Information processing system, information processing method, and information processing program

JP7686269B2Active Publication Date: 2025-06-02FIRST SCREENING CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2021100904
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-06-17
Publication Date
2025-06-02
Estimated Expiration
2041-06-17

AI Technical Summary

Technical Problem

In information processing systems where user data is linked with user IDs, data leaks at partner entities can reveal user identities despite encryption, compromising system security.

Method used

Implementing a system with distinct user ID and irreversible user ID usage areas, where user IDs are encrypted with host server keys and irreversible user IDs are encrypted with collaboration server keys, ensuring these IDs are not stored on the host server, and using different keys for each collaboration server, thus preventing identification of the original user ID from irreversible IDs.

Benefits of technology

This approach ensures that even if data leaks occur, the original user ID cannot be identified, maintaining system security by preventing the linking of user data to specific individuals, thereby minimizing security risks and enhancing overall system protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000018_0000
    Figure 00000018_0000
  • Figure 00000019_0000
    Figure 00000019_0000
  • Figure 00000020_0000
    Figure 00000020_0000
Patent Text Reader

Abstract

To provide a technology for satisfactorily ensuring security in a system so that associations between users and various kinds of data may not been identified even if the data is leaked in a system with which the system is integrated.SOLUTION: In an information processing system for exchanging data between a user terminal 10, a host server 20, and an integration server 30 located on a network, the information processing system includes: an ID management unit 21 that hashes a user ID unique to a user using the user terminal 10 and obtaining an irreversible user ID; a user ID usage region 40 that exchanges data using the user ID; and an irreversible user ID usage region 50 that exchanges data using the irreversible user ID. The user ID usage region 40 is for exchanging data with the host server 20. The irreversible user ID usage region 50 is for exchanging data with the integration server 30.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0004] , , , , , , ,

[0005] , , ,

[0003] , , , ,

[0001] The present invention relates to an information processing system, an information processing method, and an information processing program.

Background Art

[0002] In recent years, as an information processing system, there is one configured to provide an information processing service to a user by causing a plurality of computers (server devices) existing on a network to cooperate. In such an information processing system, it is common to manage various data (such as personal information) related to a user using a user ID unique to the user. In that case, it is known to ensure security for the user ID by encryption (for example, see Patent Document 1).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in an information processing system, since various data in the system is associated with a user ID, for example, if a data leak occurs at a cooperation partner, there is a risk that based on the leaked content, it can be determined which user the various data in the system relates to. This cannot be prevented if the leaked content includes an encryption key even if the user ID is encrypted.

[0005] The present disclosure provides a technology that can sufficiently ensure the security within a system such that, even if a data leak occurs at a cooperation partner, for example, on the management side that manages various data within the system, it cannot be determined which user the various data relates to.

Means for Solving the Problems

[0006] According to one aspect of this disclosure, An information processing system configured to exchange data between user terminals, host servers, and collaborative servers located on a network, An ID management unit hashing a user ID unique to the user using the user terminal to obtain an irreversible user ID, A user ID usage area for exchanging data using the aforementioned user ID, A lossy user ID usage area that uses the aforementioned lossy user ID to exchange data, It has, The aforementioned user ID usage area is for exchanging data with the host server, The aforementioned irreversible user ID usage area is for exchanging data with the aforementioned linked server. An information processing system is provided.

[0007] According to another aspect of this disclosure, An information processing method used in an information processing system configured to exchange data between user terminals, host servers, and collaborative servers located on a network, The user ID unique to the user using the aforementioned user terminal is hashed to obtain an irreversible user ID, The user ID usage area, which uses the aforementioned user ID to exchange data, is set up for data exchange with the host server. The lossy user ID usage area, which uses the aforementioned lossy user ID to exchange data, is set up for data exchange with the aforementioned cooperating server. Information processing methods are provided.

[0008] According to yet another aspect of this disclosure, On a computer on the network, A function for exchanging data between user terminals, host servers, and collaborative servers located on the aforementioned network, A function to obtain an irreversible user ID by hashing the user ID unique to the user using the aforementioned user terminal, A function to configure the user ID usage area, which uses the aforementioned user ID to exchange data, as a user ID usage area for exchanging data with the host server, A function to configure the lossy user ID usage area, which uses the aforementioned lossy user ID for data exchange, as a field for data exchange with the aforementioned cooperating server, An information processing program is provided to achieve this. [Effects of the Invention]

[0009] According to this disclosure, by allowing user IDs and irreversible user IDs to coexist within the system, and by clearly distinguishing between the user ID usage area and the irreversible user ID usage area, even if an irreversible user ID is leaked at a linked party, for example, the user ID cannot be identified because it is irreversible. Therefore, it is not possible to identify which user the management data on the host server pertains to, thereby ensuring sufficient security within the system. [Brief explanation of the drawing]

[0010] [Figure 1] This is a schematic diagram showing the general configuration of an information processing system according to the first embodiment of this disclosure. [Figure 2] This is a block diagram showing the functional configuration of an information processing system according to the first embodiment of this disclosure. [Figure 3] This is an explanatory diagram showing an example of processing operation when data is exchanged in the information processing system according to the first embodiment of this disclosure. [Figure 4] This is an explanatory diagram showing a specific example of the information management status in an information processing system according to the first embodiment of this disclosure. [Figure 5] This is a schematic diagram showing the general configuration of an information processing system according to the second embodiment of this disclosure. [Figure 6] This is an explanatory diagram showing a specific example of the information management status in an information processing system according to the second embodiment of this disclosure. [Embodiments for Carrying Out the Invention]

[0011] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.

[0012] <1. First Embodiment> First, the first embodiment of the present disclosure will be described.

[0013] (1) Example of System Configuration FIG. 1 is a schematic diagram showing a general configuration of an information processing system exemplified in this embodiment. FIG. 2 is a block diagram showing a functional configuration of the information processing system exemplified in this embodiment.

[0014] (Overall Configuration) As shown in FIG. 1, the information processing system according to this embodiment includes at least a user terminal 10, a host server 20, and a cooperation server 30 that exist on a network not shown, and is configured to exchange data among them. Note that a plurality of user terminals 10 may exist on the network. Similarly, a plurality of cooperation servers 30 may exist on the network. In that case, each of the plurality of user terminals 10 can individually exchange data with the host server 20, and can also individually exchange data with any of the plurality of cooperation servers 30.

[0015] Examples of the network include a wide area network (WAN), but it is not particularly limited as long as data can be exchanged. The types and formats of data exchanged through the network are not particularly limited either.

[0016] In this embodiment, the data exchanged through the network is assumed to include data related to the biological information of the user using the user terminal. That is, the information processing system according to this embodiment is configured to perform predetermined processing on the data related to the biological information of the user. The details of the predetermined processing will be described later.

[0017] (User terminal) User terminal 10 is a terminal device used by users to access the system, and consists of a smartphone, tablet, laptop, etc., that has computer functionality. If multiple user terminals 10 exist on the network, multiple users will be able to access the system.

[0018] As shown in Figure 2, the electrochemical sensor 11 is connected to the user terminal 10 via wireless or wired communication. The electrochemical sensor 11 measures the biological information of the user using the user terminal 10 and outputs the measurement data to the user terminal 10. Examples of biological information include information regarding the concentration of uric acid in urine collected from the user (i.e., the subject). The concentration of uric acid in urine can be measured, for example, by electrolyzing substances in the urine under specific conditions and utilizing the resulting electrochemical reaction (e.g., oxidation-reduction reaction). Thus, the electrochemical sensor 11 is configured to electrochemically measure a specific component (e.g., uric acid) in a test fluid (e.g., urine) collected from the subject. However, the test fluid may be other bodily fluids such as blood, saliva, nasal mucus, sweat, or tears. Furthermore, the specific component in the test fluid may be other than uric acid, such as urinary glucose, arginine, or albumin. The specific configuration of the electrochemical sensor 11 can be based on publicly known technology, and therefore its explanation is omitted here.

[0019] To acquire measurement data from such an electrochemical sensor 11 and to process the acquired measurement data, the user terminal 10 has the function of an application unit (hereinafter simply referred to as the "application unit") 12. The application unit 12 is a function implemented by an application program installed on the user terminal 10, which controls the processing operation of the electrochemical sensor 11 and processes the measurement data acquired from the electrochemical sensor 11. To this end, the application unit 12 has the functions of an operation instruction unit 13 for the user of the user terminal 10 to operate and give operation instructions, a communication control unit 14 that controls communication with the host server 20 and the cooperating server 30, an information storage unit 15 that stores various information in the memory of the user terminal 10 as needed, and a sensor control unit 16 that controls the processing operation of the electrochemical sensor 11 in accordance with instructions from the operation instruction unit 13.

[0020] (Host server) The host server 20 is for providing predetermined services to users using the user terminal 10, and is configured, for example, as a cloud server located on the network. However, the host server 20 does not necessarily have to be a cloud server, and may be configured as a server device connected to the network.

[0021] The services provided by the host server 20 include, for example, management services related to user registration within the system, and management services for various user data (including personal information). To provide such services, the host server 20 has the functions of an ID management unit 21, a key management unit 22, an encryption unit 23, a decryption unit 24, a first database unit 25, and a second database unit 26. Each of these functions is implemented by a predetermined program installed on the host server 20, or by a predetermined program accessible to the host server 20.

[0022] The ID management unit 21 manages user IDs that are uniquely determined within the system. Specifically, the ID management unit 21 assigns a unique ID (original user ID) to a user upon request from a user using the user terminal 10. Furthermore, the ID management unit 21 hashes the user ID to obtain an irreversible user ID. The specific hashing method is not particularly limited and any known method may be used. Similarly, the specific form of the user ID and irreversible user ID is not limited to any particular form.

[0023] The key management unit 22 manages the keys used by the encryption unit 23 when encrypting data and by the decryption unit 24 when decrypting data. The keys managed by the key management unit 22 include a common key specific to the host server 20, or at least one of a set of public and private keys specific to the host server 20, and a public key specific to the cooperating server 30 present on the network. If there are multiple cooperating servers 30 on the network, the key management unit 22 manages a different key for each cooperating server 30.

[0024] The encryption unit 23 encrypts the user ID and the irreversible user ID. Specifically, the encryption unit 23 encrypts the user ID with a common key or public key unique to the host server 20, and encrypts the irreversible user ID with a public key unique to the cooperating server 30. Hereinafter, the user ID encrypted by the encryption unit 23 will be referred to as the "encrypted user ID," and the irreversible user ID encrypted by the encryption unit 23 will be referred to as the "encrypted irreversible user ID." The encrypted user ID and encrypted irreversible user ID obtained by the encryption unit 23 are temporarily sent to the user terminal 10.

[0025] The decryption unit 24 decrypts the encrypted user ID sent from an external source. Specifically, the decryption unit 24 decrypts the encrypted user ID using a shared key or secret key unique to the host server 20.

[0026] The first database unit 25 stores and holds various user data, particularly data that should be managed locally by the host server 20. Examples of data that should be managed locally by the host server 20 include each user's personal information (name, address, credit card information, and other personally identifiable information, as well as personal payment information). The first database unit 25 stores and holds such personal information in association with each user's user ID. This ensures that each user's personal information is managed locally by the host server 20.

[0027] The second database unit 26 stores and retains various data about users, excluding the data stored and retained by the first database unit 25. The data stored and retained by the second database unit 26 includes, for example, information related to the analysis results from the linked server 30 (described later), and lifestyle information, which is information about each user's lifestyle habits. The second database unit 26 may be located on the host server 20 as shown in the diagram, but is not limited to this. It may also be located on other devices within the system (for example, the cooperating server 30 in the irreversible user ID usage area 50 described later) as long as the host server 20 is accessible. When deployed on the host server 20, the second database unit 26 stores user data associated with the user's user ID. However, when deployed on another device in the irreversible user ID usage area 50 instead of the host server 20, the second database unit 26 stores user data associated with the user's irreversible user ID. As a result, various data other than personal information about the user is managed in a state accessible to the host server 20.

[0028] Furthermore, neither the irreversible user ID nor the encrypted irreversible user ID is stored in the first database unit 25. Similarly, if the second database unit 26 is located on the host server 20, neither the irreversible user ID nor the encrypted irreversible user ID is stored in it. Therefore, after the encrypted irreversible user ID is sent from the encryption unit 23 to the user terminal 10, neither the irreversible user ID nor the encrypted irreversible user ID remains on the host server 20. In other words, the host server 20 is configured not to store the irreversible user ID.

[0029] (Integration server) The collaboration server 30 is intended to provide users using the user terminal 10 with services separate from the host server 20, and is configured, for example, as a cloud server located on the network. However, like the host server 20, the collaboration server 30 does not necessarily have to be a cloud server and may be configured as a server device connected to the network.

[0030] Another service provided by the collaboration server 30 is, for example, a service that analyzes measurement data from the electrochemical sensor 11 and notifies the user of information regarding the analysis results. If multiple collaboration servers 30 exist on the network, each collaboration server 30 may provide a different service. In other words, within the system, the host server 20 and the collaboration servers 30 work together to provide users with information processing services that would not be possible with a single server.

[0031] To provide such services, the interoperation server 30 has the functions of a key management unit 31, a decryption unit 32, a user authorization unit 33, an analysis algorithm unit 34, and a database unit 35. Each of these functions is implemented by a predetermined program installed on the interoperation server 30, or by a predetermined program that the interoperation server 30 can access.

[0032] The key management unit 31 manages the keys used by the decryption unit 32 when performing decryption. The keys managed by the key management unit 31 include a set of public and private keys unique to each collaborative server 30 on the network. Alternatively, the keys managed by the key management unit 31 may be a common key unique to each collaborative server 30. If there are multiple collaborative servers 30 on the network, the key management unit 31 in each collaborative server 30 manages different keys.

[0033] The decryption unit 32 decrypts the encrypted irreversible user ID sent from an external source. Specifically, the decryption unit 32 decrypts the encrypted irreversible user ID using a secret key or a shared key unique to the cooperating server 30.

[0034] The user authorization unit 33 determines, based on the irreversible user ID decrypted by the decryption unit 32, whether the user identified by that irreversible user ID is a user who can provide services on the cooperative server 30, that is, whether the user is authenticated by the host server 20.

[0035] The analysis algorithm unit 34 performs predetermined analysis processing on the measurement data obtained by the electrochemical sensor 11 for a user using the user terminal 10, in response to a request from that user, and outputs information regarding the analysis results. Predetermined analysis processing includes, for example, processing to analyze changes in measurement data over time, and processing to determine disease risk from those changes over time. In other words, the analysis algorithm unit 34 is configured to output information regarding the results of such analysis processing to the requested user terminal 10 as result information of a service provided by the cooperating server 30. Output to the user terminal 10 may also be performed via another device in the system (for example, the host server 20). Specifically, for example, information regarding the analysis results by the analysis algorithm unit 34 may be sent to the user terminal 10, then transferred from the user terminal 10 to the host server 20, where the host server 20 creates layout information to specify the display layout, and then sends that layout information back to the user terminal 10 to perform display output on the user terminal 10.

[0036] The database unit 35 stores and retains various data, including information related to the analysis results performed by the analysis algorithm unit 34. In addition to information related to the analysis results, the various data stored and retained by the database unit 35 include, for example, a unique irreversible user ID for each user, measurement data sent from the user terminal 10, and lifestyle information sent from the host server 20.

[0037] (User ID usage area and irreversible user ID usage area) In the information processing system according to this embodiment, configured as described above, data can be exchanged between the user terminal 10 and the host server 20, between the user terminal 10 and the collaboration server 30, and between the host server 20 and the collaboration server 30. In this case, at least between the user terminal 10 and the host server 20, and between the user terminal 10 and the collaboration server 30, the communication data will be protected separately by encrypted communication, such as SSL (Secure Sockets Layer).

[0038] Furthermore, in the information processing system according to this embodiment, when exchanging data, there is a user ID usage area 40 which is an area where data is exchanged using a user ID or an encrypted user ID, and an irreversible user ID usage area 50 which is an area where data is exchanged using an irreversible user ID or an encrypted irreversible user ID.

[0039] The user ID area 40 is primarily for exchanging data with the host server 20. More specifically, the user ID area 40 is for exchanging data between the user terminal 10 and the host server 20. The irreversible user ID area 50 is primarily for exchanging data with the cooperating server 30. More specifically, the irreversible user ID area 50 is for exchanging data between the user terminal 10 and the cooperating server 30, and between the host server 20 and the cooperating server 30.

[0040] In other words, the information processing system according to this embodiment has a user ID usage area 40 and an irreversible user ID usage area 50, with the user ID usage area 40 being the area between the user terminal 10 and the host server 20, and the irreversible user ID usage area 50 being the area between the user terminal 10 and the cooperation server 30, and between the host server 20 and the cooperation server 30. Thus, in the information processing system according to this embodiment, the original user ID (encrypted user ID) and the irreversible user ID (encrypted irreversible user ID) coexist as IDs used within the system, while clearly distinguishing the scope in which each of these IDs is used.

[0041] (program) Each of the functions in the information processing system described above is realized by the user terminal 10, host server 20, or interoperation server 30 executing a predetermined program (including an application program). In other words, the predetermined program that realizes each of the above functions corresponds to one embodiment of the "information processing program" related to this disclosure.

[0042] In that case, the predetermined programs that implement each function may be provided by being installed on the user terminal 10, host server 20, or collaboration server 30 as a computer, and may be stored on a recording medium readable by the computer (for example, a magnetic disk, optical disk, magneto-optical disk, semiconductor memory, etc.), or they may be provided from an external source via a network such as the Internet or a dedicated line.

[0043] (2) Example of processing operation Next, we will describe an example of processing operation when data is exchanged between the user terminal 10, the host server 20, and the cooperating server 30 in the information processing system according to the present embodiment configured as described above, that is, one embodiment of the "information processing method" according to this disclosure. Figure 3 is an explanatory diagram showing an example of processing operation when data is exchanged in the information processing system according to this embodiment.

[0044] In the information processing system according to this embodiment, in order for a user using the user terminal 10 to receive services provided by the host server 20 and the cooperating server 30, the user first operates the user terminal 10 and requests user registration (i.e., ID assignment) from the operation instruction unit 13 of the application unit 12 to the host server 20 (step 101, hereafter steps will be abbreviated as "S").

[0045] When the host server 20 receives a user registration request from the user terminal 10, the ID management unit 21 assigns a unique user ID to the requesting user and hashes that user ID to obtain an irreversible user ID. Then, the encryption unit 23 encrypts these to obtain an encrypted user ID and an encrypted irreversible user ID. The encrypted user ID and encrypted irreversible user ID are sent from the host server 20 to the requesting user terminal 10 (S102).

[0046] When the requesting user terminal 10 receives an encrypted user ID and an encrypted irreversible user ID from the host server 20, the information storage unit 15 of the application unit 12 stores and retains them. As a result, the communication control unit 14 on the user terminal 10 will use either the encrypted user ID or the encrypted irreversible user ID for subsequent data transmission within the system. More specifically, the communication control unit 14 uses the encrypted user ID for data transmission between itself and the host server 20 because the user ID usage area 40 is used thereafter. Furthermore, it uses the encrypted irreversible user ID for data transmission between itself and the cooperating server 30 because the irreversible user ID usage area 50 is used thereafter.

[0047] For example, consider a case where a user inputs personal information and lifestyle information at the user terminal 10. The user's personal information should be managed in the first database unit 25 of the host server 20, and the user's lifestyle information should be managed in the second database unit 26 of the host server 20. Therefore, when the communication control unit 14 receives input of personal information and lifestyle information, it sends them to the host server 20 (S103). At this time, since the user ID usage area 40 is between the user terminal 10 and the host server 20, the communication control unit 14 transmits the personal information and lifestyle information to the host server 20 using an encrypted user ID. In other words, the communication control unit 14 sends the personal information and lifestyle information to the host server 20 along with the encrypted user ID stored in the information storage unit 15 (S103).

[0048] When the host server 20 receives an encrypted user ID, personal information, and lifestyle information from the user terminal 10, the decryption unit 24 decrypts the received encrypted user ID and restores it to its original form. If the user ID was legitimately issued by the ID management unit 21 in response to a user registration request, the host server 20 stores the personal information received from the user terminal 10 in the first database unit 25, associated with the user ID, and stores the lifestyle information received from the user terminal 10 in the second database unit 26, also associated with the user ID. In other words, the first database unit 25 stores the personal information of the user identified by that user ID, in a state where the user ID can be used as a search key, and the second database unit 26 stores the lifestyle information of the user identified by that user ID, in a state where the user ID can be used as a search key. As a result, the user's personal information and lifestyle information are managed by the host server 20.

[0049] Next, consider the case where, for example, the user measures biological information using the electrochemical sensor 11. Biological information is typically measured regularly at predetermined intervals, such as once a day. Whenever biological information is measured by the electrochemical sensor 11 at such intervals, measurement data is output from the electrochemical sensor 11 to the sensor control unit 16 of the user terminal 10 (S104).

[0050] The measurement data from the electrochemical sensor 11 is what is known as raw data, and in its raw form, it is not necessarily effective in promoting the user's health. Therefore, when measurement data is output from the electrochemical sensor 11, the user terminal 10 sends the measurement data to the linked server 30 via the communication control unit 14, either according to instructions from the operation instruction unit 13 of the application unit 12 or automatically in response to the output of the measurement data, in order to have the linked server 30 analyze the measurement data and contribute to promoting the user's health (S105). At this time, since the user terminal 10 and the linked server 30 are in the irreversible user ID usage area 50, the communication control unit 14 transmits the measurement data output from the electrochemical sensor 11 to the linked server 30 using an encrypted irreversible user ID. In other words, the communication control unit 14 sends the measurement data output from the electrochemical sensor 11 to the linked server 30 along with the encrypted irreversible user ID stored in the information storage unit 15 (S105).

[0051] Upon receiving an encrypted irreversible user ID and measurement data from the user terminal 10, the collaboration server 30 uses a decryption unit 32 to decrypt the received encrypted irreversible user ID, restoring it to the original irreversible user ID. The user authorization unit 33 then determines whether the user identified by that irreversible user ID is a user who can provide services to the collaboration server 30. As a result, the collaboration server 30 will only provide services to users authenticated by the host server 20. If the user is authenticated by the host server 20, the collaboration server 30 uses an analysis algorithm unit 34 to analyze the received measurement data, and outputs information regarding the analysis results to the user terminal 10 that sent the measurement data as result information of the service provided by the collaboration server 30 (S106). The collaboration server 30 also stores the information regarding the analysis results by the analysis algorithm unit 34, along with the underlying irreversible user ID and measurement data, in the database unit 35 as needed.

[0052] Upon receiving information regarding the analysis results from the linked server 30, the user terminal 10 displays the content of the received information to the user using the user terminal 10. As previously described, the display output to the user may be performed via another device within the system (for example, the host server 20). This allows the user, upon viewing the displayed content, to take actions that contribute to improving their health, such as changing their lifestyle habits, based on the analysis results from the linked server 30.

[0053] Furthermore, while the information regarding the analysis results from the linked server 30 can contribute to improving the user's health on its own, managing it together with the lifestyle information stored in the second database unit 26 of the host server 20 can further contribute to improving the user's health. Therefore, when the user terminal 10 receives information regarding the analysis results from the linked server 30, the communication control unit 14 sends the information regarding the analysis results to the host server 20 separately from the display output to the user (S107). At this time, since the user ID usage area 40 is between the user terminal 10 and the host server 20, the communication control unit 14 transmits the data regarding the analysis results to the host server 20 using an encrypted user ID. In other words, the communication control unit 14 sends the information regarding the analysis results to the host server 20 together with the encrypted user ID stored in the information storage unit 15 (S107).

[0054] When the host server 20 receives an encrypted user ID and information regarding the analysis results from the user terminal 10, the decryption unit 24 decrypts the received encrypted user ID and returns it to the original user ID. If the user ID is legitimately issued by the ID management unit 21, the database unit 25 stores the information regarding the analysis results received from the user terminal 10, associating it with the user ID. In other words, the database unit 25 stores information regarding the analysis results related to the user identified by that user ID, in a state where the user ID can be used as a search key. As a result, the information regarding the analysis results related to that user is managed by the host server 20, just like the user's lifestyle information.

[0055] Incidentally, in the analysis of measurement data performed by the analysis algorithm unit 34 on the linked server 30, the use of the user's lifestyle information may be useful in the analysis process. Therefore, prior to the analysis processing by the analysis algorithm unit 34, the host server 20 sends the user's lifestyle information to the linked server 30 upon request from the linked server 30, or when the database unit 25 has stored the lifestyle information (S108). Although the data transmission at this time is performed without going through the user terminal 10, considering that the linked server 30 is an irreversible user ID usage area 50, the host server 20 transmits the user's lifestyle information to the linked server 30 using an encrypted irreversible user ID. In other words, when transmitting data from the host server 20 to the linked server 30, the user's lifestyle information is sent to the linked server 30 along with an encrypted irreversible user ID (S108). Although the host server 20 does not store the irreversible user ID or the encrypted irreversible user ID, when transmitting data to the cooperating server 30, the encrypted irreversible user ID can be obtained from the ID management unit 21 and the encryption unit 23 each time.

[0056] The lifestyle information transmitted in this manner is stored in the database unit 35 of the linked server 30 and used for the analysis processing of measurement data performed by the analysis algorithm unit 34.

[0057] (3) Specific examples of security protection Next, we will explain the security protection in the information processing system according to this embodiment with specific examples. Figure 4 is an explanatory diagram showing a specific example of the information management status in the information processing system according to this embodiment.

[0058] The information processing system according to this embodiment is configured to provide information processing services to users using the user terminal 10 by coordinating multiple computers (specifically, the host server 20 and the collaboration server 30) located on a network. In providing the information processing services, as described above, processing operations related to data exchange are performed between the user terminal 10, the host server 20, and the collaboration server 30.

[0059] As a result, within the system, as shown in Figure 4, the first database unit 25 of the host server 20 manages each user's personal information using a user ID unique to each user. Furthermore, in the second database unit 26 of the host server 20 or other devices accessible by the host server 20, various data other than personal information, such as information related to analysis results and lifestyle information, are managed using a user ID unique to each user. In addition, in the database unit 35 of the linked server 30, information related to analysis results is managed using a user-specific irreversible user ID.

[0060] In such information processing systems, the host server 20 and the linked server 30 are often managed by different entities (e.g., the managing company). In this case, from the perspective of the managing entity of the host server 20, the authority to manage (especially security management) the linked server 30 does not extend, resulting in a risk of data leakage.

[0061] Now, let's consider, for example, what would happen if a data breach occurred at a partner company.

[0062] In the information processing system according to this embodiment, a user ID usage area 40 and an irreversible user ID usage area 50 are set up within the system. Furthermore, the scope of use of user IDs and irreversible user IDs within the system is clearly distinguished, such as using encrypted user IDs in the user ID usage area 40 and using encrypted irreversible user IDs in the irreversible user ID usage area 50.

[0063] Therefore, if a data breach occurs at a partner, for example, the encrypted irreversible user ID used in the irreversible user ID usage area 50 and the private key unique to the partner server 30 may be leaked to the outside, potentially compromising the confidentiality of the irreversible user ID. However, even if the confidentiality of the irreversible user ID is lost, because the irreversible user ID is a hashed irreversible entity, the link between it and the user ID becomes one-way, and it is not possible to decipher the original user ID from the irreversible user ID.

[0064] Furthermore, because the user ID usage area 40 and the irreversible user ID usage area 50 are clearly distinguished, even if data is leaked at a linked party, the encrypted user IDs used in the user ID usage area 40 will not be leaked externally.

[0065] Thus, in the information processing system according to this embodiment, the user ID usage area 40 and the irreversible user ID usage area 50 are clearly distinguished, and the linked party uses an irreversible user ID (encrypted irreversible user ID) as the irreversible user ID usage area 50, so that even if data is leaked at the linked party, the original user ID cannot be deciphered.

[0066] Therefore, in the information processing system according to this embodiment, even if data is leaked at a linked server, the original user ID cannot be deciphered, and thus it is not possible to identify whose data (especially each user's personal information) is managed on the host server 20. Furthermore, since it is not linked to the personal information managed on the host server 20, it is also not possible to identify which individual user the various data managed on the linked server 30 belongs to.

[0067] In other words, even if data is leaked, the linked server 30 cannot access information that specifically identifies individual users (for example, each user's personal information), as this information is managed locally by the host server 20. This means that the linked server 30 does not need information that specifically identifies individual users when providing services to each user.

[0068] As described above, in the information processing system according to this embodiment, the security risk of personal information leakage is localized (minimized) in the coordination of multiple services provided by multiple computers on the network (specifically, the host server 20 and the collaboration server 30). Therefore, the collaboration server 30 is freed from the risk of individual users being specifically identified.

[0069] On the other hand, data leakage could also occur on the host server 20, for example. Even in that case, because the user ID usage area 40 and the irreversible user ID usage area 50 are clearly distinguished, even if the confidentiality of the user ID is lost due to data leakage, it will not be immediately linked to the irreversible user ID, and it will not be possible to identify which individual user the various data managed by the distributed collaborative servers 30 belongs to.

[0070] Furthermore, security can be further enhanced by encrypting the user ID and irreversible user ID in the user ID area 40 and irreversible user ID area 50, respectively. Specifically, by having the host server 20 of the user ID area 40 accept only encrypted user IDs, and the cooperating server 30 of the irreversible user ID area 50 accept only encrypted irreversible user IDs, and by distributing the management of both encrypted and irreversible user IDs to each user terminal 10 rather than centrally managing them on either the host server 20 or the cooperating server 30, the overall security of the system can be improved. Furthermore, to enhance security, various types of data exchanged between the user terminal 10, host server 20, and cooperating server 30, specifically measurement data, information regarding analysis results, lifestyle information, etc., may also be encrypted according to the user ID usage area 40 or irreversible user ID usage area 50, respectively.

[0071] Furthermore, various data other than the personal information of each user, which is locally managed in the first database unit 25 of the host server 20, can be stored and stored in a distributed manner using the second database unit 26 of the host server 20 and the database unit 35 of the linked server 30. This distributed management also improves the overall security of the system.

[0072] (4) Effects of this embodiment According to this embodiment, one or more of the following effects are achieved.

[0073] (a) In this embodiment, a user ID usage area 40 and an irreversible user ID usage area 50 are set up within the information processing system, and data is exchanged using encrypted user IDs in the user ID usage area 40 and encrypted irreversible user IDs in the irreversible user ID usage area 50, thereby clearly distinguishing the scope of use of user IDs and irreversible user IDs within the system. Therefore, for example, even if data is leaked at a linked party and the confidentiality of the irreversible user ID is lost, the user ID cannot be deciphered from it because it is irreversible. As a result, when the host server 20 manages various data related to users (especially the personal information of each user), even if data is leaked on the linked server 30 side, it will not be possible to identify which individual user the various data within the system belongs to, and the security within the system can be sufficiently ensured.

[0074] (b) In this embodiment, the user ID is encrypted with a key unique to the host server 20 and used for data exchange in the user ID area 40, while the irreversible user ID is encrypted with a key unique to the cooperating server 30 and used for data exchange in the irreversible user ID area 50. By encrypting the user ID and irreversible user ID in this way, security can be further enhanced. In this case, since the user ID and irreversible user ID are encrypted with different keys, even if there is a data leak on the cooperating server 30 side, for example, the encrypted user ID cannot be decrypted with the leaked content. Furthermore, even if the encrypted irreversible user ID can be decrypted with the leaked content, the user ID cannot be deciphered from it because it is irreversible. In addition, by encrypting the user ID and irreversible user ID, risks can be avoided in the event of data leakage at the user terminal 10 and in the event of data leakage during data communication over the network.

[0075] (c) In this embodiment, the host server 20 is configured not to store the irreversible user ID. That is, after sending the encrypted irreversible user ID to the user terminal 10, neither the irreversible user ID nor the encrypted irreversible user ID remains on the host server 20. By preventing any trace of the irreversible user ID from remaining on the host server 20, even if the host server 20 is accessed illegally, it is impossible to trace the irreversible user ID, which is highly desirable for ensuring sufficient security within the system.

[0076] (d) In this embodiment, if there are multiple collaboration servers 30 in the system, encryption and decryption are performed using a different key for each collaboration server 30. Therefore, when the system is constructed to provide a variety of services through multiple collaboration servers 30, even if a data leak occurs at one collaboration destination, the impact on other collaboration destinations can be suppressed, which is highly desirable for ensuring sufficient security within the system.

[0077] <2. Second Embodiment> Next, a second embodiment of this disclosure will be described. However, this will mainly describe the differences from the first embodiment described above.

[0078] Figure 5 is a schematic diagram showing the general configuration of the information processing system used as an example in this embodiment. Figure 6 is an explanatory diagram showing a specific example of the information management status in the information processing system according to this embodiment.

[0079] As shown in Figure 5, the information processing system according to this embodiment is similar to the first embodiment described above in that it has at least a user terminal 10, a host server 20, and a collaboration server 30. However, unlike the first embodiment, the user terminal 10 and the host server 20 exchange data, and the host server 20 and the collaboration server 30 also exchange data.

[0080] In an information processing system with this configuration, the user ID usage area 40 is located between the user terminal 10 and the host server 20, and the irreversible user ID usage area 50 is located between the host server 20 and the cooperating server 30.

[0081] The functional configuration of the user terminal 10, host server 20, and collaboration server 30 is the same as in the first embodiment described above.

[0082] In an information processing system with the configuration described above, the processing operations for data exchange are performed in the same manner as in the first embodiment described above.

[0083] As a result, within the system, as shown in Figure 6, the first database unit 25 of the host server 20 manages each user's personal information using a user ID unique to each user. Furthermore, in the second database unit 26 of the host server 20 or other devices accessible by the host server 20, various data other than personal information, such as information related to analysis results and lifestyle information, are managed using a user ID unique to each user. In addition, in the database unit 35 of the linked server 30, information related to analysis results is managed using a user-specific irreversible user ID.

[0084] Therefore, this embodiment also achieves one or more effects described in the first embodiment, similar to the first embodiment described above.

[0085] <3. Variant> Although the first and second embodiments of this disclosure have been described in detail above, this disclosure is not limited to the embodiments described above and can be modified in various ways without departing from its essence.

[0086] In the embodiments described above, an information processing system that performs predetermined processing on data relating to a user's biometric information was used as an example, but this disclosure is not limited to such embodiments. In other words, the contents of this disclosure can be applied in exactly the same way as in the embodiments described above to any system in which multiple servers cooperate to provide services. However, the information processing systems in each of the embodiments described above handle data related to the user's biometric information. Therefore, security is of paramount importance regarding this data and other user-related data (personal information, etc.). Even in such cases, applying the contents of this disclosure will enable sufficient security within the system, and in that respect, it is extremely useful.

[0087] Furthermore, although the embodiments described above have explained using the case where encrypted user IDs are used in the user ID usage area 40 and encrypted irreversible user IDs are used in the irreversible user ID usage area 50 as an example, this disclosure is not limited to such embodiments. For example, even if unencrypted user IDs are used in the user ID usage area 40 and unencrypted irreversible user IDs are used in the irreversible user ID usage area 50, sufficient security against data leakage at the linked party can be ensured by clearly distinguishing between the user ID usage area 40 and the irreversible user ID usage area 50.

[0088] Furthermore, while the embodiments described above have explained the case in which the first database unit 25 of the host server 20 manages each user's personal information and the second database unit 26 of the same host server 20 manages various data other than each user's personal information, this disclosure is not limited to such embodiments. For example, if the host server 20 is provided with a first database unit 25 and a second database unit 26, these may be provided as a single database unit. Also, the second database unit 26, which manages lifestyle information other than personal information, may be built on another computer accessible by the host server 20, rather than on the host server 20 itself.

[0089] Furthermore, in each of the embodiments described above, the information managed by the second database unit 26 of the host server 20 was explained using the example of a case where the information includes service result information provided from the collaboration server 30 via the user terminal 10 (i.e., information regarding the results of the analysis processing in the analysis algorithm unit 34), but this disclosure is not limited to such embodiments. For example, the second database unit 26 of the host server 20 may not store the service result information provided from the collaboration server 30, and the host server 20 may be configured to query the collaboration server 30 for the service result information using an irreversible user ID (encrypted irreversible user ID) whenever such service result information is needed. With such a configuration, since the host server 20 does not store a copy of the data provided by the collaboration server 30, it is possible to localize (minimize) the security risk of data leakage, and as a result, the security within the system can be improved.

[0090] <4. Preferred Modes of the Disclosure> The following are preferred embodiments of this disclosure.

[0091] (Note 1) According to one aspect of this disclosure, An information processing system configured to exchange data between user terminals, host servers, and collaborative servers located on a network, An ID management unit hashing a user ID unique to the user using the user terminal to obtain an irreversible user ID, A user ID usage area for exchanging data using the aforementioned user ID, A lossy user ID usage area that uses the aforementioned lossy user ID to exchange data, It has, The aforementioned user ID usage area is for exchanging data with the host server, The aforementioned irreversible user ID usage area is for exchanging data with the aforementioned linked server. An information processing system is provided.

[0092] (Note 2) Preferably, An encryption unit that encrypts the user ID with a key unique to the host server and provides it for data exchange in the user ID usage area, and encrypts the irreversible user ID with a key unique to the cooperating server and provides it for data exchange in the irreversible user ID usage area. An information processing system described in Appendix 1, which has the above characteristics, is provided.

[0093] (Note 3) Preferably, When exchanging data in the user ID area, the user ID is encrypted using a common key or public key unique to the host server, and the encrypted user ID is decrypted using a common key or private key unique to the host server. The information processing system described in Appendix 2 is provided.

[0094] (Note 4) Preferably, When exchanging data in the aforementioned irreversible user ID area, the irreversible user ID is encrypted using a shared key or public key unique to the cooperating server, and the encrypted irreversible user ID is decrypted using a shared key or private key unique to the cooperating server. An information processing system as described in Appendix 2 or 3 is provided.

[0095] (Note 5) Preferably, The system has multiple interoperable servers, and each interoperable server uses a different key for encryption and decryption. An information processing system described in any one of the embodiments described in Appendix 2 to 4 is provided.

[0096] (Note 6) Preferably, The host server is configured not to store the irreversible user ID. An information processing system described in any one of the embodiments described in Appendix 1 to 5 is provided.

[0097] (Note 7) Preferably, The user terminal has an application unit that acquires measurement data from an electrochemical sensor that measures the subject's biological information and processes the acquired measurement data. An information processing system described in any one of the embodiments described in Appendix 1 to 6 is provided.

[0098] (Note 8) Preferably, The aforementioned collaborative server has an analysis algorithm unit that performs predetermined analysis processing on the measurement data of the subject's biological information and outputs the analysis results. An information processing system described in any one of the embodiments described in Appendix 1 to 7 is provided.

[0099] (Note 9) Preferably, The aforementioned host server has a database unit that manages the personal information of the subjects. An information processing system described in any one of the embodiments described in Appendix 1 to 8 is provided.

[0100] (Note 10) Preferably, The information managed by the database unit includes the results of services provided from the linked server via the user terminal. The information processing system described in Appendix 9 is provided.

[0101] (Note 11) Preferably, The database unit does not store the result information of the service provided from the linked server via the user terminal. The host server is configured to query the linked server for the result information using the irreversible user ID whenever the result information is needed. The information processing system described in Appendix 9 is provided.

[0102] (Note 12) According to another aspect of this disclosure, An information processing method used in an information processing system configured to exchange data between user terminals, host servers, and collaborative servers located on a network, The user ID unique to the user using the aforementioned user terminal is hashed to obtain an irreversible user ID, The user ID usage area, which uses the aforementioned user ID to exchange data, is set up for data exchange with the host server. The lossy user ID usage area, which uses the aforementioned lossy user ID to exchange data, is set up for data exchange with the aforementioned cooperating server. Information processing methods are provided.

[0103] (Note 13) According to yet another aspect of this disclosure, On a computer on the network, A function for exchanging data between user terminals, host servers, and collaborative servers located on the aforementioned network, A function to obtain an irreversible user ID by hashing the user ID unique to the user using the aforementioned user terminal, A function to configure the user ID usage area, which uses the aforementioned user ID to exchange data, as a user ID usage area for exchanging data with the host server, A function to configure the lossy user ID usage area, which uses the aforementioned lossy user ID for data exchange, as a field for data exchange with the aforementioned cooperating server, An information processing program is provided to achieve this. [Explanation of Symbols]

[0104] 10 User terminals 11 Electrochemical Sensors 12. App Department 13 Operation instruction section 14. Communication Control Unit 15 Information storage section 16 Sensor Control Unit 20 Host Servers 21 ID Management Department 22 Encryption section 23 Key Management Department 24 Decoding section 25 First Database Department 26 Second Database Department 30 Linked Servers 31 Key management department 32 Decoding Unit 33 User Authorization Department 34 Analysis Algorithm Section 35 Database Department 40 User ID Usage Area 50 Irreversible User ID Usage Area

Claims

1. An information processing system configured to transmit and receive data between a user terminal, a host server, and a link server on a network, an ID management unit that hashes a user ID unique to a user who uses the user terminal to obtain a non-reversible user ID; a user ID usage area for transmitting and receiving data using the user ID; a non-reversible user ID use area for transmitting and receiving data using the non-reversible user ID; and The user ID usage area is for transmitting and receiving data to and from the host server, The irreversible user ID usage area is for exchanging data with the linked server. Information processing system.

2. an encryption unit that encrypts the user ID with a key unique to the host server and provides the encrypted user ID for data exchange in the user ID use area, and also encrypts the irreversible user ID with a key unique to the linked server and provides the encrypted user ID for data exchange in the irreversible user ID use area; The information processing system according to claim 1 , further comprising:

3. When data is exchanged in the user ID area, the user ID is encrypted using a common key or public key specific to the host server, and the encrypted user ID is decrypted using a common key or private key specific to the host server. The information processing system according to claim 2 .

4. When data is exchanged in the irreversible user ID use area, the irreversible user ID is encrypted using a common key or a public key specific to the linked server, and the encrypted irreversible user ID is decrypted using a common key or a private key specific to the linked server.

4. The information processing system according to claim 2 or 3.

5. The system has a plurality of the above-mentioned linked servers, and performs encryption and decryption using different keys for each linked server. The information processing system according to any one of claims 2 to 4.

6. The host server is configured to not store the non-reversible user ID. The information processing system according to any one of claims 1 to 5.

7. The user terminal has an application unit that acquires measurement data from an electrochemical sensor that measures biological information of the subject and processes the acquired measurement data. The information processing system according to any one of claims 1 to 6.

8. The linking server has an analysis algorithm unit that performs a predetermined analysis process on the measurement data of the subject's biological information and outputs the analysis results. The information processing system according to any one of claims 1 to 7.

9. The host server has a database section for managing personal information of subjects. The information processing system according to any one of claims 1 to 8.

10. The information managed by the database unit includes result information of the service provided by the linking server via the user terminal. The information processing system according to claim 9 .

11. the database unit does not store result information of the service provided by the linked server via the user terminal, The host server is configured to inquire of the linking server about the result information using the irreversible user ID every time the result information is required. The information processing system according to claim 9 .

12. An information processing method used in an information processing system configured to exchange data between a user terminal, a host server, and a link server on a network, comprising: hashing a user ID unique to a user who uses the user terminal to obtain a non-reversible user ID; a user ID usage area for transmitting and receiving data using the user ID is set as an area for transmitting and receiving data with the host server; A non-reversible user ID usage area for exchanging data using the non-reversible user ID is set as an area for exchanging data with the linked server. Information processing methods.

13. On a computer on the network, a function of transmitting and receiving data between user terminals, host servers, and link servers on the network; A function of hashing a user ID unique to a user who uses the user terminal to obtain a non-reversible user ID; a function of setting a user ID usage area for transmitting and receiving data using the user ID as a domain for transmitting and receiving data with the host server; a function of setting a non-reversible user ID usage area for data exchange using the non-reversible user ID as an area for data exchange with the linked server; An information processing program to achieve this.