Information management server, information management method, and program

JP7711534B2Active Publication Date: 2025-07-23TOPPAN HOLDINGS INC
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
JP2021158692
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-29
Publication Date
2025-07-23
Estimated Expiration
2041-09-29

AI Technical Summary

Technical Problem

Identity verification during every procedure is a burden for users and operators, leading to increased costs and potential safety risks due to outdated personal information.

Method used

An information management server that determines the necessity of identity verification based on procedure type, user attributes, and personal information update frequency, performing verification only when necessary.

Benefits of technology

Ensures safe procedures while reducing the burden of identity verification, maintaining up-to-date personal information, and minimizing costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007711534000001
    Figure 0007711534000001
  • Figure 0007711534000002
    Figure 0007711534000002
  • Figure 0007711534000003
    Figure 0007711534000003
Patent Text Reader

Abstract

To execute a safe procedure while suppressing a burden for identification during the procedure.SOLUTION: An information management server includes: an acquisition unit which acquires, from a user terminal, a procedure execution request for executing a procedure related to a user; a determination unit which determines whether to verify the identity of the user in the procedure requested in the procedure execution request; an identification execution unit which verifies the identity of the user on the basis of a result determined by the determination unit; and a storage unit which stores procedure type information that indicates conditions for identification for each of procedure types. The determination unit determines whether to verify the identity of the user on the basis of the procedure type information and a degree of necessity for the latest personal information of the user.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information management server, an information management method, and a program.

Background Art

[0002] In various procedures carried out in person or remotely (online), identity verification is performed (see, for example, Patent Document 1). In particular, in identity verification carried out in remote (online) procedures, for example, using an image of a driver's license or the like that has been captured, or electronic information obtained from a My Number card, it is confirmed that the person conducting the procedure is undoubtedly the individual. By performing identity verification, it is possible to prevent procedures by third-party impersonation and conduct safe procedures.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, performing identity verification every time a procedure is carried out is a heavy burden on users and the operators conducting the procedure. Here, operators include, for example, financial institutions and local governments. For users, even if there is no change in their address or name, they feel bothered when they are required to present official documents or My Number cards every time. Also, for operators, when outsourcing identity verification to an external party, if identity verification is performed every time a procedure is carried out, the cost paid to the outsourcing destination increases, resulting in a large economic burden.

[0005] As a countermeasure, it is conceivable to reduce the burden on users and companies by performing identity verification only during the first procedure and omitting identity verification in subsequent procedures. For example, if it is within the validity period of a public document such as a driver's license or a My Number card used for identity verification during the first procedure, it is conceivable to omit identity verification during subsequent procedures. However, even within the validity period of a public document, the user's address may change due to a move or the like. In this case, in the procedure after the move, although it is necessary to perform identity verification at the new address, there is a possibility that identity verification may be omitted, and there is a problem that a procedure with doubtful safety may be performed.

[0006] The present invention has been made in view of such circumstances, and an object thereof is to provide an information management server, an information management method, and a program capable of performing a safe procedure while suppressing the burden related to identity verification performed in the procedure.

Means for Solving the Problems

[0007] In order to solve the above-described problems, an information management server according to the present invention includes an acquisition unit that acquires a procedure execution request for requesting execution of a procedure related to a user from a user terminal, a determination unit that determines whether or not to perform identity verification of the user in the procedure requested by the procedure execution request, an identity verification execution unit that performs identity verification of the user based on a determination result by the determination unit, and a storage unit that stores procedure type information indicating conditions for performing identity verification for each type of procedure. The determination unit determines whether or not to perform identity verification of the user based on the procedure type information and Whether the business entity at the processing destination is a business entity that makes notifications using the personal information of the user thereon.

[0008] In addition, in order to solve the above-described problems, an information management method according to the present invention is an information management method performed by a computer having a storage unit that stores procedure type information in which conditions for performing personal identification are shown for each type of procedure. An acquisition unit acquires a procedure execution request for requesting execution of a procedure related to a user from a user terminal, a determination unit determines whether or not to perform personal identification of the user in the procedure requested by the procedure execution request, and a personal identification execution unit performs personal identification of the user based on a determination result by the determination unit. The determination unit determines whether or not to perform personal identification of the user based on the procedure type information and Whether the business entity at the processing destination is a business entity that makes notifications using the personal information of the user based on.

[0009] In addition, in order to solve the above-described problems, the present invention is a program for operating a computer as the information management server described above, and is a program for causing the computer to function as each unit included in the information management server.

Advantages of the Invention

[0010] According to the present invention, it is possible to perform a safe procedure while suppressing the burden related to personal identification performed in the procedure.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Mode for Carrying Out the Invention

[0012] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0013] <Configuration of the Procedure Information Linkage System 1> The procedure information linkage system 1 is a system that provides a procedure service. In the procedure service, various procedures such as membership registration, account registration, account transfer, address change, name change, etc. at each business operator, administrative procedures, procedures for updating personal information, and application for membership are performed in response to the requests of users.

[0014] FIG. 1 is a block diagram showing a configuration example of a procedure information linkage system 1 to which the information management server 20 according to the embodiment is applied. The procedure information linkage system 1 includes, for example, a user terminal 10, an information management server 20, an authentication server 30, and a business operator server 40. These components (user terminal 10, information management server 20, authentication server 30, and business operator server 40) in the procedure information linkage system 1 are communicably connected via a communication network NW.

[0015] The user terminal 10 is a computer having a communication function such as a smartphone, a mobile phone, or a tablet terminal. The user terminal 10 is operated by a user. The user can use the procedure service by operating the user terminal 10.

[0016] The information management server 20 is a computer such as a server, a cloud server, or a PC. The information management server 20 provides a procedure service. In the procedure service, a procedure is executed in response to a request from a user. The information management server 20 determines whether to perform an identity verification when executing the procedure requested by the user. When the information management server 20 determines to perform an identity verification, for example, it requests the authentication server 30 to perform the authentication necessary for identity verification and obtains the authentication result from the authentication server 30. If the person who has requested to execute the procedure is confirmed to be the person himself / herself as a result of the identity verification, the information management server 20 notifies the business operator server 40 of the procedure details and the result of the identity verification. Alternatively, the information management server 20 may notify the business operator server 40 of the information necessary for identity verification. In this case, the business operator server 40 performs an identity verification based on the information received from the information management server 20 (the information necessary for identity verification) and notifies the information management server 20 of the result.

[0017] The authentication server 30 is a computer such as a server, a cloud server, or a personal computer (PC). The authentication server 30 performs the authentication necessary for identity verification. The authentication server 30 performs, for example, public personal authentication (JPKI, Japanese Public Key Infrastructure) using a My Number card. Alternatively, the authentication server 30 may be configured to perform an identity verification using an identity certificate such as a driver's license.

[0018] The business operator server 40 is a computer such as a server, a cloud server, or a PC. The business operator server 40 executes various procedures in the business operator based on the procedure details and the result of the identity verification notified from the user terminal 10.

[0019] <Processing of the Procedure Information Linkage System 1> In the procedure information cooperation system 1, for identity verification, for example, official personal authentication using a My Number card is performed. In official personal authentication, the basic four pieces of information (name, date of birth, gender, address) of the user are obtained from the electronic certificate embedded in the My Number card. Also, the expiration date of the electronic certificate embedded in the authentication server 30 My Number card is obtained, and its validity is confirmed.

[0020] For example, the user logs in to the procedure service by operating the user terminal 10. When logging in to the procedure service, an authentication screen is provided by the information management server 20 and displayed on the user terminal 10. The user inputs the password set on the My Number Card or performs a touch operation of bringing the My Number Card close to the user terminal 10 according to the guidance on the authentication screen. Thereby, the user terminal 10 notifies the information management server 20 of information regarding the electronic certificate and the user's basic four pieces of information (name, date of birth, gender, address). The information management server 20 stores the user's basic four pieces of information. Also, the information management server 20 notifies the authentication server 30 of information regarding the electronic certificate embedded in the My Number Card and requests to confirm the validity of the electronic certificate. The authentication server 30 acquires the validity period of the electronic certificate, confirms the validity of the electronic certificate based on the acquired validity period, and notifies the information management server 20 of the confirmation result. The confirmation result includes the validity period of the electronic certificate and information indicating the validity of the electronic certificate. The information management server 20 stores the validity period of the electronic certificate. Alternatively, the information management server 20 may be composed of a plurality of servers. For example, the information management server 20 may be composed of a first server having an acquisition function and a second server having a verification function. In the acquisition function, information related to identity verification is acquired. In the verification function, identity verification is performed based on the information acquired by the acquisition function. For example, the first server acquires information regarding the electronic certificate embedded in the My Number Card by a touch operation by the user or the like and outputs the acquired information to the second server. The second server notifies the authentication server 30 of the information acquired from the first server and requests to confirm the validity of the electronic certificate. The second server acquires the confirmation result of the validity of the electronic certificate from the authentication server 30 and outputs the acquired confirmation result to the first server.

[0021] Alternatively, in the procedure information cooperation system 1, identity verification is performed using an identity document such as a driver's license. In this case, for example, the information management server 20 requests the authentication server 30 to verify the identity of the user using the identity document, and the authentication screen provided by the authentication server 30 is displayed on the user terminal 10. Instructions for performing identity verification using the identity document are displayed on the authentication screen. The user captures an image of the driver's license or their own face according to the instructions on the authentication screen. As a result, the user terminal 10 notifies the authentication server 30 of the image information of the identity document and the user's own face. The authentication server 30 performs identity verification based on the image information obtained from the user terminal 10 and notifies the information management server 20 of the verification result. The verification result of the identity verification includes, for example, personal information such as the user's address, name, and date of birth described in the identity document, the degree of match between the face photo published in the identity document and the user's face image, and information such as the expiration date of the identity document. The information management server 20 acquires information indicating the verification result of the identity verification by the authentication server 30 and stores the acquired information. Alternatively, the information management server 20 may notify the image information obtained from the user terminal 10 to the operator server 40. In this case, the operator server 40 performs identity verification based on the image information received from the information management server 20 and notifies the information management server 20 of the result.

[0022] In the conventional procedure information cooperation system, identity verification was performed in the following cases. (1-1) When the user creates an account for the procedure service (1-2) When performing a procedure that requires identity verification (1-3) When the expiration date of the electronic certificate embedded in the My Number card has passed (1-4) When the expiration date of the identity document has passed However, (3) is the case where identity verification is performed using public personal authentication by the My Number card. Also, (4) is the case where identity verification is performed using an identity document.

[0023] In a conventional procedure information linkage system, when performing procedures that do not require identity verification each time a procedure is carried out (for example, procedures for making account transfers, etc.), the procedures were executed without identity verification. However, when creating an account for a procedure service, etc., the identity verification of the user is performed, and it is assumed that the procedure is carried out within the validity period of the electronic certificate or identity certificate used for the identity verification. In the procedure information linkage system, personal information such as the address and name of the user used for identity verification is registered in the information management server 20 as the latest personal information of the user. When identity verification is omitted in a procedure, the opportunity to update the user's personal information is lost. In the following description, the electronic certificate or identity certificate used for identity verification may be collectively referred to as a "public document".

[0024] The validity period of a public document is often set to about five years. If identity verification is not performed until the validity period of the public document expires, the user's personal information will not be updated for up to about five years. During this period, consider the case where the user's personal information such as address changes due to a move. After moving, if a procedure that requires identity verification is carried out through a procedure service, identity verification will be performed at that time and the new address after moving can be registered as the latest personal information of the user. However, if a procedure that does not require identity verification is carried out, or if a procedure is carried out without reporting that the user's personal information has been updated at the user's request, although the procedure itself is executed, the procedure will be executed in a state that does not match the latest personal information of the user, and as a result, there is a possibility that a procedure with suspected security will be executed.

[0025] Or even if the procedure is carried out safely, there may be disadvantages due to the non-update of the user's personal information. For example, when the user's address changes due to a move, it becomes impossible to contact the user after moving. For example, when a procedure notice regarding a procedure with an approaching deadline is mailed, the mailed item does not reach the address of the user after moving, making it difficult to provide appropriate procedure services.

[0026] In addition, depending on the business operator, there may be drawbacks due to the failure to update the personal information of the user. When a procedure that requires identity verification is executed, the result of the identity verification is notified from the information management server 20 to the business operator server 40 together with the procedure details, so the business operator can grasp the latest personal information of the user. However, when a procedure that does not require identity verification is executed, the result of the identity verification is not notified. Although the procedure itself can be executed without problems, the business operator cannot grasp the latest personal information of the user. As a result, for example, even if a notice such as the expiration of the contract period or a new product guide is mailed to the user, the mailed item may not reach the address of the user after the move, resulting in a loss of opportunity.

[0027] As a countermeasure against this, in the procedure information cooperation system 1, a mechanism has been completed to set the timing for checking whether the personal information of the user is up-to-date for each user and procedure.

[0028] Specifically, the information management server 20 sets a flag for each user and procedure based on various conditions. The various conditions here are, for example, conditions such as the type of procedure, the necessity for the user's personal information to be up-to-date, and the possibility of the user's personal information being changed. The flag here is a variable indicating whether to perform identity verification. For example, when 1 is set in the flag, it indicates that it is checked whether the user's personal information is up-to-date, and when 0 (zero) is set in the flag, it indicates that it is not checked whether the user's personal information is up-to-date. In this case, 1 is always set in the flag for procedures that require identity verification.

[0029] The information management server 20 checks whether the user's personal information is up-to-date according to the set value of the flag. When the user's personal information is updated, the information management server 20 stores the latest personal information of the user. Thereby, the personal information of the user is updated to maintain the up-to-dateness of the personal information. In addition, the information management server 20 may notify the business operator server 40 of the latest personal information of the user. Thereby, the latest personal information of the user can be coordinated with the business operator.

[0030] Here, as a method for confirming whether the user's personal information is up-to-date, a method of compulsorily verifying the identity using official documents and a method of asking the user questions can be considered.

[0031] A method of confirming whether the user's personal information is up-to-date by asking the user will be described. The information management server 20 sends a notification asking whether there is any change in the user's personal information to the user terminal 10. The user terminal 10 displays the question received from the information management server 20. In this case, on the user terminal 10, for example, together with the user's personal information obtained at the previous identity verification, a message such as "Is there any change to this information?" is displayed. Also, buttons such as "Yes" and "No" are displayed so that they can be selected as answers to the message. The user operates the screen to select the "Yes" or "No" button. When either button is selected, the user terminal 10 sends a response corresponding to the selection result to the information management server 20. Alternatively, the information management server 20 may ask whether there is any change in the user's personal information on the screen presented in the procedure service. In this case, the information management server 20 causes the user terminal 10 to display a question screen asking whether there is any change in the user's personal information. The user operates the screen to select the "Yes" or "No" button displayed together with a message such as "Is there any change to this information?". When either button is selected, the response corresponding to the selection result is notified to the information management server 20.

[0032] When the information management server 20 receives a response from the user terminal 10 indicating that the user's personal information has been changed, it sends a notification to the user terminal 10 asking whether it is possible to present official documents that can prove the changed content. The user terminal 10 sends a response to the information management server 20 regarding the question. The response indicates whether official documents that can prove the changed content can be presented.

[0033] When it is shown that there is an official document that can prove the changed content in the response obtained from the user terminal 10, the information management server 20 performs identity verification using the official document. Then, if the result of the identity verification confirms that the user is the right person, the information management server 20 notifies the procedure details and the result of the identity verification to the business operator server 40.

[0034] On the other hand, when it is shown that there is no official document that can prove the changed content in the response obtained from the user terminal 10, the information management server 20 notifies the user terminal 10 that the procedure cannot be executed without performing identity verification. This suppresses the occurrence of waste such that only the labor and cost of identity verification occur as a result of performing identity verification with the old information before the change, and ultimately the procedure cannot be executed.

[0035] In the following description, confirming whether the user's personal information is up-to-date is simply referred to as "performing identity verification" or the like.

[0036] The information management server 20 performs identity verification on the user at the following frequencies, for example. (2-1) Frequency according to the score based on the result of the questionnaire conducted on the user (2-2) Frequency according to the age of the user (2-3) Frequency according to the number of procedures performed by the user within a predetermined period (for example, one year) (2-4) Frequency according to the necessity for the user's personal information to be up-to-date

[0037] (2-1) will be described. The information management server 20 conducts a questionnaire survey on users and stores the results (the response history of the user attribute information 220 described later). The questionnaire here is a questionnaire regarding financial transactions and crime risks. In this questionnaire, for example, questions regarding whether remittances are made overseas are asked from the perspective of measures against money laundering. The information management server 20 conducts a questionnaire survey regularly, for example, when a user creates an account for a procedure service and after the account is created. The information management server 20 calculates a score based on the responses to the questionnaire. Alternatively, the information management server 20 may calculate a score using external information in addition to the responses to the questionnaire. Specifically, the information management server 20 monitors the transaction status of the user's account and, if there is a difference from the response content of the questionnaire by the user, may vary the score based on the actual transaction status. The score here is an indicator showing the possibility that the security is doubted when identity verification is omitted in a procedure that a user may execute.

[0038] In the following, a case where the higher the score, the higher the security and the lower the score, the lower the security will be described as an example. For example, when a user makes a remittance overseas, the procedure for making an overseas remittance may be used for money laundering. Therefore, when identity verification is omitted in the procedure for making an overseas remittance, the security of the procedure may be doubted. For this reason, the information management server 20 calculates a lower score when the user makes a remittance overseas. On the other hand, when the user does not make a remittance overseas, since the procedure for making an overseas remittance is not executed, a higher score is calculated.

[0039] The information management server 20 conducts identity verification at a frequency corresponding to the calculated score. For procedures performed by users with a low score, the information management server 20 sets a high frequency of identity verification and conducts identity verification frequently (for example, once a year). Thereby, the security of the procedure can be ensured and the personal information of the user can be updated to the latest information.

[0040] Regarding (2-2), an explanation will be given. In the first personal verification, the information management server 20 stores the date of birth included in the personal information of the user (the personal information of the user attribute information 220 described later). Based on the obtained date of birth of the user, the information management server 20 classifies the user by age group and performs personal verification at a frequency corresponding to the classified age group. For example, the information management server 20 classifies the user into a young age group (e.g., up to the 30s) and other age groups (e.g., 40s and above).

[0041] Generally, the proportion of young people living in rental housing is larger compared to other age groups. Therefore, if the user is in the young age group, the user is highly likely to live in rental housing and the address may be changed by moving at the time of renewal of the rental housing or other such timings. For this reason, when the user is in the young age group, the information management server 20 sets a high frequency for performing personal verification and performs personal verification frequently (e.g., once a year).

[0042] When the frequency of performing personal verification is set to once a year, the information management server 20 performs personal verification, for example, when the user first accesses the procedure service after their birthday each year.

[0043] The expiration date in official documents is often set based on the user's birthday. Therefore, by setting the timing of performing personal verification based on the user's birthday, the validity period can be guaranteed on average. For example, it is possible to avoid a situation where the expiration date in the official document passes immediately after performing personal verification once a year and personal verification has to be performed using the renewed official document soon after performing personal verification.

[0044] Regarding (2-3), an explanation will be given. The information management server 20 stores the history of procedures performed by the user (personal verification history information 222, which will be described later). When the information management server 20 receives a request from the user to execute a procedure, it acquires the history of procedures performed by that user in the past. The information management server 20 calculates the number of procedures the user has performed since the beginning of this year based on the acquired history. If the user has performed multiple procedures since the beginning of this year, the information management server 20 conducts personal verification at predetermined intervals (for example, when the number of times is a multiple of 3). As a result, in procedures that the user repeats many times, personal verification can be conducted about once every several times, ensuring the safety of the procedures and enabling the user's personal information to be updated to the latest information.

[0045] Regarding (2-4), an explanation will be given. The information management server 20 stores information indicating the conditions for conducting personal verification for each procedure (procedure type information 221). Also, the information management server 20 stores the history of personal verification performed on the user (personal verification history information 222). When the information management server 20 receives a request from the user to execute a procedure, it acquires the conditions for conducting personal verification in the procedure requested by that user, and based on the acquired conditions, determines whether it is a condition to conduct personal verification to perform the procedure. In addition, the information management server 20 determines the necessity for the user's personal information to be up-to-date. For example, when the business operator of the procedure destination is a business operator that notifies the user by mail, the information management server 20 determines that the necessity for the user's personal information to be up-to-date is high. On the other hand, when the business operator of the procedure destination is a business operator that does not notify the user by mail, the information management server 20 determines that the necessity for the user's personal information to be up-to-date is low.

[0046] When the information management server 20 determines that it is highly necessary for the user's personal information to be up-to-date, it refers to the history of identity verification performed on the user and obtains the date of the previous identity verification for the user. If a predetermined period (for example, three years) has elapsed since the date of the previous identity verification, the information management server 20 determines that an identity verification is to be performed even if it is not a condition for performing the procedure. Alternatively, the information management server 20 may change a predetermined period (for example, three years) based on the user's age group, the results of a questionnaire, or the history of procedures. For example, when the user is in the young age group, the information management server 20 may determine that an identity verification is to be performed even if it is not a condition for performing the procedure when a predetermined period (for example, one year) has elapsed since the date of the previous identity verification. Thereby, the user's personal information can be updated to the latest information according to the necessity.

[0047] (2-1) to (2-4) show that by checking whether the user's personal information is up-to-date at the indicated frequencies, the user's personal information can be updated at an appropriate timing. Therefore, it is possible to maintain the up-to-dateness of the user's personal information without imposing an excessive load on the user and without increasing the cost and processing cost associated with identity verification.

[0048] Note that a uniform frequency (the frequency of checking whether the user's personal information is up-to-date) does not have to be set for each procedure and each user. The frequency may be arbitrarily set for each procedure and each user according to the number of identity verifications performed by the user within a predetermined period, the cost required for each identity verification, the importance of identity verification in the procedures performed by the user, and the like.

[0049] For example, even for the same type of procedure, when a certain user performs the procedure, identity verification may not be performed, but when another user performs the procedure, it may be performed. Also, even when the same user performs the same type of procedure, although identity verification has been performed at a frequency of once a year until now, it may be performed at a frequency of once a month from the next time on.

[0050] <Configuration of Information Management Server 20> Here, the configuration of the information management server 20 will be described with reference to FIG. 2. FIG. 2 is a block diagram showing the configuration of the information management server 20 according to the embodiment. The information management server 20 includes, for example, a communication unit 21, a storage unit 22, and a control unit 23. The communication unit 21 communicates with the user terminal 10, the authentication server 30, and the service provider server 40.

[0051] The storage unit 22 is composed of a storage medium, for example, an HDD (Hard Disk Drive), a flash memory, an EEPROM (Electrically Erasable Programmable Read Only Memory), a RAM (Random Access read / write Memory), a ROM (Read Only Memory), or an arbitrary combination of these storage media. The storage unit 22 stores programs for executing various processes of the information management server 20 and temporary data used when performing various processes. The storage unit 22 stores, for example, user attribute information 220, procedure type information 221, personal verification history information 222, and determination condition information 223.

[0052] The user attribute information 220 is the attribute information of the user. The user's attribute information includes, for example, the user's personal information, questionnaire response history, procedure history, etc. FIGS. 3 to 5 are diagrams showing examples of the user attribute information 220 according to the embodiment. The user attribute information 220 is generated for each user. Note that, as the user's attribute information, information other than the information shown in FIGS. 3 to 5, for example, the transaction status of the user's account, may be included.

[0053] In FIG. 3, an example of the user's personal information is shown as the user attribute information 220A. As shown in FIG. 3, the personal information stores information corresponding to items such as name, date of birth, gender, address, etc. These personal information are, for example, information obtained from official documents when performing personal verification.

[0054] FIG. 4 shows an example of the questionnaire response history as the user attribute information 220B. As shown in FIG. 4, the questionnaire response history stores information corresponding to items such as, for example, the date when the questionnaire was conducted, the questionnaire content, and the score calculated based on the questionnaire responses. These response histories are created, for example, each time a questionnaire is administered to the user.

[0055] FIG. 5 shows an example of the procedure history as the user attribute information 220C. As shown in FIG. 5, the procedure history stores information corresponding to items such as, for example, the date when the procedure was performed, the procedure content, and whether or not identity verification was performed in the procedure. These procedure histories are created, for example, each time a procedure is performed.

[0056] The procedure type information 221 is information in which the conditions for performing a procedure by a business operator are shown for each type of procedure. FIG. 6 is a diagram showing an example of the procedure type information 221 according to the embodiment. The procedure type information 221 stores information corresponding to items such as, for example, the name of the procedure and the necessity of identity verification. The procedure type information 221 is created, for example, for each business operator, and for each of the various procedures performed by the business operator, it is shown whether or not identity verification is required in the procedure.

[0057] The personal verification history information 222 is information showing the history of performing personal verification. The personal verification history information 222 is created for each user, for example. FIG. 7 is a diagram showing an example of the personal verification history information 222 according to the embodiment. The personal verification history information 222 stores information corresponding to items such as the implementation date, verification motivation, verification method, and expiration date. The implementation date stores information indicating the date when the personal verification was performed. The verification motivation stores information indicating the motivation that triggered the personal verification. The verification method stores information indicating what kind of official document was used for the personal verification, for example, whether it is a My Number card, a driver's license, or other document. Also, as the verification method, information indicating whether the personal verification was performed using public personal authentication (JPKI), whether the personal verification was performed using an image of an official document, etc. may be included. The expiration date stores information indicating the expiration date of the electronic certificate or official document such as an identity certificate used for the personal verification.

[0058] The determination condition information 223 is information showing the criteria for determining whether to perform personal verification. FIG. 8 is a diagram showing an example of the determination condition information 223 according to the embodiment. The determination condition information 223 stores information corresponding to items such as the target user and implementation conditions. The target user stores information indicating the users who can be the target of personal verification. The implementation conditions show the conditions for performing personal verification. In the example of FIG. 8, it is shown that young users should perform personal verification every year. Also, for users who have performed a predetermined procedure (Procedure A) more than three times in a year, it is shown that personal verification should be performed when the number of procedures is a multiple of three. Also, for users whose score in Questionnaire A is below a predetermined value (A3), it is shown that personal verification should be performed each time the procedure is carried out. Also, for users whose score in Questionnaire B is below a predetermined value (B2), it is shown that personal verification should be performed every six months.

[0059] Returning to FIG. 2, the control unit 23 controls each component of the information management server 20. The control unit 23 is realized, for example, by the CPU (Central Processing Unit) of the information management server 20 executing a program stored in advance in the storage unit 22. Further, the control unit 23 may be realized as an integrated circuit such as an ASIC (Application Specific Integrated Circuit). The control unit 23 includes, for example, an acquisition unit 230, a determination unit 231, an identity verification execution unit 232, an information cooperation unit 233, and a device control unit 234.

[0060] The acquisition unit 230 acquires various types of information. The acquisition unit 230 acquires various types of information notified from the user terminal 10, the authentication server 30, and the business operator server 40 via the communication unit 21. The acquisition unit 230 outputs the acquired information to functional units (the determination unit 231, the identity verification execution unit 232, the information cooperation unit 233, and the device control unit 234) that perform processing using the information.

[0061] The acquisition unit 230 acquires a procedure execution request notified from the user terminal 10. The procedure execution request is a notification requesting the execution of a procedure using a procedure service. The procedure execution request includes, for example, information indicating the content of the procedure requested by the user and personal information such as the user's name and address.

[0062] The determination unit 231 acquires a procedure execution request from the acquisition unit 230 and determines whether to perform identity verification in the procedure requested by the procedure execution request. The determination unit 231 identifies the type of procedure requested by the user based on the procedure request information, and acquires the procedure type information 221 including the identified procedure from the storage unit 22. The determination unit 231 determines whether identity verification is essential in the procedure requested by the user based on the acquired procedure type information 221. If it is essential, the determination unit 231 determines to perform identity verification. Further, if the conditions for performing identity verification in the procedure requested by the user (for example, if three or more months have passed since the previous procedure) are indicated based on the acquired procedure type information 221, the determination unit 231 determines whether those conditions are satisfied. If those conditions are satisfied, the determination unit 231 determines to perform identity verification.

[0063] In addition, the determination unit 231 identifies the user who requested the procedure based on the procedure request information, and acquires the user attribute information 220 and the identity verification history information 222 of the identified user from the storage unit 22. The determination unit 231 determines whether the user corresponds to the user targeted by the determination condition information 223 based on the user attribute information 220, the identity verification history information 222, and the determination condition information 223. When the user corresponds to the user targeted by the determination condition information 223, the determination unit 231 acquires the implementation conditions thereof. The determination unit 231 determines whether the acquired implementation conditions (for example, performing identity verification every year) are satisfied. If those conditions are satisfied, the determination unit 231 determines to perform identity verification.

[0064] The personal verification execution unit 232 performs personal verification according to the determination result by the determination unit 231. When it is determined by the determination unit 231 that personal verification is to be performed, the personal verification execution unit 232 transmits, to the user terminal 10, an authentication screen for implementing JPKI using, for example, a My Number card. Alternatively, before performing personal verification, the personal verification execution unit 232 asks a question to confirm whether the personal information of the user has changed, and performs personal verification after confirming that the personal information has not changed. Alternatively, when the personal information has changed, the personal verification execution unit 232 asks whether a public document proving the change in personal information can be presented, and when the changed public document can be presented, performs personal verification using the changed public document. When the changed public document is not presented, the personal verification execution unit 232 notifies the user terminal 10 that the procedure cannot be performed without performing personal verification.

[0065] The information cooperation unit 233 notifies the business operator server 40 of the content of the procedure corresponding to the procedure execution request notified from the user terminal 10, and the result of the personal verification if personal verification is performed.

[0066] The device control unit 234 integrally controls the information management server 20. For example, the device control unit 234 controls the communication unit 21 to output the information received by the communication unit 21 from the user terminal 10, the authentication server 30, and the business operator server 40 to the acquisition unit 230.

[0067] <Flow of processing> Here, the flow of processing performed by the information management server 20 will be described. FIG. 9 is a flowchart showing the flow of processing performed by the information management server 20 of the embodiment.

[0068] The information management server 20 receives a procedure execution request from the user terminal 10 (step S10). The information management server 20 acquires procedure type information 221 including the procedure requested by the user based on the procedure request information (step S11). The information management server 20 determines whether the conditions for performing identity verification in the procedure requested by the user are satisfied (step S12). For example, when identity verification is essential in the procedure, or when the conditions for performing identity verification in the procedure (for example, if three or more months have passed since the previous procedure) are met, the information management server 20 determines that the conditions for performing identity verification in the procedure are satisfied. When the information management server 20 determines that the conditions for performing identity verification in the procedure are satisfied, it sets 1 in a flag (identity verification flag) (step S15).

[0069] On the other hand, when the information management server 20 determines in step S12 that the conditions for performing identity verification in the procedure requested by the user are not satisfied, it acquires the user attribute information 220 and the identity verification history information 222 of the user who requested the procedure. The information management server 20 determines whether the user satisfies the conditions for performing identity verification based on the user attribute information 220, the identity verification history information 222, and the determination condition information 223 (step S14).

[0070] For example, when the age group of the user satisfies the conditions for performing identity verification shown in the determination condition information 223, the information management server 20 determines that the conditions for performing identity verification are satisfied. For example, when the number of procedures performed by the user in one year satisfies the conditions for performing identity verification shown in the determination condition information 223, the information management server 20 determines that the conditions for performing identity verification are satisfied. For example, when the score of the questionnaire conducted on the user satisfies the conditions for performing identity verification shown in the determination condition information 223, the information management server 20 determines that the conditions for performing identity verification are satisfied.

[0071] When the information management server 20 determines that the user has satisfied the conditions for identity verification, it sets 1 in a flag (identity verification flag) (step S15). On the other hand, when the information management server 20 determines that the user has not satisfied the conditions for identity verification, it sets 0 (zero) in the flag (identity verification flag) (step S16).

[0072] As described above, the information management server 20 of the embodiment includes an acquisition unit 230, a determination unit 231, an identity verification execution unit 232, and a storage unit 22. The acquisition unit 230 acquires a procedure execution request notified from the user terminal 10. The procedure execution request is a notification requesting the execution of a procedure related to the user. The determination unit 231 determines whether to perform identity verification of the user in the procedure requested by the procedure execution request. The identity verification execution unit 232 performs identity verification of the user based on the determination result by the determination unit. The storage unit 22 stores procedure type information 221 indicating the conditions for performing identity verification for each type of procedure. The determination unit 231 determines whether to perform identity verification of the user based on the procedure type information 221 and the necessity for the user's personal information to be up-to-date. Thereby, the information management server 20 of the embodiment can perform identity verification if necessary and refrain from performing identity verification if not, in accordance with the conditions for performing identity verification in the procedure, and can perform a safe procedure while suppressing the burden associated with identity verification. Also, since identity verification can be performed according to the necessity for the user's personal information to be up-to-date, for example, identity verification can be performed according to the case where it is necessary to mail a guide after the procedure. For this reason, for example, in a case where a user changes the name of a credit card through a procedure service and a new card with the changed name is mailed at a later date, it is possible to avoid a situation where an opportunity loss occurs because the mailed item does not reach the user's address.

[0073] In the information management server 20 of the embodiment, the storage unit 22 stores the identity verification history information 222 indicating the history of identity verification performed on the user. When the determination unit 231 determines not to perform identity verification based on the procedure type information 221, it determines based on the identity verification history information 222 whether or not a predetermined period has elapsed since the previous identity verification. If a predetermined period has elapsed since the previous identity verification, it is determined to perform identity verification. Thereby, it is possible to periodically confirm whether or not the personal information of the user has been changed, and it is possible to avoid a situation in which an opportunity loss occurs.

[0074] In the information management server 20 of the embodiment, when performing identity verification, the identity verification execution unit 232 may send a first notification to the user terminal 10 asking whether or not there has been a change in the user's personal information. When a response indicating that there has been a change in the user's personal information is obtained for the first notification, the identity verification execution unit 232 sends a second notification to the user terminal 10 asking whether or not it is possible to present a public document that can prove that there has been a change in the user's personal information. When a response indicating that it is not possible to present a public document that can prove that there has been a change in the user's personal information is obtained for the second notification, the identity verification execution unit 232 does not perform the user's identity verification and notifies the user terminal 10 that the procedure cannot be performed. Thereby, it is possible to suppress a waste in which only the labor and cost of identity verification occur as a result of performing identity verification with the old information before the change, and ultimately the procedure cannot be executed.

[0075] The procedure information cooperation system 1 and all or part of the information management server 20 in the above-described embodiment may be realized by a computer. In that case, a program for realizing this function may be recorded on a computer-readable recording medium, and the program recorded on this recording medium may be read into a computer system and executed. Here, the "computer system" shall include hardware such as an OS and peripheral devices. Further, the "computer-readable recording medium" refers to a portable medium such as a flexible disk, a magneto-optical disk, a ROM, a CD-ROM, or a storage device such as a hard disk built into a computer system. Furthermore, the "computer-readable recording medium" refers to a medium that dynamically holds a program for a short time, such as a communication line when transmitting a program via a network such as the Internet or a communication line such as a telephone line, and also includes a volatile memory inside a computer system that serves as a server or a client in that case and holds a program for a certain period of time. Also, the above program may be for realizing a part of the above-described functions, and may further be realized in combination with a program already recorded in a computer system for the above-described functions, or may be realized using a programmable logic device such as an FPGA (Field Programmable Gate Array).

[0076] As described above, the embodiments of the present invention have been described in detail with reference to the drawings. However, the specific configuration is not limited to this embodiment, and designs and the like within the scope not departing from the gist of the present invention are also included.

Explanation of Reference Numerals

[0077] 1... Procedure information cooperation system, 10... User terminal, 20... Information management server, 21... Communication unit, 22... Storage unit, 220... User attribute information, 221... Procedure type information, 222... Identity confirmation history information, 223... Judgment condition information, 23... Control unit, 230... Acquisition unit, 231... Judgment unit, 232... Identity confirmation execution unit, 233... Information cooperation unit, 234... Device control unit, 30... Authentication server, 40... Business operator server

Claims

1. An acquisition unit that acquires a procedure execution request for requesting execution of a procedure related to a user from a user terminal; A determination unit that determines whether or not to perform identity verification of the user in the procedure requested by the procedure execution request; An identity verification execution unit that performs identity verification of the user based on the determination result by the determination unit; A storage unit that stores procedure type information indicating conditions for performing identity verification for each type of procedure; Comprising: The determination unit determines whether or not to perform identity verification of the user based on the procedure type information and whether or not the business operator of the procedure destination is a business operator that uses the personal information of the user to send a notification. An information management server.

2. The storage unit stores identity verification history information indicating the history of identity verification performed on the user, When the determination unit determines not to perform identity verification based on the procedure type information, the determination unit determines whether or not a predetermined period has elapsed since the previous identity verification based on the identity verification history information, and if a predetermined period has elapsed since the previous identity verification, determines to perform identity verification. The information management server according to Claim 1.

3. The identity verification execution unit sends a first notification to the user terminal to inquire whether there has been a change in the personal information of the user, and when a response indicating that there has been a change in the personal information of the user is obtained for the first notification, sends a second notification to the user terminal to inquire whether it is possible to present a public document capable of proving that there has been a change in the personal information of the user. When a response indicating that it is not possible to present a public document capable of proving that there has been a change in the personal information of the user is obtained for the second notification, the identity verification of the user is not performed. The information management server according to Claim 1 or Claim 2.

4. An information management method performed by a computer having a storage unit that stores procedure type information indicating conditions for performing identity verification for each type of procedure, An acquisition unit acquires a procedure execution request for requesting execution of a procedure related to a user from a user terminal, and a determination unit determines whether or not to perform identity verification of the user in the procedure requested by the procedure execution request, An identity verification execution unit performs identity verification of the user based on the determination result by the determination unit, The determination unit determines whether or not to perform identity verification of the user based on the procedure type information and whether or not the business operator of the procedure destination is a business operator that uses the personal information of the user to send a notification. An information management method.

5. A program for operating a computer as the information management server according to any one of Claims 1 to 3, the program for causing the computer to function as each unit included in the information management server.

Citation Information

Patent Citations

  • Card, card transaction system, card supplying method, and card transaction method

    JP1998063721A

  • Member attribute information update system

    JP2001109827A

  • System and method for managing registered information and recording medium therefor

    JP2002024422A

  • Individual identification recording and managing device

    JP2005173752A

  • Member information extraction method, system therefor, and program therefor

    JP2007334744A