The present invention relates to low cost and simple information protection system for preventing hackers from accessing and protecting data stored in a storage medium, a storage medium to be used therefor and a storage medium storage case.
In recent years, electronics are widely used in various areas of our life including all business fields as well as medial and welfare fields and networking in communication is accelerated, thereby significantly improving convenience. As a result of application of electronics, various kinds of information are normally stored in a storage (or recording) medium in personal computers (PCs) and various kinds of storage media are widely used. Hard discs (HDDs) are mostly used because of their large storage capacity and relatively reasonable price. However, in consideration of not only storage capacity but also portability, price and friendliness of the material (plastics) to environment in case of disposal, optical discs are attracting interest as promising storage media in recent years.
Incidentally, a basic resident register network has recently been established, in which all local governments and the central government are integrated in a network and private information of all residents in any city, town or village are stored in a database so that such private information can be accessible from any location within the country.
Such basic resident register network enables each municipality to install a communication server by way of a firewall. Existing basic resident management system can also be connected to the communication server. It is basically possible that the central and local government organizations can send or receive necessary information by interconnecting the communication server and servers in each municipality and the Municipality Information Center in Tokyo using a dedicated line.
Since confidential information such as private information are handled in this type of network, it is absolutely necessary to have very high degree of security. On the other hand, in certain local governments, since there are installed an internal LAN to be connected to internet by way of a firewall, there is a possibility that someone may illegally gain access to the system through internet. If once accessed to the system, there is a possibility that the person may invade into the entire system.
In order to solve such problem, countermeasures have been made to use independently developed protocols for the network inside the firewall of the communication servers in the local governments or to independently develop even application software to be used with the servers. However, such protocols or application software independently developed by local governments are tend to be relatively large scale and new protocols or application software must be developed if once broken by a hacker. As a result, this is a never lasting struggle with hackers.
Such problems are, of course, not limited to the basic resident register network and similar networks and storage media are subject to such problems.
As described hereinabove, any conventional network connected to internet cannot be completely free from illegal access by hackers even if a firewall may be provided.
It is, therefore, an object of the present invention to provide a simple and low cost information protection system capable of preventing hackers from accessing and protecting data that are stored in individual storage medium, storage medium to be used therefor and storage medium storage (or accommodation) case.
In order to solve the above problems, the information protection system, the storage medium to be used therefor and the storage medium storage case according to the present invention have the following unique constructions.
The information protection system, the storage medium to be used therefor and the storage medium storage case according to the present invention have the following significant practical advantages:
That is, even if any outside hacker successfully invaded into or accessed to PCs from internet or accessed to other PCs connected to the LAN that he/she has successfully accessed, the storage medium (or intelligent disc) in which confidential information is stored actively controls the PCs and is protected by individual security programs installed in the PCs, thereby providing a further barrier for more reliable protection of the confidential information. It is to be noted herein that by simply changing a security program for each disc, it acts as an independent security program, thereby enabling one to easily develop programs. Moreover, it is possible to store a plurality of storage media in a storage medium storage case and to enable only a person to be certified as one of the particular persons who are previously registered is able to pick out the storage medium. If a person is determined to be NG in certification, a warning is generated when he/she picks out the storage medium and moves it to a distant location outside the predetermined area and such warning is transmitted to a control or an administration center by way of a communication line, thereby providing control of the storage medium itself and reliable security. Additionally, if optical discs are used as the storage media, a large storage capacity can be obtained at a low cost and environmental pollution can be avoided when disposing them.
In the accompanying drawings:
Now, embodiments of the information protection system, the storage medium therefor and the storage medium storage case according to the present invention will be described in construction and operation with reference to the accompanying drawings.
A service network in local government 100 comprises a basic resident register/family registration server, a tax/finance server, a basic system server and the like 11 that are connected to a large number of PCs 12-14, 15A, 15B, 16 and 17 for processing services shared by respective servers. The PCs 12, 13 and 14 are terminals designated to provide services exclusively as a CS terminal, a basic resident register terminal and a finance terminal, respectively. The PCs 15A, 15B, 16 and 17 are general purpose terminals to be used for various purposes other than the above services, wherein the PC 16 is a PC privately owned by a staff in the local government, the PC 17 is a PC connected to the service network in local government 100 and accessed for utilizing the LAN network from an outside through a public network.
Connected to the service network in local government 100 is a basic resident register network 200 that is connected to a highly secured virtually dedicated line network for the basic resident register network by way of a router, a firewall (F/W) and a hub (HUB).
Incidentally, in such system, since sufficient countermeasures for security are not provided at the junction between the service network in local government and the basic resident register network, there is a possibility where a hacker may gain access through internet from outside to the service network in local government that is connected to internet.
It is general in a conventional system that private information data are stored in a hard disc installed in a PC or a disc (or discs) that is connected to such PC. If anyone may get in the service network in local government through internet, there is a risk that the hard disc installed in such PC or such disc (or discs) connected thereto are accessed by him/her. As a result, there is a possibility where private information as stored in the hard disc may be read out and leaked to outside.
It is also true that PCs connected to the service network in local government are not limited to PCs essentially dedicated to respective services but some other general purpose PCs including private PCs 16 may also be connected thereto for convenience reasons as mentioned hereinabove. It is general that special attentions to security are paid in the PCs designed for particular purposes but no or less attention is paid to other general purpose PCs such as the PCs 15A, 15B and 16, thereby increasing a risk to be a target for an ill-willed third party or a hacker. There encounters the same problem when gaining access from outside using the PC 17.
In accordance with the particular embodiment of the present invention, in order to prevent leakage of private information even if accessed through internet, an optical disc (referred to as an intelligent disc or i-DISC below) 1A, 1B that is detachable to any PC is used as a storage medium rather than a disc built-in a PC. An optical disc is advantages over any other type of storage media because of significantly low cost, large storage capacity and friendly to environment when disposing. The intelligent disc 1A is not integrated with a drive and is used with a PC by loading in a drive mechanism equipped within the PC. The intelligent disc 1B is an integrated intelligent disc including an integrated drive as access means to the disc.
Different from conventional optical discs, the intelligent disc contains information such as private information or the like stored therein as well as a storage or memory portion for memorizing predetermined application programs for controlling the operation of the PC in which the optical disc is loaded. Eventually, the control means is to control the operation of the PC which acts as an external device and to which the optical disc is loaded. That is, an application program (security) for prohibiting any access to read/write the information stored in the optical disc is memorized for each optical disc. Such program may be one for encrypting the information data at the time of storing in the storage portion in the optical disc (including encryption key and the like) and one for controlling access itself to the optical disc. Information including confidential information such as private information or the like is stored in the intelligent disc and also the processed information data is also stored in such intelligent disc. As a result, even if a hacker may attempt to enter the system through internet, he/she is successful to enter only the PC but is prevented from entering the intelligent disc, thereby maintaining security.
In
On the contrary, the embodiment of the present invention as shown in
In other words, according to the present invention, the contents (the data such as private information and the like stored in the intelligent disc 1) and the security programs stored in the same intelligent disc 1 cooperate with each other and the operation modes differ from disc to another disc, thereby enabling the intelligent disc to provide very high degree of security by itself. As a result, even if the hard ware such as the PC has no security system such as a firewall, an anti-virus program or the like installed in it, the intelligent disc 1 itself is able to protect the contents, thereby providing unique and significant security as compared to a conventional system.
A simple security program to be installed in the intelligent disc is an electronic circuit provided with an identification code for enabling to mutually identify itself and a PC as an external device. It is possible to encrypt the information data stored in the intelligent disc so that the encrypted data can not be read out without the key information. It is also possible to set a special security program.
In the foregoing description on the above embodiment, the intelligent disc 1 comprises a disc main body and access is made by a drive that is provided at the PC side. However, it is also possible to provide an intelligent disc unit by integrating a disc as shown in
Now, referring again to
In order to further enhance security, the particular embodiment controls the use of the intelligent disc or the intelligent disc unit. A description will be made hereunder about an example of controlling the intelligent disc itself.
A plurality of intelligent discs to be used in a local government service network are controlled all together at a predetermined storage location. Access to such storage location is strictly controlled so that only authorized persons can get in and out of such location and get-ins/get-outs to and from such location are recorded.
A large number of intelligent discs are stored in a locked storage case and only persons who are registered in advance are permitted to take out such discs. They must be identified before taking out any one of such discs. The identification is carried out by identification means provided in the storage case and they are permitted to take out any intelligent disc from the storage case only if they pass the identification. It is also possible to provide identification means in the intelligent disc itself so that it cannot be taken out unless they pass the identification. Any identification means including biometric identification such as fingerprints or the like, ID card or the like maybe used for identifying individuals. In case of failure in identification, it is possible to generate a warning.
If a person in charge who is permitted to take out any intelligent disc is appointed, more strict control of the intelligent discs can be made for improving security. That is, before starting the service, a person in charge takes out the necessary intelligent discs after identifying himself/herself and passes such discs to respective persons in a department or a section so that they can commence the services. At this time, it is also possible that the intelligent discs are provided with identification means for performing identification of the individual persons who engage in the services.
Preferably, the storage case is provided with a display portion such as a liquid crystal display or the like so that the name of the identified person, the name given to the intelligent disc, a warning on the occasion of failure in identification and the like may be displayed thereon.
Also, in the embodiment as shown in
Although the intelligent disc is described as an optical disc in the above embodiment, it is of course possible to hold the disc in a cartridge. In this case, various functions may be installed in the cartridge. For example, a wireless communication section for making wireless communication, an identification section, a display section, an audio output section (speaker) and the like as well as a battery section (preferably a rechargeable battery) for these functional sections may be installed in or on the cartridge. Wireless communication of the wireless section is utilized for controlling the location of the cartridges (or the intelligent discs) so that a warning is generated when any intelligent disc is brought out of the predetermined area (or the service room) or notifies the situation to a security center by way or a wireless communication network. Similarly, if any person who tries to take out the cartridge is determined to be not one of the registered persons who are permitted to use it (NG in identification process) by the identification section installed on the cartridge, it is possible to generate a warning or to notify to the security center. Such arrangement contributes to more reliable control and prevention of larger scale damages. Although the cartridge can store the intelligent disc, by adopting a flexible design to put in or take out such intelligent disc, it is possible to share the relatively expensive cartridge for storing a desired intelligent disc according to the need. In other words, an intelligent disc is fixedly stored in a cartridge in an expensive system, while a cartridge can be commonly used for plural intelligent discs in a multipurpose system.
In another embodiment of the present invention, since the antenna section 106 for making a weak wireless communication is on the intelligent disc side as shown in
Although the above description is made on the assumption that a hacker tries to enter the PC through internet, it is to be noted that the present invention should not necessarily be restricted to such particular case but is applicable to any case of preventing a hacker from trying to get access to and reading out the data stored in the storage medium connected to a PC by way of the PC operation. Additionally, the storage medium should not be limited to an optical disc but may be any storage medium having the similar construction.
Although preferred embodiments of the present invention have been described hereinabove, such embodiments are nothing but examples of the present invention and it is of course possible to make various modifications and alternations depending on particular applications.
Number | Date | Country | Kind |
---|---|---|---|
2003-352110 | Oct 2003 | JP | national |
Filing Document | Filing Date | Country | Kind | 371c Date |
---|---|---|---|---|
PCT/JP2004/015199 | 10/7/2004 | WO | 00 | 1/17/2008 |