Data distribution intermediation system and data distribution intermediation method

The data distribution intermediation system efficiently monitors data usage by generating metadata for predetermined units, addressing inefficiencies in existing systems by reducing metadata size and improving compliance monitoring.

JP7755549B2Active Publication Date: 2025-10-16HITACHI LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2022096857
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-06-15
Publication Date
2025-10-16
Estimated Expiration
2042-06-15

AI Technical Summary

Technical Problem

Monitoring metadata for time-series data usage is inefficient due to the enormous amount of metadata updates, making it time-consuming and cumbersome.

Method used

A data distribution intermediation system that generates metadata for each predetermined unit of data usage, such as a time window or service provider, rather than for each individual data value, to reduce metadata size and enable efficient monitoring.

Benefits of technology

This approach reduces the size and number of metadata, allowing for efficient monitoring of data usage by service providers, ensuring compliance with predetermined purposes and reducing the time required for monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007755549000001
    Figure 0007755549000001
  • Figure 0007755549000002
    Figure 0007755549000002
  • Figure 0007755549000003
    Figure 0007755549000003
Patent Text Reader

Abstract

To provide a data distribution intermediation system and method which can efficiently monitor data use.SOLUTION: A data distribution intermediation system 10 for mediating data provided from a data providing system 20 to a service providing system 30 is configured to: generate data collections in a predetermined unit from time-series data provided from the data providing system; generate meta data for monitoring data use, to be stored for each of the generated data collections; and provide the generated data collections to the service providing system. The service providing system detects a service generated by using the data collections, updates the meta data, and determines whether the detected service conforms to a predetermined purpose set in advance.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a data distribution intermediation system and a data distribution intermediation method. [Background technology]

[0002] We are living in the age of the Internet of Things (IoT), where large amounts of digital data are generated by each user. This data is circulating across domains to improve existing services and create new services.

[0003] The present disclosure is based on a data distribution governance framework that distributes data between data providers, service providers, and data-driven service users so that data owners can manage their data.

[0004] The governance framework for data distribution is provided by a data distribution intermediary system, which provides a trusted environment for participants in a digital marketplace. It allows participants to collectively cooperate in a way that all acceptable rules, legally compliant standards are mutually and transparently respected.

[0005] A data distribution intermediary system is composed of various functions that solve problems related to data distribution, such as safety, privacy, and security risks. Patent Documents 1 and 2 disclose data distribution intermediary systems for data distribution. Patent Document 1 relates to efficient access to medical records. Patent Document 2 relates to the reliability of data distribution. Patent Document 3 relates to the generation of metadata for a collection of items.

[0006] One of the functions of the data distribution intermediary system is to ensure the traceability and reliability of data. To ensure data traceability, metadata is monitored. Metadata is created for each data transfer and updated each time the data is used. Blockchain is used to record metadata during data distribution.

[0007] Patent Document 1 provides a method for recording data distribution and consent in a ledger record that implements a blockchain mechanism. Patent Document 1 uses the blockchain mechanism to create a record of data distribution for each patient. Patent Document 2 updates data tracking information (such as a blockchain) that indicates data storage, processing, and distribution. Patent Document 2 uses the data tracking information to measure the trustworthiness of an entity.

[0008] Metadata is monitored to understand how data is being used. Service providers acquire data through a data distribution intermediary system and provide services based on pre-agreed data usage conditions. If a service provider violates these conditions and uses data in an unintended manner, this method allows the data owner to track data usage.

[0009] To monitor data usage metadata, a metadata model is designed with "service" and "owner" items, which record the service creator and the current data owner. The data monitoring method determines whether there is any unintended data usage by comparing the created "service" with the service agreed upon in advance by the "owner." If there is any unintended data usage, a warning is given to the data owner.

[0010] The data monitoring method is applied to time-series data. Since this data is generated at short time intervals of seconds, metadata for delivering the corresponding data to service providers is generated at a frequency of seconds. The monitoring metadata records are updated according to the data usage. [Prior art documents] [Patent documents]

[0011] [Patent Document 1] U.S. Patent Application Publication No. 2018 / 0082023 [Patent Document 2] U.S. Patent No. 9,928,290 [Patent Document 3] U.S. Patent No. 8,321,456 Summary of the Invention [Problem to be solved by the invention]

[0012] Time-series data is created for distribution from data providers to service providers, and the amount of metadata that is updated for data usage is enormous, making monitoring the metadata time-consuming and inefficient.

[0013] The present invention has been made in view of the above problems, and its object is to provide a data distribution intermediation system and a data distribution intermediation method that enable efficient monitoring of data usage. [Means for solving the problem]

[0014] In order to solve the above problem, a data distribution intermediation system according to one aspect of the present invention is a data distribution intermediation system that mediates data provided from a data providing system to a service providing system, and comprises a processor unit, a memory unit used in the processor unit, and a communication unit used in the processor unit and connected to the data providing system and the service providing system, wherein the processor unit generates data collections of a predetermined unit from time-series data provided from the data providing system, generates and stores metadata for monitoring data usage for each generated data collection, provides the generated data collections to the service providing system, detects services generated by the service providing system using the data collections, updates the metadata, and determines whether the detected services are services that are suitable for a predetermined purpose that has been set in advance. [Effects of the Invention]

[0015] According to the present invention, data is provided to a service provision system in data collections of predetermined units, and metadata for monitoring data usage is generated for each data collection, thereby reducing the size of the metadata and enabling efficient monitoring of data usage. [Brief explanation of the drawings]

[0016] [Figure 1] Figure 1 shows the overall configuration of a data distribution system that verifies whether data is being used as intended. [Figure 2] FIG. 2 is a diagram showing the configuration of a data distribution intermediation system that monitors data usage, and includes a TWP (Time Window Processor Unit) that collects data based on a time window. [Figure 3] FIG. 3 is a sequence diagram showing a process for monitoring data usage. [Figure 4] FIG. 4 is a flowchart showing the process of evaluating the reliability. [Figure 5] FIG. 5 is a flowchart showing a process for collecting data based on a time window value designated by a service provider. [Figure 6] FIG. 6 is a flow chart showing the process by which metadata is created for data transfer. [Figure 7] FIG. 7 shows an example of distribution data to be monitored. [Figure 8] FIG. 8 shows an example structure of a metadata model configured to record data usage. [Figure 9] FIG. 9 is a flowchart showing metadata updates during service creation. [Figure 10] FIG. 10 is a flowchart showing the determination result for the intended service. [Figure 11] FIG. 11 is a storage table showing the intended data usage for each service provider. [Figure 12] FIG. 12 is a flowchart illustrating a flow control decision when accessing a service generated by a service provider. [Figure 13] FIG. 13 is a configuration diagram of a data distribution intermediation system according to the second embodiment. [Figure 14] FIG. 14 is a flowchart showing a process for collecting data according to the data owner. [Figure 15] FIG. 15 is a flowchart showing a determination result regarding emergency services according to the third embodiment. [Figure 16] FIG. 16 is a table that stores data usage in emergencies by each service provider. DETAILED DESCRIPTION OF THE INVENTION

[0017] An embodiment of the present invention will now be described with reference to the drawings. This embodiment relates to data traceability technology for monitoring data usage. One approach is to use metadata to determine "unintended data usage" by a service provider. For example, a metadata model may include "data usage" as an item for determining intentional data usage. The data distribution intermediation system and data distribution intermediation method of this embodiment are applied to time-series data.

[0018] Here, intended data use refers to data use for a purpose agreed upon between the data provider and the service provider. Unintended data use, or unintended data use, refers to data use that does not obtain the prior consent of the data provider. For example, driving data of each vehicle while it is in motion is collected by the data provider, an automobile company. A service provider that diagnoses accident risks and notifies drivers of such risks acquires driving data from the data provider for each time window. There is no problem if the service provider uses the driving data for an accident risk diagnosis service. However, if the service provider uses the driving data for an unplanned service such as new car sales, this constitutes unintended data use, and the data provider's use of the driving data is subject to restrictions. The above examples are provided for illustrative purposes and do not narrow the scope of this embodiment.

[0019] In this embodiment, metadata is created for each set of data (for each data collection) rather than for each data value, thereby making it possible to reduce the enormous amount of metadata that needs to be created.

[0020] Patent Document 1 does not create a record of data distribution for a set of data, but creates a record for a single data value (patient). Patent Document 2 does not use metadata to record data tracking information. Patent Document 3 mentions generating metadata for a set of items, but this is done to provide a method for automatically generating an efficient representation of a set of content items. Patent Document 3 also does not mention a method for reducing metadata. Furthermore, Patent Document 3 collects data at intervals for time-series data.

[0021] In contrast, in this embodiment, a data collection is created based on the value of a time window for data distribution, thereby reducing the size of metadata. As a result, in this embodiment, the time required to monitor data usage is significantly reduced compared to the prior art where data collection is not performed. Therefore, according to this embodiment, data usage by service providers can be efficiently monitored. The configuration of this embodiment is not easily achieved by combining the above-mentioned Patent Documents 1 to 3, and is beyond the scope of design matters of those skilled in the art. [Example]

[0022] The first embodiment will be described with reference to FIGS.

[0023] [Overall structure of the data distribution system]

[0024] FIG. 1 is an explanatory diagram showing the overall configuration of a data distribution system according to a first embodiment. The data distribution system shown in FIG. 1 includes, for example, a plurality of data providing systems 20(1) to 20(N), at least one data distribution intermediation system 10, a plurality of service providing systems 30(1) to 30(N), and a plurality of service using devices 40(1) to 40(N). Hereinafter, unless otherwise specified, the numbers (1) to (N) attached to the reference numerals will be omitted. For example, the service providing systems 30(1) to 20(N) will be referred to as service providing system 30.

[0025] In the data distribution system shown in Figure 1, data held by a data providing system 20 is provided to a service providing system 30 via a data distribution intermediation system 10. The service providing system 30 generates a predetermined service based on the provided data and provides it to a service using device 40 used by a service user.

[0026] In this embodiment, as will be described in detail below, the service providing system 30 monitors whether data is being used in accordance with a predetermined purpose that has been set in advance, and controls data usage in accordance with the monitoring results. Furthermore, in this embodiment, metadata is generated in predetermined units to track and monitor whether data usage is in accordance with the predetermined purpose. That is, in this embodiment, metadata is not generated every time a piece of data is provided to the service providing system 30, but one piece of metadata is generated for each predetermined unit of data usage.

[0027] Returning to Figure 1, the network configuration will be described. The data distribution intermediation system 10 is communicably connected to a data providing system 20 via a communication network CN1. The data distribution intermediation system 10 is communicably connected to a service providing system 30 via a communication network CN2. The service providing system 30 is communicably connected to a service using device 40 via a communication network CN3.

[0028] The communication networks CN1 to CN3 may be public communication networks such as the Internet, or may be private communication networks. The communication networks CN1 to CN3 may include wireless communication and wired communication.

[0029] The data providing system 20 is a computer system that provides data (time-series user data) to the service providing system 30 via the data distribution intermediary system 10. The user data includes, for example, personal data, and is collected and stored by the data providing system 20. The data providing system 20 is a computer system operated by a business operator such as an automobile company, a railway company, or a communications carrier, and manages automobile driving data, passenger boarding and alighting data, various data obtained from users' smartphones, and the like.

[0030] The service providing system 30 is a computer system operated by a business that provides services to users. The service providing system 30 requires user data to generate services. The service providing system 30 processes the acquired data to generate a predetermined service and provides it to the service using device 40.

[0031] The service utilizing device 40 is a device that utilizes the services provided by the service providing system 30. The service utilizing device 40 provides any type of service to the user.

[0032] In this embodiment, the service consumption device 40 may be configured as, for example, a smartphone, a wearable terminal such as glasses, a wristwatch, or an earphone, a desktop, laptop, or tablet personal computer, etc. The service consumption device may be built into a dedicated device such as an increment panel or a car navigation system of an automobile.

[0033] [Configuration of a data distribution intermediary system for data monitoring]

[0034] 2 shows a block diagram of the data distribution intermediation system 10. The data distribution intermediation system 10 is a computer system that mediates and manages data distribution between the data providing system 20 and the service providing system 30.

[0035] The data distribution intermediation system 10 includes, for example, a processor unit 100, a memory unit 110, a communication unit 120, and a user interface unit 130. The data distribution intermediation system 10 can also be connected to a storage medium MM that non-temporarily stores data.

[0036] The processor unit 100 reads and executes a predetermined computer program stored in the memory unit 110, thereby realizing the functions 111 to 117 of the data distribution intermediation system 10.

[0037] The communication unit 120 is a device that communicates with each data providing system 20 and each service providing system 30 via the communication networks CN1 and CN2.

[0038] The user interface unit 130 is a device for exchanging information between the administrator (operator) of the data distribution intermediation system 10 and the data distribution intermediation system 10. The user interface unit 130 includes, for example, a monitor display, a keyboard, a pointing device such as a mouse, a touch panel, and the like.

[0039] The memory unit 110 includes a main storage device and an auxiliary storage device. In addition to an operating system (not shown), the memory unit 110 also stores computer programs that implement various functions for monitoring the usage status of data.

[0040] The functional units 111 to 117 realized by the computer program are described below. That is, the data distribution intermediation system 10 includes, for example, a flow control determination unit 111, a time window processing unit 112, a reliability evaluation unit 113, a data providing unit 114, a monitoring determination unit 115, a metadata handler unit 116, and a ledger storage 117 that stores metadata.

[0041] The data providing unit 114 communicates with the data providing system 20 via the communication network CN1. The data providing unit 114 communicates with the service providing system 30 via the communication network CN2. For example, the data providing unit 114 receives a request to acquire data for a specific time window S110 from the service providing system 30 via the communication network CN2. Then, the data providing unit 114 transmits a data request (step S112 shown in FIG. 3) to the data providing system 20 via the communication network CN1.

[0042] The flow control determination unit 111 performs access control for the shared service provided by the data providing system 20. The access control determination by the data providing system 20 is transmitted from the communication network CN1 to the data providing unit 114, and is passed from the data providing unit 114 to the flow control determination unit 111. The flow control determination unit 111 obtains the result of the access control provided by the data providing unit 114, and controls whether or not to allow access to the data sharing service of the service providing system 30.

[0043] The time window processing unit 112 acquires a time window value, which is an example of a predetermined unit, from the data providing unit 114. The time window processing unit 112 creates a data collection for the time window based on the time window value. The time window processing unit 112 transmits the created data collection including data for the time window to the service providing system 30.

[0044] The monitoring and determination unit 115 has a function of monitoring how the data provided from the data providing system 20 is being used in the services generated by the service providing system 30. To this end, the monitoring and determination unit 115 monitors operations related to metadata, such as the creation of ledger storage 117 that stores metadata and the updating of stored metadata.

[0045] The monitoring and determination unit 115 checks the data usage status in the service providing system 30 based on information provided by the service using device 40, and if it finds unauthorized use of data, it determines whether to create an alert or take other action.

[0046] The metadata handler unit 116 creates metadata for data transfer in ledger storage 117 (step S115 in FIG. 3). The metadata handler unit 116 further updates the metadata for the generated service among the metadata stored in ledger storage 117 (step S121 in FIG. 3).

[0047] The reliability evaluation unit 113 evaluates and manages the reliability of the data usage status in the service providing system 30. The reliability evaluation unit 113 evaluates the reliability of the service providing system 30 based on the determination result of the monitoring and determination unit 115.

[0048] [Process to monitor data usage]

[0049] 3 shows a sequence for monitoring the data usage status using the metadata method, using the data distribution intermediary system 10. An outline of this sequence diagram will be explained below.

[0050] The data distribution intermediary system 10 evaluates the reliability of the service providing system 30 and distributes data according to the reliability. Data provided from the data providing system 20 is grouped into, for example, one data collection based on a time window value provided from the service providing system 30. A data collection that collects data for a time window, which is an example of a predetermined unit, is provided to the service providing system 30. Metadata is created for each data collection provided to the service providing system 30.

[0051] The metadata created during data distribution is updated according to the service used by the service-using device 40. The service-created record of the metadata is used to determine permissible data usage (data usage that conforms to the pre-agreed purpose).

[0052] This decision is sent to the data providing system 20. The data providing system 20 performs access control of the data sharing service according to the decision. The data providing system 20 can control access to the data sharing service by providing a decision that allows the service consuming device 40 to use the service. Ultimately, the service consuming device 40 can use the service approved by the data providing system 20.

[0053] In the figure, the service providing system is abbreviated as "SP." In step S110, the service providing system 30 requests the data distribution intermediary system 10 to acquire time-series data for a specific time window value in accordance with the requirements of the use case. For example, in the automotive field, EDR (Event Data Recorder) data, which records sensor data (such as driving data) at 5-second intervals, is useful for analyzing accident scenarios.

[0054] The data distribution intermediation system 10 receives a request for a reliability evaluation using the reliability evaluation unit 113 via the data providing unit 114 (S111). In step S111, the reliability evaluation unit 113 evaluates the reliability of the service providing system 30.

[0055] The reliability evaluation method (S111) performed by the reliability evaluation unit 13 will be described with reference to Fig. 4. Fig. 4 is a flowchart showing the details of the reliability evaluation.

[0056] Here, as an example, the maximum value of the reliability is 100 points, and 50 points is the predetermined threshold for allowing the data flow.

[0057] First, the reliability evaluation unit 113 checks whether the service providing system 30 that requested the data for the time window in step S110 of FIG. 3 is a new service providing system 30 (S1110).

[0058] When the reliability evaluation unit 113 determines that the service providing system 30 requesting data is a new service providing system 30 (S1110: YES), it registers a predetermined purpose of the new service providing system 30 in the monitoring and determination unit 115 (S1111). The predetermined purpose is the intended purpose of use of the new service providing system 30.

[0059] In step S1112, the reliability evaluation unit 113 sets the reliability TS of the new service providing system 30 to an initial value γ (TS=γ). The initial value γ is greater than a predetermined threshold Th1 for providing data to the service providing system 30 (γ>Th1). For example, the initial value of the reliability is "55" and the predetermined threshold is "50".

[0060] When the reliability evaluation unit 113 determines that the service providing system 30 is not new (S1110: NO), it acquires the reliability based on the history of the service being allowed (S1113). The history of the service being allowed is the history of the service being determined to be within the allowable range in step S1117, which will be described later.

[0061] The reliability evaluation unit 113 compares the reliability TS of the service providing system 30 with a predetermined threshold Th1 and determines whether the reliability TS is equal to or greater than the threshold Th1 (S1114). If the reliability evaluation unit 113 determines that the reliability TS is equal to or greater than the threshold Th1 (S1114: YES), it issues a request to acquire data from the data providing system 20 and passes it to the data providing unit 114 (S1115). Upon receiving the data acquisition request, the data providing unit 114 requests data from the data providing system 20, as shown in step S112 of FIG. 3.

[0062] The reliability evaluation unit 113 acquires the determination result by the monitoring and determination unit 115 (S1116), and evaluates whether the determination result by the monitoring and determination unit 115 is positive (S1117). A positive evaluation here means an evaluation that the data use by the service providing system 30 is the intended data use, that is, an evaluation that the data use is compatible with a predetermined purpose that has been approved in advance.

[0063] If the reliability evaluation unit 113 evaluates that the data usage of the service providing system 30 does not suit the predetermined purpose (S1117: NO), it lowers the reliability TS by a predetermined value β (S1118). On the other hand, if the reliability evaluation unit 113 evaluates that the data usage of the service providing system 30 suits the predetermined purpose (S1117: YES), it raises the reliability TS by a predetermined value α (S1119). Then, the reliability evaluation unit 113 normally ends this process (S111).

[0064] Returning to Figure 3, the data providing unit 114 transmits a request to the data providing system 20 to acquire data from the data providing system 20 (S112). The data providing system 20, having received this request, provides time series data to the data distribution intermediary system 10 (S113). Figure 7 is an example of time series data 50 provided by the data providing system 20. The time series data 50 shown in Figure 7 is data related to automobiles. The time series data 50 will be described in more detail below.

[0065] When the data providing unit 114 receives data from the data providing system 20 (S113), it provides the received data to the time window processing unit 112.

[0066] The time window processing unit 112 collects data based on the time window value specified in step S110.

[0067] 5 is a flowchart showing details of the data collection generation process (S114) executed by the time window processing unit 112. The time window processing unit 112 acquires time series data from the data providing unit 114 (S1140).

[0068] An example of time-series data 50 related to an automobile will be described with reference to Fig. 7. The time-series data 50 includes, for example, a data ID 501, a timestamp 502, a vehicle ID 503, a latitude 504, a longitude 505, a steering angle 506, a speed 507, and a brake 508.

[0069] Data ID 501 is information for identifying each time series data. Timestamp 502 is time information when the time series data was acquired. Vehicle ID 503 is information for identifying the vehicle body that is the information source. Longitude 504 and latitude 505 are vehicle position information. Steering angle 506 indicates the traveling direction of the vehicle. Speed ​​507 is the vehicle speed. Brake 508 is the operating state of the brake.

[0070] The time-series data 50 of a vehicle is recorded, for example, every 100 milliseconds so that it can be searched for by a timestamp 502. FIG. 7 shows a total of 12 seconds of time-series data 50 at a cycle of 100 milliseconds. A data ID 501 is associated with each piece of data having a timestamp 502. In the example of FIG. 7, a total of 120 data IDs 501 exist.

[0071] 5 again, the value of the time window specified in step S110 is acquired by the service providing system 30 (S1141). For example, it is assumed that "6 seconds" is acquired from the service providing system 30 as the time window value.

[0072] The time window processing unit 112 reads the current timestamp 502 of the data as a reference time for collecting data based on the width of the time window (6 seconds) (S1142). The time window processing unit 112 reads the next timestamp 502 of the data (S1143) and calculates the difference between the current timestamp and the next timestamp (S1144).

[0073] The time window processing unit 112 compares the timestamp difference calculated in step S1144 with the time window value and determines whether they match (S1145). Take an example where the time window is 6 seconds and the data acquisition cycle is 100 milliseconds. In this case, data is extracted until the timestamp difference becomes 6 seconds.

[0074] If the difference in timestamps 502 does not reach the time window value (S1145: NO), the time window processing unit 112 returns to step S1143, and if the difference in timestamps 502 reaches the time window value (S1145: YES), data collection is performed for a time width equal to the time window (S1146).

[0075] For example, in the automotive field, a 6-second time window is used for time-series data (speed, steering, braking, etc.) with an interval of 100 milliseconds, so a total of 60 pieces of data are required for one data collection. Therefore, in the case of Figure 7, 60 pieces of data with data ID 501 ranging from "1" to "60" constitute one data collection.

[0076] The time window processing unit 112 requests the data providing unit 114 to provide data (S1147). The time window processing unit 112 sends a metadata generation request to the metadata handler unit 116 (S1148).

[0077] Referring again to Figure 3, when the metadata handler unit 116 receives a request from the time window processing unit 112, it creates metadata associated with the data transfer in the ledger storage 117 (S115). The metadata is data for tracking and monitoring what services the data included in the data collection is used for.

[0078] 6 is a flowchart showing the process (S115) for generating metadata in the ledger storage 117. This process (S115) is executed by the metadata handler unit .

[0079] When the metadata handler unit 116 receives a request to create metadata (S1148) (S1150), it acquires a design (template) of metadata 60 having items 601 to 610 shown in FIG. 8, for example.

[0080] An example of the structure of the metadata 60 will be described with reference to Fig. 8. This template is stored in the ledger storage 117. The metadata 60 has items such as a metadata ID 601, a start ID 602, an end ID 603, a data origin 604, a link 605, an access permission 606, a data type 607, a holder 608, a service 609, and a time window 610.

[0081] The items metadata ID 601, start ID 602, and end ID 603 are provided by the time window processing unit 112. The metadata ID 601 is identification information of metadata created for data collection. The start ID 602 ​​and end ID 603 indicate the entry that serves as the start point and the entry that serves as the end point when collecting the time series data 50. In other words, the start ID 602 ​​and end ID 603 are the start point and end point of the time series data corresponding to the value of the specified time window 610. For example, if the value of the time window 610 is "6 seconds," a total of 60 pieces of time series data with data IDs from "1" to "60" are created as one data collection.

[0082] Each item of data origin 604, link 605, access permission 606, and data type 607 is provided from the data providing system 20 via the communication network CN1.

[0083] Data source 604 is information that identifies the source of the time-series data; in this example, a car ID is used. Link 605 is a cloud link for data search provided by the data providing system 20. Access permission 606 indicates the authority to access the data. Data type 607 is described by metadata that can include, for example, any time-varying data in the automobile domain (latitude, longitude, steering angle, speed, brake).

[0084] The holder 608 is set when the metadata is created in step S1152 described in Fig. 6. Information specifying the service providing system 30 that uses the data collection is set in the holder 608. The metadata can be updated while the current data collection is being provided to the service providing system 30 (S116).

[0085] The service 609 is information that identifies the service that the service providing system 30 provides to the service using device 40. The service 609 is updated by the service using device 40 via the communication networks CN3, CN3.

[0086] The metadata model is composed of the items "Service 609" and "Holder 608" that are used by the monitoring and determining unit 115 to compare data usage. Furthermore, the metadata model has information on the time window 610 that is provided by the data providing unit 114 to create a data collection of time-series data.

[0087] 6, in step S1152, the metadata handler unit 116 creates ledger storage 117 for recording data distribution. Ledger storage 117 uses blockchain technology.

[0088] Referring again to FIG. 3, the data distribution intermediary system 10 provides a data collection to the service providing system 30 (S116). The data providing unit 114 provides the data collection to the service providing system 30. The service providing system 30 generates a service using the time-series data included in the data collection (S117). For example, an accident warning service uses automobile driving data from accident history. By analyzing the driving data included in the history of past traffic accidents, it is possible to predict where and how a car is likely to be driven when an accident is likely to occur. By providing this prediction result to the driver, it is possible to prevent traffic accidents from occurring. For example, a machine learning model can be used for this prediction.

[0089] The service providing system 30 provides the service using device 40 with a link for using the service (S118). The link contains information about the type of service generated. The service using device 40 accesses the received link to use the service generated by the service providing system 30. When the service using device 40 clicks the link, it is automatically redirected to the data distribution intermediation system 10 (S120).

[0090] When the data providing unit 114 receives the redirected link, it passes information about the service accessed by the service using device 40 to the metadata handler unit 116. The metadata handler unit 116 updates the metadata created for the service in step S115 in the ledger storage 117 (S121).

[0091] 9 is a flowchart showing the details of step S121 executed by the metadata handler unit 116. The metadata is updated in the ledger storage 117. The metadata created in the blockchain in the processing of step S115 is updated in this step S121.

[0092] The metadata handler unit 116 receives a request for updating metadata from the service using device 40 (S1210). The metadata handler unit 116 acquires service information from the link and updates the "service 609" in the ledger storage 117. For example, in the automobile domain, the "accident alert service" 609 in the ledger storage 117 is updated.

[0093] Referring again to Fig. 3, the fact that the metadata has been updated in step S121 is detected by the monitoring and determining unit 115, which then creates a determination result as to whether the service is permitted (S122).

[0094] FIG. 10 is a flowchart showing the details of step S122 executed by the monitoring and determining unit 115.

[0095] When the monitoring and determination unit 115 detects in step S115 that metadata has been created in the ledger storage 117 (S1220), it acquires the holder 608 in the metadata from the ledger storage 117 (S1221). The monitoring and determination unit 115 acquires the information set in the holder 701 from the data usage purpose management table 70 shown in FIG.

[0096] The monitoring and determining unit 115 acquires the purpose of use 702 of the data intended by the holder 608 from the data purpose of use management table 70 (S1222).

[0097] 11 shows the data usage purpose management table 70 held by the monitoring and determination unit 115. The data usage purpose management table 70 is used to determine whether the use of data provided by the data providing system 20 conforms to the intended data use (purpose of data use).

[0098] The data use purpose (predetermined purpose) intended by the service providing system 30 is the service content or data use purpose that the service providing system 30 has registered in advance in the data distribution intermediation system 10. The service providing system 30 registers the intended data use purpose when registering in the data distribution intermediation system.

[0099] For example, in the automobile domain, "Service provider A" of holder 701 has registered "accident reception service" as data usage purpose 702. Monitoring and determination unit 115 compares service 609 in the metadata with data usage purpose 702.

[0100] Returning to Fig. 10, the monitoring and determination unit 115 detects that the service 609 in the metadata of the ledger storage 117 has been updated (S1223). The monitoring and determination unit 115 compares the service 609 in the metadata with the intended data usage 702, and determines whether they match (S1224).

[0101] If the preset purpose of use and the actual service content do not match, the monitoring and determination unit 115 issues a warning to the data providing system 20 (S1225). If the preset purpose of use and the actual service content match, the monitoring and determination unit 115 provides the determination result to the reliability evaluation unit 113 (S1226).

[0102] See Fig. 3. The data providing unit 114 transmits the determination result of the monitoring and determining unit 115 to the data providing system 20 (S123). The data providing system 20 determines access control to the data sharing service (S124). The determined access control result is provided from the data providing system 20 to the data distribution intermediary system 10 (S125). The access control result is received by the data providing unit 114 and passed to the flow control determining unit 111.

[0103] The flow control determination unit 111 determines flow control in order to provide the result of the access control determination to the data providing unit 114 (S126).

[0104] 12 is a flowchart showing details of the flow control determination (S126) executed by the flow control determination unit 111. In the flow control determination, access control to the data sharing service provided by the data providing system 20 is determined.

[0105] When the flow control determination unit 111 receives the access control result to the data sharing service (S1260), it determines whether access permission has been granted (S1261). If access permission has not been granted (S1261: NO), the flow control determination unit 111 restricts access to the service by the service using device 40 (S1262). If access permission has been granted (S1261: YES), the flow control determination unit 111 provides access to the service to the service using device (S1263).

[0106] Returning to Fig. 3, the data providing unit 114 redirects the determination result of step S126 to the service using device 40 (S127).

[0107] According to this embodiment configured as described above, data from the data providing system 20 is provided to the service providing system 30 in data collection units, which are predetermined units, and metadata for monitoring the data usage status is generated for each data collection. Therefore, compared to the conventional technology in which metadata is generated each time data is transmitted, the number and overall size of metadata can be reduced, and the data usage status can be monitored efficiently. [Example]

[0108] The second embodiment will be described with reference to Figures 13 and 14. In the following embodiments including this embodiment, differences from the first embodiment will be mainly described.

[0109] In the first embodiment, a time window is used as the predetermined unit of data, and the data for the time window is treated as one collection, whereas in the present embodiment, a service provider is used as the predetermined unit.

[0110] In this embodiment, a data collection is created (S114A) based on the holder 608 of the metadata 60 shown in Fig. 8. When multiple service providing systems 30 receive data, creating metadata for each holder makes it possible to reduce the number and overall size of monitoring metadata in the data distribution intermediation system 10.

[0111] 13 shows a block configuration of a data distribution intermediation system 10A. The data distribution intermediation system 10A of this embodiment has a data collection generation unit 112A instead of the time window processing unit 112. The data collection generation unit 112A executes the data collection generation process (S114A) shown in FIG.

[0112] The data collection generation unit 112A acquires data from the data providing unit 114 (S1140A). The data collection generation unit 112A acquires the name of the data holder or the name of the service providing system 30 (S1141A).

[0113] The data collection generation unit 112A creates a data collection to be provided to the service providing system 30 (S1142A). The data collection generation unit 112A issues a data provision request to the data providing unit 114 (S1143A). Then, the data collection generation unit 112A sends a metadata creation request to the metadata handler unit 116 (S1144A).

[0114] This embodiment configured as described above also achieves the same effects as those of embodiment 1. Furthermore, in this embodiment, a data collection is generated for each service providing system 30 (for each service provider that operates a service providing system), and monitoring metadata is created for each data collection. Therefore, it is possible to determine whether data is being used appropriately for each service providing system, and the number and overall size of metadata can be further reduced compared to embodiment 1, thereby making it possible to efficiently monitor the appropriateness of data usage. [Example]

[0115] A third embodiment will be described with reference to Figures 15 and 16. In this embodiment, it is approved that the service providing system 30 provides an exceptional service that does not conform to a predetermined purpose. In this embodiment, a method (S122B) for monitoring data usage in an emergency, which is not intended data usage, will be described.

[0116] Data usage in an emergency is exceptional data usage that deviates from the specified purpose, and is data usage for services provided from the service providing system 30 to the service using device 40 in an emergency. An emergency situation refers to, for example, natural disasters such as floods, storms, earthquakes, and cyclones, or man-made disasters such as chemical accidents, biological accidents, nuclear attacks, and civil unrest. A government agency or private agency that oversees the data distribution intermediary system can define what constitutes an emergency. The data distribution intermediary system can also define an emergency on its own.

[0117] Fig. 15 is a flowchart showing the service monitoring and determination process S122B executed in an emergency by the data usage monitoring and determination unit 115. The only difference between the process in Fig. 14 and the process in Fig. 10 is that step S1222B is replaced by step S1222 and step S1224B is replaced by step S1224. All other steps are the same.

[0118] In step S1222B, the emergency data use purpose 702B of the holder 608 is requested from the data use purpose management table 70B stored in the monitoring and determination unit 115.

[0119] 16 shows a data usage purpose management table 70B held by the monitoring determination unit 115. Table 70B stores holder 701B, which is the name of the holder, and data usage purpose 702B, which is an emergency service that the service providing system, which is the holder, provides to the service using device 40 in an emergency. For example, in the automobile domain, "service provider A" in holder 701B is associated with using data for a storm warning service in an emergency.

[0120] 15, the monitoring determination unit 115 compares the metadata service 609 with the emergency data use purpose 702B and determines whether they match (S1224B). If they are determined to be incompatible, a warning is issued to the data providing system 20 (S1225B). If they are determined to be compatible, the determination result is provided to the reliability evaluation unit 113 (S1226B).

[0121] This embodiment configured as described above also has the same effects as those of the first embodiment. In this embodiment, data collection can be provided even for exceptional services generated in an emergency, improving convenience for service users. This embodiment can be combined with either the first embodiment or the second embodiment.

[0122] The present invention is not limited to the above-described embodiments and includes various modifications. For example, the above-described embodiments have been described in detail to clearly explain the present invention, and the present invention is not necessarily limited to those including all of the described configurations. Furthermore, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of each embodiment with other configurations.

[0123] Although the present invention has been described using an example of application to the automotive field, it can also be applied to fields other than automotive. For example, passenger boarding and alighting statistics data held by a railway company can be used for marketing purposes at department stores and other institutions to send sales promotion emails to service-using devices. Based on the user's health data collected from a smartphone, the system can estimate the user's health condition and recommend the user to take a break or suggest a meal. If a crisis is detected in the user's health condition, the system can also contact a nearby medical institution as an emergency service.

[0124] This embodiment can also be expressed as a computer program invention as follows, and the computer program can be stored in a storage medium MM and distributed.

[0125] "A computer program that causes a computer to function as a data distribution intermediary system that mediates data provided from a data providing system (20) to a service providing system (30), the computer generating data collections of predetermined units from time-series data provided from the data providing system, generating and storing metadata for monitoring data usage for each generated data collection, providing the generated data collections to the service providing system, detecting services generated by the service providing system using the data collections and updating the metadata, and determining whether the detected services are services that meet a predetermined purpose, or a storage medium that stores the computer program." [Explanation of symbols]

[0126] 10, 10A: Data distribution intermediary system, 20: Data providing system, 30: Service providing system, 40: Service using device, 111: Flow control determination unit, 112: Time window processing unit, 112A: Data collection generation unit, 113: Reliability evaluation unit, 114: Data providing unit, 115: Monitoring determination unit, 116: Metadata handler unit, 117: Ledger storage

Claims

1. A data distribution intermediation system that mediates data provided from a data providing system to a service providing system, a processor unit, a memory unit used by the processor unit, and a communication unit used by the processor unit and connected to the data providing system and the service providing system, The processor unit generating a data collection in a predetermined unit from the time-series data provided by the data providing system; generating and storing, for each of the generated data collections, metadata for monitoring data usage; providing the generated data collection to the service providing system; The service providing system detects services generated using the data collection and updates the metadata; Determining whether the detected service is a service that meets a predetermined purpose that has been set in advance. Data distribution intermediary system.

2. 2. The data distribution intermediation system according to claim 1, The processor unit When a request for provision of data is received from the service providing system, determining whether to provide the data to the service providing system based on a reliability indicating that the service providing system is using the data for the predetermined purpose; If it is determined that the reliability of the service providing system is equal to or greater than a predetermined threshold, a request is made to the data providing system to provide data; storing the data provided from the data providing system via the communication unit in the memory unit, and generating a data collection of the predetermined unit; generating and storing, for each of the generated data collections, metadata for monitoring usage of the data; transmitting the generated data collection to the service providing system via the communication unit; updating the metadata according to the services provided by the service providing system based on the data collection; A determination is made based on the metadata as to whether the service provided by the service providing system is a service that meets the predetermined purpose, and the reliability is updated in accordance with the determination result. Data distribution intermediary system.

3. 2. The data distribution intermediation system according to claim 1, The processor unit If the service provided by the service providing system does not conform to the predetermined purpose, a warning is given to the data providing system. Data distribution intermediary system.

4. 2. The data distribution intermediation system according to claim 1, The processor unit If the service provided by the service providing system does not conform to the predetermined purpose, restricting the provision of the data collection to the service providing system Data distribution intermediary system.

5. 2. The data distribution intermediation system according to claim 1, The processor unit In certain cases, authorizing the service providing system to provide exceptional services that do not conform to the specified purpose. Data distribution intermediary system.

6. 2. The data distribution intermediation system according to claim 1, The data collection in the predetermined unit is a set of time series data for each predetermined time window having a preset time length. Data distribution intermediary system.

7. 7. The data distribution intermediation system according to claim 6, The processor unit generating a data collection for each of the predetermined time windows based on time information contained in the time-series data provided by the data providing system; Data distribution intermediary system.

8. 2. The data distribution intermediation system according to claim 1, The data collection in the predetermined unit is a set of time-series data provided for each of the service providing systems. Data distribution intermediary system.

9. 2. The data distribution intermediation system according to claim 1, The metadata includes information indicating the purpose of the service provided by the service providing system. Data distribution intermediary system.

10. 10. The data distribution intermediation system according to claim 9, The metadata further includes information identifying a service delivery system that uses the data collection. Data distribution intermediary system.

11. 6. The data distribution intermediation system according to claim 5, The processor unit The exceptional service provided by the service providing system is also monitored. Data distribution intermediary system.

12. 2. The data distribution intermediation system according to claim 1, When a new service providing system requests data provision, the processor unit acquires data from the data providing system at least once, generates a data collection requested by the new service providing system, and transmits the data collection to the service providing system. Data distribution intermediary system.

13. A data distribution intermediation method for mediating data provided from a data providing system to a service providing system by a data distribution intermediation system, comprising: The data distribution intermediation system includes: generating a data collection in a predetermined unit from the time-series data provided by the data providing system; generating and storing, for each of the generated data collections, metadata for monitoring data usage; providing the generated data collection to the service providing system; The service providing system detects services generated using the data collection and updates the metadata; Determining whether the detected service is a service that meets a predetermined purpose that has been set in advance. Data distribution intermediation method.

Citation Information

Patent Citations

  • Content distribution

    JP2009505239A

  • Sensor management device and method and program therefor, and matching device and method and program therefor

    JP2019113950A

  • Communication program, communication method, and communication device

    JP2021077223A

  • Secure Distributed Patient Consent and Information Management

    US20180082023A1

  • Generating metadata for association with a collection of content items

    US8321456B2