Information processing system, information processing method, and information processing device
The information processing system enhances user data combination accuracy by using integrated IDs associated with common authentication IDs to link and merge user data across different services, addressing the challenges of data set matching and user consent management.
Patent Information
- Application Number
- JP2023207972
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-08
- Publication Date
- 2025-06-19
- Estimated Expiration
- 2043-12-08
AI Technical Summary
Existing methods struggle to accurately combine user data from different services, particularly when features extracted from multiple data sets are similar, leading to issues in identifying and merging data sets corresponding to the same user.
An information processing system that issues an integrated ID associated with a common authentication ID, allowing for the accurate combination of user data across different services by using the integrated ID as a key to associate and collate user data from multiple sources.
Improves the accuracy of combining user data by ensuring that data sets corresponding to the same user can be accurately identified and merged, while also facilitating the management of user consent for data sharing across services.
Smart Images

Figure 2025092226000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing system, an information processing method, and an information processing apparatus.
Background Art
[0002] A method for analyzing customer information obtained by various means in order to analyze customer behavior is known (see, for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In the prior art, when features extracted from each of a plurality of data sets match or are similar, the data sets are combined with each other, but there has been a problem that data sets corresponding to exactly the same user cannot be accurately combined.
[0005] Therefore, the present invention has been made in view of these points, and an object thereof is to improve the accuracy of combining user data.
Means for Solving the Problems
[0006] In the information processing system according to the first aspect of the present invention, it includes a first device and a second device. The first device issues an integrated ID, which is an ID for identifying a user authenticated in a predetermined authentication service in a first service that is a service different from the authentication service, in association with a common authentication ID, which is an ID for identifying a user in the predetermined authentication service. An ID transmission unit that transmits the issued integrated ID to a device that provides the first service and a device that provides a second service that is a service different from the first service, and transmits the issued integrated ID and the common authentication ID corresponding to the integrated ID to the second device in association with each other. The second device includes a first storage unit that stores first user data, which is user data indicating the behavior content of each of the plurality of users in the first service, acquired in association with the integrated ID of each of the plurality of users, and a second storage unit that stores second user data, which is user data indicating the behavior content of each of the plurality of users in the second service, acquired in association with the common authentication ID. A related ID data storage unit that stores related ID data in which the common authentication ID transmitted by the ID transmission unit and the integrated ID corresponding to the common authentication ID are associated with each other, a generation request acquisition unit that acquires a generation request for requesting a reference to user information from an account, and a generation unit that generates collation data in which the user data included in the first user data and the second user data is associated with each other using as keys the integrated ID included in the first user data and the integrated ID corresponding to the common authentication ID associated with the second user data, and collates the user data permitted to be referenced by the account that transmitted the generation request.
[0007] The generation request acquisition unit may acquire a generation request including the common authentication ID or the integrated ID of one or more users for which user data is to be generated, and the generation unit may generate the collation data corresponding to the integrated ID included in the generation request or the common authentication ID included in the generation request among the collation data.
[0008] The second device may further include an authority management unit that manages an account for referring to user data and an integrated ID of a user whose reference is permitted by using the account.
[0009] When the ID transmission unit obtains consent from a user who receives the issuance of the integrated ID to provide the user's information, the ID transmission unit transmits consent information in which information indicating that consent has been obtained from the user is associated with the integrated ID of the user to the second device. The second device further includes a consent information acquisition unit that acquires the consent information. The authority management unit may manage the integrated ID of the user included in the consent information as the integrated ID of a user that can be referred to by the account.
[0010] When the ID transmission unit obtains consent from a user who receives the issuance of the integrated ID to provide the user's information, the ID transmission unit further transmits the consent information in which the content of the consent obtained from the user, which specifies the disclosure range of the accounts that can be provided, is associated with the consent information to the second device. The authority management unit may manage the integrated ID of the user included in the consent information as the integrated ID of a user that can be referred to by the accounts within the disclosure range specified by the content of the consent indicated by the consent information.
[0011] The ID transmission unit further transmits consent information in which items of user data to which the user has consented to be provided are associated with the second device. The authority management unit manages the items to which the user indicated by the consent information has consented as items that can be referred to by the account among the data included in the user data. The generation unit generates matching data in which the user data included in the first user data and the second user data are associated with each other using the integrated ID included in the first user data and the integrated ID corresponding to the common authentication ID included in the second user data as keys, and the matching data is obtained by matching the items permitted to be referred to by the account that transmitted the generation request.
[0012] The issuing unit may issue the integrated ID of the user on the condition that consent to providing the user's information to a third party has been obtained.
[0013] The second storage unit stores second user data in which a hashed common authentication ID obtained by hashing the common authentication ID is associated with the behavior content of each of the plurality of users in the second service. The associated ID data storage unit stores the associated ID data in which the hashed common authentication ID is associated with the integrated ID corresponding to the common authentication ID. The generation unit generates the matching data in which the user data included in the first user data and the second user data is associated with the integrated ID included in the first user data and the integrated ID corresponding to the hashed common authentication ID included in the second user data as keys, and the matching data may be generated by matching the user data for which reference by the account that transmitted the generation request is permitted.
[0014] The information of the account that requests reference to the user's information may be independent of the information of the account that manages the access right to the first device.
[0015] In the information processing method according to the second aspect of the present invention, a unified ID that is an ID for identifying a user authenticated in a predetermined authentication service and executed by a computer in a first service that is a service different from the authentication service is issued in association with a common authentication ID that is an ID for identifying a user in the predetermined authentication service; a step of transmitting the issued unified ID to a device that provides the first service and a device that provides a second service that is a service different from the first service; a step of obtaining a generation request from an account that requests reference to user information; a first storage unit that stores first user data, which is user data indicating the behavior content of each of the plurality of users in the first service, obtained in association with the unified ID of each of the plurality of users; a second storage unit that stores second user data, which is user data indicating the behavior content of each of the plurality of users in the second service, obtained in association with the common authentication ID; a related ID data storage unit that stores related ID data associating the common authentication ID and the unified ID corresponding to the common authentication ID; referring to the first user data and the user data included in the second user data, the unified ID included in the first user data and the unified ID corresponding to the common authentication ID associated with the second user data as keys, generating matching data in which the user data is associated, and generating the matching data in which the user data permitted to be referred to by the account that transmitted the generation request is matched.
[0016] In the information processing apparatus according to the third aspect of the present invention, an integrated ID which is an ID for identifying a user authenticated in a predetermined authentication service in a first service which is a service different from the authentication service is issued in association with a common authentication ID which is an ID for identifying a user in the predetermined authentication service; an ID transmission unit that transmits the issued integrated ID to a device that provides the first service and a device that provides a second service which is a service different from the first service; a first storage unit that stores first user data which is user data indicating the behavior content of each of the plurality of users in the first service, obtained in association with the integrated ID of each of the plurality of users; a second storage unit that stores second user data which is user data indicating the behavior content of each of the plurality of users in the second service, obtained in association with the common authentication ID; a related ID data storage unit that stores related ID data associating the common authentication ID and the integrated ID corresponding to the common authentication ID; a generation request acquisition unit that acquires a generation request from an account that requests reference to user information; and a generation unit that generates collation data in which the user data included in the first user data and the second user data is associated with the integrated ID included in the first user data and the integrated ID corresponding to the common authentication ID associated with the second user data as keys, and collates the user data permitted to be referenced by the account that transmitted the generation request.
Effect of the Invention
[0017] According to the present invention, there is an effect of improving the accuracy of combining user data. According to the present invention, it is possible to easily obtain and manage consent for third-party provision of user data.
Brief Description of the Drawings
[0018]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
[0019] [Overview of Information Processing System S] FIG. 1 is a diagram for explaining the overview of the information processing system S. The information processing system S is a system for processing and analyzing user data. The information processing system S includes a first device 1, a second device 2, a third device 3, a fourth device 4, an information terminal 5, and a management device 6.
[0020] The first device 1 is a device that provides an authentication service. Based on the authentication request of the user obtained from the third device 3, the first device 1 authenticates the user and transmits the authentication result (for example, the authorization of the permissions permitted to the user) to the third device 3.
[0021] The second device 2 is a device for collecting and processing data related to the user's behavior (hereinafter referred to as "user data"). Although the details of the user data will be described later, it includes information related to the user's attributes and information related to the user's behavior history. The second device 2 acquires user data from the third device 3 and the fourth device 4, and processes and outputs the user data acquired in response to a request from an account that uses the user data. As an example, the second device 2 is a device for providing a data clean room (DCR (Data Clean Room)). In the second device 2, the information accessible for each account that requests the use of data is controlled.
[0022] The third device 3 provides the first service. The first service is a web service provided on the Internet, such as services like information provision, video, payment, e-commerce, etc. The third device 3 collects the behavior history of the users who receive the service. The behavior history of the users is, for example, the viewed content or viewing time in a video distribution service, the purchase behavior in e-commerce, etc. The fourth device 4 provides the second service. The second service is a service different from the first service, such as a web service provided by another operator, etc.
[0023] The information terminal 5 is a terminal used by the users who use the service. The information terminal 5 is, for example, a smartphone, a tablet, or a personal computer. The user uses the first service and the second service provided by the third device 3 and the fourth device 4 respectively via the information terminal 5.
[0024] The management device 6 is a device used by enterprises, users, etc. that make use of the user data stored in the second device 2. The management device 6 sends an instruction to process the user data to the second device 2 and acquires the data generated by the second device 2 after processing.
[0025] The processing in the information processing system S will be described. The third device 3 transmits an authentication request to the first device 1 ((1) in FIG. 1). The authentication request is information that requests authentication of a user who uses a service. The authentication request includes information for identifying a user who uses a service and information for identifying the service. The first device 1 authenticates the user related to the authentication request in response to the authentication request acquired from the third device 3. The first device 1 authenticates the user indicated by the authentication request based on authentication information including a common authentication ID. The common authentication ID is an ID for identifying a user in a predetermined authentication service. In the predetermined authentication service, a user can receive authentication for using a plurality of services using one common authentication ID. The predetermined authentication service is a service that provides so-called single sign-on. The common authentication ID is used as an ID for managing a user in a second service provided by the fourth device 4. In other words, user data collected in the second service is collected in association with the common authentication ID.
[0026] If the integrated ID associated with the authenticated common authentication ID has not been issued, the first device 1 issues an integrated ID in association with the authenticated common authentication ID ((2) in FIG. 1). The integrated ID is an ID for identifying a user authenticated in a predetermined authentication service in a first service that is a service different from the authentication service. The integrated ID is also an ID for combining user data in the first service and user data in the second service in the second device 2. The first device 1 transmits the integrated ID of the authenticated user to the third device 3 ((3) in FIG. 1). The first device 1 transmits related ID data associating the issued integrated ID and the common authentication ID corresponding to the integrated ID to the second device 2 ((4) in FIG. 1).
[0027] The user operates the information terminal 5 and uses the services provided by the third device 3 and the fourth device 4 ((5) in FIG. 1). The third device 3 and the fourth device 4 acquire user data. The user data indicates the user's behavior content in the user's first service or second service. Hereinafter, the user data in the first service acquired by the third device 3 is referred to as first user data, and the user data in the second service acquired by the fourth device 4 is referred to as second user data. The user's behavior content includes, for example, the viewing history of content, the viewing frequency, the viewing time zone, the content of purchased products, and the like. In the fourth device 4, user data is collected in association with the user's common authentication ID, and the collected second user data is transmitted to the second device 2.
[0028] The third device 3 and the fourth device 4 transmit the acquired user data to the second device 2 ((6) in FIG. 1). The second device 2 stores the acquired first user data and second user data.
[0029] The second device 2 acquires a generation request from the management device 6 ((7) in FIG. 1). The generation request is information that requests to generate matching data by matching user data. The generation request is, for example, a query. The generation request includes information for specifying the user data to be extracted and the processing method. The second device 2 generates matching data in response to the received generation request ((8) in FIG. 1). The second device 2 specifies the integrated ID corresponding to the common authentication ID corresponding to the second user data. The second device 2 generates matching data by matching the integrated ID included in the first user data with the integrated ID corresponding to the common authentication ID included in the second user data as keys. The second device 2 transmits the generated matching data to the management device 6 ((9) in FIG. 1).
[0030] By configuring the information processing system S in this way, there is an effect of improving the accuracy of combining user data. Although the first device 1 and the second device 2 have been described as separate bodies, they may be integrally configured.
[0031] [Configuration of the First Device 1] FIG. 2 is a block diagram showing the configuration of the first device 1. The first device 1 includes a communication unit 11, a storage unit 12, and a control unit 13. The control unit 13 includes an issuing unit 131 and an ID transmitting unit 132.
[0032] The communication unit 11 is a communication interface for transmitting and receiving data with other devices via a network. The storage unit 12 is a storage medium including a ROM (Read Only Memory), a RAM (Random Access Memory), an SSD (Solid State Drive), a hard disk drive, and the like. The storage unit 12 stores in advance a program executed by the control unit 13.
[0033] The control unit 13 is a processor such as a CPU (Central Processing Unit). The control unit 13 functions as the issuing unit 131 and the ID transmitting unit 132 by executing the program stored in the storage unit 12.
[0034] The issuing unit 131 issues an integrated ID in association with a common authentication ID. As an example, the issuing unit 131 acquires an authentication request from the third device 3. When the integrated ID in the service provided by the third device 3 corresponding to the common authentication ID included in the authentication request has not been issued, the issuing unit 131 issues an integrated ID in association with the common authentication ID of the user.
[0035] The ID transmitting unit 132 transmits the issued integrated ID to the third device 3 that provides the first service. The ID transmitting unit 132 transmits the issued integrated ID and the common authentication ID corresponding to the integrated ID in association to the second device 2.
[0036] The issuing unit 131 may issue a unified ID for the user on the condition that the user has given consent to provide the acquired user information to a third party. When the issuing unit 131 has acquired an authentication request and the unified ID in the service provided by the third device 3 corresponding to the common authentication ID included in the authentication request has not been issued, the issuing unit 131 causes the information terminal 5 to display a screen (hereinafter referred to as the "consent selection screen") for prompting the user to select to consent to providing the acquired user data to a third party. When the user selects to consent to providing the acquired user data to a third party on the consent selection screen displayed on the information terminal 5, the issuing unit 131 issues a unified ID.
[0037] With the first device 1 configured in this way, it is possible to reliably obtain consent for the utilization of the user data to be acquired. In addition, by issuing a unified ID to the user who has given consent and collecting the user data, it is possible to avoid the failure of matching the data collected after obtaining consent, and the accuracy of being able to utilize the data collected based on the unified ID can be improved.
[0038] When the issuing unit 131 has obtained the user's consent, the issuing unit 131 may transmit to the second device 2 that the user has consented to the utilization of the data. When the ID transmission unit 132 has obtained consent from the user who receives the issuance of the unified ID to provide the information of the user, the ID transmission unit 132 transmits consent information indicating that consent has been obtained from the user, in association with the unified ID of the user, to the second device 2.
[0039] When the ID transmission unit 132 obtains consent from a user who receives the issuance of the integrated ID to provide the user's information, the consent information obtained from the user and further associated with the consent content for specifying the disclosure range of the accounts that can be provided is transmitted to the second device 2. As an example, the issuance unit 131 displays a consent selection screen including information indicating the destination of the user data. The ID transmission unit 132 transmits to the second device 2 the consent information associated with the consent content indicating that the user has consented to use the destination displayed on the consent selection screen as the account within the disclosure range.
[0040] Also, the accounts within the disclosure range may be specified according to the timing when consent is obtained. In this case, the consent information associated with the information indicating the acquisition timing when consent is obtained may be transmitted to the second device 2.
[0041] The ID transmission unit 132 may also transmit to the second device 2 the consent information further associated with the items of data for which the user has consented to provide. As an example, the item is a column corresponding to the item collected as user data. As an example, the issuance unit 131 may display on the consent selection screen a screen including information that can be provided to a third party among the information collected as user data. The ID transmission unit 132 transmits to the second device 2 the consent information associated with the corresponding column displayed on the consent selection screen.
[0042] Also, the issuance unit 131 may display on the consent selection screen a screen for allowing the user to select information that can be provided to a third party among the information collected as user data. In this case, on the consent selection screen, the consent information associated with the column corresponding to the information selected by the user is transmitted to the second device 2.
[0043] [Configuration of the second device 2] FIG. 3 is a block diagram showing the configuration of the second device 2. The second device 2 includes a communication unit 21, a storage unit 22, and a control unit 23. The storage unit 22 includes a first user data storage unit 221, a second user data storage unit 222, and an associated ID data storage unit 223. The control unit 23 includes a user data acquisition unit 231, a generation request acquisition unit 232, a generation unit 233, an authority management unit 234, and a consent information acquisition unit 235.
[0044] The communication unit 21 is a communication interface for transmitting and receiving data to and from other devices via a network. The storage unit 22 is a storage medium including a ROM, a RAM, an SSD, a hard disk drive, etc. The storage unit 22 stores in advance a program executed by the control unit 23.
[0045] The first user data storage unit 221 stores first user data, which is user data indicating the behavior content of each of a plurality of users in a first service acquired in association with the integration ID of each of the plurality of users. The second user data storage unit 222 stores in association a common authentication ID of each of a plurality of users and second user data, which is user data indicating the behavior content of each of the plurality of users in a second service. An example of the data structure of the first user data and the second user data is shown in FIG. 4. In the first user data and the second user data, an integration ID, data indicating the attributes of the user corresponding to the integration ID, and data indicating the behavior content of the user are associated (FIG. 4(a)). In the second user data, a common authentication ID, data indicating the attributes of the user, and data indicating the behavior content of the user are associated (FIG. 4(b)). The data indicating the attributes of the user is, for example, the age, gender, residential area, etc. of the user. The behavior content of the user is, for example, information such as the browsing history, browsing frequency, and purchased products of the content in each service. Note that, as will be described later, the common authentication ID associated in the second user data may be a value obtained by hashing the common authentication ID.
[0046] The related ID data storage unit 223 stores related ID data that associates a common authentication ID with an integrated ID corresponding to the common authentication ID. FIG. 5 is a diagram showing an example of the data structure of the related ID data stored in the related ID data storage unit 223. In the related ID data shown in FIG. 5(a), a "common authentication ID" and an "integrated ID" are associated. The "common authentication ID" indicates the common authentication ID targeted by the record. The "integrated ID" indicates the integrated ID associated with the common authentication ID in the first service.
[0047] In the information system S, services different from the first service and the second service may be provided, or devices different from the third device 3 and the fourth device 4 may provide the service. Note that the service may be provided in the third device 3 or the fourth device 4. In this case, user data is collected for each service. An integrated ID corresponding to the common authentication ID may be issued for a plurality of services. An example of the data structure of the related ID data in this case is shown in FIG. 5(b). In FIG. 5(b), a "service ID" is further associated. The "service ID" is associated. The "service ID" is an ID for identifying the service for which the integrated ID is used and associated with the record.
[0048] The control unit 23 is a processor such as a CPU (Central Processing Unit). By executing the program stored in the storage unit 22, the control unit 23 functions as a user data acquisition unit 231, a generation request acquisition unit 232, a generation unit 233, an authority management unit 234, and a consent information acquisition unit 235.
[0049] The user data acquisition unit 231 acquires first user data and second user data from the third device 3 and the fourth device 4. The user data acquisition unit 231 stores the acquired first user data and second user data in the first user data storage unit 221 and the second user data storage unit 222, respectively. The user data acquisition unit 231 is included in the user data acquired from the fourth device 4.
[0050] The generation request acquisition unit 232 acquires a generation request from an account that requests reference to user information. The account is used by a company or user that utilizes user data for using the second device 2. As will be described later, the authority management unit 234 manages referenceable user data for each account. The generation request acquisition unit 232 acquires a generation request from the management device 6 used by the account.
[0051] The generation unit 233 generates collation data in which the user data included in the first user data and the second user data is associated with the integration ID included in the first user data and the integration ID corresponding to the common authentication ID included in the second user data as keys, and collates the user data permitted to be referenced by the account that has transmitted the generation request. The generation unit 233 inquires of the authority management unit 234 about the user data that can be referenced by the account that has transmitted the generation request, and specifies the user data that can be referenced by the account. The generation unit 233 refers to the related ID data to specify the integration ID corresponding to the common authentication ID included in the second user data, and uses the specified integration ID as a key to collate the user data included in the first user data and the user data included in the second user data that can be referenced by the specified account.
[0052] When the integration ID is different for each service to be collated, the generation request acquisition unit 232 acquires a generation request further including the service ID of the first service to be collated. The generation unit 233 may specify the integration ID corresponding to the common authentication ID based on the acquired service ID.
[0053] The generation request acquisition unit 232 may acquire a generation request including the integration ID or the common authentication ID of one or more users for whom user data is to be generated. That is, the generation request may include the integration ID of the user for whom collation data is to be generated, or may include the common authentication ID corresponding to the integration ID of the user for whom collation data is to be generated.
[0054] The generation unit 233 generates matching data corresponding to the integrated ID included in the generation request or the common authentication ID included in the generation request. When the integrated ID of the user for whom the matching data is to be generated is included in the generation request, the generation unit 233, among the user data included in the first user data, the user data associated with the integrated ID, and among the user data included in the second user data, the user data associated with the integrated ID, uses the integrated ID as a key to match the user data that can be referenced by the account and generates matching data. When the generation request includes a common authentication ID, the related ID data is referenced to identify the integrated ID corresponding to the common authentication ID, and the process of generating the above-mentioned matching data is executed based on the identified integrated ID.
[0055] By configuring the information processing system S in this way, there is an effect of improving the accuracy of combining user data collected in different services.
[0056] The management of permissions for each account will be described. The permission management unit 234 manages an account for referencing user data and the integrated ID corresponding to the user data of the user who is permitted to reference the account by using the account. The permission management unit 234 refers to the permission information stored in the storage unit 22 to identify the user data that can be referenced by the account that can be referenced by the account and inputs it to the generation unit 233. The permission information stored in the storage unit 22 may include executable queries for each account, or may include integrated IDs or common authentication IDs that can be referenced for each account. The permission management unit 234 updates the permission information of the account when the account is registered.
[0057] The second device 2 may be configured to store that the user has consented to the provision of user data to a third party. The consent information acquisition unit 235 acquires the consent information transmitted by the first device 1. The authority management unit 234 manages the integrated ID of the user included in the consent information acquired by the consent information acquisition unit 235 as the integrated ID of the user that the account can refer to. The authority management unit 234 stores the integrated ID of the user included in the consent information acquired by the consent information acquisition unit 235 in the authority information stored in the storage unit 22.
[0058] The second device 2 may be configured to manage user data that can be referred to for each account that utilizes the user data.
[0059] The authority management unit 234 manages the integrated ID of the user included in the consent information as the integrated ID of the user that the accounts within the disclosure scope specified by the consent content indicated by the consent information can refer to. The authority management unit 234 stores the accounts within the disclosure scope specified based on the consent information in the authority information in association with the integrated ID included in the consent information. As an example, the consent information may include the accounts that are the disclosure scope. Further, the storage unit 22 stores information associating the time when consent was obtained with the accounts that are the disclosure scope, and the authority management unit 234 may specify the accounts within the disclosure scope based on the time when the consent included in the consent information was obtained.
[0060] The second device 2 may be configured to generate matching data based on the columns that can be referred to for each account. The authority management unit 234 manages the data items indicated by the consent information as the items that the account can refer to among the data included in the user data. In the consent information, as an example, it includes columns that can be disclosed to a third party. The authority management unit 234 stores the columns associated with the consent information acquired by the consent information acquisition unit 235 in the authority information. The authority management unit 234 specifies the columns that the account can refer to in response to an inquiry from the generation unit 233.
[0061] In this way, it becomes possible to appropriately manage the consent information in pairs with the integration ID. Therefore, compared with separately managing the consent information and integrating the consent information data, the man-hours required for obtaining consent from a third party are reduced, it becomes easier to obtain consent, and it also becomes easier to manage the obtained third-party-provided consent.
[0062] The generation unit 233 generates matching data in which the user data included in the first user data and the second user data is associated with the integration ID included in the first user data and the integration ID corresponding to the common authentication ID included in the second user data as keys, and generates matching data obtained by matching items for which reference by the account that sent the generation request is permitted. That is, the generation unit 233 inquires of the authority management unit 234 about the columns that can be referenced by the account that sent the generation request, and generates matching data based on the first user data narrowed down to the columns specified by the authority management unit 234 and the second user data narrowed down to the columns specified by the authority management unit 234.
[0063] With the second device 2 configured in this way, it is possible to limit the information that can be referenced by the account that utilizes the user data, and it becomes possible to securely manage the user data.
[0064] In the second device, instead of the common authentication ID, the second device 2 may be configured to manage the user's information in association with the hashed common authentication ID. In this case, the related ID data storage unit 223 stores related ID data in which the hashed common authentication ID obtained by hashing the common authentication ID and the integration ID corresponding to the common authentication ID are associated. The hashed common authentication ID indicates a hash value generated based on a predetermined hash function for the common authentication ID.
[0065] The user data acquisition unit 231 acquires, from the fourth device 4, second user data indicating the behavior content in the second service associated with the hashed common authentication ID of each of the plurality of users.
[0066] User data for which matching data is to be generated may be specified based on the hashed common authentication ID. The generation request acquisition unit 232 acquires a generation request including the common authentication IDs of one or more users for which matching data is to be generated. The generation unit 233 calculates a hashed common authentication ID corresponding to the common authentication ID included in the acquired generation request, and specifies an integration ID based on the calculated hashed common authentication ID. Note that the hashed common IDs of one or more users for which matching data is to be generated may be included in the generation request.
[0067] The generation unit 233 generates matching data in which the user data included in the first user data and the second user data is associated with the integration ID included in the first user data and the integration ID corresponding to the hashed common authentication ID included in the second user data as keys, and the matching data is obtained by matching the user data for which reference by the account that transmitted the generation request is permitted. That is, the generation unit 233 specifies the integration ID corresponding to the hashed common authentication ID in the related ID data, and generates matching data based on the specified integration ID. By configuring the information processing apparatus 1 in this way, there is no need to hold the common authentication ID in the database, and a secure system can be configured.
[0068] By being configured in this way, since only the hashed information exists for both the common authentication ID associated with the second user data held in the second apparatus and the common authentication ID included in the related ID data, the common authentication ID itself cannot be acquired from the account that utilizes the user data, and the common authentication ID, which is important information serving as the basis for authentication, is protected at a higher level.
[0069] Note that the second device 2 may store information for authenticating an account for utilizing user data. Note that the information of the account for utilizing user data in the second device is independent of the information of the account for managing the access right to the first device. That is, enterprises, users, etc. that utilize user data cannot access the information for managing the integrated ID issued by the first device and the common authentication ID corresponding to the integrated ID using the information of the account for utilizing user data in the second device. By configuring the first device 1 and the second device 2 in this way, the common authentication ID, which is important information serving as the basis for authentication, will be protected at a higher level.
[0070] [Processing flow in the second device 2] FIG. 6 is a flowchart showing the processing flow in the second device 2. The user data acquisition unit 231 acquires first user data (S01). The user data acquisition unit 231 acquires second user data (S02). The user data acquisition unit 231 stores the acquired first user data and second user data in the first user data storage unit 221 and the second user data storage unit 222, respectively.
[0071] The generation request acquisition unit 232 acquires a generation request (S03). The generation unit 233 identifies user data that can be referred to by the account that has sent the generation request to the authority management unit 234 (S04). The generation unit 233 identifies the integrated ID corresponding to the common authentication ID (S05). The generation unit 233 generates verification data by verifying the first user data and the second user data based on the user data that can be referred to by the account that has sent the identified generation request (S06). Then, the second device 2 ends the processing.
[0072] Note that according to the present invention, it becomes possible to contribute to Goal 9, "Build the infrastructure for industry and innovation," of the Sustainable Development Goals (SDGs) led by the United Nations.
[0073] As described above, the present invention has been explained using embodiments. However, the technical scope of the present invention is not limited to the scope described in the above embodiments, and various modifications and changes are possible within the scope of the gist. For example, all or part of the device can be configured by functionally or physically dispersing and integrating it in any unit. Also, new embodiments resulting from any combination of a plurality of embodiments are included in the embodiments of the present invention. The effects of the new embodiments resulting from the combination have the effects of the original embodiments combined.
Explanation of Signs
[0074] 1 First device 2 Second device 3 Third device 4 Fourth device 5 Information terminal 6 Management device 11 Communication unit 12 Storage unit 13 Control unit 21 Communication unit 22 Storage unit 23 Control unit 131 Issuing unit 132 ID transmission unit 221 First user data storage unit 222 Second user data storage unit 223 Related ID data storage unit 231 User data acquisition unit 232 Generation request acquisition unit 233 Generation unit 234 Authority management unit 235 Consent information acquisition unit
Claims
1. An information processing system having a first device and a second device, The first device is An issuing unit that issues an integrated ID, which is an ID for identifying a user authenticated in a predetermined authentication service in a first service that is a service different from the authentication service, in association with a common authentication ID that is an ID for identifying the user in the predetermined authentication service; An ID transmission unit that transmits the issued integrated ID to a device that provides the first service and a device that provides a second service that is a service different from the first service, and transmits the issued integrated ID and the common authentication ID corresponding to the integrated ID to the second device in association with each other; and has The second device is A first storage unit that stores first user data, which is user data indicating the behavior content of each of the plurality of users in the first service, acquired in association with the integrated ID of each of the plurality of users; A second storage unit that stores second user data, which is user data indicating the behavior content of each of the plurality of users in the second service, acquired in association with the common authentication ID; An associated ID data storage unit that stores associated ID data in which the common authentication ID transmitted by the ID transmission unit and the integrated ID corresponding to the common authentication ID are associated with each other; A generation request acquisition unit that acquires a generation request for referring to user information from an account; A generation unit that generates collation data in which the user data included in the first user data and the second user data is associated with the integrated ID included in the first user data and the integrated ID corresponding to the common authentication ID associated with the second user data as keys, and collates the user data permitted to be referred to by the account that transmitted the generation request; and has An information processing system.
2. The generation request acquisition unit acquires a generation request including a common authentication ID or an integration ID of one or more users for whom user data is to be generated. The generation unit generates the matching data corresponding to the integration ID included in the generation request or the common authentication ID included in the generation request among the matching data. The information processing system according to claim 1.
3. The second device further includes an authority management unit that manages an account for referring to user data and an integration ID of a user who is permitted to refer by using the account. The information processing system according to claim 1.
4. When the ID transmission unit obtains consent from the user who receives the issuance of the integration ID to provide the information of the user, the ID transmission unit transmits consent information in which information indicating that consent has been obtained from the user is associated with the integration ID of the user to the second device. The second device further includes a consent information acquisition unit that acquires the consent information. The authority management unit manages the integration ID of the user included in the consent information as the integration ID of a user who can be referred to by the account. The information processing system according to claim 3.
5. When the ID transmission unit obtains consent from the user who receives the issuance of the integration ID to provide the information of the user, the ID transmission unit transmits the consent information in which the consent content obtained from the user and the consent content for specifying the disclosure range of the account that can be provided are further associated to the second device. The authority management unit manages the integration ID of the user included in the consent information as the integration ID of a user who can be referred to by the account within the disclosure range specified by the consent content indicated by the consent information. The information processing system according to claim 4.
6. The ID transmission unit transmits consent information, which further associates items of user data that the user has consented to be provided, to the second device. The authority management unit manages the items consented to by the user indicated in the consent information as items that can be referred to by the account among the data included in the user data. The generation unit generates matching data in which the user data included in the first user data and the second user data is associated with the integrated ID included in the first user data and the integrated ID corresponding to the common authentication ID included in the second user data as keys, and generates the matching data obtained by matching the items permitted to be referred to by the account that has transmitted the generation request. The information processing system according to any one of claims 3 to 5.
7. The issuing unit issues the integrated ID of the user on the condition that consent to provide the user's information to a third party has been obtained. The information processing system according to any one of claims 1 to 5.
8. The second storage unit stores second user data in which the hashed common authentication ID obtained by hashing the common authentication ID is associated with the action content of each of the plurality of users in the second service. The related ID data storage unit stores the related ID data in which the hashed common authentication ID is associated with the integrated ID corresponding to the common authentication ID. The generation unit generates the matching data in which the user data included in the first user data and the second user data is associated with the integrated ID included in the first user data and the integrated ID corresponding to the hashed common authentication ID included in the second user data as keys, and generates the matching data obtained by matching the user data permitted to be referred to by the account that has transmitted the generation request. The information processing system according to claim 1.
9. The information of the account that requests reference to the user's information is independent of the information of the account that manages the access right to the first device. The information processing system according to claim 1.
10. Executed by a computer, issuing a unified ID, which is an ID for identifying a user authenticated in a predetermined authentication service in a first service that is a service different from the authentication service, in association with a common authentication ID that is an ID for identifying the user in the predetermined authentication service; transmitting the issued unified ID to a device that provides the first service and a device that provides a second service that is a service different from the first service; obtaining a generation request from an account that requests reference to user information; referring to a first storage unit that stores first user data, which is user data indicating the behavior content of each of a plurality of users in the first service, obtained in association with the unified ID of each of the plurality of users, a second storage unit that stores second user data, which is user data indicating the behavior content of each of the plurality of users in the second service, obtained in association with the common authentication ID, and an associated ID data storage unit that stores associated ID data associating the common authentication ID with the unified ID corresponding to the common authentication ID, and generating matching data in which the user data included in the first user data and the second user data is associated with the unified ID included in the first user data and the unified ID corresponding to the common authentication ID associated with the second user data as keys, and the matching data is obtained by matching the user data permitted to be referred to by the account that transmitted the generation request; An information processing method having the above.
11. An issuing unit that issues an integrated ID, which is an ID for identifying a user authenticated in a predetermined authentication service in a first service that is a service different from the authentication service, in association with a common authentication ID that is an ID for identifying a user in the predetermined authentication service. An ID transmission unit that transmits the issued integrated ID to a device that provides the first service and a device that provides a second service that is a service different from the first service. A first storage unit that stores first user data, which is user data indicating the behavior content of each of the plurality of users in the first service, obtained in association with the integrated ID of each of the plurality of users. A second storage unit that stores second user data, which is user data indicating the behavior content of each of the plurality of users in the second service, obtained in association with the common authentication ID. A related ID data storage unit that stores related ID data associating the common authentication ID and the integrated ID corresponding to the common authentication ID. A generation request acquisition unit that acquires a generation request from an account that requests reference to user information. A generation unit that generates matching data in which the user data included in the first user data and the second user data is associated with the integrated ID included in the first user data and the integrated ID corresponding to the common authentication ID associated with the second user data as keys, and the matching data is obtained by matching the user data permitted to be referenced by the account that transmitted the generation request. An information processing apparatus having the above.
Citation Information
Patent Citations
Information processing system, and program
JP2016126609A