Information processing method, information processing system, and computer program

The information processing method and system address the lack of quality assurance for regenerative medicine products by using a distributed database and blockchain to verify the authenticity of human cell-derived materials, ensuring quality and integrity through secure comparison of clinical information.

JP2025156469APending Publication Date: 2025-10-14HU GROUP RESEARCH INSTITUTE G K +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2025128595
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-07-31
Publication Date
2025-10-14

AI Technical Summary

Technical Problem

There is no complete quality inspection method for regenerative medicine products derived from human cells, making it difficult to guarantee their quality, and existing systems lack the ability to record and compare clinical information related to their manufacture or use in a distributed database system.

Method used

An information processing method and system that stores and compares clinical information about regenerative medical products in a distributed database system, using peer-to-peer connections and blockchain technology to verify the authenticity of raw materials and processed products through base sequence information and challenge-response methods, ensuring confidentiality and integrity of the data.

Benefits of technology

Enables secure and reliable verification of the authenticity of regenerative medical products by comparing base sequence information, ensuring the quality and integrity of the manufacturing process, applicable to both allogeneic and autologous transplantation processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025156469000001_ABST
    Figure 2025156469000001_ABST
Patent Text Reader

Abstract

To provide an information processing method capable of comparing clinical information recorded in a distributed database system that stores at least one of donor-derived clinical information and recipient-derived clinical information related to the manufacture or use of regenerative medical products.SOLUTION: In an information processing method for storing information about a regenerative medical product and manufacture or use of the regenerative medical product in a distributed database system, at least one of clinical information derived from a donor and clinical information derived from a recipient is stored in the distributed database system, and the clinical information recorded in the distributed database system is compared in a confidential state.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing method, an information processing system, and a computer program. [Background technology]

[0002] As for regenerative medicine products derived from human cells, there is no complete quality inspection method for the final product, making it difficult to guarantee its quality. For this reason, it is thought that the quality of processed products can be guaranteed by managing the manufacturing process from raw materials to the processed product.

[0003] Patent Document 1 discloses a system for managing a biomaterial sample collected from a patient by recording the temperature, atmospheric pressure, time, etc., during transportation of the biomaterial sample.

[0004] Patent Document 2 discloses a system that uses blockchain to track workflow processes such as DNA analysis of biological samples. The tracking system in Patent Document 2 discloses a technology that encodes genome sequences to generate personal identification information for the biological samples. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Special Publication No. 2019-518974 [Patent Document 2] Special Publication No. 2019-534525 Summary of the Invention [Problem to be solved by the invention]

[0006] However, Patent Documents 1 and 2 do not disclose any specific technology for recording clinical information related to the manufacture or use of regenerative medical products in a distributed database system and comparing the recorded clinical information.

[0007] An object of the present invention is to provide an information processing method, an information processing system, and a computer program that can compare clinical information recorded in a distributed database system that stores at least one of donor-derived clinical information and recipient-derived clinical information related to the manufacture or use of regenerative medical products. [Means for solving the problem]

[0008] The information processing method according to this aspect is an information processing method for storing information about a regenerative medical product and the manufacture or use of the regenerative medical product in a distributed database system, in which at least one of clinical information derived from a donor and clinical information derived from a recipient is stored in the distributed database system, and the clinical information recorded in the distributed database system is compared in a confidential manner.

[0009] The information processing system according to this aspect is an information processing system that stores information about regenerative medical products and the manufacture or use of the regenerative medical products in a distributed database system, and includes a plurality of information processing devices that constitute the distributed database system. The information processing devices store at least one of clinical information derived from donors and clinical information derived from recipients in the distributed database system, and compare the clinical information recorded in the distributed database system in a confidential manner.

[0010] The computer program according to this aspect is a computer program for causing a computer to execute information processing for storing information about a regenerative medical product and the manufacture or use of the regenerative medical product in a distributed database system, and causes the computer to execute processing for storing at least one of clinical information derived from a donor and clinical information derived from a recipient in the distributed database system and comparing the clinical information recorded in the distributed database system in a confidential manner. [Effects of the Invention]

[0011] Based on the above, it is possible to provide an information processing method, an information processing system, and a computer program that can compare clinical information recorded in a distributed database system that stores at least one of donor-derived clinical information and recipient-derived clinical information related to the manufacture or use of regenerative medical products. [Brief explanation of the drawings]

[0012] [Figure 1] 1 is a schematic diagram illustrating an example of the configuration of an information processing system according to a first embodiment. [Figure 2] 1 is a block diagram showing an example of the configuration of an information processing device according to a first embodiment. [Figure 3] FIG. 1 is a conceptual diagram showing information recorded in a distributed database system. [Figure 4] 10 is a flowchart showing a procedure for recording verification information according to the first embodiment. [Figure 5] 1 is a flowchart showing the steps of a process for verifying authenticity according to the first embodiment. [Figure 6] FIG. 10 is a functional block diagram of an information processing system according to a second embodiment. [Figure 7] FIG. 10 is an explanatory diagram showing a method for verifying authenticity according to a second embodiment. [Figure 8] 10 is a flowchart showing a procedure for recording verification information according to the second embodiment. [Figure 9] 10 is a flowchart showing the steps of a process for verifying authenticity according to the second embodiment. [Figure 10] FIG. 10 is an explanatory diagram showing a method for verifying authenticity according to a modified example of the second embodiment. [Figure 11] FIG. 10 is a functional block diagram of an information processing system according to a third embodiment. [Figure 12] FIG. 10 is a functional block diagram of an information processing system according to a fourth embodiment. [Figure 13] FIG. 10 is an explanatory diagram showing a channel management method according to a fifth embodiment. [Figure 14]FIG. 13 is an explanatory diagram showing a specific example of information shared on each channel according to the fifth embodiment. [Figure 15] 13 is a flowchart showing the steps of authenticity and quality authentication processing according to the sixth embodiment. [Figure 16] 13 is a flowchart showing a processing procedure for browsing information according to the sixth embodiment. [Figure 17] FIG. 13 is an explanatory diagram showing a comparison processing method according to a seventh embodiment. [Figure 18] 13 is a flowchart showing a comparison process procedure according to the seventh embodiment. [Figure 19] FIG. 13 is an explanatory diagram showing a comparison processing method according to the eighth embodiment. [Figure 20] 13 is a flowchart showing a comparison process procedure according to the eighth embodiment. [Figure 21] FIG. 20 is an explanatory diagram showing an overview of recording and comparing recipient clinical information according to the ninth embodiment. [Figure 22] FIG. 20 is an explanatory diagram showing a comparison processing method using a recipient database according to the ninth embodiment. [Figure 23] FIG. 20 is an explanatory diagram showing another comparison processing method using a certificate authority database according to the ninth embodiment. [Figure 24] 13 is a flowchart showing a comparison process procedure using a certificate authority database according to the ninth embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0013] Specific examples of an information processing method, an information processing system, and a computer program according to embodiments of the present invention will be described below with reference to the drawings. Note that the present invention is not limited to these examples, but is defined by the claims, and is intended to include all modifications within the meaning and scope equivalent to the claims. Furthermore, at least some of the embodiments described below may be combined in any manner.

[0014] (Embodiment 1) 1 is a schematic diagram illustrating an example of the configuration of an information processing system according to embodiment 1. The information processing system according to embodiment 1 is a system for performing quality control of regenerative medical products. A regenerative medicine product is a processed product B produced from raw material A containing human cells collected from donor D, and its production involves multiple organizations, such as regenerative medicine providers, manufacturers, transportation companies, and testing companies. Processed product B is, for example, somatic stem cells, skeletal myoblasts, corneal epithelial cell sheets, NK cells, platelet-rich plasma, etc. Since processed product B derived from human cells is a living cell, there is no perfect method for inspecting the quality of the final product. Therefore, it is important to guarantee the quality of processed product B by managing the manufacturing process from raw material A to processed product B. Furthermore, even if information related to the manufacturing process is recorded, quality cannot be guaranteed unless the authenticity of raw material A or processed product B is ensured. The information processing system according to embodiment 1 is a system capable of verifying the authenticity of raw material A and processed product B using base sequence information of raw material A.

[0015] The information processing system according to the first embodiment includes a plurality of information processing devices 1, which are connected via P2P (Peer to Peer) connections. The plurality of P2P-connected information processing devices 1 form a distributed database system. A terminal device 2 is connected to the information processing device 1 via a communication line. The information processing device 1 and the terminal device 2 may be the same computer.

[0016] In order to simplify the explanation, FIG. 1 shows only two parties, a first participant and a second participant, out of the multiple organizations participating as users of the information processing system. The first participant is, for example, a regenerative medicine provider. The first participant collects raw material A containing human cells from donor D and records attribute information of raw material A in a distributed database system via terminal device 2. At this time, the first participant identifies base sequence information of a specific site obtained from raw material A. The information processing system acquires the base sequence information, generates verification information for verifying the authenticity of raw material A or processed product B, and records the generated verification information in the distributed database system. The first participant transports the collected raw material A to the second participant. The first participant also transmits information regarding a method for determining the base sequence of the specific site, such as PCR primer sequence information, sequencing primer sequence information, and primer-related information such as priming temperature and PCR reaction conditions (hereinafter referred to as primer sequence information), to the second participant. The first participant may also transport materials that can be used to determine the base sequence of the specific site, such as PCR primers or sequencing primers (hereinafter referred to as primers), to the second participant.

[0017] The second participant is, for example, a manufacturer that produces processed product B from raw material A containing human cells. The second participant receives raw material A transported from the first participant. The second participant also receives or receives primer sequence information or the primer itself transmitted or transported from the first participant. The second participant then processes raw material A to produce processed product B and performs quality inspection of processed product B. The second participant records information related to processed product B in a distributed database system via a terminal device 2. At this time, the second participant identifies base sequence information of a specific site obtained from processed product B using a primer. The information processing system acquires the base sequence information and generates verification information based on the acquired base sequence information. The information processing system then verifies the authenticity of processed product B by confirming whether the verification information obtained from the base sequence information of raw material A matches the verification information obtained from the base sequence information of processed product B. If the authenticity is verified, the information processing system records information related to processed product B and the verification results in the distributed database system. If the authenticity is denied, the information processing system refuses to record the information related to processed product B.

[0018] 2 is a block diagram showing an example of the configuration of the information processing device 1 according to embodiment 1. The information processing device 1 is a computer including a processing unit 11, a storage unit 12, and a communication unit 13. Note that the information processing device 1 may be a multi-computer consisting of multiple computers, or may be a virtual machine virtually constructed by software.

[0019] The processing unit 11 has one or more arithmetic processing devices such as a central processing unit (CPU), a micro-processing unit (MPU), etc. The processing unit 11 functions as an information processing device 1 constituting a distributed database system by reading and executing a computer program 12a stored in the storage unit 12, and performs processes such as verifying the authenticity of the human-derived raw material A and processed product B, and managing the manufacturing process.

[0020] The storage unit 12 is a storage device such as a hard disk, an EEPROM (Electrically Erasable Programmable ROM), a flash memory, etc. The storage unit 12 stores a computer program 12a required for the processing unit 11 to execute processes such as verifying the authenticity of the human-derived raw material A and the processed product B and managing the manufacturing process.

[0021] The computer program 12a is a program for causing a computer to function as the information processing device 1 of the distributed database system. The computer program 12a causes the computer to execute processes such as verifying the authenticity of the human-derived raw material A and the processed product B, and managing the manufacturing process. The computer program 12a may be recorded in a computer-readable manner on a recording medium 14. The storage unit 12 stores the computer program 12a read from the recording medium 14 by a reading device (not shown). The recording medium 14 may be a semiconductor memory such as a flash memory, an optical disk, a magnetic disk, a magneto-optical disk, or the like. Alternatively, the computer program 12a according to this embodiment may be downloaded from an external server (not shown) connected to a communication network and stored in the storage unit 12.

[0022] The communication unit 13 includes a processing circuit, a communication circuit, etc. for performing communication-related processing, and transmits and receives information between a terminal device 2 connected to the information processing device 1 and other information processing devices 1 that constitute a distributed database system.

[0023] Fig. 3 is a conceptual diagram showing information recorded in a distributed database system. As shown in Fig. 3, the distributed database system stores IDs for identifying raw material A and processed product B, date and time, participant IDs (registrants), information about raw material A or processed product B, and verification results in association with each other. The ID is information for identifying raw material A and processed product B. To simplify the explanation, we will assume that raw material A and processed product B are identified by a single ID, but raw material A and processed product B may be managed using different IDs, lot numbers, etc. The date and time is the date and time when processing such as registering, correcting, or reading out information was performed. The participant ID (registrant) is information that identifies the participant who requested processing such as registering, correcting, or reading out information. Information about raw material A or processed product B is various information about the manufacturing process from raw material A to processed product B. Information about raw material A or processed product B is an example of clinical information about the donor. Information about raw material A includes, for example, information such as the medical history and outcome of donor D who provided raw material A, and information such as HLA type related to biocompatibility. Information about processed product B includes, for example, information such as quality evaluation results related to the effectiveness and safety of processed product B. The verification result is the result of verifying authenticity in accordance with this embodiment 1.

[0024] 4 is a flowchart showing the procedure for recording verification information according to embodiment 1. The information processing device 1 of the first participant acquires, via the terminal device 2, the ID of raw material A, base sequence information of a specific site obtained from raw material A, and primer sequence information for identifying the specific site (step S11). Details are as follows.

[0025] The first participant selects an arbitrary sequence that is highly suitable for personal identification from among the base sequences that can identify donor D, and determines the primer sequence required to identify that sequence. Primers are DNA fragments designed to bind to both ends of the target base sequence. Hereinafter, a PCR reaction is performed using the PCR primers, and the amplified PCR product is used as a sequencing template. The base sequence identified by the primers is referred to as the "base sequence of the specific site." The number of bases in the specific site of the sequence used to identify donor D should preferably be between 17 and 40 bases. To identify the world's population of 7 billion people, a sequence of at least 17 bases is necessary. However, a sequence of 40 bases or more is undesirable, as it may violate the General Data Protection Regulation (GDPR). If it is possible to identify an individual, HLA (Human Leukocyte Antigen) type, KIR (Killer cell Immunoglobulin-like Receptor) type, SNPs (Single Nucleotide Polymorphisms), etc. may be used instead of base sequence information.

[0026] Next, the first participant synthesizes primers (actual DNA fragments) using the determined primer sequences and uses the synthesized primers to sequence raw material A and identify the base sequence of a specific region. In addition to determining base sequences using primers, another method involves using an NGS sequencer to determine the base sequence of PCR products amplified using PCR primers. Because genomic base sequences share commonalities between different individuals, grouping genotypes using combinations of base sequences of a certain length can be used as a substitute for base sequences. For example, HLA types, which are closely related to biocompatibility, are one type of genotype. Determining HLA types is called HLA typing, and known methods include serotyping, SSP, SSO, and SBT. While any of these methods can determine base sequences, the most common method is Sanger sequencing using primers. Therefore, the following describes methods using primer sequences, whether determining the base sequence itself or determining genotypes such as HLA types. Then, the first participant uses the terminal device 2 to transmit the base sequence information of the specific site and the primer sequence information along with the ID and attribute information of raw material A to the information processing device 1. The information processing device 1 acquires the ID, attribute information, and base sequence information of the specific site of raw material A transmitted from the terminal device 2. The attribute information of raw material A is, for example, clinical information of donor D, such as the HLA type of raw material A.

[0027] The processing unit 11 of the information processing device 1 calculates verification information based on the acquired base sequence information of the specific site (step S12), and stores the calculated verification information in the distributed database system in association with the ID of raw material A (step S13). For example, the verification information is information including a hash value calculated based on data including the base sequence information.

[0028] Next, the information processing device 1 transmits the primer sequence information acquired in step S11 to the terminal device 2 or the information processing device 1 of the second participant (step S14). Note that the timing of transmitting the primer sequence information is not particularly limited. Also, while an example in which the information processing device 1 transmits the primer sequence information has been described here, the means of communication is not particularly limited as long as it is possible to transmit the primer sequence information to a subsequent participant who handles raw material A. Furthermore, instead of the primer sequence information, the synthesized primer itself may be transported to the second participant. The primer sequence information may be transported together with raw material A.

[0029] FIG. 5 is a flowchart showing the procedure of the authenticity verification process according to the first embodiment. The information processing device 1 related to the second participant receives the primer sequence information transmitted from another information processing device 1 (step S31). The second participant can acquire the primer sequence information by communicating with the information processing device 1 via the terminal device 2. Note that, as described above, if the primer itself has been transported from the first participant, the second participant receives the primer.

[0030] Next, the information processing device 1 related to the second participant acquires the ID, information related to processed product B, and base sequence information of the specific site via the terminal device 2 (step S32). Details are as follows.

[0031] The second participant synthesizes a primer using the primer sequence indicated by the acquired primer sequence information, and uses the synthesized primer to sequence analyze the base sequence of processed product B and identify the base sequence of the specific portion. Then, the second participant uses the terminal device 2 to transmit the base sequence information of the specific portion together with the ID and information about processed product B to the information processing device 1. The information processing device 1 acquires the ID, information about processed product B, and base sequence information of the specific portion transmitted from the terminal device 2. The information about processed product B is, for example, information such as the quality evaluation results of processed product B.

[0032] The processing unit 11 of the information processing device 1 calculates verification information based on the acquired base sequence information of the specific portion (step S33). The verification information is information including a hash value calculated based on data including base sequence information, for example, and is calculated by the same process as on the first participant's side. If the base sequence information of the specific portion obtained from processed product B is identical to the base sequence information of the specific portion obtained from raw material A, the same verification information as the verification information stored in the distributed database system is obtained.

[0033] The processing unit 11 of the information processing device 1 refers to the distributed database system based on the ID received in step S32, reads out the verification information associated with the ID, and verifies the authenticity of the processed product B by comparing the read out verification information with the verification information calculated in step S33 (step S34).

[0034] If the quality of the base sequence determined by sequence analysis is low, the base sequence may differ from the actual sequence. For example, even if the base sequence of a specific part of processed product B is the same as the base sequence of a specific part of raw material A, the base sequence obtained by sequencing may not match. If there is an error in the base sequence obtained by sequence analysis, the correct verification information cannot be calculated, and authenticity verification will fail. To remedy such sequence analysis errors, it is advisable to use a method that does not require a perfect match between base sequences but allows partial mismatch between base sequences. The base sequence is an arrangement of multiple bases selected from adenine (A), guanine (G), cytosine (C), and thymine (T). Therefore, a portion of the base sequence at the specific site is designated as a base sequence candidate. Similarly, multiple sequence portions at multiple locations are determined as base sequence candidates. When calculating verification information in step S11, the information processing device 1 of the first participant calculates multiple pieces of verification information based on the base sequence information of each of the multiple base sequence candidates and stores them in the distributed data system.The information processing device 1 then transmits information for identifying the multiple base sequence candidates from the base sequence of the specific site together with the multiple pieces of verification information to the terminal device 2 or the information processing device 1 of the second participant. The information processing device 1 of the second participant identifies base sequence information for each of the multiple base sequence candidates based on the base sequence information of the specific site obtained in step S32 and the information for identifying the multiple base sequence candidates transmitted from the first participant.The information processing device 1 then calculates verification information for each of the multiple base sequence candidates.The information processing device 1 reads out the verification information for each of the multiple base sequence candidates calculated and recorded by the information processing device 1 of the first participant from the distributed database system and compares it with the multiple verification information calculated by the second participant.If a predetermined number (an integer greater than or equal to 1) or more of the verification information for the multiple base sequence candidates match, the processed product B is determined to be authentic. Furthermore, the more bases that are allowed to have low-quality base sequences, i.e., the more base sequence candidates there are, the more likely it is that the cost of sequence analysis can be reduced, but on the other hand, the reliability of authenticity will decrease. In particular, when verifying the base sequence of a gene that has a significant impact on biological functions, if a mutation occurs during the processing and the base sequence is of low quality, it may not be possible to detect it.

[0035] If it is determined that processed product B is authentic (step S35: YES), the processing unit 11 of the information processing device 1 stores the information about processed product B acquired in step S32 and the verification result in the distributed database system (step S36), and ends the processing. If it is determined that processed product B is not authentic (step S35: NO), the processing unit 11 of the information processing device 1 refuses to record the information about processed product B (step S37), and ends the processing. Note that if the processing unit 11 determines that processed product B is not authentic, it may be configured to store the verification result in the distributed database system.

[0036] According to the information processing system of embodiment 1 configured in this manner, in a distributed database system that stores information regarding the manufacturing process of processed product B derived from human cells, by using verification information, the base sequence information of raw material A and processed product B can be compared in a confidential manner, thereby ensuring the authenticity of raw material A and processed product B.

[0037] In this embodiment 1, the configuration and operation of the information processing device 1 are described assuming the presence of a donor D in allogeneic transplantation, but the present invention can also be applied to the manufacturing process management of regenerative medical products related to autologous transplantation.

[0038] (Embodiment 2) The information processing system according to the second embodiment uses consortium-based distributed ledger technology to record and manage various information related to the manufacturing process of regenerative medical products. It also differs from the first embodiment in that it employs a challenge-response method to verify the authenticity of raw material A and processed product B, thereby enabling verification of authenticity while avoiding the direct use of base sequence information. Other configurations of the information processing system are similar to those of the information processing system according to the first embodiment, and therefore similar parts are designated by the same reference numerals and detailed description thereof will be omitted.

[0039] <Summary> When a hash value is calculated using base sequence information, the number of possible hash values ​​is the same as the number of possible base sequences. In this case, it is possible to identify the original base sequence associated with the hash value by calculating hash values ​​corresponding to all possible base sequences using a computer. However, for example, if a random number or string (hereinafter referred to as a challenge string) is combined with the base sequence information and the resulting string is hashed, the original base sequence information cannot be decrypted from the hash value without the challenge string. By adding a challenge string in this way, the final generated hash value (hereinafter referred to as a response string) can be varied in various ways. In other words, a hash value that is difficult to decrypt can be obtained. By using this difficult-to-decrypt hash value, the first participant can verify the authenticity of processed product B.

[0040] The information processing device 1 transmits the primer sequence information acquired in step S211 and the challenge character string acquired in step S212 to the terminal device 2 of the second participant or the information processing device 1. (step S216) (see FIG. 8).

[0041] The processing unit 11 of the information processing device 1 uses the challenge string and the response string when calculating verification information (step S234) based on the acquired base sequence information of the specific site (see FIG. 9). Therefore, when low-quality base sequences are not taken into consideration, authenticity can be verified by saving a set of the challenge string and the response string and utilizing them instead of saving the base sequence itself.

[0042] <Details> Figure 6 is a functional block diagram of an information processing system according to embodiment 2. In this embodiment 2, four organizations, namely, a regenerative medicine provider, a manufacturer, a transportation company, and a testing company, will be described as participating as users of the information processing system. The regenerative medicine provider is a medical institution that collects raw material A containing human cells and transplants processed product B manufactured from raw material A. The manufacturer is a business that processes raw material A and manufactures processed product B, which is a regenerative medicine product. The transportation company is a company that transports raw material A from the regenerative medicine provider to the manufacturer, transports processed product B from the manufacturer to a testing company, and transports processed product B from the testing company to a regenerative medicine medical institution. The testing company is a company that evaluates the quality of processed product B.

[0043] The information processing system according to the second embodiment includes a plurality of information processing devices 1, similar to the first embodiment. Each information processing device 1 functions as a peer 3, a certificate authority 4, and an orderer 5 that constitute a blockchain network by having a processing unit 11 read and execute a computer program 12a stored in a storage unit 12. In this embodiment, a blockchain network using Hyperledger (registered trademark) Fabric will be mainly described.

[0044] A peer 3 is a node belonging to each organization participating in the information processing system, and is a logical functional unit block realized by software. Multiple peers 3 are connected via P2P. Each peer 3 has a processing code 31 and a ledger 32. The processing code 31 is a program that describes procedures for verifying various transaction requests sent from the terminal device 2, procedures for executing predetermined processes in response to the transaction requests, etc. The processing code 31 is also called a smart contract, a chaincode (CC), etc. The transaction in this embodiment is processing such as recording and querying information about raw material A and processed product B.

[0045] Peer 3 executes processing code 31 based on the transaction request, and performs processes such as verification, writing information to ledger 32, reading information, and querying information. Consensus on the transaction is achieved using a distributed consensus algorithm. Peer 3 stores information (endorsement policy) that indicates which organization's approval is required for each type of transaction, and Peer 3 performs consensus on the transaction in accordance with the endorsement policy.

[0046] The ledger 32 is composed of a blockchain 32a and a state DB 32b. The blockchain 32a records, as one block, one or more transaction details verified and executed by peers 3 of one or more organizations, information related to raw materials A and processed products B, or their hash values. A series of blocks are linked by recording a hash value calculated based on the information of the block recorded immediately before. The state DB 32b stores the results of transaction execution and the latest state of the information processing system.

[0047] The certification authority 4 registers information about participants and peers 3, issues certificates to organizations that wish to participate in the information processing system, and performs processes such as authenticating participants who access peers 3.

[0048] The Orderer 5 is a logical functional block that controls the order in which transactions verified and approved by a specific organization according to the endorsement policy are written to the blockchain 32a. The Orderers 5 are assumed to be distributed among the participating organizations.

[0049] The outline of the transaction processing flow in the information processing system configured as above is as follows.

[0050] When a transaction request for information inquiry is sent from the terminal device 2 to the peer 3, the peer 3 verifies the signature of the certificate of the sender, the participant. If approved, the peer 3 executes the processing code 31 and sends the execution result to the transaction requester. The execution result includes, for example, information on raw material A or processed product B read from the blockchain 32a.

[0051] When a transaction request for information recording is sent from the terminal device 2 to the peer 3, the processing code 31 is executed as described above, and the execution result is sent to the terminal device 2. If verification by multiple organizations is required, similar processing is performed by the peers 3 of those multiple organizations. The terminal device 2 sends the execution result of the verified and approved transaction to the orderer 5. The orderer 5 orders one or more transactions to generate a block and sends it to the peer 3. The peer 3 links the block sent from the orderer 5 to the chain block and records it.

[0052] In the following explanation, details of the above processes such as consensus formation process will be omitted and only information inquiry and information recording processes will be explained.

[0053] Fig. 7 is an explanatory diagram showing a method for verifying authenticity according to embodiment 2. Fig. 8 is a flowchart showing the procedure for recording verification information according to embodiment 2. The certification authority 4 shown in Fig. 7 is, for example, a certification authority 4 established in a regenerative medicine provider organization. The subsequent organization shown in Fig. 7 is, for example, a manufacturer.

[0054] As in embodiment 1, the regenerative medicine provider institution prepares materials such as primers for determining the base sequence of a specific region on the genome base sequence that can identify donor D, or prepares primer sequence information related to a base sequence determination method. For example, an arbitrary primer sequence is determined, a primer is synthesized using the determined primer sequence, and the synthesized primer is used to sequence analyze the base sequence of raw material A and identify the base sequence of the specific site. The regenerative medicine provider institution uses terminal device 2 to transmit the ID of raw material A, primer sequence information for identifying the specific site, and base sequence information of the specific site obtained from raw material A to peer 3 of the regenerative medicine provider institution. If HLA typing is used as the method for identifying donor D, materials for various HLA typing methods such as serotyping, SSP, SSO, and SBT are prepared, or analysis information required for HLA typing is prepared and transmitted to peer 3 of the regenerative medicine provider institution.

[0055] Peer 3 acquires the ID, base sequence information, and primer sequence information, and registers them in the authentication DB of the regenerative medicine provider (step S211). The authentication DB is a database owned by the authentication authority 4, and stores information on participants and peer 3, etc. The authentication DB actually exists in the memory unit 12 of the information processing device 1. The fact that the base sequence information and primer sequence information have been registered in the authentication DB is recorded in the block chain (BC) 32a. Then, the authentication authority 4 generates an arbitrary challenge string (step S212). The challenge string is a randomly generated sequence of characters. The challenge string is an example of challenge data, and the challenge data may be a randomly generated sequence of characters, numbers, and other symbols.

[0056] Next, the certification authority 4 inputs the information combining the base sequence information and the challenge character string into a predetermined hash function to calculate a hash value (step S213).The certification authority 4 records the calculated hash value, which is verification information, in association with the ID of raw material A in the certification DB (step S214).

[0057] The peer 3 encrypts the challenge string used to generate the verification information using the public key of the follow-on institution (step S215). The encryption method may be, for example, SHA-3 or P256-curve. The peer 3 then transmits the primer sequence information acquired in step S211 and the challenge string encrypted in step S216 to the peer 3 of the follow-on institution (step S216). Note that, as indicated by the dashed line in FIG. 7, instead of transmitting the primer sequence information, the synthesized primer itself may be transported to the follow-on institution.

[0058] 9 is a flowchart showing the steps of the authenticity verification process according to embodiment 2. The peer 3 of the subsequent institution receives the primer sequence information and the challenge character string transmitted from the peer 3 of the healthcare provider institution (step S231).

[0059] As in embodiment 1, the subsequent institution synthesizes a primer based on the primer sequence indicated by the received primer sequence information, and uses the synthesized primer to sequence analyze the base sequence of processed product B and identify the base sequence of the specific site.The subsequent institution then uses the terminal device 2 to transmit the ID, information about processed product B, and the base sequence information of the specific site to the peer 3 of the subsequent institution.

[0060] The peer 3 of the succeeding institution acquires the ID transmitted from the terminal device 2, information on the processed product B, and information on the base sequence of the specific site (step S232).

[0061] The peer 3 of the subsequent institution decrypts the encrypted challenge string using its own private key (step S233). Then, the peer 3 calculates a hash value by inputting the information obtained by combining the base sequence information acquired in step S232 and the challenge string decrypted in step S233 into a predetermined hash function (step S234). The peer 3 transmits the ID and the verification information, which is the calculated hash value, to the peer 3 of the regenerative medicine provider institution (step S235).

[0062] The peer 3 of the regenerative medicine provider institution receives the ID and verification information transmitted from the peer 3 of the subsequent institution (step S236). Then, the peer 3 reads the verification information recorded in the authentication DB using the acquired ID, and performs verification by determining whether the read verification information matches the verification information received in step S236 (step S237). The peer 3 records the verification result in the blockchain 32a (step S238), and transmits the verification result to the peer 3 of the subsequent institution (step S239).

[0063] The subsequent institution peer 3 receives the verification result transmitted from the regenerative medicine provider peer 3 (step S240) and executes a recording process according to the verification result (step S241). Specifically, if the subsequent institution peer 3 confirms the authenticity of processed product B, it records the ID and information about processed product B in the blockchain 32a. If the subsequent institution peer 3 cannot confirm the authenticity of processed product B, it refuses to record information about processed product B.

[0064] According to the information processing system of embodiment 2, it is possible to verify the authenticity of raw material A and processed product B without directly using the base sequence information of donor D. Specifically, the base sequence information of donor D itself is not transmitted from the regenerative medicine provider to other organizations or recorded in ledger 32, and the authenticity of raw material A and processed product B can be verified by transmitting and receiving the challenge character string and primer sequence information.

[0065] (Variation) FIG. 10 is an explanatory diagram showing a method for verifying authenticity according to a modified example of the second embodiment. In the above-described second embodiment, an example was described in which the base sequence information and primer sequence information of donor D are recorded in the authentication DB. However, the management and storage location of the base sequence information and primer sequence information are not limited to this. For example, the base sequence information and primer sequence information may be configured to be recorded in the state DB 32b. In this case, hash values ​​or root hashes of the base sequence information and primer sequence information may be recorded in the blockchain 32a. In this case, the peer 3 of the subsequent organization can obtain the verification information recorded by the regenerative medicine provider by referring to the state DB 32b. Therefore, the peer 3 of the subsequent organization can verify the authenticity of the processed product B by determining whether the verification information calculated in step S234 matches the verification information read from the state DB 32b.

[0066] In the second embodiment, an example has been described in which the information processing device 1 to the peer 3 are provided in each organization that uses the information processing system, but the installation location of the information processing device 1 is not particularly limited.

[0067] In the second embodiment, the consortium-type blockchain 32a has been described, but the information processing system may be configured with a public-type blockchain 32a.

[0068] (Embodiment 3) In the third embodiment, specific examples of information relating to raw material A and processed product B that should be recorded to manage the manufacturing process of regenerative medical products will be described. In particular, the information processing system according to the third embodiment differs from the second embodiment in that it can manage electronic documents in a non-falsifiable manner by recording hash values ​​of electronic documents such as consent forms obtained from patients, documents showing the results of quality evaluation tests on processed product B, and contracts for the processing and testing of raw material A in the blockchain 32a. Other configurations of the information processing system are the same as those of the information processing system according to the second embodiment, so the same components are denoted by the same reference numerals and detailed description thereof will be omitted.

[0069] 11 is a functional block diagram of an information processing system according to embodiment 3. As with embodiment 2, the information processing system according to embodiment 3 includes a plurality of information processing devices 1, and each information processing device 1 functions as a peer 3, a certificate authority 4, and an orderer 5 that constitute a blockchain network. Furthermore, the peer 3 according to embodiment 3 includes an external DB 33 in addition to the ledger 32. The external DB 33 mainly stores information with a relatively large amount of data, such as electronic documents.

[0070] The information recorded in the blockchain 32a and the external DB 33 will be explained along with the manufacturing process of the regenerative medicine product.

[0071] (1) After submitting a regenerative medicine provision plan After submitting a regenerative medicine provision plan to an administrative agency, the regenerative medicine provider uses terminal device 2 to request peer 3 to record electronic documents describing the evaluation method for processed product B, the evaluation criteria, and a list of registered equipment for quality inspection. Peer 3 verifies the recording request, assigns document identification numbers to the various electronic documents, and records them in external DB 33. Peer 3 also calculates hash values ​​for the various electronic documents, assigns electronic identification numbers to the calculated hash values, and records them in blockchain 32a. By comparing the hash values ​​calculated from the electronic documents recorded in external DB 33 with the hash values ​​recorded in blockchain 32a, it is possible to confirm the authenticity of the electronic documents, i.e., that they have not been tampered with. Furthermore, a participant in the information processing system uses a terminal device 2 to request a peer 3 to record an electronic document relating to the outsourcing contract concluded between the organizations for the processing and inspection of raw material A. The peer 3 verifies the recording request, records the electronic document relating to the outsourcing contract in the external DB 33, and records the hash value of the electronic document in the blockchain 32a. The hash value recorded in the blockchain 32a may be a root hash or a Merkle-Patricia tree that summarizes the hash values ​​of other information. The same applies to the hash values ​​of other information below.

[0072] (2) Before cell collection The regenerative medicine provider uses terminal device 2 to request peer 3 to record donor D's patient clinical information and patient consent information. The patient consent information includes an encrypted consent document regarding the treatment and secondary use using human cells provided by donor D. The encrypted consent document contains the consent date and consent details encrypted with donor D's private key. However, donor D's consent status is public information. The consent details can be confirmed using donor D's public key. Peer 3 verifies the recording request and records donor D's patient clinical information and patient consent information in blockchain 32a.

[0073] (3) Cell collection The regenerative medicine provider uses terminal device 2 to request peer 3 to record the quality test data number, quality test data, and quality information for raw material A. Peer 3 verifies the recording request, records the quality test data in external DB 33, and records the quality test data number, hash value of the quality test data, and quality information in blockchain 32a. The quality test data information includes the HLA type obtained by testing the cells of raw material A. There are seven main types of HLA antigens: HLA-A, HLA-B, HLA-C, HLA-D, HLA-DR, HLA-DQ, and HLA-DP. The HLA type is information necessary for preventing rejection reactions and for medical monitoring of side effects after transplantation.

[0074] The quality test materials include information on the sterility test results for raw material A. As regenerative medicine products are made from biological materials, it is difficult to verify the quality of the final product, and a sterile environment is required throughout the entire manufacturing process, including the materials used. Risks of microbial contamination include contamination by general bacteria (aerobic and anaerobic) and fungi. Sterility tests are used to detect general bacteria and fungi. The Japanese Pharmacopoeia general test sterility test method uses two types of liquid culture media to comprehensively detect general bacteria (aerobic and anaerobic) and fungi. The presence or absence of turbidity in the culture medium is visually determined. The presence or absence of general bacteria and fungi is examined by checking for the occurrence of colonies after long-term culture. Other microbial contamination risks include contamination with endotoxins produced by gram-negative bacilli and mycoplasma that parasitize cells. These contaminations can be detected by endotoxin and mycoplasma tests. The results of sterility tests, endotoxin tests, and mycoplasma-free tests are recorded on blockchain 32a as quality test materials.

[0075] The quality test data also includes information on the results of virus-negative tests for raw material A. Examples of viruses include HBV, HCV, HIV-1, HTLV-1, and B19V. Detection tests include the NAT method. The results of virus-negative tests are recorded in blockchain 32a as quality test data. The quality test data also includes information on the results of karyotype analysis for raw material A. Analysis tests include the G-band staining method. The results of the karyotype analysis are recorded in blockchain 32a as quality testing material. In addition, the quality test data includes information regarding the heterogeneity of the cells contained in raw material A. Generally, raw material A has a high degree of diversity in cell properties, cell phenotype, differentiation potential, cell type, etc., making it difficult to evaluate the quality of cells using a single item such as enzyme activity. Therefore, if the results of multiple tests are reproducible, raw material A is deemed to be stable and has passed the quality test. The reproducibility of test results can be evaluated using statistical values ​​such as the median, standard deviation, 95% confidence interval, and quartile of the test results. Alternatively, the uniformity of cells can be evaluated from the distribution of image features of raw material A extracted using a machine learning device such as an autoencoder or VGG16. Furthermore, the uniformity of cells can be evaluated using heterogeneity evaluation indices such as Shannon entropy and fuzzy entropy of various gene expression data (multidimensional data).

[0076] (4) Transportation The transport company uses terminal device 2 to request the recording of basic transport information and transport time record information from peer 3. The basic transport information includes information such as the transport company's name, the name of the person in charge, receipt confirmation, transport completion confirmation, and transport fee. The transport time record information includes sensor information such as time, temperature, humidity, and vibration (acceleration) recorded during the transport of raw material A from the regenerative medicine provider to the manufacturer. Peer 3 verifies the recording request and records the basic transportation information and transportation time recording information in the blockchain 32a. The basic transportation information and transportation time record information may be configured to be automatically transmitted from the transportation machine to the peer 3 and automatically registered in the blockchain 32a. Alternatively, the basic transportation information and transportation time record information may be recorded in the external DB 33, and the hash values ​​thereof may be recorded in the blockchain 32a.

[0077] (5)Cell processing After the manufacturer processes the cells of raw material A, the manufacturer evaluates the quality of processed product B and uses terminal device 2 to request peer 3 for the quality test data number and the record of the quality test data. Peer 3 verifies the recording request, records the quality test material number and the quality test material in the external DB 33, and records the quality test material number and the hash value of the quality test material in the blockchain 32a. As in (3) above, the quality test data includes information such as the sterility test results, endotoxin test results, mycoplasma negation test results, virus negation test results, and karyotype analysis results for processed product B. The quality test data also includes information on the heterogeneity of the cells contained in processed product B.

[0078] (6) Transportation As in (4) above, the peer 3 records the basic transportation information and transportation record information in the blockchain 32a. However, the transportation record information is the information on the transportation of raw material A from the manufacturer to the inspection company. This includes sensor information such as time, cost, temperature, humidity, and vibration (acceleration) recorded during the process.

[0079] (7) Quality inspection The inspection company performs a quality inspection of processed product B, and uses terminal device 2 to request peer 3 to record the quality test document number, quality test document, and quality information of processed product B. Peer 3 verifies the recording request, records the quality test document in external DB 33, and records the quality test document number, hash value of the quality test document, and quality information in blockchain 32a.

[0080] (8) Transportation As in (4) above, the peer 3 records the basic transportation information and transportation record information in the blockchain 32a. However, the transportation record information includes sensor information such as the time, cost, temperature, humidity, and vibration (acceleration) recorded during the transportation of the processed product B from the inspection company to the regenerative medicine provider institution. (9) Before transplantation The regenerative medicine provider uses the terminal device 2 to request the peer 3 to record the patient's treatment history and progress information. The peer 3 verifies the recording request and records the patient's treatment history and progress information in the blockchain 32a. Note that the system may be configured to record the patient's treatment history and progress information in an external DB 33, and record the hash value of the information in the blockchain 32a.

[0081] (10) Before and after transplantation As in (2) above, the regenerative medicine provider uses terminal device 2 to request peer 3 to record the recipient's patient clinical information and patient consent information. The patient consent information includes an encrypted consent document regarding the treatment and secondary use using the regenerative medicine product. The encrypted consent document contains the consent date and consent details encrypted with the recipient's private key. However, the recipient's consent status is public information. The consent details can be confirmed using the recipient's public key. Peer 3 verifies the recording request and records the recipient's patient clinical information and patient consent information in blockchain 32a.

[0082] Patient clinical information includes the recipient's HLA type, tissue compatibility test results, and the doctor's judgment. Examples of tissue compatibility tests include HLA compatibility tests such as anti-HLA antibody screening and antibody specificity identification tests. The results of anti-HLA antibody screening include, for example, the presence or absence of antibodies, specifically, class I (HLA-A, B, C) positive or negative, class II (HLA-DR, DQ) positive or negative, etc. The results of antibody specificity identification tests include type identification results at the allele level, specifically, information expressed as a two-digit serology level (e.g., A24) and a four-digit gene level (e.g., 25:02). Other tissue matching tests include blood typing, cytotoxicity tests (e.g., CDC), and crossmatch tests (e.g., FCXM). In addition, peer 3 may be configured to verify the degree of match between the HLA type of processed product B and the HLA type of the recipient, and refuse to record the information if there is a discrepancy between the degree of match and the recipient's patient clinical information.

[0083] (11) After transplantation The regenerative medicine provider uses the terminal device 2 to request the peer 3 to record follow-up information on the recipient after transplantation. The follow-up information includes information such as the effectiveness of the treatment, an evaluation of the processed product B, and the presence or absence of infections and various complications. The peer 3 verifies the recording request and records the follow-up information in the blockchain 32a. Note that the configuration may also be such that the patient's follow-up information is recorded in an external DB 33, and its hash value is recorded in the blockchain 32a.

[0084] (12) Viewing An organization participating in the information processing system and authorized to make a viewing request can use a terminal device 2 to request a peer 3 to view information about raw material A or processed product B. The peer 3 authenticates the identity of the requester and verifies whether the requester has the authority to make the viewing request, and transmits the information recorded in the blockchain 32a and external DB 33 to the terminal device 2. The peer 3 also records the verification result and the transaction content of the viewing request in the blockchain 32a. The transaction content includes information such as the requester's information and the date and time of the viewing request.

[0085] (13) Check for tampering An organization participating in the information processing system and authorized to request viewing can use a terminal device 2 to request a peer 3 to confirm whether any information has been tampered with. The peer 3 verifies the identity of the person requesting the tampering confirmation, determines whether the hash value obtained from the information to be confirmed matches the hash value recorded in the blockchain 32a, and can confirm whether any improvements have been made. The peer 3 transmits the confirmation result indicating whether or not there has been tampering to the terminal device 2 that made the request. If tampering has occurred, the fact of the tampering is notified to the participants in the information processing system. The reason for the information change, the content of the change, etc. can be confirmed, which can lead to preventing the recurrence of tampering.

[0086] (14) Secondary use When a company that wishes to use information related to regenerative medical products applies for secondary use of the information, In this case, consent is obtained from all participants in the information processing system. For example, the terminal device 2 sends a request for secondary use to one peer 3. The peer 3 requests approval from the peers 3 of all organizations in accordance with the processing code 31. If the request for secondary use is approved by all peers 3, the approval result is sent to the terminal device 2. The terminal device 2 sends the approval result to the orderer 5, and the orderer 5 generates a block including a transaction for the secondary use request processing, and the block is recorded in the blockchain 32a by the peer 3. A company whose application for use has been approved can use the terminal device 2 to request information about secondary use from the peer 3. The peer 3 authenticates the company and confirms that the secondary use has been approved, and if there are no problems, extracts information for which the patient has given consent for secondary use from the blockchain 32a and the external DB 33, and transmits the extracted information to the terminal device 2 that made the request.

[0087] According to the information processing system configured in this manner, the quality of the processed product B can be guaranteed by recording information about the manufacturing process of the regenerative medicine product in the blockchain 32a. In addition, the processing code 31 of the blockchain 32a can automate the approval procedures for various transactions.

[0088] Furthermore, the patient's condition after transplant can be monitored and the monitoring results can be recorded in the blockchain 32a. Furthermore, information related to regenerative medicine recorded in the blockchain 32a can be used for secondary purposes. By using the consent information of participating companies and patients recorded in the blockchain 32a, the consent status can be reliably verified and the information can be provided to secondary users.

[0089] (Embodiment 4) In the fourth embodiment, the method of creating and modifying electronic QMS (Quality Management System) documents differs from that in the third embodiment. When handling regenerative medical products, QMS documents must be managed in accordance with the specified rules of the QMS. Specifically, it is required to record the creation, modification, and approval processes of QMS documents. The creation and modification of QMS documents must be approved through a specified approval route consisting of multiple people with approval authority as defined by the rules, and compliance with the approval route is required. The information processing system of the fourth embodiment automates the approval process for QMS documents using processing code 31. The other configurations of the information processing system are the same as those of the information processing system of the second embodiment, so similar parts are designated by the same reference numerals and detailed description will be omitted.

[0090] 12 is a functional block diagram of an information processing system according to embodiment 4. As with embodiment 3, the information processing system according to embodiment 4 includes a plurality of information processing devices 1, and each information processing device 1 functions as a peer 3, a certificate authority 4, and an orderer 5 that constitute a blockchain network. In addition, the information processing system according to embodiment 4 includes an oracle 6 outside the blockchain network.

[0091] Peer 3 of the information processing system executes processing code 31 to execute various transactions, but cannot access information outside the blockchain network. Oracle 6 is a functional block that provides information outside the blockchain network to the execution process of processing code 31. Oracle 6 is a service provided by, for example, the information processing device 1.

[0092] The storage unit 12 of the information processing device 1 stores approval route information created for each type of QMS document and a QMS member list. The approval route information includes one or more peers 3 that require approval, the approval order, and information such as the department or position that has approval authority at each peer 3. The QMS member list includes information such as the department, position, and name of the person in charge at each peer 3.

[0093] When a participant requests a peer 3 to create and record a QMS document via a terminal device 2, the peer 3 authenticates the participant and executes a process to obtain approvals required for the creation and recording of the QMS document according to the processing code 31. Specifically, the peer 3 identifies the type of QMS document and obtains approval route information and a QMS member list corresponding to the type of QMS document via the oracle 6. The peer 3 then requests approval for the creation and recording of the QMS document from a specific peer 3 based on the approval route information. If approval is obtained, the peer 3 obtains approval from the next organization according to the approval route information. The peer 3 can determine whether the approval was given by a person with appropriate approval authority by referring to the QMS member list. The peer 3 rejects approvals from persons without approval authority. It may also reject requests to send QMS documents from persons without approval authority. If approvals are obtained from all peers 3 in the organizations indicated in the approval route information, the peer 3 records the QMS document in the state DB 32b and records the transaction details indicating the creation of the QMS document and the hash value of the QMS document in the blockchain 32a.

[0094] Similarly, when amending a QMS document, approval processing is performed, and if approval is obtained from Peer 3 of all organizations indicated by the approval route information, the QMS document is recorded in the state DB 32b, and the transaction content indicating the creation of the QMS document and the hash value of the QMS document are recorded in the blockchain 32a.

[0095] According to the fourth embodiment, the approval procedures for creating and amending QMS documents can be automatically managed.

[0096] (Embodiment 5) The fifth embodiment differs from the third and fourth embodiments in that the channel function of the information processing system manages the range of information shared by each participant. Since the other configurations of the information processing system are the same as those of the information processing system according to the second embodiment, the same reference numerals are used for the same parts and detailed descriptions are omitted.

[0097] FIG. 13 is an explanatory diagram showing a channel management method according to the fifth embodiment. The information processing system can set the sharing range of information recorded in the ledger 32 by using the channel function of the blockchain network. The rectangular frame indicated by the dashed line conceptually shows a channel. A channel is a virtual network constructed within the blockchain network, and the ledger 32 and processing code 31 can be shared between specific participants in the channel. The participant peers 3 belonging to each channel share a ledger 32 and processing code 31 that differ for each channel. Furthermore, the information processing system sets the sharing range of information recorded in the external DB 33 for each channel, similar to the information sharing for the ledger 32.

[0098] Channel A is comprised of regenerative medical institutions, manufacturers, and testing companies, and the ledger 32 and processing code 31 related to Channel A are shared between the peers 3 of each organization. This ledger 32 records information on QMS documents related to cell processing, and the peers 3 belonging to Channel A share this information. Channel B is participated in by regenerative medicine institutions and manufacturers, and the ledger 32 and processing code 31 related to Channel B are shared among the peers 3 of each organization. Detailed information on donor D is recorded in this ledger 32, and the peers 3 belonging to Channel B share this information. Other peers 3 not belonging to Channel B cannot access the detailed information on donor D. In the example shown in Figure 13, the peer 3 of the testing company cannot access the detailed information on donor D.

[0099] 14 is an explanatory diagram showing specific examples of information shared on each channel according to embodiment 5. The information processing system has, for example, an "overall management ledger" channel, a "donor detailed information" channel, a "recipient detailed information" channel, a "cell processing QMS" channel, a "sensor information" channel, a "consent for secondary use (company)" channel, and a "consent for secondary use (individual)" channel.

[0100] The "Overall Management Ledger" channel shares information related to regenerative medicine provision plans and outsourcing contracts. Participants in this channel include regenerative medicine providers, manufacturers, transport companies, testing companies, donors, and recipients.

[0101] In the "Donor Details" channel, information about Donor D, such as clinical information about Donor D, is shared. Regenerative medicine providers, manufacturers, and Donor D participate in this channel.

[0102] The "Recipient Details" channel shares information about recipients, such as their clinical information. Regenerative medicine providers and recipients participate in this channel.

[0103] The "Cell Processing QMS" channel shares QMS documents related to cell processing. Regenerative medicine providers, manufacturers, and testing companies participate in this channel.

[0104] The "Sensor Information" channel shares sensor information recorded during transportation, such as time, temperature, humidity, and vibration (acceleration). Regenerative medicine providers, transport companies, manufacturers, and testing companies participate in this channel.

[0105] The "Consent for Secondary Use (Companies)" channel shares information regarding consent by participating companies for the secondary use of information related to regenerative medicine. This channel is attended by regenerative medicine providers, transport companies, manufacturers, and testing companies.

[0106] The "Consent for Secondary Use (Individual)" channel shares information regarding consent by Donor D and recipient for the secondary use of information related to regenerative medicine. This channel is attended by regenerative medicine providers, Donor D, and recipients.

[0107] According to the fifth embodiment, the extent of information sharing among the participants can be managed, and the information that each participant can access can be restricted depending on the content.

[0108] (Embodiment 6) The sixth embodiment differs from the above embodiments in that quality certification information can be stored and issued when the authenticity of the processed product B and predetermined quality conditions are satisfied. Since the other configurations are the same as those of the information processing system according to the above embodiments, the same reference numerals are used for the same parts and detailed description will be omitted.

[0109] 15 is a flowchart showing the steps of authenticity and quality authentication processing according to embodiment 6. The processing of steps S631 to S637 is the same as that of steps S31 to S36 in embodiment 1. However, in step S632, the information processing device 1 acquires quality information of the processed product B. The quality information includes the sterility test results, cell uniformity test results, etc., described in embodiment 3.

[0110] After completing the processing of step S636, the information processing device 1 determines whether the quality of processed product B meets the predetermined standard (step S638). If it determines that the predetermined standard is not met (step S638: NO), the information processing device 1 ends the processing. Note that the information processing device 1 may be configured to thereafter refuse to record information about the processed product B. If it determines that the quality of processed product B meets the predetermined standard (step S638: YES), the information processing device 1 records quality certification information indicating that processed product B meets the predetermined standard of quality in the distributed database system (step S639), and ends the processing. If the information processing system constitutes a blockchain network, it is recommended that the quality certification information be recorded in the blockchain 32a.

[0111] 16 is a flowchart showing the processing procedure for information browsing according to embodiment 6. A user of processed product B can request to browse information about raw material A or processed product B, and the information processing device 1 receives the information browsing request (step S651). The browsing request is made by specifying, for example, the ID of raw material A or processed product B.

[0112] The processing unit 11 of the information processing device 1 that has received the viewing request authenticates the applicant and verifies the viewing request, and if there are no problems, reads out information about raw material A or processed product B from the distributed database network based on the ID (step S652). The processing unit 11 of the information processing device 1 also reads out the verification result of the authenticity of the raw material A or processed product B, or the quality certification information (step S653). The processing unit 11 then transmits the read raw material A or processed product B, and the verification result of the authenticity or the quality certification information, to the source of the viewing request (step S654), and ends the processing. The verification result or the quality certification information transmitted to the source of the viewing request may be digitally signed with the private key of the information processing device 1.

[0113] According to the sixth embodiment, the user can easily confirm that the processed product B has a predetermined standard of quality based on the quality certification information. In addition, the user can confirm the authenticity of the information related to the raw material A and the processed product B based on the verification results related to the authenticity of the raw material A and the processed product B.

[0114] (Embodiment 7) The information processing system and information processing method according to the seventh embodiment record and compare donor-derived clinical information in a distributed database system. By comparing the clinical information, the authenticity of donor-derived regenerative medical products (including processed products for autologous transplantation) can be confirmed. The other configurations of the information processing system are the same as those of the information processing systems according to the first to sixth embodiments, and therefore, the same reference numerals are used for the same parts and detailed description will be omitted.

[0115] The information processing system according to the seventh embodiment includes a plurality of information processing devices 1, similar to the second embodiment, and each information processing device 1 functions as a peer 3, a certificate authority 4, and an orderer 5 that constitute a blockchain network. Note that, similar to the third embodiment, the peer 3 according to the seventh embodiment may also be configured to include an external DB 33 in addition to the ledger 32.

[0116] In the seventh embodiment, a process for comparing and verifying donor-derived clinical information will be described. Donor-derived clinical information includes, for example, a portion of the genome base sequence, HLA type, KIR type, multiple SNPs, medical history, etc. Donor-derived clinical information is recorded in a distributed database system each time a sample is collected and processed for allogeneic or autologous transplantation. The raw data of donor-derived clinical information is not recorded in the blockchain 32a of the distributed database system, but is instead processed into information with low personal identifiability, such as a challenge string, hash value, clinical information comparison results, and various other computational processing results performed using the clinical information, as described below, and then recorded. The purpose of recording donor-derived clinical information is to detect tampering in subsequent processes.

[0117] More specifically, in the seventh embodiment, a process for comparing and verifying first clinical information derived from a donor with second clinical information derived from the donor will be described. The first clinical information is information handled by a first peer 3, and the second clinical information is information handled by a second peer 3. For example, the second clinical information is donor-specific information regarding raw materials containing human cells collected from the donor, and the first clinical information is donor-specific information regarding a processed product manufactured from the raw materials. The second clinical information is stored in the authentication authority 4 of the peer 3 associated with the collecting medical institution or in an external DB 33. In the following description, the donor-specific information, which is the first and second clinical information, will be described as nucleotide sequence information.

[0118] Fig. 17 is an explanatory diagram showing a comparison processing method according to the seventh embodiment, and Fig. 18 is a flowchart showing the comparison processing procedure according to the seventh embodiment. The first peer 3 transmits its own public key to the second peer 3 (step S731). The second peer 3 receives the public key transmitted from the first peer 3 (step S732).

[0119] The second peer 3 generates an arbitrary challenge string (step S733). The second peer 3 combines the second clinical information stored in the peer 3 with the challenge string generated in step S733, and inputs the combined information into a predetermined hash function to calculate a response string B (step S734). The response string is a hash value.

[0120] Next, the second peer 3 encrypts the challenge string generated in step S733 using the public key received in step S732 (step S735), and transmits the encrypted challenge string to the first peer 3 (step S736).

[0121] The first peer 3 receives the challenge string sent by the second peer 3 (step S The first peer 3 then decrypts the received challenge string using the private key that is paired with its own public key (step S738). The first peer 3 then calculates a response string A by inputting the information obtained by combining the first clinical information stored in the first peer 3 and the challenge string decrypted in step S738 into a predetermined hash function (step S739). The hash function is the same as the hash function used by the second peer 3 to calculate the response string B. The first peer 3 then transmits the calculated response string A to the second peer 3 (step S740).

[0122] The second peer 3 receives the response string A sent from the first peer 3 (step S741). The second peer 3 then compares the received response string A with the response string B calculated in step S734 to verify whether the first clinical information and the second clinical information are identical (step S742). The processing in step S742 enables the first clinical information and the second clinical information to be compared in a confidential manner. The second peer 3 records the comparison result in the block chain (BC) 32a (step S743) and ends the processing. It is also possible to configure the system so that if the first clinical information and the second clinical information match, the comparison result is recorded in the blockchain 32a, and if they do not match, the comparison result is not recorded in the blockchain 32a. It is also preferable to configure the system so that the comparison result is notified to the first peer 3. In particular, it is preferable to configure the system so that if the first clinical information and the second clinical information do not match, a warning is notified to the first peer 3.

[0123] According to the information processing system of the seventh embodiment configured as described above, it is possible to compare and verify in a confidential state whether the first clinical information specific to the donor obtained from the donor and the second clinical information specific to the donor derived from the same donor are the same. The hash value (response string) encrypted by the challenge-response authentication method and the challenge string are stored. If you use only the hash value, you can verify the authenticity without storing the raw data. The original data cannot be restored from the range string alone. According to embodiment 7, the present invention is for example contained in a raw material containing human cells collected from a donor. and base sequence information contained in processed products manufactured from raw materials derived from the donor. This allows comparison and verification of whether the data match, thereby confirming the authenticity of regenerative medicine products. Cut.

[0124] In the seventh embodiment, an example was described in which base sequence information was compared to verify whether it matches perfectly, but in the case of a genome base sequence, if the QV (Quality Value) during sequence analysis is, for example, 30 or more, it may be compared to verify whether it matches 100%, and if the QV is 30 or less, it may be substituted with another base, and it may be compared to verify whether the base sequence information after substitution matches. In the case of clinical information being an HLA type, it is desirable to compare to verify whether it matches 100%. Furthermore, in the seventh embodiment, encryption using the challenge-response method has been described, but instead of the challenge-response method, an S / key one-time password method may be adopted.

[0125] (Embodiment 8) The information processing system and information processing method according to the eighth embodiment record and compare donor-derived clinical information and recipient-derived clinical information in a distributed database system. By comparing the clinical information, the compatibility between the donor and the recipient can be confirmed. Since the other configurations of the information processing system are the same as those of the information processing systems according to the first to seventh embodiments, the same reference numerals are used for the same parts and detailed description will be omitted.

[0126] The information processing system according to the eighth embodiment includes a plurality of information processing devices 1, similar to the second embodiment, and each information processing device 1 functions as a peer 3, a certificate authority 4, and an orderer 5 that constitute a blockchain network. Note that, similar to the third embodiment, the peer 3 according to the eighth embodiment may also be configured to include an external DB 33 in addition to the ledger 32.

[0127] In the eighth embodiment, a process for comparing and verifying first clinical information derived from a recipient and second clinical information derived from a donor will be described. The content, recording timing, and recording purpose of the first and second clinical information are the same as those in the seventh embodiment. Also, as in the seventh embodiment, the first and second clinical information, which has high personal identifiability and can identify the donor or recipient, is not recorded in the blockchain 32a of the distributed database system. In the following description, the first and second clinical information will be described as HLA types. The first clinical information is information handled by the first peer 3, and the second clinical information is information handled by the second peer 3. For example, the first clinical information is information such as the recipient's HLA type, and the second clinical information is information such as the donor's HLA type. The second clinical information is stored in the authentication authority 4 of the peer 3 associated with the collecting medical institution or in an external DB 33.

[0128] FIG. 19 is an explanatory diagram showing a comparison processing method according to the eighth embodiment, and FIG. 20 is a flowchart showing the comparison processing procedure according to the eighth embodiment. The first peer 3 encrypts the first clinical information of the recipient using its own public key (step S831) and transmits the encrypted first clinical information and the public key of the first peer 3 to the second peer 3 (step S832). Here, the first peer 3 encrypts the first clinical information using a homomorphic encryption method. Homomorphic encryption allows logical operations to be performed between two ciphertexts without decryption. An example of a homomorphic encryption method is RSA encryption.

[0129] The second peer 3 receives the first clinical information and the public key (step S833). The second peer 3 reads the second clinical information of the donor from the storage unit 12, for example, the external DB 33 (step S834), and encrypts the read second clinical information with the public key received in step S833 (step S835).

[0130] Next, the second peer 3 executes a process of comparing the encrypted first clinical information with the encrypted second clinical information (step S836). For example, the second peer 3 calculates the similarity between the first clinical information and the second clinical information. In step S836, the comparison process of the first clinical information and the second clinical information is executed while maintaining confidentiality. The process of step S836 allows the first clinical information and the second clinical information to be compared confidentially.

[0131] The similarity may be, for example, the minimum edit distance (such as the Levenshtein distance) between the first and second clinical information, which are embedded into vector representations each having the same number of dimensions, the Hamming distance, or the cosine similarity between the first and second clinical information as vectors. When the first and second clinical information are HLA types, since they are categorical variables, whether the first or second clinical information has each HLA type category can be expressed as a one-hot vector with components of 0 or 1 in a vector with components of all categories. For example, if HLA-A types are expressed in four-digit categories, the 13 most frequent types (A*0101, A*0201, A*0206, A*0207, A*0210, A*0301, A*1101, A*2402, A*2601, A*2603, A*3001, A*3101, A*3303) are considered as all categories, and if the first clinical information is A*2402, it is expressed as a vector as (0,0,0,0,0,0,0,1,0,0,0,0,0,).

[0132] Next, the second peer 3 transmits the calculated similarity to the first peer 3 (step S837), with the similarity remaining encrypted.

[0133] The first peer 3 receives the similarity transmitted from the second peer 3 (step S838) and decrypts the received similarity using the private key of the first peer 3 (step S839).Then, the first peer 3 records the decrypted comparison result, that is, the similarity, in the block chain 32a (step S840), and ends the process. It is also possible to configure the system so that if the similarity between the first clinical information and the second clinical information is equal to or greater than a predetermined value, the comparison result is recorded in the blockchain 32a, and if the similarity is less than the predetermined value, the comparison result is not recorded in the blockchain 32a. It is also possible to configure the system so that the similarity is notified to the first peer 3. In particular, it is possible to configure the system so that if the similarity between the first clinical information and the second clinical information is less than the predetermined value, a warning is notified to the first peer 3.

[0134] The information processing system according to the eighth embodiment configured as described above can compare and verify the first clinical information derived from the recipient and the second clinical information derived from the donor in a confidential manner. For example, the similarity between the HLA type of the donor and the HLA type of the recipient can be compared and verified in a confidential manner, thereby confirming the compatibility between the donor and the recipient.

[0135] The process for calculating the similarity of clinical information described in embodiment 8 may be applied to embodiment 7 to calculate the similarity between the first clinical information derived from the donor and the second clinical information derived from the donor. When the first and second clinical information are base sequence information, the similarity may be calculated as the DNA minimum edit distance, more specifically, the Levenshtein distance, or the quotient obtained by dividing the Levenshtein distance by the length of the target base sequence. Of course, the similarity may also be calculated as the Hamming distance or cosine similarity between the first and second clinical information derived from the donor.

[0136] Furthermore, in the eighth embodiment, an example has been described in which the first clinical information of a donor is compared with the second clinical information of one recipient, but the first clinical information of a donor may be compared with the second clinical information of a plurality of different recipients, a similarity regarding the compatibility between the donor and each recipient may be calculated, and the similarity may be notified to the first peer 3. Similarly, the first clinical information of a plurality of different donors may be compared with the second clinical information of the recipient, a similarity regarding the compatibility between each donor and each recipient may be calculated, and the similarity may be notified.

[0137] Furthermore, in the eighth embodiment, an example has been described in which the similarity of HLA types is calculated, but the HLA type of the donor may be compared with the donor specific antibody (DSA) of the recipient.

[0138] (Embodiment 9) The information processing system and information processing method according to the ninth embodiment record and compare clinical information from multiple different recipients in a distributed database system. By comparing the clinical information, similar cases of recipients can be identified. Since the other configurations of the information processing system are the same as those of the information processing systems according to the first to eighth embodiments, the same reference numerals are used for the same parts and detailed description will be omitted.

[0139] The information processing system according to the ninth embodiment includes a plurality of information processing devices 1, similar to the second embodiment, and each information processing device 1 functions as a peer 3, a certificate authority 4, and an orderer 5 that constitute a blockchain network. Note that, similar to the third embodiment, the peer 3 according to the eighth embodiment may also be configured to include an external DB 33 in addition to the ledger 32.

[0140] In the ninth embodiment, a process for comparing and verifying clinical information from multiple different recipients will be described. Clinical information from a recipient includes, for example, information such as age, gender, medical history, prognosis, HLA type, and SNPs. Medical history is chronological information such as disease name, International Classification of Diseases (ICD), outpatient visit date, hospitalization date, and outcome. Medical history can be used to detect adverse events (diseases that develop after medication). After transplantation of a regenerative medicine product, the recipient's clinical information is continuously recorded for several years through patient monitoring. Similar to the seventh and eighth embodiments, clinical information with a high degree of personal identification that could identify the recipient is not recorded in the blockchain 32a of the distributed database system. The purpose of recording the recipient's clinical information is to prevent tampering with adverse event records and delays in information sharing.

[0141] 21 is an explanatory diagram showing an overview of the recording and comparison process of recipient clinical information according to the ninth embodiment. Clinical information of multiple recipients obtained at a medical institution is recorded and accumulated in a recipient DB (e.g., external DB 33) and a database of the authentication authority 4 (hereinafter referred to as the authentication authority DB) or the state DB 32b. The recipient clinical information includes, for example, basic information such as the date of regenerative medicine treatment and the date of medical treatment, medical history, outcome, degree of recovery (e.g., daily living function assessment, ADL score, prognosis), and treatment details (medication, treatment method). This clinical information is recorded in the recipient DB. Past clinical information of recipients is also accumulated and consolidated in the authentication DB, and is further linked to the adverse event DB.

[0142] When administering medicines to a recipient or providing transplants of regenerative medical products, it is possible to check for similar cases by comparing and verifying the clinical information of the recipient with the clinical information of recipients stored in the recipient database and the certification authority database. Cut. An example of comparing first clinical information derived from one recipient with second clinical information derived from another recipient will be described below.

[0143] 22 is an explanatory diagram showing a comparison processing method using a recipient database according to embodiment 9. The procedure for comparing the first clinical information and the second clinical information derived from the recipient is the same as that of embodiment 8. The first peer 3 encrypts the first clinical information of the recipient using its own public key, and transmits the encrypted first clinical information and the public key of the first peer 3 to the second peer 3. The second peer 3 receives the first clinical information and the public key, reads the second clinical information of one or more other recipients from the storage unit 12, for example, from the certificate authority DB, and encrypts the read second clinical information with the public key. The second peer 3 then performs a process to compare the encrypted first clinical information with one or more encrypted second clinical information and transmits the calculated similarity to the first peer 3. The similarity remains encrypted. This process allows clinical information from different recipients to be compared in a confidential manner. The first peer 3 receives the similarity from the second peer 3, decrypts it using the private key of the first peer 3, and records the decrypted comparison result, i.e., the similarity, in the blockchain 32a. It should be noted that the system may be configured to output a warning if the prognosis (for example, five-year survival rate) of a recipient with a high degree of match of the HLA type that is considered similar is equal to or lower than a threshold value. The first clinical information is recorded in an authentication DB or the like at a later date.

[0144] Another example of the comparison process between the first and second clinical information is described below. Assume that the first peer 3 has the first clinical information of one recipient, and the second peer 3 has the second clinical information of another recipient. Fig. 23 is an explanatory diagram showing another comparison processing method using the certificate authority database according to the ninth embodiment, and Fig. 24 is a flowchart showing the comparison processing procedure using the certificate authority database according to the ninth embodiment. The second peer 3 transmits its own public key (hereinafter referred to as the second public key) to the first peer 3 (step S931).

[0145] The first peer 3 receives the second public key transmitted from the second peer 3 (step S932). The first peer 3 encrypts the first clinical information with the second public key (step S933). The first peer 3 then transmits the encrypted first clinical information to the second peer 3 (step S934). The first peer 3 also transmits its own public key (hereinafter referred to as the first public key) to the second peer 3 (step S936).

[0146] The second peer 3 receives the first clinical information transmitted from the first peer 3 (step S935). The second peer 3 also receives the first public key transmitted from the first peer 3 (step S936). The second peer 3 decrypts the first clinical information with the second private key that is paired with the second public key (step S938). The second peer 3 then executes a process of comparing the first clinical information with the second clinical information recorded on the second peer 3 (step S939). For example, the second peer 3 compares the first clinical information with the second clinical information to determine whether they are similar.

[0147] Specifically, the second peer 3 calculates the similarity between the first clinical information and the second clinical information, which may be, for example, the minimum edit distance (such as the Levenshtein distance) between the first and second clinical information, the Hamming distance, or the cosine similarity between the first and second clinical information as vectors.

[0148] The second peer 3 encrypts the comparison result of step S939 with the first public key (step S940), and transmits the encrypted comparison result to the first peer 3 (step S941).

[0149] The first peer 3 receives the comparison result sent from the second peer 3 (step S942). The first peer 3 decrypts the received comparison result with the first private key that is paired with the first public key (step S943) and records the decrypted comparison result in the block chain 32a.

[0150] The information processing system according to the ninth embodiment configured as described above can compare and verify the first clinical information derived from one recipient with the second clinical information derived from another recipient in a confidential manner. In the comparison of similar cases, the number of matching clinical information between past recipients and future recipients can be confirmed. It is possible to confirm the existence of other recipients with similar cases to one recipient without disclosing the clinical information of each recipient. Peer 3 may be configured to be able to refer to the prognosis information of similar cases from a distributed database system. [Explanation of symbols]

[0151] 1. Information processing equipment 2. Terminal Device 3 Pier 4. Certificate Authorities 5 Orderer 6. Oracle 11 Processing section 12 Storage section 12a Computer Programs 13 Communications Department 14 Recording media 31 Processing Code 32 Ledger 33 External DB 32a Blockchain 32b State DB A Raw materials B Processed products D. Donor

Claims

1. A distributed database system for storing information on regenerative medical products and their manufacture or use. An information processing method for storing information in a system, comprising: At least one of the clinical information derived from the donor and the clinical information derived from the recipient is stored in the distributed Store it in a database system, Comparing the clinical information recorded in the distributed database system in a confidential manner Information processing methods.

2. The first clinical information derived from the donor and the second clinical information derived from the donor are stored in the distributed database. Store it in a database system, first clinical information from the donor recorded in the distributed database system; and Compare the clinical information of 2 under confidentiality. The information processing method according to claim 1 .

3. The clinical information derived from the donor and the clinical information derived from the recipient are stored in the distributed database. Stored in the base system, The clinical information from the donor recorded in the distributed database system and the recipe Compare the data with clinical information from the patient under confidentiality.

3. The information processing method according to claim 1.

4. Clinical information from different recipients is stored in the distributed database system. 、 clinical information from the first recipient recorded in the distributed database system. and a second, confidential comparison of the clinical information from the recipient. The information processing method according to any one of claims 1 to 3.

5. The clinical information to be compared is encrypted using a public key by homomorphic encryption. comparing the clinical information to be compared in an encrypted state; The comparison result is decrypted with the private key corresponding to the public key. The information processing method according to any one of claims 1 to 4.

6. Clinical information from donors is collected from the donor and the source material containing human cells and the source material. Contains information about the processed products produced from Obtaining base sequence information of the raw material; Based on the obtained base sequence information, the authenticity of the raw materials and the processed products is verified. Generate verification information for The generated verification information is stored in the distributed database system. The information processing method according to any one of claims 1 to 5.

7. The verification information is a hash value calculated based on data including the base sequence information. include The information processing method according to claim 6.

8. The verification information is calculated based on data including the base sequence information and challenge data. Contains the hash value that is generated, The distributed database system comprises: obtaining the base sequence information from the first participant; providing the challenge data to a second participant; The base sequence information obtained from the raw materials or processed products handled by the second participant and the a hash value calculated based on data including the challenge data provided to the user; By determining whether or not the stored verification information matches, the second participant is identified as the participant. Verify the authenticity of the raw materials or processed products The information processing method according to claim 6.

9. The verification information is calculated based on data including the base sequence information and challenge data. Contains the hash value that is generated, The distributed database system comprises: The base sequence information from the first participant and the base sequence information from the raw material or the processed product obtain primer sequence information to obtain information on the providing the acquired primer sequence information and the challenge data to a second participant; The raw material or the processed product handled by the second participant is extracted using the primer sequence information. The obtained base sequence information and the data including the challenge data provided to the second participant and determining whether or not a hash value calculated based on the stored verification information matches the stored hash value. and verifying the authenticity of the raw material or the processed product handled by the second participant. The information processing method according to claim 6.

10. The distributed database system comprises: Obtaining information about the raw materials or the processed products; When the authenticity of the raw materials or the processed products is verified based on the verification information, Remembering acquired information The information processing method according to any one of claims 6 to 9.

11. The information about the raw materials or the processed products is related to the quality of the raw materials and the processed products. Contains information about The distributed database system comprises: If the authenticity and quality of the information on the raw materials or processed products is verified, Remember quality certification information The information processing method according to any one of claims 6 to 10.

12. The distributed database system comprises: Blocking the verification result of the authenticity of the raw material or the processed product based on the verification information Store in the chain The information processing method according to any one of claims 6 to 11.

13. The information regarding the raw materials or the processed products is as follows: Contains information on the sterility test results for the raw materials or processed products The information processing method according to any one of claims 6 to 12.

14. The information regarding the raw materials or the processed products is as follows: Contains information on the heterogeneity of cells contained in the raw materials or processed products The information processing method according to any one of claims 6 to 13.

15. The information regarding the raw materials or the processed products is as follows: Includes electronic documents related to the quality evaluation test results of the processed products. The information processing method according to any one of claims 6 to 14.

16. The information regarding the raw materials or the processed products is as follows: Including electronic documents related to the contract for the processing and inspection of the raw materials The information processing method according to any one of claims 6 to 15.

17. The distributed database system comprises: The hash value of the electronic document is stored in the blockchain.

17. The information processing method according to claim 15 or 16.

18. The information regarding the raw materials or the processed products is as follows: Contains information on tissue matching between the recipient's tissue and the processed product. The information processing method according to any one of claims 6 to 17.

19. The information regarding the raw materials or the processed products is as follows: Includes information regarding the consent of the donor of the raw materials and the recipient of the processed product.

19. The information processing method according to any one of claims 6 to 18.

20. The distributed database system comprises: Each of the plurality of participants can access the information stored in the distributed database system. Manage the scope 20. The information processing method according to any one of claims 6 to 19.

21. When a request for access to information on the raw materials and the processed products is received, and information about the processed product, and the raw material or the processed product based on the verification information. and information regarding the verification result of the authenticity of the information to the source of the request for viewing.

21. The information processing method according to any one of claims 6 to 20.

22. A distributed database system for storing information on regenerative medical products and their manufacture or use. An information processing system for storing data in a system, a plurality of information processing devices constituting the distributed database system; The information processing device includes: At least one of the clinical information derived from the donor and the clinical information derived from the recipient is stored in the distributed Store it in a database system, Comparing the clinical information recorded in the distributed database system in a confidential manner Information processing system.

23. A distributed database system for storing information on regenerative medical products and their manufacture or use. A computer program that causes a computer to execute information processing stored in a system. There was, The computer, At least one of the clinical information derived from the donor and the clinical information derived from the recipient is stored in the distributed Store it in a database system, Comparing the clinical information recorded in the distributed database system in a confidential manner A computer program for executing a process.

Citation Information

Patent Citations

  • Biomaterial sample history logging

    JP2019518974A

  • System and method for tracking samples through a sample tracking chain

    JP2019534525A