Information Processing System Dynamic Node Group Selection for Secret Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information processing systems face challenges in securely storing and restoring secret data due to the risk of unauthorized access when storing destinations of distributed data are easily identifiable, and the process of specifying these destinations is resource-intensive when not stored with associated information.
Innovation Solution
An information processing system that generates distributed data using a secret sharing scheme, selects a node group based on a time period, and performs a restoring process on multiple node groups to securely store and retrieve secret data, reducing the likelihood of unauthorized access by changing storage destinations over time and not storing information that links secret data with its storage locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If information to identify secret data and information to specify storing destinations of distributed data are stored in association with each other, then the restoring process can efficiently specify storing destinations, but the security is weakened because a user can unscrupulously obtain the secret data by specifying the storing destinations
Solution Approach 1:
The patent extracts and separates the identification information of secret data from the information specifying storing destinations of distributed data. Instead of storing them in association, the system generates a restoration specification that contains only the identification information, which is then used to retrieve the appropriate distributed data from storage destinations without exposing the link between secret data and its storage locations.
Solution Approach 2:
The patent introduces a restoration specification as an intermediary element that mediates between the identification information of secret data and the information specifying storing destinations. This restoration specification acts as a decoupled reference that enables the restoring process to efficiently locate distributed data without directly exposing the association between secret data and storage destinations, thus maintaining security while preserving operational efficiency.
2Reliability
If information to identify secret data and information to specify storing destinations of distributed data are not stored in association with each other, then the security is improved, but the restoring process becomes highly loaded
Solution Approach 1:
The patent performs preliminary action by generating and storing a restoration specification in advance that contains the identification information of secret data. This restoration specification is prepared beforehand and stored separately from the distributed data, enabling the restoring process to quickly retrieve and use it for specifying storage destinations without performing heavy processing during the actual restoration operation.
Solution Approach 2:
The patent transitions from a direct one-to-one association between secret data identification and storage destination information to a multi-dimensional structure where restoration specifications serve as an intermediate layer. This dimensional change allows the system to maintain security by decoupling the direct association while preserving efficiency through the use of pre-generated restoration specifications that can be quickly processed.
3Reliability
If the storing destinations of distributed data are changed each time secret data is stored, then the security is improved by making it harder to specify storing destinations, but the system complexity increases
Solution Approach 1:
The patent implements dynamic behavior by changing the storage destinations of distributed data for each new secret data storage operation. The system dynamically selects and updates storage destinations rather than using fixed locations, which enhances security by making it difficult for users to predict or specify where distributed data will be stored. The restoration specification mechanism manages this dynamic behavior without requiring complex real-time coordination.
Solution Approach 2:
The patent uses copying by creating restoration specifications that contain identification information as a separate copy or reference to the secret data. Instead of directly managing the complex associations between changing storage destinations and secret data, the system creates simplified copies (restoration specifications) that capture the essential identification information needed for restoration, thereby reducing system complexity while maintaining security through dynamic destination changes.
Data Source
AI summary
An information processing system including multiple memory devices and a processor configured to select one node group associated with a time point included in a time period between a current time point and a time point before a predetermined time including the current time point among multiple node groups each associated with one of multiple time points, and store the N pieces of distributed data one to each of N memory devices included in the selected node group. The information processing system carries out a restoring process on at least one of the multiple node groups, and if the restoring results in failure, carries out the restoring process on a second node group associated with a time point before a time point associated with the first node group that causes the failure among the plurality of node groups.


