Information generation apparatus, information management system, information management method, and program
The information generation device and management system securely manage building structure data by using a secure interface and authority management to trace and update usage rights, addressing data confidentiality and usage tracking.
Patent Information
- Application Number
- JP2024030931
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-01
- Publication Date
- 2025-09-11
AI Technical Summary
Existing systems fail to manage building structure data, which includes highly confidential information, effectively, leading to potential information leaks and unauthorized use, necessitating a solution to trace and secure the usage of such data.
An information generation device and management system that includes a secure interface for data transmission, a secure storage area, and an authority management unit to update usage rights based on data usage status, ensuring secure data processing and tracing.
Enables the use of highly confidential building structure data while preventing information leaks and unauthorized use, allowing secure data processing and tracing usage status.
Smart Images

Figure 2025133162000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an information generating device, an information management system, an information management method, and a program. [Background technology]
[0002] A highly practical disaster prevention simulation requires the construction of an urban structure model. A detailed urban structure model can be constructed using information about building structures. Patent Document 1 discloses a 3D map creation method aimed at creating 3D data of buildings that closely resembles actual streetscapes. The method in Patent Document 1 estimates the building type and material of each building on a 2D map based on at least one of the building's material, main use, and floor area information included in the building information accompanying the 2D map. The method in Patent Document 1 determines the number of floors of a building by probability calculation based on floor-number statistical information for each building type and material in the relevant area. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2001-266177 Summary of the Invention [Problem to be solved by the invention]
[0004] Building structure data held by local governments is useful as information for constructing urban structure models. Building structure data includes information on the number of pillars in a building, the thickness of its walls, and other such information. Building structure data also includes highly confidential information such as personal and confidential information. When using highly confidential information, it is necessary to manage it appropriately to prevent information leaks and unauthorized use. To do this, it is necessary to trace the usage of data containing highly confidential information.
[0005] An object of the present disclosure is to provide an information generation device, an information management system, an information management method, and a program that enable data including highly confidential information to be used while tracing its usage. [Means for solving the problem]
[0006] An information generating device according to one aspect of the present disclosure includes a transmission unit that transmits a usage request for managed data to a management device that manages the managed data, a secure interface that receives the managed data with usage rights set therein and that is transmitted in response to the usage request, a secure storage constructed in a secure area and in which the managed data is stored, a data processing unit that executes data processing using the managed data in the secure area, and an authority management unit that updates authority information included in the usage rights set for the managed data in accordance with the usage status of the managed data. The transmission unit transmits the updated authority information to the management device in accordance with the usage status of the managed data.
[0007] In one aspect of the information management method of the present disclosure, a computer sends a request to use the managed data to a management device that manages the managed data, receives the managed data with usage rights set in response to the usage request, stores the managed data in a secure storage constructed in a secure area, performs data processing using the managed data in the secure area, updates the permission information included in the usage rights set in the managed data depending on the usage status of the managed data, and sends the updated permission information depending on the usage status of the managed data to the management device.
[0008] A program of one embodiment of the present disclosure causes a computer to perform the following processes: sending a request to use managed data to a management device that manages the managed data; receiving managed data with usage rights set in response to the usage request; storing the managed data in a secure storage constructed in a secure area; performing data processing using the managed data in the secure area; updating the permission information included in the usage rights set in the managed data in accordance with the usage status of the managed data; and sending the updated permission information to the management device in accordance with the usage status of the managed data. [Effects of the Invention]
[0009] According to the present disclosure, it is possible to provide an information generation device, an information management system, an information management method, and a program that enable data including highly confidential information to be used while tracing its usage. [Brief explanation of the drawings]
[0010] [Figure 1] 1 is a block diagram illustrating an overview of an information management system according to the present disclosure. [Figure 2] FIG. 2 is a block diagram illustrating an example of a detailed configuration of an information generating device according to the present disclosure. [Figure 3] 10 is a conceptual diagram showing an example of a display of an image related to notification information regarding usage rights transmitted from a management device according to the present disclosure. FIG. [Figure 4] FIG. 2 is a block diagram illustrating an example of a detailed configuration of a management device according to the present disclosure. [Figure 5] 1 is a table illustrating an example of a management table according to the present disclosure. [Figure 6] FIG. 10 is a sequence diagram for explaining a phase for permitting use of management target data according to the present disclosure. [Figure 7] FIG. 10 is a sequence diagram illustrating a rights management phase for management target data according to the present disclosure. [Figure 8] 10 is a table illustrating an example of updating a management table according to the present disclosure. [Figure 9] 10A and 10B are conceptual diagrams illustrating an example of displaying notification information in response to a change in a use flag due to an update of a management table according to the present disclosure. [Figure 10] 10 is a table illustrating an example of updating a management table according to the present disclosure. [Figure 11] 10A and 10B are conceptual diagrams illustrating an example of displaying notification information in response to a change in a use flag due to an update of a management table according to the present disclosure. [Figure 12] 10 is a table illustrating an example of updating a management table according to the present disclosure. [Figure 13] 10A and 10B are conceptual diagrams illustrating an example of displaying notification information in response to a change in a use flag due to an update of a management table according to the present disclosure. [Figure 14] FIG. 1 is a conceptual diagram for explaining an example of data management according to the present disclosure. [Figure 15] 1 is a table illustrating an example of a management table according to the present disclosure. [Figure 16] 1 is a table illustrating an example of building structure data according to the present disclosure. [Figure 17] FIG. 1 is a conceptual diagram illustrating an example of a city structure model constructed by an information generating device according to the present disclosure. [Figure 18] FIG. 1 is a conceptual diagram illustrating an example of an urban structure model constructed by an information generating device according to the present disclosure. [Figure 19] 10 is a flowchart illustrating an example of building an urban structure model by the information generating device according to the present disclosure. [Figure 20] 1 is a conceptual diagram illustrating an example of disaster prevention information generated by an information generating device according to the present disclosure. [Figure 21] 1 is a conceptual diagram illustrating an example of disaster prevention information generated by an information generating device according to the present disclosure. [Figure 22] 1 is a conceptual diagram illustrating an example of disaster prevention information generated by an information generating device according to the present disclosure. [Figure 23] 1 is a conceptual diagram illustrating an example of disaster prevention information generated by an information generating device according to the present disclosure. [Figure 24] 10 is a flowchart illustrating an example of generation of disaster prevention information by the information generation device according to the present disclosure. [Figure 25]FIG. 1 is a block diagram illustrating an example of a configuration of an information generating device according to the present disclosure. [Figure 26] FIG. 10 is a conceptual diagram illustrating an example of updating disaster prevention information according to the present disclosure. [Figure 27] 10 is a flowchart illustrating an example of updating disaster prevention information by the information generating device according to the present disclosure. [Figure 28] 1 is a block diagram illustrating an example of a configuration of an evacuation information providing device according to the present disclosure. [Figure 29] 1 is a conceptual diagram illustrating an example of evacuation information generated by an evacuation information generating device according to the present disclosure. [Figure 30] 1 is a conceptual diagram illustrating an example of evacuation information generated by an evacuation information generating device according to the present disclosure. [Figure 31] 1 is a conceptual diagram illustrating an example of evacuation information generated by an evacuation information generating device according to the present disclosure. [Figure 32] 10 is a flowchart illustrating an example of generation of evacuation information by the evacuation information generation device according to the present disclosure. [Figure 33] FIG. 1 is a block diagram illustrating an example of a configuration of an information generating device according to the present disclosure. [Figure 34] 10 is a flowchart illustrating an example of an operation of the information generating device according to the present disclosure. [Figure 35] FIG. 2 is a block diagram illustrating an example of a hardware configuration for executing processing according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0011] Below, embodiments for implementing the present disclosure are described using the drawings. In this disclosure, the drawings used in the description of each embodiment relate to one or more embodiments. Furthermore, elements included in each drawing may apply to one or more embodiments. The embodiments described below are limited in a way that is technically preferable for implementing the present disclosure, but this does not limit the scope of the disclosure to the following. In all drawings used to describe the following embodiments, similar parts are designated by the same reference numerals unless otherwise specified. In the following embodiments, repeated description of similar configurations and operations may be omitted. The direction of arrows in the drawings is an example and does not limit the direction of data, etc.
[0012] (First embodiment) First, the configuration of an information management system according to the first embodiment will be described with reference to the drawings. The entities that use the information management system according to this embodiment include an administrator who manages highly confidential information (hereinafter, "confidential information") and users who use the highly confidential information. The administrator owns a database. The database stores confidential information. The administrator uses a management device to manage the confidential information stored in the database. Users use an information generation device to use the confidential information stored in the database.
[0013] In the following, an example will be described in which data (building structure data) relating to the structure of a building owned by an owner such as an individual or a corporation is used. The building structure data includes not only data relating to the structure of the building but also highly confidential secret information such as personal information and classified information. The method of this embodiment can be applied to the management of not only building structure data but also any secret information.
[0014] (composition) 1 is a block diagram showing an overview of an information management system according to the present disclosure. The information management system 1 includes an information generating device 10, a management device 170, and a database 180. The information management system 1 may be configured with only the information generating device 10 and the management device 170 without including the database 180. In this case, the database 180 is built on a server or cloud capable of data communication with the information generating device 10. The database 180 may also be built on an information processing device managed by an individual or a corporation.
[0015] The information generating device 10 is an information processing device used by a user. For example, the information generating device 10 is realized by a desktop or notebook personal computer. The information generating device 10 may be built in a cloud or a server accessible from the information processing device used by the user. The information generating device 10 may also be realized by a mobile terminal such as a smartphone or tablet. The information generating device 10 includes a secure area. For example, the secure area is realized by container-type virtualization technology.
[0016] In response to a user's input operation, the information generating device 10 transmits a request to use data including confidential information (also referred to as managed data) to the management device 170. The information generating device 10 acquires the managed data transmitted from the management device 170 in response to the use request via a highly secure interface. The information generating device 10 may be configured to grant authority to access the managed data via the highly secure interface.
[0017] The managed data transmitted from the management device 170 includes confidential information. A usage authority is set for the managed data. The information generating device 10 is granted the right to execute data processing using the managed data within the scope of the usage authority. The information generating device 10 executes data processing using the managed data in a secure area. Data processing in the secure area prevents information leakage and unauthorized use. Furthermore, the information generating device 10 updates the authority information including the usage status of the managed data according to the use of the managed data. The information generating device 10 transmits the authority information including the usage status of the managed data to the management device 170.
[0018] The management device 170 and the database 180 are managed by an administrator. For example, the management device 170 and the database 180 are constructed in a cloud or a server. For example, the status of management of confidential information by the management device 170 is presented to the administrator via an information processing device that can access the management device 170. The database 180 stores management target data including confidential information. For example, the database 180 stores building structure data as management target data. Details of the building structure data will be described later. The management device 170 manages the management target data stored in the database 180. The management device 170 includes a secure area. For example, the secure area is realized by container-type virtualization technology. The management device 170 executes processing related to the management of the management target data in the secure area.
[0019] The management device 170 receives a request to use the management target data from the information generating device 10. In response to the use request transmitted from the information generating device 10, the management device 170 acquires the management target data from the database 180. The management device 170 sets a usage authority for the management target data acquired from the database 180. The management device 170 transmits the management target data for which a usage authority has been set to the information generating device 10 via a highly secure interface. The management device 170 may be configured to grant the information generating device 10 the authority to access the management target data via the highly secure interface.
[0020] The management device 170 acquires authority information including the usage status of the managed data from the information generating device 10. The management device 170 uses the authority information to verify whether the usage status of the managed data by the information generating device 10 is within the scope of the usage authority. If the use of the managed data is within the scope of the usage authority, the management device 170 allows the information generating device 10 to continue using the managed data. If the use of the managed data exceeds the usage authority, the management device 170 terminates the use of the managed data by the information generating device 10. For example, if the use of the managed data exceeds the usage authority, the management device 170 transmits information including a warning to the information generating device 10. For example, if the use of the managed data is about to exceed the usage authority, the management device 170 may be configured to transmit information including a warning to the information generating device 10.
[0021] Next, detailed configurations of the information generating device 10 and the management device 170 will be described with reference to the drawings. In the following, an example will be described in which the management target data is building structure data. The management target data does not have to be building structure data as long as it includes confidential information. Furthermore, the management target data does not necessarily have to include confidential information.
[0022] [Information generation device] 2 is a block diagram showing an example of a detailed configuration of an information generating device according to the present disclosure. Information generating device 10 includes input / output interface 11, transmitter 12, secure interface 13, secure storage 14, data processing unit 15, authority management unit 17, and output unit 18. Secure storage 14, data processing unit 15, and authority management unit 17 are constructed within secure area 130. Data processing unit 15 includes primary processing unit 151 and high-order processing unit 152.
[0023] The information generating device 10 includes a secure area 130. The secure area 130 is a virtual area constructed in a cloud or a server accessible from the terminal device 100 used by the user. The secure area 130 includes a secure storage 14, a data processing unit 15, and an authority management unit 17. For example, the secure area 130 is realized using container-type virtualization technology. The secure area 130 is an encrypted environment and is isolated from a local environment connected to an external environment. Applications running within the secure area 130 cannot connect to the local environment. Data used in the secure area 130 is stored in the secure area 130. The data used in the secure area 130 is not stored in the terminal device accessing the secure area 130. Therefore, the data used in the secure area 130 is not leaked from the terminal device. Furthermore, the applications that can be used in the secure area 130 are limited to specific types. This prevents unauthorized use of managed data by users.
[0024] The input / output interface 11 is an interface connected to an input device such as a keyboard or a mouse and an output device such as a monitor. The input / output interface 11 is connected to the output device such as a monitor via a terminal device used by a user. The input / output interface 11 may be configured as an input interface connected to the input device and an output interface connected to the output device separately. The input / output interface 11 accepts input from a user via the input device. The input / output interface 11 accepts a request to use management target data managed by the management device 170. For example, a request to use management target data is input via a dedicated graphical user interface (GUI). The input / output interface 11 sends the input request to use management target data to the transmission unit 12. The input / output interface 11 also displays information related to data processing in the secure area on the monitor. The user can perform input operations using the keyboard or mouse while viewing the information displayed on the monitor.
[0025] The transmission unit 12 functions as a communication interface connected to the management device 170 via a network such as the Internet so as to enable data communication. The transmission unit 12 acquires a use request for the managed data input by a user. The transmission unit 12 transmits the use request for the managed data to the management device 170. The transmission unit 12 also acquires authority information including the usage status of the managed data from the authority management unit 17. The transmission unit 12 transmits the authority information including the usage status of the managed data to the management device 170.
[0026] The secure interface 13 is connected to the management device 170 via a network such as the Internet. The secure interface 13 is connected to the management device 170 via a secure gateway with a high level of security. The secure interface 13 is a communication interface dedicated to the management device 170. The secure interface 13 acquires managed data transmitted from the management device 170 in response to a usage request. The managed data transmitted from the management device 170 has usage rights set for the managed data. The secure interface 13 stores the managed data with usage rights set in the secure storage 14. The secure interface 13 may be configured to grant permission to access the managed data via a secure gateway with a high level of security. The secure interface 13 may be configured inside the secure area 130.
[0027] The secure interface 13 also acquires notification information regarding the use authority of the managed data from the management device 170. The notification information differs depending on the usage status of the managed data by the information generating device 10. If the use of the managed data by the information generating device 10 is within the scope of the usage authority, notification information indicating permission for use is issued. If the use of the managed data by the information generating device 10 is within the scope of the usage authority, notification information calling for caution is issued. If the use of the managed data by the information generating device 10 exceeds the usage authority, notification information indicating a warning is issued. If the use of the managed data by the information generating device 10 exceeds the usage authority, processing may be executed to prohibit the use of the managed data. The notification information regarding the usage authority is displayed on the screen of the terminal device 100 used by the user via the output unit 18. A user who views the notification information can take action in accordance with the notification information.
[0028] The secure storage 14 is a storage area constructed inside the secure area 130. The secure storage 14 has a highly secure storage area. Managed data is stored in the secure storage 14 via the secure interface 13. The managed data stored in the secure storage 14 can only be used inside the secure area 130. The managed data includes confidential information. Furthermore, usage rights are set for the managed data. The information generating device 10 is given the right to execute data processing using the managed data within the scope of the usage rights. The managed data stored in the secure storage 14 is used by the data processing unit 15.
[0029] Furthermore, the secure storage 14 stores models and information generated using the data to be managed. Typically, the models and information stored in the secure storage 14 can only be used within the secure area 130. Of the information stored in the secure storage 14, information that has been processed so as not to include confidential information and converted so as not to be editable may be configured to be output via the output unit 18. The models stored in the secure storage 14 may also be processed so as not to include confidential information and converted so as not to be editable.
[0030] The data processing unit 15 is constructed inside the secure area 130. For example, the data processing unit 15 is realized by an application that runs inside the secure area 130. The data processing unit 15 acquires the managed data stored in the secure storage 14. The data processing unit 15 executes data processing using the managed data. The data processing unit 15 stores the models and information generated by the data processing in the secure storage 14. The data processing using the managed data is completed only inside the secure area 130. Therefore, confidential information included in the managed data will not be leaked outside the secure area 130.
[0031] The data processing unit 15 includes a primary processing unit 151 and a high-order processing unit 152. The primary processing unit 151 executes primary processing using the data to be managed. The primary processing is processing to generate models and information used in data processing by the high-order processing unit 152. The high-order processing unit 152 executes high-order processing using the models and information generated by the primary processing unit 151. The high-order processing is processing to generate new information using the models and information generated by the primary processing. When high-order processing is not executed, the high-order processing unit 152 may be omitted, and the data processing unit 15 may be configured with only the primary processing unit 151.
[0032] For example, if the management target data is building structure data, the primary processing unit 151 generates an urban structure model using the building structure data. The urban structure model is a model that realistically represents the appearance and layout of buildings included in the target area. For example, the urban structure model is a model that represents the geographical landscape of a city in three dimensions. The urban structure model may also be represented in two dimensions. Each of the multiple buildings represented in the urban structure model reflects building structure data for that building. The urban structure model represents the layout and height of buildings in the target area. The urban structure model also represents the structure of the entire city, including transportation networks and public facilities. In this embodiment, an example is given in which disaster prevention information for a target area is generated using the urban structure model. The urban structure model can also be used to verify the layout of buildings and infrastructure facilities in urban planning, the mitigation of traffic congestion, and the like. The urban structure model may also be used for tourism promotion. For example, the urban structure model can be generated using a machine learning model constructed by machine learning. Note that the models and information generated by the primary processing unit 151 are not limited to urban structure models. The primary processing unit 151 can be configured to generate any model or information using the management target data.
[0033] Building structure data managed by local governments contains more detailed information than publicly available building data. Therefore, compared to urban structure models generated using publicly available building data, urban structure models generated using the building structure data have higher accuracy and are closer to reality. For example, building structure data owned by entities other than local governments may be added to generate urban structure models. For example, building structure data owned by entities such as real estate agents, construction companies, and equipment manufacturers may be used.
[0034] For example, the high-level processing unit 152 generates disaster prevention information using an urban structure model generated using the building structure data. For example, the disaster prevention information is an evacuation map in which information about buildings is superimposed on a map of a target area. The information about buildings may be information about a single building or information about an area including multiple buildings.
[0035] For example, the information about buildings includes the risk of building collapse. For example, the high-order processing unit 152 generates disaster prevention information in which markers for dangerous buildings with a high risk of collapse are superimposed on a map of the target area. For example, the high-order processing unit 152 generates disaster prevention information in which markers for safe buildings with a low risk of collapse are superimposed on a map of the target area. For example, the high-order processing unit 152 generates disaster prevention information in which dangerous roads near buildings with a high risk of collapse are superimposed on a map of the target area. For example, the high-order processing unit 152 generates disaster prevention information in which safe roads away from buildings with a high risk of collapse are superimposed on a map of the target area. For example, the high-order processing unit 152 generates disaster prevention information in which evacuation routes that pass through locations with a low risk of building collapse are superimposed on a map of the target area. Maps that clearly indicate the risk of building collapse can be used for evacuation in the event of an earthquake.
[0036] For example, the information about buildings includes the risk of fire spreading. For example, the high-order processing unit 152 generates disaster prevention information in which markers of dangerous buildings with a high risk of fire spreading are superimposed on a map of the target area. For example, the high-order processing unit 152 generates disaster prevention information in which markers of safe buildings with a low risk of fire spreading are superimposed on a map of the target area. For example, the high-order processing unit 152 generates disaster prevention information in which dangerous roads near buildings with a high risk of fire spreading are superimposed on a map of the target area. For example, the high-order processing unit 152 generates disaster prevention information in which safe roads away from buildings with a high risk of fire spreading are superimposed on a map of the target area. For example, the high-order processing unit 152 generates disaster prevention information in which evacuation routes that pass through locations with a low risk of fire spreading are superimposed on a map of the target area. Maps that clearly indicate the risk of fire spreading can be used for evacuation in the event of a fire caused by an earthquake or a large-scale fire.
[0037] The disaster prevention information may also include environmental information related to the surrounding environment of the building. For example, the environmental information may include information about shaded areas and sunny areas based on the positional relationship between the sun and the building. For example, if the appearance and height of buildings included in the urban structure model are accurate, shaded and sunny areas can be identified based on the positional relationship between the sun and the building according to the date and time. When evacuating in a snowy winter area, it is safer to evacuate through areas where there is no snow. If a sunny area based on the date and time can be identified, it is possible to identify areas with long sunshine hours. Snow melts easily in areas with long sunshine hours. If a shady area based on the date and time can be identified, it is possible to identify areas with short sunshine hours. Snow does not melt easily in areas with short sunshine hours. In such cases, it is preferable to generate evacuation information including an evacuation route that avoids areas with short sunshine hours and passes through areas with long sunshine hours. On the other hand, when evacuating on a sunny summer day, it is safer to evacuate through shaded areas to avoid the sunlight. In such cases, it is preferable to generate evacuation information including an evacuation route that avoids areas with long sunshine hours and passes through areas with short sunshine hours. For example, by using a machine learning model that has learned the sunshine duration for each date and time at locations included in the urban structure model, it is possible to identify shady and sunny locations according to the date and time. For example, the machine learning model for identifying shady and sunny locations may be configured to identify shady and sunny locations according to the time using weather information as well.
[0038] Furthermore, the data processing unit 15 deletes confidential information from information stored in the secure storage 14 that is to be output to the outside. The data processing unit 15 also converts the output information into a format that cannot be edited. For example, the output information is disaster prevention information that has been processed so as not to include confidential information and converted so as not to be editable. The data processing unit 15 sends the output information that has been processed so as not to include confidential information and converted so as not to be editable to the output unit 18.
[0039] The data processing unit 15 may be configured to mask not only confidential information but also information selected in response to a user's input operation on the terminal device 100. That is, the data processing unit 15 may be configured to omit information the user does not want to see through a filter set by the user. Such a configuration not only ensures security by preventing confidential information from leaking, but also allows for information management tailored to the user's convenience. Furthermore, in internal meetings and other situations where the managed data is referenced, there is no need to conceal the managed data. In such situations, models and information containing confidential information may be output. For example, when a local government employee uses the managed data in a presentation for a review or examination, the employee may not select the data for security reasons. In such cases, if the data processing unit 15 is configured to mask attribute data, such as the owner's attributes or the material of the pillars, according to the employee's selection, the employee can make a presentation using information with unnecessary data removed.
[0040] The authority management unit 17 updates authority information including the usage status of the managed data in response to the use of the managed data. The authority information includes restrictions on the use of the managed data permitted to the user. For example, the authority information includes a user identifier for identifying the user permitted to use the managed data, a dimension for tracing the usage history of the managed data, and the update date and time of the managed data. The authority information may also include information other than the user identifier, the dimension of the managed data, and the update date and time of the managed data.
[0041] The initial value of the dimension of the managed data is set by the management device 170. For example, the initial value of the dimension of the managed data is set to 1.0. The authority management unit 17 increases the dimension of the managed data depending on the use of the managed data. For example, the authority management unit 17 adds a predetermined value to the dimension of the managed data depending on the number of times the managed data is used, the duration of use, the number of changes, and the content of the changes. In other words, the authority management unit 17 updates the dimension depending on the use of the managed data. The information generating device 10 can use the managed data up to the permitted dimension set by the management device 170. The usage period of the managed data is set by the management device 170. The authority management unit 17 adds the update date and time of the managed data to the authority information. The information generating device 10 can use the managed data until the usage period set by the management device 170.
[0042] The output unit 18 functions as a communication interface connected to an external system or device via a network such as the Internet so as to enable data communication. The output unit 18 acquires output information from the data processing unit 15. The output unit 18 outputs the acquired output information. There are no particular limitations on the destination of the output information. For example, disaster prevention information for a target area managed by a local government, which is the administrator of the managed data, is distributed to residents living in the target area via the local government. The disaster prevention information may also be provided to private companies or organizations.
[0043] The output unit 18 also functions as an output interface that displays an image on the screen of a terminal device used by the user. The output unit 18 displays an image related to notification information related to usage rights transmitted from the management device on the screen of the terminal device. For example, the output unit 18 displays an image including notification information transmitted from the management device 170 on the screen of the terminal device. For example, the output unit 18 may be configured to display an image including information generated using the notification information transmitted from the management device 170 on the screen of the terminal device. For example, the output unit 18 may display an image including information generated using a large-scale language model on the screen of the terminal device. For example, the output unit 18 may be configured to display information generated on a rule-based basis using a preset template on the screen of the terminal device.
[0044] FIG. 3 is a conceptual diagram showing an example of the display of an image related to notification information regarding usage authorization transmitted from a management device according to the present disclosure. The screen of the terminal device 100 used by the user (C) displays information including a usage authorization for the managed data, such as "Permission to use data AAA has been granted in response to C's usage request." The screen of the terminal device 100 also displays information related to the usage authorization, such as "Usage expiration date: 2024 / 6 / 30_23:59:59, Usage authorization dimension: 2.0." The screen of the terminal device 100 also displays information according to the usage authorization, such as "Data may be used within the scope of the usage expiration date and usage authorization dimension." The user (C) can recognize that he or she has been granted permission to use the managed data by viewing the information displayed on the screen of the terminal device 100.
[0045] [Management device] 4 is a block diagram showing an example of a detailed configuration of a management device according to the present disclosure. Management device 170 includes acquisition unit 171, usage authority management unit 172, secure interface 176, and secure gateway 177. Secure interface 176 and secure gateway 177 are constructed inside secure area 175. Secure interface 176 is connected to database 180. Database 180 may be constructed inside secure area 175. Management device 170 also includes management table 160. Management table 160 is used to manage usage authority for managed data.
[0046] The management device 170 includes a secure area 175. The secure area 175 is a virtual area constructed in a cloud or server that can be accessed from the terminal device 100 used by the administrator. The secure area 175 includes a secure interface 176 and a secure gateway 177. For example, the secure area 175 is realized using container-type virtualization technology. The environment of the secure area 175 is encrypted, and is isolated from the local environment connected to the external environment. The management target data read into the secure area 175 is not stored in the terminal device accessing the secure area 175. The management target data read into the secure area 175 is provided to the information generating device 10 via the secure gateway 177, which has a high level of security.
[0047] Database 180 is a database accessible from secure area 175 of management device 170. Database 180 has a highly secure storage area. Managed data is stored in database 180. The managed data includes confidential information. The managed data stored in database 180 can be accessed from secure area 175. The data stored in database 180 is transferred to management device 170 via secure interface 176. Database 180 may be constructed inside secure area 175.
[0048] The acquisition unit 171 is a communication interface connected to the information generating device 10 via a network such as the Internet so as to be able to communicate data. The acquisition unit 171 acquires a use request for the management target data transmitted from the information generating device 10. The acquisition unit 171 sends the acquired use request for the management target data to the usage authority management unit 172.
[0049] The acquisition unit 171 also acquires authority information including the usage status of the data to be managed from the information generating device 10. The acquisition unit 171 sends the acquired authority information to the usage authority management unit 172.
[0050] The usage authority management unit 172 acquires a usage request transmitted from the information generating device 10. In response to the usage request, the usage authority management unit 172 issues an instruction to the secure interface 176 to acquire the management target data from the database 180. Note that the usage authority management unit 172 does not provide the management target data in response to usage requests from all users. The criteria for providing the management target data are set appropriately in accordance with the terms of the contract between the administrator and the user.
[0051] The usage authority management unit 172 sets usage authority for the managed data for which a usage request has been received. The usage authority management unit 172 manages usage authority for the managed data using a management table 160. The management table 160 records authority information for each managed data item that a user is permitted to use. The management table 160 also records usage authority information including the permission dimension and expiration date for each managed data item. Furthermore, a usage flag is set in the management table 160 according to the usage status of the managed data item by the user. The usage flag is a flag that indicates whether the user's use of the managed data item is within the scope of the usage authority (allowed) or outside the scope of the usage authority (not allowed).
[0052] 5 is a table showing an example of a management table according to the present disclosure. Management table 160 records authority information, usage permission information, and a usage flag. Management table 160 records, as authority information, an identifier of a user who has been granted permission to use the managed data, a dimension of the managed data that is updated according to the user's usage status, and an update date and time of the managed data. Management table 160 also records, as usage permission information, a permission dimension indicating an upper limit on the use of the managed data and a usage expiration date of the managed data. Furthermore, management table 160 sets a usage flag indicating whether the user is permitted to use the managed data.
[0053] For example, user C has permission to use the managed data AAA. The permission information for the managed data AAA set for the user has a permission dimension of "2.0" and a usage expiration date of "June 30, 2024, 11:59:59 PM." As of the time of update at 12:00:00 PM on March 30, 2024, the dimension indicating the usage status of the managed data AAA is 1.0. In this case, the managed data AAA is being used within the range of the permission, so the usage flag is set to "allowed." In the example of FIG. 5, the usage flags for all managed data are "allowed."
[0054] The usage authority management unit 172 acquires the permission information transmitted from the information generating device 10. The usage authority management unit 172 updates the permission information recorded in the management table 160 using the acquired permission information. The usage authority management unit 172 uses the management table 160 to verify whether the usage status of the managed data is within the scope of the usage authority. If the use of the managed data is within the scope of the usage authority, the usage authority management unit 172 allows the information generating device 10 to continue using the managed data. In this case, the usage authority management unit 172 does not need to take any particular action against the information generating device 10. If the use of the managed data exceeds the usage authority, the usage authority management unit 172 instructs the secure gateway 177 to send notification information including a warning to the information generating device 10. For example, the usage authority management unit 172 instructs the secure gateway 177 to send notification information that calls the information generating device 10's attention. The notification information may be configured to be transmitted from a general-purpose communication interface other than the secure gateway 177.
[0055] Secure interface 176 is configured inside secure area 175. Secure interface 176 is connected to database 180 so as to be able to perform data communication. Secure interface 176 acquires, from database 180, management target data corresponding to a usage request from a user in response to an instruction from usage authority management unit 172. Usage authority is set by usage authority management unit 172 for the management target data acquired by secure interface 176.
[0056] Secure gateway 177 is a highly secure gateway. Secure gateway 177 is connected to information generating device 10 via a network such as the Internet. Secure gateway 177 transmits management target data, for which usage rights have been set, to information generating device 10. For example, secure gateway 177 may be configured to be accessed from information generating device 10 via secure interface 13. For example, secure area 130 of information generating device 10 and secure area 175 of management device 170 may be configured to function as a single secure area.
[0057] (operation) Next, the operation of the information management system 1 according to this embodiment will be described with reference to the drawings. Here, we will briefly explain the processing of the information generating device 10, management device 170, and database 180 included in the information management system 1, and the exchange of information and data between these components. The following explanation will be divided into a phase of permission to use the managed data and a phase of authority management for the managed data.
[0058] [Permission Phase] 6 is a sequence diagram illustrating the permission phase for use of managed data according to the present disclosure, showing the processes of the information generating device 10, the management device 170, and the database 180, and the exchange of information and data between these components.
[0059] First, the information generating device 10 receives a user's request to use management target data (step S101). For example, a request to use building structure data related to buildings included in a target area is input as management target data to the information generating device 10. Next, the information generating device 10 transmits the received use request to the management device 170 (step S102).
[0060] The management device 170 acquires the use request transmitted from the information generating device 10 (step S103). Next, the management device 170 acquires the management target data for which the use request has been received from the database 180 (step S104). The conditions for determining whether to issue permission to use the management target data are set arbitrarily. Next, the management device 170 sets a usage authority for the management target data acquired from the database 180 (step S105). The management device 170 records the usage authority for the management target data in the management table 160. Next, the management device 170 transmits the management target data for which the usage authority has been set to the information generating device 10 (step S106). The management device 170 may be configured to grant the information generating device 10 access authority for the management target data for which the usage authority has been set.
[0061] The information generating device 10 receives the management target data for which the usage authority has been set (step S107), and then stores the received management target data in the secure area (step S108).
[0062] [Authority management phase] FIG. 7 is a sequence diagram for explaining the authority management phase of the managed data according to the present disclosure. FIG. 7 shows the processing of the information generating device 10 and the management device 170, and the exchange of information and data between these components. FIG. 7 also shows primary processing (steps S111 to S115) and higher-level processing (steps S121 to S125). The primary processing is processing for constructing a model using the managed data. The higher-level processing is processing for generating information using the model constructed by the primary processing. Note that FIG. 7 shows an example in which the managed data is used within the scope of permitted use.
[0063] In the primary processing, first, the information generating device 10 executes the primary processing using the management target data stored in the secure area (step S111). For example, in the primary processing, the information generating device 10 constructs an urban structure model of the target area using building structure data of buildings included in the target area. The information generating device 10 stores the model generated by the primary processing in the secure area (step S112). The information generating device 10 transmits authority information updated in response to the execution of the primary processing to the management device 170 (step S113). Note that the order of steps S112 and S113 may be reversed. The processing of step S113 may be executed at a preset timing, or may be executed when the authority information is updated.
[0064] The management device 170 acquires the authority information of the data to be managed transmitted from the information generating device 10 (step S114). Next, the management device 170 updates the management table 160 using the acquired authority information (step S115).
[0065] In the high-order processing, first, the information generating device 10 executes the high-order processing using the model stored in the secure area (step S121). For example, in the high-order processing, the information generating device 10 generates disaster prevention information for a target area using an urban structure model of the target area. The information generating device 10 stores the information generated by the high-order processing in the secure area (step S122). The information generating device 10 transmits authority information updated in response to the execution of the high-order processing to the management device 170 (step S123). Note that the order of steps S122 and S123 may be reversed. The processing of step S123 may be executed at a preset timing, or may be executed when the authority information is updated.
[0066] The management device 170 acquires the authority information of the data to be managed transmitted from the information generating device 10 (step S124). Next, the management device 170 updates the management table 160 using the acquired authority information (step S125).
[0067] [Management Table] Next, an example of updating the management table 160 in accordance with the user's usage of the managed data will be described with reference to the drawings. FIGS. 8 to 13 are diagrams for explaining an example of updating the management table according to the present disclosure. FIGS. 8, 10, and 12 are tables showing examples of updating the management table. FIGS. 9, 11, and 13 are conceptual diagrams showing examples of displaying notification information in accordance with changes in the usage flag due to updating the management table. The notification information may be displayed on the entire screen of the terminal device 100 used by the user, or may be displayed as a pop-up on a portion of the screen of the terminal device 100. Note that FIGS. 8 to 13 are examples of updating the management table and displaying the notification information, and are not intended to limit the updating of the management table or the display of the notification information.
[0068] FIG. 8 is a table showing an example of updating a management table according to the present disclosure. FIG. 8 shows an example in which the dimension (1.9) of the management target data AAA used by user C approaches the upper limit of the permitted dimension (2.0). When the dimension of the management target data AAA approaches the upper limit of the permitted dimension, the management device 170 updates the usage flag in the management table 160 to "Caution Required." When the usage flag in the management table 160 is updated to "Caution Required," the management device 170 generates notification information including information warning about the use of the management target data AAA. The management device 170 transmits the generated notification information to the terminal device 100 used by the user.
[0069] FIG. 9 is a conceptual diagram showing an example of displaying notification information in response to a change in the usage flag due to an update of the management table according to the present disclosure. Information in response to the usage status of the managed data AAA is displayed on the screen of the terminal device 100 used by the user. In response to the usage flag changing to "Caution Required," information urging the user to be careful, saying "Caution!!!," is displayed on the screen of the terminal device 100. In addition, information including the usage status of the managed data AAA, such as "The usage dimension has reached 1.9 dimensions. You will soon be allowed to use the dimension," is displayed on the screen of the terminal device 100. Furthermore, information in response to the usage authority, such as "You cannot use any more data," is displayed on the screen of the terminal device 100. The user (C) can recognize that he or she cannot use the managed data AAA any further by viewing the information displayed on the screen of the terminal device 100.
[0070] 10 is a table showing an example of updating a management table according to the present disclosure. FIG. 10 shows an example in which the dimension (3.0) of the management target data AAA used by user C exceeds the upper limit (2.0) of the permitted dimension. When the dimension of the management target data AAA exceeds the permitted dimension, the management device 170 updates the usage flag in the management table 160 to "unavailable." When the usage flag in the management table 160 is updated to "unavailable," the management device 170 generates notification information including a warning. The management device 170 transmits the generated notification information to the terminal device 100 used by the user.
[0071] FIG. 11 is a conceptual diagram showing an example of displaying notification information in response to a change in the usage flag due to an update of the management table according to the present disclosure. Information in response to the usage status of the managed data AAA is displayed on the screen of the terminal device 100 used by the user. In response to the usage flag changing to "Warning," information indicating a warning to the user, "Warning!!!!!," is displayed on the screen of the terminal device 100. In addition, information including the usage status of the managed data AAA, such as "The usage dimension has reached 3.0 dimension. This exceeds the permitted usage dimension," is displayed on the screen of the terminal device 100. Furthermore, information in response to the usage authority, such as "Data cannot be used," is displayed on the screen of the terminal device 100. The user (C) can view the information displayed on the screen of the terminal device 100, confirm that the managed data AAA has been used until the permitted dimension has been exceeded, and recognize that the managed data AAA cannot be used.
[0072] FIG. 12 is a table showing an example of updating a management table according to the present disclosure. FIG. 12 shows an example in which the update date and time (2024 / 7 / 1_12:00:00) of the management target data AAA used by user C has exceeded its expiration date and time (2024 / 6 / 30_23:59:59). When the update date and time of the management target data AAA has exceeded its expiration date and time, the management device 170 updates the usage flag in the management table 160 to "unavailable." When the usage flag in the management table 160 has been updated to "unavailable," the management device 170 generates notification information including a warning. The management device 170 transmits the generated notification information to the terminal device 100 used by the user.
[0073] FIG. 13 is a conceptual diagram showing an example of display of notification information corresponding to a change in the usage flag due to an update of the management table according to the present disclosure. Information corresponding to the usage status of the managed data AAA is displayed on the screen of the terminal device 100 used by the user. In response to the change of the usage flag to "Warning," information indicating a warning to the user, "Warning!!!!!," is displayed on the screen of the terminal device 100. Furthermore, information including the usage status of the managed data AAA, such as "The update date and time is 2024 / 7 / 1_12:00:00. The usage period has expired," is displayed on the screen of the terminal device 100. Furthermore, information corresponding to the usage authority, such as "Data cannot be used," is displayed on the screen of the terminal device 100. The user (C) can view the information displayed on the screen of the terminal device 100 to confirm that the managed data AAA was used until the usage period expired, and recognize that the managed data AAA cannot be used.
[0074] [Data Management] Next, an example of management of data to be managed according to the present disclosure will be described with reference to the drawings. The following data management is an example and does not limit the method of managing data to be managed according to the present embodiment.
[0075] Fig. 14 is a conceptual diagram for explaining an example of data management according to the present disclosure. Fig. 14 shows a method for managing managed data using hash values. Fig. 14 shows an example of managing managed data using hash values of blockchain technology. Depending on the use of managed data in primary processing and higher-level processing, the authority management unit 17 of the information generating device 10 generates management data in units of block 1, block 2, block 3, ..., block n (n is a natural number).
[0076] Block 1 is management data generated by the authority management unit 17 when the management target data 1 transmitted from the management device 170 is used for the first time. Block 1 includes data 1-1 generated in response to the use of the management target data 1, an initial hash value, and a nonce (nonce: number used once). Data 1-1 includes an order in response to the use of the management target data 1. The initial hash value is a value set by the management device 170. The nonce is a value used to generate a new hash value (the hash value of block 1). The authority management unit 17 generates a hash value of block 1 using data 1-1, the initial hash value, and the nonce. For example, the authority management unit 17 generates the hash value of block 1 using a hash function such as SHA-256. The authority management unit 17 transmits the generated hash value of block 1 to the management device 170. The hash value of block 1 transmitted to the management device 170 is recorded in the management table 160.
[0077] Block 2 is management data generated by the authority management unit 17 when data 1-1 generated using management target data 1 or the management target data 1 itself is used at a point in time following block 1. Block 2 includes data 1-2 generated in response to the use of data 1-1 or management target data 1, a hash value of block 1, and a nonce. Data 1-2 includes an order in response to the use of data 1-1 or management target data 1. The hash value of block 1 is the hash value of the previous block (block 1). The nonce is a value used to generate a new hash value (the hash value of block 2). The authority management unit 17 generates a hash value of block 2 using data 1-2, the hash value of block 1, and the nonce. For example, the authority management unit 17 generates the hash value of block 2 using a hash function such as SHA-256. The authority management unit 17 transmits the generated hash value of block 2 to the management device 170. The hash value of block 2 transmitted to the management device 170 is recorded in the management table 160.
[0078] Block 3 is management data generated by the authority management unit 17 when data 1-1, data 1-2, or the management target data 1 itself, generated using the management target data 1, is used at a point in time following block 2. Block 3 includes data 1-3 generated in response to the use of data 1-1, data 1-2, or the management target data 1, a hash value of block 2, and a nonce. Data 1-3 includes an order in response to the use of data 1-1, data 1-2, or the management target data 1. The hash value of block 2 is the hash value of the previous block (block 2). The nonce is a value used to generate a new hash value (the hash value of block 3). The authority management unit 17 generates a hash value of block 3 using data 1-3, the hash value of block 2, and the nonce. For example, the authority management unit 17 generates a hash value of block 3 using a hash function such as SHA-256. The authority management unit 17 transmits the generated hash value of block 3 to the management device 170. The hash value of block 3 sent to the management device 170 is recorded in the management table 160 .
[0079] Block n is management data generated by the authority management unit 17 when data 1-1, data 1-2, ..., data 1-(n-1), or the management target data 1 itself is used at a point in time following block n-1. Block 3 includes data 1-1, data 1-2, ..., data 1-(n-1), or data 1-n generated in response to the use of management target data 1, the hash value of block n, and a nonce. Data 1-n includes data 1-1, data 1-2, ..., data 1-(n-1), or an order in response to the use of management target data 1. The hash value of block n is the hash value of the previous block (block n-1). The nonce is the value used to generate a new hash value (the hash value of block n). The authority management unit 17 generates the hash value of block n using data 1-3, the hash value of block 2, and the nonce. For example, the authority management unit 17 generates a hash value of block n using a hash function such as SHA-256. The authority management unit 17 transmits the generated hash value of block n to the management device 170. The hash value of block n transmitted to the management device 170 is recorded in the management table 160.
[0080] FIG. 15 is a table showing an example of a management table according to the present disclosure. Permission information, a usage period, and a usage flag are recorded in management table 165. The permission information recorded in management table 165 includes an identifier of a user authorized to use the managed data and a hash value. The hash value transmitted in response to the use of the managed data is recorded in management table 165. Management device 170 uses the hash value to calculate a degree indicating the usage status of the managed data. Using the hash value in this way prevents users from tampering with the degree indicating the usage status of the managed data, thereby achieving data management with a higher level of security.
[0081] [Building structure data] Next, building structure data managed by a local government will be described. The building structure data is an example of managed data according to this embodiment. For example, items of building structure data managed by a local government include basic information, structure information, status information, and equipment information. The basic information, structure information, status information, and equipment information may include overlapping information. Items of building structure data may include items other than basic information, structure information, status information, and equipment information. Furthermore, the building structure data may include data managed by an entity other than the local government.
[0082] Basic information includes information about the location, owner, shape, area, and purpose of use of a building. Location includes information about the address, place name, and coordinates of the building where the building is located. Owner is an entity such as an individual or organization that owns the building. Building shape includes information about the shape, size, layout, and surrounding environment of the building. Building shape includes information about the building's exterior and internal structure. Building size includes information about the building's width and height. Building layout includes information about the building's layout on the land on which it is built. Surrounding environment includes information about the roads, topography, trees, and location and environment surrounding the building. For example, building area includes information about the building's site area, total floor area, and building volume. For example, building purpose is information indicating the purpose for which the building will be used. Specifically, building purpose includes information such as residence, store, office, factory, warehouse, clinic, and school.
[0083] Structural information includes information about the building's structural type, seismic resistance rating, wall material, wall thickness, pillar material, number of pillars, floor material, and floor thickness. Structural type refers to the type of structure supporting the building. For example, building structural types include wood, steel frame, and reinforced concrete. Depending on the structural type, the building's weight, height, allowable load, earthquake resistance, fire resistance, and maintenance requirements vary. Seismic resistance rating is a standard determined during the design phase to indicate the degree to which a building can withstand an earthquake. In Japan, the Building Standards Act sets earthquake resistance standards (seismic standards) for all buildings. These standards are determined based on the building's intended use, height, and regional seismic activity level. Seismic resistance ratings are determined by the Act on Promotion of Housing Quality Assurance (QASA). Seismic resistance ratings are expressed as numbers from 1 to 3. The lower the seismic resistance rating, the lower the seismic resistance performance of the building. The higher the seismic resistance rating, the higher the seismic resistance performance of the building. Earthquake resistance grade 1 meets the minimum seismic performance standard stipulated by the Building Standards Act. Public facilities, such as schools designated as evacuation shelters during disasters, must meet earthquake resistance grade 2 or higher. Many fire stations and police stations, which serve as bases for rescue operations and disaster recovery efforts, are built to earthquake resistance grade 3. The materials used for building walls, columns, floors, and other components vary depending on their intended use. For example, walls are made of concrete, brick, stone, wood, plaster, and gypsum board. For example, columns are made of wood, steel, reinforced concrete, iron, and aluminum. For example, floors are made of decorative plywood, tile, and carpet. Building materials are selected based on their respective characteristics, taking into account requirements for functionality, safety, aesthetics, durability, and maintainability. The materials used are an important factor affecting a building's structure, shape, and earthquake resistance.
[0084] Condition information includes information about a building's current use, repair status, durability, etc. Current use indicates how the building is currently being used. Examples of use include residential, office, store, factory, warehouse, and public facility. A building that is left vacant or on vacant land is also classified as a vacant or abandoned building. Building repair status indicates the building's condition and whether repairs or renovations are necessary. This includes the overall condition of the building, including the roof, exterior walls, interior walls, floors, pillars, foundation, and equipment, as well as information about areas that need repair and whether repairs have been completed. If building repairs and renovations are not actively carried out, the building may deteriorate, shortening its lifespan and increasing the risk of collapse. Building durability includes earthquake resistance, fire resistance, and water resistance. Building durability can be evaluated using different criteria for different types of disasters.
[0085] Facility information includes information about facilities installed in a building, such as air conditioning, water supply and drainage, and electricity. For example, facility information includes information about the type, number, and performance of facilities installed in a building. For example, air conditioning includes facilities such as air conditioners, ventilation facilities, heating facilities, and cooling facilities. Water supply and drainage includes facilities such as toilets, showers, faucets, drainage facilities, water supply facilities, and hot water supply facilities. Electricity includes facilities such as telephone, internet, the number of light switches and outlets, and wiring. Facility information may also include information about lighting, communications, security, etc.
[0086] 16 is a table showing an example of building structure data according to the present disclosure. The building structure data 145 includes basic information, structure information, status information, and equipment information. The building structure data 145 indicates specific data of the basic information and structure information. Each of the multiple buildings included in the target area is associated with the building structure data 145 for that building.
[0087] [Urban structure model] Next, an example of an urban structure model constructed by the information generating device 10 according to this embodiment will be described with reference to the drawings. The urban structure model includes information related to building structure data of buildings constructed in the target area. In other words, the urban structure model is primary information that includes confidential information.
[0088] FIG. 17 is a conceptual diagram showing an example of an urban structure model constructed by an information generating device according to the present disclosure. The urban structure generation model 140 outputs an urban structure model of a target area in response to input of a map of the target area and a group of building structure data. The group of building structure data is a data set composed of building structure data 145 associated with each of a plurality of buildings included in the target area. For example, the urban structure generation model 140 is a trained model generated by machine learning.
[0089] The urban structure generation model 140 may be realized by a generative AI (artificial intelligence) that has learned a huge number of data sets. When the urban structure generation model 140 realized by the generative AI is used, it is preferable to use a prompt that corresponds to the urban structure model to be constructed. For example, a prompt that includes a specification of the form of the urban structure model can be used. If such a specification is included, it becomes easier to generate a desired urban structure model.
[0090] FIG. 18 is a conceptual diagram illustrating an example of an urban structure model constructed by an information generating device according to the present disclosure. In FIG. 18, buildings included in a target area are represented in two dimensions. In an actual urban structure model, buildings included in the target area are represented in three dimensions. In the urban structure model 155, buildings constructed at each of multiple locations included in the target area are associated with those locations. Parameters are set for each building according to the building structure data. The urban structure model 155 is a virtual model that reflects the structure of buildings in the real world. The urban structure model 155 may include confidential information contained in the building structure data. Therefore, rather than a visualized model as shown in FIG. 18, the urban structure model 155 is configured as a model in which the building structure data for each building is linked to a location in the target area. For example, if the confidential information contained in the building structure data is masked, the visualized urban structure model 155 may be displayed on the terminal device 100 used by the user.
[0091] Fig. 19 is a flowchart showing an example of construction of a city structure model by an information generation device according to the present disclosure. In describing the processing according to the flowchart of Fig. 19, the components of the information generation device 10 will be the main focus. The main focus of the processing according to the flowchart of Fig. 19 may be the information generation device 10.
[0092] In FIG. 19, first, the primary processing unit 151 acquires the building structure data stored in the secure storage 14 included in the secure area 130 (step S131).
[0093] Next, the primary processing unit 151 uses the acquired building structure data to construct an urban structure model of the target area (step S132). For example, the primary processing unit 151 uses the urban structure generation model 140 to construct an urban structure model of the target area.
[0094] Next, the authority information updated in accordance with the use of the building structure data is transmitted to the management device 170 (step S133). The processing of step S133 may be performed every time after step S132, or may be performed at a preset timing. If the processing is to be continued after step S133 (Yes in step S134), the processing returns to step S132. If the processing is to be continued (Yes in step S134), the processing may return to step S131.
[0095] If the processing is not to be continued after step S133 (No in step S134), the primary processing unit 151 stores the constructed urban structure model in the secure storage 14 included in the secure area 130 (step S135). The urban structure model stored in the secure storage 14 is used by the high-order processing unit 152 to generate disaster prevention information.
[0096] [Disaster Prevention Information] Next, an example of disaster prevention information generated by the information generating device 10 according to this embodiment will be described with reference to the drawings. The disaster prevention information is generated using an urban structure model of the target area. In other words, the disaster prevention information is higher-level information generated using the urban structure model, which is primary information.
[0097] FIG. 20 is a conceptual diagram showing an example of disaster prevention information generated by an information generating device according to the present disclosure. A disaster prevention information generation model 150 outputs disaster prevention information for a target area in response to an input of an urban structure model. For example, the disaster prevention information generation model 150 is a trained model generated by machine learning. The building structure data group is a data set composed of building structure data 145 associated with each of a plurality of buildings included in the target area. For example, the disaster prevention information generation model 150 is a trained model generated by machine learning.
[0098] For example, the disaster prevention information generation model 150 may be realized by a generation AI that has been trained on a huge number of data sets. When the disaster prevention information generation model 150 realized by the generation AI is used, it is preferable to use a prompt that corresponds to the disaster prevention information to be generated. For example, a prompt that includes specifications such as the source and destination of the disaster prevention information, the type of disaster prevention to be generated, the display format, and the type of information to be displayed can be used. If these specifications are included, desired disaster prevention information can be more easily generated.
[0099] FIG. 21 is a conceptual diagram illustrating an example of disaster prevention information generated by an information generating device according to the present disclosure. The disaster prevention information 156 is a disaster prevention map in which information about buildings with a high risk of collapse is superimposed on a map of the target area. Confidential information included in building structure data is excluded from the disaster prevention information 156. The disaster prevention information 156 displays markers corresponding to numerical values (3, 4, 5) indicating the collapse risk at the locations of buildings with a high risk of collapse. The collapse risk of buildings with an extremely low risk of collapse due to an earthquake is set to 1, and the collapse risk of buildings with an extremely high risk of collapse due to an earthquake is set to 5. Here, it is assumed that buildings with a collapse risk of 3 to 5 have the possibility of collapsing in an earthquake. For example, notices printed with the disaster prevention information 156 may be posted around town or distributed to citizens. The disaster prevention information 156 is also provided in a viewable state via a network such as the Internet. People who view the disaster prevention information 156 can identify buildings with a high risk of collapse in the target area. In the event of an earthquake, people's safety can be ensured by evacuating by choosing a route away from buildings that are at high risk of collapse, as displayed in the disaster prevention information 156.
[0100] FIG. 22 is a conceptual diagram illustrating an example of disaster prevention information generated by an information generating device according to the present disclosure. The disaster prevention information 157 is a disaster prevention map in which information about areas with a high risk of fire spread is superimposed on a map of the target area. Confidential information included in building structure data is excluded from the disaster prevention information 157. In the disaster prevention information 157, areas with a high risk of fire spread are hatched (color-coded) according to a numerical value (3, 4, 5) indicating the fire spread risk. The fire spread risk of areas with an extremely low risk of fire spread is set to 1, and the fire spread risk of buildings with an extremely high risk of fire spread is set to 5. Here, it is assumed that buildings with a fire spread risk of 3 to 5 have the possibility of spreading in the event of a fire. For example, notices printed with the disaster prevention information 157 may be posted around town or distributed to citizens. Furthermore, the disaster prevention information 157 is provided in a viewable state via a network such as the Internet. People who view the disaster prevention information 157 can recognize areas with a high risk of fire spread within the target area. In the event of a fire, people's safety can be ensured by evacuating and avoiding areas with a high risk of fire spreading, which are displayed in the disaster prevention information 157.
[0101] FIG. 23 is a conceptual diagram illustrating an example of disaster prevention information generated by an information generating device according to the present disclosure. The disaster prevention information 158 is a disaster prevention map in which information indicating safe routes in the event of a disaster such as an earthquake or fire is superimposed on a map of a target area. Confidential information included in building structure data is excluded from the disaster prevention information 158. The disaster prevention information 158 displays signs indicating that roads are safe on roads away from areas with a high risk of collapse or fire spread. Safe roads may be set for each disaster, such as an earthquake, fire, or flood. The disaster prevention information 158 also displays evacuation shelters in the target area. For example, notices printed with the disaster prevention information 158 may be posted around town or distributed to citizens. The disaster prevention information 158 is also provided in a viewable state via a network such as the Internet. People who view the disaster prevention information 158 can recognize safe roads and evacuation shelters within the target area. In the event of an earthquake or fire, people's safety is ensured by choosing the safe route displayed in the disaster prevention information 158 and evacuating to an evacuation shelter.
[0102] Fig. 24 is a flowchart showing an example of generation of disaster prevention information by the information generation device according to the present disclosure. In the description of the processing according to the flowchart of Fig. 24, the components of the information generation device 10 will be the main focus. The main focus of the processing according to the flowchart of Fig. 24 may be the information generation device 10.
[0103] 24, first, the high-order processing unit 152 acquires the city structure model stored in the secure storage 14 (step S141). The city structure model includes building structure data for each building included in the target area.
[0104] Next, the high-order processing unit 152 generates disaster prevention information for the target area using the acquired urban structure model (step S142). For example, the high-order processing unit 152 generates disaster prevention information for the target area using the disaster prevention information generation model 150. The high-order processing unit 152 stores the generated disaster prevention information in the secure storage 14. For example, the high-order processing unit 152 removes confidential information included in the building structure data from the disaster prevention information. The disaster prevention information from which the confidential information has been removed may be stored in a storage unit other than the secure storage 14.
[0105] Next, authority information updated in accordance with the use of the building structure data included in the urban structure model is transmitted to the management device 170 (step S143). The processing of step S143 may be performed every time after step S142, or may be performed at another preset timing. If the processing is to be continued after step S143 (Yes in step S144), the processing returns to step S142. If the processing is to be continued (Yes in step S144), the processing may return to step S141.
[0106] If the process does not continue after step S143 (No in step S144), the high-order processing unit 152 converts the generated disaster prevention information into a format that cannot be edited (step S145). It is assumed that confidential information has been removed from this disaster prevention information. The process of step S145 is a process for preventing the disaster prevention information from being tampered with. For example, the high-order processing unit 152 converts the disaster prevention information into a file format that prevents characters and images included in the disaster prevention information from being copied. For example, if external editing of the disaster prevention information is permitted, the process of step S145 may be omitted.
[0107] The output unit 18 outputs the disaster prevention information converted into an uneditable format (step S146). For example, the disaster prevention information may be printed on paper or the like and posted around town or distributed to citizens. The disaster prevention information may also be provided in a viewable state via a network such as the Internet. There are no particular limitations on the use of the disaster prevention information as long as it is for the purpose of disaster prevention.
[0108] As described above, the information management system according to this embodiment includes an information generating device and a management device, and may include a database in which data to be managed is stored.
[0109] The information generating device comprises a transmitting unit, a secure interface, a secure storage, a data processing unit, and an authority management unit. The transmitting unit transmits a request to use the managed data to a management device that manages the managed data. The secure interface receives the managed data, for which usage rights have been set, transmitted in response to the usage request. The secure storage is constructed in a secure area. The managed data is stored in the secure storage. The data processing unit executes data processing using the managed data in the secure area. The authority management unit updates the authority information included in the usage rights set for the managed data in accordance with the usage status of the managed data. The transmitting unit transmits the updated authority information to the management device in accordance with the usage status of the managed data.
[0110] The management device has an acquisition unit, a usage rights management unit, a secure interface, and a secure gateway. The acquisition unit acquires a usage request transmitted from the information generating device. The usage rights management unit manages the usage status of the managed data using a management table that manages permission information of the managed data. The secure interface acquires the managed data from a database in response to the usage request transmitted from the information generating device. The usage rights management unit sets usage rights for the managed data acquired from the database. The secure gateway transmits the managed data with usage rights set to the information generating device. In addition, the acquisition unit acquires permission information for the managed data that has been updated in accordance with the usage status of the managed data. The usage rights management unit records the updated permission information for the managed data in the management table.
[0111] The information generating device of this embodiment executes data processing using managed data in a secure area. Furthermore, the information generating device of this embodiment updates the permission information included in the usage rights set for the managed data according to the usage status of the managed data, and transmits the updated permission information to the management device. The management device traces the usage status of the managed data in the information generating device using the permission information acquired from the information generating device. Therefore, according to this embodiment, data including highly confidential information can be used while tracing its usage status. Furthermore, according to this aspect, managed data including highly confidential information can be used safely, thereby increasing opportunities for general users to use strictly managed managed data. If such opportunities increase, it will be possible to build, for example, an urban structure model that enables more practical disaster prevention simulations.
[0112] In one aspect of this embodiment, the data processing unit has a primary processing unit and a high-order processing unit. The primary processing unit constructs a model by data processing using the managed data. The primary processing unit stores the constructed model in secure storage. The high-order processing unit generates information by data processing using the model stored in the secure storage. In this aspect, the primary processing unit constructs a model using the managed data in a secure area. The primary processing unit stores the constructed model in secure storage constructed in the secure area. Also in this aspect, the secondary processing unit executes data processing using the model in the secure area. In other words, according to this aspect, the construction of the model by the primary processing unit and the generation of information by the secondary processing unit are completed in the secure area, so confidential information included in the managed data will not be leaked to the outside.
[0113] In one aspect of this embodiment, the managed data is building structure data related to the structures of buildings built in the target area. The primary processing unit constructs an urban structure model of the target area using the building structure data for each building built in the target area. The high-level processing unit generates disaster prevention information for the target area using the urban structure model. In this aspect, the primary processing unit constructs the urban structure model in a secure area using the building structure data. The primary processing unit stores the constructed urban structure model in secure storage constructed in the secure area. Also, in this aspect, the secondary processing unit generates disaster prevention information for the target area using the urban structure model in the secure area. In other words, according to this aspect, the construction of the urban structure model by the primary processing unit and the generation of disaster prevention information by the secondary processing unit are completed in the secure area, so confidential information included in the building structure data will not be leaked to the outside.
[0114] An information generation device according to one aspect of the present embodiment includes an output unit that outputs disaster prevention information. The data processing unit removes confidential information from the disaster prevention information. The output unit outputs the disaster prevention information from which the confidential information has been removed. According to this aspect, the disaster prevention information generated by the secondary processing unit can be distributed by removing the confidential information from the disaster prevention information.
[0115] In one aspect of this embodiment, the authority management unit generates a hash value at the current stage using data generated in response to the use of the managed data, a hash value from a previous data processing stage, and a nonce. The transmission unit transmits the generated hash value at the current stage to the management device. According to this aspect, the usage status of the managed data can be managed using the hash value. For example, blockchain technology can be applied to the method of this aspect.
[0116] An information generating device according to one aspect of the present embodiment includes an input / output interface connected to a terminal device used by a user authorized to use the managed data. The input / output interface displays information corresponding to the authorization information set for the managed data on the screen of the terminal device. According to this aspect, a user authorized to use the managed data can check the usage status of the managed data. Therefore, according to this aspect, the user can be encouraged to use the managed data appropriately.
[0117] (Second embodiment) Next, an information generating device according to a second embodiment will be described with reference to the drawings. The information generating device according to the second embodiment differs from the first embodiment in that it updates information in response to changes in the streetscape of the target area. In this embodiment, an example of updating disaster prevention information will be described. The information generating device according to the second embodiment is combined with the management device according to the first embodiment to form an information management system. In the following, the description of the same configuration and functions as those of the information generating device according to the first embodiment will be simplified.
[0118] (composition) 25 is a block diagram showing an example of the configuration of an information generating device according to the present disclosure. The information generating device 20 includes an input / output interface 21, a transmitter 22, a secure interface 23, a secure storage 24, a data processing unit 25, an authority management unit 27, an output unit 28, and an update unit 29. The secure storage 24, the data processing unit 25, and the authority management unit 27 are constructed inside a secure area 230. The data processing unit 25 includes a primary processing unit 251 and a high-order processing unit 252.
[0119] The information generating device 20 includes a secure area 230. The secure area 230 has the same configuration as the secure area 130 of the first embodiment. The secure area 230 is a virtual area constructed in a cloud or a server accessible from a terminal device (not shown) used by a user. The secure area 230 includes a secure storage 24, a data processing unit 25, and an authority management unit 27. For example, the secure area 230 is realized using container-type virtualization technology. The secure area 230 is an encrypted environment and is isolated from a local environment connected to an external environment. Applications running in the secure area 230 cannot connect to the local environment. Data used in the secure area 230 is stored in the secure area 230. The data used in the secure area 230 is not stored in the terminal device accessing the secure area 230. Therefore, the data used in the secure area 230 is not leaked from the terminal device. Furthermore, the applications that can be used in the secure area 230 are limited to specific types. This prevents unauthorized use of managed data by users.
[0120] The input / output interface 21 has the same configuration as the input / output interface 11 of the first embodiment. The input / output interface 21 accepts input from a user via an input device. The input / output interface 21 accepts a request to use the management target data managed by the management device 270. The input / output interface 21 sends the input request to use the management target data to the transmission unit 22.
[0121] The transmission unit 22 has the same configuration as the transmission unit 12 of the first embodiment. The transmission unit 22 functions as a communication interface connected to the management device 270 via a network such as the Internet so as to be able to perform data communications. The transmission unit 22 acquires a use request for the managed data input by a user. The transmission unit 22 transmits the use request for the managed data to the management device 270. The transmission unit 22 also acquires authority information including the usage status of the managed data from the authority management unit 27. The transmission unit 22 transmits the authority information including the usage status of the managed data to the management device 270.
[0122] The secure interface 23 has the same configuration as the secure interface 13 of the first embodiment. The secure interface 23 is connected to the management device 270 via a network such as the Internet. The secure interface 23 is connected to the management device 270 via a secure gateway with a high level of security. The secure interface 23 is a communication interface dedicated to the management device 270. The secure interface 23 acquires management target data transmitted from the management device 270 in response to a usage request. The management target data transmitted from the management device 270 has usage rights set for the management target data. The secure interface 23 stores the management target data with usage rights set in the secure storage 24. The secure interface 23 may be configured to grant permission to access the management target data via a secure gateway with a high level of security. The secure interface 23 may be configured inside the secure area 230.
[0123] The secure interface 23 also acquires notification information regarding the use authority of the managed data from the management device 270. The notification information differs depending on the usage status of the managed data by the information generating device 20. If the use of the managed data by the information generating device 20 is within the scope of the usage authority, notification information indicating permission for use is issued. If the use of the managed data by the information generating device 20 is within the scope of the usage authority, notification information calling for caution is issued. If the use of the managed data by the information generating device 20 exceeds the usage authority, notification information indicating a warning is issued. If the use of the managed data by the information generating device 20 exceeds the usage authority, processing may be executed to prohibit the use of the managed data. The notification information regarding the usage authority is displayed on the screen of a terminal device (not shown) used by the user via the output unit 28. A user who views the notification information can take action in accordance with the notification information.
[0124] The secure storage 24 has the same configuration as the secure storage 14 of the first embodiment. The secure storage 24 is a storage area constructed inside the secure area 230. The secure storage 24 has a highly secure storage area. Managed data is stored in the secure storage 24 via the secure interface 23. The managed data stored in the secure storage 24 can only be used inside the secure area 230. The managed data includes confidential information. In addition, usage rights are set for the managed data. The information generating device 20 is given the right to execute data processing using the managed data within the scope of the usage rights. The managed data stored in the secure storage 24 is used by the data processing unit 25.
[0125] Furthermore, the secure storage 24 stores models and information generated using the data to be managed. Typically, the models and information stored in the secure storage 24 can only be used within the secure area 230. Of the information stored in the secure storage 24, information that has been processed so as not to include confidential information and converted so as not to be editable may be configured to be output via the output unit 28. The models stored in the secure storage 24 may also be processed so as not to include confidential information and converted so as not to be editable.
[0126] The data processing unit 25 has the same configuration as the data processing unit 15 of the first embodiment. The data processing unit 25 is constructed inside the secure area 230. For example, the data processing unit 25 is realized by an application that runs inside the secure area 230. The data processing unit 25 acquires the management target data stored in the secure storage 24. The data processing unit 25 executes data processing using the management target data. The data processing unit 25 stores models and information generated by the data processing in the secure storage 24. The data processing using the management target data is completed only inside the secure area 230. Therefore, confidential information included in the management target data will not be leaked outside the secure area 230.
[0127] The data processing unit 25 includes a primary processing unit 251 and a high-order processing unit 252. The primary processing unit 251 and the high-order processing unit 252 have the same configurations as the primary processing unit 151 and the high-order processing unit 152 of the first embodiment. The primary processing unit 251 performs primary processing using the data to be managed. The primary processing is processing to generate models and information used in data processing by the high-order processing unit 252. For example, if the data to be managed is building structure data, the primary processing unit 251 generates an urban structure model using the building structure data. The high-order processing unit 252 performs high-order processing using the models and information generated by the primary processing unit 251. The high-order processing is processing to generate new information using the models and information generated by the primary processing. For example, the high-order processing unit 252 generates disaster prevention information using an urban structure model generated using the building structure data. If high-order processing is not performed, the high-order processing unit 252 may be omitted, and the data processing unit 25 may be configured with only the primary processing unit 251.
[0128] Furthermore, the data processing unit 25 deletes confidential information from information stored in the secure storage 24 that is to be output to the outside. Furthermore, the data processing unit 25 converts the output information into a format that cannot be edited. For example, the output information is disaster prevention information that has been processed so as not to include confidential information and converted so as not to be editable. The data processing unit 25 sends the output information that has been processed so as not to include confidential information and converted so as not to be editable to the output unit 28.
[0129] Furthermore, the data processing unit 25 acquires update information from the update unit 29. The data processing unit 25 updates the urban structure model and disaster prevention information using the acquired update information. The updated urban structure model is stored in the secure storage 24. The updated disaster prevention information is processed so that it does not contain confidential information, and is converted so that it cannot be edited.
[0130] The authority management unit 27 has the same configuration as the authority management unit 17 of the first embodiment. The authority management unit 27 updates authority information including the usage status of the managed data in accordance with the use of the managed data.
[0131] The update unit 29 acquires information indicating changes in the streetscape included in the target area. For example, the update unit 29 acquires information indicating changes in the streetscape detected from video footage captured by a surveillance camera or a dashcam. For example, the update unit 29 may be configured to acquire information indicating changes in the streetscape detected from images or videos posted to a social networking service (SNS). For example, the update unit 29 acquires information regarding changes in buildings included in the target area. Changes in buildings include situations where a site where a building used to be has been cleared, a building has been built on a vacant site, or a building has been renovated. The update unit 29 may be configured to detect changes in the streetscape using the acquired information. For example, the update unit 29 detects changes in the streetscape using a trained model generated by machine learning.
[0132] When the update unit 29 acquires information indicating a change in the streetscape, it instructs the data processing unit 25 to update the urban structure model and the disaster prevention information. For example, when the update unit 29 acquires information indicating a change in the streetscape, it may be configured to transmit the information to the management device 270. Furthermore, the update unit 29 may be configured to acquire information indicating a change in the streetscape from the management device 270.
[0133] The output unit 28 has the same configuration as the output unit 18 in the first embodiment. The output unit 28 functions as a communication interface connected to an external system or device via a network such as the Internet so as to be able to perform data communication. The output unit 28 acquires output information from the data processing unit 25. The output unit 28 outputs the acquired output information. The output unit 28 also functions as an output interface that displays an image on the screen of a terminal device used by the user.
[0134] FIG. 26 is a conceptual diagram illustrating an example of updating disaster prevention information according to the present disclosure. The disaster prevention information 258 is an example in which the disaster prevention information 158 ( FIG. 23 ) of the first embodiment has been updated. In the example of FIG. 26 , update information is acquired indicating that one of the buildings with a collapse risk level of 3 that had been built in the target area has been removed, leaving an empty lot. In the disaster prevention information 158 of FIG. 23 , roads located around the building with a collapse risk level of 3 are not designated as safe roads. In the disaster prevention information 258 of FIG. 26 , since the building with a collapse risk level of 3 has been removed, the roads around the building have been added as safe roads. For example, notices printed with the disaster prevention information 258 may be posted around town or distributed to citizens. The disaster prevention information 258 may also be provided in a viewable state via a network such as the Internet. People who view the disaster prevention information 258 can identify safe roads and evacuation shelters within the target area. In the event of an earthquake or fire, people's safety can be ensured by choosing a safe route displayed in the disaster prevention information 258 and evacuating to an evacuation shelter. As described above, according to this embodiment, disaster prevention information is updated in accordance with changes in the streetscape of the target area, so that disaster prevention measures that are more in line with reality can be taken.
[0135] For example, disaster prevention information providers may offer incentives such as rewards to sources of updated information. If the disaster prevention information provider is a company, incentives such as a reward can be considered. If the disaster prevention information provider is a local government, incentives such as tax reductions can be considered. For example, if a system is established that offers incentives based on the quality of updated information, disaster prevention information can be continuously updated with higher quality updated information in line with real cityscapes.
[0136] For example, the update information can also be used to update building structure data for each building. For example, if a system were established in which building structure data for each building is automatically updated in response to changes inside the building and the update information is notified to the local government, the building structure data for each building managed by the local government could be automatically updated. If such a system were established, it would make the management of building structure data in local governments more efficient.
[0137] (operation) Next, the operation of the information generating device according to this embodiment will be described with reference to the drawings. Fig. 27 is a flowchart showing an example of updating disaster prevention information by the information generating device according to the present disclosure. In describing the processing according to the flowchart of Fig. 27, the components of the information generating device 20 will be the main focus. The main focus of the processing according to the flowchart of Fig. 27 may be the information generating device 20.
[0138] 27, first, the update unit 29 acquires update information relating to changes in the streetscape in the target area (step S211). The update unit 29 sends the acquired update information to the high-order processing unit 252.
[0139] Next, in response to the acquisition of the update information, the high-order processing unit 252 acquires the disaster prevention information stored in the secure storage 24 (step S212).
[0140] Next, the high-order processing unit 252 updates the disaster prevention information for the target area using the acquired update information (step S213). The high-order processing unit 252 stores the updated disaster prevention information in the secure storage 24. For example, the high-order processing unit 252 removes confidential information included in the building structure data from the disaster prevention information. The disaster prevention information from which the confidential information has been removed may be stored in a storage unit other than the secure storage 24.
[0141] Next, the authority information updated in response to the update of the disaster prevention information is transmitted to the management device 270 (step S214). The process of step S214 may be performed every time after step S213, or may be performed at another preset timing. If the process is to continue after step S214 (Yes in step S215), the process returns to step S213.
[0142] If the process does not continue after step S214 (No in step S215), the high-order processing unit 252 converts the generated disaster prevention information into a format that cannot be edited (step S216). It is assumed that confidential information has been removed from this disaster prevention information. The process of step S216 is a process for preventing the disaster prevention information from being tampered with. For example, the high-order processing unit 252 converts the file format into one that does not allow characters or images included in the disaster prevention information to be copied. For example, if external editing of the disaster prevention information is permitted, the process of step S216 may be omitted.
[0143] The output unit 28 outputs the disaster prevention information converted into an uneditable format (step S217). For example, the updated disaster prevention information may be printed on paper or the like and posted around town or distributed to citizens. The updated disaster prevention information may also be provided in a viewable state via a network such as the Internet. There are no particular limitations on how the updated disaster prevention information may be used, as long as it is for the purpose of disaster prevention.
[0144] As described above, the information generating device according to this embodiment includes a transmission unit, a secure interface, a secure storage, a data processing unit, an authority management unit, and an update unit. The transmission unit transmits a request to use the managed data to the management device that manages the managed data. The secure interface receives the managed data, for which usage rights have been set, transmitted in response to the usage request. The secure storage is constructed in a secure area. The managed data is stored in the secure storage. The data processing unit executes data processing using the managed data in the secure area. The authority management unit updates the authority information included in the usage rights set for the managed data in accordance with the usage status of the managed data. The transmission unit transmits the updated authority information in accordance with the usage status of the managed data to the management device. The update unit acquires information regarding changes in the target area. The data processing unit updates the urban structure model and disaster prevention information in accordance with the changes in the target area.
[0145] The information generating device of this embodiment executes data processing using managed data in a secure area. The information generating device of this embodiment also updates the permission information included in the usage rights set for the managed data in accordance with the usage status of the managed data, and transmits the updated permission information to the management device. Furthermore, the information generating device of this embodiment updates the urban structure model and disaster prevention information in accordance with changes in the target area. Therefore, according to this embodiment, high-value-added information can be updated at any time using data containing highly confidential information while tracing usage status.
[0146] (Third embodiment) Next, an evacuation information providing device according to a third embodiment will be described with reference to the drawings. The evacuation information providing device of this embodiment generates evacuation information using disaster prevention information generated by the information generating device of the first embodiment. The disaster prevention information may be information updated by the information generating device of the second embodiment. The evacuation information providing device of this embodiment may be incorporated into the information management systems of the first and second embodiments. For example, the functions of the evacuation information providing device of this embodiment may be incorporated into the information generating devices of the first and second embodiments. In the following, it is assumed that a person to be evacuated carries a mobile terminal such as a smartphone or tablet.
[0147] (composition) 28 is a block diagram showing an example of the configuration of an evacuation information providing device according to the present disclosure. The evacuation information generating device 30 includes a position acquiring unit 31, a disaster prevention information storage unit 32, an evacuation information generating unit 33, and an evacuation information output unit 35.
[0148] The location acquisition unit 31 acquires location information of evacuation targets. For example, the location acquisition unit 31 acquires location information measured by a function such as a global positioning system (GPS) implemented in a mobile terminal carried by the evacuation target. The location acquisition unit 31 may be configured to acquire location information of evacuation targets identified from video captured by a surveillance camera installed in the city of the target area. The location acquisition unit 31 may be configured to acquire location information of evacuation targets identified from video captured by a drive recorder installed in a vehicle traveling in the city of the target area.
[0149] The disaster prevention information storage unit 32 stores disaster prevention information generated by the information generating device of the first embodiment. The disaster prevention information may be information updated by the information generating device of the second embodiment. The disaster prevention information stored in the disaster prevention information storage unit 32 is used to generate evacuation information customized according to the locations of evacuation targets.
[0150] The evacuation information generation unit 33 acquires location information of evacuation targets. The evacuation information generation unit 33 also acquires disaster prevention information for the target area from the disaster prevention information storage unit 32. The evacuation information generation unit 33 uses the disaster prevention information for the target area to generate evacuation information customized to the location information of the evacuation targets. For example, the evacuation information generation unit 33 generates an evacuation map including evacuation routes from the locations of the evacuation targets to evacuation shelters. For example, the evacuation information generation unit 33 generates an evacuation map including safety levels of ... shelters to which the evacuation targets can be evacuated from the locations of the evacuation targets. The evacuation information generated by the evacuation information generation unit 33 is not particularly limited as long as it is customized according to the locations of the evacuation targets. For example, the evacuation information is generated when an event requiring evacuation occurs. The evacuation information may be updated as time passes since the occurrence of the event requiring evacuation. When the evacuation information is updated as time passes, the disaster prevention information updated in accordance with changes in buildings in the target area may be used.
[0151] The evacuation information output unit 35 outputs the evacuation information generated by the evacuation information generation unit 33. The evacuation information output unit 35 transmits the information to a mobile terminal carried by the person to be evacuated. For example, the evacuation information output unit 35 may be displayed on the screen of a terminal device placed in a position visible to the person to be evacuated. The evacuation information transmitted to the mobile terminal is displayed on the screen of the mobile terminal. The person to be evacuated who views the information displayed on the screen of the mobile terminal can act according to the evacuation information customized to their location.
[0152] FIG. 29 is a conceptual diagram illustrating an example of evacuation information generated by the evacuation information generation device according to the present disclosure. The evacuation information 331 is a disaster prevention map in which information indicating safe routes in the event of a disaster such as an earthquake is superimposed on a map of the target area. The disaster prevention information used to generate the evacuation information 331 does not include confidential information contained in the building structure data. The evacuation information 331 displays the location (current location) of the person to be evacuated. The evacuation information 331 displays signs indicating that the road is safe on roads away from locations where buildings with a high risk of collapse are located. Safe roads may be set for each disaster, such as an earthquake, fire, or flood. The evacuation information 331 also displays evacuation shelters in the target area. The evacuation information 331 displays a safe evacuation route from the location (current location) of the person to be evacuated to the evacuation shelter. The evacuation information 331 also displays the risk level of the location (current location) of the person to be evacuated and the safety level of the evacuation shelter. The safety level and risk level are indicators set according to the building structure data for each building.
[0153] Evacuation targets who view the evacuation information 331 can recognize that they are in danger by checking the risk level of their current location. Furthermore, by checking the safety levels of available evacuation shelters and the safety levels of evacuation routes to the shelters, they can determine which shelter to head for and which evacuation route to take. In the event of a disaster such as an earthquake, if the evacuation target selects a safe route or shelter displayed in the evacuation information 331 customized to their location and evacuates to the shelter, their safety will be ensured.
[0154] FIG. 30 is a conceptual diagram illustrating an example of evacuation information generated by the evacuation information generation device according to the present disclosure. The evacuation information 332 is a disaster prevention map in which information indicating safe routes is superimposed on a map of a target area in response to a situation in which a fire has occurred following a disaster such as an earthquake. The disaster prevention information used to generate the evacuation information 332 does not include confidential information contained in building structure data. The evacuation information 332 displays the location (current location) of the person to be evacuated. The evacuation information 332 also displays evacuation shelters in the target area. The evacuation information 332 displays a safe evacuation route from the location (current location) of the person to be evacuated to the evacuation shelter. The evacuation information 332 displays an evacuation route that avoids areas with a high risk of fire spreading as much as possible. The evacuation information 332 also displays the risk level of the location (current location) of the person to be evacuated and the safety level of the evacuation shelter. The safety level and risk level are indices set according to the building structure data for each building.
[0155] A person to be evacuated who views the evacuation information 332 can recognize that he or she is in danger by referring to the danger level of his or her location. In addition, the person to be evacuated can determine which evacuation shelter to head for and which evacuation route to take by referring to the safety level of available evacuation shelters and the safety level of evacuation routes to the shelters. In a situation where a fire occurs following a disaster such as an earthquake, the safety of the person to be evacuated can be ensured if the person to be evacuated selects a safe route or evacuation shelter displayed in the evacuation information 332 customized to the person's location and evacuates to the evacuation shelter.
[0156] FIG. 31 is a conceptual diagram illustrating an example of evacuation information generated by an evacuation information generation device according to the present disclosure. FIG. 31 illustrates an example of evacuation information for the interior of a building. For example, disaster prevention information for the interior of a building is generated using building structure data of the building. The disaster prevention information for the interior of a building may also be generated using a structural model constructed based on the building structure data of the building. The evacuation information 333 is a disaster prevention map in which information indicating evacuation routes to emergency exits is superimposed on a map of the interior of a building in response to a situation in which a disaster such as an earthquake has occurred. The disaster prevention information used to generate the evacuation information 333 does not include confidential information included in the building structure data. The evacuation information 333 displays the location (current location) of a person to be evacuated. The evacuation information 333 also displays emergency exits near the person to be evacuated. The evacuation information 333 displays an evacuation route from the location (current location) of the person to be evacuated to the emergency exit. For example, the location of the person to be evacuated is identified by location information acquired by a mobile device carried by the person to be evacuated, video footage from a surveillance camera, a beacon installed indoors, or the like. In the evacuation information 333, the interior of a room that the evacuees cannot enter is masked.
[0157] For example, the evacuation information 333 may be delivered to a mobile device carried by the evacuation target. For example, the evacuation information 333 may be displayed on a monitor visible from the location of the evacuation target. For example, the evacuation information 333 may be projected onto a wall, ceiling, or floor by a projector installed indoors. For example, the evacuation information 333 may be provided via a device using XR (Cross Reality) technology, such as AR (Augmented Reality), VR (Virtual Reality), or MR (Mixed Reality). For example, devices using XR technology include smart glasses. After viewing the evacuation information 333, the evacuation target can determine that they should follow the evacuation route and head for an evacuation exit. For example, a visitor visiting a high-rise building for business purposes, such as a business meeting with a client, may not be familiar with the building's information. In such a situation, if a disaster occurs, the visitor may not be able to evacuate appropriately. Providing evacuation routes tailored to the evacuation target's location to evacuation targets inside a building, as in the evacuation information 333, can ensure safer evacuation. For example, the system may be configured so that disaster prevention information for the target area that the building is in is provided to evacuees who have evacuated from inside the building to the outside, allowing them to evacuate not only from inside the building but also to a safe evacuation shelter in the target area.
[0158] (operation) Next, the operation of the evacuation information generation device 30 according to this embodiment will be described with reference to the drawings. FIG. 32 is a flowchart showing an example of generation of evacuation information by the evacuation information generation device according to the present disclosure. In describing the processing according to the flowchart of FIG. 32, the components of the evacuation information generation device 30 will be the main focus. The main focus of the processing according to the flowchart of FIG. 32 may be the evacuation information generation device 30.
[0159] In FIG. 32, first, the position acquisition unit 31 acquires the position information of the evacuation target person (step S311).
[0160] Next, the evacuation information generating unit 33 acquires disaster prevention information corresponding to the location of the evacuation target person from the disaster prevention information storage unit 32 (step S312).
[0161] Next, the evacuation information generating unit 33 generates evacuation information customized to the location of the evacuation target person using the acquired disaster prevention information (step S313).
[0162] Next, the evacuation information output unit 35 presents the evacuation information customized according to the location of the evacuation target person to the evacuation target person (step S314). For example, the evacuation information customized according to the location of the evacuation target person is displayed on the screen of a mobile terminal carried by the evacuation target person.
[0163] As described above, the evacuation information generation device of this embodiment includes a location acquisition unit, a disaster prevention information storage unit, an evacuation information generation unit, and an evacuation information output unit. The location acquisition unit acquires location information of evacuation targets. The disaster prevention information storage unit stores disaster prevention information for the target area. The evacuation information generation unit acquires disaster prevention information according to the location of the evacuation target from the disaster prevention information storage unit. The evacuation information generation unit generates evacuation information customized to the location of the evacuation target using the acquired disaster prevention information. The evacuation information output unit presents the evacuation information customized to the location of the evacuation target to the evacuation target. For example, the evacuation information customized to the location of the evacuation target is displayed on the screen of a mobile device carried by the evacuation target.
[0164] The evacuation information generation device of this embodiment generates customized evacuation information according to the location of each evacuation target person. The evacuation information generation device of this embodiment can provide evacuation information customized for each evacuation target person located in a target area. According to this aspect, safe evacuation information can be provided to any evacuation target person staying in the target area.
[0165] (Fourth embodiment) Next, an information generating device according to a fourth embodiment will be described with reference to the drawings. The information generating device of this embodiment has a simplified configuration of the information generating devices of the first and second embodiments.
[0166] (composition) 33 is a block diagram showing an example of the configuration of an information generating device according to the present disclosure. The information generating device 40 includes a transmitting unit 42, a secure interface 43, a secure storage 44, a data processing unit 45, and an authority management unit 47.
[0167] The transmission unit 42 transmits a request to use the managed data to a management device that manages the managed data. The secure interface 43 receives the managed data, for which usage rights have been set, transmitted in response to the usage request. The secure storage 44 is constructed in the secure area 430 and stores the managed data. The data processing unit 45 executes data processing using the managed data in the secure area 430. The authority management unit 47 updates the authority information included in the usage rights set for the managed data in accordance with the usage status of the managed data. The transmission unit 42 transmits the updated authority information to the management device in accordance with the usage status of the managed data.
[0168] (operation) Fig. 34 is a flowchart showing an example of generation of evacuation information by the information generation device according to the present disclosure. In describing the processing according to the flowchart of Fig. 34, the components of the information generation device 40 will be the main focus. The main focus of the processing according to the flowchart of Fig. 34 may be the information generation device 40.
[0169] In FIG. 34, first, the transmission unit 42 transmits a request to use the management target data to the management device that manages the management target data (step S411).
[0170] Next, the secure interface 43 receives the management target data for which the usage authority has been set, which has been transmitted in response to the usage request (step S412).
[0171] Next, the management target data is stored in the secure storage 44 constructed in the secure area 430 (step S413).
[0172] Next, data processing unit 45 executes data processing using the management target data in secure area 430 (step S414).
[0173] Next, the authority management unit 47 updates the authority information included in the usage authority set for the management target data in accordance with the usage status of the management target data (step S415).
[0174] Next, the transmission unit 42 transmits the authority information updated according to the usage status of the management target data to the management device (step S416).
[0175] The information generating device of this embodiment executes data processing using managed data in a secure area. The information generating device of this embodiment also updates the permission information included in the usage authorization set for the managed data according to the usage status of the managed data, and transmits the updated permission information to the management device. Therefore, this embodiment allows the usage status of the managed data to be traced. Therefore, this embodiment allows data containing highly confidential information to be used while tracing its usage status.
[0176] (Hardware) Next, a hardware configuration for executing the processes in the present disclosure will be described with reference to the drawings. Here, an information processing device 90 (computer) in Fig. 35 is given as an example of such a hardware configuration. The information processing device 90 in Fig. 35 is an example of a configuration for executing the processes in the present disclosure and does not limit the scope of the present disclosure.
[0177] As shown in Fig. 35, an information processing device 90 includes a processor 91, a memory 92, an auxiliary storage device 93, an input / output interface 95, and a communication interface 96. In Fig. 35, interface is abbreviated as I / F (Interface). The processor 91, memory 92, auxiliary storage device 93, input / output interface 95, and communication interface 96 are connected to each other via a bus 98 so as to be able to communicate data with each other. The processor 91, memory 92, auxiliary storage device 93, and input / output interface 95 are also connected to a network such as the Internet or an intranet via the communication interface 96.
[0178] The processor 91 loads a program (instructions) stored in an auxiliary storage device 93 or the like into the memory 92. For example, the program is a software program for executing the processes of the present disclosure. The processor 91 executes the program loaded into the memory 92. The processor 91 executes the program to execute the processes of the present disclosure.
[0179] The memory 92 is a storage device having an area in which a program is loaded. The processor 91 loads a program stored in an auxiliary storage device 93 or the like into the memory 92. The memory 92 is realized by a volatile memory such as a DRAM (Dynamic Random Access Memory). Alternatively, a non-volatile memory such as an MRAM (Magnetoresistive Random Access Memory) may be used as the memory 92.
[0180] The auxiliary storage device 93 stores various data such as programs. For example, the auxiliary storage device 93 is realized by a local disk such as a hard disk or flash memory. Note that it is also possible to configure the system so that various data is stored in the memory 92, and omit the auxiliary storage device 93.
[0181] The input / output interface 95 is an interface for connecting the information processing device 90 to peripheral devices based on standards and specifications. The communication interface 96 is an interface for connecting to external systems and devices via a network such as the Internet or an intranet based on standards and specifications. The input / output interface 95 and the communication interface 96 may be a common interface for connecting to external devices.
[0182] Input devices such as a keyboard, mouse, and touch panel may be connected to the information processing device 90 as needed. These input devices are used to input information and settings. When a touch panel is used as the input device, a screen having the function of the touch panel serves as the interface. The processor 91 and the input devices are connected via an input / output interface 95.
[0183] The information processing device 90 may be equipped with a display device for displaying information. When a display device is equipped, the information processing device 90 is equipped with a display control device (not shown) for controlling the display of the display device. The information processing device 90 and the display device are connected via an input / output interface 95.
[0184] The information processing device 90 may be equipped with a drive device. The drive device acts as an intermediary between the processor 91 and a recording medium (program recording medium) to read data and programs stored on the recording medium and to write processing results of the information processing device 90 to the recording medium. The information processing device 90 and the drive device are connected via an input / output interface 95.
[0185] The above is an example of a hardware configuration for enabling the processing in the present disclosure. The hardware configuration in Figure 35 is an example of a hardware configuration for executing the processing in the present disclosure and does not limit the scope of the present disclosure. A program that causes a computer to execute the processing in the present disclosure is also included in the scope of the present disclosure.
[0186] A program recording medium on which a program for executing the processing in this embodiment is recorded is also included in the scope of the present invention. For example, the program recording medium is a computer-readable non-transitory recording medium. The recording medium can be realized as an optical recording medium such as a CD (Compact Disc) or a DVD (Digital Versatile Disc). The recording medium may also be realized as a semiconductor recording medium such as a USB (Universal Serial Bus) memory or an SD (Secure Digital) card. The recording medium may also be realized as a magnetic recording medium such as a flexible disk or other recording medium.
[0187] The components in the present disclosure may be combined in any manner. The components in the present disclosure may be realized by software. The components in the present disclosure may be realized by circuits.
[0188] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate.
[0189] A part or all of the above-described embodiments can be described as, but not limited to, the following supplementary notes. (Appendix 1) a transmission unit that transmits a request to use the management target data to a management device that manages the management target data; a secure interface for receiving the management target data for which a usage right is set and which is transmitted in response to the usage request; a secure storage constructed in a secure area and storing the data to be managed; a data processing unit that executes data processing using the management target data in the secure area; an authority management unit that updates authority information included in the use authority set for the management target data in accordance with a usage status of the management target data, The transmission unit An information generating device that transmits the authority information updated in accordance with the usage status of the management target data to the management device. (Appendix 2) The data processing unit a primary processing unit that constructs a model by data processing using the data to be managed and stores the constructed model in the secure storage; and a high-order processing unit that generates information by data processing using the model stored in the secure storage. (Appendix 3) the management target data is building structure data relating to the structure of buildings constructed in the target area; The primary processing unit includes: constructing an urban structure model of the target area using the building structure data for each building constructed in the target area; The high-level processing unit 3. The information generating device according to claim 2, which generates disaster prevention information for the target area using the urban structure model. (Appendix 4) an output unit that outputs the disaster prevention information; The data processing unit removing confidential information contained in the disaster prevention information; The output unit 4. The information generating device according to claim 3, which outputs the disaster prevention information from which the confidential information has been removed. (Appendix 5) an update unit that acquires information about changes in the target area; The data processing unit 4. The information generating device according to claim 3, wherein the urban structure model and the disaster prevention information are updated in accordance with changes in the target area. (Appendix 6) The authority management unit generating a hash value at a current stage using data generated in accordance with the use of the management target data, a hash value at a previous stage of data processing, and a nonce; The transmission unit 2. The information generating device according to claim 1, wherein the generated hash value at the current stage is transmitted to the management device. (Appendix 7) an input / output interface connected to a terminal device used by a user authorized to use the management target data; The input / output interface includes: 2. The information generating device according to claim 1, wherein information corresponding to the authority information set for the management target data is displayed on a screen of the terminal device. (Appendix 8) An information generating device according to any one of Supplementary Notes 1 to 7; an information management system comprising: a management device that manages the usage status of the managed data using a management table that manages authority information of the managed data; transmits the managed data, for which usage authority has been set, to the information generating device in accordance with a usage request transmitted from the information generating device; obtains authority information of the managed data that has been updated in accordance with the usage status of the managed data; and records the updated authority information of the managed data in the management table. (Appendix 9) The computer Sending a request to use the managed data to a management device that manages the managed data; receiving the management target data for which a usage right has been set and which has been transmitted in response to the usage request; storing the management target data in a secure storage constructed in a secure area; executes data processing using the management target data in the secure area; updating the right information included in the use right set for the management target data according to the usage status of the management target data; An information management method for transmitting the authority information updated in accordance with the usage status of the management target data to the management device. (Appendix 10) A process of transmitting a request to use the managed data to a management device that manages the managed data; a process of receiving the management target data for which a usage right is set and which has been transmitted in response to the usage request; A process of storing the management target data in a secure storage constructed in a secure area; a process of executing data processing using the management target data in the secure area; a process of updating authority information included in the usage authority set for the management target data in accordance with the usage status of the management target data; and transmitting the authority information updated in accordance with the usage status of the management target data to the management device. Furthermore, some or all of the configurations described in Supplementary Notes 2 to 8, which are dependent on Supplementary Note 1, may also be dependent on Supplementary Notes 9 and 10 in the same dependent relationship as Supplementary Notes 2 to 8. Furthermore, not limited to Supplementary Notes 1, 9, and 10, but within the scope of each of the above-mentioned embodiments, some or all of the configurations described as Supplements may also be dependent on various hardware, software, various recording means for recording software, or systems. [Explanation of symbols]
[0190] 1 Information Management System 10, 20, 40 Information generation device 11, 21 Input / Output Interface 12, 22, 42 Transmitter 13, 23, 43 Secure Interface 14, 24, 44 Secure Storage 15, 25, 45 Data processing section 17, 27, 47 Authority Management Department 18, 28 Output section 29 Update section 30 Evacuation information generation device 31 Position acquisition part 32 Disaster prevention information storage unit 33 Evacuation information generation section 35 Evacuation information output unit 100 Terminal Device 130, 230, 430 Secure Area 140 Urban Structure Generation Model 150 Disaster Prevention Information Generation Model 151, 251 Primary treatment section 152, 252 Higher processing unit 160 Management Table 170 Management device 171 Acquisition Department 172 Usage Rights Management Department 175 Secure Area 176 Secure Interface 177 Secure Gateway 180 databases
Claims
1. a transmission unit that transmits a request to use the management target data to a management device that manages the management target data; a secure interface for receiving the management target data for which a usage right is set and which is transmitted in response to the usage request; a secure storage constructed in a secure area and storing the data to be managed; a data processing unit that executes data processing using the management target data in the secure area; an authority management unit that updates authority information included in the use authority set for the management target data in accordance with a usage status of the management target data, The transmission unit An information generating device that transmits the authority information updated in accordance with the usage status of the management target data to the management device.
2. The data processing unit a primary processing unit that constructs a model by data processing using the data to be managed and stores the constructed model in the secure storage; The information generating device according to claim 1 , further comprising: a high-order processing unit that generates information by data processing using the model stored in the secure storage.
3. the management target data is building structure data relating to the structure of buildings constructed in the target area; The primary processing unit includes: constructing an urban structure model of the target area using the building structure data for each building constructed in the target area; The high-level processing unit The information generating device according to claim 2 , wherein the information generating device generates disaster prevention information for the target area using the urban structure model.
4. an output unit that outputs the disaster prevention information; The data processing unit removing confidential information contained in the disaster prevention information; The output unit The information generating device according to claim 3 , wherein the disaster prevention information is output with the confidential information removed.
5. an update unit that acquires information about changes in the target area; The data processing unit The information generating device according to claim 3 , wherein the urban structure model and the disaster prevention information are updated in response to changes in the target area.
6. The authority management unit generating a hash value at a current stage using data generated in accordance with the use of the management target data, a hash value at a previous stage of data processing, and a nonce; The transmission unit The information generating device according to claim 1 , wherein the generated hash value at the current stage is transmitted to the management device.
7. an input / output interface connected to a terminal device used by a user authorized to use the management target data; The input / output interface includes: The information generating device according to claim 1 , wherein information corresponding to the authority information set for the management target data is displayed on a screen of the terminal device.
8. An information generating device according to any one of claims 1 to 7; an information management system comprising: a management device that manages the usage status of the managed data using a management table that manages authority information of the managed data; transmits the managed data, for which usage authority has been set, to the information generating device in accordance with a usage request transmitted from the information generating device; obtains authority information of the managed data that has been updated in accordance with the usage status of the managed data; and records the updated authority information of the managed data in the management table.
9. The computer Sending a request to use the managed data to a management device that manages the managed data; receiving the management target data for which a usage right has been set and which has been transmitted in response to the usage request; storing the management target data in a secure storage constructed in a secure area; executes data processing using the management target data in the secure area; updating the right information included in the use right set for the management target data according to the usage status of the management target data; An information management method for transmitting the authority information updated in accordance with the usage status of the management target data to the management device.
10. A process of transmitting a request to use the managed data to a management device that manages the managed data; a process of receiving the management target data for which a usage right is set and which has been transmitted in response to the usage request; A process of storing the management target data in a secure storage constructed in a secure area; a process of executing data processing using the management target data in the secure area; a process of updating authority information included in the usage authority set for the management target data in accordance with the usage status of the management target data; and transmitting the authority information updated in accordance with the usage status of the management target data to the management device.
Citation Information
Patent Citations
Three-dimensional map preparing method, recording medium with three-dimensional map preparing program recorded thereon and disaster preventing information providing system using the method
JP2001266177A