information of each of the conservation points that is managed in a black box environment by the conservation point information management means. It is preferable that all of the file data linked across the information of all of the conservation points in an encrypted and divided state, extracted by the smart contract (or server application) for extracting encrypted and divided file data and downloaded to the second temporary storage area by the downloading means, is combined into one file data using a program (or smart contract) having the decryption and combination algorithm linked to a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection accepting means, and that the combined file data is decrypted based on a first private key (first offline decryption key) created by each of the customer and the data manager.

[0029] In the real-time save / restore type digital asset guard service providing system according to the first aspect of the present invention, the server index information recording smart contract (or server application) stores the server index information created by the server index information creating smart contract (or server application) in a second public key (second encryption key) created by the digital asset guard service administrator or in a second encryption key (modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from a second decryption parameter (modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is designated by the digital asset guard service administrator and managed offline. It is preferable that the smart contract (or server application) for decrypting server index information has a function of encrypting the encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information for each group of file data linked to the information of each of the protection points managed in a black box environment by the protection point information management means, based on a second private key (second decryption key) created by the digital asset guard service operator or a second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) specified by the digital asset guard service operator and managed offline.

[0030] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the program (or smart contract) equipped with the encryption and division algorithm is configured to encrypt and divide file data into multiple parts using secret sharing technology.

[0031] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the program (or smart contract) equipped with the decryption and combination algorithm is configured to decrypt file data that has been encrypted and divided into multiple pieces and restore it to the original file data that has been combined into one piece using secret sharing technology.

[0032] In the real-time save / restore type digital asset guard service providing system according to the first aspect of the present invention, it is preferable that the secret sharing technique is a polynomial division processing type secret sharing technique.

[0033] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, the file data real-time backup system further comprises a planet configuration pattern setting means for selecting the number of nodes constituting the planet and the nodes at each base and the recording devices at multiple bases connected to the nodes at each base via a network (distributed file management group constructed by these) based on the recording capacity (file size) of file data specified by the customer and the number of divisions of file data based on the degree of distribution, and the distributed file management group sorting means or the distributed file management group sorting smart contract (or server application) sorts each of the file data associated with the information of the conservation point sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means via the planet configuration pattern setting means according to the conditions specified by the customer. It is preferable that the digital asset guard service operator has a function of distributing the data to a plurality of distributed file management groups, which are configured by the digital asset guard service operator and are composed of the nodes of each location that constitute the planet corresponding to the security point and the recording devices of multiple locations that are networked to the nodes of the locations, and that each of the distributed recording means or the smart contract for distributed recording (or server application) has a function of distributing and recording each of the file data that is linked to the information of each of the security points that is sorted by the file data security point correspondence sorting means and managed in a black box environment by the security point information management means, to the nodes of each of the locations that belong to the corresponding distributed file management groups and the recording devices of multiple locations that are networked to the nodes of the locations.

[0034] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the planet configuration pattern setting means adds a predetermined number of dummy file data (having code internally that allows the encrypted / divided file data extraction means or the smart contract (or server application) for extracting encrypted / divided file data to recognize that it is dummy information) to the number of divisions of the file data, and selects the number of nodes that constitute the planet, and the distributed file management group constructed by the nodes at each base and the recording devices at multiple bases connected to the nodes at the base via a network.

[0035] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the smart contract (or server application) for creating server index information has the function of creating the server index information, including, as configuration information for each of the distributed file management groups, information on the nodes at each base that distribute and record the dummy file data added by the planet configuration pattern setting means and information on recording devices at multiple bases that are network-connected to the nodes at those bases.

[0036] In addition, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means, extracts from the configuration information of each of the distributed file management groups in the server index information decrypted by the smart contract (or server application) for decrypting server index information, a node at each base that distributes and records dummy file data (having a code therein that can be recognized as dummy information) and multiple nodes connected to the node at each base via a network. It is preferable that the system has a function to extract, using server index information excluding information on recording devices at several locations, each of the encrypted and divided file data that has been allocated to each of the distributed file management groups by the distributed file management group allocation means or the smart contract (or server application) for distributed file management group allocation, and distributedly recorded by each of the distributed recording means or the smart contract (or server application) on each of the node at each location belonging to each of the distributed file management groups and on recording devices at multiple locations connected to the node at each of the locations via a network, from any of the node at each of the distributed file management groups and any of the recording devices at multiple locations connected to the node at each of the locations via a network.

[0037] Furthermore, in the first aspect of the real-time backup / restore type digital asset guard service providing system of the present invention, it is preferable that the planet configuration pattern setting means selects the nodes of each base within each of the distributed file management groups and the recording devices of multiple bases connected to the nodes of the base via a network so that they are the nodes and recording devices located at the locations with the greatest distance (= maximum degree of distribution).

[0038] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, the planet configuration pattern setting means preferably regards the spherical Earth as a plane, creates a matrix in which the Earth's regions are divided into multiple sections both vertically and horizontally, and determines the spacing in the X-axis direction, based on the Y-axis in the matrix for the node that distributes and records one divided file data within one of the distributed file management groups and the bases of multiple recording devices connected to the node via a network, using a calculated value based on the number of divisions of the file data, and selects the nodes of each base within each of the distributed file management groups and the recording devices of multiple bases connected to the node of the base via a network.

[0039] Furthermore, in the first aspect of the present invention, in the real-time backup and restoration type digital asset guard service provision system, it is preferable that the nodes in the planet that distribute and record each divided file data and the locations of multiple recording devices that are connected to the nodes via a network are managed using information such as GPS and are classified in the matrix.

[0040] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, when the planet configuration pattern setting means is unable to open the spacing in the X-axis direction according to the calculated value based on the number of divisions of the file data, due to insufficient remaining recording capacity of the node at a specified base or one of the recording devices at multiple bases connected to the node at that base via the network, it is preferable to select a base node or a recording device connected to the node at that base via the network that has a numerical difference in the Y-axis direction that is approximately the same as the calculated value of the spacing in the X-axis direction.

[0041] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, the planet configuration pattern setting means preferably selects the base of each node constituting the planet in accordance with the number of file data divisions based on the recording capacity (file size) of the file data specified by the customer, and selects multiple individual bases belonging to the distributed file management group constructed by each selected node so as to maximize the degree of distribution within the distributed file management group, and selects multiple recording devices to be disposed at each individual base (and connected to the node via a network).

[0042] Furthermore, in the real-time backup / restore type digital asset guard service provision system of the first aspect of the present invention, the planet configuration pattern setting means preferably records in the matrix information such as total remaining recording capacity and total remaining communication capacity of the nodes at each base in each region to which the base of each node belongs and the recording devices at multiple bases connected to the nodes at those bases via a network, and when selecting the nodes that constitute the distributed file management group and the bases of the multiple recording devices connected to those nodes via a network, uses information such as the total remaining recording capacity and total remaining communication capacity of the nodes at each base in each region and the recording devices at multiple bases connected to the nodes at those bases via a network, as well as the degree of distribution, to select the optimal combination of nodes and the bases of the multiple recording devices connected to those nodes via a network.

[0043] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the planet configuration pattern setting means calculates areas where it is necessary to reinforce the recording capacity and communication capacity of each node at a specific base and the recording devices at multiple bases connected to the node at that base via a network, in a combination of nodes at a specific base that constitute the distributed file management group and recording devices at multiple bases connected to the node at that base via a network.

[0044] Furthermore, in the first aspect of the real-time backup / restore type digital asset guard service provision system of the present invention, it is preferable that each of the distributed file management groups has a core node that designates and manages the individual equipment that constitutes the recording devices of each location belonging to the distributed file management group.

[0045] Furthermore, in the real-time backup and restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the nodes at each location are connected via a communication means such as the Internet or a closed network, and that the distributed recording means or the smart contract for distributed recording (or server application) is incorporated.

[0046] Furthermore, in the real-time backup / restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the file data real-time backup system has a wallet function that reads the customer index information encrypted and recorded in a group of nodes at a specific location in the distributed ledger structure, and grasps the recording destination corresponding to each piece of file data encrypted and divided into multiple pieces by the file data encryption / division means.

[0047] Furthermore, in the real-time backup / restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the file data real-time backup system further has a backup file data list information creation means that creates backup file data list information linked to each of the client and the data manager, and that includes terminal information (fixed IP address) when the file data was uploaded to the first temporary storage area using the upload means, the original file name of the file data to be backed up, and information on the upload date, and a backup file data list information reference control means that is configured to allow the backup file data list information created by the backup file data list information creation means to be referenced only by communication devices (management / processing programs) managed by the fixed IP addresses of each of the client and the data manager.

[0048] Furthermore, in the real-time backup and restoration type digital asset guard service provision system of the first aspect of the present invention, the multiple chains, which are mainly based on a closed blockchain such as the private type or the consortium type that forms the distributed ledger structure and which may include the distributed ledger group and public type blockchains, preferably have nodes at each of the bases that make up the planet, recording devices at multiple bases that are network-connected to the base nodes, and a multiple-level file data real-time backup and restoration system configuration for operating the file data real-time backup system and the file data real-time restoration system.

[0049] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable to have a Level S file data real-time backup and restoration system configuration that is based on next-generation distributed communications in general, and is configured to operate nodes at each base that constitutes the planet, recording devices at multiple bases that are network-connected to the base nodes, the file data real-time backup system, and the file data real-time restoration system using closed networks that are not connected to the Internet, such as satellite communications, 5G / 6G private communications, LTE networks, and dedicated closed networks.

[0050] Furthermore, in the first aspect of the real-time evacuation and restoration type digital asset guard service provision system of the present invention, it is preferable that the system utilizes an internet communication network, is based on a closed blockchain such as the private or consortium type that forms the distributed ledger structure, and is composed of highly creditworthy companies that approve each of the participants of multiple chains that may include the distributed ledger group and public blockchains, and has a level 4 file data real-time evacuation and restoration system configuration configured to operate nodes at each base that constitutes the planet, recording devices at multiple bases that are network-connected to the base nodes, the file data real-time evacuation system, and the file data real-time restoration system in a high-security space such as a dedicated room.

[0051] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service provision system of the present invention, it is preferable that the system utilizes an internet communication network, is primarily based on a closed blockchain such as the private or consortium type that forms the distributed ledger structure, and is composed of highly credible companies that approve each of the participants of multiple chains that may in some cases include the distributed ledger group, public blockchain, etc., and has a level 3 file data real-time backup and restoration system configuration in which a file server for data backup is installed in a space with a security level equivalent to an office, etc., or an inexpensive cloud service (including the use of globally distributed regional services) is used to operate nodes at each base that constitutes the planet, recording devices at multiple bases that are networked to the base nodes, the file data real-time backup system, and the file data real-time restoration system.

[0052] Furthermore, in the first aspect of the present invention, the real-time backup and restoration type digital asset guard service provision system preferably utilizes the Internet communication network, is open to organizations such as general companies (e.g., branch network), and is configured to operate nodes at each base that make up the planet, recording devices at multiple bases that are network-connected to the base nodes, the file data real-time backup system, and the file data real-time restoration system, and is provided with a level 2 file data real-time backup and restoration system configuration.

[0053] Furthermore, in the first aspect of the present invention, the real-time backup and restoration type digital asset guard service provision system preferably utilizes the Internet communication network, is open to private homes, etc., and is configured to operate nodes at each location that make up the planet, recording devices at multiple locations that are network-connected to the nodes at those locations, the file data real-time backup system, and the file data real-time restoration system, providing a level 1 file data real-time backup and restoration system configuration.

[0054] Furthermore, in the real-time backup and restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the file data real-time backup and restoration system configuration form of levels 1 to 4 is configured so that the nodes at each of the locations around the world that make up each of the planets, and the recording devices (file servers) at multiple locations that are network-connected to the nodes at those locations, are network-connected to the Internet communication network and operate during nighttime hours when waste electricity can be utilized.

[0055] Furthermore, in the real-time backup and restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the file data real-time backup and restoration system configuration form of levels 1 to 4 is configured so that the nodes at each of the locations around the world that make up each of the planets, and the recording devices (file servers) at multiple locations that are network-connected to the nodes at those locations, can operate during daytime hours using renewable energy power such as solar power generation.

[0056] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, a data save service contract application procedure acceptance means accepts a data save service contract application procedure from a customer who desires to save file data, and at the time of accepting the data save service contract application procedure, accepts from the customer a designation of the recording capacity, distribution degree (whether domestically only or overseas as well), storage period, and real-time processing of the file data that the customer desires to save, and manages the information on the recording capacity, distribution degree (whether domestically only or overseas as well), storage period, and real-time processing of the file data that the customer desires to save that has been accepted by the data save service contract application procedure acceptance means. It is preferable that the system further has a smart contract (or server application) for recording application acceptance information for a data evacuation service contract, which has the function of automatically calculating and generating the basic configuration of the entire planet by setting conditions from the customer (such as budget, whether the data contains the most confidential information related to personal information or security (i.e., the amount of risk, etc.), and the function of encrypting and recording the generated information as part of the system configuration information in a group of nodes at a specific location in the distributed ledger structure, so that the recorded configuration information can be read by a specified smart contract (or server application) that performs the relevant processing, along with the customer's personal information, allowing the system to grasp the overall picture.

[0057] In addition, in the real-time save / restore type digital asset guard service providing system according to the first aspect of the present invention, the file data real-time save system calculates a hash value based on encrypted and divided file data that is recorded in the nodes of each of the distributed file management groups and in the storage devices of multiple locations connected to the nodes of the base via a network, records the calculated hash value in a block in the nodes and storage devices, and constantly stores the hash value recorded in the nodes of each of the distributed file management groups and in the storage devices of multiple locations connected to the nodes of the base via a network, or in the blocks in the nodes or storage devices. It is preferable to further have a data tampering check control means that compares the hash recorded in a specific node or recording device or in a block on that node or recording device and, if there is a difference between the hash recorded in a block on another node or recording device or in that node or recording device, detects that the encrypted and divided file data recorded on that specific node or recording device has been tampered with or destroyed, excludes that specific node or recording device from the file data backup process (and deletes the blocks on that specific node or recording device), and notifies the operator of the node and the digital asset guard service operator / manager of the alarm.

[0058] In addition, in the real-time backup / restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the system is configured to manage, with a fixed IP address, communication devices that can use a first private key (first offline decryption key) created by each of the customer and the data manager to restore each encrypted and divided file data that has been distributed and recorded in each base node belonging to each of the distributed file management groups and in multiple base recording devices connected to the base nodes via a network to the original data before the backup via the file data real-time restoration system.

[0059] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the management information of the IP addresses of communication devices on which the customer and the data manager can use the first private keys (first offline decryption keys) created by each of them is presented to the digital asset guard service operator only when a multi-signature type private key transaction is approved by the holders of specific nodes at multiple locations that constitute the digital asset guard service operator.

[0060] In addition, in the real-time backup / restore type digital asset guard service provision system of the first aspect of the present invention, it is preferable that node information for which access is permitted is recorded in the node group at a specific location in the distributed ledger structure.

[0061] Furthermore, in the real-time backup / restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable to further have an upload process-enabled IP address check means that controls the upload process (operation of the encryption / splitting algorithm selection receiving means, the customer data backup instruction receiving means, the file data encryption / splitting means, and the upload means) of the file data to be evacuated by the customer in the file data real-time backup system so that only operations at a customer terminal that has a fixed IP address pre-registered as part of the system setting information in a node group at a specific location in the distributed ledger structure are possible, as terminal information for uploading to the first temporary storage area using the upload means.

[0062] Furthermore, in the real-time evacuation / restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the smart contract (or server application) for recording data evacuation service contract application acceptance information confirms the recorded amount of file data that the customer wishes to evacuate, which has been accepted by the data evacuation service contract application procedure acceptance means, and if the confirmed recorded amount of file data exceeds the maximum recording capacity of one file defined in the system, determines the number of divisions of the file data so that the recorded amount is less than the maximum recording capacity.

[0063] Furthermore, in the real-time backup / restore type digital asset guard service provision system of the first aspect of the present invention, it is preferable that each base node belonging to each of the distributed file management groups and the recording devices at multiple bases connected to the base nodes via a network are provided with multiple sub-configuration file servers (or a group of file servers accessible from each base node belonging to each of the file management groups) that are respectively connected to the base nodes and the recording devices at multiple bases connected to the base nodes via a network.

[0064] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, each of the distributed recording means or the distributed recording smart contract (or server application) checks the data recording capacity and usage status of each of the file servers of the sub-components connected to the node of each base belonging to each of the distributed file management groups and the recording devices of multiple bases connected to the node of the base via a network, and based on the checked data recording capacity, sorts the large file data that has been encrypted and divided into multiple pieces and uploaded to the first temporary storage area by the file data preservation point association sorting means, and is linked to the information of the preservation point that is managed in a black box environment by the preservation point information management means. It is preferable that the system has the function of selecting a file server of a specific sub-configuration having a data recording capacity capable of recording file data, recording the large file data that has been encrypted, divided into multiple pieces, and uploaded to the first temporary storage area and sorted by the file data conservation point matching sorting means on the selected file server of the specific sub-configuration, and that is linked to the information of the conservation point managed in a black box environment by the conservation point information management means, and recording information about the file server of the specific sub-configuration that is the recording destination for the large file data that has been encrypted, divided into multiple pieces, and uploaded to the first temporary storage area as second index information on the nodes of each base belonging to each of the distributed file management groups.

[0065] In addition, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, each of the distributed recording means or the distributed recording smart contract (or server application) is recorded in a predetermined sub-configuration file server connected to each base node belonging to each of the distributed file management groups and to a recording device of a plurality of bases connected to the base node via a network, and the large file data linked to the information of the conservation point that is encrypted, divided into multiple pieces, and uploaded to the first temporary storage area is sorted by the file data conservation point association sorting means, and managed in a black box environment by the conservation point information management means. When the upper limit of the server's recording capacity is exceeded, it is preferable that the recording capacity of each base node belonging to each of the distributed file management groups and each of the other sub-configuration file servers connected to recording devices at multiple bases connected to the base node via a network is calculated for the file data that exceeds the upper limit of the recording capacity of the file server, and based on the calculated recording capacity, the file server of the sub-configuration that is the optimal recording destination is selected, the data is recorded on the file server of the selected sub-configuration, and the settings of the original file server are changed to put it into a dormant state, and information on the file servers of the sub-configuration that are the recording destination is recorded (updated) as second index information on each base node belonging to each of the distributed file management groups.

[0066] Furthermore, in the first aspect of the present invention, in the real-time backup / restore type digital asset guard service provision system, it is preferable that the nodes at each base belonging to each of the distributed file management groups and the recording devices at multiple bases connected to the base nodes via a network are each equipped with a sub-configuration file server (or a recording medium connected to the sub-configuration file server) that can be expanded.

[0067] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data has the function of referencing the second index information recorded in the nodes of each base belonging to each of the distributed file management groups, detecting multiple sub-configuration file servers where the large file data linked to the information of the conservation point that is managed in a black box environment by the conservation point information management means is recorded, extracting file data recorded on the sub-configuration file servers from the multiple sub-configuration file servers, combining the extracted multiple file data, and restoring the large file data linked to the information of the conservation point that is sorted by the file data conservation point association sorting means in the original encrypted and divided state and managed in a black box environment by the conservation point information management means.

[0068] Furthermore, in the real-time backup / restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the file data real-time backup system further has a period-recording amount check means which, if the file data uploaded by a customer who wishes to back up file data and distributedly recorded on each base node belonging to each of the distributed file management groups and on recording devices at multiple bases connected to the base nodes via a network, exceeds the maximum value of the file data recording amount within a specified period, requests the customer to re-apply for a file data backup service contract, and if the customer does not go through the re-application procedure, treats it as an error.

[0069] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that at any of the bases belonging to each of the distributed file management groups, there is a node or recording device that is in a stopped state and not connected to the Internet, and that when the stopped node or recording device at that base is restarted, it is configured to receive and record encrypted and divided file data that is recorded on a node or recording device at another base that is in an operating state.

[0070] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, there is provided a data destruction attack detection means for detecting an attack (or the existence of data destruction due to equipment failure, etc.) on file data in an encrypted and divided state that is recorded in (a node or recording device at any of the bases that constitute the planet), and determining that a data destruction attack is being carried out when destruction of multiple file data managed over a certain period of time (e.g., 30 minutes, 8 hours, 24 hours, etc.) is detected; and when the data destruction attack detection means detects an attack on the encrypted and divided file data, it notifies the nodes at each base that constitutes the planet and the corresponding It is preferable to have an automatic data evacuation means in the event of an attack, which is configured to stop recording devices at multiple locations connected to the node of the base via a network or forcibly disconnect the Internet connection path, and to set up a separate network to automatically evacuate the encrypted and divided file data that is distributed and recorded on the node of the base that has not been attacked or on recording devices at multiple locations connected to the node of the base via a network, to each of the nodes of the base that make up another planet where attacks on the encrypted and divided file data have not been detected by the data destruction attack detection means, and to recording devices at multiple locations connected to the node of the base via a network.

[0071] Furthermore, in the real-time backup / restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the data destruction attack detection means has a communication switching control means configured to, when it detects an attack on the encrypted and divided file data, maintain the stopped node and the recording devices at multiple locations connected to the node at that location via a network in a stopped state with their Internet connection cut off, and switch to a connection with a communication means other than the Internet (such as LTE).

[0072] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the automatic data backup means at the time of attack is configured to automatically backup, when the data destruction attack detection means detects an attack on the file data in an encrypted and divided state, the encrypted and divided file data that is distributed and recorded in the nodes of a base that is not under attack and that constitutes the planet and in recording devices of multiple bases that are network-connected to the nodes of the base, via a communication means other than the Internet (such as LTE), to the nodes of each base that constitutes another planet that is not under attack on the file data in an encrypted and divided state and in recording devices of multiple bases that are network-connected to the nodes of the base.

[0073] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service provision system of the present invention, it is preferable that the file data constituting the digital asset (information of some high value) to be guarded is tokens, customer information of existing business systems, asset information, source code and modules, confidential information, design documents, parameters such as settings, digital contracts, rights, designs, and any other data that can be expressed digitally.

[0074] Furthermore, in the real-time backup / restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the data backup service contract application procedure acceptance means, when accepting the data backup service contract application procedure, further accepts from the customer a specification of the guarantee level of the file data desired to be saved, the nodes of each base that constitutes each of the planets, the recording devices of multiple bases that are network-connected to the nodes of the bases, and the level of the file data real-time backup / restoration system configuration for operating the file data real-time backup system and the file data real-time restoration system.

[0075] Furthermore, in the real-time backup / restore type digital asset guard service provision system of the first aspect of the present invention, the nodes of each base that constitutes each of the distributed file management groups and the recording devices of multiple bases that are connected to the base nodes via a network have different operating hours and are in a mixture of operating and stopped states, and all of the nodes of the bases and the recording devices of multiple bases that are connected to the base nodes via a network are in operation over a 24-hour period, and it is preferable that at a given point in time, at least one of the nodes of the bases or at least one of the recording devices of the bases that is connected to the base nodes via a network is in operation within each of the distributed file management groups.

[0076] Furthermore, in the real-time backup / restore type digital asset guard service provision system of the first aspect of the present invention, the nodes of each base that constitutes each of the distributed file management groups and the recording devices of multiple bases that are connected to the base nodes via a network operate only during nighttime hours using waste electricity generated during nighttime hours, and at a predetermined point in time, at least one of the base nodes or at least one of the base recording devices connected to the base nodes via a network within each of the distributed file management groups is operating, and when it changes from a stopped state to an operating state, the base node or the base recording device connected to the base node via a network is preferably configured to automatically correct information such as stored file data to the latest information within each of the distributed file management groups.

[0077] Furthermore, in the real-time backup and restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the node at each base and the recording devices at multiple bases connected to the node at that base via a network have a container or housing equipped with a generator of renewable energy such as solar power, a file server / CPU, a 5G communication device, and a battery.

[0078] Furthermore, in the real-time backup / restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the node at each base and the recording devices at multiple bases connected to the node at that base via a network have a container or housing equipped with a file server / CPU, a 5G communication device, a battery (capable of withstanding short-term operation), a cooling device, etc.

[0079] Furthermore, in the real-time evacuation and restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the system is configured to mainly use a closed blockchain such as the private type or the consortium type that forms the distributed ledger structure, offset the file data recording capacity provided at nodes owned by node holders participating in multiple chains that may include the distributed ledger group, public type blockchains, etc., with the file data recording capacity used by the node holder, calculate the difference between the total file data recording capacity and the provided file data recording capacity, and collect and allocate an amount based on this difference from each node holder.

[0080] Furthermore, in the real-time backup / restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable to further include a customer registration information designation receiving means that receives, from a customer who wishes to backup file data, a customer ID and designation of terminal information (fixed IP address) to be used for backup / restoration of file data, and a customer registration smart contract (or server application) that has the function of encrypting and recording the customer ID and terminal information (fixed IP address) to be used for backup / restoration of file data received by the customer registration information designation receiving means in a group of nodes at a specific location in the distributed ledger structure.

[0081] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the system further comprises a first parameter designation receiving / recording means for receiving designation of the first parameter from the customer who wishes to back up file data, and recording the first parameter that has been designated and received on an offline recording medium.

[0082] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable to further have a second parameter designation receiving and setting means for receiving designation of the second parameter from the digital asset guard service operator and setting the second parameter whose designation has been received in a predetermined processing means that performs the corresponding processing or in the source code of a smart contract (or server application) to modularize it.

[0083] In addition, in the real-time saving and restoring type digital asset guard service providing system of the first aspect of the present invention, the index information creating means, the index information recording means, the encrypted index information extracting means, and the index information decrypting means are configured separately on the user (customer and data manager) side and on the digital asset guard service operation manager side, The index information creation means has a user (customer and data manager) side index information creation program (wallet function) (or smart contract) that operates on the side of the user (customer and data manager) who desires to save file data, and a digital asset guard service operator-side index information creation smart contract (or server application) that operates on the side of the digital asset guard service operator-side, and the user (customer and data manager) side index information creation program (or smart contract) has a function to create user (customer and data manager) side index information that has the original file name, upload date information, and storage date of the file data to be saved when uploaded to the first temporary storage area using the upload means, and the digital asset guard service operator-side index information creation smart contract (or server application) The digital asset guard service operator-side index information has a function of creating digital asset guard service operator-side index information including information on the file name (after renaming) of each of the file data linked to the information on the preservation points that are sorted by the file data preservation point association sorting means and managed in a black box environment by the preservation point information management means, which are distributed and recorded by each of the distributed recording means or the distributed recording smart contract (or server application), and (encrypted) corresponding recording destination information, and the index information recording means comprises a user (customer and data manager) side index information recording program (or smart contract) that operates on the side of the user (customer and data manager) who desires to save the file data, and a digital asset guard service operator-side index information recording smart contract (or server application) that operates on the side of the digital asset guard service operator-side,the user (customer and data manager) side index information recording program (or smart contract) has a function of encrypting and recording the user (customer and data manager) side index information created by the user (customer and data manager) side index information creation program (or smart contract) in a node group at a specific location in the distributed ledger structure when approval is given using a private key for first blockchain access generated based on a first private key (first offline decryption key) created by each of the customer and the data manager, and the digital asset guard service operator-side index information recording smart contract has a function of encrypting and recording the digital asset guard service operator-side index information created by the digital asset guard service operator-side index information creation smart contract (or server application) in a function of encrypting and recording the digital asset guard service operator-side index information created by the digital asset guard service operator-side index information creation smart contract (or server application) in a function of encrypting and recording the digital asset guard service operator-side index information created by the digital asset guard service operator-side index information creation smart contract (or server application) when approval is given using a private key for second blockchain access generated based on a second private key (second decryption key) created by the digital asset guard service operator. the encrypted index information extraction means has a user (customer and data manager)-side encrypted index information extraction smart contract (or server application) that operates on the side of the user (customer and data manager) who desires to restore the file data, and a digital asset guard service operator-side encrypted index information extraction smart contract (or server application) that operates on the side of the digital asset guard service operator-side, and the user (customer and data manager)-side encrypted index information extraction smart contract (or server application) that operates on the side of the digital asset guard service operator-side, and when authorization is made using a first private key for accessing the blockchain generated based on a first private key (first offline decryption key) created by each of the customer and the data operator, the user (customer and data manager)-side encrypted index information extraction smart contract (or server application) links the file data to be extracted that has been accepted by the customer data restoration instruction acceptance means to the file data that has been accepted for extraction, for each group of file data that is linked to the information of each of the conservation points that is managed in a black-box environment by the conservation point information management means;The digital asset guard service operator-side encrypted index information extracting smart contract (or server application) has a function of extracting encrypted user (customer and data manager)-side index information that is recorded in a node group at a specific location in the distributed ledger structure by the user (customer and data manager)-side encrypted index information recording smart contract (or server application) based on key information (or the first parameter and the second parameter included in the key information) that uses the first authenticator ID information and the second authenticator ID information necessary for data restoration in the agreement information between the first authenticator and the second authenticator regarding the restoration process of the data to be restored for the customer that is acquired by the data restoration process agreement information acquisition means, and the digital asset guard service operator-side encrypted index information extracting smart contract (or server application) has a function of extracting encrypted user (customer and data manager)-side index information that is recorded in an encrypted state in a node group at a specific location in the distributed ledger structure by the digital asset guard service operator-side encrypted index information extracting smart contract (or server application) when approval is given using a second private key for accessing the blockchain that is generated based on a second private key (second decryption key) created by the digital asset guard service operator-side encrypted index information and a function of extracting encrypted digital asset guard service operator-side index information recorded in a group of nodes at a specific location in the distributed ledger structure by the digital asset guard service operator-side encrypted index information recording smart contract (or server application) based on key information (or the first parameter and the second parameter included in the key information) formed using the first authenticator ID information and the second authenticator ID information necessary for data restoration in agreement information between the first authenticator and the second authenticator regarding the restoration process of the data to be restored for the customer, which is associated with the file data to be extracted and received by the data restoration process agreement information acquisition means, for each group of file data linked to the information of the conservation point of the above. The index information decryption means includes a user (customer and data administrator) side index information decryption smart contract (or server application) running on the side of the user (customer and data administrator) who desires to restore the file data,and a digital asset guard service operator-side index information decryption smart contract (or server application) running on the digital asset guard service operator-side, wherein the user (customer and data manager) side index information decryption smart contract (or server application) has a function of decrypting the encrypted user (customer and data manager) side index information extracted by the user (customer and data manager) side encrypted index information extraction smart contract (or server application) based on a first private key (first offline decryption key) created by the customer and the data manager, respectively, and the digital asset guard service operator-side index information decryption smart contract (or server application) has a function of decrypting the encrypted digital asset guard service operator-side index information extracted by the digital asset guard service operator-side encrypted index information extraction smart contract (or server application) based on a second private key (second decryption key) created by the digital asset guard service operator-side.

[0084] Furthermore, in the real-time backup and restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the group of nodes at a specific location in the distributed ledger structure be configured to record, in encrypted form, the following as configuration information for each of the customer and the data manager: IP addresses and user IDs; agreement information between the first authenticator and the second authenticator (or the first parameter included in the agreement information) regarding the backup processing of the data to be backed up for the customer, which is acquired by the data backup processing agreement information acquisition means; a smart contract address on the digital asset guard service operator's side that can reference the configuration information for each of the customer and the data manager; the file name and file data capacity, processing date and time, and storage date when the file data is backed up, which are index information for the customer; configuration information for the smart contract (or server application) running on the digital asset guard service operator's side to back up the customer's file data; and information on the renamed file names of each of the file data that have been distributedly recorded by each of the distributed recording means or the distributed recording smart contract (or server application), which are index information on the digital asset guard service operator's side.

[0085] Furthermore, in the real-time backup and restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the recording devices at multiple locations connected to the nodes at each location via a network consist of nodes that constitute the same blockchain network as the nodes at the location, or devices that do not belong to the blockchain network constituted by the nodes at the location but can be connected in a state that allows them to access the nodes at the location.

[0086] Furthermore, in the first aspect of the present invention, in the real-time backup and restoration type digital asset guard service provision system, it is preferable that the recording devices at multiple locations connected to the nodes at each location via a network be devices that constitute a different network from the nodes at the respective locations.

[0087] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the distributed file management group allocation means or the smart contract (or server application) for distributed file management group allocation, and the encrypted / split file data extraction means or the smart contract (or server application) for encrypted / split file data extraction each have a second parameter specified by the digital asset guard service operator hard-coded internally.

[0088] In addition, in the real-time saving and restoring type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the distributed ledger structure is constructed using a blockchain such as a private type or a consortium type.

[0089] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the private type or consortium type blockchain is constructed having a planet consisting of a group of nodes combining multiple virtual nodes at one base.

[0090] In addition, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the digital asset guard service operator-side file data real-time save system is a digital asset guard service operator-side file data real-time save system that incorporates the functions of the distributed file management group allocation means or the distributed file management group allocation smart contract (or server application), the distributed recording means or the distributed recording smart contract (or server application), the server index information creation smart contract (or server application), and the server index information recording smart contract (or server application). It is preferable that the digital asset guard service operator side file data real-time restoration system has a smart contract (or server application) for real-time data evacuation, and that the digital asset guard service operator side file data real-time restoration system has a smart contract (or server application) for real-time file data restoration on the digital asset guard service operator side that is configured by incorporating the functions of the smart contract (or server application) for extracting encrypted server index information, the smart contract (or server application) for decrypting server index information, and the encrypted / split file data extraction means or the smart contract (or server application) for extracting encrypted / split file data.

[0091] Furthermore, in the first aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable that the smart contract (or server application) for real-time backup of file data on the digital asset guard service operator's side has a second parameter specified by the digital asset guard service operator hard-coded internally.

[0092] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the smart contract (or server application) for real-time file data restoration on the digital asset guard service operator side has hard-coded therein a second parameter specified by the digital asset guard service operator or a second composite parameter (composed of a pair of a second decryption parameter specified by the digital asset guard service operator and managed offline (which is incorporated and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) and a second encryption parameter automatically generated from the second decryption parameter (which is incorporated and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing)).

[0093] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the smart contract (or server application) for real-time file data evacuation on the digital asset guard service administrator side creates a renaming and encryption key using agreement information between the first authenticator and the second authenticator regarding the evacuation process of the data to be evacuated by the customer, acquired by the data evacuation process agreement information acquisition means (or the first parameter specified by the customer who desires to save the file data and the second parameter hard-coded therein, which are included in the agreement information), and changes the file name and encrypts each of the file data linked to the information of the protection point that is encrypted and divided into multiple pieces by the file data encryption / division means, uploaded to the first temporary storage area by the upload means, sorted by the file data protection point association sorting means, and managed in a black box environment by the protection point information management means, using the renaming and encryption key. a function of allocating the data to a plurality of the distributed file management groups, and creating server index information including information on renamed file names of each of the distributed and recorded file data, which is sorted by the file data conservation point association sorting means and linked to information on each of the conservation points managed in a black box environment by the conservation point information management means, and address information of the nodes and recording devices that will store the file data in each of the distributed file management groups to which each of the file data will be allocated, and before encrypting and recording the information on the node group at a specific location in the distributed ledger structure, changing the information on the renamed file names and the address information of the node and recording device that will store the file data to a name that is further different from the renamed file names (based on the second parameter hard-coded internally) to create new server index information, and encrypting the created new server index information and recording it to the node group at a specific location in the distributed ledger structure, and thenIt is preferable that the distributed file management system has a function of erasing address information of the nodes and recording devices that are the storage destinations of the file data in each of the distributed file management groups to which the file data is allocated.

[0094] Furthermore, in the real-time backup and restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the smart contract (or server application) for real-time backup of file data on the digital asset guard service operator side further has the function of changing the name of the file to a name that is different from the converted file name (based on the second parameter hard-coded internally), and then adding dummy file information to the information on the changed file name and the address information of the node and recording device where the file data will be stored to create new server index information, encrypting the new server index information and recording it on a group of nodes at a specific location in the distributed ledger structure, and then erasing the information on the renamed file name of each of the original distributedly recorded file data and the address information of the node and recording device where the file data will be stored in each of the distributed file management groups to which each file data will be allocated.

[0095] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the smart contract (or server application) for real-time file data restoration on the digital asset guard service operator side acquires agreement information between the first authenticator and the second authenticator regarding the save processing of the data to be saved by the customer, acquired by the data save processing agreement information acquisition means (or the first parameter specified by the customer or a first composite parameter (composed of a pair of a first decryption parameter specified by the customer and managed offline and a first encryption parameter automatically generated from the first decryption parameter, which is included in the agreement information), and a second parameter specified by the digital asset guard service operator that is hard-coded internally or a second decryption parameter (specified by the digital asset guard service operator and managed offline (modularized by being incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing)) that is hard-coded internally. and a second composite parameter) which is a pair of second encryption parameters automatically generated from the second decryption parameters (which are incorporated and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing), extracts encrypted server index information (recorded in a node group at a specific location in the distributed ledger structure) for each group of file data linked to the information of each of the conservation points managed in a black-box environment by the conservation point information management means, restores the state of new server index information which has been changed to a name that is further different from the name-converted file name (based on the second parameter or the second composite parameter hard-coded internally), then restores the changed name to the name-converted file name information, and then restores the file name information before the name change of each of the distributed-recorded file data based on the name restoration and decryption key.

[0096] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the smart contract (or server application) for real-time file data restoration on the digital asset guard service administrator side is configured to acquire agreement information between the first authenticator and the second authenticator regarding the save processing of the data to be saved by the customer, acquired by the data save processing agreement information acquisition means (or the first parameter specified by the customer or a first composite parameter (composed of a pair of a first decryption parameter specified by the customer and managed offline and a first encryption parameter automatically generated from the first decryption parameter, which is included in the agreement information), and a second parameter specified by the digital asset guard service administrator (a second parameter specified by the digital asset guard service administrator and managed offline (modularized by being incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is hard-coded internally), and a second composite parameter) which is a pair of a second encryption parameter automatically generated from the decryption parameter of the first parameter (which is incorporated and modularized in a predetermined processing means or a smart contract (or server application) that performs the relevant processing), and for each group of file data linked to the information of each of the conservation points managed in a black-box environment by the conservation point information management means, extract encrypted server index information recorded in a node group at a specific location in the distributed ledger structure, exclude dummy file information (based on the second parameter or the second composite parameter hard-coded internally), then restore the state of new server index information which has been changed to a name which is further different from the file name after name conversion, then restore the changed name to the information of the file name after name conversion, and then restore the file name information before the name change of each of the distributed-recorded file data based on the name recovery and decryption key.

[0097] A real-time evacuation and restoration type digital asset guard service provision system according to a second aspect of the present invention is a real-time evacuation and restoration type digital asset guard service provision system for guarding digital assets from high-level cyber attacks, which is constructed with a distributed ledger in distributed ledger technology and a server application for performing predetermined processing using data managed in the distributed ledger, and which includes a distributed ledger group of private or consortium type etc. constructed with a plurality of planets (forming one unit of a distributed ledger group) consisting of a combination of nodes at multiple locations in different regions around the world, and a first authentication required to authenticate a first certifier who is one of the customers and the data administrator who manages the customer data. a first authenticator information management means for managing first authenticator authentication information, first authenticator ID information and key information required for saving and restoring data, etc.; a second authenticator information management means for managing second authenticator authentication information required for authenticating a second authenticator who is the other of the customers and the data managers who manage the customer's data, and second authenticator ID information and key information required for saving and restoring data, etc.; an external first authenticator authentication system that authenticates the first authenticator; an external second authenticator authentication system that authenticates the second authenticator; a file data real-time saving system; and a file data real-time restoring system, wherein nodes at each location are connected via a network to recording devices at multiple locations in different regions around the world to form a distributed file management group; The file data real-time saving system includes a data saving processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the saving processing of the data to be saved for the customer, a customer data saving instruction means for instructing the saving of the customer's data based on the agreement information when the agreement information between the first authenticator and the second authenticator regarding the saving processing of the data to be saved for the customer is acquired by the data saving processing agreement information acquisition means, a program having a plurality of encryption / division algorithms for different methods of encrypting and dividing file data, and a program for instructing the saving processing of the customer's data to be saved acquired by the data saving processing agreement information acquisition means toan encryption / division algorithm selection receiving means for receiving a selection of a program having a predetermined encryption / division algorithm based on agreement information between the first authenticator and the second authenticator (or a first parameter included in the agreement information and specified by the customer who desires to save file data); a customer data evacuation instruction receiving means for receiving an instruction to save the customer's data from the customer data evacuation instruction means; a file data encryption / division means for encrypting and dividing the customer's data to be saved, which has been received by the customer data evacuation instruction receiving means, into a plurality of file data using a program having the encryption / division algorithm received by the encryption / division algorithm selection receiving means; an uploading means for uploading each of the file data encrypted and divided into a plurality of pieces by the file data encryption / division means to a first temporary storage area; a file data security point associating and sorting each of the file data encrypted and divided into a plurality of pieces by the file data encryption / division means and uploaded to the first temporary storage area by the uploading means by associating it with one of at least two security points for managing the file data; and a security point information management means for managing information of the security points for managing the file data sorted by the file data security point associating and sorting means in a black box environment. The file data preservation point matching and sorting means is provided on each planet, and based on the agreement information between the first authenticator and the second authenticator (or the first parameter included in the agreement information and the second parameter specified by the digital asset guard service operator) regarding the evacuation processing of the data to be evacuated for the customer, which is acquired by the data evacuation processing agreement information acquisition means, sorts the file data linked to the information of the preservation point managed in a black box environment by the preservation point information management means, and constructs the file data linked to the information of the preservation point on the digital asset guard service operator side according to the conditions specified by the customer, using the nodes of each base that constitute the planet corresponding to the preservation point and recording devices of multiple bases that are connected to the nodes of the base via a network.a distributed file management group sorting means having a function of sorting the file data into a plurality of the distributed file management groups; a distributed recording means provided in each planet, the distributed file management group sorting means having a function of distributing and recording the file data associated with the information of each of the conservation points sorted by the distributed file management group sorting means, sorted by the file data conservation point association sorting means, and managed in a black box environment by the conservation point information management means, in a node at each base belonging to each of the corresponding distributed file management groups and in recording devices at multiple bases connected to the node at each base via a network; terminal information (information specifying the other party such as a fixed IP address) for uploading to the first temporary storage area using the upload means, the number of a predetermined processing means that performs the corresponding processing at the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and a group of file servers (at the node at the predetermined base and the recording devices at multiple bases connected to the node at the base via a network) that constitute the distributed file management group; and a system setting information creating and recording means having a function of creating system setting information having information such as the above, encrypting it, and recording it in a node group at a specific location in the distributed ledgers of the private type, the consortium type, or the like; key information using the first authenticator ID information and the second authenticator ID information necessary for data evacuation, which is included in the agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer acquired by the data evacuation processing agreement information acquisition means; file name information of each of the file data that is distributed and recorded by each of the distributed recording means, sorted by the file data conservation point association sorting means, and managed in a black box environment by the conservation point information management means; and server index information creating means for creating server index information having configuration information of each of the distributed file management groups to which each of the file data is allocated; and the server index information created by the server index information creating means,a server index information recording means having a function of encrypting and recording the data in a node group at a specific location in the distributed ledgers of the private type, the consortium type, or the like; a customer setting information creation means (or a program having a wallet function) having a function of creating customer setting information that includes agreement information between the first authenticator and the second authenticator (or setting information of the first parameter included in the agreement information) regarding the evacuation processing of the data to be evacuated for the customer, which is linked to a program having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means; and a customer setting information creation means (or a program having a wallet function) that includes information on the original file name and upload date of the customer's file data to be evacuated. a customer index information creation means (or a program with a wallet function) having a function of creating index information; a customer index information recording means having a function of encrypting the customer index information created by the customer index information creation means (or the program with a wallet function) and recording it in a node group at a specific location in the distributed ledgers of the private type, the consortium type, or the like; and a first data erasure means for erasing each file data uploaded to the first temporary storage area after the server index information has been encrypted and recorded in the node group at a specific location in the distributed ledgers of the private type, the consortium type, or the like by the server index information recording means; the data saving processing agreement information acquisition means comprises: data saving processing request instruction means for issuing an instruction to request saving processing of the data to be saved of the client via the first authenticator; data saving processing request instruction acceptance means for accepting an instruction to request saving processing of the data to be saved of the client from the data saving processing request instruction means; and first authenticator authentication requesting means at data saving processing request instruction acceptance time for acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means when the data saving processing request instruction acceptance means accepts an instruction to request saving processing of the data to be saved of the client; anda data saving first authenticated person ID information and key information receiving means for receiving the first authenticated person ID information and key information required for saving data from the first authenticated person information managing means when the first authenticated person is authenticated by the external first authenticated person authentication system; and a data saving first authenticated person ID information and key information receiving means for receiving, when the first authenticated person ID information and key information required for saving data is received, information indicating that the first authenticated person has issued a request instruction for saving processing of the data to be saved for the customer and information indicating that the data to be saved for the customer has been saved. a first information notification means for notifying the second authenticated person of information prompting an approval instruction for the evacuation process of the data to be saved to the second authenticated person; a data evacuation process approval instruction means for instructing approval of the evacuation process of the data to be saved to the second authenticated person via the second authenticated person who has received the notification from the first information notification means; a data evacuation process approval instruction receiving means for receiving an approval instruction for the evacuation process of the data to be saved to the second authenticated person from the data evacuation process approval instruction means; a second authenticated person authentication requesting means for requesting authentication of the second authenticated person when the data saving process approval instruction is received, which obtains second authenticated person authentication information required for authenticating the second authenticated person from the second authenticated person information managing means and provides it to an external second authenticated person authentication system, and requests authentication of the second authenticated person; a second authenticated person ID information and key information receiving means for data saving, which receives second authenticated person ID information and key information required for data saving from the second authenticated person information managing means when the second authenticated person is authenticated by the external second authenticated person authentication system; a second information notification means for notifying the first authenticator, when the second authenticator ID information and key information receiving means receives the second authenticator ID information and key information necessary for data evacuation, of information that the second authenticator has issued an approval instruction for evacuation processing of the data to be evacuated for the client and information urging the first authenticator to issue an instruction to request evacuation processing of the data to be evacuated for the client; and a data evacuation processing request instruction means for instructing the first authenticator, who has received the notification from the second information notification means, to request evacuation processing of the data to be evacuated for the client.data evacuation processing request instruction receiving means for receiving a request instruction for evacuation processing of data to be saved for the client from said data evacuation processing request instruction means; and data evacuation processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the data evacuation processing of the client, when said data evacuation processing request instruction receiving means receives a request instruction for evacuation processing of data to be saved for the client, using the first authenticator ID information and key information required for data evacuation received by said first authenticator ID information and key information receiving means for data evacuation and the second authenticator ID information and key information required for data evacuation received by said second authenticator ID information and key information receiving means for data evacuation, The file data real-time restoration system includes a data restoration processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding restoration processing of data to be restored for the customer, a customer data restoration instruction means for instructing restoration of the customer's data based on the agreement information when the agreement information between the first authenticator and the second authenticator regarding restoration processing of data to be restored for the customer is acquired by the data restoration processing agreement information acquisition means, and a plurality of decryption and combination programs having different file data decryption and combination processing methods, each of which is linked to a program having the encryption and division algorithm. a program having an algorithm, a customer data restoration instruction receiving means for receiving a restoration instruction for data to be restored for the customer from the customer data restoration instruction means, and a means for receiving a restoration instruction for data to be restored for the customer from the customer data restoration instruction means, the means being provided in each planet, and for each group of file data linked to information of each of the protection points managed in a black box environment by the protection point information management means in the planet corresponding to the protection point, agreement information between the first authenticator and the second authenticator regarding restoration processing of the data to be restored for the customer acquired by the data restoration processing agreement information acquisition means, which is linked to file data to be extracted and accepted by the customer data restoration instruction receiving means,Encrypted server index information having a function of extracting encrypted server index information (recorded by the server index information recording means in a node group at a specific location in the distributed ledgers of the private type, the consortium type, or the like) based on key information using the first authenticator ID information and the second authenticator ID information required for restoring data (or the first parameter included in the key information or a first composite parameter (composed of a pair of a first decryption parameter designated by the customer and managed offline and a first encryption parameter automatically generated from the first decryption parameter), and the second parameter or a second composite parameter (composed of a pair of a second decryption parameter designated by the digital asset guard service administrator and managed offline (modularized in a predetermined processing means that performs the relevant processing) and a second encryption parameter automatically generated from the second decryption parameter (modularized in a predetermined processing means that performs the relevant processing)). an extraction means, a server index information decryption means provided in each planet and having a function of decrypting the encrypted server index information extracted by the encrypted server index information extraction means for each group of file data linked to the information of each of the security points managed in a black-box environment by the security point information management means in the planet corresponding to the security point; and a server index information decryption means provided in each planet and having a function of decrypting the encrypted server index information extracted by the encrypted server index information extraction means for each group of file data linked to the information of each of the security points managed in a black-box environment by the security point information management means in the planet corresponding to the security point, the server index information decrypted by the server index information decryption means being allocated to each of the distributed file management groups by the distributed file management group allocation means, and being distributedly recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in recording devices at multiple bases connected to the base nodes via a network.an encrypted and divided file data extraction means having a function of extracting each of the file data in an encrypted and divided state from any of the nodes of each base belonging to each of the distributed file management groups and the recording devices of multiple bases connected to the nodes of the base via a network; a download means provided in each planet for downloading each of the file data in an encrypted and divided state extracted by the encrypted and divided file data extraction means for each group of the file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point; a file data restoration means for decrypting and combining all of the file data associated with the information of all of the security points in an encrypted and divided state, which is extracted by the encrypted and divided file data extraction means and downloaded to the second temporary storage area by the download means, into one file data by using a program having the decryption and combination algorithm linked to a program having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means, for each group of the file data associated with the information of each of the security points being managed, and which is encrypted and divided into multiple pieces, to restore the client's data before being saved; and a second data erasure means for erasing each of the file data in an encrypted and divided state downloaded to the second temporary storage area after being restored to the client's data before being saved by the file data restoration means, The data restoration processing agreement information acquisition means includes a data restoration processing request instruction means for instructing, via the first authenticator, a request for restoration processing of the data to be restored of the customer, and a data restoration processing request instruction acceptance means for accepting, from the data restoration processing request instruction means, an instruction to request restoration processing of the data to be restored of the customer, and when the data restoration processing request instruction acceptance means accepts the instruction to request restoration processing of the data to be restored of the customer,a first authenticator authentication requesting means for receiving a data restoration processing request instruction, which acquires first authenticator authentication information required for authenticating the first authenticator from the first authenticator information managing means, provides the acquired information to an external first authenticator authentication system, and requests authentication of the first authenticator; a first authenticator ID information and key information receiving means for data restoration, which receives the first authenticator ID information and key information required for data restoration from the first authenticator information managing means when the first authenticator is authenticated by the external first authenticator authentication system; a third information notifying means for, when the information receiving means receives the first authenticator ID information and key information necessary for restoring data, notifying the second authenticator of information that the first authenticator has issued a request instruction for restoration processing of the data to be restored for the customer and information urging the second authenticator to issue an approval instruction for the restoration processing of the data to be restored for the customer; a data restoration processing approval instructing means for issuing an instruction to approve the restoration processing of the data to be restored for the customer via the second authenticator who has received the notification from the third information notifying means; and a data restoration processing approval instructing means for issuing an instruction to approve the restoration processing of the data to be restored for the customer via the second authenticator who has received the notification from the third information notifying means. a data restoration processing approval instruction receiving means for receiving an approval instruction for the restoration processing of the data to be restored of the customer; a data restoration processing approval instruction receiving second authenticator authentication request means for, when the data restoration processing approval instruction receiving means receives an approval instruction for the restoration processing of the data to be restored of the customer, acquiring second authenticator authentication information required for authenticating the second authenticator from the second authenticator information management means, providing the acquired information to an external second authenticator authentication system, and requesting authentication of the second authenticator; and a data restoration processing approval instruction receiving second authenticator authentication request means for, when the second authenticator is authenticated by the external second authenticator authentication system, a second authenticator ID information and key information receiving means for data restoration, which receives the second authenticator ID information and key information required for data restoration from the second authenticator information managing means; and a fourth information notifying means, when the second authenticator ID information and key information receiving means for data restoration receives the second authenticator ID information and key information required for data restoration, notifying the first authenticator of information that the second authenticator has issued an approval instruction for restoration processing of the data to be restored by the customer and information that prompts the first authenticator to issue a request instruction for restoration processing of the data to be restored by the customer.data restoration processing request instruction means for instructing a request for restoration processing of data to be restored for the customer via the first authenticator who has received notification from the fourth information notification means; data restoration processing request instruction receiving means for receiving an instruction to request restoration processing of data to be restored for the customer from the data restoration processing request instruction means; and data restoration processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding restoration processing of data to be restored for the customer, when the data restoration processing request instruction receiving means receives an instruction to request restoration processing of data to be restored for the customer, by combining the first authenticator ID information and key information required for data restoration received by the first authenticator ID information and key information for data restoration receiving means and the second authenticator ID information and key information required for data restoration received by the second authenticator ID information and key information for data restoration receiving means.

[0098] Furthermore, in the real-time save / restore type digital asset guard service providing system of the second aspect of the present invention, the file data real-time save system comprises a user-side file data real-time save system that operates on the side of a user (customer and data manager) who desires to save file data, and a digital asset guard service operator-side file data real-time save system that operates on the side of the digital asset guard service operator, the user-side file data real-time save system comprises the data save processing agreement information acquisition means, the customer data save instruction means, a program having a plurality of the encryption / division algorithms, the encryption / division algorithm selection acceptance means, the customer data save instruction acceptance means, the file data encryption / division means, the upload means, the file data preservation point correspondence sorting means, and the preservation point information management means, and the digital asset guard service operator-side file data real-time save system comprises the distributed file management group allocation means, the distributed recording means, and the above The file data real-time restoration system has the server index information creation means, the server index information recording means, and the first data erasure means, and is composed of a user-side file data real-time restoration system operating on the side of the user (customer or data manager) who wishes to restore the saved file data, and a digital asset guard service operator-side file data real-time restoration system operating on the side of the digital asset guard service operator-side, and the user-side file data real-time restoration system has the data restoration processing agreement information acquisition means, the customer data restoration instruction means, a program having a plurality of the decryption and combination algorithms, the downloading means, the file data restoration means, and the second data erasure means, and it is preferable that the digital asset guard service operator-side file data real-time restoration system has the customer data restoration instruction acceptance means, the encrypted server index information extraction means, the server index information decryption means, and the encrypted and divided file data extraction means.

[0099] In addition, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the at least two conservation points are at least two addresses in one blockchain.

[0100] In addition, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the at least two conservation points are at least one address in each of at least two blockchains.

[0101] In addition, in the second aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable that the at least two conservation points are at least two addresses in one distributed ledger group.

[0102] In addition, in the second aspect of the real-time backup and restoration type digital asset guard service providing system of the present invention, it is preferable that the at least two conservation points are at least one address in each of at least two distributed ledgers.

[0103] Furthermore, in the real-time backup / restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the file data real-time restoration system further has a restoration processing time zone etc. setting receiving means that receives settings from a customer who wishes to restore file data, such as settings of the time zone for performing the file data restoration process, settings of the IP address for restoration, and settings of the period during which restoration is possible, and a file data restoration processing operation control means that controls the customer data restoration instruction receiving means, the smart contract (or server application) for extracting encrypted server index information, the smart contract (or server application) for decrypting server index information, the smart contract (or server application) for extracting encrypted and split file data, the download means, the file data restoration means, and the second data erasure means to operate only during the time zone for which the restoration processing time zone etc. setting receiving means has received settings.

[0104] Furthermore, in the real-time backup / restoration type digital asset guard service providing system of the first aspect of the present invention, the file data real-time restoration system preferably further has an authorization code setting receiving means for receiving the setting of an authorization (license) code from a customer who wishes to restore file data, and the file data restoration processing operation control means preferably controls the customer data restoration instruction receiving means, the smart contract (or server application) for extracting encrypted server index information, the smart contract (or server application) for decrypting server index information, the smart contract (or server application) for extracting encrypted / split file data, the downloading means, the file data restoration means, and the second data erasure means to operate only during the time period for which the restoration processing time period, etc. setting receiving means has accepted the setting, and when the authorization code accepted by the authorization code setting receiving means has been approved by the digital asset guard service operator.

[0105] Furthermore, in the real-time backup / restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the approval code set in the approval code setting receiving means is a code that a customer wishing to restore file data receives from the digital asset guard service operations manager, and the file data restoration processing operation control means is configured to grant an operating license for a program (or smart contract) having the decryption / combination algorithm linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection accepting means when the approval code accepted by the approval code setting receiving means is approved by the digital asset guard service operations manager and the customer's identity is confirmed systematically by multi-step authentication, biometric authentication, one-time passcode, etc. registered on the customer's smartphone.

[0106] In addition, in the real-time backup and restoration type digital asset guard service providing system according to the first aspect of the present invention, each divided file data recorded in the node of each base belonging to each of the distributed file management groups and in the recording devices of multiple bases connected to the node of the base via a network is managed in an encrypted state, index information such as the hash of each file data and the distributed file group to which the recorded file data is assigned is recorded in a block, and the blocks are linked by a chain in which time data is incorporated into the hash, and the file data real-time backup system is configured to perform the data backup service contract application acceptance information recording smart contract (or server application) It is preferable that the distributed ledger structure further comprises a storage period setting smart contract (or server application) having a function of setting the storage period of the block on a planet-by-planet basis when each of the file data is distributedly recorded by each of the distributed recording smart contracts (or server applications) based on information on the storage period of the file data that the customer wishes to evacuate, which information is recorded in a node group at a specific location in the distributed ledger structure by a smart contract for setting a storage period, and a chain disconnection smart contract (or server application) having a function of disconnecting the chain of a block that has passed the storage period set by the storage period setting smart contract (or server application).

[0107] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the file data real-time backup system further has a block deletion smart contract (or server application) that has the function of deleting unnecessary blocks that have been detached via the chain detachment smart contract (or server application).

[0108] Furthermore, in the real-time backup and restoration type digital asset guard service provision system of the first aspect of the present invention, the file data real-time backup system preferably has the function of sending a notification to the customer to confirm whether or not the unnecessary blocks separated via the chain separation smart contract (or server application) can be deleted via the block deletion smart contract (or server application) before the unnecessary blocks separated via the chain separation smart contract (or server application) are deleted via the block deletion smart contract (or server application), and if there is no reply from the customer, notifying the digital asset guard service operator and confirming whether or not the unnecessary blocks can be deleted, and even if it is confirmed that the unnecessary blocks can be deleted, it is preferable that the file data real-time backup system further has an unnecessary block data backup means configured to provisionally record each of the encrypted and divided file data as backup data via a specified recording medium disconnected from the network, and erase the provisionally recorded backup data after a certain period of time has passed.

[0109] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, when the unnecessary block data backup means sends a notification to the customer to confirm whether or not the unnecessary blocks can be deleted, if it is confirmed that the customer wishes to extend the storage period of the file data, it is preferable that the means is configured to provisionally record each of the encrypted and divided file data as backup data via a specified recording medium disconnected from the network, and at the same time select a new planet that meets the conditions of the extended storage period of the file data desired by the customer, automatically backup the file data to the nodes of each base that make up the selected planet and to recording devices at multiple bases that are network-connected to the nodes of the base, and update the server index information, and after the update, erase the provisionally recorded backup data after a certain period of time has passed.

[0110] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, in order to extend the storage period of each file data in an encrypted and divided state that is recorded as the block in each base node belonging to each of the distributed file management groups and in multiple base storage devices connected to the base nodes via a network before the expiration of the storage period of the block set by the storage period setting smart contract (or server application), it is preferable to further have a rollover smart contract (or server application) that has the function of setting a new planet and distributed file management group, inheriting the management number of the old server index information and changing it to a new management number to create new server index information, re-recording the file data in each base node belonging to the new distributed file management group and in multiple base storage devices connected to the base nodes via a network, and then deleting the file data and the old server index information for the file data that are recorded in each base node belonging to the original distributed file management group and in multiple base storage devices connected to the base nodes via a network.

[0111] Furthermore, in the real-time backup and restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the system further comprises: a small amount of file data provisional recording means for recording small amounts of file data to be backed up in real time within the block capacity in a specified confidential blockchain; a file data integration means configured to integrate each small amount of file data recorded in the specified confidential blockchain by the small amount of file data provisional recording means into one integrated file data in batch processing several times a day, and to use the integrated file data for backup processing such as dividing and encrypting the file data by the file data real-time backup system and distributing the recording to each base node belonging to the distributed file management group and to recording devices at multiple bases connected to the base nodes via a network; and a small amount of file data erasure means for, after the file data real-time backup system has completed the backup processing of the integrated file data, cutting the chain of the block that records the corresponding small amount of file data in the specified confidential blockchain and erasing the file data recorded in that block.

[0112] Furthermore, in the real-time backup / restoration type digital asset guard service provision system of the first aspect of the present invention, it is preferable that the file data integration means integrates each small amount of file data recorded in the specified confidential blockchain by the small amount file data temporary recording means into one integrated file data in batch processing several times a day, and passes the integrated file data to a smart contract (or server application) in the file data real-time backup system that has the encryption / division algorithm accepted by the encryption / division algorithm selection accepting means, and controls the backup process to be performed from splitting / encrypting the file data to the nodes of each base belonging to the distributed file management group and distributed recording to recording devices of multiple bases connected to the nodes of the base via a network.

[0113] Furthermore, in the real-time backup / restoration type digital asset guard service providing system of the first aspect of the present invention, it is preferable that the small amount of file data erasure means has a function of setting a provisional storage period of a predetermined number of days (for example, approximately 7 days) for file data that has been recorded in the specified confidential blockchain by the small amount of file data provisional recording means, and that has been integrated into one integrated file data by the file data integration means, and for which the file data real-time backup system has completed the backup process for the integrated file data, and a function of cutting the chain of the corresponding block in the specified confidential blockchain after the provisional storage period has elapsed, and erasing the file data recorded in that block.

[0114] Furthermore, the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention has a second file data real-time deletion system, the second file data real-time deletion system having: data deletion processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding deletion processing of data to be deleted for the customer; customer data deletion instruction means for issuing an instruction to delete the data to be deleted for the customer based on the agreement information when agreement information between the first authenticator and the second authenticator regarding deletion processing of data to be deleted for the customer is acquired by the data deletion processing agreement information acquisition means; customer data deletion instruction acceptance means for accepting an instruction to delete the data to be deleted for the customer from the customer data deletion instruction means; and file data preservation point deletion means for deleting information of the preservation points linked to the file data to be deleted accepted by the customer data deletion instruction acceptance means, which is managed in a black box environment by the preservation point information management means. and a data deletion processing agreement information acquisition means for acquiring first authenticator authentication information from the first authenticator information management means when the data deletion processing request instruction means receives a request for deletion of data to be deleted by the customer. a first authenticator authentication requesting means for receiving a data deletion processing request instruction, which provides the first authenticator to an external first authenticator authentication system and requests authentication of the first authenticator; a first authenticator ID information and key information receiving means for data deletion, which receives the first authenticator ID information and key information necessary for data deletion from the first authenticator information managing means when the first authenticator is authenticated by the external first authenticator authentication system; and a first authenticator ID information and key information receiving means for data deletion, which receives the first authenticator ID information and key information necessary for data deletion from the first authenticator information managing means when the first authenticator ID information and key information receiving means for data deletion receives the first authenticator ID information and key information necessary for data deletion.a fifth information notification means for notifying the second authenticated person of information that the first authenticated person has issued a request instruction for deletion of the data to be deleted of the client and information urging the second authenticated person to give an instruction to approve the deletion of the data to be deleted of the client; a data deletion process approval instruction means for instructing approval of the deletion of the data to be deleted of the client via the second authenticated person who has received the notification from the fifth information notification means; and a data deletion process approval instruction receiving means for receiving an instruction to approve the deletion of the data to be deleted of the client from the data deletion process approval instruction means. a data deletion processing approval instruction receiving means for receiving, when the data deletion processing approval instruction receiving means receives an approval instruction for the deletion processing of the data to be deleted by the customer, second authenticated person authentication information required for authenticating the second authenticated person from the second authenticated person information managing means, and providing the second authenticated person authentication information to an external second authenticated person authentication system, and requesting authentication of the second authenticated person; and a data deletion processing approval instruction receiving second authenticated person authentication request means for receiving, when the second authenticated person is authenticated by the external second authenticated person authentication system, second authenticated person ID information and key information required for data deletion from the second authenticated person information managing means. a sixth information notifying means for notifying the first authenticator of information that the second authenticator has instructed to approve the deletion of the data to be deleted for the customer and information that prompts the first authenticator to instruct to request the deletion of the data to be deleted for the customer when the second authenticator ID information and key information receiving means for data deletion receives the second authenticator ID information and key information necessary for deleting data; and a sixth information notifying means for notifying the first authenticator of information that the second authenticator has instructed to approve the deletion of the data to be deleted for the customer and information that prompts the first authenticator to instruct to request the deletion of the data to be deleted for the customer when the second authenticator ID information and key information receiving means for data deletion receives the second authenticator ID information and key information necessary for deleting data. a data deletion processing request instruction means for instructing a request for data deletion processing, a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of data to be deleted from the data deletion processing request instruction means, and when the data deletion processing request instruction receiving means receives a request instruction for deletion processing of data to be deleted from the customer, the first authenticator ID information and key information receiving means for data deletion receives the first authenticator ID information and key information necessary for data deletion and the second authenticator ID information and key information receiving means receives the first authenticator ID information and key information necessary for data deletion.It is preferable to have a data deletion processing agreement information creation means for creating agreement information between the first authenticator and the second authenticator regarding the deletion processing of the data to be deleted for the customer, using the second authenticator ID information and key information required for data deletion.

[0115] Furthermore, in the real-time backup / restore type digital asset guard service providing system of the first aspect of the present invention, the second file data real-time deletion system comprises a user-side second file data real-time deletion system operating on the side of the user (customer and data manager) who wishes to delete file data, and a digital asset guard service operator-side second file data real-time deletion system operating on the side of the digital asset guard service operator-side, and it is preferable that the user-side second file data real-time deletion system has the data deletion processing agreement information acquisition means and the customer data deletion instruction means, and that the digital asset guard service operator-side second file data real-time deletion system has the customer data deletion instruction acceptance means and the file data preservation point information deletion means.

[0116] Furthermore, the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention has a second file data real-time update (saving and deletion) system, the second file data real-time update (saving and deletion) system including: data update (saving and deletion) processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer between the first authenticator and the second authenticator; customer data update (saving and deletion) instruction means for instructing the update (saving and deletion) of the data to be updated (saving and deletion) for the customer based on the agreement information when agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer is acquired by the data update (saving and deletion) processing agreement information acquisition means; a program (or smart contract) having a plurality of the encryption / division algorithms for different file data encryption and division processing methods; an update (saving and deletion) processing time encryption / division algorithm selection receiving means for receiving a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer acquired by the data update (saving and deletion) processing agreement information acquisition means; an update (saving and deletion) processing time customer data evacuation instruction receiving means for receiving an instruction to evacuate the data to be evacuated for the customer from the customer data update (saving and deletion) instruction means; an update (saving and deletion) processing time file data encryption / division means for encrypting and dividing the customer data to be evacuated, which has been accepted by the update (saving and deletion) processing time customer data evacuation instruction accepting means, into a plurality of file data using a program (or smart contract) having the encryption / division algorithm accepted by the update (saving and deletion) processing time encryption / division algorithm selection accepting means; and each of the file data encrypted and divided into a plurality of file data by the update (saving and deletion) processing time file data encryption / division means,an update (saving and deletion) processing time uploading means for uploading to a first temporary storage area; an update (saving and deletion) processing time file data conservation point associating and sorting each piece of file data encrypted and divided by the update (saving and deletion) processing time file data encryption / division means and uploaded to the first temporary storage area by the update (saving and deletion) processing time uploading means, by associating the file data with one of the conservation points corresponding to at least two planets for managing the file data; and an update (saving and deletion) processing time conservation point information management means for managing, in a black box environment, information on the conservation points for managing the file data sorted by the update (saving and deletion) processing time file data conservation point associating and sorting means; The file data protection point associating and sorting means for updating (saving and deleting) processing is provided in each planet, and based on the agreement information between the first certifier and the second certifier (or a first parameter included in the agreement information and a second parameter designated by the digital asset guard service administrator) regarding the saving process of the data to be saved by the customer, which is acquired by the data update (saving and deleting) processing agreement information acquisition means, sorts the file data linked to the information of the protection points managed in a black box environment by the protection point information management means for updating (saving and deleting) processing, and sorts the file data linked to the information of the protection points managed in a black box environment by the protection point information management means for updating (saving and deleting) processing, according to the conditions designated by the customer, a smart contract (or server application) for distributed file management group allocation during update (saving and deletion) processing, which is configured by a host service administrator and is constructed by nodes at each base constituting the planet corresponding to the conservation point and recording devices at multiple bases connected to the base nodes via a network, and which has the function of allocating to multiple distributed file management groups; and a file data conservation point association sorting means for update (saving and deletion) processing, which is provided on each planet and sorted by the smart contract (or server application) for distributed file management group allocation during update (saving and deletion) processing,a smart contract (or server application) for distributed recording at update (backup and deletion) processing, which has a function of distributing and recording each of the file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means at update (backup and deletion) processing in the nodes of each base belonging to the corresponding distributed file management group and in recording devices of multiple bases connected to the nodes of the base via a network; and a smart contract (or server application) for distributed recording at update (backup and deletion) processing, which has a function of creating system setting information including terminal information (information identifying the other party such as a fixed IP address) for uploading to the first temporary storage area using the upload means at update (backup and deletion) processing, the number of a predetermined processing means that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, information on a group of file servers (in the node of a predetermined base and in recording devices of multiple bases connected to the node of the base via a network) that constitutes the distributed file management group, encrypting the information, and recording it in a group of nodes of a specific base in the distributed ledger structure. a smart contract (or server application) for creating and recording system setting information during update (saving and deletion) processing; and a smart contract (or server application) for creating server index information during update (saving and deletion) processing, the smart contract (or server application) having a function for creating server index information including: key information formed using the first authenticator ID information and the second authenticator ID information required for data evacuation, which are included in agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer acquired by the data update (saving and deletion) processing agreement information acquisition means; file name information of each of the file data linked to the information of the conservation point sorted by the file data conservation point association sorting means during update (saving and deletion) processing and managed in a black box environment by the conservation point information management means during update (saving and deletion) processing, which has been distributed and recorded by each of the distributed recording means during update (saving and deletion) processing; and configuration information of each of the distributed file management groups to which each of the file data is allocated;a smart contract (or server application) for recording server index information during update (saving and deletion) processing, which has a function of encrypting and recording the server index information created by the smart contract (or server application) for creating server index information during update (saving and deletion) processing in a node group at a specific location in the distributed ledger structure; a smart contract (or program with a wallet function) for creating customer setting information during update (saving and deletion) processing, which has a function of creating customer setting information containing agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer, which is acquired by the data update (saving and deletion) processing agreement information acquisition means linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means for update (saving and deletion) processing; and a smart contract (or program with a wallet function) for creating customer setting information during update (saving and deletion) processing, which has a function of creating customer setting information containing agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer, which is acquired by the data update (saving and deletion) processing agreement information acquisition means linked to the program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means for update (saving and deletion) processing; and a smart contract (or a program with a wallet function) for creating customer index information during update (saving and deletion) processing having a function of encrypting the customer index information created by the smart contract (or the program with a wallet function) for creating customer index information during update (saving and deletion) processing and recording it in a group of nodes at a specific location in the distributed ledger structure; a first data erasure means during update (saving and deletion) processing that erases each file data uploaded to the first temporary storage area after the server index information has been encrypted and recorded in the group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information during update (saving and deletion) processing; and a customer data deletion instruction receiving means during update (saving and deletion) processing that receives an instruction to delete data to be deleted for the customer from the update (saving and deletion) instruction means.and a file data preservation point information deletion means for deleting information on the preservation points associated with the file data to be deleted that is received by the customer data deletion instruction receiving means for update (saving and deleting) processing, the preservation point information management means for update (saving and deleting) processing managing the information on the preservation points in a black box environment, The data update (saving and deletion) processing agreement information acquisition means includes data update (saving and deletion) processing request instructing means for instructing a request for processing to update (saving and deleting) data to be updated (saving and deleted) for the customer via the first authenticator, data update (saving and deletion) processing request instruction receiving means for receiving a request instruction for processing to update (saving and deleting) data to be updated (saving and deleted) for the customer from the data update (saving and deletion) processing request instructing means, and when the data update (saving and deletion) processing request instruction receiving means receives a request instruction for processing to update (saving and deleting) data to be updated (saving and deleted) for the customer, it acquires first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means and provides it to an external first authenticator authentication system, and when it receives a data update (saving and deletion) processing request instruction requesting authentication of the first authenticator, an authenticator authentication requesting means; a first authenticator ID information and key information receiving means for data update (saving and deleting) which receives the first authenticator ID information and key information required for updating (saving and deleting) data from the first authenticator information managing means when the first authenticator is authenticated by the external first authenticator authentication system; a seventh information notifying means for notifying the second authenticator, when the first authenticator ID information and key information receiving means for data update (saving and deleting) has received the first authenticator ID information and key information required for updating (saving and deleting), the second authenticator receiving the information that the first authenticator has issued a request instruction for updating (saving and deleting) data of the customer and that the second authenticator is urged to issue an approval instruction for updating (saving and deleting) data of the customer; anda data update (saving and deletion) processing approval instruction means for instructing approval of the update (saving and deletion) processing of the data to be updated (saved and deleted) by the customer; a data update (saving and deletion) processing approval instruction receiving means for receiving an instruction to approve the update (saving and deletion) processing of the data to be updated (saved and deleted) by the customer from the data update (saving and deletion) processing approval instruction means; and a second authenticated person authentication requesting means for receiving a data update (saving and deleting) processing approval instruction, which acquires second authenticated person authentication information required for authenticating the second authenticated person from the second authenticated person information managing means, provides the acquired information to an external second authenticated person authentication system, and requests authentication of the second authenticated person; and a second authenticated person ID information and key information receiving means for data update (saving and deleting), which receives the second authenticated person ID information and key information required for updating (saving and deleting) data from the second authenticated person information managing means when the second authenticated person is authenticated by the external second authenticated person authentication system. an eighth information notification means for notifying the first authenticator of information that the second authenticator has given an approval instruction for the update (saving and deletion) process of the data to be updated (saving and deletion) of the customer when the second authenticator ID information and key information receiving means for data update (saving and deletion) receives the second authenticator ID information and key information necessary for data update (saving and deletion) and information that prompts the first authenticator to give a request instruction for the update (saving and deletion) process of the data to be updated (saving and deletion) of the customer; and a data update (saving and deletion) processing request instruction means for instructing a request for processing to update (saving and deleting) data to be updated (saved and deleted) by the customer via the data update (saving and deletion) processing request instruction receiving means for receiving a request instruction for processing to update (saved and deleted) data to be updated (saved and deleted) by the customer from the data update (saving and deletion) processing request instruction means; and when the data update (saving and deletion) processing request instruction receiving means receives a request instruction for processing to update (saved and deleted) data to be updated (saved and deleted) by the customer,It is preferable to have a data update (saving and deletion) processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer, using the first authenticator ID information and key information required for data update (saving and deletion) received by the first authenticator ID information and key information receiving means for data update (saving and deletion) and the second authenticator ID information and key information required for data update (saving and deletion) received by the second authenticator ID information and key information receiving means for data update (saving and deletion).

[0117] Furthermore, in the real-time save / restore type digital asset guard service providing system of the first aspect of the present invention, the second file data real-time update (saving and deletion) system comprises a user-side second file data real-time update (saving and deletion) system that operates on the side of a user (customer or data manager) who desires to update (saving and deleting) file data, and a digital asset guard service operator-side second file data real-time update (saving and deletion) system that operates on the side of the digital asset guard service operator, and the user-side second file data real-time update (saving and deletion) system comprises the data update (saving and deletion) processing agreement information acquisition means, the customer data update (saving and deletion) instruction means, a program (or smart contract) having a plurality of the encryption / division algorithms, the encryption / division algorithm selection acceptance means at the time of the update (saving and deletion) processing, the customer data save instruction acceptance means at the time of the update (saving and deletion) processing, the file data encryption / division means at the time of the update (saving and deletion) processing, and the The digital asset guard service operator side preferably has an upload means at the time of update (saving and deletion) processing, a file data preservation point correspondence sorting means at the time of update (saving and deletion) processing, and a preservation point information management means at the time of update (saving and deletion) processing, and the second file data real-time update (saving and deletion) system on the digital asset guard service operator side preferably has a smart contract (or server application) for allocating distributed file management groups at the time of update (saving and deletion) processing, a smart contract (or server application) for distributing recording at the time of update (saving and deletion) processing, a smart contract (or server application) for creating server index information at the time of update (saving and deletion) processing, a smart contract (or server application) for recording server index information at the time of update (saving and deletion) processing, a first data erasure means at the time of update (saving and deletion) processing, a customer data deletion instruction receiving means at the time of update (saving and deletion) processing, and a file data preservation point information deletion means at the time of update (saving and deletion) processing.

[0118] Furthermore, a real-time evacuation and restoration type digital asset guard service provision system according to a third aspect of the present invention is a real-time evacuation and restoration type digital asset guard service provision system for guarding digital assets from high-level cyber attacks, constructed with a distributed ledger in distributed ledger technology such as blockchain, and a smart contract or server application for performing predetermined processing using the data managed in the distributed ledger, or a system for handling data that is difficult to manage in a system, such as personal information, mainly on-chain in two configurations, one in which the information is managed by a company, and the other in which the information is managed by an individual, and is a base system for managing the personal information directly on-chain in both configurations, or for separating the personal information portion based on the information and utilizing it as personal attribute information for big data analysis, etc., and is composed of a group of nodes combining nodes at multiple locations in different regions around the world (for example, blockchain and file distributed management functions). and the like, which constitutes one unit constituting a system for providing services that implement distributed smart contracts, server applications, etc., and which is constructed having a plurality of planets (planets each of which is a unit combining a plurality of blockchains, ...a data evacuation processing agreement information acquisition means for acquiring agreement information between the first user and the second user; a customer data evacuation instruction means for, when the data evacuation processing agreement information acquisition means has acquired agreement information between the first user and the second user regarding the evacuation processing of the customer's data to be evacuated, instructing the evacuation of the customer's data to be evacuated based on the agreement information; a program (or smart contract) having a plurality of encryption / division algorithms for encrypting and dividing file data differently, and an encryption / division algorithm selection acceptance means for accepting a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on the agreement information between the first user and the second user regarding the evacuation processing of the customer's data to be evacuated acquired by the data evacuation processing agreement information acquisition means (or a first parameter included in the agreement information and specified by the customer who desires to evacuate file data); and a program (or smart contract) having a predetermined encryption / division algorithm based on the agreement information between the first user and the second user regarding the evacuation processing of the customer's data to be evacuated acquired by the data evacuation processing agreement information acquisition means. a file data encryption and division means for encrypting and dividing the customer data to be saved, which has been received by the customer data evacuation instruction receiving means, into a plurality of file data using a program (or smart contract) having the encryption and division algorithm received by the encryption and division algorithm selection receiving means; an upload means for uploading each of the file data encrypted and divided into a plurality of pieces by the file data encryption and division means to a first temporary storage area; a file data security point associating and sorting each of the file data encrypted and divided into a plurality of pieces by the file data encryption and division means and uploaded to the first temporary storage area by the upload means, by associating it with one of at least two security points for managing the file data; and a security point information management means for managing information of the security points for managing the file data sorted by the file data security point associating and sorting means in a black box environment,The file data is sorted by the file data conservation point associating and sorting means based on the agreement information between the first user and the second user (or the first parameter included in the agreement information and the second parameter specified by the digital asset guard service administrator) regarding the evacuation process of the data to be evacuated for the customer acquired by the data evacuation process agreement information acquisition means, and the file data associated with the information of the conservation point managed in a black box environment by the conservation point information management means is set by the digital asset guard service administrator according to conditions specified by the customer, and the file data is sorted by the file data conservation point associating and sorting means, and the file data is managed in a black box environment by the conservation point information management means, into the plurality of distributed file management groups configured by the nodes of each base constituting the planet corresponding to the conservation point and recording devices of multiple bases connected to the nodes of the base via a network; and the distributed file management group sorting means or the distributed file management group sorting smart contract (or server application) is provided on each planet and has a function of sorting the file data. a distributed recording means or a smart contract (or server application) having a function of distributing and recording each of the file data associated with the information of each of the conservation points sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means, in each of the base nodes belonging to the corresponding distributed file management group and in recording devices at multiple bases connected to the base nodes via a network; and creating system setting information including terminal information (information identifying the other party, such as a fixed IP address) for uploading to the first temporary storage area using the upload means, the number of a predetermined processing means or smart contract (or server application) that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and information on a group of file servers (at the node at the predetermined base and the recording devices at multiple bases connected to the node at the base via a network) that constitute the distributed file management group;a smart contract (or server application) for creating and recording system setting information, which has a function of encrypting the data and recording it in a group of nodes at a specific location in the distributed ledger structure; a smart contract (or server application) for creating server index information, which has a function of creating server index information, which includes: key information using the first user ID information and the second user ID information required for data evacuation, which are included in agreement information between the first user and the second user regarding the evacuation process of the data to be evacuated for the customer acquired by the data evacuation process agreement information acquisition means; file name information of each of the file data that is distributedly recorded by each of the distributed recording means or the distributed recording smart contract (or server application), sorted by the file data conservation point association sorting means, and linked to the information of the conservation point that is managed in a black box environment by the conservation point information management means; and configuration information of each of the distributed file management groups to which each of the file data is allocated; a smart contract (or a server application) for recording server index information having a function of encrypting server index information created by the smart contract (or server application) for creating server index information and recording it in a group of nodes at a specific location in the distributed ledger structure; a smart contract (or a program with a wallet function) for creating customer setting information having agreement information between the first user and the second user (or setting information of the first parameter included in the agreement information) regarding the evacuation process of the data to be evacuated for the customer, which is linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means; and a smart contract (or a program with a wallet function) for creating customer index information having information on the original file name and upload date of the customer's file data to be evacuated.a customer index information recording smart contract (or server application) having a function of encrypting the customer index information created by the customer index information creation smart contract (or program having a wallet function) and recording the encrypted customer index information in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means for erasing each file data uploaded to the first temporary storage area after the server index information is encrypted and recorded in the group of nodes at a specific location in the distributed ledger structure by the server index information recording smart contract (or server application), The data saving processing agreement information acquisition means includes a data saving processing request instruction means for instructing, via the first user, a request for saving processing of the data to be saved of the customer, a data saving processing request instruction acceptance means for accepting a request instruction for saving processing of the data to be saved of the customer from the data saving processing request instruction means, a first user ID information reception means for receiving the first user ID information necessary for saving data from the first user information management means when the data saving processing request instruction acceptance means accepts a request instruction for saving processing of the data to be saved of the customer, and a first user ID information reception means for receiving the first user ID information necessary for saving data from the first user information management means when the first user ID information reception means for data saving accepts the first user ID information necessary for saving data. a first information notification means for notifying the second user of information that a request instruction for data evacuation processing has been issued and information urging the second user to give an approval instruction for the data evacuation processing of the data to be evacuated for the customer; a data evacuation processing approval instruction means for instructing approval of the data evacuation processing of the data to be evacuated for the customer via the second user who has received the notification from the first information notification means; a data evacuation processing approval instruction receiving means for receiving an instruction to approve the data evacuation processing of the data to be evacuated for the customer from the data evacuation processing approval instruction means; and a data evacuation second user ID information receiving means for receiving the second user ID information required for data evacuation from the second user information management means when the data evacuation processing approval instruction receiving means receives an instruction to approve the data evacuation processing of the data to be evacuated for the customer.a second information notification means for notifying the first user, when the second user ID information receiving means for data evacuation has received the second user ID information necessary for data evacuation, of information that the second user has given an approval instruction for evacuation processing of the data to be evacuated for the customer and information urging the first user to give an instruction to request evacuation processing of the data to be evacuated for the customer; a data evacuation processing request instruction means for instructing the first user, who has received the notification from the second information notification means, to request evacuation processing of the data to be evacuated for the customer; and a data evacuation processing request instruction means for receiving an instruction to request evacuation processing of the data to be evacuated for the customer from the data evacuation processing request instruction means. and a data evacuation processing agreement information creation means for, when the data evacuation processing request instruction acceptance means accepts an instruction to request evacuation processing of data to be evacuated for the client, using the first user ID information required for data evacuation and key information managed by the first user received by the data evacuation first user ID information reception means and the second user ID information required for data evacuation and key information managed by the second user received by the data evacuation second user ID information reception means, to create agreement information between the first user and the second user regarding the evacuation processing of the data to be evacuated for the client, The file data real-time restoration system includes: a data restoration processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding the restoration processing of the data to be restored for the customer, the data restoration processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding the restoration processing of the data to be restored for the customer, a customer data restoration instruction means for instructing the restoration of the data to be restored for the customer based on the agreement information when the agreement information between the first user and the second user regarding the restoration processing of the data to be restored for the customer is acquired by the data restoration processing agreement information acquisition means, a program (or smart contract) having a plurality of decryption and combination algorithms with different file data decryption and combination processing methods, each linked to a program (or smart contract) having the encryption and division algorithm, and a customer data restoration instruction acceptance means for accepting an instruction to restore the data to be restored for the customer from the customer data restoration instruction means.A means for managing the data restoration instruction for the digital asset guard service provided in each planet and corresponding to the digital asset guard service is provided for each group of file data linked to the information of each of the security points managed in a black box environment by the security point information management means, and for each group of file data linked to the information of each of the security points managed in a black box environment by the security point information management means, the means for managing the data restoration instruction for the digital asset guard service is provided for each planet and corresponding to the security point, and for each group of file data linked to the information of each of the security points managed in a black box environment by the security point information management means, the means for managing the data restoration instruction for the digital asset guard service is provided for each planet and corresponding to the security point, and for each group of file data linked to the information of each of the security points managed in a black box environment by the security point information management means, the means for managing the data restoration instruction for the digital asset guard service is provided for each planet and corresponding to the security point, and for each group of file data linked to the information of each of the security points managed in a black box environment by the security point information management means, the means for managing the data restoration instruction for the digital asset guard service is provided for each planet and corresponding to the security point, a smart contract (or server application) for extracting encrypted server index information that has a function of extracting encrypted server index information (recorded in a node group at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on a second composite parameter (composed of a pair of a second decryption parameter (embedded and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) and a second encryption parameter (embedded and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter); and a smart contract (or server application) for extracting encrypted server index information that is provided in each planet and that extracts, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point,a server index information decryption smart contract (or server application) having a function of decrypting encrypted server index information; and a server index information decryption smart contract (or server application) provided in each planet, for each group of file data linked to information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point, using the server index information decrypted by the server index information decryption smart contract (or server application), to decrypt each of the encrypted and divided file data that has been allocated to each of the distributed file management groups by the distributed file management group allocation means or the distributed file management group allocation smart contract (or server application) and distributedly recorded in each of the base nodes belonging to each of the distributed file management groups and in recording devices at multiple bases connected to the base nodes via a network by each of the distributed recording means or the distributed recording smart contract (or server application). the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data having a function of extracting data from any of the nodes of each base belonging to each of the distributed file management groups and from any of the recording devices of multiple bases connected to the nodes of the base via a network; a download means provided in each planet for downloading, to a second temporary storage area, each of the file data in an encrypted and divided state extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data for each group of the file data linked to the information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point;a file data restoration means for decrypting and combining all of the file data linked across information on all of the conservation points in an encrypted and divided state, which has been extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data and downloaded to the second temporary storage area by the download means, into one file data, using a program (or smart contract) having the decryption and combination algorithm linked to a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means, to restore the client's data before it was saved; and a second data erasure means for erasing each of the file data in an encrypted and divided state, which has been downloaded to the second temporary storage area after being restored to the client's data before it was saved by the file data restoration means, The data restoration processing agreement information acquisition means includes a data restoration processing request instruction means for instructing, via the first user, a request for restoration processing of data to be restored for the customer, a data restoration processing request instruction acceptance means for accepting a request instruction for restoration processing of data to be restored for the customer from the data restoration processing request instruction means, a first user ID information reception means for data restoration that receives the first user ID information required for data restoration from the first user information management means when the data restoration processing request instruction acceptance means accepts a request instruction for restoration processing of data to be restored for the customer, and a data restoration first user ID information receiver. a third information notification means for, when the stage receives the first user ID information necessary for data restoration, notifying the second user of information that the first user has issued a request instruction for restoration processing of the data to be restored for the customer and information urging the second user to give an instruction to approve the restoration processing of the data to be restored for the customer, a data restoration processing approval instruction means for issuing an instruction to approve the restoration processing of the data to be restored for the customer via the second user who has received the notification from the third information notification means, and a data restoration processing approval instruction receiving means for receiving an instruction to approve the restoration processing of the data to be restored for the customer from the data restoration processing approval instruction means;a second user ID information receiving means for data restoration that receives the second user ID information required for data restoration from the second user information managing means when the data restoration processing approval instruction receiving means receives an instruction to approve the restoration processing of the data to be restored for the customer; a fourth information notifying means that, when the second user ID information receiving means for data restoration receives the second user ID information required for data restoration, notifies the first user of information that the second user has issued an instruction to approve the restoration processing of the data to be restored for the customer and information urging the first user to issue an instruction to request the restoration processing of the data to be restored for the customer; and a data restoration processing request instructing means that instructs the first user who has received the notification from the fourth information notifying means to request the restoration processing of the data to be restored for the customer, via the first user. and a data restoration processing request instruction receiving means for receiving a request instruction for restoration processing of data to be restored for the customer from the data restoration processing request instruction means, and a data restoration processing agreement information creating means for creating agreement information between the first user and the second user regarding the restoration processing of the data to be restored for the customer, using the first user ID information required for data restoration and key information managed by the first user, which are received by the first user ID information for data restoration receiving means, and the second user ID information required for data restoration and key information managed by the second user, which are received by the second user ID information for data restoration receiving means, when the data restoration processing request instruction receiving means receives a request instruction for restoration processing of data to be restored for the customer.

[0119] Furthermore, in the real-time save / restore type digital asset guard service providing system of the third aspect of the present invention, the file data real-time save system comprises a user-side file data real-time save system that operates on the side of a user (customer and data manager) who desires to save file data, and a digital asset guard service operator-side file data real-time save system that operates on the side of the digital asset guard service operator, and the user-side file data real-time save system comprises the data save processing agreement information acquisition means, the customer data save instruction means, a program (or smart contract) comprising a plurality of the encryption / division algorithms, the encryption / division algorithm selection acceptance means, the customer data save instruction acceptance means, the file data encryption / division means, the upload means, the file data preservation point association sorting means, and the preservation point information management means, and the digital asset guard service operator-side file data real-time save system comprises the distributed file management group allocation means or the distributed file management group allocation means. the file data real-time restoration system comprises a user-side file data real-time restoration system operated on the side of a user (customer or data manager) who desires to restore saved file data, and a digital asset guard service operator-side file data real-time restoration system operated on the side of the digital asset guard service operator, the user-side file data real-time restoration system comprising the data restoration processing agreement information acquisition means, the customer data restoration instruction means, a program (or smart contract) having a plurality of the decryption and combination algorithms, the downloading means, the file data restoration means, and the second data erasure means;The digital asset guard service operator-side file data real-time restoration system preferably comprises the customer data restoration instruction receiving means, the encrypted server index information extraction smart contract (or server application), the server index information decryption smart contract (or server application), and the encrypted and divided file data extraction means or the encrypted and divided file data extraction smart contract (or server application).

[0120] Furthermore, a real-time save / restore type digital asset guard service providing system according to a third aspect of the present invention comprises a file data real-time deletion system, the file data real-time deletion system comprising: a data deletion processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding the deletion processing of data to be deleted for the customer; a customer data deletion instruction means for issuing an instruction to delete the data to be deleted for the customer based on the agreement information when the agreement information between the first user and the second user regarding the deletion processing of data to be deleted for the customer is acquired by the data deletion processing agreement information acquisition means; a customer data deletion instruction receiving means for receiving an instruction to delete the data to be deleted for the customer from the customer data deletion instruction means; and a customer data deletion instruction receiving means provided on each planet, which receives, in the planet corresponding to the protection point, the customer data deletion instruction receiving means for receiving, for each group of file data linked to information of each of the protection points managed in a black box environment by the protection point information management means. key information formed using the first user ID information and the second user ID information required for data deletion in the agreement information between the first user and the second user regarding the deletion process of the data to be deleted for the customer acquired by the data deletion process agreement information acquisition means, which is linked to the file data to be deleted received by the attachment means (or the first parameter included in the key information or a first composite parameter (composed of a pair of a first decryption parameter designated and managed offline by the customer and a first encryption parameter automatically generated from the first decryption parameter); the second parameter or a second decryption parameter (designated and managed offline by the digital asset guard service administrator and incorporated and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing), and a second encryption parameter automatically generated from the second decryption parameter (embedded and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing);a smart contract (or server application) for extracting encrypted server index information to be deleted, which has a function of extracting encrypted server index information (recorded in a node group at a specific site in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on a second composite parameter (composed of a pair of parameters, each of which is a parameter consisting of a first composite parameter and a second composite parameter consisting of a first composite parameter and a second composite parameter), a smart contract (or server application) for decrypting server index information to be deleted, which is provided in each planet, and has a function of decrypting the encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information to be deleted, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point; and a smart contract (or server application) for deleting encrypted and divided file data that has a function of deleting, for each group of file data linked to information of each of the conservation points managed in a black-box environment, from each of the base nodes belonging to each of the distributed file management groups and from all of the base node storage devices connected to the base nodes via a network, the encrypted and divided file data being allocated to each of the distributed file management groups by the distributed file management group allocation means using server index information decrypted by the smart contract (or server application) for decrypting server index information to be deleted, and being distributedly recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in all of the base node storage devices connected to the base nodes via a network, the encrypted and divided file data being targeted for deletion; the encrypted and divided file data being allocated to each of the distributed file management groups by the distributed file management group allocation means using server index information decrypted by the smart contract (or server application) for decrypting server index information to be deleted, and being distributedly recorded in each of the base nodes belonging to each of the distributed file management groups and from all of the base node storage devices connected to the base nodes via a network, the distributed recording means being distributedly recorded in each of the base nodes belonging to each of the distributed file management groups and from all of the base node storage devices connected to the base nodes via a network, the data deletion processing agreement information acquisition means comprising: a data deletion processing request instruction means for instructing a request for deletion processing of the data to be deleted of the customer via the first user;a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of data to be deleted of the customer from the data deletion processing request instruction means; a data deletion first user ID information receiving means for receiving the first user ID information necessary for data deletion from the first user information management means when the data deletion processing request instruction receiving means receives a request instruction for deletion processing of data to be deleted of the customer; a fifth information notifying means for notifying the second user, when the data deletion first user ID information receiving means receives the first user ID information necessary for data deletion, of information that the first user has issued a request instruction for deletion processing of data to be deleted of the customer and information urging the second user to give an instruction to approve the deletion processing of the data to be deleted of the customer; a data deletion processing approval instruction receiving means for giving an instruction to approve the deletion processing of the data to be deleted of the customer via the second user who has received the notification from the fifth information notifying means; a second user ID information receiving means for data deletion, which receives the second user ID information necessary for data deletion from the second user information managing means when the management approval instruction receiving means receives an instruction to approve the deletion of data to be deleted for the customer; a sixth information notifying means, when the second user ID information receiving means for data deletion receives the second user ID information necessary for data deletion, notifying the first user of information that the second user has given an instruction to approve the deletion of data to be deleted for the customer and information urging the first user to give an instruction to request the deletion of data to be deleted for the customer; a data deletion processing request instruction receiving means, which receives an instruction to request the deletion of data to be deleted for the customer from the data deletion processing request instruction means when the data deletion processing request instruction receiving means receives an instruction to request the deletion of data to be deleted for the customer;It is preferable to have a data deletion processing agreement information creation means for creating agreement information between the first user and the second user regarding the deletion processing of the data to be deleted for the customer, using the first user ID information required for data deletion, key information managed by the first user, and the second user ID information required for data deletion and key information managed by the second user, which are received by the data deletion second user ID information receiving means.

[0121] Furthermore, in the third aspect of the present invention, the real-time backup and restoration type digital asset guard service providing system, the file data real-time deletion system comprises a user-side file data real-time deletion system that operates on the side of the user (customer and data administrator) who wishes to delete file data, and a digital asset guard service operator-side file data real-time deletion system that operates on the side of the digital asset guard service operator-side, and the user-side file data real-time deletion system has the data deletion processing agreement information acquisition means and the customer data deletion instruction means, and the digital asset guard service operator-side file data real-time deletion system has the customer data deletion instruction acceptance means, a smart contract (or server application) for extracting the encrypted server index information to be deleted, a smart contract (or server application) for decrypting the server index information to be deleted, and a smart contract (or server application) for deleting the encrypted and divided file data.

[0122] Furthermore, a real-time save / restore type digital asset guard service providing system according to a third aspect of the present invention includes a file data real-time update (saving and deletion) system, the file data real-time update (saving and deletion) system including: a data update (saving and deletion) processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer between the first user and the second user; a customer data update (saving and deletion) instruction means for instructing the update (saving and deletion) of the data to be updated (saving and deletion) for the customer based on the agreement information when the agreement information between the first user and the second user regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer is acquired by the data update (saving and deletion) processing agreement information acquisition means; a program (or smart contract) having a plurality of encryption / division algorithms that differ in the file data encryption and division processing methods; and a data update (saving and deletion) instruction means for instructing the update (saving and deletion) of the data to be updated (saving and deletion) for the customer based on the agreement information when the agreement information between the first user and the second user regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer is acquired by the data update (saving and deletion) processing agreement information acquisition means. an update (saving and deletion) processing time encryption / division algorithm selection receiving means for receiving a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on agreement information between the first user and the second user regarding the evacuation processing of the data to be evacuated for the customer acquired by the update (saving and deletion) processing agreement information acquisition means; an update (saving and deletion) processing time customer data evacuation instruction receiving means for receiving an instruction to evacuate the data to be evacuated for the customer from the customer data update (saving and deletion) instruction means; an update (saving and deletion) processing time file data encryption / division means for encrypting and dividing the customer data to be evacuated, which has been accepted by the update (saving and deletion) processing time customer data evacuation instruction accepting means, into a plurality of file data using a program (or smart contract) having the encryption / division algorithm accepted by the update (saving and deletion) processing time encryption / division algorithm selection accepting means; and each of the file data encrypted and divided into a plurality of file data by the update (saving and deletion) processing time file data encryption / division means,an update (saving and deletion) processing time uploading means for uploading to a first temporary storage area; an update (saving and deletion) processing time file data conservation point associating and sorting each piece of file data encrypted and divided by the update (saving and deletion) processing time file data encryption / division means and uploaded to the first temporary storage area by the update (saving and deletion) processing time uploading means, by associating the file data with one of the conservation points corresponding to at least two planets for managing the file data; and an update (saving and deletion) processing time conservation point information management means for managing, in a black box environment, information on the conservation points for managing the file data sorted by the update (saving and deletion) processing time file data conservation point associating and sorting means; The file data update (saving and deletion) processing time file data protection point associating and sorting means is provided in each planet and is sorted based on agreement information between the first user and the second user (or a first parameter included in the agreement information and a second parameter designated by the digital asset guard service administrator) regarding the saving process of the data to be saved for the customer, which is acquired by the data update (saving and deletion) processing agreement information acquisition means, and each file data associated with the information of the protection point managed in a black box environment by the update (saving and deletion) processing time protection point information management means. The data is set by the digital asset guard service administrator in accordance with conditions designated by the customer, and the data is sorted by a file data preservation point associating means for update (saving and deleting) processing at distributed file management groups, the file data being configured by nodes at each base constituting the planet corresponding to the preservation point and recording devices at multiple bases connected to the nodes at each base via a network, and the file data is sorted by a file data preservation point associating means for update (saving and deleting) processing at distributed file management groups, the file data being sorted by the ...a distributed recording means for update (backup and deletion) processing that has a function of distributing and recording each of the file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means for update (backup and deletion) processing in the nodes of each base belonging to the corresponding distributed file management group and in recording devices of multiple bases connected to the nodes of the base via a network; and a system setting means for update (backup and deletion) processing that has a function of creating system setting information including terminal information (information specifying the other party such as a fixed IP address) for uploading to the first temporary storage area using the upload means for update (backup and deletion) processing, the number of a predetermined processing means that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and information on a group of file servers (in the node of a predetermined base and in recording devices of multiple bases connected to the node of the base via a network) that constitute the distributed file management group, encrypting the information, and recording it in a group of nodes of a specific base in the distributed ledger structure. a smart contract (or server application) for creating server index information during update (saving and deletion) processing, the smart contract (or server application) having a function for creating server index information including: key information using the first user ID information and the second user ID information required for data evacuation, which are included in the agreement information between the first user and the second user regarding the evacuation processing of the data to be evacuated for the customer acquired by the data update (saving and deletion) processing agreement information acquisition means; file name information of each of the file data linked to the information of the conservation point sorted by the file data conservation point association sorting means during update (saving and deletion) processing and managed in a black box environment by the conservation point information management means during update (saving and deletion) processing; and configuration information of each of the distributed file management groups to which each of the file data is allocated;a smart contract (or server application) for recording server index information during update (saving and deletion) processing, which has a function of encrypting and recording server index information created by the smart contract (or server application) for creating server index information during update (saving and deletion) processing in a group of nodes at a specific location in the distributed ledger structure; a smart contract (or program with a wallet function) for creating customer setting information during update (saving and deletion) processing, which has a function of creating customer setting information including agreement information between the first user and the second user regarding the evacuation processing of the data to be evacuated for the customer, which is acquired by the data update (saving and deletion) processing agreement information acquisition means linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means during update (saving and deletion) processing; and a smart contract (or a program with a wallet function) for creating customer index information during update (saving and deletion) processing, which has a function of creating customer index information having information on a file name and an upload date; a smart contract (or a server application) for recording customer index information during update (saving and deletion) processing, which has a function of encrypting the customer index information created by the smart contract (or the program with a wallet function) for creating customer index information during update (saving and deletion) processing and recording it in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means (or server application) for updating (saving and deletion) processing, which erases each file data uploaded to the first temporary storage area after the server index information has been encrypted and recorded in the group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information during update (saving and deletion) processing; a means for accepting a deletion instruction for data to be deleted from the update (saving and deletion) instruction means during the update (saving and deletion) processing; and a means for accepting a deletion instruction for data to be deleted from the customer from the update (saving and deletion) instruction means, the means being provided on each planet;In the planet corresponding to the security point, for each group of file data linked to the information of each of the security points managed in a black box environment by the security point information management means at the time of update (saving and deletion) processing, key information (or the first parameter included in the key information or a first composite parameter (composed of a pair of a first decryption parameter designated and managed offline by the customer and a first encryption parameter automatically generated from the first decryption parameter) using the first user ID information and the second user ID information required for data deletion in the agreement information between the first user and the second user regarding the deletion process of the data to be deleted of the customer acquired by the data update (saving and deletion) processing agreement information acquisition means, which is linked to the file data to be deleted accepted by the customer data deletion instruction acceptance means at the time of update (saving and deletion) processing, and a smart contract (or server application) for extracting encrypted server index information to be deleted during update (backup and deletion) processing, which has a function of extracting encrypted server index information (recorded in a node group at a specific location in the distributed ledger structure by the server index information recording smart contract (or server application)) based on a second composite parameter (composed of a pair of second decryption parameters (embedded and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) and a second encryption parameter (embedded and modularized in a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameters; and a smart contract (or server application) for extracting encrypted server index information to be deleted during update (backup and deletion) processing, which is provided in each planet and, in the planet corresponding to the conservation point, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means during update (backup and deletion) processing,a smart contract (or server application) for decrypting server index information to be deleted during update (saving and deletion) processing, which has a function of decrypting the encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information to be deleted during update (saving and deletion) processing; and a smart contract (or server application) for decrypting server index information to be deleted during update (saving and deletion) processing, which is provided in each planet and manages, in the planet corresponding to the maintenance point, for each group of file data associated with the information of each of the maintenance points managed in a black box environment by the maintenance point information management means during update (saving and deletion) processing. and a smart contract (or server application) for deleting encrypted and divided file data during update (saving and deletion) processing, which has a function of deleting each of the encrypted and divided file data to be deleted from each of the base nodes belonging to each of the distributed file management groups and from all of the base node recording devices connected to the base node via a network, the file data being allocated to each of the distributed file management groups by the distributed file management group allocation means and distributedly recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in all of the base node recording devices connected to the base node via a network, using server index information decrypted by the distributed file management group allocation means (or server application), The data update (saving and deletion) processing agreement information acquisition means includes a data update (saving and deletion) processing request instruction means that instructs, via the first user, a request for processing to update (saving and deletion) data that is to be updated (saving and deletion) for the customer, a data update (saving and deletion) processing request instruction acceptance means that accepts, from the data update (saving and deletion) processing request instruction means, an instruction to request processing to update (saving and deletion) data that is to be updated (saving and deletion) for the customer, and when the data update (saving and deletion) processing request instruction acceptance means accepts an instruction to request processing to update (saving and deletion) data that is to be updated (saving and deletion) for the customer,a first user ID information receiving means for data update (saving and deletion) that receives the first user ID information necessary for updating (saving and deleting) data from the first user information management means; and when the first user ID information receiving means for data update (saving and deletion) receives the first user ID information necessary for updating (saving and deleting) data, information that the first user has issued a request instruction for updating (saving and deleting) data of the customer to be updated (saving and deleted) and information that the first user has issued a request instruction for updating (saving and deleting) data of the customer to be updated (saving and delete) are received. a seventh information notification means for notifying the second user of information urging the second user to issue an approval instruction for the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer, via the second user who has received the notification from the seventh information notification means; a data update (saving and deletion) processing approval instruction means for receiving an approval instruction for the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer from the data update (saving and deletion) processing approval instruction means. a data update (saving and deletion) second user ID information receiving means for receiving the second user ID information required for updating (saving and deleting) data from the second user information management means when the data update (saving and deletion) processing approval instruction receiving means receives an approval instruction for updating (saving and deleting) data of the customer; and a data update (saving and deletion) second user ID information receiving means for receiving the second user ID information required for updating (saving and deleting) data when the data update (saving and deletion) processing approval instruction receiving means receives the second user ID information required for updating (saving and deleting) data from the second user information management means. an eighth information notification means for notifying the first user of information that the second user has given an approval instruction for the update (saving and deletion) processing of the data to be updated (saving and deletion) by the customer and information urging the first user to give an instruction to request the update (saving and deletion) processing of the data to be updated (saving and deletion) by the customer, when the eighth information notification means is received; and a data update (saving and deletion) processing request instruction means for instructing the first user, who has received the notification from the eighth information notification means, to request the update (saving and deletion) processing of the data to be updated (saving and deletion) by the customer.a data update (saving and deletion) processing request instruction receiving means for receiving a request instruction for updating (saving and deleting) data to be updated (saving and deleted) by the customer from the data update (saving and deletion) processing request instruction receiving means; and a data update (saving and deletion) first user ID information receiving means for receiving information required for updating (saving and deleting) data, which is received when the data update (saving and deletion) processing request instruction receiving means receives a request instruction for updating (saving and deleting) data to be updated (saving and deleted) by the customer. It is preferable to have a data update (saving and deletion) processing agreement information creation means for creating agreement information between the first user and the second user regarding the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer, using the first user ID information, key information managed by the first user, and the second user ID information required for data update (saving and deletion) and key information managed by the data update (saving and deletion) second user ID information receiving means.

[0123] Furthermore, in the real-time save / restore type digital asset guard service providing system of the third aspect of the present invention, the file data real-time update (saving and deletion) system comprises a user-side file data real-time update (saving and deletion) system that operates on the side of a user (customer or data manager) who desires to update (saving and deleting) file data, and a digital asset guard service operator-side file data real-time update (saving and deletion) system that operates on the side of the digital asset guard service operator, and the user-side file data real-time update (saving and deletion) system comprises the data update (saving and deletion) processing agreement information acquisition means, the customer data update (saving and deletion) instruction means, a program (or smart contract) having a plurality of the encryption and division algorithms, an encryption and division algorithm selection acceptance means at the time of the update (saving and deletion) processing, a customer data save instruction acceptance means at the time of the update (saving and deletion) processing, the file data encryption and division means at the time of the update (saving and deletion) processing, and an upload at the time of the update (saving and deletion) processing. means, the file data preservation point correspondence sorting means at the time of update (saving and deletion) processing, and the preservation point information management means at the time of update (saving and deletion) processing, and the digital asset guard service operator side file data real-time update (saving and deletion) system comprises the distributed file management group allocation means at the time of update (saving and deletion) processing, the distributed recording means at the time of update (saving and deletion) processing, a smart contract (or server application) for creating server index information at the time of update (saving and deletion) processing, a smart contract (or server application) for recording server index information at the time of update (saving and deletion) processing, a first data erasure means at the time of update (saving and deletion) processing, a customer data deletion instruction receiving means at the time of update (saving and deletion) processing, a smart contract (or server application) for extracting encrypted server index information to be deleted at the time of update (saving and deletion) processing, and a smart contract (or server application) for decrypting server index information to be deleted at the time of update (saving and deletion) processing,and a smart contract (or server application) for deleting encrypted and divided file data during the update (saving and deletion) process.

[0124] Furthermore, a real-time save / restore type digital asset guard service providing system according to a third aspect of the present invention has a second file data real-time deletion system, the second file data real-time deletion system comprising: a data deletion processing agreement information acquisition means for acquiring agreement information between the first user and the second user regarding the deletion processing of data to be deleted for the customer; a customer data deletion instruction means for issuing an instruction to delete the data to be deleted for the customer based on the agreement information when the agreement information between the first user and the second user regarding the deletion processing of data to be deleted for the customer is acquired by the data deletion processing agreement information acquisition means; a customer data deletion instruction receiving means for receiving an instruction to delete the data to be deleted for the customer from the customer data deletion instruction means; and a file data preservation point information deletion means for deleting information of the preservation points associated with the file data to be deleted accepted by the customer data deletion instruction accepting means, which is managed in a black box environment by the preservation point information management means. the data deletion processing agreement information acquisition means comprises: data deletion processing request instruction means for issuing an instruction to request deletion processing of the data to be deleted of the customer via the first user; data deletion processing request instruction acceptance means for accepting an instruction to request deletion processing of the data to be deleted of the customer from the data deletion processing request instruction means; first user ID information for data deletion receiving means for receiving the first user ID information necessary for data deletion from the first user information management means when the data deletion processing request instruction acceptance means accepts an instruction to request deletion processing of the data to be deleted of the customer; fifth information notification means for notifying the second user, when the first user ID information for data deletion receiving means receives the first user ID information necessary for data deletion, of information that the first user has issued a request instruction to request deletion processing of the data to be deleted of the customer and information prompting the second user to issue an instruction to approve the deletion processing of the data to be deleted of the customer; and data deletion processing approval instruction means for issuing an instruction to approve the deletion processing of the data to be deleted of the customer via the second user who has received the notification from the fifth information notification means.a data deletion processing approval instruction receiving means for receiving an instruction to approve the deletion processing of the data to be deleted of the customer from the data deletion processing approval instruction means; a data deletion second user ID information receiving means for receiving the second user ID information necessary for data deletion from the second user information management means when the data deletion processing approval instruction receiving means receives an instruction to approve the deletion processing of the data to be deleted of the customer; a sixth information notifying means for notifying the first user, when the data deletion second user ID information receiving means receives the second user ID information necessary for data deletion, of information that the second user has issued an instruction to approve the deletion processing of the data to be deleted of the customer and information that urges the first user to issue a request instruction for the deletion processing of the data to be deleted of the customer via the first user who has received the notification from the sixth information notifying means; It is preferable to have a data deletion processing request instructing means for instructing a request for deletion processing of the target data, a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of the target data for deletion of the customer from the data deletion processing request instructing means, and a data deletion processing agreement information creating means for creating agreement information between the first user and the second user regarding the deletion processing of the target data for deletion of the customer, using the first user ID information required for data deletion and key information managed by the first user, which are received by the first user ID information for data deletion receiving means, and the second user ID information required for data deletion and key information managed by the second user, which are received by the second user ID information for data deletion receiving means.

[0125] In addition, in the third aspect of the real-tim...

Claims

1. A real-time evacuation and restoration type digital asset guard service provision system for protecting digital assets from high-level cyber attacks, constructed with a distributed ledger in distributed ledger technology such as blockchain, and a smart contract or server application for performing predetermined processing using the data managed in the distributed ledger; or a system for handling data that is difficult to manage through systems, such as personal information, primarily on-chain in two configurations: one in which the information is managed by a company, and one in which the information is managed by an individual, and which serves as a base system for managing the personal information directly on-chain in both configurations, or for separating the personal information section based on the information and using it as personal attribute information for big data analysis, etc. at least one distributed ledger structure constructed having a plurality of planets (a unit that combines blockchain and distributed file management functions, etc., and that constitutes one unit that constitutes a system for providing services that implement distributed smart contracts, server applications, etc.) that are made up of a group of nodes that combine nodes at multiple locations in different regions around the world, and that is mainly a closed blockchain such as a private or consortium type, and that is made up of a plurality of chains that may include distributed ledgers, public blockchains, etc.; first authenticator information management means that manages first authenticator authentication information required to authenticate a first authenticator that is one of the data managers that manages customers and customer data, first authenticator ID information and key information required for data evacuation, restoration, etc.; second authenticator information management means that manages second authenticator authentication information required to authenticate a second authenticator that is the other of the data managers that manages customers and customer data, second authenticator ID information and key information required for data evacuation, restoration, etc.; an external first authenticator authentication system that authenticates the first authenticator; a file data real-time backup system; and a file data real-time restoration system, wherein nodes at each location are connected via a network to recording devices at multiple locations in different regions around the world to form a distributed file management group;The file data real-time saving system includes: a data saving process agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the saving process of the data to be saved for the customer, between the first authenticator and the second authenticator; a customer data saving instruction means for, when agreement information between the first authenticator and the second authenticator regarding the saving process of the data to be saved for the customer is acquired by the data saving process agreement information acquisition means, issuing an instruction to save the data to be saved for the customer based on the agreement information; a program (or smart contract) having a plurality of encryption / division algorithms for encrypting and dividing file data differently; and an encryption / division algorithm selection acceptance means for accepting a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on the agreement information between the first authenticator and the second authenticator regarding the saving process of the data to be saved for the customer acquired by the data saving process agreement information acquisition means (or a first parameter included in the agreement information and specified by the customer who desires to save file data). a customer data evacuation instruction receiving means for receiving an instruction to save data to be saved for the customer from the customer data evacuation instruction means; a file data encryption / division means for encrypting and dividing the customer data to be saved received by the customer data evacuation instruction receiving means into a plurality of file data using a program (or smart contract) having the encryption / division algorithm received by the encryption / division algorithm selection receiving means; an upload means for uploading each of the file data encrypted and divided into a plurality of pieces by the file data encryption / division means to a first temporary storage area; and a file data security point associating and sorting each of the file data encrypted and divided into a plurality of pieces by the file data encryption / division means and uploaded to the first temporary storage area by the upload means, in association with one of at least two security points for managing the file data.a storage point information management means for managing, in a black box environment, information on the storage points for managing the file data sorted by the file data storage point association sorting means; and a distributed file management group allocation means or a smart contract (or server application) for distributed file management group allocation, which is provided in each planet and has a function of allocating, based on agreement information between the first authenticator and the second authenticator (or the first parameter included in the agreement information and a second parameter specified by the digital asset guard service administrator) regarding the evacuation process of the data to be evacuated for the customer, each of the file data associated with the information on the storage points sorted by the file data storage point association sorting means and managed in a black box environment by the storage point information management means, to a plurality of distributed file management groups, which are configured by the digital asset guard service administrator according to conditions specified by the customer and are composed of nodes at each base constituting the planet corresponding to the storage points and recording devices at multiple bases connected to the nodes at each base via a network; a distributed recording means or a smart contract for distributed recording (or a server application) that is provided on each planet and has a function of distributing and recording each of the file data associated with the information of each of the conservation points that has been sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means, which has been sorted by the distributed file management group sorting means or the smart contract for distributed file management group sorting (or a server application), in each of the base nodes belonging to the corresponding distributed file management group and in recording devices at multiple bases that are connected to the base nodes via a network;a smart contract (or server application) for creating and recording system setting information that has the function of creating system setting information including terminal information (information identifying the other party, such as a fixed IP address) for uploading to the first temporary storage area using the upload means, the number of a predetermined processing means or smart contract (or server application) that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and information on the file server groups (in the node at a predetermined base and in recording devices at multiple bases that are networked to the node at that base) that make up the distributed file management group, encrypting the information, and recording it in the node group at a specific base in the distributed ledger structure; a server index information creating smart contract (or server application) having a function to create server index information including: key information using the first authenticator ID information and the second authenticator ID information required for data evacuation, which are included in the agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer acquired by the data evacuation processing agreement information acquisition means; file name information of each of the file data that is distributedly recorded by each of the distributed recording means or the distributed recording smart contract (or server application) and is linked to the information of the conservation point that is sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means; and configuration information of each of the distributed file management groups to which each of the file data is allocated; and a server index information recording smart contract (or server application) having a function to encrypt the server index information created by the server index information creating smart contract (or server application) and record it in a node group at a specific location in the distributed ledger structure;a smart contract (or a program with a wallet function) for creating customer setting information that is linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means and that has a function of creating customer setting information that includes agreement information between the first authenticator and the second authenticator (or setting information of the first parameter included in the agreement information) regarding the evacuation process of the data to be evacuated for the customer acquired by the data evacuation process agreement information acquisition means; a smart contract (or a program with a wallet function) for creating customer index information that includes information on the original file name and upload date of the customer's file data to be evacuated; and a smart contract (or a server application) for recording customer index information that has a function of encrypting the customer index information created by the smart contract (or program with a wallet function) and recording it in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means for erasing each file data uploaded to the first temporary storage area after the server index information has been encrypted and recorded in a node group at a specific location in the distributed ledger structure by the server index information recording smart contract (or server application), wherein the data evacuation processing agreement information acquisition means comprises: a data evacuation processing request instruction means for issuing an instruction to request evacuation processing of the data to be evacuated of the customer via the first authenticator; a data evacuation processing request instruction acceptance means for accepting an instruction to request evacuation processing of the data to be evacuated of the customer from the data evacuation processing request instruction means; and a first authenticator authentication requesting means at the time of data evacuation processing request instruction acceptance means for acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information management means, when the data evacuation processing request instruction acceptance means accepts an instruction to request evacuation processing of the data to be evacuated of the customer, and providing the information to an external first authenticator authentication system to request authentication of the first authenticator.a first authenticator ID information and key information receiving means for data evacuation, which receives the first authenticator ID information and key information required for data evacuation from the first authenticator information management means when the first authenticator is authenticated by the external first authenticator authentication system; a first information notifying means, when the first authenticator ID information and key information receiving means for data evacuation has received the first authenticator ID information and key information required for data evacuation, notifying the second authenticator of information that the first authenticator has issued a request instruction for evacuation processing of the data to be evacuated for the customer and information urging the second authenticator to issue an instruction to approve the evacuation processing of the data to be evacuated for the customer; a data evacuation processing approval instruction receiving means, which issues an instruction to approve the evacuation processing of the data to be evacuated for the customer via the second authenticator who has received the notification from the first information notifying means; and a data evacuation processing approval instruction receiving means which receives an instruction to approve the evacuation processing of the data to be evacuated for the customer from the data evacuation processing approval instruction means. a data saving processing approval instruction receiving second authenticator authentication requesting means for, when the data saving processing approval instruction receiving means receives an instruction to approve the saving processing of the data to be saved for the client, acquiring second authenticator authentication information required to authenticate the second authenticator from the second authenticator information managing means, providing the second authenticator authentication information to an external second authenticator authentication system, and requesting authentication of the second authenticator; a data saving second authenticator ID information and key information receiving means for, when the second authenticator is authenticated by the external second authenticator authentication system, receiving the second authenticator ID information and key information required for saving data from the second authenticator information managing means; a second information notification means for notifying the first authenticator of information that the second authenticator has instructed approval for the evacuation process of the data to be saved by the customer and information urging the first authenticator to instruct a request for the evacuation process of the data to be saved by the customer, when the second authenticator ID information and key information receiving means for data evacuation has received the second authenticator ID information and key information necessary for data evacuation; and a data evacuation process request instruction means for instructing the first authenticator, who has received the notification from the second information notification means, to request the evacuation process of the data to be saved by the customer.data evacuation processing request instruction receiving means for receiving a request instruction for evacuation processing of data to be saved for the client from said data evacuation processing request instruction means; and data evacuation processing agreement information creating means for, when said data evacuation processing request instruction receiving means receives a request instruction for evacuation processing of data to be saved for the client, creating agreement information between the first authenticator and the second authenticator regarding the evacuation processing of data to be saved for the client, using the first authenticator ID information and key information required for data evacuation received by said first authenticator ID information and key information receiving means for data evacuation and the second authenticator ID information and key information required for data evacuation received by said second authenticator ID information and key information receiving means for data evacuation; and said file data real-time restoration system comprises: data restoration processing agreement information acquiring means for acquiring agreement information between the first authenticator and the second authenticator regarding the restoration processing of data to be restored for the client, between said first authenticator and the second authenticator; a customer data restoration instruction means for instructing the restoration of the data to be restored for the customer based on the agreement information when the data restoration processing agreement information acquisition means acquires agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer; a program (or smart contract) having a plurality of decryption and combination algorithms with different file data decryption and combination processing methods, linked to programs (or smart contracts) each having the encryption and division algorithm; and a customer data restoration instruction acceptance means for accepting an instruction to restore the data to be restored for the customer from the customer data restoration instruction means.a data restoration instruction receiving means for receiving the data restoration instruction from the data restoration instruction receiving means for receiving the data restoration instruction for the data restoration target of the customer, ... a smart contract (or server application) for extracting encrypted server index information that has a function of extracting encrypted server index information (recorded in a group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on a meter or (a second composite parameter that is a pair of a second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) designated by the digital asset guard service operator and managed offline, and a second encryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter);a server index information decryption smart contract (or server application) that is provided in each planet and has a function of decrypting the encrypted server index information extracted by the encrypted server index information extraction smart contract (or server application) for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point; an encrypted and divided file data extraction means or a smart contract (or server application) for extracting encrypted and divided file data, which is provided in each planet and has a function of extracting, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point, from any of the nodes at each base belonging to each of the distributed file management groups and any of the recording devices at each of the multiple bases connected to the nodes at each of the multiple bases via a network, each of the encrypted and divided file data being allocated to each of the distributed file management groups by the distributed file management group allocation means or the smart contract (or server application) for allocating the file data using server index information decrypted by the smart contract (or server application) for decrypting server index information, and distributed and recorded in each of the nodes at each of the multiple bases belonging to each of the distributed file management groups and any of the recording devices at each of the multiple bases connected to the nodes at each of the multiple bases via a network;a downloading means provided in each planet, which downloads, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point, each of the encrypted and divided file data extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data, into a second temporary storage area; file data restoration means provided in each planet, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point, for decrypting and combining all of the file data linked across the information of all of the conservation points in an encrypted and divided state that has been extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data and downloaded to the second temporary storage area by the download means, into one file data by using a program (or smart contract) having the decryption and combination algorithm that is linked to a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means, to restore the client's data before it was saved; and second data erasure means that erases each of the file data in an encrypted and divided state that has been downloaded to the second temporary storage area after being restored to the client's data before it was saved by the file data restoration means, a data restoration processing request instruction means for instructing a request for restoration processing of the data to be restored of the customer via the first authenticator; and a data restoration processing request instruction receiving means for receiving a request instruction for restoration processing of the data to be restored of the customer from the data restoration processing request instruction means.a first authenticator authentication requesting means for requesting authentication of the first authenticator from the first authenticator information managing means when the data restoration processing request instruction receiving means receives a request instruction for restoration of data to be restored for the customer, and providing the first authenticator authentication information required to authenticate the first authenticator to an external first authenticator authentication system to request authentication of the first authenticator; a first authenticator ID information and key information receiving means for data restoration, for receiving the first authenticator ID information and key information required for data restoration from the first authenticator information managing means when the first authenticator ID information and key information receiving means for data restoration receives the first authenticator ID information and key information required for data restoration; and a third information notifying means for notifying the second authenticator of information that the first authenticator has issued a request instruction for restoration of the data to be restored for the customer and information urging the second authenticator to give an approval instruction for the restoration of the data to be restored for the customer, when the first authenticator ID information and key information receiving means for data restoration has received the first authenticator ID information and key information required for data restoration. a data restoration processing approval instruction means for instructing approval of the restoration processing of the data to be restored for the customer via the second authenticator notified by the third information notification means; a data restoration processing approval instruction receiving means for receiving an instruction to approve the restoration processing of the data to be restored for the customer from the data restoration processing approval instruction means; a second authenticator authentication requesting means at the time of receiving a data restoration processing approval instruction for, when the data restoration processing approval instruction receiving means receives an instruction to approve the restoration processing of the data to be restored for the customer, acquiring second authenticator authentication information required for authenticating the second authenticator from the second authenticator information management means, providing the information to an external second authenticator authentication system, and requesting authentication of the second authenticator; a second authenticator ID information and key information receiving means for data restoration for, when the second authenticator is authenticated by the external second authenticator authentication system, receiving the second authenticator ID information and key information required for data restoration from the second authenticator information management means.a fourth information notifying means for notifying the first authenticator of information that the second authenticator has instructed to approve the restoration of the data to be restored by the second authenticator and information urging the first authenticator to instruct a request for the restoration of the data to be restored by the second authenticator when the data restoration second authenticator ID information and key information receiving means receives the second authenticator ID information and key information necessary for data restoration; a data restoration processing request instructing means for instructing the first authenticator to request the restoration of the data to be restored by the first authenticator who has received the notification from the fourth information notifying means; and a data restoration processing request instruction receiving means for receiving an instruction to request the restoration of the data to be restored by the data restoration processing request instructing means. and a data restoration processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the restoration processing of the data to be restored for the customer, using the first authenticator ID information and key information required for data restoration received by the first authenticator ID information and key information receiving means for data restoration and the second authenticator ID information and key information required for data restoration received by the second authenticator ID information and key information receiving means for data restoration, when the data restoration processing request instruction receiving means receives an instruction to request restoration processing of the data to be restored for the customer.

2. A file data real-time deletion system, comprising: a data deletion processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the deletion processing of data to be deleted for the customer; a customer data deletion instruction means for issuing an instruction to delete the data to be deleted for the customer based on the agreement information when the data deletion processing agreement information acquisition means acquires agreement information between the first authenticator and the second authenticator regarding the deletion processing of data to be deleted for the customer; and a customer data deletion instruction receiving means for receiving an instruction to delete the data to be deleted for the customer from the customer data deletion instruction means.a data deletion processing agreement information acquisition means for acquiring data for the data to be deleted for the customer, the ... a smart contract (or server application) for extracting encrypted server index information to be deleted, which has a function of extracting encrypted server index information (recorded in a group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on the data or (a second composite parameter consisting of a pair of a second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) designated by the digital asset guard service operator and managed offline, and a second encryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter);a smart contract (or server application) for decrypting server index information to be deleted, which is provided in each planet and has a function of decrypting the encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information to be deleted, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means in the planet corresponding to the conservation point; and a smart contract (or server application) for deleting encrypted and divided file data that is provided in each planet and has a function of deleting, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means in the planet corresponding to the conservation point, from each of the base nodes belonging to each of the distributed file management groups and from all of the base storage devices connected to the base nodes via a network, the encrypted and divided file data that is allocated to each of the distributed file management groups by the distributed file management group allocation means using server index information decrypted by the smart contract (or server application) for decrypting server index information to be deleted, and that is distributed and recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in storage devices of multiple bases connected to the base nodes via a network, the encrypted and divided file data that is to be deleted is a data deletion processing request instruction receiving means for receiving a request instruction for deletion processing of the data to be deleted from the data deletion processing request instruction means;a first authenticator authentication requesting means for receiving a data deletion request instruction, when the data deletion request instruction receiving means receives a request instruction for deletion of data to be deleted for the customer, acquiring first authenticator authentication information necessary for authenticating the first authenticator from the first authenticator information managing means, providing the information to an external first authenticator authentication system, and requesting authentication of the first authenticator; a first authenticator ID information and key information receiving means for data deletion, receiving the first authenticator ID information and key information necessary for data deletion from the first authenticator information managing means when the first authenticator ID information and key information receiving means for data deletion receives the first authenticator ID information and key information necessary for data deletion, fifth information notifying means for notifying the second authenticator of information that the first authenticator has issued a request instruction for deletion of data to be deleted for the customer and information urging the second authenticator to give an approval instruction for deletion of the data to be deleted for the customer, a data deletion processing approval instruction means for instructing approval of the deletion processing of the data to be deleted for the client via the second authenticator notified by the fifth information notification means; a data deletion processing approval instruction receiving means for receiving an instruction to approve the deletion processing of the data to be deleted for the client from the data deletion processing approval instruction means; a data deletion processing approval instruction reception second authenticator authentication request means for, when the data deletion processing approval instruction receiving means receives an instruction to approve the deletion processing of the data to be deleted for the client, acquiring second authenticator authentication information required for authenticating the second authenticator from the second authenticator information management means, providing the information to an external second authenticator authentication system, and requesting authentication of the second authenticator; a data deletion second authenticator ID information and key information receiving means for receiving the second authenticator ID information and key information required for data deletion from the second authenticator information management means when the second authenticator is authenticated by the external second authenticator authentication system.a sixth information notifying means for, when the data deletion second authenticator ID information and key information receiving means receives the second authenticator ID information and key information necessary for deleting data, notifying the first authenticator of information that the second authenticator has issued an instruction to approve the deletion process of the data to be deleted for the customer and information urging the first authenticator to issue an instruction to request the deletion process of the data to be deleted for the customer; a data deletion process request instructing means for issuing an instruction to request the deletion process of the data to be deleted for the customer via the first authenticator who has received the notification from the sixth information notifying means; and a data deletion process request instruction receiving means for receiving an instruction to request the deletion process of the data to be deleted for the customer from the data deletion process request instructing means. and a data deletion processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the deletion processing of the data to be deleted for the customer, using the first authenticator ID information and key information required for data deletion received by the first authenticator ID information and key information receiving means for data deletion and the second authenticator ID information and key information required for data deletion received by the second authenticator ID information and key information receiving means for data deletion, when the data deletion processing request instruction receiving means receives an instruction to request deletion processing of the data to be deleted for the customer.

3. The real-time backup and restoration type digital asset guard service providing system according to claim 2, characterized in that the file data real-time deletion system comprises a user-side file data real-time deletion system operating on the side of the user (customer and data manager) who wishes to delete file data, and a digital asset guard service operator-side file data real-time deletion system operating on the side of the digital asset guard service operator, wherein the user-side file data real-time deletion system has the data deletion processing agreement information acquisition means and the customer data deletion instruction means, and the digital asset guard service operator-side file data real-time deletion system has the customer data deletion instruction acceptance means, a smart contract (or server application) for extracting the encrypted server index information to be deleted, a smart contract (or server application) for decrypting the server index information to be deleted, and a smart contract (or server application) for deleting the encrypted and divided file data.

4. A file data real-time update (saving and deletion) system, comprising: a data update (saving and deletion) processing agreement information acquisition means for acquiring agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer between the first authenticator and the second authenticator; a customer data update (saving and deletion) instruction means for instructing the update (saving and deletion) of the data to be updated (saving and deletion) for the customer based on the agreement information when agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of data to be updated (saving and deletion) for the customer is acquired by the data update (saving and deletion) processing agreement information acquisition means; a program (or smart contract) having a plurality of encryption and division algorithms that use different methods for encrypting and dividing file data; an update (saving and deletion) processing time encryption / division algorithm selection receiving means for receiving a selection of a program (or smart contract) having a predetermined encryption / division algorithm based on agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer acquired by the data update (saving and deletion) processing agreement information acquisition means; an update (saving and deletion) processing time customer data evacuation instruction receiving means for receiving an instruction to evacuate the data to be evacuated for the customer from the customer data update (saving and deletion) instruction means; an update (saving and deletion) processing time file data encryption / division means for encrypting and dividing the customer data to be evacuated, which has been accepted by the update (saving and deletion) processing time customer data evacuation instruction accepting means, into a plurality of file data using a program (or smart contract) having the encryption / division algorithm accepted by the update (saving and deletion) processing time encryption / division algorithm selection accepting means; an update (saving and deleting) processing time uploading means for uploading each of the file data encrypted and divided into a plurality of pieces by the update (saving and deleting) processing time file data encryption / division means to a first temporary storage area;a file data security point associating and sorting means for associating each file data encrypted and divided into a plurality of pieces by the file data encryption and division means for update (saving and deletion) processing and uploaded to the first temporary storage area by the upload means for update (saving and deletion) processing with one of security points corresponding to at least two planets for managing the file data; and a security point information management means for managing, in a black box environment, information on the security points for managing the file data sorted by the file data security point associating and sorting means for update (saving and deletion) processing. a distributed file management group allocation means for update (saving and deletion) processing, which is provided in each planet and has a function of allocating the file data associated with the information of the conservation points managed in a black box environment by the conservation point information management means for update (saving and deletion) processing, which is sorted by the file data conservation point association sorting means based on agreement information between the first authenticator and the second authenticator regarding the backup processing of the data to be backed up for the customer, acquired by the data update (saving and deletion) processing agreement information acquisition means (or a first parameter included in the agreement information and a second parameter specified by the digital asset guard service operator), to a plurality of distributed file management groups, which are set by the digital asset guard service operator according to conditions specified by the customer and are constituted by nodes at each base constituting the planet corresponding to the conservation points and recording devices at multiple bases connected to the nodes at each base via a network;an update (saving and deletion) processing time distributed recording means provided in each planet, which has a function of distributively recording the file data associated with the information of each of the conservation points that has been sorted by the update (saving and deletion) processing time file data conservation point association sorting means and managed in a black box environment by the update (saving and deletion) processing time conservation point information management means, in the nodes of each base belonging to the corresponding distributed file management group and in recording devices of multiple bases connected to the base nodes via a network; a smart contract (or server application) for creating and recording system setting information during update (backup and deletion) processing, which has the function of creating system setting information including terminal information (information identifying the other party, such as a fixed IP address) for uploading to the first temporary storage area using the upload means during update (backup and deletion) processing, the number of the predetermined processing means that performs the corresponding processing of the recording destination of the customer's file data, information on the planet to which the recording destination of the file data belongs, and information on the file server groups (in the node at a predetermined base and in recording devices at multiple bases that are networked to the node at that base) that make up the distributed file management group, encrypting the information, and recording it in the node group at a specific base in the distributed ledger structure; anda smart contract (or server application) for creating server index information during update (saving and deletion) processing, the smart contract having a function of creating server index information including: key information using the first authenticator ID information and the second authenticator ID information required for data evacuation, which are included in agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer, acquired by the data update (saving and deletion) processing agreement information acquisition means; file name information of each of the file data linked to the information of the conservation point, which is sorted by the file data conservation point association sorting means during update (saving and deletion) processing and managed in a black box environment by the conservation point information management means during update (saving and deletion) processing, and configuration information of each of the distributed file management groups to which each of the file data is allocated; and a smart contract (or server application) for recording server index information during update (saving and deletion) processing, which has a function of encrypting and recording the server index information created by the smart contract (or server application) for creating server index information during update (saving and deletion) processing in a group of nodes at a specific location in the distributed ledger structure; a smart contract (or program with a wallet function) for creating customer setting information during update (saving and deletion) processing, which has a function of creating customer setting information including agreement information between the first authenticator and the second authenticator regarding the evacuation processing of the data to be evacuated for the customer, which is acquired by the data update (saving and deletion) processing agreement information acquisition means linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means during update (saving and deletion) processing; a smart contract (or a program with a wallet function) for creating customer index information during update (saving and deletion) processing, which has a function of creating customer index information including information on the original file name and upload date of the customer's file data to be saved during update (saving and deletion) processing;a smart contract (or server application) for recording customer index information during update (saving and deletion) processing, which has a function of encrypting the customer index information created by the smart contract (or program with wallet function) for creating customer index information during update (saving and deletion) processing and recording it in a group of nodes at a specific location in the distributed ledger structure; a first data erasure means during update (saving and deletion) processing, which erases each file data uploaded to the first temporary storage area after the server index information has been encrypted and recorded in the group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information during update (saving and deletion) processing; and a customer data deletion instruction receiving means during update (saving and deletion) processing, which receives an instruction to delete data to be deleted for the customer from the update (saving and deletion) instruction means.and a data update (saving and deletion) processing agreement information acquisition means for acquiring a first composite parameter (or the first parameter included in the key information) which is a combination of the first and second authenticators ID information and the second authenticator ID information required for deleting data, the first composite parameter being a pair of a first decryption parameter designated by the customer and managed offline by the customer data deletion instruction acceptance means for each group of file data linked to the information of each of the security points managed in a black-box environment by the update (saving and deletion) processing time security point information management means in the planet corresponding to the security point. a smart contract (or server application) for extracting encrypted server index information to be deleted during update (backup and deletion) processing, which has a function of extracting encrypted server index information (recorded in a group of nodes at a specific location in the distributed ledger structure by the smart contract (or server application) for recording server index information) based on the second parameter or a second composite parameter (composed of a pair of a second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) designated and managed offline by the digital asset guard service operator), and a second encryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from the second decryption parameter);a smart contract (or server application) for decrypting server index information to be deleted during update (saving and deletion) processing, which is provided in each planet and has a function of decrypting encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information to be deleted during update (saving and deletion) processing, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means during update (saving and deletion) processing in the planet corresponding to the conservation point; a smart contract (or server application) for deleting encrypted and divided file data during update (backup and deletion) processing, which is provided in each planet and has a function of deleting, for each group of file data linked to information of each of the conservation points managed in a black-box environment by the conservation point information management means during update (backup and deletion) processing, from each of the base nodes belonging to each of the distributed file management groups and from all of the base node recording devices connected to the base node via a network, each of the encrypted and divided file data to be deleted, which has been allocated to each of the distributed file management groups by the distributed file management group allocation means using server index information decrypted by the smart contract (or server application) for decrypting server index information to be deleted during update (backup and deletion) processing, and which has been distributed and recorded by each of the distributed recording means in each of the base nodes belonging to each of the distributed file management groups and in recording devices of multiple bases connected to the base node via a network; The data update (saving and deletion) processing agreement information acquisition means includes: a data update (saving and deletion) processing request instruction means for instructing, via the first authenticator, a request for processing to update (saving and deletion) data of the client to be updated (saving and deletion);a data update (saving and deletion) processing request instruction receiving means for receiving a request instruction for updating (saving and deleting) data to be updated (saving and deleting) for the customer from the data update (saving and deletion) processing request instruction receiving means; a data update (saving and deletion) processing request instruction receiving first authenticator authentication requesting means for, when the data update (saving and deletion) processing request instruction receiving means receives a request instruction for updating (saving and deleting) data to be updated (saving and deletion) for the customer, acquiring first authenticator authentication information required for authenticating the first authenticator from the first authenticator information managing means, providing the information to an external first authenticator authentication system, and requesting authentication of the first authenticator; a data update (saving and deletion) first authenticator ID information and key information receiving means for receiving the first authenticator ID information and key information required for updating (saving and deleting) data from the first authenticator information managing means when the first authenticator is authenticated by the external first authenticator authentication system; a seventh information notifying means for, when the data update (saving and deletion) first authenticator ID information and key information receiving means receives the first authenticator ID information and key information necessary for data update (saving and deletion), notifying the second authenticator of information that the first authenticator has issued a request instruction for update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer and information urging the second authenticator to issue an approval instruction for the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer; a data update (saving and deletion) processing approval instruction instructing means for issuing an instruction to approve the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer, via the second authenticator who has received the notification from the seventh information notifying means; and a data update (saving and deletion) processing approval instruction receiving means for receiving an approval instruction for the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer from the data update (saving and deletion) processing approval instruction means.a data update (saving and deletion) processing approval instruction receiving second authenticator authentication requesting means for, when the data update (saving and deletion) processing approval instruction receiving means receives an instruction to approve the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer, acquiring second authenticator authentication information required to authenticate the second authenticator from the second authenticator information managing means, providing the second authenticator information to an external second authenticator authentication system, and requesting authentication of the second authenticator; a data update (saving and deletion) second authenticator ID information and key information receiving means for, when the second authenticator is authenticated by the external second authenticator authentication system, receiving the second authenticator ID information and key information required for updating (saving and deletion) data from the second authenticator information managing means; an eighth information notification means for, when the second authenticator ID information and key information receiving means for data update (saving and deletion) receives the second authenticator ID information and key information necessary for data update (saving and deletion), notifying the first authenticator of information that the second authenticator has issued an approval instruction for the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer and information urging the first authenticator to issue a request instruction for the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer; a data update (saving and deletion) processing request instruction receiving means for receiving an instruction to request the update (saving and deletion) processing of the data to be updated (saving and deletion) of the customer from the data update (saving and deletion) processing request instruction means;and a data update (saving and deletion) processing agreement information creating means for creating agreement information between the first authenticator and the second authenticator regarding the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer, using the first authenticator ID information and key information required for the data update (saving and deletion) received by the first authenticator ID information and key information receiving means for data update (saving and deletion) and the second authenticator ID information and key information required for the data update (saving and deletion) received by the second authenticator ID information and key information receiving means for data update (saving and deletion), when the data update (saving and deletion) processing request instruction receiving means receives an instruction to request the update (saving and deletion) processing of the data to be updated (saving and deletion) for the customer.

5. The distributed file management group sorting means or the distributed file management group sorting smart contract (or server application) further has a function of converting the file format and name of each of the file data encrypted and divided into multiple pieces by the file data encryption and division means and uploaded to the first temporary storage area by the uploading means into a predetermined file format and name before sorting, to the multiple distributed file management groups, each of the file data associated with the information of the conservation points sorted by the file data conservation point association sorting means and managed in a black-box environment by the conservation point information management means; and the encrypted and divided file data extraction means or the encrypted and divided file data extraction smart contract (or server application) further has a function of converting the file format and name of each of the extracted file data into the original file format and name after extracting each of the encrypted and divided file data for each group of the file data associated with the information of the conservation points managed in a black-box environment by the conservation point information management means.

2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.

6. The agreement information between the first authenticator and the second authenticator (or the first parameter included in the agreement information) regarding the evacuation process of the customer's data acquired by the data evacuation process agreement information acquisition means has a file division code and a file storage code, and the encryption / division algorithm selection acceptance means accepts the selection of a program (or smart contract) having a predetermined encryption / division algorithm based on the file division code, The distributed file management group allocation means or the distributed file management group allocation smart contract (or server application) has a function of converting the file format and name of each of the file data linked to the information of the conservation point that has been encrypted and divided by the file data encryption and division means, uploaded to the first temporary storage area by the upload means, sorted by the file data conservation point association sorting means, and managed in a black box environment by the conservation point information management means, into a predetermined file format and name based on the file storage code (or the file storage code and the second parameter), while encrypting the file data, and allocating it to a plurality of distributed file management groups that are set by the digital asset guard service operator according to conditions specified by the customer and are configured by nodes at multiple locations that constitute the planet corresponding to the conservation point, and recording devices at multiple locations that are connected to the nodes at the locations via a network; Each of the distributed recording means or the distributed recording smart contract (or server application) has a function of distributively recording each of the file data associated with the information of each of the conservation points sorted by the file data conservation point association sorting means and managed in a black box environment by the conservation point information management means, which has been sorted by the distributed file management group sorting means or the distributed file management group sorting smart contract (or server application), in each of the base nodes belonging to the corresponding distributed file management group and in recording devices at multiple bases connected to the base nodes via a network,the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data has a function of extracting, for each group of file data linked to information on each of the conservation points managed in a black-box environment by the conservation point information management means, each of the encrypted and divided file data being allocated to each of the distributed file management groups by the distributed file management group allocation means or the smart contract (or server application) for distributed file management group allocation, and distributedly recorded in each of the base nodes belonging to each of the distributed file management groups and in recording devices at multiple bases connected to the base nodes via a network by each of the distributed recording means or the smart contract (or server application), from each of the base nodes belonging to each of the distributed file management groups and from any of the recording devices at multiple bases connected to the base nodes via a network, based on the file storage code (or the file storage code and the second parameter), and decrypting the extracted file data, and at the same time converting the file format and name of the file data to the original file format and name; The file data restoration means has a function of decrypting and combining all of the file data associated with the information of all of the conservation points in an encrypted and divided state that has been extracted by the encrypted and divided file data extraction means or the smart contract (or server application) for extracting encrypted and divided file data and downloaded to the second temporary storage area by the download means, for each group of the file data associated with the information of each of the conservation points managed in a black-box environment by the conservation point information management means, into one file data to restore the file data before saving, based on the file division code, using a program (or smart contract) having the decryption and combination algorithm that is associated with a program (or smart contract) having the encryption and division algorithm accepted by the encryption and division algorithm selection acceptance means.

2. The real-time saving and restoring type digital asset guard service providing system according to claim 1.

7. The file data encryption / division means divides the customer data to be evacuated, which has been accepted by the customer data evacuation instruction acceptance means, into multiple pieces using a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means, and encrypts each of the multiple pieces of file data based on a first public key (first encryption key) created by each of the customer and the data manager; 2. The real-time backup and restoration type digital asset guard service providing system according to claim 1, wherein the file data restoration means decrypts, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means, all of the file data linked across the information of all of the conservation points in an encrypted and divided state that has been extracted by the encrypted / divided file data extraction means or the smart contract (or server application) for extracting encrypted / divided file data and downloaded to the second temporary storage area by the download means, based on a first private key (first offline decryption key) created by each of the customer and the data administrator, and combines all of the file data linked across the decrypted information of all of the conservation points into one file data using a program (or smart contract) having the decryption / combination algorithm that is linked to a program (or smart contract) having the encryption / division algorithm accepted by the encryption / division algorithm selection acceptance means.

8. The server index information recording smart contract (or server application) has a function of encrypting the server index information created by the server index information creating smart contract (or server application) based on a second encryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) that is automatically generated from a second public key (second encryption key) created by the digital asset guard service operator or a second decryption parameter (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing) designated by the digital asset guard service operator and managed offline; The real-time backup and restoration type digital asset guard service providing system described in claim 1, characterized in that the smart contract (or server application) for decrypting server index information has the function of decrypting the encrypted server index information extracted by the smart contract (or server application) for extracting encrypted server index information for each group of file data linked to the information of each of the conservation points managed in a black box environment by the conservation point information management means, based on a second private key (second decryption key) created by the digital asset guard service operator or a second decryption parameter specified by the digital asset guard service operator and managed offline (modularized and incorporated into a predetermined processing means or smart contract (or server application) that performs the relevant processing).

9. The real-time backup and restoration type digital asset guard service providing system of claim 1, characterized in that the program (or smart contract) equipped with the encryption and division algorithm is configured to encrypt and divide file data into multiple pieces using secret sharing technology based on polynomial fragmentation processing, and the program (or smart contract) equipped with the decryption and combination algorithm is configured to decrypt the encrypted and divided file data using secret sharing technology based on polynomial fragmentation processing and restore the original file data in a combined state.

10. The file data real-time backup system further comprises a planet configuration pattern setting means for selecting the number of nodes constituting the planet and the distributed file management groups (constructed by the nodes at each base and the recording devices at multiple bases connected to the nodes at each base via a network) based on the recording capacity (file size) of file data specified by the customer and the number of file data divisions based on the degree of distribution; the distributed file management group allocation means or the distributed file management group allocation smart contract (or server application) has the function of allocating each of the file data sorted by the file data conservation point association sorting means and linked to the information of the conservation point managed in a black box environment by the conservation point information management means to multiple distributed file management groups that are set by the digital asset guard service operator manager via the planet configuration pattern setting means according to conditions specified by the customer, and are constructed by the nodes at each base constituting the planet corresponding to the conservation point and the recording devices at multiple bases connected to the nodes at each base via a network; The real-time backup and restoration type digital asset guard service providing system of claim 1, characterized in that each of the distributed recording means or the distributed recording smart contract (or server application) has the function of distributively recording each of the file data associated with the information of each of the conservation points sorted by the file data conservation point correspondence sorting means and managed in a black box environment by the conservation point information management means, which has been sorted by the distributed file management group sorting means or the distributed file management group sorting smart contract (or server application), to each of the base nodes belonging to the corresponding distributed file management group and to recording devices at multiple bases connected to the base nodes via a network.

11. The real-time backup and restoration type digital asset guard service provision system described in claim 10, characterized in that the planet configuration pattern setting means adds a predetermined number of dummy file data (having code internally that allows the encrypted / divided file data extraction means or the smart contract (or server application) for extracting encrypted / divided file data to recognize that it is dummy information) to the number of divisions of the file data, and selects the number of nodes that constitute the planet, and the distributed file management group constructed by the nodes at each base and the recording devices at multiple bases connected to the nodes at the base via a network.

12. The real-time backup and restoration type digital asset guard service provision system described in claim 10, characterized in that the planet configuration pattern setting means regards the spherical Earth as a plane, creates a matrix in which the Earth's regions are divided into multiple sections both vertically and horizontally, and determines the spacing in the X-axis direction, based on the Y-axis in the matrix for the node that distributes and records one divided file data within one of the distributed file management groups and the bases of multiple recording devices connected to the node via a network, using a calculated value based on the number of divisions of the file data, thereby selecting the node at each base within each of the distributed file management groups and the recording devices at multiple bases connected to the node at that base via a network.

13. The file data real-time backup system calculates hash values ​​based on encrypted and divided file data that is recorded in the nodes of each base belonging to each of the distributed file management groups and in the storage devices of multiple bases connected to the nodes of the base via a network, records the calculated hash values ​​in blocks in the nodes and storage devices, and constantly compares the hash values ​​recorded in the nodes of each of the distributed file management groups and in the storage devices of multiple bases connected to the nodes of the base via a network, or in blocks in the nodes or storage devices, and records the calculated hash values ​​in blocks in the nodes or storage devices. The real-time backup and restoration type digital asset guard service providing system of claim 1, further comprising a data tampering check control means that, if there is a difference between the hash recorded on the specific node or recording device and the hash recorded on another node or recording device or in a block on the node or recording device, detects that the encrypted and divided file data recorded on the specific node or recording device has been tampered with or destroyed, excludes the specific node or recording device from the file data backup process (and deletes the block on the specific node or recording device), and notifies the operator of the node and the digital asset guard service operations manager of an alarm.

14. The real-time backup and restoration type digital asset guard service provision system of claim 1, further comprising an upload process-enabled IP address check means for controlling the upload process (operation of the encryption / splitting algorithm selection receiving means, the customer data backup instruction receiving means, the file data encryption / splitting means, and the upload means) of the file data to be evacuated by the customer in the file data real-time backup system to be possible only when the customer terminal has a fixed IP address pre-registered as part of the system setting information in a node group at a specific location in the distributed ledger structure as terminal information for uploading to the first temporary storage area using the upload means.

15. A data destruction attack detection means for detecting attacks (or the existence of data destruction due to equipment failure, etc.) on encrypted and divided file data recorded on the planet (or on a node or recording device at any of the bases constituting the planet), and determining that a data destruction attack is taking place when destruction of multiple file data managed within a certain period of time (e.g., 30 minutes, 8 hours, 24 hours, etc.) is detected; The real-time backup and restoration type digital asset guard service providing system of claim 1, characterized in that it comprises an automatic data backup means in the event of an attack, configured to, when the data destructive attack detection means detects an attack on the encrypted and divided file data, stop the nodes of each base that constitutes the planet and the recording devices of multiple bases that are connected to the nodes of the base via a network, or forcibly disconnect the Internet connection path, and to set up a separate network to automatically backup the encrypted and divided file data that is distributed and recorded on the nodes of the base that are not attacked or the recording devices of multiple bases that are connected to the nodes of the base via a network, to the nodes of each base that constitute other planets where an attack on the encrypted and divided file data by the data destructive attack detection means has not been detected, and to the recording devices of multiple bases that are connected to the nodes of the base via a network.

16. A cold wallet; registration means for registering a list of destination addresses (whitelist) for digital assets in said cold wallet; and transaction destination address check means for, when creating agreement information between said first authenticator and said second authenticator regarding the evacuation processing of said customer's data to be evacuated by said data evacuation processing agreement information creation means, comparing the destination address of said transaction with the destination addresses in the whitelist registered in said cold wallet before approval of the transaction for the evacuation processing of said customer's data to be evacuated, and determining that the transaction is correct if the destination address of said transaction is included in the destination addresses in the whitelist registered in said cold wallet, and determining that the transaction is incorrect if the destination address is not included in the whitelist registered in said cold wallet.

2. The real-time save / restore digital asset guard service providing system according to claim 1, further comprising a save transaction approval processing control means for, if the transaction destination address check means determines that the transaction is incorrect, notifying the first authenticator and the second authenticator that the destination address is invalid and halting the creation of agreement information between the first authenticator and the second authenticator by the data save processing agreement information creation means.

Citation Information

Patent Citations

  • Authentication system, authentication information management apparatus, authentication information distribution method and computer program

    JP2007272506A

  • Method for managing input and output of data

    JP2008186315A

  • Secret sharing system

    JP2009103774A

  • Shared Secret-Based Blockchain Storage

    JP2020511808A

  • Information processing method, information processing system, information processing device, and information processing program

    JP2022157519A