System, method executed by system, and program
The system uses a trusted execution environment with pseudonymization and probabilistic encryption to convert sensitive information into secure forms, preventing re-identification and reducing computational burdens, enabling efficient analysis of sensitive data.
Patent Information
- Application Number
- JP2024039625
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-14
- Publication Date
- 2025-09-29
AI Technical Summary
Existing methods for anonymizing or pseudonymizing sensitive information, such as customer IDs, are insufficient to prevent re-identification by unauthorized parties, and they incur excessive computational resource consumption and management burdens as the number of entities increases.
A system utilizing a trusted execution environment (TEE) with pseudonymization and probabilistic encryption processes converts sensitive information into pseudonymized and encrypted form, using random numbers to generate secure sensitive information, which is then decrypted and analyzed by a data analysis platform without revealing the original content.
This approach effectively prevents re-identification of sensitive information while allowing analysis, reducing computational overhead and simplifying key management, thus maintaining confidentiality and efficiency.
Smart Images

Figure 2025140305000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a technology for analyzing information associated with sensitive information, such as identification information (e.g., customer ID) for identifying an individual, group, or organization, while concealing the sensitive information that should be prevented from leaking to third parties. [Background technology]
[0002] Analysis of information associated with sensitive information that should be prevented from being leaked to third parties, such as identification information (e.g., customer ID) for identifying individuals, groups, or organizations, is sometimes conducted. When analyzing this information, it is essential to prevent the sensitive information from being leaked to third parties who do not have access rights. Measures to prevent the leakage of sensitive information include, for example, anonymizing or pseudonymizing the sensitive information.
[0003] Patent Document 1 discloses prior art for anonymizing sensitive information. Patent Document 1 also discloses a security management system that performs analysis using data from multiple entities. The security management system of Patent Document 1 has individual trusted execution environments (TEEs) corresponding to each of the entities and a common trusted execution environment (TEE). Each individual trusted execution environment (TEE) anonymizes data from the entity corresponding to the TEE. The common trusted execution environment (TEE) performs analysis using the anonymized data obtained from each of the individual trusted execution environments (TEE). [Prior art documents] [Patent documents]
[0004] [Patent Document 1] US Patent Application Publication No. 2023 / 0022539 Summary of the Invention [Problem to be solved by the invention]
[0005] Even if sensitive information is anonymized or pseudonymized and becomes anonymized sensitive information or pseudonymized sensitive information, there is still a risk that a third party who does not originally have access authority can identify the content of the sensitive information based on the anonymized or pseudonymized sensitive information. For example, by referencing one or more information sources (e.g., tables) in which the anonymized or pseudonymized sensitive information is recorded in association with information other than the sensitive information, the value of the sensitive information before the anonymization or pseudonymization process may be inferred (re-identified). In other words, it is difficult to say that merely anonymizing or pseudonymizing sensitive information is a sufficient measure to prevent the leakage of sensitive information.
[0006] The prior art disclosed in Patent Document 1 involves anonymizing data from entities and then performing data analysis using the anonymized data. However, as already pointed out, there is a risk that the value of the data before anonymization (which may include sensitive information) may be inferred (re-identified). In the prior art disclosed in Patent Document 1, as the number of entities providing data increases, the number of individual trusted execution environments (TEEs) and the number of parameters used in the anonymization process also increase. Therefore, as the number of entities increases, the prior art disclosed in Patent Document 1 consumes more computational resources and also imposes a heavier management burden.
[0007] In light of the above, one of the purposes of the present disclosure may be to ensure that when analyzing information associated with sensitive information, the sensitive information is kept confidential while the information is analyzed, so as to reduce the possibility that the value of the sensitive information will be inferred (re-identified) by a third party who does not originally have access rights. [Means for solving the problem]
[0008] In order to achieve at least one of the above objects, the present disclosure may have the following features, for example. One aspect of the present disclosure is a system. The system includes a trusted execution environment unit and a data analysis platform unit. The trusted execution environment unit includes a pseudonymization unit and a trusted execution environment probabilistic encryption unit. The pseudonymization unit converts sensitive information in data including a portion of sensitive information and a portion of information other than the sensitive information into pseudonym information associated with the sensitive information. The trusted execution environment probabilistic encryption unit performs an encryption process on a combination of a random number and the pseudonym information to generate secure sensitive information. The data analysis platform unit includes an data analysis platform probabilistic decryption unit and a data analysis unit. The data analysis unit performs a decryption process on the secure sensitive information to generate pseudonym information. The data analysis unit performs analysis on the data using one or both of the pseudonym information generated by the data analysis platform probabilistic decryption unit and the portion of information other than the sensitive information. [Effects of the Invention]
[0009] As described above, the present disclosure generates secure sensitive information by converting sensitive information into pseudonymized information in a trusted execution environment (TEE) through a pseudonymization process and then encrypting the combination of a random number and the pseudonymized information. (Because the encryption process uses random numbers, it can be considered a type of probabilistic encryption process.) Because random numbers are used in the encryption process, even if the value of the pseudonymized information (sensitive information) is the same, the value of the secure sensitive information can be made different for each encryption process. In other words, it is extremely difficult to estimate (re-identify) the value of the sensitive information before the pseudonymization process and the probabilistic encryption process were performed based on the secure sensitive information. Therefore, even if the secure sensitive information is stored outside the trusted execution environment (TEE), it is unlikely to be subject to computer security threats.
[0010] Furthermore, in the present disclosure, a data analysis platform unit (DAP unit) decrypts secure sensitive information to generate pseudonymized information, and then performs analysis using either or both of the pseudonymized information and information other than the sensitive information (associated with the sensitive information).Since there is a roughly one-to-one correspondence between the value of the sensitive information and the value of the pseudonymized information, data analysis using the pseudonymized information is possible even when the content of the sensitive information itself is unknown.
[0011] As a result of the above, the present disclosure enables analysis of information associated with sensitive information while keeping the sensitive information confidential, so as to reduce the possibility that the value of the sensitive information will be inferred (re-identified) by a third party who does not originally have access rights.
[0012] Methods and programs that achieve the same processing as the above system can also achieve the same effects as the above system. In the form of a program, costs can often be reduced. Programs also make it easier to make design changes to the processing. Other features that the present disclosure may have and the effects corresponding to those features will be disclosed in this specification, claims, or drawings. [Brief explanation of the drawings]
[0013] [Figure 1] 1 illustrates a basic functional configuration of an embodiment of the present disclosure. [Figure 2] An example of two-layer encryption for sensitive information is shown below. [Figure 3] 1 shows an overall configuration including an embodiment of the present disclosure. [Figure 4] 1 illustrates a computer architecture for implementing embodiments of the present disclosure. [Figure 5] 1 shows a flow diagram of a process performed by an embodiment of the present disclosure. [Figure 6] The detailed functional configuration of the external system is shown below. [Figure 7] 1 shows a detailed functional configuration of the trusted execution environment unit. [Figure 8] The detailed functional configuration of the data analysis platform is shown below. [Figure 9] The detailed functional configuration of the data analysis platform is shown below. [Figure 10] 1 shows the data structure of a database in an example of power consumption analysis. [Figure 11] 10 shows a customer information table in an example of power consumption analysis. [Figure 12] 10 shows an edge device information table in an example of power consumption analysis. [Figure 13] 10 shows an edge device data table for an example of power consumption analysis. [Figure 14] 1 shows a power plan table in an example of power consumption analysis. [Figure 15] 1 shows a retailer recommendation table for an example of power consumption analysis. [Figure 16] 10 shows an execution command table in an example of power consumption analysis. [Figure 17] An example of a dashboard display is shown below. [Figure 18] 10 shows an example of a key management screen display on the dashboard. [Figure 19] 10 shows an example of a database management screen display on the dashboard. [Figure 20] 10 shows an example of a data analysis report screen display on a dashboard. DETAILED DESCRIPTION OF THE INVENTION
[0014] Embodiments of the present disclosure will be described in detail below with reference to the drawings. Note that the embodiments described below do not limit the disclosure according to the claims, and not all of the elements and combinations thereof described in the embodiments are necessarily essential to the solutions of the present disclosure. The following description and drawings are examples for explaining the present disclosure, and appropriate omissions and simplifications have been made for clarity of explanation. The present disclosure can be implemented in various other forms. Unless otherwise specified, each component may be singular or plural. The position, size, shape, range, etc. of each component shown in the drawings may not represent the actual position, size, shape, range, etc., in order to facilitate understanding of the invention. Therefore, the present disclosure is not necessarily limited to the position, size, shape, range, etc. disclosed in the drawings. Each of the systems, devices, or functional units disclosed herein may be integrated into a single piece of hardware, or may be divided into multiple parts that work together to perform their functions. Several systems, devices, or functional units may be integrated into one hardware configuration. Each of the systems, devices, or functional units may be realized by causing a computer to execute software (programs) (as in FIG. 4). Some of the functions of the system, device, or functional unit may be realized by hardware (e.g., hardwired logic or a field programmable gate array (FPGA)), and the remaining functions may be realized by executing software (programs). All of the functions of each of the systems, devices, or functional units may be realized by hardware. Some or all of the steps shown in the flow charts, etc. described in this disclosure may be realized by hardware. One or more systems, devices, or functional units of the present disclosure may be realized using one or more hardware resources. For this purpose, each of the systems, devices, or functional units of the present disclosure may be realized virtually. For example, a virtual computer or container technique may be used. The program of the present disclosure may be included in the general concept of software that encompasses software in which software and hardware resources cooperate to construct a specific information processing system (system) or its operating method according to the intended use. In other words, the program of the present disclosure is not limited to a specific type or form of program. Furthermore, the program may be initially recorded in a compressed format. The same reference numbers are used in multiple drawings and are similar to each other. In the drawing showing the flow diagram (FIG. 5), rectangular boxes with step numbers indicate processing steps. In the drawing showing the flow diagram (FIG. 5), "step" is abbreviated as "S." Also, the display or output modes shown in the drawings (FIGS. 17, 18, 19, and 20) are merely examples. Within the scope of the present disclosure, the display or output modes may differ from those shown in the drawings.
[0015] 1. Basic functional configuration (Fig. 1, Fig. 2) FIG. 1 shows a basic functional configuration 100 (and the information handled) of a system according to an embodiment of the present disclosure. Note that not all functional configurations shown in FIG. 1 are required. Furthermore, functional configurations other than those shown in FIG. 1 may also exist. In FIG. 1, the "units" are functional units. These functional units may be realized by executing a program that describes the processing to be performed by the functional units. Alternatively, these functional units may be realized by hardware. In FIG. 1, items enclosed in dotted lines indicate some kind of information (data).
[0016] A system 101 according to an embodiment of the present disclosure includes a trusted execution environment unit 102 (Trusted Execution Environment (TEE) unit) and a data analysis platform unit 103 (Data Analysis Platform (DAP) unit). The trusted execution environment unit 102 (TEE unit) includes, as internal functional units, a pseudonymization processing unit 123 and a trusted execution environment probabilistic encryption processing unit 124 (TEE probabilistic encryption processing unit). The data analysis platform unit 103 (DAP unit) includes, as internal functional units, a data analysis platform probabilistic decryption unit 132 (DAP probabilistic decryption unit) and a data analysis unit 133. The system 101 according to an embodiment of the present disclosure may include a single trusted execution environment unit 102 (TEE unit) regardless of the value of the sensitive information 161 (customer ID). Unlike the prior art disclosed in Patent Document 1, which includes an individual execution environment (TEE) corresponding to each entity, the embodiment of the present disclosure does not require an increase in the number of trusted execution environment units 102 (TEE units) even in cases where the sensitive information 161 (customer ID) can take on various values. Therefore, the system 101 according to an embodiment of the present disclosure can reduce the possibility of excessive costs and loads in terms of hardware or software.
[0017] The trusted execution environment unit 102 (TEE unit) may be, for example, composed of a storage area that is isolated and protected from other parts of the system 101, and resources such as a processor that are isolated and protected from other parts of the system 101. The trusted execution environment unit 102 (TEE unit) may use encryption technology or the like to achieve the above-mentioned isolation and protection. For example, data and information in the trusted execution environment unit 102 (TEE unit) may be protected so that they cannot be read or written from outside the trusted execution environment unit 102 (TEE unit). Known examples of hardware that can realize a trusted execution environment (TEE) include Intel's Software Guard Extensions (SGX) and Advanced Micro Devices' (AMD) Secure Encypted Virtualization-Secure Nested Paging (SEV-SNP). However, the trusted execution environment unit 102 (TEE unit) in the present disclosure is not limited to the above examples.
[0018] Data 160, which is the target of analysis in the present disclosure, may include a portion of sensitive information 161 and a portion of information other than sensitive information 162 (others). Sensitive information 161 is information (sensitive information) that should be prevented from leaking to a third party who does not have access rights. Sensitive information 161 may be, for example, identification information (e.g., customer ID) for identifying an individual, a group, or an organization. In the following, an example in which sensitive information 161 is identification information (customer ID) will be described. However, sensitive information 161 in the present disclosure is not limited to the example of identification information. While the sensitive information 161 is handled within the trusted execution environment unit 102 (TEE unit), there is a low possibility that the contents of the sensitive information 161 will be leaked to a third party. However, if the data 160 including the sensitive information 161 is recorded outside the trusted execution environment unit 102 (TEE unit), there is a high possibility that a security attack on the data 160 will occur from a third party who does not have access rights. Furthermore, if analysis of the data 160 including the sensitive information 161 is performed by the data analysis platform unit 103 (DAP unit) located outside the trusted execution environment unit 102 (TEE unit), although there is a relatively low possibility that a security attack on the inside of the data analysis platform unit 103 (DAP unit) will occur from a third party, it is often necessary for the data analysis platform unit 103 (DAP unit) itself to avoid directly knowing the contents of the sensitive information 161.
[0019] Therefore, in an embodiment of the present disclosure, within the trusted execution environment unit 102 (TEE unit), first, the tokenization processing unit 123 performs a tokenization process on sensitive information 161 (e.g., a customer ID) included in the data 160, thereby generating tokenized information 163 (pseudonym). The tokenization process performed by the tokenization processing unit 123 converts the sensitive information 161 (customer ID) into tokenized information 163 (pseudonym), which is information in a form in which the content of the sensitive information 161 cannot be known. Here, each time the tokenization process is performed, if the value of the sensitive information 161 (customer ID) before the tokenization process is the same, the value of the tokenized information 163 (pseudonym) after the tokenization process will also be the same. In this sense, the tokenization process may be called a deterministic process. When the pseudonymization processing unit 123 performs the pseudonymization process using a key, the same key (first key 791 shown in FIG. 5 or FIG. 7 described below) can be used regardless of the value of the sensitive information 161 (customer ID). In the prior art disclosed in Patent Document 1, an individual anonymization process is performed for each entity, and therefore parameters for the individual anonymization processes must be managed. However, in the embodiment of the present disclosure, the key for the pseudonymization process is one of the first keys 791, which simplifies key management. The pseudonymization process may be, for example, encryption processing using a common key cryptosystem. However, any method may be used for the pseudonymization process as long as it is capable of converting the sensitive information 161 (customer ID) into the pseudonym information 163 (pseudonym) by the above-mentioned deterministic (deterministic) processing and is capable of reverse conversion from the pseudonym information 163 (pseudonym) to the sensitive information 161 (customer ID). Although the pseudonym information 163 (pseudonym) is information in a form that prevents the content of the sensitive information 161 from being known, there is often a roughly one-to-one correspondence between the sensitive information 161 (customer ID) and the pseudonym information 163 (pseudonym). Therefore, when the pseudonym information 163 (pseudonym) is output outside the trusted execution environment unit 102 (TEE unit), for example, by referencing one or more information sources (e.g., tables) in which the pseudonym information 163 (pseudonym) and information other than the pseudonym information 163 (pseudonym) are associated and recorded, there is a risk that the value of the sensitive information 161 (customer ID) before the pseudonymization process may be inferred (re-identified). In other words, it is difficult to say that merely performing the pseudonymization process is sufficient as a measure to prevent the sensitive information 161 (customer ID) from being leaked.
[0020] Therefore, in an embodiment of the present disclosure, in the trusted execution environment unit 102 (TEE unit), the trusted execution environment probabilistic encryption unit 124 (TEE probabilistic encryption unit) performs encryption processing on a combination of a random number 164 and pseudonym information 163 (pseudonym) to generate secure sensitive information 165 (e.g., a secured ID). The TEE probabilistic encryption unit 124 may generate and use the random number 164 each time it performs encryption processing. In other words, even if the value of the pseudonym information 163 (pseudonym) is the same before encryption processing, the value of the random number 164 is different each time encryption processing is performed, and therefore the value of the secure sensitive information 165 (secured ID) obtained after encryption processing is different. In this sense, the encryption processing performed by the TEE probabilistic encryption unit 124 may be called a probabilistic (non-deterministic) processing (probabilistic encryption processing). Because random numbers 164 are used, the value of sensitive information 161 (customer ID) and the value of secure sensitive information 165 (secured ID) do not have a one-to-one correspondence. Therefore, the possibility that the value of sensitive information 161 (customer ID) will be correctly estimated based on secure sensitive information 165 (secured ID) is low. Therefore, even if secure sensitive information 165 (secured ID) is recorded outside the trusted execution environment unit 102 (TEE unit), it is unlikely that a third party who does not originally have access rights will correctly estimate (re-identify) the value of sensitive information 161 (customer ID) based on the content of secure sensitive information 165 (secured ID). The encryption process included in the probabilistic encryption process may be, for example, encryption process using a common key cryptosystem. However, any method may be used as the encryption process as long as it can convert the combination of the random number 164 and the pseudonym information 163 (pseudonym) into the secure sensitive information 165 (secured ID) and can reversely convert the secure sensitive information 165 (secured ID) back to the combination of the random number 164 and the pseudonym information 163 (pseudonym).
[0021] FIG. 2 shows an example of two-layer encryption for sensitive information 161 (customer ID), which is composed of the above-described pseudonymization process and probabilistic encryption process. FIG. 2 shows that when sensitive information 161 (customer ID) has the same value, "C2," the value of pseudonym information 163 (pseudonym) is also the same, "P2." Thereafter, when the probabilistic encryption process is performed, random number 164 is generated. FIG. 2 shows that although the value of pseudonym information 163 (pseudonym) is the same, "P2," different values, "006" and "009," are generated as random number 164 each time the probabilistic encryption process is performed. The encryption process is performed on the combination of pseudonym information 163 (pseudonym) and random number 164. FIG. 2 shows that as a result of encrypting the combination of "P2" and "006," secure sensitive information 165 (secured ID) of "asqqwf" is generated after the encryption process. 2 also shows that the combination of "P2" and "009" is encrypted, resulting in the generation of secure sensitive information 165 (secured ID) "gfdghf" after encryption processing. In this way, even if the value of sensitive information 161 (customer ID) is the same "C2," the secure sensitive information 165 (secured ID) can have different values, "asqqwf" and "gfdghf." In other words, it is difficult to correctly estimate (re-identify) sensitive information 161 (customer ID) from secure sensitive information 165 (secured ID).
[0022] Note that the intra-TEE probabilistic encryption processing unit 124 may use any method for combining the pseudonym information 163 (pseudonym) and the random number 164. For example, the intra-TEE probabilistic encryption processing unit 124 may concatenate the pseudonym information 163 (pseudonym) and the random number 164 and treat the concatenated result as the target of encryption processing. The intra-TEE probabilistic encryption processing unit 124 may also mix (interleave) the bit group included in the pseudonym information 163 (pseudonym) and the bit group included in the random number 164 (by swapping the order of the bits) and treat the mixed (interleaved) result as the target of encryption processing.
[0023] In the system 101 according to an embodiment of the present disclosure, analysis of the data 160 may be performed by a data analysis platform unit 103 (DAP unit) located outside the trusted execution environment unit 102 (TEE unit). By dividing the roles between the trusted execution environment unit 102 (TEE unit) and the data analysis platform unit 103 (DAP unit), the trusted execution environment unit 102 (TEE unit), which is to maintain a relatively high level of security, can be prevented from becoming bloated in terms of hardware or software. Furthermore, by dividing the roles between the TEE unit and the DAP unit, it becomes easier to use existing software resources for data analysis in an expanded form and to appropriately expand the functions of the data analysis platform unit 103 (DAP unit). In addition, it is possible to simplify the management of access rights by giving the DAP unit access rights to databases that record information derived from secure sensitive information 165 (secured ID) and information other than sensitive information 162 (others), such as database 104 shown in Figures 3 and 10 described below.
[0024] The combination of the secure sensitive information 165 (secured ID) provided by the trusted execution environment unit 102 (TEE unit) and the information other than the sensitive information 162 (others) is difficult to analyze in its original data form, because the correspondence between the sensitive information 161 (customer ID) and the secure sensitive information 165 (secured ID) is not one-to-one.
[0025] Therefore, within the data analysis platform unit 103 (DAP unit), the probabilistic decryption unit 132 within the data analysis platform (probabilistic decryption unit within the DAP) performs a decryption process on the secure sensitive information 165 (secured ID) and generates (restores) the pseudonym information 163 (pseudonym). For example, when encryption processing is performed in the intra-TEE probabilistic encryption processing unit 124 using a common key cryptosystem, the intra-DAP probabilistic decryption unit 132 also performs decryption processing using a common key cryptosystem. In this case, the intra-TEE probabilistic encryption processing unit 124 and the intra-DAP probabilistic decryption unit 132 use the same key (second key 792 shown in FIG. 5, FIG. 7, or FIG. 9, which will be described later). Here, the same key can be used as the second key 792 regardless of the value of the sensitive information 161. In the prior art disclosed in the aforementioned Patent Document 1, an individual anonymization process is performed for each entity, and therefore it is necessary to manage parameters for each individual anonymization process. However, in the embodiment of the present disclosure, the key for the probabilistic encryption process and the probabilistic decryption process can be used as one of the second keys 792, thereby simplifying key management.
[0026] After the pseudonym information 163 (pseudonym) is generated (restored), the data analysis unit 133 in the data analysis platform unit 103 (DAP unit) analyzes the data 160 using one or both of the pseudonym information 163 (pseudonym) generated (restored) by the in-DAP probabilistic decryption unit 132 and the information other than sensitive information 162 (others). As already pointed out, there is a roughly one-to-one correspondence between sensitive information 161 (customer ID) and pseudonym information 163 (pseudonym). Therefore, the data analysis unit 133 can analyze the information other than sensitive information 162 while associating it with the pseudonym information 163 (pseudonym) without knowing the content of the sensitive information 161 (customer ID) itself. In other words, the data analysis unit 133 can essentially analyze data for each sensitive information 161 (customer ID).
[0027] The system 101 according to the embodiment of the present disclosure has the above-described functional configuration, and therefore can have the effects described in the above-described [Effects of the Invention].
[0028] 2. Overall configuration including the embodiment of the present disclosure (FIG. 3) FIG. 3 shows an overall configuration 300 including a system 101 according to an embodiment of the present disclosure. Note that not all of the functional configurations shown in FIG. 3 are essential. Furthermore, functional configurations other than those shown in FIG. 3 may also exist. In FIG. 3, the "units" refer to functional units. These functional units may be realized by executing a program that describes the processing to be performed by the functional units. Alternatively, these functional units may be realized by hardware.
[0029] 3, the system 101 according to an embodiment of the present disclosure may be capable of communicating with one or both of an external system 301 and a retailer external system 305 via some means of communication (for example, a network 306 shown in FIG. 3). In a case where the sensitive information 161 indicates identification information, the external system 301 may be, for example, a system used for an individual, group, or organization indicated by the identification information (customer ID) that is the sensitive information 161. The retailer external system 305 may be, for example, a system used for an individual, group, or organization (for example, a retailer) that performs business for the individual, group, or organization indicated by the identification information (customer ID) that is the sensitive information 161. 3, data 160 including a portion of sensitive information 161 and a portion of non-sensitive information 162 is transmitted (encrypted) from external system 301 to system 101. System 101 analyzes data 160 (after decryption processing) and generates analysis result related information (which may be analysis result related information 904 (ar / re / co) in FIGS. 9 and 10 described below, analysis result information 901 (ar), recommended content information 902 (re), command information 903 (co), information included in power plan table 144 in FIG. 14, information included in retailer recommendation table 145 in FIG. 15, or information included in execution command table 146 in FIG. 16). Analysis result related information is transmitted (encrypted) from system 101 to either or both of external system 301 and retailer external system 305.
[0030] The system 101 may include a database 104 in addition to the trusted execution environment unit 102 (TEE unit) and the data analysis platform unit 103 (DAP unit) described in FIG. 1. The system 101 may also include a database management unit 105 that includes a dashboard display control unit 151. The database 104 may record, for example, information derived from sensitive information 161 (customer ID) and information other than sensitive information 162 (others). The database 104 may be, for example, as shown in FIG. 10, FIG. 11, FIG. 12, FIG. 13, FIG. 14, FIG. 15, or FIG. 16, which will be described later. 3, a data analysis platform unit (DAP unit) may be interposed between the trusted execution environment unit 102 (TEE unit) and the database 104. In such a configuration, it is possible to simplify management of access rights to the database 104. Alternatively, the trusted execution environment unit 102 (TEE unit) may be configured to directly access the database 104. 3, the database management unit 105 may be capable of directly accessing the database 104 and exchanging data and information with the data analysis platform unit 103 (DAP unit). Note that the database management unit 105 may be integrated with the data analysis platform unit 103 (DAP unit). Dashboard display control unit 151 in database management unit 105 controls the display or output of data and information recorded in database 104. Dashboard display control unit 151 may also receive an instruction to edit (add, change, or delete) data and information recorded in database 104, and edit database 104 in accordance with the instruction. The form of dashboard 1700 or the like displayed under the control of dashboard display control unit 151 may be, for example, as shown in FIG. 17, FIG. 18, FIG. 19, or FIG. 20, which will be described later.
[0031] The external system 301 may include one or more edge devices 302, one or more building energy management systems (BEMS) or factory energy management systems (FEMS) 303 (BEMS / FEMS), or both. The external system 301 includes an external system control unit 304. The edge device 302 and the BEMS / FEMS 303 generate data and information to be included in the data 160 and provide the generated data and information to the external system control unit 304. Based on the provided data and information, the external system control unit 304 organizes the data and information into the form of data 160, performs encryption processing, and transmits the encrypted data 160 to the system 101. When the external system control unit 304 receives the encrypted analysis result related information from the system 101, it restores the analysis result related information by decryption processing. The external system control unit 304 presents the restored analysis result related information to the edge device 302 or the BEMS / FEMS 303 as appropriate. The edge device 302 or the BEMS / FEMS 303 performs control based on the presented analysis result related information.
[0032] Alternatively, the analysis result related information sent from the system 101 may be received by the retailer external system 305. The retailer external system 305 can use the received analysis result related information to perform a transaction for an individual, group, or organization using the external system 301 in the capacity of a retailer.
[0033] 3. Computer Architecture for Implementing Embodiments of the Present Disclosure (FIG. 4) FIG. 4 illustrates a computer architecture 400 for implementing the system 101 of an embodiment of the present disclosure. To realize the system 101, some or all of the information processing device 401, storage device 402, non-volatile storage medium (storage device) 403, external storage medium drive 404, input device 406, display or output device 407, communication device 408, external input / output port 409, and reading device 410 may be interconnected via an interconnection unit 411. (Note that some or all of the interconnection unit 411 may be a network. In that case, the system 101 is realized by a plurality of devices connected via the network.) The information processing device 401 may be, for example, a processor. Examples of this processor include a CPU, an MPU, or a GPU. Alternatively, the processor referred to here may be another semiconductor device that executes a predetermined process. The information processing device 401 may also be one or more (micro)processors. The storage device 402 may be, for example, a memory. The non-volatile recording medium (storage device) 403 may be, for example, a non-volatile memory (e.g., a flash memory) or a non-volatile disk device. The external recording medium drive 404 may be, for example, a disk drive. The input device 406 may be, for example, a mouse, a keyboard, an imaging device, a sensor, a touch panel, or a pointing device. The display or output device 407 may be, for example, a display, a printer, or a speaker. The communication device 408 may be, for example, a communication device for wired communication or a communication device for wireless communication. The communication device 408 may be, for example, a network interface device (NIC) that controls communication with other systems, devices, terminals, or servers according to a predetermined protocol. The interconnection unit 411 may be, for example, a bus or a crossbar switch. (As mentioned above, some or all of interconnection unit 411 may be a network.)
[0034] The non-volatile recording medium (recording device) 403 may record various programs included in the program group 431 (for example, programs for realizing the functional configuration related to the present disclosure; for example, various programs for implementing each of the functional units realized in the system 101), various data groups included in the data group 432, or various information 433. The program group 431 may include various programs for realizing each of the functional units indicated as "units" in the functional configuration diagrams of Figures 1, 3, 6, 7, 8, and 9. Some of the above programs may be integrated into one program. Also, any of the above programs may be divided into multiple programs. The data group 432 may include information (data, etc.) handled by the above functional units. Alternatively, some or all of the various programs included in the program group 431, the various data groups included in the data group 432, or the information included in the various information 433 may be obtained from outside the configuration shown in FIG. 4.
[0035] The external recording medium drive 404 can be connected to an external recording medium 405. The external recording medium 405 may be, for example, a portable recording disk (such as a DVD), an IC card, an SD card, a nonvolatile memory (such as a flash memory), or a portable hard disk. Various programs included in the program group 431, various data included in the data group 432, or information similar to the information included in the various information 433 may be transferred and stored from the external recording medium 405 to the nonvolatile recording medium (recording device) 403 or the storage device 402. The external recording medium 405 may be used to record programs and data handled in the system 101. The external recording medium drive 404 and the external recording medium 405 may be connected to the system 101 shown in FIG. 4 via a network. The various programs included in the program group 431, the various data included in the data group 432, or the information included in the various information 433 may be brought via the communication device 408, the external input / output port 409, the input device 406, or the reading device 410, and recorded or stored in the non-volatile recording medium (recording device) 403 or the storage device 402.
[0036] In order for the architecture of FIG. 4 to function as the system 101, each functional unit within the system 101, or a part of each functional unit (to execute one or a series of processes (steps)), various programs included in the program group 431 may be loaded into the storage device 402 (for example, from the non-volatile recording medium (recording device) 403). The loaded program is indicated by 421 in FIG. 4. The information processing device 401 may then execute the program 421 (using, as necessary, various data and the like included in the data group 432 stored in the non-volatile recording medium (recording device) 403, or information included in the various information 433). Execution of the program 421 realizes the function of the system 101, each functional unit within the system 101, or a part of each functional unit (to execute one or a series of processes (steps)). At this time, various buffers 423 temporarily formed in the storage device 402 may also be used as appropriate.
[0037] 4. Processing performed by the embodiment of the present disclosure The following describes processing performed by an embodiment of the present disclosure. It is not necessary to realize all of the functional configurations and perform all of the processing described below. Furthermore, it is not prohibited to realize functional configurations and perform processing other than the functional configurations and processing described below. In the following, first, the processing steps in FIG. 5, which shows a processing flow diagram, will be described in order. In describing the processing steps, reference will be made as appropriate to FIG. 6, FIG. 7, FIG. 8, or FIG. 9, which shows detailed functional configurations included in the overall configuration showing an embodiment of the present disclosure. In FIG. 6, FIG. 7, FIG. 8, or FIG. 9, elements enclosed in solid lines and having the word "unit" in their names are functional units. Each functional unit may be realized by executing a program, or may be realized by hardware. In FIG. 6, FIG. 7, FIG. 8, or FIG. 9, elements enclosed in dotted lines indicate some kind of information (data). Next, a case of power consumption analysis will be described as an example to which the embodiments of the present disclosure are applied. In the description of the case of power consumption analysis, mainly FIG. 10, FIG. 11, FIG. 12, FIG. 13, FIG. 14, FIG. 15, or FIG. 16 will be appropriately referenced. Next, a dashboard that is displayed for an administrator or the like to view or edit information handled in an embodiment of the present disclosure will be described. In the description of the dashboard, Figures 17, 18, 19, and 20 are primarily referenced as appropriate. Note that a portion of the description of the dashboard uses an example of power consumption analysis.
[0038] 4.1. Flowchart showing the series of processes and detailed functional configuration (Figs. 5-9) Fig. 5 is a flow diagram showing a series of processes realized by the trusted execution environment unit 102 (TEE unit), the data analysis platform unit 103 (DAP unit), and the database 104 in the system 101 according to an embodiment of the present disclosure. Fig. 5 also shows processes in an edge device 302 in an external system 301, which is a provider of data 160 and one of the recipients of analysis result-related information relating to analysis of the data 160, a Building Energy Management System (BEMS) or a Factory Energy Management System (FEMS) 303 (referred to as "BEMS / FEMS" in Fig. 5), and a control unit 304 in the external system (referred to as "control unit" in Fig. 5).
[0039] 4.1.1. Data collection, encryption, and transmission in external systems (Figures 5 and 6) Steps 501 to 507 in Fig. 5 are executed by functional units and devices present in external system 301. A detailed functional configuration of external system 301 is shown in Fig. 6. Steps 501 to 507 in Fig. 5 will be described below with reference to Fig. 6. 5, the sensor data generator 321 in the edge device 302 generates sensor data 601. The sensor data generator 321 may generate the sensor data 601 based on, for example, measurement values obtained by a sensor provided in the edge device 302 measuring an object. 5, the sensor data providing unit 322 in the edge device 302 provides the sensor data 601 generated in step 501 to the external system control unit 304. The sensor data providing unit 322 may provide the sensor data 601 to the external system control unit 304 via, for example, a wired or wireless interconnection unit. 5, the BEMS / FEMS data generation unit 331 in the Building Energy Management System (BEMS) or Factory Energy Management System (FEMS) 303 (BEMS / FEMS) generates BEMS / FEMS data 602. The BEMS / FEMS data generation unit 331 may generate the BEMS / FEMS data 602 based on the results of measurements and acquired status information of devices and the like in the building or factory. 5, the BEMS / FEMS data providing unit 332 in the BEMS / FEMS 303 provides the BEMS / FEMS data 602 generated in step 503 to the external system control unit 304. The BEMS / FEMS data providing unit 332 may provide the BEMS / FEMS data 602 to the external system control unit 304 via, for example, a wired or wireless interconnection unit. One or both of steps 501 and 502 in which sensor data 601 is generated and submitted, and steps 503 and 504 in which BEMS / FEMS data 602 is generated and submitted, may be executed. If either the edge device 302 or the BEMS / FEMS 303 is not present in the external system 301, the step corresponding to the absent device is not executed. Also, even if both the edge device 302 and the BEMS / FEMS 303 are present in the external system 301, it is not necessary to always execute all of steps 501, 502, 503, and 504.
[0040] In step 505 of FIG. 5 , the various data collection unit 341 in the external system control unit 304 collects one or both of the sensor data 601 provided in step 502 and the BEMS / FEMS data 602 provided in step 504. The various data collection unit 341 creates data 160 based on one or both of the collected sensor data 601 and BEMS / FEMS data 602. This data 160 is the same as that described in FIG. 1 . The sensitive information 161 (customer ID) included in the created data 160 may be, for example, information identifying the external system 301 itself in which the various data collection unit 341 is included, or information identifying an individual, group, or organization (such as a customer) that uses the external system 301. The sensitive information 161 may also include other types of information. Information 162 (others) other than the sensitive information included in the created data 160 may be information reflecting one or both of the sensor data 601 and the BEMS / FEMS data 602.
[0041] 5, the various data encryption processing unit 342 in the external system control unit 304 performs encryption processing on the data 160 (customer ID and others) created in step 505 to generate encrypted data ((encrypted) customer ID and others). The various data encryption processing unit 342 may perform encryption processing using an individual key 691 used for the data 160 transmitted from the external system 301 to the system 101. If a common key cryptosystem is used for data transmitted and received from the external system 301 to the system 101, the individual key 691 may be different for each external system 301. By performing such encryption processing, it is possible to reduce the possibility that the contents of the data 160 will be discovered by a third party (including the external system 301 for a third party) other than the sending external system 301 and the receiving system 101. In step 507 of FIG. 5, the various data transmission unit 343 in the external system control unit 304 transmits the encrypted data generated by the encryption process in step 506 to the system 101 .
[0042] 4.1.2. Reception, Decryption, Pseudonymization, and Probabilistic Encryption in the TEE (Figures 5, 7, and 8) Steps 508 to 511 in Fig. 5 are executed by a functional unit that resides in the trusted execution environment unit 102 (TEE unit) in the system 101. A detailed functional configuration of the TEE unit 102 is shown in Fig. 7. Steps 508 to 511 in Fig. 5 will be described below with reference to Fig. 7. Additionally, step 512 executed by a functional unit in the data analysis platform unit 103 (DAP unit) and step 513 executed in the database 104 in response to step 511 will also be described with reference to Fig. 8. Fig. 8 shows the detailed functional configuration of the DAP unit related to step 512.
[0043] In step 508 of FIG. 5, the data receiving unit 121 in the TEE unit 102 receives the encrypted data ((encrypted) customer ID and others) sent from the external system 301. 5, the received data decryption processing unit 122 in the TEE unit 102 performs decryption processing on the encrypted data to restore the data 160 (customer ID and others). If a common key cryptosystem is used for data transmitted and received from the external system 301 to the system 101, the received data decryption processing unit 122 may perform decryption processing using an individual key 691 used for the data 160 transmitted from the external system 301 to the system 101. Here, the individual key used in the encryption process in step 506 may be the same as the individual key used in step 509. In other words, the encryption process in step 506 and the decryption process in step 509 may be a common key cryptosystem. The individual key 691 used in step 509 may be different for each external system 301 that is the sender of the encrypted data. The encryption process in step 506 and the decryption process in step 509 may be performed using a public key cryptosystem. That is, the encryption process in step 506 may be performed using a public key, and the decryption process in step 509 may be performed using a private key. As described above, the TEE unit 102 decrypts the encrypted data ((encrypted) customer ID and others) received from the external system 301, so the decrypted sensitive information 161 (customer ID) can be protected by the trusted execution environment (TEE). Furthermore, encrypted data is used in transmission and reception from the external system 301 to the system 101, which reduces the risk of data being intercepted.
[0044] 5, the tokenization processing unit 123 in the TEE unit 102 performs a tokenization process on the sensitive information 161 (customer ID) included in the data 160, thereby generating the tokenized information 163 (pseudonym). Details of the tokenization process have already been described with reference to FIG. 1. The tokenization processing unit 123 may perform the tokenization process using a first key 791. As described above, sensitive information 161 (customer ID) is converted into pseudonym information 163 (pseudonym) within TEE unit 102, which prevents sensitive information 161 (customer ID) from being output from TEE unit 102 to outside TEE unit 102. Furthermore, since sensitive information 161 (customer ID) and pseudonym information 163 (pseudonym) have a roughly one-to-one correspondence, once pseudonym information 163 (pseudonym) is generated, DAP unit 103 can use pseudonym information 163 (pseudonym) to perform data analysis similar to that performed when sensitive information 161 (customer ID) is used. Furthermore, regardless of the value of the sensitive information 161 (customer ID) (external system 301 that is the sender of data 160), the same value of the first key 791 may be used, which simplifies key management and also prevents a heavy load on the computational resources of the tokenization processing unit 123. 5, in step 511 (probabilistic encryption processing step), the trusted execution environment probabilistic encryption processing unit 124 in the TEE unit 102 (TEE probabilistic encryption processing unit) generates secure sensitive information 165 (secured ID) by performing probabilistic encryption processing on the pseudonym information 163 (pseudonym) generated in step 510. The probabilistic encryption processing has already been described using FIGS. 1 and 2. The TEE probabilistic encryption processing unit 124 may internally generate a random number 794, and then perform encryption processing on the random number 794 and the pseudonym information 163 (pseudonym) using a second key 792, thereby generating secure sensitive information 165 (secured ID). Because the random number 794 is used, the secure sensitive information 165 (secured ID) does not have a one-to-one correspondence with the sensitive information 161 (customer ID) and the pseudonym information 163 (pseudonym). This makes it difficult for a third party to infer the sensitive information 161 (customer ID) based on the secure sensitive information 165 (secured ID). Therefore, even if the secure sensitive information 165 (secured ID) is output to an external device (e.g., a database 104) outside the TEE unit 102, vulnerability in computer security is unlikely to occur. Furthermore, regardless of the value of the sensitive information 161 (customer ID) (external system 301 that is the sender of data 160), the same value of the second key 792 may be used, which simplifies key management and also prevents a heavy load on the computational resources of the probabilistic encryption processing unit 124 within the TEE.
[0045] The secure sensitive information 165 (secured ID) and the information other than the sensitive information 162 (others) generated in step 511 may be temporarily recorded in the database 104. In the case where the system 101 is configured such that the trusted execution environment unit 102 (TEE unit) is not given direct access to the database 104, the secure sensitive information 165 (secured ID) and the information other than the sensitive information 162 (others) may be passed from the execution environment unit 102 (TEE unit) to the data analysis platform unit 103 (DAP unit) in order to record this information in the database 104. 5, the database writing unit 131 (see FIG. 8) in the DAP unit 103 receives the secure sensitive information 165 (secured ID) and information 162 (others) other than the sensitive information from the TEE unit 102. Then, the database writing unit 131 requests the database 104 to record the secure sensitive information 165 (secured ID) and information 162 (others) other than the sensitive information. As described above, if the TEE unit 102 is not given direct access rights to the database 104 and the DAP unit 103 has direct access rights to the database 104, access rights management for the database 104 becomes simple. 5, the database 104 records the secure sensitive information 165 (secured ID) and the non-sensitive information 162 (others) that were the subject of the recording request in step 512. Recording of information in the database 104 may be, for example, recording of information in a table such as that shown in Figure 10, 11, 12, 13, 14, 15, or 16, which will be described later. Alternatively, information may be recorded in a manner different from the tables exemplified in these figures. Even if database 104 is relatively likely to be targeted as a computer security attack target by a third party without access rights, if secure sensitive information 165 (secured ID) is recorded instead of sensitive information 161 (customer ID) and pseudonym information 163 (pseudonym) as described above, it is less likely to cause computer security vulnerabilities.
[0046] 4.1.3. Probabilistic Decryption, Data Analysis, and Probabilistic Encryption in the DAP Section (Figures 5 and 9) Steps 515 to 517 in Fig. 5 are executed by a functional unit inherent in the trusted data analysis platform unit 103 (DAP unit) in the system 101. A detailed functional configuration of the DAP unit 103 is shown in Fig. 9. Steps 515 to 517 in Fig. 5 will be described below with reference to Fig. 9. Also described are step 514, which is performed in database 104 prior to step 515, and step 518, which is performed in database 104 in conjunction with step 517.
[0047] 5, the database 104 reads out one or both of the information to be subjected to data analysis, which is derived from the secure sensitive information 165 (secured ID) and the information other than the sensitive information 162 (others), and outputs it to the data analysis platform unit 103 (DAP unit). For example, in response to the DAP unit 103 specifying the information to be subjected to data analysis, the information to be subjected to data analysis may be output from the database 104. In step 515 (probabilistic decryption step) of FIG. 5, the data analysis platform probabilistic decryption unit 132 (DAP probabilistic decryption unit) in the DAP unit 103 receives one or both of the secure sensitive information 165 (secured ID) to be analyzed and information derived from information other than sensitive information 162 (others). The DAP probabilistic decryption unit 132 generates (restores) pseudonym information 163 (pseudonym) by performing a decryption process (decryption of probabilistic encryption) on the secure sensitive information 165 (secured ID). This decryption process (decryption of probabilistic encryption) has already been described using FIG. 1. The DAP probabilistic decryption unit 132 may perform the decryption process (decryption of probabilistic encryption) using a second key 792. Here, the second key used by the probabilistic encryption processing unit 124 in the TEE in the encryption process (probabilistic encryption process) in step 511 and the second key used by the probabilistic encryption decryption unit 132 in the DAP in the decryption process (decryption of probabilistic encryption) in step 515 may be of the same value. As described above, the DAP unit 103 restores the pseudonym information 163 (pseudonym) based on the secure sensitive information 165 (secured ID), so the DAP unit 103 can perform data analysis using the pseudonym information 163 (pseudonym) (which roughly corresponds one-to-one with the sensitive information 161 (customer ID)).
[0048] In step 516 (data analysis step) of Figure 5, the data analysis unit 133 in the DAP unit 103 performs data analysis using one or both of the pseudonym information 163 (pseudonym) generated (restored) in step 515 and information derived from information 162 (others) other than sensitive information read out as the subject of data analysis in step 514. The data analysis unit 133 in the DAP unit 103 may generate analysis result related information 904 (ar / re / co) as information related to the results of the data analysis. Even when pseudonym information 163 (pseudonym) is used instead of sensitive information 161 (customer ID) itself, it has already been explained using Figure 1 that analysis related to information derived from information 162 (others) other than sensitive information is possible.
[0049] 9 shows that the functional units within the data analysis unit 133 may include an analysis result generation unit 134, a recommended content generation unit 135, and a command generation unit 136, and that the information generated by the data analysis unit 133 may include analysis result information 901(ar), recommended content information 902(re), and command information 903(co). These functional units and information may be provided when the system 101 is constructed to correspond to the power consumption analysis examples shown in FIGS. 10, 11, 12, 13, 14, 15, or 16, which will be described later. When the system 101 is constructed to correspond to other types of examples, the internal configuration of the data analysis unit 133 may be different from that shown in FIG. 9. The analysis result generation unit 134 performs data analysis using one or both of the pseudonym information 163 (pseudonym) generated (restored) by the intra-DAP probabilistic decryption unit 132 and information derived from the information other than sensitive information 162 (others) read out as the target of data analysis in step 514. The analysis result generation unit 134 may generate, for example, analysis result information 901(ar) as a result of the data analysis. This analysis result information 901(ar) may be, for example, something like power consumption analysis result information 1506 that is to be recorded in the retailer recommendation table 145 in FIG. 15 (described later). The recommendation content generation unit 135 and the command generation unit 136 may use the analysis result information 901(ar) to generate information to be presented to the external system 301 or the retailer external system 305. The recommendation content generator 135 may generate recommendation content information 902(re) using the analysis result information 901(ar). The recommendation content information 902(re) may be information indicating recommended processes or actions to be performed by the external system 301 or by an individual, group, or organization (customer, etc.) that uses the external system 301. This recommendation content information 902(re) may be, for example, unit price information for time-of-day electricity rates recorded in a power plan table 144 in FIG. 14 (described later), or proposed power plan information 1504, proposed facility information 1505, or estimated savings information 1507 recorded in a retailer recommendation table 145 in FIG. 15 (described later). The command generation unit 136 may generate command information 903(co) using the analysis result information 901(ar). The command information 903(co) may be information indicating a command for controlling a device or the like included in the external system 301 (for example, an edge device 302, a Building Energy Management System (BEMS), or a Factory Energy Management System (FEMS) 303 (BEMS / FEMS)). This command information 903(co) may be, for example, a combination of a device ID 1603, an operation command 1605, and an operation reference 1606 recorded in an execution command table 146 in FIG. 16 , which will be described later. 9, analysis result related information 904 (ar / re / co) is formed by one or more of analysis result information 901 (ar), recommended content information 902 (re), and command information 903 (co). In the data analysis of step 516 in FIG. 5, the analysis result generation unit 134, the recommended content generation unit 135, and the command generation unit 136 execute processing to generate the analysis result related information 904 (ar / re / co). As described above, if data relating to the external system 301 or an individual, group, or organization (customer, etc.) that uses the external system 301 is analyzed, and information indicating recommended processes or actions to be taken by the external system 301 or the customer, etc., as well as information indicating commands for controlling devices, etc., possessed by the external system 301, is also generated, it will be possible to provide business value to the customer, etc., and to achieve appropriate control of the external system 301. For example, in the case of power consumption analysis described below, it is possible to provide business value related to power consumption to customers and the like, and to realize appropriate control of power consumption in the external system 301.
[0050] The generated analysis result related information 904 (ar / re / co) may be temporarily recorded together with the corresponding pseudonym information 163 (pseudonym) in the database 104. As already pointed out, recording the pseudonym information 163 (pseudonym) in the database 104 makes it vulnerable to computer security attacks by third parties who do not actually have access rights. Therefore, in step 517 of FIG. 5 , the data analysis platform probabilistic encryption processing unit 137 (DAP probabilistic encryption processing unit) in the DAP unit 103 performs probabilistic encryption processing on the pseudonym information 163 (pseudonym) corresponding to the analysis result related information 904 (ar / re / co) to be recorded in the database 104. Details of the probabilistic encryption processing are similar to the probabilistic encryption processing in the TEE probabilistic encryption processing unit 124. The DAP probabilistic encryption processing unit 137 may internally generate a random number 991 and perform encryption processing on a combination of the random number 991 and the pseudonym information 163 (pseudonym), thereby generating secure sensitive information 165 (secured ID). Here, the DAP probabilistic encryption processing unit 137 may perform encryption processing using a third key 793. The value of the third key 793 may be different from or the same as the value of the second key 792. Furthermore, the value of the secure sensitive information 165 (secured ID) generated by the DAP probabilistic encryption processing unit 137 will generally be different from the value of the secure sensitive information 165 (secured ID) output from the database 104 to the DAP probabilistic decryption unit 132. As described above, even when the analysis result related information 904 (ar / re / co) generated by the DAP unit 103 is written to the database 104, the DAP unit 103 generates secure sensitive information 165 (secured ID) based on the pseudonym information 163 (pseudonym), making it less likely to cause vulnerabilities in computer security. In step 518 of FIG. 5, the secure sensitive information 165 (secured ID) generated in step 517 and the analysis result related information 904 (ar / re / co) generated in step 516 may be recorded in the database 104. Since secure sensitive information 165 (secured ID) is recorded in database 104, rather than sensitive information 161 (customer ID) and pseudonym information 163 (pseudonym), vulnerability in computer security is less likely to occur.
[0051] 4.1.4 Probabilistic Decryption, Pseudonymization, Encryption, and Transmission in the TEE (Figures 5, 7, and 8) Steps 521 to 524 in Fig. 5 are executed by a functional unit that resides in the trusted execution environment unit 102 (TEE unit) in the system 101. A detailed functional configuration of the TEE unit 102 is shown in Fig. 7. Steps 521 to 524 in Fig. 5 will be described below with reference to Fig. 7. Additionally, step 519, which is executed in the database 104 prior to step 521, and step 520, which is executed by a functional unit within the data analysis platform unit 103 (DAP unit), will also be described with reference to Fig. 8. Fig. 8 shows the detailed functional configuration of the DAP unit related to step 520.
[0052] 5, the analysis result related information 904 (ar / re / co) to be presented to the external system 301 or the retailer external system 305, and the secure sensitive information 165 (secured ID) corresponding to the analysis result related information 904 (ar / re / co) are output from the database 104. The database reading unit 138 (see FIG. 8) in the data analysis platform unit 103 (DAP unit) specifies the analysis result related information 904 (ar / re / co) to be presented to the external system 301 or the retailer external system 305, and the secure sensitive information 165 (secured ID) corresponding to the analysis result related information 904 (ar / re / co), and the specified information is output from the database 104 in response to this. The database reading unit 138 passes the output secure sensitive information 165 (secured ID) and analysis result related information 904 (ar / re / co) to the trusted execution environment unit 102 (TEE unit). As described above, even when reading from the database 104, the TEE unit 102 is not given direct access to the database 104, and the DAP unit 103 has direct access to the database 104, which simplifies access right management for the database 104.
[0053] 5, the in-Trusted Execution Environment probabilistic decryption unit 125 (in-TEE probabilistic decryption unit) in the TEE unit 102 generates (restores) pseudonym information 163 (pseudonym) by performing a decryption process (decryption of probabilistic encryption) on secure sensitive information 165 (secured ID) corresponding to analysis result related information 904 (ar / re / co) to be presented to the external system 301 or the retailer external system 305. The decryption process (decryption of probabilistic encryption) performed by the in-TEE probabilistic decryption unit 125 may be similar to the decryption process (decryption of probabilistic encryption) performed by the in-DAP probabilistic decryption unit 132. The in-TEE probabilistic decryption unit 125 may perform the decryption process (decryption of probabilistic encryption) using a third key 793. Here, the third key used by the probabilistic encryption processing unit 137 in the DAP in the encryption process (probabilistic encryption process) in step 517 and the third key used by the probabilistic encryption decryption unit 125 in the TEE in the decryption process (decryption of probabilistic encryption) in step 521 may be of the same value. As described above, the pseudonym information 163 (pseudonym) is restored within the TEE unit 102 based on the secure sensitive information 165 (secured ID) generated by the DAP unit 103, so the pseudonym information 163 (pseudonym) is not exposed on the path from the DAP unit 103 to the TEE unit 102 or in the database 104, making it less likely that computer security vulnerabilities will occur.
[0054] 5, the de-pseudonymization unit 126 in the TEE unit 102 generates (restores) sensitive information 161 (customer ID) by de-pseudonymizing the pseudonym information 163 (pseudonym) generated (restored) in step 521. The de-pseudonymization unit 126 may perform de-pseudonymization using a first key 791. Here, the value of the first key used by the pseudonymization processing unit 123 for the pseudonymization process in step 510 may be the same as the value of the first key used by the de-pseudonymization unit 126 for de-pseudonymization in step 522. Since the sensitive information 161 (customer ID) is restored within the TEE unit 102 based on the pseudonym information 163 (pseudonym), there is little risk that the sensitive information 161 (customer ID) will be exposed to the outside of the TEE unit 102.
[0055] 5, the transmission data encryption processing unit 127 in the TEE unit 102 performs encryption processing on the sensitive information 161 (customer ID) and analysis result related information 904 (ar / re / co) generated (restored) in step 522, thereby generating encrypted sensitive information (customer ID) and analysis result related information 904 (ar / re / co). When a common key cryptosystem is used for data transmitted from the system 101, the transmission data encryption processing unit 127 may perform encryption processing using an individual key 692 for data transmitted from the system 101 to the external system 301 or retailer external system 305 that is the transmission destination. The individual key 692 may be different for each external system 301 or retailer external system 305 that is the transmission destination. The above shows a case where a symmetric key cryptosystem is applied to data transmitted and received from the system 101 to the external system 301 or the retailer external system 305, but a public key cryptosystem may also be applied to the transmitted and received data. In a case where a public key cryptosystem is applied, encryption processing using a public key is performed on the system 101 side, which is the sender, while decryption processing using a private key is performed on the external system 301 or the retailer external system 305 side, which is the destination. As described above, the sensitive information 161 (customer ID) and analysis result related information 904 (ar / re / co) transmitted from the system 101 are encrypted within the TEE unit 102, thereby reducing the risk of interception by a third party when transmitted from the system 101. In step 524 of Figure 5, the data transmission unit 128 in the TEE unit 102 transmits the encrypted sensitive information (customer ID) and analysis result related information 904 (ar / re / co) generated in step 523 to the destination external system 301 or retailer external system 305. As described above, the analysis result related information 904 (ar / re / co) can be transmitted not only to the external system 301 for customers, etc., but also to the retailer external system 305 for retailers, enabling flexible responses in businesses related to electricity supply (for example, Energy as a Service businesses).
[0056] 4.1.5. Reception, Decoding, and Presentation in External Systems (Figures 5 and 6) The encrypted sensitive information (customer ID) and analysis result related information 904 (ar / re / co) sent in step 524 can be received by either the external system 301 or the retailer external system 305. Below, the processing performed by the external system 301 will be described for an example in which the external system 301 receives the information. In addition, in the description, the detailed functional configuration of the external system 301 shown in FIG. 6 will be referred to as appropriate.
[0057] In step 525 of Figure 5, the analysis result related information receiving unit 344 in the control unit 304 in the external system receives the encrypted sensitive information (customer ID) and analysis result related information 904 (ar / re / co) sent in step 524. 5, the analysis result related information decryption processing unit 345 in the external system control unit 304 generates (restores) the sensitive information (customer ID) and analysis result related information 904 (ar / re / co) by performing a decryption process on the encrypted sensitive information (customer ID) and analysis result related information 904 (ar / re / co) received in step 525. If a common key cryptosystem is used for data transmitted from the system 101, the analysis result related information decryption processing unit 345 may perform the decryption process using an individual key 692. Here, (in the case where a common key cryptosystem is used for transmission and reception with the system 101) the individual key used for the encryption process by the transmission data encryption processing unit 127 in step 523 may be the same as the individual key used for the decryption process by the analysis result related information decryption processing unit 345 in step 526. In addition, the value of the individual key 691 used for transmission and the value of the individual key 692 used for reception may be the same or different in one external system 301. In a case where a public key cryptosystem is applied for transmission and reception with the system 101, encryption processing using a public key is performed on the system 101 side, which is the source of transmission, while decryption processing using a private key is performed on the external system 301 or retailer external system 305 side, which is the destination of transmission.
[0058] 5 , the analysis result related information presentation unit 346 in the external system control unit 304 presents control information to the edge device 302 or a Building Energy Management System (BEMS) or Factory Energy Management System (FEMS) 303 (BEMS / FEMS) based on the analysis result related information 904 (ar / re / co) generated (restored) in step 526. The analysis result related information presentation unit 346 may, for example, present command information 903(co) included in the analysis result related information 904 (ar / re / co) to the edge device 302 or the BEMS / FEMS 303. Alternatively, the analysis result related information presentation unit 346 may, for example, generate a control command based on the analysis result information 901(ar) and recommended content information 902(re) included in the analysis result related information 904 (ar / re / co), and then present the control command to the edge device 302 or the BEMS / FEMS 303. If control information (sensor control information 603) is presented to the edge device 302 in step 527, in step 528 of Figure 5, the sensor control unit 323 in the edge device 302 controls the sensors, etc. in the edge device 302 based on the sensor control information 603. When control information (PLC control information 604) is presented to BEMS / FEMS303 in step 527, in step 529 of Figure 5, the PLC control unit 333 in BEMS / FEMS303 controls a programmable logic controller (PLC) etc. included in BEMS / FEMS303 based on the PLC control information 604.
[0059] As described above, through the series of processes shown in the flow diagram of Fig. 5, the system 101 analyzes the data 160 based on information provided from the edge device 302 and BEMS / FEMS 303 in the external system 301. Then, based on the analysis result related information generated by the system 101, the edge device 302 and BEMS / FEMS 303 in the external system 301 are controlled. Here, it is extremely unlikely that the contents of the sensitive information 161 (customer ID) indicating the external system 301 or an individual, group, or organization using the external system 301 will be leaked to a third party.
[0060] In the flow diagram of FIG. 5 , the analysis result related information 904 (ar / re / co) generated by the system 101 is transmitted to the external system 301. Here, the destination of the analysis result related information 904 (ar / re / co) may be the retailer external system 305. The retailer external system 305 can use the received analysis result related information 904 (ar / re / co) for business purposes for the external system 301 and individuals, groups, or organizations (customers, etc.) using the external system 301. For example, if the analysis result related information 904 (ar / re / co) includes recommendation content information 902 (re), an individual, group, or organization (retailer) using the retailer external system 305 can make beneficial business proposals to individuals, groups, or organizations (customers, etc.) using the external system 301.
[0061] 5, the analysis result related information 904 (ar / re / co) generated by the system 101 is transmitted to the external system 301. The analysis result related information 904 (ar / re / co) is used as information for controlling devices and the like that the system 101 has (for example, the edge device 302, and devices such as PLCs that the BEMS / FEMS 303 has). Alternatively, or in addition to the above, the analysis result related information 904 (ar / re / co) may present beneficial business suggestions directly to the external system 301 or to individuals, groups or organizations (customers, etc.) that use the external system 301 (without going through a retailer).
[0062] 4-2. Examples of power consumption analysis (Figures 10-16) An example of using the system 101 according to an embodiment of the present disclosure for power consumption analysis is described below. In this example, the various data collection unit 341 in the external system 301 collects information about power consumption in the external system 301 and creates data 160 based on the collected information. The external system 301 transmits the data 160 to the system 101 (after performing necessary encryption processing).
[0063] The system 101 analyzes the received data 160 (after performing necessary decoding processing) and generates analysis result related information 904 (ar / re / co). Here, the analysis result related information 904 (ar / re / co) may include one or more of analysis result information 901 (ar), recommended content information 902 (re), and command information 903 (co). In this example, the analysis result information 901(ar) may be the power consumption analysis result information 1506, which is the subject of recording in the retailer recommendation table 145 of Fig. 15. As shown in the example of Fig. 15, the power consumption analysis result information 1506 may be the result of analyzing the mode of power consumption for each external system 301 (or for each individual, group, or organization (customer, etc.) that uses the external system 301). In this example, the recommended content information 902(re) may be information on the unit price of electricity for each time period, which is recorded in the power plan table 144 of Figure 14, or proposed power plan information 1504, proposed equipment information 1505, and estimated savings information 1507, which are recorded in the retailer recommendation table 145 of Figure 15. The information on the unit price of electricity for each time period recorded in the electricity plan table 144 of Figure 14 may be the unit price of electricity for each time period proposed by a power generator or a retailer that uses the retailer external system 305 to the external system 301 (or to each individual, group or organization (customer, etc.) that uses the external system 301), for each external system 301 (or for each individual, group or organization (customer, etc.) that uses the external system 301). The proposed electricity plan information 1504 and proposed equipment information 1505 recorded in the retailer recommendation table 145 of Figure 15 may indicate the electricity plan and equipment to be installed that a retailer, which is a power generator or an electricity retailer using the retailer external system 305, proposes to the external system 301 (or an individual, group, or organization (customer, etc.) using the external system 301) for each external system 301 (or for each customer, etc. using the external system 301). The estimated savings information 1507 recorded in the retailer recommendation table 145 of Figure 15 may indicate an estimated amount of savings on electricity bills if a proposal regarding electricity usage made by a power generator or a retailer that is a retailer of electricity using the retailer external system 305 is accepted by the external system 301 (or an individual, group, or organization (such as a customer) that uses the external system 301). In this example, the command information 903(co) may be a combination of a device ID 1603, an operation command 1605, and an operation reference 1606, which are targets to be recorded in the execution command table 146 of Fig. 16. The combination of the device ID 1603, the operation command 1605, and the operation reference 1606 may be for causing an apparatus (within the external system 301) indicated by the device ID 1603 (for example, the edge device 302, or a device such as a programmable logic controller (PLC) included in the BEMS / FEMS 303) to execute a command of the type indicated by the operation command 1605, and for setting parameters for the device as indicated by the operation reference 1606.
[0064] The system 101 transmits command information 903(co) from among the information that may be included in the analysis result related information 904(ar / re / co) to the external system 301. Upon receiving the command information 903(co), the external system 301 performs control based on the command information 903(co) on devices, etc., that the external system 301 has (for example, the edge device 302, or a device such as a programmable logic controller (PLC) that the BEMS / FEMS 303 has). Of the information that may be included in the analysis result related information 904 (ar / re / co), the system 101 may transmit the analysis result information 901 (ar) and the recommendation content information 902 (re) to either the external system 301 or the retailer external system 305. When the transmission destination is the external system 301, the external system 301 or an individual, group, or organization (customer, etc.) using the external system 301 can directly refer to and utilize the analysis result information 901 (ar) and the recommendation content information 902 (re). When the transmission destination is the retailer external system 305, the retailer external system 305 or a retailer that is an electricity retailer and uses the retailer external system 305 can make useful suggestions regarding electricity usage to an individual, group, or organization (customer, etc.) using the external system 301 based on the analysis result information 901 (ar) or the recommendation content information 902 (re).
[0065] The above is an overview of the process when the system 101 according to the embodiment of the present disclosure is used in the case of power consumption analysis. In the following, an example of information recorded in the database 104 in the case of power consumption analysis will be described.
[0066] 4.2.1. Overview of the database for the power consumption analysis example (Fig. 10) FIG. 10 shows a group of tables recorded in the database 104 when the system 101 according to the embodiment of the present disclosure is used in an example of power consumption analysis. As shown in FIG. 10 , in the case of power consumption analysis, the database 104 may record a customer information table 141, an edge device information table 142, an edge device data table 143, a power plan table 144, a retailer recommendation table 145, and an execution command table 146. By having the above-mentioned group of tables, the system 101 can record and manage the results of analyzing the data 160 provided to the system 101 from the external system 301, the business recommendations regarding power consumption for individuals, groups, or organizations (customers, etc.) that use the external system 301, and the control regarding power consumption for devices, etc. owned by the external system 301. Between the data analysis platform unit 103 (DAP unit) and the database 104, there are cases where a combination of secure sensitive information 165 (secured ID) and information derived from information other than sensitive information 162 (others) is read and written, and there are cases where a combination of secure sensitive information 165 (secured ID) and analysis result related information 904 (ar / re / co) is read and written. (Information other than these may also be read and written as appropriate.) As already pointed out, among the analysis result related information 904 (ar / re / co), the analysis result information 901 (ar) can be recorded in the retailer recommendation table 145. Depending on the information handled by the system 101, the analysis result information 901 (ar) may also be recorded in other tables (for example, the edge device information table 142 or the edge device data table 143). As already pointed out, the recommendation content information 902 (re) of the analysis result related information 904 (ar / re / co) can be recorded in one or both of the power plan table 144 and the retailer recommendation table 145. As already pointed out, the command information 903 (co) of the analysis result related information 904 (ar / re / co) is recorded in the execution command table 146 . Information derived from non-sensitive information 162 (others) may be recorded in one or more tables in database 104 . The tables listed in FIG. 10 are described below.
[0067] 4.2.2. Customer information table for the power consumption analysis example (Figure 11) 11 shows an example of the customer information table 141. The customer information table 141 is used to record information about the external system 301 and individuals, groups, or organizations (customers, etc.) that use the external system 301, for example. As shown in FIG. 11, each record (row) of the customer information table 141 may have the following fields: customer identification information (customer ID) 1101, customer name 1102, billing address 1103, telephone number 1104, and email address 1105. The customer ID 1101 is information that identifies the external system 301 or an individual, group, or organization (customer, etc.) that uses the external system 301. This identification information may be considered sensitive information 161. While the customer ID, which is sensitive information 161, is recorded in the customer information table 141, other tables in the database 104 store secure sensitive information 165 (secured ID), which is generated by both the pseudonymization process and the probabilistic encryption process described above. Even if the customer ID 1101, which is sensitive information 161, is read from the customer information table 141 by a third party, this is unlikely to pose a threat to computer security. However, in order to reduce the possibility of computer security threats, the secure sensitive information 165 (secured ID) may be recorded in the records of the customer information table 141 instead of the customer ID 1101, which is sensitive information 161. The customer name 1102 indicates the name or full name of the external system 301 or an individual, group, or organization (customer, etc.) that uses the external system 301. The billing address 1103 indicates the address or residence of the party to whom a fee is billed as consideration for a service (e.g., power supply service) provided by a service provider (e.g., a power generator or an electricity retailer) to the external system 301 or an individual, group, or organization (customer, etc.) that uses the external system 301. The telephone number 1104 and email address 1105 indicate the telephone number and email address, respectively, of the external system 301 or an individual, group, or organization (customer, etc.) that uses the external system 301. In Figure 11, it appears as if the items customer name 1102, billing address 1103, telephone number 1104, and email address 1105 are stored in customer information table 141 without being encrypted, but in reality, items whose contents you want to prevent from being leaked to third parties may be stored in customer information table 141 in an encrypted state. The contents of each item of the record in the customer information table 141 may be created by the database management unit 105 and recorded in the database 104 .
[0068] 4.2.3. Edge Device Information Table for Power Consumption Analysis Example (Figure 12) 12 shows an example of the edge device information table 142. The edge device information table 142 is used to record information such as specifications of each device or the like included in the external system 301 (for example, the edge device 302, or a device such as a programmable logic controller (PLC) included in the BEMS / FEMS 303). As shown in FIG. 12, each record (row) of the edge device information table 142 may have the following fields: secure sensitive information 1201 (secured ID), device ID 1202 (device ID), edge device type 1203, installation date 1204, serial number 1205, specifications 1206, timestamp 1207, number of failures 1208, runtime 1209 (run time), efficiency rating 1210 (rating), and past data 1211. The secure sensitive information 1201 (secured ID) is obtained as a result of performing the above-mentioned pseudonymization process and probabilistic encryption process on the identification information 1101 (customer ID) of a customer, etc., which is the sensitive information 161. In other words, the item 1201 of the record (row) of the edge device information table 142 corresponds to the above-mentioned secure sensitive information 165 (secured ID). The device ID 1202 and the edge device type 1203 indicate information for identifying each of the devices and the like included in the external system 301 (for example, the edge device 302, or a device such as a programmable logic controller (PLC) included in the BEMS / FEMS 303) and the type of the device and the like. The edge device type 1203 may indicate the role or function performed by the device and the like. The installation date 1204 indicates the date on which the device or the like was installed so that it can be used in the external system 301. The serial number 1205 indicates, for example, identification information assigned by the manufacturer of the device or the like so that the device or the like can be identified. The serial number 1205 may originally be used for inventory management or after-sales service management.
[0069] The specs 1206 indicate the specifications and capabilities of a device, etc. The specifications and capabilities of the device, etc. indicated in the specs 1206 may be determined according to the type of the device, etc. indicated by the edge device type 1203. For example, the specifications 1206 corresponding to the power receiving panel may indicate any of the rated allowable power, voltage, and current. The specifications 1206 corresponding to the power receiving panel may also include information on the number of devices connected to the output side of the power receiving panel, and any of the power, voltage, and current that can be supplied to those devices. For example, the specifications 1206 corresponding to a battery may indicate either the amount of electricity that can be stored in the battery, or the rated allowable power, voltage, or current when exchanging (storing or discharging) electricity between the battery and the power grid. For example, specifications 1206 for heating, ventilation, and air conditioning (HVAC) may indicate heating and cooling capacities. Cooling capacities may indicate the amount of heat removed from indoor air, for example, using British thermal units (BTUs) or the mass (e.g., in tons) of the object being heated or cooled. Specifications 1206 for HVAC may include rated allowable power, voltage, and current. For example, specifications 1206 for a heat pump may indicate heating and cooling capacity (similar to HVAC). Specifications 1206 for a heat pump may indicate the efficiency of the heat pump, such as the coefficient of performance (COP) for heating and the seasonal energy efficiency ratio (SEER) for cooling. Specifications 1206 for a heat pump may include the rated allowable power, voltage, and current. For example, specifications 1206 corresponding to a water heater may indicate heating efficiency. Heating efficiency may indicate, for example, the amount of water (e.g., in gallons) that the water heater heats, or a rating of the energy efficiency of the heater when heating water. For example, specifications 1206 corresponding to a water heater may include rated allowable power, voltage, and current. Note that in FIG. 12, specifications 1206 corresponding to a water heater may indicate "300L," which may mean that the water heater can hold 300 liters of hot water. For example, the specifications 1206 corresponding to a solar panel may indicate the rated value of the power output from the solar panel. Here, the rated value of the output power may be assumed to be under ideal circumstances. Furthermore, if the total amount of power output from the solar panel under ideal circumstances is set to be greater than the capacity of an inverter or power conditioner interposed between the solar panel and the power transmission and distribution grid (the solar panel is overloaded), the specifications 1206 corresponding to the solar panel may include information on the ratio of the total amount of power output from the solar panel under ideal circumstances to the rated power of the inverter or power conditioner.
[0070] The timestamp 1207 may indicate the time information when the contents of the record in the edge device information table 142 were updated. Alternatively, the timestamp 1207 may indicate the time information of a failure that caused the number of failures 1208, which will be described later, to be updated. Alternatively, the timestamp 1207 may indicate the time information when a critical report on the status of a device or the like was obtained based on real-time monitoring of the device or on an analysis of the past history of measurement values obtained by monitoring the device or the like. The number of failures 1208 may indicate the number of times a device has failed since the device was installed. A failure here may refer to a discrepancy between the function expected of a device (normal function) and the function actually provided by the device. Failures may include mechanical failures, software problems, problems with connections between devices, and reduced efficiency of functions. The events that are considered to be failures may also vary depending on the type of device. For example, a failure in a power receiving panel may include the activation of a circuit breaker control due to fluctuations in power. The runtime 1209 (run time) may be information indicating the time that the device or the like has actually been operating since the device or the like was installed in the external system 301. The runtime 1209 does not need to include the time when the device or the like is installed but not operating (for example, the time when the device or the like is down, the time when the device or the like is undergoing maintenance, the time when the device or the like is out of order, or the time when the device or the like is powered off). The efficiency rating 1210 (rating) may indicate, for example, in the form of a rank, the efficiency of the function realized by the device. The efficiency of the function may be related to the amount of power input / output to the device or the amount of power produced, converted, or consumed, or may be related to the reliability of the function provided by the device. For example, the efficiency rating 1210 (rating) for a power receiving panel may include the efficiency of responding to power fluctuations, switching power supply sources, and responding to power supply from solar panels (backflow of power). The efficiency rating 1210 (rating) may be determined by the manufacturer of the device through a prior inspection before shipping the device. The efficiency rating 1210 (rating) may also be updated as appropriate. The historical data 1211 may indicate a history of the operation results of an apparatus (device), etc. The historical data 1211 may be information about measurements of the amount of energy or power produced, the time it was available for use, and past efficiency ratings.
[0071] In FIG. 12, the items of device ID 1202, edge device type 1203, installation date 1204, serial number 1205, specifications 1206, timestamp 1207, number of failures 1208, runtime 1209, efficiency rating 1210, and past data 1211 appear to be stored in the edge device information table 142 without being encrypted, but in reality, items whose contents should be prevented from being leaked to third parties may be stored in the edge device information table 142 in an encrypted state. The contents of each item of the record of the edge device information table 142 may be created by the database management unit 105 and recorded in the database 104. Items such as a device ID 1202, an edge device type 1203, an installation date 1204, a serial number 1205, specifications 1206, and an efficiency rating 1210 may be recorded in a record of the edge device information table 142 when an apparatus (device) or the like is installed in the external system 301. Items such as a timestamp 1207, a failure count 1208, a runtime 1209, and past data 1211 (and, in some cases, an efficiency rating 1210) may be recorded in a record of the edge device information table 142 when some event occurs while the apparatus (device) or the like is operating in the external system 301, or at regular time intervals. When recording the historical data 1211, the data analysis platform unit 103 (DAP unit) or other functional units within the system 101 or the external system 301 may be involved in generating the historical data 1211 to be recorded. The database management unit 105 and the data analysis platform unit 103 (DAP unit) that perform the above-described roles may be included in a platform for Energy as a Service (EaaS).
[0072] 4.2.4.Edge Device Data Table for Power Consumption Analysis Example (Figure 13) 13 shows an example of the edge device data table 143. The edge device data table 143 records information and data generated, acquired, and collected by each device, etc., included in the external system 301 (for example, the edge device 302, or a device such as a programmable logic controller (PLC) included in the BEMS / FEMS 303). The recorded information and data may include the execution status and measurement values. As shown in FIG. 13, each record (row) of the edge device data table 143 may have the following fields: data ID 1301 (data ID), secure sensitive information 1201 (secured ID), device ID 1202 (device ID), data 1304, timestamp 1305, and status 1306. The data ID 1301 is information for identifying a record. A record may be provided corresponding to each device, etc., included in the external system 301 (such as the edge device 302 or a device such as a programmable logic controller (PLC) included in the BEMS / FEMS 303). In Fig. 13, a record having a data ID 1301 of "1" relates to a battery, a record having a data ID 1301 of "2" relates to a heating, ventilation and air conditioning (HVAC) system, and a record having a data ID 1301 of "3" relates to a hot water supply system. The secure sensitive information 1302 (secured ID) is obtained as a result of performing the above-mentioned pseudonymization process and probabilistic encryption process on the customer identification information 1101 (customer ID), which is the sensitive information 161. In other words, the item 1302 of the record (row) of the edge device data table 143 corresponds to the above-mentioned secure sensitive information 165 (secured ID). The device ID 1303 indicates information for identifying each of the devices and the like included in the external system 301 (for example, the edge device 302, a programmable logic controller (PLC) in the BEMS / FEMS 303, and the like). Data 1304 indicates the content of data output by an apparatus (device), etc. For example, data 1304 may indicate the content of data output by an apparatus (device), etc. on Modbus, which is a network for PLC (and the communication protocol for that network). In Fig. 13, data 1304 is expressed in hexadecimal. The timestamp 1305 indicates the time when the data 1304 was observed. The status 1306 indicates the state of the device at the time indicated by the timestamp 1305. The status 1306 may include information that distinguishes whether the device is active, in operation, waiting, or in an error state. The status 1306 may also indicate an interpretation of the value indicated by the data 1304. Note that "280L of hot water" in FIG. 13 may indicate that 280 liters of hot water is stored.
[0073] In FIG. 13, the items of device ID 1202, data 1304, timestamp 1305, and status 1306 appear to be stored in the edge device data table 143 without being encrypted, but in reality, items whose contents need to be prevented from being leaked to third parties may be stored in the edge device data table 143 in an encrypted state. The contents of each item of the record in the edge device data table 143 may be recorded in the database 104 by the database management unit 105, the data analysis platform unit 103 (DAP unit), or other functional units in the system 101. The database management unit 105 and the data analysis platform unit 103 (DAP unit) that perform the above-described roles may be included in a platform for Energy as a Service (EaaS).
[0074] 4.2.5. Power Plan Table for Power Consumption Analysis Example (Figure 14) 14 shows an example of the power plan table 144. The power plan table 144 records information about power rate plans recommended to each external system 301 and each individual, group, or organization (customer, etc.) that uses the external system 301. When the information recorded in the power plan table 144 is sent to the retailer external system 305, the power rate plan proposal is made to the customer, etc., who uses the external system 301, by the power retailer (retailer) that uses the retailer external system 305.
[0075] As shown in FIG. 14, each record (row) of the power plan table 144 may have the following items: optimal plan ID 1401 (opt plan ID), secure sensitive information 1402 (secured ID), first time 1403 (T_1), first electricity rate unit price 1404 (price_1), second time 1405 (T_2), second electricity rate unit price 1406 (price_2), third time 1407 (T_3), third electricity rate unit price 1408 (price_3), fourth time 1409 (T_4), and fourth electricity rate unit price 1410 (price_4). The optimum plan ID 1401 indicates information for identifying a record. The record may be provided for each external system 301 or for each individual, group, or organization (such as a customer) that uses the external system 301. The secure sensitive information 1402 (secured ID) is obtained as a result of performing the above-mentioned pseudonymization process and probabilistic encryption process on the customer identification information 1101 (customer ID), which is the sensitive information 161. In other words, the item 1402 of the record (row) of the power plan table 144 corresponds to the above-mentioned secure sensitive information 165 (secured ID). The first electricity rate unit price 1404 (price_1) indicates the electricity rate unit price (e.g., the rate per kilowatt-hour (1 kWh) of electricity) for the time period from the first time 1403 (T_1) to the second time 1405 (T_2) in the electricity rate plan recommended to the customer, etc. The second electricity rate unit price 1406 (price_2) indicates the electricity rate unit price for the time period from the second time 1405 (T_2) to the third time 1407 (T_3) in the electricity rate plan recommended to the customer, etc. The third electricity rate unit price 1408 (price_3) indicates the electricity rate unit price for the time period from the third time 1407 (T_3) to the fourth time 1409 (T_4) in the electricity rate plan recommended to the customer, etc. The fourth electricity unit price 1410 (price_4) indicates the electricity unit price for the time period from the fourth time 1409 (T_4) to the first time 1403 (T_1) of the next day in the electricity rate plan recommended to the customer.
[0076] In Figure 14, it appears as if the items of first time 1403 (T_1), first electricity rate unit price 1404 (price_1), second time 1405 (T_2), second electricity rate unit price 1406 (price_2), third time 1407 (T_3), third electricity rate unit price 1408 (price_3), fourth time 1409 (T_4), and fourth electricity rate unit price 1410 (price_4) are stored in the power plan table 144 without being encrypted, but in reality, items whose contents should be prevented from being leaked to third parties may be stored in the power plan table 144 in an encrypted state. The content of each item of the record in the power plan table 144 may be recorded in the database 104 by the data analysis platform unit 103 (DAP unit).
[0077] 4.2.6. Retailer recommendation table for power consumption analysis example (Figure 15) 15 shows an example of the retailer recommendation table 145. The retailer recommendation table 145 mainly shows information on the content of proposals regarding electricity usage that are recommended to each external system 301 and each individual, group, or organization (customer, etc.) that uses the external system 301. When the information recorded in the retailer recommendation table 145 is sent to the retailer external system 305, the proposals regarding electricity usage are made to customers, etc., who use the external system 301, by electricity retailers (retailers) that use the retailer external system 305.
[0078] As shown in FIG. 15, each record (row) of the retailer recommendation table 145 may have the following fields: recommendation ID 1501 (recommendation ID (rec ID)), secure sensitive information 1502 (secured ID), timestamp 1503, proposed power plan information 1504, proposed equipment information 1505, power consumption analysis result information 1506, and estimated savings information 1507. The recommendation ID 1501 (recommendation ID (rec ID)) indicates information for identifying a record. A record may be provided for each external system 301 or for each individual, group, or organization (customer, etc.) that uses the external system 301, for example. The secure sensitive information 1502 (secured ID) is obtained as a result of performing the above-mentioned pseudonymization process and probabilistic encryption process on the customer identification information 1101 (customer ID), which is the sensitive information 161. In other words, the item 1502 of the record (row) of the retailer recommendation table 145 corresponds to the above-mentioned secure sensitive information 165 (secured ID). The timestamp 1503 indicates the time when one or more of the proposed power plan information 1504, proposed equipment information 1505, power consumption analysis result information 1506, or estimated savings information 1507 was recorded. The power consumption analysis result information 1506 indicates the results of an analysis of the power consumption patterns in the external system 301 by the data analysis unit 133 (the analysis result generation unit 134) in the system 101 based on data 160 transmitted from the external system 301 to the system 101.
[0079] The proposed power plan information 1504 and the proposed equipment information 1505 indicate the results of the data analysis unit 133 (recommended content generation unit 135) in the system 101 considering the recommended content related to power in the external system 301 based on the contents of the power consumption analysis result information 1506, etc. The proposed power plan information 1504 indicates the contents of a power plan proposed to the external system 301 or a customer or the like who uses the external system 301 . The "Time-of-Use Plan" shown in Figure 15 is an electricity plan in which the unit price of electricity is set separately for each time period. Electricity consumers who accept the "Time-of-Use Plan" are motivated to reduce their electricity consumption during times when the unit price of electricity is high and shift to electricity consumption during times when the unit price of electricity is low (cheap). The "Solar Incentive Plan" shown in FIG. 15 is an electricity plan that includes time-of-day electricity rate unit pricing similar to the above-mentioned "Time-of-Use Plan," and also provides incentives for the use of solar panels (solar power). In the record with rec ID "2" in FIG. 15, the electricity consumption analysis result information 1506 indicates that "excessive electricity usage during daytime hours was detected." Considering this, it is expected that the use of solar panels will significantly reduce the peak height of electricity supply (electricity consumption) from the power transmission and distribution network during daytime hours. Therefore, in the record with rec ID "2" in FIG. 15, the "Solar Incentive Plan" is recorded as the proposed electricity plan information 1504. The "Demand Response Plan" shown in FIG. 15 is an electricity plan that includes a time-of-use electricity rate setting by time period similar to the above-mentioned "Time-of-Use Plan," and also provides an incentive to adjust the electricity consumption in the external system 301 using the results of real-time monitoring of the electricity consumption in the external system 301. In the record with rec ID "3" in FIG. 15, considering the content of the electricity consumption analysis result information 1506 that "short-term spikes were frequently detected," when a short-term spike in electricity consumption occurs in the external system 301, adjusting the electricity consumption in the external system 301 (for example, by changing the temperature setting of a heating / cooling device) to mitigate the severity of the short-term spike is desirable not only for the external system 301 and the customers using the external system 301, but also for power generators and electricity retailers. Therefore, in the record with rec ID "3" in FIG. 15, a "Demand Response Plan" is recorded as the proposed electricity plan information 1504.
[0080] The proposed facility information 1505 indicates the details of the facility investment proposed to the external system 301 and the customer or the like who uses the external system 301. Here, the facility investment refers to an investment in facilities related to electricity for an individual, group, or organization (customer or the like) who uses the external system 301. This proposed facility investment may be an investment in facilities owned by the customer himself, or may be an investment in facilities that can be used by the customer but are not owned by the customer himself. 15, in the record with rec ID "1," the power consumption analysis result information 1506 indicates "high power usage detected during peak hours," and the proposed equipment information 1505 indicates "upgrade to high-efficiency HVAC." The intention is to reduce power consumption (power bills) during peak hours by using high-efficiency equipment. In the record in Figure 15 with rec ID "2", the power consumption analysis result information 1506 indicates "excessive power usage detected during daytime hours", and the proposed equipment information 1505 indicates "install solar panels". In the record in Figure 15 with rec ID "3", the power consumption analysis result information 1506 indicates "frequent short-term spikes detected", and the proposed equipment information 1505 indicates "install a smart thermostat".
[0081] The estimated savings information 1507 indicates an estimate of the amount of savings in electricity charges related to the external system 301, assuming that the proposed power plan information 1504 and the proposed facility information 1505 are accepted by the external system 301 or an individual, group, or organization (customer, etc.) that uses the external system 301. This estimate may be generated by the data analysis unit 133 (the recommendation content generation unit 135 therein) in the system 101.
[0082] If the value of the secure sensitive information (secured ID) in a record in the power plan table 144 of FIG. 14 is the same as the value of the secure sensitive information (secured ID) in a record in the retailer recommendation table 145 of FIG. 15, these records are associated. Specifically, the record in FIG. 14 with an opt plan ID of "1" and the record in FIG. 15 with a rec ID of "1" have the same value, "rasrrzmn," and therefore these records are associated. Similarly, the record in FIG. 14 with an opt plan ID of "2" and the record in FIG. 15 with a rec ID of "2" have the same value, "dakkgyui," and therefore these records are associated. The record in FIG. 14 with an opt plan ID of "3" and the record in FIG. 15 with a rec ID of "3" have the same value, "qsfmfgu," and therefore these records are associated. Note that, for records having the same value of secure sensitive information (secured ID), the information recorded in these records may be handled collectively in steps 516, 517, and 518 in FIG. When the above association is made, the proposed unit price of electricity for each time period shown in the record of Figure 14 may be applicable to the external system 301 or the customers using the external system 301, provided that the recommended electricity content indicated by the proposed electricity plan information 1504 and the proposed equipment information 1505 in the record of Figure 15 is accepted by the external system 301 or the customers using the external system 301.
[0083] In Figure 15, the items device ID 1202, timestamp 1503, proposed power plan information 1504, proposed equipment information 1505, power consumption analysis result information 1506, and estimated savings information 1507 appear to be stored in retailer recommendation table 145 without being encrypted, but in reality, items whose contents you want to prevent from being leaked to third parties may be stored in retailer recommendation table 145 in an encrypted state. The contents of each item of the record in the retailer recommendation table 145 may be recorded in the database 104 by the data analysis platform unit 103 (DAP unit).
[0084] 4.2.7. Execution command table for power consumption analysis example (Figure 16) 16 shows an example of the execution command table 146. The execution command table 146 records commands for controlling devices and the like that the external system 301 has (for example, devices such as the edge device 302 or a programmable logic controller (PLC) and the like that the BEMS / FEMS 303 has). The execution command table 146 also has a role of recording a log of the commands. As shown in FIG. 16, each record (row) of the execution command table 146 may have the following items: operational plan ID 1601 (operational plan ID (ope ID)), secure sensitive information 1602 (secured ID), device ID 1603 (device ID), timestamp 1604, operation command 1605, and operation reference 1606. An operational plan ID 1601 (operational plan ID (ope ID)) indicates information for identifying a record. The secure sensitive information 1602 (secured ID) is obtained as a result of performing the above-mentioned pseudonymization process and probabilistic encryption process on the identification information 1101 (customer ID) of the customer, etc., which is the sensitive information 161. In other words, the item 1602 of the record (row) of the execution command table 146 corresponds to the above-mentioned secure sensitive information 165 (secured ID). The device ID 1604 indicates information for identifying each of the devices and the like that the external system 301 has (for example, the edge device 302, a programmable logic controller (PLC) in the BEMS / FEMS 303, and the like). The timestamp 1604 may indicate the time when the operation command 1605 and the operation reference 1606 are applied to the device indicated by the device ID 1604. Alternatively, the timestamp 1604 may indicate the time when the operation command 1605 and the operation reference 1606 are recorded in the record.
[0085] An operation command 1605 indicates the content of a command to be applied to the device indicated by the device ID 1604. "Run" as shown in Fig. 16 may mean causing the device to perform a predetermined process or operation, or continuing the predetermined process or operation. The operation reference 1606 may indicate optional processing or operation instructions when the command indicated by the operation command 1605 is applied to the device indicated by the device ID 1604. 16 may mean, for example, increasing (incrementing) the value of a predetermined parameter for processing or operation by a value of 10. Increasing (incrementing) the value of a predetermined parameter for processing or operation may also mean, for example, increasing the output amount or operating speed (processing capacity) of a device or the like. "Zero" shown in Fig. 16 may mean, for example, resetting a value of a predetermined parameter for a process or operation to a baseline, or may mean stopping a process or operation of a device or the like (turning off a function). "One" in Fig. 16 may mean, for example, starting a predetermined mode of processing or operation. Alternatively, "One" in Fig. 16 may mean, for example, starting a predetermined processing or operation (a predetermined process). Even if the operation reference 1606 itself is referenced, only authorized persons can understand the meaning of the operation reference 1606, and the meaning of the operation reference 1606 is difficult for other persons (e.g., third parties) to understand, thereby increasing the strength of computer security.
[0086] In FIG. 16, it appears as if the items of device ID 1603, timestamp 1604, operation command 1605, and operation reference 1606 are stored in the execution command table 146 without being encrypted, but in reality, items whose contents should be prevented from being leaked to third parties may be stored in the execution command table 146 in an encrypted state. Of the contents of each item of the record in the execution command table 146, the contents of the operation command 1605 and the operation reference 1606 may be generated by the data analysis unit 133 (the command generation unit 136 therein) in the system 101. The content of each item of the record in the execution command table 146 may be recorded in the database 104 by the data analysis platform unit 103 (DAP unit).
[0087] 4.3. Dashboard (Figures 17-20) The following describes a dashboard that is displayed for an administrator or the like to view or edit information handled in an embodiment of the present disclosure. Note that a portion of the description of the dashboard uses an example of power consumption analysis. 3, the dashboard display control unit 151 in the database management unit 105 controls the display or output of data and information recorded in the database 104. The dashboard display control unit 151 may also receive an instruction to edit (add, change, or delete) the data and information recorded in the database 104, and edit the database 104 in accordance with the instruction. Furthermore, the dashboard display control unit 151 may control the display or output of not only the data and information recorded in the database 104 but also the data and information handled by the system 101 and the external system 301, and may also control the editing (addition, change, deletion) of such data and information. Specific examples will be described below. When displaying a dashboard (including displaying a pop-up window or a balloon), even if the dashboard is intended for an administrator, the sensitive information 161 (customer ID) itself may not be displayed, and instead secure sensitive information 165 (secured ID) may be displayed. By preventing the sensitive information 161 (customer ID) itself from being displayed, threats to computer security are reduced.
[0088] 4.3.1. Dashboard Front Page (Figure 17) FIG. 17 shows the front page of a dashboard 1700 (administrative dashboard). The dashboard display control unit 151 receives a login operation from an administrator or the like, for example, via the input device 406 (see FIG. 4) in the system 101. In response to the reception of the login, the dashboard display control unit 151 performs control so that the front page of the dashboard 1700 (administrative dashboard) shown in FIG. 17 is displayed on the display or output device 407 in the system 101, for example.
[0089] The front page of the dashboard 1700 (management dashboard) shown in FIG. 17 may be a single window displayed on a display included in the display or output device 407 in the system 101, for example. 17 may have seven clickable icons. The seven clickable icons may be, for example, a data flow monitoring icon 1701, a key management icon 1702, a database management icon 1703, an error and incident reporting icon 1704, a data analytics reports icon 1705, an edge device monitoring icon 1706, and a billing reports icon 1707.
[0090] When the data flow monitoring icon 1701 (data flow monitoring) is clicked with a mouse or the like, the dashboard display control unit 151 may perform control to display a window visually showing the flow of data and information in the system 101 or the external system 301 on, for example, a display of the display or output device 407 within the system 101. The window may display one or more of the following: a real-time data or information transfer rate, a data packet transfer source or destination, a log of data requests and responses to those requests, and a log of errors and interrupts in data transmission (transfer). Displaying this window helps monitor whether the data transfer and processing pipeline is normal or abnormal, and confirm whether the data transfer and processing are as expected.
[0091] When the key management icon 1702 (Key Management) is clicked with a mouse or the like, the dashboard display control unit 151 may perform control to display a window for managing keys used in the system 101, for example, on a display of the display or output device 407 in the system 101. Details of the window for managing keys will be described later with reference to FIG. 18.
[0092] When the database management icon 1703 (database management) is clicked with a mouse or the like, the dashboard display control unit 151 may perform control to display a window for viewing or managing the data and information recorded in the database 104 on, for example, a display of the display or output device 407 in the system 101. Details of the window for viewing or managing the data and information recorded in the database 104 will be described later with reference to FIG. 19.
[0093] When the error and incident reporting icon 1704 (error and incident reporting) is clicked with a mouse or the like, the dashboard display control unit 151 may perform control to display a window showing a log of errors and computer security incidents that have occurred in the system 101 or the external system 301, for example, on a display of the display or output device 407 within the system 101. The window may display a detailed report on one or more of a failure of the system 101 or the external system 301, a problem reported by a person (e.g., a user) using the system 101 or the external system 301, a breakdown, or an access attempt by a third party without access authority.
[0094] When the data analysis report icon 1705 (data analytics reports) is clicked with a mouse or the like, the dashboard display control unit 151 may perform control to display, for example, on a display of the display or output device 407 in the system 101, a window for viewing data and information derived from the analysis result related information 904 (ar / re / co) of the analysis performed by the data analysis unit 133 in the system 101. Details of the window for viewing data and information derived from the analysis result related information 904 (ar / re / co) will be described later with reference to FIG. 20.
[0095] When the edge device monitoring icon 1706 is clicked with a mouse or the like, the dashboard display control unit 151 may control, for example, a display of the display or output device 407 in the system 101 to display a window for viewing the status of devices, etc., of the external system 301 (e.g., the edge device 302 or a device such as a programmable logic controller (PLC) of the BEMS / FEMS 303) and information (health information) on whether the devices, etc. are normal or abnormal. The window may display real-time data on one or more of the performance of the devices, the status of processing execution of the devices, faults, warnings, and maintenance schedules. The display of the window may enable remote diagnosis of the devices, etc., of the external system 301 and remote intervention in the devices, etc. These diagnoses and interventions may enable identification of problems occurring in the devices, etc., of the external system 301 and updating firmware in the devices, etc. to resolve the problems.
[0096] When the billing report icon 1707 (billing reports) is clicked with a mouse or the like, the dashboard display control unit 151 may control, for example, a display of the display or output device 407 in the system 101 to display a window for viewing financial reports related to the use of services provided by the system 101 and the use of the power supply service. The window may display one or more of the following: the billing cycle, the payment status, the bill, a summary showing the service usage status, and the past history of payment.
[0097] The dashboard display control unit 151 can also accept a logout operation from an administrator or the like, for example, via the input device 406 (see FIG. 4) in the system 101. In response to the acceptance of the logout, the dashboard display control unit 151 controls, for example, the display or output device 407 in the system 101 to end the display of the dashboard 1700.
[0098] 4.3.2. Displaying the key management screen on the dashboard (Figure 18) FIG. 18 shows a key management screen display 1800 showing the appearance of a window for managing keys used in system 101, which is displayed, for example, on a display within system 101 or on a display of output device 407 when key management icon 1702 (Key Management) is clicked with a mouse or the like. 18, when key management icon 1702 (Key Management) is clicked with a mouse or the like, key management window 1801 may be displayed as a pop-up window on the display. Key management window 1801 may have a tokenization process key management area 1802 for managing a first key 791 used in the tokenization process, and a probabilistic encryption process key management area 1803 for managing a second key 792 (or a third key 793) used in the probabilistic encryption process. (Key management window 1801 may also have an area for managing individual keys 691 and 692 used for transmission and reception between system 101 and external system 301 or retailer external system 305.) Both the pseudonymization processing key management area 1802 and the probabilistic encryption processing key management area 1803 may have a list icon 1804 (list of keys) of keys in the key warehouse, a status icon 1805 (key status) of keys in the key warehouse, a new key generation icon 1806 (generate new key) as a key-related operation, a key update icon 1807 (update key) as a key-related operation, and a key retirement icon 1808 (retire key) as a key-related operation.
[0099] When the key list icon 1804 (list of keys) is clicked with a mouse or the like, the dashboard display control unit 151 controls the display of, for example, a display within the system 101 or a display of the output device 407 to display a list of keys currently being managed by the system 101. When a key status icon 1805 (key status) is clicked with a mouse or the like, the dashboard display control unit 151 performs control to display (a summary or details of) the current status of the keys currently being managed by the system 101, for example, on a display of the display or output device 407 within the system 101. The key whose status is displayed may be a specific key specified with a mouse or the like, or may be all keys currently being managed by the system 101. The status of a key may be, for example, active, inactive, expiring soon, expired, pending retirement, or compromised. The status of a key may also include one or more of the following: the date and time when the key was generated, the date and time when the key was last used, and the date and time when the key is scheduled to expire or be retired. "Active" means that the key is currently in use. "Inactive" means that the key is not currently in use and is stored in a vault. "Expiring soon" means that the key is nearing its predetermined expiration date and time. "Expired" means that the key's predetermined time has passed and it should no longer be used. "Pending retirement" means that the key is awaiting retirement. "Compromised" means that the key has been exposed to an unauthorized entity and should be replaced immediately.
[0100] When a new key generation icon 1806 (generate new key) is clicked with a mouse or the like, the dashboard display control unit 151 requests the function unit that manages keys in the system 101 to perform processing to generate a new key.
[0101] When the key update icon 1807 (update key) is clicked with a mouse or the like, the dashboard display control unit 151 requests a process to replace an existing key with a new key to a functional unit that manages keys in the system 101. The process of replacing an existing key with a new key may be comprised of a series of processes: (1) a process to select an existing key to be replaced, (2) a process to generate a new key, (3) a process to apply the new key to the system 101 or the like so that the new key is used in subsequent processes (e.g., pseudonymization process, probabilistic encryption process, encryption process related to transmission and reception), and (4) a process to invalidate the existing key to be replaced. Note that, since there is only one active key in the system 101 at a given time for each of the first key 791 and the second key 792 (or the third key 793), the type of key (either the first key 791, the second key 792, or the third key 793) may be specified in the process of selecting the existing key to be replaced. However, if the status of the existing key to be replaced is not limited to active, the process of selecting the existing key to be replaced may be such that a list of existing keys is displayed and the selection of the existing key to be replaced is accepted using a mouse or the like. As the individual key 691 or the individual key 692 differs for each external system 301 or retailer external system 305, the process of selecting the existing key to be replaced may specify information that identifies the external system 301 or the retailer external system 305 that corresponds to the existing key to be replaced (or information that identifies the person using these systems). However, if the status of the existing key to be replaced for the individual key 691 or the individual key 692 is not limited to active, the process of selecting the existing key to be replaced may be such that a list of existing keys is displayed and the selection of the existing key to be replaced is accepted using a mouse or the like.
[0102] When the key retirement icon 1808 (retire key) is clicked with a mouse or the like, the dashboard display control unit 151 requests the function unit that manages keys in the system 101 to retire or revoke the key. The method for specifying the key to be retired may be the same as the method for selecting an existing key to be replaced, as already explained.
[0103] 4.3.3. Displaying the database management screen on the dashboard (Figure 19) 19 shows a database management screen display 1900 showing an aspect of a window for viewing or managing data and information recorded in database 104, which is displayed, for example, on a display of display or output device 407 in system 101 when database management icon 1703 (database management) is clicked with a mouse or the like. As shown in Fig. 19, when database management icon 1703 (database management) is clicked with a mouse or the like, a database management window 1901 may be displayed as a pop-up window on the display. The database management window 1901 may have a view tables icon 1902 (view tables), an insert data icon 1905 (insert data), an update data icon 1906 (update data), and a delete data icon 1907 (delete data).
[0104] When the table view icon 1902 (view tables) is clicked with a mouse or the like, the dashboard display control unit 151 performs control to display a balloon 1903 displaying a list of tables held by the database 104, for example, on a display of the display or output device 407 in the system 101. Note that while Fig. 19 shows the balloon 1903 displaying only the "edge device data table," in reality, the balloon 1903 displays a list of tables held by the database 104. When a specific table is selected with a mouse or the like from the list of tables displayed in balloon 1903, only the name of the specific table may be displayed, and the selected table body may also be displayed in balloon 1903. In the example of Fig. 19, in response to "edge device data table" being selected with a mouse or the like in balloon 1903, the table name displayed in balloon 1903 becomes "edge device data table" alone, and the edge device data table body is displayed in table area 1904.
[0105] When the data insertion icon 1905 (insert data) is clicked with a mouse or the like, the dashboard display control unit 151 performs a process of adding data (records) to a table included in the database 104. The process of adding data (records) to a table included in the database 104 may be a series of processes including: (1) a process of displaying a list of tables included in the database 104 (this process may be similar to the process of displaying the balloon 1903), (2) a process of recognizing the name of a table selected by clicking with a mouse or the like in the list of tables, (3) a process of accepting the contents of the data (records) to be added to the table (for example, a process of displaying a new pop-up window and inputting the contents of the data (records) to be added into the pop-up window using a keyboard or the like), and (4) a process of adding the input data (records) to the selected table in response to clicking a confirm button or the like with a mouse or the like. The number of data (records) added in response to a single click of the data insertion icon 1905 (insert data) may be one or more.
[0106] When the data update icon 1906 (update data) is clicked with a mouse or the like, the dashboard display control unit 151 performs processing to change the contents of the existing data (records) in the tables included in the database 104 . The process of changing the contents of existing data (records) in a table included in database 104 may be a series of processes including: (1) a process of displaying a list of tables included in database 104 (this process may be similar to the process of displaying balloon 1903); (2) a process of recognizing the name of a table selected in the list of tables by clicking with a mouse or the like; (3) a process of displaying the selected table body (which may be displayed in the same manner as table area 1904); (4) a process of recognizing the data (records) whose contents are to be changed in response to an operation of selecting the data (records) whose contents are to be changed (for example, an operation of selecting data (records) with a mouse or the like); (5) a process of accepting the contents of the changed data (records) (for example, a process of displaying a new pop-up window and inputting the contents of the changed data (records) into the pop-up window using a keyboard or the like); and (6) a process of reflecting the changes to the contents of the data (records) that have been input in the selected table in response to clicking a confirm button or the like with a mouse or the like. The number of data (records) whose contents are changed in response to a single click of the data update icon 1906 (update data) may be one or more.
[0107] When the data deletion icon 1907 (delete data) is clicked with a mouse or the like, the dashboard display control unit 151 performs a process of deleting specified data (records) in a table included in the database 104. The process of deleting specified data (records) in a table included in the database 104 may be a series of processes including: (1) a process of displaying a list of tables included in the database 104 (this process may be similar to the process of displaying the balloon 1903), (2) a process of recognizing the name of a table selected in the list of tables by clicking with a mouse or the like, (3) a process of displaying the selected table body (which may be displayed in the same manner as the table area 1904), (4) a process of recognizing the data (records) to be deleted in response to an operation of selecting the data (records) to be deleted (for example, an operation of selecting data (records) with a mouse or the like), and (5) a process of deleting the data (records) selected to be deleted in the selected table in response to a click of a confirm button or the like with a mouse or the like. The number of data (records) whose contents are changed in response to a single click of the data deletion icon 1907 (delete data) may be one or more.
[0108] 4.3.4. Displaying the data analysis report screen on the dashboard (Figure 20) 20 shows a data analysis report screen display 2000 illustrating the form of a window for viewing data and information derived from analysis result related information 904 (ar / re / co) of the analysis performed by the data analysis unit 133 in the system 101, which is displayed, for example, on a display included in the display or output device 407 in the system 101 when the data analysis report icon 1705 (data analytics reports) is clicked with a mouse or the like. As shown in FIG. 20, when the data analysis report icon 1705 (data analytics reports) is clicked with a mouse or the like, a data analysis report window 2001 may be displayed as a pop-up window on the display. 20, even if the window is intended for an administrator, the sensitive information 161 (customer ID) itself may not be displayed, and instead secure sensitive information 165 (secured ID) may be displayed. By preventing the sensitive information 161 (customer ID) itself from being displayed, threats to computer security are reduced.
[0109] 5. Other (variations) The present disclosure is not limited to the above-described embodiments and includes various modifications. Part of the configurations and processes of the embodiments may be replaced with the configurations and processes of other conceivable embodiments. The configurations and processes of other conceivable embodiments may be added to the configurations and processes of the embodiments. For example, the present disclosure may include the following modified embodiments.
[0110] (A) Access rights from the trusted execution environment (TEE) to the database In the above embodiment, the trusted execution environment unit 102 (TEE unit) does not have direct access rights to the database 104. Therefore, when the trusted execution environment unit 102 (TEE unit) accesses the database 104, the data analysis platform unit 103 (DAP unit) acts as an intermediary. In a variant, the Trusted Execution Environment unit 102 (TEE unit) may have direct access to the database 104. In this variant, steps 512 and 520 in the flow diagram 500 of Figure 5 are not required. According to the above modification, the management of access rights to the database 104 becomes slightly more complicated, but the access from the trusted execution environment unit 102 (TEE unit) to the database 104 becomes faster.
[0111] (B) Dashboard display and other aspects In the above embodiment, the display or output device 407 of the system 101 has a display or the like that displays the dashboard 1700 . In a modified example, the dashboard 1700 may be displayed on a display or the like of a terminal or the like owned by an administrator or the like of the system 101. For example, a dashboard display control unit 151 may be provided in a terminal or the like owned by an administrator or the like of the system 101, and the system 101 may be remotely accessed from the terminal or the like owned by the administrator or the like of the system 101. The above modification provides high convenience for viewing the dashboard 1700, etc.
[0112] (C) Dashboard information output In the above embodiment, information relating to the dashboard 1700 (information in the windows shown in FIG. 17, FIG. 18, FIG. 19 or FIG. 20) is displayed on a display or the like. In a modified example, part or all of the above information may be output to a printer or the like, or may be output as digital data. The above-described variations contribute to flexible use of information related to the dashboard 1700.
[0113] The technical matters shown in the above-described embodiments of the present disclosure and the modified examples of the embodiments can be combined as appropriate as long as no technical contradiction occurs.
Claims
1. 1. A system comprising: The system includes a trusted execution environment unit and a data analysis platform unit; the trusted execution environment unit includes a pseudonymization processing unit and a trusted execution environment probabilistic encryption processing unit, the pseudonymization processing unit converts the sensitive information in data including a portion of sensitive information and a portion of information other than the sensitive information into pseudonym information associated with the sensitive information, the probabilistic encryption processing unit in the trusted execution environment performs encryption processing on a combination of a random number and the pseudonym information to generate secure sensitive information; The data analysis platform unit includes a data analysis platform probabilistic decryption unit and a data analysis unit, the probabilistic decryption unit in the data analysis platform performs a decryption process on the secure sensitive information to generate the pseudonym information; The data analysis unit performs analysis on the data using one or both of the pseudonymous information generated by the probabilistic decryption unit within the data analysis platform and the portion of the information other than the sensitive information.
2. 2. The system of claim 1, the trusted execution environment unit further includes a received data decryption processing unit, a pseudonymization removal unit, and a transmitted data encryption processing unit; the received data decryption processing unit performs a decryption process on the received data, which is encrypted data including the sensitive information portion and the information portion other than the sensitive information, the pseudonymization processing unit converts the sensitive information in the data resulting from the decoding process performed by the received data decoding processing unit into the pseudonym information, the pseudonymization de-subunit converts the pseudonym information associated with analysis result-related information related to a result of analysis of the data by the data analysis unit into the sensitive information associated with the pseudonym information, The transmission data encryption processing unit generates transmission data by performing encryption processing on the sensitive information generated by the de-pseudonymization unit and the analysis result related information.
3. 3. A system according to claim 2, comprising: the trusted execution environment unit further includes a trusted execution environment probabilistic decryption unit; The data analysis platform unit further includes an in-data analysis platform probabilistic encryption processing unit, the probabilistic encryption processing unit in the data analysis platform performs encryption processing on a combination of a random number and the pseudonym information associated with the analysis result-related information to generate secure sensitive information associated with the analysis result-related information; the probabilistic decryption unit in the trusted execution environment performs a decryption process on the secure sensitive information associated with the analysis result-related information to generate the pseudonym information associated with the analysis result-related information; The system, wherein the pseudonymization unit converts the pseudonym information generated by the probabilistic decryption unit in the trusted execution environment into the sensitive information associated with the pseudonym information.
4. 2. The system of claim 1, The system further comprises a database; the database records the secure sensitive information generated by the probabilistic encryption processing unit in the trusted execution environment, A system in which the probabilistic decryption unit within the data analysis platform performs a decryption process on the secure sensitive information recorded in the database.
5. 5. A system according to claim 4, The data analysis platform unit further includes a database writing unit, The database writing unit writes the secure sensitive information generated by the probabilistic encryption processing unit in the trusted execution environment to a database.
6. 4. A system according to claim 3, comprising: The system further comprises a database; the database records the secure sensitive information associated with the analysis result-related information generated by the probabilistic encryption processing unit in the data analysis platform; A system in which the probabilistic decryption unit in the trusted execution environment performs a decryption process on the secure sensitive information associated with the analysis result related information recorded in the database.
7. 7. A system according to claim 6, comprising: The data analysis platform unit further includes a database reading unit, The system, wherein the database reading unit reads from the database the secure sensitive information associated with the analysis result-related information that is the target of decryption processing by the probabilistic decryption unit in the trusted execution environment.
8. 3. A system according to claim 2, comprising: the pseudonymization processing unit converts the sensitive information into the pseudonym information by using a common first key regardless of the value of the sensitive information, the probabilistic encryption processing unit in the trusted execution environment performs encryption processing on a combination of the random number and the pseudonym information by using a common second key regardless of the value of the sensitive information, to generate the secure sensitive information; the probabilistic decryption unit in the data analysis platform performs a decryption process on the secure sensitive information using the second key to generate the pseudonym information; The de-pseudonymization unit converts the pseudonymized information into the sensitive information using the first key.
9. 2. The system of claim 1, The system further includes a database and a database management unit. the database records information derived from a portion of information other than the sensitive information and the secure sensitive information; the database management unit has a dashboard display control unit, the dashboard display control unit controls display of a dashboard related to information recorded in the database or information handled by the system, the dashboard is for displaying information recorded in the database or information handled by the system, or for receiving instructions regarding addition, change, or deletion of information recorded in the database or information handled by the system; The dashboard display control unit controls the dashboard to display the secure sensitive information instead of the sensitive information included in the data.
10. 3. A system according to claim 2, comprising: The system further includes a data receiving unit and a data transmitting unit, the data receiving unit receives, as the received data, encrypted data transmitted from an external system for the individual, group, or organization indicated by the sensitive information; the data transmission unit transmits the transmission data to the external system or a retailer external system for an individual, group, or organization that performs business for the individual, group, or organization indicated by the sensitive information; the received data decryption processing unit performs a decryption process on the received data using a key associated with the external system that transmitted the received data, The system, wherein the transmission data encryption processing unit generates the transmission data by performing encryption processing using a key associated with the external system or the retailer external system to which the transmission data is to be sent.
11. 3. A system according to claim 2, comprising: The system further includes a data receiving unit and a data transmitting unit, the data receiving unit receives, as the received data, encrypted data transmitted from an external system for the individual, group, or organization indicated by the sensitive information; the data transmission unit transmits the transmission data to the external system or a retailer external system for an individual, group, or organization that performs business for the individual, group, or organization indicated by the sensitive information; the data analysis unit includes an analysis result generation unit, a recommendation content generation unit, and a command generation unit; the analysis result generation unit performs an analysis of the data using one or both of the pseudonym information and the portion of the information other than the sensitive information, and generates analysis result information; the recommended content generation unit generates, based on the analysis result information generated by the analysis result generation unit, recommended content information indicating recommendations to the individual, group, or organization indicated by the sensitive information associated with the pseudonym information, or to the external system for the individual, group, or organization; the command generation unit generates, based on the analysis result information generated by the analysis result generation unit, command information indicating a command executable in the external system for the individual, group, or organization indicated by the sensitive information associated with the pseudonym information; The analysis result related information includes one or more of the analysis result information, the recommended content information, or the command information.
12. 12. The system of claim 11, the recommendation content information indicates recommendations regarding power consumption in the external system; The command information indicates commands that can be executed by a device of the external system.
13. 13. A system according to claim 12, comprising: The system further comprises a database; the database includes a customer information table, an edge device information table, an edge device data table, an electricity plan table, a retailer recommendation table, and an execution command table; the customer information table records information about an individual, group, or organization indicated by the sensitive information; the edge device information table records information or specifications about devices included in the external system; the edge device data table records information acquired by a device included in the external system and provided to the system from the external system; the power plan table records the recommendation content information generated by the recommendation content generation unit, the recommendation content information indicating a power consumption plan recommended to the external system; the retailer recommendation table records the recommendation content information generated by the recommendation content generation unit, and indicates information to be proposed regarding power consumption in the external system so that a plan regarding power consumption recorded in the power plan table is applied to the external system; The execution command table records the command information generated by the command generation unit.
14. A method performed by a system, comprising: a pseudonymization processing step of converting, in a trusted execution environment, sensitive information in data including a portion of sensitive information and a portion of information other than the sensitive information into pseudonym information associated with the sensitive information; a probabilistic encryption processing step of encrypting a combination of a random number and the pseudonym information in the trusted execution environment to generate secure sensitive information; a probabilistic decryption step of performing a decryption process on the secure sensitive information within a data analysis platform to generate the pseudonym information; a data analysis step of performing analysis on the data within the data analysis platform using one or both of the pseudonymous information generated by the probabilistic decryption step and the portion of the information other than the sensitive information.
15. A program, The program includes: a pseudonymization processing step of converting, in a trusted execution environment, sensitive information in data including a portion of sensitive information and a portion of information other than the sensitive information into pseudonym information associated with the sensitive information; a probabilistic encryption processing step of encrypting a combination of a random number and the pseudonym information in the trusted execution environment to generate secure sensitive information; a probabilistic decryption step of performing a decryption process on the secure sensitive information within a data analysis platform to generate the pseudonym information; A program for executing, within the data analysis platform, a data analysis step that performs analysis on the data using one or both of the pseudonymous information generated by the probabilistic decryption step and the portion of the information other than the sensitive information.
Citation Information
Patent Citations
Multi-tenancy trusted data anonymization
US20230022539A1