WO2024201790A1 - 情報取得装置、情報取得システム、情報取得方法、及び記録媒体 - Google Patents

情報取得装置、情報取得システム、情報取得方法、及び記録媒体 Download PDF

Info

Publication number
WO2024201790A1
WO2024201790A1 PCT/JP2023/012821 JP2023012821W WO2024201790A1 WO 2024201790 A1 WO2024201790 A1 WO 2024201790A1 JP 2023012821 W JP2023012821 W JP 2023012821W WO 2024201790 A1 WO2024201790 A1 WO 2024201790A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
customer
product
information acquisition
customer product
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2023/012821
Other languages
English (en)
French (fr)
Inventor
昇 長谷
秀一 狩野
智雄 安達
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
NEC Corp
Original Assignee
NEC Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by NEC Corp filed Critical NEC Corp
Priority to PCT/JP2023/012821 priority Critical patent/WO2024201790A1/ja
Priority to JP2025509404A priority patent/JPWO2024201790A5/ja
Publication of WO2024201790A1 publication Critical patent/WO2024201790A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q30/00Commerce
    • G06Q30/01Customer relationship services
    • G06Q30/015Providing customer assistance, e.g. assisting a customer within a business location or via helpdesk
    • G06Q30/016After-sales

Definitions

  • This disclosure relates to an information acquisition device, an information acquisition system, an information acquisition method, and a recording medium.
  • Patent Document 1 discloses a technology that manages stored information related to the production of products, parts, equipment, workers, etc. by linking it to the product's production lot number or identification number, etc., and extracts a specified production lot number or individual identification number and the value of that information item related to production.
  • Patent Document 1 the invention described in Patent Document 1 above is based on the premise that the identification number of the product being used by the customer is known in advance.
  • the product vendor is usually unable to obtain the individual number of the product sold to the customer.
  • product information provided to a specific customer cannot be passed on to other customers.
  • One example of the objective of this disclosure is to provide an information acquisition system that can provide a customer's product information while concealing the product information of other customers.
  • the information acquisition device includes a data acquisition means for acquiring encrypted data of management information related to products shipped by a vendor to multiple customers, a number acquisition means for acquiring individual numbers of customer products owned by the customer, an extraction means for extracting customer product information related to the customer products from the encrypted data that has been decrypted using the individual numbers and the encryption key, and a display means for displaying the extracted customer product information.
  • the information acquisition system includes an information management device and the information acquisition device described above, and the information management device includes encryption means for encrypting management information related to products shipped to multiple customers.
  • a computer acquires encrypted data of management information related to products shipped by a vendor to multiple customers, acquires individual numbers of customer products owned by the customers, extracts customer product information related to the customer products from the encrypted data that has been decrypted using the individual numbers and an encryption key, and displays the extracted customer product information.
  • the recording medium stores a program that causes a computer to obtain encrypted data of management information related to products shipped by a vendor to multiple customers, obtain individual numbers of customer products owned by the customers, extract customer product information related to the customer products that has been decrypted from the encrypted data using the individual numbers and an encryption key, and display the extracted customer product information.
  • One example of the effect of this disclosure is the provision of an information acquisition system that can provide a customer's product information while concealing the product information of other customers.
  • FIG. 1 is a block diagram showing a configuration of an information management device according to the present disclosure.
  • FIG. 2 is a block diagram showing a configuration of an information acquisition device according to the present disclosure.
  • FIG. 3 is a diagram showing a hardware configuration in which the information management device and the information acquisition device according to the present disclosure are realized by a computer device and its peripheral devices.
  • FIG. 4 is a diagram showing the configuration of a customer's intranet network including an information acquisition device according to the present disclosure.
  • FIG. 5 is an example of a screen displaying extracted customer product information in this disclosure.
  • FIG. 6 is a flowchart showing an information acquisition operation in the present disclosure.
  • FIG. 7 is a block diagram showing a configuration of an information acquisition system according to the present disclosure.
  • FIG. 8 is a flowchart showing an information acquisition operation in the present disclosure.
  • FIG. 1 is a block diagram of an information management device 100 in the present disclosure.
  • FIG. 2 is a block diagram of an information acquisition device 200 in the present disclosure.
  • the information management device 100 is, for example, a server owned by a vendor that sells products, and stores management information related to the products up until the vendor ships the products.
  • the information acquisition device 200 is a server owned by each customer who purchases products from the vendor, and is used to acquire information related to customer products owned by the customers.
  • the information management device 100 and the information acquisition device 200 of the present disclosure will be described in detail below.
  • FIG. 3 is a diagram showing an example of a hardware configuration in which the information management device 100 and the information acquisition device 200 in the first embodiment of the present disclosure are realized by a computer device 500 including a processor.
  • the information acquisition system 10 includes a CPU (Central Processing Unit) 501, memories such as a ROM (Read Only Memory) 502 and a RAM (Random Access Memory) 503, a storage device 505 such as a hard disk for storing a program 504, a communication interface 508 for network connection, and an input/output interface 511 for inputting and outputting data.
  • each component of the information management device 100 and the information acquisition device 200 is connected to each other via a bus 512.
  • the CPU 501 runs an operating system to control each of the information management device 100 and the information acquisition device 200 according to the first embodiment of the present disclosure.
  • the CPU 501 also reads programs and data from a recording medium 506 mounted in, for example, a drive device 507 into memory.
  • the CPU 501 also functions as each component of the information management device 100 and the information acquisition device 200 or as a part of these components, and executes the processes or commands in the flowcharts shown in Figures 6 and 8, which will be described later, based on the programs.
  • the recording medium 506 is, for example, an optical disk, a flexible disk, a magneto-optical disk, an external hard disk, or a semiconductor memory.
  • a recording medium that is part of the storage device is a non-volatile storage device, and the program is recorded therein.
  • the program may also be downloaded from an external computer (not shown) that is connected to a communication network.
  • the input device 509 is realized, for example, by a mouse, keyboard, built-in key buttons, etc., and is used for input operations.
  • the input device 509 is not limited to a mouse, keyboard, or built-in key buttons, but may be, for example, a touch panel.
  • the output device 510 is realized, for example, by a display, and is used to check the output.
  • the first embodiment shown in FIG. 1 and FIG. 2 is realized by the computer hardware shown in FIG. 3.
  • the means for realizing each component of the information management device 100 in FIG. 1 and the information acquisition device 200 in FIG. 2 are not limited to the configurations described in this specification.
  • the information management device 100 and the information acquisition device 200 may each be realized by a single device that is physically combined, or may be realized by two or more physically separate devices that are connected by wire or wirelessly.
  • the input device 509 and the output device 510 may be connected to the computer device 500 via a network.
  • the information management device 100 includes an encryption unit 101.
  • the storage device 505 of the information management device 100 stores the encryption information until the vendor ships the product.
  • the management information of the product is stored.
  • the management information is, for example, inspection information of the product up to the time of shipment. If the product is a device, the inspection information includes the authenticity inspection at the time of shipment from the factory. This includes the presence or absence of information about the device, the presence or absence of confirmation of the device's status, etc.
  • Authenticity means confirming that no unauthorized hardware or programs are installed in the device. The authenticity of hardware can be confirmed, for example, by The authenticity of the program is confirmed by checking whether the program can be executed at the time of starting up the device, for example, by using secure boot.
  • the management information may contain dummy data. This dummy data is used to conceal the amount of data in the management information, and is created using a known method and mixed with the real management information.
  • the encryption unit 101 encrypts management information related to products shipped to multiple customers. For example, the encryption unit 101 encrypts the management information using an encryption key enclosed by the manufacturer of the information acquisition system 10. The encryption unit 101 may encrypt the management information periodically at predetermined intervals. For example, the encryption unit 101 stores the encrypted data of the management information in a recording medium 506 attached to a drive device 507 or the like.
  • the information acquisition device 200 includes a data acquisition unit 201, a number acquisition unit 202, an extraction unit 203, and a display unit 204.
  • 4 is a diagram showing a configuration of a customer's in-house network including an information acquisition device 200 according to the present disclosure. As shown in FIG. 4, the information acquisition device 200 is connected to a customer product purchased from a vendor by the customer on the in-house network N. In addition, each customer's product is not connected to an external network.
  • the data acquisition unit 201 acquires the encrypted data of the management information and outputs it to the extraction unit 203.
  • the data acquisition unit 201 acquires the encrypted data, for example, from a storage medium on which the encrypted data is stored.
  • the number acquisition unit 202 acquires the individual number of the customer product held by the customer.
  • An individual number is a number used to identify a product, such as a serial number.
  • the number acquisition unit 202 acquires, for example, data including the individual number from the information stored in the customer product.
  • the number acquisition unit 202 may verify the acquired individual number. Specifically, the number acquisition unit 202 verifies the individual number by verifying a digital signature for data including the individual number using a certificate enclosed with each customer product. This certificate is, for example, an IEEE802.1AR (IDevID: Initial Device Identifier), and the key in the certificate cannot be extracted to the outside. Furthermore, the number acquisition unit 202 may instruct the CPU of the customer product to assign a Nonce to the verified digital signature. The assigned Nonce is a unique value, which makes it possible to prevent the individual number from being swapped.
  • IDevID Initial Device Identifier
  • the extraction unit 203 has an encryption key, and extracts customer product information related to the customer product decrypted using the individual number and the encryption key.
  • the encryption key is, for example, an encryption key stored in a tamper-resistant storage area.
  • the tamper-resistant storage area may be, for example, configured as a TPM (Trusted Platform Module), but is not limited to this as long as it is configured to achieve tamper resistance.
  • the extraction unit 203 may also be configured to obfuscate the encryption key information so that the information cannot be extracted from the outside.
  • the encryption key may, for example, be built in by the manufacturer of the information acquisition system 10 in a pair with an encryption key for encrypting the management information.
  • the extraction unit 203 uses the individual number and the encryption key to extract customer product information related to the decrypted customer product from the encrypted data.
  • extraction refers to taking out the decrypted customer product information from the extraction unit 203.
  • the extraction unit 203 may decrypt all the encrypted data using the encryption key, and extract the customer product information from the decrypted management information using the individual number.
  • the extraction unit 203 may also decrypt only the encrypted data related to the customer product from the encrypted data, and extract the decrypted customer product information.
  • an encryption key for decrypting only the encrypted data related to a specific individual number is used.
  • This encryption key is a derived key generated by limiting the data to be decrypted from a master key that decrypts all encrypted data.
  • the extraction unit 203 outputs the extracted customer product information to the display unit 204. After extracting the customer product information, the extraction unit 203 may delete management information related to products other than the customer product.
  • the display unit 204 displays the decrypted customer product information.
  • the display unit 204 displays the decrypted customer product information in a customer product list. That is, the customer products displayed by the display unit 204 may not include product information.
  • the display unit 204 outputs the customer product information to the output device 510 or the like.
  • FIG. 5 is an example of displaying the inspection history of a device before shipment as customer product information. As shown in FIG. 5, the inspection history links each inspection result regarding the quality and authenticity of the product to the inspection time information. In FIG. 5, " ⁇ " indicates that the product has been inspected, and " ⁇ " indicates that the product has not been inspected. This allows the customer product manager to check the quality and security reliability of the product before the product is shipped. Note that the display example of the inspection history in this embodiment is not limited to the example in FIG. 5.
  • the display unit 204 may transmit information to another device using an API (Application Programming Interface) or the like without displaying it on the output device 510.
  • API Application Programming Interface
  • FIG. 6 is a flowchart showing an overview of the operation of the information acquisition device 200 in the first embodiment. Note that the processing according to this flowchart may be executed based on program control by the processor described above.
  • the data acquisition unit 201 acquires encrypted data of management information related to products shipped by a vendor to multiple customers (step S101).
  • the number acquisition unit 202 acquires the individual numbers of customer products owned by the customers (step S102).
  • the extraction unit 203 extracts customer product information related to the customer products decrypted from the encrypted data using the individual numbers and the encryption key (step S103).
  • the display unit 204 displays the extracted customer product information (step S104).
  • the extraction unit 203 extracts customer product information about the customer product that has been decrypted from the encrypted data using the individual number and encryption key, and the display unit 204 displays the customer product information.
  • the display unit 204 displays the customer product information.
  • FIG. 7 is a block diagram showing the configuration of the information acquisition system 10 in the first embodiment.
  • the information acquisition system 10 has an information management device 100 and an information acquisition device 200.
  • the configurations of the information management device 100 and the information acquisition device 200 are similar to the configurations shown in Figs. 1 and 2, respectively.
  • the information management device 100 transmits encrypted data of the management information encrypted by the encryption unit 101 to the information acquisition device 200, and the data acquisition unit 201 of the information acquisition device 200 receives the encrypted data of the management information. Note that the transmission and reception of encrypted data between the information management device 100 and the information acquisition device 200 is performed via the communication interface 508 of each device.
  • the encryption unit 101 may also encrypt the management information stored in the storage device 505 in response to a request from the information acquisition device 200 to transmit information related to a customer product.
  • FIG. 8 is a flowchart showing an overview of the operation of the information acquisition system 10 in the first embodiment. Note that the processing according to this flowchart may be executed based on program control by the processor described above.
  • the encryption unit 101 in the information management device 100 encrypts management information related to products shipped to multiple customers (step S111) and transmits it to the information acquisition device 200 (step S112).
  • the data acquisition unit 201 acquires the encrypted data (step S113).
  • the number acquisition unit 202 acquires the individual number of the customer product held by the customer (step S114).
  • the extraction unit 203 extracts customer product information related to the customer product decrypted from the encrypted data using the individual number and the encryption key (step S115).
  • the display unit 204 displays the extracted customer product information (step S116). With this, the information acquisition system 10 ends its operation.
  • the information acquisition system 10 has an information management device 100 that encrypts management information related to products shipped to multiple customers, and in the information acquisition device 200, an extraction unit 203 extracts customer product information related to the customer product that has been decrypted from the encrypted data using the individual number and encryption key, and a display unit 204 displays the customer product information.
  • an extraction unit 203 extracts customer product information related to the customer product that has been decrypted from the encrypted data using the individual number and encryption key
  • a display unit 204 displays the customer product information.
  • the factory cannot identify which product the customer has purchased.
  • the factory cannot identify which product the customer has purchased.
  • a customer who has purchased a product wants to obtain information on the customer's product from the vendor, there are problems such as the product ID number of the product operating in the customer's system cannot be transmitted outside the customer's system, and the product ID number of the product sold to the customer cannot be obtained from a sales system or the like that manages product information shipped by the vendor to the customer.
  • the number acquisition unit 202 of the information acquisition device 200 acquires the product ID number of the customer's product held by the customer.
  • Another use case of the information acquisition system 10 of the present disclosure is device license management.
  • a commercial product such as a network device is equipped with many functions
  • the customer needs to purchase licenses from the vendor to activate the corresponding functions.
  • the customer activates the corresponding functions by inputting the license data purchased from the vendor into the information acquisition device 200. All functions that can be activated are implemented in advance in the information acquisition device 200, and only functions whose usage rights have been confirmed by the license data are controlled within the device so that they can be operated.
  • the invention disclosed herein can be applied to the above-mentioned information acquisition device 200 when activating only functions for which licenses have been purchased. That is, the encryption unit 101 of the information management device 100 encrypts control information for controlling all functions.
  • the number acquisition unit 202 of the information acquisition device 200 acquires specific information that identifies the activation functions to be activated on the customer's device, and the extraction unit 203 extracts control information for the activation functions decrypted from the encrypted data using the specific information and the encryption key. This makes it possible to provide control information for functions for which the customer does not have the right to use, while keeping the control information for functions for which the customer does not have the right to use confidential. This makes it possible to control the functions of the device by acquiring a license.
  • the information management device 100 manages information such as the place of origin, shipping volume, production volume, and distribution volume of the agricultural products, for example, and provides information about the place of origin to the information acquisition device 200 while concealing information other than the place of origin.
  • a data acquisition means for acquiring encrypted data of management information related to products shipped by a vendor to a plurality of customers;
  • a number acquisition means for acquiring an individual number of a customer product owned by a customer;
  • an extracting means for extracting customer product information related to the customer product from the encrypted data, the customer product information being provided with an encryption key and decrypted using the individual number and the encryption key; and
  • a display means for displaying the extracted customer product information.
  • Appendix 4 The information acquisition device according to any one of appendices 1 to 3, wherein the number acquisition means verifies the individual number by verifying a digital signature for data including the individual number.
  • Appendix 7 The information acquisition device according to any one of appendices 1 to 6, wherein the management information is a pre-shipment inspection history of devices shipped to multiple customers.
  • Appendix 8 An information acquisition system having an information management device and an information acquisition device according to any one of appendices 1 to 7, The information acquisition system, wherein the information management device includes encryption means for encrypting management information relating to products shipped to a plurality of customers.
  • the management information is control information for enabling a plurality of functions installed in a specific product, the encryption means encrypts control information for controlling all functions;
  • the number obtaining means obtains specific information for identifying an activation function to be activated in the customer's product,
  • the computer Obtaining encrypted data of management information regarding products shipped by a vendor to multiple customers; Obtain the individual number of the customer product owned by the customer, extracting customer product information related to the customer product decrypted using the individual number and the encryption key from the encrypted data; and displaying the extracted customer product information.
  • Information acquisition system 100 Information management device 101 Encryption unit 200 Information acquisition device 201 Data acquisition unit 202 Number acquisition unit 203 Extraction unit 204 Display unit

Landscapes

  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Development Economics (AREA)
  • Economics (AREA)
  • Finance (AREA)
  • Marketing (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

本開示の情報取得装置は、ベンダが複数の顧客に出荷した製品に関する管理情報の暗号データを取得する、データ取得手段と、顧客が保有する顧客製品の個体番号を取得する、番号取得手段と、暗号鍵を備え、暗号データのうち、個体番号及び暗号鍵を用いて復号された顧客製品に関する顧客製品情報を抽出する、抽出手段と、抽出された顧客製品情報を表示する、表示手段と、を備える。

Description

情報取得装置、情報取得システム、情報取得方法、及び記録媒体
 本開示は、情報取得装置、情報取得システム、情報取得方法、及び記録媒体に関する。
 製品の検査結果と製品の個体識別番号を紐づけて管理する技術がある。
 例えば、特許文献1には、記憶されている製品、部品、設備、作業者等の製造にかかわる情報を製品の製造ロット番号や識別番号等に紐付けて管理し、指定した製造ロット番号または個体識別番号とその製造に係わる情報項目の値とを抽出する技術が開示されている。
特開2010-182284号公報
 しかしながら、上述した特許文献1に記載された発明は、予め顧客が使っている製品の識別番号を把握していることを前提としている。しかしながら、通常、製品を提供するベンダ側は、顧客に販売した製品の個体番号を取得できない。また、特定の顧客に提供した製品情報を他の顧客に渡すことはできない。
 本開示の目的の一例は、他の顧客の製品情報を秘匿しつつ、顧客の製品情報を提供可能な情報取得システムを提供することにある。
 本開示の一態様における情報取得装置は、ベンダが複数の顧客に出荷した製品に関する管理情報の暗号データを取得する、データ取得手段と、顧客が保有する顧客製品の個体番号を取得する、番号取得手段と、暗号鍵を備え、暗号データのうち、個体番号及び暗号鍵を用いて復号された顧客製品に関する顧客製品情報を抽出する、抽出手段と、抽出された顧客製品情報を表示する、表示手段と、を備える。
 本開示の一態様における情報取得システムは、情報管理装置と上述に記載の情報取得装置を有する情報取得システムであって、情報管理装置は、複数の顧客に出荷した製品に関する管理情報を暗号化する、暗号化手段を備える。
 本開示の一態様における情報取得方法は、コンピュータが、ベンダが複数の顧客に出荷した製品に関する管理情報の暗号データを取得し、顧客が保有する顧客製品の個体番号を取得し、暗号データのうち、個体番号及び暗号鍵を用いて復号された顧客製品に関する顧客製品情報を抽出し、抽出された顧客製品情報を表示する。
 本開示の一態様における記録媒体は、ベンダが複数の顧客に出荷した製品に関する管理情報の暗号データを取得し、顧客が保有する顧客製品の個体番号を取得し、暗号データのうち、個体番号及び暗号鍵を用いて復号された顧客製品に関する顧客製品情報を抽出し、抽出された顧客製品情報を表示する、ことをコンピュータに実行させるプログラムを格納する。
 本開示による効果の一例は、他の顧客の製品情報を秘匿しつつ、顧客の製品情報を提供可能な情報取得システムを提供できることにある。
図1は、本開示における情報管理装置の構成を示すブロック図である。 図2は、本開示における情報取得装置の構成を示すブロック図である。 図3は、本開示における情報管理装置及び情報取得装置をコンピュータ装置とその周辺装置で実現したハードウェア構成を示す図である。 図4は、本開示における情報取得装置を含む顧客の社内ネットワークの構成を示す図である。 図5は、本開示において、抽出された顧客製品情報を表示した画面の例である。 図6は、本開示における情報取得の動作を示すフローチャートである。 図7は、本開示における情報取得システムの構成を示すブロック図である。 図8は、本開示における情報取得の動作を示すフローチャートである。
 次に、実施形態について図面を参照して詳細に説明する。本実施形態では、製品が装置である場合を例に説明するが、本開示における製品は装置に限られない。
 [第一の実施形態]
 図1は、本開示にける情報管理装置100のブロック図である。また、図2は、本開示にける情報取得装置200のブロック図である。情報管理装置100は、例えば、製品を販売するベンダが所有しているサーバであって、ベンダが製品を出荷するまでの製品に関する管理情報が格納されている。情報取得装置200は、ベンダから製品を購入した各顧客が所有するサーバであって、その顧客が保有する顧客製品に関する情報を取得するために用いられる。以下、本開示の情報管理装置100及び情報取得装置200について詳しく説明する。
 図3は、本開示の第一の実施形態における情報管理装置100と情報取得装置200を、プロセッサを含むコンピュータ装置500で実現したハードウェア構成の一例を示す図である。図3に示されるように、情報取得システム10は、CPU(Central Processing Unit)501、ROM(Read Only Memory)502、RAM(Random Access Memory)503等のメモリ、プログラム504を格納するハードディスク等の記憶装置505、ネットワーク接続用の通信インターフェース508、データの入出力を行う入出力インターフェース511を含む。第一の実施形態において、情報管理装置100と情報取得装置200の各構成部は、バス512を介して各構成部と接続されている。
 CPU501は、オペレーティングシステムを動作させて本開示の第一の実施の形態に係る情報管理装置100と情報取得装置200のそれぞれを制御する。また、CPU501は、例えばドライブ装置507等に装着された記録媒体506からメモリにプログラムやデータを読み出す。また、CPU501は、情報管理装置100と情報取得装置200の各構成部及びこれらの一部として機能し、プログラムに基づいて後述する図6及び図8に示すフローチャートにおける処理または命令を実行する。
 記録媒体506は、例えば光ディスク、フレキシブルディスク、磁気光ディスク、外付けハードディスク、または半導体メモリ等である。記憶装置の一部の記録媒体は、不揮発性記憶装置であり、そこにプログラムを記録する。また、プログラムは、通信網に接続されている図示しない外部コンピュータからダウンロードされてもよい。
 入力装置509は、例えば、マウスやキーボード、内蔵のキーボタン等で実現され、入力操作に用いられる。入力装置509は、マウスやキーボード、内蔵のキーボタンに限らず、例えばタッチパネルでもよい。出力装置510は、例えばディスプレイで実現され、出力を確認するために用いられる。
 以上のように、図1及び図2に示す第一の実施形態は、図3に示されるコンピュータ・ハードウェアによって実現される。ただし、図1の情報管理装置100と図2の情報取得装置200が備える各構成部の実現手段は、本明細書で説明した構成に限定されない。また、情報管理装置100及び情報取得装置200は、それぞれ、物理的に結合した一つの装置により実現されてもよいし、物理的に分離した二つ以上の装置を有線または無線で接続し、これら複数の装置により実現されてもよい。たとえば、入力装置509及び出力装置510は、コンピュータ装置500とネットワークを経由して接続されていてもよい。
(情報管理装置100)
 まず、情報管理装置100について説明する。図1に示すように、情報管理装置100は、暗号化部101を備える。また、情報管理装置100の記憶装置505には、ベンダが製品を出荷するまでの製品の管理情報が格納されている。管理情報としては、例えば、製品を出荷するまでの製品の検査情報である。製品が装置である場合、検査情報には、工場出荷時の真正性検査の情報の有無、装置の状態の確認の有無等を含む。真正性とは、装置に不正なハードウェアやプログラムが組み込まれていないことを確認することである。ハードウェアの真正性は、例えば、ハードウェアの偽造またはすり替えがされていないことにより確認する。プログラムの真正性は、例えば、セキュアブートにより、装置起動時のプログラムが実行できるか否かにより確認する。
 なお、管理情報には、ダミーデータが含まれていてもよい。このダミーデータは、管理情報のデータ量を秘匿するためのデータであって、既知の方法で作成し、本物の管理情報と混合される。
 暗号化部101は、複数の顧客に出荷した製品に関する管理情報を暗号化する。暗号化部101は、例えば、情報取得システム10の製造元により封入された暗号鍵を用いて管理情報を暗号化する。暗号化部101は、所定期間ごとに定期的に管理情報を暗号化してもよい。暗号化部101は、例えば、管理情報を暗号化した暗号データをドライブ装置507等に装着された記録媒体506に格納する。
(情報取得装置200)
 続いて、情報取得装置200について説明する。図2に示すように、情報取得装置200は、データ取得部201と、番号取得部202と、抽出部203と、表示部204を備える。図4は、本開示における情報取得装置200を含む顧客の社内ネットワークの構成を示す図である。図4に示すように、情報取得装置200は、顧客がベンダから購入した顧客製品と社内ネットワークN上で接続されている。なお、各顧客製品は、外部ネットワークには接続されていない。
 データ取得部201は、管理情報の暗号データを取得し、抽出部203に出力する。データ取得部201は、例えば、暗号データが格納された記憶媒体等から暗号データを取得する。
 番号取得部202は、顧客が保有する顧客製品の個体番号を取得する。個体番号とは、シリアル番号等の製品を識別するための番号である。番号取得部202は、例えば、顧客製品に格納された情報の中から個体番号を含むデータを取得する。
 番号取得部202は、取得した個体番号を検証してもよい。具体的には、番号取得部202は、顧客製品ごとに封入された証明書により個体番号を含むデータに対するデジタル署名を検証することで、個体番号を検証する。この証明書は、例えば、IEEE802.1ARの(IDevID:Initial Device Identifier)であり、証明書内の鍵は外部に取り出せないようになっている。さらに、番号取得部202は、顧客製品のCPUに対して、検証したデジタル署名にNonceを付与するように指示してもよい。付与されるNonceは固有値であるため、個体番号のすり替えを防ぐことができる。
 抽出部203は、暗号鍵を備え、個体番号及び暗号鍵を用いて復号された顧客製品に関する顧客製品情報を抽出する。暗号鍵は、例えば、耐タンパー性を持った記憶領域に格納された暗号鍵である。耐タンパー性を持った記憶領域としては、例えば、TPM(Trusted Platform Module)で構成されるが、耐タンパー性を実現できる構成であればこれに限らない。また、抽出部203は、暗号鍵の情報を難読化することで、外部から情報が取り出せないような構成であってもよい。暗号鍵は、例えば、情報取得システム10の製造元により、管理情報を暗号化するための暗号鍵とペアになって組み込まれていてもよい。
 抽出部203は、個体番号及び暗号鍵を用いて、暗号データのうち、復号された顧客製品に関する顧客製品情報を抽出する。本実施形態において、抽出とは、抽出部203から復号された顧客製品情報を取り出すことを指す。抽出部203は、暗号鍵を用いて暗号データを全て復号し、復号された管理情報の中から、個体番号を用いて顧客製品情報を抽出してもよい。また、抽出部203は、暗号データのうち、顧客製品に関する暗号データのみを復号し、復号された顧客製品情報を抽出してもよい。この場合は、特定の個体番号に関する暗号データのみを復号するための暗号鍵が用いられる。この暗号鍵の一例としては、全ての暗号データを復号するマスター鍵から復号するデータを限定して生成された派生鍵である。抽出部203は、抽出した顧客製品情報を表示部204に出力する。また、抽出部203は、顧客製品情報を抽出した後、顧客製品以外の製品に関する管理情報を削除してもよい。
 表示部204は、復号された顧客製品情報を表示する。表示部204は、例えば、復号された顧客製品情報を顧客製品一覧の中に表示する。すなわち、表示部204が表示する顧客製品の中には、製品情報が含まれない場合もある。表示部204は、出力装置510等に顧客製品情報を出力する。図5は、顧客製品情報として、装置の出荷前の検査履歴を表示した例である。図5に示すように、検査履歴には、検査した時刻情報に製品の品質、真正性について各検査結果が紐づけられている。図5中、「〇」は検査済みであり、「×」は未検査であることを示す。これにより、顧客製品の管理者は、製品の出荷前において、製品の品質やセキュリティ面での信頼性を確認できる。なお、本実施形態における検査履歴の表示例は図5の例に限られない。また、表示部204は、出力装置510に表示せずに、API(Application Programming Interface)等で他の装置に情報を送信してもよい。
 図6は、第一の実施形態における情報取得装置200の動作の概要を示すフローチャートである。尚、このフローチャートによる処理は、前述したプロセッサによるプログラム制御に基づいて、実行されてもよい。
 図6に示すように、まず、データ取得部201が、ベンダが複数の顧客に出荷した製品に関する管理情報の暗号データを取得する(ステップS101)。次いで、番号取得部202は、顧客が保有する顧客製品の個体番号を取得する(ステップS102)。抽出部203は、暗号データのうち、個体番号及び暗号鍵を用いて復号された顧客製品に関する顧客製品情報を抽出する(ステップS103)。最後に、表示部204は、抽出された顧客製品情報を表示する(ステップS104)。
 本実施形態の情報取得装置200では、抽出部203が、暗号データのうち、個体番号及び暗号鍵を用いて復号された顧客製品に関する顧客製品情報を抽出し、表示部204が顧客製品情報を表示する。この構成により、顧客製品情報を抽出した顧客は、ベンダが他の顧客に出荷した製品に関する情報を取り出すことはできない。よって、ベンダが複数の顧客に出荷した製品に関する管理情報のうち、他の顧客の製品情報を秘匿しつつ、顧客の製品情報を提供可能となる。
(情報取得システム10)
 続いて、本実施形態の情報取得システム10について説明する。図7は、第一の実施形態における情報取得システム10の構成を示すブロック図である。図7を参照すると、情報取得システム10は、情報管理装置100と情報取得装置200を有している。情報管理装置100と情報取得装置200の構成は、それぞれ図1及び図2で示した構成と同様である。
 情報取得システム10は、情報管理装置100が暗号化部101により暗号化された管理情報の暗号データを情報取得装置200に送信し、情報取得装置200のデータ取得部201が管理情報の暗号データを受信する。なお、情報管理装置100と情報取得装置200の間の暗号データの送受信は、各装置の通信インターフェース508を介して行われる。また、暗号化部101は、情報取得装置200からの顧客製品に関する情報の送信要求があったことをトリガーとして、記憶装置505に格納している管理情報を暗号化してもよい。
 以上のように構成された情報取得システム10の動作について、図8のフローチャートを参照して説明する。
 図8は、第一の実施形態における情報取得システム10の動作の概要を示すフローチャートである。尚、このフローチャートによる処理は、前述したプロセッサによるプログラム制御に基づいて、実行されてもよい。
 図8に示すように、まず、情報管理装置100における暗号化部101は、複数の顧客に出荷した製品に関する管理情報を暗号化し(ステップS111)、情報取得装置200に送信する(ステップS112)。次いで、情報取得装置200において、データ取得部201が、暗号データを取得する(ステップS113)。次いで、番号取得部202は、顧客が保有する顧客製品の個体番号を取得する(ステップS114)。抽出部203は、暗号データのうち、個体番号及び暗号鍵を用いて復号された顧客製品に関する顧客製品情報を抽出する(ステップS115)。最後に、表示部204は、抽出された顧客製品情報を表示する(ステップS116)。以上で、情報取得システム10は、動作を終了する。
 第一の実施形態における情報取得システム10は、情報管理装置100が、複数の顧客に出荷した製品に関する管理情報を暗号化し、情報取得装置200において、抽出部203が、その暗号データのうち、個体番号及び暗号鍵を用いて復号された顧客製品に関する顧客製品情報を抽出し、表示部204が顧客製品情報を表示する。この構成により、顧客製品情報を抽出した顧客は、ベンダが他の顧客に出荷した製品に関する情報を取り出すことはできない。よって、ベンダが複数の顧客に出荷した製品に関する管理情報のうち、他の顧客の製品情報を秘匿しつつ、顧客の製品情報を提供可能となる。
 また、ベンダが製品を購入した顧客から顧客製品の検査情報を依頼されても、工場では、顧客がどの製品を購入したのか特定できないといった課題がある。また、製品を購入した顧客がベンダから顧客製品の情報を取得したくても、顧客システム内で動作する製品の個体番号を顧客システム外に送信できないといった課題や、ベンダが顧客に出荷した製品情報を管理する販売システム等から顧客に販売された製品の個体番号を取得できないといった課題がある。これに対し、本開示の情報取得システム10によれば、情報取得装置200の番号取得部202が、顧客が保有する顧客製品の個体番号を取得する。よって、上述した課題を解決しながら、ベンダが複数の顧客に出荷した製品に関する管理情報のうち、他の顧客の製品情報を秘匿しつつ、顧客の製品情報を提供可能となる。また、本開示の情報取得システム10によれば、製品の生産または出荷数量も秘匿しながら、顧客の製品情報を提供可能である。
<適用例>
 本開示の情報取得システム10の他のユースケースとしては、装置のライセンス管理が挙げられる。ネットワーク装置等の商用の製品に対して多数の機能が搭載されている場合、顧客はベンダからライセンスを購入して該当機能を有効化させる必要がある。顧客は、ベンダから購入したライセンスデータを情報取得装置200に入力することで、該当機能を有効にする。情報取得装置200には、予め、有効化可能な全機能が実装されており、ライセンスデータにて使用権が確認された機能のみ、それが動作するよう、装置内で制御されることになる。
 上述の情報取得装置200において、ライセンスを購入した機能のみを有効化する場合に、本開示の発明が適用できる。すなわち、情報管理装置100の暗号化部101は、全ての機能を制御するための制御情報を暗号化する。情報取得装置200の番号取得部202は、顧客の装置で有効化させる有効化機能を特定する特定情報を取得し、抽出部203は、暗号データのうち、特定情報及び暗号鍵を用いて復号された有効化機能の制御情報を抽出する。これにより、顧客が使用権を持っていない機能の制御情報を秘匿しつつ、使用権を持っている機能の制御情報を提供できる。これにより、ライセンス取得による装置の機能制御が可能となる。
 また、他の適用例として、農産物等のトレーサビリティに関する情報が挙げられる。この場合、情報管理装置100は、例えば、農産物の産地、出荷量,生産量及び流通量等の情報を管理し、情報取得装置200に対して、産地以外の情報を秘匿しつつ、産地の情報を提供する。
 以上、各実施の形態を参照して本発明を説明したが、本発明は上記実施の形態に限定されるものではない。本発明の構成や詳細には、本発明のスコープ内で当業者が理解しえる様々な変更をすることができる。
 例えば、複数の動作をフローチャートの形式で順番に記載してあるが、その記載の順番は複数の動作を実行する順番を限定するものではない。このため、各実施形態を実施するときには、その複数の動作の順番は内容的に支障しない範囲で変更することができる。
 上記の実施の形態の一部または全部は、以下の付記のようにも記載されることができる。ただし、上記の実施の形態の一部または全部は、以下に限られない。
(付記1)
 ベンダが複数の顧客に出荷した製品に関する管理情報の暗号データを取得する、データ取得手段と、
 顧客が保有する顧客製品の個体番号を取得する、番号取得手段と、
 暗号鍵を備え、前記暗号データのうち、前記個体番号及び前記暗号鍵を用いて復号された前記顧客製品に関する顧客製品情報を抽出する、抽出手段と、
 抽出された前記顧客製品情報を表示する、表示手段と、を備える、情報取得装置。
(付記2)
 前記抽出手段は、前記暗号データを全て復号し、復号された管理情報の中から、前記顧客製品情報を抽出する、付記1に記載の情報取得装置。
(付記3)
 前記抽出手段は、前記暗号データのうち、顧客製品に関する暗号データのみを復号し、前記顧客製品情報を抽出する、付記1に記載の情報取得装置。
(付記4)
 前記番号取得手段は、前記個体番号を含むデータに対するデジタル署名を検証することで、前記個体番号を検証する、付記1~3のいずれかに記載の情報取得装置。
(付記5)
 前記管理情報は、ダミーデータを含む、付記1~4のいずれかに記載の情報取得装置。
(付記6)
 前記抽出手段は、前記顧客製品情報を抽出した後、顧客製品以外の製品に関する管理情報を削除する、付記1~5のいずれかに記載の情報取得装置。
(付記7)
 前記管理情報は、複数の顧客に出荷した装置の出荷前の検査履歴である、付記1~6のいずれかに記載の情報取得装置。
(付記8)
 情報管理装置と付記1~7のいずれかに記載の情報取得装置を有する情報取得システムであって、
 前記情報管理装置は、複数の顧客に出荷した製品に関する管理情報を暗号化する、暗号化手段を備える、情報取得システム。
(付記9)
 前記管理情報は、特定の製品に搭載された複数の機能を有効化させるための制御情報であり、
 前記暗号化手段は、全ての機能を制御するための制御情報を暗号化し、
 前記番号取得手段は、顧客の製品で有効化させる有効化機能を特定する特定情報を取得し、
 前記抽出手段は、前記暗号データのうち、前記特定情報及び前記暗号鍵を用いて復号された前記有効化機能の制御情報を抽出する、付記8に記載の情報取得システム。
(付記10)
 コンピュータが、
 ベンダが複数の顧客に出荷した製品に関する管理情報の暗号データを取得し、
 顧客が保有する顧客製品の個体番号を取得し、
 前記暗号データのうち、前記個体番号及び暗号鍵を用いて復号された前記顧客製品に関する顧客製品情報を抽出し、
 抽出された前記顧客製品情報を表示する、情報取得方法。
(付記11)
 ベンダが複数の顧客に出荷した製品に関する管理情報の暗号データを取得し、
 顧客が保有する顧客製品の個体番号を取得し、
 前記暗号データのうち、前記個体番号及び暗号鍵を用いて復号された前記顧客製品に関する顧客製品情報を抽出し、
 抽出された前記顧客製品情報を表示する、ことをコンピュータに実行させるプログラムを格納する記録媒体。
 10  情報取得システム
 100 情報管理装置
 101 暗号化部
 200 情報取得装置
 201 データ取得部
 202 番号取得部
 203 抽出部
 204 表示部

Claims (11)

  1.  ベンダが複数の顧客に出荷した製品に関する管理情報の暗号データを取得する、データ取得手段と、
     顧客が保有する顧客製品の個体番号を取得する、番号取得手段と、
     暗号鍵を備え、前記暗号データのうち、前記個体番号及び前記暗号鍵を用いて復号された前記顧客製品に関する顧客製品情報を抽出する、抽出手段と、
     抽出された前記顧客製品情報を表示する、表示手段と、を備える、情報取得装置。
  2.  前記抽出手段は、前記暗号データを全て復号し、復号された管理情報の中から、前記顧客製品情報を抽出する、請求項1に記載の情報取得装置。
  3.  前記抽出手段は、前記暗号データのうち、顧客製品に関する暗号データのみを復号し、前記顧客製品情報を抽出する、請求項1に記載の情報取得装置。
  4.  前記番号取得手段は、前記個体番号を含むデータに対するデジタル署名を検証することで、前記個体番号を検証する、請求項1~3のいずれか一項に記載の情報取得装置。
  5.  前記管理情報は、ダミーデータを含む、請求項1~4のいずれか一項に記載の情報取得装置。
  6.  前記抽出手段は、前記顧客製品情報を抽出した後、顧客製品以外の製品に関する管理情報を削除する、請求項1~5のいずれか一項に記載の情報取得装置。
  7.  前記管理情報は、複数の顧客に出荷した装置の出荷前の検査履歴である、請求項1~6のいずれか一項に記載の情報取得装置。
  8.  情報管理装置と請求項1~7のいずれか一項に記載の情報取得装置を有する情報取得システムであって、
     前記情報管理装置は、複数の顧客に出荷した製品に関する管理情報を暗号化する、暗号化手段を備える、情報取得システム。
  9.  前記管理情報は、特定の製品に搭載された複数の機能を有効化させるための制御情報であり、
     前記暗号化手段は、全ての機能を制御するための制御情報を暗号化し、
     前記番号取得手段は、顧客の製品で有効化させる有効化機能を特定する特定情報を取得し、
     前記抽出手段は、前記暗号データのうち、前記特定情報及び前記暗号鍵を用いて復号された前記有効化機能の制御情報を抽出する、請求項8に記載の情報取得システム。
  10.  コンピュータが、
     ベンダが複数の顧客に出荷した製品に関する管理情報の暗号データを取得し、
     顧客が保有する顧客製品の個体番号を取得し、
     前記暗号データのうち、前記個体番号及び暗号鍵を用いて復号された前記顧客製品に関する顧客製品情報を抽出し、
     抽出された前記顧客製品情報を表示する、情報取得方法。
  11.  ベンダが複数の顧客に出荷した製品に関する管理情報の暗号データを取得し、
     顧客が保有する顧客製品の個体番号を取得し、
     前記暗号データのうち、前記個体番号及び暗号鍵を用いて復号された前記顧客製品に関する顧客製品情報を抽出し、
     抽出された前記顧客製品情報を表示する、ことをコンピュータに実行させるプログラムを格納する記録媒体。
PCT/JP2023/012821 2023-03-29 2023-03-29 情報取得装置、情報取得システム、情報取得方法、及び記録媒体 Ceased WO2024201790A1 (ja)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/JP2023/012821 WO2024201790A1 (ja) 2023-03-29 2023-03-29 情報取得装置、情報取得システム、情報取得方法、及び記録媒体
JP2025509404A JPWO2024201790A5 (ja) 2023-03-29 情報取得装置、情報取得システム、情報取得方法、及びプログラム

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2023/012821 WO2024201790A1 (ja) 2023-03-29 2023-03-29 情報取得装置、情報取得システム、情報取得方法、及び記録媒体

Publications (1)

Publication Number Publication Date
WO2024201790A1 true WO2024201790A1 (ja) 2024-10-03

Family

ID=92903609

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2023/012821 Ceased WO2024201790A1 (ja) 2023-03-29 2023-03-29 情報取得装置、情報取得システム、情報取得方法、及び記録媒体

Country Status (1)

Country Link
WO (1) WO2024201790A1 (ja)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2009003896A (ja) * 2007-06-25 2009-01-08 Daikin Ind Ltd 管理システム
JP2019159353A (ja) * 2018-03-07 2019-09-19 京セラドキュメントソリューションズ株式会社 取引システムおよび電子機器
JP2021033882A (ja) * 2019-08-28 2021-03-01 富士電機株式会社 自動販売機及びサービス管理方法

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2009003896A (ja) * 2007-06-25 2009-01-08 Daikin Ind Ltd 管理システム
JP2019159353A (ja) * 2018-03-07 2019-09-19 京セラドキュメントソリューションズ株式会社 取引システムおよび電子機器
JP2021033882A (ja) * 2019-08-28 2021-03-01 富士電機株式会社 自動販売機及びサービス管理方法

Also Published As

Publication number Publication date
JPWO2024201790A1 (ja) 2024-10-03

Similar Documents

Publication Publication Date Title
US7313828B2 (en) Method and apparatus for protecting software against unauthorized use
KR101390574B1 (ko) 원격 디바이스 등록 시스템 및 방법
EP3873024B1 (en) Device using secure storage and retrieval of data
CN102081716B (zh) 向受信任平台模块提供可更新密钥绑定的方法和装置
CN101484901B (zh) 用于控制生产过程的系统和方法
US20090217054A1 (en) Secure software and hardware association technique
US20230088172A1 (en) System for secure provisioning and enforcement of system-on-chip (soc) features
US20020116632A1 (en) Tamper-resistant computer system
US20080027871A1 (en) Update method and update system
US20150347758A1 (en) Methods and systems for securely transferring embedded code and/or data designed for a device to a customer
JPH06501120A (ja) パーソナルコンピュータのソフトウエアを遠隔位置で起動するための安全システム
CN106304040A (zh) 管理移动应用的方法、装置
EP1837789A2 (en) Method and apparatus for temporarily accessing content using temporary license
WO2020048290A1 (zh) 用于发行证书的系统和方法
US20120030471A1 (en) Download management system
US20190044709A1 (en) Incorporating software date information into a key exchange protocol to reduce software tampering
CN110674525A (zh) 一种电子设备及其文件处理方法
US8103804B2 (en) Method and system for embedded regenerative licensing
CN110619194A (zh) 一种升级包加密、解密方法及装置
CN107992760B (zh) 秘钥写入方法、装置、设备及存储介质
JP4454280B2 (ja) ライセンス認証方法およびライセンス認証システム
US20040172556A1 (en) Data communication system, information processing device and method, recording medium and program
WO2024201790A1 (ja) 情報取得装置、情報取得システム、情報取得方法、及び記録媒体
US9769125B2 (en) Information administration system
JP5018558B2 (ja) 記憶領域割当方法および情報処理装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23930429

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2025509404

Country of ref document: JP

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 2025509404

Country of ref document: JP

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 23930429

Country of ref document: EP

Kind code of ref document: A1