Program, information processing device, and information processing method

The system addresses the limitation of uniform data anonymization by separating user data into personal and non-personal components, enabling targeted data provision that balances utilization and privacy.

JP2025162776AActive Publication Date: 2025-10-28JCB CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024066194
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-16
Publication Date
2025-10-28
Estimated Expiration
2044-04-16

AI Technical Summary

Technical Problem

Existing data anonymization technologies uniformly anonymize user data, failing to consider the specific utilization needs of the data recipient, thus limiting effective data utilization while protecting personal information.

Method used

A system that separates user data into personal information (first data) and non-personal information (second data) based on user settings, allowing targeted data provision to service providers and other recipients, with optional encryption and controlled decryption.

Benefits of technology

Enables data utilization that respects personal information protection by providing non-identifying data to recipients, enhancing data value while safeguarding user privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025162776000001_ABST
    Figure 2025162776000001_ABST
Patent Text Reader

Abstract

To realize provision of data that takes into account an intended use at a recipient while protecting user's personal information, when providing user data of a user using a service to a recipient.SOLUTION: A program causes a computer to realize: a reception function for accepting, from a user device of a user of a first service provided by a first service provider, a separation setting for separating user data into first data containing user's personal information and second data not containing the personal information and providing the separated user data to one or more recipients, including the first service provider; an acquisition function for acquiring the user data from the user device in response to user input on the user device when the user uses the first service via the user device; a separation function for separating the user data into the first data and the second data based on the separation setting; and a provision function for providing the second data separated from the user data to each of recipient devices of one or more recipients.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a program, an information processing device, and an information processing method. [Background technology]

[0002] Conventionally, there is known a technology for anonymizing data related to users who use a service (hereinafter referred to as "user data") to protect the users' personal information, and then providing the data to recipients, including businesses that provide the service. Patent Document 1 discloses a linking server that acquires anonymized customer data from multiple business servers that manage customer data, each of which has been anonymized and processed to provide the customer data. This linking server combines the anonymized customer data acquired from the multiple business servers, and provides the combined data to the business servers and / or other external devices. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2021-117679 Summary of the Invention [Problem to be solved by the invention]

[0004] The device described in Patent Document 1 above can protect personal information by anonymizing the user data to be provided, but since the data to be provided is uniformly anonymized, there is room for improvement in the way data is provided from the perspective of data utilization.

[0005] Therefore, the present invention provides user data when a user uses a service, while protecting the user's personal information and providing data that takes into account the utilization at the destination. [Means for solving the problem]

[0006] A program according to one embodiment of the present invention causes a computer to implement the following: a reception function that accepts, from a user device of a user of a first service provided by a first service provider, a separation setting for separating user data about the user into first data including the user's personal information and second data not including the personal information and providing the separated data to one or more destinations including the first service provider; an acquisition function that acquires user data from the user device in accordance with the user's operational input to the user device when the user uses the first service via the user device; a separation function that separates the user data into the first data and the second data based on the separation setting; and a provision function that provides the second data separated from the user data to each of the destination devices of one or more destinations.

[0007] An information processing device according to one embodiment of the present invention includes a reception unit that receives, from a user device of a user of a first service provided by a first service provider, a separation setting for separating user data relating to the user into first data including the user's personal information and second data not including the personal information and providing the separated data to one or more destinations including the first service provider; an acquisition unit that acquires user data from the user device in accordance with the user's operational input to the user device when the user uses the first service via the user device; a separation unit that separates the user data into the first data and the second data based on the separation setting; and a provision unit that provides the second data separated from the user data to each of the one or more destination devices.

[0008] An information processing method according to one embodiment of the present invention comprises a computer receiving a separation setting from a user device of a user of a first service provided by a first service provider, for separating user data relating to the user into first data including the user's personal information and second data not including the personal information and providing the separated data to one or more destinations including the first service provider; when the user uses the first service via the user device, the computer obtains user data from the user device in response to the user's operational input to the user device, separates the user data into the first data and the second data based on the separation setting, and provides the second data separated from the user data to each of the one or more destination devices. [Effects of the Invention]

[0009] According to the present invention, when providing user data to a user using a service, it is possible to provide data that takes into account the utilization at the destination while protecting the user's personal information. [Brief explanation of the drawings]

[0010] [Figure 1] 1 is a diagram illustrating an example of a system configuration of a data intermediation system according to an embodiment of the present invention. [Figure 2] 1 is a diagram for explaining an overview of a data intermediation system according to an embodiment of the present invention; [Figure 3] 1 is a diagram for explaining an overview of a data intermediation system according to an embodiment of the present invention; [Figure 4] FIG. 2 is a diagram illustrating an example of a functional configuration of a server device according to the present embodiment. [Figure 5] FIG. 10 is a diagram illustrating an example of the operation of the data intermediation system according to the present embodiment. [Figure 6] FIG. 2 is a diagram illustrating an example of a hardware configuration of a server device according to the present embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0011] A preferred embodiment of the present invention (hereinafter referred to as "the present embodiment") will be described with reference to the accompanying drawings. In the drawings, components with the same reference numerals have the same or similar configurations.

[0012] In this invention, the terms "unit," "means," "device," or "system" do not simply mean physical means, but also include cases where the functions of the "unit," "means," "device," or "system" are realized by software. Furthermore, the functions of one "unit," "means," "device," or "system" may be realized by a combination of two or more physical means, devices, or software modules, and the functions of two or more "units," "means," "device," or "system" may be realized by a single physical means, device, or software module.

[0013] <1. System configuration> An example of the system configuration of a data intermediation system 1 according to this embodiment will be described with reference to FIG. 1. The data intermediation system 1 is a system that acts as an intermediary between a service provider (also referred to as a "service provider") and a user who uses the service. Through this intermediation, when a user uses a service, the data intermediation system 1 separates data about the user (also referred to as "user data") into data including the user's personal information (also referred to as "first data") and data not including personal information (also referred to as "second data") in accordance with the user's wishes, and provides the data to the service provider. Furthermore, the data intermediation system 1 may, for example, provide the user data to a recipient other than the service provider.

[0014] The personal information included in the first data may be, for example, information that can identify or discern an individual user. Furthermore, the second data may include, for example, information indicating a user's instruction to the first operator device 300a for the first service through an operational input by the user (also referred to as "instruction information"), and anonymous information other than this instruction information. The anonymous information may be, for example, information that cannot identify or discern an individual user. In other words, the anonymous information may be information that does not constitute personal information of the user. Furthermore, the anonymous information may be, for example, information that does not constitute pseudonym information.

[0015] The first data may include, for example, pseudonym information (including pseudonymized information), and / or information regarding the user's transactions and payments (for example, purchase and payment history, authentication history, information regarding characters such as avatars owned by the user, information regarding assets owned by the user such as NFTs, crypto assets, in-game currency, information regarding game media such as items owned by the user, etc.).

[0016] In this embodiment, an example will be described in which a business operator (also referred to as an "intermediary") acting as an intermediary between users and service providers operates and manages the data intermediation system 1. For example, the intermediary manages user data provided by users when using a service and / or provides user interfaces on behalf of the service provider.

[0017] For example, the intermediary accepts user data entered by a user when using a service on behalf of the service provider, separates the accepted user data into first data and second data, and then mediates the data to the service provider. In this way, the intermediary restricts the service provider's acquisition of user data.

[0018] The following patterns (1) to (3) are possible for separating user data. (1) When user data consists of only primary data: Separate the entire user data as primary data. (2) If the user data consists only of secondary data: Separate the entire user data as secondary data. (3) When the user data consists of the first data and the second data: Divide the user data into the first data and the second data.

[0019] The intermediary may, for example, provide the service provider with second data separated from the user data. The intermediary may also encrypt the first data separated from the user data before providing it to the service provider. The intermediary may also provide the service provider with information for decrypting the encrypted first data (also referred to as "decryption information") when certain conditions (also referred to as "decryption conditions"), such as a predetermined period of time, are met. The intermediary may also stop providing the service provider with the decryption information when the decryption conditions are no longer met. The decryption conditions may include, for example, that each service provider has consent information indicating consent from the user to the provision and use of personal information, and / or has acquired ISMS certification (ISO 27001) or P-mark certification.

[0020] 1, the data intermediation system 1 includes, for example, a server device 100, a user device 200 of a user, and a service provider device 300 of a service provider. The server device 100, the user device 200, and the service provider device 300 are connected to each other via a network N so as to be able to communicate with each other.

[0021] [Server device] The server device 100 is an information processing device capable of communicating with the user device 200 and the provider device 300. The server device 100 executes a predetermined program (also referred to as a "server program") to acquire user data from the user device 200, separate the acquired user data according to the user's settings, and provide the separated data to the provider device 300. In this embodiment, the server device 100 is operated and managed by an intermediary, but this is not intended to be limiting.

[0022] [User device] The user device 200 is an information processing device used by a user, such as a terminal device such as a smartphone or laptop. By executing a predetermined program (also referred to as a "user program"), the user device 200 transmits user data and the like to the server device 100, displays various screens of the data intermediation system 1 to the user, and accepts operational input from the user on the displayed screen. The user program may be, for example, an application program dedicated to the data intermediation system 1 installed on the user device 200, or a web browser that is standard on the terminal device.

[0023] [Business equipment] The provider device 300 is an information processing device used by a service provider. The service provider provides various services to users. The provider device 300 may be, for example, one of the devices constituting a system (also referred to as a "service system") through which the service provider provides services to users. Note that the provider device of a first service provider that provides a first service is referred to as a "first provider device 300a," and the provider device of a second service provider that provides a second service different from the first service is referred to as a "second provider device 300b." The first service provider and the second service provider are one aspect of the service recipient. Furthermore, the provider device 300 is one aspect of the service recipient device.

[0024] User data may include, for example, personal information of the user, including user identification information for identifying the user, payment method information or payment account information of the payment method used by the user, and service information or service account information of the service used by the user.

[0025] Personal information may be, for example, user identification information (ID), personal or corporate attribute information (name, trade name, corporate name, location or address, contact information (telephone number or email address), gender, date of birth, and / or occupation, etc.).

[0026] Payment method information is information related to a payment method. Payment method information includes, for example, type information indicating the type of payment method (e.g., credit card payment, debit card payment, electronic money payment, etc.), payment method identification information for identifying the payment method (e.g., ID, card number, account number, etc.), payment service provider information related to the payment service provider that provides the payment method, user identification information for the payment method, security information for security of the payment method, etc. Payment method information may also include, for example, at least a portion of the payment account information for the corresponding payment method.

[0027] Payment account information is information about a user's account for using a payment method (hereinafter also referred to as "payment account"). Payment account information may include, for example, payment account identification information (e.g., ID or card number, etc.) for identifying the user's payment account and payment method information for the corresponding payment method. Payment account information may also include, for example, authentication information (e.g., payment account password, etc.) for user authentication of the payment account.

[0028] The user data may include, for example, information for verification processes such as registration, authentication, and authorization with the service provider (also referred to as "verification information"). Some or all of the verification information may be classified as personal information.

[0029] The user data may include, for example, instruction information for the provider device 300 based on an operation input by the user to the user device 200 when the user uses the service.

[0030] The instruction information may be, for example, various operation / input information (e.g., processing commands) by a user to the service system. Furthermore, the instruction information may be, for example, a request to a website (also referred to as a "first service site") of a first service provided by the first business operator device 300a. Specifically, the instruction information may be input information input by a user to the user device 200 by keyboard input, voice input, mouse processing, controller processing, or the like when the user uses the first service.

[0031] The user data may include, for example, usage history information indicating the usage history (in other words, usage history) of each of the multiple services for each user. Specifically, the usage history information may be browsing history information of the sites of each of the multiple services, operation history information (including instruction information) for the user device 200 when accessing the site, and / or login history information of the site. Such history information may be information included in a cookie of the user device 200. The user data may include, for example, location information of the user (specifically, location information of the user device 200).

[0032] The user data may include, for example, authentication information (one aspect of confirmation information) for authenticating the user. The authentication information is information that is an element of a predetermined authentication method and is information for authenticating the user in the predetermined authentication method. The authentication information may include, for example, possession information, biometric information, and memory information.

[0033] Possession information may be, for example, card information relating to an IC card or magnetic card possessed by the user, information that can be read from a terminal or card with an NFC tag, information that can be read from a personal identification number card (My Number Card), driver's license, passport, resident registration card (with the user's photograph), etc., and / or device information (specifically, device identification information, etc.) relating to a device possessed by the user (e.g., user device 200).

[0034] The biometric information may be information about the user's body, such as the user's appearance, fingerprints, palm print, voice print, veins and / or irises.

[0035] The stored information may be, for example, user identification information, a number related to a payment method (e.g., a card number or account number, etc.), a telephone number, an account name such as an email address, a password (including a PIN code), a sign or figure entered or selected by the user, a free-entry or multiple-choice answer to a specified question, or any other information stored by the user that can be obtained by the server device 100.

[0036] The user data may include, for example, device information about the user's user device 200. As another example, for each user, the user data and device information for each of the user's one or more user devices 200 may be associated with each other and registered in the storage unit 130. The device information may be classified as, for example, personal information or anonymous information.

[0037] The device information may include, for example, device identification information for identifying each device (e.g., an ID assigned to each device, device-specific identification information, or other information set for each device), device type (e.g., classification as a PC, smartphone, tablet, EV, drone, or service-specific communicator), product name, MAC address, IP address, serial number, and / or other device-specific information.

[0038] The device information may include, for example, information about the OS, information recorded in the memory of each device (e.g., ID token information for each of one or more apps installed on each device), and the location positioning method (e.g., GPS, UWB, BLE, or NFC classification, etc.) corresponding to the location information provided by each device to the data intermediation system 1 (server device 100).

[0039] The device information may include, for example, peripheral device configuration information indicating how a user configures peripheral devices such as keyboards, cookies stored on each device, and / or other data that can be used for tracking.

[0040] [network] The network N is configured by a wireless network or a wired network. Examples of the network N include a mobile phone network, a PHS (Personal Handy-phone System) network, a wireless LAN (including a local area network, communication conforming to IEEE802.11 (so-called WI / Fi (registered trademark))), 3G (3rd Generation), LTE (Long Term Evolution), 4G (4th Generation), 5G (5th Generation), WiMax (registered trademark), infrared communication, visible light communication, Bluetooth (registered trademark), a wired LAN, a telephone line, a power line communication, a power line network, a network conforming to IEEE1394, etc.

[0041] <2. Overview> An example of the data intermediation system 1 will be described with reference to FIGS.

[0042] <2-2. Data brokerage> 2 is a diagram showing an example of user data mediation by the data intermediation system 1. In this example, an example is described in which the first service provided by the first service provider is a Web service, but the first service is not limited to a Web service. The first service may be any service that involves the exchange of user data between the user device 200 and the provider device 300 via a network.

[0043] 2, for example, the server device 100 may relay communication between the user device 200 and the first business operator device 300a that occurs when a user uses the first service. During this relay, the server device 100 separates the user data based on settings (separation settings, which will be described later) for each user and each service.

[0044] The separation of user data in the data intermediation system 1 may be, for example, separation (separation) according to the following categories. Distinguishing between data containing personal information of users (also called "primary data") and data not containing personal information of users (also called "secondary data") - Separation of the information contained in the first data into personal information and pseudonymous information of users and information related to transactions and payments - Separation of the information contained in the secondary data into instruction information indicating the user's instructions and anonymous information other than instruction information

[0045] The anonymous information may include, for example, location information of the device (including the user device 200) used by the user, character information regarding the type of program the user is running in an area in the virtual space and characters such as avatars that the user can control (for example, coordinate axis information indicating the character's position, information regarding the character's modeling and animation, etc.), history information regarding the processing history of the program run by the user (for example, the processing start time and the time required for each process, etc.), and setting information indicating various settings such as language settings and security settings for each device and each application used by the user.

[0046] The classification of user data in the data intermediation system 1 may be, for example, classification (division) by data item included in the user data. Furthermore, in this classification, for example, one data item may be classified into multiple categories. For example, a data item indicating a request to the first service site may be classified into two categories: instruction information and anonymous information.

[0047] (1) The user device 200 sends a request for displaying the first service site (including a request for user authentication for the first service) to the first business device 300a as a request for displaying the first service site in order to log in to the first service site provided by the business and display the top page. The server device 100 receives the display request in order to separate the user data included in the display request and pass it to the first business device 300a. The display request includes, for example, information about a cookie (first party cookie) of the first service site. The cookie information may include, for example, website browsing history information, input data to the first service site (e.g., cart contents in an EC cart function), confirmation information (account information) for logging in to the first service site, etc.

[0048] For example, when relaying the display request to the first business apparatus 300a, the server apparatus 100 may separate the information in the cookie as follows. Website browsing history information: Secondary data (anonymous information) Input information to the first service site: Second data (instruction information) Verification information for logging into the first service site: first data (personal information)

[0049] The server device 100 may, for example, perform authentication processing of the user on behalf of the first business device 300a based on the separated confirmation information. If the authentication of the user is successful, the server device 100 may generate authentication result information (for example, an authentication token) indicating the authentication result. This authentication token may indicate that the authenticity of the user has been confirmed by the authentication processing in the server device 100. Furthermore, after the authentication processing, the server device 100 may encrypt the account information and register it in the storage unit 130.

[0050] In the above display request sent from the user device 200, the server device 100 separates some or all of the information in the cookie sent from the user device 200 into first data and second data, and sends only the second data (and authentication result information) to the first business operator device 300a.

[0051] (2) In response to the transmitted display request, the first business operator device 300a transmits display information including an HTML file and images for displaying the top page of the first service site to the user device 200. The server device 100 receives the transmitted display information and transmits it to the user device 200. Note that if there is no need to process the display information, the display information may be transmitted from the first business operator device 300a to the user device 200 without being relayed by the server device 100 in this manner. The user device 200 receives the display information and displays the top screen of the first service site based on the received display information.

[0052] (3) The user device 200 transmits information entered by the user into each input form on the displayed top screen as input information for the first service site to the first business operator device 300a. This input information includes, for example, the user's ID, name, address, a DM send / non-send flag, information on the destination screen, etc. The server device 100 receives this input information in order to separate the user data included in the input information and pass it to the business operator device 300.

[0053] For example, when relaying the input information to the first business operator device 300a, the server device 100 may separate (divide) the input information as follows: The user ID may be separated as second data (anonymous information) depending on the separation setting, information held by the first business operator to which the information is provided, etc. User ID: Primary data (personal information) Name: Primary data (personal information) Address: Primary data (personal information) DM sending flag: Second data (instruction information) - Screen information of the destination: Second data (instruction information)

[0054] The server device 100 transmits, instead of the input information of the display request transmitted from the user device 200, input information from which the first data has been separated (deleted) to the first business device 300a.

[0055] <2-3. Data mediation> Figure 3 is a diagram showing an example of the overall functional configuration of the data intermediation system 1. As shown in Figure 3, the functions realized by the data intermediation system 1 may be classified and arranged, for example, as follows: The classified functions cooperate with each other (including information cooperation and / or function cooperation; the same applies below). [Business operator device 300: service operator] Service provision function: Function that realizes the provision of a service (for example, in the case of a web service, the functions provided by the web server (presentation layer) and AP server (application layer)) Data management function: A function for managing data necessary for providing services, such as user data (for example, a function provided by the DB server (database layer) for web services) [Server device 100: Intermediary] Anonymous information processing function: A function that performs various processes on anonymous information separated by the separation function. Separation function: A function of accepting input information from the user device 200, separating the first data and the second data, and separating the second data into instruction information and anonymous information, and providing the separated information to the business device 300. User IF function: A function for receiving input information from the user device 200 and providing output information (including display information) received from the business device 300 to the user device 200 Personal information processing function: A function that performs various processes on personal information collected through the collection function

[0056] In this example, it is assumed that the receiving unit 111 of the server device 100 has received in advance from the user device 200 settings (also referred to as "separation settings") for dividing user data among one or more service providers including the first service provider, and that information indicating the received division settings (also referred to as "separation setting information") has been registered in the storage unit 130. Also, in this example, it is assumed that the user has logged in to the first service site in advance, and that the screen displayed after login to the first service site is displayed.

[0057] The separate setting may be, for example, a setting for providing user data of a user divided into first data and second data from a user device 200 of a user of a first service provided by a first service provider to one or more destinations including the first service provider. The separate setting may also include, for example, a setting for providing the second data divided into instruction information and anonymous information.

[0058] (1) As shown in Fig. 3, the user performs operational input on the screen of the first service site displayed on the user device 200. The user device 200 transmits input information (one aspect of user data) resulting from this operational input to the server device 100. The acquisition unit 112 of the server device 100 acquires this transmitted input information.

[0059] (2) The dividing unit 113 of the server device 100 divides the input information into first data and second data based on the dividing setting information. The dividing unit 113 may further divide the divided second data into instruction information and anonymous information (and other information).

[0060] (3) The data processing execution unit 115 of the server device 100 executes processing (also referred to as "internal processing") on the anonymous information separated from the second data for each destination or for multiple destinations, for example, based on the data processing settings. Furthermore, the registration unit 117 of the server device 100 may register, for example, the anonymous information separated from the second data and / or information indicating the execution result of this internal processing (also referred to as "internal execution result information") in the second storage unit 132. Furthermore, the providing unit 118 of the server device 100 may provide the internal execution result information and / or the separated anonymous information to the second business operator device 300b of the second service operator.

[0061] The internal processing may, for example, extract data items common to the anonymous information of multiple users and calculate statistical values ​​(e.g., average, median, mode, etc.) of the extracted data items. The internal processing may also, for example, extract specific data items that meet predetermined conditions from the anonymous information and analyze the relationship between these data items and other data items (e.g., calculate correlation coefficients between data items). Furthermore, the internal processing may, for example, analyze the transition of these values ​​over time.

[0062] The second business operator device 300b may execute processing (also referred to as "external processing") on the provided internal execution result information and / or anonymous information, and transmit information indicating the execution result of the external processing (also referred to as "external execution result information") to the server device 100 in order to provide the information to the user device 200. The acquisition unit 112 of the server device 100 acquires the transmitted external execution result information, and the provision unit 118 of the server device 100 provides the acquired external execution result information to the user device 200. The internal execution result information and the external execution result information are collectively referred to as "execution result information."

[0063] The external processing may, for example, classify users based on the anonymous information using preset typologies or machine learning techniques (such as clustering). The external processing may also generate and distribute information (also referred to as "advertising information") showing advertisements for products and / or services according to the results of this classification. For example, if the anonymous information indicates that the user is in their 30s and female, and the site browsing history information includes browsing history for sites related to mountain climbing, the second business operator device 300b may classify the user as a "female in her 30s who likes mountain climbing." Based on the results of this classification, the second business operator device 300b may transmit advertising information for mountain climbing-related products and services (especially products and services for women) to the server device 100 to distribute to the user device 200 of the classified user.

[0064] (4) The providing unit 118 of the server device 100 provides, for example, instruction information separated from the second data to the first business operator device 300a. The service providing function of the first business operator device 300a acquires the provided instruction information. The service providing function starts providing the first service to the user in accordance with the instruction information. Specifically, the service providing function generates display information for displaying a screen of the first service site in accordance with the instruction information, and transmits the generated display information to the server device 100. The acquiring unit 112 of the server device 100 acquires the transmitted display information. The providing unit 118 of the server device 100 transmits the acquired display information to the user device 200. The user device 200 receives the transmitted display information and displays the screen of the first service site for the user based on the display information.

[0065] (5) The encryption unit 116 of the server device 100 performs an encryption process on the personal information set aside as the first data. The registration unit 117 of the server device 100 may register this encrypted personal information in the first storage unit 131. Furthermore, the provision unit 118 of the server device 100 may provide this encrypted personal information to the first business operator device 300a of the first service operator.

[0066] With the above configuration, the data intermediation system 1 can separate user data into first data including personal information and second data not including personal information, and provide the separated second data to the recipient without anonymizing it. Therefore, the second data separated from the user's personal information can be provided to the recipient without unduly narrowing the scope of its use. Therefore, the recipient can utilize the provided second data as data that does not identify individuals. Therefore, when providing user data to a user using a service, it is possible to provide data that takes into account the recipient's use while protecting the user's personal information.

[0067] <3. Functional configuration> The functional configuration of the server device 100 according to this embodiment will be described with reference to Fig. 4. As shown in Fig. 4, the server device 100 includes a control unit 110, a communication unit 120, and a storage unit .

[0068] The control unit 110 includes a reception unit 111, an acquisition unit 112, a distribution unit 113, and a provision unit 118. The control unit 110 may also include, for example, a confirmation unit 114, a data processing execution unit 115, an encryption unit 116, and / or a registration unit 117.

[0069] [Reception] The reception unit 111 receives various settings and / or requests from the user device 200 and / or the provider device 300. For example, as one mode of reception, when a user inputs information on a screen of the website of the data intermediation system 1 (also referred to as the "data intermediation site") displayed on the user device 200, the reception unit 111 may receive a message indicating the input information.

[0070] The reception unit 111 receives, from the user device 200 of a user of a first service provided by the first service provider, a serving setting for one or more destinations including the first service provider. The serving setting may be, for example, a setting for providing user data related to the user separately as first data and second data. For example, the user may input the serving setting on a screen of a data intermediation site on the user device 200, and the reception unit 111 may receive and accept information indicating the input serving setting from the user device 200. The reception unit 111 may also register, in the storage unit 130, serving setting information indicating the received serving setting.

[0071] The receiving unit 111 may receive data processing settings for processing (internal processing and / or external processing) to be performed on anonymous information from, for example, the first business operator device 300a of the first service operator, the destination device of one or more destinations, or the operations manager device (not shown) of the operations manager. The operations manager may be, for example, a system administrator or a person in charge of system operation and maintenance of the data intermediation system 1.

[0072] The reception unit 111 may, for example, receive a request from the first provider device 300a of the first service provider to provide user data (encrypted first data and / or second data) to a destination (e.g., a second service provider, etc.) different from the first service provider. Furthermore, the reception unit 111 may, for example, receive from the user device 200 of a user of a first service provided by the first service provider a special setting and / or an encryption setting for providing user data (e.g., second data, etc.) related to the user to one or more service providers including the first service provider.

[0073] The serving setting may be, for example, a setting for how to serve food for each user and for each service. Note that the serving setting may also be a setting that is common to a plurality of service providers.

[0074] The allocation setting may further include, for example, a setting for a destination, specifically, a setting for how to allocate for each destination. The allocation setting may include, for example, a setting for allocation for a second service provider.

[0075] The receiving unit 111 may receive a decryption request to decrypt at least a part of the encrypted first data from, for example, the business operator device 300 of the service operator. When the decryption request is received, the following modes are conceivable: (a) the encryption unit 116 of the server device 100 decrypts the data itself; or (b) the providing unit 118 provides decryption information to the business operator device 300 that made the request so that the business operator device 300 can decrypt the data.

[0076] The receiving unit 111 may receive, for example, a request to provide the second data from the first business operator device 300a of the first service operator to a destination (for example, a second service operator) different from the first service operator.

[0077] [Acquisition Department] The acquisition unit 112 acquires various information and requests (e.g., authentication requests, display requests, processing requests for external processing, etc.) from the user device 200 and / or the provider device 300. For example, when a user inputs various information into the first service site or data intermediation site displayed on the user device 200, the acquisition unit 112 may receive a message indicating the input various information as needed. As another example, the acquisition unit 112 may receive a data file of various information from the user device 200 or the provider device 300 in a cyclic or event-driven manner. As another example, the acquisition unit 112 may instruct an API implemented in an external system (not shown), such as a cloud file system, to reference various information and acquire the various information as a result. Alternatively, the acquisition unit 112 may acquire various information by having the user device 200 use an SDK library or the like corresponding to the data intermediation system 1.

[0078] For example, when a user uses the first service via the user device 200, the acquisition unit 112 may acquire user data of the user (including, for example, user data included in various requests such as authentication requests and display requests) from the user device 200 in response to the user's operational input to the user device 200.

[0079] The acquiring unit 112 may acquire, for example, from the user device 200, permission information indicating permission from the user to decrypt (decrypt) the encrypted user data.

[0080] The acquisition unit 112 may, for example, acquire from the user device 200 consent information indicating the user's consent to the provision of at least one of (a) user data, (b) first data, (c) second data, and (d) anonymous information of the second data to a recipient.

[0081] [Serving section] The dividing unit 113 divides the user data of the user into first data and second data based on the dividing setting received from the user. For example, the dividing unit 113 may classify each data item of the user data as either the first data or the second data, and divide (separate) each of one or more data items of the user data into the first data and the second data based on the result of this classification.

[0082] As one mode of distribution by the distribution unit 113, for example, the following process can be considered. If the user data includes both primary data and secondary data: (a) to (c) below (A) Divide the user data into first data and second data. (a) Delete or conceal data items corresponding to the first data from the user data, leaving only data items corresponding to the second data (c) Delete the data items corresponding to the second data from the user data, leaving only the data items corresponding to the first data; If the user data contains only primary data: Separate (identify) the entire user data as primary data. If the user data contains only secondary data: Separate (identify) the entire user data as secondary data.

[0083] The dividing unit 113 may divide the second data into instruction information and anonymous information based on, for example, a dividing setting.

[0084] The serving unit 113 may store information indicating the history of the serving process in the storage unit 130, for example.

[0085] [Verification section] The verification unit 114 verifies the legitimacy of a user (e.g., the authenticity and / or existence of the user) when the user uses the first service and / or the data intermediation system 1, etc. The verification unit 114 verifies the legitimacy of the user, for example, based on verification information included in the user data. Specifically, the verification of the legitimacy of the user may be the user's identity verification and / or authentication. For example, when the verification unit 114 determines that the legitimacy of the user has been verified on behalf of the first service provider and / or when the special setting or encryption setting is set to provide an authentication token instead of the verification information, the verification unit 114 may generate an authentication token based on the verification information.

[0086] The verification information is information for verifying the legitimacy of a user when using the first service and / or the data intermediation system 1, i.e., verifying that the user is the user himself / herself. The verification information may be, for example, authentication information or may indicate authentication elements (knowledge, possessions, biometrics). Furthermore, the verification information may combine multiple types of authentication elements for multi-factor authentication (for example, a combination of a credit card and a PIN code).

[0087] For example, the verification unit 114 may compare (in other words, match) the information contained in the user data stored in the memory unit 130 with the verification information obtained from the user device 200 to verify the authenticity of the user.

[0088] [Data Processing Execution Unit] The data processing execution unit 115 executes processing on the anonymous information separated from the second data for each destination or for multiple destinations in common, based on the data processing setting.

[0089] [Encryption section] The encryption unit 116 performs encryption processing on the first data. The encryption processing by the encryption unit 116 may encrypt all or part of the first data using an encryption key, for example. The encryption method used for this encryption may be, for example, a common key encryption method, a public key encryption method, or a hybrid method.

[0090] For example, the encryption unit 116 may encrypt, as personal information, the confirmation information of the user to be provided to the business operator device 300. For example, the encryption unit 116 may separate the user identification information (ID) of the user in the first service and other personal information included in the confirmation information, and encrypt only the other personal information.

[0091] The encryption setting may include, for example, whether or not the encrypted first data is to be provided to each recipient. The encryption setting may also include, for example, settings for each recipient, such as an encryption processing method and / or decryption conditions (for example, a period during which decryption is permitted).

[0092] The encryption unit 116 may decrypt the encrypted first data based on the decryption request received by the reception unit 111.

[0093] [Registration Department] The registration unit 117 registers user data and the like in the storage unit 130, etc. The registration unit 117 may register encrypted first data in the first storage unit 131. The registration unit 117 may also register anonymous information in the second storage unit 132. The first storage unit 131 and the second storage unit 132 have physically or logically different storage areas.

[0094] According to the above configuration, the encrypted first data and the anonymous information can be registered in different storage units. Therefore, for example, the level of information security for the first storage unit 131 that registers the encrypted first data may be set relatively high to lower its availability, and the level of information security for the second storage unit 132 may be set relatively low. Furthermore, when comparing registering the encrypted first data and the anonymous information in the same storage unit with registering them in different storage units, the former is considered to be more likely to involve a risk of the first data and the anonymous information being associated (combined) and decrypted, resulting in a higher security risk. Therefore, it is possible to address the risk of the first data and the anonymous information being associated with each other.

[0095] [Provider] The providing unit 118 provides various data to the user device 200 and / or the business operator device 300, etc., based on, among other things, settings, etc. The providing unit 118 may provide various data in any manner. For example, the providing unit 118 may send a data file or a message (e.g., an HTTP request, etc.) including the second data to these devices in an event-driven manner. As another example, the providing unit 118 may provide the second data to the business operator device 300, etc., via an API or SDK library implemented by the providing unit 118 itself.

[0096] The providing unit 118 provides, for example, the second data separated from the user data to each of the one or more destination devices.

[0097] According to the above configuration, the separated second data can be provided to the recipient while protecting the user's personal information, without uniformly anonymizing the user data. Therefore, the user data can be provided to the recipient without unduly narrowing the scope of utilization by separating the second data from the user's personal information. Therefore, when providing user data to a user using a service, it is possible to provide data that takes into account the utilization at the recipient while protecting the user's personal information.

[0098] For example, the providing unit 118 may provide the instruction information separated from the second data to the first operator device 300a.

[0099] Instruction information from the user to the first service site, etc. needs to be delivered to the first business operator device 300a in order to use the first service appropriately in accordance with the user's request, etc. With this configuration, it is possible to protect the user's personal information while delivering necessary information to the first service business operator side, thereby preventing interference with the use of the first service.

[0100] For example, the providing unit 118 may provide the destination device with execution result information indicating the execution result of the processing (internal processing) by the data processing executing unit 115. With this configuration, it is possible to provide only the result of the processing on the anonymous information to the first operator device 300a of the first service operator without providing the anonymous information to the first operator device 300a. This makes it possible to ensure the information security of the user's anonymous information.

[0101] For example, the providing unit 118 may provide the business entity device 300 with decryption information for decrypting encrypted user data based on the decryption request and / or permission information. For example, the providing unit 118 may provide the business entity device 300 with a common key that forms a pair with the decryption information for user data encrypted using a common key cryptosystem. In addition, for example, an expiration date may be set for the decryption information. When the expiration date of the decryption information has expired, the business entity device 300 may no longer be able to perform decryption using this decryption information.

[0102] According to the above configuration, with the user's permission, the encryption can be decrypted and the user data can be used later in the business operator device 300. Therefore, the decrypted user data can be used at the destination by simply providing the decryption information, without the need to provide (transmit) the decrypted user data again to the business operator device 300, thereby ensuring security and improving convenience.

[0103] For example, the providing unit 118 may provide anonymous information separated from the user data to a destination device (e.g., second service provider device 300b) of a destination different from the first service provider (e.g., second service provider) based on a provision request from the first service provider and consent information from the user received by the receiving unit 111. Furthermore, the providing unit 118 may provide the encrypted first data and / or the separated second data based on the provision request and consent information, for example.

[0104] According to the above configuration, the server device 100 can provide anonymized user data to a different destination such as a second service provider in response to a request from the first service provider, so that the destination can obtain and utilize the anonymized user data without the first service provider itself providing the user data to the different destination.

[0105] [Communications Department] The communication unit 120 transmits and receives various data to and from the user device 200, the business device 300, or other devices of external systems via the network N.

[0106] [Storage] The storage unit 130 stores setting information related to users or user data (e.g., setting information, information indicating data processing settings, information indicating encryption settings, etc.). The storage unit 130 may store each piece of data using a database management system (DBMS), or may store each piece of data using a file system. When using a DBMS, a table may be provided for each piece of data, and each piece of data may be managed by associating the tables with each other.

[0107] The storage unit 130 may include, for example, a first storage unit 131 and / or a second storage unit 132. The first storage unit 131 may store encrypted first data. The second storage unit 132 may store, for example, anonymous information and / or execution result information.

[0108] The first storage unit 131 and the second storage unit 132 may be set to different security levels, for example. Specifically, when the security level is set to three levels, "high," "medium," and "low," and the scope of access rights and the level of access rights are set to differ depending on the level, the first storage unit 131 may be set to the security level "high," while the second storage unit 132 may be set to the security level "medium." When the security level is set to "high," for example, data registered in the first storage unit 131 may be accessible only by limited users such as a system administrator, and only read and write operations of CRUD (Create, Read, Update, Delete) may be permitted. On the other hand, when the security level is set to "medium," for example, data registered in the first storage unit 131 may be accessible by specific users, including users other than the system administrator, and all operations of CRUD except for delete may be permitted.

[0109] <4. Example of operation> An example of the operation of the data intermediation system 1 will be described with reference to Figure 5. Figure 5(a) is a flow diagram showing an example of the flow of the allocation setting process in the data intermediation system 1. Figure 5(b) is a flow diagram showing an example of the flow of the user data provision process in the data intermediation system 1. Note that the order of the processes shown below is an example and may be changed as appropriate.

[0110] 5(a), the reception unit 111 of the server device 100 receives, from the user device 200 of the user of the first service, a separation setting for providing user data relating to the user divided into first data and second data to one or more destinations including the first service provider (S10). The registration unit 117 of the server device 100 registers separation setting information indicating the separation setting in the storage unit 130 in association with the user's account information (S11).

[0111] 5(b), when a user uses the first service via the user device 200, the acquisition unit 112 of the server device 100 acquires user data from the user device 200 in response to an operation input by the user to the user device 200 (S20). The division unit 113 of the server device 100 divides the acquired user data into first data and second data based on the division setting (S21). The provision unit 118 of the server device 100 provides the second data divided from the user data to each of the one or more destination devices (S22).

[0112] <5. Hardware Configuration> 6, an example of a hardware configuration in which the above-described server device 100 and / or user device 200 are realized by a computer 800 will be described. Note that the functions of each device can also be realized by dividing them among multiple devices.

[0113] As shown in FIG. 6, the computer 800 includes a processor 801, a memory 803, a storage device 805, an input I / F unit 807, a data I / F unit 809, a communication I / F unit 811, and a display device 813.

[0114] The processor 801 controls various processes in the computer 800 by executing a program (e.g., a server program or a user program) stored in the memory 803. For example, each functional unit provided in the control unit 110 of the server device 100 and / or the control unit of the user device 200 can be realized by the processor 801 executing a program temporarily stored in the memory 803.

[0115] The memory 803 is a storage medium such as a RAM (Random Access Memory), etc. The memory 803 temporarily stores the program code of the program executed by the processor 801 and data required when the program is executed.

[0116] The storage device 805 is a non-volatile storage medium such as a hard disk drive (HDD) or flash memory. The storage device 805 stores an operating system and various programs for implementing the above-mentioned configurations. In addition, the storage device 805 can also store tables for registering various data such as user data and setting information, and a DB for managing the tables. Such programs and data are loaded into the memory 803 as needed and can be referenced by the processor 801.

[0117] The input I / F unit 807 is a device for receiving input from a user. Specific examples of the input I / F unit 807 include a keyboard, a mouse, a touch panel, various sensors, and a wearable device. The input I / F unit 807 may be connected to the computer 800 via an interface such as a USB (Universal Serial Bus).

[0118] The data I / F unit 809 is a device for inputting data from outside the computer 800. A specific example of the data I / F unit 809 is a drive device for reading data stored in various storage media. The data I / F unit 809 may be provided outside the computer 800. In this case, the data I / F unit 809 is connected to the computer 800 via an interface such as a USB.

[0119] The communication I / F unit 811 is a device for performing data communication via a network N, either wired or wirelessly, with an external device of the computer 800. The communication I / F unit 811 may be provided outside the computer 800. In this case, the communication I / F unit 811 is connected to the computer 800 via an interface such as a USB.

[0120] The display device 813 is a device for displaying various types of information. Specific examples of the display device 813 include a liquid crystal display, an organic EL (Electro-Luminescence) display, and a display of a wearable device. The display device 813 may be provided outside the computer 800. In this case, the display device 813 is connected to the computer 800 via, for example, a display cable. Furthermore, when a touch panel is adopted as the input I / F unit 807, the display device 813 can be configured as an integral part of the input I / F unit 807.

[0121] It should be noted that the present embodiment is an example for explaining the present invention, and is not intended to limit the present invention to only this embodiment. Furthermore, the present invention can be modified in various ways without departing from the gist of the present invention. Furthermore, those skilled in the art can adopt embodiments in which the elements described below are replaced with equivalents, and such embodiments are also within the scope of the present invention.

[0122] [Variations] Although the present invention has been described based on the above embodiment, the following cases are also included in the present invention.

[0123] [Variation 1] At least a part of the components of the server device 100 according to the above embodiment may be provided in the user device 200 and / or the provider device 300. For example, all or a part of the functions of the confirmation unit 114 of the server device 100 may be implemented in the provider device 300.

[0124] [Variation 2] In the above embodiment, an example was described in which the memory unit 130 of the server device 100 is provided with a first memory unit for registering encrypted personal information and a second memory unit for registering anonymous information, but at least one of these memory units may be provided by a memory unit of a device of an external system (e.g., a file system, etc.). [Explanation of symbols]

[0125] 1...data intermediation system, 100...server device, 110...control unit, 111...reception unit, 112...acquisition unit, 113...sorting unit, 114...confirmation unit, 115...data processing execution unit, 116...encryption unit, 117...registration unit, 118...provision unit, 120...communication unit, 130...storage unit, 200...user device, 300...operator device, 800...computer, 801...processor, 803...memory, 805...storage device, 807...input I / F unit, 809...data I / F unit, 811...communication I / F unit, 813...display device.

Claims

1. On the computer, a reception function for receiving, from a user device of a user of a first service provided by a first service provider, a separation setting for providing user data relating to the user divided into first data including personal information of the user and second data not including the personal information to one or more destinations including the first service provider; an acquisition function that acquires the user data from the user device in response to an operation input by the user to the user device when the user uses the first service via the user device; a dividing function for dividing the user data into the first data and the second data based on the dividing setting; a provision function of providing the second data separated from the user data to each of the one or more destination devices; program.

2. the second data includes instruction information indicating an instruction from the user to a first carrier device of the first service through the operation input, and anonymous information other than the instruction information; the separate setting includes a setting for providing the second data separately as the instruction information and the anonymous information, the dividing function divides the second data into the instruction information and the anonymous information based on the dividing setting; the providing function provides the instruction information separated from the second data to the first carrier device. The program according to claim 1.

3. the second data includes instruction information indicating an instruction from the user to a first carrier device of the first service through the operation input, and anonymous information other than the instruction information; the separate setting includes a setting for providing the second data separately as the instruction information and the anonymous information, the reception function receives data processing settings for processing to be executed on the anonymous information from a destination device of each of the one or more destinations or an operation manager device of an operation manager; the dividing function divides the second data into the instruction information and the anonymous information based on the dividing setting; further realizing a data processing execution function in the computer that executes processing on the anonymous information separated from the second data for each of the destinations or for multiple destinations in common based on the data processing setting; the providing function provides execution result information indicating an execution result of the processing to the destination device. The program according to claim 1 or 2.

4. the second data includes anonymous information that does not correspond to personal information of the user, The computer, an encryption function for performing encryption processing on the first data; a registration function of registering the encrypted first data in a first storage unit and the anonymous information in a second storage unit, The program according to claim 1 or 2.

5. the second data includes anonymous information that does not correspond to personal information of the user, the reception function receives a request to provide the user data to a destination different from the first service provider from a first service provider device of the first service provider; the acquiring function acquires, from the user device, consent information indicating the user's consent to the provision of the anonymous information to the destination; the providing function provides the anonymous information separated from the user data to the destination device of the destination based on the provision request and the consent information. The program according to claim 2.

6. a receiving unit that receives, from a user device of a user of a first service provided by a first service provider, a separation setting for providing user data relating to the user divided into first data including personal information of the user and second data not including the personal information to one or more destinations including the first service provider; an acquisition unit that acquires the user data from the user device in response to an operation input by the user to the user device when the user uses the first service via the user device; a dividing unit that divides the user data into the first data and the second data based on the dividing setting; a providing unit that provides the second data separated from the user data to each of the one or more destination devices, Information processing device.

7. The computer receiving, from a user device of a user of a first service provided by a first service provider, a separation setting for providing user data relating to the user divided into first data including personal information of the user and second data not including the personal information to one or more destinations including the first service provider; When the user uses the first service via the user device, the user data is acquired from the user device in response to an operation input by the user to the user device; Dividing the user data into the first data and the second data based on the division setting; providing the second data separated from the user data to a destination device of each of the one or more destinations; Information processing methods.

Citation Information

Patent Citations

  • Method and system for implementing privacy notice, consent, and preference with a privacy proxy

    US20060095956A1

  • Data sanitization system for public host platform

    US20190190890A1

  • Coordination server program, business operator server program, and data coordinated system

    JP2021117679A