Questionnaire system, questionnaire management method, and program

The survey system generates encrypted user IDs from survey and monitor IDs to manage respondent information anonymously, addressing the challenge of individual identification and facilitating survey analysis.

JP2025180264APending Publication Date: 2025-12-11RAKUTEN GROUP INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024087460
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-29
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

Existing survey systems face challenges in managing respondent information to prevent individual identification while facilitating analysis, as they often require personal information, leading to lower response rates and hinder honest responses.

Method used

A survey system generates encrypted user IDs based on survey and monitor IDs, allowing for anonymous respondent management and analysis without revealing personal information.

Benefits of technology

The system effectively manages respondent information to prevent individual identification while enabling comprehensive survey analysis, ensuring secure and efficient data utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025180264000001_ABST
    Figure 2025180264000001_ABST
Patent Text Reader

Abstract

To provide a technique for managing information on answerers of each questionnaire in such a way that individual answerers cannot be identified.SOLUTION: A questionnaire system is provided, comprising ID generation means configured to generate an encrypted user ID based on a questionnaire ID representing identification information of a questionnaire performed by the questionnaire system and monitor ID representing identification information of an answerer answering the questionnaire.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a questionnaire system, a questionnaire management method, and a program. [Background technology]

[0002] Systems are available that distribute questionnaires to multiple respondents (monitors) via a network and collect their responses. Such systems may require personal information, such as addresses, but requiring personal information can lower the response rate and make it difficult to obtain honest responses. To address this issue, Patent Document 1 discloses a system that collects questionnaire responses anonymously. However, this system does not provide a means for identifying respondents on the questionnaire server side, and it is not possible to perform so-called analytical processing, such as combining questionnaire responses with information related to the respondent and adding additional information on the questionnaire server side. It is necessary to manage respondent information in a way that makes it easy to analyze survey results, while paying attention to the handling of personal information. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2016-095656 Summary of the Invention [Problem to be solved by the invention]

[0004] One of the objectives is to provide a technology for managing information on survey respondents in a way that prevents individuals from being identified and allows information related to the respondents to be utilized. [Means for solving the problem]

[0005] According to one aspect of the present invention, the survey system is provided with an ID generation means for generating an encrypted user ID based on a survey ID, which is identification information for a survey conducted by the survey system, and a monitor ID, which is identification information for a respondent who answers the survey.

[0006] According to one aspect of the present invention, a survey management method generates an encrypted user ID based on a survey ID, which is identification information for a survey conducted by a survey system using a computer, and a monitor ID, which is identification information for a respondent who answers the survey.

[0007] According to one aspect of the present invention, the program causes a computer to function as a means for generating an encrypted user ID based on a survey ID, which is identification information for a survey conducted by a survey system, and a monitor ID, which is identification information for a respondent who answers the survey. [Effects of the Invention]

[0008] According to the present invention, information on respondents to a questionnaire can be managed in a manner that prevents individuals from being identified, while facilitating the use of the information for the analysis of questionnaire results, etc. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is a diagram illustrating an example of a questionnaire system according to an embodiment. [Figure 2] 10 is a flowchart illustrating an example of an operation of the questionnaire system according to the embodiment. [Figure 3] 10A and 10B are diagrams illustrating an example of a questionnaire result and a questionnaire DB according to the embodiment. [Figure 4] 10 is a second flowchart showing an example of the operation of the questionnaire system according to the embodiment. [Figure 5] FIG. 10 is a diagram illustrating selection of topping data according to an embodiment. [Figure 6] FIG. 10 is a diagram showing an example of a survey result to which topping data according to the embodiment has been added. [Figure 7] 10 is a third flowchart showing an example of the operation of the questionnaire system according to the embodiment. [Figure 8] FIG. 1 is a diagram illustrating an example of a hardware configuration of a questionnaire system according to an embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0010] <Embodiment> (System Configuration) Fig. 1 is a diagram showing an example of a questionnaire system according to an embodiment. As shown in the figure, the questionnaire system 1 includes respondent terminals 10a, 10b, ..., a requesting company terminal 20, a questionnaire management server 30, and a big data DB (DB is an abbreviation for database) 40. The respondent terminals 10a, 10b, etc. and the questionnaire management server 30 are communicatively connected. The requesting company terminal 20 and the questionnaire management server 30 are communicatively connected. The big data DB 40 and the questionnaire management server 30 are communicatively connected.

[0011] The respondent terminals 10a, 10b, etc. are terminal devices such as smartphones and PCs (personal computers) that are used by respondents to a survey (hereinafter, respondents to a survey and candidate respondents may be referred to as monitors) when answering a survey. Respondents to a survey are selected for each survey, and the number of respondents varies for each survey. Therefore, the respondent terminals 10a, 10b, etc. may change for each survey, but for convenience, they will be referred to as respondent terminals 10a, 10b, etc. in this document. Although two respondent terminals 10a, etc. are shown in FIG. 1, three or more respondent terminals 10a, etc. may be present.

[0012] The requesting company terminal 20 is a terminal device such as a smartphone or PC (personal computer) used by a company requesting a survey. For example, a company developing a product targeting a certain demographic of users will specify the target users' age, gender, hobbies, and preferences to create questions that can be used for product development and sales. The requesting company terminal 20 transmits survey implementation request information, including target conditions and question content, to the survey management server 30 to request the implementation of the survey. The requesting company terminal 20 also receives the survey implementation results from the survey management server 30. While one requesting company terminal 20 is shown in FIG. 1, multiple requesting company terminals 20 may be present since various companies request the implementation of surveys.

[0013] The survey management server 30 is a server device operated by a research company that conducts surveys at the request of companies and the like. For example, the research company has users who are willing to answer various surveys as members. The survey management server 30 selects monitors for each survey from among the members and conducts the survey for the selected monitors. For example, members who answer a survey may be awarded points that can be used for online shopping, etc. The survey management server 30 accepts survey requests, conducts and tally surveys, and outputs survey results. The survey management server 30 includes an input accepting unit 31, a control unit 32, and a memory unit 33.

[0014] The input receiving unit 31 receives a request for a survey. Specifically, the input receiving unit 31 receives, from the requesting company terminal 20, survey implementation request information including the conditions of the survey target, question content, survey implementation period, deadline, etc.

[0015] The control unit 32 creates survey information based on the question content included in the implementation request information, extracts monitors based on the target conditions included in the implementation request information, distributes the survey information to the extracted monitors, collects responses to the survey and registers them in the survey DB 332, creates and transmits survey result information to be provided to the company requesting the survey, etc. The control unit 32 includes an ID (identification) management unit 321.

[0016] The ID management unit 321 generates and decrypts encrypted user IDs. Specifically, the ID management unit 321 generates an intermediate code using a monitor ID, which is identification information for the monitor (member), and a survey ID, which is identification information for the survey, in a predetermined manner, and encrypts the intermediate code using a predetermined password in a predetermined encryption method to generate an encrypted user ID. The ID management unit 321 also decrypts the encrypted user ID using the password used for encryption to calculate the intermediate code, and extracts the monitor ID from the intermediate code.

[0017] When providing survey results to a requesting company, it is undesirable to identify monitors from the perspective of protecting personal information. For example, a monitor ID is assigned to each member, but it is not possible to immediately identify an individual from the monitor ID. However, if a monitor ID were provided to a requesting company, a combination of multiple survey results could potentially lead to the identification of a monitor's personal information. On the other hand, for survey analysis purposes, it is desirable for research companies to manage information such as which members responded to which surveys and what responses they gave for each member. Therefore, when providing monitor information to an external party, the control unit 32 generates code information (referred to as an encrypted user ID) that does not identify the monitor using the ID management unit 321, and uses the generated code information to provide the survey results, etc. to the requesting company. Within the survey management server 30, the control unit 32 manages the survey results for each member (monitor) using the monitor ID.

[0018] The memory unit 33 stores various data. For example, the memory unit 33 stores a monitor DB 331 and a survey DB 332. The monitor DB 331 stores attribute information of members. For example, the monitor DB 331 stores demographic information such as age and gender, marketing information such as hobbies, preferences, and tendencies, points earned by members, and member rank, all linked to a monitor ID. The survey DB 332 stores response results for each monitor for each survey. For example, the survey DB 332 stores monitor IDs (or encrypted user IDs) and responses to each question in the survey, all linked to a survey ID. In the configuration example of FIG. 1, the monitor DB 331 and the survey DB 332 are stored in the memory unit 33 of the survey management server 30. However, these DBs may be stored in a storage device external to the survey management server 30 (for example, the big data DB 40).

[0019] The big data DB 40 stores survey results, such as large-scale surveys conducted independently by research companies on members, linked to monitor IDs. For example, the big data DB 40 stores lifestyle consciousness data, which is the result of a survey on attitudes, values, hobbies, and how time and money are spent, as well as category data, which is the result of a survey on purchasing habits of food, beverages, durable consumer goods, and the like. This data is called topping data. Large-scale surveys are not necessarily conducted for all members; some surveys are conducted only for a certain subset of members (e.g., those with a certain number of points or more). Furthermore, some members may not respond to a large-scale survey even if they are selected as targets. Therefore, the response results registered in the big data DB 40 vary from member to member. Since it is desirable to store as much data as possible about members' thoughts, attitudes, and behaviors in the big data DB 40, the survey management server 30 may register survey results conducted at the request of a company in the big data DB 40 with the company's approval. Various attribute information about monitors (members) may be registered in the big data DB 40 rather than in the monitor DB 331. Furthermore, the survey management server 30 can add (topping) the results of a large-scale survey registered in the big data DB 40 to the results of a survey requested by a company and provide them. For example, when a company requesting a survey specifies, by encrypted user ID, a monitor to whom topping data managed by the big data DB 40 is to be added, the ID management unit 321 decrypts the specified encrypted user ID and extracts the monitor ID. Then, the control unit 32 uses the extracted monitor ID to search the big data DB 40, add the topping data desired by the company to the survey results, and provide them to the requesting company. The big data DB 40 may be registered in the storage unit 33 of the survey management server 30.

[0020] (Basic operation) Next, the basic operation of the questionnaire management server 30 will be described with reference to FIG. FIG. 2 is a flowchart showing an example of the operation of the questionnaire system according to the embodiment. First, the input accepting unit 31 accepts a survey request (step S1). For example, the requesting company terminal 20 transmits survey request information including the conditions of the target monitors, question content, deadline, etc., and the input accepting unit 31 receives the survey request information. In addition to accepting a survey request from the requesting company terminal 20, an operator who has received a request from a company may input the survey request information to the survey management server 30. When the input accepting unit 31 acquires the survey request information sent from the requesting company terminal 20 or input directly, acceptance of the survey request is completed. The input accepting unit 31 outputs the survey request information to the control unit 32.

[0021] Next, the control unit 32 creates survey information based on the survey request information (step S2). The survey information includes a survey ID unique to the survey to be registered in the survey DB 332 and question information to be distributed to respondents. The control unit 32 assigns a survey ID to the accepted survey, links it to the survey requester information (e.g., the company ID of the requesting company) and the question content, and registers it in the survey DB 332. Furthermore, based on the questions included in the survey request information, question information linked to the survey ID is generated. The question information may be automatically generated by an application or the like, or may be generated by an operator referencing the survey request information and inputting the question content as text. The question information is, for example, an HTML web page that displays questions in text and has an area where respondents can select answers to the questions from options using radio buttons or check boxes, and an area where they can input answers as text. This web page is configured so that when the respondent enters their answers and presses a send button or the like, the respondent's answers are sent to the survey management server 30. If the survey ID is identified by the process in step S2, the requester of the survey and the question information can be identified.

[0022] Next, the control unit 32 extracts respondents based on the survey request information (step S3). The control unit 32 references the monitor DB 331 to extract monitors who meet the monitor conditions included in the survey request information. For example, the monitor conditions may include demographic information such as age group and region of residence, and marketing information such as hobbies and interests, as desired by the requester (e.g., age: 30s to 50s, region: nationwide, hobbies and interests: likes movies and anime, likes cars, etc.). The control unit 32 references the monitor DB 331 (or the big data DB 40 if the monitor's attribute information is registered therein) and extracts the monitor IDs of members who match these conditions. The monitor conditions may also include loyalty information such as membership rank, the number of past responses, the period and frequency since the most recent response, whether the member uses various services provided by the survey company or affiliated companies, etc. Furthermore, monitors may be designated by the operator of the survey management server 30 or the requesting company, regardless of the above method. Furthermore, monitors may be selected not only by referring to the demographic information, etc., registered in the monitor DB 331, but also by referring to various data on the monitors' thoughts and behaviors, registered in the big data DB 40. For example, the big data DB 40 may store lifestyle awareness data, such as responses to questionnaire items, such as whether the monitor is conscious about personal grooming, whether the monitor is conscious about health, what kind of investments the monitor is likely to make, etc., on a five-point scale. In addition to demographic information and marketing information, the client company may request the selection of survey monitors by specifying, for example, "people who are conscious about personal grooming." Note that the order in which steps S2 and S3 are performed is arbitrary. Step S2 may be performed after step S3, or they may be performed simultaneously.

[0023] Next, the control unit 32 conducts the survey (step S4). The control unit 32 distributes the question information created in step S2 to the monitors extracted in step S3. The monitors check the distributed questions using the respondent terminal 10, input answers, and operate the respondent terminal 10 to transmit the input answers to the survey management server 30. In the survey management server 30, the control unit 32 acquires the answers to the distributed question information. Upon acquiring the answers, the control unit 32 registers the survey response results in the survey DB 332 (step S5). The control unit 32 links the answers of the monitors assigned with the monitor IDs and registers them in the survey DB 332.

[0024] Next, the ID management unit 321 generates an encrypted user ID (step S6). For each of the monitor IDs extracted in step S3, the ID management unit 321 generates an encrypted user ID based on the monitor ID and survey ID. The encrypted user ID is used as the monitor's identification information (substitute for the monitor ID) when providing the survey response results to the requesting company. Because the monitor ID, which is the monitor's identification information, is also code information generated by the system, a requesting company cannot identify the monitor by looking at the monitor ID. However, for example, if a monitor's monitor ID is "001" and the monitor identification information field in the survey results contains "001" every time a survey is requested, it will be assumed that the same respondent is the same person. Furthermore, if the same monitor identification information "001" is included in multiple survey results, it will be possible to accumulate the response results for "001," but there is a need to reduce the possibility of accumulating data for individual monitors. To meet such needs, it is possible to identify respondents simply by a "sequential number" without using a monitor ID to avoid identifying monitors. However, this means that when adding topping data, the survey management server 30 cannot determine which monitor ID's topping data to add. While this problem could be addressed by linking the "sequential number" to the monitor ID, this would increase the amount of data to be managed and make management more complicated. Therefore, the ID management unit 321 generates an encrypted user ID using not only the monitor ID but also the survey ID. This reduces the possibility of individuals being identified or of data related to individuals being accumulated. An example of encrypted user ID generation is shown below.

[0025] <Example of generating an encrypted user ID> (Step 1) Create a string of text information with a hyphen between the survey ID and the monitor ID. If the survey ID is "ABC" and the monitor ID is "001", "ABC-001" will be generated. (Step 2) Using an arbitrary password, the intermediate code obtained in step 1 is encrypted with a specified algorithm. For example, "7sLqyUsPHXuyUu20Ik8R7w==" is generated. The generated "7sLqy~" is the encrypted user ID. The password used for encryption may be the same for all monitor IDs. The password may be stored in the storage unit 33.

[0026] Because the string of the encrypted user ID does not include the string of the monitor ID or the survey ID, it is difficult for the requesting company to identify individual monitor IDs even if the encrypted user ID is included in the survey results provided. For example, even if multiple surveys are conducted at the request of the same company, the encrypted user ID is generated based on the survey ID assigned to each survey and the monitor ID of the monitor who answered that survey, so even if the same monitor was present among the respondents to multiple surveys, it is unlikely that the requesting company would be able to recognize this.

[0027] Furthermore, since the ID management unit 321 knows how to generate an encrypted user ID from the encryption password, survey ID, and monitor ID, it can extract the monitor ID and survey ID from the encrypted user ID by performing the reverse procedure. Specifically, it decrypts the data using the encryption password, splits the resulting text information at the hyphen, and extracts the portion before the hyphen as the survey ID and the portion after the hyphen as the monitor ID. Because the monitor ID can be decrypted, it becomes possible to link the results of large-scale surveys stored in the big data DB 40 using the topping function (a function that adds topping data to survey results), which will be described later. In this way, by introducing encrypted user IDs, respondent information can be managed in a way that facilitates the use of information, such as in survey result analysis, without increasing the amount of management data mentioned in the example of "sequential numbers" above, and without providing information that could lead to the identification of individuals to external parties.

[0028] Next, the control unit 32 outputs the survey results (step S7). The control unit 32 reads out the survey response results associated with the monitor IDs and registered in the survey DB 332, and generates information associating the monitor IDs with encrypted user IDs generated based on the survey IDs. The control unit 32 transmits the generated information (survey results) to the requesting company terminal 20. FIG. 3(a) shows an example of the survey results generated in step S7, and FIG. 3(b) shows an example of the survey DB 332. The values ​​of 7sLqy~, wOpN~, HQSfT~, and 5jvbs~ in the "Respondent" column in FIG. 3(a) are respectively values ​​obtained by encrypting monitor ID=001 and survey ID=ABC, monitor ID=002 and survey ID=ABC, monitor ID=003 and survey ID=ABC, and monitor ID=004 and survey ID=ABC using a predetermined password. As shown in the figure, the survey DB 332 stores survey response results for each monitor ID. In contrast, the survey results provided to the survey requesting company display encrypted user IDs instead of monitor IDs. According to the process shown in FIG. 2, the information of respondents (encrypted user IDs) for each survey is managed in a format that prevents the identification of individual monitors. Because encrypted user IDs make it difficult to identify or estimate individuals, they can be provided to the requesting company. Furthermore, the survey management server 30 can accumulate the results of multiple surveys for each monitor ID and manage the monitor's attribute information. Furthermore, the survey management server 30 can generate encrypted user IDs and extract monitor IDs from encrypted user IDs, so it can manage various information (attribute information, survey results, topping data) in association with the monitor IDs. By generating encrypted user IDs as needed and using them in place of monitor IDs, various information associated with the monitor IDs can be provided to external parties.

[0029] (Operation 1 including topping function) Next, the operation when adding topping data to the questionnaire results will be described with reference to FIGS. 4 is a second flowchart showing an example of the operation of the questionnaire system according to the embodiment. The process up to step S7 is the same as that in FIG. 2, so only a brief description will be given. First, the input receiving unit 31 receives a survey request (step S1). Next, the control unit 32 creates survey information (step S2). Next, the control unit 32 extracts respondents (step S3). Next, the control unit 32 conducts the survey (step S4). Next, the control unit 32 registers the survey response results in the survey DB 332 (step S5). Next, the ID management unit 321 generates an encrypted user ID (step S6). Next, the control unit 32 outputs the survey results to the requesting company terminal 20 (step S7). The survey results include the encrypted user ID and the responses of the monitor corresponding to the encrypted user ID. Next, the requesting company operates the requesting company terminal 20 to request the survey management server 30 to add topping data (step S8). For example, the requesting company operates the requesting company terminal 20 to specify the survey ID or the survey ID and the encrypted user ID of the monitor to whom topping data is to be added, and performs an operation to request the addition of topping data to the survey results. The requesting company terminal 20 transmits the identified survey ID and / or encrypted user ID and topping data addition request information to the survey management server 30. In the survey management server 30, the control unit 32 acquires the survey ID and / or encrypted user ID and outputs a topping data selection screen to the requesting company terminal 20 (step S9). Note that if only the survey ID is identified in step S8, the control unit 32 may perform the following processing assuming that the encrypted user IDs of all monitors who responded to the survey indicated by the identified survey ID have been identified.

[0030] Figure 5 shows an example of a topping data selection screen. The topping data selection screen 50 displays major categories of topping data, such as lifestyle consciousness data, category data, etc. Selecting the "+" to the right of a major category displays more detailed sub-categories of the selected major category (right diagram in Figure 5). For example, selecting the major category "Lifestyle Consciousness Data" displays sub-categories of lifestyle consciousness data, such as "Lifestyle Consciousness," "Work-Life Consciousness," "Shopping Consciousness," "Food Consciousness," and "Fashion Consciousness." The client company selects the items they wish to link to the survey they have requested. For example, if, after reviewing the survey results, they want to gain a deeper understanding of the health consciousness and behavior of the respondents in addition to the survey results they requested, the client company may select, for example, "Health Consciousness" or "Food Consciousness" as topping data.

[0031] As described above, the big data DB 40 stores topping data for each monitor, such as the monitor's lifestyle consciousness data. Each piece of data is registered in association with a monitor ID. However, the same topping data does not exist for all monitors; it is registered only for monitors who responded to a survey, such as a large-scale questionnaire, aimed at collecting topping data. Large-scale questionnaires aimed at collecting topping data are conducted multiple times. Because some monitors may not be targeted for a particular large-scale questionnaire (e.g., they were not members) or may not respond to the large-scale questionnaire, the amount of topping data registered in the big data DB 40 varies depending on the monitor. The control unit 32 may prioritize (e.g., display at the top) the items with the largest amount of response data from monitor IDs decrypted from the encrypted user ID identified in step S8 on the topping data selection screen 50. For example, the selection screen of FIG. 5 may be displayed when the monitor corresponding to the identified encrypted user ID has the most responses to a large-scale questionnaire on lifestyle consciousness data, followed by category data. Furthermore, the screen on the right side of Figure 5 may be a screen that is displayed when, in the lifestyle consciousness data, the number of responses to questions about shopping consciousness is the largest, followed by questions about health consciousness, then food consciousness, and then fashion consciousness.

[0032] When the requesting company selects the topping data to be added (step S10), the requesting company terminal 20 transmits the selected topping data items "health awareness" and "diet awareness" linked to the survey ID to the survey management server 30. The survey management server 30 receives the survey ID, "health awareness," and "diet awareness." Next, the requesting company operates the requesting company terminal 20 to upload the survey results output in step S7 to the survey management server 30 (step S11). The survey management server 30 receives the survey results. Note that since the survey management server 30 can generate the survey results from the survey ID, the processing of step S9 can be omitted. Furthermore, the processing of steps S8 to S10 and step S11 can be performed in any order. Step S11 may be performed first and then the processing of steps S8 to S10, or they may be performed simultaneously in parallel. Next, the survey management server 30 extracts monitor IDs from the encrypted user IDs identified in step S8 and adds topping data for each monitor ID (step S12). Specifically, the ID management unit 321 decrypts the encrypted user ID using the password and extracts the monitor ID. The ID management unit 321 extracts the monitor ID for all encrypted user IDs identified in step S8. The control unit 32 receives the extracted monitor ID, searches the big data DB 40, and reads out the results (topping data) of a large-scale survey on "health awareness" and "diet awareness." The control unit 32 adds the read topping data to the survey results of the encrypted user ID corresponding to the monitor ID. The control unit 32 adds the topping data for all encrypted user IDs identified in step S8.

[0033] Next, the control unit 32 outputs the survey results with the topping data added (step S13). The control unit 32 sends information linking the survey results and the topping data to the requesting company terminal 20 with the encrypted user ID. Figure 6 shows an example of the survey results with the topping data added. The amount of topping data registered in the big data DB 40 varies depending on the monitor. In Figure 6, "-" indicates a question that was not included in the large-scale survey or a question that the monitor did not answer. When generating the survey results with the topping data added, the control unit 32 may generate the survey results by sorting the encrypted user IDs in a display order such that monitors who have responded with a large amount of topping data are ranked higher, as shown in Figure 6 as an example. This can improve the work efficiency when the requesting company checks the survey results.

[0034] In the processing flow of FIG. 4 , the encrypted user ID is decrypted to extract the user ID, and the topping data stored in the big data database 40 is linked to the survey results based on the extracted user ID. This allows the requesting company to receive the survey results with the added topping data in a format that prevents the individual survey respondents from being identified, while the survey management server 30 manages the survey results and attribute information by linking them to the survey respondents' IDs. For example, it is possible to reduce the possibility of identifying individuals by providing the survey results to the requesting company terminal 20 using a simple "sequential number" instead of the encrypted user ID. However, this method makes it difficult for the survey management server 30 to determine which survey respondents' IDs should be added when adding topping data. In contrast, according to this embodiment, the encrypted user ID is provided to the requesting company, reducing the possibility of identifying individuals, while decrypting the survey respondents' IDs from the encrypted user IDs allows the topping data to be easily added.

[0035] (Operation 2 including topping function) In the processing flow of Figure 4, the survey results are output once, then uploaded and topping data is added. However, it is also possible to configure the system so that the survey results with added topping data are output without outputting and uploading the survey results. 7 is a third flowchart showing an example of the operation of the questionnaire system according to the embodiment. Processing similar to that in FIGS. 2 and 4 will be briefly described. First, the input receiving unit 31 receives a survey request (step S1). Next, the control unit 32 creates survey information (step S2). Next, the control unit 32 extracts respondents (step S3). Next, the control unit 32 conducts the survey (step S4). Next, the control unit 32 registers the survey response results in the survey DB 332 (step S5). Next, the ID management unit 321 generates an encrypted user ID (step S6). Next, the control unit 32 outputs a topping data selection screen, for example, as shown in FIG. 5, to the requesting company terminal 20 (step S9) and checks whether or not topping data has been added. If no topping data has been added, the control unit 32 generates survey results in the same manner as in step S7 of FIG. 2 and outputs them to the requesting company terminal 20. Here, the processing when topping data has been added will be described. The company requesting the survey selects the topping data to be added (step S10). At this time, the requesting company may specify the conditions for the monitor to whom the topping data is to be added. For example, it may be possible to specify that topping data A (e.g., "health consciousness") be added to a monitor who answered "Yes" to question 1, and topping data B (e.g., "dietary consciousness") be added to a monitor who answered "Yes" to question 2 (a similar specification may be made in step S8 in the processing flow of FIG. 4). In the survey management server 30, the ID management unit 321 extracts monitor IDs from the encrypted user IDs generated in step S6 (if monitor conditions were specified in step S10, the encrypted user IDs of monitors who meet the conditions), and the control unit 32 adds topping data for each monitor ID (step S12). Alternatively, the control unit 32 may search the big data DB 40 using the monitor IDs extracted in step S3, read out the topping data to be added, and add the read out topping data to the survey results for the encrypted user IDs corresponding to the survey results. Next, the control unit 32 outputs the survey results to which the topping data has been added (step S13).By generating an encrypted user ID from the monitor ID and survey ID in this way, the server can manage survey results and topping data based on the monitor ID, and by disclosing only the encrypted user ID to the requesting company, it is possible to prevent the identification or estimation of individuals, or the accumulation of data related to a particular individual.

[0036] (effect) As described above, according to this embodiment, when conducting a survey using a survey system, monitor information for each survey can be managed in a manner that prevents the identification of individuals and facilitates the use of information such as survey result analysis. For example, by generating an encrypted user ID based on a survey ID and a monitor ID and linking the generated encrypted user ID to the responses of the monitor identified by the monitor ID in the survey identified by the survey ID, the monitor information for each survey can be managed in a format that facilitates analytical processing on the survey management server 30 side, combining the survey responses with information related to the respondent, while avoiding the identification of individuals. Survey results managed using encrypted user IDs, which are code information that changes for each survey and does not identify individuals, do not lead to the identification of individuals even when accumulated, so they can be safely provided to clients who requested the survey. Meanwhile, the server side can link the response results of multiple surveys to the monitor ID and accumulate them.

[0037] The survey management server 30 may be configured from multiple server devices. For example, the function of generating and outputting survey results and the function of adding topping data may be implemented in separate servers. In addition, in the above embodiment, the survey requester is a company, but the survey requester may also be an individual or a government agency.

[0038] FIG. 8 is a diagram showing an example of the hardware configuration of a questionnaire system according to an embodiment. The computer 900 includes a CPU 901, a main storage device 902, an auxiliary storage device 903, an input / output interface 904, and a communication interface 905. The respondent terminals 10a and 10b, the client company terminal 20, and the questionnaire management server 30 described above are implemented in the computer 900. The above-described processes are stored in the auxiliary storage device 903 in the form of a program. The CPU 901 reads the program from the auxiliary storage device 903, loads it into the main storage device 902, and executes the above-described processes in accordance with the program. The CPU 901 also allocates a memory area in the main storage device 902 in accordance with the program. The CPU 901 also allocates a memory area in the auxiliary storage device 903 for storing data being processed in accordance with the program.

[0039] In at least one embodiment, the auxiliary storage device 903 is an example of a non-transitory tangible medium. Other examples of non-transitory tangible media include a magnetic disk, a magneto-optical disk, a CD-ROM, a DVD-ROM, and a semiconductor memory connected via the input / output interface 904. Furthermore, when this program is distributed to the computer 900 via a communication line, the computer 900 that receives the program may load the program into the main storage device 902 and execute the above-described processing. The program may also be for realizing part of the above-described functions. Furthermore, the program may be a so-called differential file (differential program) that realizes the above-described functions in combination with another program already stored in the auxiliary storage device 903.

[0040] In addition, the components in the above-described embodiments can be replaced with well-known components as appropriate without departing from the spirit of the present invention. Furthermore, the technical scope of the present invention is not limited to the above-described embodiments, and various modifications can be made without departing from the spirit of the present invention.

[0041] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes.

[0042] (Appendix 1) A questionnaire system comprising an ID generation means for generating an encrypted user ID based on a questionnaire ID, which is identification information for a questionnaire conducted by the questionnaire system, and a monitor ID, which is identification information for a respondent who answers the questionnaire.

[0043] (Appendix 2) a storage means for storing the survey ID, the monitor ID, and the answer of the respondent associated with the monitor ID to the survey associated with the survey ID in association with each other; The survey system described in Appendix 1 further includes an output means for outputting survey results that link the respondent's answers to the survey stored in the storage means with the encrypted user ID generated by the ID generation means based on the survey ID and monitor ID linked to the answers.

[0044] (Appendix 3) A survey system as described in Appendix 1 or Appendix 2, wherein, for a first respondent who answers a first survey and a second survey, the ID generation means generates the encrypted user ID for the first survey of the first respondent based on the survey ID of the first survey and the monitor ID of the first respondent when the survey system conducts the first survey, and generates the encrypted user ID for the second survey of the first respondent based on the survey ID of the second survey and the monitor ID of the first respondent when the survey system conducts a second survey.

[0045] (Appendix 4) A survey system as described in Appendix 3, wherein the encrypted user ID for the first survey of the first respondent and the encrypted user ID for the second survey of the first respondent are composed of different character strings.

[0046] (Appendix 5) The survey system according to Appendices 2 to 4 further comprises a big data storage means for storing the monitor ID in association with topping data that is the result of a survey on the awareness and / or behavior of the respondent associated with the monitor ID, wherein the output means outputs the survey results with topping data that is obtained from the big data storage means and added to the responses to the survey with the monitor ID included in the survey results.

[0047] (Appendix 6) The survey system described in Appendix 5 further comprises an extraction means for extracting the monitor ID from the encrypted user ID, wherein the extraction means extracts the monitor ID from the encrypted user ID included in the survey results, and the output means obtains the topping data linked to the monitor ID from the big data storage means based on the extracted monitor ID, and adds the obtained topping data to the survey results.

[0048] (Appendix 7) The survey system described in Appendix 5 to Appendix 6, wherein the output means outputs the survey results with the topping data in order of the encrypted user IDs associated with the monitor IDs with the largest number of survey results included in the topping data acquired from the big data storage means.

[0049] (Appendix 8) The survey system according to any one of Appendices 5 to 7, further comprising a selection means for accepting a selection of survey items to be added to the survey results from the topping data stored in the big data storage means, wherein the output means adds the results of the survey items accepted by the selection means to the survey results.

[0050] (Appendix 9) The survey system described in Appendix 5 to Appendix 8 further comprises a means for accepting conditions for respondents to the survey, and a means for searching the topping data stored in the big data storage means and extracting the monitor ID that satisfies the conditions of the awareness and / or behavior that respondents to the survey should have, as specified by the conditions.

[0051] (Appendix 10) A survey management method in which a computer generates an encrypted user ID based on a survey ID, which is identification information for a survey conducted by a survey system, and a monitor ID, which is identification information for a respondent who answers the survey.

[0052] (Appendix 11) A program for causing a computer to function as a means for generating an encrypted user ID based on a survey ID, which is identification information for a survey conducted by a survey system, and a monitor ID, which is identification information for a respondent who answers the survey. [Explanation of symbols]

[0053] 1. Survey system 10a, 10b: Respondent terminal 20. Requesting company terminal 30. Survey management server 31 Input reception section 32 Control section 321...ID Management Department 33...Storage section 331···Monitor DB 332···Survey DB 40 Big Data Database 900···Computer 901 CPU 902...Main memory 903...Auxiliary storage device 904 Input / Output Interface 905···Communication Interface

Claims

1. ID generation means for generating an encrypted user ID based on a questionnaire ID, which is identification information of a questionnaire conducted by the questionnaire system, and a monitor ID, which is identification information of a respondent who answers the questionnaire; A questionnaire system comprising:

2. a storage means for storing the questionnaire ID, the monitor ID, and the answer of the respondent associated with the monitor ID to the questionnaire associated with the questionnaire ID in association with each other; an output means for outputting a survey result in which the answer of the respondent to the survey stored in the storage means is linked to the encrypted user ID generated by the ID generation means based on the survey ID and the monitor ID linked to the answer; The questionnaire system according to claim 1 , further comprising:

3. For a first respondent who answers the first questionnaire and the second questionnaire, the ID generation means When the questionnaire system conducts the first questionnaire, the encrypted user ID for the first respondent is generated based on the questionnaire ID of the first questionnaire and the monitor ID of the first respondent; When the questionnaire system conducts a second questionnaire, the encrypted user ID for the second questionnaire of the first respondent is generated based on the questionnaire ID of the second questionnaire and the monitor ID of the first respondent. The questionnaire system according to claim 1 or 2.

4. The encrypted user ID of the first respondent for the first questionnaire and the encrypted user ID of the first respondent for the second questionnaire are configured with different character strings. The questionnaire system according to claim 3 .

5. The system further includes a big data storage means for storing the monitor ID in association with topping data that is a result of a survey on the awareness and / or behavior of the respondent associated with the monitor ID, The output means outputs the survey results with topping data obtained by adding the topping data associated with the monitor ID acquired from the big data storage means to the answers to the survey of the respondent associated with the monitor ID included in the survey results. The questionnaire system according to claim 2 .

6. further comprising an extraction means for extracting the monitor ID from the encrypted user ID, the extraction means extracts the monitor ID from the encrypted user ID included in the survey result; the output means acquires the topping data linked to the monitor ID from the big data storage means based on the extracted monitor ID, and adds the acquired topping data to the survey results. The questionnaire system according to claim 5 .

7. The output means outputs the survey results with the topping data in order of the encrypted user IDs associated with the monitor IDs having the largest number of survey results included in the topping data acquired from the big data storage means.

7. The questionnaire system according to claim 5 or 6.

8. The system further includes a selection unit that accepts a selection of the survey items to be added to the questionnaire results from the topping data stored in the big data storage unit, the output means adds the results of the survey items accepted by the selection means to the questionnaire results.

7. The questionnaire system according to claim 5 or 6.

9. means for accepting conditions of respondents to the questionnaire; a means for searching the topping data stored in the big data storage means and extracting the monitor IDs that satisfy the conditions of the awareness and / or behavior that the respondents of the questionnaire should have, which are specified by the conditions; The questionnaire system according to claim 5 or 6, further comprising:

10. The computer generating an encrypted user ID based on a survey ID, which is identification information of a survey conducted by the survey system, and a monitor ID, which is identification information of a respondent who will respond to the survey; Survey administration methods.

11. Computer, A means for generating an encrypted user ID based on a survey ID, which is identification information of a survey conducted by the survey system, and a monitor ID, which is identification information of a respondent who answers the survey; A program to function as a

Citation Information

Patent Citations

  • Monitoring system and method

    JP2002073947A

  • Anonymous questionnaire system concerning user and staff web survey in welfare service third-party evaluation

    JP2016095656A

  • Information processing apparatus, information processing method, and information processing program

    JP2019046263A