Information processing system, information processing method, and program
A distributed data management system with access control and ledger technology ensures secure data sharing and analysis across organizations, addressing confidentiality challenges in sensitive data management.
Patent Information
- Application Number
- JP2025118251
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-07-14
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-07-14
AI Technical Summary
Existing data management systems face challenges in securely sharing sensitive data across multiple organizations while maintaining confidentiality, particularly in areas requiring collaboration such as child support, due to varying security policies and data formats, and lack of configurations for data analysis.
A distributed management system using a closed network with node terminals, access control units, and a distributed ledger system to manage and analyze sensitive data, ensuring secure access and processing history recording.
Provides a secure management function for sensitive data, enabling its utilization in specific areas by maintaining confidentiality and facilitating data sharing among organizations.
Smart Images

Figure 0007738362000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing system, an information processing method, and a program. [Background technology]
[0002] In recent years, in various fields such as healthcare, welfare, and education, the utilization of personal information and sensitive data (PII: Personally Identifiable Information) is expected to contribute to the provision of individually optimized services and the resolution of social issues. Because the problems and circumstances that arise for each individual are diverse, specific responses are required. For example, in child support in the fields of child welfare and maternal and child health, the importance of early detection and early intervention is increasing from the perspective of preventing abuse and preventing serious situations. Therefore, a system that can manage and analyze a wide range of sensitive information across the board and support appropriate decision-making is essential.
[0003] Due to the nature of sensitive information such as the above, strict privacy protection and security measures are required. Conventional data management and analysis systems face challenges such as the risk of information leaks due to centralized data management, vulnerability to unauthorized access, and limitations on data utilization due to restrictions imposed by the Personal Information Protection Act.
[0004] Furthermore, local governments and other organizations that provide child support services are composed of multiple organizations. Each organization has different security policies and data management methods for sensitive information. In addition, the data formats and data items of each piece of information may also differ from organization to organization. As a result, there are various constraints on integrating information sharing between these organizations.
[0005] Meanwhile, with regard to data analysis related to the above-mentioned services, recent remarkable advances in AI (Artificial Intelligence) technology, particularly LLM (Large Language Model), have made it possible to extract knowledge from large amounts of information and support the judgment of complex situations. When considering the use of such technology in child support, it is important to consider the management of sensitive data such as that mentioned above when utilizing it.
[0006] For example, Patent Document 1 discloses a configuration for controlling data sharing and access permissions among multiple users. [Prior art documents] [Patent documents]
[0007] [Patent Document 1] Patent No. 7568598 Summary of the Invention [Problem to be solved by the invention]
[0008] In the data management described above, for example, secret sharing technology and secure computing technology have attracted attention as effective means of increasing data confidentiality. However, sufficient consideration has not been given to a configuration that assumes data analysis by sharing data between organizations while maintaining data confidentiality. In particular, sufficient consideration has not been given to the handling of data in specific areas where collaboration between various organizations is required depending on the situation, specifically, in the case of child support such as responding to child abuse.
[0009] In view of the above problems, the present invention aims to provide a secure sensitive data management function that assumes the utilization of data in specific areas. [Means for solving the problem]
[0010] In order to solve the above problems, one aspect of the present invention has the following configuration: That is, an information processing system for managing sensitive assessment data related to child abuse assessments collected by each of a plurality of organizations, comprising: a distributed management unit that stores the assessment data in a distributed manner in a plurality of node terminals provided in a closed network; an access control unit that performs access control in response to an access request to the assessment data from a user having a predetermined authority related to the plurality of organizations, in accordance with the predetermined authority; a processing unit that executes processing in response to a request from any one of the plurality of organizations using the assessment data stored in a distributed manner in the plurality of node terminals; a record management unit that manages, in a distributed ledger system, data indicating a processing history by the processing unit using the assessment data stored in a distributed manner in the plurality of node terminals; It has.
[0011] Another aspect of the present invention has the following configuration: That is, an information processing method by an information processing system that manages sensitive assessment data related to child abuse assessments collected by each of a plurality of organizations, comprising: a distributed management step of storing the assessment data in a distributed manner in a plurality of node terminals provided in a closed network; an access control step of performing access control in response to an access request to the assessment data from a user having a predetermined authority related to the plurality of organizations, in accordance with the predetermined authority; a processing step of executing a process in response to a request from any one of the plurality of organizations using the assessment data stored in a distributed manner in the plurality of node terminals; a record management process for managing, in a distributed ledger system, data indicating a processing history of the processing process using the assessment data stored in a distributed manner among the plurality of node terminals; It has.
[0012] Another aspect of the present invention has the following configuration: That is, a program comprising: A computer that constitutes an information processing system that manages sensitive assessment data related to child abuse assessments collected by each of a plurality of organizations, a distributed management unit that stores the assessment data in a distributed manner in a plurality of node terminals provided in a closed network; an access control unit that performs access control in response to an access request to the assessment data from a user having a predetermined authority related to the plurality of organizations, in accordance with the predetermined authority; a processing unit that executes processing in response to a request from any one of the plurality of organizations using the assessment data stored in a distributed manner in the plurality of node terminals; a record management unit that manages, in a distributed ledger system, data indicating a processing history by the processing unit using the assessment data stored in a distributed manner in the plurality of node terminals; Function as. [Effects of the Invention]
[0013] According to the present invention, it is possible to provide a secure management function for sensitive data, assuming that data will be utilized in a specific area. [Brief explanation of the drawings]
[0014] [Figure 1] FIG. 1 is a diagram showing an example of a network configuration of an information processing system according to an embodiment of the present invention. [Figure 2A] FIG. 1 is a diagram showing an example of a network configuration of an information processing system according to an embodiment of the present invention. [Figure 2B] FIG. 1 is a diagram showing an example of a network configuration of an information processing system according to an embodiment of the present invention. [Figure 2C] FIG. 1 is a diagram showing an example of a network configuration of an information processing system according to an embodiment of the present invention. [Figure 3] FIG. 1 is a diagram showing an example of a network configuration of an information processing system according to an embodiment of the present invention. [Figure 4] A functional block diagram showing an example of the configuration of a business support server according to an embodiment of the present invention. [Figure 5] FIG. 1 is a functional block diagram showing an example of the configuration of an organization server according to an embodiment of the present invention. [Figure 6] FIG. 1 is a functional block diagram showing an example of the configuration of a user terminal according to an embodiment of the present invention. [Figure 7] 1 is a flowchart of a data recording process according to an embodiment of the present invention; [Figure 8] 1 is a flowchart of a data access process according to an embodiment of the present invention. [Figure 9] 1 is a flowchart of a secure computation process according to an embodiment of the present invention. [Figure 10] 1 is a flowchart of an emergency notification process according to an embodiment of the present invention; DETAILED DESCRIPTION OF THE INVENTION
[0015] Hereinafter, embodiments of the present invention will be described with reference to the drawings. Note that the embodiment described below is one embodiment for explaining the present invention and is not intended to be interpreted as limiting the present invention. Furthermore, not all configurations described in each embodiment are necessarily essential configurations for solving the problems of the present invention. Furthermore, in each drawing, the same components are assigned the same reference numerals to indicate their correspondence. Note that to avoid unnecessary redundancy and to facilitate understanding by those skilled in the art, some of the description may be omitted or simplified. For example, detailed descriptions of already well-known matters or redundant descriptions of substantially identical configurations may be omitted.
[0016] First, in the embodiment of the present invention, a description will be given assuming a child support service, which is a type of administrative service. Note that some or all of the functions and components of the embodiments described below are not limited to application only to support services, but may be applied to various fields and services. Furthermore, modifications, adjustments, extensions, etc. may be made as appropriate depending on the field or service to which they are applied.
[0017] Furthermore, the term "personal information" used in the following description may include data collected directly from an individual, regardless of whether it is collected directly from the individual, and may also include data consisting of one or more items. Note that if other types of information are generated or derived based on personal information, such other types of information may also be treated as personal information. PII, including personal information, is generally managed with strict restrictions on its handling. However, in embodiments of the present invention, such information subject to restrictions on handling is referred to as "sensitive data" and its management and utilization are envisioned. Sensitive data also includes assessment data from child abuse assessments related to child support services, as envisioned in the following embodiments. Note that the various data items handled in the following embodiments are merely examples, and may be added, deleted, or modified depending on the field, service, business content, etc. to which the present invention is applied. For example, assessment data related to child abuse, child welfare, and maternal and child health may include related information such as progress (survey) records related to response and support, and the support record of supporters. Furthermore, various data formats may be used, such as text data, audio data, and image data.
[0018] Furthermore, organizations that collect and share data as envisioned by the present invention are assumed to be administrative agencies, such as national and local governments, and their respective organizations that are capable of handling sensitive data. Examples of such organizations include organizations that belong to basic local governments such as cities, wards, towns, and villages, and organizations that belong to prefectures, which are regional local governments larger than basic local governments. Other examples include police, medical institutions, and non-profit organizations (NPOs) that collaborate across local governments and regions. Organizations vary in size, the types of data they can handle, and their authority varies widely. Security policies and privacy policies regarding sensitive data also vary depending on the organization. While details will be described later, one embodiment of the present invention envisions data sharing and access according to the level of each organization.
[0019] Furthermore, in the configuration according to the present invention, a network where user access is restricted is assumed in order to handle sensitive data on the network. Such a network may be a closed network where data transmission and reception and access are restricted. Note that the access restriction method and network configuration are not limited to the configurations shown below.
[0020] The data managed by the data management method according to the present embodiment may be used for, for example, data processing based on AI technology, which includes various algorithms, learning methods, data input / output, and the like, such as trained models and generative AI, but is not limited to any specific ones.
[0021] First Embodiment [System Configuration] 1 to 3, an example of the configuration of a system and a network according to this embodiment will be described. Note that each configuration is an example, and the components included therein may be changed as desired as long as the functions described below can be realized. In the following description, there are multiple components with similar configurations. When these components require individual explanation, they are indicated with suffixes (a, b, c, ...), and when they can be explained comprehensively, the suffixes will be omitted.
[0022] FIG. 1 is a schematic diagram showing an example of the configuration of a business support system (information processing system) according to a first embodiment of the present invention. The business support system 1 is, for example, a system whose main function is to provide services related to business support. Here, a child consultation center that performs child support services will be described as an example of an institution that uses the services provided by this system, but the present system is not limited to this. This system may be applied to systems of institutions such as city / ward / town / village offices, maternal and child health centers, schools, kindergartens, daycare centers, medical institutions, police, prosecutors, fire departments, child welfare institutions, and non-profit organizations (NPOs), or may be configured to cooperate with these systems. The business support system 1 includes a business support server 100, a user terminal 200, and a cooperation system 300. Each device constituting the business support system 1 is configured to be able to communicate via a network NW.
[0023] The business support server 100 is a device for providing various functions provided by the business support system 1 to the user terminal 200. The business support server 100 provides applications and functions for business support to the user terminal 200 and manages information input via the user terminal 200. Note that some or all of the functions related to business support may be provided by the user terminal 200 or by a linkage system 300 that can link via a network NW. The business support server 100 may be configured on-premise using a general-purpose computer such as a workstation or a personal computer, or may be logically realized by cloud computing. In this embodiment, for convenience of explanation, one business support server 100 is illustrated as an example, but the present invention is not limited to this. Multiple business support servers 100 may be used, and servers with different roles, such as an authentication server and a database server, may also be included.
[0024] The user terminal 200 is an operation terminal used by users such as staff of a child consultation center. The user terminal 200 may be configured, for example, by an information processing device such as a personal computer, a tablet terminal, a smartphone, or a POS terminal. The user terminal 200 provides the user with web services provided by the business support server 100 and the functions of applications installed and running on the user terminal 200. Although the example of FIG. 1 shows one user terminal 200, more user terminals may be used. The configurations of the multiple user terminals 200 may be different from each other or may be the same. Furthermore, the available functions may differ depending on the role and authority of the user using the user terminal 200.
[0025] The linkage system 300 is an external system that functions in cooperation with the business support server 100 via a network NW. The linkage system 300 may be configured, for example, as a child consultation record system, and its primary functions may be recording child consultations and issuing administrative documents. The child consultation record system performs tasks such as issuing child ID numbers and reception numbers related to children, issuing consultation tickets and temporary protection decision notices, managing family information and fees linked to administrative information, and managing the progress of procedures. The configuration of the linkage system 300 is not particularly limited, and it may be configured to provide, for example, various functions related to business support. While only one linkage system 300 is shown, this configuration is not limited, and the linkage system may be configured with one or more devices depending on the functions and services.
[0026] The network NW may be configured by the Internet, an intranet, a wireless LAN (Local Area Network), a WAN (Wide Area Network), etc. Note that there are no particular limitations on the communication standards or wired / wireless nature of the network NW, and the network NW may be configured by combining multiple communication standards. As mentioned above, in consideration of the confidentiality of the information handled, the network NW may be configured as a closed network accessible only to specified users, rather than a public network such as the Internet.
[0027] [Network Configuration] 2A to 2C are conceptual diagrams showing examples of network configurations including multiple storage devices (node terminals 600) for storing sensitive data. For example, organizations that handle sensitive data include government agencies such as national and local governments. Users belonging to these organizations collect data from support recipients and the like based on the authority granted to them by the organizations. The collected data is then stored and managed in a server device (organization server 400) or the like managed by each organization.
[0028] In this embodiment, three networks will be described as examples according to the authority and structure of an organization such as a local government. For convenience, each organization that uses the functions according to this embodiment is configured to be able to use at least one organization server. One organization may be able to use multiple organization servers. The organization server may be configured, for example, to record and manage data collected by the organization itself and share the data within the organization.
[0029] As described above, security policies for sensitive data and authority over data may differ depending on the organization. In this embodiment, the following three patterns of networks are assumed. Pattern 1: Data sharing among multiple organizations belonging to a local government (including data sharing within a single organization) -For example, when sharing information on the Basic Resident Register at the municipal level Pattern 2: Data sharing among multiple organizations belonging to a wide-area local government (including data sharing within a single local government or organization) -For example, when sharing information about children suspected of being abused at the prefectural level Pattern 3: Data sharing among designated organizations within each local government -For example, when sharing data with police and medical institutions across the country
[0030] Depending on the pattern, the organizations that share data will differ, and the data that can be accessed will also differ.
[0031] FIG. 2A shows a conceptual diagram of a network configuration assuming the above-mentioned pattern 1. In addition to the business support server 100 shown in FIG. 1, two organization servers 400a and 400b managed by two organizations belonging to a local government are shown as an example. The organization servers 400a and 400b can be accessed by users such as staff members belonging to the same organization using user terminals 500a and 500b, respectively. Each user is granted authority to access the organization server. Note that the data that each user can access may differ depending on the role and attributes assigned to that user. Therefore, even users belonging to the same organization may have different authority to access data.
[0032] The multiple node terminals 600 function as storage devices. By applying blockchain technology, the multiple node terminals 600 achieve resistance to tampering and reliability. Each organization server 400 also functions as a node terminal 600. In the case of pattern 1, the node terminals 600 correspond to the server devices of each organization, such as a child consultation center, a child and family center, a maternal and child health center, a school, a kindergarten, and a nursery school, in a certain city, ward, town, or village. The multiple node terminals 600, including the organization server, send and receive data based on a predetermined protocol (for convenience, referred to as the "first protocol"). The blockchain network BNWa shown in FIG. 2A exchanges data at the local government level based on the first protocol. For convenience, the edges between the node terminals are shown with different line types to indicate that data is exchanged using different protocols depending on the different scope and level of data sharing in each of FIGS. 2A to 2C.
[0033] The type, algorithm, and protocol of the applied blockchain technology are not particularly limited, and any method may be applied. The number and configuration of the node terminals 600 are also not particularly limited, and may be increased or decreased depending on the number of devices that access the data, for example. The data recorded in each node terminal 600 may be partially or completely duplicated.
[0034] The business support server 100 can access the node terminals 600 via the blockchain network BNWa based on predetermined access rights. At least a portion of the data recorded and managed by the business support server 100 can be stored in any of the node terminals 600. Furthermore, when the business support server 100 executes predetermined processing, it can access and use the data stored in the node terminals 600.
[0035] The organization server 400 is connected to the blockchain network BNWa so that at least some of the data it records and manages can be managed on the blockchain network BNWa. In this embodiment, the organization server 400 performs processing based on secure computation technology on each piece of data when storing the data in the node terminal 600. Known secure computation techniques include "homomorphic encryption" and "secret sharing," and either method may be used. For example, in the case of the secret sharing method, when storing data in the node terminal 600, the organization server 400 divides the target data into multiple pieces of data and stores each piece in a separate node terminal 600. The node terminal 600 that serves as the storage destination may be specified in advance for each organization server.
[0036] FIG. 2B shows a conceptual diagram of a network configuration assuming the above-mentioned pattern 2. The basic configuration is the same as FIG. 2A, but the organizations (node terminals) that share data change. In this example, in addition to the business support server 100 shown in FIG. 1, two organization servers 401a and 401b managed by two organizations belonging to a wide-area local government are shown. Organization servers 401a and 401b can be accessed by users such as staff members belonging to the same organization using user terminals 501a and 501b, respectively. Each user is granted authority to access the organization server. Depending on the network configuration, the organization server and node terminals in FIG. 2A may be the same as the organization server and node terminals shown in FIG. 2B.
[0037] The multiple node terminals 601 function as storage devices. By applying blockchain technology, the multiple node terminals 601 also achieve resistance to tampering and reliability. In the case of Pattern 2, the node terminals 601 correspond to server devices of various institutions, such as child consultation centers, child and family centers, maternal and child health centers, schools, kindergartens, and nurseries in Tokyo's wards and cities. The multiple node terminals 600, including the organization server, transmit and receive data based on a predetermined protocol (referred to as the "second protocol" for convenience). The blockchain network BNWb shown in FIG. 2B exchanges data at the regional municipality level based on the second protocol. The organizations belonging to the regional municipality here may include all or only some of the organizations belonging to the basic municipalities included in Pattern 1. These may be controlled and configured based on security policies, access permissions, and the like.
[0038] FIG. 2C shows a conceptual diagram of a network configuration assuming the above-mentioned pattern 3. The basic configuration is the same as FIG. 2A, but the organizations (node terminals) that share data change. In this example, in addition to the business support server 100 shown in FIG. 1, two organization servers 402a and 402b managed by two organizations belonging to local governments across the country are shown. Each of the organization servers 402a and 402b can be accessed by users, such as staff members, belonging to the same organization using user terminals 502a and 502b. Each user is granted authority to access the organization server. Depending on the network configuration, the organization server and node terminals in FIG. 2A may be the same as the organization server and node terminals shown in FIG. 2C.
[0039] The multiple node terminals 602 function as storage devices. By applying blockchain technology, the multiple node terminals 602 also achieve reliability and resistance to tampering. In the case of pattern 3, the node terminal 603 corresponds to, for example, police server devices located throughout the country. The multiple node terminals 602, including the organizational server, send and receive data based on a predetermined protocol (referred to as the "third protocol" for convenience). The blockchain network BNWc shown in FIG. 2C exchanges data at a national level across regions based on the third protocol.
[0040] FIG. 3 is a diagram showing an example of the configuration of a closed network including the blockchain network shown in FIGS. 2A to 2C. Communication between devices that include sensitive data is restricted based on the security policy and data management regulations of the organization to which the devices belong. A closed network that complies with these security requirements is assumed. For example, the network between the business support server 100 and user terminal 200, the network between each server, the network between the business support server and node terminals (storage devices), and the network between node terminals including the organization server may each be configured as a logically separate closed network.
[0041] [Device configuration] (Business support server) 4 is a block diagram showing an example of the functional configuration of the business support server 100 according to this embodiment. The business support server 100 includes a control unit 110, a communication unit 120, and a storage unit 130. Each unit is configured to be able to communicate with each other via an internal bus or the like.
[0042] The control unit 110 controls the operation of the business support server 100. The control unit 110 is composed of, for example, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), an NPU (Neural network Processing Unit), etc., and provides various functions by reading and executing various programs and data stored in the storage unit 130. The control unit 110 functions as, for example, a data management unit 111, a display control unit 112, a request receiving unit 113, an access control unit 114, a data processing unit 115, an output control unit 116, and a communication control unit 117.
[0043] The data management unit 111 manages the recording, reference, and updating of data in various DBs configured in the storage unit 130. The data management unit 111 may also manage storage locations of data arranged on an external network.
[0044] The display control unit 112 generates a display screen for data processed by the data processing unit 115 and the like, and controls the display. The display control unit 112 also displays a screen for receiving various instructions from the user. For example, the display control unit 112 may provide data for a UI (User Interface) screen for display to the user terminal 200.
[0045] The request receiving unit 113 receives requests from external devices such as an organization server, a user terminal, etc. The requests here may include various requests such as requests to process or provide data.
[0046] The access control unit 114 controls access to data used for requests from external devices and for its own internal processing. For example, access to data managed by the access control unit 114 may be controlled in response to external requests. Alternatively, access to data managed on a network based on the blockchain technology shown in Figures 2A to 2C may be controlled.
[0047] The data processing unit 115 collects data based on internal / external processing requests and processes the data. At this time, the data processing unit 115 generates and appropriately records history information including data access, usage, processing results, etc. The content of the processing executed by the data processing unit 115 is not particularly limited. For example, the analysis methods disclosed in Patent Nos. 7252688 and 7261523 by the applicant of the present application may be executed.
[0048] The output control unit 116 outputs data such as the processing results and request results of the data processing unit 115. The output here may be an output related to a screen display, or may be transmitted to or recorded in an external device.
[0049] The communication control unit 117 controls communication with external devices and transmits and receives data. The communication control here may be performed according to the configuration of the closed network and access restrictions, for example.
[0050] The communication unit 120 is a communication interface for communicating with external devices via the network NW. The communication unit 120 may be configured to be compatible with a plurality of communication standards depending on the configuration of the network NW.
[0051] The storage unit 130 is a storage device for storing programs, data, etc. for executing various control processes and functions in the control unit 110. The storage unit 140 is composed of volatile / non-volatile storage devices such as RAM (Random Access Memory), ROM (Read Only Memory), HDD (Hard Disk Drive), and flash memory. The business support server 100 according to this embodiment is configured to be able to access data managed on an external network in addition to the storage unit 130. Note that the storage unit 130 may be configured with various databases (DBs) corresponding to processes that can be executed by the data processing unit 115, for example, and the configuration is not particularly limited.
[0052] (organization server) FIG. 5 is a block diagram showing an example of the functional configuration of the organization server 400 according to this embodiment. The organization server 400 includes a control unit 410, a communication unit 420, and a storage unit 430. Each unit is configured to be able to communicate with each other via an internal bus or the like. While FIGS. 2A to 2C illustrate organization servers 400, 401, and 402 corresponding to a plurality of patterns, they may have the same configuration or different configurations as long as they can realize the functions according to this embodiment. Here, the organization server 400 will be described as an example.
[0053] The control unit 110 controls the operation of the organization server 400. The control unit 410 is composed of, for example, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), an NPU (Neural network Processing Unit), etc., and provides various functions by reading and executing various programs and data stored in the storage unit 430. The control unit 410 functions as, for example, a data management unit 411, a display control unit 412, a request receiving unit 413, a policy processing unit 414, a protocol control unit 415, a data access unit 416, a data processing unit 417, an output control unit 418, and a communication control unit 419.
[0054] The data management unit 411 manages the recording, reference, and updating of data in various DBs configured in the storage unit 130. The data management unit 411 may also manage the storage location of data arranged on an external network.
[0055] The display control unit 412 generates a display screen for data processed by the data processing unit 417 and the like, and controls the display. The display control unit 412 also displays a UI screen (not shown) for receiving various instructions from the user. For example, the display control unit 412 may provide data of the UI screen for display to the user terminal 500.
[0056] The request receiving unit 413 receives requests from external devices such as the user terminal 500. The requests here may include various requests such as requests to process or provide data.
[0057] The policy processing unit 414 processes each piece of data based on the privacy policy and security policy of the organization. Information on the privacy policy and security policy corresponding to each organization is set in advance. The processing here is not particularly limited. For example, when data is output to the outside, encryption processing and secret sharing processing may be performed based on the policy. In addition, filtering processing and pseudonymization processing may also be performed.
[0058] As shown in Figures 2A to 2C, when recording data to an external network based on blockchain technology, the protocol control unit 415 determines at what level data sharing will be performed and determines a protocol corresponding to that level. As described above, different protocols are used depending on the level, and data is sent and received to the external network using those protocols. For a blockchain network, one organization server may be compatible with multiple protocols, or may be compatible with only one of them.
[0059] The access control unit 416 controls access to data used for requests from external devices and for its own internal processing. For example, access to data managed by the access control unit 416 may be controlled in response to external requests. Alternatively, access to data managed on a network based on the blockchain technology shown in Figures 2A to 2C may be controlled.
[0060] The data processing unit 417 collects data based on internal / external processing requests and processes the data. At this time, the data processing unit 417 generates and appropriately records history information including data access, usage, processing results, etc. The processing executed by the data processing unit 417 is not particularly limited. The processing executed by the organization server 400 may differ for each organization.
[0061] The output control unit 418 outputs data such as the processing results and request results of the data processing unit 417. The output here may be an output related to a screen display, or may be transmitted to or recorded in an external device.
[0062] The communication control unit 419 controls communication with external devices and transmits and receives data. The communication control here may be performed according to the configuration of the closed network and access restrictions, for example.
[0063] The communication unit 420 is a communication interface for communicating with external devices via the network NW. The communication unit 420 may be configured to be compatible with a plurality of communication standards depending on the configuration of the network NW.
[0064] The storage unit 430 is a storage device for storing programs, data, etc. for executing various control processes and functions in the control unit 410. The storage unit 140 is configured with volatile / non-volatile storage devices such as RAM (Random Access Memory), ROM (Read Only Memory), HDD (Hard Disk Drive), and flash memory. The organization server 400 according to this embodiment is configured to be able to access data managed on an external network in addition to the storage unit 430. Note that the storage unit 430 may be configured with various databases (DBs) corresponding to processes that can be executed by the data processing unit 417, for example, and the configuration is not particularly limited.
[0065] (user terminal) 6 is a block diagram showing an example of the functional configuration of a user terminal 200 according to this embodiment. The user terminal 200 includes a control unit 210, a storage unit 220, a communication unit 230, an operation unit 240, a display unit 250, and an external IF (Interface) 260.
[0066] The control unit 210 controls the operation of the user terminal 200. The control unit 210 is composed of, for example, a CPU (Central Processing Unit) and a GPU (Graphics Processing Unit), and provides various functions by reading and executing various programs and data stored in the storage unit 220.
[0067] The storage unit 220 is a storage device for storing programs, data, etc. for executing various control processes and functions of the control unit 210. The storage unit 220 is configured from volatile / non-volatile storage devices such as a RAM (Random Access Memory), a ROM (Read Only Memory), an HDD (Hard Disk Drive), and a flash memory.
[0068] The communication unit 230 is a communication interface for communicating with external devices via the network NW. The communication unit 230 may be configured to be compatible with a plurality of communication standards depending on the configuration of the network NW.
[0069] The operation unit 240 is an interface for receiving operations from a user of the user terminal 200. The operation unit 240 may be composed of a mouse, a keyboard, etc. The display unit 250 is an interface for displaying various screens and is composed of a display, etc. A touch panel display integrating the operation unit 240 and the display unit 250 may be used. The external IF 260 is an interface for connecting to various devices, and may be, for example, a connection interface with an imaging unit (not shown) for capturing images, sensors for acquiring predetermined information, etc.
[0070] [process] Various processes according to this embodiment will be described below with reference to Figures 7 to 10. The subject of each process may be described collectively to simplify the description. Therefore, the subject is not limited to the subjects shown below, and some of the processing subjects may be changed depending on the data transmission / reception, data access, processing load, device configuration, etc.
[0071] In this embodiment, it is assumed that the scope of data sharing based on the blockchain technology shown in Figures 2A to 2C, the policy for sensitive data in each organization, the access rights of each user, etc. are set in advance. These can be set and changed arbitrarily, but may be defined in accordance with laws and regulations applied to the country, local government, etc.
[0072] (Data recording processing) 7 is a flowchart showing the overall processing flow when the organization server according to this embodiment records sensitive data in the blockchain network. This processing flow is realized, for example, by the control unit 410 of the organization server 400 reading and executing programs and various data stored in the storage unit 430. Here, for simplicity of explanation, the processing entity will be described as the organization server 400.
[0073] In step S701, the organization server 400 displays a UI screen (not shown) in response to a request from the user terminal 500. The UI screen here is not particularly limited, and may be, for example, a screen for inputting sensitive data or a screen for instructing some kind of processing using the sensitive data. The UI screen displayed here may be defined in advance and configured to be presentable on the user terminal 500.
[0074] In step S702, the organization server 400 accepts various data via the UI screen displayed in step S701. When an instruction to process the data is accepted, the organization server 400 refers to the relevant data from the storage unit 430 based on the instruction. In this example, the instruction is assumed to be an instruction that requires the desired data to be stored in the blockchain network.
[0075] In step S703, the organization server 400 processes the data received in step S702 based on a predefined policy for storing the data in the blockchain network, and performs data conversion. For example, encryption or pseudonymization may be performed.
[0076] In step S704, the organization server 400 performs a fragmentation process on the data processed in step S703 into a plurality of data pieces so that the data can be divided and stored in a plurality of storage devices (i.e., node terminals). The algorithm for the fragmentation process here is not particularly limited, and a known algorithm may be used. Note that the processes in steps S703 and S704 may be executed together as a secret sharing process.
[0077] In step S705, the organization server 400 determines one or more node terminals that will be used to store the fragmented data pieces generated in step S704. The node terminals determined here may be specified in advance, or may be determined each time based on a predetermined rule. The organization server 400 itself may also be determined as one of the storage destinations.
[0078] In step S706, the organization server 400 detects whether data has been tampered with based on the data stored in the destination node determined in step S705. The detection of data tampering may be performed based on a known blockchain algorithm. After confirming that no tampering has occurred, the organization server 400 proceeds to step S707.
[0079] In step S707, the organization server 400 transfers the data fragment to the node terminal that is the storage destination determined in step S705 using a predetermined protocol. As described above, the protocol used for transmitting the data may differ depending on the scope and level of sharing of the data.
[0080] In step S708, the organization server 400 causes each piece of data to be recorded in the node terminal.
[0081] In step S709, the organization server 400 records the history of processing of the target data as a log. At this time, calculation of a hash value may be performed based on the blockchain algorithm. Then, this processing flow ends.
[0082] The above process is executed each time data is recorded on the blockchain network by each organization server.
[0083] (Data access processing) 8 is a flowchart showing the overall processing flow when the business support server 100 according to this embodiment accesses data on a blockchain network. This processing flow is realized, for example, by the control unit 110 of the business processing server 100 reading and executing programs and various data stored in the storage unit 130. Here, for ease of explanation, the processing entity will be described as the business server 100.
[0084] In step S801, the business support server 100 performs authentication processing for the accessing user. The authentication processing may be authentication using, for example, a user ID and a password.
[0085] In step S802, the business support server 100 identifies the access range of the user authenticated in step S801. The user's access range to data is assumed to be predefined in association with user information. The access range here includes data stored in the storage unit 130 by the business support server 100 as well as data managed in the blockchain network.
[0086] In step S803, the business support server 100 receives a processing request from the user. The content of the processing request is not particularly limited, but may be, for example, a request for analysis processing based on child information.
[0087] In step S804, the business support server 100 identifies the data required for the processing requested in step S803. The data here may include not only data held and managed by the business support server 100, but also data fragments recorded in multiple node terminals that make up the blockchain network.
[0088] In step S805, the business support server 100 determines whether the data identified in step S804 is included in the access range identified in step S802. If the data is included in the access range, it means that the user can access the data. If the data is accessible (step S805: YES), the processing of the business support server 100 proceeds to step S806. On the other hand, if the data is not accessible (step S805: NO), the processing of the business support server 100 proceeds to step S811.
[0089] In step S806, the business support server 100 refers to the data identified in step S804 and executes the process for the request accepted in step S803.
[0090] In step S807, the business support server 100 records the processing result of step S806. The recording destination here may be the storage unit 130 of the business support server 100, or may be determined based on the storage destination of the data identified in step S804.
[0091] In step S808, the business support server 100 notifies the user of the processing result of step S806. The notification here may be made by generating a UI screen (not shown) and displaying it on the user terminal 200, or by notifying the user of information about the recording destination where the processing result was recorded in step S807.
[0092] In step S809, the business support server 100 records the processing history as a log. The processing history here may include information such as access to data, processing content, and processing results. Furthermore, when data on a blockchain network is used, calculation of a hash value may be performed based on the blockchain algorithm. Then, the processing of the business processing server 100 proceeds to step S810.
[0093] In step S810, the business support server 100 determines whether the processing request from the user has been completed. For example, this determination may be made based on whether an instruction to close the UI screen provided by the business support server 100 has been received. If the processing request has been completed (step S810: YES), this processing flow is terminated. If the processing request has not been completed (step S810: NO), the processing of the business support server 100 returns to step S803 and the processing is repeated.
[0094] In step S811, the business support server 100 notifies the user of the failure to access the data.
[0095] In step S812, the business support server 100 records the history of failed attempts to access data as a log. The processing history here may include information about access to data and the data that was attempted to be accessed. In addition, when data on a blockchain network is used, calculation of a hash value may be performed based on the blockchain algorithm. Then, the processing of the business processing server 100 proceeds to step S810. Note that if access to data fails, the processing may be performed only on accessible data.
[0096] (Secret computation processing) 9 is a flowchart showing the overall processing flow when the business support server 100 according to this embodiment performs secure computation processing using data on a blockchain network. This processing flow is realized, for example, by the control unit 110 of the business processing server 100 reading and executing programs and various data stored in the storage unit 130. For ease of explanation, the processing entity will be described as the business server 100. This processing flow may be executed, for example, as the processing of steps S806 to S809 in FIG. 8.
[0097] In step S901, the business support server 100 collects pieces of data that are managed in a distributed manner by each node terminal that constitutes the blockchain network, which is a closed network. The pieces of data collected here may vary depending on the target processing content. The collected data may be, for example, basic information about the child and the family (child's age, family situation, guardian's situation), information obtained from the resident registration system, past support history, and other related data specialized for risk assessment of child abuse and other social issues.
[0098] In step S902, the business support server 100 initializes a secure computation protocol. The secure computation protocol may vary depending on the content of the target process. For example, the target process may be an analytical process such as correlation analysis, risk scoring, or aggregation of specific intervention indicators. Then, an optimal secure computation protocol is selected and initialized accordingly. The secure computation protocol may be, for example, a Secure Multi-Party Computation (SMPC) protocol (additive homomorphic encryption, multiplicative homomorphic encryption, secret sharing scheme, Goldreich-Micali-Wigderson (GMW), Ben-Or / Goldwasser / Wigderson (BGW), Smart-Pastro-Damgard-Zakarias (SPDZ), etc.), or a partial application of homomorphic encryption. Note that these techniques are well known, and therefore detailed description thereof will be omitted here.
[0099] In step S903, the business support server 100 converts the data pieces collected in step S901 into a format that can be processed by the secure computation protocol selected in step S902. Note that if conversion is not required, this step may be omitted.
[0100] In step S904, the business support server 100 performs predetermined analytical processing (addition, multiplication, comparison, machine learning model inference, etc.) on the data fragments converted in step S903 using the secure computation protocol selected in step S902. Because this processing is performed using secret sharing shares provided by multiple municipalities, each share is not individually restored. This allows processing to be performed in a highly confidential manner. The content of the processing is not particularly limited, and may include, for example, risk scoring, common trend analysis, and intervention effectiveness evaluation. Risk scoring may be, for example, a calculation to calculate a risk score in an encrypted state based on each child's risk factors. Common trend analysis may be, for example, a calculation to analyze common trends and correlations between risk factors related to child abuse and other social issues across multiple municipalities in an encrypted state. Intervention effectiveness evaluation may be a calculation to statistically evaluate, in an encrypted state, the impact of a specific child support intervention on improving a child's situation. The effectiveness evaluation may be performed, for example, by using assessment data collected from multiple organizations in multiple municipalities and performing an analytical process optimized for the data structure and analytical parameters specified for child abuse assessments related to child support services, thereby evaluating the analysis of common risk factors across multiple organizations or the effectiveness of specific interventions.
[0101] In step S905, the business support server 100 securely exchanges and aggregates the intermediate results of the processing in step S904. For example, intermediate results generated during a multi-party calculation may be securely exchanged and aggregated among the participants. In this case, the intermediate results remain encrypted. Note that this step may be omitted depending on the processing content.
[0102] In step S906, the business support server 100 performs an anonymization / pseudonymization collaborative process for each piece of data. The business support server 100 performs this process for the scope that cannot be fully addressed by the confidential calculations up to this point, or for publication, search, and display. For example, irreversible anonymization (e.g., k-anonymization, l-diversity) or reversible pseudonymization (e.g., conversion to unique IDs and strict separation and management of correspondence tables) is applied to information that is aggregated and published as a result of confidential calculations, or data elements that are used exclusively for search and display within the system. In addition, different anonymization / pseudonymization levels may be dynamically applied taking into account the characteristics of PII (e.g., name, address, date of birth, family composition) in assessment data related to social issues such as child abuse. The target and scope of application may be specified in advance based on laws and regulations.
[0103] In step S907, the business support server 100 outputs the secret calculation results. The business support server 100 outputs the final secret calculation results (integrated risk score, statistical trends, inference results of the analytical model, etc.). If necessary, the results may be output in an encrypted or anonymized state. The results are output in a form that does not identify the information of individual children and can be shared and used by relevant institutions. The scope of sharing may be specified in advance, for example, within one of the blockchain networks shown in Figures 2A to 2C.
[0104] In step S908, the business support server 100 records the access history and data operation log on the blockchain. Specifically, the business support server 100 records the execution history of secure computation and important data operation logs within the system (such as data registration, update, and deletion, and output of secure computation results) as hash values on the blockchain based on a predetermined blockchain protocol. This makes it impossible to tamper with the recorded logs, ensuring high traceability and auditability.
[0105] In step S909, the business support server 100 notifies the users who can use the processing results of the processing results. Each user can then refer to and use the processing results to provide the necessary support as needed. For example, the calculated risk index and analysis results can be safely provided to each relevant institution (such as a local government, medical institution, or child consultation center) and can be used for credit decisions, disease prediction, and threat intelligence development. This processing flow then ends.
[0106] (Emergency notification processing) 10 is a flowchart showing the overall process flow for detecting a situation requiring an emergency response based on data on a blockchain network by the business support server 100 according to this embodiment. This process flow is realized, for example, by the control unit 110 of the business processing server 100 reading and executing programs and various data stored in the storage unit 130. For ease of explanation, the processing entity will be described as the business server 100. This process flow is executed by continuously monitoring the update status of data on the blockchain network.
[0107] In step S1001, the business support server 100 detects a data update of a predetermined node terminal in the blockchain network. The data update here may be an update of a hash value or an update of a data fragment.
[0108] In step S1002, the business support server 100 performs a predetermined analysis process in response to the data update. The content of the analysis process may be predefined. For example, the business support server 100 may analyze the degree of risk of child abuse based on the updated data, or analyze whether a new case has occurred.
[0109] In step S1003, the business support server 100 determines whether a predetermined trigger has occurred based on the results of the analysis in step S1002. For example, triggers related to the occurrence of a highly urgent case of child abuse, the registration of a new child abuse case, an increase in the risk level in the analysis results, etc. may be set in advance, and the determination may be made based on these. If a trigger has occurred (step S1003: YES), the processing of the business support server 100 proceeds to step S1004. On the other hand, if a trigger has not occurred (step S1003: NO), this processing flow is terminated.
[0110] In step S1004, the business support server 100 records the analysis results of step S1002. The recording destination here may be the storage unit 130 of the business support server 100, or any of the node terminals of the blockchain network. When stored in a node terminal of the blockchain network, processing such as generation of a hash value is performed based on a predetermined blockchain algorithm.
[0111] In step S1005, the business support server 100 identifies a user related to the event for which the occurrence of the trigger was detected in step S1003. The user identified here may be predetermined, for example, depending on the organization or the support content. The user may be, for example, a person in charge of providing predetermined business support in each organization. The user may also be switched depending on the content of the trigger that occurred.
[0112] In step S1006, the business support server 100 sets access rights to the data resulting from the occurrence of the trigger for the user identified in step S1005. The access rights here may be set to the minimum necessary scope (organization, department, person in charge, etc.) based on the zero trust principle. A secure configuration may be achieved by limiting the users who can access the sensitive data. Also, a time limit for access may be set.
[0113] In step S1007, the business support server 100 notifies the related users identified in step S1005 that a trigger has occurred.
[0114] In step S1008, the business support server 100 determines whether or not it has received an access request to the data from the user notified in step S1007. If it has received an access request (step S1008: YES), the processing of the business support server 100 proceeds to step S1009. On the other hand, if it has not received an access request (step S1008: NO), it ends this processing flow.
[0115] In step S1009, the business support server 100 presents the data in response to the request. Here, the storage location of the data recorded in step S1004 may be presented.
[0116] In step S1010, the business support server 100 records the data access history in step S1009 as a log. The access history may be stored in a node terminal on the blockchain network. Then, this processing flow ends.
[0117] As described above, this embodiment makes it possible to provide a secure sensitive data management function that assumes the utilization of data in a specific area. In particular, in administrative support services that handle sensitive data, it becomes possible to securely realize data sharing between organizations belonging to the national or local government.
[0118] It also makes it possible to achieve data security and privacy protection in multi-institutional collaboration, including between local governments. This embodiment uses a multi-layered and complex technical approach, including secret sharing, closed networks, zero trust, blockchain, secure computation, and PII anonymization and pseudonymization, as well as a distributed management model that respects the privacy policies of each local government. This minimizes the risk of information leaks for extremely sensitive personal information, such as child abuse assessments, and enables higher levels of security and privacy protection. It also provides an environment in which related organizations, which have previously been hesitant to collaborate, can safely share and utilize data, thereby improving social trust in data utilization.
[0119] It also enables a dramatic promotion of secure and efficient multi-agency collaboration. This embodiment provides a mechanism for cross-sectional confidential calculation and analysis of data distributed across various local governments and agencies while maintaining privacy protection for each, as well as data collaboration for child abuse assessments. This makes it possible to dramatically facilitate multi-agency collaboration in child abuse cases. This makes it possible to improve the effectiveness of early detection and early intervention, and strengthen the social infrastructure for ensuring the safety of children.
[0120] It also makes it possible to provide practical analytical capabilities specialized for sensitive child abuse assessment data. This embodiment enables data collaboration between multiple organizations, and enables the application of secret sharing and secure computation algorithms optimized for the special structure and analytical requirements of child abuse assessment data. This enables cross-sectional analysis by integrating data collected by multiple organizations in a way that does not violate privacy, something that could not be achieved by a single organization. As a result, it becomes possible to extract more advanced knowledge, such as identifying abuse risk factors, evaluating effective intervention measures, and analyzing trends by region.
[0121] It also makes it possible to ensure high transparency and reliability in data sharing and utilization. In this embodiment, all data flows within the system can be traced in detail by using blockchain technology to record access history and data operation logs in an unalterable manner. As a result, high transparency and reliability are ensured for the entire data sharing process, enabling each institution to fulfill its responsibilities and respond quickly in the event of an incident.
[0122] <Other embodiments> In the above embodiment, an example was described assuming the management and use of sensitive data related to child abuse, etc., but the present invention is not limited to this. As described above, the present invention can be applied to providing functions related to application procedures that require a response in a short period of time, such as child support other than child abuse, maternal and child health, domestic violence response, sexual violence response, delinquency and crime response, developmental disorder response, elderly welfare, disability welfare, public assistance, and treatment and support for mental disorders.
[0123] In addition, in the present invention, a program or application for realizing the functions of one or more of the above-mentioned embodiments can be supplied to a system or device using a network or a storage medium, etc., and one or more processors in the computer of the system or device can read and execute the program.
[0124] Alternatively, it may be realized by a circuit that realizes one or more functions (for example, an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array)).
[0125] Although various embodiments have been described above with reference to the drawings, it goes without saying that the present disclosure is not limited to these examples. It is clear to those skilled in the art that various modifications, alterations, substitutions, additions, deletions, and equivalents may be made within the scope of the claims, and it is understood that these also fall within the technical scope of the present disclosure. Furthermore, the components of the various embodiments described above may be combined in any manner without departing from the spirit of the invention.
[0126] Furthermore, in this specification, expressions such as "first" and "second" are used merely for convenience to distinguish from other elements. Therefore, they are not intended to be interpreted as being limited to a specific component. Therefore, it goes without saying that when there are more components, these expressions may be interpreted appropriately depending on the applied configuration.
[0127] As such, the present invention is not limited to the above-described embodiments, and the present invention also contemplates the mutual combination of the various components of the embodiments, as well as modifications and applications by those skilled in the art based on the description in the specification and well-known techniques, and these modifications and applications are included in the scope of protection sought.
[0128] As described above, the present specification discloses the following:
[0129] (Technology 1) An information processing system for managing sensitive assessment data related to child abuse assessments collected by each of a plurality of organizations, comprising: a distributed management unit that stores the assessment data in a distributed manner in a plurality of node terminals provided in a closed network; an access control unit that performs access control in response to an access request to the assessment data from a user having a predetermined authority related to the plurality of organizations, in accordance with the predetermined authority; a processing unit that executes processing in response to a request from any one of the plurality of organizations using the assessment data stored in a distributed manner in the plurality of node terminals; a record management unit that manages, in a distributed ledger system, data indicating a processing history by the processing unit using the assessment data stored in a distributed manner in the plurality of node terminals; An information processing system comprising: This configuration makes it possible to provide a secure sensitive data management function that assumes data utilization in specific areas, and in particular, in administrative support services that handle sensitive data, it becomes possible to securely share data between organizations belonging to national and local governments.
[0130] (Technology 2) a conversion unit that, when receiving assessment data from a first organization among the plurality of organizations, executes a conversion process on the assessment data based on a security policy or a privacy policy associated with the first organization; a dividing unit that divides the assessment data converted by the converting unit into a plurality of data pieces to be stored in the plurality of node terminals by the distributed management unit; The information processing system according to Technology 1 further comprises:
[0131] (Technology 3) The information processing system described in Technology 2, wherein the distributed management unit determines in which of the plurality of node terminals the plurality of data pieces divided by the division unit will be stored, based on a policy or regulation associated with the first organization.
[0132] (Technology 4) The information processing system according to Technology 2 or Technology 3, wherein the dividing unit determines settings for dividing the assessment data from the first organization into multiple data pieces based on a policy or regulation associated with the first organization.
[0133] (Technology 5) The information processing system according to any one of Technology 1 to Technology 4, wherein the processing unit performs an analysis process optimized for a data structure and analysis factors defined corresponding to the child abuse assessment using assessment data collected from the plurality of organizations, thereby analyzing common risk factors across the plurality of organizations or evaluating the effectiveness of specific intervention measures.
[0134] (Technology 6) The information processing system according to any one of Technology 1 to Technology 5, wherein the access control unit controls the scope of access rights to the assessment data collected by each of the plurality of organizations for the person in charge belonging to each of the plurality of organizations depending on the case of child abuse.
[0135] (Technology 7) The information processing system according to any one of Technology 1 to Technology 6, wherein the record management unit records a hash value using a history of access to or operation of the assessment data stored in each of the plurality of node terminals, or a history of processing execution by the processing unit, and monitors the consistency of the assessment data stored in each of the plurality of node terminals using the hash value.
[0136] (Technology 8) The information processing system described in Technology 5, wherein the processing unit identifies whether or not the case is a case of child abuse with a high urgency in the analysis process, and if a case of child abuse with a high urgency is identified, notifies the person in charge of the identified case after granting them access rights to assessment data related to the identified case.
[0137] (Technology 9) An information processing method for an information processing system that manages sensitive assessment data related to child abuse assessments collected by each of a plurality of organizations, comprising: a distributed management step of storing the assessment data in a distributed manner in a plurality of node terminals provided in a closed network; an access control step of performing access control in response to an access request to the assessment data from a user having a predetermined authority related to the plurality of organizations, in accordance with the predetermined authority; a processing step of executing a process in response to a request from any one of the plurality of organizations using the assessment data stored in a distributed manner in the plurality of node terminals; a record management process for managing, in a distributed ledger system, data indicating a processing history of the processing process using the assessment data stored in a distributed manner among the plurality of node terminals; An information processing method comprising: This configuration makes it possible to provide a secure sensitive data management function that assumes data utilization in specific areas, and in particular, in administrative support services that handle sensitive data, it makes it possible to securely share data between organizations belonging to national and local governments.
[0138] (Technology 10) A computer that constitutes an information processing system that manages sensitive assessment data related to child abuse assessments collected by each of a plurality of organizations, a distributed management unit that stores the assessment data in a distributed manner in a plurality of node terminals provided in a closed network; an access control unit that performs access control in response to an access request to the assessment data from a user having a predetermined authority with respect to the plurality of organizations, in accordance with the predetermined authority; a processing unit that executes processing in response to a request from any one of the plurality of organizations using the assessment data stored in a distributed manner in the plurality of node terminals; a record management unit that manages, in a distributed ledger system, data indicating a processing history by the processing unit using the assessment data stored in a distributed manner in the plurality of node terminals; A program to function as a This configuration makes it possible to provide a secure sensitive data management function that assumes data utilization in specific areas, and in particular, in administrative support services that handle sensitive data, it makes it possible to securely share data between organizations belonging to national and local governments. [Industrial Applicability]
[0139] The present invention is useful, for example, as an apparatus, a system, and a method for handling sensitive data among multiple organizations. [Explanation of symbols]
[0140] 1. Business support system (information processing system) 100: Business support server 200...User terminal 300... Collaboration system 400, 401, 402...Organization server 500, 501, 502...User terminal 600, 601, 602...node terminals
Claims
1. An information processing system for managing sensitive assessment data related to child abuse assessments collected by each of a plurality of organizations, comprising: a distributed management unit that stores the assessment data in a distributed manner in a plurality of node terminals provided in a closed network; an access control unit that performs access control in response to an access request to the assessment data from a user having a predetermined authority related to the plurality of organizations, in accordance with the predetermined authority; a processing unit that executes processing in response to a request from any one of the plurality of organizations using the assessment data stored in a distributed manner in the plurality of node terminals; a record management unit that manages, in a distributed ledger system, data indicating a processing history by the processing unit using the assessment data stored in a distributed manner in the plurality of node terminals; and The processing unit performs an analytical process optimized for the data structure and analytical factors specified for the child abuse assessment using assessment data collected from the multiple organizations, thereby analyzing common risk factors across the multiple organizations or evaluating the effectiveness of specific intervention measures.
2. a conversion unit that, when receiving assessment data from a first organization among the plurality of organizations, executes a conversion process on the assessment data based on a security policy or a privacy policy associated with the first organization; a dividing unit that divides the assessment data converted by the converting unit into a plurality of data pieces to be stored in the plurality of node terminals by the distributed management unit; The information processing system of claim 1 , further comprising:
3. 3. The information processing system according to claim 2, wherein the distributed management unit determines in which of the plurality of node terminals the plurality of data pieces divided by the division unit will be stored, based on a policy or regulation associated with the first organization.
4. The information processing system of claim 1, wherein the access control unit controls the scope of access rights to assessment data collected by each of the multiple organizations for personnel belonging to each of the multiple organizations depending on the case of child abuse.
5. 2. The information processing system of claim 1, wherein the record management unit records a hash value using a history of access to or operation of assessment data stored in each of the plurality of node terminals, or a history of processing by the processing unit, and uses the hash value to monitor the consistency of the access or operation history, or the execution history.
6. The information processing system of claim 1, wherein the processing unit, in the analysis process, identifies whether the case is a case of child abuse with a high urgency, and if a case of child abuse with a high urgency is identified, notifies the person in charge of the identified case after granting them access rights to assessment data related to the identified case.
7. An information processing method for an information processing system that manages sensitive assessment data related to child abuse assessments collected by each of a plurality of organizations, comprising: a distributed management step of storing the assessment data in a distributed manner in a plurality of node terminals provided in a closed network; an access control step of performing access control in response to an access request to the assessment data from a user having a predetermined authority related to the plurality of organizations, in accordance with the predetermined authority; a processing step of executing a process in response to a request from any one of the plurality of organizations using the assessment data stored in a distributed manner in the plurality of node terminals; a record management process for managing, in a distributed ledger system, data indicating a processing history of the processing process using the assessment data stored in a distributed manner among the plurality of node terminals; and An information processing method characterized in that, in the processing step, an analytical process optimized for the data structure and analytical factors specified for the child abuse assessment is performed using assessment data collected from the multiple organizations, thereby analyzing common risk factors across the multiple organizations or evaluating the effectiveness of specific intervention measures.
8. A computer that constitutes an information processing system that manages sensitive assessment data related to child abuse assessments collected by each of a plurality of organizations, a distributed management unit that stores the assessment data in a distributed manner in a plurality of node terminals provided in a closed network; an access control unit that performs access control in response to an access request to the assessment data from a user having a predetermined authority related to the plurality of organizations, in accordance with the predetermined authority; a processing unit that executes processing in response to a request from any one of the plurality of organizations using the assessment data stored in a distributed manner in the plurality of node terminals; a record management unit that manages, in a distributed ledger system, data indicating a processing history by the processing unit using the assessment data stored in a distributed manner in the plurality of node terminals; It functions as The processing unit is a program that analyzes common risk factors across the multiple organizations or evaluates the effectiveness of specific intervention measures by performing analytical processing optimized for the data structure and analytical factors specified for the child abuse assessment using assessment data collected from the multiple organizations.
Citation Information
Patent Citations
Information sharing system, information sharing method, and information sharing program
JP2022038314A
Data management system, data management method, and node
JP2022156182A
Efficient Threshold Storage of Data Objects
JP2023504492A
Abuse response support device, abuse response support method, program, and recording medium
JP2024084910A
History data management program, information processing device, and information processing system
JP2025008647A