Data cleansing system, data cleansing apparatus, and data cleansing method

The data cleansing system addresses information leakage and cost issues in cloud services by securely cleansing data in a centralized manner, using encrypted data processing in a secure memory area.

JP2026053102APending Publication Date: 2026-03-25HITACHI LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-12
Publication Date
2026-03-25

Smart Images

  • Figure 2026053102000001_ABST
    Figure 2026053102000001_ABST
Patent Text Reader

Abstract

We provide technology that enables secure data cleansing in cloud services. [Solution] The data cleansing system is a data cleansing system in which multiple computers, each having a processor and memory and connected to each other via a network to enable data communication, acquire encrypted data via the network, decrypt it, cleanse the decrypted data in a secure area in memory, encrypt the cleansed data, and output it via the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0004] , , , , ,

[0006] , , , ,

[0005] , , , , ,

[0001] The present invention mainly relates to a technique for performing data cleansing in a cloud environment.

Background Art

[0002] Quite often, data collected and obtained from residents and service users (hereinafter also referred to as "raw data") contains various errors including mistakes and noise.

[0003] Therefore, various techniques have been proposed today that can appropriately cleanse raw data containing such errors (for example, Patent Document 1). <000)0013>

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] ) The so-called cloud computing technology that provides computer resources composed of a plurality of computers, servers, etc. that are interconnected via a network and can communicate data with each other to a user via a network mainly based on the Internet has many advantages such as reducing environmental settings and execution costs, and thus is widely used in various applications today.

[0006] However, due to its nature, cloud computing technology carries the risk of information leakage when used. Specifically, for example, in various services using cloud computing technology (hereinafter also referred to as "cloud services"), when cleansing raw data containing errors using the technology described in Patent Document 1, there is room for improvement in terms of information leakage from the perspective of such raw data.

[0007] On the other hand, if the cleansing of raw data containing errors is not performed on the cloud, there is a problem in that it is necessary to build a cleansing environment for each type of raw data, for example, which increases costs.

[0008] This invention has been made in view of the above-mentioned problems, and aims to provide a technology that enables the secure cleansing of data in cloud services. [Means for solving the problem]

[0009] The data cleansing system according to the present invention is a data cleansing system in which multiple computers, each having a processor and memory and connected to each other via a network capable of data communication, acquire encrypted data via the network, decrypt it, cleanse the decrypted data in a secure area in memory, encrypt the cleansed data, and output it via the network.

[0010] Further details regarding the problems disclosed in this application, and their solutions, will be made clear in the section on embodiments for carrying out the invention and in the drawings. [Effects of the Invention]

[0011] According to the present invention, data can be securely cleansed in cloud services. [Brief explanation of the drawing]

[0012] [Figure 1]This figure shows an example of the overall system configuration, including the data cleansing system according to the embodiment. [Figure 2] This diagram schematically shows an example of the hardware configuration of a data cleansing server (data cleansing device) that constitutes a data cleansing system. [Figure 3] This figure shows an example of data to be cleansed. [Figure 4] This figure shows an example of data to be cleansed. [Figure 5] This flowchart shows an example of the data cleansing process performed in a data cleansing system. [Figure 6] This diagram illustrates the procedure for data cleansing. [Figure 7] This diagram illustrates the procedure for data cleansing. [Figure 8] This figure shows an example of a display screen. [Figure 9A] This figure shows an example of an API. [Figure 9B] This figure shows an example of a UI. [Figure 10] This is a sequence diagram showing an example of the overall processing flow, including data cleansing. [Figure 11] This is a sequence diagram showing an example of the overall processing flow, including data cleansing. [Figure 12] This is a sequence diagram showing an example of the overall processing flow, including data cleansing. [Figure 13] This is a sequence diagram showing an example of the overall processing flow, including data cleansing. [Figure 14] This flowchart shows an example of the flow of the automatic generation / update process for error detection rules performed in a data cleansing system. [Figure 15] This flowchart shows an example of the flow of the automatic generation / update process of data cleansing rules performed in a data cleansing system. [Modes for carrying out the invention]

[0013] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. However, the present invention is not limited to the description content of the examples illustrated below. Examples of modifications to the specific configuration are also included without departing from the spirit or gist of the present invention. For example, the following examples explain the present invention in detail and are not necessarily limited to those having all the configurations included in the explanation.

[0014] In the configuration of the invention described below, the same parts and / or elements, or parts and / or elements having similar functions, are commonly used with the same reference numerals among different drawings, and duplicate explanations may be omitted.

[0015] Also, when there are a plurality of the same parts and / or elements, or parts and / or elements having similar functions, in order to distinguish the plurality of parts and / or elements, the same reference numeral may be appended with different subscripts for explanation. On the other hand, when it is not necessary to distinguish the plurality of parts and / or elements, the subscripts may be omitted for explanation.

[0016] The notations such as "first", "second", "third", etc. in this specification and the like are for identifying components and do not necessarily limit the number, order, or content thereof. Also, the numbers for identifying components are used for each context, and the numbers used in one context do not necessarily indicate the same configuration in other contexts. Also, it does not prevent a component identified by a certain number from having the functions of a component identified by another number.

[0017] The positions, sizes, shapes, ranges, etc. of each configuration shown in this specification and / or the drawings may not represent the actual positions, sizes, shapes, ranges, etc. in order to facilitate the understanding of the invention. Therefore, the present invention is not necessarily limited to the positions, sizes, shapes, ranges, etc. disclosed in this specification and / or the drawings.

[0018] In this specification, elements expressed in the singular form shall include the plural form unless otherwise clearly indicated in the context.

[0019] Furthermore, in the following explanation, "interface device" may refer to one or more interface devices. These one or more interface devices may be at least one of the following: • One or more I / O (Input / Output) interface devices. An I / O (Input / Output) interface device is an interface device to at least one of the following: an I / O device and a remote display computer. The I / O interface device to the display computer may be a communication interface device. The at least one I / O device may be either a user interface device, such as an input interface device like a keyboard or pointing device, or an output interface device like a display device. • One or more communication interface devices. One or more communication interface devices may be one or more identical communication interface devices (e.g., one or more NICs (Network Interface Cards)) or two or more different communication interface devices (e.g., a NIC and an HBA (Host Bus Adapter)). The network that the communication interface device accesses for communication may be the Internet, a LAN (Local Area Network), a WAN (Wide Area Network), or a mobile phone network, but is not limited to these.

[0020] Furthermore, in the following explanation, "memory" refers to one or more main memory devices, which are examples of one or more storage devices, and are typically memory devices. At least one memory device in memory may be a volatile memory device or a non-volatile memory device.

[0021] Furthermore, in the following explanation, "storage" may refer to one or more auxiliary storage devices, which are examples of one or more storage devices. Auxiliary storage devices are typically non-volatile storage devices (e.g., persistent storage devices), and specifically, they may be HDDs (Hard Disk Drives), SSDs (Solid State Drives), NVMe (Non-Volatile Memory Express) drives, or SCMs (Storage Class Memory).

[0022] Furthermore, in the following explanation, "storage device" may refer to at least memory, which is part of memory and storage.

[0023] Furthermore, in the following explanation, the term "processor," which refers to an arithmetic unit, may be one or more processor devices. At least one processor device is typically a microprocessor device such as a CPU (Central Processing Unit), but may also include other types of processor devices such as a GPU (Graphics Processing Unit). At least one processor device may be single-core or multi-core. At least one processor device may be a processor core. At least one processor device may be a broad processor device such as a hardware circuit that performs some or all of the processing (e.g., an FPGA (Field Programmable Gate Array), a CPLD (Complex Programmable Logic Device), or an ASIC (Application Specific Integrated Circuit)).

[0024] Furthermore, in the following explanation, we may use expressions such as "xxx database" or "xxx table" to describe information from which an output is obtained for a given input. This information can be represented by data of any structure (for example, it can be structured data or unstructured data), or by a learning model such as a neural network, genetic algorithm, or random forest that generates an output for a given input. Therefore, "xxx database" or "xxx table" can be replaced with "xxx information." Also, in the following explanation, the configuration of each database or table is just an example; one database or table may be divided into two or more databases or tables, or all or part of two or more databases or tables may be one database or table.

[0025] Furthermore, in the following explanation, the subject of the process may be "program," but since a program is executed by a processor and performs defined processes using memory and / or interface devices as appropriate, the subject of the process may also be the processor (or a device such as a controller having that processor). A program may be installed from a program source into a device such as a computer. The program source may be, for example, a program distribution server or a computer-readable (e.g., non-temporary) recording medium. Also, in the following explanation, two or more programs may be implemented as one program, or one program may be implemented as two or more programs.

[0026] Furthermore, in the following explanation, the "data cleansing system" refers to a system implemented on a group of physical computing resources (e.g., a cloud infrastructure) (e.g., a cloud computing system), but it may also be a system composed of one or more physical computers (e.g., an on-premise system). The data cleansing system "displaying" information may mean displaying the information on a display device owned by a computer, or it may mean the computer transmitting the information to a display computer (in the latter case, the display computer displays the information). <Example System Configuration>

[0027] First, an example of the configuration of the data cleansing system 100 according to this embodiment will be described using Figures 1 and 2. Figure 1 is a diagram showing an example of the overall system configuration including the data cleansing system 100. Figure 2 is a diagram schematically showing an example of the hardware configuration of the data cleansing server (data cleansing device) 110 that constitutes the data cleansing system 100. (Example of the overall system configuration)

[0028] The data cleansing system 100 is, in general terms, a computer system that securely cleanses data in cloud services by securing a confidential and secure area (hereinafter also referred to as the "confidential area 200") in the memory of a cloud server, and is implemented by multiple computers or servers, each having one of the configurations described below. In this embodiment, the "confidential area" provided in memory may be a protected area called an "enclave," and specifically, it may be an area set up by an extended function of the Intel CPU according to the Intel SGX mechanism ("Intel" is a registered trademark, and "SGX" is an abbreviation for Software Guard Extensions). Data is input and output to the enclave in an encrypted state, and processing can be performed while protecting the data within the enclave. An example of a protocol for obtaining a confidential processing certificate is an "attestation" for authentication of the enclave, and in this embodiment, a remote attestation can be used as the attestation, but a local attestation may also be used. In other words, the "confidential area" is an area where data is input and output in an encrypted state, and where the integrity of the data and software within that area is verified (authenticated).

[0029] As illustrated in Figure 1, the data cleansing server 110, which constitutes this data cleansing system 100, is connected to a confidential processing certificate issuing server 120 owned and managed by a certification authority that authenticates that data has been securely cleansed in a confidential area 200 on the memory of the data cleansing server 110, which is a cloud server. The confidential processing certificate issuing server 120 is connected to the data cleansing server 110 via an appropriate network 170, such as the internet or a dedicated line, enabling data communication between them. The data cleansing server 110 and the data server 130 and the network 170 are both connected by wire via well-known communication equipment (not shown), but they may also be connected wirelessly.

[0030] Furthermore, as shown in Figure 1, the data cleansing server 110, which constitutes the data cleansing system 100, is connected to data servers 130 owned and managed by the owners (hereinafter also referred to as "data owners") of the various data to be cleansed in the data cleansing system 100 (hereinafter also referred to as "data to be cleansed"), such as local governments, via an appropriate network 170 such as the Internet or a dedicated line, enabling data communication between them. The data cleansing server 110 and the data servers 130 and the network 170 are both connected by wire via well-known communication equipment (not shown), but they may also be connected wirelessly.

[0031] Furthermore, as shown in Figure 1, the data cleansing server 110, which constitutes the data cleansing system 100, and the data server 130, which stores the various data that has been cleansed in the data cleansing system 100, are connected to each other via an appropriate network 170, such as the internet or a dedicated line, by client terminals 140a, 140b, ... 140n (hereinafter collectively referred to as "client terminal 140" when referring to them collectively or when not making a distinction), such as laptop PCs, tablets, and smartphones owned by users of the various data (hereinafter also referred to as "data users"), such as pharmaceutical companies and application developers. Each client terminal 140 and the network 170 are connected wirelessly, but they may also be connected by wire.

[0032] Furthermore, other devices, such as a server providing the generated AI service 150 or a data server storing the public information database 160, may be connected to the data cleansing server 110, which constitutes the data cleansing system 100, and the data server 130, which stores various data that has been cleansed in the data cleansing system 100, via the network 170, as illustrated in Figure 1, enabling them to communicate with each other via data. In this case, the other devices and the network 170 may be connected by wire via well-known communication equipment (not shown) or by wireless connection.

[0033] In this embodiment, the data cleansing server 110 constituting the data cleansing system 100 was described as a cloud server consisting of multiple devices connected to each other in a data communication manner. However, for example, the data cleansing server 110 may consist of a single device.

[0034] Furthermore, in this embodiment, the data cleansing server 110 and other devices such as the data server 130 and client terminal 140 that constitute the data cleansing system 100 have been described as being separate devices. However, the data cleansing server 110 and other devices such as the data server 130 and client terminal 140 may be composed of the same device. In this case, the data cleansing system may be configured as a system that includes, for example, the data server 130 and client terminal 140. Alternatively, for example, the data cleansing system may be configured to include some or all of the functions performed by other devices such as the data server 130 and client terminal 140. (Example hardware configuration for data cleansing server 110)

[0035] Next, an example of the hardware configuration of the data cleansing server 110, which constitutes the data cleansing system 100, will be explained using Figure 2.

[0036] As described above, the data cleansing server 110 according to this embodiment is a cloud server consisting of a plurality of devices connected to each other in a manner that enables data communication. Each data cleansing server 110 is implemented by a computer having at least a storage device including memory 102 and storage 103, an interface device including at least a network interface 104, and a processor 101 connected thereto, as illustrated in Figure 2. In addition, each data cleansing server 110 may include an input device 105 and / or an output device 106 as part of the interface device.

[0037] The following description assumes that each data cleansing server 110 is implemented by a single general-purpose server or computer, each comprising one or more processors 101, one or more memories 102, one or more storage devices 103, one or more network interfaces 104, one or more input devices 105, one or more output devices 106, and wired or wireless communication lines 107 connecting them.

[0038] In other words, each data cleansing server 110 has a storage device including memory 102 and storage 103, an interface device including a network interface 104, an input device 105 and an output device 106, and a processor 101 connected thereto.

[0039] Storage 103 is an auxiliary storage device consisting of non-volatile memory elements such as flash memory. Specific examples of storage 103 include SSDs (Solid State Drives) and HDDs (Hard Disk Drives). Storage 103 stores at least a data cleansing program. The data cleansing program is a computer program that implements the necessary functions for the data cleansing system 100.

[0040] In other words, when the data cleansing program is executed by the processor 101, various processes are performed, including the data cleansing process described later in relation to Figure 5 (hereinafter referred to as "data cleansing process"), the automatic generation and / or updating of error detection rules described later in relation to Figure 14 (hereinafter referred to as "automatic error detection rule generation / update process"), and the automatic generation and / or updating of data cleansing rules described later in relation to Figure 15 (hereinafter referred to as "automatic data cleansing rule generation / update process").

[0041] The data cleansing program may be installed from the program source. The program source may be, for example, a program distribution computer or a computer-readable recording medium. The data cleansing program may also consist of a device driver, an operating system, various application programs located at a higher layer, and libraries that provide common functions to these programs. Furthermore, two or more programs may be implemented as one data cleansing program, or one data cleansing program may be implemented as two or more programs.

[0042] Memory 102 is a main memory device consisting mainly of volatile memory elements such as RAM (Random Access Memory). Memory 102 temporarily holds data representing various information read from storage 103, as well as various data acquired via the network interface 104 and / or input device 105.

[0043] The processor 101 is a processor device such as a CPU (Central Processing Unit) and various coprocessors. This processor 101 controls the data cleansing system 100 itself by calling and executing a data cleansing program in memory 102, and also controls a control unit (not shown) that performs various processing such as arithmetic processing and judgment processing.

[0044] The interface device includes a network interface 104 that connects to the network 170 and communicates with other devices such as the confidential processing certificate issuing server 120 and the data server 130, an input device 105, and an output device 106.

[0045] The network interface 104 is a network interface device that controls communication with other devices via the network 170 according to a predetermined protocol.

[0046] The input device 105 is a type of input interface device that receives input from a user, such as the administrator of the data cleansing system 100, such as a keyboard, mouse, or touchscreen.

[0047] The output device 106 is a variety of output interface devices that output the program execution results in a format that can be recognized by the user, such as various display devices like liquid crystal displays and touch screens, or speakers and printers.

[0048] As described above, the processor 101, memory 102, storage 103, network interface 104, input device 105, and output device 106 are connected to each other via wired or wireless communication lines 107, and data and programs are transmitted to each other through these communication lines 107.

[0049] The data cleansing server 110 may be a standalone device or an embedded device. (Examples of hardware configurations for other devices)

[0050] Furthermore, the hardware configuration of the various devices (120, 130, 140, 150, 160) that constitute the data cleansing system 100 and are connected to the data cleansing server 110 via the network 170 and communicate with each other is generally the same as the hardware configuration of the data cleansing server 110 exemplified in Figure 2.

[0051] In other words, various other devices according to this embodiment, such as the confidential processing certificate issuance server 120, data server 130, client terminal 140, the server providing the generation AI service 150, and the data server storing the public information database 160, are each implemented by a computer having at least a storage device including memory and storage, an interface device including at least a network interface, and a processor connected thereto, similar to the hardware configuration of the data cleansing server 110 illustrated in Figure 2. Furthermore, in these various devices (120, 130, 140, 150, 160), the interface device may also include an input device and / or an output device.

[0052] The following description assumes that these various devices (120, 130, 140, 150, 160) are implemented by one or more general-purpose computers and / or servers, each comprising one or more processors, one or more memory, one or more storage, one or more network interfaces, one or more input devices, one or more output devices, and wired or wireless communication lines connecting them. (Example of a functional block for data cleansing server 110)

[0053] Next, an example of the various function blocks provided by the data cleansing server 110 according to this embodiment will be explained using Figure 1. Note that the blocks described below represent function-based blocks, not hardware-based configurations.

[0054] The data cleansing server 110 is configured with functional blocks comprising a control unit (not shown), a storage unit (not shown), and a communication unit (not shown), as well as a user interface unit consisting of an input unit (not shown) and an output unit (not shown).

[0055] The control unit performs various data processing based on the programs and data stored in the memory unit and the data acquired by the communication unit. The control unit also performs various processes such as the aforementioned data cleansing process (details will be described later in relation to Figure 5), automatic error detection rule generation / update process (details will be described later in relation to Figure 14), and automatic data cleansing rule generation / update process (details will be described later in relation to Figure 15). The control unit also functions as an interface between the memory unit and the communication unit.

[0056] As illustrated in Figure 1, the control unit includes at least the following functional blocks: a decryption unit 211, a data cleansing unit 212, an encryption unit 213, and an automatic cleansing rule update unit 214.

[0057] The decryption unit 211 performs the process of decrypting the encrypted raw data in the confidential area 200 of the memory 102 (details will be described later).

[0058] The data cleansing unit 212 performs various data cleansing processes in the confidential area 200 of the memory 102 (details will be described later).

[0059] The encryption unit 213 performs the process of encrypting the cleansed data in the confidential area 200 of the memory 102 (details will be described later).

[0060] The cleansing rule automatic update unit 214 performs various processes related to the automatic update of cleansing rules (details will be described later).

[0061] Furthermore, the control unit may have functional blocks such as a data splitting unit 215 and a cloud data collection unit 216, as illustrated in Figure 1.

[0062] The data partitioning unit 215 performs various processes related to data partitioning in the confidential area 200 of the memory 102.

[0063] The cloud data collection unit 216 performs various processes related to the collection of cloud data.

[0064] The control unit is configured using the processor 101 and can realize these functional blocks by executing a predetermined data cleansing program. Alternatively, the control unit may be configured using logic circuits such as an FPGA (Field Programmable Gate Array) instead of the processor 101. Furthermore, the control unit may be configured using a combination of the processor 101 and logic circuits.

[0065] The storage unit is configured using, for example, a storage device consisting of a storage device 103 and a memory device 102, and stores a program that supplies various processing instructions to the control unit, and data representing various information used in the processing executed by the control unit.

[0066] The memory unit stores at least the cleansing rule database 221, as illustrated in Figure 1.

[0067] The cleansing rule database 221 is a database for managing cleansing rules in a table format.

[0068] Furthermore, the memory unit may store a confidentiality level database 222, as illustrated in Figure 1.

[0069] The confidentiality level database 222 is a database for managing information in a table format that represents the confidentiality level of data when performing various data processing in the confidential area 200 of memory 102.

[0070] The control unit can perform various processes, such as the aforementioned data cleansing process (details will be described later in relation to Figure 5), automatic error detection rule generation / update process (details will be described later in relation to Figure 14), and automatic data cleansing rule generation / update process (details will be described later in relation to Figure 15), by reading and writing various information, including this information, to the storage unit.

[0071] The communications unit is responsible for processing communication with client terminals 140 and other devices via the internet (for example, network 170). The communications unit is configured using components such as a NIC (Network Interface Card) and an HBA (Host Bus Adapter).

[0072] The user interface section consists of functional blocks for the input and output sections.

[0073] The input unit is responsible for processing related to user interface input, such as receiving input operations from the user. The input unit is configured using input devices 105, such as a keyboard, pointing device, or touch panel, and detects various operations from the user.

[0074] The output unit is responsible for processing related to the user interface, including output processing such as displaying various screens on a display device and outputting audio. The output unit is configured using an output device 106, such as a liquid crystal display or a touchscreen.

[0075] Furthermore, for example, when remotely logging into the data cleansing server 110 from another external device, or when receiving input information from an external device or providing output information to an external device via a communication unit, the inclusion of an input unit and / or output unit is not mandatory. In this case, the data cleansing server 110 may accept access from an external device using a predetermined protocol by having web server functionality.

[0076] In other words, each component of the data cleansing server 110 that constitutes the data cleansing system 100 is realized by hardware including a processor 101, memory 102 and storage 103, wired or wireless communication lines 107 and interface devices (104, 105, 106) that connect them, and software stored in the storage 103 that supplies processing instructions to the arithmetic unit.

[0077] In this embodiment, the functions of the data cleansing system 100 and / or data cleansing server 110 have been described as being integrated by multiple interconnected servers and / or computers. However, each of these functions may be implemented by a single server or computer.

[0078] Furthermore, the data cleansing system 100 and / or data cleansing server 110 may be configured to include a general-purpose computer device such as a laptop PC and a web browser installed thereon, or it may be configured to include various portable devices.

[0079] Furthermore, the above descriptions of each function are merely examples, and multiple functions may be combined into one function, or one function may be divided into multiple functions.

[0080] Furthermore, the data cleansing system 100 and / or data cleansing server 110 may have additional functions in addition to the various functions described above. (Examples of functional blocks for other devices)

[0081] Next, using Figure 1, we will explain an example of the various functional blocks provided by the various devices (120, 130, 140, 150, 160) that make up the data cleansing system 100 and are connected to each other via the network 170 and communicate with each other. Note that the blocks described below represent functional blocks, not hardware-level configurations.

[0082] In this embodiment, various other devices such as the confidential processing certificate issuing server 120, data server 130, client terminal 140, server providing the generation AI service 150, and data server storing the public information database 160 are each configured, similar to the data cleansing server 110, with functional blocks comprising a control unit (not shown), a storage unit (not shown), and a communication unit (not shown), as well as a user interface unit consisting of an input unit (not shown) and an output unit (not shown).

[0083] The control unit performs various data processing operations based on the programs and data stored in the memory unit, as well as the data acquired by the communication unit. The control unit also functions as an interface between the memory unit and the communication unit.

[0084] The control unit of the data server 130 has functional blocks for encryption 311 and decryption 312, as illustrated in Figure 1.

[0085] Furthermore, the control unit of the client terminal 140 has at least a decoding unit 411 as a functional block, as illustrated in Figure 1.

[0086] The encryption unit 311 performs the process of encrypting the data to be cleansed (raw data) to be sent to the data cleansing server 110 (details will be described later).

[0087] The decryption units (312, 411) perform the process of decrypting the cleansed data received from the data cleansing server 110, that is, the data that has been cleansed in the data cleansing server 110 and then encrypted for transmission over the network 170 (details will be described later).

[0088] The control unit is configured using a processor, and each of the above-mentioned functional blocks can be realized by executing the corresponding program. Alternatively, the control unit may be configured using logic circuits such as an FPGA (Field Programmable Gate Array) instead of a processor. Furthermore, the control unit may be configured using a combination of a processor and logic circuits.

[0089] The storage unit is configured using, for example, a storage device and memory, and stores programs that supply various processing instructions to the control unit, and data representing various information used in the processing executed by the control unit.

[0090] Furthermore, the storage unit of the data server that stores the public information database 160 stores the public information database 160, as illustrated in Figure 1.

[0091] Public Information Database 160 is a database that manages data representing various types of publicly available information.

[0092] The control unit of the data server storing the public information database 160 can perform various processes by reading and writing various types of information, including the public information managed by the public information database 160, to the storage unit.

[0093] The communications unit is responsible for processing communication with the data cleansing server 110 and other devices via the internet (for example, network 170). The communications unit is configured using, for example, a NIC (Network Interface Card) and an HBA (Host Bus Adapter).

[0094] The user interface section consists of functional blocks for the input and output sections.

[0095] The input unit is responsible for processing related to user interface input, such as receiving input operations from the user. The input unit is configured using input devices such as a keyboard, pointing device, or touch panel, and detects various operations from the user.

[0096] The output unit is responsible for processing related to the user interface, including output-related processing such as displaying various screens on a display device and outputting audio. The output unit is configured using output devices such as liquid crystal displays or touchscreens.

[0097] Furthermore, for example, when remotely logging into the device (120, 130, 140, 150, 160) from another external device, or when receiving input information from an external device or providing output information to an external device via the communication unit, the inclusion of an input unit and / or output unit is not mandatory. In this case, the device (120, 130, 140, 150, 160) may accept access from an external device using a predetermined protocol by having web server functionality.

[0098] In other words, each component, such as the confidential processing certificate issuance server 120, the data server 130 and client terminal 140, the server providing the generation AI service 150, and the data server storing the public information database 160, is realized by hardware including a processor, memory and storage devices, wired or wireless communication lines and interface devices connecting them, and software stored in the storage that supplies processing instructions to the arithmetic unit.

[0099] Please note that the above descriptions of each function are merely examples, and multiple functions may be combined into one function, or one function may be divided into multiple functions.

[0100] Furthermore, various devices such as the confidentiality certificate issuing server 120, the data server 130, the client terminal 140, the server providing the generation AI service 150, and the data server storing the public information database 160 may have additional functions in addition to the functions described above. (Example of data to be cleansed)

[0101] Next, we will explain an example of the cleansing target data mentioned above using Figures 3 and 4.

[0102] Figures 3 and 4 are diagrams showing examples of data to be cleansed. Figure 3 shows an example of the configuration of a resident basic information database 300 stored on a data server 130 owned by a local government, which is the data owner. Figure 4 shows an example of the configuration of a healthcare information database 400 stored on a data server 130 owned by a healthcare-related company, which is the data owner.

[0103] In the resident basic information database 300 illustrated in Figure 3, each resident's date of birth is generally managed in the Gregorian calendar, however, for resident number "10002," the date of birth is registered in the Japanese calendar.

[0104] Furthermore, in the resident basic information database 300 illustrated in Figure 3, each resident's name is generally managed using kanji characters for both their surname and given name, however, for resident number "10003," only the surname is registered in katakana.

[0105] Furthermore, in the healthcare information database 400 illustrated in Figure 4, there are three entries of step count data recorded for user "10001" on "240203 (February 3, 2024)" at "09:01:44 (9:01:44)," and all of them record abnormal values: "99999," "0," and "0."

[0106] Raw data collected and obtained from residents, service users, etc., containing various errors such as these errors and noise, becomes the data to be cleansed in the data cleansing system 100. <Example of system operation>

[0107] Next, an example of the operation of the data cleansing system 100 according to this embodiment will be explained using Figures 5 to 15. (Data cleansing process)

[0108] Figure 5 is a flowchart showing an example of the data cleansing process performed in the data cleansing system 100.

[0109] In step S501, the control unit of the data cleansing server 110 executes a process to obtain encrypted raw data from the data server 130 via the communication unit. As a result, encrypted raw data is obtained from the data server 130. Once the process in step S501 is completed, the control unit of the data cleansing server 110 proceeds to step S502.

[0110] In step S502, the control unit of the data cleansing server 110 executes a process to move the encrypted raw data acquired in step S501 to the secure area 200 of memory 102. This makes it possible to perform various data processing in the secure area 200 of memory 102 from then on. Once the processing in step S502 is completed, the control unit of the data cleansing server 110 proceeds to step S503.

[0111] In step S503, the control unit of the data cleansing server 110 uses the decryption unit 211 to decrypt the encrypted raw data acquired in step S501 in the secure area 200 of the memory 102. As a result, the encrypted raw data acquired in step S501 is decrypted in the secure area 200 of the memory 102. Once the processing in step S503 is complete, the control unit of the data cleansing server 110 proceeds to step S504.

[0112] In step S504, the control unit of the data cleansing server 110 executes a process to acquire error detection rules using the data cleansing unit 212. As a result, error detection rules are acquired. Once the process in step S504 is completed, the control unit of the data cleansing server 110 proceeds to step S505.

[0113] In step S505, the control unit of the data cleansing server 110 uses the data cleansing unit 212 to perform error detection according to the error detection rules acquired in step S504. As a result, errors are detected. Once the processing in step S505 is complete, the control unit of the data cleansing server 110 proceeds to step S506.

[0114] In step S506, the control unit of the data cleansing server 110 executes a process to acquire data cleansing rules using the data cleansing unit 212. As a result, data cleansing rules are acquired. Once the process in step S506 is complete, the control unit of the data cleansing server 110 proceeds to step S507.

[0115] In step S507, the control unit of the data cleansing server 110 uses the data cleansing unit 212 to perform a process to cleanse errors in the data to be cleaned, according to the data cleansing rules acquired in step S506. In this paragraph, "data to be cleaned" refers to the raw data that resides in the confidential area 200 of memory 102 and was decrypted in step S503. In this paragraph, "error" refers to the error detected in step S505. The process in step S507 is performed, for example, as shown in Figures 6-7. Specifically, Figure 6 shows the case where the data to be cleaned is point usage data. As illustrated in Figure 6, the detected errors in the data to be cleaned 601 (for example, duplicate user IDs in the "User ID" column or values ​​meaning no number in the "Point Usage ID" column) are cleansed according to the data cleansing rules 602, and as a result, the data to be cleaned 601 is converted into cleansed data 703. Figure 7 illustrates the case where the data to be cleansed is health check data. As illustrated in Figure 7, errors detected in the data to be cleansed 701 (for example, irregular numbers in the "Year" column that do not answer in the Gregorian calendar, or incorrect values ​​for BMI derived from height and weight in the "Test Value...BMI" column) are cleansed according to the data cleansing rule 702, and as a result, the data to be cleansed 701 is converted into cleansed data 703. Once the processing in step S507 is complete, the control unit of the data cleansing server 110 proceeds to step S508.

[0116] In step S508, the control unit of the data cleansing server 110 uses the encryption unit 213 to encrypt the data cleansed in step S507 in the confidential area 200 of the memory 102. As a result, the data cleansed in step S507 is encrypted in the confidential area 200 of the memory 102. Once the processing in step S508 is complete, the control unit of the data cleansing server 110 proceeds to step S509.

[0117] In step S509, the control unit of the data cleansing server 110 executes the process of moving the cleansed data encrypted in step S508 to the non-secret area of ​​memory 102. From this point onward, various data processing will be performed in the non-secret area of ​​memory 102, but security is robust because the cleansed data was encrypted in step S508. Once the processing in step S509 is complete, the control unit of the data cleansing server 110 proceeds to step S510. Note that the "non-secret area" of memory 102 is an area other than the secure area 200, and specifically, it may be any or a predetermined area other than the secure area 200.

[0118] In step S510, the control unit of the data cleansing server 110 executes a process to send the cleansed and encrypted data (the data moved to the non-secret area in step S509) to the data server 130 and / or client terminal 140 via the communication unit. As a result, the cleansed and encrypted data is sent to the data server 130 and / or client terminal 140 via the communication unit. Consequently, the data cleansing system 100 can securely cleanse data in the cloud service. Once the processing in step S410 is completed, the control unit of the data cleansing server 110 terminates the data cleansing process shown in the flowchart of Figure 5.

[0119] The results of the data cleansing process shown in the flowchart of Figure 5 are displayed on a display screen, for example, the UI (User Interface) shown in Figures 8 and 9B. Either UI in Figures 8 and 9B may be provided to and displayed on the client terminal 140 from the data server 130 (or from the data cleansing server 110 via or without the data server 130). For example, UI 800 illustrated in Figure 8 has UI 801, which is an example of a UI that displays the data to be cleansed (raw data), UI 802, which is an example of a UI that displays the cleansed data (data from which errors detected in the data to be cleansed have been cleaned), and UI 803, which is an example of a UI that displays the confidential processing certificate. For example, when the user presses the "Cleanse START" button on UI 801, the processing from step S502 (or S501) onward may be started. Furthermore, when the user presses the “Save cleaned data” button in UI802, the cleaned data may be saved to the data server 130, or the cleaned data may be downloaded to the client terminal 140. UI801 to 803 may be displayed as different UIs instead of a single UI800. Also, UI900b shown in Figure 9B is an example of a UI that displays cleaned data. The confidentiality processing certificate is obtained in the manner illustrated in Figures 10 to 13, which will be described later.

[0120] Furthermore, as illustrated in Figure 9A, the data cleansing system 100 can also provide an API (Application Programming Interface) to facilitate the execution of the data cleansing process shown in the flowchart of Figure 5. Figure 9A is UI900a, which displays an example of an API and its explanation.

[0121] Furthermore, the fact that the data to be cleansed has been securely cleaned in the confidential area 200 of the memory 102 of the data cleansing server 110 is proven by the issuance of a confidential processing certificate from the confidential processing certificate issuing server 120 in the manner illustrated in Figures 10 to 13.

[0122] In other words, as shown in the example in Figure 10, the data cleansing server 110 receives a request for an SGX quote from the data server 130, for example, via the communication unit (step S1001), generates an SGX quote (for example, metadata for the confidential area 200 (enclave)) according to the request, for example via the control unit, and returns a response with the generated SGX quote to the data server 130, for example via the communication unit (step S1002). The data server 130 sends a request for a remote attestation to the confidential processing certificate issuing server 120 based on the SGX quote (step S1003), and receives a response with an attestation status regarding the SGX enclave instance from the confidential processing certificate issuing server 120 (step S1004). The request for a remote attestation may have an SGX quote, and the confidential processing certificate issuing server 120 may authenticate the confidential area 200 (enclave) based on the SGX quote and generate an attestation status according to the authentication result. The attestation status when the authentication result is positive may be an example of a confidential processing certificate. The data server 130 determines from the attestation status whether the authentication result for the confidential area 200 is positive (step S1005). If the authentication result is negative (S1005: No), the data server 130 may interrupt processing. If the authentication result is positive (S1005: Yes), the data cleansing server 110 receives a request for secure tunnel setup from the data server 130, for example by the communication unit (step S1006), and completes the secure tunnel setup, for example by the control unit and the communication unit (step S1007). Subsequently, for example, the data cleansing server 110 receives the data to be visualized from the data server 130 through the secure tunnel, for example by the communication unit (step S1008), generates data for visualization of that data, for example by the control unit, and returns the generated visualization data to the data server 130 through the secure tunnel, for example by the communication unit (step S1009).Subsequently, the data cleansing server 110 receives a request from the data server 130 to deactivate the secure tunnel, for example, via the communications unit (step S1010), and the secure tunnel is dropped, for example, via the control unit and the communications unit (step S1011).

[0123] As described above, data processing can be performed in the secure area 200 only after remote attestation (verification of the integrity of data and software in the secure area 200) has been performed and a secure processing certificate (guarantee of integrity) has been obtained. For example, after remote attestation, the process shown in Figure 5 may be started, or the process shown in Figure 14 or Figure 15 described later may be started. In the processing after remote attestation, steps S1008 and S1009 are just examples of processing depending on the purpose, and other processing may be performed instead of steps S1008 and S1009.

[0124] For example, as shown in Figure 11, steps S1101 and S1102 may be performed instead of steps S1008 and S1009. That is, the data cleansing server 110 receives data for schema estimation from the data server 130 via a secure tunnel, for example by the communication unit (step S1101), estimates the schema based on that data, for example by the control unit, and returns the estimated schema (typically an incomplete schema) to the data server 130 via a secure tunnel, for example by the communication unit (step S1102). The schema estimation by the data cleansing server 110 may be performed based on data obtained from the public information database 160. The data server 130 may display the schema via, for example, the client terminal 140 and accept schema editing requests from the user (step S1103). The schema may be at least some of the rules of the data cleansing rules, or at least some of the rules of the error detection rules. Furthermore, the initial data cleansing rule may be created by the user and stored in the cleansing rule database 221, and subsequent updates to the data cleansing rule may be performed by the automatic cleansing rule update unit 214 or by the user.

[0125] Furthermore, as shown in Figure 12, for example, steps S1201 and S1202 may be performed instead of steps S1008 and S1009. That is, the data cleansing server 110 receives data for verification (e.g., data to be cleansed) and schema (e.g., error detection rules) from the data server 130 via a secure tunnel, for example by the communication unit (step S1201), performs verification (e.g., detection of errors in the data to be cleansed) based on that data and schema, for example by the control unit, and returns the verification results (e.g., error list) to the data server 130 via a secure tunnel, for example by the communication unit (step S1202). The data server 130 may display the verification results via, for example, the client terminal 140, and accept requests from the user to specify or edit rules (e.g., cleansing rules for correcting errors) based on the verification results (step S1203).

[0126] Furthermore, as shown in Figure 13, for example, steps S1301 and S1302 may be performed instead of steps S1008 and S1009. That is, the data cleansing server 110 receives the data to be cleansed and the cleansing rules from the data server 130 via a secure tunnel, for example by the communication unit (step S1301), cleanses the data to be cleansed based on the cleansing rules, and encrypts the cleansed data, for example by the control unit, and returns the cleansed and encrypted data to the data server 130 via a secure tunnel, for example by the communication unit (step S1302). (Automatic generation / update of error detection rules)

[0127] Figure 14 is a flowchart showing an example of the flow of the automatic error detection rule generation / update process performed in the data cleansing system 100.

[0128] In step S1401, the control unit of the data cleansing server 110 executes a process to acquire information from the cloud (for example, the public information database 160) via the communication unit. As a result, information is acquired from the cloud. Once the process in step S1401 is completed, the control unit of the data cleansing server 110 proceeds to step S1402.

[0129] In step S1402, the control unit of the data cleansing server 110 executes a process to move the information acquired in step S1401 to the confidential area 200 of memory 102. This makes it possible to perform various data processing in the confidential area 200 of memory 102 thereafter. Once the processing in step S1402 is completed, the control unit of the data cleansing server 110 proceeds to step S1403.

[0130] In step S1403, the control unit of the data cleansing server 110 executes a process to generate new error detection rules. This process is performed, for example, using a generation AI. This generates new error detection rules. Once the process in step S1403 is complete, the control unit of the data cleansing server 110 proceeds to step S1404. Specifically in step S1403, for example, the control unit of the data cleansing server 110 may compare a first piece of information identified based on information obtained from the public information database 160 (for example, the gender ratio nationwide) with a second piece of information identified based on the cleansing target data (raw data) (for example, the gender ratio in a certain region), and, assuming the first piece of information is correct, identify which piece of the second piece of information may be an error based on the results of the comparison, and generate rules for detecting potentially erroneous information as new error detection rules. The prompt to the generating AI includes a text statement based on the information obtained in step S1401, and a new error detection rule may be obtained as a response to that prompt, or as a result of data processing based on that response.

[0131] In step S1404, the control unit of the data cleansing server 110 executes a process to retrieve existing error detection rules from the error detection rule database. As a result, existing error detection rules are retrieved from the error detection rule database. Once the process in step S1404 is completed, the control unit of the data cleansing server 110 proceeds to step S1405.

[0132] In step S1405, the control unit of the data cleansing server 110 performs a process to merge the error detection rules newly generated in step S1403 with the existing error detection rules acquired in step S1404. As a result, the error detection rules newly generated in step S1403 are merged with the existing error detection rules acquired in step S1404. Once the processing in step S1405 is complete, the control unit of the data cleansing server 110 proceeds to step S1406.

[0133] In step S1406, the control unit of the data cleansing server 110 performs a process to update the error detection rules with the error detection rules merged in step S1405. As a result, the error detection rules are updated with the error detection rules merged in step S1405. Once the process in step S1406 is complete, the control unit of the data cleansing server 110 proceeds to step S1407.

[0134] In step S1407, the control unit of the data cleansing server 110 executes the process of storing the error detection rules updated in step S1406 in the error detection rule database. As a result, the error detection rules updated in step S1406 are stored in the error detection rule database. In this way, the data cleansing system 100 can conceal error detection rules that it does not want to show to other businesses or that may not be desirable to make public, such as when matching medical history, and as a result, data can be cleansed more securely in cloud services. That is, steps S1403 to S1406 are performed in the confidential area 200, and the error detection rule database where the error detection rules are stored may reside in the confidential area 200. When the processing in step S1407 is completed, the control unit of the data cleansing server 110 terminates the automatic generation / update of error detection rules as shown in the flowchart of Figure 14. (Automatic generation / update of noise cleansing rules)

[0135] Figure 15 is a flowchart showing an example of the flow of the automatic noise cleansing rule generation / update process performed in the data cleansing system 100.

[0136] In step S1501, the control unit of the data cleansing server 110 executes a process to acquire information from the cloud (for example, the public information database 160) via the communication unit. As a result, information is acquired from the cloud. Once the process in step S1501 is completed, the control unit of the data cleansing server 110 proceeds to step S1502.

[0137] In step S1502, the control unit of the data cleansing server 110 executes a process to move the information acquired in step S1501 to the confidential area 200 of memory 102. This makes it possible to perform various data processing in the confidential area 200 of memory 102 thereafter. Once the processing in step S1502 is complete, the control unit of the data cleansing server 110 proceeds to step S1503.

[0138] In step S1503, the control unit of the data cleansing server 110 executes a process to generate new data cleansing rules. This process is performed, for example, using a generation AI. This generates new data cleansing rules. Once the process in step S1503 is complete, the control unit of the data cleansing server 110 proceeds to step S1504. Specifically in step S1503, for example, the control unit of the data cleansing server 110 may compare a first piece of information identified based on information obtained from the public information database 160 (for example, the gender ratio nationwide) with a second piece of information identified based on the data to be cleansed (raw data) (for example, the gender ratio in a certain region). Based on the results of this comparison, it may identify which pieces of the second piece of information may be errors, assuming the first piece of information is correct, and generate new data cleansing rules for cleansing the potentially erroneous information into correct information without errors. The prompt to the generating AI may include a text statement based on the information obtained in step S1501, and a new data cleansing rule may be obtained as a response to that prompt, or as a result of data processing based on that response.

[0139] In step S1504, the control unit of the data cleansing server 110 executes a process to retrieve existing data cleansing rules from the cleansing rule database 221. As a result, existing data cleansing rules are retrieved from the cleansing rule database 221. Once the process in step S1504 is complete, the control unit of the data cleansing server 110 proceeds to step S1505.

[0140] In step S1505, the control unit of the data cleansing server 110 performs a process to merge the data cleansing rules newly generated in step S1503 with the existing data cleansing rules acquired in step S1504. As a result, the data cleansing rules newly generated in step S1503 are merged with the existing data cleansing rules acquired in step S1504. Once the processing in step S1505 is complete, the control unit of the data cleansing server 110 proceeds to step S1506.

[0141] In step S1506, the control unit of the data cleansing server 110 performs a process to update the data cleansing rules to the data cleansing rules merged in step S1505. As a result, the data cleansing rules are updated to the data cleansing rules merged in step S1505. Once the processing in step S1506 is complete, the control unit of the data cleansing server 110 proceeds to step S1506.

[0142] In step S1507, the control unit of the data cleansing server 110 executes the process of storing the data cleansing rules updated in step S1506 in the cleansing rule database 221. As a result, the data cleansing rules updated in step S1506 are stored in the cleansing rule database 221. In this way, the data cleansing system 100 can conceal data cleansing rules that may not be desirable to disclose, such as those that should not be shown to other businesses or those related to matching medical history, thereby enabling more secure data cleansing in cloud services. Specifically, steps S1503 to S1506 are performed in the confidential area 200, and the cleansing rule database 221 where the data cleansing rules are stored may reside in the confidential area 200 as shown in Figure 1. When the processing in step S1507 is completed, the control unit of the data cleansing server 110 terminates the automatic generation / update of data cleansing rules as shown in the flowchart of Figure 15.

[0143] The procedures described above are merely examples, and the order and content of the processes may be changed as needed.

[0144] This concludes the explanation of the data cleansing system 100.

[0145] The embodiments of the present invention described above can be summarized as follows, for example. The summary below may include supplementary explanations and descriptions of modified examples to the above description.

[0146] (1) The data cleansing system (e.g., data cleansing system 100) is a data cleansing system, each having a processor and memory (e.g., processor 101 and memory 102), and connected to each other via a network (e.g., network 170) to enable data communication, which retrieves encrypted data via the network, decrypts it, cleanses the decrypted data in a secure area in memory (e.g., secure area 200), encrypts the cleansed data, and outputs it via the network. In this way, the data cleansing system can securely cleanse data in a cloud service. The data cleansing system may be a computer system that provides a cloud service as a data cleansing service, for example, a first service system built in a first cloud environment provided by a first cloud provider, or a system that includes the first service system and also includes (or cooperates with) a second service system in a second cloud environment different from the first cloud environment. The data cleansing system may communicate with a data source system, which is a computer system that serves as the source of encrypted data. The data source system may be, for example, a data server 130 or a client terminal 140. The data server 130 may store raw data from multiple different data owners (e.g., multiple different municipalities). Encrypted data may be retrieved from the data source system. The encrypted data may be encrypted raw data, which is the data before cleansing and may contain some errors (e.g., noise). The output destination of the cleansed and encrypted data may be the data source system of the encrypted data (e.g., data server 130) or a computer system other than the data source system (e.g., client terminal 140).

[0147] (2) At least one of the multiple computers described in (1) analyzes the information obtained via the network in a confidential area and automatically generates and / or updates error detection rules and / or data cleansing rules based on the analysis results. In this way, the data cleansing system 100 can keep these rules confidential if it does not want to show them to other businesses or if there are rules that may not be desirable to make public, such as medical history matching. As a result, the data cleansing system can clean data more securely in cloud services. Encrypted data is decrypted in a confidential area, but in this paragraph, "information obtained via the network" is the information that forms the basis for the automatic generation and / or automatic updating of error detection rules and / or data cleansing rules, and may be, for example, information obtained from a data source system (for example, a system having a public information database 160) that stores publicly available information that is updated as needed. "Error detection rules" may be rules for detecting errors when there are errors in the data decrypted in the confidential area. A "data cleansing rule" may be a rule for cleansing (e.g., correcting or removing) errors detected in data decrypted in a secure area. At least one of multiple computers may analyze information acquired via a network in a secure area, compare the analysis results (e.g., statistics obtained from publicly available information) with the data decrypted in the secure area (e.g., characteristics such as trends represented by the data), and automatically generate and / or update error detection rules based on the results of this comparison. Alternatively, at least one of multiple computers may analyze information acquired via a network in a secure area, compare the analysis results (e.g., statistics obtained from publicly available information) with errors detected in the secure area and the decrypted data containing those errors (e.g., characteristics such as trends represented by the data), and automatically generate and / or update data cleansing rules based on the results of this comparison.

[0148] (3) The data acquired via the network is divided by at least one of the multiple computers described in (1) or (2), and a different confidentiality level is set for each fragment, thereby changing the level of public access to the cleansed data for each fragment. In this way, the data cleansing system 100 can clean data more securely in cloud services by changing the security level for each data owner, even when there are differences in security policies for each data owner. Specifically, for example, the control unit (e.g., data division unit 215) of the data cleansing server 110 may be used as at least one of the multiple computers. The control unit may divide the raw data (data to be cleansed) acquired from the data source system (e.g., data server 130), or the cleansed data in the confidential area, into multiple data fragments (e.g., multiple columns or records). Confidentiality level management data (e.g., confidentiality level database 222), which is data representing the confidentiality level for each data attribute (e.g., data owner or data item), may be stored in the confidential area. The "confidentiality level" may be the degree of anonymization (for example, the number of characters anonymized). The control unit may, for each data fragment (for example, a column or record), identify data attributes that match the data attributes of the data fragment from the confidentiality level management data, identify the confidentiality level corresponding to the identified data attribute, and perform confidentiality processing (for example, anonymization processing) on ​​the data fragment in the confidential area according to the identified confidentiality level. By setting different confidentiality levels for different data attributes, for example, if the cleaned data is data to be made public, the level of public access to the cleaned data can be varied depending on the data fragment.

[0149] It should be noted that the present invention is not limited to the embodiments described above, and can be implemented using any components without departing from the spirit of the invention.

[0150] The embodiments described above are merely examples, and the present invention is not limited to these, provided that the features of the invention are not impaired. Furthermore, although various embodiments have been described above, the present invention is not limited to these, and not all of these are necessarily essential to the solutions provided by the present invention. Other embodiments conceivable within the scope of the technical idea of ​​the present invention are also included within the scope of the present invention.

[0151] In the diagrams above, the control lines and information lines shown are those deemed necessary for explanation and do not necessarily represent all control lines and information lines required for implementation. For example, in reality, it can be assumed that almost all components are interconnected.

[0152] Furthermore, the arrangement of each functional component of the data cleansing system 100 described above is merely an example. The arrangement of each functional component can be changed to the optimal arrangement from the perspective of the performance, processing efficiency, and communication efficiency of the hardware and software of the data cleansing system 100.

[0153] Furthermore, some or all of the configuration, functions, processing units, and processing means of the data cleansing system 100 described above may be implemented in hardware, for example, by designing them as integrated circuits, or they may be implemented in software by having the processor 101 interpret and execute programs that realize each function. Information such as programs, tables, and files that realize each function can be stored in memory 102, a storage device including storage 103 such as a hard disk or SSD, or a recording medium such as an IC card, SD card, or DVD (Digital Versatile Disc). [Explanation of Symbols]

[0154] 100...Data Cleansing System

Claims

1. A data cleansing system that cleanses data, Multiple computers, each having a processor and memory, and connected to each other via a network capable of data communication, Encrypted data is retrieved and decrypted via the network. The cleansing of the decrypted data is performed in a secure area on the memory. The cleansed data is encrypted and output via the network. Data cleansing system.

2. A data cleansing system according to claim 1, A data cleansing system that analyzes information acquired via the aforementioned network in the aforementioned confidential area, and automatically generates and / or updates error detection rules and / or data cleansing rules based on the analysis results.

3. A data cleansing system according to claim 1, A data cleansing system that divides data acquired via the aforementioned network and sets a different level of confidentiality for each fragment, thereby changing the level of public access to the cleansed data for each fragment.

4. A data cleansing device that cleanses data, It consists of at least one computer having a processor and memory, Encrypted data is retrieved from another device via the network and decrypted. The cleansing of the decrypted data is performed in a secure area on the memory. The cleansed data is encrypted and output via the network. Data cleansing device.

5. A data cleansing method for cleansing data, This is performed by multiple computers, each having a processor and memory, and connected to each other via a network capable of data communication. Encrypted data is retrieved and decrypted via the network. The cleansing of the decrypted data is performed in a secure area on the memory. The cleansed data is encrypted and output via the network. Data cleansing methods.

6. In a data cleansing system that cleanses data using multiple computers, each having at least a processor and a memory device, and connected to each other via a network capable of data communication, Encrypted data is retrieved and decrypted via the network. The cleansing of the decrypted data is performed in a secure area on the memory. The cleansed data is encrypted and output via the network. To cause the computer to perform the following: Computer program.

Citation Information

Patent Citations

  • Apparatus and method for data processing

    JP2021039595A