Information processing system

The system addresses the challenge of using sensitive personal data by generating and publishing metadata that conceals identities, allowing for the utilization of such data as big data while maintaining privacy.

JP7702096B2Active Publication Date: 2025-07-03KEYSOFT CO LTD +1
View PDF 13 Cites 0 Cited by

Patent Information

Application Number
JP2024096023
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2017-04-28
Filing Date
2024-06-13
Publication Date
2025-07-03
Estimated Expiration
2038-03-30

AI Technical Summary

Technical Problem

Existing information processing systems struggle with utilizing personal data as big data due to restrictions on external access, particularly for sensitive information like physical characteristics and health history, which limits the amount of data available for analysis.

Method used

An information processing system that includes a storage unit to store individual information with flags indicating disclosure, a person metadata generation unit to create metadata that conceals identities, and an information disclosure unit to publish this metadata over a network, ensuring individuals cannot be identified.

Benefits of technology

Enables the publication and utilization of sensitive personal data as big data, facilitating easier access and feedback while maintaining privacy, thus enhancing data availability for analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007702096000003
    Figure 0007702096000003
  • Figure 0007702096000004
    Figure 0007702096000004
  • Figure 0007702096000005
    Figure 0007702096000005
Patent Text Reader

Abstract

To provide an information processing system that discloses individual-related information so as not to be individually identifiable.SOLUTION: A SNS information processing system 400 is connected to a user terminal 160, a user terminal 162, and a retrieval server 180 over a network and includes a database 102 for storing individual-related disclosed information, an information disclosure server 104, and a person metadata generator 402. The SNS information processing system is connected to the outside via a network. The database is configured to store each piece of individual related disclosed information together with a flag indicating whether the information is disclosed so as not to be individually identifiable. The person metadata generator is configured to generate person metadata on the basis of the disclosed information to be disclosed so as not to be individually identifiable. The information disclosure server is configured to separately disclose, among the disclosed information stored in the database, the disclosed information that is not indicated to be disclosed so as not to be individually identifiable and the generated person metadata.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing system, and more particularly to an information processing system that processes information related to individuals.

Background Art

[0002] In recent years, the usefulness of utilizing big data has attracted attention. Big data refers to unstructured data and irregular data that include various types and formats, and is a collection of data that accumulates daily and increases in volume. Conventionally overlooked data groups that could not be managed due to their huge volume are now being recorded, stored, and immediately analyzed, and are being effectively utilized in business and other fields.

[0003] The sources of big data are SNSs (social networking services) such as FACEBOOK (registered trademark) and TWITTER (registered trademark), and information transmitted in large quantities daily from such sources, as well as GPS information of smartphones, etc., are big data.

[0004] By using big data, for example, it becomes possible to appropriately grasp market needs in product development and the like. Therefore, conventionally, data publicly available on the Internet such as the above-mentioned SNSs has been used as big data and analyzed.

[0005] In addition, it is expected to use information such as the medical records and prescriptions of patients and outpatients in medical institutions such as hospitals as big data. If information such as medical records and prescriptions can be used as big data, pharmaceutical companies and the like can develop products that better meet market needs.

Summary of the Invention

[0006] However, SNSs publish information on the Internet so that only specific people who form a community can access it, or so that unspecified people can access it. Information published so that only specific people can access it is difficult to use as big data because external access is restricted. Information published so that unspecified people can access it can be used as big data.

[0007] FIG. 1 is a diagram showing a schematic configuration of an SNS information processing system. FIG. 1 shows a network 190 such as the Internet to which an SNS information processing system 100 is connected, and user terminals 160 and 162 and a search server 180 that are connected to the SNS information processing system 100 via the network 190.

[0008] The SNS information processing system 100 can be composed of one or more computers including a processor such as a CPU, a semiconductor memory or a magnetic or optical memory, a wired or wireless communication device, an input device such as a keyboard, an input pad, a mouse pointer, a microphone, and an output device such as a display, a printer, a speaker.

[0009] The SNS information processing system 100 includes a database (DB) 102, an information disclosure server 104, a communication server 106, and an authentication server 108.

[0010] The database 102 is a database that stores information for each user of the SNS information processing system 100. The database 102 is held in memory and information writing / reading is performed in response to requests.

[0011] FIG. 2 is a diagram showing an example of user information stored in the database 102. The database 102 includes authentication information 202 (user ID, password), registration information 204 (name, date of birth, address, phone number, email address, gender), and public information 206 (profiles 1, 2, blog articles, etc.). The database 102 can include a contact list 208 (names / names of other users, email addresses, phone numbers, etc.). The example shown in FIG. 2 shows that the information input / set by the user AAA from the user terminal 160 is stored.

[0012] The information disclosure server 104 is implemented by causing a processor to execute a program such as, for example, an HTML (HyperText Markup Language) server. The information disclosure server 104 can disclose the user information stored in the database 102 at a predetermined address.

[0013] FIG. 3 is a diagram showing an example of user information published by the information disclosure server 104. In FIG. 3, an example of a state where the public information 206 of user AAA stored in the database 102 shown in FIG. 2 is arranged and published in a blog format is illustrated. The blog of user AAA can be accessed from the user terminal 162 of another user (for example, user BBB in the contact list of user AAA) by specifying the address aaa on the Internet. Also, it can be searched using the search server 180. Further, in the example of FIG. 3, in the blog, there are displayed areas (buttons) that can be activated to send messages such as emails to AAA and areas (buttons) that can be activated to write comments on blog articles. For example, user BBB accesses the blog of user AAA published from the user terminal 162, and by activating the message button, a user interface for sending a message to the email address (ID1@xxx) of AAA is presented on the user terminal 162, and the user can create and send a message. Also, user BBB can activate the comment button, and a user interface UI for creating comments is presented on the user terminal 162, and the user can write comments on the public information.

[0014] The communication server 106 is implemented by, for example, a processor that executes a program supporting Internet Protocol (IP) communication and a communication device. The communication server 106 can also be a server that executes a mail server program using protocols such as POP (Post Office Protocol) / SMTP (Simple Mail Transfer Protocol) or IMAP (Internet Message Access Protocol), or a short message service SMS program. Further, the communication server 106 can also be a file server that executes a file transfer program using a protocol such as FTP (File Transfer Protocol). The communication server 106 can communicate with the user terminals 160, 162, the search server 180, the information disclosure server 104, the authentication server 108, or other mail servers or SNS servers, or other file servers.

[0015] In addition to the function of authenticating the users of the information disclosure server 104 (for example, verifying passwords), the authentication server 108 provides an access control function to the information stored in the database 102.

[0016] However, as shown in FIG. 3, there are quite a few people who are resistant to including information on physical characteristics such as their own physique or information on health and medical history in the information published on SNS. That is, they do not want to disclose information on physical characteristics such as physique or information on health and medical history in a public manner that can identify an individual. Also, some people similarly do not want to disclose information regarding hobbies and interests. This affects the number of information that is publicly available on the Internet and can be used as big data.

[0017] The present invention has been made in view of such problems, and an object thereof is to provide an information processing system that discloses information regarding an individual so that the individual cannot be identified.

[0018] In order to solve the above problems, an information processing system according to an embodiment of the present invention includes a storage unit that is connected to the outside via a network and stores information about an individual, an information disclosure unit, and a person metadata generation unit. The storage unit is configured to store each piece of information about an individual with a flag indicating whether to disclose it so that the individual cannot be identified. The person metadata generation unit is configured to generate person metadata based on the information about the individual indicated by the flag to be disclosed so that the individual cannot be identified. The information disclosure unit is configured to disclose the person metadata so that it can be accessed via the network.

[0019] According to the present invention, it is possible to provide an information processing system that discloses information about an individual so that the individual cannot be identified.

Brief Description of the Drawings

[0020]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9A

Figure 9B

Figure 9C

Figure 9D

Figure 10A

Figure 10B

Figure 10C

Figure 10D

Figure 11

Embodiments for Carrying Out the Invention

[0021] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. The same or similar reference numerals indicate the same or similar elements, and repeated descriptions will be omitted. The embodiments described below are examples of the present invention. Therefore, the present invention can be implemented in other forms without being limited to the following embodiments and without losing generality.

[0022] An information processing system according to an embodiment of the present invention is an information processing system connected to the outside via a network, and includes a memory that stores information about an individual, an information disclosure server (SV), and a person metadata generation unit. The memory stores each piece of information about an individual with a flag indicating whether to disclose the information so that the individual cannot be identified. The person metadata generation unit generates person metadata based on the information about the individual indicated to be disclosed so that the individual cannot be identified by the flag. The information disclosure server discloses the information about the individual not indicated to be disclosed so that the individual cannot be identified by the flag and the person metadata separately so that they can be accessed via the network.

[0023] Person metadata includes all or part of a person's back data. A person's back data includes, for example, personal information of a person representing the person's nature, such as the person's personality, hobbies, blood type, height, weight, atopy, etc., medical history, work history, contact information, etc. Person metadata can be used to represent more detailed characteristics of the person, apart from information usually used to identify the person, such as the person's personal number, name, and address. The data of information for identifying a person, such as personal number, name, and address (hereinafter also referred to as main data), and person metadata may be configured separately and associated with each other. In another example, the personal number may be included in the main data, and the name and address may be included in the person metadata together with other information elements. However, in this case, the information for identifying a person, such as name and address, usually becomes person metadata that is not disclosed.

[0024] FIG. 4 is a diagram showing a schematic configuration of an SNS information processing system according to an embodiment of the present invention. The SNS information processing system 400 can be connected to user terminals 160 and 162 and a search server 180 via a network 190. The SNS information processing system 400 shown in FIG. 4 can be configured by one or more computers including a processor such as a CPU, a semiconductor memory or a magnetic or optical memory, a wired or wireless communication device, an input device such as a keyboard, an input pad, a mouse pointer, a microphone, and an output device such as a display, a printer, a speaker.

[0025] Similar to FIG. 1, the SNS information processing system 400 includes a database 102, an information disclosure server 104, a communication server 106, and an authentication server 108. As shown in FIG. 4, the SNS information processing system 400 of the present embodiment further includes a person metadata generation unit 402.

[0026] The database 102 is data that stores information about each user of the SNS system. The database 102 is held in a memory.

[0027] FIG. 5 is a diagram showing an example of user information stored in the database 102 according to the present embodiment. Similar to FIG. 2, the database 102 includes authentication information 202 (user ID, password), registration information 204 (name / title, date of birth, address, telephone number, email address, gender), and public information 206 (profiles 1, 2, blog articles, etc.). The database 102 can include a contact list 208 (name / title of other users, email address, telephone number, etc.). As shown in FIG. 5, the database 102 according to the present embodiment includes a flag 502.

[0028] Flag 502 indicates whether to publicly disclose each piece of information about an individual stored in database 102 in a way that the individual cannot be identified. For example, information with the flag set to "1" (e.g., profiles 1, 2) indicates that it will be publicly disclosed as personal metadata, i.e., information with the identifying information of the individual concealed, as will be described later. Information with the flag set to "0" (e.g., blog posts) will be publicly disclosed in the conventional form. Information with the flag set to "1" (e.g., profiles 1, 2) will be publicly disclosed separately from the information with the flag set to "0". For example, they will be publicly disclosed in different designs / formats, on different servers or at different addresses respectively. Information with the flag set to "1" and information with the flag set to "0" will not be provided together or associated with each other when accessing one of them.

[0029] In the above example, profiles to be publicly disclosed with flag "1" are associated, but other categories of information may also be associated. For example, for each value of the flag, the types of publicly disclosed information such as "medical data" to be publicly disclosed for "1", "hobbies" to be publicly disclosed for "2", and "food preferences" to be publicly disclosed for "3" may be associated. By doing so, it becomes possible to organize and search the publicly disclosed information.

[0030] In the above, an example of using a flag to identify whether to publicly disclose and to identify the category of information has been described. In yet another example, the flag can be used to identify whether to publicly disclose and to identify who is permitted to access (the target of the public disclosure). For example, as shown in Table 1, a flag is set in the registration information stored in database 102 in the same way as shown in Figure 6. For the flag values "0" to "5" shown in Table 1, whether to publicly disclose and who is permitted to access (the target of the public disclosure) are pre-associated as shown in Table 2 respectively.

[0031]

Table 1

[0032]

Table 2

[0033] In the example shown in Table 1, person metadata is created and published so that mail, food preferences (likes), and color preferences can be accessed by medical personnel, food manufacturers, and sports equipment manufacturers, but not by publishing personnel, health food manufacturers, and others. Alternatively, instead of creating person metadata, when the information disclosure server 104 publishes the registration information shown in Table 1, it determines which flag the accessor corresponds to (determines which registration information the access right is assigned to), and allows access to the registration information according to the determined flag. For example, the accessor accessing the information provides information (such as information indicating types such as occupation and industry) for the search server 180 or the information disclosure server 104 to determine the access right from the user terminals 160 and 162. The search server 180 provides the information disclosure server 104 with information for determining the access right from the user terminal. When it is determined based on the provided information that the accessor is a medical personnel and corresponds to the flag "1", the information disclosure server 104 may be configured to provide the information registered as mail, profile 1, color only (likes), color preferences (dislikes), and color preferences, and mask and provide the information registered as name, address, and profile 2. Here, examples such as medical personnel and food manufacturers are shown, but the flag does not necessarily represent such types as occupation and industry, and can represent the authority and distinction of the person accessing the data.

[0034] Furthermore, information to be disclosed may be identified so that individuals cannot be identified without using flags. For example, specific data items in database records may be pre-determined to be information to be disclosed so that individuals cannot be identified, and the person metadata generation unit may generate person metadata including the content of the data items, and the information disclosure server may disclose it. For example, for Profile 1 and Profile 2 in FIG. 5, a method of setting them in advance on the program may be adopted. Alternatively, all items except name, address, phone number, email address, etc. can be determined as public data. In this case, in addition to the method of generating and disclosing person metadata only for the public information as described below, a method of disclosing the original data as an item but hiding the content such as name, address, phone number, email address, etc. can be considered.

[0035] In the example shown in Table 1, it was explained that for each piece of information about an individual stored in the database 102, a flag 502 indicating whether to disclose it so that the individual cannot be identified is set. However, as described above, the main data including data items for identifying a person such as a personal number, name, and address, and the person metadata that can be used to represent more detailed characteristics of a person may be separately configured and associated with each other. For example, when a person's personal number is 0001, an identifier A001 is assigned to the person's main data, an identifier B001 is assigned to the person metadata, stored in the database 102, and the information disclosure server 104 may be configured to disclose only the person metadata assigned with B001. At this time, only the content of the person metadata of B001 is disclosed, and the personal number 0001 included in the main data of A001 may be kept non-disclosed.

[0036] Also, it is acceptable to save the main data and the personal metadata separately, as long as they are associated in some way. For example, the main data and the personal metadata can be stored separately in tabular form, and another table-formatted data can be created and stored to associate that the main data and the personal metadata in these two tabular forms are information of the same person. Instead of the other table-formatted data, identifiers A001 and B001 can be concatenated and stored so that a series of identifiers can identify the information of a person. The table-formatted data and the series of identifiers are like a kind of map indicating the data storage location.

[0037] In this way, by associating the main data and the personal metadata with another table-formatted data or a series of identifiers, even if the data leaks, only the main data, only the personal metadata, or only the other table-formatted data or a series of identifiers will leak. Therefore, the leaked data alone has little significance and is difficult for those who illegally obtain the data to utilize, so the damage is small and it is secure in terms of security. If the personal metadata is further divided into only the personal number, only the name, only the address (or including multiple items such as the name and address together), each personal information is divided into several pieces of personal metadata, so it is more secure. Note that a flag indicating whether to disclose the personal metadata to another table-formatted data or a series of identifiers may be included. Thereby, it is possible to indicate the disclosure or non-disclosure of the personal metadata with another table-formatted data or a series of identifiers instead of the personal metadata.

[0038] FIG. 6 is a diagram showing an example of user information stored in the database 102 according to an embodiment of the present invention. FIG. 6 shows an example in which information with the flag set to "0" is published at an address that is a combination of the address aaa of the server and the user ID ID1 of the user AAA, and information with the flag set to "1" (for example, profiles 1 and 2) is published at different addresses. The information disclosure server 104 or other elements are configured to determine the server and address for publishing information with the flag set to "1". The information disclosure server 104 or other elements may refer to a list (stored in memory) of a plurality of servers and addresses for publishing person metadata, and randomly determine from the list the server and address for publishing each person metadata. Such a list may be stored in association with a theme or classification regarding the content of the person metadata published by each server. In this case, the information disclosure server 104 or other elements may determine a theme or classification through analysis (for example, morphological analysis) and determination (for example, statistical determination and / or determination based on a learning model) of the content of the person metadata to be published, and select from the list the server and address that match this. When selecting a server and address based on the analysis of the content of the person metadata to be published, the person metadata of the same or similar themes or classifications of a plurality of users (a plurality of individuals) is aggregated and published at the same server and address.

[0039] The person metadata generation unit 402 can be implemented by a processor that executes a program stored in the memory. The person metadata generation unit 402 generates person metadata based on information about the individual that is shown to be published so that the individual cannot be identified by the flag.

[0040] FIG. 7 is a diagram showing an example of user information published by the information disclosure server 104 according to an embodiment of the present invention. Among the user information shown in FIG. 6, the person metadata 702 and 704 generated from the information with the flag set to "1" are published on different servers and addresses ("bbb" and "ccc"), respectively, and the information with the flag set to "0" is published as a blog of AAA at the address "aaa / ~ID1". For example, the user BBB registered in the contact list of the user AAA can access the person metadata 702 and 704 and the blog information from the user terminal 162. The user BBB can recognize that the blog is the information of the user AAA, but cannot recognize who the person metadata 702 and 704 are about.

[0041] As shown in FIG. 7, the information disclosure server 104 publishes the person metadata 702, 704 together with an area (button) that can be activated to present a user interface UI for creating a message or comment on the person metadata to the user terminals 160, 162 (laptop PC, tablet PC, mobile terminal, mobile phone, smartphone) of the users who accessed the person metadata 702, 704. The UI is displayed on the user terminal so that a message or comment can be created without specifying the address information of the user (individual) who provided the information that is the source of the person metadata or by specifying address information that is not that of the individual (for example, a dedicated address for sending messages). For example, a message including the address of the destination of the person metadata is received by the communication server 106 of the SNS information processing system 400, and the comment is stored in association with the person metadata as log information in the server (bbb or ccc) that publishes the person metadata. The communication server 106 may notify an individual whose person metadata cannot be identified from the person metadata of the existence of a message or comment on the person metadata using the address information of the individual registered in the database 102.

[0042] In the above embodiment, the SNS information processing system 100 is configured to be connected to the external search server 180 via a network. However, the SNS information processing system 100 may include the search server 180.

[0043] Alternatively, instead of using the above-mentioned flag, a specific area stored in the database 102 may be designated in advance to generate person metadata.

[0044] Additionally, the area that can be activated to present the above user interface may instead display an address to which messages or comments should be sent (address information that is not that of the individual in question (e.g., a dedicated address for sending messages)).

[0045] As described above, according to the present embodiment, it is possible to provide an SNS information processing system that publishes information about an individual in such a way that the individual cannot be identified. Since information about an individual can be published in such a way that the individual cannot be identified, for example, information about physical characteristics such as constitution or information about health and medical history can be easily published. For example, when one wants to know information about a medical history or a special hobby, in the past, one had to inform the other person that one has a medical history or a special hobby, which caused a problem of others finding out about such a medical history or special hobby. However, according to the SNS information processing system of the present embodiment, such a problem is improved by publishing the information as person metadata. That is, it becomes easier to publish information, and it is expected that the information can be utilized as big data. In addition, since a message can be sent or a comment can be provided for the published person metadata, it is expected that feedback on information about a medical history or a special hobby can be easily obtained.

[0046] In the above embodiment, an example of an SNS information processing system was described. However, the invention of the present application is not limited to the SNS information processing system, and can be applied to many other embodiments as long as personal metadata can be separately stored. For example, by applying the invention of the present application to information about individuals held by companies, facilities, government offices, etc., it is conceivable to disclose, share, or exchange only personal metadata and utilize it as big data. For example, the invention of the present application can be implemented as an information system related to medical care and nursing care. Hereinafter, an example of implementing the invention of the present application as an information processing system related to a hospital (referred to as a hospital information processing system in this specification) will be described.

[0047] FIG. 8 is a diagram showing a schematic configuration of a hospital information processing system according to an embodiment of the present invention.

[0048] The hospital information processing system 800 can be connected to the user terminals 160 and 162 and the search server 180 via the network 190. The hospital information processing system 800 can be composed of one or more computers including a processor such as a CPU, a semiconductor memory or a magnetic or optical memory, a wired or wireless communication device, an input device such as a keyboard, an input pad, a mouse pointer, a microphone, and an output device such as a display, a printer, a speaker.

[0049] The hospital information processing system 800 includes an information disclosure server 104, a communication server 106, and an authentication server 108. The hospital information processing system 800 includes a patient information database 802, a personal metadata generation unit 804, and a personal metadata database 806.

[0050] The patient information database 802 is a database that stores patient information. The patient information database 802 is held in a memory.

[0051] Figures 9A to 9D are diagrams showing an example of patient information stored in the patient information database 802. Figure 9A is a diagram showing an example of diagnostic record information 901, and Figures 9B to 9D are diagrams showing prescription information 902 to 904 associated with the diagnostic record information 901. As shown in Figure 9A, the diagnostic record information 901 stores diagnostic record information and prescription information regarding a patient who is an individual, with a flag indicating whether to disclose it in a way that the individual cannot be identified. Information of a patient whose flag is set to "1" (diagnostic record information 901, prescription information 902 to 904) indicates that it will be disclosed as person metadata, that is, information with personal identifying information concealed. Further, the diagnostic record information 901 includes the address of the disclosure destination of the patient information, and the contact information (e.g., email address) of the patient to be notified of the existence of messages and comments regarding the disclosed person metadata.

[0052] The person metadata generation unit 804 can be implemented by a processor that executes a program stored in the memory. The person metadata generation unit 804 generates person metadata based on the information regarding the individual (the patient's diagnostic record information 901 and prescription information 902 to 904) indicated to be disclosed in a way that the individual cannot be identified by the flag. For example, the person metadata generation unit 804 can generate person metadata by deleting the information (name, date of birth, email address) that identifies the individual from the patient information. The person metadata generation unit 804 can also generate person metadata by replacing the information (name) that identifies the individual with an alphanumeric string.

[0053] The person metadata database 806 stores the generated person metadata. The person metadata database 806 is held in the memory.

[0054] Figs. 10A to 10D are diagrams showing person metadata according to an embodiment of the present invention, and Figs. 10A to 10D are person metadata 1001 corresponding to the diagnostic record information 901 in Fig. 9A and the prescription information 902 to 904 in Figs. 9B to 9D, respectively. The person metadata 1001 in Fig. 10A deletes the information identifying an individual (patient) by deleting the date of birth in the diagnostic record information 901 and replacing the name with numbers. The person metadata in Figs. 10B to 10D are person metadata corresponding to the prescription information 902 to 904 in Figs. 9B to 9D, respectively. The person metadata in Figs. 10B to 10D also deletes the information identifying an individual (patient) by deleting the date of birth in the prescription information in Figs. 9B to 9D and replacing the name with numbers. It would be useful if person metadata including details of a patient's health condition could be used as big data. For example, if information about the drugs a patient is actually taking can be grasped more accurately, it would be beneficial for the development of new drugs by pharmaceutical companies.

[0055] Similar to the explanation with reference to FIG. 7, the information disclosure server 104 of the hospital information processing system 800 can disclose person metadata 1001 to 1004. The person metadata 1001 to 1004 may be disclosed together with an area (button) that can be activated to present a user interface for creating a message or comment on the person metadata to the user terminal of the accessed user. A pharmaceutical company can access, for example, the person metadata 1001 to 1004 as search results by the search server 180 from the user terminal 162. At this time, without specifying the address information of the patient (individual) who provided the patient information that is the source of the person metadata or by specifying address information that is not that of the patient (for example, a dedicated address for message transmission of the hospital information processing system 800), the user interface is displayed on the user terminal 162 of the pharmaceutical company so that a message or comment can be created. Using this user interface, the pharmaceutical company can create a message or comment on the metadata. For example, a message including the address (http: / / ccc) of the disclosure destination of the person metadata is received by the communication server 106 of the hospital information processing system 800, and the comment is stored in association with the person metadata as log information in the server (ccc) that discloses the person metadata. The communication server 106 of the hospital information processing system may notify an individual, who cannot be identified from the person metadata, of the existence of a message or comment on the person metadata using the address information (ID1@xxx) of the patient registered in the patient information database 802. The patient can access and view the content of a message or comment on the person metadata from, for example, the user terminal 160.

[0056] Also, similar to the above, the information disclosure server 104 or other elements may determine a theme or classification through analysis (e.g., morphological analysis) and determination (hard determination or soft determination) of the contents of the person metadata 1001 to 1004 to be disclosed, and select a server and address that match from the list. In this case, person metadata of the same or similar themes or classifications of multiple users (multiple individuals) is aggregated and disclosed at the same server and address. For example, the person metadata related to atopy is aggregated at the server (ccc). In this way, by selecting a server and address according to the theme or classification, person metadata of the same theme or classification can be aggregated at the same server and address, but multiple regions may be provided on the same server, and person metadata of different themes or classifications may be aggregated in different regions.

[0057] As shown in FIG. 8, the search server 180 can access the person metadata disclosed by a plurality of hospital information processing systems 800, 812, 814, and can search across this person metadata. The search server 180 may be provided in at least one of the plurality of hospital information processing systems 800, 812, 814.

[0058] In the above description, an example in which the hospital information processing systems 800, 812, and 814 each include a person metadata database 806 has been described. However, the person metadata database 806 may be provided in an external search server 180, and the person metadata generation unit 804 of each hospital information processing system may store the generated person metadata in the person metadata database 806 of the external search server 180. At this time, the hospital information processing systems 800, 812, and 814 can store the contact information (email address) together so that they can receive notifications regarding the provided metadata from the external search server 180. The external search server 180 provides a search service for the person metadata database 806 and provides the person metadata that is the search result. When a message or comment is generated for the person metadata, the external search server 180 can obtain the contact information stored together with the person metadata and notify the hospital information processing system. For example, the notification can include the identification number included in the person metadata. The notification may include a message or comment, or may include a procedure for accessing the message or comment. The communication server 106 of the corresponding hospital information processing system can obtain the contact information (e.g., email address) of the patient who is the source of the person metadata from the patient information database 802 and notify the corresponding patient of the existence of a message or comment for the person metadata. As described above, the person metadata generation unit 804 of each hospital information processing system can store the generated person metadata in the person metadata database 806 of the external search server 180. Each hospital information processing system includes a search server 180, and the person metadata generation unit 804 may store the person metadata in different spaces within the search server. When storing in the person metadata database 806, the external search server 180 may add additional information in the form of a string that combines an identifier for identifying the theme or classification of the data item in the person metadata, and an identifier for permitting or not permitting publication and identifying the publication target, and store them together.As an alternative to or in combination with the above-described flags, the search server 180 can utilize additional information. For example, the registration information in Table 1 and the additional information corresponding to the flags can be configured in string format as A: Yamada Taro: 0; B: Kanagawa Prefecture: 0; B: a@bbb.jp: 125; C: Tennis: 12345; D: Atopy: 34; E: Eel: 125; F: Parsley: 125; G: Yellow: 125 and stored in the person metadata database 806. Here, A to G are examples of identifiers for identifying themes or classifications. A is an identifier corresponding to the name, B is an identifier corresponding to the contact information, C is an identifier corresponding to the hobby, D is an identifier corresponding to the constitution, and E to G are identifiers corresponding to likes / dislikes. The string "D: Atopy: 34" in the additional information indicates that the theme or classification of the third data item in the data record corresponds to the constitution, the data value is "Atopy", and it indicates that publication is permitted for "publishers" and "health food related persons". If it is permitted to disclose information on themes or classifications related to the constitution only to medical personnel, the string in the additional information corresponding to the third data item in the data record may be set to "D: Atopy: 1". Instead of storing the data value in each string of the additional information, the address (pointer) in the recording medium where the data value is stored may be stored. In this way, even if the storage location of the data is known, a system having the person metadata database 806 storing the person metadata (for example, the hospital information management systems 800, 812, 814, the search server 180) can also refer to the string in the additional information to reject or restrict access to the person metadata, and can more freely disclose or not disclose the person metadata. Also, even if the string in the additional information is attacked from the outside, the content is not the data value but the address (pointer) in the recording medium where the data value is stored, so it is safer.

[0059] As described above, according to the present embodiment, it is possible to provide a hospital information processing system that discloses information about a patient (individual) without being able to identify the patient. Since the patient's information can be disclosed without being able to identify the patient, it can be expected to be utilized as big data. In addition, since a message can be sent to the disclosed person metadata or a comment can be provided, it can be expected that it will be easier to obtain feedback from the patient.

[0060] In the embodiment of the hospital information processing system, an example in which a data item (main data) for identifying a person such as a name and a data item (person metadata) that can be used for a more detailed expression of the person are included in one table-form data has been described. The main data and the person metadata may be configured separately and associated with each other. As described above, for example, the main data and the person metadata are stored separately in a table format, and another table-form data for associating that these two table-form main data and person metadata are information of the same person is created and stored. Instead of the data in another table format, the identifier of the main data and the identifier of the person metadata may be connected and stored so as to identify the information of a person having a series of identifiers.

[0061] FIG. 11 is a diagram showing a processing flow in the information processing system of the present invention. The information processing method shown in FIG. 11 can be implemented in an information processing system including the above-described SNS information processing system 400 or hospital information processing system 800. The user terminal 160 is, for example, a terminal used by a user who discloses personal information as person metadata. The user terminal 162 is a terminal used by a user who accesses the metadata.

[0062] In S1101, an information processing system (communication server) receives and stores input data. For example, the SNS information processing system 400 communicates with the user terminal 160 operated by a user to receive the input profile data and the setting of the flag for the profile. Also, the hospital information processing system 800 communicates with the user terminal 160 operated by a doctor to receive the input patient information (diagnosis record information and prescription information). It also receives the setting of the flag as needed.

[0063] In S1103, an information processing system (person metadata generation unit) generates person metadata based on the input data. In S1105, an information processing system (information disclosure server) discloses the generated person metadata.

[0064] In S1107, the user terminal sends a search request to the search server. In S1109, the search server executes the requested search. In S1111, the search server returns the search result to the user terminal. In S1113, the user terminal accesses the person metadata and generates and sends a message or comment via the user interface presented on the terminal.

[0065] In S1115, an information processing system (communication server or other element) extracts the address of the provider of the input data corresponding to the person metadata to which the message or comment was sent. The extraction of the address of the provider of the input data can be performed when the information processing system (communication server or other element) receives the message sent to the address of the information processing system, or detects that the comment has been recorded as a log on the server that discloses the person metadata.

[0066] In S1117, an information processing system (communication server) notifies that the message or comment has become available.

[0067] In S1119, the user terminal accesses the message or comment addressed to the person metadata.

[0068] In addition, the information processing system (information disclosure server) may execute authentication of the user associated with the request in response to receiving an access request to the disclosed person metadata. The authentication of the user can be, for example, authentication by an authenticator including password authentication or biometric authentication. Information indicating types such as occupations and industries as described above can be associated with the authenticator in advance. Similarly, the search server may execute authentication of the user associated with the search request before executing the requested search.

[0069] As described above, the invention of the present application can also be implemented as an information processing method for disclosing information about an individual so that the individual cannot be identified. Further, the invention of the present application can also be implemented as a computer program for causing a computer to execute this information processing method.

Explanation of Signs

[0070] 100, 400 SNS information processing system 102 Database 104 Information disclosure server 106 Communication server 108 Authentication server 160, 162 User terminals 180 Search server 190 Network 202 Authentication information 204 Registration information 206 Public information 208 Contact list 402 Person metadata generation unit 502 Flag 602 Publication destination address 702, 704 Person metadata 800, 812, 814 Hospital information processing system 802 Patient information database 804 Person metadata generation unit 806 Person metadata database 901 Diagnostic record information Prescription information 902, 903, 904 Person metadata 1001, 1002, 1003, 1004

Claims

1. An SNS information processing system connected to the outside via a network, comprising a storage means for storing information about an individual, an information disclosure means, and a person metadata generation means, wherein the storage means is configured to store each of the information about the individual with a flag indicating whether to disclose the information so that the individual cannot be identified, the person metadata generation means is configured to generate person metadata based on the information about the individual indicated by the flag to be disclosed so that the individual cannot be identified, the information disclosure means is configured to disclose the person metadata so that it can be accessed via the network, and the information disclosure means is further configured to disclose the person metadata for big data use by providing the person metadata about information of a plurality of individuals to a storage device provided in an external search system. An SNS information processing system characterized by the above.

2. The SNS information processing system according to claim 1, wherein the flag indicates whether to disclose the information so that the individual cannot be identified and also indicates the type of information to be disclosed.

3. The SNS information processing system according to claim 1 or 2, wherein the flag indicates whether to disclose the information so that the individual cannot be identified and also indicates the target of disclosure.

4. The person metadata according to any one of claims 1 to 3, wherein the person metadata includes, for each of the information about the individual, an identifier for identifying the theme or classification of the information about the individual, and an identifier for identifying whether to permit the disclosure of the information about the individual and the target of the disclosure of the information about the individual, and additional information in the form of a string formed by combining them.

Citation Information

Patent Citations

  • Information providing method

    JP2001312565A

  • Information providing device, information providing system, and distributed database system

    JP2004318391A

  • Medical information processing system and medical information processing program

    JP2008083847A

  • Privacy credentials protocol for secure data exchange, collection, monitoring and / or alerting

    JP2008527520A

  • Outsourced analysis system of personal information

    JP2011123712A