Information processing apparatus, information processing method, and computer program
The system uses hash values to associate and verify identification information, enhancing security in managing sensitive data like genomic information by eliminating the risk of conversion table leakage, ensuring secure and confidential data management.
Patent Information
- Application Number
- JP2024002177
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-10
- Publication Date
- 2025-07-23
AI Technical Summary
Existing information management systems for highly sensitive data, such as genomic information, lack sufficient security measures, particularly in the risk of leakage through conversion tables used to anonymize patient and genomic management numbers.
A system that utilizes hash values to associate first and second identification information, storing these associations in lists, and calculating third hash values to confirm correct combinations, ensuring no one-to-one correspondence table is created, thereby enhancing security.
This approach provides strong security measures by eliminating the risk of leakage of correspondence tables, ensuring secure management of multiple types of information without direct linking, thus maintaining confidentiality.
Smart Images

Figure 2025108313000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing apparatus, an information processing method, and a computer program.
Background Art
[0002] When managing information with a very high privacy level for an individual, such as genomic information, by an information processing apparatus, it is necessary to manage it so that the information provider cannot be identified. An example of a database system for managing genomic information has been proposed (see, for example, Patent Document 1).
[0003] The system disclosed in Patent Document 1 includes a data storage unit that stores the respective clinical information and genomic information of a plurality of patients. The clinical information and genomic information do not include information that can identify a patient, and the genomic information and clinical information of the same patient are stored in association with each other by link information that cannot identify the patient. This link information is a conversion table that converts the patient code included in the clinical information into a regular patient code and converts the genomic management number included in the genomic information into a regular genomic management number. This conversion table is strictly managed by a third party outside the system.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] The system disclosed in Patent Document 1 is converted into a regular patient code and a regular genomic management number by a conversion table, but the risk of the conversion table leaking to the outside cannot be avoided. Therefore, the information management method disclosed in the system of Patent Document 1 is not sufficient as a security measure for information.
[0006] The present invention has been made in view of such a situation, and aims to improve the security of information to be managed.
Means for Solving the Problems
[0007] To achieve the above object, one aspect of the present invention is a first identification information acquisition means for acquiring first identification information, a second identification information generation means for generating second identification information in association with the first identification information, storing the first identification information in association with a first hash value which is a hash value of first information, and storing the second identification information in association with second information, and a storage means for storing, as a list, a second hash value which is a hash value of a combination of the second identification information and the first identification information, a combination means for generating a combination of any of the first identification information and any of the second identification information, a hash value calculation means for calculating a third hash value which is a hash value of a combination of the second identification information and the first identification information combined by the combination means, a comparison means for comparing the third hash value calculated by the hash value calculation means with the second hash value in the list stored in the storage means, a control means for associating the first information and the second information based on the comparison result of the comparison means, and is an information processing apparatus having the above.
Effects of the Invention
[0008] According to the present invention, for first information and second information to be managed, the hash value of the first information is associated with first identification information, the second information is associated with second identification information, and the second hash value based on the combination of the second identification information and the first identification information is stored in a list. When the third hash value based on the combination of any first identification information and any second identification information matches the second hash value in the list, the first identification information and the second identification information are determined to be the correct combination, and the first information and the second information are associated. There is no one-to-one correspondence table for linking multiple types of information to be managed, and there is no risk of leakage of the correspondence table when managing multiple types of information with one correspondence table. As a result, strong security measures can be taken for the information to be managed.
Brief Description of the Drawings
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Figure 19
Figure 20
Figure 21
Figure 22
Figure 23
Figure 24
Figure 25
Figure 26
Mode for Carrying Out the Invention
[0010] [Embodiment] [Overview] Hereinafter, this embodiment will be described with reference to the drawings. FIG. 1 is a diagram showing an example of a genomic information trust system applied to the information processing apparatus according to this embodiment. The outline of the genomic information trust system of this embodiment will be described.
[0011] In recent years, the analysis of human genomic information has advanced, and genomic information is not only used for disease prevention and treatment, but also for the development of beverages and foods for health promotion, as well as in the apparel industry. If a person can know in advance the diseases with a high risk of onset for themselves, they can take preventive measures so as not to contract those diseases. Therefore, the number of people who want to know their own genomic information, such as what kind of constitution they have and what diseases have a high risk of onset, is increasing. There are companies that provide personal genomic analysis services for testing genomic information for such people. People who use this service put saliva into the tube of the test kit sent by the service company, put the sample into the envelope enclosed with the test kit, and return it to the service company. Then, they can view the test results on the web page at a later date.
[0012] However, among the entire human genome of about 3 billion base pairs, only a part of the base pairs that have been clarified to be related to diseases, and most of the genomic information is unknown about what kind of influence it has on a person's health status. A person who has obtained their own genomic information only knows the risk of onset for specific diseases and cannot be said to be effectively using the genomic information. On the other hand, for example, even if a company developing drugs wants to investigate the relationship between genomic information and diseases to develop new drugs, it is difficult to obtain genomic information from many people because genomic information is personal information. To solve this problem, the genomic information trust system of this embodiment enables the acquisition of genomic information from many people and the utilization of the acquired genomic information.
[0013] A person who permits an external organization such as a company or medical institution that requires genomic information to use their own genomic information becomes a user of the genomic information trust system. Instead of entrusting the management of their own genomic information to a genomic information trust institution, the user receives compensation when their genomic information is used.
[0014] The genomic information trust institution 200 shown in FIG. 1 mediates between the user Ur who provides their own genomic information and the external organization 210 that requires genomic information. The genomic information trust institution 200 acquires genomic information and user information from many users Ur. User information is information that is referred to when analyzing the user's genomic information. User information is, for example, information on the results of health-related tests and the results of health-related questionnaires. A genomic database (DB) for managing the acquired genomic information is constructed in the genomic information trust institution 200. The external organizations A to D belonging to the external organization 210 shown in FIG. 1 are companies or medical institutions that require genomic information and user information, and are output destination institutions where information is output from the genomic information trust institution 200. For example, external organization A is an insurance company, external organization B is a pharmaceutical company, external organization C is a food company, and external organization D is a company related to apparel.
[0015] (Information management method) The information management method by the genomic information trust institution 200 will be described with reference to FIGS. 1 to 4. FIG. 2 is a diagram for explaining acquiring genomic information from a user. Here, the case where user information includes both test results and questionnaire results will be described, but user information may be only one of the test results and questionnaire results. The user sends their own genomic information to the genomic information trust institution 200 (step S1 in FIG. 1). The genomic information trust institution 200 stores the genomic information acquired from the user in the genomic DB. The genomic information trust institution 200 holds a genomic hash value that is a hash value calculated from the genomic information using a predetermined hash function. In addition, when the Genome Information Trust Institution 200 receives genome information from a user, it generates a user ID, which is unique identification information for the user, and stores the genome hash value and the user ID. When the Genome Information Trust Institution 200 receives genome information, it generates a questionnaire ID and an examination ID for each user.
[0016] Figure 3 is a diagram for explaining obtaining examination results and questionnaire results from a user. The Genome Information Trust Institution 200 sends the generated questionnaire ID and examination ID to the user. After filling in a predetermined questionnaire, the user attaches the questionnaire ID to the questionnaire result and sends it to the Genome Information Trust Institution 200 (step ST1 in FIG. 1). The user attaches the examination ID to the result of an examination received at a hospital regarding their health condition and passes it to the Genome Information Trust Institution 200 (step ST1 in FIG. 1). The Genome Information Trust Institution 200 receives the questionnaire result with the questionnaire ID attached and the examination result with the examination ID attached from the user. The Genome Information Trust Institution 200 calculates the hash value of the combination of the user ID and the questionnaire ID, and manages the obtained hash value as the questionnaire hash value. In addition, the Genome Information Trust Institution 200 calculates the hash value of the combination of the user ID and the examination ID, and manages the obtained hash value as the examination hash value.
[0017] Figure 4 is a diagram showing an example of information managed by the Genome Information Trust Institution 200. The Genome Information Trust Institution 200 holds a list of examination hash values, a list of questionnaire hash values, and a list of genome hash values. The Genome Information Trust Institution 200 holds a correspondence table between the examination ID and the examination result, a correspondence table between the questionnaire ID and the questionnaire result, and a correspondence table between the user ID and the genome hash value. The Genome Information Trust Institution 200 stores the list of the above three types of hash values and the correspondence table for the three types of IDs separately. Even if an external person reads one piece of data from the above correspondence table and list, they cannot piece together the information related to the read data. For example, even if the inspection ID and the inspection results can be linked from the correspondence table of inspection IDs and inspection results for a user, the inspection ID cannot be linked to the genomic information of the target user. Also, the inspection ID and the questionnaire ID are sent to the user, but the user ID associated with the genomic information is not output externally, so the confidentiality of the genomic information is improved. As described above, in this embodiment, even if all the data tables in FIG. 4 are fraudulently obtained, as long as the calculation formula of the hash function and the like are not stolen, the connections between the tables cannot be reconstructed, and the user's information can be managed more securely.
[0018] (Consideration Payment Procedure) Just having their genomic information managed securely by the Genome Information Trust Institution 200 does not provide an incentive for users to entrust the management of their genomic information to the institution. The genomic information trust system of this embodiment aims to provide genomic information to more users in the following way.
[0019] Any one of the external institutions 210, namely External Institutions A to D, sends an output request including output conditions for receiving the necessary genomic information to the Genome Information Trust Institution 200 (step ST2 in FIG. 1). Here, for example, a case where External Institution B sends an output request including output conditions necessary for the development of a new drug to the Genome Information Trust Institution 200 will be described.
[0020] When the Genome Information Trust Institution 200 receives an output request from an external institution B, it searches for genome information and user information that match the output conditions based on three types of lists and three types of correspondence tables. This search method will be described later. The Genome Information Trust Institution 200 provides the genome information and user information obtained by the search to the external institution B (step ST3 in FIG. 1). The Genome Information Trust Institution 200 receives the consideration for the information provision from the external institution B (step ST4 in FIG. 1). The Genome Information Trust Institution 200 pays the user Ur the consideration for providing the genome information and user information to the external institution B (step ST5 in FIG. 1).
[0021] When the user Ur has their genome information provided to the external institution 210, they can obtain the consideration. Therefore, the Genome Information Trust Institution 200 can collect genome information from more users Ur. In addition, each of the plurality of external institutions 210 utilizes a large amount of genome information for product development or preemptive medicine, thereby suppressing the number of people falling ill and reducing the medical expenses borne by the Health Insurance Federation 220, which is a public medical insurance institution. The hospital 230, which is a non-profit institution, can use the genome information stored in the Genome DB for medical purposes.
[0022] (Search method) When the Genome Information Trust Institution 200 receives an output request from the external institution 210, it reconstructs the correspondence relationship of three types of IDs by performing arithmetic processing on a plurality of data based on the three types of lists and three types of correspondence tables shown in FIG. 4. For example, when calculating a hash value using the correct combination of the test ID and the user ID, this hash value matches one of the test hash values described in the list of retained test hash values. Using this calculation, the correspondence relationship of the three types of IDs can be confirmed. A specific example of the search method will be described.
[0023] (Search example 1) FIG. 5 is a diagram for explaining an example of a search case. When checking the correspondence between the genomic information and the questionnaire results of a specific user, the genomic information trustee 200 processes as follows. Assume that the user ID is specified. The genomic information trustee 200 reads out the questionnaire ID one by one from the correspondence table of the questionnaire ID and the questionnaire results, and calculates the hash value of the combination of the read questionnaire ID and the user ID. When the calculated hash value matches the questionnaire hash value in the list of questionnaire hash values, the genomic information trustee 200 determines that the questionnaire ID and the user ID that are the source of the calculated hash value are the correct combination. In this way, the correspondence between the user ID and the questionnaire ID can be confirmed. The genomic information trustee 200 specifies the genomic information corresponding to the user ID by referring to the correspondence table between the user ID and the genomic hash value, and specifies the questionnaire result corresponding to the questionnaire ID by referring to the correspondence table between the questionnaire ID and the questionnaire results.
[0024] (Search case 2) FIG. 6 is a diagram for explaining another example of a search case. When wanting to find the test ID of a specific user, the genomic information trustee 200 processes as follows. The user ID is specified. The genomic information trustee 200 reads out the test ID one by one from the correspondence table of the test ID and the test results, and calculates the hash value of the combination of the read test ID and the user ID. When the calculated hash value matches the test hash value in the list of test hash values, the genomic information trustee 200 determines that the test ID and the user ID that are the source of the calculated hash value are the correct combination. In this way, the correspondence between the user ID and the test ID can be confirmed.
[0025] (Method for managing information related to output) FIG. 7 is a diagram for explaining an example of a method for managing information related to output. The Genome Information Trust Institution 200 records information related to output in chronological order for each user in order to grasp the external institutions to which the genome information and user information are output. This record is referred to as history information. Also, when the Genome Information Trust Institution 200 receives a deletion request to the effect that the user requests deletion of the genome information, it deletes the target genome information and records information to the effect that the genome information has been deleted in the history information. The Genome Information Trust Institution 200 manages the history information using a blockchain. The Genome Information Trust Institution 200 endeavors to clearly calculate the consideration to be paid to the user. Also, each user can, by referring to the history information, conduct a trace investigation of when and by which external institution 210 their information was used. Also, when a user requests deletion of the genome information, each user can, by referring to the history information, conduct a trace investigation of whether the deletion process has been carried out in response to the request.
[0026] (Information provision process) FIG. 8 is a diagram for explaining an example of information provision to an external institution. In response to an output request from an external institution 210 that requires genome information, the Genome Information Trust Institution 200 provides user information (step ST11) and provides genome information (step ST12). When the Genome Information Trust Institution 200 provides information to the external institution 210, it assigns an output number, which is identification information unique to the output, to the information to be output. The Genome Information Trust Institution 200 performs a confidentiality process on the information to be output and the information on the assigned output number using a public key encryption method and transmits it. Since the information output to the external institution 210 is encrypted, the confidentiality of the information provided to the external institution 210 can be enhanced.
[0027] The Genome Information Trust Institution 200 comprehensively manages the genome information, user information, key information for decrypting the encrypted document, and the like. In the Genome Information Trust System, by performing encryption processing on the genome information and user information at any time, the correspondence relationship is made confidential, so that no correspondence table is created and high security is ensured. Details of the genome information trust system to which the present embodiment is applicable will be described below.
[0028] <System Configuration> The configuration of the genomic information trust system according to this embodiment will be described. FIG. 9 is a diagram showing an overview of the system configuration of the genomic information trust system to which this embodiment is applicable. The genomic information trust system includes an information processing apparatus 1 operated by a genomic information trust institution 200, a user terminal 2 used by a user, and external institution terminals 3-1 to 3-n used by an external institution 210 such as a company or a research institution that is the output destination of genomic information. n is an arbitrary integer of 1 or more. The information processing apparatus 1 has a storage unit 22. A financial processing terminal 4 is connected to the network 100. The financial processing terminal 4 is operated by a financial institution such as a bank. The information processing apparatus 1 is communicably connected to each of the user terminal 2, the financial processing terminal 4, and the external institution terminals 3-1 to 3-n via the network 100. However, the external institution terminals 3-1 to 3-n cannot communicate with the user terminal 2. The network 100 is a network including, for example, the Internet.
[0029] The information processing apparatus 1 is, for example, a server. The user terminal 2 is, for example, an information processing apparatus such as a smartphone or a PDA (Personal Digital Assistant). The external institution terminals 3-1 to 3-n are, for example, information processing apparatuses such as a server or a PC (Personal Computer). The financial processing terminal 4 is, for example, a server. When the financial processing terminal 4 receives payment data including information on the consideration, the account for debit of the consideration, and the account for transfer of the consideration, it performs a process of transferring the consideration from the designated debit account to the transfer account.
[0030] <Hardware Configuration> FIG. 10 is a block diagram showing the hardware configuration of the information processing apparatus 1 according to the present embodiment. The information processing apparatus 1 includes a CPU (Central Processing Unit) 11, a ROM (Read Only Memory) 12, a RAM (Random Access Memory) 13, a bus 14, an input / output interface 15, an output unit 16, an input unit 17, a storage unit 18, a communication unit 19, and a drive 20. The CPU 11 is connected to the storage unit 22 shown in FIG. 9 via a signal line (not shown).
[0031] The CPU 11 executes various processes according to a program recorded in the ROM 12 or a program loaded from the storage unit 18 to the RAM 13. The RAM 13 also appropriately stores data and the like necessary for the CPU 11 to execute various processes. The CPU 11, the ROM 12, and the RAM 13 are mutually connected via the bus 14. The input / output interface 15 is also connected to this bus 14.
[0032] The output unit 16, the input unit 17, the storage unit 18, the communication unit 19, and the drive 20 are connected to the input / output interface 15. The output unit 16 is composed of a display, a speaker, or the like, and outputs various information as an image or sound. The input unit 17 is composed of a keyboard, a mouse, or the like, and inputs various information. The storage unit 18 is composed of an HDD (Hard Disk Drive), an SSD (Solid State Drive), or the like, and stores various data. The communication unit 19 communicates with other devices via the network 100.
[0033] A removable medium 21 made of a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, etc. is appropriately mounted on the drive 20. The program read from the removable medium 21 by the drive 20 is installed in the storage unit 18 as necessary. Also, the removable medium 21 can store various data stored in the storage unit 18 in the same manner as the storage unit 18.
[0034] <Functional Configuration> FIG. 11 is a functional block diagram showing an example of the functional configuration in the information processing apparatus 1 according to the present embodiment.
[0035] In the information processing apparatus 1, when the CPU 11 executes processing according to a program, the functions of the management unit 51, the selection unit 33, the output request acquisition unit 34, the specifying unit 35, the output unit 36, the consideration calculation unit 37, the payment data generation unit 38, the payment data output unit 39, the deletion request acquisition unit 40, the determination unit 41, and the deletion unit 42 are executed.
[0036] FIG. 12 is a functional block diagram showing an example of the functional configuration in the management unit 51 shown in FIG. 11. The management unit 51 includes the functions of the information acquisition unit 31, the identification information assigning unit 32, the second identification information generation unit 65, the combination unit 66, the hash value calculation unit 67, the comparison unit 68, the control unit 69, and the first hash value acquisition unit 70. The information acquisition unit 31 includes the functions of the first identification information acquisition unit 61, the first information acquisition unit 62, the second identification information acquisition unit 63, and the second information acquisition unit 64. The hash value calculation unit 67 includes the functions of the first hash value calculation unit 67a and the second hash value calculation unit 67b.
[0037] The configurations of the storage unit 18 and the storage unit 22 will be described. The storage unit 18 and the storage unit 22 store, in a shared manner, as information related to the user, (1) genomic information, (2) user information, (3) contract information, (4) consideration calculation conditions, and (5) output-related information. Specifically, the storage unit 22 stores genomic information, and the storage unit 18 stores user information, contract information, consideration calculation conditions, and output-related information for the purpose of managing a plurality of types of user information. Hereinafter, each of the information (1) genomic information to (5) output-related information will be described in detail.
[0038] (1) Genomic Information Genomic information is base sequence information that varies from person to person. The amount of information in a person's genomic information is said to be approximately 750 MB, for example, when the information of four types of bases, adenine, guanine, cytosine, and thymine, is expressed as 2-bit information. The genomic information for each user stored in the storage unit 18 does not have to be all of the genomic information, and may be a part that includes the main part of the entire genomic information.
[0039] (2) User information User information is information related to the user and is information referred to when analyzing genomic information. User information is, for example, information on test results or questionnaire results. User information may include both test results and questionnaire results.
[0040] Test results are the results of tests related to the user's health status. Tests related to health status include, for example, general health check-up tests and special health check-up tests that are obligatory for companies to conduct. General health check-ups are tests that are obligatory regardless of industry and occupation, and special health check-ups are tests targeted at people engaged in legally hazardous work. General health check-ups include pre-employment health check-ups and regular health check-ups. General health check-up tests and special health check-ups have multiple test items, but tests related to health status may be individual tests such as vision, hearing, blood pressure, gastric camera tests, and blood tests. Furthermore, tests related to health status may be tests related to motor functions such as grip strength. Also, the test results are not limited to the latest test results and may include past test results.
[0041] The questionnaire results are the results of the questionnaire conducted on the user. The questionnaire includes, for example, items related to the user's attributes and lifestyle habits. The attributes are the user's age and gender. The items related to lifestyle habits are, for example, the frequency of drinking alcohol, the frequency of smoking, and the average sleep time per day. The questionnaire may also include items related to hobbies such as the user's hobbies or favorite colors. The items of the questionnaire can be set arbitrarily. The questionnaire results can be obtained not only at the timing of obtaining genomic information but also after obtaining genomic information.
[0042] Note that the pre - physical examination questionnaire for the user may include items such as medical history, family medical history, presence or absence of allergies, alcohol consumption, sleep time, exercise time, or stress check. These items may be included in the health - related examination or in the questionnaire.
[0043] Also, when the user is wearing a wearable terminal such as a wristwatch that measures biological information such as heart rate, the measurement results of the change in biological information over time by the wearable terminal may be included in the examination results or in the questionnaire results. Also, when the wearable terminal has a function of measuring the user's wake - up time and bedtime, the measurement results of the wake - up time and bedtime may be included in the examination results or in the questionnaire results. If the wearable terminal transmits the measurement results to the information processing device 1 via the user terminal 2, the measurement results are included in the examination results. If the user operates the user terminal 2 to input the measurement results into the questionnaire, the measurement results are included in the questionnaire results.
[0044] Also, when the user measures their own blood pressure value using an automatic blood pressure monitor installed at home, at work, or in a sports gym, etc., the measured blood pressure value may be included in the examination results. In addition, a test kit for self - blood collection by the user is sold at pharmacies. After the user collects their own blood using the test kit, they may obtain the results of a blood test by sending the test kit to a test service company. The results of the blood test obtained by the user using the test kit may be included in the test results of the user information.
[0045] Furthermore, the user information may include identification information unique to the user terminal 2 necessary for the information processing device 1 to communicate with the user terminal 2. The identification information unique to the user terminal 2 is, for example, the IP (Internet Protocol) address of the user terminal 2, or an email address, etc. Hereinafter, the identification information unique to the user terminal 2 is referred to as the terminal ID. The terminal ID may be stored in the storage unit 18 included in the questionnaire results or test results.
[0046] (3) Contract information The contract information stipulates the handling of deletion of genomic information and user information from the storage unit 18 in response to a deletion request from the user.
[0047] Among the above five types of information, genomic information, user information, and contract information are provided, for example, from the user terminal 2 to the information processing device 1. The storage unit 18 stores, for each user, information indicating the payment destination of the consideration to the user, in addition to these three types of information, as information related to the user. The information indicating the payment destination of the consideration is, for example, the user's bank account or the account of a fund transfer operator. The user information may include information indicating the payment destination of the consideration. For example, the information indicating the payment destination of the consideration may be included in the test results or questionnaire results. In this embodiment, the case where the information indicating the payment destination of the consideration is stored in the storage unit 18 included in the test results or questionnaire results will be described.
[0048] FIG. 13 is a diagram showing an example of information associating user information stored by the storage unit 18. The storage unit 18 stores the inspection hash value list 113 and the questionnaire hash value list 114. The storage unit 18 stores the genome correspondence table 112, the inspection correspondence table 115, and the questionnaire correspondence table 116. The inspection hash value list 113 is a list of inspection hash values of all users. The questionnaire hash value list 114 is a list of questionnaire hash values of all users.
[0049] The genome correspondence table 112 is a correspondence table between user IDs and genome hash values. The inspection correspondence table 115 is a correspondence table between inspection IDs and storage addresses indicating the locations where the inspection results corresponding to the inspection IDs are stored in the storage unit 18. The questionnaire correspondence table 116 is a correspondence table between questionnaire IDs and storage addresses indicating the locations where the questionnaire results corresponding to the questionnaire IDs are stored in the storage unit 18.
[0050] The storage unit 18 uses the genome correspondence table 112 to store the user ID in association with the genome hash value, which is the hash value of the genome information. The user ID is an example of the first identification information. The genome information is an example of the first information. The genome hash value is an example of the first hash value. The genome hash value serves as the identification information of the genome information. The genome hash value is calculated from the genome information by a predetermined hash function. The hash function is, for example, SHA (Secure Hash Algorithm)-2 or SHA-3. The hash value is represented by a hexadecimal value combining numbers from 0 to 9 and lowercase Roman letters from a to f.
[0051] The storage unit 18 uses the inspection correspondence table 115 to store the inspection results in association with the inspection IDs. The storage unit 18 uses the questionnaire correspondence table 116 to store the questionnaire results in association with the questionnaire IDs. The inspection results and the questionnaire results are examples of the second information. When the second information is the inspection result, the inspection ID corresponds to the second identification information, which is an identifier assigned corresponding to the user's inspection result. When the second information is the questionnaire result, the questionnaire ID corresponds to the second identification information, which is an identifier assigned corresponding to the user's questionnaire result.
[0052] When the second information is an inspection result, the storage unit 18 stores, in a list, a hash value of a combination of an inspection ID and a user ID, which is an inspection hash value. The inspection hash value is an example of the second hash value, and this list corresponds to the inspection hash value list 113. When the second information is a questionnaire result, the storage unit 18 stores, in a list, a hash value of a combination of a questionnaire ID and a user ID, which is a questionnaire hash value. The questionnaire hash value is an example of the second hash value, and this list corresponds to the questionnaire hash value list 114.
[0053] The genomic information is not stored in the storage unit 18, but is stored in a storage unit 22, which is another storage means physically different from the storage unit 18. Since the genomic information contains a lot of information related to genetic factors such as a user's personality, intelligence, and diseases that are likely to occur, it is called "ultimate personal information". Therefore, it is desirable that the genomic information be stored in a storage means different from the storage unit 18 that stores information associating a plurality of types of information for each user. In the present embodiment, the genomic information is stored in the storage unit 22. In the storage unit 22, a database is constructed so that the genomic information can be read out using the genomic hash value as a key. This database is referred to as a genomic DB.
[0054] Note that FIG. 9 shows a case where the information processing apparatus 1 has the storage unit 22, but the installation location of the storage unit 22 is not limited to the configuration shown in FIG. 9. For example, the storage unit 22 may be provided in another server (not shown) connected to the network 100. In this case, the CPU 11 is communicatively connected to the storage unit 22 via the communication unit 19 and the network 100.
[0055] (4) Calculation conditions for consideration The storage unit 18 stores a plurality of calculation conditions as the calculation conditions for the consideration to the user. The plurality of calculation conditions are stored in the storage unit 18 in advance, but may be updated by the administrator of the information processing apparatus 1. The plurality of calculation conditions include (a) the type of genomic information, (b) the acquisition of at least one of genomic information and user information, and (c) the number of times that genomic information and user information are output to the external institution terminal 3-k (k is an arbitrary integer from 1 to n).
[0056] (a) The type of genomic information The type of genomic information is, for example, the type of SNPs scattered at 3 million to 10 million locations among about 3 billion base pairs. Also, the type of genomic information may be genomic information of a part where the DNA base sequence is different from that of a general person. When this calculation condition is selected, if the type of genomic information is a rare type, the possibility of an increase in the output request by an external institution is high, and the consideration paid to the user becomes large. (b) The acquisition of at least one of genomic information and user information This calculation condition is a condition for encouraging the user to actively provide genomic information and user information to the genomic information trust institution 200. When this calculation condition is selected, when at least one of genomic information and user information is acquired from the user, a predetermined consideration is calculated as the consideration paid to the user. For example, when one of genomic information and user information is acquired from the user, C1 is calculated as the consideration. In this case, when genomic information and user information are acquired from the user, a consideration twice that of C1 may be calculated. (c) The number of times that genomic information and user information are output to the external institution terminals 3-1 to 3-n This condition is a condition in which the consideration increases in proportion to the number of times that genomic information and user information are output to the external institution terminals 3-1 to 3-n.
[0057] (5) Output-related information The output-related information is information including a user ID, an output date and time, an external institution 210 as an output destination, and the presence or absence of payment of consideration, which is associated with an output number that is a unique number different for each output.
[0058] Figure 14 is a table showing an example of the history of output-related information stored in the storage unit 18. The external institution A shown in FIG. 7 means, for example, the external institution terminal 3-1 operated by the external institution A. The storage unit 18 stores output-related information for each output of genomic information and user information.
[0059] The output-related information is accumulated in the storage unit 18 each time the genomic information and the user information are output from the information processing apparatus 1 to the external institution terminal 3-k.
[0060] Next, each function executed by the CPU 11 will be described. The information acquisition unit 31 acquires the genomic information and the user information of the user from the user terminal 2. The identification information adding unit 32 adds a user ID to the genomic information and the user information acquired by the information acquisition unit 31. When the identification information adding unit 32 acquires the user information in multiple portions, the divided user information is associated with each other and one user ID is added.
[0061] When the first information acquisition unit 62 acquires a genome from the user terminal 2, the first information acquisition unit 62 stores the genomic information in the storage unit 22. When the first information acquisition unit 62 acquires a genome, the identification information adding unit 32 generates a user ID and passes the generated user ID to the first identification information acquisition unit 61. When the first identification information acquisition unit 61 acquires the user ID from the identification information adding unit 32, the first identification information acquisition unit 61 stores the user ID in the storage unit 18 in association with the genomic hash value. The second identification information generation unit 65 generates a questionnaire ID and an inspection ID in association with the user ID. The second identification information generation unit 65 transmits the generated questionnaire ID and inspection ID to the user terminal 2. When the second information acquisition unit 64 acquires the inspection result with the inspection ID attached from the user terminal 2, it stores the inspection result in the storage unit 18 in association with the inspection ID. When the second information acquisition unit 64 acquires the questionnaire result with the questionnaire ID attached from the user terminal 2, it stores the questionnaire result in the storage unit 18 in association with the questionnaire ID.
[0062] The combination unit 66, the hash value calculation unit 67, the comparison unit 68, and the control unit 69 serve to create an ID correspondence table for associating multiple types of information of each user when necessary. When the combination unit 66 receives the correspondence relationship request information, which is information indicating a request for creating an ID correspondence table, from the selection unit 33, it generates a combination of an arbitrary user ID and an arbitrary inspection ID. When the combination unit 66 receives the correspondence relationship request information from the output request acquisition unit 34, it generates a combination of an arbitrary user ID and an arbitrary questionnaire ID.
[0063] The hash value calculation unit 67 includes the functions of a first hash value calculation unit 67a and a second hash value calculation unit 67b. The first hash value calculation unit 67a calculates genomic information using a predetermined hash function to obtain a genomic hash value. The second hash value calculation unit 67b calculates a combination of an inspection ID and a user ID using a predetermined hash function to obtain an inspection hash value. The second hash value calculation unit 67b calculates a combination of a questionnaire ID and a user ID using a predetermined hash function to obtain a questionnaire hash value. For example, the second hash value calculation unit 67b calculates a questionnaire hash value by calculating a string obtained by concatenating one string after the other for the string of the user ID and the string of the questionnaire ID using a predetermined hash function. The second hash value calculation unit 67b may obtain the questionnaire hash value from a string obtained by adding an arbitrary symbol such as a comma between the string of the user ID and the string of the questionnaire ID when obtaining the questionnaire hash value.
[0064] When the combination unit 66 combines the user ID and the inspection ID, the hash value calculation unit 67 calculates the combination of the inspection ID and the user ID using a predetermined hash function to obtain a third hash value. When the combination unit 66 combines the user ID and the questionnaire ID, the hash value calculation unit 67 calculates the combination of the questionnaire ID and the user ID using a predetermined hash function to obtain a third hash value.
[0065] The comparison unit 68 compares the third hash value calculated by the hash value calculation unit 67 with the inspection hash value in the inspection hash value list 113 or the questionnaire hash value in the questionnaire hash value list 114 stored in the storage unit 18.
[0066] When the comparison result by the comparison unit 68 indicates that the inspection hash value and the third hash value match, the control unit 69 determines that the user ID and the inspection ID combined by the combination unit 66 are the correct combination, and associates the user ID and the inspection ID. When the comparison result by the comparison unit 68 indicates that the questionnaire hash value and the third hash value match, the control unit 69 determines that the user ID and the questionnaire ID combined by the combination unit 66 are the correct combination, and associates the user ID and the questionnaire ID. Based on the associated user ID, questionnaire ID, inspection ID, and the genome correspondence table 112, the control unit 69 creates an ID correspondence table and stores it in the storage unit 18. The ID correspondence table is a table in which the genome hash value, questionnaire ID, and inspection ID are described in association with the user ID. The control unit 69 transmits correspondence relationship construction information for notifying that the construction of the ID correspondence table is completed to the specifying unit 35. The control unit 69 specifies the combination of the genome hash value and the inspection result based on the associated user ID and inspection ID. The control unit 69 specifies the combination of the genome hash value and the questionnaire result based on the associated user ID and questionnaire ID. The control unit 69 specifies the genome information based on the genome hash value. The control unit 69 transmits correspondence information indicating information on correct combinations of multiple types of information of each user to the specifying unit 35. The correspondence information is information indicating, for each user, combinations of genomic hash values and test results, combinations of genomic hash values and questionnaire results, and combinations of genomic hash values and genomic information.
[0067] When the selection unit 33 receives an output request from an arbitrary external institution terminal 3-k, it reads out output conditions and related conditions selected by the external institution 210 from the output request for one or both of the genomic information and the user information. The selection unit 33 transfers the output request including the read output conditions and related conditions to the output request acquisition unit 34. The output conditions are conditions for extracting necessary genomic information from the genomic DB. The output conditions are, for example, diabetic patients aged 20 to 39 years old. The related conditions are conditions for extracting necessary information from the user information for the user of the genomic information extracted by the output conditions. When the user information includes test results, the related conditions are, for example, blood tests. When the user information includes questionnaire results, the related conditions are, for example, diet content.
[0068] When the output request acquisition unit 34 receives an output request including output conditions and related conditions from the selection unit 33, it transfers the output request including the output conditions and related conditions to the specifying unit 35. The specifying unit 35 receives an output request including output conditions and related conditions from the output request acquisition unit 34, and when it receives the correspondence relationship construction information from the control unit 69, it reads out the ID correspondence table from the storage unit 18. When the specifying unit 35 receives the correspondence information from the control unit 69, it refers to the ID correspondence table and specifies genomic information and user information that match the output conditions and related conditions.
[0069] The output unit 36 deletes the information among the genomic information and user information specified by the specifying unit 35 that was not selected as an output condition or a related condition, and outputs it to the external institution terminal 3-k that is the transmission source of the output request. The output unit 36 registers the output-related information in the blockchain. After the output unit 36 registers the output-related information in the blockchain, it deletes the ID correspondence table stored by the storage unit 18. The output unit 36 calculates the output frequency of the genomic information and user information for each user at a predetermined cycle based on the output-related information stored in the storage unit 18.
[0070] The consideration calculation unit 37 calculates the consideration for the user based on at least one of the plurality of calculation conditions stored in the storage unit 18.
[0071] The payment data generation unit 38 generates payment data that designates the user's bank account or the account of a funds transfer operator based on the calculated consideration. Specifically, the payment data generation unit 38 generates payment data including information on the consideration, the account from which the consideration is to be withdrawn, and the account to which the consideration is to be transferred. The payment data output unit 39 outputs the payment data generated by the payment data generation unit 38 to the financial processing terminal 4.
[0072] When the deletion request acquisition unit 40 acquires a deletion request for genomic information and user information from the user terminal 2, it outputs the deletion request to the determination unit 41. The deletion request acquisition unit 40 specifies the genomic information to be deleted by the terminal ID indicating the transmission source of the deletion request. The determination unit 41 determines whether deletion is possible based on the user's contract information stored in the storage unit 18. The determination unit 41 outputs the determination result of whether deletion is possible, determined based on the contract information of the user who requested deletion, to the deletion unit 42. The deletion unit 42 deletes the genomic information stored in the storage unit 22 and the user information stored in the storage unit 18 based on the deletion request.
[0073] <Processing content> (Information storage process) FIG. 15 is a diagram schematically showing the flow of information acquisition processing. FIG. 16 is a flowchart showing an example of the procedure of information acquisition processing. In step S11, the first information acquisition unit 62 acquires genomic information from the user terminal 2. In step S12, the first information acquisition unit 62 stores the genomic information in the storage unit 22. In step S13, the identification information assigning unit 32 generates a user ID for the genomic information. For example, the identification information assigning unit 32 may use a timestamp indicating the date and time when the first information acquisition unit 62 acquired the genomic information from the user terminal 2 as the user ID. When there is no possibility that the first information acquisition unit 62 acquires genomic information from a plurality of user terminals 2 simultaneously, the timestamp is unique information and serves as identification information different for each user. In step S14, the second identification information generation unit 65 generates an inspection ID and a questionnaire ID in association with the user ID. In step S15, the second identification information generation unit 65 transmits the inspection ID and the questionnaire ID to the user terminal 2.
[0074] In step S16, the second information acquisition unit 64 acquires from the user terminal 2 an inspection result with an attached inspection ID and a questionnaire result with an attached questionnaire ID. In step S17, the second information acquisition unit 64 stores the inspection ID and the inspection result, and the questionnaire ID and the questionnaire result in the storage unit 18. In step S18, the first hash value calculation unit 67a calculates a first hash value, which is the hash value of the genomic information acquired from the user. In step S19, the first identification information acquisition unit 61 stores the genomic hash value and the user ID in the storage unit 18 in association with each other. In step S20, the first identification information acquisition unit 61 combines the inspection ID and the user ID, and combines the questionnaire ID and the user ID.
[0075] In step S21, the second hash value calculation unit 67b calculates a test hash value, which is a hash value of the test ID and the user ID. The second hash value calculation unit 67b calculates a questionnaire hash value, which is a hash value of the questionnaire ID and the user ID. In step S22, the second hash value calculation unit 67b stores the two hash values calculated in step S21 in the storage unit 18. Specifically, the second hash value calculation unit 67b stores a test hash value list, which is a list in which the test hash values of all users are described, in the storage unit 18. The second hash value calculation unit 67b stores a questionnaire hash value list, which is a list in which the questionnaire hash values of all users are described, in the storage unit 18.
[0076] (Basic processing) The procedure of the process in which the information processing apparatus 1 provides user information to the external organization 210 in response to a request from the external organization 210 is described. FIG. 17 is a sequence diagram showing an example of basic processing by the information processing apparatus 1.
[0077] In step S31, the external organization terminal 3-k makes an output request including output conditions to the information processing apparatus 1. In step S32, the output request acquisition unit 34 acquires the output request from the external organization terminal 3-k. In step S33, the specifying unit 35 specifies the user information stored in the storage unit 18 and the genomic information stored in the storage unit 22 based on the output request.
[0078] In step S34, the output unit 36 deletes information not related to the output request from the genomic information and the user information specified by the specifying unit 35. In step S35, the output unit 36 outputs the genomic information and the user information after the process of step S17 to the external organization terminal 3-k. In step S36, the consideration calculation unit 37 calculates the consideration for the user who provided the genomic information and the user information.
[0079] Note that in step S35, the output destination of the genomic information and user information output from the output unit 36 may be the display unit of the external institution terminal 3-k. In this case, the external institution terminal 3-k does not temporarily store the genomic information and user information. Therefore, it is possible to suppress the secondary use of these information without obtaining permission from the genomic information trust institution 200.
[0080] (Specific processing) Next, the specific processing procedure from when the information processing apparatus 1 acquires genomic information from the user to when it provides the genomic information to an external institution will be described.
[0081] FIG. 18 is a diagram schematically showing the flow of processing from information provision by the information processing apparatus 1 to consideration calculation. FIG. 19 is a flowchart showing a specific example of the processing procedure from information provision to consideration calculation.
[0082] In step S41, the selection unit 33 determines whether there is an output request including output conditions from the external institution terminal 3-k. If there is no output request from the external institution terminal 3-k, the selection unit 33 repeats the determination in step S41.
[0083] As a result of the determination in step S41, when the selection unit 33 receives an output request including output conditions from the external institution terminal 3-k, it transmits correspondence relationship request information to the management unit 51. In step S42, when the management unit 51 receives the correspondence relationship request information from the selection unit 33, the combination unit 66, the hash value calculation unit 67, the comparison unit 68, and the control unit 69 construct an ID correspondence table. Further, the control unit 69 transmits correspondence relationship information indicating the correspondence relationship of a plurality of types of information for each user to the specifying unit 35 based on the constructed ID correspondence table. A specific example of the processing in step S42 will be described later with reference to FIGS. 20 to 23.
[0084] In step S43, the selection unit 33 reads out the output conditions and related conditions selected by the external institution 210 from the output request. Then, the selection unit 33 transfers the output request including the output conditions and related conditions to the output request acquisition unit 34. When the output request acquisition unit 34 acquires the output request including the output conditions and related conditions from the selection unit 33, it transfers the output request including the output conditions and related conditions to the specification unit 35. In step S44, when the specification unit 35 receives the output request including the output conditions and related conditions from the output request acquisition unit 34 and receives the correspondence relationship construction information from the control unit 69, it reads out the ID correspondence table from the storage unit 18. When the specification unit 35 receives the correspondence relationship information from the control unit 69, it refers to the ID correspondence table and specifies the genomic information and user information that match the output conditions and related conditions.
[0085] In step S45, the output unit 36 determines whether the genomic information and user information specified by the specification unit 35 include information unrelated to the output request. Specifically, the output unit 36 determines whether the genomic information and user information specified by the specification unit 35 include information other than the output conditions included in the output request and information other than the related conditions.
[0086] As a result of the determination in step S45, if the specified genomic information and user information include information unrelated to the output request, the output unit 36 deletes the information unrelated to the output request from the specified genomic information and user information (step S46). After step S46, the output unit 36 proceeds to the process of step S47.
[0087] As a result of the determination in step S45, if the specified genomic information and user information do not include information unrelated to the output request, the output unit 36 proceeds to the process of step S47. In step S47, the output unit 36 outputs the genomic information and user information to the external institution terminal 3-k. In step S48, the output unit 36 identifies the user ID of the user corresponding to the genomic information and user information output in step S47 with reference to the ID correspondence table, and stores output-related information in the storage unit 18 for each output. In step S49, the output unit 36 registers the output-related information in the blockchain. After that, the output unit 36 deletes the ID correspondence table stored in the storage unit 18.
[0088] Note that in step S46, when the output unit 36 outputs the genomic information and user information to the external institution terminal 3-k, it may generate in advance the output number of the output-related information to be stored in the storage unit 18 in step S47 and attach it to the information to be output. In this case, the genomic information trust institution 200 and the external institution 210 can confirm the presence or absence of payment of the consideration for the provided information using the output number as a key. Also, the output unit 36 may perform anonymization processing on the genomic information, user information, and output number information to be output using a public-key encryption method and transmit it to the external institution terminal 3-k. In this case, since the information output to the external institution terminal 3-k is encrypted, the confidentiality of the output information can be enhanced.
[0089] Also, when the deletion unit 42 deletes the genomic information and user information stored in the storage unit 18 based on a deletion request from the user terminal 2, it may include the information on the deleted genomic information and user information in the output-related information. In this case, it is registered in the blockchain that each user's genomic information and user information have been deleted. In the table shown in FIG. 14, the deletion unit 42 may record the deletion date and time instead of the output date and time, and may not record anything in the columns of the output destination institution and payment of consideration. When each user requests deletion of genomic information, they can track whether the deletion process has been performed in response to the request by referring to the history of the output-related information registered in the blockchain.
[0090] (Specific example of the process in step S42) An example of the method for constructing the ID correspondence table in step S42 shown in FIG. 19 will be described. After the management unit 51 identifies the correspondence between the user ID and the inspection ID for each user, the process until obtaining the combination of the genomic information and the inspection result will be described. FIG. 20 is a diagram schematically showing the flow of the process for obtaining the correspondence. FIG. 21 is a flowchart showing an example of the procedure of the process for obtaining the correspondence. FIG. 22 is a diagram for explaining the procedure for creating the correspondence table of the user ID and the inspection ID.
[0091] In step S51, the combination unit 66 generates a combination of an arbitrary inspection ID and an arbitrary user ID. In step S52, the hash value calculation unit 67 calculates a third hash value, which is the hash value of the combination of the inspection ID and the user ID, using the combined inspection ID and user ID. In step S53, the comparison unit 68 searches for the third hash value in the inspection hash value list. In this case, the second hash value list is the inspection hash value list 113. In the inspection hash value list 113, let the number of data of the second hash value to be compared be Un, and let the number attached to an arbitrary second hash value be S. If the S-th second hash value is denoted as (second hash value)S, the comparison unit 68 compares (second hash value)S and the third hash value in order from S = 1 to S = Un. In step S54, the comparison unit 68 determines whether there is a second hash value that matches the third hash value calculated in step S53 in the inspection hash value list 113.
[0092] In step S54, when the comparison unit 68 determines that there is a second hash value that matches the third hash value in the inspection hash value list 113, the control unit 69 determines that the combination of the inspection ID and the user ID selected in step S51 is the correct combination (step S55). In step S56, the control unit 69 enters the user ID and the inspection ID of the correct combination into the correspondence table of the user ID and the inspection ID.
[0093] Referring to FIG. 22, the processing up to steps S51 to S56 will be described. Here, consider the case where the user ID is "20071011". The hash value calculation unit 67 reads one inspection ID from the inspection correspondence table 115, and calculates a third hash value using a predetermined hash function for the combination of the user ID "20071011" and the read inspection ID. This hash function is represented by H[ ]. For example, the hash value calculation unit 67 calculates a third hash value "4f1···de1" for the combination of the user ID "20071011" and the first inspection ID "ER29151200". The comparison unit 68 compares the third hash value "4f1···de1" one by one with the Un inspection hash values described in the inspection hash value list 113, and determines whether there is an inspection hash value that matches the third hash value.
[0094] As a result of the determination, if there is no inspection hash value that matches the third hash value "4f1···de1", the hash value calculation unit 67 calculates a third hash value for the combination of the user ID "20071011" and another inspection ID. The comparison unit 68 compares the second third hash value one by one with the Un inspection hash values described in the inspection hash value list 113, and determines whether there is an inspection hash value that matches the third hash value. As a result of the determination, if there is no inspection hash value that matches the third hash value, the hash value calculation unit 67 and the comparison unit 68 repeat the above-described processing.
[0095] Let m (for example, 2 ≦ m ≦ Un) be an arbitrary integer. Then, the hash value calculation unit 67 calculates a third hash value "23c···9b2" for the combination of the user ID "20071011" and the m-th inspection ID "ER20522010". The comparison unit 68 compares the first third hash value "23c···9b2" one by one with the Un inspection hash values described in the inspection hash value list 113, and determines whether there is an inspection hash value that matches the third hash value. When the comparison unit 68 determines that the third hash value matches the j-th inspection hash value "23c···9b2" of S, the control unit 69 determines that the user ID "20071011" and the inspection ID "ER20522010" are the correct combination. The control unit 69 enters the inspection ID "ER20522010" in the correspondence table 121 of the user ID and the inspection ID in association with the user ID "20071011" (step S56 in FIG. 21).
[0096] Return to the description of the flow shown in FIG. 21. In step S57, the control unit 69 combines the genomic hash value associated with the user ID and the inspection result associated with the inspection ID. In step S58, the control unit 69 specifies the genomic information from the genomic hash value. For example, in step S58, the control unit 69 executes the following processing. The storage unit 18 stores a genomic correspondence table 112 in which a genomic hash value calculated based on the user ID and the genomic information is associated. The control unit 69 reads arbitrary genomic information from the plurality of genomic information stored in the storage unit 22, and calculates a genomic hash value that is the hash value of the read genomic information. When the control unit 69 specifies the same genomic hash value as the calculated genomic hash value in the genomic correspondence table 112, it determines that the combination of the genomic information of the calculation source and the user ID of the genomic hash value specified in the genomic correspondence table 112 is correct. In this way, by calculating the hash value of arbitrary genomic information by the control unit 69, the genomic information associated with the genomic hash value registered in the genomic correspondence table 112 can be specified. In step S59, the control unit 69 combines the genomic information and the inspection result. The control unit 69 generates correspondence relation information of one user based on the information of these combinations.
[0097] Assuming the number of users is Nsum, the information processing apparatus 1 repeats the procedure shown in FIG. 21 (Nsum - 1) times as described above, and a correspondence table 121 of the user ID and the inspection ID is created for all users. In addition, in the genome correspondence table 112 shown in FIG. 13, a user ID and a genome hash value are associated with each other. In the inspection correspondence table 115, an inspection ID and an inspection result are associated with each other. Therefore, when the number of users is Nsum, the information processing apparatus 1 can specify the correspondence between the genome information and the inspection result for each of the Nsum users by repeating the procedure shown in FIG. 21 (Nsum - 1) times. Each time the correspondence between the genome information and the inspection result of one user is specified, the value of Un in step S53 becomes smaller. Therefore, as the number of specified correspondences increases, the arithmetic processing in steps S54 to S58 by the information processing apparatus 1 is reduced.
[0098] Referring to FIG. 21, the management unit 51 has been described as specifying the correspondence between the user ID and the inspection ID for each user and obtaining the combination of the genome information and the inspection result. Similarly, the correspondence between the user ID and the questionnaire ID can be specified, and the combination of the genome information and the questionnaire result can be obtained.
[0099] FIG. 23 is a diagram for explaining a method of constructing an ID correspondence table. Assuming that the number of users is Nsum, the management unit 51 repeats the procedure shown in FIG. 21 (Nsum - 1) times for the inspection ID, and the control unit 69 creates a correspondence table 121 of the user ID and the inspection ID. The management unit 51 repeats the procedure shown in FIG. 21 (Nsum - 1) times for the questionnaire ID, and the control unit 69 creates a correspondence table 122 of the user ID and the questionnaire ID. The control unit 69 constructs the ID correspondence table 123 shown in FIG. 23 in combination with the genome correspondence table 112 shown in FIG. 13, the correspondence table 121 of the user ID and the inspection ID, and the correspondence table 122 of the user ID and the questionnaire ID (step S42 in FIG. 19).
[0100] In step S42 shown in FIG. 19, an ID correspondence table 123 shown in FIG. 23 is constructed, and the correspondence relationships among the genomic information, test results, and questionnaire results of all users are specified. In step S43, when the output condition is that "diabetes" is included in the test results, in step S44, the specifying unit 35 can specify users whose test results include "diabetes" and their genomic information using "diabetes" as the search condition.
[0101] Note that, with reference to FIG. 19, the case of the procedure where the information processing apparatus 1 constructs an ID correspondence table (step S42) and then extracts information that matches the output request (steps S43 to S44) has been described, but it is not limited to this procedure. For example, the procedures of the process in step S42 and the process in step S43 shown in FIG. 19 may be reversed. That is, the specifying unit 35 may obtain a search condition from the output request, and the management unit 51 may construct an ID correspondence table for obtaining information that matches the search condition obtained by the specifying unit 35. In this case, since it is not necessary to construct an ID correspondence table for all users, the information processing apparatus 1 can obtain the effect of reducing the load of arithmetic processing for searching for information corresponding to the output request.
[0102] A specific example will be described where the procedures of the process in step S42 and the process in step S43 shown in FIG. 19 are reversed. Assume that the output condition included in the output request is "systolic blood pressure is 140 mmHg or higher", and the "systolic blood pressure value" is entered in the test results of each user stored in the storage unit 18. When the specifying unit 35 receives the information on the output condition from the output request acquisition unit 34, it specifies the test results that match the search condition "systolic blood pressure is 140 mmHg or higher" among the test results of each user stored in the storage unit 18. The specifying unit 35 refers to the test correspondence table 115 and specifies the test ID of the specified test result. Subsequently, the management unit 51 creates the correspondence table 121 of the user ID and the test ID according to the procedure described with reference to FIG. 22 for the test ID specified by the specifying unit 35. For example, consider a case where the number of registered users is 100, and among the 100 users, 10 users have "systolic blood pressure of 140 mmHg or higher". In this case, since the information processing apparatus 1 only needs to create the correspondence table 121 of the user ID and the test ID for the 10 users, there is no need to obtain the correspondence relationship between the user IDs and test IDs for 90 users. Note that the processes after step S44 shown in FIG. 19 are the same as the content described with reference to FIG. 19, and thus the detailed description thereof is omitted.
[0103] Another specific example will be described. A case where the output requirements include "systolic blood pressure is 140 mmHg or higher" and "age is between 30 and 40 years" as output conditions will be described. Assume that the "systolic blood pressure value" is entered in the test results of each user stored in the storage unit 18, and the "age" is entered in the questionnaire results of each user stored in the storage unit 18. When the specifying unit 35 receives the information on the output conditions from the output requirement acquisition unit 34, it specifies the test ID of the test results that match the search condition "systolic blood pressure is 140 mmHg or higher" in the same manner as the above-described specific example. The management unit 51 creates a correspondence table 121 of user IDs and test IDs in the same manner as the above-described specific example. Also, the specifying unit 35 specifies the questionnaire results that match the search condition "age is between 30 and 40 years" among the questionnaire results of each user stored in the storage unit 18. The specifying unit 35 refers to the questionnaire correspondence table 116 and specifies the questionnaire ID of the specified questionnaire results. Subsequently, the management unit 51 creates a correspondence table 122 of user IDs and questionnaire IDs in the same procedure as described with reference to FIG. 22 for the questionnaire IDs specified by the specifying unit 35. Further, the management unit 51 extracts the user IDs belonging to the intersection of the correspondence table 121 of user IDs and test IDs and the correspondence table 122 of user IDs and questionnaire IDs. Then, the management unit 51 creates an ID correspondence table 123 shown in FIG. 23 for the extracted user IDs. For example, consider a case where the number of registered users is 100, and among the 100 users, 10 users have "systolic blood pressure of 140 mmHg or higher" and 10 users have "age between 30 and 40 years". In this case, the information processing apparatus 1 only needs to create a correspondence table 121 of user IDs and test IDs for 10 users and create a correspondence table 122 of user IDs and questionnaire IDs for 10 users, so there is no need to obtain the correspondence relationship between user IDs, test IDs, and questionnaire IDs for 80 users. Note that the processing after step S44 shown in FIG. 19 is the same as the content described with reference to FIG. 19, so the detailed description thereof is omitted.
[0104] (Registration Process of Output-Related Information) An example of a method for registering output-related information in a blockchain will be described. FIG. 24 is a schematic diagram for explaining an example of a method for registering output-related information in a blockchain.
[0105] When the output unit 36 records the output-related information for a predetermined period or number of cases in the storage unit 18, it summarizes them in one table. The unit of this table is referred to as an output information block. The output information block 1 shown in FIG. 24 is a table in which the output-related information for a predetermined period or a predetermined number of cases has been recorded since the genome information trust system of this embodiment was started.
[0106] The output unit 36 calculates the hash value h1 of the output information block 1 and adds it to the header of the next output information block 2. Subsequently, the output unit 36 calculates the hash value h2 of the output information block 2 including the hash value h1 and adds it to the header of the next output information block 3. In this way, the output unit 36 sequentially adds the hash value of the previous output information block to the header of the next output information block.
[0107] In this way, the information processing device 1 functions as a node of a distributed ledger (Hyper ledger)-type blockchain network with respect to the output-related information. By registering the output-related information in the blockchain, all users can monitor the history of payment of consideration, and it is possible to prevent the output-related information from being tampered with.
[0108] (Specific example of the processing in steps S11 to S16) A specific example of a method for acquiring genome information and user information from a user will be described. FIG. 25 is a diagram for explaining an example of a method by which the information processing device 1 acquires genome information and user information from a user. FIG. 25 shows an example of an image displayed on the display unit 2a of the user terminal 2. A touch panel (not shown) for the user to perform an input operation is provided on the display unit 2a of the user terminal 2.
[0109] The storage unit 18 stores in advance the data of the questionnaire web page including the information of the questionnaire provided with a plurality of items for the user to fill in. The output unit 36 transmits a direct mail including a message prompting registration with the Genome Information Trust Organization 200 to the user terminal 2. When the user terminal 2 receives the mail from the information processing apparatus 1, it displays the message of the mail on the display unit 2a as the image img1 in FIG. 25. In the image img1 in FIG. 25, an inquiry message "Don't you want to use your genome information for new product development etc.?" is displayed as an example of the message. When the user operates the user terminal 2 to select a "Consent" button in response to the inquiry message displayed in the image img1, the user terminal 2 transmits a consent signal, which is a signal indicating consent, to the information processing apparatus 1.
[0110] When the information acquisition unit 31 receives the consent signal from the user terminal 2, the identification information assigning unit 32 generates a user ID, a questionnaire ID, and an inspection ID. The output unit 36 transmits the questionnaire ID and inspection ID generated by the identification information assigning unit 32 and the data of the questionnaire web page to the user terminal 2. When the user terminal 2 receives the questionnaire ID, the inspection ID, and the data of the questionnaire web page from the information processing apparatus 1, it displays the questionnaire web page on the display unit 2a. The image img2 in FIG. 25 is an image showing a part of an example of the questionnaire displayed by the display unit 2a of the user terminal 2. After the user operates the user terminal 2 to fill in information for each item of the questionnaire and then presses the send button, the user terminal 2 transmits the questionnaire result information with the questionnaire ID attached to the questionnaire result to the information processing apparatus 1.
[0111] When the information acquisition unit 31 receives the questionnaire result information from the user terminal 2, it stores the questionnaire result in the storage unit 18 in association with the questionnaire ID. When the information acquisition unit 31 receives the questionnaire result information from the user terminal 2, the output unit 36 transmits the data of the web page for registering the genome information, the inspection result, and the contract information to the user terminal 2.
[0112] When the user terminal 2 receives the data of the web page received from the information processing apparatus 1, it displays the received web page on the display unit 2a. The image img3 in FIG. 25 is an example of an image for registering genomic information, test results, and contract information. When the user operates the user terminal 2 to register genomic information, test results, and contract information in order, the user terminal 2 transmits this information to the information processing apparatus 1. The user terminal 2 transmits test result information with a test ID attached to the test results to the information processing apparatus 1.
[0113] In this way, the information processing apparatus 1 may acquire user information in accordance with the timing of acquiring genomic information. Further, the information processing apparatus 1 may acquire user information from the user terminal 2 at a plurality of timings. For example, the information processing apparatus 1 may acquire from the user terminal 2 the latest results of a test whose test results and test contents acquired in the past are the same, and may acquire from the user terminal 2 the latest results of a questionnaire whose questionnaire results and contents acquired in the past are the same. When the information processing apparatus 1 acquires the latest results of a test whose test results and test contents acquired in the past are the same, it may store the latest test results and delete the past test results, or may add the latest test results to the past test results. When the information processing apparatus 1 acquires the latest results of a questionnaire whose questionnaire results and contents acquired in the past are the same, it may store the latest questionnaire results and delete the past questionnaire results, or may add the latest questionnaire results to the past questionnaire results.
[0114] Further, the information processing apparatus 1 may acquire, for example, the results of a test whose test results and test contents are different from those acquired in the past from the user terminal 2, and may acquire the results of a questionnaire whose questionnaire results and contents are different from those acquired in the past from the user terminal 2. When the information processing apparatus 1 newly acquires the results of a test whose test results and test contents are different from those acquired in the past, it may add the newly acquired test results to the test results acquired in the past. When the information processing apparatus 1 newly acquires the results of a questionnaire whose questionnaire results and contents are different from those acquired in the past, it may add the newly acquired questionnaire results to the questionnaire results acquired in the past.
[0115] (Specific examples of the processes in steps S42 to S46) A specific example of the case where the output unit 36 deletes information not related to the output request from the user information will be described. For example, consider the case where in step S42 shown in FIG. 19, the output request acquisition unit 34 acquires an output request that includes information of "diabetic patients aged 20 to 39 years" as an output condition and where "blood test and diet content" is selected as a related condition. The specifying unit 35 specifies user information that matches the output condition, and specifies it from among the plurality of genomic information stored in the storage unit 22 that stores the genomic information of the specified user. Among the user information specified by the specifying unit 35, the output unit 36 has information other than "blood test and diet content" not selected as a related condition. Therefore, the output unit 36 deletes information not selected as a related condition from the user information. The output unit 36 outputs the genomic information of "diabetic patients aged 20 to 39 years" and the user information including the information of "blood test and diet content".
[0116] (Consideration payment process) Next, the procedure of the consideration payment process to the user by the information processing apparatus 1 will be described. FIG. 26 is a flowchart showing an example of the consideration payment process to the user.
[0117] In step S61, the consideration calculation unit 37 determines whether there is a consideration claim from the user terminal 2. If there is a consideration claim, the process proceeds to the process of step S63. If there is no consideration claim, the consideration calculation unit 37 proceeds to the process of step S62. In step S62, the consideration calculation unit 37 determines whether the consideration calculation time has been reached. If the consideration calculation time has not been reached, the consideration calculation unit 37 returns to the process of step S61. If the consideration calculation time has been reached, the consideration calculation unit 37 proceeds to the process of step S63. In step S63, the consideration calculation unit 37 acquires the consideration calculation conditions from the storage unit 18.
[0118] In step S64, the consideration calculation unit 37 calculates the consideration for the user who provided the genomic information and the user information based on the output-related information and the calculation conditions. The consideration calculation unit 37 may identify the user based on the terminal ID of the user terminal 2. Further, when the user terminal 2 makes a consideration claim to the information processing apparatus 1, the inspection ID or the questionnaire ID may be included in the consideration claim. For example, the consideration calculation unit 37 can receive the information of the user ID associated with the inspection ID from the control unit 69 by transmitting the correspondence request information including the inspection ID to the combination unit 66. In step S65, the payment data generation unit 38 generates payment data that designates the user's bank account or the account of the fund transfer operator as the transfer destination of the calculated consideration based on the calculated consideration. For example, the payment data generation unit 38 refers to the user information of the specified user ID. In step S66, the payment data output unit 39 outputs the payment data generated by the payment data generation unit 38 to the financial processing terminal 4. In step S67, the payment data output unit 39 records that the consideration has been paid in the output-related information.
[0119] Note that in this embodiment, the case where the financial processing terminal 4 is provided for the payment process of the consideration to the user has been described with reference to FIG. 9, but the financial processing terminal 4 may not be provided. For example, the payment data output unit 39 may transmit the information of the digital currency corresponding to the consideration to be paid to the user to the user terminal 2.
[0120] Also, in this embodiment, the case where the first information is genomic information and the second information is one or both of the inspection result and the questionnaire result has been described, but it is not limited to this case. The first information may be one or both of the inspection result and the questionnaire result, and the second information may be genomic information. In this case, the first identification information is one or both of the inspection ID and the questionnaire ID, and the second identification information is the genomic hash value.
[0121] <Advantageous Effects of this Embodiment> According to the above-described embodiment, for the first information and the second information to be managed, the hash value of the first information is associated with the first identification information, the second information is associated with the second identification information, and the second hash value obtained by combining the second identification information and the first identification information is stored in a list. When the third hash value obtained by combining any first identification information and any second identification information matches the second hash value in the list, the first identification information and the second identification information are determined to be the correct combination, and the first information and the second information are associated. There is no one-to-one correspondence table for linking multiple types of information to be managed, and there is no risk of leakage of the correspondence table when managing multiple types of information with one correspondence table. As a result, strong security measures can be taken for the information to be managed.
[0122] Regarding the above-described embodiment, the effect when the first information is genomic information and the second information is user information will be described. According to the above-described embodiment, by dividing and managing multiple types of information related to a user so that personal information such as the user's genomic information cannot be specified, there is no one-to-one correspondence table for linking the divided information. Therefore, there is no risk of leakage of the correspondence table when managing multiple pieces of information related to a user with one correspondence table. As a result, strong security measures can be taken for the user's personal information.
[0123] Regarding the effect of the information management method according to the above-described embodiment, it will be described by comparing the ID correspondence table 123 shown in FIG. 23 with the correspondence table shown in FIG. 13. In the ID correspondence table 123 shown in FIG. 23, for each user, a genomic hash value, a questionnaire ID, and an inspection ID are described in association with the user ID. Referring to the ID correspondence table 123 shown in FIG. 23, multiple types of information can be easily linked for each user. On the other hand, when an external person refers to the ID correspondence table 123 shown in FIG. 23 by improper means, the genomic information, questionnaire results, and inspection results can be easily linked for each user. If the storage unit 18 maintains the state of storing the ID correspondence table 123 shown in FIG. 23, the risk of leakage of the ID correspondence table 123 to the outside increases. In contrast, in the above-described embodiment, as shown in FIG. 13, the genomic information, test results, and questionnaire results are managed in separate correspondence tables. Therefore, even if an external person can refer to the correspondence table shown in FIG. 13 by improper means, the genomic information cannot be linked to the test results or questionnaire results for each user. As a result, as described above, strong security measures can be taken regarding the personal information of the user.
[0124] Further, according to the above-described embodiment, by managing genomic information with a large amount of data using a hash value, the processing of information management becomes easy. Also, by not storing genomic information in the storage unit 18 that stores information for information management, stronger information security measures can be taken.
[0125] According to the above-described embodiment, a user who provides genomic information can obtain a consideration for information provision each time his or her genomic information and user information related to an output request are output. Therefore, the number of users who try to effectively utilize their own genomic information to obtain a consideration increases, and it becomes possible to collect genomic information from many users. Also, since not all the information provided by the user is output, but only the information related to the output request is output, the more information related to the output request a user has, the more opportunities the user has to obtain a consideration.
[0126] Further, according to the above-described embodiment, the genomic information trust institution 200 can grasp the usage status of genomic information by an external institution 210 using a blockchain, and thus can explain the clear payment status of rewards according to the requests of the users.
[0127] As described above, one embodiment of the present invention has been described. However, the present invention is not limited to the above-described embodiment, and modifications, improvements, etc. within the scope that can achieve the object of the present invention are included in the present invention.
[0128] In the above-described embodiments, for example, the above-described series of processes can be executed by hardware or by software. In other words, the above-described functional configurations are merely illustrative and are not particularly limited. That is, it is sufficient that the information processing system is provided with a function capable of executing the above-described series of processes as a whole, and the functional blocks used to realize this function are not particularly limited to the above examples. Also, the location of the functional blocks is not particularly limited to FIG. 9 and may be arbitrary. For example, the functional blocks of the server may be transferred to other devices (terminals) or the like. Conversely, the functional blocks of other devices may be transferred to the server or the like. Also, one functional block may be configured by hardware alone, by software alone, or by a combination thereof.
[0129] When the series of processes are executed by software, the program constituting the software is installed in a computer or the like from a network or a recording medium. The computer may be a computer incorporated in dedicated hardware. Also, the computer may be a computer capable of executing various functions by installing various programs, for example, a general-purpose smartphone or personal computer in addition to a server.
[0130] A recording medium containing such a program is not only constituted by a removable medium (not shown) distributed separately from the apparatus main body for providing the program to a user or the like, but also by a recording medium or the like provided to a user or the like in a state pre-installed in the apparatus main body. Note that the recording medium may be mounted on or accessible from a server or the like.
[0131] Note that in this specification, the steps of describing a program recorded on a recording medium include not only processes performed in time series according to the order thereof, but also processes that are not necessarily processed in time series and are executed in parallel or individually. Also, in this specification, the term "system" shall mean an overall apparatus composed of a plurality of devices, a plurality of means, or the like.
[0132] [Others] In other words, the information processing apparatus to which the present invention is applied can take various embodiments having the following configurations. That is, a first identification information acquisition means (for example, the first identification information acquisition unit 61) for acquiring first identification information, a second identification information generation means (for example, the second identification information acquisition unit 63) for generating second identification information in association with the first identification information, store the first identification information in association with a first hash value that is a hash value of the first information, and store the second identification information in association with the second information, and a storage means (for example, the storage unit 18) for storing a list of a second hash value that is a hash value of a combination of the second identification information and the first identification information, a combination means (for example, the combination unit 66) for generating a combination of any of the first identification information and any of the second identification information, a hash value calculation means (for example, the hash value calculation unit 67) for calculating a third hash value that is a hash value of a combination of the second identification information and the first identification information combined by the combination means, a comparison means (for example, the comparison unit 68) for comparing the third hash value calculated by the hash value calculation means with the second hash value in the list stored in the storage means, a control means (for example, the control unit 69) for associating the first information and the second information based on the comparison result of the comparison means, and an information processing apparatus having the above.
[0133] Also, a first identification information acquisition means (for example, the first identification information acquisition unit 61) for acquiring first identification information for identifying genomic information, a first hash value acquisition means (for example, the first hash value acquisition unit 70) for acquiring a first hash value that is a hash value of the genomic information identified by the first identification information, Storage means (e.g., storage unit 18) for associating and storing the obtained first hash value and the first identification information. The genomic information is not stored in the storage means that stores the first hash value and the first identification information. It is an information processing device. The first hash value corresponding to the genomic information and the first identification information for identifying the genomic information are associated and stored. However, the genomic information is stored in a storage means different from the storage means for associating and storing these pieces of information. Since the genomic information is not stored in the storage means for storing the information associating the genomic information and the first identification information, even if the information associating the genomic information and the first identification information is read out by improper means, it is difficult to read out the genomic information stored in another storage means. Therefore, strong security measures can be taken regarding personal information.
[0134] Further, when the second hash value and the third hash value match, the control means may specify the combination of the first hash value and the second information based on the first identification information and the second identification information combined by the combining means. When the third hash value matches the second hash value in the list of second hash values, the first identification information and the second identification information that are the calculation sources of the third hash value are determined to be the correct combination. Since the first identification information and the first hash value are associated and stored, the correct combination of the first hash value and the second information is specified. In this way, the correct combination of the first hash value and the second information can be specified from any combination of the first identification information and the second identification information.
[0135] Further, the control means may specify the first information based on the first hash value. Since the first hash value calculated based on the first identification information and the first information is stored in an associated manner, by calculating the hash value of any first information, if the calculated hash value matches the first hash value in the list of first hash values, the first information and the first hash value are determined to be a correct combination. By calculating the hash value of any first information, the first information associated with the first hash value can be specified.
[0136] Further, the first information may be stored in a storage means different from the storage means that stores the second information. Since the first information is stored in a storage means different from the storage means in which the second information is stored, it is possible to reduce the possibility that the first information and the second information are combined and read out by improper means.
[0137] Further, the first identification information may be identification information for identifying a user. Since the identification information for identifying a user and the first hash value which is the hash value of the first information are stored in an associated manner, when constructing the correspondence relationship between the user and the first information, the user and the first information can be easily associated.
[0138] Further, the first information is the genomic information of the user, the second information may be at least one of the test result regarding the health state of the user and the questionnaire result regarding the user. Since the genomic information of the user and at least one information of the test result and the questionnaire result of the user are the management targets, personal information for effectively utilizing the genomic information can be managed collectively with a strong security measure.
[0139] Further, it further has second information acquisition means (for example, second information acquisition unit 64) for acquiring the second information, the second information is at least one of the test result regarding the health state of the user of the genomic information and the questionnaire result regarding the user, The second information may not be stored in the storage means for storing the genomic information. At least one of the user's test result and questionnaire result is stored in a storage means different from the storage means for storing the genomic information. Therefore, it is possible to suppress a situation where a plurality of types of personal information of the user are collectively read out by unauthorized means.
[0140] Also, an identification information generation step of generating second identification information in association with the first identification information, a first information storage step of storing the first identification information in association with a first hash value that is a hash value of the first information, a second information storage step of storing the second identification information in association with the second information, a list generation step of storing, in a list, a second hash value that is a hash value of a combination of the second identification information and the first identification information, a combination step of generating a combination of any of the first identification information and any of the second identification information, a hash value calculation step of calculating a third hash value that is a hash value of a combination of the combined second identification information and the first identification information, a comparison step of comparing the calculated third hash value with the second hash value in the stored list, a control step of associating the first information and the second information based on the comparison result of the comparison step, may be an information processing method having the above steps.
[0141] Also, an identification information generation step of generating second identification information in association with the first identification information, a first information storage step of storing the first identification information in association with a first hash value that is a hash value of the first information, a second information storage step of storing the second identification information in association with the second information, a list generation step of storing, in a list, a second hash value that is a hash value of a combination of the second identification information and the first identification information, A combination step of generating a combination of any of the first identification information and any of the second identification information; A hash value calculation step of calculating a third hash value which is a hash value of a combination of the combined second identification information and the first identification information; A comparison step of comparing the calculated third hash value with the second hash value of the stored list; A control step of associating the first information and the second information based on the comparison result of the comparison step; It may be a computer program for causing a computer to execute.
Explanation of Signs
[0142] 1: Information processing apparatus 2: User terminal 3-k: External institution terminal 11: CPU 18: Storage unit 19: Communication unit 22: Storage unit 31: Information acquisition unit 32: Identification information imparting unit 33: Selection unit 34: Output request acquisition unit 35: Identification unit 36: Output unit 37: Consideration calculation unit 38: Payment data generation unit 39: Payment data output unit 40: Deletion request acquisition unit 41: Judgment unit 42: Deletion unit 51: Management unit
Claims
1. A first identification information acquisition means for acquiring first identification information; A second identification information generation means for generating second identification information in association with the first identification information; The first identification information is stored in association with a first hash value that is a hash value of first information, and The second identification information is stored in association with second information, and A storage means for storing, in a list, a second hash value that is a hash value of a combination of the second identification information and the first identification information; A combination means for generating a combination of any of the first identification information and any of the second identification information; A hash value calculation means for calculating a third hash value that is a hash value of a combination of the second identification information and the first identification information combined by the combination means; A comparison means for comparing the third hash value calculated by the hash value calculation means with the second hash value in the list stored in the storage means; A control means for associating the first information and the second information based on the comparison result of the comparison means; An information processing apparatus having the above.
2. A first identification information acquisition means for acquiring first identification information for identifying genomic information; A first hash value acquisition means for acquiring a first hash value that is a hash value of the genomic information identified by the first identification information; A storage means for storing the acquired first hash value and the first identification information in association with each other, wherein the genomic information is not stored in the storage means for storing the first hash value and the first identification information, An information processing apparatus.
3. When the second hash value and the third hash value match, the control means specifies a combination of the first hash value and the second information based on the first identification information and the second identification information combined by the combination means. The information processing apparatus according to Claim 1.
4. The control means specifies the first information based on the first hash value. The information processing apparatus according to Claim 1.
5. The first information is stored in a storage means different from the storage means for storing the second information. The information processing apparatus according to Claim 1.
6. The first identification information is identification information for identifying a user. The information processing apparatus according to Claim 1.
7. The first information is the genomic information of the user. The second information is at least one of an inspection result regarding the health condition of the user and a questionnaire result regarding the user. The information processing apparatus according to claim 1.
8. further comprising second information acquisition means for acquiring second information; The second information is at least one of an inspection result regarding the health condition of the user of the genomic information and a questionnaire result regarding the user. The second information is not stored in the storage means for storing the genomic information. The information processing apparatus according to claim 2.
9. an identification information generation step of generating second identification information in association with the first identification information; a first information storage step of storing the first identification information in association with a first hash value that is a hash value of the first information; a second information storage step of storing the second identification information in association with the second information; a list generation step of storing, as a list, a second hash value that is a hash value of a combination of the second identification information and the first identification information; a combination step of generating a combination of any of the first identification information and any of the second identification information; a hash value calculation step of calculating a third hash value that is a hash value of a combination of the combined second identification information and the first identification information; a comparison step of comparing the calculated third hash value with the second hash value of the stored list; a control step of associating the first information and the second information based on the comparison result of the comparison step; An information processing method having the above.
10. an identification information generation step of generating second identification information in association with the first identification information; a first information storage step of storing the first identification information in association with a first hash value that is a hash value of the first information; a second information storage step of storing the second identification information in association with the second information; a list generation step of storing, as a list, a second hash value that is a hash value of a combination of the second identification information and the first identification information; a combination step of generating a combination of any of the first identification information and any of the second identification information; a hash value calculation step of calculating a third hash value that is a hash value of a combination of the combined second identification information and the first identification information; a comparison step of comparing the calculated third hash value with the second hash value of the stored list; A control step of associating the first information and the second information based on the comparison result of the comparison step; A computer program for causing a computer to execute.
Citation Information
Patent Citations
Integrated database system of genome information and clinical information, and method for making database provided therewith
JP2009070096A