Information management server, information linkage system, information management method, and program
The information management server automates the update of personal information across multiple service providers by managing electronic certificates and user consent, addressing the burden of manual updates and ensuring accurate, automated information synchronization.
Patent Information
- Application Number
- JP2021188011
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-11-18
- Publication Date
- 2025-11-12
- Estimated Expiration
- 2041-11-18
AI Technical Summary
Users face a heavy burden when their personal information changes, such as address updates, as they need to update this information with each service provider individually, leading to potential oversight and incomplete updates.
An information management server that acquires and manages user electronic certificates, determines their validity, and with user consent, links personal information to business servers, periodically checks for changes, and updates the information as needed, reducing the user's burden by automating this process.
The system reduces the user's burden by automatically updating personal information across multiple service providers when changes occur, ensuring accurate and complete information is maintained without manual intervention.
Smart Images

Figure 0007767863000001 
Figure 0007767863000002 
Figure 0007767863000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information management server, an information linkage system, an information management method, and a program. [Background technology]
[0002] Official personal authentication is performed in various procedures (see, for example, Patent Document 1). For example, by performing official personal authentication in procedures for opening or registering an account with various businesses, such as banks, securities companies, credit companies, and insurance companies, the procedure can be performed accurately and safely based on the latest and accurate four pieces of basic information (name, address, date of birth, and gender) registered with the local government. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2017-211869 Summary of the Invention [Problem to be solved by the invention]
[0004] However, there are cases where the four basic pieces of information change due to moving, etc. In such cases, the user is required to go through the change procedures with each of the service providers, which places a heavy burden on the user. Furthermore, if there are many service providers for which the user must make changes, there is a possibility that the user may forget to go through the change procedures even though they are aware of the need to do so. As a result, there is a possibility that the change procedures will not be carried out with some service providers, contrary to the user's intention.
[0005] The present invention has been made in consideration of the above circumstances, and its purpose is to provide an information management server, an information linkage system, an information management method, and a program that can reduce the burden on users in terms of change procedures when their personal information is changed. [Means for solving the problem]
[0006] In order to solve the above-mentioned problems, an information management server according to the present invention comprises an acquisition unit that acquires identification information of a user's electronic certificate, a determination unit that determines the validity of the electronic certificate based on a response result from an authentication server obtained by transmitting the identification information to the authentication server, and a linkage unit that acquires personal information stored in the electronic certificate that has been determined to be valid, and performs a first linkage process in which the personal information is acquired and transmitted to a business server if the user consents to a first notification inquiring whether the user consents to transmitting the acquired personal information to a business server, and the determination unit periodically determines whether the personal information has been changed based on information notified from the authentication server, and the linkage unit: notifying the user of the first notification and a second notification inquiring whether the user agrees to the acquisition of the personal information from the authentication server; If the judgment unit determines that the personal information has been changed and the user has consented to a second notification inquiring whether the user agrees to the acquisition of the personal information from the authentication server, a second linkage process is performed to acquire the personal information held in the authentication server and send the acquired personal information to the business server.
[0007] Furthermore, in order to solve the above-mentioned problems, an information management method according to the present invention is an information management method performed by a computer, in which an acquisition unit acquires identification information of a user's electronic certificate, a determination unit determines the validity of the electronic certificate based on a response result from an authentication server obtained by transmitting the identification information to the authentication server, a linking unit acquires personal information stored in the electronic certificate determined to be valid, and performs the first linking process if the user has consented to a first notification inquiring whether the user agrees to performing a first linking process of transmitting the acquired personal information to a business server, and the determination unit periodically determines whether the personal information has been changed based on the information notified from the authentication server, and the linking unit: notifying the user of the first notification and a second notification inquiring whether the user agrees to the acquisition of the personal information from the authentication server;If the judgment unit determines that the personal information has been changed and the user has consented to a second notification inquiring whether the user agrees to the acquisition of the personal information from the authentication server, a second linkage process is performed to acquire the personal information held in the authentication server and send the acquired personal information to the business server.
[0008] In addition, in order to solve the above-mentioned problems, the present invention is a program for operating a computer as the information management server described above, and for causing the computer to function as each part of the information management server. [Effects of the Invention]
[0009] According to the present invention, when a user's personal information is changed, the burden on the user for the change procedure can be reduced. [Brief explanation of the drawings]
[0010] [Figure 1] 1 is a block diagram showing an example of the configuration of an information linkage system 1 to which an information management server 20 according to an embodiment is applied. [Figure 2] 2 is a sequence diagram showing the flow of processing performed by the information linkage system 1 according to the embodiment. FIG. [Figure 3] 2 is a block diagram showing an example of the configuration of an information management server 20 according to the embodiment. FIG. [Figure 4] FIG. 2 is a diagram showing an example of user information 220 according to the embodiment. [Figure 5] FIG. 10 is a block diagram showing an example of the configuration of an information linkage system 1 according to a modified example of the embodiment. [Figure 6] FIG. 10 is a sequence diagram showing the flow of processing performed by an information linkage system 1 according to a modified example of the embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0011] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0012] <Configuration of Information Linkage System 1> The information linkage system 1 is a system that provides procedure services. In the procedure services, various procedures are performed by each business operator in response to a user's request. The procedures performed here include, for example, membership registration, membership application, account registration, account transfer, address change, name change, etc. for services provided by the business operator.
[0013] FIG. 1 is a block diagram showing an example configuration of an information linkage system 1 to which an information management server 20 according to an embodiment is applied. The information linkage system 1 includes, for example, a user terminal 10, the information management server 20, an authentication server 30, and multiple provider servers 40 (a provider A server 40-1, a provider B server 40-2, a provider C server 40-3, and a provider D server 40-4). These components of the information linkage system 1 (the user terminal 10, the information management server 20, the authentication server 30, and the multiple provider servers 40) are communicatively connected via a communication network NW. In the following description, when the provider A server 40-1, the provider B server 40-2, the provider C server 40-3, and the provider D server 40-4 are not to be distinguished from one another, they may be simply referred to as "the provider servers 40."
[0014] The user terminal 10 is a computer with communication capabilities, such as a smartphone, a mobile phone, a tablet terminal, or a personal computer (PC). The user terminal 10 is operated by a user. The user here is a person who uses the procedure service, and uses the procedure service by operating the user terminal 10.
[0015] The information management server 20 is, for example, a computer such as a server, a cloud server, or a PC. The information management server 20 provides a procedure service. The information management server 20 executes a procedure in response to a request from a user. The method by which the information management server 20 executes a procedure will be described in detail later.
[0016] The authentication server 30 is a computer such as a server, a cloud server, or a PC. The authentication server 30 is, for example, a server device of a certification authority, that is, the Japan Agency for Local Government Information Systems (J-LIS). The authentication server 30 performs public personal authentication (JPKI, Japanese Public Key Infrastructure) using My Number cards.
[0017] The business entity server 40 is a computer such as a server, a cloud server, or a PC. The business entity server 40 acquires the procedure details requested by the user and information such as the user's name and address to be used in the procedure via the information management server 20. The business entity server 40 executes the procedure based on the acquired information.
[0018] Here, we will explain public personal authentication. In public personal authentication, the validity of a signature electronic certificate is confirmed by making an inquiry to a certification authority (J-LIS). Specifically, a signature verifier such as the information management server 20 transmits the issue number of the signature electronic certificate extracted from the My Number card to the certification authority, and the certification authority notifies the authority of information indicating the validity of the signature electronic certificate corresponding to that issue number. The signature verifier here is a business operator authorized to inquire about the validity of the signature electronic certificate from the certification authority.
[0019] Currently, it is permitted to inquire about the validity of a certificate from a certification authority, but it is not permitted to obtain the latest basic four information held by the certification authority. For example, if a user's address changes due to moving or other reasons, it is possible to inquire with the certification authority and find that the digital signature certificate storing the user's address before the move has expired, but it is not possible to obtain the latest address information from the certification authority. For this reason, if the user's address changes due to moving or other reasons, the information management server 20 cannot obtain the latest address information unless it inquires about the latest address from the user terminal 10.
[0020] In light of these circumstances, a policy has been announced that it will be permitted to obtain the latest four pieces of basic information from certification authorities in the future (see the Ministry of Internal Affairs and Communications explanatory document "Radical Improvement of the Convenience of My Number Cards" at https: / / www.kantei.go.jp / jp / singi / it2 / dgov / kaizen_wg / dai4 / siryou2.pdf).
[0021] In this embodiment, the information linkage system 1 is constructed on the premise that it will be possible to acquire the latest four pieces of basic information from a certificate authority in the future.
[0022] <Processing flow performed by Information Linkage System 1> 2 is a sequence diagram showing the flow of processing performed by the information linking system 1 according to the embodiment. The information linking system 1 performs the processing shown in the following steps S1 to S5, broadly divided. In step S1, a process of registering four basic pieces of information of a user is carried out. In step S1, personal information other than the four basic pieces of information of a user, such as the user's phone number, email address, account information, etc. may also be registered. In step S2, after obtaining the user's consent, a process (information linkage) is performed to transmit all or part of the user's four basic pieces of information to the business server 40. In step S3, a process is performed to determine whether the user's four basic information has been changed from the content registered in step S1. Step S3 is executed periodically, for example, every six months, after the user's four basic information has been registered in step S1. In step S4, if the user's basic four information has been changed, the latest basic four information held by the authentication server 30 is acquired from the authentication server 30 with the user's consent. In step S5, with the consent of the user, a process (information linkage) is performed in which all or part of the latest four pieces of basic information acquired in step S4 is transmitted to the business entity server 40.
[0023] First, the processing performed in step S1 will be described in detail. The user terminal 10 transmits information to the information management server 20 by, for example, accessing an application corresponding to the procedure service (step S10). For example, the user terminal 10 displays an authentication screen provided by the information management server 20. The authentication screen displays a field for inputting the password set on the My Number card and a message such as "Please bring your My Number card close." Following the instructions on the authentication screen displayed on the user terminal 10, the user, for example, inputs a password or performs a touch operation such as bringing the My Number card close to the user terminal 10. As a result, the user terminal 10 transmits the password to the information management server 20 and transmits information created based on the My Number card's digital signature certificate to the information management server 20.
[0024] The information management server 20 transmits the issue number of the digital signature certificate to the authentication server 30 (step S11). The issue number of the digital signature certificate is included in the information created based on the digital signature certificate that the information management server 20 obtained from the user terminal 10 in step S10.
[0025] The authentication server 30 receives the issue number from the information management server 20 and transmits the result of determining the validity of the digital signature certificate corresponding to the received issue number, for example, information indicating whether it is valid or invalid, to the information management server 20 (step S12). When the information management server 20 receives information indicating validity from the authentication server 30, it stores the user's basic four information in a memory unit (memory unit 22, described later) of the information management server 20. The user's basic four information is included in the information created based on the digital signature certificate that the information management server 20 obtained from the user terminal 10 in step S10.
[0026] Next, the process performed in step S2 will be described in detail. The user terminal 10 transmits consent information to the information management server 20 (step S20). The consent information here indicates which of the multiple businesses registered in the procedure service the user agrees to share information with. The information sharing here refers to transmitting all or part of the user's four basic pieces of information to the business. Information sharing may also include transmitting the user's personal information, such as a phone number, email address, or account information, other than the user's four basic pieces of information, to the business. For example, the user terminal 10 displays a consent screen (hereinafter referred to as the first consent screen) provided by the information management server 20. The first consent screen displays a message such as, "Please select a business to share information with. Once you have completed your selection, press the send button." It also displays a list of businesses registered in the procedure service, check boxes for each listed business, and a send button. The user selects a business to share information with by clicking the checkboxes according to the instructions on the first consent screen displayed on the user terminal 10. After confirming that the correct business has been selected, the user clicks the send button. This notifies the user of which businesses the user will use the procedure service to send all or part of the user's four basic information to, and which businesses the user will not send the user's four basic information to.
[0027] In this embodiment, in step S20, a process is performed to obtain the user's consent regarding how to handle any future changes to the user's four basic information. For example, the information management server 20 provides a consent screen (hereinafter referred to as the second consent screen) to the user terminal 10. The first consent screen and the second consent screen may be displayed on the same screen, or may be displayed on different screens.
[0028] For example, the second consent screen will present the user with two main points on which they can choose whether or not to agree to the following: (1) When the user's four basic information has been changed, the information management server 20 acquires the latest four basic information of the user from the authentication server 30. (2) If the user agrees to the above (1), the information management server 20 will notify the business operator of all or part of the user's latest four basic information acquired.
[0029] For example, the second consent screen displays a message such as "If the Basic 4 Information changes in the future, do you agree that the procedure service will obtain the latest Basic 4 Information from the certification authority?" along with two buttons indicating "Agree" and "Disagree." If the user agrees to the information management server 20 obtaining the latest Basic 4 Information, the user clicks the "Agree" button. On the other hand, if the user does not agree to the information management server 20 obtaining the latest Basic 4 Information, the user clicks the "Disagree" button.
[0030] When the user clicks the "Agree" button, the second consent screen displays a message such as, "If the user's Basic 4 Information changes, please select the business that will share the latest Basic 4 Information. Once you have completed your selection, press the send button." In this case, as with the first consent screen, a list of businesses registered with the procedure service, check boxes set for each listed business, and a send button are displayed. By clicking the check boxes, the user selects the business that will notify the user of the latest Basic 4 Information if the Basic 4 Information changes in the future. After confirming that the user has correctly selected the business, the user clicks the send button. This notifies the business to which the user will send all or part of the latest Basic 4 Information using the procedure service, and to which business the latest Basic 4 Information will not be sent.
[0031] The information management server 20 performs information sharing in accordance with the consent content notified from the user terminal 10. For example, FIG. 2 shows an example in which the user agrees to information sharing with business operator A, which corresponds to business operator A server 40-1. In this case, the information management server 20 transmits all or part of the user's four basic information acquired in step S12 to the business operator A server 40-1. Based on all or part of the user's four basic information received from the information management server 20, the business operator A server 40-1 checks business operator A's customer list, etc., and determines whether the information is about a customer of business operator A. If the information is about a customer of business operator A, the business operator A server 40-1 determines that the information has been correctly registered in the business operator A server 40-1 and responds to that effect (registration OK). On the other hand, if the information is not about a customer of business operator A, the business operator A server 40-1 determines that the information has not been correctly registered in the business operator A server 40-1 and responds to that effect (registration NG).
[0032] This figure also shows an example in which the user agrees to information sharing with the provider B corresponding to the provider B server 40-2. In this case, the information management server 20 transmits all or part of the four basic information of the user acquired in step S12 to the provider B server 40-2, and receives a response (registration OK or registration NG) from the provider B server 40-2.
[0033] This figure also shows an example in which the user does not agree to information sharing with the business operator C corresponding to the business operator C server 40-3. In this case, the information management server 20 does not transmit the four basic pieces of information of the user to the business operator C server 40-3.
[0034] This figure also shows an example in which the user agrees to information sharing with the business operator D corresponding to the business operator D server 40-4. In this case, the information management server 20 transmits all or part of the four basic information of the user acquired in step S12 to the business operator D server 40-4, and receives a response (registration OK or registration NG) from the business operator D server 40-4.
[0035] Next, the process performed in step S3 will be described in detail. The information management server 20 transmits an issue number to the authentication server 30 (step S30). The issue number here is the issue number that the information management server 20 transmitted to the authentication server 30 in step S11. The authentication server 30 transmits to the information management server 20 the result of determining the validity of the digital signature certificate corresponding to the issue number received from the information management server 20, for example, information indicating whether the digital signature certificate is valid or invalid (step S31).
[0036] Next, the processing performed in step S4 will be described in detail. If the signature digital certificate is invalid, the information management server 20 sends a notification to the authentication server 30 inquiring about the latest basic four information (step S40). This assumes that the user's consent has been obtained in step S20 for the information management server 20 to obtain the user's latest basic four information. In response to the inquiry received from the information management server 20, the authentication server 30 sends the user's latest basic four information to the information management server 20 (step S41).
[0037] Next, the process performed in step S5 will be described in detail. The information management server 20 transmits the latest basic four information acquired in step S41 to the provider A server 40-1. In this case, it is assumed that the user's consent has been obtained in step S21 for the information management server 20 to transmit all or part of the user's latest basic four information to the provider A corresponding to the provider A server 40-1 to carry out information linkage.
[0038] Note that this diagram shows an example in which in step S23 the information management server 20 transmits all or part of the user's latest basic four information to the provider B server 40-2, but in step S5 the information management server 20 does not transmit all or part of the user's latest basic four information to the provider B server 40-2. This is because the user has agreed to the information sharing corresponding to step S23 with provider B, but has not agreed to the transmission of the latest changed basic four information to provider B when the basic four information has been changed.
[0039] This figure also shows an example in which the information management server 20 does not transmit all or part of the user's latest basic four information to the provider C server 40-3 in step S2, and also in step S5, the information management server 20 does not transmit all or part of the user's latest basic four information to the provider C server 40-3. This is because the user has not agreed with provider C to perform information linking corresponding to step S23, or to transmit the latest changed basic four information to provider C if the basic four information is changed.
[0040] Also, this figure shows an example in which in step S25 the information management server 20 transmitted all or part of the user's latest basic four information to the provider D server 40-4, but in step S5 the information management server 20 does not transmit all or part of the user's latest basic four information to the provider D server 40-4. This is because the user agreed with provider D to conduct information linking corresponding to step S25 and also agreed that if the basic four information is changed, the latest changed basic four information will be transmitted to provider D. However, in step S26, the provider D server 40-4 notified the user of a response indicating that registration was not accepted, and therefore the latest changed basic four information was not transmitted to provider D.
[0041] <Configuration of information management server 20> The configuration of the information management server 20 will now be described with reference to Fig. 3. Fig. 3 is a block diagram showing the configuration of the information management server 20 according to the embodiment. The information management server 20 includes, for example, a communication unit 21, a storage unit 22, and a control unit 23. The communication unit 21 communicates with the user terminal 10, the authentication server 30, and the business server 40.
[0042] The storage unit 22 is configured by a storage medium, for example, a hard disk drive (HDD), flash memory, electrically erasable programmable read-only memory (EEPROM), random access read / write memory (RAM), read-only memory (ROM), or any combination of these storage media. The storage unit 22 stores programs for executing various processes of the information management server 20, and temporary data used when performing various processes. The storage unit 22 stores, for example, user information 220. The user information 220 is information about a user and includes four basic pieces of information about the user. The user information 220 is generated, for example, for each user.
[0043] 4 is a diagram illustrating an example of user information 220 according to an embodiment. The user information 220 stores information corresponding to items such as a user information ID, an issue number, four basic pieces of information, an acquisition date, a most recent change determination date, the most recent acquisition of the four basic pieces of information, and information linkage with a business operator.
[0044] The user information ID indicates identification information such as a number that uniquely identifies the user information 220. The issue number indicates the issue number of the digital signature certificate. The basic four information indicates the basic four information of the user identified by the user information ID. The acquisition date indicates the date on which the user's basic four information was acquired. The most recent change determination date indicates the date on which it was determined whether the user's basic four information has been changed. Whether the user's basic four information has been changed is determined based on the result indicating the validity of the digital signature certificate obtained when the information management server 20 sends the issue number to the authentication server 30.
[0045] The "Acquisition of Latest Basic 4 Information" indicates whether the user agrees to the information management server 20 acquiring the user's latest Basic 4 information, along with the date on which a response was received from the user. The "Information Sharing with Businesses" indicates, for each business, whether the user agrees to sending all or part of the Basic 4 Information to the business, along with the date on which a response was received from the user. The "Information Sharing with Businesses" also indicates, in the case of changes to the Basic 4 Information, whether the user agrees to sending all or part of the latest Basic 4 Information to the business, along with the date on which a response was received from the user. The "Information Sharing with Businesses" also indicates whether the business that received all or part of the Basic 4 Information responded with "OK to register" or "NG to register."
[0046] 3, the control unit 23 controls each component of the information management server 20. The control unit 23 is realized, for example, by a CPU (Central Processing Unit) of the information management server 20 executing a program pre-stored in the storage unit 22. The control unit 23 may also be realized as an integrated circuit such as an ASIC (Application Specific Integrated Circuit). The control unit 23 includes, for example, an acquisition unit 230, an application control unit 231, a determination unit 232, a collaboration unit 233, and a device control unit 234.
[0047] The acquisition unit 230 acquires various types of information. The acquisition unit 230 acquires various types of information notified from the user terminal 10, the authentication server 30, and the business server 40 via the communication unit 21. The acquisition unit 230 outputs the acquired information to a functional unit (at least one of the application control unit 231, the determination unit 232, the collaboration unit 233, and the device control unit 234) that performs processing using the acquired information.
[0048] The acquisition unit 230 acquires information generated from the user's digital signature certificate notified from the user terminal 10. The information generated from the digital signature certificate includes the issue number of the digital signature certificate and the basic four information. The acquisition unit 230 outputs the issue number to the determination unit 232. The acquisition unit 230 also outputs the information generated from the digital signature certificate to the linking unit 233. The acquisition unit 230 may also acquire information on which a digital signature has been applied to information used in a user's procedure. A digital signature may be required in a specific procedure (for example, an application procedure for opening an account). In this case, the user terminal 10 transmits the digital signature certificate embedded in the user's My Number card and the digitally signed information to the information management server 20. The acquisition unit 230 acquires the digital signature certificate and the digitally signed information.
[0049] The application control unit 231 controls an application (hereinafter referred to as application) corresponding to the procedure service. For example, when the user terminal 10 logs in to the application, the application control unit 231 transmits an authentication screen to the user terminal 10. Furthermore, the application control unit 231 transmits consent screens (first consent screen and second consent screen) to the user terminal 10 before information linkage is performed with the business operator. The application control unit 231 stores the content of consent obtained from the user terminal 10 as user information 220 in the storage unit 22.
[0050] Here, consent obtained from the user terminal 10 in response to the first consent screen is an example of "consent to the first notification." Consent obtained from the user terminal 10 in response to the second consent screen is an example of "consent to the second notification." Consent obtained from the user terminal 10 in response to the second consent screen is an example of "consent to the third notification."
[0051] The determination unit 232 determines the validity of the digital signature certificate based on a response result from the authentication server 30 obtained by transmitting the issue number to the authentication server 30. The determination unit 232 outputs the determination result of the validity of the digital signature certificate to the linking unit 233.
[0052] The linking unit 233 performs information linking when the user's consent has been obtained. Information linking involves transmitting all or part of the user's basic four information to the business server 40. When the digital signature certificate is determined to be valid, the linking unit 233 acquires the user's basic four information from information generated from the digital signature certificate acquired from the acquisition unit 230, and stores the acquired basic four information in the storage unit 22 as user information 220. The linking unit 233 also stores the date on which the basic four information was acquired as the acquisition date of the user information 220.
[0053] The linking unit 233 refers to the content of the consent stored in the user information 220 and transmits all or part of the four basic pieces of information to the business operator server 40 of the business operator with whom the user has consented to information linking. The linking unit 233 also stores the response (registration OK or registration NG) obtained from the business operator server 40 in response to the information linking as user information 220 in the storage unit 22.
[0054] After acquiring the four basic pieces of information, the determination unit 232 periodically determines the validity of the digital signature certificate. The determination unit 232 determines the validity of the digital signature certificate based on a response result from the authentication server 30 obtained by transmitting the issuance number to the authentication server 30. The determination unit 232 outputs the determination result of the validity of the digital signature certificate to the linking unit 233. The determination unit 232 stores the date on which the validity of the digital signature certificate was determined as the most recent change determination date in the user information 220.
[0055] The linking unit 233 acquires the determination result from the determination unit 232 and determines whether the user's basic four information has been changed based on the acquired determination result. If the digital signature certificate is valid, the linking unit 233 determines that the basic four information has not been changed. On the other hand, if the digital signature certificate is invalid, the linking unit 233 determines that the basic four information has been changed.
[0056] When it is determined that the basic four information has been changed, and if the user's consent has been obtained, the linking unit 233 acquires the user's latest basic four information from the authentication server 30. The linking unit 233 references the content of the consent stored in the user information 220 and determines whether the user has consented to the information management server 20 acquiring the latest basic four information. If the user has consented, the linking unit 233 notifies the authentication server 30 to request the latest basic four information, thereby acquiring the user's latest basic four information from the authentication server 30. The linking unit 233 reflects the acquired latest basic four information in the basic four information of the user information 220.
[0057] When it is determined that the basic four information has been changed, the linking unit 233 performs latest information linking if the user's consent has been obtained. Latest information linking is the transmission of all or part of the user's latest basic four information to the business operator server 40. The linking unit 233 references the content of the consent stored in the user information 220 and determines for each business operator whether the user has consented to the transmission of the latest basic four information to the business operator server 40 with which the user has consented to latest information linking. The linking unit 233 performs latest information linking by transmitting all or part of the latest basic four information to the business operator server 40 of the business operator with which the user has consented to latest information linking.
[0058] Here, when the linking unit 233 determines that the Basic 4 information has been changed, it may be configured to confirm again whether the user agrees to the information management server 20 acquiring the latest Basic 4 information. If a long period of time (for example, about one year) has passed since the Basic 4 information was acquired, the user may change his / her mind and oppose the information management server 20 acquiring the latest Basic 4 information. Alternatively, the user may change his / her mind and change his / her mind from one that opposed the information management server 20 acquiring the latest Basic 4 information to one that agrees. In such a case, by confirming again whether the user agrees to the acquisition of the latest Basic 4 information before acquiring the latest Basic 4 information, it becomes possible to respond in accordance with the user's intention.
[0059] The timing for confirming the user's consent may be set arbitrarily. It is sufficient that consent to information sharing is obtained from a business operator at least before information sharing with the business operator. It is also sufficient that consent to the information management server 20 acquiring the latest basic four information of the user is obtained at least before the information management server 20 acquires the latest basic four information. It is also sufficient that consent to the latest information sharing is obtained from a business operator at least before the latest information sharing with the business operator.
[0060] The device control unit 234 comprehensively controls the information management server 20. For example, the device control unit 234 controls the communication unit 21, and outputs information received by the communication unit 21 from the user terminal 10, the authentication server 30, and the business server 40 to the acquisition unit 230.
[0061] As described above, the information management server 20 according to the embodiment includes an acquisition unit 230, a determination unit 232, and a linking unit 233. The acquisition unit 230 acquires the issue number (identification information) of the digital signature certificate (digital certificate) embedded in the user's Individual Number Card (certification medium). The determination unit 232 determines the validity of the digital signature certificate based on a response result from the authentication server 30 obtained by transmitting the issue number to the authentication server 30. The linking unit 233 acquires the basic four information (personal information) stored in the digital signature certificate determined to be valid. If the user's consent has been obtained, the linking unit 233 performs information linking (first linking process). The information linking refers to transmitting the basic four information to the business entity server 40. The linking unit 233 determines whether the user has consented to information linking based on a response obtained from the user in response to a first consent screen (first notification inquiring whether the user consents to information linking with the business entity). The determination unit 232 periodically determines whether the basic four information has been changed. When the determination unit 232 determines that the Basic Four Information has been changed and the user's consent has been obtained, the linking unit 233 acquires the Basic Four Information held in the authentication server 30. The linking unit 233 determines whether the user has consented to acquiring the Basic Four Information held in the authentication server 30, based on a response obtained from the user to a second consent screen (a second notification inquiring whether the user consents to acquiring the Basic Four Information from the authentication server 30 when the Basic Four Information has been changed). The linking unit 233 performs latest information linking (second linking process). The latest information linking is transmitting the latest Basic Four Information held in the authentication server 30 to the business entity server 40 when the user's Basic Four Information has been changed. In this case, the linking unit 233 may be configured to perform latest information linking when the user's consent has been obtained. The linking unit 233 determines whether the user has consented to latest information linking, based on a response obtained from the user to the second consent screen (a third notification inquiring whether the user consents to latest information linking).
[0062] As a result, when it is determined that the Basic Four Information has been changed, the information management server 20 of the embodiment can obtain the Basic Four Information stored in the authentication server 30 with the user's consent. Therefore, when the Basic Four Information has been changed, the information management server 20 does not need to inquire of the user about the latest Basic Four Information. When the Basic Four Information has been changed due to a move or the like, the user does not need to notify the information management server 20 of their new address, etc. each time. Therefore, the burden on the user for the change procedures when the user's personal information has been changed can be reduced. Furthermore, when the Basic Four Information has been changed, all or part of the latest Basic Four Information can be sent to the business server 40 with the user's consent. Therefore, the business can obtain the latest Basic Four Information about the customer.
[0063] In the information management server 20 of the embodiment, the determination unit 232 determines the validity of the digital signature certificate based on a response result from the authentication server 30 obtained by transmitting the issue number to the authentication server 30. If the digital signature certificate is valid, the determination unit 232 determines that the user's basic four information has not been changed. If the digital signature certificate is invalid, the determination unit 232 determines that the user's basic four information has been changed. In this way, the information management server 20 of the embodiment can quantitatively determine whether the basic four information has been changed.
[0064] When the determination unit 232 determines that the signature digital certificate is invalid, the information management server 20 of the embodiment may again provide the second consent screen to the user terminal 10 (may issue a second notification). When the user's consent is obtained again, the linking unit 233 may acquire the latest basic four information from the authentication server 30. The linking unit 233 determines whether the user has consented based on the response obtained from the user to the second consent screen again. This allows the information management server 20 of the embodiment to once again confirm whether the user consents, thereby making it possible to respond in line with the user's wishes.
[0065] The information linkage system 1 of the embodiment includes an information management server 20 and an authentication server 30. As a result, the information linkage system 1 of the embodiment can obtain the latest four pieces of basic information from the authentication server 30 with the consent of the user, thereby achieving the same effects as those described above.
[0066] <Modifications of the embodiment> A modified example of the embodiment will now be described. This modified example differs from the above-described embodiment in that the information management server 20 is not the signature verifier. The signature verifier here is an entity authorized to inquire about the validity of a signature digital certificate from a certification authority. Below, configurations that differ from the above-described embodiment will be described, and configurations equivalent to those in the above-described embodiment will be assigned the same reference numerals and their description will be omitted.
[0067] 5 is a block diagram showing an example of the configuration of an information linkage system 1 according to a modified example of the embodiment. The information linkage system 1 includes a signature verification server 50. The signature verification server 50 is a computer such as a server, a cloud server, or a PC. The signature verification server 50 is used by a signature verifier to inquire of the authentication server 30 about the validity of a signature digital certificate.
[0068] Fig. 6 is a sequence diagram showing the flow of processing performed by the information linkage system 1 according to the modified embodiment. The processing shown in steps S200 and S500 in Fig. 6 is similar to steps S2 and S5 in Fig. 2, and therefore description thereof will be omitted.
[0069] In step S100, similar to step S1 in Fig. 2, a process of registering the four basic pieces of user information is performed. The user terminal 10 transmits information to the signature verification server 50 by, for example, accessing an application corresponding to the procedure service (step S10). The signature verification server 50 transmits the issue number of the digital signature certificate to the authentication server 30 (step S13). The authentication server 30 receives the issue number from the signature verification server 50 and transmits the result of determining the validity of the digital signature certificate corresponding to the received issue number to the signature verification server 50 (step S14). The signature verification server 50 transmits the result of the determination to the information management server 20 (step S15).
[0070] In step S300, similar to step S3, a process is performed to determine whether the user's four basic information has been changed. The information management server 20 transmits the issuance number to the signature verification server 50 (step S32). The signature verification server 50 transmits the issuance number to the authentication server 30 (step S33). The authentication server 30 transmits the determination result of the validity of the signing digital certificate corresponding to the issuance number received from the signature verification server 50 to the signature verification server 50 (step S34). The signature verification server 50 transmits the determination result to the information management server 20 (step S35).
[0071] In step S400, similar to step S4, if the user's basic four information has been changed, the latest basic four information is obtained. If the digital signature certificate is invalid, the information management server 20 sends a notification to the signature verification server 50 inquiring about the latest basic four information (step S42). The signature verification server 50 sends a notification to the authentication server 30 inquiring about the latest basic four information (step S43). In response to the inquiry received from the signature verification server 50, the authentication server 30 sends the user's latest basic four information to the signature verification server 50 (step S44). The signature verification server 50 sends the user's latest basic four information to the information management server 20 (step S45).
[0072] As described above, the information linkage system 1 according to the modified embodiment further includes a signature verification server 50. The user terminal 10 transmits the issuance number of the digital signature certificate to the signature verification server 50. The signature verification server 50 transmits the issuance number received from the information management server 20 to the authentication server 30. The signature verification server 50 transmits to the information management server 20 a response result from the authentication server 30 obtained by transmitting the issuance number to the authentication server 30. The determination unit 232 of the information management server 20 determines the validity of the digital signature certificate based on the response result received from the signature verification server 50. As a result, in the information linkage system 1 according to the modified embodiment, even if the information management server 20 is not a signature verifier, it is possible to inquire about the validity of the certificate from the authentication server 30 and obtain the latest basic four information.
[0073] Furthermore, in the information linkage system 1 according to the modified embodiment, the signature verification server 50 may periodically transmit the issue number to the authentication server 30. The signature verification server 50 may determine the validity of the digital signature certificate based on the response result from the authentication server 30, and if the digital signature certificate is invalid, may notify the information management server 20 of that fact, or if the digital signature certificate is valid, may not notify the information management server 20 of that fact. As a result, in the information linkage system 1 according to the modified embodiment, the information management server 20 can receive a notification only when the basic four information has been changed and it becomes necessary to obtain the latest basic four information, thereby making it possible to reduce unnecessary communication and suppress an increase in the processing load.
[0074] While the above description has been given with reference to an example in which the four basic pieces of user information are obtained using a My Number card, the present invention is not limited to this. Instead of a My Number card, a medium (certification medium) capable of proving the user's identity and storing the user's personal information, such as a driver's license, may be used. Furthermore, if the My Number card functionality is installed on a user's smartphone, the smartphone equipped with the My Number card functionality may be used instead of the My Number card.
[0075] The information linkage system 1 and the information management server 20 in the above-described embodiment may be implemented in whole or in part by a computer. In this case, a program for implementing the functions may be recorded on a computer-readable recording medium and then loaded and executed by a computer system. The term "computer system" as used herein includes hardware such as an operating system (OS) and peripheral devices. The term "computer-readable recording medium" refers to portable media such as flexible disks, optical magnetic disks, ROMs, and CD-ROMs, as well as storage devices such as hard disks built into a computer system. The term "computer-readable recording medium" may also include media that dynamically store programs for a short period of time, such as communication lines used when transmitting programs over a network such as the Internet or a telephone line, or media that store programs for a fixed period of time, such as volatile memory within a computer system serving as a server or client. The program may be designed to implement some of the functions described above, or may be capable of implementing the functions in combination with a program already stored in the computer system, or may be implemented using a programmable logic device such as an FPGA (Field Programmable Gate Array).
[0076] Although an embodiment of the present invention has been described in detail above with reference to the drawings, the specific configuration is not limited to this embodiment, and includes designs within the scope of the gist of the present invention. [Explanation of symbols]
[0077] 1...information linkage system, 10...user terminal, 20...information management server, 21...communication unit, 22...storage unit, 220...user information, 23...control unit, 230...acquisition unit, 231...application control unit, 232...determination unit, 233...linkage unit, 234...device control unit, 30...authentication server, 40...business operator server
Claims
1. an acquisition unit for acquiring identification information of a user's digital certificate; a determination unit that determines the validity of the electronic certificate based on a response result from an authentication server obtained by transmitting the identification information to the authentication server; a linking unit that performs a first linking process when the user has consented to a first notification inquiring whether the user consents to performing a first linking process of acquiring personal information stored in the electronic certificate that has been determined to be valid and transmitting the acquired personal information to a business server; and Equipped with the determination unit periodically determines whether the personal information has been changed based on information notified from the authentication server; the linking unit notifies the user of the first notification and a second notification inquiring whether the user agrees to the acquisition of the personal information from the authentication server together, and when the determination unit determines that the personal information has been changed and the user has agreed to the second notification inquiring whether the user agrees to the acquisition of the personal information from the authentication server, performs a second linking process to acquire the personal information held in the authentication server and transmit the acquired personal information to the business server. Information management server.
2. an acquisition unit for acquiring identification information of a user's digital certificate; a determination unit that determines the validity of the electronic certificate based on a response result from an authentication server obtained by transmitting the identification information to the authentication server; a linking unit that performs a first linking process when the user has consented to a first notification inquiring whether the user consents to performing a first linking process of acquiring personal information stored in the electronic certificate that has been determined to be valid and transmitting the acquired personal information to a business server; and Equipped with the determination unit periodically determines whether the personal information has been changed based on information notified from the authentication server; the linking unit issues a second notification inquiring whether the user agrees to acquiring the personal information from the authentication server in response to the determination unit that the personal information has been changed, and if the user agrees to the second notification, performs a second linking process of acquiring the personal information held in the authentication server and transmitting the acquired personal information to the business server. Information management server.
3. the linking unit performs the second linking process when consent is obtained from the user in response to a third notification inquiring whether or not the user consents to performing the second linking process.
3. The information management server according to claim 1.
4. the determination unit determines that the personal information has not been changed if the electronic certificate is valid, based on information indicating the validity of the electronic certificate, which is information notified from the authentication server, and determines that the personal information has been changed if the electronic certificate is invalid. The information management server according to claim 1 or 3.
5. If the determination unit determines that the personal information has been changed, the second notification is made again; the linking unit acquires the personal information held in the authentication server if consent has been obtained from the user for the second notification. The information management server according to any one of claims 1 to 4.
6. an information management server according to any one of claims 1 to 5; an authentication server; Equipped with Information collaboration system.
7. further comprising a signature verification server; the signature verification server receives identification information of the user's digital certificate from the user's terminal device, and transmits the received identification information to the authentication server, thereby obtaining a response result from the authentication server, and transmitting the response result to the information management server; The information linkage system according to claim 6.
8. further comprising a signature verification server; the signature verification server receives identification information of the user's electronic certificate from the user's terminal device, periodically transmits the received identification information to the authentication server, determines the validity of the electronic certificate based on a response result from the authentication server, notifies the information management server that the electronic certificate is invalid if the electronic certificate is invalid, and does not notify the information management server if the electronic certificate is valid; The information linkage system according to claim 6.
9. An information management method performed by a computer, comprising: The acquisition unit acquires the identification information of the user's digital certificate, a determination unit determining the validity of the electronic certificate based on a response result from the authentication server obtained by transmitting the identification information to the authentication server; a linking unit that acquires personal information stored in the electronic certificate that has been determined to be valid, and, if consent is obtained from the user in response to a first notification inquiring whether the user agrees to a first linking process of transmitting the acquired personal information to a business server, performs the first linking process; the determination unit periodically determines whether the personal information has been changed based on information notified from the authentication server; the linking unit notifies the user of the first notification and a second notification inquiring whether the user agrees to the acquisition of the personal information from the authentication server together, and when the determination unit determines that the personal information has been changed and the user has agreed to the second notification inquiring whether the user agrees to the acquisition of the personal information from the authentication server, performs a second linking process to acquire the personal information held in the authentication server and transmit the acquired personal information to the business server. Information management method.
10. An information management method performed by a computer, comprising: The acquisition unit acquires the identification information of the user's digital certificate, a determination unit determining the validity of the electronic certificate based on a response result from the authentication server obtained by transmitting the identification information to the authentication server; a linking unit that acquires personal information stored in the electronic certificate that has been determined to be valid, and, if consent is obtained from the user in response to a first notification inquiring whether the user agrees to a first linking process of transmitting the acquired personal information to a business server, performs the first linking process; the determination unit periodically determines whether the personal information has been changed based on information notified from the authentication server; the linking unit issues a second notification inquiring whether the user agrees to acquiring the personal information from the authentication server in response to the determination unit that the personal information has been changed, and if the user agrees to the second notification, performs a second linking process of acquiring the personal information held in the authentication server and transmitting the acquired personal information to the business server. Information management method.
11. 6. A program for causing a computer to operate as the information management server according to claim 1, wherein the program causes the computer to function as each unit included in the information management server.
Citation Information
Patent Citations
Proxy servicing method for individual information changing procedure application
JP2004013428A
Procedure system
JP2011048849A
Individual information management system and image formation device
JP2017211869A
Systems and methods of identity protection and management
US9106691B1
Personal information providing system, method and program
WO2017222032A1