Personal information management program, personal information management method, and user terminal
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
- Filing Date
- 2025-10-27
- Publication Date
- 2026-07-30
AI Technical Summary
【0010】 本開示によれば、複数の事業者の各々から提供されるサービスをまとめて安全に利用できるデジタルウォレットを実現できる。
Smart Images

Figure 2026123769000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a personal information management program, a personal information management method, and a user terminal.
Background Art
[0002] There is a known technology of a digital wallet for a user to safely use services and perform settlements using a user terminal represented by a smartphone. In Patent Document 1, a method of starting a blockchain transaction using a wallet device including a non-temporary processor-readable medium having a memory, a display, an input interface, and a processor communicating with a biosensor, the method including, in the wallet device, receiving a transaction request including an address and an amount from a first computing device, capturing biometric information from the user using the biosensor, generating a bio-vector from the biometric information, comparing the bio-vector with a stored vector to authenticate the user, and signing the transaction request using a private key having a corresponding public key upon authentication.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] There is room for further consideration to realize a digital wallet that can collectively and safely use services provided by each of a plurality of operators.
[0005] The purpose of this disclosure is to provide technology for realizing a digital wallet that enables secure, integrated use of services provided by multiple service providers. [Means for solving the problem]
[0006] One aspect of this disclosure provides a personal information management program that runs on a processor in a user terminal owned by a user, wherein when the user uses a service provided by a business operator, the program obtains user personal information from the memory of the user terminal, which includes at least basic personal information obtained from the user's identification document, the basic personal information includes facial image information which is the user's face image, each piece of information included in the user personal information is designated as personal attribute information, the camera on the user terminal takes a picture of the user's face and obtains captured facial image information, the program verifies whether the captured facial image information is the same person as the facial image information, and if the verification is successful, extracts personal attribute information requested by the service from the user personal information and transmits it to a predetermined service terminal managed by the business operator.
[0007] One aspect of this disclosure is a personal information management method performed on a user terminal owned by a user, wherein when the user uses a service provided by a business operator, the user terminal's memory is used to obtain user personal information, which includes at least basic personal information obtained from the user's identification document, the basic personal information includes facial image information which is the user's face image, each piece of information included in the user personal information is designated as personal attribute information, the user terminal's camera is used to photograph the user's face and obtain captured facial image information, the captured facial image information is compared to the facial image information to determine whether it is the same person, and if the comparison is successful, personal attribute information requested by the service is extracted from the user personal information and transmitted to a predetermined service terminal managed by the business operator.
[0008] One aspect of this disclosure provides a user terminal owned by a user, comprising a processor, memory, and a camera, wherein, when the user uses a service provided by a business operator, the processor acquires user personal information from the memory, which includes at least basic personal information obtained from the user's identification document, the basic personal information includes facial image information which is the user's face image, each piece of information included in the user personal information is designated as personal attribute information, the camera captures the user's face to acquire captured facial image information, the captured facial image information is compared to the facial image information to determine whether it is the same person, and if the comparison is successful, the personal attribute information requested by the service is extracted from the user personal information and transmitted to a predetermined service terminal managed by the business operator.
[0009] These comprehensive or specific embodiments may be implemented as systems, devices, methods, integrated circuits, computer programs, or recording media, or as any combination of systems, devices, methods, integrated circuits, computer programs, and recording media. [Effects of the Invention]
[0010] According to this disclosure, it is possible to realize a digital wallet that allows users to securely utilize services provided by multiple businesses in one place. [Brief explanation of the drawing]
[0011] [Figure 1] This figure shows an example of the hardware configuration of the DIW system according to Embodiment 1. [Figure 2] A diagram showing an example of the functional configuration of the DIW system according to Embodiment 1. [Figure 3] A diagram showing an example configuration of the service master list according to Embodiment 1. [Figure 4] A diagram showing an example of the configuration of a user personal information record according to Embodiment 1. [Figure 5] This figure shows an example configuration of the available service ID list and the agreed-upon service ID list according to Embodiment 1. [Figure 6]Figure showing a configuration example of the integrated personal information master list according to Embodiment 1 [Figure 7] Figure showing a configuration example of the user-linked service list according to Embodiment 1 [Figure 8] Figure showing a configuration example of the personal information provision log according to Embodiment 1 [Figure 9] Sequence diagram showing an example of the process in which a business operator applies for service linkage to a cloud operator according to Embodiment 1 [Figure 10A] Sequence diagram showing an example of the process of registering a user's personal information in the DIW app and the DIW cloud according to Embodiment 1 [Figure 10B] Sequence diagram showing the continuation of the process in Fig. 10A [Figure 11] Figure showing an example of the screen for reading an identity certificate according to Embodiment 1 [Figure 12] Figure showing an example of the input screen for additional personal information according to Embodiment 1 [Figure 13] Sequence diagram showing an example of the process of registering a user's account information in the DIW app and the DIW cloud according to Embodiment 1 [Figure 14] Sequence diagram showing an example of the process of registering a user's personal information in the DIW app and the DIW cloud via an external terminal according to Embodiment 1 [Figure 15] Schematic diagram showing an example of the confirmation screen for the basic personal information of an external terminal according to Embodiment 1 [Figure 16A] Sequence diagram showing the first example of the continuation of the process in Fig. 14 [Figure 16B] Sequence diagram showing the second example of the continuation of the process in Fig. 14 [Figure 17A] Sequence diagram showing an example of the process in which a user registers for using a new service according to Embodiment 1 [Figure 17B] Sequence diagram showing the continuation of the process in Fig. 17A [Figure 18] Figure showing an example of the available service list screen according to Embodiment 1 [Figure 19] Figure showing an example of the consent screen for service linkage according to Embodiment 1 [Figure 20] Sequence diagram showing an example of the process when using the service application of the locally registered regional currency according to Embodiment 2 [Figure 21A] Sequence diagram showing an example of the process when using the vending machine according to Embodiment 2 [Figure 21B] Sequence diagram showing the continuation of the process in Fig. 21A [Figure 22A] Sequence diagram showing an example of the process of performing personal authentication on the evacuation shelter authentication terminal according to Embodiment 2 using the DIW application [Figure 22B] Sequence diagram showing the continuation of the process in Fig. 22A [Figure 23A] Sequence diagram showing an example of the process of performing personal authentication on the evacuation shelter authentication terminal according to Embodiment 2 without using the DIW application [Figure 23B] Sequence diagram showing the continuation of the process in Fig. 23A [Figure 24A] Sequence diagram showing an example of the process of performing personal authentication on the face authentication payment terminal according to Embodiment 2 [Figure 24B] Sequence diagram showing the continuation of the process in Fig. 24A [Figure 25A] Sequence diagram showing an example of the process of reflecting the update of the identity certificate according to Embodiment 3 in the DIW application [Figure 25B] Sequence diagram showing the continuation of the process in Fig. 25A [Figure 26] Diagram for explaining the update of the user's personal information record according to Embodiment 3 [Figure 27A] Sequence diagram showing an example of the process when the availability or unavailability of the service is changed due to the update of the identity certificate according to Embodiment 3 [Figure 27B] Sequence diagram showing the continuation of the process in Fig. 27A [Figure 28] Diagram for explaining the extraction of the service that has become available or unavailable due to the update of the identity certificate according to Embodiment 3 [Figure 29A] Sequence diagram showing an example of the process of updating the service that has become available or unavailable due to the increase in the user's age according to Embodiment 3 [Figure 29B] Sequence diagram showing the continuation of the process in Figure 29A. [Figure 30] A diagram illustrating the process of updating services that have become available or unavailable due to the user's age increasing, according to Embodiment 3. [Figure 31A] Sequence diagram showing an example of processing when a business operator in Embodiment 3 changes (including adding) personal attribute information used for the service. [Figure 31B] Sequence diagram showing the continuation of the process in Figure 31A. [Figure 32] Diagram illustrating the changes to personal attribute information used by a service provider in Embodiment 3. [Figure 33A] Sequence diagram showing an example of the process when personal information of a service application according to Embodiment 3 is changed using a DIW application. [Figure 33B] A sequence diagram showing the continuation of the process shown in Figure 33A. [Figure 34A] Figures 33A and 33B show an example of the first screen of the service application in the process related to the third form of implementation. [Figure 34B] Figures 33A and 33B show examples of the DIW application screen in the process shown in the third embodiment. [Figure 34C] Figure 33A and Figure 33B show a second example screen of the service application in the process shown in the third embodiment. [Figure 35A] Sequence diagram showing an example of the process when a user checks the personal information provision log according to Embodiment 3. [Figure 35B] Sequence diagram showing the continuation of Figure 35A [Figure 36A] Figure 35A and Figure 35B show examples of screens for the DIW application related to the process shown in the third embodiment. [Figure 36B] Figure 36A shows an example of the DIW application screen. [Modes for carrying out the invention]
[0012] Embodiments of the present disclosure will be described in detail below, with appropriate reference to the drawings. However, descriptions that are unnecessarily detailed may be omitted. For example, detailed descriptions of already well-known matters and redundant descriptions of substantially identical configurations may be omitted. This is to avoid the following description becoming unnecessarily verbose and to facilitate understanding for those skilled in the art. The accompanying drawings and the following description are provided to enable those skilled in the art to fully understand the present disclosure and are not intended to limit the subject matter of the claims. The functions of one configuration shown in this embodiment may be realized by two or more physical configurations, or the functions of two or more configurations may be realized by, for example, one physical configuration.
[0013] (Embodiment 1) <Hardware Configuration> Figure 1 shows an example of the hardware configuration of the DIW system 1 according to Embodiment 1. DIW stands for Digital ID Wallet.
[0014] The DIW system 1 comprises a user terminal 10, a DIW cloud 20, a service provider server 30, and a service terminal 40. However, the DIW system 1 may not include all of these devices.
[0015] User terminal 10 is a device used by the user, such as a smartphone, tablet, or notebook PC.
[0016] The user terminal 10 includes, as hardware, a processor 11, memory 12, storage 13, a camera 14, an input device 15, a display device 16, and a communication device 17.
[0017] The processor 11 works in cooperation with the memory 12 to execute a computer program (e.g., DIW application 50) to realize the functions of the user terminal 10 of this disclosure. The processor 11 may be read as a Central Processing Unit (CPU), controller, arithmetic circuit, or control circuit, etc. The processor 11 may also include a Graphics Processing Unit (GPU) and / or a Neural Network Processing Unit (NPU).
[0018] Memory 12 is composed of a volatile storage medium and / or a non-volatile storage medium, and stores computer programs and data, etc.
[0019] The storage 13 is composed of a non-volatile storage medium and stores computer programs and data. Examples of storage 13 include flash memory, solid state drives (SSDs), or hard disk drives (HDDs).
[0020] The camera 14 is equipped with an image sensor, such as a Complementary Metal Oxide Semiconductor (CMOS) image sensor or a Charge Coupled Device (CCD) image sensor, and generates captured images.
[0021] The input device 15 is a device that receives input from the user, and is, for example, a touch panel, touchpad, keyboard, mouse, and / or microphone.
[0022] The display device 16 is a device that displays a screen, and is composed of, for example, a liquid crystal display or an organic EL display.
[0023] The communication device 17 is a device that controls wired communication and / or wireless communication. The communication device 17 supports, for example, Ethernet®, Wi-Fi®, cellular communication (e.g., LTE, 4G, 5G), Bluetooth® Classic, Bluetooth Low Energy (BLE), and / or Near Field Communication (NFC).
[0024] DIW Cloud 20 provides a cloud service for managing DIW. DIW Cloud 20 may consist of one or more server devices. The server devices comprising DIW Cloud 20 include a processor 21, memory 22, storage 23, and communication device 24.
[0025] The processor 21 works in cooperation with the memory 22 to execute a computer program, thereby realizing the functions of the DIW cloud 20 of this disclosure. The processor 21 may be read as a CPU, controller, arithmetic circuit, or control circuit, etc. The processor 21 may also include a GPU and / or NPU.
[0026] Memory 22 is composed of volatile storage media and / or non-volatile storage media, and stores computer programs and data, etc.
[0027] The storage 23 is composed of a non-volatile storage medium and stores computer programs and data, etc. Examples of storage 23 include flash memory, SSD, or HDD.
[0028] The communication device 24 is a device that controls wired communication and / or wireless communication. The communication device 24 supports, for example, Ethernet, Wi-Fi, cellular communication (e.g., LTE, 4G, 5G), Bluetooth Classic, and / or Bluetooth Low Energy (BLE).
[0029] The service provider server 30 is a server managed by the service provider. The service provider server 30 is equipped with the same hardware (e.g., processor and memory) as the server device of the DIW Cloud 20 described above.
[0030] The service terminal 40 is a terminal used when providing services, and is installed and managed by, for example, a service provider. Specific examples of the service terminal 40 will be described later.
[0031] The service terminal 40 includes, as hardware, a processor 41, memory 42, a camera 43, an input device 44, a display device 45, and a communication device 46. However, the service terminal 40 may not include some of these devices.
[0032] The processor 41 works in cooperation with the memory 42 to execute a computer program, thereby realizing the functions of the service terminal 40 of this disclosure. The processor 41 may be read as a CPU, controller, arithmetic circuit, or control circuit, etc. The processor 41 may also include a GPU and / or NPU.
[0033] Memory 42 is composed of volatile storage media and / or non-volatile storage media, and stores computer programs and data, etc.
[0034] The camera 43 is equipped with an image sensor, such as a CMOS image sensor or a CCD image sensor, and generates captured images.
[0035] The input device 44 is a device that receives input from the user, and is, for example, a touch panel, touchpad, keyboard, mouse, and / or microphone.
[0036] The display device 45 is a device that displays a screen, and is composed of, for example, a liquid crystal display or an organic EL display.
[0037] The communication device 46 is a device that controls wired communication and / or wireless communication. The communication device 46 supports, for example, Ethernet, Wi-Fi, cellular communication (e.g., LTE, 4G, 5G), Bluetooth Classic, and / or Bluetooth Low Energy (BLE). The communication device 46 may also support Near Field Communication (NFC).
[0038] The user terminal 10, the DIW cloud 20, the service provider server 30, and the service terminal 40 may send and receive information from each other via a predetermined communication network 5. However, the service terminal 40 may not be connected to the communication network 5. Examples of the communication network 5 include wired LAN, wireless LAN, the internet, or a cellular network (mobile communication network).
[0039] The user terminal 10 may establish wireless communication (e.g., short-range wireless communication) with the service terminal 40, for example, using BLE or NFC.
[0040] <Functional Configuration> Figure 2 is a diagram showing an example of the functional configuration of the DIW system 1 according to Embodiment 1.
[0041] <User terminal functions> Users can install and run the DIW app 50 and the service app 70 on their user terminal 10. The service app 70 controls and manages the provision of personal information to services provided by each service provider. The service app 70 may differ for each service (or each service provider). In other words, multiple service apps 70 may be installed on the user terminal 10. The DIW app 50 provides functions for securely using services provided by multiple service providers in a unified manner. Next, the functions of the DIW app 50 will be described.
[0042] The DIW application 50 has the following functions: a service master list acquisition unit 51, a user personal information acquisition unit 52, an available service extraction unit 53, a service usage condition output unit 54, a collaboration consent acquisition unit 55, a face matching unit 56, a request reception unit 57, a provided information extraction unit 58, a log output unit 59, and a data management unit 60.
[0043] The service master list acquisition unit 51 acquires service master list 100A from DIW Cloud 20 and stores it in the data management unit 60 as service master list 100B. Service master lists 100A and 100B are lists of services provided by each service provider. Service master lists 100A and 100B register services from service providers whose integration has been approved by the operator of DIW Cloud 20.
[0044] The User Personal Information Acquisition Unit 52 acquires personal information from the user's identification document and manages this personal information securely in conjunction with DIW Cloud 20. Hereinafter, the personal information acquired from the user's identification document will be referred to as basic personal information. Furthermore, the User Personal Information Acquisition Unit 52 acquires and manages additional personal information from the user for information that is missing from the personal information acquired from the identification document (for example, the phonetic spelling of the name). Hereinafter, the personal information acquired additionally from the user will be referred to as additional personal information. Furthermore, the User Personal Information Acquisition Unit 52 manages some of the information from the basic personal information or additional personal information (for example, information extracted only from the city or town of the address), or information identified based on the basic personal information or additional personal information (for example, age calculated based on the date of birth), as specific personal information. Hereinafter, basic personal information, additional personal information, and specific personal information may be collectively referred to as personal information. In addition, each item included in personal information may be referred to as personal attribute information.
[0045] This embodiment describes the case where the identification document is a My Number Card. However, the identification document can be any document that can obtain personal information, such as a driver's license, residence card, or passport.
[0046] The available service extraction unit 53 extracts services available to the user from the service master list 100B and generates an available service ID list 120.
[0047] The service usage conditions output unit 54 refers to the service master list 100B and displays the conditions under which a user can use the service on the screen (for example, the display device 16 of the user terminal 10).
[0048] The integration consent acquisition unit 55 obtains consent from the user regarding whether or not it is permissible to integrate the services provided by the business operator with the DIW app 50. The integration consent acquisition unit 55 obtains the service-specific user ID, which is a user ID dedicated to the service that the user has consented to integrate with the DIW app 50, from the DIW cloud 20 and registers it in the consented service ID list 130.
[0049] The face matching unit 56 compares the face image information captured by the camera 14 with the face image information recorded in the user's personal information record 110 to determine whether they belong to the same person. This face image information is obtained from an identification document. This matching may be performed using publicly known face matching technology.
[0050] The request reception unit 57 receives requests for personal information from the service application 70 or service terminal 40 when the service is used.
[0051] The information extraction unit 58 extracts personal attribute information provided at the time of consent to linkage or when using the service, and outputs it to the service application 70 or service terminal 40.
[0052] The log output unit 59 identifies the services to which personal information was provided during the initial connection or when using the service, and sends this identified information as a log to the DIW Cloud 20. The DIW Cloud 20 receives this log and stores it as a personal information provision log 220. This allows the DIW Cloud 20 to manage which personal attribute information of which user was provided to which service or business operator as a personal information provision log 220.
[0053] The data management unit 60 manages the data used by the DIW application 50. The data management unit 60 may manage the service master list 100B, user personal information records 110, the available service ID list 120, and the consented service ID list 130. These lists and records will now be described.
[0054] <Service Master List> Figure 3 shows an example configuration of service master lists 100A and 100B according to Embodiment 1.
[0055] Service master lists 100A and 100B are lists of services provided by businesses that have already integrated with DIW Cloud 20. Service master list 100A may be managed by DIW Cloud 20. DIW app 50 may, if necessary, retrieve service master list 100A from DIW Cloud 20 and retain it as service master list 100B.
[0056] Service master lists 100A and 100B include the following items: Service ID, Service Name, Business ID, Terms of Use, Personal Attribute Information Required by the Service, Service Usage Conditions, Service Integration Date, and Service Period.
[0057] The Service ID is an ID that uniquely identifies a service. The Service Name is the name of the service corresponding to the Service ID. The Service Provider ID is an ID that uniquely identifies the service provider that provides the service corresponding to the Service ID. If one service provider provides one service, one Service ID is associated with one Service Provider ID. If one service provider provides multiple services, multiple Service IDs may be associated with one Service Provider ID.
[0058] The Terms of Service outline the rules that users must follow when using the service corresponding to the Service ID. The Terms of Service may also be a file containing the Terms of Service or a URL.
[0059] The personal attribute information requested by a service refers to the personal attribute information required to use the service corresponding to the service ID. For example, if a service requires "name" and "address," then "name" and "address" will be set as the personal attribute information requested by the service.
[0060] The service usage conditions indicate the conditions that must be met to use the service corresponding to the service ID. For example, for a service provided only to residents of Adachi Ward, the service usage condition would be "the user's address is in Adachi Ward." For example, for a service provided only to those 20 years of age or older, the service usage condition would be "the user is 20 years of age or older." For example, for a service provided only to those under 20 years of age, the service usage condition would be "the user is under 20 years of age." Multiple conditions may be set for the service usage conditions.
[0061] The service integration date indicates the date on which the service provider integrated (registered) the service corresponding to the service ID with DIW Cloud 20, or the date on which the integration was updated.
[0062] The service period indicates the period during which the service corresponding to the service ID is provided. The service period may include a start date and time and an end date and time.
[0063] <User Personal Information Record> Figure 4 shows an example of the configuration of a user personal information record 110 according to Embodiment 1.
[0064] The user personal information record 110 stores basic personal information obtained from the user's identification document, additional personal information entered by the user, and specific personal information of the user generated by the DIW application 50 based on the basic personal information and / or additional personal information, all associated with the user's user ID. The user personal information record 110 is stored in the data management unit 60 of the DIW application 50.
[0065] The user ID is an ID used to uniquely identify a user and is assigned by DIW Cloud 20.
[0066] The basic personal information obtained from the user's identification document includes name, address, date of birth, gender, and facial image information. The facial image information is an image of the user's face taken when the identification document was created or renewed. If the identification document is a My Number Card, the basic personal information can be obtained from the IC chip of the My Number Card.
[0067] Additional personal information may include information that is insufficient with basic personal information when using the service. Examples of additional personal information include, but are not limited to, the phonetic spelling of the last name, the phonetic spelling of the first name, mobile phone number, email address, and password.
[0068] Specific personal information refers to information that is frequently requested when using a service, for example, and is pre-extracted or calculated. Specific personal information includes, for example, age, a flag indicating 20 years of age or older, and information extracted only from the city / town portion of the address. However, the information included in specific personal information is not limited to these.
[0069] <List of available service IDs and list of agreed-upon service IDs> Figure 5 shows an example of the configuration of the available service ID list 120 and the agreed-upon service ID list 130 according to Embodiment 1.
[0070] The Available Service ID List 120 lists the availability of services for each user. The Available Service ID List 120 includes the service ID and the availability status as its items.
[0071] The Service ID indicates the Service ID registered in Service Master Lists 100A and 100B. Availability indicates whether the user can use the service corresponding to the Service ID.
[0072] For example, if the personal attribute information in the user personal information record 110 satisfies the service usage conditions corresponding to the service ID in the service master list 100B, the DIW app 50 will set the availability of the service ID in the available service ID list 120 to "available". For example, if the personal attribute information in the user personal information record 110 does not satisfy the service usage conditions corresponding to the service ID in the service master list 100B, the DIW app 50 will set the availability of the service ID in the available service ID list 120 to "unavailable".
[0073] Furthermore, services corresponding to service IDs in the available service ID list 120 that are marked as "available" may be displayed on the display device 16 of the user terminal 10 as selectable services.
[0074] The List of Consent Service IDs 130 is a list extracted from the List of Available Service IDs 120 that shows whether or not the user has consented to providing personal information to those services. The List of Consent Service IDs 130 has the following items: Service ID, User ID for the service, and Consent Status.
[0075] The service IDs are extracted from the list of 120 available service IDs, specifically those that are "available".
[0076] The user ID for a service is a user ID assigned exclusively for the service indicated by the service ID. In the present embodiment, instead of using a common user ID, a unique user ID for each service is generated and used. The user ID for a service may be generated based on the user ID assigned to the user. For example, DIW Cloud 20 may generate a user ID for a service by converting the combination of the service ID and the user ID into a hash value. Thereby, even for the same user, different user IDs for services can be used for each service, so that it is possible to prevent personal information from being used based on the user ID across multiple services.
[0077] The consent status indicates whether the user has consented to providing personal information, etc. to the service (business operator) corresponding to the service ID. Note that when the consent status is "none", even if the business operator can conditionally provide the service to the user, the service cannot be provided to the user. That is, the user cannot use the service.
[0078] <Functions of DIW Cloud> Return to the description of FIG. 2. DIW Cloud 20 collaborates with DIW App 50 to control and manage the provision of personal information for the services provided by each business operator. DIW Cloud 20 may be operated by a predetermined business operator different from the business operator providing the service. Hereinafter, the business operator operating DIW Cloud 20 may be referred to as the cloud operator.
[0079] As functions, DIW Cloud 20 includes a service confirmation unit 81, a service master list management unit 82, an ID generation unit 83, an integrated personal information master list management unit 84, a user-linked service list management unit 85, a face verification unit 86, a request reception unit 87, a provided information extraction and output unit 88, and a personal information provision log management unit 89.
[0080] The service verification unit 81 verifies the services provided by the service provider. For example, the service verification unit 81 verifies the terms of service for the service and the personal attribute information requested by the service. This verification may be performed automatically by the service verification unit 81 or manually by the cloud operator.
[0081] The Service Master List Management Unit 82 generates, updates, and manages the Service Master List 100A, which is a list of services provided by businesses that have already linked with DIW Cloud 20.
[0082] The ID generation unit 83 generates a user ID corresponding to the user. The ID generation unit 83 also generates a service-specific user ID corresponding to each service that the user has agreed to link with.
[0083] The Integrated Personal Information Master List Management Unit 84 generates, updates, and manages the Integrated Personal Information Master List 200, which is created by integrating the user personal information records 110 of each user.
[0084] The User-Linked Service List Management Unit 85 generates, updates, and stores the User-Linked Service List 210, which is a list of services that each user has agreed to link.
[0085] The face matching unit 86 checks whether the face image information of the user captured by the camera 43 of the user terminal 10 exists in the integrated personal information master list 200 as the face image information of the same person. In other words, the face matching unit 86 performs a one-to-many (N is an integer greater than or equal to 1) match between the captured face image information and multiple face image information in the integrated personal information master list 200.
[0086] The request reception unit 87 receives requests for personal information from the service application 70 or service terminal 40 when the service is used.
[0087] The information extraction and output unit 88 extracts personal information used when consenting to link or when using the service, and outputs it to the service application 70 or service terminal 40.
[0088] The Personal Information Provision Log Management Department 89 is responsible for generating, updating, and storing the Personal Information Provision Log 220.
[0089] <Integrated Personal Information Master List> Figure 6 shows an example of the configuration of the integrated personal information master list 200 according to Embodiment 1.
[0090] The Integrated Personal Information Master List 200 is a list compiled by integrating the user personal information records 110 for each user. The Integrated Personal Information Master List 200 is managed by DIW Cloud 20.
[0091] Since the items in the Integrated Personal Information Master List 200 are the same as the items in the User Personal Information Record 110, the explanation is omitted.
[0092] <List of services linked to the user> Figure 7 shows an example of the configuration of the user-linked service list 210 according to Embodiment 1.
[0093] The User-Linked Services List 210 is a list of services that the user has agreed to link with the DIW app 50. The User-Linked Services List 210 is managed by the DIW Cloud 20.
[0094] The user-linked service list 210 includes the following items: user ID, service provider ID, service ID, service-specific user ID, linking date and time, provided information, and linking information.
[0095] In the User-Linked Services List 210, the service provider ID and service ID corresponding to the services that the user has agreed to link are associated with each user ID. Furthermore, the User-Linked Services List 210 also associates the service-specific user ID uniquely assigned to each agreed-upon service ID.
[0096] The linking date and time indicates the date and time when the user with the user ID consented to linking with the service corresponding to the service ID. The provided information indicates the personal attribute information provided (used) by the service corresponding to the service ID. The linking information indicates whether the service corresponding to the service ID is already linked or has been unlinked.
[0097] <Personal Information Provision Log> Figure 8 shows an example of the configuration of the personal information provision log 220 according to Embodiment 1.
[0098] Personal Information Provision Log 220 is a log that records the services to which personal information was provided. Personal Information Provision Log 220 is managed by DIW Cloud 20.
[0099] The personal information provision log 220 includes the following items: user ID, business ID, service ID, service-specific user ID, service name, service usage date and time, and provided information.
[0100] In the personal information provision log 220, the user ID is associated with the business ID, service ID, service-specific user ID, and service name to which the user's personal information was provided.
[0101] The "Service Usage Date and Time" indicates the date and time the user used the service. The "Provided Information" indicates the personal attribute information provided by the user when they used the service.
[0102] DIW Cloud 20, through its personal information provision log 220, can manage which users used which services from which businesses, when, and what personal attribute information was provided when using those services.
[0103] <Process for a business operator to apply for service integration with a cloud provider> Figure 9 is a sequence diagram showing an example of the process by which a business operator in Embodiment 1 applies to a cloud operator for service integration.
[0104] The service provider applies for service integration with DIW Cloud 20 through the service provider server 30 (S101). For example, the service provider applies for service integration from a web page provided by DIW Cloud 20.
[0105] Upon receiving the application in step S101, DIW Cloud 20 requests detailed information about the linked service (hereinafter referred to as "service details") from the service provider server 30. The service provider server 30 receives this request (S102).
[0106] The service provider server 30 sends detailed service information for the linked services to the DIW cloud 20. The DIW cloud 20 receives the detailed service information (S103). The detailed service information includes the service terms of use and service usage conditions. These service usage conditions correspond to the service usage conditions in the service master lists 100A and 100B shown in Figure 3.
[0107] DIW Cloud 20 reviews whether to approve the integration of the service based on the service details (S104). This review may be performed manually by the cloud operator (staff) or automatically by DIW Cloud 20 according to predetermined rules.
[0108] If DIW Cloud 20 determines in the review in step S104 to approve the integration of the service (S105: YES), it sends a review result indicating approval of the service integration to the service provider server 30 (S106). However, if DIW Cloud 20 determines in the review in step S104 not to approve the integration of the service (S105: NO), it may send a review result indicating rejection of the service integration to the service provider server 30 (S107). In this case, this process terminates.
[0109] The service provider server 30 receives the review result in step S106, which approves the service integration, and submits a service integration contract application to the DIW cloud 20 (S108). Then, the service provider and the cloud operator conclude a service integration contract (S109).
[0110] The service provider server 30 sends a request to the DIW cloud 20 to configure the service details of the linked service. The DIW cloud 20 receives the request (S110).
[0111] DIW Cloud 20 registers the received service details and other information in the service master list 100A (S111). As a result, the linked services are registered in the service master list 100A. The service details may include the service terms of use and service usage conditions provided at the time of application for service linkage (S101), and may also include additional information (for example, a detailed description of the service).
[0112] DIW Cloud 20 sends a notification of completion of integration to the service provider server 30 (S112).
[0113] DIW Cloud 20 sends the newly linked service details to DIW App 50. DIW App 50 receives this information (S113).
[0114] The DIW app 50 registers the received service details into the service master list 100B (S114). As a result, the newly linked services are added and updated in both the service master list 100A of the DIW cloud 20 and the service master list 100B of the DIW app 50.
[0115] The DIW app 50 may display the details of the newly linked services on the screen (for example, the display device 45 of the user terminal 10) (S115). This allows the user to learn about the newly available services.
[0116] Through the above process, the service newly provided by the service provider and approved by the cloud operator will be registered (i.e., linked) to the DIW Cloud 20 service master list 100A.
[0117] <Process of registering users' personal information in the DIW app and DIW cloud> Figure 10A is a sequence diagram showing an example of the process of registering the user's personal information in the DIW app 50 and DIW cloud 20 according to Embodiment 1. Figure 10B is a sequence diagram showing the continuation of the process in Figure 10A. Figure 11 is a diagram showing an example of the identity document reading screen according to Embodiment 1. Figure 12 is a diagram showing an example of the additional personal information input screen according to Embodiment 1.
[0118] DIW Cloud 20 already possesses service master list 100A.
[0119] When a user launches the DIW app 50 for the first time (S201), the DIW app 50 displays the terms of service screen (S202).
[0120] Once the user agrees to the terms of service (S203), the DIW app 50 displays the identity document reading screen shown in Figure 11(a) (S204).
[0121] The DIW app 50 reads basic personal information from the identification document provided by the user (S205). For example, if the identification document is a My Number Card, the DIW app 50 reads four pieces of basic personal information (address, name, date of birth, gender) and facial image information from the IC chip of the My Number Card. At this time, the DIW app 50 may ask the user to enter the My Number Card verification number B, as shown in Figure 11(b). The verification number B is a 14-digit number consisting of the date of birth (6 digits), expiration date (4 digits), and security code (4 digits) printed on the My Number Card. Using the verification number B, the DIW app 50 can read the four pieces of information and facial image information from the IC chip of the My Number Card. If the identification document is a driver's license, the DIW app 50 may ask the user to enter the PIN set for the driver's license.
[0122] The DIW app 50 captures the user's face with the camera 14 of the user terminal 10 (S206) and obtains the captured face image information (S207).
[0123] The DIW app 50 compares the facial image information read from the identification document in step S205 with the captured facial image information obtained in step S207 to determine whether they belong to the same person (S208). In other words, the DIW app 50 determines whether the user who took the photo is the person on the identification document. This facial matching can be implemented using publicly known technology, and subsequent facial matching can be implemented in the same way.
[0124] If the DIW app 50 fails to perform the matching in step S208 (S209: NO), it displays a screen indicating the matching failure and prompting the user to retake the image (S210). Then, the process returns to step S206.
[0125] If the DIW app 50 succeeds in the matching in step S208 (S209: YES), it displays "matching successful" and the acquired personal information on the screen (S211).
[0126] The DIW app 50 displays an input screen for additional personal information, as shown in Figure 12 (S212). As mentioned above, the input screen for additional personal information is a screen for users to enter personal information that cannot be obtained from identification documents.
[0127] The user enters additional personal information on the additional personal information input screen. For example, as shown in Figure 12, the user enters their last name (phonetic spelling), first name (phonetic spelling), mobile phone number, email address, and password as additional personal information. The DIW app 50 retrieves the entered additional personal information (S213).
[0128] The DIW app 50 extracts or calculates specific personal information of the user based on basic personal information obtained from identification documents (S214). Examples of specific personal information include the user's age calculated from the date of birth in the basic personal information, and the address extracted from the basic personal information, such as the city or town.
[0129] The DIW app 50 integrates the basic personal information (including facial image information) obtained from the identification document, the additional personal information entered by the user, and the specific personal information extracted in step S214 to generate a user personal information record 110, which is stored in the data management unit 60 (S215).
[0130] The DIW application 50 requests the DIW cloud 20 to assign a user ID to the user. The DIW cloud 20 receives the request (S216).
[0131] DIW Cloud 20 generates a user ID for the user in response to the request in step S216 (S217).
[0132] The DIW Cloud 20 sends the generated user ID to the DIW app 50. The DIW app 50 receives the user ID (S218).
[0133] The DIW application 50 associates the received user ID with the user personal information record 110 generated in step S215 (S219). This generates a user personal information record 110 as shown in Figure 4.
[0134] The DIW app 50 sends the user personal information record 110 from step S219 to the DIW cloud 20. The DIW cloud 20 receives the user personal information record 110 (S220).
[0135] DIW Cloud 20 adds the received user personal information record 110 to the integrated personal information master list 200 (S221).
[0136] As a result of the above process, a user personal information record 110 for a new user of the DIW app 50 is added to the integrated personal information master list 200 managed by DIW Cloud 20.
[0137] <Example of a process for registering user account information in the DIW app and DIW cloud> Figure 13 is a sequence diagram showing an example of the process of registering user account information in the DIW app and DIW cloud according to Embodiment 1.
[0138] The user installs the DIW application 50 on the user terminal 10 and launches the DIW application 50 (S231).
[0139] The DIW app 50 displays the account settings screen (S232).
[0140] The user enters their account information on the account settings screen of the DIW app 50 (S233). The account information may include an email address and password.
[0141] The DIW app 50 sends an account creation request containing the entered account information to the DIW cloud 20 (S234).
[0142] The DIW Cloud 20 receives an account creation request and sets and registers the account information included in the request (S235). Then, the DIW Cloud 20 sends an account creation completion notification to the DIW app 50 (S236).
[0143] The DIW app 50 receives an account creation completion notification and displays the account creation completion screen (S237).
[0144] Through the above process, the user's account information is registered in the DIW app 50 and DIW Cloud 20.
[0145] <Example of a process for registering user personal information in the DIW app and DIW cloud via an external terminal> Figure 10A illustrates how to read basic personal information from an identification document using the DIW app 50, while Figures 14 to 16B below illustrate how to read basic personal information from an identification document via an external terminal 401. The external terminal 401 may be installed in, for example, a car dealership, a real estate agency, or a city hall, and may be a device on the side of the store or facility. An employee of the store or facility may have the user use the external terminal 401 while interacting with the user face-to-face. Alternatively, there may be no employee at the store or facility, and the user may use the external terminal 401 themselves. The configuration of the external terminal 401 may be the same as that of the service terminal 40, or it may be composed of, for example, a PC and a camera.
[0146] Figure 14 is a sequence diagram showing an example of the process of registering a user's personal information to the DIW application 50 and DIW cloud 20 via the external terminal 401 according to Embodiment 1. Figure 15 is a schematic diagram showing an example of the basic personal information confirmation screen of the external terminal 401 according to Embodiment 1.
[0147] The user visits the store or facility (S240) and operates the external terminal 401 to select the menu for reading identification documents (S241).
[0148] Upon receiving the selection in step S241, the external terminal 401 displays the identity document reading screen (S242).
[0149] The external terminal 401 reads basic personal information, including facial image information, from the identification document provided by the user and stores it in its internal memory (S243). The reading method is the same as in step S205 in Figure 10A. Note that the identification document is not limited to a card type. For example, if the user terminal 10's OS stores the identification document information, the external terminal 401 may read the basic personal information from the user terminal 10 and store it in its internal memory.
[0150] The external terminal 401 captures the user's face with its camera (S244) and acquires the captured face image information (S245). Then, the external terminal 401 performs face matching processing in the same manner as steps S208 to S210 in Figure 10A (S246).
[0151] If the external terminal 401 succeeds in the face matching process, it displays a confirmation screen of the basic personal information read in step S243 and stored in its internal memory on the display device (S247), as illustrated in Figure 15. As shown in Figure 15, the confirmation screen may display the acquired basic four pieces of information and face image information. However, to prevent a third party from peeking at and illegally obtaining the basic personal information displayed on the confirmation screen, the external terminal 401 does not have to display the confirmation screen. This process then proceeds to either Figure 16A or Figure 16B. Which process proceeds from Figure 16A or Figure 16B may be determined by the configuration of the DIW system 1.
[0152] Figure 16A is a sequence diagram showing the first example of the continuation of the process in Figure 14.
[0153] If the user confirms that there are no problems after viewing the basic personal information confirmation screen displayed in step S247 of Figure 14, they perform an operation to instruct the external terminal 401 to register the basic personal information (S250).
[0154] Upon receiving the registration instruction in step S250, the external terminal 401 generates and displays a two-dimensional code containing the basic personal information read in step S243 (S251). The two-dimensional code may include basic four-person information and facial image information. Alternatively, the two-dimensional code may include basic four-person information and facial feature quantities from which facial image information can be obtained.
[0155] The user launches the DIW application 50 (S252). If the DIW application 50 is not installed on the user terminal 10, the user may install the DIW application 50 by performing the process shown in Figure 13 above before step S252.
[0156] The DIW app 50 reads the two-dimensional code displayed on the external terminal 401 via the camera 14 (S253).
[0157] The DIW app 50 obtains basic personal information, including facial image information, from the scanned QR code (S254). This allows the DIW app 50 to obtain basic personal information, including facial image information, from the user's identification document read by the external terminal 401.
[0158] When the user has finished acquiring basic personal information using the DIW app 50, they perform a completion command operation on the external terminal 401 (S255).
[0159] Upon receiving the completion instruction for step S255, the external terminal 401 deletes the basic personal information read in step S243 from its memory (S256). Even if the external terminal 401 does not receive the completion instruction for step S255 from the user, it may delete the basic personal information from its internal memory after a certain period of time has elapsed. This prevents the basic personal information from remaining on the external terminal 401.
[0160] Then, the user, the DIW application 50, and the DIW cloud 20 execute the processes from steps S211 to S221 in Figure 10B.
[0161] Through the above process, users can register their personal information with the DIW app 50 and DIW cloud 20 via the external terminal 401.
[0162] In step S251, instead of displaying a two-dimensional code, the external terminal 401 may establish wireless communication with the user terminal 10 (DIW application 50) and transmit basic personal information to the DIW application 50 via this wireless communication. The DIW application 50 may then acquire the basic personal information via wireless communication. The wireless communication may be NFC, Bluetooth®, or Direct Wi-Fi, etc. In this case, after acquiring the basic personal information, the DIW application 50 may send a completion notification to the external terminal 401, and upon receiving this completion notification, the external terminal 401 may delete the basic personal information from its internal memory.
[0163] Figure 16B is a sequence diagram showing a second example of the process continuing from Figure 14.
[0164] If the user confirms that there are no problems after viewing the basic personal information confirmation screen displayed in step S247 of Figure 14, they perform an operation to instruct the external terminal 401 to register the basic personal information (S261).
[0165] Upon receiving the registration instruction in step S261, the external terminal 401 sends a URL creation request and the basic personal information read in step S243 to the designated server 402 (S261). The external terminal 401 may also include the basic personal information in the URL creation request. The server 402 only needs to be connected to the communication network 5. Alternatively, the DIW cloud 20 may be used as the server 402.
[0166] Server 402 receives the request in step S261, temporarily stores the basic personal information, and creates a URL to retrieve the said basic personal information (S262).
[0167] Server 402 sends the URL created in step S262 to external terminal 401 (S263).
[0168] The external terminal 401 receives the URL in step S263, generates and displays a two-dimensional code containing the information of the URL (S264).
[0169] The user launches the DIW application 50 (S265). If the DIW application 50 is not installed on the user terminal 10, the user may install the DIW application 50 by performing the process shown in Figure 13 above before step S265.
[0170] The DIW app 50 reads the two-dimensional code displayed on the external terminal 401 via the camera 14 (S256).
[0171] The DIW app 50 accesses the URL contained in the scanned QR code (S267).
[0172] Upon receiving the access request, server 402 sends the temporarily stored basic personal information to the DIW application (S268). After sending the basic personal information to the DIW application 50, server 402 sends a completion notification to the external terminal 401 (S269). Then, server 402 deletes the temporarily stored basic personal information (S270). This prevents the basic personal information from remaining on server 402.
[0173] The DIW app 50 receives the basic personal information transmitted in step S268 (S271). This allows the DIW app 50 to obtain the basic personal information, including the facial image information of the user's identification document read by the external terminal 401.
[0174] Then, the user, the DIW application 50, and the DIW cloud 20 execute the processes from steps S211 to S221 in Figure 10B.
[0175] Through the above process, users can register their personal information with the DIW app 50 and DIW cloud 20 via the external terminal 401.
[0176] Alternatively, instead of sending the URL to the external terminal 401 in step S263, server 402 may send an email containing the URL to the user terminal 10 (DIW application 50). The DIW application 50 may then access the URL contained in the received email and obtain basic personal information from server 402.
[0177] <Process for users to register for a new service> Figure 17A is a sequence diagram showing an example of the process by which a user registers for a new service according to Embodiment 1. Figure 17B is a sequence diagram showing the continuation of the process in Figure 17A. Figure 18 is a diagram showing an example of the available services list screen according to Embodiment 1. Figure 19 is a diagram showing an example of the service linkage consent screen according to Embodiment 1.
[0178] When the DIW app 50 receives a request from the user to display a list of new services (S301), it begins the following process:
[0179] The DIW application 50 extracts (or filters) services available to the user from the service master list 100B based on the user personal information record 110 (S302). For example, the DIW application 50 extracts (filters) services that meet the service usage conditions of the service master list 100B based on the attribute personal information of the user personal information record 110 as available services.
[0180] The DIW app 50 generates a list of available service IDs 120 from the list extracted in step S302 (S303).
[0181] As shown in Figure 18, the DIW app 50 displays the contents of the available service ID list 120 (e.g., service name, etc.) from step S303 on the screen (S304).
[0182] From the screen in step S304, the user selects a new service to register for (link) (S305).
[0183] The DIW app 50 displays a screen (S306) asking whether the user consents to provide the service provider of the service selected in step S305 with the personal attribute information requested by that service from the user's personal information record 110. At this time, as shown in Figure 19(a), the DIW app 50 displays personal attribute information that is required to be provided and personal attribute information that is optional to be provided, and the user may optionally select which personal attribute information to provide.
[0184] If the user agrees, they select "Agree" from the screen in step S306 (S307).
[0185] If "Agree" is selected in step S307, the DIW app 50 takes a picture of the user's face with the camera 14 of the user terminal 10 (S308) and acquires the captured face image information (S309). At this time, when the DIW app 50 takes a picture of the user's face, it may display a screen prompting the user to place their face within a predetermined frame, as shown in Figure 19(b).
[0186] The DIW app 50 compares the facial image information in the user personal information record 110 with the captured facial image information obtained in step S309 to determine whether they belong to the same person (S310). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0187] If the DIW app 50 fails to perform the matching in step S310 (S311: NO), it displays a screen prompting for matching failure and / or reshooting (S312). Then, the process returns to step S308.
[0188] If the DIW app 50 succeeds in the matching in step S310 (S311: YES), it sends a request to the DIW cloud 20 for the assignment of a user ID for the service. The DIW cloud 20 receives the request (S313). The request may include the user's user ID and the service ID of the new service to be registered, which was selected in step S305 and agreed to by the user.
[0189] In response to the request received in step S313, DIW Cloud 20 generates a service-specific user ID for the newly registered service (S314).
[0190] DIW Cloud 20 sends the generated service user ID to DIW App 50. DIW App 50 receives the service user ID (S315).
[0191] The DIW app 50 associates the service ID of the newly registered service with the service user ID for that service and registers it in the list of agreed-upon service IDs 130 (S316).
[0192] The DIW application 50 extracts personal information to be provided to the service provider of the newly registered service from the user's personal information record 110 (hereinafter referred to as "provided personal information") (S317).
[0193] The DIW app 50 transmits the personal information extracted in step S316 and the user ID for the service to the service app 70 of the service to be newly registered (S318).
[0194] The service application 70 receives and stores the personal information provided in step S318 and the user ID for the service (S319). This allows the service application 70 to use the personal information provided by the user (e.g., address, age, etc.) and the user ID for the service.
[0195] The DIW app 50 transmits the information of the business operator that provided the personal information, along with the provided personal information, to the DIW cloud 20 (S320), and displays a completion screen for service registration (S321).
[0196] DIW Cloud 20 receives information about the business operator that provided the personal information in step S320, as well as the provided personal information, and stores it in the personal information provision log 220 (S322).
[0197] DIW Cloud 20 adds rows to the user-linked service list 210 for newly registered user IDs, business IDs, service IDs, and service-specific user IDs (S323).
[0198] Through the above processing, the service application 70 can retain the personal attribute information necessary for using the service and the service-specific user ID assigned to that service. In addition, the DIW cloud 20 can manage information about services that the user newly registers for as a user-linked service list 210.
[0199] Note that the processing in steps S308 to S312 may be executed immediately after step S305.
[0200] (Embodiment 2) Embodiment 2 describes several examples of how a user utilizes linked services after the processing described in Embodiment 1. Note that the contents of Embodiment 1 may be incorporated into Embodiment 2. Furthermore, in Embodiment 2, components already described in Embodiment 1 are given common reference numbers, and their descriptions may be omitted.
[0201] <Processing when using a local currency service app> Figure 20 is a sequence diagram showing an example of the process when using the registered local currency service application 70 according to Embodiment 2.
[0202] The user launches the local currency service app 70 (S401).
[0203] The service app 70 displays a list of service items related to the use of local currency on the screen (S402).
[0204] The user selects a service item, for example, the local currency charge service item, from the list of service items displayed in step S402 (S403). At this time, the user may also enter the charge amount.
[0205] The service application 70 sends a facial recognition request to the DIW application 50. The DIW application 50 receives the facial recognition request (S404). The facial recognition request may include the business ID of the business providing the local currency service and the service ID of the service selected in step S403 (local currency service).
[0206] The DIW app 50 captures the user's face with the camera 14 of the user terminal 10 (S405) and obtains the captured face image information (S406).
[0207] The DIW app 50 compares the facial image information in the user personal information record 110 with the captured facial image information obtained in step S406 to determine whether they belong to the same person (S407). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0208] If the DIW app 50 fails to perform the matching in step S407 (S408: NO), it displays a screen prompting for matching failure and / or reshooting (S409). Then, the process returns to step S405.
[0209] If the DIW app 50 succeeds in matching in step S407 (S408: YES), it sends a facial recognition success notification to the DIW cloud 20. The DIW cloud 20 receives the facial recognition success notification (S410). The facial recognition success notification may include the business ID of the local currency service provider, the service ID of the local currency service selected in step S403, and the service user ID for the selected service.
[0210] DIW Cloud 20 registers the contents of the facial recognition success notification received in step S409 in the personal information provision log 220 (S411). As a result, information about the service for which personal information was provided is registered in the personal information provision log 220.
[0211] Furthermore, if the DIW app 50 succeeds in the matching in step S407 (S408: YES), it sends a facial recognition success response to the service app 70 (S412). The facial recognition success response may include the user's personal attribute information obtained from the user personal information record 110.
[0212] The service application 70 receives a response indicating successful facial recognition in step S412 and sends a request for local currency charge to the electronic money issuing server 91. This request may include the charge amount. The electronic money issuing server 91 receives the request (S413).
[0213] In response to the request in step S413, the electronic money issuing server 91 sends a local currency charge instruction to the service application 70 (S414). The local currency charge instruction may include the charge amount.
[0214] The service app 70 receives the regional currency charge instruction in step S414 and charges the amount (S415). At this time, the service app 70 may display a charge completion screen.
[0215] This allows users to use local currency through the local currency service app 70. Furthermore, the service app 70 can prevent third parties from arbitrarily charging local currency by receiving a response from the DIW app 50 confirming successful facial recognition and then charging the local currency.
[0216] The above example described the process of topping up local currency, but similar procedures may be followed when using local currency or sending it to others. Furthermore, local currency is just one example; the above content also applies to various types of electronic money and points.
[0217] <Processing when using a vending machine> Figure 21A is a sequence diagram showing an example of the process when using the vending machine 92 according to Embodiment 2. Figure 21B is a sequence diagram showing the continuation of the process in Figure 21A. The vending machine 92 is an example of the service terminal 40 shown in Figures 1 and 2.
[0218] When a user begins using the vending machine 92 (S501), the vending machine 92 displays a two-dimensional code (for example, a QR code (registered trademark)) (S502). The two-dimensional code contains information indicating the business ID of the business operator managing the vending machine 92, the service ID of the service provided by the vending machine 92, and the device ID that identifies the vending machine 92. Note that the two-dimensional code is just an example; any image containing information will suffice.
[0219] The user launches the DIW app 50 (S503). The DIW app 50 uses the camera 14 of the user terminal 10 to read the two-dimensional code displayed in step S502 (S504).
[0220] The DIW app 50 establishes wireless communication (e.g., BLE) with the vending machine 92 (S505).
[0221] The DIW app 50 obtains the business ID, service ID, and device ID of the vending machine 92 from the information contained in the two-dimensional code read in step S504 (S506).
[0222] The DIW app 50 captures the user's face with the camera 14 of the user terminal 10 (S507) and obtains the captured face image information (S508).
[0223] The DIW app 50 compares the facial image information in the user personal information record 110 with the captured facial image information obtained in step S508 to determine whether they belong to the same person (S509). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0224] If the DIW app 50 fails to perform the matching in step S509 (S510: NO), it displays a screen prompting the user to retake the image due to the matching failure (S511). The DIW app 50 then terminates the process or returns to the process in step S507.
[0225] If the DIW app 50 succeeds in the matching in step S509 (S510: YES), it extracts specific personal information from the user personal information record 110 based on the service ID row obtained in step S506 of the service master list 100B (S512). For example, if the service usage conditions in the service ID row obtained in step S506 of the service master list 100B include an age condition, the DIW app 50 extracts specific personal information including the user's age from the user personal information record 110.
[0226] The DIW app 50 transmits a service request, including the result of the successful matching and the user's specific personal information extracted in step S512, to the vending machine 92 via the wireless communication established in step S505 (S513).
[0227] The vending machine 92 receives the service request in step S513 and displays the result of the successful matching and the acquired specific personal information (S514).
[0228] The vending machine 92 determines whether a user is eligible to use the service based on specific personal information (S515). For example, if the service usage condition is that the user must be 20 years of age or older, the vending machine 92 determines that the user is eligible to use the service if the age indicated by the specific personal information is 20 years of age or older, and that the user is ineligible to use the service if the age indicated by the specific personal information is under 20 years of age.
[0229] If the vending machine 92 determines in step S515 that the service is unavailable (S516: NO), it displays a screen indicating that the service is unavailable (S517) and terminates this process.
[0230] If the vending machine 92 determines in step S515 that the service is available (S516: YES), it provides the user with the service (for example, a product that can be purchased by someone 20 years of age or older) (S518).
[0231] Furthermore, if the vending machine 92 determines in step S515 that the service is available (S516: YES), it transmits service provision information to the service provider server 30 (S519). The service provision information may include the device ID and the details of the service provided (for example, information about the products provided to the user).
[0232] The service provider server 30 receives the service provision information in step S519 and manages the contents of that service provision information (S520). This allows the service provider server 30 to manage which service (product) was provided from which vending machine 92.
[0233] Furthermore, if the vending machine 92 determines in step S515 that the service is available (S516: YES), it sends a service availability response to the DIW application 50 (S521).
[0234] The DIW app 50 receives the response from step S521 and displays a screen indicating that the service is available (S522).
[0235] The DIW app 50 transmits service usage information to the DIW cloud 20 (S523). The service usage information may include the business ID of the vending machine 92 and specific personal information (or personal attribute information) provided to the vending machine 92.
[0236] DIW Cloud 20 receives the service usage information in step S523 and stores its contents in the personal information provision log 220 (S524). This allows DIW Cloud 20 to manage which specific personal information (or personal attribute information) it has provided to which business operator. In addition, users can check the personal attribute information they have provided to business operators by referring to the information stored in the personal information provision log 220 through the DIW app 50.
[0237] Through the above process, the vending machine 92 can verify the user's personal attribute information (e.g., age) through the DIW app 50 and determine whether or not to provide the service depending on whether the personal attribute information meets the service usage conditions.
[0238] <Processing when using an evacuation center authentication terminal (Example 1)> Figure 22A is a sequence diagram showing an example of the process of performing personal authentication using the DIW application 50 on the evacuation center authentication terminal 93 according to Embodiment 2. Figure 22B is a sequence diagram showing the continuation of the process in Figure 22A. The evacuation center authentication terminal 93 is an example of the service terminal 40 shown in Figures 1 and 2. Figures 22A and 22B describe the case in which the evacuation center authentication terminal 93 does not have a camera 43 and authentication function.
[0239] When a user begins using the evacuation center authentication terminal 93 installed at the evacuation center (S601), the evacuation center authentication terminal 93 displays a two-dimensional code (S602). The two-dimensional code contains information indicating the business ID of the local government managing the evacuation center authentication terminal 93, the service ID corresponding to this evacuation, and the device ID that identifies the evacuation center authentication terminal 93. Note that the two-dimensional code is just an example; any image containing the information will suffice.
[0240] The user launches the DIW app 50 (S603). The DIW app 50 uses the camera 14 of the user terminal 10 to read the two-dimensional code displayed in step S602 (S604).
[0241] The DIW app 50 uses the communication settings information read from the two-dimensional code to establish wireless communication (e.g., BLE) with the evacuation center authentication terminal 93 (S605).
[0242] The DIW app 50 obtains the business ID, service ID, and device ID of the evacuation center authentication terminal 93 from the information contained in the two-dimensional code read in step S604 (S606).
[0243] The DIW app 50 captures the user's face with the camera 14 of the user terminal 10 (S607) and obtains the captured face image information (S608).
[0244] The DIW app 50 compares the facial image information in the user personal information record 110 with the captured facial image information obtained in step S608 to determine whether they belong to the same person (S609). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0245] If the DIW app 50 fails to perform the matching in step S609 (S610: NO), it displays a screen prompting the user to retake the image due to the matching failure (S611). The DIW app 50 then terminates the process or returns to the process in step S607.
[0246] If the DIW app 50 succeeds in the verification in step S609 (S610: YES), it sends the verification success result to the evacuation center authentication terminal 93 (S612).
[0247] The evacuation center authentication terminal 93 receives the verification success result from step S612 and displays the verification success result (S613).
[0248] The evacuation center authentication terminal 93 sends a request for the user's personal attribute information to the DIW application 50 (S614). This request may include the business ID, service ID, and device ID.
[0249] The DIW app 50 receives the request in step S614 and extracts at least some personal attribute information (e.g., name and address, etc.) from the user personal information record 110 based on the service ID row obtained in step S606 of the service master list 100B (S615).
[0250] The DIW app 50 transmits the user's personal attribute information and evacuation shelter admission information to the evacuation shelter authentication terminal 93 (S616). The evacuation shelter admission information may include the business ID and device ID.
[0251] The evacuation shelter authentication terminal 93 receives the information in step S616 and displays a screen for guiding entry into the evacuation shelter (S617). The evacuation shelter authentication terminal 93 provides services related to evacuation to the user (S618).
[0252] If the communication network is unavailable due to a disaster or the like, the process ends here once, and the following processes may be performed after the communication network is restored.
[0253] The DIW application 50 transmits service usage information to the DIW cloud 20 (S619). The service usage information may include the business operator ID and the device ID. <00009Figure 23A is a sequence diagram showing an example of a process for performing personal authentication on the evacuation center authentication terminal 93 according to Embodiment 2 without using the DIW application 50. Figure 23B is a sequence diagram showing the continuation of the process in Figure 23A. The evacuation center authentication terminal 93 is an example of the service terminal 40 shown in Figures 1 and 2. Figures 23A and 23B describe a case in which the evacuation center authentication terminal 93 has a camera 43 and does not have an authentication function.
[0259] When a user begins using the evacuation center authentication terminal 93 installed at the evacuation center (S701), the evacuation center authentication terminal 93 displays a screen prompting facial recognition (S702).
[0260] The evacuation center authentication terminal 93 captures the user's face with the camera 43 (S703) and acquires the captured facial image information (S704).
[0261] The evacuation center authentication terminal 93 sends a face matching request to the DIW cloud 20 (S705). The face matching request may include the captured face image information obtained in step S704, the business ID of the local government managing the evacuation center authentication terminal 93, the service ID corresponding to this evacuation, and the device ID that identifies the evacuation center authentication terminal 93.
[0262] DIW Cloud 20 receives the face matching request in step S705 and matches the captured face image information included in the face matching request with the face image information of all users included in the integrated personal information master list 200 (i.e., a one-to-many match) (S706). In other words, DIW Cloud 20 determines whether or not the same person as the captured face image information exists in the integrated personal information master list 200.
[0263] In step S706, if the captured facial image information fails to match with any of the facial image information in the integrated personal information master list 200 (i.e., if the one-to-many matching fails) (S707: NO), the DIW Cloud 20 displays a screen indicating the matching failure on the evacuation center authentication terminal 93 (S708). Then, the DIW Cloud 20 terminates this process or returns to step S703.
[0264] In step S706, if the captured facial image information is successfully matched with one facial image information in the integrated personal information master list 200 (i.e., if a one-to-many match is successful) (S707: YES), the DIW Cloud 20 transmits the match success result to the evacuation center authentication terminal 93 (S709).
[0265] The evacuation center authentication terminal 93 receives the verification success result from step S708 and displays a screen indicating that the verification success result and the user's personal information will be used (S710).
[0266] The evacuation center authentication terminal 93 sends a request for the user's personal information to the DIW cloud 20 (S711). This request may include the business ID, service ID, and device ID.
[0267] The DIW Cloud 20 receives the request in step S711 and extracts at least some of the personal attribute information (e.g., name and address) of the user who succeeded in the matching in step S707 from the Integrated Personal Information Master List 200 (S712).
[0268] The DIW cloud 20 sends a response to the request in step S711 to the evacuation center authentication terminal 93 (S713). This response may include at least some of the user's personal attribute information extracted in step S712, as well as the business ID, service ID, and device ID.
[0269] DIW Cloud 20 stores the response content and authentication result from step S713 in the personal information provision log 220 (S714).
[0270] The evacuation center authentication terminal 93 receives the response in step S713 and transmits the user's personal attribute information and evacuation center admission information to the service provider server 30 managed by the local government (S715). The evacuation center admission information may include the service provider ID and the device ID.
[0271] The evacuation shelter authentication terminal 93 displays a screen for guiding people into the evacuation shelter (S716).
[0272] The operator server 30 receives the information in step S715, and holds and manages it (S717). The operator server 30 creates an evacuation shelter list indicating which person is present in which evacuation shelter based on the information in step S714 (S718).
[0273] Through the above processing, the local government can manage which person has taken shelter in which evacuation shelter.
[0274] <Processing when using the face authentication payment terminal> FIG. 24A is a sequence diagram showing an example of a process for performing personal authentication on the face authentication payment terminal 94 according to the second embodiment. FIG. 24B is a sequence diagram showing the continuation of the process of FIG. 24A. The face authentication payment terminal 94 is an example of the service terminal 40 shown in FIG. 1. In FIGS. 24A and 24B, a case where the face authentication payment terminal 94 has a camera 43 and an authentication function will be described.
[0275] When the user starts using the face authentication payment terminal 94 (S801), the face authentication payment terminal 94 displays a screen prompting the user to read the two-dimensional code with the DIW app 50 together with the two-dimensional code. Note that the two-dimensional code is an example, and any image containing information may be used.
[0276] The user starts the DIW app 50 and reads the two-dimensional code in step S802 with the camera 14 of the user terminal 10 (S803).
[0277] The DIW app 50 establishes wireless communication (for example, BLE) with the face authentication payment terminal 94 using the communication setting information read from the two-dimensional code (S804).
[0278] The face authentication payment terminal 94 transmits a request for face image information to the DIW app 50 through the wireless communication (S805).
[0279] The DIW app 50 receives the request in step S805 and obtains consent from the user to provide facial image information (S806).
[0280] The DIW app 50 extracts facial image information from the user's personal information record 110 (S807).
[0281] The DIW app 50 transmits the facial image information extracted in step S807 to the facial recognition payment terminal 94. The facial recognition payment terminal 94 receives the facial image information (S808).
[0282] The facial recognition payment terminal 94 captures the user's face with the camera 43 (S809) and acquires the captured facial image information (S810).
[0283] The facial recognition payment terminal 94 checks whether the facial image information received in step S808 and the captured facial image information acquired in step S809 belong to the same person (S811). In other words, the facial recognition payment terminal 94 determines whether the user captured by the camera 43 is the person whose facial image information was provided by the DIW app 50.
[0284] If the facial recognition payment terminal 94 fails to perform the verification in step S811 (S812: NO), it displays a screen indicating that the facial verification failed (S813). The facial recognition payment terminal 94 then terminates the process or returns to step S809.
[0285] If the facial recognition payment terminal 94 succeeds in matching in step S811 (S812: YES), it displays a screen indicating that facial matching was successful (S814).
[0286] The facial recognition payment terminal 94 sends a request for the user's personal information to the DIW app 50 (S815). This request may include the business ID, service ID, and terminal ID.
[0287] The DIW app 50 receives the request in step S814 and extracts the user's specific personal information from the user personal information record 110 (S816). This specific personal information includes the user's age.
[0288] The DIW app 50 transmits the specific personal information extracted in step S816 to the facial recognition payment terminal 94 (S817).
[0289] The DIW app 50 also sends the contents of step S817 to the DIW cloud 20 (S818). The DIW cloud 20 receives the contents and stores them in the personal information provision log 220 (S819).
[0290] The facial recognition payment terminal 94 receives the specific personal information in step S817 and determines whether the user is eligible to make a payment based on that specific personal information (S820). For example, if the age included in the specific personal information is under 20 years old, the facial recognition payment terminal 94 determines that payment is not possible, and if the age included in the specific personal information is 20 years old or older, it determines that payment is possible.
[0291] If the facial recognition payment terminal 94 determines in step S820 that payment is not possible (S821: NO), it displays a screen indicating that payment is not possible (S822) and terminates this process.
[0292] If the facial recognition payment terminal 94 determines in step S820 that payment is possible (S821: YSE), it sends a payment processing request to the business server 30 (S823).
[0293] The service provider server 30 receives the request in step S823 and processes the payment (S824). The service provider server 30 sends a payment completion response to the facial recognition payment terminal 94 (S825).
[0294] The facial recognition payment terminal 94 transmits service provision information to the service provider server 30 (S826). The service provision information may include a payment terminal ID that identifies the facial recognition payment terminal 94 and the details of the service provided.
[0295] The service provider server 30 receives the service provision information in step S826 and manages the service provision information (S827).
[0296] Through the above process, the facial recognition payment terminal 94 can determine whether or not to approve a payment based on the user's specific personal information (or personal attribute information) provided from the DIW app 50.
[0297] Furthermore, the following are examples of users utilizing linked services: (1) The Silver Pass (an example of the Service App 70) works in conjunction with the DIW App 50 to verify the user's identity, and if the identity verification is successful, discounts and other benefits will be applied. (2) The library pass available to the user (an example of the service app 70) is linked with the DIW app 50 to verify the user's identity, and if the identity verification is successful, the user can reserve, borrow, or return books. (3) The bank pass (an example of the service app 70) works in conjunction with the DIW app 50 to verify the user's identity. If the identity verification is successful, the bank will open an account or perform other procedures. (4) Online services will verify the user's identity in conjunction with the DIW app 50. If the verification is successful, online payment, deposit, reservation, or member registration will be performed. (5) The monitoring service works in conjunction with the DIW app 50 to verify the parent's identity. If the parent's identity is verified, the service provides information about the elderly person's family and children. In other words, the monitoring service can be used.
[0298] (Embodiment 3) Embodiment 3 describes the processing that takes place when personal information is changed after the processing described in Embodiment 1. Note that the contents of Embodiments 1 and 2 may be incorporated into Embodiment 3. Furthermore, in Embodiment 3, components already described in Embodiment 1 may be given common reference numbers, and their descriptions may be omitted.
[0299] <Process to reflect updated identification documents in the DIW app> Figure 25A is a sequence diagram showing an example of the process of reflecting the update of the identification document according to Embodiment 3 in the DIW application 50. Figure 25B is a sequence diagram showing the continuation of the process in Figure 25A. Figure 26 is a diagram for explaining the update of the user personal information record 110 according to Embodiment 3.
[0300] The user launches the DIW app 50 (S1001) and instructs the DIW app 50 to update the identification document (S1002).
[0301] DIW app 50 displays the terms of service screen (S1003).
[0302] Once the user agrees to the terms of service (S1004), the DIW app 50 displays a screen for reading the identification document (see Figure 11) (S1005).
[0303] The DIW app 50 reads basic personal information from the updated identification document provided by the user (S1006). The reading method is the same as in step S205 in Figure 10A.
[0304] The DIW app 50 captures the user's face with the camera 14 of the user terminal 10 (S1007) and obtains the captured face image information (S1008).
[0305] The DIW app 50 checks whether the facial image information read from the updated identification document in step S1006 and the captured facial image information obtained in step S1008 belong to the same person (S1009). In other words, the DIW app 50 determines whether the user whose face was photographed is the person on the updated identification document.
[0306] If the DIW app 50 fails to perform the matching in step S1009 (S1010: NO), it displays a screen prompting for matching failure and / or reshooting (S1011), and returns to step S1007.
[0307] If the DIW app 50 succeeds in the matching in step S1009 (S1010: YES), it displays "matching successful" and the basic personal information obtained in step S1006 on the screen (S1012).
[0308] The DIW app 50 displays a screen for entering additional personal information (see Figure 12) (S1013).
[0309] The user enters additional personal information on the additional personal information input screen. The DIW app 50 also displays previously entered additional personal information on the additional personal information input screen, and the user may update only the parts that need updating. The DIW app 50 then retrieves the entered additional personal information (S1014).
[0310] The DIW app 50 extracts or calculates the user's specific personal information based on the basic personal information obtained from the identification document (S1015).
[0311] The DIW app 50 reintegrates the basic personal information (including facial image information) obtained from the updated identification document, the additional personal information entered (modified) by the user, and the specific personal information extracted in step S1015, and updates the user personal information record 110 held in the data management unit 60 (S1016). As a result, the contents of the updated identification document are reflected in the user personal information record 110.
[0312] For example, if a user's surname changes due to marriage or other reasons, as shown in Figure 26, the name in the basic personal information of the user's personal information record 110 will be updated from "Yamada" to "Yamamoto," and the phonetic spelling of the surname in the additional personal information will be updated from "Yamada" to "Yamamoto." For example, if a user moves from "Adachi Ward, Tokyo" to "Shinagawa Ward, Tokyo," as shown in Figure 26, the address in the basic personal information of the user's personal information record 110 will be updated from "Adachi Ward, Tokyo" to "Shinagawa Ward, Tokyo," and accordingly, the residential area in the specific personal information will be updated from "Adachi Ward" to "Shinagawa Ward."
[0313] The DIW app 50 sends the user personal information record 110, which was updated in step S1015, along with the user ID to the DIW cloud 20 (S1017).
[0314] DIW Cloud 20 receives the updated user personal information record 110 and user ID, and updates the row in the integrated personal information master list 200 corresponding to the user ID with the contents of the updated user personal information record 110 (S1018).
[0315] Through the above process, when an identity document is updated, the updated information can be reflected in the user personal information record 110 of the DIW app 50 and the integrated personal information master list 200 of the DIW cloud 20.
[0316] <Handling of cases where service availability changes due to updating identification documents> Figure 27A is a sequence diagram showing an example of the process when the availability or unavailability of a service changes due to the renewal of an identification document according to Embodiment 3. Figure 27B is a sequence diagram showing the continuation of the process in Figure 27A. Figure 28 is a diagram for explaining the extraction of services that have become available or unavailable due to the renewal of an identification document according to Embodiment 3.
[0317] The DIW application 50 retrieves the service master list 100A from the DIW cloud 20 and stores it in the data management unit 60 as the service master list 100B (S1101).
[0318] Based on the user's personal information record 110, the DIW app 50 extracts (or filters) the services available to the user from the service master list 100B obtained in step S1101 (S1102).
[0319] The DIW app 50 generates a list of available service IDs 120 from the list extracted in step S1102 (S1103).
[0320] The DIW app 50 displays the contents of the available service ID list 120 from step S1103 on the screen (S1104). At this time, if there are any services that have become unavailable, the DIW app 50 may display those services as unavailable on the screen.
[0321] For example, if a user moves from "Adachi Ward" to "Shinagawa Ward," as shown in Figure 28, services in "Adachi Ward" become unavailable, while services in "Shinagawa Ward" become available. In this case, in step S1104, services in "Shinagawa Ward" are displayed as available services, and services in "Adachi Ward" are displayed as unavailable services. Services that remain available before and after the move are also displayed.
[0322] Furthermore, if the user agrees to unlink the Adachi Ward service that has become unavailable (for example, if the user presses the unlink button on the screen displaying the unavailable service and the user's face is successfully verified), the following process may be performed. Specifically, the DIW app 50 sends a request to unlink the unavailable service to the DIW cloud 20. The DIW cloud 20 receives the request to unlink and sends a request to the business server 30 managed by Adachi Ward to dispose of the user's personal information. The business server 30 receives the disposal request and disposes of the user's personal information. After disposal, the business server 30 sends a notification of completion of unlinking to the DIW cloud 20, and if the DIW cloud 20 receives the notification of completion of unlinking, it may send the notification of completion of unlinking to the DIW app 50. When the DIW app 50 receives the notification that the unlinking process has been completed, it may display on the screen that the unlinking process has been completed for the service to which the user agreed to unlink (i.e., that the service provider (Adachi Ward) has disposed of the user's personal information). This allows the user to confirm that the personal information they provided to a service has been disposed of if that service becomes unavailable.
[0323] The user looks at the screen displayed in step S1104 and selects the service they wish to register for (S1105).
[0324] The DIW app 50 displays a screen (S1106) asking whether the user consents to provide the service provider of the service selected in step S1105 with the personal attribute information requested by that service in the user's user personal information record 110.
[0325] If the user agrees, they select "Agree" from the screen in step S1106 (S1107).
[0326] If "Agree" is selected in step S1107, the DIW app 50 takes a picture of the user's face with the camera 14 of the user terminal 10 (S1108) and obtains the captured face image information (S1109).
[0327] The DIW app 50 compares the facial image information in the user personal information record 110 with the captured facial image information obtained in step S1109 to determine whether they belong to the same person (S1110). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0328] If the DIW app 50 fails to perform the matching in step S1110 (S1111: NO), it displays a screen prompting the user to retake the image due to the matching failure (S1112). The process then returns to step S1108.
[0329] If the DIW app 50 succeeds in the matching in step S1110 (S1111: YES), it extracts the updated personal attribute information to be provided from the updated user personal information record 110 (S1113).
[0330] The DIW app 50 sends the updated personal attribute information extracted in step S1113 to the service app 70 of the service that the user wants to register for (S1114). This allows the service app 70 to use the user's updated personal attribute information (e.g., address, age, etc.).
[0331] The DIW app 50 sends the information of the business operator that provided the updated personal attribute information, along with the updated personal attribute information, to the DIW cloud 20 (S1115). Then, the DIW app 50 displays that registration is complete (S1116).
[0332] The service app 70 receives the updated personal attribute information from step S1114 and updates the personal information it holds (S1117).
[0333] DIW Cloud 20 receives the updated personal attribute information from step S1115 and stores it in the personal information provision log 220 (S1118).
[0334] DIW Cloud 20 updates the user-linked service list 210 with the received updated personal attribute information (S1119).
[0335] Through the above process, users can recognize which services have become available or unavailable due to the renewal of their identification document, and register for new services as needed.
[0336] <Process to update services that have become available or unavailable due to the user's age increase> Figure 29A is a sequence diagram showing an example of the process of updating services that have become available or unavailable due to the user's age increasing, according to Embodiment 3. Figure 29B is a sequence diagram showing the continuation of the process in Figure 29A. Figure 30 is a diagram illustrating the process of updating services that have become available or unavailable due to the user's age increasing, according to Embodiment 3.
[0337] The process shown in Figure 29A may be started when the DIW Cloud 20 checks checkpoints such as age conditions in a daily batch or similar manner and detects a status change (age update in this embodiment).
[0338] The DIW application 50 retrieves the service master list 100A from the DIW cloud 20 and stores it in the data management unit 60 as the service master list 100B (S1201).
[0339] Based on the user's personal information record 110, the DIW app 50 extracts (or filters) the services available to the user from the service master list 100B obtained in step S1201 (S1202).
[0340] The DIW app 50 generates a list of available service IDs 120 from the list extracted in step S1202 (S1203).
[0341] The DIW app 50 displays the contents of the available service ID list 120 from step S1203 on the screen (S1204). At this time, if there are any services that have become unavailable, the DIW app 50 may display those services as unavailable on the screen. For example, if the user's age increases from 19 to 20, as shown in Figure 30, services for users under 20 become unavailable, and services for users 20 and over become available. In this case, in step S1204, services for users 20 and over are displayed as available services, and services for users under 20 are displayed as unavailable services. Services that remain available regardless of age are also displayed.
[0342] If any services become unavailable, the DIW app 50 sends a request to the DIW cloud 20 to unlink the unavailable services, after obtaining the user's consent (S1205). At this time, the DIW app 50 performs facial recognition of the user, and if the facial recognition is successful, it may unlink the services, assuming that the user's consent has been obtained.
[0343] When DIW Cloud 20 receives a request to unlink in step S1205, it unlinks the service from the user-linked service list 210 (S1206). At this time, DIW Cloud 20 sends a request to the service provider server 30 of the service provider that provides the service that has become unavailable to dispose of the user's personal information. The service provider server 30 receives the disposal request and disposes of the user's personal information. After disposal, the service provider server 30 sends a notification of completion of unlinking to DIW Cloud 20, and if DIW Cloud 20 receives the notification of completion of unlinking, it may send the notification to DIW App 50. If DIW App 50 receives the notification of completion of unlinking, it may display on the screen that the unlinking has been completed for the service that the user agreed to unlink (i.e., that the service provider has disposed of the user's personal information). This allows the user to confirm that the personal information they provided to a service has been disposed of when the service becomes unavailable.
[0344] The user looks at the screen displayed in step S1204 and selects the service they wish to register for from the newly available services (S1207).
[0345] The DIW app 50 displays a screen (S1208) asking whether the user consents to provide the service provider of the service selected in step S1207 with the personal attribute information requested by that service in the user's user personal information record 110.
[0346] If the user agrees, they select "Agree" from the screen in step S1208 (S1209).
[0347] If "Agree" is selected in step S1209, the DIW app 50 takes a picture of the user's face with the camera 14 of the user terminal 10 (S1210) and obtains the captured face image information (S1211).
[0348] The DIW app 50 compares the facial image information in the user personal information record 110 with the captured facial image information obtained in step S1211 to determine whether they belong to the same person (S1212). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0349] If the DIW app 50 fails to perform the matching in step S1212 (S1213: NO), it displays a screen prompting the user to retake the image due to the matching failure (S1214). The process then returns to step S1210.
[0350] If the DIW app 50 succeeds in the matching in step S1212 (S1213: YES), it extracts the updated personal attribute information to be provided from the updated user personal information record 110 (S1215).
[0351] The DIW app 50 sends the updated personal attribute information extracted in step S1215 to the service app 70 of the service that the user wants to register for (S1216). This allows the service app 70 to use the user's updated personal attribute information (e.g., address, age, etc.).
[0352] The DIW app 50 transmits the information of the business operator that provided the updated personal attribute information, along with the updated personal information provided, to the DIW cloud 20 (S1217). Then, the DIW app 50 displays a message indicating that registration is complete (S1218).
[0353] The service application 70 receives the updated personal attribute information from step S1216 and updates the personal information with the updated personal attribute information (S1219).
[0354] DIW Cloud 20 receives the updated personal attribute information from step S1216 and stores it in the personal information provision log 220 (S1220).
[0355] DIW Cloud 20 updates the user-linked service list 210 with the updated personal attribute information received (S1221).
[0356] Through the above process, users can recognize which services have become available or unavailable due to their age, and register for new services as needed.
[0357] <Handling of cases where a service provider changes personal attribute information used for providing services> Figure 31A is a sequence diagram showing an example of the process when a business operator according to Embodiment 3 changes (including additions) personal attribute information used for the service. Figure 31B is a sequence diagram showing the continuation of the process in Figure 31A. Figure 32 is a diagram for explaining the change of personal attribute information used for the service by a business operator according to Embodiment 3.
[0358] The service provider server 30 determines the modified personal attribute information to be used for the service, the purpose of use, and the terms of use (S1301). For example, as shown in Figure 32, the service provider changes the service to newly use "age," which is one of the personal attribute information (or specific personal information).
[0359] The service provider server 30 transmits the information determined in step S1301 to the DIW cloud 20. The DIW cloud 20 receives this information and obtains the modified personal attribute information, purpose of use, and terms of use, etc., to be used for service provision (S1302).
[0360] DIW Cloud 20 transmits the modified personal attribute information, purpose of use, and terms of use, etc., obtained in step S1302, to DIW App 50 (S1303).
[0361] The DIW app 50 receives the information from step S1403 and, based on that information, displays a screen for consenting to the purpose of use and terms of service (S1304).
[0362] The user views the screen in step S1304 and enters "Agree" if they wish to continue using the service (S1305). If the user does not wish to continue using the service and enters "Disagree," the DIW app 50 may coordinate with the DIW cloud 20, etc., to cancel the user's registration for the service.
[0363] If "Agree" is entered in step S1305, the DIW app 50 displays a screen (S1306) asking whether the user agrees to provide the service provider with the modified personal attribute information used for the service. For example, as shown in Figure 32, if "age," which is one of the personal attribute information (or specific personal information), is to be newly used for the service, the DIW app 50 displays a screen in step S1306 asking whether the user agrees to provide the service provider with the new "age" information.
[0364] If the user agrees, they select "Agree" from the screen in step S1306 (S1307).
[0365] If "Agree" is selected in step S1307, the DIW app 50 takes a picture of the user's face with the camera 14 of the user terminal 10 (S1308) and obtains the captured face image information (S1309).
[0366] The DIW app 50 compares the facial image information in the user personal information record 110 with the captured facial image information obtained in step S1310 to determine whether they belong to the same person (S1310). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0367] If the DIW app 50 fails to perform the matching in step S1310 (S1311: NO), it displays a screen prompting the user to retake the image due to the matching failure (S1312). The process then returns to step S1308.
[0368] If the DIW app 50 succeeds in matching in step S1310 (S1311: YES), it extracts the modified personal attribute information to be provided from the user personal information record 110 (S1313).
[0369] The DIW app 50 sends the modified personal attribute information extracted in step S1313 to the service app 70, which has changed the personal attribute information it uses (S1314). This allows the service app 70 to use the modified personal attribute information. The modified personal attribute information sent in step S1314 may include only the changed parts (only the differences). For example, if only the surname has been changed, the modified personal attribute information may include only the changed "full name" and "surname phonetic spelling". For example, if only the "address" has been changed, the modified personal attribute information may include only the changed "address". Alternatively, the modified personal attribute information sent in step S1314 may include all of the changed and unchanged parts.
[0370] The DIW app 50 sends the information of the business operator that provided the modified personal attribute information, along with the modified personal attribute information, to the DIW cloud 20 (S1315). The DIW app 50 then displays that the modification is complete (S1316). The modified personal information sent in step S1314 may also include only the modified parts, or it may include all parts, both modified and unchanged, as described above.
[0371] The service application 70 receives the modified personal attribute information from step S1314 and updates the personal information with the modified personal attribute information (S1317).
[0372] DIW Cloud 20 receives the modified personal attribute information from step S1315 and stores it in the personal information provision log 220 (S1318).
[0373] DIW Cloud 20 updates the user-linked service list 210 with the received updated personal attribute information (S1319).
[0374] Through the above process, if a service provider changes the personal attribute information used for the service, they can obtain the user's consent, provide the user's updated personal attribute information to the service application 70, and manage it in the DIW Cloud 20.
[0375] <Processing when changing personal information in a service app using the DIW app> Figure 33A is a sequence diagram showing an example of the process when personal information of the service application 70 according to Embodiment 3 is changed using the DIW application 50. Figure 33B is a sequence diagram showing the continuation of the process shown in Figure 33A. Figure 34A is a diagram showing a first example screen of the service application 70 in the process shown in Figures 33A and 33B according to Embodiment 3. Figure 34B is a diagram showing a screen example of the DIW application 50 in the process shown in Figures 33A and 33B according to Embodiment 3. Figure 34C is a diagram showing a second example screen of the service application 70 in the process shown in Figures 33A and 33B according to Embodiment 3.
[0376] The user selects menu 301 for the personal attribute information to be changed from the screen of the service app 70 (S1401). For example, if the service app 70 is a banking app and the user wants to change the address and phone number registered with that bank, the user selects menu 301 for changing the address and phone number from the banking app, as shown in Figure 34A(a).
[0377] The service app 70 displays currently registered personal information corresponding to the personal attribute information to be changed selected in step S1401 (S1402). For example, the banking app displays the registered address and phone number, as shown in Figure 34A(b).
[0378] When a user presses (touches) the "Change" button 302 on the screen of the service app 70 shown in Figure 34A(b), the service app 70 displays the personal attribute information it requests from the DIW app 50, as shown in Figure 34A(c) (S1403). For example, the bank app displays that the information to be linked from the DIW app 50 (i.e., the information to be changed) is the address and telephone number, as shown in Figure 34A(c).
[0379] When a user presses (touches) the "Launch DIW app" button 303 on the screen shown in Figure 34A(c), the service app 70 sends a command to the DIW app 50 to launch the DIW app 50 and the requested personal attribute information (S1404).
[0380] The DIW app 50 receives the startup instruction in step S1404 and starts up (S1405).
[0381] As shown in Figure 34B(a), the DIW app 50 displays a screen (S1406) confirming that it will share (link) personal information (e.g., address and telephone number) corresponding to the requested personal attribute information with the requesting service app 70 (e.g., banking app). The screen may display the name of the requesting service app 70, the purpose of using the personal information, and the personal attribute information to be shared, as shown in Figure 34B(a). The screen shown in Figure 34B(a) may also display the type of identification document (e.g., My Number Card).
[0382] When a user presses (touches) the "Recognize Face and Share" button 304 on the screen shown in Figure 34B(a), the DIW app 50 takes a picture of the user's face with the camera 14 of the user terminal 10 (S1407) and acquires the captured face image information (S1408), as shown in Figure 34B(b).
[0383] The DIW app 50 compares the facial image information in the user personal information record 110 with the captured facial image information obtained in step S1409 to determine whether they belong to the same person (S1409). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0384] If the DIW app 50 fails to perform the matching in step S1410 (S1410: NO), it displays a screen prompting the user to retake the image due to the matching failure (S1411). The process then returns to step S1407.
[0385] If the DIW app 50 succeeds in the matching in step S1409 (S1410: YES), it extracts the personal information corresponding to the personal attribute information requested in step S1404 from the user personal information record 110 (S1412).
[0386] As shown in Figure 34B(c), the DIW app 50 displays a confirmation screen (S1413) to share the personal information extracted in step S1412 with the service app 70. If the telephone number, etc., shown in Figure 34B(c) is manually entered information, the user may manually change the telephone number, etc., from the screen of the DIW app 50 shown in Figure 34B(c). In this case, the telephone number, etc., in the user personal information record 110 may also be changed. The user may also manually change the telephone number, etc., from the service app 70.
[0387] If the user presses (touches) the "Cancel" button 305 from the confirmation screen in step S1413 (S1414: NO), the DIW app 50 may terminate this process without sharing personal information.
[0388] If the user presses (touches) the "Share" button 306 from the confirmation screen in step S1413 (S1414: YES), the DIW app 50 performs the following process. That is, the DIW app 50 sends the personal information extracted in step S1412 to the service app 70 as personal information corresponding to the personal attribute information requested in step S1404 (S1415), and then sends information about the personal information sent to the service app 70 to the DIW cloud 20 (S1416). This information about the personal information includes, for example, the service ID corresponding to the service app 70 and the personal attribute information provided.
[0389] DIW Cloud 20 receives the information from step S1416 and records it in the personal information provision log 220 (S1417).
[0390] The service app 70 receives the personal information in step S1415 and displays a verification completion screen as shown in Figure 34C(a). When the user presses (touches) the "Next" button 307 on the completion screen shown in Figure 34C(a), the service app 70 then displays the registered personal information and the personal information received in step S1415 (i.e., the modified personal information) as shown in Figure 34C(b) (S1418). On this screen, the user may further modify the displayed personal information or enter additional personal information. For example, as shown in Figure 34C(b), the service app 70 may display the modified address and phone number obtained from the DIW app 50 in an editable text box.
[0391] When the user presses (touches) the "Next" button 308 on the screen shown in Figure 34C(b), the service application 70 modifies the registered personal information with the personal information from step S1415 and displays a change completion screen as shown in Figure 34C(c) (S1419).
[0392] The service application 70 sends the modified personal information to the service provider server 30 (S1420). The service provider server 30 modifies the registered personal information with the modified personal information sent from the service application 70 (S1421).
[0393] Examples of service apps 70 include banking apps for using banking services, securities apps for using securities services, insurance apps for using insurance services, and online shopping apps for using online shops.
[0394] Furthermore, the user personal information record 110 of the DIW app 50 may also hold personal information such as bank account numbers, securities account numbers, insurance policy numbers, credit card numbers, and a designated service common ID, in addition to the personal information described above. The service app 70 may request the aforementioned personal information registered in the user personal information record 110 from the DIW app 50. In this case, the DIW app 50 may perform the facial recognition described above, and if the facial recognition is successful, it may provide the requested personal information to the service app 70.
[0395] Through the above process, users can easily change their personal information in each service application 70 by changing their personal information in the DIW application 50. In other words, users are freed from the hassle of changing their personal information for each service application 70 when changes to their personal information are necessary.
[0396] In step S1412 of Figure 33B, the DIW app 50 may determine whether the personal information to be extracted is valid or not, depending on the type of personal information being extracted. For example, if the requested personal attribute information is "previous year's withholding tax data," the DIW app 50 may determine in step S1412 whether the extracted withholding tax data is from the previous year (i.e., whether it is valid or not). If the DIW app 50 determines that the extracted withholding tax data is expired, it may display a message indicating that it cannot provide the requested data. The DIW app 50 may then update the user personal information record 110, extract the withholding tax data, and then determine again whether the extracted withholding tax data is from the previous year. If the determination is positive, the DIW app 50 may proceed to step S1413. The service app 70 may also perform the aforementioned determination of whether the extracted withholding tax data is from the previous year (i.e., whether it is valid or not).
[0397] Furthermore, if the service app 70 is a securities account opening app or a utility bill payment app, etc., and a bank account number is already registered in the user personal information record 110, the DIW app 50 may include the bank account number in the personal information and send it to the service app 70 (securities account opening app or utility bill payment app, etc.) in step S1415. Also, if multiple bank account numbers are already registered in the user personal information record 110, the DIW app 50 may, on the screen in step S1413, have the user select which bank account number to provide to the service app 70 (securities account opening app or utility bill payment app, etc.) from among the multiple bank account numbers. The DIW app 50 may then include the selected bank account number in the personal information and send it to the service app 70 (securities account opening app or utility bill payment app, etc.) in step S1415.
[0398] <Processing when a user checks the personal information provision log> Figure 35A is a sequence diagram showing an example of the process when a user checks the personal information provision log according to Embodiment 3. Figure 35B is a sequence diagram continuing from Figure 35A. Figure 36A is a diagram showing an example screen of the DIW application 50 related to the process shown in Figures 35A and 35B according to Embodiment 3. Figure 36B is a diagram showing an example screen of the DIW application 50 continuing from Figure 36A.
[0399] The user launches the DIW app 50 (S1501) and selects the link history menu 321 as shown in Figure 35A(a) (S1502).
[0400] As shown in Figure 35A(b), the DIW application 50 captures the user's face with the camera 14 of the user terminal 10 (S1503) and acquires the captured face image information (S1504).
[0401] The DIW app 50 compares the facial image information in the user personal information record 110 with the captured facial image information obtained in step S1504 to determine whether they belong to the same person (S1505). In other words, the DIW app 50 determines whether the user whose face was photographed is the person whose personal information record 110 is linked to the DIW app 50.
[0402] If the DIW app 50 fails to perform the matching in step S1505 (S1506: NO), it displays a screen prompting for matching failure and / or reshooting (S1507). Then, the process returns to step S1503.
[0403] If the DIW application 50 succeeds in the matching in step S1505 (S1506: YES), it requests a list of personal information from the DIW cloud 20 (S1507). The request for the list of personal information may include the user's user ID.
[0404] Upon receiving the request in step S1507, the DIW Cloud 20 extracts the personal information provision list (list of service linkage history) corresponding to the user ID from the personal information provision log 220 (S1508) and sends it to the DIW app 50 (S1509).
[0405] The DIW app 50 receives the personal information provision list (service linkage history list) in step S1509 (S1510) and displays the personal information provision list (service linkage history list) in a list format as shown in Figure 36B(c) (S1511).
[0406] When a user selects a service integration history (for example, row 322) from the list displayed (S1512), the DIW app 50 displays detailed information about the selected service integration history (S1513), as shown in Figure 36B(d).
[0407] Through the above process, only the user who successfully undergoes facial recognition can view the contents of the personal information provision log 220, preventing anyone other than the user from viewing the user's personal information provision log 220. Furthermore, by performing facial recognition when the linking history menu is selected in step S1502, and omitting individual facial recognition within the menu, the user can easily perform the operations in steps S1511 and S1512 within the menu.
[0408] (Summary of this disclosure) Based on the descriptions of embodiments 1 to 3 above, the following technologies are disclosed.
[0409] <Technology A1> The personal information management program (e.g., DIW app 50) that is executed on the processor (11) of the user terminal (10) owned by the user, as per this disclosure, reads the user's basic personal information from the user's identification document, displays an input screen for the user's additional personal information, obtains the additional personal information based on the user's input operation on the input screen, transmits the user personal information (e.g., user personal information record 110) including the basic personal information and the additional personal information to a predetermined external server (e.g., DIW cloud 20), and stores the user personal information in the memory (12) of the user terminal. This allows the user terminal to store user personal information in memory, including basic personal information read from identification documents and additional personal information entered by the user.
[0410] <Technology A2> In the personal information management program described in Technical A1, specific personal information is generated based on the basic personal information and the additional personal information, and the specific personal information is included in the user's personal information. This allows the user terminal to store specific personal information, including frequently used information, in its memory as part of the user's personal information.
[0411] <Technology A3> In the personal information management program described in Technology A1 or A2, a first screen is displayed to obtain the user's first consent to provide the user's personal information to the external server, and if the first consent is obtained from the user on the first screen, the user's personal information is transmitted to the external server. This allows the user's device to transmit personal information to an external server with the user's consent.
[0412] <Technology A4> In the personal information management program described in Technical A3, each piece of information included in the user's personal information is designated as personal attribute information, and the program displays information including at least one piece of personal attribute information used by the business operator for the service, and a second purpose of use of the personal attribute information. The program also displays a second screen for obtaining the user's second consent to provide the personal attribute information to the business operator, and if the second consent is obtained from the user on the second screen, the personal attribute information is transmitted to a business operator server managed by the business operator. This allows the user's device to provide the service provider with personal attribute information used for the service, with the user's consent.
[0413] <Technology A5> In the personal information management program described in Technical A4, if the second consent is obtained from the user on the second screen, information including at least the user ID of the user who gave the second consent and the service ID of the service for which the second consent was obtained is transmitted to the external server. This allows an external server (e.g., DIW Cloud 20) to manage the users and services that have provided personal information as a personal information provision log 220.
[0414] <Technology A6> In the personal information management program described in any one of the technologies A1 to A5, the basic personal information includes facial image information, which is the face image of the user. The camera (14) provided in the user terminal captures the user's face to obtain captured facial image information. The captured facial image information is then compared to the facial image information to determine whether it belongs to the same person. If the comparison is successful, the input screen is displayed. As a result, if the user's terminal successfully verifies the user's face, that is, if the user is the person whose personal information is stored on the terminal, it can display a screen for entering additional personal information.
[0415] <Technology A7> In the personal information management program described in any one of Technical A4 to A6, if the contents of the identification document are updated, the basic personal information is read from the updated identification document, the first screen is displayed, and if the user gives their consent again, the user's personal information, including the updated basic personal information, is sent to the external server, and the second screen is displayed, and if the user gives their consent again, the updated user's personal information is sent to the business server. As a result, if the information on the identification document is updated, the user's terminal can, after obtaining the user's consent again, transmit the updated user personal information to an external server and service provider.
[0416] <Technology A8> The personal information management method described herein, which is performed on a user terminal owned by the user, reads the user's basic personal information from the user's identification document, displays an input screen for the user's additional personal information, obtains the additional personal information based on the user's input operation on the input screen, transmits the user's personal information, including the basic personal information and the additional personal information, to a predetermined external server, and stores the user's personal information in the memory of the user terminal. This allows the user terminal to store user personal information in memory, including basic personal information read from identification documents and additional personal information entered by the user.
[0417] <Technology A9> The user terminal possessed by the user relating to this disclosure is equipped with a processor and memory. The processor reads the user's basic personal information from the user's identification document, displays an input screen for the user's additional personal information, acquires the additional personal information based on the user's input operation on the input screen, transmits the user personal information, including the basic personal information and the additional personal information, to a predetermined external server, and stores the user personal information in the memory. This allows the user terminal to store user personal information in memory, including basic personal information read from identification documents and additional personal information entered by the user.
[0418] <Technology B1> The personal information management program (e.g., DIW app 50) that is executed on the processor (11) of the user terminal (10) owned by the user, as per this disclosure, acquires user personal information (e.g., user personal information record 110) from the memory (12) of the user terminal, which includes at least basic personal information obtained from the user's identification document, and treats each piece of information contained in the user personal information as personal attribute information. The program receives service usage condition information, which includes the conditions for using the service provider's services, from a predetermined external server (e.g., DIW cloud 20), and determines whether the user personal information satisfies the conditions shown in the service usage condition information. If it is determined that the user personal information satisfies the conditions shown in the service usage condition information, the program generates the service corresponding to the service usage condition information as available service information indicating the services available to the user, and stores it in the memory. This allows the user's terminal to store in memory, as available service information, services that meet the conditions specified in the service usage conditions information, based on the user's personal attribute information.
[0419] <Technology B2> In the personal information management program described in Technology B1, multiple service usage condition information corresponding to each of multiple services is received, the determination is made for each of the multiple service usage condition information, and the multiple available service information generated when it is determined that the conditions are met is listed and stored in the memory. This allows the user terminal to store the available service information in memory as a list (for example, a list of available service IDs 120).
[0420] <Technology B3> In the personal information management program described in Technology B2, a list of available service information is displayed, and when the user selects the available service information for a service they wish to use from the list, the program identifies the personal attribute information required by the service, which is included in the service usage conditions information corresponding to the selected available service information, and displays a consent screen to obtain the user's consent to provide the identified personal attribute information required by the service to the business operator from the user's personal information. If the user gives their consent on the consent screen, the program extracts the personal attribute information required by the service from the user's personal information and provides it to the business operator. This allows the user's device to quickly display a list of services available to the user. Furthermore, when a user starts using a new service, the user's device can, with the user's consent, provide the service provider with the personal attribute information requested by that service.
[0421] <Technology B4> In the personal information management program described in Technology B3, the basic personal information includes facial image information, which is the user's facial image. The camera (14) on the user terminal captures the user's face to obtain captured facial image information. The captured facial image information is then compared to the facial image information to determine if it is the same person. If the comparison is successful, the consent screen is displayed. This allows the user's device to display a consent screen and obtain consent from the user if it successfully verifies the user's face, i.e., if the user is the person whose personal information is stored on the device.
[0422] <Technology B5> In the personal information management program described in Technology B3 or B4, when the service usage conditions information is updated, the updated service usage conditions information is received from the external server, and it is determined whether the user's personal information satisfies the conditions indicated in the updated service usage conditions information. If it is determined that the user's personal information satisfies the conditions indicated in the service usage conditions information, the personal attribute information requested by the service, which is included in the updated service usage conditions information corresponding to the available service information selected by the user, is re-identified, and a consent screen is displayed to obtain the user's consent to provide the re-identified personal attribute information requested by the service from the user's personal information to the service provider. If the user gives their consent on the consent screen, the personal attribute information requested by the service, extracted from the user's personal information, is provided to the service provider again. This means that if a service provider updates the service terms and conditions information, the user's device can provide the service provider with the personal attribute information requested by the service, after obtaining the user's consent again.
[0423] <Technology B6> The personal information management method described herein, which is performed on a user terminal (10) owned by the user, involves acquiring user personal information, including at least basic personal information obtained from the user's identification document, from the memory (12) of the user terminal; receiving service usage conditions information, including the conditions for using the service provider's services, from a predetermined external server; determining whether the user personal information satisfies the conditions indicated in the service usage conditions information; and, if it is determined that the user personal information satisfies the conditions indicated in the service usage conditions information, generating the service corresponding to the service usage conditions information as available service information indicating the services available to the user, and storing it in the memory. This allows the user's terminal to store in memory, as available service information, services that meet the conditions specified in the service usage conditions information, based on the user's personal attribute information.
[0424] <Technology B7> The user terminal (10) possessed by the user in this disclosure is equipped with a processor (11) and memory (12). The processor obtains user personal information from the memory, which includes at least basic personal information obtained from the user's identification document. The processor receives service usage conditions information, which includes the conditions for using the service provider's services, from a designated external server. The processor determines whether the user personal information satisfies the conditions indicated in the service usage conditions information. If it determines that the user personal information satisfies the conditions indicated in the service usage conditions information, it generates the service corresponding to the service usage conditions information as available service information indicating the services available to the user, and stores it in the memory. This allows the user's terminal to store in memory, as available service information, services that meet the conditions specified in the service usage conditions information, based on the user's personal attribute information.
[0425] <Technology C1> The personal information management program described herein, which is executed on the processor (11) of a user terminal (10) owned by the user, acquires user personal information from the memory of the user terminal, including at least basic personal information obtained from the user's identification document, when the user uses a service provided by the business operator. The basic personal information includes facial image information, which is the user's face image. Each piece of information included in the user personal information is treated as personal attribute information. The camera (14) of the user terminal captures the user's face to acquire captured facial image information. The captured facial image information is compared to the facial image information to determine whether it is the same person. If the comparison is successful, the personal attribute information requested by the service is extracted from the user personal information and transmitted to a designated service terminal (40) managed by the business operator. This allows the user terminal to extract personal attribute information requested by the service from the user's personal information if it successfully verifies the user's face, i.e., if the user is the person whose personal information is stored on the user terminal, and transmit that information to the service terminal.
[0426] <Technology C2> In the personal information management program described in Technical C1, if the service terminal determines that the received personal attribute information satisfies the conditions indicated in the service usage conditions information corresponding to the service, it transmits a positive determination result to the user terminal, and if the positive determination result is received, it displays information indicating that the user can use the service. As a result, if the service terminal determines that the personal attribute information transmitted from the user terminal meets the conditions specified in the service usage conditions information, the user terminal can display that the service is available and notify the user.
[0427] <Technology C3> The personal information management method performed on a user terminal (10) owned by the user relating to this disclosure is as follows: When the user uses a service provided by the business operator, the user terminal's memory (12) acquires user personal information, which includes at least basic personal information obtained from the user's identification document; the basic personal information includes facial image information, which is the user's face image; each piece of information included in the user personal information is considered personal attribute information; the user terminal's camera takes a picture of the user's face to acquire captured facial image information; the captured facial image information is compared to the facial image information to determine whether it is the same person; if the comparison is successful, the personal attribute information requested by the service is extracted from the user personal information and transmitted to a designated service terminal managed by the business operator. This allows the user terminal to extract personal attribute information requested by the service from the user's personal information if it successfully verifies the user's face, i.e., if the user is the person whose personal information is stored on the user terminal, and transmit that information to the service terminal.
[0428] <Technology C4> The user terminal (10) possessed by the user in this disclosure comprises a processor (11), memory (12), and a camera (14). When the user uses a service provided by the business operator, the processor obtains user personal information from the memory, which includes at least basic personal information obtained from the user's identification document. This basic personal information includes facial image information, which is the user's face. Each piece of information included in the user personal information is considered personal attribute information. The camera captures the user's face to obtain captured facial image information. The captured facial image information is compared to the facial image information to determine if it belongs to the same person. If the comparison is successful, the personal attribute information requested by the service is extracted from the user personal information and transmitted to a designated service terminal managed by the business operator. This allows the user terminal to extract personal attribute information requested by the service from the user's personal information if it successfully verifies the user's face, i.e., if the user is the person whose personal information is stored on the user terminal, and transmit that information to the service terminal.
[0429] While embodiments have been described above with reference to the attached drawings, this disclosure is not limited to such examples. It is clear to those skilled in the art that various modifications, alterations, substitutions, additions, deletions, and equivalents can be conceived within the scope of the claims, and these are also understood to fall within the technical scope of this disclosure. Furthermore, the components of the embodiments described above can be combined in any way without departing from the spirit of the invention. [Industrial applicability]
[0430] The technology disclosed herein is useful for realizing services that utilize personal information. [Explanation of Symbols]
[0431] 1 DIW System 5. Communication Network 10. User terminals 11 processors 12 memory 13 Storage 14 Cameras 15 Input device 16 Display device 17. Communication equipment 20 DIW Cloud 21 processors 22 memory 23 Storage 24 Communication equipment 30. Service Provider Servers 40 Service Terminals 41 processors 42 memory 43 Cameras 44 Input devices 45 Display device 46 Communication equipment 50 DIW apps 51 Service Master List Acquisition Department 52 User personal information acquisition department 53 Available Services Extraction Unit 54. Service Usage Conditions Output Section 55. Department for Obtaining Collaborative Agreements 56 Face matching unit 57 Request Reception Department 58 Provided information extraction part 59 Log output section 60 Data Management Department 70 Service Apps 81 Service Verification Department 82 Service Master List Management Department 83 ID generation section 84. Integrated Personal Information Master List Management Department 85. User-Linked Service List Management Department 86 Face Recognition Unit 87 Request Reception Department 88 Output section 89 Personal Information Provision Log Management Department 91 Electronic money issuance server 92 Vending machines 93 Evacuation Shelter Authentication Terminal 94 Facial Recognition Payment Terminal 100A, 100B Service Master List 110 User Personal Information Records 120 Available Service ID List 130 List of Consent Service IDs 200 Integrated Personal Information Master List 210 List of services linked to the user 220 Personal Information Provision Log 401 External terminal 402 Server
Claims
1. A personal information management program that runs on the processor of a user terminal owned by the user, When the aforementioned user uses a service provided by the business operator, From the memory of the user terminal, user personal information is obtained, which includes at least basic personal information obtained from the user's identification document. This basic personal information includes facial image information, which is the user's facial image. Each piece of information included in the user personal information is considered personal attribute information. The camera on the user terminal captures the user's face and acquires the captured facial image information. The captured facial image information is compared to the facial image information to determine whether it is the same person as the person described above. If the matching is successful, the personal attribute information requested by the service is extracted from the user's personal information and transmitted to a designated service terminal managed by the service provider. Personal information management program.
2. If the service terminal determines that the received personal attribute information satisfies the conditions indicated in the service usage conditions information corresponding to the service, it transmits a positive determination result to the user terminal. Upon receiving the aforementioned positive judgment result, information indicating that the user is able to use the service will be displayed. The personal information management program according to claim 1.
3. A method for managing personal information that is performed on a user terminal owned by the user, When the aforementioned user uses a service provided by the business operator, From the memory of the user terminal, user personal information is obtained, which includes at least basic personal information obtained from the user's identification document. This basic personal information includes facial image information, which is the user's facial image. Each piece of information included in the user personal information is considered personal attribute information. The camera on the user terminal captures the user's face and acquires the captured facial image information. The captured facial image information is compared to the facial image information to determine whether it is the same person as the person described above. If the matching is successful, the personal attribute information requested by the service is extracted from the user's personal information and transmitted to a designated service terminal managed by the service provider. How to manage personal information.
4. A user terminal owned by a user, equipped with a processor, memory, and camera, The aforementioned processor, When the aforementioned user uses a service provided by the business operator, From the memory, user personal information is obtained, which includes at least basic personal information obtained from the user's identification document, and the basic personal information includes facial image information, which is the user's facial image, and each piece of information included in the user personal information is designated as personal attribute information. The camera captures the user's face and acquires the captured facial image information. The captured facial image information is compared to the facial image information to determine whether it is the same person as the person described above. If the matching is successful, the personal attribute information requested by the service is extracted from the user's personal information and transmitted to a designated service terminal managed by the service provider. User terminal.
Citation Information
Patent Citations
BioCrypto Digital Wallet
JP2022508773A