Data circulation system and data usage condition determination method
The data circulation system addresses the compliance risk in data transactions by dynamically negotiating data usage conditions, enhancing security and safety through feasibility and utility-based candidate extraction.
Patent Information
- Application Number
- JP2021207065
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-12-21
- Publication Date
- 2025-07-30
- Estimated Expiration
- 2041-12-21
AI Technical Summary
Existing data transaction systems lack assurance that trading partners will comply with agreed-upon data usage conditions, compromising security and safety in data transactions.
A data circulation system and method that includes provider and user devices, along with a negotiation mediation service unit, to dynamically negotiate data usage conditions by calculating feasibility indices and utility values, extracting suitable condition candidates, and facilitating agreement based on compliance risks and benefits.
Enhances security and safety in data transactions by ensuring optimal data usage conditions are agreed upon, considering the likelihood of compliance by trading partners.
Smart Images

Figure 0007715624000001 
Figure 0007715624000002 
Figure 0007715624000003
Abstract
Description
Technical Field
[0001] The present invention relates to a data circulation system and a method for determining data usage conditions, and is suitable for application to a data circulation system and a method for determining data usage conditions in which usage conditions are determined between a data provider and a data user to conduct data transactions.
Background Art
[0002] In recent years, data circulation services utilizing platforms that mediate between people who provide data (data providers) and people who want data (data users) have been provided. For example, an information bank is considered a form of data circulation service, and the data circulated is personal data including personal information.
[0003] In data transactions, it is necessary for the parties to agree on the usage conditions of the data (data usage conditions). In open data transactions, it is common for the data provider to disclose the data usage conditions formulated by the provider, and for the data transaction to be made when the data user agrees to the data usage conditions. And making the data usage conditions dynamic is considered to increase flexibility, enabling the data user to obtain data that meets their own requirements and enabling the data provider to provide data to more users.
[0004] Negotiation is a method for dynamically determining data usage conditions in data transactions, and methods for automatically negotiating have also been proposed. For example, Non-Patent Document 1 discloses that a mediator presents candidates for conditions for negotiation regarding usage conditions in data circulation, assuming that socially useful automatic negotiation can be achieved through the intervention of a third-party agent (mediator).
Prior Art Documents
Non-Patent Documents
[0005]
Non-Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0006] However, in the prior art including the above-mentioned Non-Patent Document 1, even if the data usage conditions can be adjusted through automatic negotiation, it is not known whether the other party will actually comply with the usage conditions. Therefore, it is assumed that it is difficult to achieve a secure and safe data transaction. Accordingly, it is required to be able to determine the optimal data usage conditions among data traders in consideration of whether the other party will comply with the data usage conditions.
[0007] The present invention has been made in consideration of the above points, and when dynamically agreeing on data usage conditions, enables a data trader to select and determine suitable usage conditions in consideration of the possibility of compliance with the usage conditions by the trading partner, thereby proposing a data circulation system and a data usage condition determination method capable of enhancing security and safety in data transactions.
Means for Solving the Problems
[0008] In order to solve such problems, in the present invention, there is provided a data circulation system for dynamically negotiating data transaction usage conditions, comprising: one or more provider devices used by a data provider who is one of the data traders; one or more user devices used by a data user who is the other of the data traders; and a negotiation mediation service unit that mediates the negotiation of the usage conditions. The provider device and the user device each hold preference information indicating matters adjustable in the usage conditions that are acceptable to the data provider or the data user. When a data transaction is carried out between predetermined data traders, the negotiation mediation service unit Based on the preference information of each of the data traders in the data transaction targeted by the usage conditions For each of a plurality of usage conditions that can be implemented between the data traders extract, and the plurality of usage conditions extracted Calculates an index of feasibility representing the possibility that the data trader will perform the usage condition For each item constituting the usage condition First process, along with calculating utility values indicating the utilities that the data provider and the data user can respectively obtain when using the usage condition AndCalculated for each of the usage conditions by the first process the index of feasibility and the utility values Based on this, a second process is performed, which extracts a predetermined number of usage condition candidates from the plurality of usage conditions and notifies the provider device and the user device of the usage condition candidates. A data distribution system is provided that executes this process.
[0009] Further, in order to solve such problems, in the present invention, there is provided a method for determining data usage conditions by a data distribution system that dynamically negotiates data usage conditions for data transactions. The data distribution system includes one or more provider devices used by a data provider who is one of the data traders, one or more user devices used by a data user who is the other data trader, and a negotiation mediation service unit that mediates the negotiation of the usage conditions. The provider device and the user device each hold preference information indicating matters adjustable in the usage conditions that are acceptable to the data provider or the data user. When a data transaction is performed between predetermined data traders, the negotiation mediation service unit Based on the preference information of each of the data traders in the data transaction targeted by the usage conditions For each of the plurality of usage conditions that can be implemented between the data traders extract, and the plurality of usage conditions extracted calculate an index of feasibility that represents the likelihood that the data trader can comply with the usage condition For each item constituting the usage condition step; the negotiation mediation service unit along with calculating utility values indicating the utilities that the data provider and the data user can respectively obtain when using the usage condition, a first Based on the index of feasibility, extract a predetermined number of usage condition candidates from the plurality of usage conditions, notify the provider device and the user device of the usage condition candidates, and request evaluation by both of the data traders Calculated for each of the usage conditions in the first step step; the negotiation mediation service unit and the utility values Based on the results of the evaluation by both of the data traders, determine the final usage conditions in the data transaction, and notify the provider device and the user device A second step; A method for determining data usage conditions is provided that includes these steps. Requested in the second step step; A method for determining data usage conditions is provided that includes these steps. A third step; A method for determining data usage conditions is provided that includes these steps.
Advantages of the Invention
[0010] According to the present invention, it is possible to enhance the security and safety in data transactions where the usage conditions of data are dynamically agreed upon. In addition, problems, configurations, and effects other than those described above will be clarified by the description of the following embodiments.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Modes for Carrying Out the Invention
[0012] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.
[0013] In the following description, various information may be described using expressions such as "table", "sheet", "list", etc., but the various information may be expressed in other data structures. In order to indicate that it does not depend on the data structure, "XX table", "XX list", etc. may be referred to as "XX information". When explaining the content of each information, expressions such as "identification information", "identifier", "name", "ID", "number", etc. are used, but these can be replaced with each other.
[0014] In the following description, there may be cases where the processing performed by executing a program is described. However, the program is executed by at least one processor (e.g., CPU), and in order to perform the defined processing while appropriately using a storage resource (e.g., memory) and / or an interface device (e.g., communication port), etc., the subject of the processing may be the processor. Similarly, the subject of the processing performed by executing the program may be a controller, device, system, computer, node, storage system, storage device, server, management computer, client, or host having a processor. The subject of the processing performed by executing the program (e.g., processor) may include a hardware circuit that performs part or all of the processing. For example, the subject of the processing performed by executing the program may include a hardware circuit that performs encryption and decryption, or compression and decompression. The processor operates as a functional unit that realizes a predetermined function by operating according to the program. The device and system including the processor are devices and systems including these functional units.
[0015] The program may be installed from a program source into a device such as a computer. The program source may be, for example, a program distribution server or a computer-readable storage medium. When the program source is a program distribution server, the program distribution server includes a processor (e.g., CPU) and a storage resource, and the storage resource may further store a distribution program and the program to be distributed. Then, by the processor of the program distribution server executing the distribution program, the processor of the program distribution server may distribute the program to be distributed to other computers. Also, in the following description, two or more programs may be realized as one program, or one program may be realized as two or more programs.
[0016] In the following description, when describing elements of the same type without distinction, the common part of the reference signs including subscripts and branch numbers (excluding subscripts and branch numbers) is used, and when describing elements of the same type separately, reference signs including subscripts and branch numbers may be used. For example, when describing the provider device without particular distinction, it is described as "provider device 10", whereas when describing individual provider devices 10 separately, it is described as "provider device 10-1", "provider device 10-2", ···, "provider device 10-N".
[0017] (1) First Embodiment (1-1) Configuration of Data Circulation System 1 FIG. 1 is a block diagram showing a configuration example of a data circulation system 1 according to the first embodiment of the present invention.
[0018] As shown in FIG. 1, the data circulation system 1 includes one or more provider devices 10 which are information processing devices used by data providers, one or more user devices 20 which are information processing devices used by data users, a catalog management service device 30 that centrally manages data catalogs, a negotiation mediation service device 40 that mediates negotiation of data usage conditions (data usage conditions) between data providers and data users, a management terminal 51 that manages the provider device 10 via a network, and a management terminal 52 that manages the user device 20 via a network. The provider device 10, the user device 20, the catalog management service device 30, and the negotiation mediation service device 40 are interconnected via a network 60. Also, the provider device 10 and the management terminal 51 are connected via a network 61, and the user device 20 and the management terminal 52 are connected via a network 62.
[0019] Note that in the following description, "data provider" and "provider device 10" are mutually interchangeable when used from the perspective of the side providing data. Similarly, "data user" and "user device 20" are mutually interchangeable when used from the perspective of the side to which data is provided (the side using the data).
[0020] (1-1-1) Provider device 10 The provider device 10 is configured to include a business system 110 and a data transaction connector 120.
[0021] The business system 110 is a system that the organization of the data provider processes in its business, and processes customer data and other data necessary for the business. Also, the business system 110 has a function of storing (accumulating) the data processed in its own system as a data source. In the data transaction by the data distribution system 1 of the present embodiment, among the data sources stored in the business system 110, the data made available to the data user is provided to the user device 20 via the data transaction connector 120.
[0022] The data transaction connector 120 is a processing unit through which data stored in the business system 110 is provided to the data user, and has a function of processing data (processing the data to be available according to the data usage conditions) so as to conform to predetermined data usage conditions and controlling the data destination. The data transaction connector 120 is configured to include a usage condition management unit 121 and a usage control unit 122.
[0023] The usage condition management unit 121 is a processing unit that manages the data usage conditions applicable to the data to be provided, and determines the data usage conditions that can be agreed upon between the trading partners through interaction with the negotiation mediation service device 40.
[0024] The usage control unit 122 is a processing unit that provides data in a form that conforms to the data usage conditions determined by the usage condition management unit 121. The usage control unit 122 interacts with the data transaction connector 220 of the user device 20 regarding the data acquired from the business system 110, provides the data in accordance with the data usage conditions, and transmits and receives control information regarding the data provision.
[0025] (1-1-2) User device 20 The user device 20 is configured to include a business system 210 and a data transaction connector 220.
[0026] The business system 210 is a system that the organization of data users processes in their business, and it processes the data necessary for the business obtained by the organization and the data obtained from data providers. Also, the business system 210 has a function as a data sink, that is, it also has a function of storing (accumulating) the data necessary for the business obtained by the organization and the data obtained from data providers. In the data transaction by the data circulation system 1 of the present embodiment, the data obtained from the data provider is stored (accumulated) in the business system 210 via the data transaction connector 220 and is used in the business in the organization of the data user.
[0027] The data transaction connector 220 is a processing unit through which the data obtained from the data provider is accumulated in the business system 210, and it has functions of processing the data so as to conform to predetermined data usage conditions and managing the above data usage conditions. Similar to the data transaction connector 120, the data transaction connector 220 is configured to include a usage condition management unit 221 and a usage control unit 222.
[0028] The usage condition management unit 221 is a processing unit that manages the data usage conditions applied to each data used by the data user, and determines the data usage conditions that can be agreed upon between trading partners through interactions with the negotiation mediation service device 40.
[0029] The usage control unit 222 is a processing unit that uses the data in a form that conforms to the data usage conditions determined by the usage condition management unit 221. For the data received from the provider device 10, the usage control unit 222 interacts with the data transaction connector 120 of the provider device 10 to process the data according to the data usage conditions (for example, deleting the data after a certain period of time, allowing acquisition within a certain number of times, etc.) and to transmit and receive control information related to data usage.
[0030] (1-1-3) Catalog management service device 30 The catalog management service device 30 has functions of collecting, holding, and managing the metadata of the data to be traded, the metadata related to the connectors (data trading connectors 120 and 220), and the metadata of the organizations that trade the data, and further has a function of replying with the corresponding metadata to requests for acquisition of these metadata.
[0031] The above-mentioned metadata of the data includes the title and description of the data, the specifications of the data, the location of the data, and the default usage conditions. In addition, the metadata of the connectors includes information related to the overall connector functions, such as the connector transaction history like the history of data transactions via the connectors, the ID and version of the connectors, and the list of functions that the connectors have. Also, the metadata of the organizations includes information such as the ID, name, and description of the organizations, as well as the history data of data transactions conducted by the organizations and the creditworthiness related to the data transactions of the organizations.
[0032] As shown in FIG. 1, the catalog management service device 30 is configured to include a connector transaction history management unit 310, a connector function management unit 320, an organization transaction history management unit 330, an organization creditworthiness management unit 340, and a usage condition management unit 350.
[0033] The connector transaction history management unit 310 collects and holds the history of data transactions via the connectors from the connectors. Here, the history of data transactions manages, as a log, the history of the date and time when the transaction was conducted, the ID of the data provider, the ID of the data user, the ID of the data, and the content of the transaction (for example, data transmission, data processing, or execution of a predetermined process defined in the data usage conditions). Also, the connector transaction history management unit 310 returns the corresponding metadata to requests for acquisition targeting the metadata it holds.
[0034] The connector function management unit 320 collects and holds information on connector functions, such as the ID and version of the connectors and the list of functions that the connectors have. Also, the connector function management unit 320 returns the corresponding metadata to requests for acquisition targeting the metadata it holds.
[0035] The Organization Transaction History Management Department 330 collects and retains information on the history data of data transactions implemented by the organization. Also, in response to an acquisition request targeting the metadata held by itself, the Organization Transaction History Management Department 330 returns the corresponding metadata. Note that although the functions and the data handled by the Organization Transaction History Management Department 330 and the Connector Transaction History Management Department 310 partially overlap, the Connector Transaction History Management Department 310 manages the history data of data transactions via the connector in terms of each connector, while the Organization Transaction History Management Department 330 manages the history data of data transactions via all the connectors owned by the organization in terms of the organization.
[0036] The Organization Creditworthiness Management Department 340 retains information on the creditworthiness regarding the organization's data transactions. The "creditworthiness" mentioned here is an index obtained by quantifying the degree to which the agreed data usage conditions are likely to be complied with. The creditworthiness regarding the organization's data transactions is calculated by a person or a program based on a plurality of past transaction data implemented through the mediation of the data circulation system 1. Specifically, for example, based on whether there is a certain amount of data transaction performance, the number of violations of the agreed data usage conditions, whether there has been an information security incident (such as information leakage of personal data) in the information system (business system 210) of the corresponding organization, etc., the creditworthiness regarding the organization's data transactions is calculated and determined. When calculating the above creditworthiness by a program, for example, the Organization Creditworthiness Management Department 340 executes the program. Based on the above, the data structure of the information held by the Organization Creditworthiness Management Department 340 includes the organization's ID and a numerical value representing the organization's creditworthiness.
[0037] The Usage Condition Management Department 350 acquires and manages the default values of usage conditions in data transactions (the values of initial conditions applied when no negotiation is conducted) and information regarding whether each item of the usage conditions can be adjusted. The Usage Condition Management Department 350 registers these values for each data provider or for each piece of available data. Below, taking the case of registering for each piece of available data as an example, a data structure example of the information (usage condition management table) held by the Usage Condition Management Department 350 will be described.
[0038] FIG. 2 is a diagram showing an example of a usage condition management table. The usage condition management table 710 illustrated in FIG. 2 is information acquired and managed by the usage condition management unit 350 as described above.
[0039] The usage condition management table 710 includes a data ID 711 indicating the ID of transaction data, a usage condition item 712 indicating the name of each item constituting the data usage condition, a default value 713 indicating the default value of the usage condition item 712, and an adjustable flag 714 indicating whether the value of the usage condition item 712 can be adjusted through negotiation.
[0040] Examples of the usage condition item 712 include whether to use a connector when providing data (connector usage), whether there are restrictions on the usage purpose (restriction on usage purpose), whether there are restrictions on the usage location (restriction on usage location), and the like. Also, in the example of FIG. 2, when the value of the target item can be adjusted through negotiation, the adjustable flag 714 is represented as "adjustable", and when the value of the target item cannot be adjusted through negotiation, the adjustable flag 714 is represented as "non-adjustable".
[0041] Such a usage condition management table 710 is used, for example, by an administrator of a data user to view the usage conditions of data that is a transaction candidate, to confirm whether the usage conditions can be accepted with the default values, whether the usage condition items that cannot be accepted are adjustable items, and to comprehensively determine whether to conduct negotiations on the usage conditions. Also, although it is assumed that the above determination is usually made by a person, it may be configured to be automatically determined by a program based on predetermined determination criteria.
[0042] (1-1-4) Negotiation Mediation Service Device 40 The negotiation mediation service device 40 is a device that mediates between a data provider and a data user without directly negotiating data usage conditions, and presents data usage conditions that are Win-Win for both parties (that is, beneficial for both parties). As shown in FIG. 1, the negotiation mediation service device 40 includes a utility function management unit 410, a usage condition feasibility management unit 420, and a usage condition candidate recommendation unit 430.
[0043] The utility function management unit 410 manages what utility values each data trader (data provider and data user) obtains when using data usage conditions. Here, the utility function is a quantification of the utility (benefit) obtained by the data trader when the values of each item of the data usage conditions are given. As a method for calculating the utility, a numerical value (the total is 1) that serves as a weight is given to each data usage condition, and when the utility score for each individual item of the data usage condition is set to 0 to 1 (for example, it means that a larger value is more beneficial), the sum of the products of the weight and the utility value of each individual item is taken. This utility function may be determined by the users of the organization that becomes the data trader, or several questions may be asked of the user (or organization) regarding the data usage conditions, and the utility function may be automatically estimated and determined from the results.
[0044] The usage condition feasibility management unit 420 numerically manages, for each data trader, how high the feasibility is or how high the risk of non - fulfillment is for each item of the data usage condition and its value. This numerical value is calculated, for example, based on the function of the connector. If there is a function of the connector corresponding to each item of the data usage condition, it is determined that the feasibility is high (the risk of non - fulfillment is low), and if there is no corresponding connector function, it is determined that the feasibility is low (the risk of non - fulfillment is high). Also, it may be calculated based not only on the function of the connector but also on the transaction history of the corresponding organization and the creditworthiness of the organization.
[0045] The conditional candidate recommendation unit 430 outputs a predetermined number (one or a predefined number) of candidates for data usage conditions suitable for both data traders based on the utility functions of the data provider and the data user and the feasibility of fulfilling the data usage conditions, and notifies these candidates via the connectors of the data provider and the data user.
[0046] The management terminals 51 and 52 are information processing devices mainly used to set connectors for the information processing devices (provider device 10, user device 20) of the data providers and data users to which they are connected, provide information to users along with the agreement on data usage conditions, and have the users judge data usage conditions, etc. That is, the management terminals 51 and 52 have the function of exchanging messages with the connectors of the provider device 10 or the user device 20 to which they are connected.
[0047] With the data circulation system 1 according to this embodiment having the configuration described above, the provider device 10 can determine optimal data usage conditions with the user device 20 via the negotiation mediation service device 40. Also, since the negotiation mediation service device 40 calculates candidates for data usage conditions considering the feasibility of the data provider and the data user, the data provider and the data user can select and agree on more appropriate data usage conditions considering the feasibility of the data usage conditions of the trading partner.
[0048] In the above description, the data catalog is centrally managed by the catalog management service device 30, but in the data circulation system 1 according to this embodiment, these data catalogs may be managed in a distributed manner. Also, although described separately for the provider device 10 and the user device 20, a person (user) or an organization may serve as both the data provider and the data user, and in that case, the provider device 10 and the user device 20 may be the same.
[0049] (1-2) Data Usage Condition Agreement Sequence FIG. 3 is a sequence diagram showing an example of a procedure for reaching an agreement on data usage conditions executed in the data circulation system 1 in the first embodiment. Hereinafter, with reference to FIG. 3, the sequence of reaching an agreement on data usage conditions in this embodiment will be described.
[0050] In the description of FIG. 3, the procedures performed by the data provider or its organization actually mean that the provider device 10 takes the lead in performing the processing corresponding to the procedures, and the procedures performed by the data user or its organization actually mean that the user device 20 takes the lead in performing the processing corresponding to the procedures. This is the same in the description of other sequence diagrams (FIG. 8) and flowcharts (FIGS. 4 and 6) described later.
[0051] According to FIG. 3, first, the organization of the data user sends a request to the catalog management service device 30 to obtain the data usage conditions of the business partner (step S101). In response to the request in step S101, the catalog management service device 30 returns the corresponding business partner and data usage conditions to the data user (step S102).
[0052] Next, if the data user examines the data usage conditions obtained in step S102 and determines that it cannot reach an agreement under those data usage conditions and wants to conduct transactions under different conditions, the data user sends a request to adjust the data usage conditions to the negotiation mediation service device 40 (step S103). This adjustment request includes information such as a business partner ID that can uniquely identify the business partner (for example, the business partner of the data usage conditions obtained in step S102).
[0053] When the negotiation and mediation service device 40 receives a request for adjusting data usage conditions, based on the trading partner ID included in the adjustment request, it sends a request to the data provider, who is the corresponding data trader, to obtain the preferences for data usage conditions (step S104), and obtains this (step S105). Here, the preferences for data usage conditions are information indicating which items among the multiple items constituting the data usage conditions are adjustable, which items have a higher priority among the multiple items, etc., and represent information regarding utility functions and information such as acceptable feasibility. These preference information are necessary information for the data trader to derive candidates for win-win data usage conditions, and are determined in advance by the data provider and the data user and are held and managed in each connector.
[0054] Also, the negotiation and mediation service device 40 similarly sends a request to obtain the preferences for data usage conditions to the data user who sent the request for adjusting data usage conditions in step S103 (step S106), and obtains this (step S107).
[0055] Next, the negotiation and mediation service device 40 requests the catalog management service device 30 to obtain the functions of the connectors in the data user and the data provider (step S108). In response to this request, the catalog management service device 30 obtains the function list information of the corresponding connectors from the database held by the connector function management unit 320 and passes this information to the negotiation and mediation service device 40 (step S109).
[0056] Next, the negotiation and mediation service device 40 requests the catalog management service device 30 to obtain the creditworthiness of the organizations in the data user and the data provider (step S110). In response to this request, the catalog management service device 30 obtains the creditworthiness values of the corresponding organizations from the database held by the organization creditworthiness management unit 340 and passes these to the negotiation and mediation service device 40 (step S111).
[0057] Next, the negotiation mediation service device 40 extracts all combinations that can constitute data usage conditions, and calculates the utility value and the feasibility risk for each of these data usage conditions (step S112). Details of the process in step S112 will be described later with reference to FIG. 4.
[0058] Next, based on the utility value and the feasibility risk calculated in step S112, the negotiation mediation service device 40 extracts the top N candidates considering the risk from among the plurality of data usage conditions extracted in step S112, and sets this as the candidate usage conditions for recommendation (step S113). Details of the extraction process of the candidate usage conditions in step S113 will be described later with reference to FIG. 6.
[0059] Next, the negotiation mediation service device 40 presents the candidate usage conditions determined in step S113 and their feasibility risks to the data provider and the data user, and further requests the data provider and the data user to evaluate each candidate usage condition (steps S114, S115).
[0060] Then, in response to the requests in steps S114 and S115, the data provider and the data user transmit the evaluation results for each candidate usage condition to the negotiation mediation service device 40 (steps S116, S117).
[0061] Next, based on the evaluation results from both the data provider and the data user obtained in steps S116 and S117 (specifically, for example, OK / NG, a score representing the level of evaluation), the negotiation mediation service device 40 determines the data usage conditions that can be agreed upon by both the data provider and the data user (step S118), and notifies the determined data usage conditions to the data provider and the data user (steps S119, S120). Here, for the determination of the data usage conditions that can be agreed upon, for example, those with OK evaluation results from both parties are extracted, and from among them, those with the maximum product of the evaluation scores of both parties are extracted. If there are multiple candidate usage conditions with the maximum product of the evaluation scores, those with a larger product of the utilities may be extracted.
[0062] Through the above processing, the negotiation mediation service device 40 can recommend candidate usage conditions that result in a win-win situation, taking into account the risk of feasibility of data usage conditions. Also, the data provider and the data user can each evaluate from the recommended candidate usage conditions, taking into account the feasibility risk, and based on the evaluation results, the final data usage conditions are determined, enabling an agreement on data usage conditions that take into account the feasibility risk.
[0063] (1-2-1) Calculation of Feasibility Risk FIG. 4 is a flowchart showing an example of a processing procedure for calculating the feasibility risk. The series of processes shown in FIG. 4 corresponds to the processes of steps S104 to S113 in FIG. 3 and is executed by the negotiation mediation service device 40 when a request for adjustment of data usage conditions is received from a data trader (step S103 in FIG. 3). However, the details of the process in step S206 (corresponding to step S113 in FIG. 3) will be described later with reference to FIG. 6.
[0064] According to FIG. 4, first, the negotiation mediation service device 40 acquires the preferences of the data usage conditions of the relevant data traders (provider device 10, user device 20) (step S201). As described above, the preference of the data usage conditions is information indicating which items among the plurality of items constituting the data usage conditions are adjustable, which item has a higher priority among the plurality of items, etc., and represents information regarding the utility function and information such as acceptable feasibility. These preference information is information necessary for the data trader to derive candidate data usage conditions that result in a win-win situation, and is determined in advance by the data provider and the data user and is held and managed in each connector.
[0065] Next, the negotiation mediation service device 40 acquires information on the functions of the connector and the usage environment of the data trader connected to the connector from the catalog management service device 30 (step S202). Note that regarding the functions of the connector, it is assumed that the correctness of the information is verified by someone other than the data trader, rather than simply accepting the functions declared by the data trader as they are.
[0066] FIG. 5 is a diagram showing an example of a capability management table for usage control. The capability management table 720 for usage control shown in FIG. 5 is a list of information used when the negotiation mediation service device 40 acquires the information on the functions of the connector and the usage environment described above. For example, it is stored in a database held by the connector function management unit 320 of the catalog management service device 30 (it may be held outside the catalog management service device 30).
[0067] As shown in FIG. 5, the capability management table 720 for usage control is configured to have items of a connector ID 721, an item 722, a corresponding level 723, a corresponding location 724, and the presence or absence of related log output 725.
[0068] The connector ID 721 is an identifier for uniquely identifying the connector. The item 722 indicates the name of each item of the data usage conditions provided by the connector. The corresponding level 723 indicates the value corresponding to each item. The corresponding location 724 indicates information on where the usage control of each item is implemented, and is indicated by a value such as "connector" or "usage environment". The presence or absence of related log output 725 indicates whether the corresponding function is output as a related log.
[0069] By using such a capability management table 720, the negotiation mediation service device 40 can collect information on the connector and the usage environment necessary for calculating the feasibility.
[0070] Return to the description of FIG. 4. Next, following step S202, the negotiation mediation service device 40 acquires the creditworthiness of the organization from the catalog management service device 30 (step S203). Here, it is assumed that the catalog management service device 30 holds and manages this information, but if the same information can be obtained from another institution or the like, it may be obtained from others.
[0071] Next, the negotiation mediation service device 40 extracts all combinations of data usage conditions that can be obtained between the data provider and the data user (step S204). The process of step S204 means extracting a plurality of data usage conditions corresponding to all combination patterns by combining the selectable values for each item constituting the data usage conditions.
[0072] Next, for each data usage condition extracted in step S204, the negotiation mediation service device 40 calculates the feasibility risk based on the individual items and values (step S205). The individual feasibility is comprehensively determined based on, for example, the presence or absence of the connector function, the presence or absence of past transaction records in the organization, and the creditworthiness of the organization. Specifically, for example, when there is a connector function, its execution is technically forced, so the feasibility is extremely high, and the risk that the data usage condition will not be executed is extremely low (risk level: None). Also, even when there is no connector function, if it has been appropriately processed in the past transaction records, the feasibility is considered high and the risk is low (risk level: Low). Also, when there is neither a connector function nor past transaction records, it can be determined based on the creditworthiness of the organization. If the creditworthiness of the organization is high, the possibility of execution in each data usage condition is considered high and the risk is low (risk level: Low), but when the creditworthiness of the organization is low, the feasibility is low and the risk can be determined to be high (risk level: High). Note that the degrees of "high" or "low" in the above description may be considered to be classified based on a predetermined threshold value, and each threshold value may be statically determined in advance, or may be dynamically set by a program or a person according to the situation, environment, etc.
[0073] Then, when individual risks for each data usage condition are calculated in step S205, finally, the negotiation mediation service device 40 calculates candidates for more preferable data usage conditions in consideration of both utility and risk (step S206). Details of the process in step S206 will be described later with reference to FIG. 6.
[0074] By performing the processing as described above, the negotiation mediation service device 40 can calculate the individual feasibility risks of the data usage conditions and extract candidates for more appropriate data usage conditions based on the calculated risks.
[0075] (1-2-2) Extraction of Usage Condition Candidates FIG. 6 is a flowchart showing an example of the processing procedure for extracting usage condition candidates. The series of processes shown in FIG. 6 corresponds to the process of step S113 in FIG. 3 and is executed by the negotiation mediation service device 40 after the calculation of the feasibility risk is completed.
[0076] According to FIG. 6, first, the negotiation mediation service device 40 derives all possible combinations of data usage conditions by combining the data usage conditions from the preferences of the data provider and the data user (step S301). In the process of step S301, for example, when there is little restriction on the processing time, the utility and risk are calculated for all combinations, and a more preferable part is selected based on the calculated values. Note that when there is a restriction on the processing time or when the number of combinations of usage conditions becomes extremely large, it is not possible (or not necessary) to calculate for all combinations. Therefore, if necessary, the number of combinations to be derived may be limited, and combinations of data usage conditions may be randomly extracted.
[0077] Next, the negotiation mediation service device 40 calculates the utility value and risk in each combination for the combinations of data usage conditions derived in step S502 (step S302). The specific method for calculating the risk is as described in step S205 of FIG. 4.
[0078] Next, the negotiation mediation service device 40 calculates the risk-adjusted utility for each combination (step S303). Specifically, for example, the calculation formula of "Σ{(utility value under condition i) × (1 - (risk probability under condition i))}" can be used as the calculation method in step S303.
[0079] Next, the negotiation mediation service device 40 calculates the product of the adjusted utility of the data provider and the adjusted utility of the data user for each combination (step S304).
[0080] Next, the negotiation mediation service device 40 rearranges the combinations in descending order of the product calculated in step S304, extracts the top N candidates, and uses this as the candidate usage conditions for recommendation (step S305). Here, a high product means a high profit (utility) when considering both data traders.
[0081] By performing the processing as described above, the negotiation mediation service device 40 can extract the data usage conditions near the Nash equilibrium point as candidate usage conditions, and thus can calculate more preferable candidates for both the data provider and the data user.
[0082] Then, the negotiation mediation service device 40 presents the extracted candidate usage conditions and the feasibility of each usage condition to the data traders (provider device 10, user device 20).
[0083] FIG. 7 is a diagram showing an example of a candidate recommendation message. The candidate recommendation message 730 shown in FIG. 7 is an example of a message for the negotiation mediation service device 40 to present the candidate usage conditions and their feasibility risks to the data traders (provider device 10, user device 20) in steps S114 and S115 of FIG. 3 after calculating the candidate usage conditions described in FIG. 6.
[0084] As shown in FIG. 7, the candidate recommendation message 730 is composed of items of a candidate number 731, an item 732, a value 733, an execution responsibility 734, a risk level 735, a risk reason 736, and a utility function score 737.
[0085] The candidate number 731 indicates an identifier assigned to each usage condition candidate. The item 732 indicates the name of each item constituting the usage condition of the candidate, and the value 733 indicates its value. The name shown in the item 732 represents, for example, whether the usage purpose is restricted (restriction of usage purpose), whether the usage location is restricted (restriction of usage location), and the like.
[0086] The execution responsibility 734 indicates the location of the person responsible for execution in each item, and the organization that should execute the item is described. The risk level 735 indicates a value representing the execution possibility risk of each item. The risk level 735 may be represented by a numerical value or may use enumerated values. In the case of FIG. 7, the example of the risk level described in the explanation of step S205 in FIG. 3 is applied. The risk reason 736 indicates the reason for determining the risk level. For example, when it is described as "No related function implemented In A. Trust level of organization A is low", it means that "no related function is implemented in organization A and the credibility of organization A is low".
[0087] The utility function score 737 indicates the score of the utility function of the entire data usage condition for each candidate. Specifically, in the utility function score 737, a value with a range is described in consideration of the risk (risk level 735) in each item of the data usage condition of the candidate. In this example, it is assumed that a value from 0 to 1 is described, but it is not limited thereto.
[0088] As described above, according to the data circulation system 1 according to the present embodiment, in the dynamic agreement on data usage conditions, an index indicating the degree to which a trading partner complies with each item of the data usage conditions is calculated, and the data trader can simplify the consent by confirming the data provision content when providing personal data to a large number of data providers in consideration of this. As a result, the organization trading data can select and determine a more optimal data usage condition in consideration of the possibility that the trading partner complies with the data usage condition, and can enhance the security and safety in the data transaction for dynamically agreeing on the data usage condition.
[0089] (2) Second Embodiment In the data circulation system 1 according to the first embodiment, when determining the data usage condition, the negotiation mediation service device 40 recommends candidates for usage conditions that are likely to lead to an agreement for both data traders in consideration of utility and feasibility, and the catalog management service device 30 and the negotiation mediation service device 40 are required. However, the present invention is not limited to a configuration including an intermediary device such as the catalog management service device 30 and the negotiation mediation service device 40, and it is also possible to implement it by having some functions of the intermediary device in the data provider (provider device 10) and the data user (user device 20).
[0090] Therefore, in the second embodiment, a data circulation system 2 will be described centering on the differences from the first embodiment, in which data traders (provider device 10, user device 20) calculate the feasibility by themselves by grasping the function of the connector of the information processing device that will be the trading partner or inquiring about past performance, and conduct negotiations on data usage conditions among the traders based on the calculation results.
[0091] The data circulation system 2 according to the second embodiment is different from the configuration of the data circulation system 1 shown in FIG. 1 in that it does not include the negotiation mediation service device 40, and the functions of the negotiation mediation service device 40 are arranged in the provider device 10 and the user device 20. And the data circulation system 2 according to the second embodiment is different from the data usage condition agreement sequence in the first embodiment in that the data provider and the data user directly negotiate about the data usage condition agreement sequence.
[0092] FIG. 8 is a sequence diagram showing an example of the procedure for reaching an agreement on data usage conditions executed in the data circulation system 1 in the second embodiment. Hereinafter, the procedure shown in FIG. 8 will be described. However, since the detailed technical content implemented in each procedure can basically be applied by referring to FIG. 3 in the first embodiment, the description will be omitted.
[0093] According to FIG. 8, first, the data user makes a request to obtain the data usage conditions of the business partner (data provider) (step S401) and receives the response (step S402). Next, when the data user examines the data usage conditions obtained in step S402 and determines that it cannot agree to the data usage conditions and wants to conduct a transaction under different conditions, the data user directly sends a request to adjust the data usage conditions to the data provider (step S403).
[0094] Next, when the data provider receives the request to adjust the data usage conditions, the data provider sends a request to obtain the preference of the data usage conditions to the data provider (step S404) and obtains the preference information from the data provider (step S405). Here, since the data provider itself holds the preference information on the data provider side, the request to obtain the preference is unnecessary.
[0095] Also, the data provider requests the catalog management service device 30 to obtain the functions of the connectors of the data user (step S406) and receives this from the catalog management service device 30 (step S407). On the other hand, similarly, the data user requests the catalog management service device 30 to obtain the functions of the connectors of the data provider (step S408) and receives this from the catalog management service device 30 (step S409).
[0096] Also, the data provider requests the catalog management service device 30 to obtain the creditworthiness of the organization of the data user (step S410) and receives this from the catalog management service device 30 (step S411). On the other hand, similarly, the data user requests the catalog management service device 30 to obtain the creditworthiness of the organization of the data provider (step S412) and receives this from the catalog management service device 30 (step S413).
[0097] Next, the data provider extracts all combinations that can be data usage conditions, and calculates the utility value and the feasibility risk for each combination of data usage conditions (step S414). Further, based on the calculated utility value and feasibility risk, the data provider extracts the top N candidates considering the risk from among the data usage conditions extracted in step S414, and sets this as the candidate usage conditions for recommendation (step S415). Then, the data provider presents the candidate usage conditions determined in step S415 and its feasibility risk to the data user (step S417).
[0098] The data user to whom the usage condition candidates were presented in step S417 evaluates each usage condition candidate, and uses the evaluation results to determine the acceptable data usage conditions by a predetermined decision method (step S418). The evaluation results are indicated, for example, by OK / NG and scores representing the level of evaluation. The determination of acceptable data usage conditions is, for example, to extract those for which the evaluation results of both data traders are OK, and from among them, extract the one with the maximum product of their evaluation scores. If there are multiple usage condition candidates with the maximum product of evaluation scores, the one with the larger product of utilities may be extracted. Then, the data user notifies the data provider of the acceptable data usage conditions determined in step S418 (step S419).
[0099] Note that in this example, the data user determines the acceptable data usage conditions based on the presentation of usage condition candidates from the data provider, but it is not limited to such a procedure. For example, the data traders may exchange their respective evaluation results for each usage condition candidate, use each other's evaluation results to determine and present the final usage condition candidate, and if both parties agree to this, it may be determined as the acceptable data usage condition, etc.
[0100] Finally, the data provider and the data user digitally sign the data usage conditions with respect to each other in order to prove that they have agreed to the finally selected data usage conditions (step S420), and end the process. By performing digital signature, it can be expected to have the effect of preventing tampering with the agreed data usage conditions.
[0101] The processing procedure shown in FIG. 8 above can be said to be significantly different from the processing procedure shown in FIG. 3 of the first embodiment in the following respects. That is, in the processing procedure of FIG. 8, the data trader collects the information necessary to calculate the feasibility risk by himself / herself by implementing a preference acquisition request for data usage conditions (step S404), a connector function acquisition request (steps S406, S408), and an organization's creditworthiness acquisition request (steps S410, S412). Also, the feasibility risk is calculated independently by the data trader (not by the negotiation mediation service device 40).
[0102] By performing the processing shown in FIG. 8 as described above, in the data circulation system 2 according to the second embodiment, without using the negotiation mediation service, the data usage conditions are adjusted between the data traders considering the feasibility risk, and it becomes possible to reach an agreement on the data usage conditions that are Win-Win for both data traders.
[0103] Note that each of the above-described embodiments has been described in detail for the purpose of clearly explaining the present invention, and is not necessarily limited to those having all the configurations described. Also, a part of the configuration of one embodiment can be replaced with the configuration of another embodiment, and the configuration of another embodiment can also be added to the configuration of one embodiment. Further, for a part of the configuration of each embodiment, it is possible to add, delete, or replace other configurations.
[0104] Also, in each of the above-described embodiments, it is assumed that the processing is performed by a single catalog management service device 30 or negotiation mediation service device 40, but the processing may be distributed among a plurality of devices. Also, each function of the device may be executed on a separate machine.
[0105] Also, the control lines and information lines show those considered necessary for explanation, and not necessarily all the control lines and information lines on the product. In reality, it may be considered that almost all the components are interconnected.
Explanation of Reference Numerals
[0106] 1,2 Data circulation system 10 Provider device 110 Business system 120 Data transaction connector 121 Usage condition management department 122 Usage control department 20 User device 210 Business system 220 Data transaction connector 221 Usage condition management department 222 Usage control department 30 Catalog management service device 310 Connector transaction history management department 320 Connector function management department 330 Organization transaction history management department 340 Organization credit management department 350 Usage condition management department 40 Negotiation mediation service device 410 Utility function management department 420 Usage condition feasibility management department 430 Usage condition candidate recommendation department 51,52 Management terminal 60,61,62 Network 710 Usage condition management table 720 Capability management table 730 Candidate recommendation message
Claims
1. A data circulation system that dynamically negotiates the usage conditions of data transactions, comprising: One or more provider devices used by a data provider, who is one of the data transaction parties; One or more user devices used by a data user, who is the other data transaction party; A negotiation mediation service unit that mediates the negotiation of the usage conditions; The provider device and the user device each hold preference information indicating adjustable items in the usage conditions that are acceptable to the data provider or the data user. When a data transaction is conducted between predetermined data transaction parties, the negotiation mediation service unit: Extracts a plurality of usage conditions that can be implemented among the data transaction parties based on the preference information of each of the data transaction parties regarding the data transaction for which the usage conditions are applicable. For each usage condition among the extracted plurality of usage conditions, calculates an index of feasibility indicating the likelihood that the data transaction party will fulfill the usage condition for each item constituting the usage condition, and calculates a utility value indicating the utility that the data provider and the data user will each obtain when the usage condition is used (first process); Based on the index of feasibility and the utility value calculated for each usage condition in the first process, extracts a predetermined number of usage condition candidates from the plurality of usage conditions, and notifies the provider device and the user device of the usage condition candidates (second process). A data circulation system characterized by the above.
2. The provider device and the user device conduct data transmission, reception, and transactions via connectors provided therein. In the first process, the negotiation mediation service unit calculates the index of feasibility for each item constituting the usage condition for each usage condition among the extracted plurality of usage conditions based on the functions of the connectors of the provider device and the user device used by the data transaction parties. The data circulation system according to claim 1, characterized by the above.
3. In the first process, the negotiation mediation service unit calculates the index of feasibility for each item constituting the usage condition for each usage condition among the extracted plurality of usage conditions based on the past performance of data transactions conducted via the connectors in the organizations of the data transaction parties. The data circulation system according to claim 2, characterized by the above.
4. [[ID=41 In the first process, the negotiation mediation service unit calculates an index of feasibility for each item constituting the usage condition, based on the creditworthiness derived from the past data transactions of the data trader's organization, for each of the plurality of usage conditions extracted above. The data circulation system according to claim 1, characterized in that.
5. In the second process, the negotiation mediation service unit extracts, as the usage condition candidates, the usage conditions existing near the Nash equilibrium point, based on the risk derived from the index of feasibility and the utility values of the data provider and the data user. The data circulation system according to claim 1, characterized in that.
6. The negotiation mediation service unit In the second process, the negotiation mediation service unit notifies the provider device and the user device of the extracted usage condition candidates, along with the range of the index of feasibility and the utility value in the usage condition of each usage condition candidate, and requests evaluation by both parties of the data trader. Furthermore, based on the results of the evaluation by both parties of the data trader, the negotiation mediation service unit executes a third process of determining the final usage condition in the data transaction and notifying the provider device and the user device. The data circulation system according to claim 1, characterized in that.
7. The negotiation mediation service unit is implemented in another device connected to the one or more provider devices and the one or more user devices via a network. The data circulation system according to claim 1, characterized in that.
8. The negotiation mediation service unit is implemented in at least each of the one or more provider devices. The provider device executes the first process and the second process while exchanging information with the user device. The data circulation system according to claim 1, characterized in that.
9. A method for determining data usage conditions by a data circulation system that dynamically negotiates usage conditions for data transactions, wherein The data circulation system One or more provider devices used by a data provider who is one of the data traders, One or more user devices used by a data user who is the other of the data traders, A negotiation mediation service unit that mediates the negotiation of the usage conditions, And has The provider device and the user device each hold preference information indicating matters adjustable in the usage condition, which are acceptable to the data provider or the data user. When a data transaction is conducted among predetermined data traders, a first step in which the negotiation mediation service unit extracts a plurality of usage conditions that can be implemented among the data traders based on the preference information of each of the data traders in the data transaction subject to the usage conditions, calculates an index of feasibility indicating the possibility that the data trader will perform the usage condition for each item constituting the usage condition for each of the extracted plurality of usage conditions, and calculates a utility value indicating the utility that the data provider and the data user will respectively obtain when the usage condition is used; a second step in which the negotiation mediation service unit extracts a predetermined number of usage condition candidates from the plurality of usage conditions based on the feasibility and utility value indices calculated for each of the usage conditions in the first step, and notifies the provider device and the user device of the usage condition candidates and requests evaluation by both of the data traders; a third step in which the negotiation mediation service unit determines the final usage conditions in the data transaction based on the results of the evaluation by both of the data traders requested in the second step, and notifies the provider device and the user device; A data usage condition determination method characterized by comprising the above.
Citation Information
Patent Citations
Transaction support system and transaction negotiation support method
JP2021152760A
JPP7314993B
Mediation device, system, and computer program
WO2020184580A1