Data access control system, data access control method, and program
The data access control system allows users to track and control the reuse of their personal information across services by recording usage histories, enhancing transparency and enabling efficient data management for service providers.
Patent Information
- Application Number
- JP2024006933
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-19
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2044-01-19
AI Technical Summary
Existing systems do not provide users with visibility into how their personal information is reused across different services, leading to a lack of transparency and control over its usage.
A data access control system that includes a storage unit for personal information, a permission processing unit to obtain user consent, a data linking unit to link information across services, and a usage history management unit to record the history of personal information usage, enabling users to track how their information is reused.
Users can now grasp how their personal information is reused between services, ensuring transparency and control over its usage, while service providers can efficiently manage and monetize user data with recorded usage histories.
Smart Images

Figure 2025112606000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a data access control system, a data access control method, and a program.
Background Art
[0002] Conventionally, various techniques for sharing a user's personal information between services have been proposed under the permission of the user.
[0003] For example, Patent Document 1 below discloses a technique that enables the exchange of the user's personal information required by each other between the service provided by Business Operator A and the service provided by Business Operator B on the premise that there is permission from the user.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, in the technique disclosed in Patent Document 1 above, information indicating which personal information is provided and used for which service is not provided to the user. For this reason, the user could not grasp how their personal information was being reused between services.
[0006] In view of the above problems, an object of the present invention is to provide a data access control system, a data access control method, and a program that enable a user to grasp personal information that is being reused between services.
Means for Solving the Problems
[0007] In order to solve the above problems, a data access control system according to an aspect of the present invention includes a storage unit that stores first personal information obtained by a user using a first service, and when the first personal information corresponding to second personal information required for using a second service is stored in the storage unit, a permission processing unit that obtains a permission to use from the user regarding the first personal information corresponding to the second personal information to be used by the second service, a data linking processing unit that links the first personal information stored in the storage unit to the second service based on the permission to use, and a usage history management unit that records a usage history of the first personal information based on the fact that the first personal information stored in the storage unit has been linked to the second service.
[0008] A data access control method according to an aspect of the present invention includes a storage process of storing first personal information obtained by a user using a first service in a storage unit, a permission processing process of obtaining a permission to use from the user regarding the first personal information corresponding to second personal information required for using a second service when the first personal information corresponding to the second personal information is stored in the storage unit, a data linking processing process of linking the first personal information stored in the storage unit to the second service based on the permission to use, and a usage history management process of recording a usage history of the first personal information based on the fact that the first personal information stored in the storage unit has been linked to the second service, and is a data access control method executed by a computer including these processes.
[0009] A program according to an aspect of the present invention causes a computer to function as storage means for storing first personal information obtained when a user uses a first service in a storage unit, and when the first personal information corresponding to second personal information necessary for using a second service is stored in the storage unit, permission processing means for obtaining permission from the user for the second service to use the first personal information corresponding to the second personal information, data linking processing means for linking the first personal information stored in the storage unit to the second service based on the use permission, and use history management means for recording a use history of the first personal information based on the first personal information stored in the storage unit being linked to the second service.
Effect of the Invention
[0010] According to the present invention, it is possible to grasp personal information that is being reused by a user between services.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Mode for Carrying Out the Invention
[0012] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.
[0013] <1. Overview of Data Link Service> With reference to FIG. 1, the overview of the data link service according to this embodiment will be described. FIG. 1 is a diagram showing the overview of the data link service according to this embodiment.
[0014] The data link service is a service for linking (sharing) the personal information of users, who are users of each service, among a plurality of services. In FIG. 1, as an example, a data link service SA for linking the personal information of user US between the first service SA1 and the second service SA2 is shown. In the example shown in FIG. 1, based on the control by the data link system 1, the personal information of user US is linked between the first service SA1 and the second service SA2.
[0015] Here, the flow when user US uses the data link service SA will be described. First, user US deposits personal information with the data link system 1 (step S1). The personal information deposited by the user here is information that can be commonly used in a plurality of services, such as name, date of birth, address, phone number, email address, etc. The data link system 1 obtains a usage permission from the user regarding the use of the personal information deposited by user US in the first service SA1. (Step S2). When obtaining the license from the user US, the data linkage system 1 links the personal information deposited by the user US to the first service SA1 (step S3). Based on the personal information linked from the data linkage system 1, the first service SA1 provides services to the user US (step S4).
[0016] The data linkage system 1 obtains the license from the user regarding depositing the personal information obtained by the user US using the first service SA1 from the first service SA1 to the data linkage system 1. (step S5). When obtaining the license from the user US, the first service SA1 deposits the personal information obtained by the user US using the first service SA1 to the data linkage system 1 (step S6).
[0017] The data linkage system 1 obtains the license from the user regarding using the personal information deposited by the user US with the second service SA2 and using the personal information deposited from the first service SA1 with the second service SA2. (step S7). When obtaining the license from the user US, the data linkage system 1 links the personal information deposited by the user US and the personal information deposited from the first service SA1 to the second service SA2 (step S8, step S9). Based on the personal information linked from the data linkage system 1, the second service SA2 provides services to the user US (step S10).
[0018] The data linkage system 1 obtains the license from the user regarding depositing the personal information obtained by the user US using the second service SA2 from the second service SA2 to the data linkage system 1. (step S11). When obtaining the license from the user US, the second service SA2 deposits the personal information obtained by the user US using the second service SA2 to the data linkage system 1 (step S12). The second service SA2 pays the first service SA1 the consideration for using the personal information of the first service SA1 via the data linkage system 1 (step S13).
[0019] <2. Configuration of the data linkage system> As described above, the outline of the data linkage service according to this embodiment has been explained. Next, with reference to FIG. 2, the configuration of the data linkage system according to this embodiment will be explained. FIG. 2 is a diagram showing an example of the configuration of the data linkage system according to this embodiment. The data linkage system 1 shown in FIG. 2 is a system for operating the data linkage service SA whose outline was explained with reference to FIG. 1.
[0020] As shown in FIG. 2, the data linkage system 1 includes a user terminal 10, a data access control system 20, a first service system 30, and a second service system 40. For the network NW, as a configuration for exchanging information, for example, a LAN (Local Area Network), a WAN (Wide Area Network), a telephone network (such as a mobile phone network, a fixed telephone network, etc.), a regional IP (Internet Protocol) network, the Internet, a QKD network, etc. are applicable.
[0021] (1) User terminal 10 The user terminal 10 is a terminal that a user operates to use the data linkage service. The user terminal 10 is, for example, a smartphone, a tablet terminal, a PC (Personal Computer), etc. The user terminal 10 is communicably connected to the data access control system 20, the first service system 30, and the second service system 40 via the network NW.
[0022] On the user terminal 10, a screen for controlling access to personal information from each service is displayed by an application (hereinafter also referred to as the "access control application") for the user to use the data access control system 20. The user can manage access control (permission to use) to personal information by operating the screen displayed on the user terminal 10 by the access control application. In addition, on the user terminal 10, a screen for using each service is displayed by an application (hereinafter also referred to as the "service application") for the user to use each service. The user can use each service by operating the screen displayed on the user terminal 10 by the service application. Note that the functions of the access control application and the service application may be provided by installing the access control application and the service application on the user terminal 10 (that is, a native application), or may be provided by a Web system (that is, a Web application). In the case of a Web application, the access control application and the service application are managed on a server, and their functions are provided via a Web browser.
[0023] (2) Data access control system 20 The data access control system 20 is a system for controlling access by each service to the user's personal information. The data access control system 20 is composed of, for example, a PC, one or more servers (for example, a cloud server), a combination of a PC and a server, and the like. The data access control system 20 is communicably connected to the user terminal 10, the first service system 30, and the second service system 40 via the network NW.
[0024] (3) First service system 30 The first service system 30 is a system used for the first service SA1 provided by the first operator. The first service system 30 is composed of, for example, a PC, one or more servers (such as cloud servers), a combination of a PC and a server, etc. The first service system 30 is communicably connected to the user terminal 10 and the data access control system 20 via the network NW.
[0025] (4) The second service system 40 The second service system 40 is a system used for the second service SA2 provided by the second operator. The second service system 40 is composed of, for example, a PC, one or more servers (such as cloud servers), a combination of a PC and a server, etc. The second service system 40 is communicably connected to the user terminal 10 and the data access control system 20 via the network NW.
[0026] (3. Functional configuration of the user terminal) As described above, the configuration of the data linkage system 1 according to the present embodiment has been explained. Subsequently, with reference to FIG. 3, the functional configuration of the user terminal 10 according to the present embodiment will be explained. FIG. 3 is a block diagram showing an example of the functional configuration of the user terminal 10 according to the present embodiment. As shown in FIG. 3, the user terminal 10 includes a communication unit 110, an input unit 120, a storage unit 130, a control unit 140, and an output unit 150.
[0027] (1) Communication unit 110 The communication unit 110 has a function of transmitting and receiving various information. The communication unit 110 performs transmission and reception of various information with, for example, the data access control system 20, the first service system 30, and the second service system 40.
[0028] (2) Input unit 120 The input unit 120 has a function of receiving an input. The input unit 120 is composed of, for example, an input device provided by the user terminal 10 as hardware, such as buttons, a touch panel, a microphone, a mouse, a keyboard, etc.
[0029] (3) Memory unit 130 The memory unit 130 has a function of storing various information. The function of the memory unit 130 is realized by a storage medium provided by the user terminal 10 as hardware, such as an HDD (Hard Disk Drive), an SSD (Solid State Drive), a flash memory, an EEPROM (Electrically Erasable Programmable Read Only Memory), a RAM (Random Access read / write Memory), a ROM (Read Only Memory), or an arbitrary combination of these storage media.
[0030] (4) Control unit 140 The control unit 140 has a function of controlling the overall operation of the user terminal 10. The function of the control unit 140 is realized, for example, by causing a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit) provided by the user terminal 10 as hardware to execute a program. As shown in FIG. 3, the control unit 140 includes an input processing unit 141 and an output processing unit 142.
[0031] (4-1) Input processing unit 141 The input processing unit 141 has a function of receiving the user's operation input to the input unit 120 and executing processing according to the operation content. The function of the input processing unit 141 is executed by an access control application and a service application. When the input unit 120 receives a deposit operation of personal information, the input processing unit 141 transmits the personal information input by the user from the communication unit 110 to the data access control system 20. In addition, when the input processing unit 141 receives a personal information use permission operation from the input unit 120, it transmits the result of the use permission input by the user from the communication unit 110 to the data access control system 20. In addition, when the input processing unit 141 receives a personal information deposit permission operation from the input unit 120, it transmits the result of the deposit permission input by the user from the communication unit 110 to the data access control system 20. In addition, when the input processing unit 141 receives a service use operation from the input unit 120, it transmits a service provision request selected by the user from the communication unit 110 to the service system corresponding to the selected service.
[0032] (4-2) Output processing unit 142 The output processing unit 142 has a function of controlling the output in the output unit 150. The output processing unit 142 causes the output unit 150 to display a screen based on the information received by the communication unit 110 from the data access control system 20, the first service system 30, and the second service system 40.
[0033] (5) Output unit 150 The output unit 150 has a function of outputting various types of information. The output unit 150 is composed of, for example, an output device provided as hardware in the user terminal 10, such as a display device such as a display or a touch screen (touch panel), or an audio output device such as a speaker.
[0034] <4. Functional configuration of the data access control system> As described above, the functional configuration of the user terminal 10 according to the present embodiment has been described. Next, with reference to FIG. 4, the functional configuration of the data access control system 20 according to the present embodiment will be described. FIG. 4 is a block diagram showing an example of the functional configuration of the data access control system 20 according to the present embodiment. As shown in FIG. 4, the data access control system 20 includes a communication unit 210, a storage unit 220, and a control unit 230.
[0035] (1) Communication unit 210 The communication unit 210 has a function of transmitting and receiving various types of information. The communication unit 210 performs transmission and reception of various types of information with, for example, the user terminal 10, the first service system 30, and the second service system 40.
[0036] (2) Memory unit 220 The memory unit 220 has a function of storing various types of information. The function of the memory unit 220 is configured by a storage medium that the data access control system 20 includes as hardware, for example, an HDD, an SSD, a flash memory, an EEPROM, a RAM, a ROM, or any combination of these storage media.
[0037] The memory unit 220 stores, for example, item information. The item information is information (for example, a list) indicating the item names of personal information related to each service. The item information is information indicating, for example, personal information necessary for using the service and personal information obtained by using the service. The item information is prepared for each of the first service SA1 and the second service SA2. Also, the memory unit 220 stores, for example, personal information that the user registers in advance from the user terminal 10, personal information (first personal information) obtained by the user using the first service SA1, and personal information obtained by the user using the second service SA2. Each personal information is information deposited in the data access control system 20 based on the user's permission to use.
[0038] Note that hereinafter, the personal information that the user registers in advance from the user terminal 10 is also referred to as "registered personal information". The personal information necessary for using the first service SA1 is also referred to as "first necessary personal information", and the personal information necessary for using the second service SA2 is also referred to as "second necessary personal information". The personal information obtained by the user using the first service SA1 is also referred to as "first used personal information", and the personal information obtained by the user using the second service SA2 is also referred to as "second used personal information".
[0039] (3) Control unit 230 The control unit 230 has a function of controlling the overall operation of the data access control system 20. The control unit 230 is realized, for example, by causing a CPU or GPU included in the data access control system 20 as hardware to execute a program. As shown in FIG. 4, the control unit 230 includes a data cooperation processing unit 231, an authorization processing unit 232, a matching processing unit 233, a data extraction unit 234, a usage history management unit 235, a consideration processing unit 236, and an output control unit 237.
[0040] (3-1) Data cooperation processing unit 231 The data cooperation processing unit 231 has a function of performing processing related to data cooperation. For example, the data cooperation processing unit 231 acquires the registered personal information received by the communication unit 210 from the user terminal 10 and stores (registers) it in the storage unit 220.
[0041] Also, based on the user's usage authorization, the data cooperation processing unit 231 cooperates the registered personal information stored in the storage unit 220 with the first service SA1 or the second service SA2. Specifically, the data cooperation processing unit 231 transmits the registered personal information to the first service system 30 or the second service system 40 via the communication unit 210. Also, based on the user's usage authorization, the data cooperation processing unit 231 cooperates the first usage personal information stored in the storage unit 220 with the second service SA2. Specifically, the data cooperation processing unit 231 transmits the first usage personal information to the second service system 40 via the communication unit 210. Also, based on the user's usage authorization, the data cooperation processing unit 231 cooperates the second usage personal information stored in the storage unit 220 with the first service SA1. Specifically, the data cooperation processing unit 231 transmits the second usage personal information to the first service system 30 via the communication unit 210.
[0042] (3-2) Authorization processing unit 232 The permission processing unit 232 has a function of performing processing related to various permissions by the user. For example, the permission processing unit 232 obtains from the user a permission to use personal information via the user terminal 10. As an example, the permission processing unit 232 obtains from the user a permission to use the registered personal information by the first service SA1 or the second service SA2, a permission to use the second personal information to be used by the first service SA1, a permission to use the first personal information to be used by the second service SA2, and the like.
[0043] In addition, the permission processing unit 232 obtains from the user a permission to deposit personal information via the user terminal 10. As an example, the permission processing unit 232 obtains from the user a permission to deposit the first personal information to be used by the first service SA1 into the data access control system 20, a permission to deposit the second personal information to be used by the second service SA2 into the data access control system 20, and the like.
[0044] (3-3) Matching processing unit 233 The matching processing unit 233 has a function of performing matching processing. The matching processing unit 233 performs matching between the personal information of the cooperation source and the personal information of the cooperation destination in the matching processing. For example, the matching processing unit 233 performs matching between the personal information obtained by using the service that is the cooperation source of the personal information and the necessary personal information required for using the service that is the cooperation destination of the personal information. The matching processing unit 233 extracts data that matches (coincides) between the personal information to be used and the necessary personal information by the matching.
[0045] As an example, the matching processing unit 233 performs matching between the first personal information to be used and the second necessary personal information based on the item information (first item information) indicating the item name of the first personal information to be used obtained by the first service SA1 and the item information (second item information) indicating the item name of the personal information (second personal information) required for using the second service SA2. Through this matching, the matching processing unit 233 can check whether there is personal information necessary for the user to use the second service SA2 among the personal information obtained by the user using the first service SA1.
[0046] (3-4) Data extraction unit 234 The data extraction unit 234 has a function of extracting data. For example, the data extraction unit 234 extracts necessary personal information from the personal information stored in the storage unit 220. As an example, the data extraction unit 234 extracts the first usage personal information to be provided to the second service SA2 from the first usage personal information stored in the storage unit 220 based on the matching result by the matching processing unit 233.
[0047] (3-5) Usage history management unit 235 The usage history management unit 235 has a function of managing the usage history of personal information. For example, when the personal information stored in the storage unit 220 is linked to each service, the usage history management unit 235 records the details regarding the linkage as the usage history. As an example, the usage history management unit 235 records the usage history of the first usage personal information based on the fact that the first usage personal information stored in the storage unit 220 is linked to the second service SA2. The details regarding the linkage indicated by the usage history are, for example, the item name of the linked personal information, the source of linkage (access source), the destination of linkage (access destination), the number of usage times (number of accesses), the data volume, and the like.
[0048] (3-6) Consideration processing unit 236 The consideration processing unit 236 has a function of performing processing related to the payment of consideration for the use of personal information. For example, based on the usage history, the consideration processing unit 236 calculates the consideration for the use of personal information stored in the storage unit 220 and causes the user to pay the consideration to the provider of the personal information. As an example, when the first usage personal information of the first service SA1 stored in the storage unit 220 is linked to the second service SA2, the consideration processing unit 236 causes the second service SA2 to pay the consideration for using the first usage personal information to the first service SA1. In this case, the consideration processing unit 236 calculates the consideration according to the usage of the first usage personal information by the second service SA2 based on the usage history. The usage of the first usage personal information can be calculated, for example, from the number of usage times and the data volume indicated by the usage history.
[0049] Here, the method for calculating the consideration by the consideration processing unit 236 will be specifically described. As an example, the method for calculating the consideration when the second service SA2 uses the first usage personal information of the first service SA1 will be described. First, the consideration processing unit 236 extracts the access source (in this case, the second service SA2), the access destination (in this case, the first service SA1), the number of access times, and the data volume from the usage history stored in the storage unit 220. Based on the extracted number of access times and data volume, the consideration processing unit 236 calculates the consideration (for example, the fee) that the access source pays to the access destination. At this time, the consideration processing unit 236 may automatically calculate the rate so that the higher the number of access times (that is, the higher the demand), the higher the fee, and the lower the number of access times (that is, the lower the demand), the lower the fee. Similarly, for the data volume, the consideration processing unit 236 may also automatically calculate the rate so that the larger the data volume, the higher the fee, and the smaller the data volume, the lower the fee. On the other hand, the consideration processing unit 236 may also automatically calculate the rate so that the higher the number of access times or the data volume, the lower the fee, and the lower the number of access times or the data volume, the higher the fee. Note that the calculated fee may be a real currency such as yen or dollars, or may be a token such as an alternative currency or a virtual currency.
[0050] (3-7) Output control unit 237 The output control unit 237 has a function of controlling the output of various information. For example, the output control unit 237 transmits the usage history recorded by the usage history management unit 235 to the user terminal 10, and causes the user terminal 10 to display the usage history. The usage history is transmitted to the user terminal 10 via the communication unit 210. By checking the usage history displayed on the user terminal 10, the user can grasp how his / her personal information is reused among services.
[0051] <5. Functional configuration of the first service system> The functional configuration of the data access control system 20 according to the present embodiment has been described above. Subsequently, with reference to FIG. 5, the functional configuration of the first service system 30 according to the present embodiment will be described. FIG. 5 is a diagram showing an example of the functional configuration of the first service system 30 according to the present embodiment. As shown in FIG. 5, the first service system 30 includes a communication unit 310, a storage unit 320, and a control unit 330.
[0052] (1) Communication unit 310 The communication unit 310 has a function of transmitting and receiving various information. The communication unit 310 performs transmission and reception of various information with, for example, the user terminal 10 and the data access control system 20.
[0053] (2) Storage unit 320 The storage unit 320 has a function of storing various information. The function of the storage unit 320 is configured by a storage medium included in the first service system 30 as hardware, for example, an HDD, an SSD, a flash memory, an EEPROM, a RAM, a ROM, or any combination of these storage media.
[0054] The storage unit 320 stores, for example, registered personal information that has been permitted by the user and linked from the data access control system 20, and first usage personal information obtained by the user using the first service SA1.
[0055] (3) Control unit 330 The control unit 330 has a function of controlling the overall operation of the first service system 30. The control unit 330 is realized, for example, by causing a CPU or GPU provided as hardware in the first service system 30 to execute a program. As shown in FIG. 5, the control unit 330 includes a personal information processing unit 331, a service processing unit 332, and an output control unit 333.
[0056] (3-1) Personal information processing unit 331 The personal information processing unit 331 has a function of performing processing related to personal information. For example, the personal information processing unit 331 generates item information indicating personal information related to the first service SA1 and transmits it to the data access control system 20. The item information is information indicating, for example, personal information necessary for using the first service SA1 or personal information obtained by using the first service SA1. Note that the item information is transmitted to the data access control system 20 via the communication unit 310.
[0057] In addition, the personal information processing unit 331 prepares the personal information requested from the data access control system 20 and transmits it to the data access control system 20. The personal information is, for example, the first usage personal information permitted by the user to be deposited in the data access control system 20.
[0058] (3-2) Service processing unit 332 The service processing unit 332 has a function of performing processing related to the first service SA1. For example, the service processing unit 332 performs processing for the user to access the first service SA1, processing for the user to register for the first service SA1, processing for providing the first service SA1 to the user, and the like.
[0059] (3-3) Output control unit 333 The output control unit 333 has a function of controlling the output of various information. For example, the output control unit 333 transmits information regarding a screen for the user to use the first service SA1 to the user terminal 10 and causes the user terminal 10 to display the screen. The information regarding the screen is transmitted to the user terminal 10 via the communication unit 310.
[0060] <6. Functional configuration of the second service system> The functional configuration of the first service system 30 according to the present embodiment has been described above. Subsequently, with reference to FIG. 6, the functional configuration of the second service system 40 according to the present embodiment will be described. FIG. 6 is a diagram showing an example of the functional configuration of the second service system 40 according to the present embodiment. As shown in FIG. 6, the second service system 40 includes a communication unit 410, a storage unit 420, and a control unit 430.
[0061] (1) Communication unit 410 The communication unit 410 has a function of transmitting and receiving various information. The communication unit 410 performs transmission and reception of various information with, for example, the user terminal 10 and the data access control system 20.
[0062] (2) Storage unit 420 The storage unit 420 has a function of storing various information. The function of the storage unit 420 is configured by a storage medium included in the second service system 40 as hardware, for example, an HDD, an SSD, a flash memory, an EEPROM, a RAM, a ROM, or an arbitrary combination of these storage media.
[0063] The storage unit 320 stores, for example, registered personal information permitted by the user and linked from the data access control system 20, first usage personal information permitted by the user and linked from the data access control system 20, second usage personal information obtained when the user uses the second service SA2, and the like.
[0064] (3) Control Unit 430 The control unit 430 has a function of controlling the overall operation of the second service system 40. The control unit 430 is realized, for example, by causing a CPU or GPU provided as hardware in the second service system 40 to execute a program. As shown in FIG. 6, the control unit 430 includes a personal information processing unit 431, a service processing unit 432, and an output control unit 433.
[0065] (3-1) Personal Information Processing Unit 431 The personal information processing unit 431 has a function of performing processing related to personal information. For example, the personal information processing unit 431 generates item information indicating personal information related to the second service SA2 and transmits it to the data access control system 20. The item information is information indicating, for example, personal information necessary for using the second service SA2 or personal information obtained by using the second service SA2. Note that the item information is transmitted to the data access control system 20 via the communication unit 410.
[0066] In addition, the personal information processing unit 431 prepares personal information requested from the data access control system 20 and transmits it to the data access control system 20. The personal information is, for example, second-use personal information permitted by the user to be deposited in the data access control system 20.
[0067] (3-2) Service Processing Unit 432 The service processing unit 432 has a function of performing processing related to the second service SA2. For example, the service processing unit 432 performs processing for the user to access the second service SA2, processing for the user to register for the second service SA2, processing for providing the second service SA2 to the user, and the like.
[0068] (3-3) Output Control Unit 433 The output control unit 433 has a function of controlling the output of various information. For example, the output control unit 433 transmits information regarding a screen for the user to use the second service SA2 to the user terminal 10 and causes the user terminal 10 to display the screen. The information regarding the screen is transmitted to the user terminal 10 via the communication unit 410.
[0069] <7. Flow of processing> The functional configuration of the second service system 40 according to the present embodiment has been described above. Subsequently, with reference to FIGS. 7 to 10, the flow of processing according to the present embodiment will be described.
[0070] (1) Flow of processing related to the use of the first service With reference to FIG. 7, the flow of processing related to the use of the first service SA1 according to the present embodiment will be described. FIG. 7 is a sequence diagram showing an example of the flow of processing related to the use of the first service SA1 according to the present embodiment. The processing shown in FIG. 7 includes processing corresponding to steps S1 to S4 described with reference to FIG. 1.
[0071] As shown in FIG. 7, first, the user terminal 10 transmits personal information to the data access control system 20 (step S101). The processing of step S101 is processing performed for the user to deposit personal information in the data access control system 20 and corresponds to the processing of step S1 shown in FIG. 1. Specifically, when the input processing unit 141 of the user terminal 10 receives a personal information deposit operation from the user by the input unit 120, the input processing unit 141 transmits the personal information input by the user from the communication unit 110 to the data access control system 20.
[0072] The data linking processing unit 231 of the data access control system 20 registers the personal information (step S102). Specifically, the data linking processing unit 231 stores the personal information received from the user terminal 10 by the communication unit 210 in the storage unit 220.
[0073] The first service system 30 transmits item information of personal information related to the first service SA1 to the data access control system 20 (step S103). Specifically, the personal information processing unit 331 of the first service system 30 generates item information indicating personal information necessary for using the first service SA1, personal information obtained by using the first service SA1, etc., and transmits it to the data access control system 20 via the communication unit 310. The data linkage processing unit 231 of the data access control system 20 registers the item information (step S104). Specifically, the data linkage processing unit 231 causes the storage unit 220 to store the item information received by the communication unit 210 from the first service system 30.
[0074] Next, the data access control system 20 obtains permission for using personal information in the first service SA1 (step S105). Note that the process of step S105 corresponds to the process of step S2 shown in FIG. 1. Specifically, the permission processing unit 232 of the data access control system 20 obtains permission for using the registered personal information in the first service SA1 from the user via the user terminal 10.
[0075] The user terminal 10 transmits the permission result to the data access control system 20 (step S106). Specifically, when the input processing unit 141 of the user terminal 10 receives a personal information use permission operation by the input unit 120, the input processing unit 141 transmits the use permission result input by the user from the communication unit 110 to the data access control system 20. The data access control system 20 registers the permission result (step S107). Specifically, the permission processing unit 232 of the data access control system 20 causes the storage unit 220 to store the use permission result received by the communication unit 210 from the user terminal 10.
[0076] Next, the user terminal 10 transmits a service provision request to the first service system 30 (step S108). Specifically, when the input processing unit 141 of the user terminal 10 receives a service usage operation from the input unit 120, it transmits a provision request for the first service SA1 selected by the user to the first service system 30 via the communication unit 110. Next, the first service system 30 accesses personal information (step S109). Specifically, the service processing unit 332 of the first service system 30 accesses the personal information stored in the storage unit 220 of the data access control system 20 in order to obtain the personal information necessary for providing the first service SA1.
[0077] The permission processing unit 232 of the data access control system 20 checks whether the service that has accessed the personal information has already obtained permission to use it (step S110). If permission has already been obtained (step S110 / YES), the process proceeds to step S111. On the other hand, if permission has not been obtained (step S110 / NO), the permission processing unit 232 requests permission to use from the user. If there is a permission operation from the user, the process is repeated from step S106. Note that instead of requesting permission to use, the permission processing unit 232 may send a notification indicating that the first service SA1 cannot be used to the user terminal 10, or may display an error screen on the user terminal 10.
[0078] When the process proceeds to step S111, the data access control system 20 transmits the personal information to the first service system 30 (step S111). Note that the process of step S111 corresponds to the process of step S3 shown in FIG. 1. Specifically, the data linking processing unit 231 of the data access control system 20 transmits the registered personal information to the first service system 30 via the communication unit 210. At this time, the data linking processing unit 231 may transmit only the necessary personal information to the first service system 30 based on the item information registered in step S104.
[0079] Next, the first service system 30 provides the first service SA1 (step S112). The process of step S112 corresponds to the process of step S4 shown in FIG. 1. Specifically, the service processing unit 332 of the first service system 30 transmits information for the user to use the first service SA1 to the user terminal 10 via the communication unit 310.
[0080] (2) Flow of processing related to personal information obtained in the first service With reference to FIG. 8, the flow of processing related to personal information obtained in the first service SA1 according to the present embodiment will be described. FIG. 8 is a sequence diagram showing an example of the flow of processing related to personal information obtained in the first service SA1 according to the present embodiment. The processing shown in FIG. 8 includes processing corresponding to steps S5 to S6 described with reference to FIG. 1.
[0081] As shown in FIG. 8, first, the data access control system 20 acquires a deposit permission for personal information obtained in the first service SA1 (step S201). The process of step S201 corresponds to the process of step S5 shown in FIG. 1. Specifically, the permission processing unit 232 of the data access control system 20 acquires a deposit permission from the user via the user terminal 10 regarding the deposit of the first used personal information into the data access control system 20.
[0082] The user terminal 10 transmits the permission result to the data access control system 20 (step S202). Specifically, when the input processing unit 141 of the user terminal 10 receives a deposit permission operation for personal information, the input processing unit 141 transmits the deposit permission result input by the user from the communication unit 110 to the data access control system 20. The data access control system 20 registers the permission result (step S203). Specifically, the permission processing unit 232 of the data access control system 20 stores the deposit permission result received from the user terminal 10 in the storage unit 220 via the communication unit 210.
[0083] Next, the permission processing unit 232 of the data access control system 20 checks whether the user has already given permission for the first personal information for deposit (step S204). If the permission for deposit has already been given (step S204 / YES), the process proceeds to step S205. On the other hand, if the permission for deposit has not been given (step S204 / NO), the permission processing unit 232 requests the user to give permission for deposit. If there is a deposit permission operation from the user, the process is repeated from step S202. Note that instead of requesting the deposit permission, the permission processing unit 232 may send a notification indicating that the deposit of the first personal information has not been permitted to the user terminal 10, or may cause an error screen to be displayed on the user terminal 10.
[0084] When the process proceeds to step S205, the data access control system 20 requests personal information from the first service system 30 (step S205). Specifically, the data cooperation processing unit 231 of the data access control system 20 sends a request for the first personal information permitted to be deposited by the user to the first service system 30 via the communication unit 210.
[0085] The first service system 30 sends the personal information requested from the data access control system 20 (step S206). Note that the process of step S206 corresponds to the process of step S6 shown in FIG. 1. Specifically, the personal information processing unit 331 of the first service system 30 sends the first personal information permitted by the user to be deposited to the data access control system 20 via the communication unit 310.
[0086] The data access control system 20 registers the personal information received from the first service system 30 (step S207). Specifically, the data cooperation processing unit 231 of the data access control system 20 stores the first personal information received by the communication unit 210 from the first service system 30 in the storage unit 220.
[0087] (3) Processing flow for using the second service With reference to FIG. 9, the processing flow for using the second service SA2 according to the present embodiment will be described. FIG. 9 is a sequence diagram showing an example of the processing flow for using the second service SA2 according to the present embodiment. Note that the processing shown in FIG. 9 includes processing corresponding to steps S7 to S10 described with reference to FIG. 1.
[0088] As shown in FIG. 9, first, the second service system 40 transmits item information of personal information related to the second service SA2 to the data access control system 20 (step S301). Specifically, the personal information processing unit 431 of the second service system 40 generates item information indicating personal information necessary for using the second service SA2 and personal information obtained by using the second service SA2, and transmits it to the data access control system 20 via the communication unit 410. The data linkage processing unit 231 of the data access control system 20 registers the item information (step S302). Specifically, the data linkage processing unit 231 causes the storage unit 220 to store the item information received by the communication unit 210 from the second service system 40.
[0089] Next, the data access control system 20 performs a matching process (step S303). Specifically, the matching processing unit 233 of the data access control system 20 performs matching between the first item information indicating the first usage personal information in the first service SA1 and the second item information indicating the second necessary personal information in the second service SA2, based on the first usage personal information and the second necessary personal information.
[0090] Next, the data access control system 20 extracts personal information (step S304). Specifically, based on the matching result by the matching processing unit 233, the data extraction unit 234 of the data access control system 20 extracts the first usage personal information to be provided to the second service SA2 from the first usage personal information stored in the storage unit 220. Here, the data extraction unit 234 extracts the personal information that matches (is identical) between the first usage personal information indicated by each item information and the second necessary personal information from the first usage personal information in the storage unit 220.
[0091] Next, the data access control system 20 generates and presents a list of items (step S305). Specifically, the matching processing unit 233 of the data access control system 20 generates a list indicating the items of the personal information that matched in the matching process and transmits it to the user terminal 10 via the communication unit 210.
[0092] Next, the data access control system 20 obtains permission for the use of personal information in the second service SA2 (step S306). Note that the process of step S306 is the process corresponding to step S7 shown in FIG. 1. Specifically, the permission processing unit 232 of the data access control system 20 obtains permission for use from the user via the user terminal 10 regarding the use of the registered personal information in the second service SA2 and the use of the first usage personal information in the second service SA2.
[0093] Regarding the acquisition of permission for the use of the first usage personal information, when the first usage personal information corresponding to the second necessary personal information is stored in the storage unit 220, the permission processing unit 232 obtains permission for use from the user regarding the use of the first usage personal information corresponding to the second necessary personal information by the second service SA2. Note that the first usage personal information for which the permission processing unit 232 obtains permission for use is also the first usage personal information extracted by the data extraction unit 234.
[0094] The user terminal 10 transmits the permission result to the data access control system 20 (step S307). Specifically, when the input processing unit 141 of the user terminal 10 receives a personal information use permission operation by the input unit 120, the input processing unit 141 transmits the permission result input by the user from the communication unit 110 to the data access control system 20.
[0095] The permission processing unit 232 of the data access control system 20 confirms the permission result received from the user terminal 10 by the communication unit 210 (step S308). If the permission result indicates that permission has been granted (step S308 / YES), the process proceeds to step S309. On the other hand, if the permission result indicates that permission has not been granted (step S308 / NO), the process proceeds to step S310.
[0096] When the process proceeds to step S309, the data access control system 20 grants an access right (step S309). Specifically, the permission processing unit 232 of the data access control system 20 grants an access right to the second service system 40 for the registered personal information registered in the data access control system 20 and the first used personal information. After the granting, the process proceeds to step S310. When the process proceeds to step S310, the data access control system 20 registers the permission result (step S310). Specifically, the permission processing unit 232 of the data access control system 20 stores the use permission result received from the user terminal 10 by the communication unit 210 in the storage unit 220.
[0097] Next, the user terminal 10 transmits a service provision request to the second service system 40 (step S311). Specifically, when the input processing unit 141 of the user terminal 10 receives a service use operation by the input unit 120, the input processing unit 141 transmits a service provision request for the second service SA2 selected by the user to the second service system 40 via the communication unit 110. Next, the second service system 40 accesses personal information (step S312). Specifically, the service processing unit 432 of the second service system 40 accesses the personal information stored in the storage unit 220 of the data access control system 20 in order to obtain the personal information necessary for providing the second service SA2.
[0098] The permission processing unit 232 of the data access control system 20 checks whether the service that has accessed the personal information has been permitted for use (access rights have been granted) (step S313). If it has been permitted for use (step S313 / YES), the process proceeds to step S314. On the other hand, if it has not been permitted for use (step S313 / NO), the permission processing unit 232 requests permission for use from the user. If there is a permission for use operation from the user, the process is repeated from step S307. Note that instead of requesting permission for use, the permission processing unit 232 may send a notification indicating that the second service SA2 cannot be used to the user terminal 10, or may display an error screen on the user terminal 10.
[0099] When the process proceeds to step S314, the data access control system 20 transmits the personal information to the second service system 40 (step S314). Note that the process of step S314 corresponds to the processes of steps S8 and S9 shown in FIG. 1. Specifically, the data cooperation processing unit 231 of the data access control system 20 transmits the registered personal information and the first used personal information to the second service system 40 via the communication unit 210. At this time, the data cooperation processing unit 231 may transmit only the necessary personal information to the second service system 40 based on the item information registered in step S302.
[0100] Next, the data access control system 20 records the usage history of personal information (step S315). Specifically, the usage history management unit 235 of the data access control system 20 records, as the usage history, the details regarding the linkage for the personal information linked to the second service system 40 among the personal information stored in the storage unit 220.
[0101] Next, the second service system 40 provides the second service SA2 (step S316). Note that the process of step S316 corresponds to the process of step S10 shown in FIG. 1. Specifically, the service processing unit 432 of the second service system 40 transmits, via the communication unit 410, information for the user to use the second service SA2 to the user terminal 10.
[0102] (4) Flow of processing related to payment of consideration for personal information obtained in the second service With reference to FIG. 10, the flow of processing related to payment of consideration for personal information obtained in the second service SA2 according to the present embodiment will be described. FIG. 10 is a sequence diagram showing an example of the flow of processing related to payment of consideration for personal information obtained in the second service SA2 according to the present embodiment. Note that the processing shown in FIG. 10 includes processing corresponding to steps S11 to S13 described with reference to FIG. 1.
[0103] As shown in FIG. 10, first, the data access control system 20 acquires the deposit permission for the personal information obtained in the second service SA2 (step S401). Note that the process of step S401 corresponds to the process of step S11 shown in FIG. 1. Specifically, the permission processing unit 232 of the data access control system 20 acquires the deposit permission from the user via the user terminal 10 regarding the deposit of the second used personal information into the data access control system 20.
[0104] The user terminal 10 transmits the permission result to the data access control system 20 (step S402). Specifically, when the input processing unit 141 of the user terminal 10 receives the deposit permission operation of personal information by the input unit 120, the input processing unit 141 transmits the deposit permission result input by the user from the communication unit 110 to the data access control system 20. The data access control system 20 registers the permission result (step S403). Specifically, the permission processing unit 232 of the data access control system 20 causes the storage unit 220 to store the deposit permission result received by the communication unit 210 from the user terminal 10.
[0105] Next, the permission processing unit 232 of the data access control system 20 checks whether the user has already given permission for the second use of personal information (step S404). If the permission has already been given (step S404 / YES), the process proceeds to step S405. On the other hand, if the permission has not been given (step S404 / NO), the permission processing unit 232 requests the user for permission to deposit. If a permission operation is received from the user, the process is repeated from step S402. Note that instead of requesting permission to deposit, the permission processing unit 232 may send a notification indicating that permission to deposit the second use of personal information has not been granted to the user terminal 10, or may display an error screen on the user terminal 10.
[0106] When the process proceeds to step S405, the data access control system 20 requests personal information from the second service system 40 (step S405). Specifically, the data linkage processing unit 231 of the data access control system 20 transmits a request for the second use of personal information permitted by the user to the second service system 40 via the communication unit 210.
[0107] The second service system 40 transmits the personal information requested from the data access control system 20 (step S406). Note that the process of step S406 corresponds to the process of step S12 shown in FIG. 1. Specifically, the personal information processing unit 431 of the second service system 40 transmits the second usage personal information permitted by the user to be deposited in the data access control system 20 to the data access control system 20 via the communication unit 410.
[0108] The data access control system 20 registers the personal information received from the second service system 40 (step S407). Specifically, the data cooperation processing unit 231 of the data access control system 20 causes the storage unit 220 to store the second usage personal information received by the communication unit 210 from the second service system 40.
[0109] Next, the data access control system 20 calculates the consideration (step S408). Specifically, the consideration processing unit 236 of the data access control system 20 calculates the consideration corresponding to the usage of the first usage personal information by the second service SA2 based on the usage history. After the calculation, the consideration processing unit 236 causes the second service SA2 to pay the consideration for using the first usage personal information to the first service SA1 (step S409). Note that the process of step S409 corresponds to the process of step S13 shown in FIG. 1. Specifically, the consideration processing unit 236 transmits consideration information indicating the calculated consideration to the second service system 40 via the communication unit 210. The second service SA2 pays the consideration to the first service SA1 based on the consideration information.
[0110] The flow of the process according to this embodiment has been described above. As described above, the data access control system 20 according to the present embodiment includes a storage unit 220 that stores first personal information obtained by a user using a first service SA1, and a first personal information corresponding to second personal information necessary for using a second service SA2. When the first personal information is stored in the storage unit 220, a permission processing unit 232 that obtains a usage permission from the user for the second service SA2 to use the first personal information corresponding to the second personal information, and based on the usage permission, a data linking processing unit 231 that links the first personal information stored in the storage unit 220 to the second service SA2, and a usage history management unit 235 that records the usage history of the first personal information based on the fact that the first personal information stored in the storage unit 220 has been linked to the second service SA2.
[0111] With such a configuration, when the first personal information obtained by using the first service SA1 is linked to the second service SA2, its usage history is managed. As a result, the user can grasp his / her personal information that is being reused between services by referring to the usage history. Therefore, the data access control system 20 according to the present embodiment enables the user to grasp personal information that is being reused between services.
[0112] In addition, the data access control system 20 according to the present embodiment manages the personal information obtained with the user's deposit permission among the personal information obtained for each of the plurality of services, and provides the personal information obtained with the user's usage permission among the deposited personal information to other services. If the service provider (service provider) can obtain a usage permission from the user through the data access control system 20, it can obtain personal information with aggregated attributes. As a result, the service provider no longer needs to collect the personal information necessary for the user to use the service independently, and can provide services to the user more efficiently.
[0113] In addition, when the data access control system 20 according to the present embodiment provides the usage personal information deposited by the service provider under the permission of the user to other services under the permission of the user, the usage history is recorded. Further, the data access control system 20 calculates the consideration that the service provider that uses the usage personal information pays to the service provider that has the usage personal information based on the usage history. As a result, the service provider can receive the consideration when providing the personal information it has to other services.
[0114] Note that the operating entity of the data linkage system 1 and the data access control system 20 may be a for-profit organization such as a company that earns revenue from operation fees, or a non-profit neutral organization that does not obtain operation fees.
[0115] <8. Example> The above is the description of the present embodiment. Next, an example of the present embodiment will be described.
[0116] (1) First Example In the first example, an example in which the data linkage system 1 according to the present embodiment is applied to a health information service will be described.
[0117] The health information service is a service that provides the user with the result of analyzing the user's PHR (Personal Health Record) data. In the health information service, the first service acquires the PHR data, and the second service performs an analysis using the PHR data acquired by the first service.
[0118] The first service is, for example, a service that uses the step count data as the PHR data. The first service provides the step count data (usage personal information) acquired by its own service to the second service under the usage permission from the user.
[0119] The second service is, for example, a service that uses meal data as PHR data. The second service combines the step count data obtained in the first service and the meal data obtained in its own service to analyze the user's health and presents the analysis results to the user.
[0120] The analysis in the second service may be performed using AI (Artificial Intelligence). In this case, in the second service, a trained model is generated by machine learning based on the training data that combines the step count data obtained in the first service and the meal data obtained in its own service. The trained model is a model that has learned the relationship between the step count data and meal data and the user's health. Therefore, when the step count data and meal data are input, the trained model can output the analysis results regarding the user's health. Thereby, the service provider can provide an AI health recommendation service by AI.
[0121] Suppose that originally, the service provider planned to procure the step count data by itself or from the users of its own service in the second service. In this case, by using the data cooperation system 1, the provider of the second service can efficiently obtain the step count data from other services without collecting it by itself. Also, the provider of the second service pays a usage fee for the step count data to the provider of the first service. Thereby, the provider of the first service can obtain benefits by making use of the data collected by itself.
[0122] Note that the service user (user) will be contacted each time regarding the usage permission from both the first service and the second service. Thereby, the user can grasp which service the usage has been permitted for. Also, a list showing the permission status may be provided to the user from the data access control system 20. By referring to the list, the user can grasp which personal information usage has been permitted for which service.
[0123] (2) Second Embodiment In the second embodiment, an example in which the data linkage system 1 according to the present embodiment is applied to a conference room rental information service will be described.
[0124] The conference room rental information service is a service that provides the user with the result of analyzing the user's location data. In the conference room rental information service, the first service acquires location data, and the second service performs an analysis using the location data acquired by the first service.
[0125] The first service is, for example, a service using location data. The first service provides the location data (usage personal information) acquired by its own service to the second service under the user's permission to use.
[0126] The second service is, for example, a conference room reservation service. The second service analyzes the conference rooms recommended to the user based on the location data acquired by the first service, and presents the analysis result to the user. For example, it recommends a conference room close to the user's location data.
[0127] In the second service, originally, it was desired to grasp where there is a need from the user for a conference room and which conference rooms should be contracted as service-using conference rooms, but for that purpose, it did not have a means to efficiently acquire the user's location data. Therefore, by using the data linkage system 1, the provider of the second service can efficiently acquire location data from other services without collecting it by itself. As a result, the provider of the second service can contract with conference rooms with a high potential for use by analyzing the location data.
[0128] Note that since the payment of usage fees and the grasping of the usage permission status are the same as in the first embodiment, the description thereof will be omitted.
[0129] (3) Third Embodiment In the third embodiment, an example in which the data linkage system 1 according to the present embodiment is applied to a nutritional value utilization service will be described.
[0130] The nutritional value utilization service is a service that provides the user with the results of analyzing the user's lunch data. In the nutritional value utilization service, the first service acquires lunch data, and the second service performs an analysis using the lunch data acquired by the first service.
[0131] The first service is, for example, a service that sells boxed lunches to students such as high school students. The first service provides the lunch data (usage personal information) acquired by its own service to the second service under the user's permission to use.
[0132] The second service is, for example, a service that sells meal kits to students. The second service analyzes the meal kits sold to the user who is a student based on the lunch data acquired by the first service, and presents the analysis results to the user. For example, sell boxed lunches that eliminate the uneven distribution of nutritional value from the user's lunch data.
[0133] In the second service, originally, in order to provide a service that eliminates the bias in the user's diet, it was desired to grasp what kind of diet the user usually takes, but for that purpose, there was no means to efficiently acquire the user's lunch data. Therefore, by using the data linkage system 1, the provider of the second service can efficiently acquire lunch data from other services without collecting it by itself. As a result, the provider of the second service can develop and sell meal kits that eliminate the uneven distribution of nutritional value by analyzing the lunch data.
[0134] Note that since the payment of the usage fee and the grasp of the usage permission status are the same as in the first embodiment, the description thereof will be omitted.
[0135] (4) Other embodiments Note that the service to which the data linkage system 1 according to the present embodiment is applied is not limited to the services in the above-described embodiments. For example, the data linkage system 1 may be applied to services such as recommendation of content and items to service users, targeted advertising to service users, and crowd flow analysis services, in the same manner as in the above-described embodiments.
[0136] <9. Variation> The above-described examples of the present embodiment have been described. Next, variations of the present embodiment will be described. Note that the variations described below may be applied to the embodiment alone or in combination. Further, the variations may be applied in place of the configurations described in the embodiment, or may be additionally applied to the configurations described in the embodiment.
[0137] The data linkage system 1 according to the above-described embodiment may have a function for proving the authenticity of personal information. For example, the data linkage system 1 may have a public personal authentication function (JPKI: Japanese Public Key Infrastructure) using an electronic certificate. Further, the data linkage system 1 may have an online personal confirmation function (eKYC: electronic Know Your Customer) that allows a third party to confirm that the user is the person himself / herself, using an identity document and, for example, image data of the user's appearance including the user's face. Further, the data linkage system 1 may have a digital certification function (VC: Verifiable Credentials) that can perform content verification online.
[0138] In the above-described embodiment, it has been described that the user can grasp his / her personal information that is secondarily used between services by referring to the usage history, but the interface is not particularly limited. For example, the usage history may be displayed through a user interface such as the portal site of an application. Also, it may be an interface in which a plurality of apps are arranged, such as a wallet app. Also, even if there is no portal site or launcher with a list such as the above-described portal site or wallet app, there may be confirmation of a usage license or presentation of a new service based on the usage from individual services associated with the system. For example, it is a mechanism in which mails or messages are sent to service users from individual services without a list portal.
[0139] Also, in the above-described embodiment, an example has been described in which data that matches (is identical) between the usage personal information and the necessary personal information is extracted in the matching process by the matching processing unit 233, but the example is not limited thereto. For example, the matching processing unit 233 may extract not only data in which the item names (labels) between the matching personal information match, but also data in which the contents correspond even if the item names do not match. For example, in the case of the first embodiment described above, the item name of the data required by the second service is step count data, but when the data corresponding to the step count data registered in the first service is registered under the item name of pedometer information. In this case, the matching processing unit 233 may perform matching in consideration of the difference between the expression (item name) in the first service and the expression (item name) in the second service. That is, the matching processing unit 233 determines that the pedometer information of the first service is the step count data required by the second service, and extracts the pedometer information.
[0140] In the above-described embodiment, an example in which the service (for example, the first service SA1) that is the source of personal information linkage is one has been described, but the example is not limited thereto. For example, there may be a plurality of services that are the sources of personal information linkage. In this case, the data access control system 20 may link the personal information required by the service (for example, the second service SA2) that is the destination of personal information linkage from one service that is the source of linkage, or from a plurality of services that are the sources of linkage. When there are multiple services as cooperation sources, the data access control system 20 may determine the cooperation source in consideration of, for example, the quality of data and the consideration to be paid by the cooperation destination. For example, when the cooperation destination prioritizes the quality of data, the data access control system 20 determines all services having high-quality data as cooperation sources. Here, when the consideration to be paid by the cooperation destination is to be suppressed, the services to be cooperation sources may be further narrowed down.
[0141] The variations of the embodiments of the present invention have been described above. Note that part or all of the functions of the data cooperation system 1, the user terminal 10, the data access control system 20, the first service system 30, and the second service system 40 in the above-described embodiments may be realized by a computer. In that case, a program for realizing this function may be recorded on a computer-readable recording medium, and the program recorded on this recording medium may be read into a computer system and executed to be realized. Note that the "computer system" referred to here includes hardware such as an OS and peripheral devices. In addition, the "computer-readable recording medium" refers to a portable medium such as a flexible disk, a magneto-optical disk, a ROM, a CD-ROM, or the like, and a storage device such as a hard disk incorporated in a computer system. Further, the "computer-readable recording medium" also includes, like a communication line when transmitting a program via a network such as the Internet or a communication line such as a telephone line, a medium that dynamically holds a program for a short time, and a volatile memory inside a computer system serving as a server or a client in that case, which holds a program for a certain period of time. Also, the above program may be for realizing a part of the above-described functions, and may further be realized in combination with a program already recorded in a computer system for realizing the above-described functions, or may be realized using a programmable logic device such as an FPGA (Field Programmable Gate Array).
[0142] As described above, the embodiments of the present invention have been described in detail with reference to the drawings. However, the specific configuration is not limited to the above, and various design changes and the like can be made without departing from the gist of the present invention.
Explanation of Reference Numerals
[0143] 1…Data linkage system, 10…User terminal, 20…Data access control system, 30…First service system, 40…Second service system, 110…Communication unit, 120…Input unit, 130…Storage unit, 140…Control unit, 141…Input processing unit, 142…Output processing unit, 150…Output unit, 210…Communication unit, 220…Storage unit, 230…Control unit, 231…Data linkage processing unit, 232…Permission processing unit, 233…Matching processing unit, 234…Data extraction unit, 235…Usage history management unit, 236…Consideration processing unit, 237…Output control unit, 310…Communication unit, 320…Storage unit, 330…Control unit, 331…Personal information processing unit, 332…Service processing unit, 333…Output control unit, 410…Communication unit, 420…Storage unit, 430…Control unit, 431…Personal information processing unit, 432…Service processing unit, 433…Output control unit, NW…Network
Claims
1. A storage unit that stores first personal information obtained by a user using a first service; A permission processing unit that, when the first personal information corresponding to second personal information necessary for using a second service is stored in the storage unit, obtains a usage permission from the user for the second service to use the first personal information corresponding to the second personal information; A data linking processing unit that links the first personal information stored in the storage unit to the second service based on the usage permission; A usage history management unit that records a usage history of the first personal information based on the first personal information stored in the storage unit being linked to the second service; A data access control system comprising:
2. A consideration processing unit that causes the second service to pay a consideration for using the first personal information to the first service when the first personal information of the first service stored in the storage unit is linked to the second service; The data access control system according to claim 1, further comprising:
3. The consideration processing unit calculates the consideration according to the use of the first personal information by the second service based on the usage history; The data access control system according to claim 2.
4. A matching processing unit that performs matching between the first personal information and the second personal information based on first item information indicating item names of the first personal information obtained in the first service and second item information indicating item names of the second personal information necessary for using the second service; A data extraction unit that extracts the first personal information to be provided to the second service from the first personal information stored in the storage unit based on the result of the matching; further comprising: The permission processing unit obtains a usage permission from the user for the extracted first personal information; The data access control system according to claim 1.
5. A storage process of storing first personal information obtained by a user using a first service in a storage unit; A permission processing process of obtaining a usage permission from the user for the second service to use the first personal information corresponding to the second personal information when the first personal information corresponding to the second personal information necessary for using the second service is stored in the storage unit; A data linkage processing process for linking the first personal information stored in the storage unit to the second service based on the license; A usage history management process for recording the usage history of the first personal information based on the fact that the first personal information stored in the storage unit has been linked to the second service; A data access control method executed by a computer including the above.
6. A computer, A storage means for storing the first personal information obtained by a user using a first service in a storage unit; A license processing means for obtaining a license from the user for the second service to use the first personal information corresponding to the second personal information required for using the second service when the first personal information corresponding to the second personal information is stored in the storage unit; A data linkage processing means for linking the first personal information stored in the storage unit to the second service based on the license; A usage history management means for recording the usage history of the first personal information based on the fact that the first personal information stored in the storage unit has been linked to the second service; A program for causing the computer to function as above.
Citation Information
Patent Citations
Method for information management distribution service
JP2002007862A
Personal data trust system and personal data trust program
JP2020013193A
Personal information management server, personal information management method, and personal information management system
JP2020181275A
System, management server, control method of management server, and storage medium
WO2023166541A1
Personal information management server, personal information management method, and personal information management system
JP7171504B2