Program, information processing device and information processing method
The program and information processing apparatus address the issue of user data anonymization by implementing functions to receive, anonymize, and provide anonymized data, ensuring user privacy and security in data sharing.
Patent Information
- Application Number
- JP2023221555
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-27
- Publication Date
- 2025-07-09
- Estimated Expiration
- 2043-12-27
AI Technical Summary
Existing systems fail to reflect user needs for anonymization when providing user data to service providers.
A program and information processing apparatus that includes a reception function to receive anonymization settings, an acquisition function to acquire user data, an anonymization function to anonymize the data based on these settings, and a provision function to provide anonymized data to service providers.
Ensures that user anonymization needs are reflected when providing data to service providers, enhancing data security and user privacy.
Smart Images

Figure 2025103868000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a program, an information processing apparatus, and an information processing method.
Background Art
[0002] Conventionally, a technique for providing data regarding a user who uses a service (hereinafter referred to as "user data") to an operator who provides this service is known. Patent Document 1 discloses a server device that receives a request for the definition of user data (first customer data) from an operator device of an operator who provides a payment service. When a user (customer) uses the payment service, this server device acquires user data from the user's terminal device based on the requested definition of the user data, and provides the acquired user data to the operator device.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] By the way, when providing user data, there are needs regarding user anonymization, such as the need to anonymize some or all of the user data. However, the device described in Patent Document 1 has a problem that it cannot reflect such user needs.
[0005] Therefore, an object of the present invention is to provide a program, an information processing apparatus, and an information processing method that can reflect the needs regarding user anonymization when providing user data to a service provider when a user uses a service.
Means for Solving the Problems
[0006] A program according to one aspect of the present invention causes a computer to implement a reception function that receives a anonymization setting for providing user data regarding a user from a user device of a user of a first service provided by a first service provider to one or more destinations including the first service provider, an acquisition function that acquires user data from the user device in response to an operation input of the user to the user device when the user uses the first service via the user device, an anonymization function that anonymizes the user data based on the anonymization setting, and a provision function that provides the anonymized user data to a destination device of each of the one or more destinations.
[0007] An information processing apparatus according to one aspect of the present invention includes a reception unit that receives a anonymization setting for providing user data regarding a user from a user device of a user of a first service provided by a first service provider to one or more service providers including the first service provider, an acquisition unit that acquires user data from the user device in response to an operation input of the user to the user device when the user uses the first service via the user device, an anonymization unit that anonymizes the user data based on the anonymization setting, and a provision unit that provides the anonymized user data to a business operator device of each of the one or more service providers.
[0008] An information processing method according to one aspect of the present invention includes a computer receiving a anonymization setting for providing user data regarding a user from a user device of a user of a first service provided by a first service provider to one or more service providers including the first service provider, acquiring user data from the user device in response to an operation input of the user to the user device when the user uses the first service via the user device, anonymizing the user data based on the anonymization setting, and providing the anonymized user data to a business operator device of each of the one or more service providers.
Advantages of the Invention
[0009] According to the present invention, when a user provides user data to a service provider when using a service, the needs regarding the anonymization of the user can be reflected.
Brief Description of the Drawings
[0010]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Modes for Carrying Out the Invention
[0011] With reference to the accompanying drawings, a preferred embodiment of the present invention (hereinafter referred to as "the present embodiment") will be described. In each figure, those denoted by the same reference numerals have the same or similar configurations.
[0012] In the present invention, "part", "means", "device", or "system" does not simply mean a physical means, but also includes cases where the functions of the "part", "means", "device", or "system" are realized by software. Further, even if the functions of one "part", "means", "device", or "system" are realized by a combination of two or more physical means, devices, or software modules, or the functions of two or more "parts", "means", "devices", or "systems" are realized by one physical means, device, or software module, it is acceptable.
[0013] <1. System Configuration> Referring to FIG. 1, an example of the system configuration of the data mediation system 1 according to the present embodiment will be described. The data mediation system 1 is a system that mediates between a service provider (also referred to as a "service provider") who provides a service and a user who uses this service. The data mediation system 1, through this mediation, when a user uses a service, provides data related to the user (also referred to as "user data") to the service provider in a form anonymized according to the user's intention. Further, the data mediation system 1 may provide, for example, user data to a destination other than the service provider.
[0014] In the present embodiment, an example in which a business operator (also referred to as a "mediator") that mediates between a user and a service provider operates and manages the data mediation system 1 will be described. The mediator, for example, manages user data provided by the user when using a service and / or provides a user IF on behalf of the service provider.
[0015] The mediator, for example, receives on behalf of the service provider the user data input by the user when using a service, anonymizes the received user data, and then mediates it to the service provider. Thereby, the mediator restricts the acquisition of user data by the service provider. This anonymization may be, for example, anonymization processing of user data and / or encryption of user data.
[0016] The mediator may, for example, encrypt the user data and then provide it to the service provider. Further, when the mediator satisfies a predetermined condition such as a predetermined period, the mediator may provide the service provider with information (also referred to as "decryption information") for decrypting this encrypted user data. The mediator may stop providing the decryption information to the service provider when the predetermined condition is no longer satisfied.
[0017] As shown in FIG. 1, the data mediation system 1 includes, for example, a server device 100, a user's user device 200, and a service provider's operator device 300. The server device 100, the user device 200, and the operator device 300 are connected to each other via a network N so as to be communicable with each other.
[0018] [Server device] The server device 100 is an information processing device capable of communicating with the user device 200 and the operator device 300. By executing a predetermined program (also referred to as a "server program"), the server device 100 acquires user data from the user device 200, anonymizes the acquired user data according to the user's settings, and provides the anonymized user data to the operator device 300. In the present embodiment, it is assumed that the server device 100 is operated and managed by an intermediary.
[0019] [User device] The user device 200 is an information processing device used by the user, and is, for example, a terminal device such as a smartphone or a laptop. By executing a predetermined program (also referred to as a "user program"), the user device 200 transmits user data and the like to the server device 100, displays various screens of the data mediation system 1 to the user, and receives operation inputs from the user for the displayed screens. The user program may be, for example, an application program dedicated to the data mediation system 1 installed on the user device 200, or may be a web browser standardly provided in the terminal device.
[0020] [Operator device] The operator device 300 is an information processing device used by a service provider. The service provider provides various services to users. The operator device 300 may be, for example, one of the devices constituting a system (also referred to as a "service system") for the service provider to provide services to users. Note that the operator device of the first service provider providing the first service is referred to as the "first operator device 300a", and the operator device of the second service provider providing a second service different from the first service is referred to as the "second operator device 300b". The first service provider and the second service provider are one aspect of the destination. Also, the operator device 300 is one aspect of the destination device.
[0021] User data may include, for example, information for confirmation processes such as registration, authentication, and authorization for the service provider, various operation and input information for service use, and various information regarding the devices used by the user for operations (for example, OS, location information, keyboard settings, device-specific information, Cookies, and / or other data that can be used for tracking).
[0022] User data may include, for example, user identification information for identifying the user, payment means information or payment account information of the payment means used by the user, and service information or service account information of the service used by the user. Also, user data may include, for example, when the user is an individual, the user's attributes (the user's personal data) such as name, phone number, address, email address, personal number (My Number), gender, and / or date of birth.
[0023] User data may include, for example, as the user's personal data, usage record information (in other words, usage history) for each of a plurality of services for each user. Specifically, the usage record information may be, for example, browsing history information of each site of a plurality of services, operation history information (including instruction information described later) for the user device 200 when accessing the site, and / or login history information of the site, etc. These history information may be information included in the Cookie of the user device 200. User data may include, for example, the location information of the user (specifically, the location information of the user device 200).
[0024] Payment means information is information regarding payment means. The payment means information includes, for example, type information indicating the type of payment means (e.g., credit card payment, debit card payment, electronic money payment, etc.), payment means identification information for identifying the payment means (e.g., ID, card number, or account number, etc.), payment business operator information regarding the payment business operator providing the payment means, identification information of the user in the payment means, security information for the security of the payment means, etc. Also, the payment means information may include, for example, at least a part of the payment account information of the corresponding payment means.
[0025] Payment account information is information regarding the user's account (hereinafter, also referred to as "payment account") for using the payment means. The payment account information may include, for example, payment account identification information (e.g., ID or card number, etc.) for identifying the user's payment account and the payment means information of the corresponding payment means. The payment account information may include, for example, authentication information (e.g., password of the payment account, etc.) in the user authentication of the payment account.
[0026] User data may include, for example, authentication information (one aspect of confirmation information) for authenticating the user. The authentication information is information that is an element of a predetermined authentication method and is information for authenticating the user in the predetermined authentication method. The authentication information may include, for example, possession information, biometric information, and memory information.
[0027] The information on the belongings may be, for example, card information regarding an IC card or a magnetic card which is a belonging held by the user, information readable from a terminal or a card with an embedded NFC tag, information readable from a personal identification number card (My Number card), a driver's license, a passport, a resident basic register card (with the user's face photo), etc., and / or device information (specifically, device identification information, etc.) regarding a device which is a belonging (for example, the user device 200).
[0028] The biometric information may be, for example, information regarding the user's living body such as the user's appearance, fingerprint, palm print, voiceprint, vein, and / or iris.
[0029] The memory information may be, for example, user identification information, a number regarding a payment means (for example, a card number or an account number, etc.), a telephone number, an account name such as an email address, a password (including a PIN code), a signature or a figure input or selected by the subject person, an answer in a free input format or a choice format for a predetermined question, and / or other information memorized by the subject person as long as it can be acquired by the server device 100.
[0030] The user data may include, for example, device information regarding the user's user device 200. As another example, for each user, the user data and the device information of each of one or more user devices 200 of each user may be associated and registered in the storage unit 130.
[0031] The user data may include, for example, instruction information indicating the user's instruction to the service provider device 300 of the first service by an operation input, and at least any one of the user's personal data. The instruction information may be, for example, a request to the first service site of the service provider device 300 of the first service.
[0032] The device information may include, for example, device identification information for identifying each device (e.g., an ID assigned to each device, device-specific identification information, or other information set for each device), the type of the device (e.g., classification of a PC, smartphone, tablet, EV, drone, or communication device dedicated to a service), product name, MAC address, IP address, and / or manufacturing number, etc. Further, the device information may include, for example, information regarding the OS, information recorded in the memory of each device (e.g., ID / token information of each of one or more apps installed in each device), and a positioning method corresponding to the location information provided by each device to the data mediation system 1 (server device 100) (e.g., classification of GPS, UWB, BLE, or NFC, etc.).
[0033] [Network] The network N is composed of a wireless network or a wired network. As an example of the network N, there are a mobile phone network, a PHS (Personal Handy-phone System) network, a wireless LAN (Local Area Network, communication compliant with IEEE802.11 (so-called WI / Fi (registered trademark))), 3G (3rd Generation), LTE (Long Term Evolution), 4G (4th Generation), 5G (5th Generation), WiMax (registered trademark), infrared communication, visible light communication, Bluetooth (registered trademark), a wired LAN, a telephone line, a power line communication, a power line network, a network compliant with IEEE1394, etc.
[0034] <2. Overview> With reference to FIGS. 2 to 3, an example of the data mediation system 1 will be described.
[0035] <2-2. Mediation of Data> FIG. 2 is a diagram showing an example of intermediation of user data by the data mediation system 1. In this example, an example where the first service provided by the first service provider is a web service will be described, but the main idea is not to limit the first service to a web service. The first service may be any service as long as user data exchange occurs between the user device 200 and the operator device 300 via a network.
[0036] As shown in FIG. 2, for example, when a user uses the first service, the server device 100 may relay the communication between the user device 200 and the first operator device 300a. When relaying, the server device 100 anonymizes the user data based on the settings for each user and each service. In this example, an example of re-accessing from the user device 200 to the website of the first service (hereinafter also referred to as the "first service site") will be described.
[0037] (1) The user device 200 sends a display request for the top screen (including a user authentication request for the first service) to the first operator device 300a as an HTTP request to log in to the first service site provided by the operator and display the top screen. The server device 100 receives this display request in order to anonymize the user data included in this display request and pass it to the first operator device 300a. This display request includes, for example, information of a cookie (1st Party Cookie) of the first service site. This cookie information may include, for example, web site browsing history information, input data to the first service site (e.g., contents of the cart in the EC cart function), account information for logging in to the first service site, etc.
[0038] When relaying the above display request to the first operator device 300a, for example, the server device 100 may anonymize (anonymize and process) the above cookie information as follows. · Web site browsing history information: Encryption with an encryption key · Input information to the first service site: Specific information corresponding to the personal information of the user is secretly processed (for example, deletion or replacement of data, etc.)
[0039] The server device 100 may, for example, perform user authentication on behalf of the first operator device 300a based on the above account information. When the user authentication is successful, the server device 100 may generate an authentication token. This authentication token may indicate that the authenticity of the user has been confirmed by the authentication process in the server device 100.
[0040] In the above display request transmitted from the user device 200, the server device 100 transmits the anonymized information and the generated authentication token (the cookie with some information replaced is also referred to as a "processed cookie") to the first operator device 300a instead of some of the information of the cookie transmitted from the user device 200.
[0041] (2) The first operator device 300a transmits, as an HTTP response corresponding to the above transmitted HTTP request (processed cookie), display information including an HTML file and images for displaying the top screen of the first service site (also referred to as the "top page") to the user device 200. The server device 100 receives this transmitted display information and transmits it to the user device 200. When there is no need to process the display information, it may be transmitted from the first operator device 300a to the user device 200 without being relayed by the server device 100 in this way. The user device 200 receives the display information and displays the top screen of the first service site based on the received display information.
[0042] (3) The user device 200 sends, as an HTTP request (POST method), the input information from the user for each input form on the displayed top screen to the first service provider device 300a. The input information includes, for example, the user's ID (id), name, address, DM sending permission flag (DM_Flag), information on the destination screen, etc. in the request body (HTTP body part). The server device 100 receives the HTTP request in order to anonymize the user data included in this HTTP request and pass it to the service provider device 300.
[0043] When the server device 100 relays the above HTTP request to the first service provider device 300a, for example, part of the information included in the request body may be anonymized as follows. · User ID: No processing · Name: Anonymization processing (for example, replace with "XX XX", etc.) · Address: Anonymization processing (for example, shorten to the city, ward, town, or village level) · DM sending permission flag: No processing · Destination screen information: No processing
[0044] Instead of the input information of the above request sent from the user device 200, the server device 100 sends the input information with the above part anonymized to the first service provider device 300a.
[0045] <2-3. Data intermediation> Figure 3 is a diagram showing an example of the functional configuration of the entire data mediation system 1. As shown in Figure 3, the functions realized by the data mediation system 1 may be classified and arranged as follows, for example. The classified functions cooperate with each other (including information cooperation and / or functional cooperation. The same applies hereinafter). [Service provider device 300: Service provider] · Verification function: A function to verify the legitimacy of the user in providing the service · Service provision function: A function for realizing service provision (for example, in the case of a web service, functions provided by a web server (presentation layer) and an AP server (application layer)) · Data management function: A function for managing data necessary for service provision such as user data (for example, in the case of a web service, a function provided by a DB server (database layer)) [Server device 100: Broker] · Confirmation agency function: A function for acting as an agent for the confirmation function on the service provider side, confirming the legitimacy of the user, and providing the confirmation result to the service provider · User IF function: A function for receiving input information from the user device 200 and providing output information (including display information) received from the business operator device 300 to the user device 200 · Encryption function: A function for encrypting user data provided by the user when receiving a service according to settings from the user, etc.
[0046] In this example, it is assumed that, in advance, the user device 200 receives a encryption setting for providing user data related to the user to one or more service providers including the first service provider, and information indicating this received encryption setting (also referred to as "encryption setting information") is registered in the storage unit 130.
[0047] (1) As shown in FIG. 3, when the user uses the first service via the user device 200, the user performs an operation input (login operation input) for logging in to the first service of the user on the user device 200. The user device 200 transmits the input information by this operation input to the server device 100. This input information may include an authentication request and authentication information for user authentication in the first service. The server device 100 acquires user data (user authentication information) from the user device 200 in response to the user's login operation input to the user device 200.
[0048] (2) The confirmation unit 114 of the server device 100 substitutes user authentication by confirming the legitimacy of the user based on the above authentication information. Further, the confirmation unit 114 may transmit an authentication request including the above authentication information to the confirmation function of the service provider device 300 without substituting user authentication when the service provider makes settings and / or meets predetermined conditions. The service provider device 300 may perform user authentication to confirm the legitimacy of the user by itself based on the authentication request transmitted from the server device 100.
[0049] (3) The service provision function of the service provider device 300 obtains the result of user authentication from the confirmation function of the server device 100 or its own device. When the result of user authentication indicates successful authentication, the service provision function starts providing the first service to the user. Specifically, the service provision function generates display information for displaying a screen (in this example, the "top screen") that transitions after logging in to the first service site, and transmits this generated display information to the server device 100. The acquisition unit 112 of the server device 100 acquires this transmitted display information. The provision unit 115 of the server device 100 transmits this acquired display information to the user device 200. The user device 200 receives this transmitted display information and displays the top screen of the first service site to the user based on this display information.
[0050] (4) The user makes an operation input to the top screen displayed on the user device 200. The user device 200 transmits input information (a form of user data) based on this operation input to the server device 100. The acquisition unit 112 of the server device 100 acquires this transmitted input information.
[0051] (5) The anonymization unit 113 of the server device 100 executes the anonymization process of the acquired input information based on the anonymization setting information. The anonymization unit 113 registers this anonymized input information in the storage unit 130. Further, the provision unit 115 of the server device 100 provides this anonymized input information to the service provider devices 300 of one or more service providers (in this example, the first service provider and the second service provider).
[0052] The anonymization process by the anonymization unit 113 may be, for example, the processes (a) to (c) below. (a) Encrypt all data: Provide all data after performing an encryption process. This ensures that the content of the data cannot be confirmed without performing a decryption process, thereby ensuring confidentiality. (b) Encrypt other data excluding the data (processing instructions) necessary for service provision: When it is necessary to receive processing instructions such as functional operations from the user for service provision, the data related to the processing instructions is not subject to encryption, and the data not directly related to the processing instructions (for example, location information and device information about the user, various history information, etc.) is encrypted. This ensures confidentiality. (c) By performing intermediate processing, direct data transfer between the user (data provider) and the first service provider (data user) is not generated, and all or part of the data is separately encrypted and provided: The processing instructions such as operations related to service provision are regarded as instructions from the data mediation system 1, and a model is adopted in which the data from the user is not directly provided. Separately, all or part of the encrypted data is provided to the destination. As a result, the first service provider is in a state where the identification and instructions of the user are not visible.
[0053] Based on the above configuration, the data mediation system 1 can control the content of the user data provided to the service provider according to the anonymization settings of the intermediary, and can also undertake part of the user IF on behalf of the service provider. Therefore, when the user uses the service and provides user data to the service provider, the needs regarding the anonymization of the user can be reflected.
[0054] Under the above configuration, the data mediation system 1 can apply the anonymization settings on the cloud side, that is, via the network N. Therefore, it is possible to apply the anonymization settings without depending on the edge side, that is, the terminal device of the user device 200 and the installed applications and configuration files such as the Web browser. Thus, for example, although the cookie settings of the browser of this device reject the provision of cookies for a certain service site, the burden on the user of having to set them separately because this setting is not shared when using another device or another browser can be reduced.
[0055] <3. Functional configuration> Referring to FIG. 4, the functional configuration of the server device 100 according to the present embodiment will be described. As shown in FIG. 4, the server device 100 includes a control unit 110, a communication unit 120, and a storage unit 130.
[0056] The control unit 110 includes a reception unit 111, an acquisition unit 112, an anonymization unit 113, and a provision unit 115. Further, the control unit 110 may include, for example, a confirmation unit 114.
[0057] [Reception unit] The reception unit 111 receives various settings and / or various requests from the user device 200 and / or the operator device 300. For example, as one mode of reception, when information is input by the user on the screen of the Web site of the data mediation system 1 (also referred to as the "data mediation site") displayed on the user device 200, the reception unit 111 may receive a message indicating the input information.
[0058] The reception unit 111 receives a anonymization setting for providing user data regarding a user from a user device 200 of a user of a first service provided by a first service provider to one or more service providers including the first service provider. For example, the reception unit 111 may receive information indicating the anonymization setting input by the user on a screen of a data mediation site of the user device 200 from the user device 200 and accept it. Further, the reception unit 111 may register anonymization setting information indicating the accepted anonymization setting in the storage unit 130.
[0059] The anonymization setting may include, for example, whether user data can be provided to each destination from the user, one or more data items to be provided, and the anonymized content of each data item (for example, whether it is a target of anonymization, and if it is a target of anonymization, the degree of anonymization, etc.). Further, the anonymization setting may be set, for example, for each destination registered in the data mediation system 1, to (a) anonymize all data, (b) anonymize sensitive information, (c) anonymize personal information, in terms of the degree of anonymization. The anonymization setting may be set, for example, for each destination, the presence or absence of anonymization for data items, the method of anonymization processing, and the conditions for data disclosure (for example, the provision period and / or the necessity of encryption / transformation processing, etc.).
[0060] The anonymization setting may be set, for example, for each user and for each service, indicating how to anonymize. The anonymization setting may be set, for example, for each user and / or for each service provider (service), with individual settings for each of the instruction information and the personal data. The anonymization setting may be a setting that the instruction information is not uniformly anonymized and the personal data is uniformly anonymized. Further, the anonymization setting may indicate, for example, that the personal information of the user is uniformly anonymized (specifically, anonymized processing or encrypted), while the usage history information of the user is not anonymized. Note that the anonymization setting may be a common setting for a plurality of service providers, for example.
[0061] According to the above configuration, different settings can be made for instruction information and personal data. For example, it is considered that the anonymization of instruction information is likely to affect the provision of services, and confidentiality is often relatively low. On the other hand, it is considered that the anonymization of personal data is relatively low, but confidentiality is relatively high. In this way, anonymization settings can be flexibly made according to the characteristics of each piece of user data.
[0062] The anonymization setting may further include, for example, a setting as to how to anonymize for each destination. The anonymization setting may include, for example, an anonymization setting for the second service provider.
[0063] The reception unit 111 may receive, for example, a release request to release the anonymity of at least a part of the anonymized user data from the service provider device 300 of the service provider. When the release request is received, the following modes are possible: (A) the server device 100 releases the anonymity itself; or (B) the server device 100 provides release information so that the requesting service provider device 300 can release the anonymity.
[0064] The receiving unit 111 may receive, for example, a request for providing user data from the first business operator device 300a of the first service operator to a destination (for example, a second service operator) different from the first service operator.
[0065] The reception unit 111 may receive conditions for user confirmation (also referred to as “confirmation conditions”) from, for example, the business operator device 300 of the service operator. The reception unit 111 may register information indicating the received confirmation conditions (also referred to as “confirmation condition information”) in the storage unit 130.
[0066] The verification conditions may, for example, specify the method of user registration, the method of identity verification when registering the data, the method of user identification, and / or the method of authentication and authorization for user verification.
[0067] The method of user data registration may be, for example, the types of user data to be acquired, the user's personal data (such as name, email address, mobile phone number, address, date of birth, etc.), and other data necessary for service provision, etc.
[0068] The method of identity verification for data registration may be, for example, eKYC, public personal authentication, OTP arrival confirmation, platform-dependent confirmation, etc.
[0069] The method of identifying users may be, for example, the issuance of IDs for identifying each user, the registration of the user's email address, the provision of cookies to the user device 200, the issuance of electronic certificates for proving the user or the user device 200, etc.
[0070] The methods for authentication and authorization may be, for example, requesting the registration and confirmation of ID / PW, etc., requesting the registration and confirmation of biometric authentication, device authentication, FIDO authentication, etc., or combining a plurality of them.
[0071] The reception unit 111 may receive, for example, the registration destination of all or part of the user data. This registration destination may be the data mediation system 1 (specifically, the storage unit 130 of the server device 100, etc.) and / or the system of the first service (specifically, the storage unit of the first operator device 300a). The reception unit 111 may register information indicating this received registration destination (also referred to as "registration destination information") in the storage unit 130.
[0072] [Acquisition Unit] The acquisition unit 112 acquires various information from the user device 200 and / or the operator device 300.
[0073] The acquisition unit 112 may receive, as needed, a message indicating the various pieces of information input by the user when the user inputs various pieces of information on the first service site or data intermediation site displayed on the user device 200, for example. As another example, the acquisition unit 112 may receive, in a cyclic or event-driven manner, data files of various pieces of information from the user device 200 or the operator device 300, for example. As another example, the acquisition unit 112 may instruct an API implemented by an external system (not shown) such as a cloud file system to refer to various pieces of information, and as a result, acquire the various pieces of information. Further, the acquisition unit 112 may acquire various pieces of information, for example, by causing the user device 200 to use a library of an SDK corresponding to the data intermediation system 1.
[0074] When the user uses the first service via the user device 200, the acquisition unit 112 acquires user data from the user device 200 in response to an operation input by the user to the user device 200.
[0075] The acquisition unit 112 may acquire, for example, permission information indicating permission from the user for the decryption of user data from the user device 200.
[0076] The acquisition unit 112 may acquire, for example, consent information indicating consent from the user for the provision of user data to the second service provider from the user device 200.
[0077] The acquisition unit 112 may register the acquired user data (for example, highly confidential information such as account information and / or authentication information) in the storage unit 130 based on the registration destination information indicating the registration destination of the user data.
[0078] The acquisition unit 112 may acquire information regarding a provider such as a service provider (also referred to as "provider information") from the operator device 300, for example. The acquisition unit 112 may register the acquired provider information in the storage unit 130.
[0079] The provided information may include, for example, the attribute information of the recipient (e.g., name, corporate name / trade name, location, services provided, contact information, corporate website, etc.), the purpose of using the provided data (e.g., service provision, public interest, requirements by government / laws and regulations, etc.), and the method of data provision (e.g., information indicating the provision method such as API connection, identification information for provision, and / or the data provision cycle (e.g., immediate, periodic batch processing, on-demand provision according to provision requests, etc.)).
[0080] [Anonymization Department] The anonymization department 113 anonymizes the user data based on the anonymization settings by the user. For example, as anonymization, the anonymization department 113 may perform anonymization processing on the user data. Specifically, the anonymization department 113 may perform anonymization processing by deleting items or cells of the user data, abstracting all or part of the user data, generalizing by replacing with upper-level concepts or numerical shortening, top (bottom) coding, data exchange, or adding noise (error).
[0081] When the anonymization department 113 performs anonymization processing, it may register the processing history information indicating the processing history in the storage department 130. Also, for example, the anonymization department 113 may restore the user data to the state before anonymization processing based on the cancellation request received by the reception department 111 and the processing history information.
[0082] For example, as anonymization, the anonymization department 113 may encrypt all or part of the user data with an encryption key. Encryption methods used for encryption may include, for example, symmetric key encryption, public key encryption, hybrid methods, etc.
[0083] For example, the anonymization department 113 may not perform anonymization on the instruction information and may perform anonymization on at least part of the personal data.
[0084] According to the above configuration, the anonymization unit 113 can handle instruction information and personal data differently without any settings by the user. For example, it is considered that anonymization of instruction information is likely to affect the provision of services, and confidentiality is often relatively low. On the other hand, it is considered that personal data is relatively unlikely to affect the provision of services, but confidentiality is relatively high. In this way, anonymization can be flexibly performed according to the characteristics of each piece of user data.
[0085] For example, the anonymization unit 113 may anonymize the confirmation information to be provided to the business operator device 300. For example, the anonymization unit 113 may not encrypt the identification information (ID) of the user in the first service included in the confirmation information, but may encrypt other personal information.
[0086] The anonymization unit 113 may de-anonymize the user data based on the de-anonymization request received by the reception unit 111. The anonymization unit 113 may, for example, decrypt the encrypted user data.
[0087] [Verification section] The confirmation unit 114 confirms the legitimacy of the user (e.g., the authenticity and / or existence of the user, etc.). The confirmation unit 114 performs the confirmation of the legitimacy of the user based on, for example, confirmation information included in the user data. The confirmation unit 114 may perform the confirmation of the legitimacy of the user further based on, for example, a confirmation condition. Specifically, the confirmation of the legitimacy of the user may be the identity confirmation and / or authentication of the user. For example, when the confirmation unit 114 determines that the legitimacy of the user has been confirmed and / or when the anonymization setting is set to provide an authentication token instead of the confirmation information, the confirmation unit 114 may generate an authentication token based on the confirmation information.
[0088] The confirmation information is information for verifying the legitimacy of the user when using the first service, that is, for verifying that the user is the user himself / herself. The confirmation information may be, for example, authentication information or may indicate authentication factors (knowledge, possessions, biometrics). Also, the confirmation information may combine multiple types of authentication factors for, for example, multi-factor authentication (e.g., a combination of a credit card and a PIN code, etc.).
[0089] The confirmation unit 114 may, for example, collate (in other words, match) the information included in the user data stored in the storage unit 130 with the confirmation information acquired from the user device 200 in order to verify the authenticity of the user.
[0090] When the business operator device 300 performs the process of verifying the legitimacy of the user when using the first service, the confirmation unit 114 may, for example, cause the confirmation information included in the user data to be provided to the providing unit 115 of the business operator device 300.
[0091] [Providing Unit] The providing unit 115 provides various data to the user device 200 and / or the business operator device 300, etc. The manner in which the providing unit 115 provides various data may be any manner. For example, the providing unit 115 may transmit a data file or a message (e.g., an HTTP request, etc.) including user data to these devices in an event-driven manner. Also, as another example, the providing unit 115 may provide user data to the business operator device 300, etc. via an API or SDK library implemented by itself.
[0092] The providing unit 115 provides, for example, the anonymized user data to the providing destination device (e.g., the business operator device 300) of each of one or more providing destinations (e.g., service providers).
[0093] According to the above configuration, user data provided to a recipient can be anonymized according to the anonymization settings made by the user. Therefore, when providing user data to a service provider when the user uses the service, the needs of the user regarding anonymization can be reflected.
[0094] The providing unit 115 may provide, for example, anonymized confirmation information and / or confirmation result information indicating the confirmation result of the confirmation unit 114 to the operator device 300. The confirmation result information may be, for example, information indicating the confirmation result as it is, or an authentication token generated according to the confirmation result. The confirmation information may include highly confidential information such as a password or the biometric information of the user, and there are issues from the perspective of security in directly sending the confirmation information to the destination device. According to such a configuration, the security of highly confidential information can be improved by anonymizing or sending the confirmation result instead of the confirmation information.
[0095] The providing unit 115 may provide, for example, non-anonymized instruction information and / or personal data with at least a part anonymized to the operator device 300.
[0096] The providing unit 115 may provide, for example, release information for releasing the anonymization of the anonymized user data to the operator device 300 based on a release request and permission information. When the anonymization is encryption of the user data, the release information may be decryption information. The providing unit 115 may provide, for example, a common key paired with the release information to the operator device 300 for the user data encrypted by the common key encryption method. Further, the release information may have, for example, an expiration date set. When the expiration date of the release information has passed, the operator device 300 may be configured so that the anonymization cannot be released using this release information.
[0097] According to the above configuration, even in the operator device 300, if there is permission from the user, the anonymization can be lifted afterwards and the user data can be used. Therefore, without having to provide (transmit) the user data with the anonymization lifted again to the operator device 300, the user data with the anonymization lifted can be used at the destination just by providing the release information. Thus, convenience can be enhanced while ensuring security.
[0098] The providing unit 115 may provide the anonymized user data to a destination device (for example, the second operator device 300b) of a destination different from the first service provider (for example, the second service provider) based on, for example, the provision request of the first service provider received by the reception unit 111 and the consent information from the user.
[0099] According to the above configuration, in response to a request from the first service provider, the server device 100 can provide the anonymized user data to a different destination such as the second service provider. Therefore, even if the first service provider itself does not provide the user data to a different destination, the anonymized user data at this destination can be acquired and utilized.
[0100] [Communication Unit] The communication unit 120 transmits and receives various data to and from the user device 200, the operator device 300, or devices of other external systems via the network N.
[0101] [Storage Unit] The storage unit 130 stores user data and information related to the management of user data. The storage unit 130 may store each data using a database management system (DBMS), or may store each data using a file system. When using a DBMS, a table may be provided for each data, and the tables may be associated with each other to manage each data.
[0102] <4. Operation Example> Referring to FIG. 5, an operation example of the data mediation system 1 will be described. FIG. 5(a) is a flowchart showing an example of the flow of the anonymization setting process in the data mediation system 1. FIG. 5(b) is a flowchart showing an example of the flow of the user data providing process in the data mediation system 1. Note that the order of the processes shown below is an example and may be changed as appropriate.
[0103] As shown in FIG. 5(a), the reception unit 111 of the server device 100 receives an anonymization setting for providing user data from the user device 200 of the user of the first service to one or more destinations including the first service provider (S10). The acquisition unit 112 of the server device 100 acquires consent information indicating the user's consent to the provision of user data to one or more service providers from the user device 200 (S11). Each of the reception unit 111 and the acquisition unit 112 of the server device 100 registers the anonymization setting information indicating the anonymization setting and the consent information in the storage unit 130 in association with the user's account information (S12).
[0104] As shown in FIG. 5(b), when the user uses the first service via the user device 200, the acquisition unit 112 of the server device 100 acquires user data from the user device 200 in response to the user's operation input to the user device 200 (S20). The anonymization unit 113 of the server device 100 refers to the storage unit 130 and anonymizes the user data based on the anonymization setting (S21). The provision unit 115 of the server device 100 provides the anonymized user data to the respective service provider devices 300 of one or more service providers (S22).
[0105] <5. Hardware Configuration> Referring to FIG. 6, an example of the hardware configuration when the above-described server device 100 and / or user device 200 is realized by a computer 800 will be described. Note that the functions of each device can also be realized by dividing them among a plurality of devices.
[0106] As shown in FIG. 6, the computer 800 includes a processor 801, a memory 803, a storage device 805, an input I / F unit 807, a data I / F unit 809, a communication I / F unit 811, and a display device 813.
[0107] The processor 801 controls various processes in the computer 800 by executing a program (for example, a server program or a user program) stored in the memory 803. For example, each functional unit included in the control unit 110 of the server device 100 and / or the control unit of the user device 200 can be realized by the processor 801 executing a program temporarily stored in the memory 803.
[0108] The memory 803 is a storage medium such as a RAM (Random Access Memory). The memory 803 temporarily stores the program code of the program executed by the processor 801 and the data required during the execution of the program.
[0109] The storage device 805 is a non-volatile storage medium such as a hard disk drive (HDD) or a flash memory. The storage device 805 stores an operating system and various programs for realizing the above-described configurations. In addition, the storage device 805 can also store a table for registering various data such as user data and a DB for managing the table. Such programs and data are referred to by the processor 801 by being loaded into the memory 803 as needed.
[0110] The input I / F unit 807 is a device for receiving an input from a user. Specific examples of the input I / F unit 807 include a keyboard, a mouse, a touch panel, various sensors, and wearable devices. The input I / F unit 807 may be connected to the computer 800 via an interface such as a USB (Universal Serial Bus).
[0111] The data I / F unit 809 is a device for inputting data from outside the computer 800. Specific examples of the data I / F unit 809 include a drive device for reading data stored in various storage media. It is also conceivable that the data I / F unit 809 is provided outside the computer 800. In that case, the data I / F unit 809 is connected to the computer 800 via an interface such as USB.
[0112] The communication I / F unit 811 is a device for performing data communication via the network N, either wired or wirelessly, with a device outside the computer 800. It is also conceivable that the communication I / F unit 811 is provided outside the computer 800. In that case, the communication I / F unit 811 is connected to the computer 800 via an interface such as USB.
[0113] The display device 813 is a device for displaying various information. Specific examples of the display device 813 include, for example, a liquid crystal display, an organic EL (Electro-Luminescence) display, a display of a wearable device, and the like. The display device 813 may be provided outside the computer 800. In that case, the display device 813 is connected to the computer 800 via, for example, a display cable. Further, when a touch panel is adopted as the input I / F unit 807, the display device 813 can be configured integrally with the input I / F unit 807.
[0114] Note that this embodiment is an exemplification for explaining the present invention, and is not intended to limit the present invention only to its embodiments. Further, the present invention can be variously modified without departing from its gist. Furthermore, those skilled in the art can adopt embodiments in which each element described below is replaced with an equivalent one, and such embodiments are also included in the scope of the present invention.
[0115] [Modification Example] Note that although the present invention has been described based on the above embodiments, the following cases are also included in the present invention.
[0116] [Modification Example 1] At least a part of each component included in the server device 100 according to the above embodiment may be included in the user device 200 and / or the operator device 300. For example, all or part of the functions of the confirmation unit 114 of the server device 100 may be implemented by the operator device 300.
[0117] [Modification Example 2] (2) In the above embodiment, an example in which the operator device 300 has a function of generating display information for providing the first service (for example, information for displaying each screen of the first service site, etc.) has been described. However, part or all of this function may be provided by the server device 100.
Description of Reference Numerals
[0118] 1... Data mediation system, 100... Server device, 110... Control unit, 111... Reception unit, 112... Acquisition unit, 113... Encryption unit, 114... Confirmation unit, 115... Provision unit, 120... Communication unit 120... Storage unit, 200... User device 200... Operator device, 800... Computer, 801... Processor, 803... Memory, 805... Storage device, 807... Input I / F unit, 809... Data I / F unit, 811... Communication I / F unit, 813... Display device.
Claims
1. A computer, a reception function for receiving a anonymization setting for providing user data related to the user to one or more destinations including the first service provider from a user device of a user of a first service provided by the first service provider; an acquisition function for acquiring the user data from the user device in response to an operation input of the user to the user device when the user uses the first service via the user device; an anonymization function for anonymizing the user data based on the anonymization setting; a provision function for providing the anonymized user data to a destination device of each of the one or more destinations, a program.
2. The user data includes confirmation information for confirming the legitimacy of the user when using the first service, the computer realizes a confirmation function for confirming the legitimacy of the user based on the confirmation information, the provision function provides the anonymized confirmation information and / or confirmation result information indicating the confirmation result of the confirmation function to a first service provider device of the first service provider, The program according to claim 1.
3. The user data includes at least one of instruction information indicating an instruction of the user to a first service provider device of the first service by the operation input and personal data of the user, the anonymization setting makes individual settings for each of the instruction information and the personal data for each user and / or for each destination, The program according to claim 1 or 2.
4. The user data includes at least one of instruction information indicating an instruction of the user to a first service provider device of the first service by the operation input and personal data of the user, the anonymization function does not anonymize the instruction information and anonymizes at least a part of the personal data, the provision function provides the first service provider device with the non-anonymized instruction information and / or personal data at least a part of which is anonymized, The program according to claim 1 or 2.
5. The reception function receives a release request for releasing at least a part of the anonymization of the anonymized user data from a first service provider device of the first service provider, The acquisition function acquires permission information indicating permission from the user for the cancellation from the user device, The providing function provides cancellation information for canceling the anonymization of the anonymized user data to the first service provider device based on the cancellation request and the permission information. The program according to claim 1 or 2.
6. The reception function receives a request to provide the user data to a destination different from the first service provider from the first service provider device of the first service provider, The acquisition function acquires consent information indicating consent of the user for the provision of the user data to the destination from the user device, The anonymization setting includes an anonymization setting for the destination, The providing function provides the anonymized user data to the destination device of the destination based on the provision request and the consent information. The program according to claim 1 or 2.
7. A reception unit that receives an anonymization setting for providing user data related to the user to one or more service providers including the first service provider from a user device of a user of the first service provided by the first service provider; An acquisition unit that acquires the user data from the user device in response to an operation input of the user to the user device when the user uses the first service via the user device; An anonymization unit that anonymizes the user data based on the anonymization setting; A providing unit that provides the anonymized user data to the service provider devices of the one or more service providers, respectively. An information processing apparatus.
8. A computer receives an anonymization setting for providing user data related to the user to one or more service providers including the first service provider from a user device of a user of the first service provided by the first service provider, acquires the user data from the user device in response to an operation input of the user to the user device when the user uses the first service via the user device, performs anonymization of the user data based on the anonymization setting, and provides the anonymized user data to the service provider devices of the one or more service providers, respectively. An information processing method.
Citation Information
Patent Citations
Interaction support program
JP2005234939A
Relay device, system, and program
JP2015176546A
Information provision management device, method, and program
JP2016004324A
Data distribution mediation system and data distribution mediation method
JP2022139522A
Data providing device, program and information processing method
JP2021165873A