Systems and methods

The system addresses privacy concerns in information distribution by generating a target ID for each data provision application, ensuring user data is managed without exposing individual identifiers, thereby enhancing privacy protection.

JP7761146B2Active Publication Date: 2025-10-28NEC CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024528005
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-06-15
Publication Date
2025-10-28
Estimated Expiration
2042-06-15

Smart Images

  • Figure 0007761146000001
    Figure 0007761146000001
  • Figure 0007761146000002
    Figure 0007761146000002
  • Figure 0007761146000003
    Figure 0007761146000003
Patent Text Reader

Abstract

The present invention provides a system that protects the privacy of a user participating in an information distribution system. The system comprises a transaction server, a service server, a data utilization server, and a distribution control server. The data utilization server is operated by a data utilization business operator and transmits, to the transaction server, a data provision request which is for acquiring, via data provision, data that satisfies a prescribed requirement from among one or more pieces of user data, and which includes the prescribed requirement. The distribution control server controls data provision. The transaction server transmits the data provision request to the distribution control server. The distribution control server transmits, to the service server, a provision instruction that includes information which specifies data satisfying the prescribed requirement and a subject ID, which is an ID of a user and which has been generated in correspondence with the data provision request. The service server transmits the specified data and the subject ID to the data utilization server.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a system and method. [Background technology]

[0002] 2. Description of the Related Art There is an information distribution system that provides personal information held by a hospital or the like to a destination device such as a business operator with the consent of the individual.

[0003] For example, Patent Document 1 describes that a personal data provision system, provision method, and information processing device that realize privacy protection according to an individual's wishes are provided. The personal data provision system of Patent Document 1 has a plurality of information processing devices. Each of the plurality of information processing devices includes a first transmission unit and an encoding unit. The first transmission unit transmits an inquiry about an encoding method for an individual's identifier to each individual's terminal. The encoding unit encodes each individual's identifier based on a response to the inquiry received from each individual's terminal to generate a code for each individual, and associates the individual's code with each individual's personal data. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Publication No. 2018-128884 Summary of the Invention [Problem to be solved by the invention]

[0005] In the information distribution system (data distribution system) disclosed in Patent Document 1, in order to make it possible to provide user data to a third party, consent from the users who contributed to the generation of the user data is required. Here, in the personal data trading market, the personal data to be provided may be stored across multiple data providers.

[0006] In this case, the data provided to the data recipient must be assigned an ID to indicate that it is data from the same person. Without such an ID, the data recipient will not be able to utilize the data they have obtained.

[0007] The ID assigned to data may be an identifier known to the individual (user ID issued by an information distribution system). If such an identifier is used, data utilization businesses may be able to associate user data obtained through multiple data provision applications. As a result, there is a possibility that user privacy may be leaked.

[0008] Furthermore, when an identifier known to an individual is used, the risk of privacy leakage increases if the individual does not adequately manage their ID. In other words, even if the ID management of the data source and data recipient is sufficient, the risk of privacy leakage increases if the individual does not adequately manage their ID.

[0009] A primary object of the present invention is to provide a system and method that contribute to protecting the privacy of users participating in an information distribution system. [Means for solving the problem]

[0010] According to a first aspect of the present invention, there is provided a system including: a trading server; a service server operated by a service provider and storing at least one or more user data items generated by providing a service to users; a data utilization server operated by a data utilization provider and transmitting a data provision application to the trading server, the data provision application being an application to obtain, by data provision, data from the at least one or more user data items that meets specified requirements, the data provision application including the specified requirements; and a distribution control server that controls the data provision, wherein the trading server transmits the data provision application to the distribution control server, and the distribution control server transmits a provision instruction to the service server, the provision instruction including information specifying data that meets the specified requirements and a target ID that is the user's ID and is generated in response to the data provision application, and the service server transmits the specified data and the target ID to the data utilization server.

[0011] According to a second aspect of the present invention, there is provided a method for a system including a trading server, a service server operated by a service provider and storing at least one or more user data items generated by providing a service to a user, a data utilization server operated by a data utilization provider and transmitting a data provision application to the trading server, the data provision application being an application to acquire, by data provision, data from the at least one or more user data items that meets predetermined requirements, the data provision application including the predetermined requirements, the data provision application including the predetermined requirements, the trading server, transmitting the data provision application to the distribution control server, and the distribution control server transmitting a provision instruction to the service server including information specifying data that meets the predetermined requirements and a target ID that is the user's ID and is generated in response to the data provision application, the service server transmitting the specified data and the target ID to the data utilization server. [Effects of the Invention]

[0012] According to each aspect of the present invention, a system and a method are provided that contribute to protecting the privacy of users participating in an information distribution system. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the above effects. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 1 is a diagram for explaining an outline of an embodiment. [Figure 2] FIG. 2 is a flowchart showing an example of the operation of one embodiment. [Figure 3] FIG. 3 is a diagram illustrating an example of a schematic configuration of an information distribution system according to the first embodiment. [Figure 4] FIG. 4 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 5] FIG. 5 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 6] FIG. 6 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 7] FIG. 7 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 8] FIG. 8 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 9] FIG. 9 is a diagram illustrating an example of catalog information according to the first embodiment. [Figure 10] FIG. 10 is a diagram illustrating an example of a data provision application according to the first embodiment. [Figure 11] FIG. 11 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 12] 12A, 12B, and 12C are diagrams showing examples of a data provision contract according to the first embodiment. [Figure 13] FIG. 13 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 14] FIG. 14 is a diagram illustrating an example of data provision status information according to the first embodiment. [Figure 15] FIG. 15 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 16] FIG. 16 is a diagram illustrating an example of a processing configuration of the distribution control server according to the first embodiment. [Figure 17] FIG. 17 is a diagram illustrating an example of a part of the user information database according to the first embodiment. [Figure 18] FIG. 18 is a diagram illustrating an example of a location information database according to the first embodiment. [Figure 19] FIG. 19 is a diagram illustrating an example of the consent management database according to the first embodiment. [Figure 20] FIG. 20 is a diagram illustrating an example of a processing configuration of the service server according to the first embodiment. [Figure 21] FIG. 21 is a diagram illustrating an example of a customer information database according to the first embodiment. [Figure 22] FIG. 22 is a diagram illustrating an example of a processing configuration of the trading server according to the first embodiment. [Figure 23] FIG. 23 is a diagram showing an example of an account holder list according to the first embodiment. [Figure 24] FIG. 24 is a diagram illustrating an example of a processing configuration of a terminal according to the first embodiment. [Figure 25] FIG. 25 is a sequence diagram showing an example of the operation of the information distribution system according to the first embodiment. [Figure 26] FIG. 26 is a diagram illustrating an example of a hardware configuration of a transaction server according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0014] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of main signals (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.

[0015] The system according to one embodiment includes a trading server 101, a service server 102, a data utilization server 103, and a distribution control server 104 (see FIG. 1). The service server 102 is operated by a service provider and stores at least one or more user data items generated by providing services to users. The data utilization server 103 is operated by a data utilization provider and transmits a data provision request, which is an application for acquiring at least one or more user data items that meet certain requirements through data provision, to the trading server. The distribution control server 104 controls data provision. The trading server 101 transmits the data provision request to the distribution control server 104 (step S1 in FIG. 2). The distribution control server 104 transmits a provision instruction to the service server 102, which includes information specifying the data that meets the certain requirements and a target ID, which is a user ID and is generated in response to the data provision request (step S2). The service server 102 transmits the specified data and the target ID to the data utilization server 103 (step S3).

[0016] In the above system, the distribution control server 104 instructs the service server 102, which is the data provider, to transmit the target data for data provision (data that meets the specified requirements of the data recipient) along with the target ID corresponding to the data provision application. That is, the distribution control server 104 generates a different target ID for each data provision application and instructs the service server 102 to transmit the target ID as the user's ID. This configuration prevents data utilization businesses from inappropriately associating user data obtained from multiple data provision applications. Furthermore, the provided user data is managed by the target ID, which cannot be known by individuals. The target ID is not leaked from the user himself, so the user's privacy is protected.

[0017] Specific embodiments will be described in more detail below with reference to the drawings.

[0018] [First embodiment] The first embodiment will be described in more detail with reference to the drawings.

[0019] [System Configuration] Fig. 3 is a diagram showing an example of a schematic configuration of an information distribution system according to the first embodiment. As shown in Fig. 3, participating members (actors) of the information distribution system include information distribution companies, service companies, data utilization companies, and trading companies.

[0020] An information distribution business is a business that provides a platform for a data distribution service (information distribution service) for personal data accumulated in a service business. The information distribution business controls data distribution between businesses (service businesses, data utilization businesses). The information distribution business is equipped with a distribution control server 10.

[0021] The distribution control server 10 is operated by an information distribution business operator. The distribution control server 10 is a server device that controls (realizes) data distribution between service businesses and controls data distribution between service businesses and data utilization businesses. The distribution control server 10 realizes an information distribution service for data held by the service business operator.

[0022] A service provider is an entity that provides services to individuals. A service provider may be a private business or a public institution. Examples of service providers include medical institutions (hospitals, pharmacies, etc.) that provide medical services to users, retailers, and educational institutions that teach languages, sports, arts, etc. to customers.

[0023] Each service provider has a service server 20 for providing services to customers. The service server 20 is managed and operated by the service provider. The service server 20 holds (stores) data generated by the service provider when the service provider provides services to users, data necessary to provide services to users, etc. The service provider holds user data related to the services it provides to users.

[0024] Data utilization businesses are entities that do not provide services directly to individuals. Examples of data utilization businesses include pharmaceutical companies. For example, pharmaceutical companies develop new drugs using data obtained from service providers.

[0025] In this disclosure, entities that do not provide services to individuals will be referred to as "data utilization businesses" for explanation, but it goes without saying that data utilization businesses act as "service businesses" when providing services to users. In other words, depending on the business model of a data utilization business, the data utilization business may also be a service business.

[0026] The data utilization business has a data utilization server 30 for acquiring and utilizing data from the service business. The data utilization server 30 is operated by the data utilization business. The data utilization server 30 acquires at least one user data from the service server 20 by providing the data.

[0027] A trading business is an entity that realizes transactions between service providers and data utilization businesses. A trading business realizes data distribution between data generators (service providers) and data consumers (data utilization businesses). A trading business is a business that acts as an intermediary in data distribution transactions between service providers and data utilization businesses.

[0028] The trading company has a trading server 40 for realizing the data distribution. The trading server 40 is operated by the trading company. The trading server 40 controls the data provision contract between the service provider and the data utilization company.

[0029] A user of the information distribution system uses a terminal 50 .

[0030] The devices shown in Fig. 3 are connected to each other via a network. For example, the distribution control server 10 and the service server 20 are connected by wired or wireless communication means and are configured to be able to communicate with each other.

[0031] 3 is an example and is not intended to limit the configuration of the information distribution system disclosed in the present application. For example, an information distribution business may include two or more distribution control servers 10. Furthermore, with regard to trading businesses and data utilizing businesses, the information distribution system includes data utilization servers 30 and trading servers 40 according to the number of businesses participating in the system.

[0032] [System Overview] Next, the general operation of the information distribution system according to the first embodiment will be described.

[0033] A user enters into an individual contract with a service provider from which the user wishes to receive a service. For example, the user provides the service provider with their name and other information and requests to enter into a new contract (a contract to receive the service) with the service provider.

[0034] For example, a user who wishes to visit a hospital submits a health insurance card or the like bearing the user's name, etc. to the hospital. Alternatively, in the case of an EC (Electronic Commerce) business that provides services related to online shopping, the user accesses a service server 20 operated by the EC business and creates an account.

[0035] A service provider generates a "personal identification ID" to identify a new customer (user). For example, a hospital assigns a patient card number to manage users (patients) and generates the patient card number as the personal identification ID. An e-commerce business generates a membership number or the like to manage customers as the personal identification ID. The service server 20 stores the generated personal identification ID (for example, a patient card number or membership number) in a database or the like.

[0036] Once the personal identification ID is generated, the user can receive services from the service provider. For example, the user can receive medical services (health checkups, consultations, etc.) from a hospital, or can use an e-commerce provider to do online shopping.

[0037] In order for user data generated by service providers when they provide services to users to be subject to data distribution, the data must be "stored." Data storage occurs when a service provider (the provider of user data) registers the user data in an information distribution system as data that can be provided to third parties.

[0038] The distribution control server 10 controls data accumulation for making data related to services provided to users by data accumulators (service providers) the subject of data distribution. That is, the distribution control server 10 controls data accumulation for registering user data in the information distribution system as data that can be provided to third parties. The accumulated data becomes the subject of data distribution.

[0039] There are two means of data distribution in an information distribution system: "sharing" and "provision." The distribution control server 10 controls data sharing, which allows user data registered by data accumulation to be shared from one service server 20 to another service server 20. The distribution control server 10 controls data provision, which allows user data registered by data accumulation to be provided from the service server 20 to the data utilization server 30.

[0040] "Sharing" is a means by which service providers obtain data accumulated by other service providers. For example, data distribution through "sharing" is used when an e-commerce operator obtains data generated by a hospital providing services to users. The e-commerce operator uses the data obtained from the hospital through data sharing to provide better services to users.

[0041] "Sharing" is used to improve the convenience of the service user themselves, so no compensation is paid to the user for data distribution (compensation for the user). "Sharing" is used to utilize data accumulated by other service providers in order for users to receive better services from the service provider.

[0042] "Provision" is a means by which data utilization businesses obtain data accumulated by other service businesses. For example, data distribution by "provision" is used when a pharmaceutical company obtains the results of health checkups and medical examinations from a hospital. The pharmaceutical company uses the data obtained from the hospital through data provision to help develop new drugs.

[0043] "Provision" is a method used by data utilization businesses that do not provide services directly to users, so compensation is incurred for data distribution (compensation to users). In other words, when "provision" is made, compensation is paid to the user. Also, when "provision" is made, compensation is paid from the data acquirer (data recipient) to the data provider (data accumulator) and the information distribution system (information distribution business).

[0044] For the sake of convenience, this disclosure will be described assuming that no compensation (fees) are paid to trading companies. In reality, a portion of the compensation paid by the data recipient to the data provider may be paid to the trading company as a "fee."

[0045] The distribution control server 10 controls data sharing so that data sharing destinations (service businesses that receive data) can acquire the accumulated data. The distribution control server 10 controls data provision so that data providing destinations (data utilizing businesses that receive data) can acquire the accumulated data.

[0046] <Create a system account> Users of the information distribution system must register in advance (user registration, system registration). More specifically, the user accesses the distribution control server 10 and performs procedures for creating an account. In the following explanation, an account created in the information distribution system will be referred to as a "system account."

[0047] To create a system account, the user operates the terminal 50 that the user owns to access the distribution control server 10. In response to the access from the terminal 50, the distribution control server 10 displays a WEB page for creating a system account.

[0048] The user performs an operation for generating a system account (for example, pressing a predetermined button) to generate a system account. At this time, the distribution control server 10 acquires information necessary for generating the user's system account. Specifically, the distribution control server 10 acquires the user's login information (login ID, password) and personal information (name, date of birth, contact information, account information, etc.).

[0049] After acquiring the login information, personal information, etc., the distribution control server 10 generates a user ID (Identifier) for uniquely identifying the user in the information distribution system.

[0050] The distribution control server 10 stores the generated user ID of the user, login information, and personal information (for example, name, date of birth, contact information) in association with each other. The distribution control server 10 stores these information in the "user information database". Details of the user information database will be described later.

[0051] The distribution control server 10 pays out the generated user ID to the user (terminal 50). The terminal 50 stores the paid-out user ID.

[0052] <ID Linkage> As described above, in order to make the user data held by the service provider the subject of data distribution, "data accumulation" is required. In order to achieve data accumulation, it is necessary to link the ID (user ID) of the system account and the ID (personal identification ID) generated by the service provider.

[0053] For example, as shown in FIG. 4, the user conveys to the hospital staff at the hospital counter that he / she wishes to utilize the user data held by the hospital (submits an application for data utilization). The hospital staff inputs the user's personal identification information, the user's personal identification ID (for example, examination ticket number), and the business operator code into the hospital terminal 60.

[0054] The personal identification information is information for identifying a user, and examples of the personal identification information include the user's name, or a combination of the user's name and date of birth.

[0055] Furthermore, the business code is identification information (ID) used to identify service businesses participating in the information distribution system. For example, different codes are assigned to hospitals and e-commerce businesses. The business code is shared by any means among system participants (information distribution businesses, service businesses, and data utilization businesses). For example, when a service business participates in the information distribution system, the information distribution business generates a business code to be assigned to the service business. The information distribution business notifies the service business, etc. of the generated business code.

[0056] The hospital terminal 60 transmits to the distribution control server 10 an "ID federation request" including the acquired individual specifying information, individual identification ID, and business code.

[0057] Alternatively, a user who wishes to utilize the user data of an EC business operates a terminal 50 to access the service server 20 of the EC business (see FIG. 5). The user logs in to an account of the EC business and submits an application for data utilization through the account. In response to the application, the service server 20 transmits an "ID federation request" including the user's personal identification information, personal identification ID, and business code to the distribution control server 10.

[0058] The distribution control server 10 acquires from the hospital terminal 60 and the service server 20 the personal identification information of the person desiring ID federation, the personal identification ID, and the business code of the service business (for example, hospital, e-commerce business) that is the target of ID federation.

[0059] The distribution control server 10 identifies the service provider that is the target of ID federation from the provider code. The distribution control server 10 also identifies the user registered in the system account from the personal identification information. The distribution control server 10 associates the service provider with the personal identification ID in the account of the identified user.

[0060] Once a personal identification ID is registered in a system account (when ID linking is completed), the service provider that is the subject of ID linking will be able to "store" the user data of users who wish to utilize the data.

[0061] <Data accumulation>

[0062] When a service provider provides a service to a user, the service provider stores the user's personal identification ID and user data (personal data) in association with each other. For example, when a hospital examines a user and obtains a disease name, the hospital stores the user's personal identification ID (such as a patient card number) and the disease name (for example, a specific disease name such as stomach cancer) in association with each other. For example, the service server 20 uses a "customer information database" to store the user's personal identification ID and user data in association with each other. The customer information database will be described in detail later.

[0063] The service provider's service server 20 controls data accumulation for users who have completed ID integration (users who have applied for data utilization) each time it stores user data (data resulting from the provision of the service, data necessary for the provision of the service).

[0064] Specifically, the service server 20 registers the user data of the user as accumulated data (user data to be distributed) in the information distribution system. Specifically, the service server 20 transmits "location information" regarding the user for whom ID federation has been completed to the distribution control server 10 (see FIG. 6).

[0065] Location information is information about the storage location of user data (data storage entity; service provider), etc. Location information includes a data ID for identifying user data (stored data), a personal identification ID, a business code, the type of data being held, etc.

[0066] The distribution control server 10 stores the acquired location information in a "location information database." Details of the location information database will be described later. The location information database stores data IDs, individual identification IDs, business codes, data types, etc. in association with each other.

[0067] <Data sharing> A service provider that wishes to acquire data accumulated by another service provider (user data resulting from the provision of services to users by another service provider) can acquire that data through "sharing."

[0068] 7, a case will be described in which EC business operator B acquires, by "sharing," user data (examination results; disease name) stored in Hospital A. The hospital is equipped with service server 20-1, and the EC business operator is equipped with service server 20-2.

[0069] The EC business operator B (service server 20-2) transmits a "sharing request" to the distribution control server 10 (step S11).

[0070] Based on the sharing request, the distribution control server 10 identifies the user who is the target of data distribution and the data accumulator (hospital A) of the data to be distributed. The distribution control server 10 transmits an inquiry regarding data sharing to the terminal 50 possessed by the identified target user (step S12).

[0071] The terminal 50 that receives the data sharing inquiry acquires the user's intention regarding data sharing. For example, the terminal 50 acquires the user's intention using a GUI (Graphical User Interface). In the above example, the terminal 50 displays a GUI with the content such as "By sharing your hospital examination results with the EC business operator, you will receive better service. Do you want to share?" and acquires the user's intention (agree or disagree to data sharing).

[0072] The terminal 50 transmits a response to the inquiry about data sharing (agreement to data sharing or denial of data sharing) to the distribution control server 10 (step S13).

[0073] If the user's consent is obtained, the distribution control server 10 transmits a sharing instruction to the data sharing source (hospital A) (step S14).

[0074] Upon receiving the sharing instruction, Hospital A (service server 20-1) refers to the customer information database and transmits the examination results (disease name) of the target user, etc. to service server 20-2, the designated data sharing destination (step S15).

[0075] Next, data distribution through "provision" will be explained.

[0076] <Opening an account> Users who wish to receive compensation for providing data must open an account with a trading company. Opening an account for data provision will be explained with reference to Figure 8.

[0077] A trading business partner will partner with at least one of the multiple service businesses participating in the information distribution system. For example, a trading business that handles medical data will partner with a medical institution (hospital, pharmacy, etc.). Or, a trading business that handles educational data will partner with an education provider. The trading business will store the business code of the service business partner.

[0078] In addition, trading businesses store the business code of the data-utilizing business. For example, trading businesses generate the business code of the data-utilizing business when starting a transaction with the data-utilizing business. The business code of the data-utilizing business is shared among the information distribution business, trading businesses, and data-utilizing business by any method.

[0079] The trading business sells (intermediates sales of) data held by the partner service business (accumulated data) to data utilization businesses. For example, if the partner service business shown in Figure 8 is a medical institution, the trading business sells the data held by the partner medical institution to pharmaceutical companies, etc.

[0080] As mentioned above, users who wish to receive compensation for providing data via a trading company must open an account with the trading company (trading server 40). Users participating in the information distribution system who wish to earn revenue by providing data open an "information account" with the trading server 40.

[0081] The user presents the user ID issued by the distribution control server 10 to the trading server 40 to open an information account. The trading server 40 stores the acquired user ID. The trading server 40 manages the user IDs of users who have opened accounts in an account holder list.

[0082] <Catalogue information> To realize data distribution through "provision," information distribution businesses prepare catalog information. The person in charge (system administrator) at the information distribution business defines the catalog information that lists the data that can be sold (see Figure 9). The catalog information is information that shows details of the data that the information distribution system can sell to data utilization businesses.

[0083] The dataset name included in the catalog information shown in Fig. 9 is information for identifying the catalog information. For example, a dataset related to a health checkup is given the name "Examination Results 1," and a dataset related to examination results is given the name "Examination Results 1."

[0084] The data type included in the catalog information indicates the type of data held by the service provider (accumulated data that can be provided to third parties). For example, information such as "height," "weight," and "blood pressure" in medical examination results, and "disease name," "medication," and "test results" in examination results correspond to data types. The data format specifies the format in which the data will be provided.

[0085] The data utilization business acquires the catalog information via the trading business. More specifically, the data utilization server 30 transmits a “catalog information presentation request” to the trading server 40.

[0086] Upon receiving the catalog information presentation request, the transaction server 40 transmits a “catalog information transmission request” to the distribution control server 10 .

[0087] In response to receiving the catalog information transmission request, the distribution control server 10 transmits the catalog information defined by the information distributor to the transaction server 40 .

[0088] The transaction server 40 selects catalog information related to the partner service provider and transmits it to the data utilization server 30. For example, in the above example, the transaction server 40 selects catalog information related to the business of a pharmaceutical company and transmits it to the data utilization business. The data utilization business views the received catalog information and identifies the catalog information necessary for its own business.

[0089] <Data distribution through provision> Data utilization businesses that wish to obtain data accumulated by service providers can obtain that data by "provision."

[0090] Here, we will explain the case where pharmaceutical company D obtains a user's disease name, test results, and activity amount by "provision." Hospital A and Hospital B hold user data related to the user's disease name and test results, and fitness club C holds user data related to activity amount.

[0091] An employee of the data recipient (pharmaceutical company D) creates a data provision application by referring to the publicly available catalog information. The data provision application is an application to acquire at least one or more pieces of user data that meet certain requirements.

[0092] For example, an employee or the like inputs a data provision application as shown in Fig. 10 into the data utilization server 30. The input date of the data provision application is January 1, 2021.

[0093] The data provision application includes general information on data provision, requirements for the data to be provided, and a proposal for the price of the data to be provided.

[0094] The data provision summary information is information about the outline of the data provision applied for by the data recipient (pharmaceutical company D). The data provision summary information includes information about the business requesting the data provision, the purpose of the data provision application, the target period (the period during which the data was accumulated), the budget, the deadline, etc.

[0095] Information about the business entity requesting the provision of data (data utilizing business entity, for example, pharmaceutical company D) includes the name of the business entity, business code, data recipient (address to which data will be sent), etc.

[0096] The requirements for data provided are requirements regarding the data provided to data utilization businesses through data provision. The requirements for data provided include information on the target individuals, the number of target individuals required, and information on the required data (type of data, minimum and maximum limits indicating the amount of data required), etc.

[0097] The provision consideration proposal is detailed information regarding the provision consideration that the data utilization business will pay for the data provision. The provision consideration proposal includes the consideration for each data type that will be paid by the data recipient.

[0098] The operation of the information distribution system when providing data will be described with reference to FIG.

[0099] First, the data utilization server 30 transmits a data provision application to the transaction server 40 (step S21).

[0100] The transaction server 40, which has received the data provision application, assigns an application ID to the data provision application and stores the received data provision application. Thereafter, the transaction server 40 transmits a "provision request" including the application ID, the data provision application, and the account holder list to the distribution control server 10 (step S22).

[0101] The transaction server 40 notifies the data utilization server 30 of the provision application ID assigned to the data provision application. The data utilization server 30 associates the notified provision application ID with the data provision application sent to the transaction server 40 and stores them.

[0102] In response to receiving the request for provision, the distribution control server 10 notifies the user of candidates for data providers (data accumulators) and obtains the user's consent regarding the provision of data.

[0103] <Identification of data providers and subjects> The distribution control server 10 identifies a data provider (service provider) that holds user data that meets the requirements for the data to be provided described in the data provision application. Specifically, the distribution control server 10 refers to the user information database and the location information database to identify a data provider that holds data of a user (target person) that meets the requirements described in the data provision application.

[0104] In the example of FIG. 10, the distribution control server 10 refers to the user information database and identifies users aged between 20 and 65 who are listed on the account holder list.

[0105] The distribution control server 10 refers to the location information database and identifies, from the identified users, subjects who further meet the requirements of the provided data. In the example of Fig. 10, the distribution control server 10 identifies users who have registered a disease name, test results from tests performed at least once a year, and activity levels three or more times a month during the target period (January 1, 2019 to December 31, 2020).

[0106] The distribution control server 10 refers to the location information database and identifies the service provider that holds the target data (provided data) for the identified user. In the above example, Hospital A and Hospital B that hold the disease name and test results, and Fitness Club C that holds the activity amount are identified.

[0107] The distribution control server 10 stores the identified user, the data ID of the data to be provided, the identified service provider, and the provision application ID in association with each other.

[0108] The distribution control server 10 notifies the transaction server 40 of information about the identified data provider. Specifically, the distribution control server 10 transmits a "provider notification" including the data provision application ID, the name of the identified data provider, contact information (the address of the service server 20), the type of data stored by the data provider, etc. to the transaction server 40 (step S23). In the above example, the transaction server 40 is notified that Hospital A and Hospital B store the disease names and test results, and that Fitness Club C stores the activity amounts.

[0109] <Negotiations regarding data provision agreements> When the transaction server 40 receives the provider notification, it requests the service provider identified by the distribution control server 10 to conclude a contract for a data provision application with the data utilization business.

[0110] First, the trading server 40 separates the data provision application for each data provider notified by the provider notification. Specifically, the trading server 40 generates individual data provision contracts (draft data provision contracts) between the data recipient and each data provider.

[0111] In the above example, the trading server 40 generates the data provision contract shown in Figure 12A as a data provision contract for Hospital A, which accumulates user data related to disease names and test results. Similarly, the trading server 40 generates the data provision contract shown in Figure 12B as a data provision contract for Hospital B, which accumulates user data related to disease names and test results. The trading server 40 generates the data provision contract shown in Figure 12C as a data provision contract for Fitness Club C, which accumulates user data related to activity levels.

[0112] 12A to 12C, the data provision contract includes information on the data recipient, information on the data provider, the type of data to be provided, and the price thereof. Note that the data provision contract shown in Figures 12A to 12C may be prepared by the trading server 40 or by an employee of the trading company.

[0113] The transaction server 40 assigns a data provision contract ID to each data provision contract. The transaction server 40 stores the data provision contract and the data provision contract ID in association with each other. The transaction server 40 stores the data provision application ID of the data provision application in association with the data provision contract ID of the data provision contract.

[0114] The transaction server 40 sends a "request for conclusion of a provision contract" including the provision application ID, the individual provision contract ID, and the data provision contract to each contact notified by the distribution control server 10 (for example, the service servers 20 of Hospital A, Hospital B, and Fitness Club C) (step S24).

[0115] In response to receiving the request to conclude a data provision contract, the data provider negotiates with the data recipient (data utilizing business) regarding the provision of data. An employee of the data provider inputs the results of their review of the data provision contract into the service server 20. The service server 20 transmits a response to the request to conclude a data provision contract to the transaction server 40 in accordance with the acquired review results (step S25).

[0116] Specifically, if the employee of the data provider agrees to the conditions set forth in the data provision contract (mainly the proposed compensation for the data provision), he / she inputs this fact into the service server 20. The service server 20 transmits to the transaction server 40 an affirmative response indicating that the employee agrees to the data provision contract (that the data provision contract is concluded).

[0117] If the employee of the data provider does not agree to the conditions set forth in the data provision contract, he / she will input this fact into the service server 20. The service server 20 will then send a negative response to the transaction server 40 indicating that the data provision application will not be accepted (that the data provision contract will not be concluded).

[0118] If a positive response is received (if the data provision contract has been concluded), the trading server 40 stores the fact that the data provision contract has been concluded. The trading server 40 notifies the distribution control server 10 and the data utilization server 30 that the data provision contract has been concluded. Specifically, the trading server 40 transmits an "individual contract conclusion notification" including the provision application ID, the individual provision contract ID, and the data provision contract to the distribution control server 10 and the data utilization server 30 (step S26).

[0119] If a negative response is received (if the data provision contract is not concluded), the trading server 40 notifies the data utilization server 30 that the data provision contract is not concluded. The trading server 40 transmits to the data utilization server 30 a "notice of non-conclusion of individual contract" including the provision application ID, the individual provision contract ID, and the data provision contract (not shown in FIG. 11).

[0120] If the data provision contract is not concluded, the staff of the data utilization business operator will consider whether to withdraw the data provision contract or raise the conditions and apply for the data provision contract again.

[0121] When a data provision contract is to be withdrawn, an employee of the data utilization business operator or the like inputs this into the data utilization server 30. The data utilization server 30 transmits an "individual contract withdrawal notice" including the data provision application ID and the individual data provision contract ID to the trading server 40 (not shown in FIG. 11). The trading server 40 forwards the received individual contract withdrawal notice to the distribution control server 10.

[0122] When renegotiating the data provision contract, an employee of the data utilization business operator inputs a data provision contract with new conditions set out in the data utilization server 30. The data utilization server 30 transmits the new data provision contract to the transaction server 40.

[0123] The transaction server 40 transmits a request for concluding a data provision contract, including a new data provision contract, to the service server 20. The data provider considers the presented new conditions and notifies the data recipient of the consideration results via the transaction server 40. The data provider and the data recipient repeat the price negotiations as described above.

[0124] The following explanation will cover the case where a data provision contract is concluded between Hospital A and the data provider (pharmaceutical company D), no contract is concluded between Hospital B and the data provider, and a contract is concluded between Fitness Club C and the data provider.

[0125] The distribution control server 10, the data utilization server 30, and the transaction server 40 manage data provision contracts that have been concluded and data provision contracts that have not been concluded using a provision contract ID and a provision application ID.

[0126] <Acquisition of user consent> When the distribution control server 10 identifies the data distribution target person, it obtains consent for data distribution from the target person.

[0127] The distribution control server 10 sends an inquiry about data provision to the contact information (an email address that can be received by the terminal 50) of the user identified using the user information database, location information database, etc. (step S27 in FIG. 11).

[0128] The distribution control server 10 is a data provider that holds user data and has concluded a data provision contract with the data recipient, and sends an inquiry about data provision to the identified user. In the above example, an inquiry about data provision is sent regarding user data stored in each of Hospital A and Fitness Club C.

[0129] The data request includes information about the data requester (pharmaceutical company D in the above example), the data provider (hospital A, fitness club C), and the type of data requested (e.g., disease name, test results, activity level).

[0130] The terminal 50, which has received the inquiry about data provision, displays a GUI for acquiring the user's intention regarding data provision. The terminal 50 acquires the user's intention (agreement or disagreement to data provision) using the GUI.

[0131] The terminal 50 transmits a response to the inquiry about the data provision (agreement to the data provision or refusal to provide the data) to the distribution control server 10 (step S28).

[0132] When a user agrees to the data provision, the distribution control server 10 stores this fact. At that time, the distribution control server 10 generates identification information for identifying the user who agreed to the data provision. More specifically, the distribution control server 10 generates a different target ID (ID that identifies the individual who agreed to the data provision) for each data provision application. The distribution control server 10 associates the provision application ID, target ID, and user ID and stores them in a consent management database. The consent management database will be described in detail later.

[0133] The distribution control server 10 sends the data provision inquiry to the target user's terminal 50 periodically or at a predetermined timing until consent is obtained from at least the required number of people specified in the data provision application. For example, the distribution control server 10 sends a data provision inquiry to a user who has refused data provision after a predetermined number of days have passed.

[0134] In this way, the trading server 40 transmits a request for provision including a data provision application to the distribution control server 10. The distribution control server 10 transmits a data provision inquiry to the terminal 50 held by the user corresponding to the data that meets the specified requirements. By transmitting the data provision inquiry to the terminal 50, the distribution control server 10 obtains consent (consent to data provision) from the user who contributed to the generation of the user data that the data utilization business operator wishes to provide.

[0135] When the user agrees to the provision of data, the distribution control server 10 calculates the amount of data to be provided with the user's consent. The distribution control server 10 refers to the location information database to determine the amount of data to be provided with the user's consent.

[0136] For example, when one user agrees to provide data, data will be provided for each data type, such as one disease name, 10 test results, and 100 activity levels.

[0137] Every time the user's consent is obtained, the distribution control server 10 notifies the trading server 40 of the calculated data volume. The distribution control server 10 transmits a "notification of data volume to be provided" including the provision application ID and the calculated data volume to the trading server 40 (step S31 in FIG. 13).

[0138] The trading server 40 generates "data provision status information" that indicates the status of data provision. The trading server 40 generates data provision status information for each data provision application. Using the data provision status information, the trading server 40 manages the amount of data for each data type provided to the data recipient, and the consideration (total consideration) that the data recipient will pay when data provision is established.

[0139] For example, upon receiving a notification of the amount of data provided, the trading server 40 calculates and graphs the amount of data (accumulation amount) for each data type. Similarly, the trading server 40 graphs the fee paid by the data recipient. For example, the trading server 40 creates a time-series graph as shown in FIG. 14 as data provision status information.

[0140] The trading server 40 transmits the generated data provision status information (for example, a graph as shown in FIG. 14) to the data utilization server 30 periodically or at a predetermined timing (not shown in FIG. 13).

[0141] In this way, when the user agrees to the data provision, the distribution control server 10 notifies the trading server 40 of the amount of data that can be provided from the service server 20 to the data utilization server 30, which is generated based on the user's consent. The trading server 40 generates data provision status information that indicates the status of the data provision application, based on the amount of data that can be provided from the service server 20 to the data utilization server 30, which is received from the distribution control server 10. The trading server 40 transmits the generated data provision status information to the data utilization server 30.

[0142] <Cancellation of data provision application> A data utilization business can cancel a data provision application (and all data provision contracts derived from the data provision application). An employee of the data utilization business can decide whether to cancel or continue the data provision application while checking the data provision status information obtained from the transaction server 40. That is, a data utilization business can refer to a time series graph (data provision status information) such as that shown in Figure 14 and decide whether to continue or cancel the data provision contract.

[0143] However, data utilization businesses cannot cancel data provision applications unconditionally. Data utilization businesses cannot cancel data provision applications if the requirements for the data provided in the data provision application to be canceled are met.

[0144] Specifically, if a portion of the target data does not meet the minimum required data volume, the data recipient can cancel the data provision application regardless of the deadline of the data provision contract. In other words, the data utilization business (data recipient) can cancel the data provision application at any time, regardless of the deadline for data provision, if at least one of the data specified in the requirements for the data to be provided is not available.

[0145] On the other hand, if all of the target data meets the minimum required data volume, the data recipient cannot cancel the data provision application regardless of the deadline for the data provision application. In other words, if the requirements for the data provided that the data utilization business operator applied for are met, the data provision application cannot be canceled regardless of the deadline for the data provision application.

[0146] This approach means that data recipients will not have to pay for the data they need even if they are unable to obtain it. As a result, data recipients will be protected. Furthermore, once the necessary data is secured, the data provider will not have the data provision contract canceled. As a result, data recipients will be protected.

[0147] A data utilization business operator who wishes to cancel a data provision application inputs this into the data utilization server 30. When the data utilization server 30 receives the request to cancel the data provision application, it notifies the transaction server 40 of this. The data utilization server 30 sends a "provision application cancellation request" including the data provision application ID to the transaction server 40 (step S32 in FIG. 13).

[0148] Upon receiving the request to cancel the data provision application, the transaction server 40 checks the status of the data provision application and determines whether the data provision application can be canceled. The transaction server 40 transmits a response according to the determination result to the data utilization server 30 (step S33).

[0149] If the status of the data provision application is in a state where cancellation is possible, the trading server 40 transmits an affirmative response to the effect that cancellation of the data provision application is accepted to the data utilization server 30. If the status of the data provision application is in a state where cancellation is not possible, the trading server 40 transmits a negative response to the data utilization server 30 to the effect that cancellation of the data provision application is not accepted.

[0150] When the transaction server 40 receives the cancellation of the data provision application, it notifies the distribution control server 10 of this (not shown in FIG. 13). The distribution control server 10 discards information and the like related to the data provision application for which the cancellation has been notified.

[0151] In this way, the transaction server 40 rejects a request to cancel a data provision application when data that meets predetermined requirements (requirements for provided data) becomes available to be provided from the service server 20 to the data utilization server 30. The predetermined requirements include the data type and lower limit of the required data amount for each type of provided data that is provided from the service server 20 to the data utilization server 30. The transaction server 40 rejects a request to cancel a data provision application when the amount of data that can be provided from the service server 20 to the data utilization server 30 for each data type of provided data exceeds the lower limit of the required data amount.

[0152] <Data provision execution> The trading server 40 executes the data provision when predetermined conditions are met. When predetermined conditions are met, the trading server 40 instructs the distribution control server 10 to execute the data provision. When predetermined conditions are not met, the trading server 40 may discard the data provision application.

[0153] For example, the transaction server 40 executes the data provision if the deadline stated in the data provision application has arrived and the requirements for the data to be provided stated in the data provision application have been met.

[0154] When the deadline for data provision applications arrives and the amount of data that can be provided from the service server 20 to the data utilization server 30 for each data type of provided data exceeds the lower limit of the required data amount, the transaction server 40 instructs the execution of data provision.

[0155] In other words, it is determined that the data provision requirements are met when data equal to or greater than the minimum required data amount can be provided for all of the target data described in the data provision application. In the example of Figure 10, it is determined that the data provision requirements are met when data on five or more disease names, twenty or more test results, and one thousand or more activity amounts can be provided.

[0156] In this case, the transaction server 40 transmits a "data provision execution instruction" including the supply application ID to the distribution control server 10 (see FIG. 15).

[0157] Upon receiving the data provision execution instruction, the distribution control server 10 transmits a provision instruction to the data provider for the users who have given consent to the data provision (step S29 in FIG. 11).

[0158] At that time, the distribution control server 10 transmits a provision instruction including the subject ID stored in the consent management database to the data provider. The distribution control server 10 instructs the service server 20 to replace the personal identification ID managed independently by each data provider with the subject ID and provide the data.

[0159] For example, if consent has been obtained from 10 users, the distribution control server 10 transmits a provision instruction to the service server 20 regarding the data of those 10 people. For example, the distribution control server 10 transmits a provision instruction to the service server 20 of Hospital A to provide the disease names and test results of 10 people. Similarly, the distribution control server 10 transmits a provision instruction to the service server 20 of Fitness Club C to provide the activity amounts of 10 people.

[0160] In this way, when data that satisfies predetermined requirements (data to be provided) is stored in multiple service servers 20, the distribution control server 10 transmits a provision instruction including the same target person ID to each of the multiple service servers 20.

[0161] Upon receiving the provision instruction, the service server 20 refers to the customer information database and transmits the user data of the consenting user to the designated data destination (step S30).

[0162] At that time, the service server 20, which is the data provider, transmits the target ID notified by the distribution control server 10 to the data recipient together with the user data. The service server 20 replaces the personal identification ID of the data distribution target with the target ID specified by the distribution control server 10, and provides the data.

[0163] The data utilization server 30 of the data provider (data utilization business operator) associates the user data received from each service server 20 based on the target person ID received from that service server 20. The data utilization server 30 uses the target person ID to perform name matching of the user data.

[0164] In this way, the transaction server 40 transmits the data provision application to the distribution control server 10. The distribution control server 10 transmits a provision instruction to the service server 20, which includes information specifying data that meets predetermined requirements (for example, a data ID) and a target ID that is the user's ID and is generated in response to the data provision application. The service server 20 transmits the specified data and the target ID to the data utilization server 30.

[0165] If the deadline stated in the data provision application has arrived but the requirements for the data to be provided have not been met, the transaction server 40 will cancel the data provision contract. In this case, the transaction server 40 notifies the distribution control server 10 and the data utilization server 30 of this fact.

[0166] Alternatively, the transaction server 40 may provide data based on the budget of the data provision request.

[0167] The transaction server 40 executes the data provision if the total amount of consideration paid by the data utilization business to the service business exceeds the budget and the requirements for the data to be provided as stated in the data provision application are met.

[0168] Specifically, if the user agrees to the data provision and the price to be paid by the data recipient exceeds the budget stated in the data provision application, and the requirements for the data to be provided stated in the data provision application are met, the trading server 40 will instruct the data to be provided.

[0169] On the other hand, if the price paid by the data provider exceeds the budget stated in the data provision application but the requirements for the data to be provided stated in the data provision application are not met, the transaction server 40 discards the data provision application.

[0170] Alternatively, the trading server 40 may provide data if at least one of the target data exceeds the upper limit of the required data amount and the requirements for the provided data described in the data provision application are met. That is, the trading server 40 provides data if, for at least one data type of the provided data, the amount of data that can be provided from the service server 20 to the data utilization server 30 exceeds the upper limit of the required data amount and the requirements for the provided data are met.

[0171] On the other hand, the trading server 40 may discard the data provision request if at least one of the target data exceeds the upper limit of the required data amount but does not satisfy the requirements for the data to be provided set forth in the data provision request.

[0172] In this way, the transaction server 40 decides whether to provide or discard the data when the deadline arrives, when the price paid by the data recipient exceeds the budget, when at least one of the target data exceeds the upper limit of the number of required data items, etc.

[0173] Next, each device included in the information distribution system according to the first embodiment will be described in detail.

[0174] [Distribution control server] 16 is a diagram showing an example of a processing configuration (processing module) of the distribution control server 10 according to the first embodiment. Referring to FIG. 16, the distribution control server 10 includes a communication control unit 201, a user registration unit 202, an ID linking unit 203, a location information management unit 204, a data distribution control unit 205, a catalog information management unit 206, and a storage unit 207.

[0175] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the service server 20. The communication control unit 201 also transmits data to the service server 20. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0176] The user registration unit 202 is a means for realizing the above-mentioned user registration (system registration of a user). The user registration unit 202 acquires personal information (such as name, date of birth, contact information, and account information) from the user's terminal 50.

[0177] When the user registration unit 202 acquires the personal information, it generates a user ID for identifying the user. For example, the user registration unit 202 assigns a unique number each time a user registers in the system, and uses the assigned number as the user ID.

[0178] The user registration unit 202 stores the user ID and personal information in a user information database (see FIG. 17). As shown in FIG. 17, the user information database stores the user ID, personal information, and a personal identification ID for each service provider in association with each other. The user information database shown in FIG. 17 is an example and is not intended to limit the items to be stored. For example, the date and time of user registration may also be registered in the user information database.

[0179] The user registration unit 202 transmits the generated user ID to the terminal 50.

[0180] The ID federation unit 203 is a means for realizing the above-mentioned ID federation. The ID federation unit 203 receives an "ID federation request" from a terminal of a service provider (for example, a hospital terminal 60) or the service server 20. The ID federation request includes personal identification information, a personal identification ID, and a business code of a user who desires ID federation (registration with a service provider).

[0181] The ID linking unit 203 searches the user information database using personal identification information (such as the user's name or a combination of the name and date of birth) as a key to identify the corresponding user. The ID linking unit 203 sets the personal identification ID included in the ID linking request in a field corresponding to the business code among the personal identification ID fields of the identified user. That is, the ID linking unit 203 identifies the user registered in the system account from the personal identification information, and associates the service provider with the personal identification ID in the account of the identified user.

[0182] The location information management unit 204 is a means for managing location information acquired from service providers. The location information management unit 204 controls data accumulation for registering user data generated by service providers providing services to users in the information distribution system as data that can be provided to third parties.

[0183] The location information management unit 204 stores the location information acquired from each service server 20 in a location information database (see FIG. 18). As shown in FIG. 18, the location information database stores a personal identification ID, a business code, a data ID, a data type, a data accumulation date, and the like in association with each other.

[0184] Note that the location information database shown in Fig. 18 is an example and is not intended to limit the items to be stored, etc. Also, in the drawings including Fig. 18, for ease of understanding, the business code is expressed using the name of the service business.

[0185] The data distribution control unit 205 is a means for controlling data distribution by "sharing" or "provision."

[0186] First, data distribution related to "sharing" will be explained.

[0187] The data distribution control unit 205 receives a sharing request from the service server 20. The sharing request includes the personal identification ID of the user who is the target of data acquisition, the business code of the sender of the sharing request, and the type of data desired to be acquired. In the example of Fig. 7, the sharing request includes the personal identification ID generated for the user by EC business B (service server 20-2), the business code of EC business B, and the data type "disease name."

[0188] The data distribution control unit 205 identifies the target person for data distribution based on the personal identification ID and business code included in the sharing request. Specifically, the data distribution control unit 205 identifies the target person by referring to the user information database shown in Fig. 17. In the above example, when a sharing request including the personal identification ID "EC01" is received from EC business B, the data distribution control unit 205 determines from the entry in the first row shown in Fig. 17 that user U1 is the target person for data distribution.

[0189] The data distribution control unit 205 then identifies a service provider that stores the required data using the identified user's personal identification ID and the data type included in the sharing request. Specifically, the data distribution control unit 205 refers to the location information database shown in Fig. 18 and identifies a service provider that stores data corresponding to the data type included in the sharing request. In the above example, Hospital A is identified based on user U1's personal identification ID "HL01" and the data type "disease name" included in the sharing request.

[0190] If the combination of the user's personal identification ID and the data type included in the sharing request is not stored in the location information database, the data distribution control unit 205 sends a negative response to the sender of the sharing request, indicating that the data cannot be shared. In the above example, if the combination of user U1's personal identification ID "HL01" and the data type "disease name" is not registered in the location information database, a negative response is sent to EC business operator B (service server 20-2).

[0191] Once the target of data distribution and the accumulator of the data to be distributed are identified, the data distribution control unit 205 inquires about data sharing from the target of data distribution. Specifically, the data distribution control unit 205 sends an inquiry about data sharing to the contact information of the target of data distribution. In the above example, the inquiry is sent to the terminal 50 owned by user U1.

[0192] The data sharing inquiry includes information such as the requester of the data sharing, the data accumulator, the type of data to be shared, etc. In the above example, the requester of the data sharing is set to E-commerce business operator B, the data accumulator is set to Hospital A, and the type of data to be shared is set to "disease name."

[0193] The data distribution control unit 205 receives a response to the data sharing inquiry from the terminal 50 .

[0194] If the user refuses to share the data, the data distribution control unit 205 notifies the data sharing request source that the data cannot be shared. In the above example, the data distribution control unit 205 transmits a negative response to the sharing request to the service server 20-2 of the EC business operator B.

[0195] If the user agrees to data sharing, the data distribution control unit 205 transmits a sharing instruction to the data accumulator. In the above example, the sharing instruction is transmitted to the service server 20-1 of Hospital A, which is the data accumulator.

[0196] The sharing instruction includes the personal identification ID generated by the data accumulator, information about the data sharing destination, and the data type to be shared. In the above example, a sharing instruction including the personal identification ID "HL01" of user U1, the address of service server 20-2 of EC business B, and the data type "disease name" is sent to service server 20-1 of Hospital A.

[0197] In this way, the data distribution control unit 205 transmits a sharing instruction including the personal identification ID of the user (target person) who has agreed to data sharing, which is generated by the data accumulator.

[0198] Next, data distribution related to "provision" will be explained.

[0199] The data distribution control unit 205 receives a "provision request" from the transaction server 40. The provision request includes a provision application ID, a data provision application, and a list of account holders.

[0200] The data distribution control unit 205 identifies a data provider (service operator) that holds user data that meets the requirements for the data to be provided described in the data provision application. The data distribution control unit 205 refers to the user information database and the location information database to identify a data provider that holds data of a user (target person) that meets the requirements described in the data provision application.

[0201] In the example of FIG. 10, the data distribution control unit 205 refers to the user information database and identifies users aged between 20 and 65 who are listed on the account holder list.

[0202] Thereafter, the data distribution control unit 205 refers to the location information database and identifies, from among the identified users, subjects who further meet the requirements of the provided data. In the example of Fig. 10, the data distribution control unit 205 identifies users who have registered disease names, test results from tests performed at least once a year, and activity amounts three or more times a month during the target period (January 1, 2019 to December 31, 2020).

[0203] The data distribution control unit 205 refers to the location information database and identifies the service provider that holds the target data (provided data) for the identified user.

[0204] In the example of FIG. 18, if user U1 with personal identification ID "HL01" corresponds to the identified user, the data distribution control unit 205 identifies hospital A that holds the disease name and test results.

[0205] Furthermore, if user U1 visits Hospital B and the disease name and test results are registered in the location information database as data to be provided, the data distribution control unit 205 identifies Hospital B that holds the disease name and test results.

[0206] Similarly, if the user with the personal identification ID "FC01" is user U1 and corresponds to the identified user, the data distribution control unit 205 identifies fitness club C that holds the activity amount.

[0207] The data distribution control unit 205 stores the user ID of the identified user, the data ID of the target data for each identified user, the business code of the identified service business, and the provision application ID in association with each other.

[0208] The data distribution control unit 205 notifies the transaction server 40 of information about the identified data provider. Specifically, the distribution control server 10 transmits to the transaction server 40 a "provider notification" including the supply application ID, the name of the identified data provider, contact information (the address of the service server 20), the type of data stored by the data provider, etc.

[0209] The data distribution control unit 205 refers to table information that stores the business code of the data provider, the name of the data provider, contact information, etc., which have been previously input into the distribution control server 10 by an employee of the information distribution business, and obtains information about the data provider.

[0210] The data distribution control unit 205 receives an "individual contract establishment notification" or an "individual contract withdrawal notification" from the transaction server 40. The data distribution control unit 205 manages the establishment or non-establishment of individual data provision contracts (contracts for each data provision destination) based on the provision contract ID contained in these notifications.

[0211] When a data provision contract is established, the data distribution control unit 205 performs control to obtain consent from the subject for the data provision. The data distribution control unit 205 sends an inquiry regarding the data provision to the user's contact information (an email address that can be received by the terminal 50) identified using a user information database, a location information database, etc.

[0212] Specifically, the data distribution control unit 205 makes an inquiry about data provision to the identified user regarding the data provider with whom the data provision contract has been established. In the above example, a data provision contract has been established between Hospital A and Pharmaceutical Company D, and a data provision contract has been established between Fitness Club C and Pharmaceutical Company D. Therefore, the data distribution control unit 205 sends an inquiry about data provision regarding the user data held by Hospital A and Fitness Club C to the terminal 50 of the data distribution target.

[0213] A data request includes information about the source of the data request (pharmaceutical company D in the above example), the source of the data (hospital A, fitness club C), and the type of data requested (e.g., disease name, test results, etc.).

[0214] The data distribution control unit 205 receives a response to the inquiry about the provision of data from the terminal 50. If the user does not agree to the provision of data, the data distribution control unit 205 does not take any special action.

[0215] When a user agrees to the data provision, the data distribution control unit 205 generates a target ID for each data provision application to identify the user who agreed to the data provision. For example, the data distribution control unit 205 calculates a concatenation value of the provision application ID of the data provision application and the user ID of the user who agreed to the data provision. The data distribution control unit 205 generates a hash value of the calculated concatenation value as the target ID.

[0216] The data distribution control unit 205 associates the provision application ID, the target ID of the user who agreed to the data provision, and the user ID and stores them in the consent management database (see FIG. 19). Note that the consent management database shown in FIG. 19 is an example and is not intended to limit the items to be stored.

[0217] Referring to Figure 19, two users have agreed to the data provision application for "PID01." In addition, a user with user ID "ID11" has agreed to two data provision applications for "PID01" and "PID02." The users in question have been assigned different target IDs.

[0218] Furthermore, when the user agrees to the provision of data, the data distribution control unit 205 calculates the amount of data to be provided with the user's consent.

[0219] If the user agrees to the provision of user data held by Hospital A, the amount of data accumulated during the period covered by the data provision application is calculated, such as one disease name and three test results. Specifically, the data distribution control unit 205 refers to the location information database and counts the amount of user data (disease name, test results) of the user accumulated by the data provider during the period covered.

[0220] Every time the user's consent is obtained, the data distribution control unit 205 notifies the trading server 40 of the calculated data volume. The distribution control server 10 transmits to the trading server 40 a "notification of data volume to be provided" including the provision application ID and the calculated data volume (volume of data for each data type).

[0221] The data distribution control unit 205 sends the data provision inquiry to the target person's terminal 50 periodically or at a predetermined timing until consent is obtained from the required number of people described in the data provision application.

[0222] The data distribution control unit 205 receives a “data provision execution instruction” from the transaction server 40 .

[0223] When receiving the data provision execution instruction, the data distribution control unit 205 transmits a provision instruction to each data provider for users who have consented to the data provision. For example, if consent to the data provision has been obtained from 10 users, the data distribution control unit 205 transmits a provision instruction to each service server 20 for the 10 users.

[0224] The provision instruction includes the personal identification ID of the user who has agreed to the data provision, the target ID, information on the data destination (for example, the business name, business code, and address of the data utilization server 30), and information for identifying (designating) the provided data. The information for identifying the provided data may be a data ID or a combination of the period for which the provided data has been accumulated and the data type.

[0225] Note that a target ID is generated for each data provision application. Therefore, even if the provision instructions are sent to different service servers 20, the same target ID is included in provision instructions resulting from the same data provision application. In the above example, the provision instructions sent to Hospital A and Fitness Club C (provision instructions related to the same user) include the same target ID.

[0226] The data distribution control unit 205 obtains consent from the user to data provision from a service provider that has concluded a data provision contract with the data utilization business. The data distribution control unit 205 transmits a provision instruction to the service server 20 of the service provider that has concluded a data provision contract with the data utilization business and with whom the user has agreed to data provision.

[0227] The catalog information management unit 206 is a means for managing catalog information, and stores the catalog information created by the system administrator in the storage unit 207.

[0228] The catalog information management unit 206 receives a "catalog information transmission request" from the transaction server 40. In response to the reception of the request, the catalog information management unit 206 transmits the catalog information stored in the storage unit 207 to the transaction server 40.

[0229] The storage unit 207 stores information necessary for the operation of the distribution control server 10. In the storage unit 207, a user information database and the like are constructed.

[0230] [Service Server] 20 is a diagram showing an example of a processing configuration (processing module) of the service server 20 according to the first embodiment. Referring to FIG. 20, the service server 20 includes a communication control unit 301, an ID linkage control unit 302, a data distribution request unit 303, a data storage control unit 304, a data distribution unit 305, a contract conclusion control unit 306, and a storage unit 307.

[0231] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the distribution control server 10. The communication control unit 301 also transmits data to the distribution control server 10. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0232] The ID federation control unit 302 is a means for controlling ID federation of users. The ID federation control unit 302 acquires a request for ID federation from a user who is logged in to an account using a GUI (Graphical User Interface) or the like. In response to the request from the user, the ID federation control unit 302 transmits an "ID federation request" including personal identification information (such as the name of the logged-in user), a personal identification ID (such as the user's membership number), and a business code to the distribution control server 10.

[0233] The user's personal identification ID, personal specification information, user data, etc. are managed using a customer information database (see FIG. 21). As shown in FIG. 21, the customer information database holds information (flag) indicating whether or not ID federation for the user has been completed. Upon completing ID federation, the ID federation control unit 302 sets a flag in the ID federation status field for the corresponding user (a circle is set in FIG. 21).

[0234] The data distribution request unit 303 is a means for requesting data distribution (data sharing) of user data to an information distribution business operator. The data distribution request unit 303 transmits a sharing request to the distribution control server 10 in response to an operation by a service provider employee or the like. Specifically, the data distribution request unit 303 transmits a sharing request to the distribution control server 10, which includes the personal identification ID of the user who is the target of data acquisition, the business code of the user's own device, and the type of data desired to be acquired.

[0235] The data storage control unit 304 is a means for controlling the storage of user data generated as a result of providing a service to a user. The data storage control unit 304 associates the user's personal identification ID with the user's user data (data generated as a result of providing a service to the user or data necessary for the service to be provided to the user) and stores them in a customer information database.

[0236] As shown in Fig. 21, the data storage control unit 304 stores user data in a field corresponding to the type of data generated (stores specific data content). At that time, the data storage control unit 304 generates a data ID for identifying the user data and stores it in association with the user data and the data storage date. Note that Fig. 21 shows an example of a customer information database constructed in the service server 20 of Hospital A.

[0237] Here, for users for whom ID federation has been completed, the data storage control unit 304 transmits location information to the distribution control server 10 each time user data is stored in the customer information database. For example, consider a case where a service is provided to a user with a personal identification ID "HL01" and data on a disease name is generated as a result of a medical examination. In this case, location information including the personal identification ID "HL01", the business code "Hospital A", the data ID "HLD01", and the data type "Disease Name" is transmitted to the distribution control server 10.

[0238] The data distribution unit 305 is a means for realizing data distribution by “sharing” or “provision.” The data distribution unit 305 processes a “sharing instruction” or a “provision instruction” received from the distribution control server 10.

[0239] When a sharing instruction is received, the data distribution unit 305 refers to the customer information database and identifies an entry corresponding to the personal identification ID and data type included in the sharing instruction. For example, when a sharing instruction including the personal identification ID "HL01" and the data type "disease name" is received, the data distribution unit 305 identifies the entry shown in the top row of Fig. 21.

[0240] The data distribution unit 305 transmits the user data described in the corresponding data type field of the identified entry to the data sharing destination specified in the sharing instruction. In the examples of Figures 7 and 21, "stomach cancer" is transmitted to the service server 20-2 of the EC business operator B.

[0241] When a provision instruction is received, the data distribution unit 305 identifies the target data for data provision based on the data ID included in the provision instruction. The data distribution unit 305 transmits the user data described in the corresponding data type field of the identified entry to the data destination specified in the provision instruction.

[0242] At this time, the data distribution unit 305 transmits the target user ID included in the provision instruction together with the user data to the data destination specified in the provision instruction.

[0243] Alternatively, the data distribution unit 305 may transmit user data determined by the personal identification ID, data accumulation period, and data type included in the provision instruction to a data destination specified by the provision instruction.

[0244] When transmitting shared data based on a sharing instruction, the data distribution unit 305 may transmit the user's personal identification information (such as name) to the destination service server 20. The data distribution unit 305 may also assign an ID to the provided data so that the business operator receiving the provided data can associate the data with the acquired data. For example, the data distribution unit 305 may calculate a hash value of the user's personal identification information and transmit the hash value as the user's ID to the data distribution destination.

[0245] The contract conclusion control unit 306 is a means for controlling the data provision contract. The contract conclusion control unit 306 processes a data provision contract conclusion request received from the transaction server 40. Upon receiving the request, the contract conclusion control unit 306 presents the contents of the request to a staff member or the like of the service provider.

[0246] 12A to 12C and decides whether to enter into the data provision contract. The contract entry control unit 306 acquires the content of the decision made by the staff member (whether to enter into or reject the data provision contract) using a GUI or the like.

[0247] If a data provision contract is concluded, the contract conclusion control unit 306 transmits an affirmative response to the transaction server 40 indicating that the data provision contract is to be concluded.

[0248] If the data provision contract is rejected, the contract conclusion control unit 306 transmits a negative response to the transaction server 40 indicating that the data provision contract will not be concluded.

[0249] The storage unit 307 stores information necessary for the operation of the service server 20 .

[0250] [Data Utilization Server] The data utilization server 30 presents information to the user (such as an employee of the data utilization business operator) and accepts operations from the user. Specifically, the data distribution request unit 303 displays a list of catalog information acquired from the transaction server 40, and transmits a data provision application entered by the user to the transaction server 40.

[0251] The data utilization server 30 processes various notifications received from the transaction server 40. Specifically, when the data utilization server 30 is notified that the data provision contract has not been concluded, it notifies the staff of the data utilization business operator of this fact. In this case, the data utilization server 30 receives instructions from the staff to enter into a new data provision contract or to cancel the data provision application. The data utilization server 30 transmits the new data provision contract or a notice of withdrawal of the individual contract to the transaction server 40.

[0252] Furthermore, if the data utilization business operator indicates an intention to cancel the data provision application, the data utilization server 30 transmits a provision application cancellation request to the transaction server 40.

[0253] When utilizing user data acquired through data provision, the data utilization server 30 associates the user data received from each service server 20 based on the target person ID received from each service server 20. The data utilization server 30 performs name matching of the user data using the target person ID.

[0254] [Trade Server] 22 is a diagram showing an example of a processing configuration (processing module) of the trading server 40 according to the first embodiment. Referring to FIG. 22, the trading server 40 includes a communication control unit 401, an account opening unit 402, a catalog information request unit 403, a provision contract control unit 404, and a storage unit 405.

[0255] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the distribution control server 10. The communication control unit 401 also transmits data to the distribution control server 10. The communication control unit 401 hands over data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 401. The communication control unit 401 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0256] The account opening unit 402 is a means for opening an account for a user who wishes to distribute data through provision. The account opening unit 402 acquires a user ID from the user's terminal 50. The account opening unit 402 adds the acquired user ID to a list of account holders (see FIG. 23).

[0257] The catalog information request unit 403 is a means for transmitting a “catalog information transmission request” to the distribution control server 10 .

[0258] When the catalog information request unit 403 receives a “catalog information presentation request” from the data utilization server 30 , it transmits a “catalog information transmission request” to the distribution control server 10 .

[0259] In response to sending the request, the catalog information requesting unit 403 acquires catalog information stored in the distribution control server 10. The catalog information requesting unit 403 selects catalog information related to the service provider with which the device is affiliated, and transmits it to the data utilization business (data utilization server 30). The catalog information requesting unit 403 selects catalog information related to the affiliated service business based on the business code of the affiliated service business and the business code included in the catalog information.

[0260] The data provision contract control unit 404 is a means for controlling the data provision contract. The data provision contract control unit 404 processes the data provision application received from the data utilization server 30.

[0261] When a data provision application is received, the data provision contract control unit 404 assigns a data provision application ID to the received data provision application. The data provision contract control unit 404 manages the data provision application using the data provision application ID.

[0262] The data provision contract control unit 404 transmits to the distribution control server 10 a "data provision request" including the data provision application ID, the data provision application, and the account holder list.

[0263] The data provision contract control unit 404 receives a provider notification from the distribution control server 10. The provider notification includes a data provision application ID, the name of the data provider that stores the data to be provided, contact information (the address of the service server 20), the data type, etc.

[0264] Upon receiving the provider notification, the data provision contract control unit 404 separates the data provision application into individual contracts (individual contract proposals) for each data provider. Specifically, the data provision contract control unit 404 generates one data provision contract for data providers that share the notified data type.

[0265] In the above example, the disease name and test results are held in Hospital A and Hospital B, respectively, so the data provision contract control unit 404 generates a data provision contract for Hospital A and a data provision contract for Hospital B. In addition, the activity amount is held in Fitness Club C, so the data provision contract control unit 404 generates a data provision contract for Fitness Club C.

[0266] Alternatively, an individual data provision contract may be generated by an employee of the trading business. The data provision contract control unit 404 presents the content of the provider notification to the employee. The data provision contract control unit 404 acquires the data provision contract generated by the employee using a GUI or the like.

[0267] The data provision contract control unit 404 assigns a data provision contract ID to the generated data provision contract. The transaction server 40 stores the data provision application ID, data provision contract ID, and data provision contract in association with each other.

[0268] When an individual contract for each data provider (data accumulator) is generated, the data provision contract control unit 404 requests each data provider to conclude a data provision contract. Specifically, the data provision contract control unit 404 sends a "data provision contract conclusion request" including the data provision application ID, the individual data provision contract ID, and the data provision contract to each contact point (service server 20) notified by the distribution control server 10.

[0269] The provider contract control unit 404 receives a response to the provider contract conclusion request from the service server 20 .

[0270] When a positive response (a response indicating that the data provider agrees to the data provision contract) is received, the provision contract control unit 404 stores the provision contract ID of the established data provision contract. Furthermore, the provision contract control unit 404 notifies the distribution control server 10 and the data utilization server 30 that the data provision contract has been established. The provision contract control unit 404 transmits an "individual contract establishment notification" including the provision application ID, provision contract ID, and data provision contract to the distribution control server 10 and the data utilization server 30.

[0271] If a negative response (a response indicating that the data provider does not agree to the data provision contract) is received, the provision contract control unit 404 notifies the data utilization server 30 that the data provision contract has not been established. Specifically, the provision contract control unit 404 transmits to the data utilization server 30 a notification of non-establishment of the individual contract, including the provision application ID, the provision contract ID, and the data provision contract.

[0272] In this case, the provision contract control unit 404 receives from the data utilization server 30 a new data provision contract (a data provision contract with revised conditions) or a notice of withdrawal of the individual contract.

[0273] When a new data provision contract is received, the provision contract control unit 404 transmits a provision contract conclusion request including the new data provision contract to the service server 20 that is the data provider.

[0274] When the individual contract withdrawal notice is received, the provision contract control unit 404 transfers the received individual contract withdrawal notice to the distribution control server 10 .

[0275] The provision contract control unit 404 controls the cancellation of a data provision application from a data utilization business operator.

[0276] The provision contract control unit 404 receives a “provision application cancellation request” including the provision application ID from the data utilization server 30.

[0277] When receiving the data provision application cancellation request, the data provision contract control unit 404 checks the status of the data provision contract and determines whether the data provision application can be canceled.

[0278] If the requirements for the provided data in the data provision application are met, the data provision contract control unit 404 determines that the data provision application cannot be canceled.If the requirements for the provided data in the data provision application are not met, the data provision contract control unit 404 determines that the data provision application can be canceled.

[0279] Specifically, if the data volume of a portion of the target data does not exceed the minimum required data volume, the data provision application is determined to be cancelable regardless of the deadline for the data provision application. Conversely, if the data volume of all of the target data exceeds the minimum required data volume, the data provision application is determined to be non-cancellable regardless of the deadline for the data provision contract.

[0280] If the data provision status is such that cancellation is permitted, the provision contract control unit 404 transmits an affirmative response to the effect that cancellation of the data provision application is accepted to the data utilization server 30. If the data provision status is such that cancellation is not permitted, the provision contract control unit 404 transmits a negative response to the data utilization server 30 to the effect that cancellation of the data provision application is not accepted.

[0281] Moreover, when the data provision application is cancelled, the data provision contract control unit 404 notifies the distribution control server 10 of this fact.

[0282] The data provision contract control unit 404 controls the execution of data provision. The data provision contract control unit 404 executes data provision when predetermined conditions are met. The data provision contract control unit 404 has an automatic closing function that automatically closes the data provision contract when predetermined conditions are met.

[0283] Specifically, if the deadline stated in the data provision application has arrived and the requirements for the data to be provided stated in the data provision application have been met, the provision contract control unit 404 instructs the distribution control server 10 to carry out the data provision.

[0284] Alternatively, the data provision contract control unit 404 may execute the data provision based on the budget of the data provision application. Specifically, the data provision contract control unit 404 executes the data provision application if the price paid by the data provision destination when the user agrees to the data provision exceeds the budget stated in the data provision application and the requirements for the data to be provided stated in the data provision application are satisfied.

[0285] Alternatively, the data provision contract control unit 404 may provide data if at least one of the target data exceeds the upper limit of the required data amount and the requirements for the data to be provided described in the data provision application are met.

[0286] When executing the data provision, the data provision contract control unit 404 transmits a “data provision execution instruction” including the data provision application ID to the distribution control server 10 .

[0287] The data provision contract control unit 404 manages the status of the data provision application. The data provision contract control unit 404 processes the “notification of the amount of data to be provided” received from the distribution control server 10.

[0288] The provision contract control unit 404 identifies the data provision application for which the distribution control server 10 has obtained the user's consent, based on the provision application ID included in the provision data amount notification. The provision contract control unit 404 reflects the data amount notified in the provision data amount notification in the data amount of the provided data being managed. The provision contract control unit 404 adds the data amount notified in the provision data amount notification to the parameter that manages the amount of data that can be provided, for each type of provided data.

[0289] The data provision contract control unit 404 calculates the price to be paid by the data recipient based on the price stated in the data provision contract (price agreed upon by the parties) and the type of data and amount of data to be provided agreed upon by the user.

[0290] 12A, if the user agrees to the provision of one disease name and three test results, the fee to be paid by the data recipient in response to that agreement is calculated as 10 yen + 6 (2 × 3) yen = 16 yen. The data provision contract control unit 404 calculates the total amount of fee to be paid by the data recipient by adding the fee arising from the user's agreement to the fee already calculated.

[0291] In response to receiving the notification of the amount of data provided, the data provision contract control unit 404 generates "data provision status information" including the amount of data (accumulated amount) of the provided data for each data type and the total amount of payment to be made by the data recipient. Alternatively, the data provision status information may be a graph visualizing the amount of data and the total amount to be paid.

[0292] The data provision contract control unit 404 transmits the generated data provision status information (for example, a graph as shown in FIG. 14) to the data utilization server 30 periodically or at a predetermined timing.

[0293] The storage unit 405 stores information necessary for the operation of the transaction server 40. The storage unit 405 stores the business code of the partner service business.

[0294] [Device] 24 is a diagram showing an example of a processing configuration (processing module) of the terminal 50 according to the first embodiment. Referring to FIG. 24, the terminal 50 includes a communication control unit 501, a personal information input unit 502, an inquiry processing unit 503, and a storage unit 504.

[0295] The communication control unit 501 is a means for controlling communication with other devices. For example, the communication control unit 501 receives data (packets) from the distribution control server 10. The communication control unit 501 also transmits data to the distribution control server 10. The communication control unit 501 passes data received from other devices to other processing modules. The communication control unit 501 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 501. The communication control unit 501 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0296] The personal information input unit 502 is a means for inputting personal information to the distribution control server 10 when a user registers. The personal information input unit 502 uses any means to input personal information (such as name, date of birth, contact information, and account information) to the distribution control server 10. For example, the personal information input unit 502 acquires the above personal information from the user using a GUI and transmits the acquired personal information to the distribution control server 10.

[0297] The personal information input unit 502 stores the user ID issued by the distribution control server 10 in the storage unit 504 .

[0298] The inquiry processing unit 503 is a means for processing an inquiry about data sharing or data provision. The inquiry processing unit 503 acquires the user's intention (agreement or disagreement) using a GUI that matches the content of the inquiry (data sharing, data provision). The inquiry processing unit 503 transmits a response including the user's intention to the distribution control server 10.

[0299] The storage unit 504 stores information necessary for the operation of the terminal 50.

[0300] [Hospital terminal] Examples of the hospital terminal 60 include mobile terminal devices such as smartphones and tablets, and computers (personal computers, laptop computers). The hospital terminal 60 can be any equipment or device that can accept operations from hospital staff and communicate with the distribution control server 10, etc. Furthermore, the configuration of the hospital terminal 60 is clear to those skilled in the art, so a detailed description will be omitted.

[0301] The hospital terminal 60 may transmit an ID federation request to the distribution control server 10 in response to an operation by a hospital staff member. The hospital terminal 60 also transmits the ID federation request to its own service server 20. The service server 20 (ID federation control unit 302) sets a flag in the ID federation status field of the entry (entry in the customer information database) of the user corresponding to the personal identification ID included in the ID federation request.

[0302] [System Operation] Next, the operation of the information distribution system according to the first embodiment will be described. Fig. 25 is a sequence diagram showing an example of the operation of the information distribution system according to the first embodiment. The operation of the system when providing data will be described with reference to Fig. 25. The distribution control server 10 obtains consent for the data provision from the target of the data provision (step S41).

[0303] When the user's consent is obtained, the distribution control server 10 generates a target person ID that identifies the user and that is different for each data provision application (step S42).

[0304] When instructed by the trading server 40 to provide data, the distribution control server 10 sends a provision instruction to each service server 20, which includes a data ID specifying the data to be provided and the target ID of the user who contributed to the generation of the target data (step S43).

[0305] Each service server 20 transmits the user data (stored data) specified by the provision instruction and the target person ID to the data utilization server 30 (step S44).

[0306] The data utilization server 30 associates the user data based on the target person ID acquired from each service server 20 (step S45).

[0307] As described above, in the information distribution system according to the first embodiment, when a user's consent to data provision is obtained, the distribution control server 10 generates a target ID for identifying the user involved in the generation of the target data. The distribution control server 10 generates a different target ID for each data provision request. When executing data provision, the distribution control server 10 transmits a provision instruction including the target ID to the service server 20. In response to receiving the provision instruction, the service server 20 transmits the user data and the target ID to the data utilization server 30. The data utilization server 30 associates the received user data based on the target ID received from each service server 20. This configuration prevents data utilization businesses from improperly associating user data obtained from multiple data provision requests. In other words, since the target ID is different for each data provision request, the data utilization business cannot associate data obtained from different data provision requests. Furthermore, the target ID transmitted and received between the service server 20 and the data utilization server 30 is not notified to the user. Therefore, the target ID is not leaked by the user. From this perspective, data utilization businesses cannot associate user data, and as a result, individual privacy is protected.

[0308] The personal identification ID used by a data provider to manage a user is different for each data provider. If each data provider transmits user data to a data destination without taking into account the differences in the personal identification ID, the data destination cannot ensure data consistency. As a result, the data destination cannot effectively utilize the acquired data. Therefore, in the information distribution system disclosed in the present application, the distribution control server 10 transmits a target person ID to each data provider, and instructs the data provider to rewrite (replace) the target person ID with the personal identification ID and transmit the user data to the data destination.

[0309] Next, the hardware of each device constituting the information distribution system will be described. Figure 26 is a diagram showing an example of the hardware configuration of the trading server 40.

[0310] The trading server 40 can be configured by an information processing device (so-called a computer), and has the configuration exemplified in Fig. 26. For example, the trading server 40 includes a processor 311, a memory 312, an input / output interface 313, and a communication interface 314. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.

[0311] However, the configuration shown in Fig. 26 is not intended to limit the hardware configuration of the trading server 40. The trading server 40 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the trading server 40 is not intended to be limited to the example shown in Fig. 26, and for example, the trading server 40 may include multiple processors 311.

[0312] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).

[0313] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.

[0314] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a device that accepts user operations such as a keyboard or a mouse.

[0315] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).

[0316] The functions of the trading server 40 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. The processing modules can also be realized by semiconductor chips.

[0317] The distribution control server 10, the service server 20, etc. can also be configured using information processing devices in the same manner as the transaction server 40, and their basic hardware configurations are no different from those of the transaction server 40, so a description thereof will be omitted.

[0318] The trading server 40, which is an information processing device, is equipped with a computer, and the computer executes a program to realize the functions of the trading server 40. The trading server 40 also executes a control method for the trading server 40 by the program.

[0319] [Variations] The configuration, operation, etc. of the information distribution system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.

[0320] In the above embodiment, the explanation has been given on the assumption that the information distribution business and the trading business are different businesses. However, one business may also carry out both the information distribution business and the trading business. In this case, one server device may have the functions of the distribution control server 10 and the trading server 40.

[0321] The data provision status information described in the above embodiment (for example, the time series graph shown in FIG. 14) is merely an example, and the trading server 40 can generate data provision status information of various contents. For example, the trading server 40 may generate a time series graph including a lower limit value of the required data amount for each data. In this case, the trading server 40 may generate a time series graph indicating the latest status regarding cancellation (whether cancellation is currently possible) and the status in which cancellation is not possible. Alternatively, the trading server 40 may generate a time series graph indicating the timing (approximate) when data will be automatically provided.

[0322] If a digital signature is attached to the data (original data) to be provided, the so-called sanitized signature technology may be applied. By using this sanitized signature technology, signature verification becomes possible even if the ID is changed from a personal identification ID to a target ID.

[0323] In the above embodiment, the case where the user's consent is obtained after the data provision contract is concluded has been described. However, the data provision contract may be concluded after the user's consent is obtained. Alternatively, the acquisition of the user's consent and the conclusion of the data provision contract may be executed in parallel.

[0324] The data distribution system according to the above embodiment may be provided with a mechanism for extending the deadline for data provision applications. Specifically, the data utilization business operator checks the status of data provision and, if it determines that an extension of the deadline is necessary, inputs this information into the data utilization server 30. The data utilization server 30 then requests an extension of the deadline to the trading server 40. The trading server 40 then updates the deadline for the corresponding data provision application to the notified deadline.

[0325] The data distribution system according to the above embodiment may include a mechanism for allowing the data recipient to add a budget. Specifically, the data utilization business operator checks the status of data provision, and if it determines that an additional budget is necessary, inputs this information into the data utilization server 30. The data utilization server 30 notifies the trading server 40 of the additional budget. The trading server 40 updates the budget of the corresponding data provision request to the notified budget.

[0326] The data distribution system according to the above embodiment may be configured to allow the deadline to be set manually. Specifically, the data utilization business operator checks the status of data provision, and when it determines that the necessary data has been collected, inputs to the data utilization server 30 that the data provision application is to be completed. The data utilization server 30 then requests the trading server 40 to terminate the data provision application. The trading server 40 then terminates the corresponding data provision application and instructs the distribution control server 10 to provide the data.

[0327] In the above embodiment, a case has been described in which the deadline for data provision and the execution of data provision occur at substantially the same time. However, the deadline for data provision and the execution of data provision may occur at different times. For example, the data recipient inputs a "scheduled execution date" in the data provision application. The trading server 40 may execute (execute) the data provision when the scheduled execution date arrives.

[0328] In the above embodiment, a case has been described in which the user information database is configured inside the distribution control server 10, but the database may also be constructed in an external database server or the like. That is, some of the functions of the distribution control server 10 may be implemented in another server. More specifically, it is sufficient that the above-described "data distribution control unit (data distribution control means)" and the like are implemented in any of the devices included in the system.

[0329] The form of data transmission and reception between each device (distribution control server 10, service server 20, etc.) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Personal information of users and the like is transmitted and received between these devices, and in order to appropriately protect this information, it is desirable to transmit and receive encrypted data.

[0330] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the execution order of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the illustrated steps can be changed to the extent that the content is not affected, such as by executing each process in parallel.

[0331] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.

[0332] From the above explanation, it is clear that the present invention has industrial applicability, and the present invention can be suitably applied to an information distribution system that distributes stored data relating to services provided to users.

[0333] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes. [Appendix 1] a trading server; a service server operated by a service provider, which stores at least one user data item generated by providing a service to a user; a data utilization server operated by a data utilization business operator, which transmits a data provision application including the predetermined requirements to the transaction server, the data provision application being an application to acquire data that satisfies predetermined requirements from among the at least one or more pieces of user data through data provision; a distribution control server that controls the provision of the data; Including, The transaction server transmits the data provision application to the distribution control server, the distribution control server transmits to the service server a provision instruction including information specifying data that satisfies the predetermined requirements and a target ID that is the user's ID and is generated in response to the data provision application; The service server transmits the specified data and the target person ID to the data utilization server. [Appendix 2] The system described in Appendix 1, wherein, when data that meets the specified requirements is stored in multiple service servers, the distribution control server sends the provision instruction including the same target ID to each of the multiple service servers. [Appendix 3] The system described in Appendix 2, wherein the data utilization server associates data received from the multiple service servers based on the target person ID. [Appendix 4] The system described in Appendix 3, wherein the distribution control server generates the target ID so that it is different for each data provision application. [Appendix 5] The system described in Appendix 4, wherein the distribution control server sends a data provision inquiry to a terminal held by a user corresponding to data that meets the specified requirements. [Appendix 6] The distribution control server receives a response to the application for data provision, The system described in Appendix 5, wherein when the user agrees to the data provision, the user ID of the user who agreed to the data provision, the target ID, and the data provision application ID of the data provision application are associated and stored in a consent management database. [Appendix 7] The system described in any one of Appendices 1 to 6, wherein the trading server is operated by a trading business that mediates data distribution transactions between the service provider and the data utilization business. [Appendix 8] The system described in Appendix 7, wherein the transaction server controls the data provision contract between the service provider and the data utilization business. [Appendix 9] The system described in Appendix 8, wherein the distribution control server transmits the provision instruction to the service server of the service provider with which the data utilization business has concluded the data provision contract. [Appendix 10] a trading server; a service server operated by a service provider, which stores at least one user data item generated by providing a service to a user; a data utilization server operated by a data utilization business operator, which transmits a data provision application including the predetermined requirements to the transaction server, the data provision application being an application to acquire data that satisfies predetermined requirements from among the at least one or more pieces of user data through data provision; a distribution control server that controls the provision of the data; In a system including The transaction server transmits the data provision application to the distribution control server, the distribution control server transmits to the service server a provision instruction including information specifying data that satisfies the predetermined requirements and a target ID that is the user's ID and is generated in response to the data provision application; The service server transmits the specified data and the target person ID to the data utilization server.

[0334] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof. [Explanation of symbols]

[0335] 10 Distribution Control Server 20 Service Server 20-1 Service Server 20-2 Service Server 30 Data Utilization Server 40 trading servers 50 devices 60 Hospital terminals 101 trading server 102 Service Server 103 Data Utilization Server 104 Distribution Control Server 201 Communication control unit 202 User Registration Department 203 ID Linkage Department 204 Location Information Management Department 205 Data Distribution Control Unit 206 Catalog Information Management Department 207 Memory section 301 Communication Control Unit 302 ID linkage control unit 303 Data Distribution Request Department 304 Data storage control unit 305 Data Distribution Department 306 Contract conclusion control section 307 Storage section 311 processor 312 memory 313 Input / Output Interface 314 Communication Interface 401 Communication control unit 402 Account Opening Department 403 Catalog Information Request 404 Provision contract control section 405 Storage section 501 Communication control unit 502 Personal information input section 503 Query processing unit 504 Storage section

Claims

1. a trading server; a service server operated by a service provider and storing at least one user data item generated by providing a service to a user; a data utilization server operated by a data utilization business operator, which transmits a data provision application including the predetermined requirements to the transaction server, the data provision application being an application for acquiring data that satisfies predetermined requirements from among the at least one or more pieces of user data through data provision; a distribution control server that controls the provision of the data; Including, The transaction server transmits the data provision application to the distribution control server, the distribution control server transmits to the service server a provision instruction including information specifying data that satisfies the predetermined requirements and a target ID that is the user's ID and is generated in response to the data provision application; The service server transmits the specified data and the target person ID to the data utilization server, The distribution control server generates the target ID so that it is different for each data provision application.

2. The system according to claim 1, wherein, when data that meets the specified requirements is stored in a plurality of the service servers, the distribution control server transmits the provision instruction including the same target ID to each of the plurality of service servers.

3. The system according to claim 2 , wherein the data utilization server associates the data received from the plurality of service servers based on the target person ID.

4. 4. The system according to claim 3, wherein said distribution control server transmits a data provision inquiry to a terminal carried by a user corresponding to data that satisfies said predetermined requirements.

5. The distribution control server receives a response to the application for data provision, The system described in claim 4, wherein when the user agrees to the data provision, the user ID of the user who agreed to the data provision, the target ID, and the data provision application ID of the data provision application are associated and stored in a consent management database.

6. The system according to claim 1 , wherein the transaction server is operated by a transaction company that mediates data distribution transactions between the service company and the data utilization company.

7. The system according to claim 6 , wherein the transaction server controls a data provision contract between the service provider and the data utilizing business.

8. The system according to claim 7 , wherein the distribution control server transmits the provision instruction to the service server of the service provider with which the data utilization business has concluded the data provision contract.

9. a trading server; a service server operated by a service provider and storing at least one user data item generated by providing a service to a user; a data utilization server operated by a data utilization business operator, which transmits a data provision application including the predetermined requirements to the transaction server, the data provision application being an application for acquiring data that satisfies predetermined requirements from among the at least one or more pieces of user data through data provision; a distribution control server that controls the provision of the data; In a system including The transaction server transmits the data provision application to the distribution control server, the distribution control server transmits to the service server a provision instruction including information specifying data that satisfies the predetermined requirements and a target ID that is the user's ID and is generated in response to the data provision application; The service server transmits the specified data and the target person ID to the data utilization server, The distribution control server generates the target ID so that it is different for each data provision application.

Citation Information

Patent Citations

  • Information collecting system, information providing system, intermediary processor, information anomyzing device, program for information providing process and program for information relaying process

    JP2003316965A

  • Personal data providing system, personal data providing method, and information processing device

    JP2018128884A

  • Attribute information intermediary system, intermediary device, attribute information intermediary method and attribute information intermediary program

    WO2011129380A1