Personal data management system, personal data management method, and program

The personal data management system addresses the challenge of managing personal data for minors by digitally verifying and authorizing agents, ensuring secure and cost-effective data utilization.

JP2025112519AActive Publication Date: 2025-08-01TOPPAN HOLDINGS INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024006789
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-19
Publication Date
2025-08-01
Estimated Expiration
2044-01-19

AI Technical Summary

Technical Problem

Existing systems fail to adequately manage personal data for individuals who lack judgment capabilities, such as minors, leading to issues like personal information leakage and incorrect billing, as agents cannot effectively manage their data.

Method used

A personal data management system that includes an input reception unit for verifying an agent's relationship with the data owner and a permission management unit to grant the agent authority to manage the owner's data, using digital proof information.

Benefits of technology

Ensures safe and secure utilization of personal data by digitally proving the agent's relationship and managing data access, preventing privacy issues and data loss, while reducing costs associated with conventional analog media.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025112519000001_ABST
    Figure 2025112519000001_ABST
Patent Text Reader

Abstract

To provide a personal data management system, a personal data management method, and a program capable of safely utilizing personal data including personal information.SOLUTION: A personal data management system comprises: an input reception unit which accepts input of certification information indicating that it is proved by a third person that, regarding a relation between a first user who is a management object person in which management of personal data by an agent is required, and a second user who is the agent, the second user is an agent of the first user; and an authority management unit which gives authority which can manage the personal data of the first user who is the management object person, with respect to the second user who is the agent, based on the certification information whose input has been accepted.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a personal data management system, a personal data management method, and a program.

Background Art

[0002] Conventionally, when using various services, users may be required by service providers to provide personal data such as personal information. Regarding the provision of personal information, when a person who does not have the ability to judge the results arising from the consent of the person himself / herself regarding the handling of personal information (for example, a minor), it is stipulated by the Personal Information Protection Law that consent must be obtained from the person's agent (for example, a parent). In this regard, there are also services in which an agent can perform procedures on behalf of the service user, and various technologies for this purpose have been proposed.

[0003] For example, Patent Document 1 below discloses a technique for assisting the authentication of an agent in procedures by the agent of a user. In this technique, when a family member (agent) of a contractor (user) performs procedures on behalf of the contractor, the contract data of the contractor is compared with the information described in the identity certificate of the person performing the procedure, and when it can be determined that both are family members, the procedure by the agent is enabled. The agent performing the procedure also means that the user has consented to provide the user's personal information to the service.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, in the technology described in Patent Document 1 above, an agent could not even manage the user's personal data, and the management was entrusted to the user himself / herself. In modern times when anyone can easily use SNS (Social networking service), the Internet, etc., damages have occurred due to minors managing personal data, such as personal information leakage or incorrect billing for high - cost services. Therefore, for users who require an agent in handling personal information, it is desirable that the agent can appropriately manage the user's data.

[0006] In view of the above problems, an object of the present invention is to provide a personal data management system, a personal data management method, and a program capable of safely utilizing personal data including personal information.

Means for Solving the Problems

[0007] In order to solve the above problems, a personal data management system according to an aspect of the present invention includes, regarding the relationship between a first user who is a management target person who requires an agent to manage personal data and a second user who is the agent, an input reception unit that receives an input of proof information indicating that the second user is proven by a third party to be the agent of the first user, and a permission management unit that, based on the received proof information, grants the second user who is the agent the permission to manage the personal data of the first user who is the management target person. The personal data management system is provided with these components.

[0008] A personal data management method according to an aspect of the present invention includes an input reception process of receiving input of proof information indicating that, regarding the relationship between a first user who is a management target person requiring management of personal data by an agent and a second user who is the agent, it has been proven by a third party that the second user is the agent of the first user, and an authority management process of granting an authority to the second user who is the agent to manage the personal data of the first user who is the management target person based on the received proof information. It is a personal data management method executed by a computer including these processes.

[0009] A program according to an aspect of the present invention causes a computer to function as an input reception means for receiving input of proof information indicating that, regarding the relationship between a first user who is a management target person requiring management of personal data by an agent and a second user who is the agent, it has been proven by a third party that the second user is the agent of the first user, and an authority management means for granting an authority to the second user who is the agent to manage the personal data of the first user who is the management target person based on the received proof information.

Effects of the Invention

[0010] According to the present invention, personal data including personal information can be utilized safely.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Embodiments for Carrying Out the Invention

[0012] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.

[0013] <1. Overview of Personal Data Management Service> With reference to FIG. 1, the overview of the personal data management service according to this embodiment will be described. FIG. 1 is a diagram showing the overview of the personal data management service according to this embodiment. The personal data management service SA shown in FIG. 1 is a service that can permit the use of personal data of a user (first user) who is the person to be managed by the control of a user (second user) who is an agent.

[0014] The person to be managed is a person who requires an agent to manage their personal data. The person to be managed is a person who does not have the ability to judge the results arising from their own consent to the handling of personal information. Examples of persons to be managed include minors, the elderly, and those whose judgment ability has declined due to illness (such as dementia or mental disorders). Regarding such persons to be managed, the Personal Information Protection Law stipulates that when providing their own personal information to other companies, it is necessary to obtain consent from their personal agent (such as a parent). The agent is a person who manages the personal data of the person to be managed on behalf. The agent is a person who has a legally recognized relationship with the person to be managed. Examples of agents include legal representatives (parents), guardians (minor guardians, adult guardians), etc.

[0015] Here, the service flow when the user uses the personal data management service SA will be described. In the following, an example where the person to be managed is a child (minor) and the agent is a parent (parent of parental authority) will be used to describe the service flow. In this case, the period during which the parent manages the child's personal data (hereinafter, also referred to as the "management target period") is the period from when the parent is granted authority until the child becomes an adult. Note that a minor is a person who has not reached adulthood (under 18 years old), but the range of minors to be managed may be even more limited. For example, the person to be managed may be a child under the age of 12 to 15. In this case, the management target period may be set according to the range of minors to be managed.

[0016] As shown in FIG. 1, first, the child US1 and the parent US2 perform identity verification (step S1). The identity verification is performed, for example, by online identity verification (eKYC: electronic Know Your Customer) or a public personal authentication service (JPKI: Japanese Public Key Infrastructure). In online identity verification (eKYC), identity verification is performed online by comparing an image of an identity document with a photo (e.g., a driver's license) and an image of the person's face. In the public personal authentication service (JPKI), identity verification is performed using an electronic certificate for signature or an electronic certificate for user authentication installed on the IC chip of the My Number card.

[0017] Next, the child US1 and the parent US2 prepare information for proving their relationship (step S2). The information is, for example, a family register extract. In this case, the child US1 and the parent US2 obtain a family register extract at the government office and upload an image of the photographed family register extract to the system as family register extract information.

[0018] Next, a third party different from the child US1 and the parent US2 issues Verifiable Credentials (VC) based on the identity verification result in step S1 and the family register extract information uploaded in step S2 (step S3). VC is information indicating a digitally verifiable certificate online and is an example of the proof information according to the present embodiment. The proof information is information indicating that it has been proven by a third party that the parent US2 is the agent of the child US1. A third party verifies whether the relationship between the person to be managed and the agent is appropriate by using information that can verify the relationship (hereinafter also referred to as "verification information"). The household register transcript information is an example of verification information. For a paper printout such as a household register transcript, for example, an image captured by a camera may be used as verification information, or character information read by OCR (Optical Character Recognition) may be used as verification information. If the third party visually confirms the verification information and determines that the relationship between the person to be managed and the agent is appropriate, the third party issues a VC to prove the relationship. Note that the third party that issues the VC may be any operator. For example, the third party may be an operator that provides a personal data management service SA or an operator that has outsourced its operations through BPO (Business Process Outsourcing).

[0019] When the VC is issued by a third party, a relation between the child DB and the parent DB is set in the PDS (Personal Data Store) (step S4). The PDS is a mechanism for managing each user's personal data. The child DB is a database in which the personal data of the child US1 is managed. The parent DB is a database in which the personal data of the parent US2 is managed. Note that each user can manage their own personal data using a data catalog. The data catalog is generated for each user based on the personal data registered in the DB of the PDS.

[0020] Also, when the VC is issued by a third party, the agent, the parent US2, is given the authority to manage the personal data of the person to be managed, the child US1 (step S5). By setting the relation and granting the authority, when the parent US2 updates their own personal data (parent DB), if the information common to the child US1, who is the person to be managed by the parent US2, is included in the updated personal data, the personal data of the child US1 (child DB) is also updated accordingly.

[0021] The authorized parent US2 can manage its own personal data and the personal data of the child US1 who is the subject of management by the master catalog (step S6). The master catalog is generated based on the personal data of the persons to be managed and their agents registered in the DB of the PDS.

[0022] When the child US1 uses the service, the parent US2 opts in to the service with the information necessary for the service from among the personal data of the child US1 (step S7). The parent US2 can select the personal data of the child US1 to opt in to the service by referring to the master catalog. Note that the parent US2 can confirm the information necessary for using the service by the service catalog. The service catalog is presented by the service provider who is the service provider, and shows the content (value provided) of the service provided by the service provider and the personal data necessary for using the service. In FIG. 1, as an example, the service catalog of service A provided by service provider A and the service catalog of service B provided by service provider B are shown.

[0023] When the information required by the user is opted in, the service provider provides the service to the target user (step S8). In the case of the example shown in FIG. 1, the personal data of the child US1 is opted in to service A provided by the service provider by the parent US2. For this reason, service provider A provides service A to the child US1 and the parent US2.

[0024] <2. Configuration of Personal Data Management System> Above, the personal data management service SA according to the present embodiment has been described. Next, with reference to FIG. 2, the configuration of the personal data management system according to the present embodiment will be described. FIG. 2 is a block diagram showing an example of the configuration of the personal data management system according to the present embodiment. The personal data management system 1 shown in FIG. 2 is a system for operating the personal data management service SA whose overview was described with reference to FIG. 1.

[0025] As shown in FIG. 2, the personal data management system 1 includes a user terminal 10, an authentication server 20, a personal data management server 30, and a service management server 40. The network NW is configured for exchanging information, and for example, a LAN (Local Area Network), WAN (Wide Area Network), telephone network (mobile phone network, fixed phone network, etc.), regional IP (Internet Protocol) network, Internet, QKD network, etc. are applicable.

[0026] (1) User terminal 10 The user terminal 10 is a terminal that a user operates to use the personal data management service. The user terminal 10 is, for example, a smartphone, a tablet terminal, a PC (Personal Computer), etc. The user terminal 10 is communicably connected to the authentication server 20, the personal data management server 30, and the service management server 40 via the network NW. Note that the number of user terminals 10 is not particularly limited, and there may be one or a plurality of terminals. Also, when using the personal data management service SA, the person being managed and the agent may each use the user terminal 10 they own, or only use the user terminal 10 owned by one of them.

[0027] On the user terminal 10, various UIs (User Interfaces) are displayed by an application (hereinafter also referred to as a "portal app") that functions as a portal for the user to use the personal data management system 1. The user can use the personal data management system 1 by operating the UI displayed on the user terminal 10 by the portal app. Note that the functions of the portal application may be provided by installing the portal application on the user terminal 10 (i.e., a native application), or may be provided by a Web system (i.e., a Web application). In the case of a Web application, the portal application is managed by a server, and its functions are provided via a Web browser.

[0028] (2) Authentication Server 20 The authentication server 20 is a server that performs processing related to authentication for the user to use the personal data management service SA. The authentication server 20 is composed of, for example, a PC, one or more servers (e.g., a cloud server). The authentication server 20 is communicably connected to the user terminal 10 and the personal data management server 30 via the network NW.

[0029] (3) Personal Data Management Server 30 The personal data management server 30 is a server that performs processing for managing the user's personal data. The personal data management server 30 is composed of, for example, a PC, one or more servers (e.g., a cloud server). The personal data management server 30 is communicably connected to the user terminal 10, the authentication server 20, and the service management server 40 via the network NW.

[0030] (4) Service Management Server 40 The service management server 40 is a server that performs processing for managing services. The service management server 40 is composed of, for example, a PC, one or more servers (e.g., a cloud server). The service management server 40 is communicably connected to the user terminal 10 and the personal data management server 30 via the network NW. Note that the number of service management servers 40 is not particularly limited, and one or more servers may exist. For example, the number of service management servers 40 may be the same as the number of services provided to the user.

[0031] <3. Functional Configuration of User Terminal> The configuration of the personal data management system 1 according to the present embodiment has been described above. Subsequently, with reference to FIG. 3, the functional configuration of the user terminal 10 according to the present embodiment will be described. FIG. 3 is a block diagram showing an example of the functional configuration of the user terminal 10 according to the present embodiment. As shown in FIG. 3, the user terminal 10 includes a communication unit 110, an input unit 120, an imaging unit 130, a storage unit 140, a control unit 150, and an output unit 160.

[0032] (1) Communication unit 110 The communication unit 110 has a function of transmitting and receiving various types of information. The communication unit 110 performs transmission and reception of various types of information with the authentication server 20, the personal data management server 30, and the service management server 40 via, for example, the network NW. Further, the communication unit 110 may have a configuration capable of communicating by NFC (Near Field Communication). The communication unit 110 can read, for example, an electronic certificate for signature or an electronic certificate for user authentication mounted on the IC chip of the My Number card by NFC.

[0033] (2) Input unit 120 The input unit 120 has a function of receiving an input. The input unit 120 is composed of, for example, an input device provided as hardware in the user terminal 10, such as a button, a touch panel, a microphone, a mouse, a keyboard, or the like.

[0034] (3) Imaging unit 130 The imaging unit 130 has a function of imaging an image. The imaging unit 130 is composed of, for example, a camera provided as hardware in the user terminal 10. The imaging unit 130 images various types of images according to the user's operation when the user performs identity verification or uploads verification information. When the user performs identity verification by eKYC, an image of an identity document with a photo (for example, a driver's license) and an image of the user's face are required. Therefore, the imaging unit 130 images an image of the user's identity document (hereinafter also referred to as "identity document image") and an image of the user's face (face image) according to the user's operation. When the user uploads verification information, the imaging unit 130 captures, for example, an image of a household register transcript.

[0035] (4) Storage unit 140 The storage unit 140 has a function of storing various information. The function of the storage unit 140 is configured by a storage medium provided as hardware in the user terminal 10, for example, an HDD (Hard Disk Drive), an SSD (Solid State Drive), a flash memory, an EEPROM (Electrically Erasable Programmable Read Only Memory), a RAM (Random Access read / write Memory), a ROM (Read Only Memory), or any combination of these storage media.

[0036] (5) Control unit 150 The control unit 150 has a function of controlling the overall operation of the user terminal 10. The function of the control unit 150 is realized, for example, by causing a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit) provided as hardware in the user terminal 10 to execute a program. As shown in FIG. 3, the control unit 150 includes an input processing unit 151, an application processing unit 152, a wallet management unit 153, and an output processing unit 154.

[0037] (5-1) Input processing unit 151 The input processing unit 151 has a function of receiving the user's operation input to the input unit 120 and executing processing according to the operation content. The function by the input processing unit 151 is executed by the portal application. The user's operation is, for example, an ID authentication authorization operation, an identity authentication operation, a verification information registration operation, a proof information issuance operation, a personal reference operation, a data update operation, an agent reference operation, a data update operation, a service use operation, an opt-in operation, etc.

[0038] (5-2) Application processing unit 152 The application processing unit 152 has functions for providing the functions of the application. For example, the application processing unit 152 executes processing for providing the functions of the portal application. As an example of the functions of the portal application, there are an ID authentication authorization function, an identity authentication function, a verification information reading and registration function, an opt-in management function, a proof information issuance function, a personal data management function, and the like. The application processing unit 152 outputs a UI corresponding to each function in order to provide these functions. The application processing unit 152 executes processing for providing each function according to the operations input by the user to the UI. In the identity authentication function, for example, eKYC or JPKI can be selected. When eKYC is selected, the application processing unit 152 performs image capture in conjunction with the imaging unit 130. On the other hand, when JPKI is selected, the application processing unit 152 performs reading from the IC chip of the my number card in conjunction with the communication unit 110. In the proof information issuance function, for example, VC is issued.

[0039] (5-3) Wallet management unit 153 The wallet management unit 153 has a function of managing proof information. For example, the wallet management unit 153 stores the proof information issued by the proof information issuance function of the portal application and outputs it as necessary. Note that the function of the wallet management unit 153 is provided by, for example, the OS (Operating System) installed in the user terminal 10.

[0040] (5-4) Output processing unit 154 The output processing unit 154 has a function of controlling the output in the output unit 160. The output processing unit 154 causes the output unit 160 to display, for example, the UI provided by the portal application or the UI related to the service provided by the service provider.

[0041] (6) Output unit 160 The output unit 160 has a function of outputting various types of information. The output unit 160 is constituted by an output device that the user terminal 10 has as hardware, for example, a display device such as a display or a touch screen (touch panel), or an audio output device such as a speaker.

[0042] <4. Functional Configuration of Authentication Server> As described above, the functional configuration of the user terminal 10 according to the present embodiment has been explained. Subsequently, with reference to FIG. 4, the functional configuration of the authentication server 20 according to the present embodiment will be explained. FIG. 4 is a block diagram showing an example of the functional configuration of the authentication server 20 according to the present embodiment. As shown in FIG. 4, the authentication server 20 includes a communication unit 210, a storage unit 220, and a control unit 230.

[0043] (1) Communication Unit 210 The communication unit 210 has a function of transmitting and receiving various types of information. The communication unit 210 performs transmission and reception of various types of information with the user terminal 10 and the personal data management server 30 via, for example, the network NW.

[0044] (2) Storage Unit 220 The storage unit 220 has a function of storing various types of information. The function of the storage unit 220 is constituted by a storage medium that the authentication server 20 has as hardware, for example, an HDD, an SSD, a flash memory, an EEPROM, a RAM, a ROM, or an arbitrary combination of these storage media.

[0045] As shown in FIG. 4, the storage unit 220 includes an authentication information storage unit 221.

[0046] (2-1) Authentication Information Storage Unit 221 The authentication information storage unit 221 has a function of storing authentication information. The authentication information is, for example, an authentication ID and authorization information in LDAP (Lightweight Directory Access Protocol). Further, the authentication information is information indicating that the identity verification (eKYC) has been completed, the basic information for the verification, that the personal authentication (JPKI) has been completed, and the basic information for the authentication, etc.

[0047] (3) Control unit 230 The control unit 230 has a function of controlling the overall operation of the authentication server 20. The control unit 230 is realized, for example, by causing the CPU or GPU provided as hardware in the authentication server 20 to execute a program. As shown in FIG. 4, the control unit 230 includes an image acquisition unit 231, an ID authentication authorization unit 232, a personal verification unit 233, a public personal authentication unit 234, and a certification information issuance unit 235.

[0048] (3-1) Image acquisition unit 231 The image acquisition unit 231 has a function of acquiring various images. For example, when the user performs identity verification by eKYC, the image acquisition unit 231 acquires an identity verification document image and a face image from the user terminal 10. The image acquisition unit 231 outputs the acquired identity verification document image and face image to the personal verification unit 233. Further, when the user uploads verification information, the image acquisition unit 231 captures an image of a family register extract from the user terminal 10. The image acquisition unit 231 outputs the acquired image of the family register extract to the certification information issuance unit 235.

[0049] (3-2) ID authentication authorization unit 232 The ID authentication and authorization unit 232 has a function of authenticating and authorizing the ID issued for each user. The ID authentication and authorization unit 232 authenticates the ID and password to confirm that the user attempting to access is indeed the person himself / herself, and permits (authorizes) access to specific systems or data based on the authentication result. For example, the ID authentication and authorization unit 232 permits (returns an authorization result) an authenticated parent (agent) through eKYC or JPKI to access the data of a child (person to be managed). The ID authentication and authorization unit 232 also manages the authentication information in the authentication information storage unit 221.

[0050] (3-3) Person confirmation unit 233 The person confirmation unit 233 has a function of executing a person confirmation process as the person authentication process. For example, when the communication unit 210 receives a person confirmation request signal from the user terminal 10, the person confirmation unit 233 performs person confirmation of the user based on the person confirmation document image received by the communication unit 210 together with the signal and the registered face image. When the person confirmation is successful, the person confirmation unit 233 outputs information indicating that the person confirmation is successful to the user terminal 10 or the certification information issuance unit 235. On the other hand, when the person confirmation fails, the person confirmation unit 233 outputs information indicating that the person confirmation has failed to the user terminal 10 or the certification information issuance unit 235.

[0051] (3-4) Public personal authentication unit 234 The public personal authentication unit 234 has a function of executing a public personal authentication process as the person authentication process. For example, when the communication unit 210 receives a person authentication request signal from the user terminal 10, the public personal authentication unit 234 performs public personal authentication of the user based on the electronic certificate for signature and the electronic certificate for user certification received by the communication unit 210 together with the signal. When the public personal authentication is successful, the public personal authentication unit 234 outputs information indicating that the public personal authentication is successful to the user terminal 10 or the certification information issuance unit 235. On the other hand, when the public personal authentication fails, the public personal authentication unit 234 outputs information indicating that the public personal authentication has failed to the user terminal 10 or the certification information issuance unit 235.

[0052] (3-5) Proof Information Issuing Unit 235 The proof information issuing unit 235 has a function of performing processes related to the issuance of proof information. The proof information issuing unit 235 outputs the household register image input by the image acquisition unit 231 and the result of the personal authentication process input by the personal confirmation unit 233 or the official personal authentication unit 234 to a third party's terminal. The third party visually checks the household register image and the result of the personal authentication output to the terminal, and verifies whether the relationship between the person to be managed and the agent is appropriate. If it can be determined that the relationship is appropriate as a result of the verification, the third party performs an operation to issue proof information to the terminal. In response to this operation, the proof information issuing unit 235 issues the proof information.

[0053] <5. Functional Configuration of Personal Data Management Server> The functional configuration of the authentication server 20 according to the present embodiment has been described above. Subsequently, with reference to FIG. 5, the functional configuration of the personal data management server 30 according to the present embodiment will be described. FIG. 5 is a block diagram showing an example of the functional configuration of the personal data management server 30 according to the present embodiment. As shown in FIG. 5, the personal data management server 30 includes a communication unit 310, a storage unit 320, and a control unit 330.

[0054] (1) Communication Unit 310 The communication unit 310 has a function of transmitting and receiving various information. The communication unit 310 performs transmission and reception of various information with the user terminal 10, the authentication server 20, and the service management server 40 via, for example, the network NW.

[0055] (2) Storage Unit 320 The storage unit 320 has a function of storing various information. The function of the storage unit 320 is configured by a storage medium provided as hardware in the personal data management server 30, for example, an HDD, an SSD, a flash memory, an EEPROM, a RAM, a ROM, or any combination of these storage media.

[0056] As shown in FIG. 5, the storage unit 320 includes a personal data storage unit 321 and a relation information storage unit 322.

[0057] (2-1) Personal Data Storage Unit 321 The personal data storage unit 321 has a function of storing personal data. That is, the personal data storage unit 321 functions as a PDS (Personal Data Store). The personal data storage unit 321 manages the personal data of the person to be managed (the first user) and the personal data of the agent (the second user) in separate databases. As shown in FIG. 5, the personal data storage unit 321 according to the present embodiment includes a child DB 3211 for managing the personal data of the child who is the person to be managed, and a parent DB 3212 for managing the personal data of the parent who is the agent.

[0058] (2-2) Relation Information Storage Unit 322 The relation information storage unit 322 has a function of storing relation information. The relation information is information indicating a DB in which a relation is set. For example, when a relation between a child and a parent is set by a relation management unit 334 described later, the relation information storage unit 322 registers that there is a relation between the child DB 3211 of the child and the parent DB 3212 of the parent.

[0059] (3) Control Unit 330 The control unit 330 has a function of controlling the overall operation of the personal data management server 30. The control unit 330 is realized, for example, by causing a CPU or GPU included in the personal data management server 30 as hardware to execute a program. As shown in FIG. 5, the control unit 330 includes an input reception unit 331, a personal data management unit 332, a catalog processing unit 333, a relation management unit 334, an authority management unit 335, and an opt-in management unit 336.

[0060] (3-1) Input Reception Unit 331 The input reception unit 331 has a function of receiving various inputs. For example, the input reception unit 331 receives inputs such as the input of the certification information issued by the authentication server 20 via the communication unit 310, the information input by the user to the user terminal 10 for managing personal data, and the information input by the user to the user terminal 10 for using the service.

[0061] (3-2) Personal data management unit 332 The personal data management unit 332 has a function of managing personal data. For example, the personal data management unit 332 manages the personal data of each user stored in the personal data storage unit 321 based on the input from each user. When the user is the person to be managed, the personal data management unit 332 only permits the reference of the personal data stored in the personal data storage unit 321.

[0062] When the user is an agent, the personal data management unit 332 manages the personal data of each user stored in the personal data storage unit 321 based on the authority granted to the agent and the relationship between the agent and the person to be managed. For example, when no particular authority is granted to the agent and no relationship with the person to be managed is set, the personal data management unit 332 permits the agent to reference and update his or her own personal data stored in the personal data storage unit 321. When authority is granted to the agent and a relationship with the person to be managed is set, the personal data management unit 332 permits the agent to reference and update the personal data of himself or herself and the person to be managed stored in the personal data storage unit 321.

[0063] In addition, when an authorized agent updates their own personal data, if the information common to the agent's managed subjects is included in the updated personal data, the personal data of the managed subjects is also updated accordingly. Information common between the agent and the managed subjects includes, for example, address, shared phone number, email address, etc.

[0064] Note that when the authority granted to the agent is deleted and the relationship with the managed subjects is also deleted, the agent can only refer to and update the personal data of themselves and the managed subjects stored in the personal data storage unit 321, and cannot refer to and update the personal data of the users who were the managed subjects. On the other hand, the user who was the managed subject can also update their personal data that was only viewable.

[0065] (3-3) Catalog Processing Unit 333 The catalog processing unit 333 has a function of performing processing related to catalogs. For example, the catalog processing unit 333 generates a data catalog including management information indicating the management status of personal data for each user based on the personal data stored in the personal data storage unit 321. The catalog processing unit 333 causes the generated data catalog to be displayed on the user terminal 10. In addition, the catalog processing unit 333 generates a master catalog including management information indicating the management status of the personal data of the managed subjects and the agent based on the personal data stored in the personal data storage unit 321 and the relationship information stored in the relationship information storage unit 322. The catalog processing unit 333 causes the generated master catalog to be displayed on the user terminal 10.

[0066] (3-4) Relationship Management Unit 334 The relationship management unit 334 has a function of managing the relationship between the person to be managed and the agent. For example, based on the proof information received by the input reception unit 331, the relationship management unit 334 sets a relationship between a DB (first database) in which the personal data of a user who is the person to be managed is managed and a DB (second database) in which the personal data of a user who is the agent of the person to be managed is managed.

[0067] As an example of relationship management, assume that the person to be managed is a minor. In this case, the relationship management unit 334 sets a relationship between the database of the user who is the person to be managed and the database of the user who is the agent of the said user at the timing when the proof information of the person to be managed and the agent is issued. When the user who is the person to be managed becomes an adult (i.e., after the elapse of the management period), the relationship management unit 334 releases the relationship between the database of the said user and the database of the user who is the agent of the said user. The database of the person to be managed and the database of the agent are managed separately. For this reason, along with the release of the relationship, the agent can directly transfer the management of the database of the person to be managed from the agent to the person to be managed. Thereby, the person to be managed can retain, as their own life log data even after becoming an adult, the child data (such as report cards in elementary school, health check results in kindergarten, and travel photos) since their birth. Also, when the agent transfers the management of the database of the person to be managed to the person to be managed, the agent can no longer refer to or update the database of the person to be managed. Thereby, after the person to be managed takes over the management from the agent, the person to be managed can ensure privacy regarding the management of their own database.

[0068] (3 - 5) Authority management unit 335 The authority management department 335 has a function of managing the authority of an agent. For example, based on the certification information received by the input reception department 331, the authority management department 335 grants the user who is the agent the authority to manage the personal data of the user who is the management target.

[0069] As an example of authority management, assume that the management target is a minor. In this case, the authority management department 335 grants the authority to the user who is the agent at the timing when the certification information of the management target and the agent is issued. When the authority is granted to the user who is the agent, the management period starts. When the user who is the management target becomes an adult (i.e., after the elapse of the management period), the authority management department 335 deletes the authority from the user who is the agent of the said user.

[0070] (3-6) Opt-in management department 336 The opt-in management department 336 has a function of managing the opt-in of the user's personal data. For example, in response to a request from the user who is an agent with authority, the opt-in management department 336 opt-ins to the service the information necessary for the service used by the user who is the management target among the personal data of the user who is the management target. Also, the opt-in management department 336 may opt-out the personal data opt-ed into the service from the said service in response to a request from the user who is an agent with authority.

[0071] Note that the information for which the opt-in management department 336 opt-ins or opt-outs to / from the service is not limited to personal data. For example, when the service used by the user who is the management target is a service that requires proof of the relationship between the user who is the management target and the user who is the agent, the opt-in management department 336 may opt-in the certification information to the service or opt-out from the said service.

[0072] <6. Functional configuration of the service management server> The functional configuration of the personal data management server 30 according to the present embodiment has been described above. Subsequently, with reference to FIG. 6, the functional configuration of the service management server 40 according to the present embodiment will be described. FIG. 6 is a block diagram showing an example of the functional configuration of the service management server 40 according to the present embodiment. As shown in FIG. 6, the service management server 40 includes a communication unit 410, a storage unit 420, and a control unit 430.

[0073] (1) Communication unit 410 The communication unit 410 has a function of transmitting and receiving various information. The communication unit 410 performs transmission and reception of various information with the user terminal 10 and the personal data management server 30 via, for example, the network NW.

[0074] (2) Storage unit 420 The storage unit 420 has a function of storing various information. The function of the storage unit 420 is configured by a storage medium provided as hardware in the service management server 40, for example, an HDD, an SSD, a flash memory, an EEPROM, a RAM, a ROM, or an arbitrary combination of these storage media.

[0075] As shown in FIG. 6, the storage unit 420 includes a service catalog storage unit 421 and a user information storage unit 422.

[0076] (2-1) Service catalog storage unit 421 The service catalog storage unit 421 has a function of storing service catalogs. For example, the service catalog storage unit 421 stores service catalogs prepared for each service provided by service providers.

[0077] (2-2) User information storage unit 422 The user information storage unit 422 has a function of storing information about users who use the service. For example, the user information storage unit 422 stores information registered by the user, information opt-in by the user, information generated by the user using the service, and the like.

[0078] (3) Control Unit 430 The control unit 430 has a function of controlling the overall operation of the service management server 40. The control unit 430 is realized, for example, by causing a CPU or GPU included in the service management server 40 as hardware to execute a program. As shown in FIG. 6, the control unit 430 includes an input reception unit 431, a service catalog management unit 432, and a service processing unit 433.

[0079] (3-1) Input Reception Unit 431 The input reception unit 431 has a function of receiving various inputs. For example, the input reception unit 431 receives information input by the user to the user terminal 10 for using the service and input of personal data opt-in from the personal data management server 30 via the communication unit 410.

[0080] (3-2) Service Catalog Management Unit 432 The service catalog management unit 432 has a function of managing the service catalog. For example, based on a reference request for the service catalog received by the input reception unit 431, the service catalog management unit 432 causes the service catalog stored in the service catalog storage unit 421 to be displayed on the user terminal 10.

[0081] (3-3) Service Processing Unit 433 The service processing unit 433 has a function of executing processing related to the service provided to the user. For example, based on information about the user, the service processing unit 433 updates the information stored in the user information storage unit 422 or provides a service to the user.

[0082] <7. Flow of Processing> The functional configuration of the service management server 40 according to the present embodiment has been described above. Subsequently, with reference to FIGS. 7 to 13, the flow of processing according to the present embodiment will be described. Hereinafter, an example in which the person to be managed is a child and the agent is a parent will be taken as an example to describe the flow of processing.

[0083] (1) Flow of preparation process in proof information issuance Referring to Fig. 7, the flow of the preparation process in proof information issuance according to this embodiment will be described. Fig. 7 is a sequence diagram showing an example of the flow of the preparation process in proof information issuance according to this embodiment. Note that the operations of the user shown in Fig. 7 may be performed by the child or the parent respectively, or the parent may perform the operations on behalf of the child.

[0084] As shown in Fig. 7, first, the user performs an ID authentication authorization operation on the user terminal 10 (step S101). When the application processing unit 152 of the user terminal 10 receives an ID authentication authorization operation from the user by the input processing unit 151, it sends an ID authentication authorization request from the communication unit 110 to the authentication server 20 (step S102). When the ID authentication authorization unit 232 of the authentication server 20 receives an ID authentication authorization request from the user terminal 10 by the communication unit 210, it executes an ID authentication authorization process (step S103).

[0085] Next, the user performs an identity authentication operation on the user terminal 10 (step S104). In this operation, the user selects whether to perform identity authentication by eKYC or JPKI. Also, the user prepares the necessary information (such as taking a picture or reading the My Number card) according to the selected identity authentication method. When the application processing unit 152 of the user terminal 10 receives an identity authentication operation from the user by the input processing unit 151, it sends an identity authentication request from the communication unit 110 to the authentication server 20 (step S105). At this time, the application processing unit 152 also sends the information prepared by the user to the authentication server 20. When the personal verification unit 233 or the public personal authentication unit 234 of the authentication server 20 receives a personal authentication request from the user terminal 10 through the communication unit 210, it executes a personal authentication process (step S106). When it is indicated that the personal authentication request is eKYC, the personal verification unit 233 performs a personal authentication process by eKYC. When it is indicated that the personal authentication request is JPKI, the public personal authentication unit 234 performs a personal authentication process by JPKI.

[0086] Next, the user performs a verification information registration operation on the user terminal 10 (step S107). In this operation, the user prepares the verification information to be registered (takes a photo of the family register transcript). When the application processing unit 152 of the user terminal 10 receives a verification information registration operation from the user through the input processing unit 151, it sends a verification information registration request from the communication unit 110 to the authentication server 20 (step S108). At this time, the application processing unit 152 also sends the verification information prepared by the user to the authentication server 20. When the image acquisition unit 231 of the authentication server 20 receives a verification information registration request from the user terminal 10 through the communication unit 210, it registers the verification information received by the communication unit 210 in the storage unit 220 (step S109).

[0087] (2) Flow of proof information issuance process Referring to FIG. 8, the flow of the proof information issuance process according to the present embodiment will be described. FIG. 8 is a sequence diagram showing an example of the flow of the proof information issuance process according to the present embodiment. Note that the operations of the user shown in FIG. 8 are performed by the parent who is the agent.

[0088] As shown in FIG. 8, first, the user performs a proof information issuance operation on the user terminal 10 (step S201). When the application processing unit 152 of the user terminal 10 receives a proof information issuance operation from the user through the input processing unit 151, it sends a proof information issuance request from the communication unit 110 to the authentication server 20 (step S202). When the authentication information issuing unit 235 of the authentication server 20 receives an authentication information issuance request from the user terminal 10 via the communication unit 210, it requests a third party to verify the relationship between the person to be managed and the agent (step S203). At this time, the authentication information issuing unit 235 causes the third party's terminal to display the result of the authentication process obtained in step S106 and the verification information obtained in step S109. Based on the result of the authentication process and the verification information displayed on the terminal, the third party verifies the relationship between the person to be managed and the agent (step S204). After the verification, the third party operates the terminal to register the verification result with the authentication server 20 (step S205).

[0089] The authentication information issuing unit 235 of the authentication server 20 confirms the verification result registered by the third party (step S206). If the verification result indicates that the relationship between the person to be managed and the agent is inappropriate (step S206 / NO), the process proceeds to step S207. On the other hand, if the verification result indicates that the relationship between the person to be managed and the agent is appropriate (step S206 / YES), the process proceeds to step S208. If the process proceeds to step S207, the authentication information issuing unit 235 notifies the user terminal 10 of an error indicating that the relationship between the person to be managed and the agent is inappropriate (step S207). If the process proceeds to step S208, the authentication information issuing unit 235 issues authentication information proving that the relationship between the person to be managed and the agent is appropriate (step S208).

[0090] (3) Flow of processing in the personal data management server associated with the issuance of authentication information Referring to FIG. 9, the flow of processing in the personal data management server 30 associated with the issuance of authentication information according to the present embodiment will be described. FIG. 9 is a sequence diagram showing an example of the flow of processing in the personal data management server 30 associated with the issuance of authentication information according to the present embodiment.

[0091] As shown in FIG. 9, first, the certification information issuing unit 235 of the authentication server 20 transmits the issued certification information from the communication unit 210 to the personal data management server 30 (step S301). The input reception unit 331 of the personal data management server 30 receives the input of the certification information received by the communication unit 310 from the authentication server 20 (step S302). The personal data management unit 332 of the personal data management server 30 registers the certification information received by the input reception unit 331 in the personal data storage unit 321 of the storage unit 320 (step S303). At this time, the personal data storage unit 321 registers the certification information as common data of the management target person and the agent. Next, the relation management unit 334 of the personal data management server 30 sets a relation between the DB in which the personal data of the user who is the management target person is managed and the DB in which the personal data of the user who is the agent of the management target person is managed, based on the certification information received by the input reception unit 331 (step S304). Also, the authority management unit 335 of the personal data management server 30 grants the user who is the agent the authority to manage the personal data of the user who is the management target person, based on the certification information received by the input reception unit 331 (step S305).

[0092] (4) Flow of processing when an individual refers to his / her own data Referring to FIG. 10, the flow of processing when an individual according to the present embodiment refers to his / her own data will be described. FIG. 10 is a sequence diagram showing an example of the flow of processing when an individual according to the present embodiment refers to his / her own data. Note that the operations of the user shown in FIG. 10 can be executed by a child or a parent, respectively.

[0093] As shown in FIG. 10, first, the user performs a personal reference operation on the user terminal 10 (step S401). The personal reference operation is an operation for the user to refer to his / her own personal data. When the application processing unit 152 of the user terminal 10 receives a personal reference operation from the user by the input processing unit 151, it transmits a data catalog reference request from the communication unit 110 to the personal data management server 30 (step S402). When the catalog processing unit 333 of the personal data management server 30 receives a data catalog reference request from the user terminal 10 by the communication unit 310, it generates a data catalog of the user who performed the personal reference operation (step S403). After generation, the catalog processing unit 333 transmits the generated data catalog from the communication unit 310 to the user terminal 10 (step S404). The output processing unit 154 of the user terminal 10 causes the output unit 160 to display the data catalog received from the personal data management server 30 by the communication unit 110 (step S405). The user refers to the data catalog displayed on the output unit 160 of the user terminal 10 (step S406).

[0094] (5) Flow of processing when an agent updates their own data With reference to FIG. 11, the flow of processing when an agent according to the present embodiment updates their own data will be described. FIG. 11 is a sequence diagram showing an example of the flow of processing when an agent according to the present embodiment updates their own data. Note that the user operations shown in FIG. 11 are performed by the parent who is the agent.

[0095] As shown in FIG. 11, first, the user performs a data update operation on the user terminal 10 to update their personal data (step S501). When the application processing unit 152 of the user terminal 10 receives a data update operation from the user (parent) by the input processing unit 151, it transmits a data update request from the communication unit 110 to the personal data management server 30 (step S502). When the personal data management unit 332 of the personal data management server 30 receives a data update request from the user terminal 10 by the communication unit 310, it updates the DB of the parent who performed the data update operation (step S503). Also, the Personal Data Management Unit 332 checks whether the updated parent data contains data common to the child's data (step S504). If common data is included (step S504 / YES), the process proceeds to step S505. On the other hand, if no common data is included (step S504 / NO), the process ends. When the process proceeds to step S505, the Personal Data Management Unit 332 updates the child's DB in the same manner as the parent's DB for the common data (step S505) and ends the process.

[0096] (6) Flow of processing when an agent also refers to or updates the data of the person to be managed With reference to FIG. 12, the flow of processing when an agent according to the present embodiment also refers to or updates the data of the person to be managed will be described. FIG. 12 is a sequence diagram showing an example of the flow of processing when an agent according to the present embodiment also refers to or updates the data of the person to be managed. Note that the user operations shown in FIG. 12 are performed by the parent who is the agent.

[0097] As shown in FIG. 12, first, the user performs an agent reference operation on the user terminal 10 (step S601). The agent reference operation is an operation for the user who is the agent to refer to his or her own personal data and the personal data of the user to be managed. When the application processing unit 152 of the user terminal 10 receives an agent reference operation from the user by the input processing unit 151, it transmits a master catalog reference request from the communication unit 110 to the Personal Data Management Server 30 (step S602). When the catalog processing unit 333 of the Personal Data Management Server 30 receives a master catalog reference request from the user terminal 10 by the communication unit 310, it generates a master catalog regarding the user who performed the agent reference operation and the user who is the person to be managed by that user (step S603). After generation, the catalog processing unit 333 transmits the generated master catalog from the communication unit 310 to the user terminal 10 (step S604). The output processing unit 154 of the user terminal 10 causes the output unit 160 to display the master catalog received by the communication unit 110 from the personal data management server 30 (step S605). The user refers to the master catalog displayed on the output unit 160 of the user terminal 10 (step S606).

[0098] Also, the user performs a data update operation for updating the master catalog on the user terminal 10 (step S607). When the application processing unit 152 of the user terminal 10 receives a data update operation for updating the master catalog from the user (parent) by the input processing unit 151, it transmits a data update request from the communication unit 110 to the personal data management server 30 (step S608). When the personal data management unit 332 of the personal data management server 30 receives a data update request for updating the master catalog from the user terminal 10 by the communication unit 310, it checks the data to be updated (step S609). If the data to be updated is the parent data (step S609 / YES), the process proceeds to step S610. On the other hand, if the data to be updated is the child data (step S609 / NO), the process proceeds to step S611. When the process proceeds to step S610, the personal data management unit 332 updates the parent DB (step S610) and ends the process. When the process proceeds to step S611, the personal data management unit 332 updates the child DB (step S611) and ends the process.

[0099] (7) Flow of opt-in processing when the user uses the service With reference to FIG. 13, the flow of opt-in processing when the user according to the present embodiment uses the service will be described. FIG. 13 is a sequence diagram showing an example of the flow of opt-in processing when the user according to the present embodiment uses the service. Note that the operations of the user shown in FIG. 13 are performed by the parent who is the agent.

[0100] As shown in FIG. 13, first, the user performs a service usage operation on the user terminal 10 (step S701). When the application processing unit 152 of the user terminal 10 receives a service usage operation from the user by the input processing unit 151, it sends a service catalog reference request from the communication unit 110 to the service management server 40 (step S702). When the service catalog management unit 432 of the service management server 40 receives a service catalog reference request from the user terminal 10 by the communication unit 410, it sends the service catalog from the communication unit 410 to the user terminal 10 (step S703). The output processing unit 154 of the user terminal 10 causes the output unit 160 to display the service catalog received from the service management server 40 by the communication unit 110 (step S704). The user refers to the service catalog displayed on the output unit 160 of the user terminal 10 (step S705).

[0101] After referring to the service catalog, the user refers to the master catalog on the user terminal 10 (step S706). Next, the user selects data necessary for using the service from the master catalog displayed on the user terminal 10 (step S707). After the selection, the user performs an opt-in operation on the user terminal 10 (step S708). When the application processing unit 152 of the user terminal 10 receives an opt-in operation from the user by the input processing unit 151, it sends an opt-in request from the communication unit 110 to the personal data management server 30 (step S709). When the opt-in management unit 336 of the personal data management server 30 receives an opt-in request from the user terminal 10 by the communication unit 310, it opts in the necessary data from the communication unit 310 to the service management server 40 (step S710). The service processing unit 433 of the service management server 40 provides services to users based on the data opt-in from the personal data management server 30 (step S711).

[0102] The flow of the process according to this embodiment has been described above. As described above, the personal data management system 1 according to this embodiment relates to the relationship between a first user who is a management target person who requires personal data management by an agent and a second user who is an agent. It includes an input reception unit 331 that receives an input of proof information indicating that the second user is proven by a third party to be an agent of the first user, and based on the received proof information, a permission management unit 335 that grants the second user, who is an agent, the permission to manage the personal data of the first user, who is the management target person.

[0103] With such a configuration, the relationship between the management target person and the agent can be digitally proven, and the proof information indicating that it has been proven can also be digitally retained. As a result, it becomes possible to realize the agent's management of the personal data of the management target person, and to perform controls such as opting in the personal data of the management target person to a service provider in a safe and appropriate manner in a digitally complete manner. As a result, it is possible to prevent privacy problems, loss, forgetting, and theft risks of the personal data of the management target person, and to safely and securely utilize personal data including personal information. Therefore, the personal data management system 1 according to this embodiment enables the safe utilization of personal data including personal information. In addition, since the personal data management system 1 can seamlessly perform all the mechanisms for obtaining consent digitally, the procedures on the applicant side and the data management on the enterprise side can be easily implemented. As a result, it is also possible to reduce the costs associated with registration and management using conventional analog media.

[0104] <8. Modification Example> Embodiments of the present invention have been described. Subsequently, modifications of the embodiments of the present invention will be described. Note that the modifications described below may be applied to the embodiments of the present invention alone or in combination. Further, the modifications may be applied in place of the configurations described in the embodiments of the present invention, or may be additionally applied to the configurations described in the embodiments of the present invention.

[0105] In the above-described embodiment, an example in which the person to be managed is a child (minor) and the agent is a parent (guardian), that is, an example in which the agent is a minor guardian, has been described. However, the present invention is not limited to such an example. For example, the agent may be an adult guardian. In this case, the person to be managed is, for example, a parent, and the agent is, for example, a child.

[0106] Also, in the above-described embodiment, an example in which the period from when authority is granted to the parent until the child becomes an adult is set as the management target period when the person to be managed is a child and the agent is a parent has been described. However, the present invention is not limited to such an example. For example, the management target period may be set based on the law corresponding to the country or region to which the person to be managed and the agent belong. Information indicating the country or region to which each of the person to be managed and the agent belongs is hereinafter also referred to as "affiliation information". The affiliation information is information that can be extracted, for example, from the address of the person described in the identity document or the issuer of the document. The identity verification unit 233 of the authentication server 20 extracts and acquires the affiliation information of the person to be managed and the agent from the identity document when verifying the identities of the person to be managed and the agent. The identity verification unit 233 transmits the acquired affiliation information to the personal data management server 30 via the communication unit 210. The input reception unit 331 of the personal data management server 30 receives the input of the affiliation information received by the communication unit 310 from the authentication server 20. The personal data management unit 332 of the personal data management server 30 registers the affiliation information input by the input reception unit 331 in the personal data storage unit 321 of the storage unit 320. The authority management unit 335 of the personal data management server 30 sets a management target period based on the affiliation information when granting authority to an agent. For example, the authority management unit 335 sets a management target period during which the agent manages the personal data of the person to be managed based on the law corresponding to the country or region indicated by the affiliation information. Thereby, in accordance with the laws of the country to which the person to be managed belongs, the privacy rights of the person to be managed can be appropriately protected.

[0107] Also, in the above-described embodiment, an example in which the authority to manage the personal data of the person to be managed granted to the agent is deleted after the expiration of the management target period has been described, but the present invention is not limited to such an example. For example, the authority management unit 335 may allow the person to be managed to select whether to continue the personal data management by the agent after the expiration of the management target period. If the person to be managed selects to continue the personal data management by the agent, the authority management unit 335 does not delete the authority granted to the agent even after the expiration of the management target period. Alternatively, the authority management unit 335 may re-grant the authority after deleting the authority granted to the agent. Also, the management target period may be re-set by the authority management unit 335 based on the affiliation information, or may be arbitrarily set by the person to be managed or the agent. If the person to be managed selects not to continue the personal data management by the agent (to be removed from the management of the agent), the authority management unit 335 deletes the authority granted to the agent. Thereby, the person to be managed can appropriately control data access to his or her own personal data.

[0108] <9. Example> The above describes the embodiments of the present invention. Subsequently, examples of the embodiments of the present invention will be described.

[0109] (1) First Example In the first example, an example in which the personal data management system 1 according to the above-described embodiment is applied to a bento reservation service will be described. The bento reservation service is a service that reserves and sells bentos for students (e.g., high school students). In this service, a parent (agent) can use the personal data management system 1 to reserve a bento on behalf of a child (person to be managed). In this service, when a parent reserves a bento, for example, they can also search for and select a bento that the child wants to eat or a bento that they want the child to eat. Also, in this service, it is possible to link the result data of the child's bento consumption to the parent and accumulate it in the child's DB. With this service, the parent can manage the child's health condition, and the child can cultivate life log data.

[0110] (2) Second Example In the second example, an example in which the personal data management system 1 according to the above-described embodiment is applied to a face authentication entrance and exit management service will be described. The face authentication entrance and exit management service is a service that manages the entrance and exit of users to spaces such as rooms based on face authentication data. In this service, a parent (agent) can use the personal data management system 1 to opt-in the face image data of their child (person to be managed) together with their own face image data. As a result, the child can use the service without registering themselves.

[0111] (3) Third Example In the third example, an example in which the personal data management system 1 according to the above-described embodiment is applied to a senior greeting service will be described. The senior-oriented welcoming service is a service that picks up elderly people using nursing facilities or retirement homes and takes them home. In this service, a child (agent) can apply for the pick-up on behalf of the elderly parent (the person to be managed) by using the Personal Data Management System 1.

[0112] The above describes the examples of the embodiments of the present invention. Note that some or all of the functions of the Personal Data Management System 1, the user terminal 10, the authentication server 20, the Personal Data Management Server 30, and the Service Management Server 40 in the above-described embodiments may be realized by a computer. In that case, a program for realizing this function may be recorded on a computer-readable recording medium, and the program recorded on this recording medium may be read into a computer system and executed to realize it. Here, the "computer system" shall include hardware such as an OS and peripheral devices. Further, the "computer-readable recording medium" refers to a portable medium such as a flexible disk, a magneto-optical disk, a ROM, a CD-ROM, etc., and a storage device such as a hard disk built in a computer system. Furthermore, the "computer-readable recording medium" also includes something that dynamically holds a program for a short time like a communication line when transmitting a program via a network such as the Internet or a communication line such as a telephone line, and something that holds a program for a certain time like a volatile memory inside a computer system that becomes a server or a client in that case. Also, the above program may be for realizing a part of the aforementioned functions, and may further be realized in combination with a program already recorded in the computer system for realizing the aforementioned functions, or may be realized using a programmable logic device such as an FPGA (Field Programmable Gate Array).

[0113] The embodiments of the present invention have been described in detail with reference to the drawings above. However, the specific configuration is not limited to the above, and various design changes and the like can be made without departing from the gist of the present invention.

Explanation of Signs

[0114] 1…Personal data management system, 10…User terminal, 20…Authentication server, 30…Personal data management server, 40…Service management server, 110…Communication unit, 120…Input unit, 130…Imaging unit, 140…Storage unit, 150…Control unit, 151…Input processing unit, 152…Application processing unit, 153…Wallet management unit, 154…Output processing unit, 160…Output unit, 210…Communication unit, 220…Storage unit, 221…Authentication information storage unit, 230…Control unit, 231…Image acquisition unit, 232…ID authentication approval unit, 233…Identity confirmation unit, 234…Official personal authentication unit, 235…Proof information issuance unit, 310…Communication unit, 320…Storage unit, 321…Personal data storage unit, 322…Relationship information storage unit, 330…Control unit, 331…Input reception unit, 332…Personal data management unit, 333…Catalog processing unit, 334…Relationship management unit, 335…Authority management unit, 336…Opt-in management unit, 410…Communication unit, 420…Storage unit, 421…Service catalog storage unit, 422…User information storage unit, 430…Control unit, 431…Input reception unit, 432…Service catalog management unit, 433…Service processing unit, 3211…Child DB, 3212…Parent DB, NW…Network, SA…Personal data management service, US1…Child, US2…Parent

Claims

1. An input reception unit that receives an input of proof information indicating that, with respect to the relationship between a first user who is a person to be managed and who requires personal data management by an agent, and a second user who is the agent, it has been proven by a third party that the second user is the agent of the first user; An authority management unit that, based on the received proof information, grants the second user, who is the agent, the authority to manage the personal data of the first user, who is the person to be managed; A personal data management system comprising the above.

2. An opt-in management unit that opt-in to the service the information necessary for the service used by the first user among the personal data of the first user, in response to a request from the second user having the authority; The personal data management system according to claim 1, further comprising the above.

3. When the service used by the first user is a service that requires proof of the relationship between the first user and the second user, the opt-in management unit opt-in the proof information to the service. The personal data management system according to claim 2.

4. The personal data of the first user and the personal data of the second user are each managed in separate databases. A relation management unit that sets a relation between a first database in which the personal data of the first user is managed and a second database in which the personal data of the second user, who is the agent of the first user, is managed, based on the received proof information; A personal data management unit that manages the personal data based on the authority and the relation; The personal data management system according to claim 1, further comprising the above.

5. When the personal data of the second user having the authority is updated, if the information common to the first user, who is the person to be managed by the second user, is included in the updated personal data, the personal data management unit also updates the personal data of the first user in the same manner. The personal data management system according to claim 4.

6. When the person to be managed is a minor, when the first user becomes an adult, The authority management department deletes the authority from the second user who is the agent of the first user, The relation management department cancels the relation between the first database of the first user and the second database of the second user who is the agent of the first user, The personal data management system according to claim 4.

7. The agent is a person who has a legally recognized relationship with the person to be managed, The personal data management system according to claim 1.

8. An identity verification department that acquires affiliation information indicating the country or region to which each of the first user and the second user belongs when verifying the identities of the first user and the second user, further comprising, Based on the law corresponding to the country or region indicated by the affiliation information, the authority management department sets the period during which the second user manages the personal data of the first user, The personal data management system according to claim 1.

9. After the expiration of the period, the authority management department allows the first user to select whether to continue the management by the second user, The personal data management system according to claim 8.

10. An input reception process for receiving input of proof information indicating that it has been proven by a third party that the second user is the agent of the first user regarding the relationship between the first user who is the person to be managed and for whom personal data management by the agent is necessary, and the second user who is the agent, An authority management process for granting the second user who is the agent the authority to manage the personal data of the first user who is the person to be managed based on the received proof information, A personal data management method executed by a computer including.

11. A computer, An input reception means for receiving input of proof information indicating that it has been proven by a third party that the second user is the agent of the first user regarding the relationship between the first user who is the person to be managed and for whom personal data management by the agent is necessary, and the second user who is the agent, An authority management means for granting the second user who is the agent the authority to manage the personal data of the first user who is the person to be managed based on the received proof information, A program for causing it to function as...

Citation Information

Patent Citations

  • Service providing method using certificate

    JP2001188757A

  • Information management server, information management method and program

    JP2022138699A

  • Information management server, information management method and program

    JP2023010221A

  • Server device, method for controlling server device, and storage medium

    WO2023242961A1

  • Fukugozairyo

    JP1976066330A