Cloud server, information processing system, management method, and program

The cloud server system addresses IoT device security by acquiring user consent and setting security levels, ensuring secure data collection and usage, thereby protecting privacy data from leaks and tampering.

JP7763972B2Active Publication Date: 2025-11-04MITSUBISHI ELECTRIC CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024566954
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-12-26
Publication Date
2025-11-04
Estimated Expiration
2042-12-26

AI Technical Summary

Technical Problem

Existing technologies for remotely controlling IoT devices do not adequately address the security of data collection and storage, leaving them vulnerable to data leaks and tampering, despite user privacy protection options.

Method used

A cloud server system that manages IoT devices by acquiring user consent, setting security levels based on consent, confirming firmware versions, and ensuring the IoT device meets the required security standards before data collection, providing services only when security is ensured.

Benefits of technology

The system effectively protects privacy data by ensuring IoT devices meet security standards before data collection, preventing unauthorized access and tampering, and allowing secure data usage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007763972000001
    Figure 0007763972000001
  • Figure 0007763972000002
    Figure 0007763972000002
  • Figure 0007763972000003
    Figure 0007763972000003
Patent Text Reader

Abstract

An apparatus-connecting cloud server (20) that manages an IoT apparatus for collecting and storing privacy data related to user privacy comprises, in a control unit (23), a consent content acquisition means (231) and a setting means (232). The consent content acquisition means (231) acquires consent content pertaining to the use of privacy data from a terminal operated by the user. The setting means (232) sets, to the IoT apparatus, a security level that corresponds to the consent content acquired by the consent content acquisition means (231).
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a cloud server, an information processing system, a management method, and a program. [Background technology]

[0002] In recent years, various technologies have been proposed to remotely control IoT (Internet of Things) devices installed in homes from outside via the Internet. These IoT devices often store private data related to users' privacy. This poses a risk that private data may be leaked from IoT devices or tampered with.

[0003] Therefore, technologies that allow users to select privacy protection methods have also been disclosed. For example, the technology disclosed in Patent Document 1 allows users to select or reject privacy options to prevent data associated with their personal workspace from being collected, to collect data but not link it to their personal workspace, or to limit the purpose of data use. In other words, Patent Document 1 discloses a technology that allows users to change the data collection method or usage method. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Publication No. 2018-056128 Summary of the Invention [Problem to be solved by the invention]

[0005] The technology disclosed in the above-mentioned Patent Document 1 allows users to change the data collection method or usage method, but does not fully consider the security of the device that collects the data. Therefore, even if the technology disclosed in Patent Document 1 is applied, there remains a risk that private data will be leaked from the IoT device or that private data stored in the IoT device will be tampered with.

[0006] The present disclosure has been made to solve the above-mentioned problems, and aims to provide a cloud server, an information processing system, a management method, and a program that can appropriately protect privacy data stored in IoT devices. [Means for solving the problem]

[0007] In order to achieve the above object, the cloud server according to the present disclosure: A cloud server that manages IoT devices that collect and store privacy data related to user privacy, consent content acquisition means for acquiring consent content regarding the use of the privacy data from a terminal operated by a user; a setting means for setting a security level corresponding to the consent content acquired by the consent content acquisition means to the IoT device; a service processing means for processing a service using the privacy data; a confirmation means for confirming a security level set in the IoT device when the service processing means starts the service; The IoT device has a security level defined according to the installed firmware version, the confirmation means confirms the firmware version installed in the IoT device when the service processing means starts the service; The service processing means does not collect the privacy data from the IoT device if the firmware version confirmed by the confirmation means is lower than a required standard. [Effects of the Invention]

[0008] In the cloud server according to the present disclosure, a consent acquisition means acquires consent regarding the use of privacy data from a terminal operated by a user. Then, a setting means sets a security level for the IoT device according to the consent acquired by the consent acquisition means. Therefore, services using privacy data are provided only after the security of the IoT device is ensured. As a result, privacy data stored in the IoT device can be appropriately protected. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is a diagram illustrating an example of the overall configuration of an information processing system according to a first embodiment of the present disclosure. [Figure 2] A diagram showing an example of the configuration of IoT devices [Figure 3] A diagram showing an example of the configuration of a device connection cloud server. [Figure 4] FIG. 10 is a diagram illustrating an example of a service management table. [Figure 5] FIG. 10 is a diagram showing an example of a level management table. [Figure 6] An example of the consent screen displayed on the device [Figure 7] Sequence diagram for explaining the process flow for setting the security level [Figure 8] Sequence diagram for explaining the process flow for checking the security level [Figure 9] Sequence diagram for explaining the process flow for displaying configurable items on the consent screen [Figure 10] A diagram showing an example of another consent screen displayed on the device [Figure 11] FIG. 10 is a diagram showing an example of another management table; [Figure 12] Sequence diagram for explaining the process flow for deleting privacy data [Figure 13] A diagram showing an example of privacy data DETAILED DESCRIPTION OF THE INVENTION

[0010] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. Hereinafter, a case where an IoT device is an air conditioning device will be described as an example, but as will be described later, the present disclosure can also be applied to cases where other types of devices, such as lighting devices, are managed. That is, the embodiments described below are for illustrative purposes only and do not limit the scope of the present disclosure. Therefore, those skilled in the art can adopt embodiments in which each or all of these elements are replaced with equivalents, and these embodiments are also within the scope of the present disclosure. Furthermore, in each figure described in the following embodiments, common elements are designated by the same reference numerals.

[0011] (Embodiment 1) Fig. 1 is a diagram illustrating an example of the overall configuration of an information processing system 1 according to the first embodiment of the present disclosure. As illustrated in Fig. 1, the information processing system 1 includes an IoT device 10, a device connection cloud server 20, a service operation cloud server 30, and a terminal 40, which are communicably connected via the Internet N.

[0012] The IoT device 10 is, for example, an air conditioning device installed in a user's home, and is capable of collecting and storing privacy data relating to the user's privacy using a sensor camera, which will be described later.

[0013] The device connection cloud server 20 is, for example, a server computer, and manages the IoT devices 10 in cooperation with the service operation cloud server 30.

[0014] The service operation cloud server 30 is, for example, a server computer that authenticates the terminal 40 and accepts access from the authenticated terminal 40. Note that, although the information processing system 1 will be described as including the device connection cloud server 20 and the service operation cloud server 30, the functions of the device connection cloud server 20 and the service operation cloud server 30 may be integrated into a single cloud server.

[0015] The terminal 40 is, for example, a smartphone, tablet, or the like operated by the user, and displays a consent screen (described later) and transmits the consent details according to the user's operation to the device connection cloud server 20 via the service operation cloud server 30.

[0016] The configurations of the IoT device 10 and the device connection cloud server 20, which are the most distinctive features of the information processing system 1, will be described in more detail below.

[0017] 2 is a schematic diagram showing an example of the configuration of an IoT device 10. The IoT device 10 includes a sensor camera 11, a privacy data storage unit 12, a software service 13, a network service 14, a device authentication unit 15, and a network I / F (interface) 16.

[0018] The sensor camera 11 is a temperature sensor, humidity sensor, thermal imaging camera, etc., and acquires privacy data related to the privacy of the user who uses the IoT device 10. Note that the sensor camera 11 is not limited to being located inside the IoT device 10, but may be located outside the IoT device 10. In this case, the sensor camera 11 is connected to the IoT device 10 via a wired or wireless connection. For example, the sensor camera 11 may be a wearable sensor worn by the user. In this case, the sensor camera 11 acquires privacy data such as the user's heart rate and body temperature.

[0019] The privacy data storage unit 12 accumulates and stores the privacy data acquired by the sensor camera 11. As will be described later, the accumulation of privacy data in the privacy data storage unit 12 starts after a request for security level setting is made by the device connection cloud server 20 in response to an operation on a consent screen on the terminal 40. Alternatively, the IoT device 10 may be configured to collect and store privacy data by itself, without going through an operation on the consent screen.

[0020] The software service 13 provides local functions that are standard functions of the IoT device 10. For example, the software service 13 causes the IoT device 10 to perform standard air conditioning control that does not require communication with the device connection cloud server 20.

[0021] The network service 14 provides a network function that is an additional function of the IoT device 10. For example, the network service 14 causes the IoT device 10 to perform air conditioning control in accordance with a command from the device connection cloud server 20.

[0022] The device authentication unit 15 performs device authentication when providing the network service 14 or when displaying a consent screen, which will be described later. For example, the device authentication unit 15 stores account information such as a user name and a password, and performs device authentication together with the user who uses the terminal 40 via the service operation cloud server 30.

[0023] The network I / F 16 is, for example, a communication unit for communicating with the device connection cloud server 20 via the Internet N.

[0024] Since the IoT device 10 configured as described above is connected to the Internet N, it may be subject to cyber attacks such as leakage of communication data, unauthorized operation, etc. For this reason, the IoT device 10 is equipped with security functions such as encryption of communication data, encryption of storage, and automatic updating of F / W (firmware).

[0025] These security features are configured to be best practices by default. However, there are drawbacks, such as slower communication speeds due to encryption and waiting times due to automatic firmware updates, so these security features are designed so that users can manually switch them on and off. In other words, users can turn off security features if they accept the risks or if they want to set up alternative security features. Examples of alternative security features include when the IoT device 10 is used only within a local network, or when a separate router with access control functionality is installed.

[0026] The user may configure the security function by operating a switch installed on the IoT device 10 or by operating an operation screen on the terminal 40.

[0027] Next, the configuration of the device connection cloud server 20 will be described with reference to Fig. 3. Fig. 3 is a schematic diagram showing an example of the configuration of the device connection cloud server 20. The device connection cloud server 20 includes a storage unit 21, a network I / F 22, and a control unit 23.

[0028] The storage unit 21 is, for example, an SSD (Solid State Drive), a hard disk, etc., and stores various information. For example, the storage unit 21 stores a service management table 211 and a level management table 212.

[0029] 4, the service management table 211 stores items 211a requiring user consent and required security levels 211b in association with each other. Note that the larger the value of the security level 211b, the higher the security level.

[0030] On the other hand, the level management table 212 stores, for example, a security level 212a and a required setting 212b in association with each other, as shown in FIG.

[0031] In addition, the storage unit 21 can store privacy data collected from the IoT device 10.

[0032] 3, the network I / F 22 is, for example, a communication unit for communicating with the IoT device 10 via the Internet N. It should be noted that the network I / F 22 also communicates with the service operation cloud server 30 via the Internet N.

[0033] The control unit 23 is an arithmetic unit including, for example, a CPU (Central Processing Unit), RAM (Random Access Memory), ROM (Read Only Memory), etc., and controls the entire device connection cloud server 20. For example, the CPU uses the RAM as a work memory and appropriately executes a control program stored in the ROM, thereby realizing consent content acquisition means 231, setting means 232, confirmation means 233, service processing means 234, revocation instruction acquisition means 235, and deletion means 236.

[0034] The consent content acquisition means 231 acquires the consent content sent from the terminal 40 via the service operation cloud server 30. For example, a consent screen CG1 for privacy data as shown in FIG. 6 is displayed on the terminal 40, and the user can arbitrarily enter a check mark for each item that requires consent. When the consent button BT1 is pressed on the consent screen CG1, the consent content is sent to the device connection cloud server 20 via the service operation cloud server 30. Therefore, the consent content acquisition means 231 acquires this consent content. When the consent withdrawal button BT2 on the consent screen CG1 is pressed, a withdrawal instruction is sent to the device connection cloud server 20 via the service operation cloud server 30, as will be described later.

[0035] Returning to Fig. 3, the setting means 232 sets a security level in the IoT device 10 according to the consent content acquired by the consent content acquisition means 231. Specifically, the setting means 232 refers to the service management table 211 shown in Fig. 4 described above, and identifies the security level required for each consent item included in the consent content. Then, the setting means 232 sets the highest security level of the identified security levels in the IoT device 10. More specifically, the setting means 232 sets a security option in the IoT device 10 that corresponds to the security level.

[0036] The confirmation means 233 confirms the security level set in the IoT device 10. More specifically, the confirmation means 233 reads out the security options set in the IoT device 10. Then, the confirmation means 233 compares the security level required for the consent content with the security level set in the IoT device 10.

[0037] The service processing means 234 provides a service according to the security level using the IoT device 10 whose security level has been set by the setting means 232. For example, the service processing means 234 provides an automatic control service using privacy data using the IoT device 10 whose security level has been set to "3." Specifically, the service processing means 234 collects privacy data such as heart rate, body temperature, and temperature from the IoT device 10, and performs air conditioning control appropriate for the user.

[0038] The withdrawal instruction acquisition means 235 acquires the withdrawal instruction sent from the terminal 40 via the service operation cloud server 30. For example, when the consent withdrawal button BT2 is pressed on the consent screen CG1 as shown in Fig. 6 described above, a withdrawal instruction is sent to the device connection cloud server 20 via the service operation cloud server 30. Therefore, the withdrawal instruction acquisition means 235 acquires this withdrawal instruction.

[0039] When the cancellation instruction acquisition means 235 acquires a cancellation instruction, the deletion means 236 instructs the IoT device 10 to delete the accumulated privacy data. In addition, when the privacy data is stored in the storage unit 21, the deletion means 236 also deletes the privacy data from the storage unit 21.

[0040] The operation of the information processing system 1 configured as above will be described in detail below with reference to the drawings.

[0041] First, the process of setting a security level will be described with reference to Fig. 7. Fig. 7 is a sequence diagram illustrating the flow of the process of setting a security level. Note that although Fig. 7 omits communications regarding user authentication, device authentication, etc., in reality, the process of setting a security level is executed after user authentication, device authentication, etc. are performed, as will be described below.

[0042] First, the terminal 40 transmits the consent details to the service operation cloud server 30 (SQ1). For example, when the user arbitrarily checks each item that requires consent on the consent screen CG1 as shown in Fig. 6 described above and then presses the consent button BT1, the terminal 40 transmits the consent details, including whether each item is checked or not, to the service operation cloud server 30.

[0043] The service operating cloud server 30 transmits the consent details sent from the terminal 40 to the device connection cloud server 20 (SQ2). That is, upon receiving the consent details, the service operating cloud server 30 transfers the consent details to the device connection cloud server 20.

[0044] The device connection cloud server 20 determines a security level according to the consent details (SQ3). That is, when the consent details acquisition means 231 acquires the consent details sent from the terminal 40, the setting means 232 determines a security level according to the consent details. Note that SQ3 is an example of an consent details acquisition step.

[0045] The device connection cloud server 20 transmits a security level setting request to the IoT device 10 (SQ4). That is, the setting means 232 sets the security level identified in SQ3 above in the IoT device 10. More specifically, the setting means 232 sets the security option corresponding to the security level in the IoT device 10. Note that SQ4 is an example of a setting step.

[0046] In response to the setting request, the IoT device 10 sets the security level (SQ5). More specifically, the IoT device 10 sets the security options corresponding to the security level.

[0047] The IoT device 10 returns the setting result to the device connection cloud server 20 (SQ6). That is, when the IoT device 10 successfully completes the security level setting, it sends a reply to the device connection cloud server 20 indicating that the setting result is "OK."

[0048] The device connection cloud server 20 starts providing the service (SQ7). That is, the service processing means 234 uses the IoT device 10 for which the security level has been set to provide a service according to the security level. For example, the service processing means 234 uses the IoT device 10 for which the security level has been set to "3" to provide an automatic control service using privacy data. Specifically, the service processing means 234 collects privacy data such as heart rate, body temperature, and temperature from the IoT device 10, and performs air conditioning control appropriate for the user.

[0049] 7, a service using private data is provided after ensuring the security of the IoT device 10. As a result, the private data stored in the IoT device 10 can be appropriately protected.

[0050] If the user does not consent on the consent screen CG1 described above, the security level will not be set for the IoT device 10, and services using privacy data will not be provided. However, there are the following advantages.

[0051] The unsecured storage area can also be used, allowing for efficient resource utilization. When access rights control is not required, sensor information including privacy data can be viewed locally.

[0052] Next, the process of checking the security level will be described with reference to Fig. 8. Fig. 8 is a sequence diagram illustrating the flow of the process of checking the security level. Note that, although communication regarding user authentication, device authentication, etc. is omitted in Fig. 8 as well, in reality, the process of checking the security level is executed after user authentication, device authentication, etc. are performed, as will be described below. Furthermore, the same process content as that already explained will be explained in a simplified manner.

[0053] First, the terminal 40 transmits the consent details to the service operating cloud server 30 (SQ11). The service operating cloud server 30 then transmits the consent details sent from the terminal 40 to the device connection cloud server 20 (SQ12).

[0054] The device connection cloud server 20 requests the security level from the IoT device 10 (SQ13). That is, the confirmation means 233 confirms the security level set in the IoT device 10. More specifically, the confirmation means 233 reads out the security options set in the IoT device 10.

[0055] In response to the request, the IoT device 10 returns the set security level (SQ14). More specifically, the IoT device 10 returns the security option corresponding to the security level to the device connection cloud server 20.

[0056] The device connection cloud server 20 confirms the security level required for the agreed content (SQ15). That is, the confirmation means 233 confirms whether the security level set in the IoT device 10 meets the security level required for the agreed content. More specifically, the confirmation means 233 compares the security option corresponding to the security level required for the agreed content with the security option set in the IoT device 10.

[0057] If the security level set in the IoT device 10 does not meet the security level required for the agreement, that is, does not satisfy the required criteria, the device connection cloud server 20 notifies the service operation cloud server 30 of the insufficient security level (SQ16). Note that if the security level set in the IoT device 10 meets the security level required for the agreement, the device connection cloud server 20 starts providing the service, similar to SQ7 in FIG. 7 described above.

[0058] The service providing cloud server 30 issues a warning to the user (SQ17). For example, the service providing cloud server 30 causes the terminal 40 to display a warning message indicating that the security level is insufficient.

[0059] By performing the process shown in FIG. 8, it is possible to prevent services using private data from being provided without ensuring security.

[0060] In SQ11 and SQ12 of Fig. 8, the consent details may be sent each time a check mark is entered in any of the items requiring consent on the consent screen CG1 as shown in Fig. 6. In this case, items with insufficient security levels may be sent in SQ16 and SQ17, and the items with insufficient security levels may be highlighted in red, for example, on the consent screen CG1.

[0061] Next, the process of displaying configurable items on the consent screen will be described with reference to Fig. 9. Fig. 9 is a sequence diagram illustrating the process flow of displaying configurable items on the consent screen. Note that, even in Fig. 9, communications regarding user authentication, device authentication, etc. are omitted, but in reality, after user authentication, device authentication, etc. are performed, the process of displaying configurable items on the consent screen will be executed as described below. Furthermore, the same process content as that already explained will be explained in a simplified manner.

[0062] First, the terminal 40 transmits to the service operating cloud server 30 a message that the consent screen has been selected (SQ21). That is, the terminal 40 transmits to the service operating cloud server 30 a message that an instruction to display the consent screen has been issued.

[0063] The service operation cloud server 30 requests selectable items from the device connection cloud server 20 (SQ22).

[0064] The device connection cloud server 20 requests the security level from the IoT device 10 (SQ23). In response to the request, the IoT device 10 returns the set security level (SQ24).

[0065] The device connection cloud server 20 identifies configurable items from the security level that has already been set (SQ25). That is, the confirmation means 233 identifies configurable items by referring to the service management table 211 in Fig. 4 described above based on the security level set in the IoT device 10. For example, if the security level set in the IoT device 10 is "2," the device connection cloud server 20 identifies "upload private data" and "remote viewing of private data" as configurable items.

[0066] The device connection cloud server 20 transmits the identified configurable items to the service operation cloud server 30 (SQ26).

[0067] The service operation cloud server 30 displays a consent screen corresponding to the configurable items on the terminal 40 (SQ27). For example, if the configurable items are "upload of private data" and "remote viewing of private data," the terminal 40 displays "collection of data" and "remote viewing of data" as selectable, and grays out "automatic control" so that it cannot be selected, as in the consent screen CG2 shown in Fig. 10.

[0068] By performing the process shown in FIG. 9, it is possible to appropriately display configurable items on the consent screen according to the security level set in the IoT device 10.

[0069] In the above-described first embodiment, the case where the security level is managed by a numerical value has been described. However, the security level may be managed by the F / W (firmware) version of the IoT device 10.

[0070] In this case, the device connection cloud server 20 stores a management table as shown in Fig. 11 in the storage unit 21 instead of the service management table 211 of Fig. 4 described above. The management table shown in Fig. 11 associates items requiring user consent with firmware versions.

[0071] Then, in the process shown in Fig. 7 described above, the device connection cloud server 20 determines a F / W version according to the consent content, instead of determining a security level in SQ3. Then, when making a setting request in SQ4, the device connection cloud server 20 requests the IoT device 10 to set the determined F / W version. In response to this request, the IoT device 10 updates the F / W version as appropriate, instead of setting a security level in SQ5. That is, if the F / W version requested to be set is newer than the current F / W version, the IoT device 10 updates to the requested F / W version. Note that if the F / W version requested to be set is older than the current F / W version, the IoT device 10 does nothing in particular.

[0072] 8 and 9, the device connection cloud server 20 requests the F / W version instead of requesting the security level from the IoT device 10 in SQ13 and SQ23. In response to this request, the IoT device 10 replies with the current F / W version instead of returning the set security level in SQ14 and SQ24. Then, the device connection cloud server 20 checks the F / W version required for consent instead of checking the security level in SQ15. Furthermore, the device connection cloud server 20 identifies the configurable items from the current F / W version instead of identifying the configurable items from the security level in SQ25.

[0073] In this way, even when using a new firmware version of the IoT device 10, it is possible to provide services that use private data after ensuring security. Also, the firmware of the IoT device 10 can be used with an older version as needed. For example, this can accommodate users who are reluctant to update the firmware due to limitations in the specifications of the IoT device 10 or because the users are accustomed to the UI (user interface) of the older version.

[0074] Next, the process of deleting privacy data will be described with reference to Fig. 12. Fig. 12 is a sequence diagram illustrating the flow of the process of deleting privacy data. Note that, although Fig. 12 also omits communications regarding user authentication, device authentication, etc., in reality, it is assumed that user authentication, device authentication, etc. are performed, and then a process of confirming the security level is executed as described below. It is also assumed that a service using the privacy data has already been provided, and that the device connection cloud server 20 and the IoT device 10 have stored the privacy data shown in Fig. 13.

[0075] First, the terminal 40 transmits a consent withdrawal to the service operation cloud server 30 (SQ31). For example, when the consent withdrawal button BT2 is pressed on the consent screen CG1 as shown in FIG. 6, the terminal 40 transmits a consent withdrawal to the service operation cloud server 30.

[0076] The service operation cloud server 30 transmits the consent revocation sent from the terminal 40 to the device connection cloud server 20 (SQ32).

[0077] The device connection cloud server 20 identifies the privacy data according to the content of the revoked consent (SQ33). For example, the deletion means 236 refers to Fig. 13 and identifies the privacy data stored in the device connection cloud server 20 and the IoT device 10 according to the content of the revoked consent.

[0078] The device connection cloud server 20 transmits a request to delete the identified privacy data to the IoT device 10 (SQ34). For example, the deletion means 236 instructs the IoT device 10 to delete the privacy data stored in the IoT device 10 identified in SQ33 above.

[0079] In response to the deletion request, the IoT device 10 deletes the privacy data (SQ35). More specifically, the IoT device 10 deletes the privacy data from the privacy data storage unit 12.

[0080] The IoT device 10 returns the deletion result to the device connection cloud server 20 (SQ36). That is, when the IoT device 10 successfully completes the deletion of the private data, it sends a reply to the device connection cloud server 20 indicating that the deletion result is "OK."

[0081] The device connection cloud server 20 deletes the private data in the storage unit 21 (SQ37). For example, the deletion means 236 deletes the private data stored in the device connection cloud server 20 identified in SQ33 described above.

[0082] The device connection cloud server 20 sends a deletion notification to the service operation cloud server 30 (SQ38). The service operation cloud server 30 also sends a deletion notification to the terminal 40 (SQ39).

[0083] 12, it is possible to properly delete not only the private data stored in the device connection cloud server 20 but also the private data stored in the IoT device 10. Since a deletion notification is sent to the terminal 40, the user can confirm that the stored private data has been deleted from both the device connection cloud server 20 and the IoT device 10 upon revocation of consent. In particular, when the IoT device 10 is sold, or when the IoT device 10 is temporarily used in a hotel, rental facility, or the like, it becomes possible to delete the private data in the IoT device 10 from the terminal 40 even if the user is not the owner of the IoT device 10.

[0084] (Other embodiments) In the above-described first embodiment, the case where the IoT device 10 is an air conditioning device has been described, but the present disclosure can also be applied to other devices as the IoT device 10. For example, the present disclosure can also be applied as appropriate to a case where the IoT device 10 is a lighting device.

[0085] In the above-described first embodiment, the CPU of the device connection cloud server 20 uses RAM as a work memory and appropriately executes control programs stored in ROM, thereby realizing the consent content acquisition means 231, setting means 232, confirmation means 233, service processing means 234, revocation instruction acquisition means 235, and deletion means 236. However, all or part of the control unit 23 may be realized by dedicated hardware. The dedicated hardware may be, for example, a single circuit, a composite circuit, a programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a combination thereof.

[0086] In addition, the above control program can also be stored and distributed on a computer-readable recording medium such as a CD-ROM (Compact Disc Read Only Memory), a DVD (Digital Versatile Disc), a Magneto-Optical Disc, a USB (Universal Serial Bus) memory, a memory card, or an HDD (Hard Disk Drive).

[0087] In a configuration in which such a control program is executed by a device separate from the device connection cloud server 20, the program distributed as described above can be installed on a specific or general-purpose computer, causing the computer to function as the device connection cloud server 20. Alternatively, the control program may be stored in a disk device of another server on the Internet, and the control program may be downloaded from that server to the control device.

[0088] The present disclosure allows various embodiments and modifications without departing from the broad spirit and scope. Furthermore, the above-described embodiments are intended to explain the present disclosure and do not limit the scope of the disclosure. That is, the scope of the present disclosure is defined by the claims, not the embodiments. Various modifications made within the scope of the claims and the scope equivalent thereto are considered to be within the scope of the present disclosure. [Industrial Applicability]

[0089] The present disclosure can be suitably adopted in a cloud server, an information processing system, a management method, and a program that can appropriately protect privacy data stored in IoT devices. [Explanation of symbols]

[0090] 1 Information processing system, 10 IoT device, 11 Sensor / camera, 12 Privacy data storage unit, 13 Software service, 14 Network service, 15 Device authentication unit, 16 Network I / F, 20 Device connection cloud server, 21 Storage unit, 211 Service management table, 212 Level management table, 22 Network I / F, 23 Control unit, 231 Consent content acquisition means, 232 Setting means, 233 Confirmation means, 234 Service processing means, 235 Cancellation instruction acquisition means, 236 Deletion means, 30 Service operation cloud server, 40 Terminal

Claims

1. A cloud server that manages IoT (Internet of Things) devices that collect and store privacy data related to user privacy, consent content acquisition means for acquiring consent content regarding the use of the privacy data from a terminal operated by a user; a setting means for setting a security level corresponding to the consent content acquired by the consent content acquisition means in the IoT device; a service processing means for processing a service using the privacy data; a confirmation means for confirming a security level set in the IoT device when the service processing means starts the service, The IoT device has a security level defined according to the installed firmware version, the confirmation means confirms the firmware version installed in the IoT device when the service processing means starts the service; the service processing means does not collect the privacy data from the IoT device if the firmware version confirmed by the confirmation means is lower than a required standard; Cloud server.

2. a revocation instruction acquisition means for acquiring a revocation instruction to revoke the consent content acquired by the consent content acquisition means; and a deletion unit that, when the cancellation instruction acquisition unit acquires the cancellation instruction, commands the IoT device to delete the stored privacy data. The cloud server of claim 1 .

3. A cloud server that manages IoT devices that collect and store privacy data related to user privacy, consent content acquisition means for acquiring consent content regarding the use of the privacy data from a terminal operated by a user; a setting means for setting a security level corresponding to the consent content acquired by the consent content acquisition means in the IoT device; a revocation instruction acquisition means for acquiring a revocation instruction to revoke the consent content acquired by the consent content acquisition means; a deletion means for instructing the IoT device to delete the stored privacy data when the cancellation instruction acquisition means acquires the cancellation instruction; A cloud server comprising:

4. An information processing system in which an IoT device that collects and stores privacy data related to a user's privacy, a terminal operated by the user, and a cloud server are communicably connected, The cloud server consent content acquisition means for acquiring consent content regarding the use of the privacy data from the terminal; a setting means for setting a security level corresponding to the consent content acquired by the consent content acquisition means in the IoT device; a revocation instruction acquisition means for acquiring a revocation instruction to revoke the consent content acquired by the consent content acquisition means; a deletion means for instructing the IoT device to delete the stored privacy data when the cancellation instruction acquisition means acquires the cancellation instruction. Information processing system.

5. A management method executed by a cloud server that manages IoT devices that collect and store privacy data related to user privacy, comprising: a consent content acquisition step of acquiring consent content regarding the use of the privacy data from a terminal operated by the user; a setting step of setting a security level corresponding to the consent content acquired in the consent content acquisition step in the IoT device; a revocation instruction acquisition step of acquiring a revocation instruction to revoke the consent content acquired in the consent content acquisition step; a deletion step of instructing the IoT device to delete the stored privacy data when the cancellation instruction is acquired in the cancellation instruction acquisition step; A management method comprising:

6. A computer that manages IoT devices that collect and store privacy data related to users' privacy, a consent content acquisition step of acquiring consent content regarding the use of the privacy data from a terminal operated by the user; a setting step of setting a security level corresponding to the consent content acquired in the consent content acquisition step in the IoT device; a revocation instruction acquisition step of acquiring a revocation instruction to revoke the consent content acquired in the consent content acquisition step; a deletion step of instructing the IoT device to delete the stored privacy data when the cancellation instruction is acquired in the cancellation instruction acquisition step; A program to execute.

Citation Information

Patent Citations

  • Method and apparatus for monitoring media presentation

    JP2015531122A

  • Method for providing privacy protection in network lighting control system

    JP2018056128A

  • Monitoring apparatus, monitoring method, and program

    JP2018151881A

  • Information management method, control system, and method for controlling display device

    WO2014119255A1