Control Method, Data Circulation System, and Program
The control method in a data distribution system with authentication servers and a service server addresses user concerns by ensuring traceability and providing incentives, facilitating continuous data collection and utilization.
Patent Information
- Application Number
- JP2022568283
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-12-08
- Filing Date
- 2021-12-07
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2041-12-07
AI Technical Summary
Users are hesitant to provide data due to concerns about data leakage and lack of traceability and benefits, which hinders effective data collection and utilization.
A control method utilizing a data distribution system with authentication servers and a service server that generates challenge content with incentives, executes smart contracts, and records transaction data in a distributed ledger to ensure traceability and provide benefits to users.
Ensures data traceability while providing incentives to users, encouraging continuous data provision and utilization.
Smart Images

Figure 0007710465000001 
Figure 0007710465000002 
Figure 0007710465000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a control method, a data circulation system, and a program.
Background Art
[0002] In recent years, systems for collecting, analyzing, and circulating user data and device data have been studied. In the future, with the development of IoT (Internet of Things) and the spread of AI and the like, it will be possible to collect more data than ever before, and thus the utilization of the collected data is expected.
[0003] For example, Non-Patent Document 1 discloses a human-centered society, Society 5.0, which achieves both economic development and the solution of social problems through a system that highly integrates the cyber space (virtual space) and the physical space (real space).
[0004] According to Non-Patent Document 1, in Society 5.0, for example, personal data is collected and utilized in tourism or healthcare.
Prior Art Documents
Non-Patent Documents
[0005]
Non-Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0006] However, if users do not know where and how the data collected from them is being utilized, that is, if the traceability of the data collected from users cannot be ensured, many users may be concerned about the risk of data leakage and may not provide the data itself. Furthermore, if there is no benefit for the users, it is also conceivable that the users will not continue to provide data. Therefore, in order to collect sufficient data to enable data utilization, it is necessary not only to ensure the traceability of the data but also to present benefits to the users.
[0007] The present disclosure has been made in view of the above circumstances, and an object thereof is to provide a control method or the like that can present benefits to users while ensuring the traceability of data.
Means for Solving the Problems
[0008] To achieve the above object, a control method according to the present disclosure is a control method in a data distribution system including a plurality of authentication servers each having a distributed ledger and a service server, wherein the service server generates challenge content that is a target determinable based on user data and for which an incentive is given to the user when the target is achieved, which the user challenges, the service server generates a first smart contract programmed to be executable to give an incentive to the user when the target shown in the generated challenge content is achieved, the service server generates first transaction data including the first smart contract and transmits the first transaction data to a first authentication server among the plurality of authentication servers, the first authentication server executes a consensus algorithm for reaching an agreement on the validity of the first transaction data together with a plurality of second authentication servers different from the first authentication server among the plurality of authentication servers, records the first transaction data in the distributed ledger, and operates the first smart contract, the first authentication server notifies the challenge content to a device used by the user, the first authentication server acquires second transaction data including first challenge content selected as a registration target by the user from among the challenge content from the device, and the first authentication server executes a consensus algorithm for reaching an agreement on the validity of the second transaction data together with the plurality of second authentication servers, and records the second transaction data in the distributed ledger.
[0009] These general or specific aspects may be implemented in a system, method, integrated circuit, computer program, or recording medium such as a computer-readable CD-ROM, or may be implemented in any combination of a system, method, integrated circuit, computer program, and recording medium.
Advantages of the Invention
[0010] According to the present disclosure, it is possible to realize a control method or the like that can present benefits to users while ensuring data traceability.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12A
Figure 12B
Figure 13A
Figure 13B
Figure 14A
Figure 14B
Figure 15A
Figure 15B
DETAILED DESCRIPTION OF THE INVENTION
[0012] The control method according to an embodiment of the present disclosure is a control method in a data circulation system including a plurality of authentication servers each having a distributed ledger and a service server, wherein the service server generates challenge content that is a target determinable based on user data and for which an incentive is given to the user when the target challenged by the user is achieved, the service server generates a first smart contract programmed to be executable to give an incentive to the user when the target indicated in the generated challenge content is achieved, the service server generates first transaction data including the first smart contract and transmits the first transaction data to a first authentication server among the plurality of authentication servers, the first authentication server executes a consensus algorithm for agreeing on the validity of the first transaction data together with a plurality of second authentication servers different from the first authentication server among the plurality of authentication servers, records the first transaction data in the distributed ledger, and operates the first smart contract, the first authentication server notifies the challenge content to the device used by the user, the first authentication server acquires second transaction data including first challenge content selected as a registration target by the user from among the challenge content from the device, and the first authentication server executes a consensus algorithm for agreeing on the validity of the second transaction data together with the plurality of second authentication servers, and records the second transaction data in the distributed ledger.
[0013] Accordingly, the challenge content for which an incentive is given to the user when the target challenged by the user is achieved can be notified to the user, and the incentive can be automatically given to the user when it is determined that the challenge has been achieved based on the data acquired from the user. In this way, by presenting the benefit to the user, data can be continuously acquired from the user.
[0014] Furthermore, since it utilizes a distributed ledger, which is blockchain technology, it can record information such as information about the data obtained from the user. That is, data traceability can be ensured.
[0015] Therefore, it is possible to present benefits to the user while ensuring data traceability.
[0016] Also, when it is determined that the goal indicated in the first challenge content has been achieved based on the user's data obtained by the device, the first authentication server acquires third transaction data including information about the data, which is generated in this case. The first authentication server executes a consensus algorithm for reaching an agreement on the validity of the third transaction data together with the plurality of second authentication servers, records the third transaction data in the distributed ledger, and the first smart contract may grant an incentive to the device used by the user when the goal indicated in the first challenge content is achieved when the third transaction data is recorded in the distributed ledger.
[0017] Thereby, based on the data obtained from the user, by recording the transaction data generated when the challenge is actually achieved in the distributed ledger, it is possible to automatically cause the smart contract to grant an incentive to the device used by the user.
[0018] In addition, the first smart contract is further programmed to be able to register support information for the challenge content. The first authentication server obtains fourth transaction data including support information for the first challenge content generated by a device different from the device, and the first authentication server executes a consensus algorithm for reaching an agreement on the validity of the fourth transaction data together with the plurality of second authentication servers, thereby recording the fourth transaction data in the distributed ledger. When the fourth transaction data is recorded in the distributed ledger, the first smart contract may register the support information for the first challenge content.
[0019] By recording, in the distributed ledger, transaction data including support information for the challenge content challenged by the user, it is possible to automatically register, in the smart contract, support information for the challenge content.
[0020] In addition, the first smart contract is further programmed to be able to grant an incentive to a supporter who has registered support information for the first challenge content when the goal indicated by the first challenge content is achieved. When the third transaction data is recorded in the distributed ledger, the first smart contract may grant the incentive granted when the goal indicated by the first challenge content is achieved to the device used by the user and the different device used by the supporter.
[0021] Also, by recording transaction data including support information in the distributed ledger, it is possible to automatically grant an incentive to the device used by the supporter who generated the transaction data in the smart contract.
[0022] Further, the first smart contract may be programmed to be executable to provide more incentives as the number of supporters who register support information for the first challenge content increases.
[0023] As a result, the more supporters who register support information for the challenge content that the user challenges, the more incentives will be provided, and the user can be continuously made to engage in the challenge content. That is, more benefits for the user can be presented.
[0024] Also, the fifth transaction data including a second smart contract programmed to be executable for the first authentication server to determine whether it is possible to provide the data based on the consent information regarding the utilization of the data from the device is obtained, and the second smart contract is operated by recording the fifth transaction data in the distributed ledger. The service server generates sixth transaction data including a data acquisition request indicating a request to acquire the data and transmits it to the first authentication server. The first authentication server acquires the sixth transaction data and records the sixth transaction data in the distributed ledger. When the sixth transaction data is recorded in the distributed ledger, the second smart contract determines whether the data can be provided to the service server. When it is determined by the second smart contract that the data can be provided to the service server, the data may be provided to the service server.
[0025] In this way, since it is recorded that the data has been transferred or made referenceable in the distributed ledger, the data can be utilized while ensuring data traceability. Therefore, the user can provide the data with confidence.
[0026] Further, the challenge content may include a goal for improving or maintaining the user's health, which is determined based on the user's vital data.
[0027] Thereby, challenge content including goals that the user challenges to improve or maintain their health can be presented to the user as a benefit.
[0028] Further, the challenge content may include a goal for the user to perform, for a certain period, a usage method for suppressing the deterioration of a storage battery installed in the house where the user lives, which is determined based on data indicating the remaining amount of the storage battery.
[0029] Thereby, challenge content including goals for an energy-saving and ecological user lifestyle can be presented to the user as a benefit.
[0030] Further, the challenge content may include a goal for the user to perform, for a certain period, an action of covering the electricity used in the house only with a self-generation facility installed in the house where the user lives, which is determined based on data indicating the power generation amount of the self-generation facility and the electricity consumption amount in the house.
[0031] Thereby, challenge content including goals for an energy-saving and ecological user lifestyle that is beneficial to the user can be presented.
[0032] The data circulation system according to an embodiment of the present disclosure is a data circulation system including a plurality of authentication servers and a service server each having a distributed ledger. The service server includes a CPU and a memory. The service server uses the CPU and the memory to generate challenge content, which is a target determinable based on user data and for which an incentive is given to the user when the target challenged by the user is achieved. The service server is programmed to be able to give an incentive to the user when the target indicated in the generated challenge content is achieved, generates a first smart contract, generates first transaction data including the first smart contract, and transmits the first transaction data to a first authentication server among the plurality of authentication servers. The first authentication server, together with a plurality of second authentication servers different from the first authentication server among the plurality of authentication servers, executes a consensus algorithm for agreeing on the validity of the first transaction data, records the first transaction data in the distributed ledger, and operates the first smart contract. The first authentication server causes the first smart contract to notify the challenge content to the device used by the user. The first authentication server acquires second transaction data including first challenge content selected as a registration target by the user from among the challenge content from the device, and executes a consensus algorithm for agreeing on the validity of the second transaction data together with the plurality of second authentication servers, and records the second transaction data in the distributed ledger.
[0033] Hereinafter, embodiments will be described with reference to the drawings. Note that the embodiments described below are all specific examples of the present disclosure. Therefore, the numerical values, shapes, materials, components, arrangements and connection forms of the components, steps, order of steps, etc. shown in the following embodiments are examples of the present disclosure and are not intended to limit the present disclosure. In addition, among the components in the following embodiments, the components not described in the independent claims indicating the implementation forms according to one form of the present disclosure are described as optional components. The implementation forms of the present disclosure are not limited to the current independent claims and can also be expressed by other independent claims.
[0034] (Embodiment 1) [1 System Configuration] In the data circulation system of the present disclosure, it is possible to present benefits to users while ensuring data traceability.
[0035] Hereinafter, the data circulation system and the like in the embodiment will be described with reference to the drawings.
[0036] [1.1 Overall Configuration of Data Circulation System 10] FIG. 1 is a diagram showing an example of the overall configuration of the data circulation system 10 according to the present embodiment. As shown in FIG. 1, the data circulation system 10 includes a house 100, terminals 110 and 120, authentication servers 200a, 200b, and 200c, a detection server 300, and a service server 400. These are connected by a communication network 500.
[0037] The authentication servers 200a, 200b, and 200c (hereinafter also referred to as the authentication server 200) are connected to a storage device having a distributed ledger in which blockchain transaction data and blocks are electronically recorded. Note that the authentication server 200 may be connected to the storage device via the communication network 500 or may include the storage device internally.
[0038] In FIG. 1, an example is shown in which the data circulation system 10 includes three authentication servers 200, but the present invention is not limited to this. That is, the data circulation system 10 may include four or more authentication servers 200.
[0039] [1.2 Configuration of the house 100] FIG. 2 is a diagram showing an example of the overall configuration of the house 100 according to the present embodiment.
[0040] The house 100 is an example of a device according to the present disclosure that acquires or collects user data. The data to be acquired or collected may be, for example, healthcare data such as the user's medical examination data, sleep data, blood pressure data, weight data, exercise data, etc., but is not limited to this. The data to be acquired or collected may be, for example, not limited to healthcare data, but may be any user data that can be utilized by service providers, that is, user personal data. The data to be acquired or collected may be, for example, vital data such as heart rate, or measurement data such as vital data measured by the device or the status of the device, or history information of the device such as the operation history of the device or the operation history of the device.
[0041] In the present embodiment, as shown in FIG. 2, the house 100 includes a controller 101, a solar power generation device 102, a storage battery 103, an air conditioner 104, a body composition monitor 105, and a blood pressure monitor 106. These are connected by a communication network.
[0042] [1.2.1 Controller 101] The controller 101 controls in-house devices such as the air conditioner 104, the body composition monitor 105, and the blood pressure monitor 106. Further, the control unit 1011 may display the operating status of the solar power generation device 102 and the storage battery 103, such as the power generation status of the solar power generation device 102 and the power storage status of the storage battery 103.
[0043] In addition, the controller 101 may collect history information such as the operation history or operation history of in-house devices, or may collect history information on the operation status of the solar power generation device 102 and the storage battery 103. Further, the controller 101 may collect measurement data measured by the in-house devices, or may display the collected measurement data.
[0044] Furthermore, the controller 101 may transmit data such as the collected history information and measurement data to the detection server 300, or may transmit the generated transaction data to the authentication server 200.
[0045] The specific configuration of the controller 101 will be described later.
[0046] [1.2.2 Solar power generation device] The solar power generation device 102 is a device equipped with a power generation method that directly converts sunlight into electricity using solar cells. The power generated by the solar power generation device 102 is used in the house 100 or stored in the storage battery 103. The power generation status of the solar power generation device 102 may be acquired as data of the user living in the house 100, that is, measurement data. Note that the solar power generation device 102 is not an essential component and may not be provided in the house 100.
[0047] [1.2.3 Storage battery 103] The storage battery 103 stores the power generated by the solar power generation device 102. The storage battery 103 may be used in the house 100, such as supplying the stored power to the air conditioner 104, the body composition monitor 105, and the blood pressure monitor 106. In this case, the storage status of the storage battery 103 is acquired as data of the user living in the house 100, that is, measurement data. Note that the storage battery 103 is not an essential component and may not be provided in the house 100.
[0048] [1.2.4 Air conditioner 104, body composition monitor 105, and blood pressure monitor 106] The air conditioner 104, body composition monitor 105, and blood pressure monitor 106 are in-house devices used by the user, and may also be an example of the devices used by the user according to the present disclosure. For example, history information such as the operation history or operation log of the air conditioner 104 is transmitted to the detection server 300. Also, history information such as the operation history or operation log of the body composition monitor 105 and blood pressure monitor 106, the weight data of the user measured by the body composition monitor 105, and / or measurement data such as the blood pressure data of the user measured by the blood pressure monitor 106 are also transmitted to the detection server 300. The weight data and blood pressure data of the user are an example of the measurement data of the present disclosure, but are also referred to as the user's vital data. Note that these data may be transmitted to the detection server 300 via the controller 101, or may be directly transmitted to the detection server 300.
[0049] Hereinafter, an example of the configuration of the controller 101 will be described.
[0050] [1.3 Configuration of Controller 101] FIG. 3 is a block diagram showing an example of the configuration of the controller 101 shown in FIG. 2.
[0051] The controller 101 includes a processor (not shown) and a memory (not shown) in which a program for causing the processor to execute a predetermined process is stored. That is, the controller 101 is realized by the processor executing a predetermined program using the memory. In the present embodiment, as shown in FIG. 3, the controller 101 includes a control unit 1011, a transaction data generation unit 1012, an input unit 1013, a recording unit 1014, and a communication unit 1015.
[0052] [1.3.1 Control Unit 1011] The control unit 1011 may control home appliances. In the example shown in FIG. 2, the control unit 1011 operates home appliances such as the air conditioner 104, the body composition monitor 105, and the blood pressure monitor 106, and manages the operation history and status of the home appliances. Further, the control unit 1011 may display the operating status of the solar power generation device 102 and the storage battery 103. For example, the control unit 1011 may display the power generation status of the solar power generation device 102 or the power storage status of the storage battery 103. Further, the control unit 1011 may display the status of the home appliances or the vital data measured by the body composition monitor 105 or the blood pressure monitor 106.
[0053] Further, the control unit 1011 may collect history information such as the operation history or operation history of home appliances, or may collect history information on the operating status of the solar power generation device 102 and the storage battery 103. Further, the control unit 1011 may collect measurement data measured by home appliances.
[0054] [1.3.2 Input Unit 1013] The input unit 1013 generates consent information regarding the utilization of the acquired or collected data. Here, the consent information is information indicating the content to which the user consents to the utilization of the acquired or collected data, and is generated based on the user's operation. The consent information may be generated, for example, by selecting or deselecting from a list of service providers or a list of data of the data provider provided by the input unit 1013. In this case, the consent information includes the service providers for which data can be provided that the user has consented to, or the data or types of data that the user has consented to provide. That is, the consent information includes the service providers that the user has consented to provide, or the data or types of data. Further, the consent information may further include information consenting to provide when the feedback is a certain level or more.
[0055] In this case, the input unit 1013 may generate a smart contract (hereinafter referred to as the first smart contract) based on the generated consent information. Here, the first smart contract is programmed to be executable to determine whether data can be provided. The first smart contract may include the consent information generated by the input unit 1013.
[0056] In addition, the input unit 1013 selects the first challenge content from among the challenge contents provided by the service provider through the user's operation. Here, the challenge content is a target that can be determined based on the user's data and includes one or more targets for which an incentive is given to the user upon achievement of the target that the user challenges. For example, walking more than 10,000 steps a day, losing 1 kilogram in a month, or improving blood pressure by 3% in a year. The challenge content is a target that the user challenges to improve or maintain the user's health and includes a target determined based on the user's vital data. Note that the target to be challenged may be referred to as a challenge item. Also, the challenge content is not limited to targets related to the user's health. The challenge content may include targets related to healthcare, such as a target for which the user challenges to improve the values of step count data or blood pressure data. As a target related to healthcare, for example, it may be a target to register the data from the previous health checkup and consider it a challenge achievement if there is an improvement in the data from the next health checkup. Also, as a target related to healthcare, it may be the exercise time or sleep time per week or day over a certain period. Also, the challenge content may include targets related to learning, such as a target for the study time for the user to obtain a qualification or acquire a language, or may include a target for improving lifestyle habits. Furthermore, the challenge content may include a target for an energy-saving and ecological user lifestyle. For example, as the challenge content, it may include a target for the user to perform a usage method for suppressing the deterioration of the storage battery 103 installed in the house 100 where the user lives for a certain period, and the target is determined based on the data indicating the remaining amount of the storage battery 103. Also, as the challenge content, it may include a target for the user to perform an action to cover the electricity used in the house only with the self-generation equipment installed in the house 100 where the user lives for a certain period, and the target is determined based on the data indicating the power generation amount of the self-generation equipment and the electricity consumption amount in the house 100. In the present embodiment, the self-generation equipment is the solar power generation device 102, but it may be self-generation equipment using wind power, geothermal energy, or gas.
[0057] The input unit 1013 may select the first challenge content by selecting or deselecting from among a list of goals included in the challenge content provided by the service provider.
[0058] Note that the input unit 1013 may be an application installed in the controller 101. In that case, the installed application realizes the above functions of the input unit 1013.
[0059] [1.3.3 Transaction Data Generation Unit 1012] The transaction data generation unit 1012 generates transaction data in the blockchain. In the present embodiment, the transaction data generation unit 1012 generates transaction data including the consent information generated by the input unit 1013. More specifically, the transaction data generation unit 1012 generates, for example, transaction data including a blockchain address held by a user, consent information including a service provider or data or data types consented to by the user, and a signature. Note that the transaction data generation unit 1012 may further generate transaction data by assigning an identifier. The transaction data generation unit 1012 generates a signature using a user-specific signature generation key.
[0060] Further, the transaction data generation unit 1012 may generate transaction data (hereinafter also referred to as first transaction data) including the first smart contract generated by the input unit 1013. Also, the transaction data generation unit 1012 may generate first transaction data including the consent information and the first smart contract generated by the input unit 1013. Note that the first transaction data is an example of the fifth transaction data according to the present disclosure.
[0061] In addition, the transaction data generation unit 1012 generates transaction data (hereinafter referred to as the third transaction data) including the first challenge content selected by the input unit 1013. The third transaction data is an example of the second transaction data according to the present disclosure.
[0062] More specifically, the transaction data generation unit 1012 generates, for example, the third transaction data including the blockchain address held by the user, the selected first service content, and a signature. The transaction data generation unit 1012 may further generate the third transaction data by assigning an identifier. The transaction data generation unit 1012 generates a signature using a user-specific signature generation key. The selected first service content may include the service provider that provided the selected first service content and the type of data for determining the goal of the first service content.
[0063] In addition, the transaction data generation unit 1012 may generate transaction data (hereinafter also referred to as the fourth transaction data) including information indicating the user's data such as the history information or measurement data collected by the control unit 1011. In this case, the transaction data generation unit 1012 may generate, for example, the fourth transaction data including the blockchain address held by the user, the information indicating the data collected by the control unit 1011, and a signature. Here, the information indicating the data may be, for example, the user's data itself collected by the control unit 1011, the hash value of the data, or the hash value of the data and the attribute information of the data.
[0064] The attribute information of the data may include, for example, the type of the sensor or device that collected the data. Also, when the data is step count data, body weight data, body fat percentage data, blood pressure data, etc., the attribute information of the data may include data items indicating when, how, and in which item the data was measured or collected. Even when the data is for in-home devices such as home appliances, data items indicating their operation history, operation date and time, etc. may be included.
[0065] The transaction data generation unit 1012 records the generated transaction data in the recording unit 1014. The transaction data generation unit 1012 transmits it to the authentication server 200 or the detection server 300 via the communication unit 1015.
[0066] [1.3.4 Recording Unit 1014] The recording unit 1014 records data such as the history information and measurement data collected by the control unit 1011. Also, the recording unit 1014 records the transaction data generated by the transaction data generation unit 1012. Further, the recording unit 1014 may record the consent information and smart contract generated by the input unit 1013.
[0067] [1.3.5 Communication Unit 1015] The communication unit 1015 communicates with the authentication server 200, the detection server 300, and the service server 400 via the communication network 500. This communication may be performed by TLS (Transport Layer Security). In this case, the encryption key for TLS communication may be held by the communication unit 1015.
[0068] In the present embodiment, when the communication unit 1015 receives a notification of the challenge content from, for example, the authentication server 200a, etc., it records it in the recording unit 1014 and notifies the input unit 1013 to that effect.
[0069] Subsequently, an example of the configuration of the terminal 110 will be described.
[0070] [1.4 Configuration of Terminal 110] Terminal 110 or terminal 120 is an example of a device used by a user according to the present disclosure. In this case, terminal 110 or terminal 120 is a device having a display unit and an input unit such as a smartphone, or a device that collects measurement data of a user such as a wearable device. Further, terminal 110 or terminal 120 may be an example of a device used by a supporter according to the present disclosure. In this case, it is a device having a display unit and an input unit such as a smartphone. Terminal 110 and terminal 120 are both realized by a processor executing a predetermined program using a memory. Supporters will be described later.
[0071] Since terminal 110 and terminal 120 have the same configuration, terminal 110 will be described as an example below.
[0072] FIG. 4 is a block diagram showing an example of the configuration of terminal 110 according to the present embodiment.
[0073] In the present embodiment, as shown in FIG. 4, terminal 110 includes a transaction data generation unit 1101, an input unit 1102, a data acquisition unit 1103, a recording unit 1104, and a communication unit 1105. Hereinafter, it will be described on the assumption that terminal 110 is used by a user and terminal 120 is used by a supporter.
[0074] [1.4.1 Input Unit 1102] The input unit 1102 generates consent information of the user regarding the utilization of data. As described above, the consent information is information indicating the content to which the user consents to the utilization of the acquired or collected data, and is generated based on the operation of the user.
[0075] For example, the consent information may be generated by selecting or deselecting from a list of service providers or a list of data provided by the input unit 1013. In this case, the user may select a service provider of the data destination based on the purpose of data utilization, the actual results of data utilization, or feedback or incentives to the user due to data utilization. As an example of incentives or feedback, when the user provides data to a service provider, virtual currency may be paid to the user by the service provider or information indicating that it can be enjoyed may be displayed. Also, as an example of incentives or feedback, when the user provides measurement data such as a measurement history of a body composition meter or a blood pressure meter to a sports club, information indicating that a free trial or a reduction in membership fees can be enjoyed may be displayed.
[0076] In this case, the input unit 1102 may generate a first smart contract that is programmatically executable to determine whether data can be provided based on the generated consent information. The first smart contract is an example of the second smart contract according to the present disclosure.
[0077] Also, the input unit 1102 may select first challenge content by the user's operation from among the challenge content provided by the service provider.
[0078] When the terminal 120 or the terminal 110 is used as a supporter, the input unit 1102 generates support information for supporting the user's challenge based on the user's information by the operation of the supporter.
[0079] Here, the support information is information for supporting users who challenge the goals indicated by the first challenge content. The first challenge content is the challenge content selected and registered by the user among the challenge contents provided by the service provider. Also, the support information may be generated by being selected from a list of the support contents provided by the service provider and the registered first challenge content. When the goal indicated by the first challenge content supported by the supporter who generated and registered the support information is achieved, an incentive is given. Therefore, the support information may be generated by being selected by the incentive at the time of challenge achievement due to the support from a list of the support contents provided by the service provider and the registered first challenge content.
[0080] Also, the supporter may give virtual currency or points to the user being supported. In this case, the support information may be generated including that fact. Also, the support information may be further generated including a message or the like indicating that the supporter is supporting.
[0081] Note that the input unit 1102 may be an application installed in the controller 101, and in that case, the installed application realizes the above functions of the input unit 1102.
[0082] [1.4.2 Transaction Data Generation Unit 1101] The transaction data generation unit 1101 generates transaction data in the blockchain. In the present embodiment, the transaction data generation unit 1101 generates transaction data in the blockchain including the consent information generated by the input unit 1102. More specifically, the transaction data generation unit 1101 generates, for example, transaction data including a blockchain address held by the user, consent information including the service provider or data or types of data that the user has consented to provide, and a signature.
[0083] Note that the transaction data generation unit 1101 may further generate transaction data by assigning an identifier. The transaction data generation unit 1101 may generate a signature using a user-specific signature generation key.
[0084] In addition, the transaction data generation unit 1101 may generate first transaction data including the first smart contract generated by the input unit 1102. Further, the transaction data generation unit 1101 may generate first transaction data including the consent information generated by the input unit 1102 and the first smart contract.
[0085] In addition, the transaction data generation unit 1101 generates third transaction data including the first challenge content selected by the input unit 1102. More specifically, the transaction data generation unit 1101 generates, for example, third transaction data including the blockchain address held by the user, the selected first service content, and a signature. The transaction data generation unit 1101 may further generate third transaction data by assigning an identifier. The transaction data generation unit 1101 generates a signature using a user-specific signature generation key. Note that the selected first service content may include the service provider that provided the selected first service content and the type of data for determining the goal of the first service content.
[0086] In addition, the transaction data generation unit 1101 may generate fourth transaction data including information indicating the user's data such as the measurement data acquired by the data acquisition unit 1103. In this case, the transaction data generation unit 1101 may generate, for example, fourth transaction data including the blockchain address held by the user, information indicating the data acquired by the data acquisition unit 1103, and a signature. The information indicating the user's data may be, for example, the data itself acquired by the data acquisition unit 1103, the hash value of the data, or the hash value of the data and the attribute information of the data.
[0087] In addition, when the terminal 120 or the terminal 110 is used by a supporter, the transaction data generation unit 1101 generates transaction data (hereinafter also referred to as the eighth transaction data) including support information for the first challenge content. Note that the eighth transaction data is an example of the fourth transaction data according to the present disclosure. In the present embodiment, when the terminal 120 or the terminal 110 is used by a supporter, the transaction data generation unit 1101 generates the eighth transaction data including the support information generated by the input unit 1102. More specifically, the transaction data generation unit 1101 generates, for example, the eighth transaction data including the blockchain address held by the user, the generated support information, the address and signature of the second smart contract. The transaction data generation unit 1101 may further generate the eighth transaction data by assigning an identifier. The transaction data generation unit 1101 generates a signature using a user-specific signature generation key.
[0088] The transaction data generation unit 1101 records the generated transaction data in the recording unit 1104. The transaction data generation unit 1101 transmits the generated transaction data to the authentication server 200 or the detection server 300 via the communication unit 1105.
[0089] [1.4.3 Data acquisition unit 1103] The data acquisition unit 1103 acquires data such as measurement data obtained by sensors held by the terminal 110. For example, when the terminal 110 has an acceleration sensor and a GPS sensor, the data acquisition unit 1103 acquires, as measurement data, step count data including the number of steps obtained from the acceleration sensor and the position information obtained from the GPS sensor. In addition, the data acquisition unit 1103 may acquire blood pressure data or heart rate data as measurement data. That is, the data acquisition unit 1103 acquires data that can be utilized by service providers.
[0090] The data acquisition unit 1103 records the acquired data in the recording unit 1104. The data acquisition unit 1103 may transmit the data to the detection server 300 via the communication unit 1105.
[0091] [1.4.4 Recording Unit 1104] The recording unit 1104 records the transaction data generated by the transaction data generation unit 1101. In addition, the recording unit 1104 records the data acquired by the data acquisition unit 1103. Note that the recording unit 1104 may record the consent information and the first smart contract generated by the input unit 1102.
[0092] [1.4.5 Communication Unit 1105] The communication unit 1105 communicates with the authentication server 200 and the detection server 300 via the communication network 500. This communication may be performed by TLS. In this case, the encryption key for TLS communication may be held by the communication unit 1105.
[0093] In the present embodiment, when the communication unit 1105 receives a notification of challenge content from, for example, the authentication server 200a, it records the notification in the recording unit 1104 and notifies the input unit 1102 to that effect.
[0094] Note that when the terminal 120 or the terminal 110 is used by a supporter, the communication unit 1105 may acquire information of a user who has registered a challenge from, for example, the authentication server 200a and display the user information on the input unit 1102. The user who has registered a challenge means a user recorded in the challenge content including the challenge target.
[0095] Subsequently, an example of the configuration of the authentication server 200 will be described.
[0096] [1.5 Configuration of Authentication Server 200a] FIG. 5 is a block diagram showing an example of the configuration of the authentication server 200a according to the present embodiment. Since the authentication servers 200b and 200c have the same configuration, the authentication server 200a will be described as an example below.
[0097] As shown in FIG. 5, the authentication server 200a includes a transaction data verification unit 211, a block generation unit 212, a synchronization unit 213, a smart contract execution unit 214, a recording unit 215, and a communication unit 216. The authentication server 200a can be realized by a processor executing a predetermined program using a memory. Hereinafter, each component will be described.
[0098] [1.5.1 Transaction Data Verification Unit 211] The transaction data verification unit 211 verifies the received transaction data. Specifically, when receiving transaction data from devices such as the house 100, the terminal 110, the terminal 120, the detection server 300, or the service server 400, the transaction data verification unit 211 verifies whether the format of the transaction data is correct and whether the signature is valid. For example, when verifying transaction data including consent information, the transaction data verification unit 211 verifies whether the address, consent information, and signature included in the transaction data are valid. Note that, for example, when verifying transaction data including information indicating data, the transaction data verification unit 211 only needs to verify whether the address, information indicating data, and signature included in the transaction data are valid.
[0099] In this way, the transaction data verification unit 211 verifies the transaction data by confirming the validity of the received transaction data.
[0100] If the transaction data verification unit 211 confirms the validity of the transaction data as a result of verification, it records the transaction data in the recording unit 215. Here, if it is determined that the transaction data is legitimate, it notifies the synchronization unit 213.
[0101] [1.5.2 Block Generation Unit 212] When the transaction data verification in the transaction data verification unit 211 is successful, the block generation unit 212 executes a consensus algorithm for the transaction data among the plurality of authentication servers 200. Here, as the consensus algorithm, a consensus algorithm called PBFT (Practical Byzantine Fault Tolerance) may be used, or other known consensus algorithms such as PoW (Proof of Work) may be used.
[0102] In the present embodiment, the block generation unit 212 executes a consensus algorithm among the authentication server 200a, the authentication server 200b, and the authentication server 200c. That is, the block generation unit 212 first generates a block of the blockchain including one or more pieces of transaction data. Next, the block generation unit 212 executes a consensus algorithm. Then, when an agreement can be formed by executing the consensus algorithm, the block generation unit 212 records the generated block in the recording unit 215. The block generated by the block generation unit 212 is connected to the blockchain by the recording unit 215 and recorded.
[0103] Here, the data structure of the blockchain will be described.
[0104] FIG. 6 is an explanatory diagram showing the data structure of the blockchain.
[0105] A blockchain is a structure in which its recording units, i.e., blocks, are connected in a chain-like manner. Each block has a plurality of transaction data and the hash value of the previous block. Specifically, block B2 contains the hash value of the previous block B1. Then, the hash value calculated from the plurality of transaction data contained in block B2 and the hash value of block B1 is included in block B3 as the hash value of block B2. By connecting the blocks in a chain-like manner while including the content of the previous block as a hash value, it effectively prevents the alteration of the connected transaction data.
[0106] If the past transaction data is altered, the hash value of the block will become a different value from that before the alteration. To make the altered block appear as a correct one, all subsequent blocks have to be recreated, which is extremely difficult in reality.
[0107] [1.5.3 Synchronization Unit 213] The synchronization unit 213 synchronizes the blocks of the blockchain or the transaction data among a plurality of authentication servers 200 (authentication servers 200a to 200c).
[0108] In the synchronization units 213 of the plurality of authentication servers 200, the transaction data of the blockchain is synchronized in a peer-to-peer manner. Then, the synchronization unit 213 records the synchronized transaction data of the blockchain in the recording unit 215. For example, when the validity of the transaction data is verified in the transaction data verification unit 211, the synchronization unit 213 transfers the verified transaction data to the authentication servers 200b and 200c, which are other authentication servers 200. Also, when the synchronization unit 213 receives the verified transaction data from other authentication servers 200, it records the received verified transaction data in the recording unit 215.
[0109] [1.5.4 Smart Contract Execution Unit 214] The smart contract execution unit 214 stores the smart contract recorded in the distributed ledger in the working memory. The smart contract execution unit 214 executes the smart contract stored in the working memory.
[0110] For example, when transaction data including a smart contract is recorded in the distributed ledger, that is, when a block including the transaction data is generated and recorded in the distributed ledger, the smart contract execution unit 214 stores the smart contract in the working memory. Here, assume that the smart contract is a first smart contract generated based on the user's consent information. In this case, the smart contract execution unit 214 can cause the executed first smart contract to determine whether data can be provided by executing the first smart contract stored in the working memory. In addition, the executed first smart contract notifies the determination result of whether data can be provided or grants access rights to the blockchain address included in the transaction data including the data acquisition request. In this way, the smart contract execution unit 214 can manage the access of the service server 400 to the data held by the detection server 300 by triggering the access from the service server 400 and executing the smart contract.
[0111] Also, assume that the smart contract is a second smart contract generated based on the challenge content. In this case, the smart contract execution unit 214 executes the second smart contract stored in the working memory, so that the executed second smart contract is given an incentive when the challenge is achieved. Also, when support information is recorded, the smart contract execution unit 214 executes the second smart contract to register support information for the challenge content in the second smart contract. Note that the second smart contract is an example of the first smart contract according to the present disclosure. Also, the registration of support information for the challenge content means recording the support information recorded in the distributed ledger for the challenge content managed by being described in the second smart contract.
[0112] Also, for example, assume that the smart contract is a third smart contract generated based on incentive payment or feedback provision for user data provision or user data reference. In this case, the smart contract execution unit 214 executes the third smart contract stored in the working memory, so that the executed third smart contract can provide incentive payment or feedback to the device of the user who provided the data. The incentive payment or feedback provision may be by notifying that the incentive payment has been made or the feedback has been provided, or by providing incentive payment or feedback to the device used by the user who provided the data.
[0113] [1.5.5 Recording Unit 215] The recording unit 215 includes transaction data in a block and records it in the distributed ledger of the authentication server 200a. Also, the recording unit 215 records the smart contract for recording and operating in the distributed ledger. The distributed ledger may be configured inside the recording unit 215, or may be configured inside the external storage device of the authentication server 200a.
[0114] In addition, the recording unit 215 also records user information such as the challenge content and the identification information of the user who registered the challenge content.
[0115] The transaction data includes the transaction data received from devices such as the house 100, the terminal 110, the terminal 120, the detection server 300, or the service server 400.
[0116] In the present embodiment, when the validity of the received transaction data is confirmed, the recording unit 215 records the block including the transaction data in the distributed ledger of the authentication server 200a. The blocks of the blockchain recorded in the distributed ledger may be made public to the service server 400, the house 100, the terminal 110, the terminal 120, or the service server 400.
[0117] [1.5.6 Communication Unit 216] The communication unit 216 communicates with the house 100, the terminal 110, the terminal 120, the authentication servers 200b and 200c, the detection server 300, and the service server 400. This communication may be performed by TLS. In this case, the cryptographic key for TLS communication may be held by the communication unit 216.
[0118] In the present embodiment, when the second smart contract operates, the communication unit 216 notifies the terminal 110 of the challenge content. In addition, when there is a request from the terminal 120 to refer to the challenge content, the communication unit 216 provides the challenge content recorded in the recording unit 215 and the user information of the user who registered the challenge content in a referable manner. The notification of the challenge content may be performed by the second smart contract when the smart contract can implement a notification function.
[0119] In this way, the authentication server 200a performs processes for verifying the validity of data acquired from devices such as the house 100, the terminal 110, and the terminal 120, managing whether data can be provided, and providing data to the service server 400. Although it has been described that the data acquired from devices such as the house 100, the terminal 110, and the terminal 120 is recorded by the detection server 300 and not by the authentication server 200a, this is not the only case. The authentication server 200a may record the data. In this case, it may be recorded as transaction data including the data in the distributed ledger of the authentication server 200a.
[0120] Next, the detection server 300 will be described.
[0121] [1.6 Configuration of Detection Server 300] FIG. 7 is a block diagram showing an example of the configuration of the detection server 300 according to the present embodiment.
[0122] As shown in FIG. 7, the detection server 300 includes a data management unit 311, a detection unit 312, a transaction data generation unit 313, a recording unit 314, and a communication unit 315. The detection server 300 can be realized by a processor executing a predetermined program using a memory. Hereinafter, each component will be described.
[0123] [1.6.1 Data Management Unit 311] The data management unit 311 manages data acquired from devices such as the house 100, the terminal 110, and the terminal 120. The data management unit 311 records in the recording unit 314 the data that has been detected by the detection unit 312 not to be illegal data. The data management unit 311 may send the attribute information of the data acquired from devices such as the house 100, the terminal 110, and the terminal 120 to the transaction data generation unit 313. Note that the attribute information of the data may include, as described above, the type of sensor or device that collected the data or the data item. Further, the data management unit 311 may record in the recording unit 314 the data that has been detected by the detection unit 312 to be illegal data, with information indicating that it is illegal data attached.
[0124] When the data management unit 311 detects that the data acquired from devices such as the terminal 110 by the detection unit 312 is not illegal data, the data management unit 311 transmits the fourth transaction data acquired from devices such as the terminal 110 to the authentication server 200a or the like.
[0125] Furthermore, when the data management unit 311 detects, based on the data included in the fourth transaction data by the detection unit 312, that the target indicated in the first challenge content has been achieved, the data management unit 311 causes the transaction data generation unit 313 to generate fifth transaction data. Then, the data management unit 311 transmits the generated fifth transaction data to the authentication server 200a or the like. Note that the fifth transaction data is an example of the third transaction data according to the present disclosure.
[0126] In addition, when the data management unit 311 receives a data provision request from the service server 400, the data management unit 311 provides the user's data based on the consent information recorded in the distributed ledger of the authentication server 200. In the present embodiment, it is assumed that the first smart contract generated based on the consent information is executed by the authentication server 200, and the detection server 300 receives a notification indicating that data provision is possible from the authentication server 200. In this case, when the data management unit 311 receives a data provision request from the service server 400, the data management unit 311 provides the user's data. Note that the data management unit 311 may also acquire, from the service server 400, a blockchain address corresponding to the data for which data provision is desired together with the data provision request.
[0127] [1.6.2 Detection Unit 312] The detection unit 312 detects, based on the data acquired from devices such as the terminal 110, whether the user of the terminal 110 has achieved the target to be challenged indicated in the first challenge content registered by the user.
[0128] Further, the detection unit 312 detects whether the data acquired from devices such as the house 100, the terminal 110, and the terminal 120 is illegal data.
[0129] For example, when the detection unit 312 measures a step count of 10,000 steps or more in 10 minutes in the step count data, the detection unit 312 may detect that the step count data is illegal data. Since it is impossible for a person such as a user to walk 10,000 steps in 10 minutes, when the measured step count is 10,000 steps or more in 10 minutes, it can be considered that the step count data has been tampered with and is illegal data.
[0130] In this way, when the detection unit 312 acquires the measured step count data from a device such as the terminal 110, if the step count data includes a step count that is equal to or greater than a threshold value within a predetermined period, the detection unit 312 may detect that the step count data is illegal data.
[0131] In addition, when the step count data includes a step count that increases at a certain rate at a time equal to or greater than the threshold value, the detection unit 312 may detect that the step count data is illegal data. When the step count increases at a certain rate at a time equal to or greater than the threshold value, it is considered that illegal operations such as operating the terminal 110 or the like that holds a sensor using a pendulum or the like are being performed, and the step count data can be considered to be illegal data.
[0132] In addition, for example, when the detection unit 312 acquires step count data including the measured step count and the position information at the time of measurement from a device such as the terminal 110, if the step count data includes a step count in a state where the position information does not change for a predetermined time or more, the detection unit 312 may detect that the step count data is illegal data. When the step count increases even though the position information does not change, it is considered that illegal operations such as operating the terminal 110 or the like that holds a sensor using a pendulum or the like are being performed, and the step count data can be considered to be illegal data.
[0133] Also, for example, when obtaining step count data including the measured step count and heart rate at the time of measurement from a device such as the terminal 110, the detection unit 312 may detect that the step count data is invalid data when the step count data includes a step count in a state where the heart rate does not change for a predetermined time or more.
[0134] Also, for example, when obtaining step count data during measurement from a device such as the terminal 110, the detection unit 312 may transmit a message for causing the user to make some input to the device such as the terminal 110. Then, when the detection unit 312 cannot obtain any input result for the message from the device, it may detect that the obtained step count data is invalid data.
[0135] Also, when obtaining measurement data of a body composition monitor from a device such as the terminal 110, the detection unit 312 may detect that the obtained measurement data is invalid data when the measurement data includes a body composition measurement value that has changed by a value equal to or greater than a threshold value from the previous body composition measurement value.
[0136] Also, when obtaining measurement data of a body composition monitor from a device such as the terminal 110, the detection unit 312 may detect that the measurement data is invalid data when there is a change equal to or greater than a threshold value within a certain period from the previous body composition measurement value. Specifically, the detection unit 312 may detect that the measurement data of the blood pressure value is invalid data when the blood pressure value measured within 1 minute from the previous blood pressure value has changed by 30 or more. Also, the detection unit 312 may detect that the measurement data of the body composition measurement value is invalid data when the body composition measurement value measured within 1 day from the previous body composition measurement value has changed by 5 kilograms or more.
[0137] Also, for example, when obtaining data from a device such as the terminal 110 and further obtaining information indicating that the device is abnormal, the detection unit 312 may detect that the obtained data is invalid data.
[0138] Note that the detection unit 312 may detect abnormalities in devices such as the solar power generation device 102 or the storage battery 103 of the house 100. For example, the detection unit 312 obtains weather information from an external server (not shown), and when the amount of power generated by the solar power generation device 102 is large even though the weather is not sunny, it may detect that the solar power generation device 102 is abnormal or faulty. Also, for example, the detection unit 312 may detect that the storage battery 103 is abnormal or faulty when the remaining amount of the storage battery 103 does not decrease even though devices such as the air conditioner 104 in the house 100 are using the power of the storage battery 103.
[0139] In addition to detecting that the acquired data may be illegal data, the detection unit 312 may also detect abnormal operation or non-operation due to malfunctions such as device failures. Specifically, when the detection unit 312 cannot receive data regularly acquired from devices such as the solar power generation device 102 or the storage battery 103 of the house 100, or when the acquired data is abnormal data such as the acquired data being damaged, it may detect that the device is faulty.
[0140] Also, the detection unit 312 may use data from other terminals or other houses to detect abnormalities in devices such as the solar power generation device 102 or the storage battery 103 of the house 100. For example, the detection unit 312 uses the power generation amount of the solar power generation device of the house adjacent to the house 100 to verify the power generation amount of the solar power generation device 102 acquired from the house 100, and if it differs by more than the threshold value, it may detect that the solar power generation device 102 is abnormal or faulty. Also, it may be possible to verify the data based on data received in the past from the terminal or devices in the house and data of the user who uses the terminal.
[0141] Also, when the detection unit 312 detects that the data acquired from a device such as the terminal 110 is not illegal data, it transmits the data to the data management unit 311 and records it in the recording unit 314.
[0142] On the one hand, when the detection unit 312 detects that the data acquired from devices such as the house 100 or the terminal 110 is illegal data, the detection unit 312 may discard the data, or may add an attribute indicating that the data is illegal data to the data and record it in the recording unit 314. Then, the detection unit 312 may transmit the attribute information added with the indication of being illegal data to the transaction data generation unit 313.
[0143] In addition, when the detection unit 312 detects that the data acquired from the device is illegal data or detects an abnormality of the device, the detection unit 312 may send a notice to that effect to the controller 101 of the terminal 110 or the house 100 and inquire with the user.
[0144] [1.6.3 Transaction Data Generation Unit 313] When it is determined that the goal shown in the first challenge content has been achieved based on the user data acquired by a device such as the terminal 110, the transaction data generation unit 313 generates fifth transaction data including information about the data.
[0145] In the present embodiment, when the detection unit 312 detects that the goal shown in the first challenge content has been achieved by the data acquired from a device such as the terminal 110, the transaction data generation unit 313 generates fifth transaction data. Here, the fifth transaction data includes an indication that the first challenge content has been achieved in addition to the information included in the fourth transaction data.
[0146] The transaction data generation unit 313 records the generated fifth transaction data in the recording unit 314. In addition, the transaction data generation unit 313 transmits the generated fifth transaction data to the authentication server 200 via the communication unit 315.
[0147] [1.6.4 Recording Unit 314] When the recording unit 314 acquires data from a device such as the terminal 110, it records the acquired data. Further, the recording unit 314 records the detection result of detecting whether the data acquired by the detection server 300 is illegal data. Further, the recording unit 314 records the first challenge content registered by the user of the terminal 110 stored in the distributed ledger of the authentication server 200a or the like. Further, when the transaction data generation unit 313 generates the fifth transaction data, the recording unit 314 records the fifth transaction data.
[0148] [1.6.5 Communication unit 315] The communication unit 315 communicates with the house 100, the terminal 110, the terminal 120, the authentication server 200, and the service server 400 via the communication network 500. This communication may be performed by TLS. In this case, the encryption key for TLS communication may be held by the communication unit 315.
[0149] In this way, the detection server 300 detects whether the data acquired from a device such as the terminal 110 achieves the target indicated by the first challenge content registered by the user of the terminal 110. Further, the detection server 300 detects whether the data acquired from the terminal 110 or the like is illegal data, and records the data. For example, when the detection server 300 acquires step count data from the terminal 110 and detects that the step count data is not illegal data, the detection server 300 records the data and records information about the data in the authentication server 200.
[0150] In the present embodiment, the detection server 300 and the authentication server 200 are described as independent servers, but the present invention is not limited to this. The function of the detection server 300 may be included in the authentication server 200 and operate.
[0151] Subsequently, an example of the configuration of the service server 400 will be described.
[0152] [1.7 Configuration of service server 400] FIG. 8 is a block diagram showing an example of the configuration of the service server 400 according to the present embodiment.
[0153] The service server 400 is a server managed by a service provider to provide services, and is, for example, a server of a sports club. In the present embodiment, as shown in FIG. 8, the service server 400 includes a service management unit 411, a user management unit 412, a transaction data generation unit 413, a recording unit 414, and a communication unit 415. The service server 400 can be realized by a processor such as a CPU executing a predetermined program using a memory. Hereinafter, each component will be described.
[0154] [1.7.1 Service Management Unit 411] The service management unit 411 utilizes the information of the users managed by the user management unit 412 to provide services. For example, the service management unit 411 acquires data including measurement data such as the body composition measurement value or blood pressure measurement value of the user from the detection server 300, and provides a new healthcare service or demonstrates the effect.
[0155] In the present embodiment, the service management unit 411 generates challenge contents provided by the service provider. As described above, the challenge contents include at least one first challenge content that is a target determinable based on user data and that an incentive is given to the user when the target that the user challenges is achieved. As described above, the challenge contents include, for example, a target that the user challenges such as walking 10,000 steps or more per day, which is determined based on the user's vital data. Other examples will be omitted because they will be repeated.
[0156] Also, in the present embodiment, the service management unit 411 manages incentives for users who challenge and achieve the targets shown in the challenge contents. The incentive to the user for achieving the challenge may be the distribution of a predetermined amount of virtual currency, or the provision of a predetermined amount of points or a predetermined service.
[0157] The service management unit 411 generates a second smart contract that is programmed to be able to grant an incentive to a user when the goal shown in the generated challenge content is achieved.
[0158] In this embodiment, the challenge content is described and managed in the second smart contract. The authentication server 200a or the like can notify the user of the challenge content by referring to the challenge content managed in the second smart contract.
[0159] Note that the second smart contract may be further programmed to be able to register support information for the challenge content. In this case, the second smart contract is programmed to be able to grant an incentive to the supporter who registered the support information for the challenge content when the goal shown in the challenge content is achieved. Further, the second smart contract may be programmed to grant more incentives as the number of supporters who registered the support information for the challenge content is larger.
[0160] Also, the service management unit 411 manages a service that can register a user who is a supporter who supports a user who has registered challenge content including a challenge goal, that is, a user who has registered a challenge. Here, when a supporter is registered, the service management unit 411 not only manages the incentive given to the user for achieving the challenge of the challenge content in which the support information is recorded, but also manages the incentive given to the supporter. Note that the service management unit 411 may manage support for achieving the challenge, such as sending virtual currency, points, or a message indicating support prepared by the supporter to the user who has achieved the challenge.
[0161] In addition, the service management unit 411 generates a data acquisition request indicating a request to acquire data by using the information of the users managed by the user management unit 412, and transmits it to the transaction data generation unit 413. For example, the service management unit 411 determines what data of the user it wants to acquire, and generates a data acquisition request based on the attribute information of the user it wants to acquire or the type of data it wants to acquire. The data acquisition request may include, for example, a request specifying the identifier of the user if the identifier of the user is already known in advance, a request specifying the blockchain address, or a request specifying an attribute. The attribute here may be the type of device such as the house 100 or the terminal 110, the type of data acquired from the device, or the attribute of the user.
[0162] In addition, when the service management unit 411 acquires data, as consideration for the acquired data, it generates information regarding incentive payment or feedback provision to the user of the acquired or referenced data, and transmits it to the transaction data generation unit 413. Here, the information regarding incentive payment or feedback provision may include that virtual currency has been paid to the user's blockchain address as consideration for the acquired data.
[0163] Note that in this embodiment, the service management unit 411 generates a third smart contract based on incentive payment or feedback provision for the user's data provision or the user's data reference. The third smart contract may include, for example, a program for executing the payment of virtual currency to the user's blockchain address as consideration for the acquired data.
[0164] [1.7.2 User Management Unit 412] The user management unit 412 manages the information of the users who provide services.
[0165] The user management unit 412 acquires information on users who are targets of service provision and manages the acquired user information.
[0166] In the present embodiment, the user management unit 412 acquires, for example, information on users who have registered for a challenge and manages the acquired user information. Further, the user management unit 412 manages, for example, information on users who are supporters who support users who have registered for a challenge.
[0167] [1.7.3 Transaction data generation unit 413] The transaction data generation unit 413 generates transaction data including the service content generated by the service management unit 411.
[0168] In the present embodiment, the transaction data generation unit 413 generates second transaction data including a second smart contract generated by the service management unit 411 based on the challenge content. Note that the second transaction data is an example of the first transaction data according to the present disclosure.
[0169] Further, the transaction data generation unit 413 generates sixth transaction data including a data acquisition request generated by the service management unit 411. Note that the sixth transaction data is an example of the sixth transaction data according to the present disclosure.
[0170] Further, the transaction data generation unit 413 generates seventh transaction data including information on incentive payment or feedback provision for user data provision or user data reference generated by the service management unit 411.
[0171] Note that in the present embodiment, the transaction data generation unit 413 generates transaction data including a third smart contract based on the incentive payment or feedback provision generated by the service management unit 411.
[0172] [1.7.4 Recording Unit 414] The recording unit 414 records user information or service information necessary for service provision.
[0173] In this embodiment, the recording unit 414 records the challenge content provided by the service provider generated by the service management unit 411. In addition, the recording unit 414 records the information of the user who has registered for the challenge or the information of the user who is a supporter who supports the user who has registered for the challenge. In addition, the recording unit 414 records incentives for users who have challenged and achieved the goals shown in the challenge content generated by the service management unit 411.
[0174] In addition, the recording unit 414 records information regarding incentive payment or feedback provision to the user of the content of the data acquisition request generated by the service management unit 411, the acquired or referenced data.
[0175] In addition, the recording unit 414 records the smart contract generated by the service management unit 411.
[0176] In addition, the recording unit 414 records the transaction data generated by the transaction data generation unit 413.
[0177] [1.7.5 Communication Unit 415] The communication unit 415 communicates with the authentication server 200 and the detection server 300 via the communication network 500. This communication may be performed by TLS. In this case, the encryption key for TLS communication may be held by the communication unit 415.
[0178] [1.8 Operation of Data Circulation System 10] [1.8.1 Outline of Operation of Data Circulation System 10] Next, an outline of the operation of the data circulation system 10 configured as described above will be described.
[0179] FIG. 9 is a flowchart showing an example of the operation of the data distribution system 10 according to the present embodiment.
[0180] First, the service server 400 generates challenge content (S11). More specifically, the service server 400 generates challenge content that is a target determinable based on user data and for which an incentive is given to the user when the target challenged by the user is achieved.
[0181] Next, the service server 400 generates a smart contract based on the challenge content generated in step S11 (S12). More specifically, the service server 400 generates a second smart contract programmed to be able to give an incentive to the user when the target shown in the challenge content generated in step S11 is achieved.
[0182] Next, the service server 400 records the smart contract generated in step S12 in the distributed ledger and operates it (S13). More specifically, the service server 400 generates second transaction data including the second smart contract and transmits it to, for example, the authentication server 200a among the plurality of authentication servers 200. Then, the authentication server 200a executes a consensus algorithm for agreeing on the validity of the second transaction data together with a plurality of authentication servers 200b and 200c different from the authentication server 200a among the plurality of authentication servers 200. As a result, the second transaction data can be recorded in the distributed ledger, and the second smart contract stored in the working memory can be operated when the second transaction data is recorded in the distributed ledger.
[0183] Next, the authentication server 200a notifies the challenge content to the device used by the user (S14). More specifically, for example, when the second smart contract is operated, the authentication server 200a notifies the challenge content to the terminal 110 which is the device used by the user.
[0184] Next, for example, the authentication server 200a acquires transaction data including the challenge content selected by the user (S15). More specifically, for example, the authentication server 200a acquires third transaction data including the first challenge content selected as the registration target by the user from among the challenge content from the terminal 110 which is the device used by the user.
[0185] Next, for example, the authentication server 200a records the transaction data acquired in step S15 in the distributed ledger (S16). More specifically, for example, the authentication server 200a executes a consensus algorithm for reaching an agreement on the validity of the third transaction data together with the plurality of authentication servers 200b and 200c. Thereby, for example, the authentication server 200a can record the third transaction data in the distributed ledger.
[0186] [1.8.2 Overall Sequence of the Data Circulation System 10] Subsequently, the overall sequence of the data circulation system 10 will be described. FIG. 10 is an overall sequence diagram of the data circulation system 10 according to the present embodiment. Each process will be described later.
[0187] First, in step S100, consent information registration processing is performed among the terminal 110, the house 100, and the authentication servers 200a to 200c. In the consent information registration processing described later, the case where the terminal 110 registers consent information will be described. Since the same processing is performed even when the controller 101 of the house 100 registers consent information, the description of the case where the controller 101 of the house 100 registers consent information is omitted.
[0188] Next, in step S200, a challenge registration process is performed among the terminal 110, the house 100, the authentication servers 200a to 200c, and the service server 400. In the challenge registration process described later, the case where the challenge registration is performed from the terminal 110 will be explained. Since the same process is performed even when the challenge registration is performed from the controller 101 of the house 100, the explanation of the case where the challenge registration is performed from the controller 101 of the house 100 is omitted.
[0189] Next, in step S300, a data registration process is performed among the terminal 110, the house 100, the authentication servers 200a to 200c, and the detection server 300. In the data registration process described later, the case where the data of the user acquired from the terminal 110 is registered will be explained. Since the same process is performed even when the house 100 registers the data of the in-house devices, the explanation of the case where the house 100 registers the data of the in-house devices is omitted.
[0190] Next, in step S400, a data reference process is performed among the terminal 110, the house 100, the authentication servers 200a to 200c, the detection server 300, and the service server 400. Note that the data reference process in step S400 can be executed after the user's consent information is registered in the consent information registration process in step S100.
[0191] Next, in step S500, a support registration process is performed among the terminal 110, the house 100, the terminal 120, the authentication servers 200a to 200c, and the detection server 300. In the support registration process described later, the case where the support registration is performed from the terminal 120 will be explained. Note that when the support registration process is performed, the data reference process in step S400 may be executed after the support registration process in step S500.
[0192] [1.8.3 Consent Information Registration Process] Subsequently, the consent information registration process between the terminal 110 and the authentication servers 200a to 200c will be explained.
[0193] FIG. 11 is a sequence diagram showing the consent information registration process between the terminal 110 according to the present embodiment and the authentication servers 200a to 200c. In the example shown in FIG. 11, the case where the terminal 110 registers consent information will be described.
[0194] First, the terminal 110 generates consent information based on a user's operation (S101). Here, an application is introduced into the terminal 110 as the input unit 1013, and the application may generate consent information based on the user's operation. In this case, the user can cause the terminal 110 to generate consent information by simply instructing whether to select or deselect from a list of service providers or a list of data provided by the input unit 1013.
[0195] Note that when generating consent information on the terminal 110, the user may generate consent information after determining whether there is a lot of feedback from the service provider. For example, when the user provides data to the service provider, the user may determine the data provider to be selected (that is, consent to data provision) based on the content of the feedback such as virtual currency being provided or coupons or discounts of the service provider being provided. Also, for example, the user may determine the data provider to be selected (that is, consent to data provision) based on the content of the feedback to the user such as the amount of virtual currency provided or the amount of coupons or discounts provided when the user provides data to the service provider. The content of the feedback may be publicly disclosed by the service provider or may be recorded in the blockchain of the authentication server 200.
[0196] Next, based on the consent information generated in step S101, the terminal 110 generates a first smart contract (S102). The first smart contract is a smart contract programmed to be able to determine whether data can be provided. The first smart contract may include the consent information generated in step S101. Further, the first smart contract may include a program that can determine whether to provide data when the feedback is above a certain level.
[0197] Next, the terminal 110 generates transaction data (hereinafter referred to as first transaction data) including the generated consent information and the first smart contract (S103).
[0198] Next, the terminal 110 transmits the first transaction data generated in step S103 to the authentication server 200a (S104). In the example shown in FIG. 11, the terminal 110 transmits the generated first transaction data to the authentication server 200a, but it may also be transmitted to the authentication servers 200b and 200c. The same applies when it is transmitted to the authentication servers 200b and 200c.
[0199] Next, when the authentication server 200a obtains the first transaction data from the terminal 110 (S105), it verifies the obtained first transaction data (S106).
[0200] In step S106, if the verification of the first transaction data fails (N in S106), the authentication server 200a sends a notification to that effect to the terminal 110 (S107).
[0201] On the other hand, in step S106, if the verification of the first transaction data is successful (Y in S106), the authentication server 200a transfers the first transaction data to other authentication servers 200 (authentication servers 200b and 200c) (S108). Note that the other authentication servers 200 also verify the transferred first transaction data.
[0202] Next, the authentication servers 200a, 200b, and 200c execute a consensus algorithm (S109). When the authentication servers 200a, 200b, and 200c verify that the first transaction data is legitimate transaction data (i.e., legitimacy), they each generate a block containing the first transaction data. Then, the authentication servers 200a, 200b, and 200c record the blocks containing the first transaction data in the distributed ledger.
[0203] In this way, the first smart contract and the consent information created by the terminal 110 are recorded in the distributed ledger.
[0204] Then, the first smart contract becomes executable, that is, operates, by being recorded in the distributed ledger (S110). Note that after the first smart contract is recorded in the distributed ledger, it becomes executable by being stored in the working memory of the authentication server 200a or the like.
[0205] [1.8.4 Challenge Registration Process] Next, the challenge registration process among the terminal 110, the authentication servers 200a to 200c, and the service server 400 will be described.
[0206] FIGS. 12A and 12B are sequence diagrams showing the challenge registration process among the terminal 110, the authentication servers 200a to 200c, and the service server 400 according to the present embodiment.
[0207] First, the service server 400 generates challenge contents provided by the service provider (S201). More specifically, the service provider determines challenge contents related to the user data acquired from the user. Then, the service provider causes the service server 400 to generate challenge contents that are goals determinable based on the determined challenge contents, that is, the user data, and that include goals for which incentives are given to the user when the user achieves the goals to be challenged.
[0208] Next, the service server 400 generates a second smart contract based on the challenge content generated in step S201 (S202). In the present embodiment, the service provider determines the incentives to be given to the user when the goal shown in the challenge content is achieved. Further, the service provider determines the incentives to be given to the supporter who registered the support information for the challenge content when the goal shown in the challenge content is achieved. Based on these determinations, the service server 400 is caused to generate a second smart contract. Therefore, the generated second smart contract is a smart contract programmed to be capable of giving incentives to the user when the goal shown in the challenge content is achieved. Further, the generated second smart contract is programmed to be capable of giving incentives to the supporter who registered the support information for the challenge content when the goal shown in the challenge content is achieved.
[0209] Next, the service server 400 generates second transaction data including the second smart contract generated in step S202 (S203).
[0210] Next, the service server 400 transmits the second transaction data generated in step S203 to the authentication server 200c (S204). In the example shown in FIG. 12A, the terminal 110 transmits the generated second transaction data to the authentication server 200c, but it may be transmitted to the authentication servers 200a and 200b. The same applies when it is transmitted to the authentication servers 200a and 200b.
[0211] Next, when the authentication server 200c acquires the second transaction data from the service server 400 (S205), it verifies the acquired second transaction data (S206).
[0212] In step S206, if the verification of the second transaction data fails (N in S206), the authentication server 200c sends a notification to that effect to the service server 400 (S207).
[0213] On the other hand, in step S206, if the verification of the second transaction data is successful (Y in S206), the authentication server 200c transfers the second transaction data to other authentication servers 200 (authentication servers 200a and 200b) (S208). Note that the other authentication servers 200 also verify the transferred second transaction data.
[0214] Next, the authentication servers 200a, 200b, and 200c execute a consensus algorithm (S209). When the authentication servers 200a, 200b, and 200c verify that the second transaction data is legitimate transaction data (i.e., legitimacy), they each generate a block containing the second transaction data. Then, the authentication servers 200a, 200b, and 200c record the block containing the second transaction data in the distributed ledger.
[0215] In this way, the second smart contract created by the service server 400 is recorded in the distributed ledger.
[0216] Next, the second smart contract becomes executable, i.e., operates, by being recorded in the distributed ledger (S210). Note that after being recorded in the distributed ledger, the second smart contract becomes executable by being stored in the working memory of the authentication server 200a or the like.
[0217] Next, for example, the authentication server 200a notifies the terminal 110, which is a device used by the user, of the challenge content (S211). Note that the notification of the challenge content may be sent to all terminals participating in the service provided by the service server 400, or may be sent only to terminals that have registered consent information, such as the terminal 110 for example.
[0218] Next, when the terminal 110 acquires the challenge content notified in step S211 (S212), as shown in FIG. 12B, it determines whether to register the challenge (S213). For example, when the first challenge content to be registered for the challenge by the user among the challenge contents notified in step S211 is selected, the terminal 110 determines to register the challenge.
[0219] In step S213, when registering the challenge (Y in S213), the terminal 110 generates third transaction data including the first challenge content selected as the challenge content to be registered for the challenge by the user among the challenge contents notified in step S211 (S214). Note that in step S213, when not registering the challenge (N in S213), the challenge registration process ends.
[0220] Next, the terminal 110 transmits the third transaction data generated in step S214 to the authentication server 200a (S215). Note that in the example shown in FIG. 12B, the terminal 110 transmits the generated third transaction data to the authentication server 200a, but it may also be transmitted to the authentication servers 200b and 200c. The same applies when transmitted to the authentication servers 200b and 200c.
[0221] Next, when the authentication server 200a acquires the third transaction data from the terminal 110 (S216), it verifies the acquired third transaction data (S217).
[0222] In step S217, when the verification of the third transaction data fails (N in S217), the authentication server 200a transmits a notification to that effect to the terminal 110 (S218).
[0223] On the one hand, in step S217, when the verification of the third transaction data is successful (Y in S217), the authentication server 200a transfers the third transaction data to other authentication servers 200 (authentication servers 200b and 200c) (S219). Note that the other authentication servers 200 also verify the transferred third transaction data.
[0224] Next, the authentication servers 200a, 200b, and 200c execute a consensus algorithm (S220). When the authentication servers 200a, 200b, and 200c verify that the third transaction data is legitimate transaction data (i.e., legitimacy), they each generate a block including the third transaction data. Then, the authentication servers 200a, 200b, and 200c record the block including the third transaction data in the distributed ledger.
[0225] In this way, the third smart contract created by the terminal 110 is recorded in the distributed ledger.
[0226] [1.8.5 Data Registration Process] Subsequently, the data registration process among the terminal 110, the authentication servers 200a to 200c, and the detection server 300 will be described.
[0227] FIGS. 13A and 13B are sequence diagrams showing the data registration process among the terminal 110, the authentication servers 200a to 200c, and the detection server 300 according to the present embodiment. In the example shown in FIG. 13A, the case of registering the data acquired from the terminal 110 in the detection server 300 will be described. In the example shown in FIG. 13B, the case of registering the data acquired from the terminal 110 in the detection server 300 and the case where an incentive is given to the terminal 110 by achieving a challenge will be described.
[0228] First, the terminal 110 acquires the user's data such as measurement data obtained by sensors possessed by the terminal 110 (S301). When the terminal 110 is, for example, a wearable device and possesses sensors, it acquires vital data such as step count data or blood pressure data obtained by the sensors as the data. Note that the data is not limited to vital data such as step count data or blood pressure data, and may be any user data that can be utilized by the service provider.
[0229] Next, the terminal 110 generates fourth transaction data including information indicating the user's data acquired in step S301 (S302). Assume that the information indicating the user's data here is, for example, the hash value of the data and the attribute information of the data. In this case, the fourth transaction data includes a blockchain address, a hash value, attribute information, and a signature. That is, when the user's data is not recorded in the distributed ledger, the fourth transaction data does not include the user's data itself, but only includes the information indicating the user's data.
[0230] Next, the terminal 110 transmits the data acquired in step S301 and the fourth transaction data generated in step S302 to the detection server 300 (S303).
[0231] Next, when the detection server 300 acquires the fourth transaction data and the data from the terminal 110 (S304), the detection server 300 detects whether the data acquired in step S304 is invalid data (S305).
[0232] In step S305, if the data acquired in step S304 is invalid data (Y in S305), the detection server 300 transmits a notification to that effect to the terminal 110 (S306).
[0233] On the other hand, in step S305, if the data obtained in step S304 is not invalid data (N in S305), the detection server 300 detects whether the user of the terminal 110 has achieved the challenge based on the data obtained in step S304 (S307). More specifically, the detection server 300 determines whether the user of the terminal 110 has achieved the goal of the challenge shown in the first challenge content registered by the user by using the data obtained in step S304, thereby detecting whether the challenge has been achieved.
[0234] In step S307, if the user of the terminal 110 has achieved the challenge (Y in S307), the process proceeds to step S315, which will be described later.
[0235] On the other hand, in step S307, if the user of the terminal 110 has not achieved the challenge (N in S307), the fourth transaction data obtained in step S304 is transmitted to the authentication server 200a (S308). In the example shown in FIG. 13A, the terminal 110 transmits the fourth transaction data obtained in step S304 to the authentication server 200a, but it may also be transmitted to the authentication servers 200b and 200c. The same applies when it is transmitted to the authentication servers 200b and 200c.
[0236] Next, the detection server 300 records the data obtained in step S304 (S309).
[0237] Next, when the authentication server 200a obtains the fourth transaction data from the detection server 300 (S310), it verifies the obtained fourth transaction data (S311). Note that the order of steps S309 and S310 is not necessarily as described, and may be changed.
[0238] In step S311, if the verification of the fourth transaction data fails (N in S311), the authentication server 200a sends a notification to that effect to the detection server 300 (S312).
[0239] On the one hand, in step S311, when the verification of the fourth transaction data is successful (Y in S311), the authentication server 200a transfers the fourth transaction data to other authentication servers 200 (authentication servers 200b, 200c) (S313). Note that the other authentication servers 200 also verify the transferred fourth transaction data.
[0240] Next, the authentication server 200a, the authentication server 200b, and the authentication server 200c execute a consensus algorithm (S314). When the authentication server 200a, the authentication server 200b, and the authentication server 200c verify that the fourth transaction data is legitimate transaction data (i.e., validity), they each generate a block containing the fourth transaction data. Then, the authentication servers 200a, 200b, and 200c record the block containing the fourth transaction data in the distributed ledger.
[0241] In this way, while the fourth transaction data including the information indicating the user's data is recorded in the distributed ledger, the user's data itself is recorded in the detection server 300.
[0242] On the one hand, in step S307, when the user of the terminal 110 achieves the challenge (Y in S307), based on the fourth transaction data obtained in step S304, the fifth transaction data is generated (S315). The fifth transaction data includes, in addition to the information indicating the user's data included in the fourth transaction data, the fact that the challenge content has been achieved.
[0243] Next, the detection server 300 sends the fifth transaction data generated in step S315 to the authentication server 200a (S316). Note that in the example shown in FIG. 13B, the terminal 110 sends the fifth transaction data generated in step S315 to the authentication server 200a, but it may also be sent to the authentication servers 200b and 200c. The same applies when it is sent to the authentication servers 200b and 200c.
[0244] Next, the detection server 300 records the data acquired in step S304 (S317).
[0245] Next, when the authentication server 200a acquires the fifth transaction data from the detection server 300 (S318), it verifies the acquired fifth transaction data (S319). Note that the order of step S317 and step S318 is not necessarily as described, and may be changed.
[0246] In step S319, if the verification of the fifth transaction data fails (N in S319), the authentication server 200a sends a notification to that effect to the detection server 300 (S320).
[0247] On the other hand, in step S319, if the verification of the fifth transaction data succeeds (Y in S319), the authentication server 200a transfers the fifth transaction data to other authentication servers 200 (authentication servers 200b and 200c) (S321). Note that the other authentication servers 200 also verify the transferred fifth transaction data.
[0248] Next, the authentication servers 200a, 200b, and 200c execute a consensus algorithm (S322). When the authentication servers 200a, 200b, and 200c verify that the fifth transaction data is legitimate transaction data (i.e., validity), they each generate a block containing the fifth transaction data. Then, the authentication servers 200a, 200b, and 200c record the blocks containing the fifth transaction data in the distributed ledger.
[0249] Next, the authentication servers 200a, 200b, and 200c execute the second smart contract recorded in the distributed ledger (S323). As described above, this second smart contract is a smart contract generated based on the challenge content. The second smart contract has been recorded in the distributed ledger during the challenge registration process, and thus is stored in the working memory and is executable. Thereby, the second smart contract gives an incentive to the terminal 110 of the user who has achieved the challenge.
[0250] Next, the authentication server 200a notifies that an incentive at the time of achieving the challenge has been given to the terminal 110 of the user (S324).
[0251] In this way, the second smart contract can not only automatically give an incentive to the user for achieving the challenge, but also the authentication server 200a automatically notifies that the incentive has been given to the terminal 110 of the user. Note that when it becomes possible to implement a notification function in the smart contract, the challenge content notification in step S211 or the incentive notification in step S324 may be performed by the second smart contract.
[0252] [1.8.6 Data reference process] Subsequently, the data reference process among the terminal 110, the authentication servers 200a to 200c, the detection server 300, and the service server 400 will be described.
[0253] FIGS. 14A and 14B are sequence diagrams showing the data reference process among the terminal 110, the authentication servers 200a to 200c, the detection server 300, and the service server 400 according to the present embodiment. In the example shown in FIGS. 14A and 14B, the case where the service server 400 acquires user data from the detection server 300 will be described.
[0254] First, when the service server 400 determines, for example, what data of the user it wants to acquire, it decides to make a request for data acquisition (S401).
[0255] Next, the service server 400 generates a data acquisition request indicating that it requests data acquisition, and generates sixth transaction data including the data acquisition request (S402).
[0256] Next, the service server 400 transmits the sixth transaction data generated in step S402 to the authentication server 200c (S403). In the example shown in FIG. 14A, the service server 400 transmits the sixth transaction data generated in step S402 to the authentication server 200c, but it may also be transmitted to the authentication servers 200a and 200b. The same applies when it is transmitted to the authentication servers 200a and 200b.
[0257] Next, when the authentication server 200c acquires the sixth transaction data from the service server 400 (S404), it verifies the acquired sixth transaction data (S405).
[0258] In step S405, when the verification of the sixth transaction data fails (N in S405), the authentication server 200c transmits a notification to that effect to the service server 400 (S406).
[0259] On the other hand, in step S405, when the verification of the sixth transaction data is successful (Y in S405), the authentication server 200c transfers the sixth transaction data to the other authentication servers 200 (authentication servers 200a and 200b) (S407). Note that the other authentication servers 200 also verify the transferred sixth transaction data.
[0260] Next, the authentication servers 200a, 200b, and 200c execute a consensus algorithm (S408). When the authentication servers 200a, 200b, and 200c verify that the sixth transaction data is legitimate transaction data (i.e., legitimacy), they each generate a block containing the sixth transaction data. Then, the authentication servers 200a, 200b, and 200c record the blocks containing the sixth transaction data in the distributed ledger.
[0261] Next, the authentication servers 200a, 200b, and 200c execute the first smart contract recorded in the distributed ledger (S409). The first smart contract is a smart contract generated based on the consent information. By being recorded in the distributed ledger, it is stored in the working memory and becomes executable. Then, the first smart contract executed by the authentication server 200 determines whether it is possible to provide the data requested from the service server 400 based on the consent information. The first smart contract sends a notification of the determination result to the detection server 300 and the service server 400 (S410).
[0262] Next, the detection server 300 and the service server 400 receive the notification sent in step S410 (S411). Here, it is assumed that the notification sent in step S410 indicates that it is possible to provide the data requested from the service server 400.
[0263] Next, the service server 400 requests the detection server 300 to provide data (S412). Note that the service server 400 may access the detection server 300 to obtain the data provision.
[0264] Next, when the detection server 300 obtains a data provision request from the service server 400 (S413), it checks the notification received from the authentication server 200 in step S411, and determines whether it is possible to provide the data requested by the service server 400 (S414). In step S414, if it is determined that it is not possible to provide the data requested by the service server 400 after checking the notification received from the authentication server 200 in step S411 (N in S414), a notification to that effect is sent to the service server 400 (S415).
[0265] In step S414, if it is determined that it is possible to provide the data requested by the service server 400 after checking the notification received from the authentication server 200 in step S411 (Y in S414), the service server 400 provides the requested data (S416).
[0266] Next, the service server 400 obtains the requested data (S417).
[0267] Then, the service server 400 generates seventh transaction data (S418). More specifically, the service server 400 generates seventh transaction data including information regarding incentive payment for user data provision or user data reference.
[0268] Next, the service server 400 transmits the seventh transaction data generated in step S418 to the authentication server 200c (S419). In the example shown in FIG. 14B, the service server 400 transmits the generated seventh transaction data to the authentication server 200c, but it may also be transmitted to the authentication servers 200a and 200b. The same applies when it is transmitted to the authentication servers 200a and 200b.
[0269] Next, when the authentication server 200c obtains the seventh transaction data from the service server 400 (S420), it verifies the obtained seventh transaction data (S421).
[0270] In step S421, if the verification of the seventh transaction data fails (N in S421), the authentication server 200c sends a notice to that effect to the service server 400 (S422).
[0271] On the other hand, in step S421, if the verification of the seventh transaction data is successful (Y in S421), the authentication server 200c transfers the seventh transaction data to other authentication servers 200 (authentication servers 200a and 200b) (S423). Note that the other authentication servers 200 also verify the transferred seventh transaction data.
[0272] Next, the authentication servers 200a, 200b, and 200c execute a consensus algorithm (S424). When the authentication servers 200a, 200b, and 200c verify that the seventh transaction data is legitimate transaction data (i.e., legitimacy), they each generate a block including the seventh transaction data. Then, the authentication servers 200a, 200b, and 200c record the block including the seventh transaction data in the distributed ledger.
[0273] Next, the authentication servers 200a, 200b, and 200c execute the third smart contract recorded in the distributed ledger (S425). The third smart contract is a smart contract generated based on incentive payment or feedback provision for user data provision or user data reference. The third smart contract is stored in the working memory and becomes executable by being recorded in the distributed ledger. In the present embodiment, the third smart contract can distribute or notify incentives to the terminal 110 used by the user who provided or referenced the data.
[0274] Next, for example, the authentication server 200a transmits a notification to the effect that an incentive has been given to the terminal 110 used by the user to whom data has been provided or from whom data has been referenced, by means of the third smart contract (S426).
[0275] Note that the service server 400 may generate transaction data including information regarding feedback provision in step S418. In this case, in step S425, the third smart contract regarding feedback provision will be executed.
[0276] In this way, data reference processing is performed among the terminal 110, the house 100, the authentication servers 200a to 200c, the detection server 300, and the service server 400, and then incentives are automatically given.
[0277] [1.8.7 Support registration process] Subsequently, the support registration process among the terminal 110, the terminal 120, the authentication servers 200a to 200c, and the detection server 300 will be described.
[0278] FIG. 15A is a sequence diagram showing the challenge registration process among the terminal 110, the terminal 120, and the authentication servers 200a to 200c according to the present embodiment. FIG. 15B is a sequence diagram showing the challenge registration process among the terminal 110, the authentication servers 200a to 200c, and the detection server 300 according to the present embodiment. In FIGS. 15A and 15B, the device used by the supporter to register support information is described as the terminal 120.
[0279] First, the terminal 120 performs a reference process on the challenge content provided by the service provider (S501). In this embodiment, the terminal 120 can obtain and refer to the challenge content registered by the user among the challenge content from the authentication server 200a by sending a reference request for the challenge content to the authentication server 200a. Note that the authentication server 200a that has obtained the reference request for the challenge content may further send the information of the user who registered the challenge. The user information may be, for example, the identification information of the terminal 110, or the user attribute information such as height, weight, age, and gender. Further, the authentication server 200a that has obtained the reference request for the challenge content may send the content and result of the challenge registration up to the time of obtaining the reference request to the terminal 120, or may send all the information consented by the user to the terminal 120 when the user gives consent.
[0280] Next, the terminal 120 determines whether to support the user's challenge achievement based on the challenge content referred to in step S501 by the user's operation (S502). For example, when the challenge content to be supported is selected from among the challenge content registered by the user, the terminal 120 determines to support the user's challenge achievement.
[0281] In step S502, when it is determined to support the user's challenge achievement (Y in S502), the terminal 120 generates support information for supporting the user's challenge achievement based on the challenge content referred to in step S501 (S503). Note that in step S502, when not supporting the user's challenge achievement (N in S502), the support registration process ends.
[0282] Next, the terminal 120 generates the eighth transaction data including the support information generated in step S503 (S504). The eighth transaction data includes, for example, the generated support information and the address of the second smart contract.
[0283] Next, the terminal 120 transmits the eighth transaction data generated in step S504 to the authentication server 200a (S505). In the example shown in FIG. 15A, the terminal 120 transmits the generated eighth transaction data to the authentication server 200a, but it may also be transmitted to the authentication servers 200b and 200c. The same applies when transmitting to the authentication servers 200b and 200c.
[0284] Next, when the authentication server 200a acquires the eighth transaction data from the terminal 120 (S506), it verifies the acquired eighth transaction data (S507).
[0285] In step S507, if the verification of the eighth transaction data fails (N in S507), the authentication server 200a sends a notification to that effect to the terminal 120 (S508).
[0286] On the other hand, in step S507, if the verification of the eighth transaction data is successful (Y in S507), the authentication server 200a transfers the eighth transaction data to the other authentication servers 200 (authentication servers 200b and 200c) (S509). Note that the other authentication servers 200 also verify the transferred eighth transaction data.
[0287] Next, the authentication servers 200a, 200b, and 200c execute a consensus algorithm (S510). When the authentication servers 200a, 200b, and 200c verify that the eighth transaction data is legitimate transaction data (i.e., legitimacy), they each generate a block containing the eighth transaction data. Then, the authentication servers 200a, 200b, and 200c record the block containing the eighth transaction data in the distributed ledger.
[0288] Next, the authentication server 200a, the authentication server 200b, and the authentication server 200c execute the second smart contract recorded in the distributed ledger (S511). As described above, the second smart contract is a smart contract generated based on the challenge content, and is programmed to be able to register support information for the challenge content.
[0289] The authentication server 200a notifies the terminal 110 of the user of the challenge content in which the support information is recorded by the second smart contract that the support information has been recorded (S512). Note that when the smart contract can implement a notification function, the second smart contract may issue a notification indicating that the support information has been recorded, that is, a support notification.
[0290] The subsequent steps S513 to S519 are the same as steps S301 to S307 described in FIG. 13A, and steps S520 to S527 are the same as steps S315 to S322 described in FIG. 13B, so the description is omitted.
[0291] In step S528, the authentication server 200a, the authentication server 200b, and the authentication server 200c execute the second smart contract recorded in the distributed ledger. The second smart contract is a smart contract generated based on the challenge content as described above. The second smart contract is further programmed to be able to give an incentive to the supporter who registered the support information for the challenge content when the goal shown in the challenge content is achieved.
[0292] Therefore, the second smart contract stored in the working memory of the authentication server 200a gives incentives to the terminal 110 used by the user and the terminal 120 used by the supporter.
[0293] Next, for example, the authentication server 200a transmits an incentive notification indicating that incentives have been given to the terminal 110 used by the user and the terminal 120 used by the supporter by the second smart contract (S529). Note that if the smart contract can implement a notification function, the second smart contract may issue the incentive notification.
[0294] In this way, the second smart contract can automatically give incentives for achieving the challenge to the terminal 110 used by the user and the terminal 120 used by the supporter.
[0295] [1.9 Effects of the Embodiment] According to this embodiment, the consent information of the user or the content registered for the challenge can be safely recorded on the blockchain. Further, according to this embodiment, data registration and challenge registration by the user can be automatically executed by the smart contract. When the challenge can be achieved by registering the data, the smart contract can immediately distribute incentives. In addition, since the challenge items registered by the user for the challenge can be registered by the smart contract, it is possible not only to prevent the tampering of the incentive distribution, but also to flexibly design the change of the incentive by the service provider with the smart contract.
[0296] As described above, according to the disclosure control method, data circulation system, etc. according to this embodiment, it is possible to present benefits to the user while ensuring data traceability.
[0297] More specifically, the challenge content in which incentives are given to the user when the goal challenged by the user is achieved is notified to the user, and when it is determined that the challenge has been achieved based on the data acquired from the user, the incentives can be automatically given to the user. That is, by presenting benefits to the user, data can be continuously acquired from the user.
[0298] Furthermore, since it utilizes a distributed ledger, which is blockchain technology, it can record information such as information about the data obtained from users. That is, it can ensure data traceability.
[0299] Therefore, it is possible to present benefits to users while ensuring data traceability.
[0300] Also, by recording transaction data generated when a challenge is actually achieved based on the data obtained from users in the distributed ledger, incentives can be automatically given to the devices used by users for smart contracts.
[0301] As a result, by presenting benefits to users, a mechanism for continuously obtaining data from users can be automatically executed without human intervention. Consequently, more user data that can be utilized can be collected, contributing to the realization of Society 5.0.
[0302] Also, by recording transaction data including support information for the challenge content that users challenge in the distributed ledger, the smart contract can be automatically registered with support information for the challenge content.
[0303] As a result, support information for the challenge content that users challenge can be referenced at any time, so users can be continuously made to work on the challenge content. That is, benefits to users can be presented.
[0304] In this way, by automatically presenting benefits to users without human intervention, a mechanism for continuously obtaining data from users can be automatically executed without human intervention.
[0305] In addition, by recording transaction data including support information in the distributed ledger, incentives can be automatically given to the smart contract to be utilized by the device used by the supporter who generated the transaction data. Therefore, the supporter can be continuously encouraged to support the challenge content, and benefits for the user can be presented.
[0306] In this way, by automatically presenting benefits for the user and the supporter without the intervention of a person, a mechanism for continuously acquiring data from the user can be automatically executed without the intervention of a person.
[0307] Moreover, the more supporters who register support information for the challenge content challenged by the user, the more incentives are given, so the user can be continuously encouraged to engage in the challenge content. That is, more benefits for the user can be presented.
[0308] In addition, since the distributed ledger records that data has been transferred or made referenceable, the data can be utilized while ensuring data traceability. Therefore, the user can provide data with confidence.
[0309] Note that as benefits for the user, challenge content including the goals that the user challenges to improve or maintain the user's health or challenge content including goals for an energy-saving and ecological user lifestyle may be presented.
[0310] [2 Other Modifications] Although the present disclosure has been described based on the above-described embodiments, it goes without saying that the present disclosure is not limited to the above-described embodiments. The following cases are also included in the present disclosure.
[0311] (1) In the above embodiment, the service server 400 registers the challenge content in the second smart contract, and it has been described that when the first challenge content for which the user challenges the challenge content included in the second smart contract is registered, but it is not limited to this. When registering the first challenge content for which the user challenges, a new smart contract for which the first challenge content is described and managed may be registered with respect to the second smart contract. In this case, the terminal 110 may generate a new smart contract and register the first challenge.
[0312] (2) In the above embodiment, it has been described that the challenge content generated by the service server 400 is recorded in the authentication server 200a, but it is not limited to this. There may be a challenge management server that manages support information in addition to the challenge content, and the challenge content generated by the service server 400 and the like may be recorded in the challenge management server. Then, the challenge management server may disclose the recorded challenge content and the like to devices used by users such as the terminal 110. Even in this case, the smart contract is recorded in a distributed ledger such as the authentication server 200a, operates in the working memory, and incentives may be automatically given when the challenge is achieved.
[0313] (3) In the above embodiment, although not particularly mentioned, the blockchain recorded in the distributed ledger such as the authentication server 200a may be disclosed to the service server 400 and devices used by users such as the terminal 110.
[0314] (4) In the above embodiment, the smart contract generated by the service server 400 at the time of challenge registration is recorded in a distributed ledger such as the authentication server 200a, and the authentication server 200a and the like notify the challenge content to devices used by users such as the terminal 110, but it is not limited to this. The service server 400 may notify the challenge content to the devices used by the user at the time of challenge registration.
[0315] (5) In the above-described embodiment, the detection server 300 and the authentication server 200 have been described as separate devices, but this is not limiting. The detection server 300 and the authentication server 200 may be the same device.
[0316] (6) In the above-described embodiment, in step S412 of the data reference process shown in FIG. 14A, the service server 400 requests the detection server 300 to provide data, but this is not limiting. The service server 400 may generate transaction data including a data acquisition request in step S402 and transmit it to the authentication server, and it may be possible to obtain the provision of the requested data by the process of the executed smart contract. That is, steps S412 to S415 shown in FIG. 14A may be omitted.
[0317] (7) In the above-described embodiment, the case where data acquired from devices used by users such as the terminal 110 is recorded in the detection server 300 has been described, but this is not limiting. A data collection server that collects data of devices used by users such as the terminal 110 may be provided separately from the detection server 300. In this case, devices used by users such as the terminal 110 may transmit data to the detection server 300, and the detection server 300 may record only the data whose validity has been verified in the data collection server. Also, devices used by users such as the terminal 110 may transmit data to the data collection server, and the data recorded by the data collection server may be verified for validity by the detection server.
[0318] (8) In the above-described embodiment, as shown in FIG. 2, the body composition monitor 105 and the blood pressure monitor 106 have been described as being connected to the controller 101, but this is not limiting. The body composition monitor 105 and the blood pressure monitor 106 may be wirelessly connected to the terminal 110, and the terminal 110 may collect measurement data. In this case, the data collected by the terminal 110 may be transmitted to the detection server 300.
[0319] (9) Also, in the present disclosure, the challenge content generated by the service server 400 may include registering the virtual currency and points held by the user of the terminal 110 at the time of challenge registration, and distributing incentives more than the registered virtual currency or points when the challenge is achieved. Further, when support information is registered in the challenge content, it may be assumed that the virtual currency and points held by the user of the terminal 110 are registered. In this case, furthermore, when another user achieves the challenge, it may include distributing incentives more than the virtual currency or points registered when the support information was registered.
[0320] (10) In the above embodiment, it has been described that the terminal 110 registers a challenge and the terminal 120 different from the terminal 110 registers support information, but it is not limited to this. It may be assumed that the terminal 110 used by the user registers a challenge, and a supporter who is a user different from the said user uses the terminal 110 to register support information for the said challenge registration.
[0321] (11) In the above embodiment, it has been described that the challenge content of the terminal 110 is made public after being registered in the challenge content managed by the smart contract, but it is not limited to this. When the terminal 110 registers consent information or challenge content, it may be possible to select whether the registered challenge content is to be made public or not.
[0322] (12) In the above embodiment, it has been described that incentives such as virtual currency or points are distributed when the challenge is achieved after the challenge registration, but it is not limited to this.
[0323] If the achievement of the goal shown in the challenge content fails after the challenge registration, it may be necessary for the terminal 110 to pay the virtual currency or points it holds. In this case, the virtual currency or points of the terminal 110 may be sent at the time of challenge registration and paid to the blockchain address of the service server 400 at the time of challenge failure.
[0324] Furthermore, even if it is necessary for the terminal 120 that has registered support information to send the virtual currency or points held by the terminal 120 to the service server 400 when the user of the challenge content to be supported fails to achieve the goal indicated in the challenge content.
[0325] (13) Also, in the challenge content generated by the service server 400, it may include changing the amount of virtual currency or points distributed as an incentive according to the degree of achievement of the goal indicated in the challenge content.
[0326] (14) Also, in the above embodiment, it was explained that the more supporters who register support information for the challenge content, the more incentives are given, but it is not limited to this. It may include changing the amount of virtual currency or points distributed as an incentive according to the number of support information registered for the challenge content.
[0327] (15) Also, the types of incentives such as virtual currency or points obtained at the time of challenge achievement and the virtual currency or points obtained at the time of challenge achievement by registering support information may be different. Examples of the types of incentives include the expiration date or the presence or absence of usage restrictions of virtual currency or points. For example, while the virtual currency or points obtained at the time of challenge achievement can be used without restriction, the virtual currency or points obtained at the time of challenge achievement by registering support information may have an expiration date or may be available only for challenge registration.
[0328] (16) Also, it may be possible to disclose information on devices used by users such as the terminal 110 that has performed challenge registration. Examples of the information on the device include attribute information such as the gender or age of the user who uses the device, the degree of achievement of the goal shown in the challenge content when challenge registration was performed in the past, or information that was registered as data in the past. Also, all of the information on the device used by the user may be disclosed, or only a part of it may be disclosed. Even when disclosing information on the device used by the user, it may be possible to change the information disclosed for each challenge registration.
[0329] (17) In the above embodiment, data registration after challenge registration is performed on one terminal 110, but it is not limited to this. When the devices used by the user, such as a wearable device and a smartphone, are multiple terminals, data registration after challenge registration may be performed by the multiple terminals.
[0330] For example, the service server 400 may generate challenge content including the fact that the achievement of the goal can be determined by the total value of data such as the number of steps of multiple terminals. In this case, as the data for which the achievement of the goal is determined, the data that was first registered among the data registered by the multiple terminals may be selected, or the data registered by the one terminal may be selected by specifying the identification information of one terminal. Also, as the data for which the achievement of the goal is determined, it may be data randomly selected from the data registered by the multiple terminals.
[0331] (18) Further, for example, in step S214 of FIG. 12B, the terminal 110 may generate third transaction data including the contract address of the second smart contract and the blockchain address of the terminal 110 itself, i.e., the terminal that registers the challenge. Further, for example, in step S504 of FIG. 15A, the terminal 120 may generate eighth transaction data including the contract address of the second smart contract and the blockchain address of the terminal 120 itself, i.e., the terminal that registers the support information. Note that the terminal 120 may further generate the eighth transaction data including the blockchain address of the terminal 110 that registered the challenge content for which the support information is registered.
[0332] (19) In the present disclosure, the service server 400 has been described as being included in the data distribution system 10 and belonging to the same group on the same blockchain infrastructure, but it is not limited to this. The service server 400 may belong to a group different from the group formed by the data distribution system 10. In this case, it is recorded that the data has been transferred or made referenceable to both the distributed ledger belonging to the first group in which the user's data for achieving the challenge is recorded and the distributed ledger belonging to the second group to which the user's data composed of the service server 400 and the like is provided. With this configuration, it is possible to link data belonging to different groups. Therefore, even between different groups, it is possible to realize a control method of a data distribution system and the like that can utilize data while ensuring data traceability, and contribute to the realization of Society 5.0.
[0333] (20) Each device in the above-described embodiment is specifically a computer system composed of a microprocessor, ROM, RAM, hard disk unit, display unit, keyboard, mouse, etc. A computer program is recorded in the RAM or the hard disk unit. When the microprocessor operates according to the computer program, each device achieves its function. Here, the computer program is composed of a combination of a plurality of instruction codes indicating instructions to the computer in order to achieve a predetermined function.
[0334] (21) Each device in the above-described embodiment may be configured such that some or all of the constituent components are composed of one system LSI (Large Scale Integration). A system LSI is a super multifunctional LSI manufactured by integrating a plurality of components on one chip, and specifically, is a computer system including a microprocessor, ROM, RAM, etc. A computer program is recorded in the RAM. When the microprocessor operates according to the computer program, the system LSI achieves its function.
[0335] Also, each part of the constituent components constituting each of the above devices may be individually formed into one chip, or may be formed into one chip so as to include some or all of them.
[0336] Also, here, although a system LSI is used, depending on the degree of integration, it may also be called an IC, LSI, super LSI, or ultra LSI. Also, the method of integrating into a circuit is not limited to LSI, and it may be realized by a dedicated circuit or a general-purpose processor. After manufacturing the LSI, an FPGA (Field Programmable Gate Array) that can be programmed or a reconfigurable processor that can reconfigure the connection and setting of circuit cells inside the LSI may be used.
[0337] Furthermore, if a technology for integrating circuits that replaces LSI emerges due to advancements in semiconductor technology or other derived technologies, it is natural that the integration of functional blocks may be performed using such technology. The application of biotechnology, etc. may be possible.
[0338] (22) Some or all of the components constituting each of the above devices may be configured from an IC card or a single module that is detachable from each device. The IC card or the module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or the module may include the above-mentioned super multifunctional LSI. When the microprocessor operates according to a computer program, the IC card or the module achieves its function. This IC card or this module may have tamper resistance.
[0339] (23) The present disclosure may be the method shown above. It may also be a computer program for realizing these methods by a computer, or it may be a digital signal composed of the computer program.
[0340] Also, the present disclosure may be the computer program or the digital signal recorded on a computer-readable recording medium, such as a flexible disk, a hard disk, a CD-ROM, an MO, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), a semiconductor memory, etc. It may also be the digital signal recorded on these recording media.
[0341] Also, the present disclosure may be the computer program or the digital signal transmitted via a telecommunication line, a wireless or wired communication line, a network represented by the Internet, data broadcasting, etc.
[0342] Also, the present disclosure may be a computer system including a microprocessor and a memory, where the memory stores the computer program, and the microprocessor operates according to the computer program.
[0343] Alternatively, it may be implemented by another independent computer system by recording and transferring the program or the digital signal to the recording medium, or by transferring the program or the digital signal via the network or the like.
[0344] (24) It is also possible to combine the above embodiments and the above modification examples respectively.
Industrial Applicability
[0345] The present disclosure can be used in a data circulation method, a program, and a data circulation system that can automatically execute a mechanism for continuously obtaining data from a user without human intervention by automatically executing, for example, challenge registration, support information registration, incentive distribution, etc. using smart contracts.
Explanation of Signs
[0346] 10 Data circulation system 100 House 101 Controller 102 Solar power generation device 103 Storage battery 104 Air conditioner 105 Body composition monitor 106 Sphygmomanometer 110, 120 Terminal 200, 200a, 200b, 200c Authentication server 211 Transaction data verification unit 212 Block generation unit 213 Synchronization unit 214 Smart contract execution unit 215, 314, 414, 1014, 1104 Recording unit 216, 315, 415, 1015, 1105 Communication Unit 300 Detection Server 311 Data Management Unit 312 Detection Unit 313, 413, 1012, 1101 Transaction Data Generation Unit 400 Service Server 411 Service Management Unit 412 User Management Unit 500 Communication Network 1011 Control Unit 1013, 1102 Input Unit 1103 Data Acquisition Unit
Claims
1. A control method in a data circulation system including a plurality of authentication servers each having a distributed ledger and a service server, comprising: The service server generates challenge content that is a target determinable based on user data and for which an incentive is given to the user when the target challenged by the user is achieved; The service server generates a first smart contract programmed to be able to give an incentive to the user when the target indicated in the generated challenge content is achieved; The service server generates first transaction data including the first smart contract and transmits the first transaction data to a first authentication server among the plurality of authentication servers; The first authentication server executes a consensus algorithm for reaching an agreement on the validity of the first transaction data together with a plurality of second authentication servers different from the first authentication server among the plurality of authentication servers, records the first transaction data in the distributed ledger, and operates the first smart contract; The first authentication server notifies the challenge content to the device used by the user; The first authentication server acquires second transaction data including first challenge content selected as a registration target by the user from among the challenge content from the device; The first authentication server executes a consensus algorithm for reaching an agreement on the validity of the second transaction data together with the plurality of second authentication servers, and records the second transaction data in the distributed ledger; A control method.
2. When it is determined that the target indicated in the first challenge content is achieved based on the user data acquired by the device, the first authentication server acquires third transaction data including information about the data, which is generated; The first authentication server executes a consensus algorithm for reaching an agreement on the validity of the third transaction data together with the plurality of second authentication servers, and records the third transaction data in the distributed ledger; When the third transaction data is recorded in the distributed ledger, the first smart contract grants an incentive to the device used by the user when the target shown in the first challenge content is achieved. The control method according to claim 1.
3. The first smart contract is further programmed to be capable of registering support information for the challenge content. The first authentication server acquires fourth transaction data including support information for the first challenge content generated by a device different from the device. The first authentication server, together with the plurality of second authentication servers, executes a consensus algorithm for agreeing on the validity of the fourth transaction data, and records the fourth transaction data in the distributed ledger. When the fourth transaction data is recorded in the distributed ledger, the first smart contract registers the support information for the first challenge content. The control method according to claim 2.
4. The first smart contract is further programmed to be capable of granting an incentive to a supporter who has registered support information for the first challenge content when the target shown in the first challenge content is achieved. When the third transaction data is recorded in the distributed ledger, the first smart contract grants the incentive granted when the target shown in the first challenge content is achieved to the device used by the user and the different device used by the supporter. The control method according to claim 3.
5. The first smart contract is programmed to be capable of granting more incentives as the number of supporters who have registered support information for the first challenge content increases. The control method according to claim 4.
6. The first authentication server acquires fifth transaction data including a second smart contract programmed to be capable of determining whether the data can be provided based on consent information regarding utilization of the data from the device, and operates the second smart contract by recording the fifth transaction data in the distributed ledger. The service server generates sixth transaction data including a data acquisition request indicating a request to acquire the data, and transmits the data to the first authentication server. The first authentication server acquires the sixth transaction data and records the sixth transaction data in the distributed ledger. When the sixth transaction data is recorded in the distributed ledger, the second smart contract determines whether the data can be provided to the service server. When it is determined by the second smart contract that the data can be provided to the service server, the data is provided to the service server. The control method according to any one of claims 1 to 5.
7. The challenge content includes a target for improving or maintaining the user's health, which is determined based on the user's vital data. The control method according to any one of claims 1 to 6.
8. The challenge content includes a target for the user to perform a usage method for suppressing deterioration of a storage battery installed in a house where the user lives for a certain period, which is determined based on data indicating the remaining amount of the storage battery. The control method according to any one of claims 1 to 7.
9. The challenge content includes a target for the user to perform an action to cover the electric power used in the house only with a self - power generation facility installed in the house where the user lives for a certain period, which is determined based on data indicating the power generation amount of the self - power generation facility and the electric power usage amount in the house. The control method according to any one of claims 1 to 8.
10. A data circulation system including a plurality of authentication servers each having a distributed ledger and a service server, The service server includes a CPU and a memory. The service server uses the CPU and the memory to generate challenge content that is a target determinable based on user data and for which an incentive is given to the user when the target indicated in the generated challenge content is achieved, generate a first smart contract programmed to be able to give an incentive to the user when the target indicated in the generated challenge content is achieved, generate first transaction data including the first smart contract and transmit the data to a first authentication server among the plurality of authentication servers. The first authentication server, together with a plurality of second authentication servers different from the first authentication server among the plurality of authentication servers, executes a consensus algorithm for reaching an agreement on the validity of the first transaction data, records the first transaction data in a distributed ledger, and operates the first smart contract. The first authentication server, causes the first smart contract to notify the device used by the user of the challenge content. The first authentication server, obtains, from the device, second transaction data including first challenge content selected by the user as a registration target among the challenge content. together with the plurality of second authentication servers, executes a consensus algorithm for reaching an agreement on the validity of the second transaction data, and records the second transaction data in a distributed ledger. A data circulation system.
11. A program for causing a computer to execute a control method in a data circulation system including a plurality of authentication servers each having a distributed ledger and a service server, wherein the service server generates challenge content that is a target determinable based on user data and for which an incentive is given to the user when the target challenged by the user is achieved. The service server generates a first smart contract programmed to be able to give an incentive to the user when the target indicated in the generated challenge content is achieved. The service server generates first transaction data including the first smart contract and transmits it to a first authentication server among the plurality of authentication servers. The first authentication server, together with a plurality of second authentication servers different from the first authentication server among the plurality of authentication servers, executes a consensus algorithm for reaching an agreement on the validity of the first transaction data, records the first transaction data in a distributed ledger, and operates the first smart contract. The first authentication server notifies the device used by the user of the challenge content. The first authentication server obtains second transaction data including first challenge content selected by the user as a registration target among the challenge content from the device. The first authentication server records the second transaction data in a distributed ledger by executing a consensus algorithm for reaching an agreement on the validity of the second transaction data together with the plurality of second authentication servers. A program for causing a computer to execute.
Citation Information
Patent Citations
Information processing device and program
JP2020017152A
Time-bounded activity chains with multiple authenticated agent participation bound by distributed single-source-of-truth networks that can enforce automated value transfer
US20200058020A1