Information processing system, information processing method, and information processing device
The information processing system enhances user data combination accuracy by using integrated IDs to match user data across services, addressing previous inefficiencies and improving consent management.
Patent Information
- Application Number
- JP2024045588
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-21
- Publication Date
- 2025-06-19
AI Technical Summary
Existing methods for combining user data from different services struggle to accurately match data sets corresponding to the same user, leading to inefficiencies in data integration.
An information processing system that issues an integrated ID associated with a common authentication ID, allowing for the accurate combination of user data across different services by using the integrated ID as a key for matching user data.
Improves the accuracy of combining user data by ensuring that data sets from different services can be correctly matched and integrated, while also simplifying the management of user consent for data sharing.
Smart Images

Figure 2025092340000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing system, an information processing method, and an information processing apparatus.
Background Art
[0002] A method for analyzing customer information obtained by various means in order to analyze customer behavior is known (see, for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In the prior art, when features extracted from each of a plurality of data sets match or are similar, the data sets are combined, but there has been a problem that data sets corresponding to exactly the same user cannot be accurately combined.
[0005] Therefore, the present invention has been made in view of these points, and an object thereof is to improve the accuracy of combining user data.
Means for Solving the Problems
[0006] In the information processing system according to the first aspect of the present invention, it has a first device and a second device. The first device issues an integrated ID, which is an ID for identifying a user authenticated in a predetermined authentication service in a first service different from the authentication service, in association with a common authentication ID, which is an ID for identifying the user in the predetermined authentication service. An ID transmission unit that transmits the issued integrated ID to a device that provides the first service and a device that provides a second service different from the first service, and transmits the issued integrated ID and the common authentication ID corresponding to the integrated ID to the second device in association with each other. The second device includes a first storage unit that stores first user data, which is user data indicating the behavior content of each of the plurality of users in the first service, acquired in association with the integrated ID of each of the plurality of users, and a second storage unit that stores second user data, which is user data indicating the behavior content of each of the plurality of users in the second service, acquired in association with the common authentication ID. A related ID data storage unit that stores related ID data in which the common authentication ID transmitted by the ID transmission unit and the integrated ID corresponding to the common authentication ID are associated with each other, a generation request acquisition unit that acquires a generation request for requesting a reference to user information from an account, and the first user data and the user data included in the second user data are integrated ID included in the first user data and the integrated ID corresponding to the common authentication ID associated with the second user data. A generation unit that generates matching data in which the user data permitted to be referred to by the account that transmitted the generation request is matched, using the matching data as keys.
[0007] The generation request acquisition unit acquires a generation request including the common authentication ID or the integrated ID of one or more users for which user data is to be generated, and the generation unit may generate the matching data corresponding to the integrated ID included in the generation request or the common authentication ID included in the generation request among the matching data.
[0008] The second device may further include an authority management unit that manages an account for referring to user data and an integrated ID of a user whose reference is permitted by using the account.
[0009] When the ID transmission unit obtains consent from a user who receives the issuance of the integrated ID to provide the user's information, the ID transmission unit transmits consent information in which information indicating that consent has been obtained from the user is associated with the integrated ID of the user to the second device. The second device further includes a consent information acquisition unit that acquires the consent information, and the authority management unit may manage the integrated ID of the user included in the consent information as the integrated ID of the user that can be referred to by the account.
[0010] When the ID transmission unit obtains consent from a user who receives the issuance of the integrated ID to provide the user's information, the ID transmission unit further transmits consent information in which the content of the consent obtained from the user and the content of the consent for specifying the disclosure range of the accounts that can be provided are associated with each other to the second device. The authority management unit may manage the integrated ID of the user included in the consent information as the integrated ID of the user that can be referred to by the accounts within the disclosure range specified by the content of the consent indicated by the consent information.
[0011] The ID transmission unit transmits consent information in which items of user data to which the user has consented to be provided are further associated with each other to the second device. The authority management unit manages the items to which the user indicated by the consent information has consented as the items that can be referred to by the account among the data included in the user data. The generation unit generates matching data in which the user data included in the first user data and the second user data are associated with each other using the integrated ID included in the first user data and the integrated ID corresponding to the common authentication ID included in the second user data as keys, and the matching data is obtained by matching the items permitted to be referred to by the account that transmitted the generation request.
[0012] The issuing unit may issue the integrated ID of the user on the condition that consent to provide the information of the user to a third party has been obtained.
[0013] The second storage unit stores second user data in which a hashed common authentication ID obtained by hashing the common authentication ID is associated with the action content of each of the plurality of users in the second service. The related ID data storage unit stores the related ID data in which the hashed common authentication ID is associated with the integrated ID corresponding to the common authentication ID. The generation unit generates the matching data in which the user data included in the first user data and the second user data is associated with the integrated ID included in the first user data and the integrated ID corresponding to the hashed common authentication ID included in the second user data as keys, and the matching data may be generated by matching the user data for which reference by the account that has transmitted the generation request is permitted.
[0014] The information of the account that requests reference to the information of the user may be independent of the information of the account that manages the access right to the first device.
[0015] In the information processing method according to the second aspect of the present invention, a unified ID that is an ID for identifying a user authenticated in a predetermined authentication service and executed by a computer in a first service that is a service different from the authentication service is issued in association with a common authentication ID that is an ID for identifying a user in the predetermined authentication service; a step of transmitting the issued unified ID to a device that provides the first service and a device that provides a second service that is a service different from the first service; a step of obtaining a generation request from an account that requests reference to user information; a first storage unit that stores first user data, which is user data indicating the behavior content of each of the plurality of users in the first service, obtained in association with the unified ID of each of the plurality of users; a second storage unit that stores second user data, which is user data indicating the behavior content of each of the plurality of users in the second service, obtained in association with the common authentication ID; a related ID data storage unit that stores related ID data associating the common authentication ID with the unified ID corresponding to the common authentication ID; referring to the first user data and the user data included in the second user data, and generating matching data in which the user data included in the first user data and the user data included in the second user data are associated with each other using as keys the unified ID included in the first user data and the unified ID corresponding to the common authentication ID associated with the second user data, and generating the matching data obtained by matching the user data permitted to be referred to by the account that transmitted the generation request.
[0016] In the information processing apparatus according to the third aspect of the present invention, an integrated ID, which is an ID for identifying a user authenticated in a predetermined authentication service in a first service that is a service different from the authentication service, is issued in association with a common authentication ID, which is an ID for identifying a user in the predetermined authentication service. An ID transmission unit that transmits the issued integrated ID to a device that provides the first service and a device that provides a second service that is a service different from the first service. A first storage unit that stores first user data, which is user data indicating the behavior content of each of the plurality of users in the first service, acquired in association with the integrated ID of each of the plurality of users. A second storage unit that stores second user data, which is user data indicating the behavior content of each of the plurality of users in the second service, acquired in association with the common authentication ID. A related ID data storage unit that stores related ID data associating the common authentication ID and the integrated ID corresponding to the common authentication ID. A generation request acquisition unit that acquires a generation request from an account that requests reference to user information. A generation unit that generates collation data in which the user data included in the first user data and the second user data is associated with the integrated ID included in the first user data and the integrated ID corresponding to the common authentication ID associated with the second user data as keys, and the collation data is obtained by collating the user data permitted to be referenced by the account that transmitted the generation request.
Effect of the Invention
[0017] According to the present invention, there is an effect of improving the accuracy of combining user data. According to the present invention, it is possible to easily obtain and manage consent for third-party provision of user data.
Brief Description of the Drawings
[0018]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Embodiments for Carrying Out the Invention
[0019] [Overview of Information Processing System S] FIG. 1 is a diagram for explaining the overview of the information processing system S. The information processing system S is a system for processing and analyzing user data. The information processing system S includes a first device 1, a second device 2, a third device 3, a fourth device 4, an information terminal 5, and a management device 6.
[0020] The first device 1 is a device that provides an authentication service. Based on the authentication request of the user obtained from the third device 3, the first device 1 authenticates the user and transmits the authentication result (for example, the authorization of the permissions permitted to the user) to the third device 3.
[0021] The second device 2 is a device for collecting and processing data related to the user's actions (hereinafter referred to as "user data"). Details of the user data will be described later, but it includes information related to the user's attributes and information related to the user's action history. The second device 2 acquires user data from the third device 3 and the fourth device 4, and processes and outputs the user data acquired in response to a request from the account that uses the user data. As an example, the second device 2 is a device for providing a data clean room (DCR (Data Clean Room)). In the second device 2, the information accessible for each account that requests the use of data is controlled.
[0022] The third device 3 provides the first service. The first service is a web service provided on the Internet, such as services like information provision, video, payment, e-commerce, etc. The third device 3 collects the behavior history of users who receive the service. The user's behavior history is, for example, the viewed content or viewing time in a video distribution service, the purchase behavior in e-commerce, etc. The fourth device 4 provides the second service. The second service is a service different from the first service, such as a web service provided by another operator, etc.
[0023] The information terminal 5 is a terminal used by users who utilize the service. The information terminal 5 is, for example, a smartphone, a tablet, or a personal computer. The user utilizes the first service and the second service provided by the third device 3 and the fourth device 4 respectively via the information terminal 5.
[0024] The management device 6 is a device used by enterprises, users, etc. that make use of the user data stored in the second device 2. The management device 6 sends an instruction to process the user data to the second device 2 and acquires the data generated by the second device 2 through processing.
[0025] The processing in the information processing system S will be described. The third device 3 transmits an authentication request to the first device 1 ((1) in FIG. 1). The authentication request is information that requests authentication of a user who uses a service. The authentication request includes information for identifying a user who uses the service and information for identifying the service. The first device 1 authenticates the user related to the authentication request in response to the authentication request acquired from the third device 3. The first device 1 authenticates the user indicated by the authentication request based on authentication information including a common authentication ID. The common authentication ID is an ID for identifying a user in a predetermined authentication service. In the predetermined authentication service, a user can receive authentication for using a plurality of services using one common authentication ID. The predetermined authentication service is a service that provides so-called single sign-on. The common authentication ID is used as an ID for managing a user in a second service provided by the fourth device 4. In other words, user data collected in the second service is collected in association with the common authentication ID.
[0026] If the integrated ID associated with the authenticated common authentication ID has not been issued, the first device 1 issues an integrated ID in association with the authenticated common authentication ID ((2) in FIG. 1). The integrated ID is an ID for identifying a user authenticated in a predetermined authentication service in a first service that is a service different from the authentication service. The integrated ID is also an ID for combining user data in the first service and user data in the second service in the second device 2. The first device 1 transmits the integrated ID of the authenticated user to the third device 3 ((3) in FIG. 1). The first device 1 transmits related ID data associating the issued integrated ID and the common authentication ID corresponding to the integrated ID to the second device 2 ((4) in FIG. 1).
[0027] The user operates the information terminal 5 and uses the services provided by the third device 3 and the fourth device 4 ((5) in FIG. 1). The third device 3 and the fourth device 4 acquire user data. The user data indicates the user's behavior content in the user's first service or second service. Hereinafter, the user data in the first service acquired by the third device 3 is referred to as first user data, and the user data in the second service acquired by the fourth device 4 is referred to as second user data. The user's behavior content includes, for example, the viewing history of content, the viewing frequency, the viewing time zone, the content of purchased goods, and the like. In the fourth device 4, user data is collected in association with the user's common authentication ID, and the collected second user data is transmitted to the second device 2.
[0028] The third device 3 and the fourth device 4 transmit the acquired user data to the second device 2 ((6) in FIG. 1). The second device 2 stores the acquired first user data and second user data.
[0029] The second device 2 acquires a generation request from the management device 6 ((7) in FIG. 1). The generation request is information that requests to generate matching data by matching user data. The generation request is, for example, a query. The generation request includes information for specifying the user data to be extracted and the processing method. The second device 2 generates matching data in response to the received generation request ((8) in FIG. 1). The second device 2 specifies an integration ID corresponding to the common authentication ID corresponding to the second user data. The second device 2 generates matching data by matching the integration ID included in the first user data with the integration ID corresponding to the common authentication ID included in the second user data as keys. The second device 2 transmits the generated matching data to the management device 6 ((9) in FIG. 1).
[0030] By configuring the information processing system S in this way, there is an effect of improving the accuracy of combining user data. Although the first device 1 and the second device 2 have been described as being separate, they may be integrally configured.
[0031] [Configuration of the First Device 1] FIG. 2 is a block diagram showing the configuration of the first device 1. The first device 1 includes a communication unit 11, a storage unit 12, and a control unit 13. The control unit 13 includes an issuing unit 131 and an ID transmitting unit 132.
[0032] The communication unit 11 is a communication interface for transmitting and receiving data with other devices via a network. The storage unit 12 is a storage medium including a ROM (Read Only Memory), a RAM (Random Access Memory), an SSD (Solid State Drive), a hard disk drive, etc. The storage unit 12 stores in advance a program executed by the control unit 13.
[0033] The control unit 13 is a processor such as a CPU (Central Processing Unit), etc. The control unit 13 functions as the issuing unit 131 and the ID transmitting unit 132 by executing the program stored in the storage unit 12.
[0034] The issuing unit 131 issues an integrated ID in association with a common authentication ID. As an example, the issuing unit 131 acquires an authentication request from the third device 3. When the integrated ID in the service provided by the third device 3 corresponding to the common authentication ID included in the authentication request has not been issued, the issuing unit 131 issues an integrated ID in association with the common authentication ID of the user.
[0035] The ID transmitting unit 132 transmits the issued integrated ID to the third device 3 that provides the first service. The ID transmitting unit 132 transmits the issued integrated ID and the common authentication ID corresponding to the integrated ID in association to the second device 2.
[0036] The issuing unit 131 may issue a unified ID for the user on the condition that the user has given consent to provide the acquired user information to a third party. When the issuing unit 131 has acquired an authentication request and the unified ID in the service provided by the third device 3 corresponding to the common authentication ID included in the authentication request has not been issued, the issuing unit 131 causes the information terminal 5 to display a screen (hereinafter referred to as the "consent selection screen") for allowing the user to select to consent to providing the acquired user data to a third party. When the user selects to consent to providing the acquired user data to a third party on the consent selection screen displayed on the information terminal 5, the issuing unit 131 issues a unified ID.
[0037] With the first device 1 configured in this way, it is possible to surely obtain consent for the utilization of the user data to be acquired. In addition, by issuing a unified ID to the user who has given consent and collecting the user data, it is possible to avoid the failure of matching the data collected after obtaining consent, and the accuracy of being able to utilize the data collected based on the unified ID can be improved.
[0038] When the issuing unit 131 has obtained the consent of the user, the issuing unit 131 may transmit to the second device 2 that the user has consented to the utilization of the data. When the ID transmitting unit 132 has obtained consent from the user who receives the issuance of the unified ID to provide the information of the user, the ID transmitting unit 132 transmits consent information in which information indicating that the consent has been obtained from the user is associated with the unified ID of the user to the second device 2.
[0039] When the ID transmission unit 132 obtains consent from a user who receives the issuance of the integrated ID to provide the user's information, the consent information obtained from the user and further associated with the consent content for specifying the disclosure range of the accounts that can be provided is transmitted to the second device 2. As an example, the issuance unit 131 displays a consent selection screen including information indicating the destination of the user data. The ID transmission unit 132 transmits consent information associated with the consent content indicating that the user has consented to use the destination displayed on the consent selection screen as the account within the disclosure range to the second device 2.
[0040] Also, the accounts within the disclosure range may be specified according to the timing when consent is obtained. In this case, consent information associated with information indicating the acquisition timing when consent is obtained may be transmitted to the second device 2.
[0041] The ID transmission unit 132 may also transmit consent information further associated with the items of data for which the user has consented to provide to the second device 2. As an example, the item is a column corresponding to the item collected as user data. As an example, the issuance unit 131 may display, on the consent selection screen, a screen including information that can be provided to a third party among the information collected as user data. The ID transmission unit 132 transmits consent information associated with the displayed corresponding column on the consent selection screen to the second device 2.
[0042] Also, the issuance unit 131 may display, on the consent selection screen, a screen that allows the user to select information that can be provided to a third party among the information collected as user data. In this case, consent information associated with the column corresponding to the information selected by the user on the consent selection screen is transmitted to the second device 2.
[0043] [Configuration of the Second Device 2] Figure 3 is a block diagram showing the configuration of the second device 2. The second device 2 includes a communication unit 21, a storage unit 22, and a control unit 23. The storage unit 22 includes a first user data storage unit 221, a second user data storage unit 222, and an associated ID data storage unit 223. The control unit 23 includes a user data acquisition unit 231, a generation request acquisition unit 232, a generation unit 233, an authority management unit 234, and a consent information acquisition unit 235.
[0044] The communication unit 21 is a communication interface for transmitting and receiving data to and from other devices via a network. The storage unit 22 is a storage medium including a ROM, a RAM, an SSD, a hard disk drive, etc. The storage unit 22 stores in advance a program executed by the control unit 23.
[0045] The first user data storage unit 221 stores first user data, which is user data indicating the behavior content of each of a plurality of users in a first service acquired in association with the integration ID of each of the plurality of users. The second user data storage unit 222 stores in association a common authentication ID of each of the plurality of users and second user data, which is user data indicating the behavior content of each of the plurality of users in a second service. An example of the data structure of the first user data and the second user data is shown in FIG. 4. In the first user data and the second user data, an integration ID, data indicating the attributes of the user corresponding to the integration ID, and data indicating the behavior content of the user are associated (FIG. 4(a)). In the second user data, a common authentication ID, data indicating the attributes of the user, and data indicating the behavior content of the user are associated (FIG. 4(b)). The data indicating the attributes of the user is, for example, the age, gender, residential area, etc. of the user. The behavior content of the user is, for example, information such as the browsing history, browsing frequency, and purchased products of the content in each service. Note that, as will be described later, the common authentication ID associated in the second user data may be a hashed value of the common authentication ID.
[0046] The related ID data storage unit 223 stores related ID data associating a common authentication ID with an integrated ID corresponding to the common authentication ID. FIG. 5 is a diagram showing an example of the data structure of the related ID data stored in the related ID data storage unit 223. In the related ID data shown in FIG. 5(a), a "common authentication ID" and an "integrated ID" are associated. The "common authentication ID" indicates the common authentication ID targeted by the record. The "integrated ID" indicates the integrated ID associated with the common authentication ID in the first service.
[0047] In the information system S, services different from the first service and the second service may be provided, or devices different from the third device 3 and the fourth device 4 may provide the service. Note that the service may be provided in the third device 3 or the fourth device 4. In this case, user data is collected for each service. An integrated ID corresponding to the common authentication ID may be issued for each of a plurality of services. An example of the data structure of the related ID data in this case is shown in FIG. 5(b). In FIG. 5(b), a "service ID" is further associated. The "service ID" is associated. The "service ID" is an ID for identifying the service for which the integrated ID is used and is associated with the record.
[0048] The control unit 23 is a processor such as a CPU (Central Processing Unit). The control unit 23 functions as a user data acquisition unit 231, a generation request acquisition unit 232, a generation unit 233, an authority management unit 234, and a consent information acquisition unit 235 by executing the program stored in the storage unit 22.
[0049] The user data acquisition unit 231 acquires first user data and second user data from the third device 3 and the fourth device 4. The user data acquisition unit 231 stores the acquired first user data and second user data in the first user data storage unit 221 and the second user data storage unit 222, respectively. The user data acquired by the user data acquisition unit 231 is included in the data obtained from the fourth device 4.
[0050] The generation request acquisition unit 232 acquires a generation request from an account that requests reference to user information. The account is used by an enterprise or a user who utilizes user data for using the second device 2. As will be described later, the authority management unit 234 manages referenceable user data for each account. The generation request acquisition unit 232 acquires a generation request from the management device 6 used by the account.
[0051] The generation unit 233 generates collation data in which the user data included in the first user data and the second user data is associated with the integration ID included in the first user data and the integration ID corresponding to the common authentication ID included in the second user data as keys, and collates the user data permitted to be referenced by the account that has transmitted the generation request. The generation unit 233 inquires of the authority management unit 234 about the user data that can be referenced by the account that has transmitted the generation request, and specifies the user data that can be referenced by the account. The generation unit 233 refers to the related ID data to specify the integration ID corresponding to the common authentication ID included in the second user data, and uses the specified integration ID as a key to collate the user data included in the first user data and the user data included in the second user data that can be referenced by the specified account.
[0052] When the integration ID is different for each service to be collated, the generation request acquisition unit 232 acquires a generation request further including the service ID of the first service to be collated. The generation unit 233 may specify the integration ID corresponding to the common authentication ID based on the acquired service ID.
[0053] The generation request acquisition unit 232 may acquire a generation request including the integration ID or the common authentication ID of one or more users for whom user data is to be generated. That is, the generation request may include the integration ID of the user for whom the collation data is to be generated, or may include the common authentication ID corresponding to the integration ID of the user for whom the collation data is to be generated.
[0054] The generation unit 233 generates matching data corresponding to the integrated ID included in the generation request or the common authentication ID included in the generation request. When the integrated ID of the user for whom the matching data is to be generated is included in the generation request, the generation unit 233, among the user data included in the first user data, the user data associated with the integrated ID, and among the user data included in the second user data, the user data associated with the integrated ID, using the integrated ID as a key, matches the user data that can be referenced by the account to generate matching data. When the generation request includes a common authentication ID, it refers to the related ID data, identifies the integrated ID corresponding to the common authentication ID, and executes a process of generating the above-mentioned matching data based on the identified integrated ID.
[0055] By configuring the information processing system S in this way, there is an effect of improving the accuracy of combining user data collected in different services.
[0056] The management of permissions for each account will be described. The permission management unit 234 manages an account for referring to user data and an integrated ID corresponding to the user data of the user who is permitted to refer by using the account. The permission management unit 234 refers to the permission information stored in the storage unit 22 to identify the user data that can be referenced by the account that can be referenced by the account, and inputs it to the generation unit 233. The permission information stored in the storage unit 22 may include executable queries for each account, or may include integrated IDs or common authentication IDs that can be referenced for each account. The permission management unit 234 updates the permission information of the account when the account is registered.
[0057] The second device 2 may be configured to store that the user has consented to the provision of user data to a third party. The consent information acquisition unit 235 acquires the consent information transmitted by the first device 1. The authority management unit 234 manages the integrated ID of the user included in the consent information acquired by the consent information acquisition unit 235 as the integrated ID of the user that the account can refer to. The authority management unit 234 stores the integrated ID of the user included in the consent information acquired by the consent information acquisition unit 235 in the authority information stored in the storage unit 22.
[0058] The second device 2 may be configured to manage user data that can be referred to for each account that utilizes the user data.
[0059] The authority management unit 234 manages the integrated ID of the user included in the consent information as the integrated ID of the user that the accounts within the disclosure scope specified by the consent content indicated by the consent information can refer to. The authority management unit 234 stores the accounts within the disclosure scope specified based on the consent information in the authority information in association with the integrated ID included in the consent information. As an example, the consent information may include the accounts that are the disclosure scope. Also, the storage unit 22 stores information associating the time when consent was obtained with the accounts that are the disclosure scope, and the authority management unit 234 may specify the accounts within the disclosure scope based on the time when the consent included in the consent information was obtained.
[0060] The second device 2 may be configured to generate matching data based on the columns that can be referred to for each account. The authority management unit 234 manages the data items indicated by the consent information as the items that the account can refer to among the data included in the user data. In the consent information, as an example, it includes columns that can be disclosed to a third party. The authority management unit 234 stores the columns associated with the consent information acquired by the consent information acquisition unit 235 in the authority information. The authority management unit 234 specifies the columns that the account can refer to in response to an inquiry from the generation unit 233.
[0061] In this way, it becomes possible to appropriately manage the consent information in pairs with the integration ID. Therefore, compared with separately managing the consent information and integrating the consent information data, the man-hours for obtaining consent from a third party are reduced, it becomes easier to obtain consent, and it becomes easier to manage the obtained third-party-provided consent.
[0062] The generation unit 233 generates collation data in which the user data included in the first user data and the second user data is associated with the integration ID included in the first user data and the integration ID corresponding to the common authentication ID included in the second user data as keys, and generates collation data obtained by collating items for which reference by the account that transmitted the generation request is permitted. That is, the generation unit 233 inquires of the authority management unit 234 about the columns that can be referenced by the account that transmitted the generation request, and generates collation data based on the first user data narrowed down to the columns specified by the authority management unit 234 and the second user data narrowed down to the columns specified by the authority management unit 234.
[0063] With the second device 2 configured in this way, it is possible to limit the information that can be referenced by the account that utilizes the user data, and it becomes possible to securely manage the user data.
[0064] In the second device, instead of the common authentication ID, the second device 2 may be configured to manage the user's information in association with the hashed common authentication ID. In this case, the related ID data storage unit 223 stores related ID data in which the hashed common authentication ID obtained by hashing the common authentication ID and the integration ID corresponding to the common authentication ID are associated. The hashed common authentication ID indicates a hash value generated based on a predetermined hash function for the common authentication ID.
[0065] The user data acquisition unit 231 acquires, from the fourth device 4, second user data indicating the behavior content in the second service associated with the hashed common authentication ID of each of the plurality of users.
[0066] User data for which matching data is to be generated may be specified based on the hashed common authentication ID. The generation request acquisition unit 232 acquires a generation request including the common authentication IDs of one or more users for which matching data is to be generated. The generation unit 233 calculates a hashed common authentication ID corresponding to the common authentication ID included in the acquired generation request, and specifies a unified ID based on the calculated hashed common authentication ID. Note that the generation request may include the hashed common IDs of one or more users for which matching data is to be generated.
[0067] The generation unit 233 generates matching data in which the user data included in the first user data and the second user data is associated with the unified ID included in the first user data and the unified ID corresponding to the hashed common authentication ID included in the second user data as keys, and the user data for which reference by the account that sent the generation request is permitted is matched. That is, the generation unit 233 specifies the unified ID corresponding to the hashed common authentication ID in the associated ID data, and generates matching data based on the specified unified ID. By configuring the information processing apparatus 1 in this way, there is no need to hold the common authentication ID in the database, and a secure system can be configured.
[0068] By being configured in this way, since only the hashed information exists for both the common authentication ID associated with the second user data held in the second device and the common authentication ID included in the associated ID data, the common authentication ID itself cannot be acquired from the account that utilizes the user data, and the common authentication ID, which is important information serving as the basis for authentication, is protected at a higher level.
[0069] Incidentally, the second device 2 may store information for authenticating an account for utilizing user data. Note that the information of the account for utilizing user data in the second device is independent of the information of the account for managing the access right to the first device. That is, enterprises, users, etc. that utilize user data cannot access the information for managing the integrated ID issued by the first device and the common authentication ID corresponding to the integrated ID using the information of the account for utilizing user data in the second device. By configuring the first device 1 and the second device 2 in this way, the common authentication ID, which is important information serving as the basis for authentication, will be protected at a higher level.
[0070] [Flow of processing in the second device 2] FIG. 6 is a flowchart showing the flow of processing in the second device 2. The user data acquisition unit 231 acquires first user data (S01). The user data acquisition unit 231 acquires second user data (S02). The user data acquisition unit 231 stores the acquired first user data and second user data in the first user data storage unit 221 and the second user data storage unit 222, respectively.
[0071] The generation request acquisition unit 232 acquires a generation request (S03). The generation unit 233 identifies user data that can be referenced by the account that has sent the generation request to the authority management unit 234 (S04). The generation unit 233 identifies the integrated ID corresponding to the common authentication ID (S05). The generation unit 233 generates verification data by verifying the first user data and the second user data based on the user data that can be referenced by the account that has sent the identified generation request (S06). Then, the second device 2 ends the processing.
[0072] Incidentally, according to the present invention, it becomes possible to contribute to Goal 9, "Build the infrastructure for industry and innovation," of the Sustainable Development Goals (SDGs) led by the United Nations.
[0073] As described above, the present invention has been described using embodiments. However, the technical scope of the present invention is not limited to the scope described in the above embodiments, and various modifications and changes are possible within the scope of the gist. For example, all or part of the device can be configured by functionally or physically dispersing and integrating it in any unit. Also, new embodiments resulting from any combination of a plurality of embodiments are included in the embodiments of the present invention. The effects of the new embodiments resulting from the combination have the effects of the original embodiments combined.
Explanation of Reference Numerals
[0074] 1 First device 2 Second device 3 Third device 4 Fourth device 5 Information terminal 6 Management device 11 Communication unit 12 Storage unit 13 Control unit 21 Communication unit 22 Storage unit 23 Control unit 131 Issuing unit 132 ID transmission unit 221 First user data storage unit 222 Second user data storage unit 223 Related ID data storage unit 231 User data acquisition unit 232 Generation request acquisition unit 233 Generation unit 234 Authority management unit 235 Consent information acquisition unit
Claims
1. An information processing system having a first device and a second device, The first device is an issuing unit that issues an integrated ID, which is an ID for identifying a user authenticated in a predetermined authentication service in a first service that is a service different from the authentication service, in association with a common authentication ID, which is an ID for identifying a user in the predetermined authentication service; an ID transmission unit that transmits the issued integration ID to a device that provides the first service and a device that provides a second service different from the first service, and that associates the issued integration ID with a common authentication ID corresponding to the integration ID and transmits the associated ID to the second device; having The second device is a first storage unit configured to store first user data, the first user data being user data indicating the behavior of each of the plurality of users in the first service, the first user data being associated with the integration ID of each of the plurality of users; a second storage unit configured to store second user data, which is user data indicating the behavior of each of the plurality of users in the second service and which is acquired in association with the common authentication ID; a related ID data storage unit that stores related ID data that associates the common authentication ID transmitted by the ID transmission unit with an integration ID corresponding to the common authentication ID; a generation request acquisition unit that acquires a generation request from an account that requests reference to user information; a generation unit that generates matching data in which user data included in the first user data and the second user data are associated with each other using an integration ID included in the first user data and an integration ID corresponding to a common authentication ID associated with the second user data as keys, the matching data being generated by matching user data that is permitted to be referenced by the account that has sent the generation request; having Information processing system.
2. The generation request acquisition unit acquires a generation request including a common authentication ID or an integration ID of one or more users for whom user data is to be generated, The generation unit generates, from the matching data, the matching data corresponding to an integration ID included in the generation request or a common authentication ID included in the generation request. The information processing system according to claim 1 .
3. The second device further includes an authority management unit that manages an account for accessing user data and an integrated ID of a user who is permitted to access the user data by using the account. The information processing system according to claim 1 .
4. the ID transmission unit, when obtaining consent from a user to whom the integration ID is issued to provide information about the user, transmits to the second device information indicating that consent has been obtained from the user, the consent information being associated with the integration ID of the user; The second device further includes a consent information acquisition unit that acquires the consent information, The authority management unit manages the integration ID of the user included in the consent information as an integration ID of a user that can be referenced by the account. The information processing system according to claim 3 .
5. the ID transmission unit, when obtaining consent from a user to whom the integrated ID is issued to provide information about the user, transmits to the second device the consent information obtained from the user, the consent information being further associated with the consent content for specifying a disclosure range of the account that can be provided; The authority management unit manages the integration ID of the user included in the consent information as an integration ID of a user that can be referenced by an account within a disclosure scope specified by the consent content indicated by the consent information.
5. The information processing system according to claim 4.
6. The ID transmission unit transmits consent information to the second device, the consent information further associating with an item of user data that the user consented to be provided; the authority management unit manages the items to which the user has agreed, which are indicated by the consent information, as items of data included in the user data that the account can refer to; The generation unit generates matching data in which the user data included in the first user data and the second user data are associated with each other using an integration ID included in the first user data and an integration ID corresponding to a common authentication ID included in the second user data as keys, and the matching data is generated by matching items that are permitted to be referenced by the account that has sent the generation request. The information processing system according to any one of claims 3 to 5.
7. The issuing unit issues the integrated ID to the user on the condition that consent to providing information about the user to a third party has been obtained. The information processing system according to any one of claims 1 to 5.
8. the second storage unit stores second user data in which a hashed common authentication ID obtained by hashing the common authentication ID is associated with behavioral content of each of the plurality of users in the second service; the associated ID data storage unit stores the associated ID data in which the hashed common authentication ID is associated with an integration ID corresponding to the common authentication ID; The generation unit generates the matching data in which the user data included in the first user data and the second user data are associated with an integration ID included in the first user data and an integration ID corresponding to a hashed common authentication ID included in the second user data as keys, and the matching data is generated by matching user data that is permitted to be referenced by the account that transmitted the generation request. The information processing system according to claim 1 .
9. The information of the account requesting the reference to the user information is independent of the information of the account that manages the access right to the first device. The information processing system according to claim 1 .
10. The computer executes issuing an integrated ID, which is an ID for identifying a user authenticated in a predetermined authentication service in a first service that is a service different from the authentication service, in association with a common authentication ID, which is an ID for identifying a user in the predetermined authentication service; transmitting the issued integration ID to a device providing the first service and a device providing a second service that is different from the first service; obtaining a generation request from an account requesting access to the user's information; a step of referring to a first storage unit that stores first user data, the user data being associated with an integration ID of each of the multiple users and indicating the behavior of each of the multiple users in the first service, a second storage unit that stores second user data, the user data being associated with the common authentication ID and indicating the behavior of each of the multiple users in the second service, and an associated ID data storage unit that stores associated ID data associating a common authentication ID with an integration ID corresponding to the common authentication ID, and generating matching data in which user data included in the first user data and the second user data are associated using an integration ID included in the first user data and an integration ID corresponding to the common authentication ID associated with the second user data as keys, the matching data being generated by matching user data that is permitted to be referenced by the account that transmitted the generation request; An information processing method comprising the steps of:
11. an issuing unit that issues an integrated ID, which is an ID for identifying a user authenticated in a predetermined authentication service in a first service that is a service different from the authentication service, in association with a common authentication ID, which is an ID for identifying a user in the predetermined authentication service; an ID transmission unit that transmits the issued integrated ID to a device that provides the first service and a device that provides a second service that is different from the first service; a first storage unit configured to store first user data, the first user data being user data indicating the behavior of each of the plurality of users in the first service, the first user data being associated with the integration ID of each of the plurality of users; a second storage unit configured to store second user data, which is user data indicating the behavior of each of the plurality of users in the second service and which is acquired in association with the common authentication ID; a related ID data storage unit that stores related ID data that associates a common authentication ID with an integration ID corresponding to the common authentication ID; a generation request acquisition unit that acquires a generation request from an account that requests reference to user information; a generation unit that generates matching data in which user data included in the first user data and the second user data are associated with each other using an integration ID included in the first user data and an integration ID corresponding to a common authentication ID associated with the second user data as keys, the matching data being generated by matching user data that is permitted to be referenced by the account that has sent the generation request; An information processing device having the above configuration.
Citation Information
Patent Citations
Information processing system, and program
JP2016126609A