Service providing system
Patent Information
- Application Number
- JP2025069227
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2019-01-06
- Filing Date
- 2025-04-21
- Publication Date
- 2025-07-30
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The conflict between the guarantee of authenticity of recorded information and the right to delete the information, particularly in blockchain systems, results in the impossibility of erasing personal information once it is recorded, impairing the right to be forgotten.
A processing system that includes encryption, decryption, and decryption-disabling mechanisms, allowing for the encryption of information, decryption using a first and second key, and the ability to put information into a decryption-disabled state by updating the second key, along with a search mechanism for encrypted information without decryption.
Resolves the dilemma of conflicting guarantees by enabling the erasure of recorded information while maintaining its authenticity, thus addressing the right to be forgotten.
Smart Images

Figure 2025111581000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a processing system and a program for an information recording method such as blockchain that is difficult to tamper with or erase. relates to.
Background Art
[0002] Blockchain has been generally known as an information recording method that is difficult to tamper with. For example, Patent Document 1 records various information related to cargo transportation using this blockchain.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, recording information using such a blockchain is not only difficult to tamper with but also difficult to erase (hereinafter referred to as "impossibility of erasure"). As a result, once personal information is recorded using blockchain, even if the personal information owner wants to erase the personal information, it cannot be erased, and the right to erase personal information (so-called right to be forgotten) is impaired.
[0005] That is, there is a drawback that an antinomy occurs in which the guarantee of the authenticity of the recorded information and the guarantee of the right to delete the information are in conflict with each other.
[0006] The present invention has been conceived in view of such circumstances, and its object is to resolve the antinomy in which the guarantee of the authenticity of the recorded information and the guarantee of the right to delete the information are in conflict with each other.
Means for Solving the Problems
[0007] The present invention includes an encryption means for performing an encryption process to encrypt information to be recorded, a recording means for recording the information after the encryption process, a decryption means for performing a decryption process on the information recorded by the recording means using a first key and a second key to obtain plaintext information, and a decryption-disabling means for putting the information recorded by the recording means into a decryption-disabled state where it cannot be decrypted. The decryption means includes a second key concealment and retention means for concealing and retaining the second key. The decryption-disabling means puts the information into a decryption-disabled state by updating the second key retained by the second key concealment and retention means with another key.
[0008] Preferably, the decryption means further includes a first key distribution means for distributing the first key to those who wish to view the information. Preferably, the apparatus further includes a search means for searching the information recorded by the recording means without converting it into plaintext.
[0009] More preferably, the information recorded by the recording means includes personal information, and the decryption-disabling means puts the personal information of the personal information owner into the decryption-disabled state in response to a request from the personal information owner.
[0010] Another aspect of the present invention includes a step of performing an encryption process to encrypt information to be recorded, a decryption step of performing a decryption process on the information recorded by a recording means that records the information after the encryption process using a first key and a second key to obtain plaintext information, and a step of putting the information recorded by the recording means into a decryption-disabled state where it cannot be decrypted, which is executed by a computer, wherein the decryption step includes a step of concealing and retaining the second key, and the step of putting the information into a decryption-disabled state includes putting the information into a decryption-disabled state by updating the second key retained in the retaining step with another key.
Advantages of the Invention
[0011] According to the present invention, it is possible to resolve as much as possible the dilemma in which the guarantee of the authenticity of the recorded information and the guarantee of the right to delete the information are in conflict with each other.
Brief Description of the Drawings
[0012]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Figure 19
Figure 20
Figure 21
Figure 22
Figure 23
Figure 24
Figure 25
Figure 26
Figure 27
Figure 28
Figure 29
Figure 30
Figure 31
Figure 32
Figure 33
Figure 34
Figure 35
Figure 36
Figure 37
Figure 38
Figure 39
Figure 40
Figure 41
Figure 42
Figure 43
Figure 44
Figure 45
Figure 46
Figure 47
Figure 48
Figure 49
Figure 50
Figure 51
Figure 52
Figure 53
Figure 54
Figure 55
Figure 56
Figure 57
Figure 58
Figure 59
Figure 60
Best Mode for Carrying Out the Invention
[0013] [First Embodiment] The first embodiment of the present invention will be described with reference to FIGS. 1 to 13. First, referring to the overall system in FIG. 1, three types of blockchain networks, namely, private chain 2, consortium chain 3, and public chain 4, are connected to a centralized oracle 21. The public chain 4 has a completely open structure, and anyone, whether an individual or a group, can conduct transactions there. Transactions can be effectively confirmed on that blockchain. Mining (competition for the right to record) is also free and anyone can participate. The consortium chain 3 is a blockchain that can only be used by partners belonging to an association or a union. The people (each node) therein are designated as recorders. The generation of blocks is also determined in advance, and other people (nodes) can conduct transactions but do not have the right to record. The private chain 2 only records accounts using blockchain technology. The right to record is not open but is monopolized by an individual or a company, and only internal transactions are recorded. To connect blockchains to each other and exchange tokens and data between each blockchain, Polkadot is used. Polkadot is a blockchain for connecting different blockchains. A blockchain developed using Substrate can be connected to Polkadot, and by connecting to Polkadot, it becomes possible to exchange tokens and data with other blockchains connected to Polkadot.
[0014] The centralized oracle 21 is a system that bridges data between the blockchain and the Internet 1. It is connected to the Internet 1 to collect various information scattered on the network and provide information to the smart contracts of the blockchain.
[0015] Each node 19 of the private chain 2, the consortium chain 3, and the public chain 4 is composed of a user terminal such as a personal computer (hereinafter referred to as "PC") 16. This PC (hereinafter also referred to as "user terminal") 16 is connected to the Internet 1. Further connected to the Internet 1 are the server 20 of the SNS (Social Networking Service) 40 and the server 18 of the blockchain certification operator 17. Note that the server 18 of the certification operator 17 may participate in the blockchain as a node 19. Also, a server of a certification authority that issues an electronic certificate in PKI (Public Key Infrastructure) may be connected to the Internet 1.
[0016] The certification operator 17 stores personal information, issues an electronic ID mainly for the individual concerned, and records the hash value of the personal information on the blockchain. The stored personal information is stored in a personal information database (hereinafter referred to as "personal information DB") 29. Note that the certification operator 17 may participate in the blockchain as a node 19.
[0017] The PC 16 is composed of a CPU (Central Processing Unit) 10 as a control center, a RAM (Random Access Memory) 9 that functions as a work area for the CPU 10, a ROM (Read Only Memory) 11 that stores data and programs, a storage unit such as an HDD (hard disk drive) 12, an input operation unit 7 such as a display and a keyboard, a communication unit 5, a display unit 6, an interface 8, a bus 13, and various other hardware. Each server such as the server 20 and the server 18 is also composed of the same hardware as the PC 16, and the illustration and description thereof are omitted here for the sake of brevity. Note that as the storage unit, in addition to or instead of the above HDD, an SDD (Solid State Drive) may be used.
[0018] Node 19 of the consortium chain 3 is connected to the IoT (Internet of Things) device 14 and the wireless sensor network 15. Sensor signals from the IoT device 14 and the wireless sensor network 15 are input into node 19, and a drive signal for the IoT device 14 is output from node 19. The IoT device 14 is various sensors, actuators, etc. for IoT.
[0019] The wireless sensor network 15 is a wireless network that scatters a plurality of wireless terminals with sensors in space and enables them to cooperate to collect the environment and physical conditions. For example, make sensor devices with energy harvesting, M2M, or batteries, etc., and constantly monitor, for example, deterioration such as metal fatigue with pressure sensors or strain gauges, and notify when there is a change. It is mainly installed in buildings such as bridges and tunnels. Generally, it includes a plurality of sensor nodes and gateway sensor nodes. These nodes are usually composed of one or more sensors, wireless chips, microprocessors, and power sources (such as batteries). The wireless sensor network usually has an ad hoc function and a routing algorithm for sending data from each node to the central node. That is, it has a function of autonomously reconstructing another communication path when there is an obstacle in communication between nodes. There is also an element of distributed processing for nodes to cooperate as a group. In addition, it has a function of operating for a long time without receiving external power supply, and for this purpose, it has a power-saving function or a self-power generation function.
[0020] In this embodiment, the IoT device 14 and the wireless sensor network 15 are connected to the consortium chain 3 via node 19, but one or both of the IoT device 14 and the wireless sensor network 15 themselves may be part of node 19 of the consortium chain 3 without going through node 19.
[0021] Next, referring to FIG. 2(A), the information stored in the HDD 12 of the PC 16 will be described. The HDD 12 stores a user's secret key SK, public key PK, common key K1, trapdoor common key K2, the user's address in the blockchain, smart contracts, tokens, artificial intelligence (also referred to as "AI (Artificial Intelligence)"), and blockchain data, etc. Note that the user is a broad concept that includes not only natural persons but also legal persons.
[0022] The secret key SK and the public key PK are a key pair used in PKI (Public Key Infrastructure), and the data encrypted with the public key PK is decrypted with the secret key SK. The secret key SK is also used for electronic signatures. The common key K1 is a key used for common key encryption such as DES (Data Encryption Standard) or AES (Advanced Encryption Standard). The data encrypted with the common key K1 is decrypted using the same common key K1. In this embodiment, different common keys are used for each piece of personal information to be encrypted. In the first embodiment, for the encrypted personal information E K1 (personal information), an index for keyword search is provided for the ciphertext. The index is encrypted with the common key K2. To perform a keyword search, a search is performed using an encrypted search query (referred to as a "trapdoor") obtained by encrypting the keyword (search query) used for the search with the common key K2. This common key K2 is stored in the HDD 12 as the trapdoor common key K2.
[0023] The user's address in the blockchain is generated through the following process. 1. Generate a public key from the secret key using ECDSA. 2. Pass the public key through the hash function SHA-256 to obtain a hash value. 3. Pass the hash value through the hash function RIPEMD-160 to obtain a hash value. 4. Add 00 as a prefix to the beginning of the hash value. 5. Pass it through the hash function SHA-256. 6 Pass it through the hash function SHA-256 again. 7 Add a 4-byte checksum at the very end. 8 Encode it in Base58 format.
[0024] A smart contract is a computer protocol intended for smooth verification, condition confirmation, execution, enforcement, and negotiation of contracts. A token is a unique currency issued on a blockchain by a company or an individual.
[0025] Next, explain the blockchain data. The data within each block of the blockchain includes the hash value of the previous block, the nonce, and data of multiple transactions (also referred to as transactions). Although not shown in the illustration, a timestamp is also embedded in the blockchain. Such a blockchain is generated by each node 19 performing blockchain processing (see S3, S19, S30, S51, S117, S122, S153, etc. described later) and is added as a new blockchain. The blockchain processing mainly consists of three phases: transaction, propagation, and recording.
[0026] The transaction phase is an act generally referred to as a transaction and means legal acts such as buying and selling, transfer, and lending (loan) acts. This transaction phase can be more specifically divided into three phases: generation → signature → propagation.
[0027] The generation phase is to generate a transaction. For example, Person A decides to "lend the idle PC resources (computing resources) to Person B for 39,005 seconds and obtain 25.78 tokens" and electronically signs the generation of the transaction. This electronic signature is generated by passing the transaction data through a predetermined hash function to obtain a hash value and encrypting the hash value using the private keys SK of the parties (Person A and Person B) to the transaction (transaction). Also, a digital public key certificate may be issued by a certification authority. Figure 2 shows an example of lending PC resources (computing resources), but the lending target is not limited to this. For example, values such as electricity generated by self-generation at home or in a company, the user's professional knowledge, experience, skills, network (including the human network on the Internet), and credit can be considered.
[0028] The propagation phase is to have other nodes confirm that the generation and signature of the transaction have been completed correctly. If it is determined that the generation and signature of the transaction have not been performed correctly, the transaction is discarded.
[0029] The recording phase is for the miner to perform mining and record the transaction when it is confirmed that the generation and signature of the transaction have been completed correctly. The transaction for which it is confirmed that the generation and signature have been completed correctly moves to a place called a mining pool. Then, the miner selects the transaction to be recorded from the mining pool and performs mining.
[0030] Mining is the work of calculating a nonce. A nonce is a value used to adjust so that a very small hash value with many 0s lined up at the beginning is generated when the data of the block is passed through a hash function. A new block is generated when a nonce can be calculated such that the hash value is below the target value.
[0031] Note that the transaction data is encrypted with the key K1 for the user's personal information as shown in Transaction I on the right side of Figure 2. K1The hash value of (personal information), its electronic ID, and the index of personal information and the consideration for the provision of personal information (provided with 2.4 tokens in Fig. 2) are encrypted with key K2 to obtain E K2 (Provided with index + 2.4 tokens) is also included. Specific examples of personal information include vital information such as the user's heart rate, blood pressure, body temperature, and electroencephalogram, behavioral history information such as purchase history and website browsing history, the user's location information such as GPS, race, creed, social status, medical history, electronic medical record data, ID (identification), and posting information on SNS, etc.
[0032] The posting information on SNS, etc. is the past posting information that has already been posted on SNS25 and stored in server 20, which is transferred from server 20 to personal information DB29 and the blockchain. Specifically, the user encrypts all of their own past posting information and stores it in the personal information DB29 of the certifying operator, and records its hash value on the blockchain. Thereafter, instead of posting on SNS25, the user encrypts the posting content and stores it in the personal information DB29 of the certifying operator, and records its hash value on the blockchain. As a result, the user can retrieve personal information from operators such as SNS and place it under their own management.
[0033] Regarding the consideration for the provision of personal information (provided with 2.4 tokens in Fig. 2), it may be recorded on the blockchain in plain text without encryption. In that case, other users can search the blockchain and know the consideration without obtaining the encryption key K2. Furthermore, trading conditions such as the consideration for the provision of personal information and the consideration for lending PC resources (computing resources) (obtaining 25.78 tokens by lending PC resources (computing resources) for 39005 seconds in Fig. 2) can be coded in the form of a smart contract, and the smart contract can be used to automate transactions (legal acts).
[0034] The encrypted personal information itself, which is the target of the hash value recorded as transaction I, is stored in the personal information DB29 of the certifying operator 17. Specifically, as shown in Fig. 2(B), the certifying operator 17 encrypts the personal information EK1 Encrypted personal information E is associated with the electronic ID issued for K1 (personal information), and the (personal information) is stored in the personal information DB29.
[0035] An index is an index for keyword searching of encrypted personal information E K1 (personal information). In the present embodiment, since a common key encryption method is adopted in which the index is encrypted with the common key K2, in order to perform a keyword search, a keyword (search query) used for the search is encrypted with the common key K2, and the encrypted search query (this is referred to as a "trapdoor") is used for the search. The common key K2 is a different key for each user, but the same key is used for the encrypted indexes of the same user. Therefore, by a smart contract described later, for example, if user A performs a transaction to distribute the common key K2 to user B, user B can K2 search all the encrypted indexes of user A on the blockchain using (the search query).
[0036] Note that a searchable encryption such as a homomorphic encryption or a fully homomorphic encryption that can search while keeping the ciphertext encrypted may be used. In that case, the personal information may be encrypted using the homomorphic encryption or the fully homomorphic encryption, and the encrypted personal information may be directly recorded on the blockchain. Also, the encrypted personal information E K1 (personal information) may be directly recorded on the blockchain.
[0037] Next, referring to FIG. 3(A), the flowchart of the main routine program of the user terminal of the public blockchain 19 will be described. By step S (hereinafter simply referred to as "S") 1, a personal information recording process is performed, by S2, a smart contract process is performed, and by S3, a blockchain process is performed.
[0038] Personal information recording process refers to the process in which the personal information owner encrypts personal information, registers it with the certification operator 17, and records the hash value of the encrypted personal information on the blockchain. Smart contract process refers to the process of automatically performing legal acts such as conclusion and execution of contracts according to pre-determined rules. The specific content of the blockchain process is as described above based on Figure 2(A).
[0039] The personal information recording process will be described with reference to Figure 3(B). At S5, it is determined whether there is a personal information registration operation in the user terminal that constitutes the node 19 of the public chain 19. If not, this personal information recording process returns and proceeds to the smart contract process of S2. If it is determined that there is a personal information registration operation, at S6, the personal information stored in the memory (such as HDD12) of the user terminal is encrypted with the key K1, electronically signed with the private key SK, and the index is encrypted with the key K2 and sent to the server 18 of the certification operator 17.
[0040] The server 18 of the certification operator 17 that receives it at S7 issues an electronic ID and generates the hash value of E K1 (personal information). Next, the issued electronic ID is returned to the user terminal (S9). The user terminal that receives it stores the electronic ID in the memory (such as HDD12). The server 18 of the certification operator 17 performs processing for recording the electronic ID, the hash value, and the encrypted index on the blockchain at S10.
[0041] Describe the flowchart of the subroutine program for the smart contract process shown in S2. Referring to FIG. 4, in S13, it is determined whether the distribution contract of the common key K2 is established. If not, in S15, it is determined whether the lending contract of the PC resources (computing resources) of the user terminal is established. If not, in S16, it is determined whether the personal information provision contract is established. If not, in S17, it is determined whether the order contract for ordering made-to-order goods or the like is established. If not, in S22, it is determined whether the sales contract of goods or the like is established. If not, return. These determinations are made by the smart contract. For example, when the consideration and the like described above are coded as a smart contract, the smart contract determines whether the conditions of the consideration and the like of both parties match. If it is determined that they match, the conclusion and execution of the contract are automatically performed.
[0042] When it is determined that the distribution contract of the common key K2 is established, the control proceeds to S14. After the common key K2 is transmitted to the distribution destination, the control proceeds to S19. In S19, processing for recording the established contract as a transaction on the blockchain is performed. When it is determined that the lending contract of the PC resources (computing resources) is established, the control proceeds to S18, and the lending process of the PC resources (computing resources) is performed. When it is determined that the personal information provision contract is established, the control proceeds to S20, and the electronic ID of the personal information to be provided and the signature agreeing to the provision of the personal information are returned to the recipient, and the common key K1 used for encrypting the personal information to be provided is encrypted with the public key of the recipient and returned to the recipient.
[0043] When it is determined that the order contract is established, the control proceeds to S21. After the order process is performed, the control proceeds to S19. When it is determined that the sales contract is established, the control proceeds to S23, and the process of obtaining the purchase target is executed and the control proceeds to S19.
[0044] Next, the flowchart of the main routine program of the user terminal that constitutes node 19 of private chain 2 will be described based on FIG. 5(A). Personal information search processing is performed in S28, smart contract processing is performed in S29, blockchain processing is performed in S30, machine learning processing is performed in S31, AI smart contract generation processing is performed in S32, and smart contract trust subcontracting processing is performed in S33. The AI smart contract is a concept that includes both the "integrated type" and the "cooperative type". The "integrated type" is a type in which AI and a smart contract are integrated, machine learning is performed based on contract (legal act) data, and the smart contract itself is AI-ified. The "cooperative type" is a type in which an AI that has performed machine learning based on contract (legal act) data and a smart contract are cooperative. In the case of the cooperative type, a learned AI (hereinafter referred to as "cooperative AI") adds, changes, updates, etc. the smart contract according to the situation.
[0045] Personal information search processing is processing for searching an encrypted index recorded in a blockchain by a trapdoor (encrypted search query). Smart contract processing is processing for automatically performing legal acts such as conclusion and execution of a contract according to predetermined rules. The specific content of the blockchain processing is as described above based on FIG. 2(A). Machine learning processing is processing for generating a learned model of artificial intelligence by performing machine learning on personal information of a large number of users as learning data. More specifically, after generating a general learned model of artificial intelligence by performing machine learning on a vast amount of personal information in a form that cannot identify the personal information owner as learning data, a personalized learned model personalized for each personal information owner (for each address in the blockchain) is generated using the personal information classified for each data (for example, an address in the blockchain) that can identify the personal information owner.
[0046] The AI smart contract generation process is a process of generating a learned model of a smart contract by artificial intelligence through machine learning using personal information related to a contract (legal act) as learning data. More specifically, after generating a general learned model of a smart contract by artificial intelligence through machine learning using personal information related to a huge number of contracts (legal acts) in a form that cannot identify the personal information owner, for each piece of personal information related to a contract (legal act) classified for each data that can identify the personal information owner (for example, an address in a blockchain), it is a process of generating a personalized AI smart contract learned model personalized for each personal information owner (for example, for each address in a blockchain).
[0047] The smart contract trustee contracting process is a process of providing a service that executes, on behalf of the principal, a process of automatically performing legal acts such as contract conclusion and execution. More specifically, a personalized AI smart contract learned model personalized for the trustor is generated, and using that personalized AI smart contract learned model, legal acts are executed on behalf of the trustor. Based on the result of the execution, a reward for the AI is determined, and the personalized AI smart contract learned model is further strengthened through reinforcement learning using that reward.
[0048] Next, based on FIG. 5(B), the flowchart of the subroutine program of the personal information search process shown in S28 will be described. It is determined at S37 whether there is a memory of the common key K2, and if not, the process returns. When K2 is stored by S45 described later, when it is determined at S37 that there is a memory of the common key K2, the control proceeds to S38. At S38, a process of searching the encrypted index on the blockchain with a search query (trapdoor) encrypted with K2 is performed. As a result of performing that search, it is determined at S39 whether there is the personal information to be obtained. If it is determined that there is no personal information to be obtained, the process returns, but if it is determined that there is the personal information to be obtained, the electronic ID of the desired personal information is stored at S40.
[0049] Next, based on FIGS. 6 and 7(A), the flowchart of the subroutine program for the smart contract process shown in S29 will be described. It is determined at S42 whether there is personal information to be searched for. This determination is made, for example, when sequentially negotiating with the smart contracts of personal information owners who have not been searched yet and determining that the personal information of the personal information owner whose conditions match is the personal information to be searched for when the conditions are met. If it is determined at S42 that there is no personal information to be searched for, it is determined at S46 whether there is storage of personal information to be obtained. If it is determined that there is none, the control proceeds to S55 in FIG. 7(A), and it is determined whether a lending contract of PC resources (computing resources) is established. If it is determined that it is not established, it is determined at S56 whether an order contract is established. If it is determined that it is not established, it is determined at S57 whether a sales contract is established. If it is determined that it is not established, the process returns.
[0050] If it is determined at S42 that there is personal information to be searched for, the control proceeds to S43, and the common key K2 is requested from the personal information owner. Specifically, the own address and an Attribute Certificate are sent to the address of the personal information owner of the personal information to be searched for on the blockchain to request the common key K2. It is determined at S44 whether there is a reply of K2, and the process waits until there is. The personal information owner or the smart contract of the personal information owner determines whether to reply with K2 after confirming the sent Attribute Certificate, and if it is determined that it is okay to reply, K2 is replied. When there is a reply of K2 from the personal information owner, the control proceeds to S45. After storing the replied K2, the control transfers to S54. At S54, the process of storing the established contract as a transaction on the blockchain is performed. In this case, a contract stating that the common key K2 used for encrypting the index is distributed from the address of the replied personal information owner to the address of the user who received the reply is stored on the blockchain.
[0051] If it is determined by S46 that there is a memory of the personal information desired to be obtained, the control proceeds to S47, and a process of requesting the personal information desired to be obtained from the personal information owner is performed. Specifically, the own address and the attribute certificate are transmitted to the address on the blockchain of the personal information owner of the personal information desired to be obtained to request the personal information desired to be obtained. In the user terminal of the public blockchain that has received this, the smart contract checks the attribute certificate and determines whether the conditions for providing the personal information are met. When it is determined that the personal information can be provided (YES in S16), the electronic ID of the personal information to be provided and the signature agreeing to provide the personal information are returned, and the common key K1 used for encrypting the personal information to be provided is encrypted with the public key of the recipient and returned (see S20).
[0052] If there is such a reply, it is determined by S48 that there is a reply from the personal information owner, and the control proceeds to S49. The encrypted common key E PK (K1) is decrypted with the own secret key SK, that is, D SK (E PK (K1)) is performed to calculate K1. Next, by S50, a process of transmitting the electronic ID and signature returned from the personal information owner to the server 18 of the certifying authority 17 is performed. The server 18 of the certifying authority 17 that has received this checks the transmitted signature, searches the personal information DB29 (see Fig. 2(B)) based on the received electronic ID, and reads and returns the encrypted personal information E K1 (personal information) associated with the received electronic ID.
[0053] If that reply is received, it is determined to be YES by S51 and the control proceeds to S52. The encrypted personal information E K1 (personal information) is decrypted with K1 calculated in S49, that is, D K1 (E K1 (personal information)) is performed to obtain the plaintext personal information. The personal information is stored by S53. Then, the process proceeds to S54, and a process for recording the provision contract of the personal information as a transaction on the blockchain is performed.
[0054] Next, if a lending contract for PC resources (computing resources) is established with the user terminal of the public chain (YES in S15), it is determined as YES by S55 and the control proceeds to S58, and the borrowing process of PC resources (computing resources) is performed. Then the control transfers to S54, and a process for recording the lending contract as a transaction on the blockchain is performed. If an order contract is established with the user terminal of the public chain (YES in S17), it is determined that the order contract is established by S56 and the control proceeds to S59, and a process for storing the order receipt for the order is performed. Then the control transfers to S54, and a process for recording the order receipt contract as a transaction on the blockchain is performed.
[0055] If a sales contract is established with the user terminal of the public chain (YES in S15), it is determined that the lending contract for PC resources (computing resources) is established by S57 and the control proceeds to S60, and a process for providing the sales target is performed. Then the control transfers to S54, and a process for recording the sales contract as a transaction on the blockchain is performed. In the smart contract process described above, the actions (for example, S42, S47, S58, S56, S60) are not executed based only on the judgment (for example, S42, S46, S55, S56, S57) on the private chain user terminal 16 based on the smart contract, but the actions may be executed after obtaining the consent of the owner of the smart contract. This consent of the owner may also be obtained when executing the contract by the smart contract described hereinafter.
[0056] Next, based on FIG. 7(B), the flowchart of the subroutine program of the machine learning process shown in S31 will be described. By S63, a process is performed to make a huge amount of personal information stored in a form that cannot identify the personal information owner into learning data. As the learning algorithm adopted in this machine learning, for example, various algorithms such as regression and discrimination as supervised learning, model estimation and data mining as unsupervised learning, and reinforcement learning and deep learning as intermediate methods are prepared.
[0057] Next, S64 performs machine learning using the borrowed PC resources (computing resources) with the learning data. For example, in the case of regression as supervised learning, a large dataset consisting of input information (vector x) and correct answer information y is used as training data (learning data). In the case of supervised learning, since a function ci(x) (ci: x → y) that maps the input x to the correct answer y is learned, the learned model includes the function ci. Note that the machine learning performed by the machine learning means 34 is not limited to supervised learning, and can be any type of machine learning such as unsupervised learning like model estimation and pattern mining (data mining), semi-supervised learning which is an intermediate method between supervised learning and unsupervised learning, reinforcement learning, deep learning, etc.
[0058] A general learned model is generated by the machine learning by S64 and stored (S65). This general learned model is a model that uses a vast amount of personal information, which is the personal information of a large number of users and cannot identify the personal information owner, as learning data, and is an average learned model that can be widely applied to a large number of users.
[0059] Next, it is determined by S66 whether there is an order memory. If not, the process returns. If there is, it is determined by S67 whether it is an order received by artificial intelligence. If it is not an order received by artificial intelligence, the process returns. If it is an order received by artificial intelligence, then by S68, a process is performed to request personal information to the address of the order placer. If there is a reply of personal information from the order placer, it is determined as YES by S69 and the process proceeds to S70. In S70, a process is performed to personalize the general pre-trained model based on the replied personal information and generate a personalized pre-trained model. The process of personalizing this general pre-trained model and generating a personalized pre-trained model is described in Japanese Patent Publication No. 6432859. Since the personal information required for personalization is collected using the blockchain, there is an advantage that the problem of privacy can be avoided as much as possible by collecting it while ensuring the anonymity of the blockchain. Next, by S71, the personalized pre-trained model is transmitted to the address of the order placer.
[0060] Next, based on FIG. 8, a flowchart of the subroutine program of the AI smart contract generation process shown in S32 will be described. By S80, a process is performed to extract personal information related to a contract (juridical act) from a vast amount of personal information stored in a form that cannot identify the personal information owner and use it as learning data. Next, by S81, machine learning using the learning data is performed using the PC resources (computing resources) being borrowed. The processes of S80 and S81 are the same as those described in S63 and S64 above, and the repetition of the explanation will be omitted here.
[0061] Next, in S82, a process is performed to generate and store a learned model of a general AI smart contract. Next, in S83, simulation learning processing is executed. This simulation learning processing virtually executes (simulates) in a computer, by having a group of multiple AI smart contracts substitute for legal acts such as verification, condition confirmation, execution, performance, and negotiation of contracts that are originally carried out among a large number of people, and gives rewards according to the results to each AI smart contract to perform reinforcement learning. Because it is reinforcement learning by simulation in a computer instead of in the real world, there is an advantage that a huge amount of reinforcement learning can be performed in a short time. Reinforcement learning is a mechanism in which an agent placed in a state of a certain environment acquires a policy that maximizes the cumulative reward from the initial state to the goal based on the reward given when the agent selects an action. In reinforcement learning, learning progresses through the interaction between a software agent (hereinafter referred to as "agent"), which is a type of AI, and the environment. Here, the agent is a type of AI, which is software that communicates with users, software, etc. and autonomously behaves with a certain degree of judgment ability and continuously operates permanently. When the agent performs an action a on the environment, the state s of the environment changes, and when a certain target state is reached, a reward r is given to the agent. The agent learns a function that outputs the action a using the state s as input with the aim of maximizing this reward r.
[0062] Time progresses in reinforcement learning by repeating the following simple steps. 1. The agent receives an observation o (or directly, the state s of the environment) received from the environment and returns an action a to the environment based on the policy π. 2. Based on the action a received from the agent and the current state s, the environment changes to the next state s′, and based on this transition, it returns to the agent the next observation o′ and a scalar quantity (a single number) called the reward r that indicates the goodness or badness of the previous action. 3. Progress of time: t ← t + 1 Here, ← represents an assignment operation. As reinforcement learning, for example, an AlphaZero-type reinforcement learning algorithm may be used. This AlphaZero-type reinforcement learning algorithm is different from algorithms such as DQN (Deep Q-Network). It uses Monte Carlo tree search (MCTS) for exploration, and allows all values and policies to be predicted by a neural network, and the prediction is corrected only by the experience obtained from self-play by tree search. Compared with the conventional AlphaGo, the value network for predicting value and the policy network for predicting policy are integrated into one neural network, and the prediction accuracy is improved by multi-task learning. In addition, due to the improvement of the performance of the neural network, the processor layout in tree search (extending the search tree until a reward is obtained) processing becomes unnecessary, and the search can be performed faster. Furthermore, evolutionary computation, genetic algorithm, or generative adversarial networks may be used.
[0063] Next, S84 determines whether there is an order acceptance record of the AI smart contract. If not, the process returns. If the order acceptance has been recorded by the aforementioned S59, it is determined as YES by S84 and the control proceeds to S85, where it is determined whether the recorded order acceptance is an order acceptance of the AI smart contract that has completed simulation learning. If it is not an order acceptance of the AI smart contract that has completed simulation learning, it is an order acceptance of the personalized AI smart contract learned model. In that case, the control proceeds to S86, and a process of requesting personal information regarding the contract (legal act) to the address of the order placer is performed. When a reply of personal information is received from the order placer, it is determined as YES by S87 and the control proceeds to S88.
[0064] In S88, a process is performed to personalize the learned model of the general AI smart contract based on the personal information regarding the replied contract (legal act) to generate a personalized learned model of the AI smart contract. The process of personalizing the learned model of the general AI smart contract to generate a personalized learned model of the AI smart contract is described in Japanese Patent Publication No. 6432859. The personalized learned model is transmitted to the address of the orderer by S89.
[0065] On the other hand, in the case of receiving an order for the AI smart contract with the learned simulation, it is determined as YES by S85 and the control proceeds to S90, and the AI smart contract with the learned simulation is transmitted to the address of the orderer.
[0066] Next, based on FIG. 9(A), the flowchart of the subroutine program of the simulation learning process shown in S83 will be described. By S334, it is determined whether there is an input for the simulation, and if not, the process returns. This simulation is input by the user terminal of the private chain 2. For example, in the case where it is assumed that a policy or law that the government is trying to adopt (e.g., a reduced tax rate accompanying a consumption tax increase, the revised Immigration Control Law, the United Kingdom's withdrawal from the EU (European Union), partial or full adoption of basic income, amendment of Article 9 of the Japanese Constitution, etc.) is adopted, it is a transaction simulation in the investment market such as stock trading or futures trading, a company management simulation, or a consumer behavior simulation. Furthermore, it may also be a simulation of the promotion of new products (including financial products and life insurance) and new services by various media. If it is determined by S334 that there is an input for the simulation, the control proceeds to S335 and the AI smart contract group generation process is executed.
[0067] The flowchart of the subroutine program for this AI smart contract group generation process will be described based on FIG. 9(B). In S344, a process is performed to set a group of personas that match the input simulation using the borrowed PC resources (computing resources). A persona generally refers to a virtual person defined as a typical target image of a company, product, or service. In this embodiment, a persona is defined as a virtual person representing a typical target image of the simulation content. For example, in the case of the consumption behavior simulation under the reduced tax rate accompanying the aforementioned consumption tax increase, personas corresponding to general consumers are set for each group grouped by gender, age, region, annual income, etc.
[0068] The number of personas to be set is made proportional to the number of users belonging to the group. For example, when the age-based population distribution of general consumers is 5% for those in their 10s, 5% for those in their 20s, 10% for those in their 30s, 10% for those in their 40s, 20% for those in their 50s, 20% for those in their 60s, 20% for those in their 70s, 5% for those in their 80s, and 5% for those in their 90s, the number of personas representing those in their 10s is set to 1, the number of personas representing those in their 20s is set to 1, the number of personas representing those in their 30s is set to 2, the number of personas representing those in their 40s is set to 2, the number of personas representing those in their 50s is set to 4, the number of personas representing those in their 60s is set to 4, the number of personas representing those in their 70s is set to 4, the number of personas representing those in their 80s is set to 1, and the number of personas representing those in their 90s is set to 1.
[0069] Next, by S345, a process is performed to select a user group belonging to each persona using the borrowed PC resources (computing resources). Next, by S346, a process is performed to group-ping the user groups belonging to each persona and collect the transaction data of the user groups from the blockchain for each group. For example, in the case of the consumption behavior simulation under the reduced tax rate accompanying the aforementioned consumption tax increase, the user groups are grouped by gender, age, region, annual income, etc., and the transaction data of the user groups is collected from the blockchain for each group. For the selection of the user group and the collection of the transaction data of the user group in S345 and S346, it is useful to utilize, for example, the database of the questionnaire answering monitor members held by an Internet questionnaire survey company. The Internet questionnaire survey company stores in the database the contact information (such as email addresses) of the questionnaire answering monitor members in association with attributes such as gender, age, place of residence, unmarried, married, occupation, household annual income, etc., and utilizes the monitor member data by attribute. Similarly, in S145 and S146, S586 and S587, S622 and S623, etc. to be described later, it is useful to utilize the database of the questionnaire answering monitor members held by the Internet questionnaire survey company. Next, by S347, a process is performed to perform machine learning using the transaction data as learning data using the borrowed PC resources (computing resources) and generate a learned AI smart contract for each persona. This AI smart contract is generated in the same number as the number of settings of the corresponding persona. Thereby, the environment for executing the simulation is prepared, and the simulation is performed within that environment.
[0070] Returning to Fig. 9(A), each AI smart contract generated as described above executes a contract (legal act) according to act a (S336). This "act a" is act a as a result of the reinforcement learning by S338. Next, by S337, a process is performed to record the contracts established between the AI smart contracts in the blockchain.
[0071] Next, by S338, the reward r is calculated based on the established contract details using the borrowed PC resources (computing resources), and the process of obtaining the action a according to the optimal policy π by TD learning is performed. For example, in the case of the consumption behavior simulation under the reduced tax rate accompanying the aforementioned consumption tax increase, the smaller the value of (expenditure amount before tax increase - expenditure amount after tax increase), the higher the reward r is given. Then, it is determined by S339 whether the simulation has ended. If it has not ended yet, the control returns to S336, and the loop of S337→S338→S339→S336 is repeated to progress the reinforcement learning. When the simulation ends and it is determined to be YES by S339, the control proceeds to S340, and after memorizing the AI smart contract that obtained the highest reward r, it returns. Note that it is not limited to the AI smart contract that obtained the highest reward r. For example, the top 5% of AI smart contracts may be memorized. Also, the recording on the blockchain by S337 does not necessarily have to be performed. In that case, in the aforementioned cooperation type, the "AI smart contract" in S335, S336, S340, and S347 is changed to "cooperation-use AI". That is, in the case of simulation within a computer, since it does not involve the execution of a contract (juridical act) in the real world, when the recording on the blockchain is not performed, there is no need to use a smart contract deliberately, because it is sufficient for each cooperation-use AI to execute the action a and perform reinforcement learning. At the actual citation stage after the reinforcement learning is completed, the learned cooperation-use AI may cooperate with the smart contract to execute the contract and record it on the blockchain. * The process of obtaining the action a according to the optimal policy π is performed. For example, in the case of the consumption behavior simulation under the reduced tax rate accompanying the aforementioned consumption tax increase, the smaller the value of (expenditure amount before tax increase - expenditure amount after tax increase), the higher the reward r is given. Then, it is determined by S339 whether the simulation has ended. If it has not ended yet, the control returns to S336, and the loop of S337→S338→S339→S336 is repeated to progress the reinforcement learning. When the simulation ends and it is determined to be YES by S339, the control proceeds to S340, and after memorizing the AI smart contract that obtained the highest reward r, it returns. Note that it is not limited to the AI smart contract that obtained the highest reward r. For example, the top 5% of AI smart contracts may be memorized. Also, the recording on the blockchain by S337 does not necessarily have to be performed. In that case, in the aforementioned cooperation type, the "AI smart contract" in S335, S336, S340, and S347 is changed to "cooperation-use AI". That is, in the case of simulation within a computer, since it does not involve the execution of a contract (juridical act) in the real world, when the recording on the blockchain is not performed, there is no need to use a smart contract deliberately, because it is sufficient for each cooperation-use AI to execute the action a and perform reinforcement learning. At the actual citation stage after the reinforcement learning is completed, the learned cooperation-use AI may cooperate with the smart contract to execute the contract and record it on the blockchain.
[0072] Next, based on FIG. 10, the flowchart of the subroutine program for the smart contract trust subcontracting process shown in S33 will be described. By S94, it is determined whether there is an order memory for the smart contract trust. If it is determined that there is no order memory, the process returns. When it is confirmed that the content of the order memory stored by the aforementioned S59 is an order for the smart contract trust, it is determined as YES by S94 and the control proceeds to S95. In S95, personal information regarding the contract (juridical act) is requested to the address of the orderer. When personal information is replied from the orderer, it is determined as YES by S96 and the control proceeds to S97.
[0073] In S97, a process of personalizing the learned model of the general AI smart contract based on the replied personal information regarding the contract (juridical act) to generate a personalized AI smart contract learned model is performed. The process of personalizing the learned model of the general AI smart contract to generate a personalized AI smart contract learned model is described in Japanese Patent Publication No. 6432859.
[0074] Next, by S98, a process of associating and storing the address of the orderer and the personalized AI smart contract learned model is performed. Using the stored personalized AI smart contract learned model, a subcontracting process is performed for the orderer (S99). Next, by S100, a reinforcement learning process of the personalized AI smart contract learned model is executed.
[0075] Based on FIG. 11(A), the flowchart of the subroutine program for the reinforcement learning process of the personalized AI smart contract trained model shown in S100 will be described. In reinforcement learning, as a method for estimating the Q-value when the value when performing action at in state st is defined as Q(st, at), if knowledge for modeling the environment, that is, the state transition probability and the probability distribution of rewards are given, a model-based method may be used. However, when the environment model is unknown, TD (Temporal Difference) learning is used. First, since exploration of the environment is necessary, the ε-greedy method is used. At the initial stage of exploration, various actions are tried, and the concept of temperature is introduced so that optimal actions are selected more often as it stabilizes. Letting the temperature be T, actions are selected according to the probability represented by the following formula.
[0076] P(a|s)={exp(Q(s,a) / T)} / {Σexp(Q(s,b) / T} (Note that b∈A is described below Σ, and this description is omitted in the above formula) Here, a is the action, Q(s, a) is the value when performing action a in state s,
[0077] T is called the temperature in annealing, and if it is high, actions are selected with a probability close to equal probability, and if it is low, it is biased towards the optimal one. As learning progresses, by decreasing the value of T, the learning result becomes stable. Such a method for estimating the Q-value may be applied to all of the above-described reinforcement learning and the reinforcement learning to be described later. Also, as the computer for performing machine learning such as reinforcement learning, a general Neumann-type computer is used, but a neural network processor (NNP) may also be used. A large number of "artificial neurons" modeled after real neurons are mounted on the chip of the NNP, and each neuron cooperates with each other in the network. Also, a quantum computer adopting the "quantum annealing method" may be used. In particular, by using a quantum computer adopting the "quantum annealing method", the time required for optimization calculation in machine learning can be significantly shortened.
[0078] Receive, from the trustor, an evaluation of the result of performing trust subcontracting processing using the personalized AI smart contract learned model in S105. Next, in S106, a process of calculating the reward r based on the received evaluation is performed. Next, in S107, using the borrowed PC resources (computing resources), a process of obtaining the action a according to the optimal policy π * is performed. Next, in S108, a contract according to the action a is executed on behalf of the trustor. By receiving an evaluation from the trustor for the result (S105), the processes of S106 to S108 are executed.
[0079] Next, based on FIG. 11(B), a flowchart of the main routine program of the user terminal constituting the nodes of the consortium chain 3 will be described. In S114, IoT sensor data aggregation processing is executed, in S115, smart contract processing is executed, in S116, simulation processing is executed, and in S117, blockchain processing is executed. The specific content of the blockchain processing is as described above based on FIG. 2(A).
[0080] Next, based on FIG. 12(A), a flowchart of the subroutine program of the IoT sensor data aggregation processing shown in S114 will be described. In S120, a process of classifying and grouping IoT sensor data by type, period, region, etc. is performed. This process is performed not only on IoT sensor data but also on data from the wireless sensor network. Next, in S121, a process of determining the value of each grouped data is performed. According to the determined value, the consideration (amount of tokens) for the provision of the data is coded as a smart contract for each corresponding data. Next, in S122, a process of recording each grouped data on the blockchain is performed.
[0081] Next, based on FIG. 13(B), the flowchart of the subroutine program for the smart contract process shown in S115 will be described. By S150, it is determined whether a sales contract with the data requester has been established. This determination is automatically determined to be YES by S150 when the conditions of both parties match regarding the consideration (the amount of tokens) for the provision of the data encoded as a smart contract. If it is determined to be NO by S150, the control proceeds to S151, where it is determined whether a lending contract for PC resources has been established, and if not, the process returns.
[0082] If it is determined to be YES by S150, the control proceeds to S152, where the data is transmitted to the address of the requester, and the process of acquiring the tokens as the consideration is performed. The established contract is recorded as a transaction in the blockchain by S153. On the other hand, if a lending contract for PC resources (computing resources) is established, the control proceeds to S154, where the borrowing process of the PC resources (computing resources) is performed, and the contract is recorded as a transaction in the blockchain by S153.
[0083] Next, based on FIG. 12(B), the flowchart of the subroutine program for the simulation process shown in S116 will be described. This simulation process virtually executes (simulates) in a computer, on behalf of a number of AI smart contract groups, legal acts such as verification, condition confirmation, execution, performance, and negotiation of contracts that are originally carried out among a number of people, and verifies what kind of simulation results will occur under certain conditions. Specific examples of the above "certain conditions" include policies and laws that the government is trying to adopt (for example, reduced tax rates accompanying consumption tax increases, revised immigration control laws, the United Kingdom's withdrawal from the EU (European Union), partial or full adoption of basic income, amendment of Article 9 of the Japanese Constitution, etc.), marketing-related conditions (for example, setting prices or consideration for new products (including financial products and life insurance) and new services, promotion effects by various media, etc.), investment market-related conditions (for example, weather conditions in futures trading, monetary tightening policies in the stock market, etc.), and so on.
[0084] S134 determines whether there is a request for simulation. If not, the process returns. If it is determined by S134 that there is a request for simulation, the control proceeds to S135 and the AI smart contract group generation process is executed.
[0085] The flowchart of the subroutine program for this AI smart contract group generation process will be described based on FIG. 13(A). By S144, a process of setting a persona group that matches the requested simulation is performed using the PC resources (computing resources) being borrowed. A persona is generally defined as a virtual person representing the typical target image of a company, product, or service. In this embodiment, a persona is defined as a virtual person representing the typical target image of the simulation content. For example, in the case of the simulation of the reduced tax rate accompanying the aforementioned consumption tax increase, personas corresponding to general consumers are set for each group grouped by gender, age, region, annual income, etc.
[0086] The number of personas to be set is made proportional to the number of users belonging to the group. For example, when the age-based population distribution of the general public is 5% for those in their teens, 5% for those in their twenties, 10% for those in their thirties, 10% for those in their forties, 20% for those in their fifties, 20% for those in their sixties, 20% for those in their seventies, 5% for those in their eighties, and 5% for those in their nineties, the number of personas representing those in their teens is set to 1, the number of personas representing those in their twenties is set to 1, the number of personas representing those in their thirties is set to 2, the number of personas representing those in their forties is set to 2, the number of personas representing those in their fifties is set to 4, the number of personas representing those in their sixties is set to 4, the number of personas representing those in their seventies is set to 4, the number of personas representing those in their eighties is set to 1, and the number of personas representing those in their nineties is set to 1.
[0087] Next, by S145, a process is performed to select a user group belonging to each persona using the borrowed PC resources (computing resources). Next, by S146, a process is performed to group-ping the user groups belonging to each persona and collect the transaction data of the user groups from the blockchain for each group. For example, in the case of the simulation of the reduced tax rate accompanying the aforementioned consumption tax increase, the user groups are grouped by gender, age, region, annual income, etc., and the transaction data of the user groups is collected from the blockchain for each group. Next, by S147, a process is performed to perform machine learning using the borrowed PC resources (computing resources) with the transaction data as learning data and generate a learned AI smart contract for each persona. This AI smart contract is generated in the same number as the set number of the corresponding persona. As a result, the environment for executing the simulation is prepared, and the simulation is performed within that environment.
[0088] Return to FIG. 12(B), and each AI smart contract generated as described above executes a contract (juridical act) in accordance with act a (S136). This "act a" is act a as a result of reinforcement learning according to S138. Next, in S137, a process of recording the contracts established between the AI smart contracts in the blockchain is performed. Further, the changing situation of the situation due to the progress of the simulation is recorded in the blockchain. For example, in the case of the simulation of the reduced tax rate accompanying the aforementioned consumption tax hike, how domestic demand and the economy have changed as the simulation progresses is recorded in the blockchain.
[0089] Next, in S138, using the PC resources (computing resources) being borrowed, the reward r is calculated based on the established contract content, and a process of obtaining act a according to the optimal policy π * is performed by TD learning. Then, it is determined in S139 whether the simulation has ended. If it has not ended yet, the control returns to S136, and the loop of S137 → S138 → S139 → S136 is repeated to advance the reinforcement learning. When the simulation ends and is determined to be YES in S139, the control proceeds to S140, and after the process of deriving the simulation result is performed, it returns.
[0090] As a specific example of the process of deriving simulation results, for example, in the case of a simulation of economic fluctuations accompanying the adoption of a reduced tax rate due to a consumption tax hike, it is derived how each item of the economic trend index has changed as a result of the simulation. In the case of a simulation accompanying a monetary tightening policy in the stock market, it is derived how the stock market has changed as a result of the simulation. Further, a simulation optimization method may be adopted in which the optimal form of the reduced tax rate is determined while varying the specific form of the reduced tax rate accompanying the consumption tax hike (for example, what items are subject to the reduced tax rate and the reduced tax rate for each item subject to the reduced tax rate, etc.) in a plurality of forms. In this case, as the optimal form of the reduced tax rate, (tax revenue increase rate (%) + diffusion index (DI) as the economic trend index / 50) is set as the expected value E, and a simulation result that maximizes the expected value E is obtained. Let the control parameter (form of the reduced tax rate) in the simulation be θ, the result of the simulation be Y(θ), and θ in maxE[Y(θ)] be obtained. As a specific method for optimizing such a simulation, for example, the particle swarm optimization method (PSO), which is a metaheuristic algorithm, DFO (derivative free optimization) for obtaining an optimal solution when it is difficult to analytically represent the objective function or when information regarding the differentiation of the objective function cannot be used, etc. are used. Note that the recording on the blockchain by S137 does not necessarily have to be performed. In that case, in the above-described cooperation type, the "AI smart contract" in S135, S136, and S147 is changed to "cooperation-use AI". That is, in the case of a simulation within a computer, since it does not involve the execution of a contract (juridical act) in the real world, when the recording on the blockchain is not performed, there is no need to use a smart contract unnecessarily, because it is sufficient for each cooperation-use AI to execute action a and perform reinforcement learning. [Modification Example]
[0091] (1) The certified business operator 17 encrypts the personal information E of the user K1It stores K1 (personal information), but instead, encrypted personal information E may be directly recorded on the blockchain.
[0092] (2) Transaction data other than personal information, such as Transaction C and Transaction F in FIG. 2, may also be encrypted with a key K1 or the like and recorded on the blockchain in the same manner as personal information.
[0093] (3) In the above description, the operation processes of the nodes 19 in each of the blockchain networks 2, 3, and 4 are shown. However, the operation processes shown for the nodes 19 in the private blockchain 2 may be performed by the nodes 19 in the other blockchain networks 3 and 4, the operation processes shown for the nodes 19 in the consortium blockchain 3 may be performed by the nodes 19 in the other blockchain networks 2 and 4, and the operation processes shown for the nodes 19 in the public blockchain 4 may be performed by the nodes 19 in the other blockchain networks 2 and 3. This modification may be similarly applied in the embodiments described later.
[0094] (4) Mining (competition for the right of bookkeeping) in the blockchain may be performed using the borrowed PC resources (computing resources). At that time, the PC resources (computing resources) may be lent at a time unit price as in the first embodiment, or a certain percentage of the profit (tokens, etc.) obtained by the miner who has succeeded in mining (competition for the right of bookkeeping) may be distributed (dividends) to the lender of the PC resources (computing resources). The dividend ratio (dividend amount) is controlled to be proportional to the lending amount of the PC resources (computing resources) (the number of lent PCs × lending time, etc.).
[0095] (5) It may also be possible to borrow (utilize) the above-mentioned PC resources (computing resources), power generated by self-generation, etc. that are the lending (providing) targets and carry out some project. Specific examples of the project may include research and development (for example, artificial intelligence development, machine learning, human genome analysis, new product development, new drug development, etc.), exploration and excavation of rare metals, oil, natural gas, marine resources, etc., space development, etc. In that case, the lender (provider) may obtain a consideration (token, etc.) corresponding to the lending amount (providing amount) of the lending (providing) target as in the first embodiment, or a certain percentage of the profit obtained by the project executor (individual, corporation, or organization) due to the success of the project may be distributed (allocated) to the resource lender (resource provider). The allocation ratio (allocation amount) is controlled to be proportional to the lending amount (providing amount) of the resources.
[0096] Furthermore, instead of the resource lender (resource provider) receiving the dividend itself, it may be possible to obtain the right to receive the dividend (hereinafter referred to as "dividend enjoyment right"). This dividend enjoyment right may be controlled, for example, so that the lender (provider) obtains it in the form of tokens issued by the project executor. Then, the lender (provider) may control so that the obtained dividend enjoyment right (token) can be transferred to others at a price (token) corresponding to the market price at that time. By configuring in this way, the dividend enjoyment right (token) can be operated like stock trading in the secondary market in the stock market.
[0097] (6) In S71, the personalized trained model generated is sent and delivered to the address of the orderer, but in addition to or instead of that, it may also be possible to provide a personalized service to the orderer by utilizing the generated personalized trained model.
[0098] (7) In the foregoing description, verification, condition confirmation, execution, enforcement, and negotiation of contracts are automated by smart contracts. However, control may be exercised to request the commitment of the user himself / herself before concluding and executing a contract (a legal act such as a transaction). Also, instead of requesting the commitment of the user himself / herself for all contracts (legal acts such as transactions), it may be determined whether a contract (legal act such as a transaction) is a predetermined important contract, and control may be exercised to request the commitment of the user himself / herself when it is determined that the contract (legal act such as a transaction) is an important contract. Further, it may be determined whether a contract (legal act such as a transaction) is urgent in terms of conclusion and execution, and when it is determined that the contract (legal act such as a transaction) is urgent, control may be exercised to conclude and execute the contract (legal act such as a transaction) without obtaining the commitment of the user himself / herself and report it to the user himself / herself later. This modification may be similarly applied in the embodiments described later.
[0099] (8) The above-described programs operating on the user terminals 16 and various servers that constitute the nodes 19 of each blockchain may be downloaded and installed from a predetermined website or the like. However, for example, they may be recorded on a recording medium (a non-transitory recording medium) such as a CD-ROM 99 and distributed, and those who have purchased the CD-ROM 99 or the like may install the program on the user terminals 16 and various servers (see FIG. 60).
[0100] (9) In the foregoing description, the centralized oracle 21 is adopted. However, a decentralized oracle that is distributed and managed throughout the network may be adopted. Information collected by a plurality of oracles distributed throughout the network is aggregated to extract average information, and the average information is regarded as correct information and incorporated into the blockchain for use in smart contracts. This is based on the theory proposed by James Suroweicki in the book "The Wisdom of Crowds" that "by aggregating information in a group, the conclusion reached by the group can lead to a better conclusion than that of any individual in the group." Then, an incentive for operating the decentralized oracle is provided by giving a reward such as a token to the oracle that has collected information close to the average information.
[0101] In summary, it includes an extraction means for collecting information collected by a plurality of oracles distributed on a network and extracting average information, an adoption means for adopting the average information extracted by the extraction means, and a reward giving means for giving a reward to the oracle. The plurality of oracles include a first oracle and a second oracle, and the reward giving means gives more rewards to the second oracle that has collected information closer to the average information than the first oracle. Note that the reward given to the first oracle may be 0 or may be negative.
[0102] (10) For the determination of the establishment of one or both of the above-mentioned K2 distribution contract in S13 and the establishment of the personal information provision contract in S16, a function may be provided to determine whether to establish according to the information for specifying the intention of the personal information owner himself / herself (hereinafter referred to as "intention specifying information"). Specifically, when a personal information owner receives a recommendation of products or services that match himself / herself in a physical store, an e-commerce mall, etc., the specific information of the mobile terminal (smartphone or IC card, etc.) he / she possesses is read, and a password for establishing a contract is input to notify the smart contract of the personal information owner of the intention specifying information consisting of the specific information and the password, and the smart contract determines according to the intention specifying information.
[0103] By doing so, the user can utilize the personal information retrieved from an operator such as an SNS and placed under his / her own management for his / her own purposes according to his / her own intention. [Second Embodiment]
[0104] Next, the second embodiment will be described. This second embodiment responds to the need for the right to delete personal information (so-called the right to be forgotten) to delete one's own personal information by applying encryption technology to the personal information recorded using blockchain. Blockchain is characterized in that once recorded information cannot be tampered with or it is extremely difficult to tamper with. Therefore, it is impossible or extremely difficult to delete the once recorded information (hereinafter referred to as "impossibility of deletion"). On the other hand, the GDPR (General Data Protection Regulation) in Europe requires guaranteeing the right to delete personal information (so-called the right to be forgotten) that the personal information owner can delete the recorded personal information. The requirement of the right to delete personal information in this GDPR and the impossibility of deletion in blockchain are directly opposed and form an antinomic dilemma. That is, this second embodiment resolves the antinomic dilemma where the requirement to guarantee the right to delete the information to be deleted and the impossibility of deletion are in antinomy. The outline will be described based on FIG. 14.
[0105] FIG. 14(A) shows the normal state where the right to delete is not exercised, and FIG. 14(B) shows the state where the information has been made indecipherable by exercising the right to delete. Referring to FIG. 14(A), an information holder (also referred to as an information owner) 40 double-encrypts the information using two split common keys KA and KB. Expressed in an equation, it becomes E KA (E KB (information)). Next, the encrypted information E KA (E KB (information)) is recorded on a blockchain or the like. Note that the split common key KA is stored in a user terminal or the like of the information holder 40 in a confidential state.
[0106] In this state, when an information requester 41 requests information from the information owner 40, the information owner 40 decrypts the recorded encrypted information E KA (E KB (information)) with the key KA. Expressed in an equation, D KA (E KA (E KB (information)) = E KB (information). And this E KB(Information) and the split common key KB are transmitted by the information provider 40 to the information requester 41.
[0107] The information requester 41 that has received them decrypts the received E KB (Information) with the received split common key KB. Expressed by a formula, D KB (E KB (Information)) = Information. Thus, the information requester 41 can obtain the plaintext information.
[0108] Next, the state where the information is made undecipherable by exercising the deletion right will be described based on FIG. 14(B). The information provider 40 updates one of the split keys KA and KB used for encrypting the information to be made undecipherable to a random number R (≠KA). Next, when the information requester 41 that already stores the split common key KB requests information from the information provider 40, the information provider 40 decrypts the encrypted information E KA (E KB (Information)) with the key R (random number). Expressed by a formula, D R (E KA (E KB (Information)). And this D R (E KA (E KB (Information)) is transmitted by the information provider 40 to the information requester 41.
[0109] The information requester 41 that has received it decrypts D R (E KA (E KB (Information)) with the split common key KB that it already stores. Expressed by a formula, D KB (D R (E KA (E KB(Information)))) ≠ Information. In this way, in the indecipherable state, even the information requester 41 that already remembers the split common key KB cannot obtain the plaintext information, and it is possible to resolve the dilemma where the request to guarantee the deletion right of the information to be deleted and the impossibility of deletion are in antinomy. In addition, if a copy prohibition process is performed so that information such as personal information recorded in a blockchain or the like cannot be copied & pasted, the guarantee of the deletion right of the information becomes more complete. Note that it is not necessary to limit to double encryption using two keys KA and KB, and multiple encryption using three or more keys (n keys) may be used. In this case, by replacing at least any one of the n keys with a random number R, it becomes an indecipherable state.
[0110] The outline of the second embodiment described above will be described in more detail. Regarding the common points with the first embodiment, the repetition of the description will be omitted, and mainly the differences will be described. FIG. 15 corresponds to FIG. 2 in the first embodiment. Referring to the transaction I in the blockchain, in this second embodiment, the encrypted personal information E KA (E KB (Personal Information)) is directly recorded in the block. Therefore, the certifying operator 17 is unnecessary in the second embodiment. Here, KA and KB are split common keys.
[0111] Next, referring to FIG. 16, a flowchart of the main routine of the user terminal constituting the node 19 of the private blockchain 2 and the user terminal 16 constituting the node of the public blockchain 4 will be described. This main routine omits the flowchart of the operation process shown in the first embodiment, and shows only the flowchart of the operation process added or changed to the operation process shown in the first embodiment. In the user terminal 16 constituting the node of the public blockchain 4, the personal information recording process to the blockchain is performed by S160, the recording indecipherable process is performed by S161, and the personal information providing process is performed by S162. In the user terminal constituting the node 19 of the private blockchain 2, the personal information obtaining process is performed by S170.
[0112] The personal information recording process on the blockchain is a process of recording personal information on the blockchain. The record decryption prevention process is a process for making information indecipherable by exercising the right of deletion. The personal information providing process is a process in which the user terminal 16 of the public blockchain 4 provides personal information to the user terminal of the private blockchain 2. The personal information obtaining process is a process in which the user terminal of the private blockchain 2 obtains personal information from the user terminal 16 of the public blockchain.
[0113] Based on FIG. 17(A), a flowchart of a subroutine program for the personal information recording process on the blockchain will be described. In S174, a process of generating two random numbers is performed. For example, in the case of DES, two 56-bit random numbers are generated, and these 56-bit random numbers are used as the split common keys KA and KB. In the case of ADS, two 128-bit random numbers are generated, and these 128-bit random numbers are used as the split common keys KA and KB.
[0114] Next, in S177, KA (E KB (personal information)) and E K2 (index + consideration for personal information provision) and the ciphertext identifier are recorded on the blockchain. This ciphertext identifier is an identifier for specifying the encrypted personal information E KA (E KB (personal information)), and corresponds to the electronic ID in the first embodiment.
[0115] Next, in S183, KA and KB are associated with the ciphertext identifier and stored in the HDD 12 of the user terminal 16.
[0116] Next, based on FIG. 17(B), a flowchart of a subroutine program for the record decryption prevention process will be described. In S190, the ciphertext recorded on the blockchain (for example, E KA (E KBIt is determined whether there is a ciphertext that needs to be made indecipherable among (personal information), etc. If not, the process returns. However, if there is a ciphertext that needs to be made indecipherable, the control proceeds to S191, and a process of retrieving the split common key KA stored in association with the ciphertext identifier of the ciphertext from the HDD12 is performed.
[0117] Next, a random number R is generated by S192. For example, in the case of DES, a 56-bit random number is generated. In the case of ADS, a 128-bit random number is generated. Next, it is determined by S193 whether the generated random number R is equal to KA. If the generated random number R is the same as the split common key KA stored in the HDD12, the control returns to S192 and the random number is generated again. If it is determined as NO by S193, the control proceeds to S194, and a process of updating the split common key KA stored in the HDD12 with R is performed.
[0118] Next, based on FIG. 18, a flowchart of a subroutine program for personal information providing processing and personal information obtaining processing will be described. At the user terminal of the private chain 2, it is determined by S198 whether the split common key KB of the personal information desired to be obtained is already stored. If the split common key KB of the personal information desired to be obtained has already been distributed from the user terminal 16 of the public chain 4 to the user terminal of the private chain 2, it is determined as stored by S198 and the control proceeds to S203. However, if it has not been stored yet, the control proceeds to S199.
[0119] In S199, a process of transmitting the ciphertext identifier of the personal information desired to be obtained to the user terminal 16 of the public chain 4 and requesting the split common key KB is performed. At the user terminal 16 of the public chain 4 that received it in S200, it is determined by a smart contract whether to conduct a transaction to provide the personal information specified by the ciphertext identifier (see S16). When conducting a transaction to provide the personal information, a signature agreeing to provide the personal information and the split common key KB corresponding to the ciphertext identifier are returned by S201.
[0120] At the user terminal of the private chain 2 that received it in S202, in S203, the signature and the ciphertext identifier of the personal information to be obtained are transmitted to the user terminal 16 of the public chain 4. At the user terminal 16 of the public chain 4 that received it in S206, it is determined by the smart contract whether to conduct a transaction to provide the personal information specified by the ciphertext identifier (see S16). If a transaction to provide personal information is to be conducted, in S207, D KA (Encrypted personal information) or D R (Encrypted personal information) is calculated and a reply is sent. Specifically, if the split common key KA stored in the HDD 12 of the user terminal 16 has already been updated to the random number R, D R (Encrypted personal information) is calculated and sent back. However, if it has not yet been updated to the random number R, the process of calculating D KA (Encrypted personal information) and sending it back is performed.
[0121] At the user terminal of the private chain 2 that received the reply from the user terminal 16 of the public chain 4 in S208, in S209, D KB (D KA (Encrypted personal information)) = plaintext or D KB (D R (Encrypted personal information)) ≠ plaintext is calculated. Specifically, when D KA (Encrypted personal information) is received, D KB (D KA (Encrypted personal information)) = D KB (D KA (E KA (E KB (Personal information)))) = plaintext is calculated to obtain the plaintext personal information. On the other hand, when (D R (Encrypted personal information)) is received, D KB (D R (Encrypted personal information)) = D KB (D R (E KA (E KB(Personal information))))≠Plaintext will be calculated, and the plaintext personal information cannot be obtained. This can solve the dilemma in which the requirement to guarantee the right to delete the information to be deleted and the impossibility of deletion are in antinomy. [Variant example]
[0122] (1) In the above description, the encrypted personal information E KA (E KB (Personal information) was directly recorded in the blockchain. If this large amount of encrypted personal information was stored in each node (all nodes in the public blockchain 4), there would be a problem that each node (user terminal) would require a huge storage capacity. As a means to solve this, an application of a secret sharing technology that stores divided data on multiple computers is used. The data is divided and fragmented, and each fragmented data is distributed and stored in multiple nodes. Also, the data stored in each node is made redundant (duplicated) and stored. By having sufficient redundancy, even if a part of the fragmented data is lost, there will be no problem in restoration, and the difficulty of tampering as a blockchain can also be ensured. Furthermore, it may be controlled so that the storage amount responsible for storing the fragmented data is determined by the intention of each node, and a corresponding price in the form of tokens or the like is given to each node according to the storage amount to be borne.
[0123] (2) In the above description, the encrypted personal information E KA (E KB (Personal information) was directly recorded in the blockchain. However, in the variant examples shown in FIGS. 19 to 23, the encrypted personal information E KA (E KB (Personal information)) is stored in the personal information DB 29 of the certification operator 17, and the hash value of the encrypted personal information is recorded in the blockchain. In the transaction I shown in FIG. 19(A), the hash value of E KA (E KB (Personal information)) + E K2 (Index + provided with a 2.4 token) + ciphertext identifier and digital signature are recorded. Also, in the personal information DB 29 of the certification operator 17 shown in FIG. 19(B), the encrypted personal information E KA (E KB(Personal information) is stored.
[0124] Based on FIG. 20, a flowchart of the main routine of the user terminal constituting node 19 of private chain 2, the user terminal 16 constituting node 19 of public chain 4, and the server 18 of the certifying business operator 17 in this modification will be described. The server 18 of the certifying business operator 17 participates in the blockchain as node 19. The personal information recording process for the blockchain is executed by S215, the recording decryption prevention process is executed by S216, the personal information providing process is executed by S217, the hash value recording process is executed by S220, the encrypted text transmission process is executed by S221, and the personal information acquisition process is executed by S224.
[0125] The personal information recording process for the blockchain is a process in which the user terminal 16 constituting node 19 of public chain 4 transmits the encrypted personal information E KA (E KB (personal information)) to the server 18 of the certifying business operator 17. The hash value recording process is a process in which the server 18 of the certifying business operator 17 that has received the encrypted personal information E KA (E KB (personal information)) etc. stores it and generates its hash value and records it in the blockchain. The recording decryption prevention process is a process for making the encrypted text of the encrypted personal information E KA (E KB (personal information)) etc. undecipherable. The personal information providing process is a process executed by the user terminal 16 constituting node 19 of public chain 4 to provide personal information to the user terminal constituting node 19 of private chain 2. The personal information acquisition process is a process in which the user terminal constituting node 19 of private chain 2 acquires personal information. The encrypted text transmission process is a process in which the server 18 of the certifying business operator 17 transmits the encrypted text of the encrypted personal information E KA (E KB (personal information)) etc. to the user terminal constituting node 19 of private chain 2.
[0126] The details of each process will be described based on the flowchart of each subroutine program below. The differences from the second embodiment will be mainly described.
[0127] Based on FIG. 21, the flowchart of the subroutine program for personal information recording processing and hash value recording processing on the blockchain will be described. By S231, E KA (E KB (personal information)) and E K2 (index + consideration for providing personal information) are transmitted to the server 18 of the certified operator 17. At the server 18 that received it at S240, by S241, E KA (E KB (personal information)) is processed to generate a hash value and a ciphertext identifier. Next, by S242, E KA (E KB (personal information))'s hash value, E K2 (index + consideration for providing personal information), and the ciphertext identifier are recorded on the blockchain.
[0128] Next, by S243, the process of transmitting the ciphertext identifier to the user terminal 16 of the public chain 4 is performed. At the user terminal 16 of the public chain 4 that received it at S232, by S233, the split keys KA and KB are associated with the received ciphertext identifier and stored in the HDD 12. At the server 18 of the certified operator 17, by S244, E KA (E KB (personal information)) and the ciphertext identifier are associated and stored in the personal information DB 29.
[0129] The record decoding impossible process shown in FIG. 22 is the same as that already described in FIG. 17(B) of the second embodiment, so the repeated description will be omitted.
[0130] Next, based on FIG. 23, a flowchart of a subroutine program for personal information providing process, personal information obtaining process, and encrypted text transmission process will be described. In this modification example, when the user terminal of the private chain 2 receives from the user terminal 16 of the public chain 4 a signature consenting to the provision of personal information and a split common key KB corresponding to the encrypted text identifier (S264), in S265, it transmits the received signature and the encrypted text identifier of the personal information to be obtained to the server 18 of the certifying business operator 17. In the server 18 of the certifying business operator 17 that receives it in S266, in S267, after confirming the signature, a process is performed of searching the personal information DB29 for the encrypted text corresponding to the encrypted text identifier and transmitting it to the user terminal 16 of the public chain 4.
[0131] In the user terminal 16 of the public chain 4 that receives it in S268, in S269, a process is performed of calculating D KA (encrypted personal information)) or D R (encrypted personal information)) and replying to the user terminal of the private chain 2. Specifically, when the split common key KA stored in the HDD 12 of the user terminal 16 has already been updated to R, D R (encrypted personal information) is calculated and replied, but when it has not yet been updated to R, a process is performed of calculating D KA (encrypted personal information) and replying.
[0132] In the user terminal of the private chain 2 that receives the reply from the user terminal 16 of the public chain 4 in S270, in S271, a process is performed of calculating D KB (D KA (encrypted personal information)) = plaintext or D KB (D R (encrypted personal information)) ≠ plaintext. Specifically, when receiving D KA (encrypted personal information), D KB (D KA (encrypted personal information)) = D KB (D KA (E KA (E KB (personal information)))) = plaintext is calculated to obtain the plaintext personal information. On the other hand, (DR When receiving (encrypted personal information), D KB (D R (encrypted personal information)) = D KB (D R (E KA (E KB (personal information)))) ≠ plaintext will be calculated, and the plaintext personal information cannot be obtained. Thereby, it is possible to solve the dilemma in which the requirement to guarantee the deletion right of the information to be deleted and the impossibility of deletion are in antinomy.
[0133] Note that the server 18 of the certified operator 17 may be connected to the user terminals of the private chain 2 and the user terminals of the public chain 4 via the Internet 1 without participating in the blockchain as the node 19.
[0134] (3) In the above description, the split common key KA was held by the personal information owner (stored in the HDD 12 of the user terminal 16), but instead, the split common key KA may be registered in the key DB 32 of the key registration center 30, an example of a predetermined institution (third-party institution). Note that the split common key KA is stored in the key DB 32 in a confidential state. This modification example will be described with reference to FIGS. 24 to 27.
[0135] Referring to FIG. 24, the server 31 of the key registration center 30 is connected to the Internet 1. In the key DB 32 connected to the server 31, the ciphertext identifier and the split common key KA are stored in association with each address of the users who are the nodes 19 of the public chain 4. And if there is a request for making a record unreadable from the user, the split common key KA stored in association with the ciphertext identifier corresponding to the record for which the request was made is updated with a random number R. In FIG. 24, the split common key stored in association with the ciphertext identifier 307cd4 of the address 0x6079dd is updated with the random number 1R2, the split common key stored in association with the ciphertext identifier 4arb56 of the address 0x6080dd is updated with the random number 2Rn, and the split common key stored in association with the ciphertext identifier e2c87r of the address 0x6978dd is updated with the random number mR1.
[0136] Next, based on FIG. 25, a flowchart of the main routine of the user terminal 16 of the public chain 4, the server 31 of the key registration center 30, and the user terminal of the private chain 2 will be described. Regarding the common points with the second embodiment, repeated explanations will be omitted, and mainly the differences will be described.
[0137] In the user terminal 16 of the public chain 4, personal information recording processing on the blockchain is executed by S468, recording decryption incapability request processing is executed by S469, and decryption key providing processing is executed by S470. In the server 31 of the key registration center 30, key registration processing is executed by S463, recording decryption incapability processing is executed by S464, and data decryption processing is executed by S465. In the user terminal of the private chain 2, data acquisition processing is executed by S460.
[0138] Next, based on FIG. 26(A), a flowchart of the subroutine program of personal information recording processing and key registration processing on the blockchain will be described. In the user terminal 16 of the public chain 4, by S479, E KA (E KB (personal information)), E K2 (index + consideration for personal information provision), and the ciphertext identifier are recorded on the blockchain, and by S480, the process of transmitting the split common key KA and the ciphertext identifier to the key registration center 30 is performed. <m
[0139] In the server 31 of the key registration center 30 that received it at S474, by S475, the process of associating the received split common key KA and the ciphertext identifier and storing them in the key DB32 is performed.
[0140] Next, based on FIG. 26(B), the flowchart of the subroutine program for the unreadable recording request process and the unreadable recording process will be described. In the user terminal 16 of the public chain 4, it is determined by S494 whether there is a ciphertext to be made unreadable. If not, the process returns. If there is, the process of transmitting the ciphertext identifier for requesting unreadability to the server 31 of the key registration center 30 is performed by S495.
[0141] In the server 31 of the key registration center 30 that received it at S485, the process of searching for the split common key KA stored in association with the received ciphertext identifier from the key DB32 is performed. Next, a random number R is generated by S487, and it is determined by S488 whether the random number R = KA. If R = KA, the random number R is regenerated again by S487. When R ≠ KA, the process of updating the split common key KA to R is performed by S489.
[0142] Next, with reference to FIG. 27, the flowchart of the subroutine program for the split common key providing process, the data obtaining process, and the data decrypting process will be described. In the user terminal of the private chain 2, the process of transmitting the ciphertext identifier of the data to be obtained to the server 31 of the key registration center 30 is performed by S503. In the server 31 of the key registration center 30 that received it at S504, the process of searching for the ciphertext (encrypted personal information, etc.) corresponding to the ciphertext identifier from the blockchain is performed by S505. Next, the process of searching for the split common key KA or R corresponding to the ciphertext identifier is performed by S506.
[0143] Next, by S507, D KA (encrypted personal information) or D R (encrypted personal information) is returned to the user terminal of the private chain 2. Specifically, when the split common key KA stored in the key DB32 of the key registration center 30 has already been updated to R, D R (encrypted personal information) is calculated and returned. When it has not yet been updated to R, the process of calculating and returning D KA (encrypted personal information) is performed.
[0144] At the user terminal of the private chain 2 that received it at S509, at S510, D KA (D KB (encrypted personal information)) = plaintext or D KA (D R (encrypted personal information)) ≠ plaintext is calculated. Specifically, when D KA (encrypted personal information) is received, D KB (D KA (encrypted personal information)) = D KB (D KA (E KA (E KB (personal information)))) = plaintext is calculated to obtain the plaintext personal information. On the other hand, when (D R (encrypted personal information)) is received, D KB (D R (encrypted personal information)) = D KB (D R (E KA (E KB (personal information)))) ≠ plaintext is calculated, and the plaintext personal information cannot be obtained. Thus, it is possible to solve the dilemma in which the requirement to guarantee the deletion right of the information to be deleted and the impossibility of deletion are in antinomy. Moreover, since the process of updating the one-way common key KA to R is performed at the key registration center 30, it is easy to ensure the reliability that KA has been updated to R and the deletion right is guaranteed. For example, there is an advantage that it is easy to perform the update of KA to R under the supervision of a predetermined institution.
[0145] (4) As another method of solving the dilemma in which the requirement to guarantee the deletion right of the information to be deleted and the impossibility of deletion are in antinomy, E which is the encrypted personal information stored in the personal information DB 29 of the certified operator 17 KA (E KBIt may be possible to delete (personal information) in response to a request from the personal information owner. In that case, although the hash value of the personal information is recorded on the blockchain, there is a contradictory state where the corresponding personal information is not stored in the personal information DB29. However, if this contradiction can be tolerated, deleting personal information can also be an effective means.
[0146] (5) The information guaranteeing the right to delete is not limited to personal information. For example, it may be any information such as posting information to SNS or blogs (including data of posted photos and videos), notarized documents such as wills and testamentary guardianship contracts, private documents and articles of incorporation of companies, etc., which require a definite date. Also, in the second embodiment, the information guaranteeing the right to delete was recorded using the blockchain, but the blockchain is only an example, and other means may be used for recording.
[0147] (6) The aforementioned programs operating on the user terminals 16, etc. constituting the nodes 19 of each blockchain and various servers may be downloaded and installed from a predetermined website, etc. However, for example, they may be recorded on a recording medium (non-transitory recording medium) such as a CD-ROM 99 and distributed, and those who purchased the CD-ROM 99, etc. may install the program on the user terminal 16 and various servers (see Fig. 60).
[0148] (7) In the above description, two encryptions are performed by encrypting once with the split common key KA and then encrypting again with the split common key KB, and the ciphertext is converted to plaintext by two decryptions of decrypting once with the split common key KB and then decrypting again with the split common key KA. However, it is not limited to this, and multiple encryptions with the split common key KA or KB and multiple decryptions with the split common key KA or KB may be performed. Furthermore, the split common keys KA and KB are not limited to two, and three or more split common keys may be used.
[0149] Furthermore, the exclusive logical sum (exclusive OR) of the split common keys KA and KB is calculated to generate one key K (KA(+)KB = K), and the personal information is encrypted with that key K (E K (Personal Information)). The split common key KA is registered in the key DB32 of the key registration center 30, and the split common key KB is distributed to the requester of the personal information. The personal information owner who has received a request from the requester of the personal information transmits the encrypted personal information to the server 31 of the key registration center 30, and the requester of the personal information transmits the distributed split common key KB to the server 31 of the key registration center 30. At the server 31 of the key registration center 30, the exclusive logical sum (exclusive OR) of the received split common key KB and the split common key KA registered in the key DB32 is calculated to generate one key K (KA(+)KB = K), and the received encrypted personal information (E K (Personal Information)) is decrypted with that key K into plaintext (D K (E K (Personal Information)) = Plaintext), and the plaintext personal information may be transmitted to the requester of the personal information. The above (+) represents the exclusive logical sum (exclusive OR) in symbols.
[0150] Note that the exclusive logical sum (exclusive OR) is just an example, and any algorithm may be used as long as it generates one key K from the split common keys KA and KB.
[0151] Also, in the case of the above method of generating the key K using an additive group such as exclusive OR (XOR), there is an advantage that the split common keys KA and KB can be periodically updated to maintain security. For example, when one of the split common keys KA is updated to KC, the other split common key KB = K(+)KC, which can be obtained by calculation. By updating the split common keys KA and KB in this way, not only can we counter the leakage of the split common keys, but also prevent the personal information requester who has once distributed the split common key KB from decrypting the encrypted personal information on the blockchain again to prevent viewing. By performing such an update of the split common key for each distribution of the split common key KB, even if the person who received the distribution of the split common key KB leaks it to others, it is possible to make the encrypted personal information on the blockchain by the person who received the leakage undecipherable. That is, the distributed split common key KB can be made into a one-time key that can be used only once.
[0152] Also, it is not limited to the common key, and public key cryptosystems such as RSA and elliptic curve cryptography may be used.
[0153] Also, in realizing the above key update, an encryption algorithm that satisfies the following conditions may be adopted. Let the plaintext be M, its ciphertext be C, and the encryption keys be KA, KB, KC, and KD. E KA (E KB (M)) = E KC (E KD (M)) = C An algorithm for which the equation holds.
[0154] When such an algorithm is a symmetric key encryption algorithm, when the split symmetric keys KA and KB are updated to KC and KD, the plaintext M can be obtained by decrypting the ciphertext C recorded in the blockchain with the split symmetric keys KC and KD. On the other hand, in the case of a public key encryption algorithm, when the private keys KA and KB are updated to KC and KD, the plaintext M can be obtained by decrypting the ciphertext C recorded in the blockchain with the pair of public keys PKC and PKD corresponding to the private keys KC and KD. (8) In the above description, the information holder transmits the encrypted personal information (D KA (encrypted personal information)) or D R (encrypted personal information)) and the split symmetric key KB to the information requester (S201, S207), and the information requester himself / herself decrypts the encrypted personal information into plaintext using the split symmetric key KB (S209). However, the decryption using the split symmetric key KB may be performed by a third-party institution (a predetermined service institution). In this case, the information holder transmits the encrypted personal information (D KA (encrypted personal information)) or D R (encrypted personal information)) and the split symmetric key KB to a third-party institution (a predetermined service institution), and the third-party institution (a predetermined service institution) decrypts it and transmits it to the information requester. [Features of the disclosed content]
[0155] Next, the features of the disclosed content of the above-described embodiments are listed below. (Feature 1) [Technical field]
[0156] Feature 1 relates to a processing system and a program for an information recording method such as a blockchain that is difficult to tamper with or erase. [Background art]
[0157] The blockchain has been generally known as an information recording method that is difficult to tamper with or erase. For example, Japanese Patent Application Laid-Open No. 2018-128723 records various information related to cargo transportation using this blockchain. [Outline of Feature 1] [Problems to be Solved by Feature 1]
[0158] However, recording information using such a blockchain is not only difficult to tamper with but also difficult to delete (hereinafter referred to as "irretrievability"). As a result, once personal information is recorded using a blockchain, even if the personal information owner wishes to delete the personal information, it cannot be deleted, and there is a drawback that the right to delete personal information (so-called the right to be forgotten) is impaired.
[0159] That is, there is a drawback that an antinomy occurs in which the guarantee of the authenticity of the recorded information and the guarantee of the right to delete that information are in conflict.
[0160] Feature 1 was conceived in view of such circumstances, and its purpose is to resolve the antinomy in which the guarantee of the authenticity of the recorded information and the guarantee of the right to delete that information are in conflict. [Means for Solving the Problems]
[0161] The subject matter of Feature 1 is shown as items such as the following, for example. (Item 1) Encryption means (for example, S174, S177, or S228, S231, or S478, S479) that performs an encryption process to encrypt information to be recorded (for example, personal information), Recording means (for example, S177 and blockchain, or S231, S240, S242, S244, blockchain, and personal information DB29, or S479 and blockchain) that records the information after the encryption process, Decryption means (for example, S201, S202, S207 to S209, or S263 to S271, or S500 to S510) that performs a decryption process on the information recorded by the recording means using a first key and a second key to obtain plaintext information, Irretrievability means (for example, S191 to S194, or S250 to S254, or S494, S495, S485 to S489) that makes the information recorded by the recording means in an irretrievable state where it cannot be decrypted, and is provided with The decryption means includes a second key concealment holding means (for example, S194, or S233, or S475) that conceals and holds the second key (for example, the split common key KA). The decryption disabling means disables decryption by updating the second key held by the second key concealment holding means to another value (for example, a random number R) (for example, S190 - S194, or S250 - S254, or S494, S495, S485 - S489), processing system.
[0162] (Item 2) The decryption means further includes a first key distribution means (for example, S200, S201, or S2562, S263, or S500, S501) that distributes the first key (for example, the split common key KB) to the information viewer, the processing system according to Item 1. (Item 3) The processing system according to Item 1 or 2 further includes a search means (for example, S37 - S40, S42 - S45) that searches the information recorded by the recording means without decrypting it into plaintext.
[0163] (Item 4) The information recorded by the recording means includes personal information. The decryption disabling means disables the personal information of the personal information owner in response to the request of the personal information owner (for example, S190 - S194, or S250 - S254, or S494, S495, S485 - S489), the processing system according to any one of Items 1 - 3.
[0164] (Item 5) Steps of performing an encryption process for encrypting information to be recorded (for example, personal information) (for example, S174, S177, or S228, S231, or S478, S479), and A decryption step (e.g., S201, S202, S207 - S209, or S263 - S271, or S500 - S510) of performing decryption processing on the information recorded by a recording means (e.g., S177 and blockchain, or S231, S240, S242, S244, blockchain and personal information DB29, or S479 and blockchain) that records the information after the encryption processing to obtain plaintext information, A step (e.g., S191 - S194, or S250 - S254, or S494, S495, S485 - S489) of making the information recorded by the recording means in an undecipherable state where it cannot be decrypted, To be executed by a computer, The decryption step includes a step (e.g., S194, or S233, or S475) of concealing and holding the second key (e.g., split common key KA), The step of making it in the undecipherable state makes it in the undecipherable state by updating the second key held by the holding step with another thing (e.g., random number R) (e.g., S190 - S194, or S250 - S254, or S494, S495, S485 - S489), program.
[0165] (Effect of Feature 1) According to Feature 1, it is possible to resolve as much as possible the dilemma in which the guarantee of the authenticity of the recorded information and the guarantee of the deletion right of that information are in antinomy. (Feature 2) [Technical Field]
[0166] Feature 2 relates to, for example, a smart contract used in a blockchain or the like. [Background Art]
[0167] A smart contract is a computer protocol intended for smooth verification, condition confirmation, execution, enforcement, and negotiation of contracts, and has been conventionally used in blockchain and the like. Such smart contracts have been conventionally known as those that automate contracts, transactions, etc. (for example, Patent No. 6403177). [Summary of Feature 2] [Problem to be Solved by Feature 2]
[0168] In the field of such smart contracts, there is a demand for advanced smart contracts that can execute legal acts, such as various contracts represented by sales contracts and lease contracts, or various transactions, on behalf of the user himself / herself.
[0169] The object of Feature 2 conceived in view of such circumstances is to provide an advanced smart contract that can execute legal acts on behalf of the user himself / herself. [Means for Solving the Problem] The subject matter of Feature 2 is shown as items such as the following, for example. (Item 1) Machine learning means (for example, S80 to S82) that inputs information on legal acts performed by a plurality of natural persons or legal persons as data for machine learning to generate a general model, Means for personalizing the general model into a model suitable for the user, the personalizing means for personalizing based on information on legal acts performed by the user (for example, S86 to S88, or S94 to S98), Smart contract generation means (for example, S86 to S88, or S94 to S98) that generates a smart contract for executing a legal act on behalf of the user using the personalized model, a computer system comprising.
[0170] (Item 2) Means for personalizing a general model generated by inputting information on legal acts performed by a plurality of natural persons or legal persons as data for machine learning into a model suitable for a user, the personalizing means for personalizing based on information on legal acts performed by the user (for example, S80 to S82, S86 to S88, or S94 to S98), A computer system comprising smart contract generation means (for example, S86 to S88, or S94 to S98) for generating a smart contract for executing a legal act on behalf of the user using the personalized model.
[0171] (Item 3) Means for personalizing a general model generated by inputting information on legal acts performed by a plurality of natural persons or legal persons as data for machine learning into a model suitable for a user, the personalizing means for personalizing based on information on legal acts performed by the user (for example, S80 to S82, S86 to S88, or S94 to S98), A computer system comprising service providing means (for example, S99) for providing a service for executing a legal act on behalf of the user using the personalized model as a smart contract.
[0172] (Item 4) The computer system according to Item 3, further comprising reinforcement learning means (for example, S105 to S108) for learning a strategy for maximizing the accumulation of the reward by giving the reward for the legal act executed along with the provision of the service by the service providing means (for example, S99) to the executed model.
[0173] (Item 5) A computer system that performs simulations (such as stock trading and futures trading in the investment market, corporate management simulations, or consumer behavior simulations) in a computer for a predetermined theme (for example, assuming that policies or laws adopted by the government (such as reduced tax rates accompanying consumption tax hikes, revised immigration control laws, the UK's departure from the EU (European Union), partial or full adoption of basic income, amendment of Article 9 of the Japanese Constitution, etc.) are adopted) to advance reinforcement learning, Selection means (for example, S344, S345) for selecting a user group belonging to a plurality of personas that match the theme of the simulation, Collection means (for example, S346) for grouping the user group selected by the selection means for each of the plurality of personas and collecting information on legal acts performed by the user group for each group, Generation means (for example, S347) for performing machine learning using the collected information on legal acts as learning data to generate a group of learned smart contract models for each persona, Simulation means (for example, S336 - S339) for executing in a computer a simulation of performing legal acts between the generated group of learned smart contract models, comprising: The simulation means includes reinforcement learning means (for example, S336, S338) for giving a reward for the executed legal act to the learned smart contract model that executed it, so that the learned smart contract model learns a policy that maximizes the accumulation of the reward. A computer system.
[0174] (Item 6) A computer system that performs simulations in a computer to advance reinforcement learning, A computer system includes reinforcement learning means (for example, S336, S338) that performs simulation reinforcement learning processing. In this processing, simulations of performing legal acts are executed within a computer among a group of learned smart contract models generated by machine learning, and rewards for the executed legal acts are given to the learned smart contract models that executed them, so that the learned smart contract models learn strategies to maximize the accumulation of the rewards.
[0175] (Item 7) The computer system according to item 6 further includes selection means (for example, S340) that selects a learned smart contract model to be actually used based on the results of the reinforcement learning by the reinforcement learning means from among the group of learned smart contract models.
[0176] (Note) For the above-mentioned "data for machine learning" for general model generation and the "data for machine learning" used for personalization, it is sufficient if they contain "information related to legal acts", and they may also contain information other than "information related to legal acts" (for example, access history to websites, GPS location information, etc.). The above-mentioned "smart contract generation means" also includes, for example, cases where an artificial intelligence such as a personal assistant machine-learned from information related to legal acts is made to play the role of a smart contract.
[0177] (Effect of Feature 2) According to Feature 2, it becomes possible to provide an advanced smart contract that can execute various legal acts on behalf of the user himself / herself.
[0178] (Feature 3) [Technical Field] Feature 3 relates to a computer system that sets conditions such as policies and laws that the government is trying to adopt (for example, reduced tax rates associated with consumption tax increases, revised immigration control laws, the United Kingdom's withdrawal from the EU (European Union), partial or full adoption of basic income, amendment of Article 9 of the Japanese Constitution, etc.), marketing-related conditions (for example, setting prices and consideration for new products (including financial products and life insurance) and new services, promotion effects by various media, etc.), investment market-related conditions (for example, weather conditions in futures trading, monetary tightening policies in the stock market, etc.), and performs simulations in a computer under those conditions to predict in advance what simulation results will be obtained. [Background Art]
[0179] As this type of computer system, in order to clarify the liabilities that the nation should bear in the future and the resources that will be available in the future and support decision-making at the policy level, a new calculation account for changes in net assets has been set up to clarify the asset changes due to policy decisions in the current year and simulate the future burden on the nation. An accounting method has been proposed (for example, Japanese Patent Laid-Open No. 2006-155233). [Overview of Feature 3] [Problems to be Solved by Feature 3]
[0180] In such a simulation field, what is desired is a computer system that can execute a simulation in a computer that faithfully imitates the activities of natural persons and corporations in real society and derive a simulation result with as little deviation from the real world as possible.
[0181] In view of such circumstances, the purpose of Feature 3 is to enable a simulation that faithfully imitates the activities of natural persons and corporations in real society. [Means for Solving the Problems]
[0182] The subject of Feature 3 is shown as items such as the following, for example. (Item 1) A computer system that performs simulations in a computer under predetermined conditions (for example, policies and laws that the government is trying to adopt (such as reduced tax rates accompanying consumption tax increases, revised immigration control laws, the United Kingdom's withdrawal from the EU (European Union), partial or full adoption of basic income, amendment of Article 9 of the Japanese Constitution, etc.), marketing-related conditions (such as the setting of prices and consideration for new products (including financial products and life insurance) and new services, promotion effects by various media, etc.), investment market-related conditions (such as weather conditions in futures trading, monetary tightening policies in the stock market, etc.)), selection means (for example, S144, S145) for selecting a user group belonging to a plurality of personas that match the conditions of the simulation, collection means (for example, S146) for grouping the user group selected by the selection means for each of the plurality of personas and collecting information on legal acts performed by the user group for each group, generation means (for example, S147) for performing machine learning using the collected information on legal acts as learning data to generate a group of learned smart contract models for each persona, simulation means (for example, S136 - S139) for executing a simulation in a computer of performing legal acts between the generated groups of learned smart contract models, derivation means (for example, S140) for deriving the results of the simulation by the simulation means, and comprising, The simulation means includes reinforcement learning means (for example, S136, S138) for giving a reward for the executed legal act to the learned smart contract model that executed it, so that the learned smart contract model learns a strategy for maximizing the accumulation of the reward. A computer system.
[0183] (Item 2) A computer system that performs simulations in a computer, Performing a simulation in a computer of legal acts among a group of learned smart contract models generated by machine learning (e.g., S144 to S146), and giving a reward for the executed legal act to the learned smart contract model that executed it, thereby advancing reinforcement learning in which the learned smart contract model learns a strategy for maximizing the accumulation of the reward (e.g., S136, S138); A computer system comprising: derivation means (e.g., S140) for deriving the result of a simulation of performing legal acts among a group of learned smart contract models in which the reinforcement learning by the reinforcement learning means has advanced. (Effect of Feature 3)
[0184] According to Feature 3, it becomes possible to perform a simulation that faithfully imitates the activities of natural persons and corporations in the real world as much as possible. [Third Embodiment]
[0185] Next, the third embodiment will be described. This third embodiment relates to a system that performs a simulation by using the inside of a mirror world (cyberspace) composed of a digital twin of the real world (real world) as a simulation environment, for example, derives an optimal solution for predicting the future, derives an optimal solution for incentive design in a DAO (Decentralized Autonomous Organization), or performs machine learning (e.g., reinforcement learning) of AI.
[0186] A digital twin is a digital representation of a real-world entity or system. A mirror world is a mirrored world composed of digital twins in which all information in the physical world (real world), such as a real country, city, society, local government, company, and other organizations and people, is digitized. Specifically, a digital twin of a person is composed of an assistant AI (hereinafter referred to as "personal AI") that acquires, as knowledge, a life log such as the actions of the person (both real and virtual actions) and performs machine learning (for example, reinforcement learning by an agent) to assist the person in performing optimal actions. This reinforcement learning is multi-agent reinforcement learning in which multiple personal AIs cooperate to perform reinforcement learning. The digital twin of an organization such as a company in the real world is composed of the personal AIs of the people who make up the organization, the digital twin of a local government in the real world is composed of the personal AIs of the people who make up the local government, the digital twin of a city in the real world is composed of the personal AIs of the people who make up the city, and the digital twin of a country in the real world is composed of the personal AIs of the people who make up the country.
[0187] In this third embodiment, a mechanism is prepared such that a mirror world as a simulation environment is constructed by the active participation and cooperation of real countries, cities, societies, local governments, companies, and other organizations and people in the real world. Specifically, by performing various simulations within the mirror world, the personal AIs of the digital twins participating in the simulation are made to perform machine learning (for example, reinforcement learning), and the learned personal AIs that have learned more highly are restored (fed back) to the real world. Using the enjoyment of this merit as an incentive, organizations and people such as countries, cities, societies, local governments, and companies in the real world are encouraged to take the lead in participating and cooperating in the construction of the mirror world.
[0188] Referring to FIG. 28, in a data center 45 where a plurality of mirror world servers (including storage servers) 46 are installed, data of the mirror world is stored. Since the hardware configuration of the mirror world server 46 is the same as that of the user terminal 16 shown in FIG. 1, illustration and description thereof are omitted here to avoid repetition. The entire mirror world 51, which is composed of digital twins (real country digital twins (e.g., Japan digital twin 53), city digital twins 54, society, local governments, organizations such as companies, people, and the Earth digital twin 52) in which information on real countries (e.g., Japan 49), cities 50, society, local governments, organizations such as companies, people, and the Earth 48 in the real world 47 are all digitized, is stored in the data center 45 as digital data.
[0189] In the data center 45, simulations are performed using this mirror world 51 as a simulation environment. For example, optimal solutions foreseeing the future are derived through simulation optimization. Examples of simulations include trading simulations in investment markets such as stock trading and futures trading, company management simulations, or consumer behavior simulations, assuming that the policies and laws (e.g., reduced tax rates associated with consumption tax hikes, revised immigration control laws, the United Kingdom's withdrawal from the EU (European Union), partial or full adoption of basic income, amendment of Article 9 of the Japanese Constitution, etc.) that the government is attempting to adopt are adopted. Furthermore, simulations of promotions of new products (including financial products and life insurance) and new services through various media may also be possible. The optimal solutions derived through simulation optimization are fed back (restored) to the real world to provide the benefits of the optimal solutions to the real world. Also, the learned personal AI machine-learned (e.g., reinforcement learning) through simulation is restored to the real world so that tasks can be performed by a more advanced learned personal AI.
[0190] The cooperation between this personal AI and the smart contract constitutes the AI smart contract of the cooperation type described above. The data center 45 is connected to the Internet 1 shown in FIGS. 1 and 24. In FIG. 28, various blockchains 2, 3, 4, SNS 19, key registration center 30, etc. are not shown.
[0191] FIG. 29 shows a specific example of the urban digital twin 54 in the mirror world 51. In the city 50 of the real world 47, there are ABC Co., Ltd. 56, Taro 55 who is a person, and Taro's family 56, etc. In the corresponding urban digital twin 54, there are also ABC Co., Ltd. digital twin 59, Taro digital twin (Taro's personal AI) 57, and Taro's family digital twin 58, etc. The urban digital twin data composed of these data is stored in the mirror world server 46. If there are any changes (for example, personnel changes, employment, or resignation in the company, marriage, childbirth, etc. for a person) to various objects such as ABC Co., Ltd. 56, Taro 55, and Taro's family 56 in the real world 49, the corresponding various digital twins will be updated to the changed content. Such urban digital twin data is stored in the data center 45 for each city to become the data of the digital twin 53 of Japan, and the urban digital twin data in each country is stored in the data center 45 for each city to become the digital twin data of each country, and all these digital twin data together become the data of the digital twin 52 of the earth 48.
[0192] As a specific example, the Mirror World Server 46 stores, as the Taro Digital Twin (Taro's Personal AI) 57, the name: Taro, AI identification number: 82km9, Personal AI data, and Taro's personal data (e.g., life log, profile, preference data, electronic medical record data, vital data, etc.). As the Taro's Family Digital Twin 58, the names: Taro, Sakura, Shiro, family composition: husband, wife, eldest son, AI identification numbers: 82km9, 11zk9, gf43y are stored. As the ABC Co., Ltd. Digital Twin 59, the names: Taro, Hanako... Saburo, positions: representative director, managing director, department head... ordinary employee, AI identification numbers: 82km9, ba935, 2es14,... 9w1c2 are stored.
[0193] The flowchart of the main routine program between the user terminal 16 and the Mirror World Server 46 will be described based on FIGS. 30 to 33. Referring to FIG. 30A, the CPU 10 of the user terminal 16 executes a member registration request process S555 for requesting registration to participate in the Mirror World 51 as a simulation environment, a simulation preparation response process S556, and a simulation response process S557. The CPU 10 of the Mirror World Server 46 executes a member registration process 550, a simulation preparation process S551, and a simulation process S552.
[0194] The member registration process and the member registration request process will be described based on FIG. 30B. These two processes are for registering members who want to participate as digital twins in a simulation with the mirror world 51 as the simulation environment. In the member registration request process, the CPU 10 of the user terminal 16 determines whether to submit a registration application according to S560. If it is determined not to submit a registration application, this member registration process ends and returns. If it is determined to submit a registration application, in S561, it sends the predetermined matters required for the registration application to the mirror world server 46, and if there is a person without a personal AI, it also sends the fact and the person's blockchain address to the mirror world server 46. The predetermined matters required for the registration application are specifically, in the digital twin of a person, the AI identification number and personal AI data of the person's personal AI, in the digital twin of a family, the family name, family composition, and each AI identification number, and in the digital twin of a company, the names, positions, and each AI identification number of the employees, etc.
[0195] The CPU 10 of the mirror world server 46 that receives it by S565 determines in S566 whether it already owns a personal AI. If the information "not having a personal AI" is included in the information sent by S561, the control proceeds to S567 to perform the generation and sales process of the personal AI. If the information "not having a personal AI" is not included, the control proceeds to S568 to register the predetermined matters including the AI identification number sent by S562 in the mirror world 51.
[0196] The generation and sales process of the personal AI shown in S567 will be described based on FIG. 31. The CPU 10 of the mirror world server 46, in S573, collects the transaction data recorded in the blockchain address (the blockchain address of a user who does not have a personal AI) received in S565 and the posted data such as SNS from the blockchain. Next, in S574, machine learning is performed using the transaction data and the posted data such as SNS as learning data to generate a learned personal AI. Next, in S575, the learned personal AI is sold to the corresponding user.
[0197] The simulation preparation process shown in S551 and the simulation preparation response process shown in S555 will be described based on FIG. 32. The CPU 10 of the mirror world server 46 determines in S577 whether a simulation request has been received. If it is determined that no request has been received, this simulation preparation process ends and returns. If it is determined that a simulation request has been received, the control proceeds to S578, and a process of identifying a group of personal AIs and digital twins that match the requested simulation is performed. For example, in the case of a consumption behavior simulation under a reduced tax rate accompanying the aforementioned consumption tax increase, a group of personal AIs corresponding to general consumers, a group of personal AIs according to the ratio according to demographics such as gender, age, region, annual income, etc., and a manufacturer digital twin or a store digital twin of consumer goods subject to the reduced tax rate are identified. Next, a process of requesting consent for the simulation is performed to the identified group of personal AIs and digital twins. Specifically, the content of the simulation is transmitted to each user terminal 16 of the user group corresponding to the identified group of personal AIs and digital twins, and it is asked whether to consent.
[0198] The CPU 10 of each user terminal 16 corresponding to the cut-out personal AI group and the user group corresponding to the digital twin receives the content of the transmitted simulation at S580, and at S581, determines whether to agree to participate in the execution members of the simulation. This determination may be made by the personal AI or by the user himself / herself. If it is determined not to agree, this simulation preparation response process ends and returns. If it is determined to agree, at S582, a reply indicating agreement is sent back to the mirror world server 46.
[0199] The CPU 10 of the mirror world server 46 that receives it at S583 determines whether the required amount of consent has been obtained to execute the requested simulation. If it is determined that the consent has been obtained, at S584, the agreed-upon AI group and digital twin are copied and registered in the mirror world 51 as the simulation targets. The registered state is shown in FIG. 29 described above.
[0200] On the other hand, if it is determined that consent has not been obtained from the necessary personal AI group and digital twin, the control proceeds to S585, and a process of setting a persona group (including personas corresponding to the digital twins of manufacturers and retailers) that matches the insufficient personal AI group and digital twin is performed. At S586, the user group (including the user group engaged in manufacturers and retailers) belonging to each persona is selected. At S587, the user groups belonging to each persona are group-pinged, and the transaction data (including transaction data as manufacturers and retailers) of the user groups are collected from the blockchain for each group. At S588, machine learning is performed using the transaction data as learning data to generate and supplement the learned personal AI group and digital twin for each persona, and then the process proceeds to S584. These S585 to S588 are the same processes as S344 to S347 in FIG. 9(B), and the repeated detailed description is omitted here.
[0201] Next, the specific control of the simulation process shown in S552 and the simulation response process shown in S557 will be described based on FIG. 33. S593 to S595 are the same processes as S336, S338, S339 in FIG. 9 and S136, S138, S139 in FIG. 12 described above, and detailed descriptions thereof are omitted here. In S596, the simulation result is notified to the requester of the simulation. Specifically, the simulation result is transmitted to the user terminal 16 of the simulation requester. Next, in S597, each personal AI (including the personal AI engaged in the digital twin of a company organization, etc.) used in the simulation is transmitted to the user terminal 16 of each holder.
[0202] The CPU 10 of the user terminal 16 that received it at S598 determines at S599 whether to delete the received personal AI. The received personal AI is a learned AI that participated in the simulation and was reinforced (machine-learned), and its performance has been improved accordingly, enabling it to execute advanced task processing. However, depending on the content of the simulation, there may be cases where the user has received reinforcement (machine learning) that they do not desire. In such cases, it is determined as YES at S599, and at S601, the received personal AI is deleted. On the other hand, if the simulation is the content desired by the user and it is determined that the received personal AI has received desirable reinforcement (machine learning), the control proceeds to S600, and the received learned personal AI is overwritten and saved. As a result, the user has the advantage of being able to obtain a personal AI with improved performance through desirable reinforcement (machine learning). By using the enjoyment of this advantage as an incentive, organizations and people such as real-world countries, cities, societies, local governments, companies, etc. can be encouraged to take the lead and participate in the construction of the mirror world. By overwriting and saving the personal AI by S600, in the mirror world server 46, the data is updated to the digital twin of the new personal AI and the digital twin of the organization consisting of the new personal AI after overwriting and saving (see Figure 29). Note that instead of overwriting and saving, both the existing personal AI and the learned personal AI may be stored together and used appropriately as needed.
[0203] Next, a system for deriving the optimal solution of the incentive design in a DAO by performing a simulation with the mirror world as a simulation environment will be described based on FIGS. 34 to 59. FIG. 34(A) is a schematic diagram of a multi-service DAO construction system. For example, Bitcoin is a type of DAO, but the nodes (miners) are only responsible for one type of service, mining (competition for the right to record transactions). By giving the incentive of awarding Bitcoin to those who succeed in mining, blocks are added, and the Bitcoin system continues autonomously. In contrast, a DAO with multiple types of services is called a multi-service DAO. For example, in the case of a DAO of a company organization, there are multiple services such as procurement of materials, assembly, promotion, and sales. It is a difficult problem to determine what ratio and how much reward should be distributed to the nodes that execute these multiple services for an optimal incentive design. A system for deriving the optimal solution of the incentive design in such a multi-service DAO will be described.
[0204] Referring to FIG. 34(A), the mirror world server 46 that stores multi-service DAO data stores the data of the DAO agent 61, the persona agent group 62 that performs service 1, the persona agent group 63 that performs service 2, ··· the persona agent group 64 that performs service n. Further, the mirror world server 46 also stores the types of rewards r1, r2, ··· rn given to each persona agent group along with reinforcement learning.
[0205] The terminal 16 of the multi-service DAO constructor downloads and installs the DAO agent 61, the necessary persona agent group, and the types of rewards r1, r2, ··· rn from the mirror world server 46. The terminal 16 is each node 19 that constitutes the public chain 4. A digital twin 66 of the multi-service DAO 65 operating on the public chain 4 composed of each of these nodes 19 performs simulation reinforcement learning in the mirror world 51 to derive the optimal solution for incentive design in the multi-service DAO. The optimal solution for the incentive design is applied to the actual multi-service DAO 65 in the real world 47 to create a multi-service DAO 65 with an optimal incentive design. The simulation reinforcement learning in this mirror world 51 is executed on the mirror world server 46. Its control will be described below.
[0206] Referring to FIG. 34(B), the CPU 10 of the terminal 16 performs simulation reinforcement learning preparation response processing in S606 and simulation reinforcement learning response processing in S607.
[0207] The CPU 10 of the mirror world server 46 performs simulation reinforcement learning preparation processing in S611, simulation reinforcement learning processing in S612, and DAO agent reinforcement learning processing in S613.
[0208] The specific controls of the simulation reinforcement learning preparation process shown in S611 and the simulation reinforcement learning preparation response process shown in S606 will be described based on FIG. 35. In the simulation reinforcement learning preparation response process, the CPU 10 of the terminal 16 determines in S615 whether to request simulation reinforcement learning. If not, this simulation learning preparation response reinforcement process ends and returns. If a request is made, the control proceeds to S616, and the multi-service DAO data is sent to the mirror world server 46 for request. This multi-service DAO data includes the types of services. For example, in the case of the innovation induction DAO described later in FIGS. 36 to 42, there are five types of services: idea generation, improvement proposal, commercialization, infringement discovery, and token purchase, and these services are sent.
[0209] The CPU 10 of the mirror world server 46 that receives it in S620 sets a persona group that matches each of the multi-services in S621. For example, in the case of the above innovation induction DAO, people who are good at coming up with inventions can be used as the persona group for idea generation and improvement proposal, people interested in commercialization can be used as the persona group for commercialization, people familiar with patent law and copyright law can be used as the persona group for infringement discovery, and people interested in investment can be used as the persona group for token purchase, etc.
[0210] Next, in S622, a user group belonging to each persona is selected. For example, in the case of the above innovation induction DAO, the user group published as the inventor of the patent application can be used as the user group belonging to the persona group for idea generation and improvement proposal, the user group of company managers can be used as the user group belonging to the persona group for commercialization, the user group of lawyers and attorneys can be used as the user group belonging to the persona group for infringement discovery, and the user group that has purchased virtual currencies such as Bitcoin can be used as the user group belonging to the persona group for token purchase, etc.
[0211] Next, in S623, for each persona, group-ping the user groups to which they belong, collecting the transaction data of the user groups for each group from the blockchain, and in S624, performing machine learning using the transaction data as learning data to generate a learned persona agent group for each persona. These two controls are the same processes as S346 and S347 in FIG. 9(B) described above, and the repeated detailed description is omitted here. Next, in S625, deploy the persona agent group into the multi-service DAO 65 to generate a multi-service DAO digital twin 66, and register it in the mirror world 51 as the simulation target. The state is shown in FIG. 36.
[0212] Referring to FIG. 36, construct a digital twin 66 of the multi-service DAO 65 composed of a public chain in the mirror world 51. In the multi-service DAO digital twin 66, the persona agent group is deployed in S625 above, and one persona agent is deployed for each node. The identification numbers of these persona agents are classified for each service (idea proposal, improvement proposal, commercialization, infringement discovery, token purchase) and stored in the mirror world server 46. For example, as the identification numbers of the persona agents for the idea proposal service, kc29m, 1w13a, ··· 9nad8 are stored in the mirror world server 46. This multi-service DAO 65 is the innovation-inducing DAO described above, and hereafter, the multi-service DAO will be described taking the innovation-inducing DAO as an example.
[0213] Furthermore, the mirror world server 46 also stores a DAO agent that gives rewards (incentives) for the actions of each persona agent. By performing reinforcement learning (machine learning) on the distribution ratio and amount of the rewards given by this DAO agent, the optimal solution of the incentive design is derived. The schematic system of the reinforcement learning (machine learning) is shown in FIG. 37.
[0214] Referring to FIG. 37, if the persona agent group performs the original idea submission as actions a11, a12, ··· a1n, the state S1 of the environment is input to the DAO agent 61, and rewards r11, r12, ··· r1n are given to the persona agent group 67 that has performed those idea generation services. This idea generation service is a broad concept that includes the generation of dreams, ideas, business plans, technical concepts, works, etc. The state S1 of the environment is also given to the persona agent group 67 that has performed the idea generation service. This state S1 of the environment is, for example, the content of the original idea submission, the price of the fluctuating market of token A1 given as a reward to each of the persona agents 68 that have performed the idea generation service, etc.
[0215] If the persona agent group 68 performs actions a21, a22, ··· a2 such as submitting improvement plans for the above original idea, the state S2 of the environment is input to the DAO agent 61, and rewards r21, r22, ··· r2n are given to the persona agent group 68 that has performed those improvement plan services. The state S1 of the environment is also given to the persona agent group 68 that has performed the improvement plan service. This state S2 of the environment is, for example, the content of the improvement plan submission, the number of "likes" given to the improvement plan submission, etc. The entity that gives this "like" is limited, for example, to only those who have purchased token A1 given as a reward for the submission of the above original idea (persona agent group 71). The reason for limiting (restricting) the entity that gives the "like" to interested parties (stakeholders) in this way is to prevent fraud. When the entity that gives the "like" is expanded without limit, for example, it is to prevent fraud such as the person who submitted the improvement plan (persona agent group 68) colluding with a large number of people (persona agents) to get a large number of "likes". The entity that gives the "like" to the persona agent group 69 that has performed the commercialization service and the persona agent group 70 that has performed the infringement handling service is also limited to only those who have purchased token A1 (persona agent group 71) for the same reason.
[0216] If the group of persona agents 69 that have provided commercialization services for the above-mentioned original idea perform actions a31, a32, ··· a3n, the state of the environment S3 is input to the DAO agent 61, and rewards r31, r32, ··· r3n are given to the group of persona agents 69 that have provided these commercialization services. As the actions a31, a32, ··· a3n of the group of persona agents 69, for example, submission of a business plan, submission of the progress of commercialization, submission of the actual situation of commercialization implementation, submission of the amount of profit from the commercialized business, etc. can be considered. The state of the environment S3 is also given to the group of persona agents 69 that have provided commercialization services. This state of the environment S3 is, for example, the number of "likes" given to submissions such as the submission of a business plan, the submission of the progress of commercialization, and the submission of the amount of profit from the commercialized business.
[0217] If the group of persona agents 70 that have provided infringement handling services for the above-mentioned original idea perform actions a41, a42, ··· a4n, the state of the environment S4 is input to the DAO agent 61, and rewards r41, r42, ··· r4n are given to the group of persona agents 70 that have provided these infringement handling services. As the actions a31, a32, ··· a3n of the group of persona agents 70, for example, submission of a report on infringement discovery, submission of a report on infringement handling, submission of a report on license negotiation, etc. can be considered. Furthermore, it may also include submission of a report on patent applications that are the premise of these services and submission of a report on the establishment of their rights. The state of the environment S4 is also given to the group of persona agents 70 that have provided infringement handling services. This state of the environment S4 is, for example, the number of "likes" given to submissions such as the submission of a report on infringement discovery, the submission of a report on infringement handling, and the submission of a report on license negotiation.
[0218] If the persona agent group performs the services of purchasing token A1 assigned to the above-mentioned idea proposal service of the origin as actions a51, a52, ··· a5n, the state S5 of the environment is input to the DAO agent 61, and rewards r51, r52, ··· r5n are given to the persona agent group 71 that has performed those token purchase services. The state S5 of the environment is also given to the persona agent group 71 that has performed the token purchase service. This state S5 of the environment is, for example, the number of tokens purchased (or the purchase amount). The persona agent group 71 consumes virtual currency (such as ETH of Ethereum, etc.) to purchase token A1. Note that the purchased tokens can be converted (cashed in) into virtual currency according to the price in the fluctuating market, and that virtual currency can be converted (cashed in) into legal currency such as yen or dollars according to the price in the fluctuating market.
[0219] The rewards r1 to r5 given to each persona agent group are determined by the DAO agent 61 based on the reward table (see Fig. 39(A)). For the persona agent that has performed the idea proposal service, r1 = A1 + B1·b + G1·g; for the persona agent that has performed the improvement service, r2 = A2·e + B2·b + G2·g; for the persona agent that has performed the commercialization service, r3 = A3·e + B3·b; for the persona agent that has performed the infringement countermeasure service, r4 = A4·e + B4·b + G4·g; for the persona agent that has performed the token purchase service, r5 = B5·b + G5·g.
[0220] Here, A2 to A4, B1 to B5, G1, G2, G4, G5 are coefficients, and the DAO agent 61 converges to the optimal ones by reinforcement learning. A1 is a token, g is the license income, e is the number of "likes", and b is the commercialization profit.
[0221] Note that only the license income g or the commercialization income b generated after each persona agent group 68 to 71 has performed its services is considered as the rewards r2 to r5. This is to prevent improper acts such as performing improvement services or token purchase services after the license income g or the commercialization income b has already occurred for the original idea.
[0222] In addition, the persona agent group that has performed improvement services, commercialization services, or infringement handling services may also perform token purchase services together. Furthermore, the persona agent group 67 that has performed idea proposal services may also perform improvement services, commercialization services, or infringement handling services together.
[0223] The details of the DAO agent reinforcement learning process shown in S613 will be described based on FIG. 38. This process is for the DAO agent 61 to perform reinforcement learning by itself to optimize the rewards r1 to r5. In S630, the DAO agent 61 determines whether it has received each action a of the persona agent group. If not, it proceeds to S632, but if it determines that it has received it, the control proceeds to S631 and stores each received action a.
[0224] In S632, it is determined whether "like" has been given. If not, it proceeds to S634, but if it determines that "like" has been given, in S633, the "like" e is stored for each persona agent. In S634, it is determined whether there is commercialization income. If not, it proceeds to S636, but if it determines that there is, in S635, the commercialization income b is stored. In S636, it is determined whether there is license profit g. If not, it proceeds to S638, but if it determines that there is, in S637, the license profit g is stored.
[0225] In S638, it is determined whether it is the reward calculation time. If not, the process proceeds to S640. If it is determined that it is the time, in S639, each reward r1 to r5 is calculated by referring to the reward table (Fig. 39(A)) and is given to the corresponding persona agent. In S640, it is determined whether it is the learning update time. If not, this DAO agent reinforcement learning process ends and returns. If it is determined that it is the learning update time, in S641, the total grant price TT of the token A1 given as a reward and the current total price TB in the fluctuating market price of the given token are calculated. In S642, the reward R of the DAO agent is calculated from the value of TB / TT. For example, the value of TB / TT at the previous learning update and the value of TB / TT at the current learning update are compared. If the value of TB / TT at the current learning update is larger, a larger reward R is set; if it is smaller, a smaller reward R is set. As a result, the reward R that the DAO agent 61 can obtain becomes larger if the total price TB in the fluctuating market price of the token rises, and becomes smaller if the total price TB in the fluctuating market price of the token falls.
[0226] Next, in S643, based on the reward R, a process of obtaining actions A1 to A4, B1 to B5, G1, G2, G4, G5 according to the optimal policy π * by TD learning is performed. In S644, A1 to A4, B1 to B5, G1, G2, G4, G5 in the reward table are updated to the obtained actions A1 to A4, B1 to B5, G1, G2, G4, G5. As a result, the DAO agent 61 learns the optimal actions A1 to A4, B1 to B5, G1, G2, G4, G5 for increasing the total price TB in the fluctuating market price of the token. Note that this learning goal is just an example, and other learning goals may include increasing the number of submissions of original ideas, increasing the total number of submissions of original ideas and improvement plans, increasing the number of commercialization cases, increasing the total commercialization revenue, etc.
[0227] Next, in S645, it is determined whether the reinforcement learning has been completed. If it has not been completed yet, return. If it is determined that the learning has been completed, in S646, the learned multi-service DAO is sent to the requester of the simulation reinforcement learning.
[0228] The requester of the simulation reinforcement learning can operate the learned multi-service DAO (innovation-inducing DAO) 65 with an optimized incentive design in the real world 47. As a result, in this multi-service DAO (innovation-inducing DAO) 65, the "persona agent groups 67 to 71" shown in FIG. 37 become the actual user group, and the reward (incentive) optimally designed by the learned DAO agent 61 is distributed to the user group performing each service. At the stage of actual operation in this real world 47, the services such as each posted content and the trading content of tokens, etc. are recorded on the blockchain with a timestamp. As a result, the blockchain serves as a notary for the original idea posting content and improvement plan posting content, and it also becomes easier to apply the exception for loss of novelty (Article 30 of the Patent Law) and countermeasures against fraudulent applications (Article 49, Paragraph 1, Line 7, Article 74, Article 123, Paragraph 1, Item 2) of the Patent Law.
[0229] Also, even when operating the multi - service DAO (Innovation - inducing DAO) 65 in the real world 47, the DAO agent 61 may continue to perform machine learning (reinforcement learning), so that the incentive design becomes even more optimized to match the actual operating situation. Note that each learned persona agent group 67 - 71 (the learned persona agent group according to FIGS. 40(A)(B) and FIGS. 41(A)(B)) may also be included in the multi - service DAO (Innovation - inducing DAO) 65 and sent to the requester of simulation reinforcement learning, and each persona agent group 67 - 71 may function as a consultant for the user group performing each service. Furthermore, when operating the multi - service DAO (Innovation - inducing DAO) 65 in the real world 47, it may be a mixed - type multi - service DAO 65 in which both the user group and each persona agent group 67 - 71 execute each service, or it may be a persona - agent - operated multi - service DAO (Innovation - inducing DAO) 65 in which each service is executed only by each persona agent group 67 - 71. Note that this innovation - inducing DAO is not limited to being generated through the simulation reinforcement learning in the aforementioned mirror world, and may be artificially generated based on other methods, for example, artificial design. Furthermore, it may not be limited to a DAO, but may be an organization with a specific administrator or entity (for example, an ordinary stock company, etc.).
[0230] Next, based on FIG. 39(B), the main routine of the process in which the persona agent performs reinforcement learning will be described. In S648, the idea - proposal service execution process is performed. In S649, the improvement service execution process is performed. In S650, the commercialization service execution process is performed. In S651, the infringement - countermeasure service execution process is performed. In S652, the token - purchase service execution process is performed.
[0231] The details of the idea proposal service execution process shown in S648 will be described based on FIG. 40(A). In S655, it is determined whether to make an idea proposal. If not, the process returns. If it is determined to make an idea proposal, in S656, a process of creating an idea is performed. This creation of an idea uses, for example, an AI called DABUS. For example, the persona agent 67 and DABUS collaborate to create an idea. In S657, the submission content of the idea proposal is generated, and in S658, the idea proposal submission act a1i is executed.
[0232] In S659, it is determined whether the reward r1i has been received from the DAO agent 61. If not, the process returns. If it is determined that the reward has been received, in S660, based on the reward r1i, the optimal policy π * is obtained by TD learning. This act a will repeat and continue the act of making an idea proposal if the received reward r1i is satisfactory. However, if the reward r1i is not satisfactory, other acts (for example, improvement service, commercialization service, infringement handling service, token purchase service, or not performing any service) will be selected.
[0233] The details of the improvement service execution process shown in S649 will be described based on FIG. 40(B). In S664, it is determined whether to submit an improvement plan. If not, the process returns. If it is determined to submit, in S665, a process of creating an improvement plan is performed. The creation of the improvement plan uses, for example, an AI called DABUS. For example, the persona agent 68 and DABUS collaborate to perform the process of creating an improvement plan. In S666, the submission content of the improvement plan is generated, and in S667, the improvement plan submission act a2i is executed.
[0234] In S668, it is determined whether the reward r2i has been received from the DAO agent 61. If not, the process returns. If it is determined that the reward has been received, in S669, based on the reward r2i, the optimal policy π *Request for action a according to this. If the received reward r2i is satisfactory, the act of submitting improvement proposals will be repeated and continued. However, if the reward r2i is not satisfactory, other actions (for example, idea generation service, commercialization service, infringement handling service, token purchase service, or no service at all) will be selected.
[0235] The details of the commercialization service execution process shown in S650 will be described based on FIG. 41(A). In S674, it is determined whether to commercialize. If not, return. If it is determined to commercialize, in S675, a business plan is generated. In S676, the act of submitting the business plan a3i is executed. In S677, the commercialization service is performed. In S678, the act of submitting the execution status a3i is executed. This act of submitting the execution status a3i also includes the submission of the profits obtained from the above-mentioned commercialization.
[0236] In S679, it is determined whether the reward r3i has been received from the DAO agent 61. If not, return. If it is determined that it has been received, in S680, based on the received reward r3i, the optimal policy π * Request for action a according to this. If the received reward r3i is satisfactory, the act of providing the commercialization service will be repeated and continued. However, if the reward r3i is not satisfactory, other actions (for example, idea generation service, improvement service, infringement handling service, token purchase service, or no service at all) will be selected.
[0237] The details of the infringement handling service execution process shown in S651 will be described based on FIG. 41(B). In S684, it is determined whether to execute the infringement handling service. If not, the process returns. However, if it is determined to execute, in S685, an investigation of the infringement act is conducted, and in S686, it is determined whether the infringement act has been discovered. Note that before conducting the investigation of the infringement act, as described above, patent applications or acts of obtaining patent rights may be carried out. If the infringement act is not discovered, the process returns. However, if it is determined that the infringement act has been discovered, in S687, a warning letter to the suspected infringer is generated, in S688, the warning letter submission act a4i is executed, in S689, infringement handling acts a4i such as negotiation with the suspected infringer are carried out, and in S690, the execution status submission act a4i is executed.
[0238] Next, in S691, it is determined whether the reward r4i has been received from the DAO agent 61. If not received, the process returns. If it is determined that it has been received, in S692, based on the received reward r4i, the optimal policy π * is obtained according to the TD learning. This act a will repeat and continue the act of the commercialization service if the received reward r4i is satisfactory. However, if the reward r4i is not satisfactory, other acts (for example, idea proposal service, improvement service, commercialization service, token purchase service, or no service at all) will be selected.
[0239] Next, the details of the token purchase service execution process shown in S652 will be described based on FIG. 42(A). In S969, it is determined whether to purchase a token. If not, the process returns. If it is determined to purchase, in S697, the token purchase act a5i is executed. Next, in S698, it is determined whether the reward r5i has been received from the DAO agent 61. If not received, the process returns. If it is determined that it has been received, in S699, based on the received reward r5i, the optimal policy π *Demand act a in accordance with this. If the received reward r5i is satisfactory, the act of commercialization service will be repeated and continued. However, if the reward r5i is not satisfactory, other acts (for example, idea proposal service, improvement service, commercialization service, infringement handling service, or no service at all) will be selected.
[0240] Based on FIG. 42(B), explain the price fluctuation in the fluctuating market of token 72 accompanying the purchase of tokens by persona agent group 71. 50 tokens (total market value of 50,000 yen) 72 are given as reward A1 to persona agent 67 that has performed idea proposal service. A part of the tokens 72 (10 tokens) is purchased by persona agent 71a by paying virtual currency equivalent to 10,000 yen. Next, 10 tokens are purchased by persona agent 71b by paying virtual currency equivalent to 15,000 yen. As a result, the value of 10 tokens soars to 15,000 yen. Persona agent 71c purchases it by paying virtual currency equivalent to 20,000 yen. As a result, the value of 10 tokens soars to 20,000 yen. Persona agent 71d purchases it by paying virtual currency equivalent to 25,000 yen. As a result, the value of 10 tokens soars to 25,000 yen. Persona agent 71e purchases it by paying virtual currency equivalent to 30,000 yen. As a result, the value of 10 tokens soars to 30,000 yen.
[0241] As a result, the 40 tokens (total market value of 40,000 yen) held by persona agent 67 soar to a total market value of 120,000 yen. These tokens soar in direct proportion to the expected value, becoming higher for more popular original ideas, higher for more popular (with more likes) improvement proposals being submitted, higher for more popular (with more likes) commercializations being submitted, and higher for more popular (with more likes) infringement handling being submitted.
[0242] When actually operating the multi-service DAO 65 in the real world 47, as described above, the "persona agent groups 67 to 71" in FIG. 37 become the user group in the real world. In that case, not only the tokens 72 given to the user group that proposed ideas but also the tokens of the users themselves who perform various services (hereinafter referred to as "my tokens") may be bought and sold. When other users who viewed the posted service content expect the poster to purchase the poster's own my tokens, the price of the tokens in the fluctuating market soars. In this case, a part of the poster's income may be distributed to the token purchasers at a rate corresponding to the purchase amount. These tokens may be issued within the multi-service DAO 65, but they may be linked to the tokens issued to users by a professional engaged in issuing and circulating tokens, and the tokens issued by that professional may be made available for trading by the users of the multi-service DAO 65. Currently, VALU Co., Ltd. is a professional engaged in issuing and circulating tokens.
[0243] Next, a system for constructing one DAO with controlled cooperation of a plurality of functional elements will be described based on FIGS. 43 to 59. Such a DAO is hereinafter referred to as an "element-integrated DAO".
[0244] Referring to FIG. 43, this element integration DAO enables the easy construction of company organizations and the like that already exist in the real world 47 as DAOs. Element DAOs are pre-generated and prepared for each of its functional elements. That is, element DAOs modularized for each functional element are prepared, and by selecting and combining the required element DAOs, it is configured to enable the easy construction of a desired element integration DAO. The element DAO provider 73 is provided with a server 74 and an element DAO protocol DB 75. The element DAO protocol DB 75 stores, for example, element DAOs prepared for each functional element required for company relationships, element DAOs prepared for each functional element required for NPO (Nonprofit Organization) relationships, element DAOs prepared for each functional element required for local governments, and the like.
[0245] The element integration DAO constructor receives an order for constructing an element integration DAO from the requester and installs the element DAO corresponding to the required functional element on the PC terminal 76 via the server 74. In the example of FIG. 43, the A1 element DAO (including the A1 element agent), the A2 element DAO (including the A2 element agent), the A5 element DAO (including the A5 element agent), and the A9 element DAO (including the A9 element agent) are installed. Each of the element agents A1 to A9 is an AI for reinforcement learning (machine learning) so that the corresponding element DAO can exhibit the best performance.
[0246] In addition, a general agent is also installed on the PC terminal 76. This general agent controls the element agents of each element DAO so that the entire integrated element DAO is optimized. The general agent itself also performs reinforcement learning (machine learning) to achieve overall optimization. Since each element agent is for maximizing the performance of the corresponding element DAO, relying only on the element agents may lead to partial optimization and there is a risk that the overall optimization of the integrated element DAO cannot be achieved. Therefore, a general agent is required to control the entire integrated element DAO to be optimized. This can be said to be the same as finding the Pareto optimal solution in an incomplete information game, for example.
[0247] In order to perform simulation reinforcement learning on the integrated element DAO installed on the PC 67 with the mirror world 51 as the simulation environment, it is installed on a plurality of terminals 16, and a digital twin 2T of a blockchain composed of a private chain 2 with these terminals 16 as nodes 19 is generated within the mirror world 51.
[0248] The main routine of the simulation reinforcement learning of this integrated element DAO will be described based on FIG. 44(A). The CPU 10 of the user terminal 16 of the requester who requests the simulation reinforcement learning of the integrated element DAO performs simulation reinforcement learning preparation response processing in S674 and simulation reinforcement learning response processing in S675. The CPU 10 of the mirror world server 46 performs simulation reinforcement learning preparation processing in S679 and simulation reinforcement learning processing in S680.
[0249] The details of the simulation reinforcement learning preparation response process shown in S674 and the simulation reinforcement learning preparation process shown in S679 will be described based on FIG. 44(B). In the simulation reinforcement learning preparation response process, the CPU 10 of the user terminal 16 determines in S679 whether to request simulation reinforcement learning, and returns if not. If it is determined to request, in S680, the DAO data and the personal AI group are sent and requested. The DAO data is the functional element of the organization for which simulation reinforcement learning is desired. For example, in the case of a furniture assembly and sales company, it is the material procurement element, the assembly element, the promotion element, and the sales element. The personal AI group is the personal AI of the people who actually work on the element integration DAO in the real world 47. If there are workers without personal AI and if the workers have not yet been determined, as described based on the above S561, S565 - S568, S562, S573 - S575, a personal AI that matches the element integration DAO to be the target of simulation reinforcement learning is generated and prepared.
[0250] In the simulation reinforcement learning preparation process, the CPU 10 of the mirror world server 46 determines in S683 whether there is a request for simulation reinforcement learning, and returns if not. If it is determined that there is a request for simulation reinforcement learning, in S684, the personal AI group is copied and deployed into the element integration DAO to generate an element integration DAO digital twin, which is registered in the mirror world 51 as the simulation target.
[0251] That state is shown in FIG. 45. The digital twin 78 of the element integration DAO 77 in the real world 47 is registered in the mirror world 51. The element integration DAO digital twin 78 shown in FIG. 45 is, for example, the element integration DAO digital twin 78 of a furniture assembly and sales company, has each functional element of material procurement, assembly, promotion, and sales, and the identification numbers of the personal AI group of the people working on each of these functional elements are stored in the mirror world server 46.
[0252] For this integrated element DAO digital twin 78, optimal incentive design is derived through simulation-based reinforcement learning. The schematic system of the reinforcement learning (machine learning) is shown in Fig. 46.
[0253] Referring to Fig. 46, in the integrated element DAO digital twin 78, corresponding to each functional element of procurement, assembly, promotion, and sales, a procurement element agent 80 and a personal AI group 84 in charge of procurement, an assembly element agent 81 and a personal AI group 85 in charge of assembly, a promotion element agent 82 and a personal AI group 86 in charge of promotion, a procurement element agent 80 and a personal AI group 84 in charge of procurement, and a sales element agent 83 and a personal AI group 87 in charge of sales are formed. These element agents 80 to 83 are supervised by a supervisor agent 79.
[0254] The personal AI group 84 in charge of procurement performs actions a11, a12, ··· a1n such as proposals in internal consultations, and finally executes the aggregated action a1 on the digital twin group 88 of the material suppliers. The state S1 of the digital twin group 88 of the material suppliers for the action a1 is input to the procurement element agent 80 and the personal AI group 84 in charge of procurement. This state S1 is, for example, the number of requested materials and the number of replied materials and the replied price for the action a1 of price negotiation. Each action a11, a12, ··· a1n of the personal AI group 84 in charge of procurement is also input to the procurement element agent 80, and the aggregated action a1 is also input to the supervisor agent 79 and the procurement element agent 80.
[0255] Based on action a1 and state S1, the procurement element agent 80 calculates the performance p1 by the personal AI group 84 in charge of procurement, and transmits the performance p1 to the general agent 79. The general agent 79 determines the reward r1 based on the performance p1, and transmits the reward r1 to the procurement element agent 80. The procurement element agent 80 determines the reward distribution rate based on each action a11, a12, ··· a1n of the personal AI group 84 in charge of procurement, and distributes the reward r1 to each personal AI 84 in charge of procurement according to the reward distribution rate.
[0256] The personal AI group 85 in charge of assembly performs actions a21, a22, ··· a2i such as proposals in internal coordination, and finally executes the integrated action a2 on the digital twin group 89 of the assembly equipment. The state S2 of the digital twin group 89 of the assembly equipment for the action a2 is input to the assembly element agent 81 and the personal AI group 85 in charge of assembly. This state S1 is, for example, the power consumption of the digital twin group 89 of the assembly equipment and the total working hours of the personal AI group 85 in charge of assembly engaged in the digital twin group 89 of the assembly equipment. Each action a21, a22, ··· a2i of the personal AI group 84 in charge of assembly is also input to the assembly element agent 81, and the integrated action a2 is also input to the general agent 79 and the assembly element agent 81.
[0257] Based on action a2 and state S2, the assembly element agent 81 calculates the performance p2 by the personal AI group 85 in charge of assembly, and transmits the performance p2 to the general agent 79. The general agent 79 determines the reward r2 based on the performance p2, and transmits the reward r2 to the assembly element agent 81. The assembly element agent 81 determines the reward distribution rate based on each action a21, a22, ··· a2i of the personal AI group 85 in charge of assembly, and distributes the reward r2 to the personal AI 85 in charge of assembly according to the reward distribution rate.
[0258] The personal AI group 86 in charge of publicity conducts acts such as proposals a51, a52, ··· a5j during internal consultations, and finally executes the consolidated act a5 on the consumer's personal AI group 90. The state S5 of the consumer's personal AI group 90 with respect to the act a5 is input to the publicity element agent 82 and the personal AI group 86 in charge of publicity. This state S5 is, for example, the presence or absence of the consumer's purchase of the product and the purchase amount, etc. with respect to the product recommendation act a5 to the consumer. Note that each act a51, a52, ··· a5j of the personal AI group 86 in charge of publicity is also input to the publicity element agent 82, and the consolidated act a5 is also input to the general agent 79 and the publicity element agent 82.
[0259] Based on the act a5 and the state S5, the publicity element agent 82 calculates the performance p5 by the personal AI group 86 in charge of publicity and transmits the performance p5 to the general agent 79. The general agent 79 determines the reward r5 based on the performance p5 and transmits the reward r5 to the publicity element agent 82. The publicity element agent 82 determines the reward distribution rate based on each act a51, a52, ··· a5j of the personal AI group 86 in charge of publicity and distributes the reward r5 to the personal AI 86 in charge of publicity according to the reward distribution rate.
[0260] The personal AI group 87 of the sales staff conducts actions such as proposals a91, a92, ··· a9m during internal coordination, and finally executes the consolidated action a9 on the store and the digital twin group 91 of consumers. The state S9 of the store and the digital twin group 91 of consumers with respect to the action a9 is input into the sales element agent 83 and the personal AI group 87 of the sales staff. This state S9 is, for example, the total sales amount in the store, etc. The state S5 of the digital twin 88 of the material provider with respect to the above action a5 is also input into the sales element agent 83. Each action a91, a92, ··· a9m of the personal AI group 87 of the sales staff is also input into the sales element agent 83, and the consolidated action a9 is input into the general agent 79 and the sales element agent 83 as well.
[0261] Based on the action a9 and the states S5, S9, the sales element agent 83 calculates the performance p9 by the personal AI group 87 of the sales staff and transmits the performance p9 to the general agent 79. The general agent 79 determines the reward r9 based on the performance p9 and transmits the reward r9 to the sales element agent 83. The sales element agent 83 determines the reward distribution rate based on each action a91, a92, ··· a9m of the personal AI group 87 of the sales staff and distributes the reward r9 to the personal AI 87 of the sales staff according to the reward distribution rate.
[0262] The calculation methods for the above performances p1 to p9 and each reward distribution rate will be described based on FIGS. 47(A), (B), (C), and 48(A). The procurement element agent 80 stores, as knowledge, the calculation algorithm for performance p1 and the distribution rate. The calculation algorithm for performance p1 and the distribution rate will be described based on FIG. 47(A). The procurement element agent 80 sets the material purchase amount u for this time (from the previous YES time point by S689 to the current YES time point) and the current inventory number z as the state S1, and calculates the performance p1 using the formula p1 = {2(average purchase amount / u) + (z / average inventory number)} / 3. The average purchase amount is the average purchase amount of materials from the start point of simulation-based reinforcement learning to the current time. The average inventory number is the average inventory number of materials from the start point of simulation-based reinforcement learning to the current time. As a result of this formula, if the material purchase amount u for this time becomes lower, the performance p1 becomes higher, and if the current inventory number z becomes larger, the performance p1 becomes lower.
[0263] Also, the reward distribution rate is calculated in proportion to the degree of approval for the collective action a1 when p1 ≥ 1, and conversely, when p1 < 1, it is calculated in inverse proportion to the degree of approval for the collective action a1. Here, it is not limited to being proportional or inversely proportional to the first power of the "degree of approval", but also includes those proportional or inversely proportional to the nth power of the "degree of approval", etc. The procurement element agent 80 obtains the optimal proportional function or inverse proportional function by performing reinforcement learning (machine learning). Also, the "degree of approval" is the highest degree of approval for the personal AI that proposed the collective action a1 itself, and the procurement element agent 80 determines (calculates) the degree of approval of each personal AI based on each action a11, a12,... a1n of the personal AI.
[0264] The calculation algorithm for the performance p2 and the distribution rate memorized by the assembly element agent 81 as knowledge will be described based on FIG. 47(B). The assembly element agent 81 uses the current power consumption e of the assembly equipment (from the previous YES time point by S710 to the current YES time point) and the total labor time t of the current assembly workers as the state S2, and calculates the performance p2 using the formula p2 = {(average power consumption / e) + (average total labor time / t)} / 2. The current total labor time t of the assembly workers is the total labor time of the personal AI group 85 in charge of assembly who worked according to the current assembly equipment digital twin group 89. The average power consumption is the average of the power consumption of the assembly equipment from the start point of simulation-based reinforcement learning to the present. The average total labor time is the average of the total labor time of the assembly workers from the start point of simulation-based reinforcement learning to the present. As a result of this calculation formula, if the current power consumption e of the assembly equipment decreases, the performance p2 increases, and if the current total labor time t of the assembly workers increases, the performance p2 decreases.
[0265] Also, the reward distribution rate is calculated in proportion to the degree of approval for the collective action a2 when p2 ≥ 1, and conversely, when p2 < 1, it is calculated in inverse proportion to the degree of approval for the collective action a2. Here, it is not limited to being proportional or inversely proportional to the first power of the "degree of approval", but also includes those proportional or inversely proportional to the nth power of the "degree of approval", etc. The assembly element agent 81 obtains the optimal proportional function or inverse proportional function by performing reinforcement learning (machine learning). Also, the "degree of approval" is the highest degree of approval for the personal AI that proposed the collective action a2 itself, and the assembly element agent 81 judges (calculates) the degree of approval of each personal AI based on each action a21, a22,... a2i of the personal AI.
[0266] The calculation algorithm for the performance p5 and the distribution rate, which the promotion element agent 82 stores as knowledge, will be described based on FIG. 47(C). The promotion element agent 82 sets the total purchase amount k of the recommended consumer personal AI this time (from the previous YES time point by S728 to the current YES time point) as the state S5, and calculates the performance p5 using the formula p5 = k / the average total purchase amount K of the recommended consumer personal AI. The average total purchase amount K is the average of the total purchase amounts of the recommended consumer personal AI group 90 from the start point of the simulation reinforcement learning to the present. As a result of this formula, if the current total purchase amount k of the recommended consumer personal AI is high, the performance p5 will be large.
[0267] Also, the reward distribution rate is calculated in proportion to the degree of approval for the collective action a5 when p5 ≧ 1, and conversely, when p5 < 1, it is calculated in inverse proportion to the degree of approval for the collective action a5. Here, it is not limited to being proportional or inversely proportional to the first power of the "degree of approval", but also includes those proportional or inversely proportional to the nth power of the "degree of approval", etc. The promotion element agent 82 obtains the optimal proportional function or inverse proportional function by performing reinforcement learning (machine learning). Also, the "degree of approval" is the highest for the personal AI that proposed the collective action a5 itself, and the promotion element agent 82 determines (calculates) the degree of approval of each personal AI based on each action a51, a52,... a5j of the personal AI.
[0268] The calculation algorithm for the performance p5 and the distribution rate that the sales element agent 83 memorizes as knowledge will be described based on FIG. 48(A). The sales element agent 83 sets the total sales amount h and the average total sales amount H at the store this time (from the previous YES point by S749 to the current YES point) as the state S9, and calculates the performance p9 using the formula p9 = (h - k) / (H - K) based on this state S9 and the above state S5. The average total sales amount H is the average of the total sales amounts at the store from the start point of simulation-based reinforcement learning to the present. Also, k is the current total purchase amount of the recommended consumer personal AI, and K is the average of the total purchase amounts of the group of recommended consumer personal AIs 90 from the start point of simulation-based reinforcement learning to the present (see FIG. 47(C) and its description). As a result of this calculation formula, the performance p9 increases as the value obtained by subtracting the current total purchase amount k of the recommended consumer personal AI from the current total sales amount h at the store increases. The current total purchase amount k of the recommended consumer personal AI is the achievement of the personal AI group 86 in charge of promotion, and the achievement of only the personal AI group 87 in charge of sales is the value obtained by subtracting the current total purchase amount k of the recommended consumer personal AI from the current total sales amount h at the store.
[0269] Also, the reward distribution rate is calculated in proportion to the degree of approval for the collective action a9 when p9 ≥ 1, and conversely, when p9 < 1, it is calculated in inverse proportion to the degree of approval for the collective action a9. Here, it is not limited to being proportional or inversely proportional to the first power of the "degree of approval", but also includes those proportional or inversely proportional to the nth power of the "degree of approval", etc., and the advertising element agent 83 obtains the optimal proportional function or inverse proportional function by performing reinforcement learning (machine learning). Also, the "degree of approval" is the highest for the personal AI that proposed the collective action a9 itself, and the sales element agent 83 determines (calculates) the degree of approval of each personal AI based on each action a91, a92, ··· a9m of the personal AI.
[0270] Next, the reward table 92 memorized by the overall agent 79 as knowledge will be described based on FIG. 48(B). In this reward table 92, the calculation formula for the rewards distributed by the overall agent 79 to each element agent 80 to 83 is memorized. The reward to be distributed is calculated as coefficient × (profit in the current period) × (performance sent from the target element agent) ÷ (total performance sent from all element agents). Here, the "current period" refers to the period from the previous YES point by S675 to the current YES point.
[0271] Specifically, the reward r1 distributed to the material procurement element agent 80 is r1 = A1·Lt·p1 / (p1 + p2 + p5 + p9). The reward r2 distributed to the assembly element agent 81 is r2 = A2·Lt·p2 / (p1 + p2 + p5 + p9). The reward r5 distributed to the promotion element agent 82 is r5 = A5·Lt·p5 / (p1 + p2 + p5 + p9). The reward r9 distributed to the sales element agent 83 is r9 = A9·Lt·p9 / (p1 + p2 + p5 + p9). Here, Lt is the profit in the current period, and A1, A2, A5, and A9 are coefficients as the actions determined by the overall agent 79.
[0272] Next, the specific content of the simulation reinforcement learning process shown in S680 will be described based on FIG. 49. The overall agent reinforcement learning process is executed by S687, the material procurement element agent reinforcement learning process is executed by S688, the assembly element agent reinforcement learning process is executed by S689, the promotion element agent reinforcement learning process is executed by S690, the sales agent reinforcement learning process is executed by S691, the material procurement person AI reinforcement learning process is executed by S692, the assembly person AI reinforcement learning process is executed by S693, the promotion person AI reinforcement learning process is executed by S694, and the sales person AI reinforcement learning process is executed by S695.
[0273] The details of the overall agent reinforcement learning process shown in S687 will be described based on FIG. 50. In S699, the overall agent 79 determines whether it has received each performance p sent from each of the element agents 80 to 83. If not received, the control proceeds to S671. However, if it is determined that the performance p has been received, in S670, each received performance p is stored.
[0274] Next, in S671, it is determined whether each of the actions a1 to a9 has been received. If not received, the control proceeds to S673. If it is determined that the actions have been received, in S672, each received action a1 to a9 is stored. Next, in S673, it is determined whether there is an input of the state S9 sent from the store and consumer personal AI group 91. If not, the control proceeds to S675. If it is determined that there is an input, in S674, sales = ΣS9 is calculated.
[0275] Next, in S675, it is determined whether the reward calculation time has arrived. If not, the control proceeds to S677. However, if it is determined that the reward calculation time has arrived, in S676, the reward table 92 is referred to calculate the rewards r1, r2, r3, r5, r9 and send them to the corresponding element agents 80 to 83.
[0276] Next, in S677, it is determined whether it is the update time of the reinforcement learning (machine learning). If not, it returns. If it is determined that it is the update time, in S687, the profit Lt of this period = sales - expenses is calculated. Next, in S679, each of the rewards r1, r2, r5, r9 is calculated and distributed to the corresponding element agents 80 to 83.
[0277] Next, in S680, the reward R of the overall agent 79 is calculated from the profit Lt. This reward R is proportional to the profit Lt. Next, in S681, based on the above reward R, the optimal policy π is obtained by TD learning *Obtain the actions (coefficients) A1, A2, A5, and A9 according to [the relevant content]. Next, in S682, update the A1, A2, A5, and A9 in the reward table 92 to the actions (coefficients) A1, A2, A5, and A9 obtained in S681. As a result, the overall agent 79 will learn the actions (coefficients) A1, A2, A5, and A9 that maximize the profit Lt.
[0278] Explain the details of the procurement element agent reinforcement learning process shown in S688 based on FIG. 51. The procurement element agent 80 performs information collection processing by the crawler in S684. A crawler is a program that periodically acquires documents, images, etc. on the web and automatically creates a database. It is also called a "bot", "spider", "robot", etc.
[0279] Explain the details of this information collection processing by the crawler based on FIG. 52(A). The procurement element agent 80 receives the information collected by the crawler while touring the network in S702. Next, in S703, store the received information in the procurement DB 93.
[0280] The information stored in the procurement DB 93 is shown in FIG. 52(B). As shown in the figure, the procurement DB 93 stores various types of information required for the procurement business, such as economic information, social information, meteorological information, inventory information, market information,... supplier information, etc.
[0281] Returning to FIG. 51, the procurement element agent 80 determines in S685 whether it has received the actions a11, a12,... a1n from the personal AI group 84. If not received, the control proceeds to S687. If it is determined that they have been received, in S686, store each received action a11, a12,... a1n. In S687, determine whether it has received the state S1 from the digital twin group 88 of the material suppliers. If not received, the control proceeds to S689. If it is determined that it has been received, in S688, store the received S1.
[0282] In S689, it is determined whether it is the time to calculate performance p1. If it is not the time to calculate, the control proceeds to S692. If it is determined that it is the time to calculate, in S690, performance p1 = {2(average purchase amount / u)+(z / average inventory quantity)} / 3 is calculated. The performance p1 is transmitted to the general agent 79 (S691).
[0283] In S692, it is determined whether the reward r1 transmitted from the general agent 79 has been received. If it has not been received, the process returns. If it is determined that it has been received, the reward distribution rate is calculated based on the reward distribution rate algorithm shown in FIG. 47(A) (S693). In S694, each reward r11, r12... r1n is calculated by multiplying the reward by each distribution rate. In S695, each reward r11, r12... r1n is assigned to each procurement personal AI group 84 of materials. In S696, based on the received reward r1, the optimal policy π * for the behavior (proportional function or inverse proportional function) is obtained by TD learning. In S697, the proportional function or inverse proportional function is updated to the one obtained in S696. As a result, the materials procurement element agent 80 will learn the proportional function or inverse proportional function that maximizes the performance p1.
[0284] Next, the details of the assembly element agent reinforcement learning process shown in S689 will be described based on FIG. 53. The assembly element agent 81 determines in S706 whether the actions a21, a22,... a2n from the personal AI group 85 have been received. If they have not been received, the control proceeds to S708. If it is determined that they have been received, in S707, each received action a21, a22,... a2n is stored. In S708, it is determined whether the state S2 from the digital twin group 89 of the assembly equipment has been received. If it has not been received, the control proceeds to S710. If it is determined that it has been received, in S709, the received state S2 is stored.
[0285] In S710, it is determined whether it is the time to calculate the performance p2. If it is not the time to calculate, the control proceeds to S713. If it is determined that it is the time to calculate, in S711, the performance p2 = {(average power consumption / e) + (average total labor time / t)} / 2 is calculated. The performance p2 is transmitted to the general agent 79 (S712).
[0286] In S713, it is determined whether the reward r2 sent from the general agent 79 has been received. If it has not been received, the process returns. If it is determined that it has been received, the reward distribution rate is calculated based on the reward distribution rate algorithm shown in FIG. 47(B) (S714). In S715, each reward r11, r12... r1n is calculated by multiplying the reward by each distribution rate. In S695, each reward r21, r22... r2i is assigned to the assembly - responsible personal AI group 86. In S717, based on the received reward r2, the optimal policy π * According to the behavior (proportional function or inverse - proportional function) is obtained. In S718, the proportional function or inverse - proportional function is updated to the one obtained in S717. As a result, the assembly element agent 81 learns the proportional function or inverse - proportional function that maximizes the above - mentioned performance p2.
[0287] The details of the reinforcement learning process of the promotion element agent shown in S690 will be described based on FIG. 54. The promotion element agent 83 performs information collection processing by the crawler in S723. The details of this processing will be described based on FIG. 55(A). The promotion element agent 83 receives the information collected by the crawler traveling on the network in S740 and stores the received information in the promotion DB94 in S741.
[0288] The collected data stored in the promotion DB94 is shown in Fig. 55(B). The promotion DB94 stores various behavioral data of consumers such as Taro, Jiro, ... Hanako. For example, in the case of Taro, it is determined that there is a high possibility of purchasing furniture from the information of "ordering a single-family house", and furniture promotion is carried out for Taro. In the case of Jiro, from the information of "purchase of a couple's bowl", it is determined that there is a high possibility of purchasing furniture for a new house in the near future due to getting married soon, and furniture promotion is carried out for Jiro.
[0289] Returning to Fig. 54, the promotion element agent 83 determines in S742 whether it has received the actions from each personal AI group 86. If not received, the control proceeds to S726. If it is determined that the actions have been received, in S725, each received action is memorized. In S726, it is determined whether the state S5 sent from the personal AI group 90 of the consumer has been received. If not yet received, the control proceeds to S728. If it is determined that the state S5 has been received, in S727, the received state S5 is memorized.
[0290] In S728, it is determined whether it is the calculation timing of the performance p5. If it is not the calculation timing of the performance p5, the control proceeds to S731. If it is determined that it is the calculation timing of the performance p5, in S729, the performance p5 = k / the average total purchase amount K of the recommended consumer personal AI is calculated. Next, in S730, the performance P5 is transmitted to the general agent 79.
[0291] In S731, it is determined whether the reward r5 sent from the general agent 79 has been received. If not yet received, it returns. If it is determined that the reward r5 has been received, in S732, the reward distribution rate is calculated based on the algorithm of the reward distribution rate shown in Fig. 47(C) (S732). In S733, each reward r51, r52... r5j is calculated by multiplying the reward by each distribution rate. In S734, each reward r51, r52... r5j is given to the personal AI group 87 in charge of promotion. In S735, based on the received reward r5, the optimal policy π is obtained by TD learning. *Obtain the act (proportional function or inverse proportional function) according to [the relevant content]. In S736, update the proportional function or inverse proportional function to the one obtained in S735. As a result, the promotion element agent 82 will learn the proportional function or inverse proportional function that maximizes the above performance p5.
[0292] Next, the details of the sales element agent reinforcement learning process shown in S691 will be described based on FIG. 56. The sales element agent 84 performs information collection processing by the crawler in S744. The details of this processing will be described based on FIG. 57(A). The sales element agent 84 receives the information collected by the crawler cruising on the network in S760, and stores the received information in the sales DB95 in S761. Further, in S762, the POS data in the store is stored in the sales DB95.
[0293] The collected data stored in the sales DB95 is shown in FIG. 57(B). Various data such as weather data and POS data are stored in the sales DB95. "By date" in the weather information is a concept that includes by day of the week. Based on the weather information (date-by-date time-by-time weather temperature data) and the POS data (date-by-date time-by-time sold product data), for example, the arrangement of display products can be changed considering the day of the week, time, and weather conditions.
[0294] Returning to FIG. 56, the sales element agent 84 determines in S745 whether it has received the acts from each personal AI group 87. If not received, the control proceeds to S747, but if it is determined that it has received, in S746, each received act is memorized. In S747, it is determined whether the state S9 sent from the personal AI groups 91 of the store and consumers has been received. If not yet received, the control proceeds to S749. If it is determined that it has received, in S748, the received state S9 is memorized.
[0295] In S749, it is determined whether it is the timing to calculate performance p9. If it is not the timing to calculate performance p9, the control proceeds to S752. If it is determined that it is the timing to calculate performance p9, in S750, performance p9 = (h - k) / (H - K) is calculated. Next, in S751, performance p9 is transmitted to the overall agent 79.
[0296] In S752, it is determined whether the reward r9 sent from the overall agent 79 has been received. If it has not been received yet, the process returns. If it is determined that it has been received, in S753, the reward distribution rate is calculated based on the algorithm of the reward distribution rate shown in Fig. 48(A) (S753). In S754, each reward r91, r92... r9m is calculated by multiplying the reward by each distribution rate. In S755, each reward r91, r92... r9m is given to the salesperson personal AI group 88. In S756, based on the received reward r9, the optimal policy π * for the behavior (proportional function or inverse proportional function) according to TD learning is obtained. In S757, the proportional function or inverse proportional function is updated to the one obtained in S756. As a result, the sales element agent 83 will learn the proportional function or inverse proportional function that maximizes the above performance p9.
[0297] Next, the details of the procurement person personal AI reinforcement learning process shown in S692 will be described based on Fig. 58(A). The procurement person personal AI group 84 determines in S765 whether to negotiate with the digital twin group 88 of the material supplier. If not, the control proceeds to S770. If it is determined to negotiate, in S766, the stored data in the financing DB93 is browsed, and while conducting internal coordination with reference to the stored data, the action a1 is determined (S767), and negotiations are conducted with the digital twin group 88 of the material supplier (S768). In S769, it is determined whether the negotiation has ended. If it has not ended yet, the process returns to S766, and the loop of S767 → S768 → S769 → S766 is cycled. When it is determined in S769 that the negotiation has ended, the control proceeds to S770.
[0298] In S770, it is determined whether rewards r11, r12 ··· r1n are received from the material procurement element agent 80. If not received, the process returns. If it is determined that the rewards are received, in S771, based on the received rewards, the optimal policy π * is used to obtain the actions (a11, a12 ··· a1n). This action a1i may include moving (changing jobs) to another company's DAO digital twin (for example, the DAO digital twin 59 of ABC Co., Ltd. in FIG. 45) if the received reward r1i is not satisfactory. As a result of this reinforcement learning, each of the personal AIs in charge of material procurement learns actions that increase the above-mentioned performance p1.
[0299] Next, the details of the personal AI reinforcement learning process for assembly shown in S693 will be described based on FIG. 58(B). The group of personal AIs 85 in charge of assembly determines in S775 whether to conduct internal coordination. If not, the control proceeds to S779. If it is determined to conduct coordination, in S776, each personal AI in charge of assembly determines the action a2 while conducting internal coordination. Next, in S777, according to the action a2, the digital twin group 89 of the assembly equipment is test-run to verify the validity of the action a2. In S778, it is determined whether the coordination has ended. If not yet ended, the process returns to S776, and the loop of S777 → S778 → S776 is repeated. If the action a2 is determined to be valid as a result of the test run in S777, it is determined in S778 that the coordination has ended, and the control proceeds to S779.
[0300] In S779, it is determined whether rewards r21, r22 ··· r2n are received from the assembly element agent 81. If not received, the process returns. If it is determined that the rewards are received, in S780, based on the received rewards, the optimal policy π *Determine the actions (a21, a22 ··· a2i) according to this. If the received reward r2i is not satisfactory, this action a2i also includes the case of moving (changing jobs) to the DAO digital twin of another company (for example, the DAO digital twin 59 of ABC Co., Ltd. in Fig. 45). As a result of this reinforcement learning, each of the personal AIs in charge of assembly will learn actions to increase the above-mentioned performance p2.
[0301] Next, the details of the personal AI reinforcement learning process for the publicity department shown in S694 will be described based on Fig. 59(A). The group of personal AIs 86 in the publicity department determines in S784 whether to conduct an internal consultation. If not, the control proceeds to S789. If it is determined to conduct a consultation, in S785, each personal AI in the publicity department determines the action a5 while conducting an internal consultation. Next, in S787, the action a2 to consumers is executed. In S788, it is determined whether the consultation has ended. If it has not ended yet, the process returns to S785 and loops through the loop of S786 → S787 → S788. When it is determined in S788 that the consultation has ended, the control proceeds to S789.
[0302] In S789, it is determined whether the rewards r51, r52 ··· r5j have been received from the publicity element agent 82. If not, the process returns. If it is determined that the rewards have been received, in S790, according to the received rewards, the optimal policy π * Determine the actions (a51, a52 ··· a5j) according to this. If the received reward r5i is not satisfactory, this action a5i also includes the case of moving (changing jobs) to the DAO digital twin of another company (for example, the DAO digital twin 59 of ABC Co., Ltd. in Fig. 45). As a result of this reinforcement learning, each of the personal AIs in the publicity department will learn actions to increase the above-mentioned performance p5.
[0303] Next, the details of the salesperson personal AI reinforcement learning process shown in S695 will be described based on FIG. 59(B). The salesperson personal AI group 87 determines in S791 whether to conduct an internal consultation. If not, the control proceeds to S795. If it is determined to conduct a consultation, in S792, each salesperson personal AI determines action a9 while conducting an internal consultation. Next, in S793, it is determined whether the consultation has ended. If it has not ended yet, the process returns to S792, and the loop of S792→S793→S792 is repeated. When it is determined in S793 that the consultation has ended, the control proceeds to S794. In S794, the actions determined in the above consultation are executed for the consumers and stores.
[0304] Next, in S795, it is determined whether rewards r91, r92 ··· r9m have been received from the sales element agent 83. If not, the process returns. If it is determined that the rewards have been received, in S796, based on the received rewards, actions (a91, a92 ··· a9m) according to the optimal policy π* are obtained by TD learning. This action a9i includes those that will move (transfer) to other company DAO digital twins (for example, the DAO digital twin 59 of ABC Co., Ltd. in FIG. 45) if the received reward r9i is not satisfactory. As a result of this reinforcement learning, each of the salesperson personal AIs will learn actions that increase the aforementioned performance p9.
[0305] The element integration DAO for which the simulation reinforcement learning has ended is operated as an actual organization in the real world 47. At that stage, the "personal AI groups 84 to 87" in FIG. 46 will be in charge of actual humans (users) in the real world. At that time, each of the personal AI groups 84 to 87 that have completed the simulation reinforcement learning will serve as a consultant for actual humans (users), and can provide the knowledge, experience, and know-how obtained through the simulation reinforcement learning to actual humans (users).
[0306] The construction of the element-integrated DAO described above shows how to create an entire organization such as a company, NPO, or local government as a combination of element DAOs by function. However, it is also possible to construct only a part of the organization (for example, procurement) with element DAOs instead of the entire organization.
[0307] The above-described programs that operate on the user terminal 16 and various servers may be downloaded and installed from a predetermined website or the like. However, for example, they may be recorded on a recording medium (non-transitory recording medium) such as a CD-ROM 99 and distributed, and those who purchase the CD-ROM 99 or the like may install the program on the user terminal 16 and various servers (see FIG. 60). [Modification Example]
[0308] (1) For example, names such as Taro, Jiro, Sakura, and Saburo in the digital twin data shown in FIG. 29 may use pseudonyms (anonyms) from the perspective of personal information protection, and although it is possible to identify that they are the same person, it may not be possible to identify a specific individual. In that case, an AI identification number or a blockchain address may be used as the pseudonym (anonym). Similarly, for the digital twin of ABC Co., Ltd. or the like, a pseudonym (anonym) may be used for the company name (organization name), and although it is possible to identify that they are the same company (organization), it may not be possible to identify a specific company (organization). Also, for a human digital twin, multiple digital twins by multiple personal AIs may be prepared for one person. Furthermore, one digital twin of one person may be composed of a collection of multiple personal AIs (for example, a collection of specialized personal AIs in various fields).
[0309] (2) In FIGS. 34 to 59, a system for deriving the optimal solution of incentive design in a DAO was described by performing a simulation using a multi-service DAO with multiple types of services as an example. However, the system is not limited to a multi-service DAO, and it may be a system for deriving the optimal solution of incentive design by simulation for a DAO with only one type of service.
[0310] (3) In Fig. 35, a group of learned persona agents is generated for each persona. However, for each personal AI of the user group belonging to each persona, it may be selected from the existing group of personal AIs registered in the mirror world 51 and used as the persona agent group. In this case, it is necessary to inquire whether it is possible to use the personal AI for the user group belonging to each persona in the simulation and obtain consent to use it. Copy each personal AI of the user group that has given consent and use it in the simulation, and send the learned personal AI group after the completion of the simulation to the corresponding users. Each user who has received it overwrites and saves the learned personal AI for the existing personal AI if they determine that the learned personal AI is useful (necessary). Note that both the existing personal AI and the learned personal AI may be stored together and used appropriately as needed.
[0311] (4) As multi-agent reinforcement learning, a master agent system was shown in which a master agent (coordinating agent) responsible for overall optimization distributes rewards to each agent and the master agent itself also performs reinforcement learning to converge the reward distribution behavior to an optimal one. However, multi-agent reinforcement learning is not limited to this. For example, D-learning that can converge to an optimal solution under a Markov decision process, or Bucket Brigade or Profit Sharing as a reinforcement learning algorithm in a Classifier System may be used.
[0312] (5) The simulation using digital twins is not limited to digital twins of humans or organizations composed of humans (such as corporations, NPOs, etc.). For example, in the case of objects equipped with AI, such as machines or electrical products equipped with AI (such as an AI-equipped vacuum cleaner), a digital twin of the environment in which the object operates (for example, the interior of a user's home where an AI-equipped vacuum cleaner that moves independently operates) is generated in the cyber space, and the AI installed in the object is pre-simulated and strengthened in the environmental digital twin. Learning (machine learning), and a customized (personalized) object equipped with a learned AI may be provided to the corresponding user.
[0313] Since it is possible to resolve as much as possible the dilemma in which the true guarantee of the recorded information and the guarantee of the right to delete the information are in conflict, it can be used for an information recording method having non-erasability such as blockchain.
Explanation of Signs
[0314] 1 Internet 2 Private Chain 3 Consortium Chain 4 Public Chain 12 HDD 16 User Terminal 19 Node 30 Key Registration Center 32 Key DB 46 Mirror World Server 51 Mirror World 52 Earth Digital Twin 53 Japan Digital Twin 54 Town Digital Twin 57 Taro Digital Twin 58 Taro's Family Digital Twin 59 ABC Corporation Digital Twin 61 DAO Agent 72 Token 78 DAO Digital Twin 79 General Agent.
Claims
1. Encryption means for performing an encryption process to encrypt information to be recorded; Recording means for recording the information after the encryption process; Decryption means for performing a decryption process on the information recorded by the recording means using a first key and a second key to obtain plaintext information; Undecryptable state setting means for setting the information recorded by the recording means to an undecryptable state, comprising: The decryption means includes second key concealment holding means for concealing and holding the second key; The undecryptable state setting means sets the undecryptable state by updating the second key held by the second key concealment holding means with another key, a processing system.
2. The processing system according to claim 1, wherein the decryption means further includes first key distribution means for distributing the first key to an information viewer.
3. The processing system according to claim 1 or 2, further comprising search means for searching the information recorded by the recording means without converting it into plaintext.
4. The information recorded by the recording means includes personal information, The undecryptable state setting means sets the personal information of the personal information owner to the undecryptable state in response to a request from the personal information owner, the processing system according to any one of claims 1 to 3.
5. A step of performing an encryption process to encrypt information to be recorded; A decryption step of performing a decryption process on the information recorded by the recording means using a first key and a second key to obtain plaintext information; A step of setting the information recorded by the recording means to an undecryptable state, To be executed by a computer, The decryption step includes a step of concealing and holding the second key, The step of setting the undecryptable state sets the undecryptable state by updating the second key held by the holding step with another key, a program.
Citation Information
Patent Citations
Digital negotiation platform
US10482554B1
Providing Commerce-Related, Blockchain-Associated Cognitive Insights Using Blockchains
US20180165611A1
Credibility management system and credibility management method
JP2018128723A