Server device, server device control method and program

The server device and method address the challenge of terminating agency relationships by managing user accounts and determining when to transition data management from agents to individuals, ensuring a smooth transfer of personal data management in information distribution systems.

JP7768370B2Active Publication Date: 2025-11-12NEC CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024527961
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-06-14
Publication Date
2025-11-12
Estimated Expiration
2042-06-14

AI Technical Summary

Technical Problem

Existing information distribution systems fail to smoothly terminate agency relationships when minors reach adulthood, as existing technologies do not anticipate or facilitate the transition of personal data management from agents to the individuals themselves.

Method used

A server device and method that manage accounts of multiple users, store agency relationships, and determine when such relationships can be terminated, requesting the first user to consider terminating the agency when the second user reaches adulthood or a predetermined age.

Benefits of technology

Enables the smooth termination of agency relationships, ensuring that personal data management is transferred from agents to individuals capable of managing their own data, facilitating a seamless transition in information distribution systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007768370000001
    Figure 0007768370000001
  • Figure 0007768370000002
    Figure 0007768370000002
  • Figure 0007768370000003
    Figure 0007768370000003
Patent Text Reader

Abstract

The present invention provides a server device that contributes to smooth cancellation of an agency relationship that exists in an information distribution system. The server device comprises a management means and a storage means. The management means manages accounts of a plurality of users who use a data distribution service directed to data accumulated in a service server of a service provider. The storage means stores an agency relationship in which a first user among the plurality of users is designated as an agent and a second user is designated as a customer. The management means determines whether cancellation of the agency relationship is possible, and when the cancellation of the agency relationship is determined to be possible, the management means requests the first user to consider the cancellation of the agency relationship.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a server device, a control method for a server device, and a storage medium. [Background technology]

[0002] In recent years, technological developments have been progressing regarding identity verification, agent setting, authentication, and the like.

[0003] For example, Patent Document 1 describes that even if it is difficult to verify the identity of an individual, the personal information of that individual can be used. The storage unit in Patent Document 1 stores a personal ID indicating an individual and a proxy ID indicating an agent representing the individual, in association with each other, and also stores the personal ID and the personal information of the individual in association with each other. The acquisition unit acquires the personal ID from the storage unit based on the proxy ID presented by the agent, and acquires the personal information from the storage unit based on the acquired personal ID. The output unit outputs the personal information acquired by the acquisition unit.

[0004] Patent Document 2 describes that when the result of personal authentication is valid, the process can proceed, and it is possible to entrust the work of the target process to another person. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Publication No. 2018-163526 [Patent Document 2] Japanese Patent Application Laid-Open No. 2002-222168 Summary of the Invention [Problem to be solved by the invention]

[0006] With the development of information processing technology and communication technology, there are information distribution systems in which personal information held by hospitals and other institutions is provided to information recipient devices such as businesses with the consent of the individual. In such information distribution systems, users themselves are required to manage their own personal data. As the management of personal data by individuals becomes more widespread, there is a need for agents to manage the personal data of minors.

[0007] Here, if a minor is assigned as an agent and the agent manages the minor's personal data, the termination of the agent becomes an issue. That is, a minor becomes responsible for his or her own actions once he or she reaches a certain age. It is desirable for a user who is responsible for his or her own actions to manage personal data himself or herself. Therefore, it is desirable that the agent assigned to a minor be terminated smoothly when the agent is no longer needed.

[0008] It should be noted that even if the technologies disclosed in Patent Documents 1 and 2 are applied, it is not possible to smoothly terminate an agency relationship established in an information distribution system. Patent Document 1 does not anticipate the termination of an agency. Patent Document 2 does not anticipate the establishment of an agency for a user of an information distribution system.

[0009] A primary object of the present invention is to provide a server device, a method for controlling a server device, and a storage medium that contribute to the smooth release of an agency relationship that exists in an information distribution system. [Means for solving the problem]

[0010] According to a first aspect of the present invention, a server device is provided which comprises: a management means for managing the accounts of multiple users who use a data distribution service that targets data stored in a service server of a service provider; and a storage means for storing an agency relationship in which a first user of the multiple users is the agent and a second user is the agent, wherein the management means determines whether the agency relationship can be terminated, and if it is determined that the agency relationship can be terminated, requests the first user to consider terminating the agency relationship.

[0011] According to a second aspect of the present invention, there is provided a method for controlling a server device, which manages the accounts of multiple users who use a data distribution service that targets data stored in a service server of a service provider, stores an agency relationship in which a first user among the multiple users is the agent and a second user is the agent, determines whether the agency relationship can be terminated, and if it is determined that the agency relationship can be terminated, requests the first user to consider terminating the agency relationship.

[0012] According to a third aspect of the present invention, a computer-readable storage medium is provided that stores a program for causing a computer mounted on a server device to execute the following processes: managing the accounts of multiple users who use a data distribution service that targets data stored in a service server of a service provider; storing an agency relationship in which a first user among the multiple users is the agent and a second user is the agent; and determining whether the agency relationship can be terminated, and if it is determined that the agency relationship can be terminated, requesting the first user to consider terminating the agency relationship. [Effects of the Invention]

[0013] According to each aspect of the present invention, a server device, a control method for a server device, and a storage medium are provided that contribute to the smooth termination of an agency relationship that exists in an information distribution system. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above. [Brief explanation of the drawings]

[0014] [Figure 1] FIG. 1 is a diagram for explaining an outline of an embodiment. [Figure 2] FIG. 2 is a flowchart showing an example of the operation of one embodiment. [Figure 3] FIG. 3 is a diagram illustrating an example of a schematic configuration of an information distribution system according to the first embodiment. [Figure 4] FIG. 4 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 5] FIG. 5 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 6] FIG. 6 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 7] FIG. 7 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 8] FIG. 8 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 9] FIG. 9 is a diagram illustrating an example of catalog information according to the first embodiment. [Figure 10] FIG. 10 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 11] FIG. 11 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 12] FIG. 12 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 13] FIG. 13 is a diagram illustrating an example of a processing configuration of the distribution control server according to the first embodiment. [Figure 14] FIG. 14 is a diagram illustrating an example of a display on the terminal according to the first embodiment. [Figure 15] FIG. 15 is a diagram illustrating an example of a display on the terminal according to the first embodiment. [Figure 16] FIG. 16 is a diagram illustrating an example of a part of the user information database according to the first embodiment. [Figure 17] FIG. 17 is a diagram showing an example of a display on the terminal according to the first embodiment. [Figure 18] FIG. 18 is a diagram illustrating an example of a display on the terminal according to the first embodiment. [Figure 19] FIG. 19 is a flowchart illustrating an example of the operation of the user management unit according to the first embodiment. [Figure 20] FIG. 20 is a diagram illustrating an example of a location information database according to the first embodiment. [Figure 21] FIG. 21 is a diagram illustrating an example of a processing configuration of a service server according to the first embodiment. [Figure 22] FIG. 22 is a diagram illustrating an example of a customer information database according to the first embodiment. [Figure 23] FIG. 23 is a diagram illustrating an example of a processing configuration of the trading server according to the first embodiment. [Figure 24] FIG. 24 is a diagram showing an example of an account holder list according to the first embodiment. [Figure 25] FIG. 25 is a diagram illustrating an example of a processing configuration of a terminal according to the first embodiment. [Figure 26] FIG. 26 is a sequence diagram showing an example of the operation of the information distribution system according to the first embodiment. [Figure 27] FIG. 27 is a diagram illustrating an example of a hardware configuration of a distribution control server according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0015] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of main signals (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.

[0016] A server device 100 according to one embodiment includes a management means 101 and a storage means 102 (see FIG. 1). The management means 101 manages the accounts of multiple users who use a data distribution service that targets data stored in a service server of a service provider (step S1 in FIG. 2). The storage means 102 stores an agency relationship in which a first user among the multiple users is the agent and a second user is the agent (step S2). The management means 101 determines whether the agency relationship can be terminated, and if it is determined that the agency relationship can be terminated, requests the first user to consider terminating the agency relationship (step S3).

[0017] The server device 100 determines whether the agency relationship between the agent and the agent can be terminated. For example, the server device 100 determines whether the agency relationship established when the agent was a minor can be terminated when the agent reaches adulthood. If it determines that the agency relationship can be terminated when the agent reaches adulthood, the server device 100 requests the agent to consider terminating the agency relationship. If the agent wishes to terminate the agency relationship in response to the request for consideration, the server device 100 terminates the agency relationship that was previously established. As a result, the agency relationship between the agent and the agent is smoothly terminated.

[0018] In other words, the agency relationship established when the rep is an infant is maintained until the rep acquires the capacity to be held responsible for his or her own personal data. However, at the time when the rep acquires the capacity to be held responsible, a proposal is made to terminate the agency relationship. Even if the agent has forgotten about the agency relationship established for the child, the server device 100 can propose termination of the agency relationship at an appropriate time. With such a configuration, the agency relationship regarding the rep's personal data is terminated, and the management entity of the personal data is smoothly changed. In other words, the management entity of the personal data is transferred from the parent to the child (adult child).

[0019] Specific embodiments will be described in more detail below with reference to the drawings.

[0020] [First embodiment] The first embodiment will be described in more detail with reference to the drawings.

[0021] [System Configuration] Fig. 3 is a diagram showing an example of a schematic configuration of an information distribution system according to the first embodiment. As shown in Fig. 3, participating members (actors) of the information distribution system include information distribution companies, service companies, data utilization companies, and trading companies.

[0022] An information distribution business is a business that provides a platform for a data distribution service (information distribution service) for personal data accumulated in a service business. The information distribution business controls data distribution between businesses (service businesses, data utilization businesses). The information distribution business is equipped with a distribution control server 10.

[0023] The distribution control server 10 is operated by an information distribution business operator. The distribution control server 10 is a server device that controls (realizes) data distribution between service businesses and controls data distribution between service businesses and data utilization businesses. The distribution control server 10 realizes an information distribution service for data held by the service business operator.

[0024] A service provider is an entity that provides services to individuals. A service provider may be a private business or a public institution. Examples of service providers include medical institutions (hospitals, pharmacies, etc.) that provide medical services to users, retailers, and educational institutions that teach languages, sports, arts, etc. to customers.

[0025] Each service provider has a service server 20 for providing services to customers. The service server 20 is managed and operated by the service provider. The service server 20 holds (stores) data generated by the service provider when the service provider provides services to users, data necessary to provide services to users, etc. The service provider holds user data related to the services it provides to users.

[0026] Data utilization businesses are entities that do not provide services directly to individuals. Examples of data utilization businesses include pharmaceutical companies. For example, pharmaceutical companies develop new drugs using data obtained from service providers.

[0027] In this disclosure, entities that do not provide services to individuals will be referred to as "data utilization businesses" for explanation, but it goes without saying that data utilization businesses will act as "service businesses" when providing services to users. In other words, depending on the business model of a data utilization business, the data utilization business may also be a service business.

[0028] The data utilizing business operator has a business operator terminal 30 for acquiring and utilizing data from the service business operator. The business operator terminal 30 acquires at least one or more pieces of user data from the service server 20 by providing the data.

[0029] A trading business is an entity that realizes transactions between service providers and data utilization businesses. A trading business realizes data distribution between data generators (service providers) and data consumers (data utilization businesses). A trading business is a business that acts as an intermediary in data distribution transactions between service providers and data utilization businesses.

[0030] The trading company has a trading server 40 for realizing the data distribution. The trading server 40 is operated by the trading company. The trading server 40 processes requests for data provision from data utilization companies.

[0031] A user of the information distribution system uses a terminal 50 .

[0032] The devices shown in Fig. 3 are connected to each other via a network. For example, the distribution control server 10 and the service server 20 are connected by wired or wireless communication means and are configured to be able to communicate with each other.

[0033] 3 is an example and is not intended to limit the configuration of the information distribution system disclosed in the present application. For example, an information distribution business may include two or more distribution control servers 10. Furthermore, with regard to trading businesses and data utilizing businesses, the information distribution system includes business terminals 30 and trading servers 40 according to the number of businesses participating in the system.

[0034] [System Overview] Next, the general operation of the information distribution system according to the first embodiment will be described.

[0035] A user enters into an individual contract with a service provider from which the user wishes to receive a service. For example, the user provides the service provider with their name and other information and requests to enter into a new contract (a contract to receive the service) with the service provider.

[0036] For example, a user who wishes to visit a hospital submits a health insurance card or the like bearing the user's name, etc. to the hospital. Alternatively, in the case of an EC (Electronic Commerce) business that provides services related to online shopping, the user accesses a service server 20 operated by the EC business and creates an account.

[0037] A service provider generates a "personal identification ID" to identify a new customer (user). For example, a hospital assigns a patient card number to manage users (patients) and generates the patient card number as the personal identification ID. An e-commerce business generates a membership number or the like to manage customers as the personal identification ID. The service server 20 stores the generated personal identification ID (for example, a patient card number or membership number) in a database or the like.

[0038] Once the personal identification ID is generated, the user can receive services from the service provider. For example, the user can receive medical services (health checkups, consultations, etc.) from a hospital, or can use an e-commerce provider to do online shopping.

[0039] Here, a minor may receive a service from a service provider. For example, an infant may be examined at a hospital. In this case, the guardian (parent) will enter into an individual contract with the hospital as the infant's representative. In other words, a contract is concluded between the agent and the service provider, with the infant (minor) as the representative. In such cases, the service provider will also generate a "personal identification ID" to identify the new customer (infant).

[0040] In order for user data generated by service providers when they provide services to users to be subject to data distribution, the data must be "stored." Data storage occurs when a service provider (the provider of user data) registers the user data in an information distribution system as data that can be provided to third parties.

[0041] The distribution control server 10 controls data accumulation for making data related to services provided to users by data accumulators (service providers) the subject of data distribution. That is, the distribution control server 10 controls data accumulation for registering user data in the information distribution system as data that can be provided to third parties. The accumulated data becomes the subject of data distribution.

[0042] There are two means of data distribution in an information distribution system: "sharing" and "provision." The distribution control server 10 controls data sharing, which allows user data registered by data accumulation to be shared from one service server 20 to another service server 20. The distribution control server 10 controls data provision, which allows user data registered by data accumulation to be provided from the service server 20 to the business operator terminal 30.

[0043] "Sharing" is a means by which service providers obtain data accumulated by other service providers. For example, data distribution through "sharing" is used when an e-commerce operator obtains data generated by a hospital providing services to users. The e-commerce operator uses the data obtained from the hospital through data sharing to provide better services to users.

[0044] "Sharing" is used to improve the convenience of the service user themselves, so no compensation is paid to the user for data distribution (compensation for the user). "Sharing" is used to utilize data accumulated by other service providers in order for users to receive better services from the service provider.

[0045] "Provision" is a means by which data utilization businesses obtain data accumulated by other service businesses. For example, data distribution by "provision" is used when a pharmaceutical company obtains the results of health checkups and medical examinations from a hospital. The pharmaceutical company uses the data obtained from the hospital through data provision to help develop new drugs.

[0046] "Provision" is a method used by data utilization businesses that do not provide services directly to users, so compensation is incurred for data distribution (compensation to users). In other words, when "provision" is made, compensation is paid to the user. Also, when "provision" is made, compensation is paid from the data acquirer (data recipient) to the data provider (data accumulator) and the information distribution system (information distribution business).

[0047] For the sake of convenience, this disclosure will be described assuming that no compensation (fees) are paid to trading companies. In reality, a portion of the compensation paid by the data recipient to the data provider may be paid to the trading company as a "fee."

[0048] The distribution control server 10 controls data sharing so that data sharing destinations (service businesses that receive data) can acquire the accumulated data. The distribution control server 10 controls data provision so that data providing destinations (data utilizing businesses that receive data) can acquire the accumulated data.

[0049] <Create a system account> Users of the information distribution system must register in advance (user registration, system registration). More specifically, the user accesses the distribution control server 10 and performs procedures for creating an account. In the following explanation, an account created in the information distribution system will be referred to as a "system account."

[0050] To create a system account, the user operates the terminal 50 that the user owns to access the distribution control server 10. In response to the access from the terminal 50, the distribution control server 10 displays a WEB page for creating a system account.

[0051] The user performs an operation for generating a system account (for example, pressing a predetermined button) to generate a system account. At that time, the distribution control server 10 acquires information necessary for generating the user's system account. Specifically, the distribution control server 10 acquires the user's login information (login ID, password), biometric information (for example, facial image), identification document with a photograph (for example, driver's license), and personal information (name, date of birth, contact information, account information, etc.).

[0052] Upon acquiring login information, biometric information, identity verification documents, personal information, etc., the distribution control server 10 performs identity verification using the acquired biometric information and biometric information obtained from the identity verification documents. If identity verification is successful, the distribution control server 10 generates a user ID (identifier) ​​to uniquely identify the user in the information distribution system.

[0053] The distribution control server 10 stores the generated user ID, login information, and personal information (e.g., name, date of birth, contact information) of the user in association with each other. The distribution control server 10 stores this information in a "user information database." The user information database will be described in detail later.

[0054] The distribution control server 10 issues the generated user ID to the user (terminal 50). The terminal 50 stores the issued user ID.

[0055] A guardian (proxy) can register their child (represented) as a user. In this case, the guardian must first complete their own user registration.

[0056] The agent then registers the person being represented as a user. While logged in to the system account, the agent registers a document (a document proving that the agent has the authority to perform procedures, etc. on behalf of the person being represented; a proxy authority certificate) in the system to prove the relationship between the agent and the person being represented. The proxy authority certificate can be an official document such as a maternal and child health handbook or a certified copy of a family register. Once the authority of the agent is confirmed based on the proxy authority certificate, the distribution control server 10 generates a user ID for the person being represented.

[0057] The distribution control server 10 stores the generated user ID and personal information (the name, date of birth, etc. of the surnamed person) in the user information database. At that time, the distribution control server 10 stores the status of the surnamed person, the user ID of the agent set for the surnamed person, and the relationship (the relationship between the agent and the surnamed person; for example, parent and child), etc. The distribution control server 10 issues the generated user ID of the surnamed person to the terminal 50 of the agent.

[0058] <ID Linkage> As described above, in order for the user data held by the service provider to be the subject of data circulation, "data accumulation" is required. In order to achieve data accumulation, it is necessary to link the ID of the system account (user ID) and the ID (personal identification ID) generated by the service provider.

[0059] For example, as shown in FIG. 4, the user conveys to the hospital staff at the hospital counter that they hope to utilize the user data held by the hospital (submit an application for data utilization). The hospital staff inputs the user's personal identification information, the user's personal identification ID (for example, the examination ticket number), and the business operator code into the hospital terminal 60.

[0060] Note that the personal identification information is information for identifying the user. Examples of the personal identification information include the user's name, or a combination of the name and date of birth.

[0061] Also, the business operator code is identification information (ID) for identifying the service providers participating in the information circulation system. For example, different codes are assigned to hospitals and EC operators. The business operator code is shared among system participants (information circulation operators, service providers, data utilization operators) by any means. For example, when a service provider participates in the information circulation system, the information circulation operator generates a business operator code assigned to the service provider. The information circulation operator notifies the generated business operator code to the service provider, etc.

[0062] The hospital terminal 60 transmits an "ID linkage request" including the acquired personal identification information, personal identification ID, and business operator code to the circulation control server 10.

[0063] Alternatively, a user who wishes to utilize the user data of an EC business operates a terminal 50 to access the service server 20 of the EC business (see FIG. 5). The user logs in to an account of the EC business and submits an application for data utilization through the account. In response to the application, the service server 20 transmits an "ID federation request" including the user's personal identification information, personal identification ID, and business code to the distribution control server 10.

[0064] The distribution control server 10 acquires from the hospital terminal 60 and the service server 20 the personal identification information of the person desiring ID federation, the personal identification ID, and the business code of the service business (for example, hospital, e-commerce business) that is the target of ID federation.

[0065] The distribution control server 10 identifies the service provider that is the target of ID federation from the provider code. The distribution control server 10 also identifies the user registered in the system account from the personal identification information. The distribution control server 10 associates the service provider with the personal identification ID in the account of the identified user.

[0066] Once a personal identification ID is registered in a system account (when ID linking is completed), the service provider that is the subject of ID linking will be able to "store" the user data of users who wish to utilize the data.

[0067] The ID linking of the user ID and personal identification ID of the surrogate is performed by the surrogate. For example, the parent (surrogate) informs hospital staff at the hospital counter that they wish to use the user data (child's user data) held by the hospital. The hospital staff enters the child's (surrogate's) personal identification information, personal identification ID, and business code into the hospital terminal 60.

[0068] The hospital terminal 60 transmits an “ID federation request” including the personal identification information, personal identification ID, and business code of the rep, to the distribution control server 10. The distribution control server 10 processes the ID federation request of the rep in the same way as it processes an ID federation request for a normal user.

[0069] <Data accumulation>

[0070] When a service provider provides a service to a user (agent or representative), the service provider associates and stores the user's personal identification ID with user data (personal data). For example, when a hospital examines a user and obtains a disease name, the hospital associates and stores the user's personal identification ID (patient card number, etc.) with the disease name (for example, a specific disease name such as stomach cancer). For example, the service server 20 uses a "customer information database" to associate and store the user's personal identification ID with the user data. The customer information database will be described in detail later.

[0071] The service provider's service server 20 controls data accumulation for users who have completed ID integration (users who have applied for data utilization) each time it stores user data (data resulting from the provision of the service, data necessary for the provision of the service).

[0072] Specifically, the service server 20 registers the user data of the user as accumulated data (user data to be distributed) in the information distribution system. Specifically, the service server 20 transmits "location information" regarding the user for whom ID federation has been completed to the distribution control server 10 (see FIG. 6).

[0073] Location information is information about the storage location of user data (data storage entity; service provider), etc. Location information includes a data ID for identifying user data (stored data), a personal identification ID, a business code, the type of data being held, etc.

[0074] The distribution control server 10 stores the acquired location information in a "location information database." Details of the location information database will be described later. The location information database stores data IDs, individual identification IDs, business codes, data types, etc. in association with each other.

[0075] <Data sharing> A service provider that wishes to acquire data accumulated by another service provider (user data resulting from the provision of services to users by another service provider) can acquire that data through "sharing."

[0076] 7, a case will be described in which EC business operator B acquires, by "sharing," user data (examination results; disease name) stored in Hospital A. The hospital is equipped with service server 20-1, and the EC business operator is equipped with service server 20-2.

[0077] The EC business operator B (service server 20-2) transmits a "sharing request" to the distribution control server 10 (step S11).

[0078] Based on the sharing request, the distribution control server 10 identifies the user who is the target of data distribution and the data accumulator (Hospital A) of the data to be distributed. At that time, the distribution control server 10 determines the type of the identified target. The distribution control server 10 determines whether the target of data distribution is a normal user (a user for whom no agent has been set; a user who is not a representative) or a user for whom an agent has been set (a representative).

[0079] If the identified data distribution target is a normal user, the distribution control server 10 transmits an inquiry about data sharing to the terminal 50 owned by the identified user (step S12).

[0080] If the identified data distribution target is a user (represented) for whom a proxy has been set, the distribution control server 10 sends an inquiry regarding data sharing to the terminal 50 held by the proxy of the identified target.

[0081] The terminal 50 that receives the data sharing inquiry acquires the user's intention regarding data sharing. For example, the terminal 50 acquires the user's intention using a GUI (Graphical User Interface). In the above example, the terminal 50 displays a GUI with the content such as "By sharing your hospital examination results with the EC business operator, you will receive better service. Do you want to share?" and acquires the user's intention (agree or disagree to data sharing).

[0082] Alternatively, when an inquiry regarding the user data of the replicant is received, the terminal 50 displays a GUI stating, "You can receive better services by sharing the medical results of your child held by the hospital with the EC operator. Do you agree?"

[0083] The terminal 50 transmits a response to the inquiry about data sharing (agreement to data sharing or denial of data sharing) to the distribution control server 10 (step S13).

[0084] If the user's consent is obtained, the distribution control server 10 transmits a sharing instruction to the data sharing source (hospital A) (step S14).

[0085] Upon receiving the sharing instruction, Hospital A (service server 20-1) refers to the customer information database and transmits the examination results (disease name) of the target user, etc. to service server 20-2, the designated data sharing destination (step S15).

[0086] Next, data distribution through "provision" will be explained.

[0087] <Opening an account> Users who wish to receive compensation for providing data must open an account with a trading company. Opening an account for data provision will be explained with reference to Figure 8.

[0088] A trading business partner will partner with at least one of the multiple service businesses participating in the information distribution system. For example, a trading business that handles medical data will partner with a medical institution (hospital, pharmacy, etc.). Or, a trading business that handles educational data will partner with an education provider. The trading business will store the business code of the service business partner.

[0089] In addition, trading businesses store the business code of the data-utilizing business. For example, trading businesses generate the business code of the data-utilizing business when starting a transaction with the data-utilizing business. The business code of the data-utilizing business is shared among the information distribution business, trading businesses, and data-utilizing business by any method.

[0090] The trading business sells (intermediates sales of) data held by the partner service business (accumulated data) to data utilization businesses. For example, if the partner service business shown in Figure 8 is a medical institution, the trading business sells the data held by the partner medical institution to pharmaceutical companies, etc.

[0091] As mentioned above, users who wish to receive compensation for providing data via a trading company must open an account with the trading company (trading server 40). Users participating in the information distribution system who wish to earn revenue by providing data open an "information account" with the trading server 40.

[0092] The user presents the user ID issued by the distribution control server 10 to the trading server 40 to open an information account. The trading server 40 stores the acquired user ID. The trading server 40 manages the user IDs of users who have opened accounts in an account holder list.

[0093] Regarding the opening of an information account for the agent, the parent (agent) presents the user ID of the child (agent) to the transaction server 40 and opens the information account.

[0094] <Catalogue information> To realize data distribution through "provision," information distribution businesses prepare catalog information. The person in charge (system administrator) at the information distribution business defines the catalog information that lists the data that can be sold (see Figure 9). The catalog information is information that shows details of the data that the information distribution system can sell to data utilization businesses.

[0095] The dataset name included in the catalog information shown in Fig. 9 is information for identifying the catalog information. For example, a dataset related to a health checkup is given the name "Examination Results 1," and a dataset related to examination results is given the name "Examination Results 1."

[0096] The data type included in the catalog information indicates the type of data held by the service provider (accumulated data that can be provided to third parties). For example, information such as "height," "weight," and "blood pressure" in medical examination results, and "disease name," "medication," and "test results" in examination results correspond to data types. The data format specifies the format in which the data will be provided.

[0097] The data utilizing business acquires the catalog information via the business operator. More specifically, the business operator terminal 30 transmits a “catalog information presentation request” to the business server 40.

[0098] Upon receiving the catalog information presentation request, the transaction server 40 transmits a “catalog information transmission request” to the distribution control server 10 .

[0099] In response to receiving the catalog information transmission request, the distribution control server 10 transmits the catalog information defined by the information distributor to the transaction server 40 .

[0100] The transaction server 40 selects catalog information related to the partner service provider and transmits it to the business operator terminal 30. For example, in the above example, the transaction server 40 selects catalog information related to the business of a pharmaceutical company and transmits it to the data-utilizing business operator. The data-utilizing business operator views the received catalog information and identifies the catalog information necessary for its own business.

[0101] <Data distribution through provision> Data utilization businesses that wish to obtain data accumulated by service providers can obtain that data by "provision."

[0102] Here, with reference to FIG. 10, a case will be described in which a data utilization business acquires data (examination results) accumulated in medical institution A through "provision."

[0103] First, the data utilizing business refers to the catalog information presented by the trading business and identifies the necessary catalog information. Then, the business terminal 30 transmits a request for provision to the trading server 40, including information on the data utilizing business, the name of the data set of the identified catalog information, and the conditions required for the data to be provided (hereinafter referred to as search conditions) (step S21).

[0104] The information on the data utilizing business includes the name of the data utilizing business, the business code, the data recipient (the address to which the data will be sent), etc. The search criteria include, for example, "more than 100 disease name data items."

[0105] The transaction server 40 examines the acquired provision request. If no problems are found during the examination, the transaction server 40 transmits the acquired provision request and the list of account holders to the distribution control server 10 (step S22).

[0106] The distribution control server 10 identifies the personal identification ID of the user who is listed on the account holder list and who is related to the requested catalog information. At that time, the distribution control server 10 determines the type of the identified data distribution target.

[0107] If the identified data distribution target is a normal user, the distribution control server 10 transmits an inquiry regarding data provision to the terminal 50 owned by the user corresponding to the identified individual identification ID (step S23).

[0108] If the identified data distribution target is a user (represented) for whom a proxy has been set, the distribution control server 10 sends an inquiry regarding data provision to the terminal 50 held by the proxy of the identified target.

[0109] An inquiry for data provision includes information about the requester of the data provision (data utilization business), information about the data accumulator (medical institution A in the example of Figure 10), and the type of data requested to be provided (e.g., disease name).

[0110] The terminal 50 that has received the inquiry about data provision displays a GUI for acquiring the intention of each user regarding the data provision. The terminal 50 acquires the intention of the user (agreement or disagreement to the data provision) using the GUI.

[0111] The terminal 50 transmits a response to the inquiry about the data provision (either agreeing to the data provision or refusing to provide the data) to the distribution control server 10 (step S24). The terminal 50 transmits a response to the inquiry about the data provision regarding the stored data of the agent (either the agent agrees to the data provision or the agent refusing to provide the data) to the distribution control server 10.

[0112] The distribution control server 10 transmits a provision instruction to the data accumulator (medical institution A) for the users who have given their consent (step S25). For example, as described above, if the provision of 100 or more disease name data is requested, the distribution control server 10 transmits a provision instruction to the service server 20-1 for the disease name data of the 100 or more users who have given their consent to the data provision.

[0113] Upon receiving the provision instruction, medical institution A (service server 20-1) refers to the customer information database and transmits the data of the consenting user to the designated data destination (step S26).

[0114] <Notice of request for consideration of termination of agency relationship> The distribution control server 10 accesses the user information database periodically or at a predetermined timing, and detects whether the agency relationship between the agent and the agent can be terminated for each agent. Specifically, when the agent reaches a predetermined age (for example, 18 years old), the distribution control server 10 determines that the agency relationship between the agent and the corresponding agent can be terminated.

[0115] In this case, the distribution control server 10 requests the agent (parent) who is able to terminate the agency relationship to consider canceling the agency relationship. Specifically, the distribution control server 10 transmits a "notice of request to consider canceling agency" to the terminal 50 of the agent (see FIG. 11).

[0116] Upon receiving the notice of request to consider canceling the agency relationship, the terminal 50 requests the agent to consider canceling the agency relationship. For example, the terminal 50 obtains the result of the consideration using a GUI for obtaining the agent's intention as to whether or not he wishes to cancel the agency relationship. The terminal 50 transmits the result of the agent's consideration (cancel the agency relationship, continue the agency relationship) to the distribution control server 10.

[0117] If the agent wishes to terminate the agency relationship, the terminal 50 transmits the review results, including the contact information of the rep, to the distribution control server 10. For example, the agent (parent) transmits to the distribution control server 10 an email address that can be received by the terminal 50 held by the rep (child).

[0118] When the agent wishes to terminate the agency relationship, the distribution control server 10 terminates the agency relationship between the agent and the agent (the agency relationship between a parent and a child). Specifically, the distribution control server 10 accesses the user information database and deletes the agent (user ID of the agent) set as the agent.

[0119] Thereafter, the distribution control server 10 performs control to treat the agent whose agency relationship has been terminated as a normal user. First, the distribution control server 10 sets the status of the agent whose agency relationship has been terminated to "identity verification required."

[0120] Next, the distribution control server 10 requests the former agent whose agency relationship has been terminated to register a system account. Specifically, the distribution control server 10 sends an "account registration request" including the user ID of the former agent to the contact information notified by the former agent (the terminal 50 possessed by the agent) (see FIG. 12).

[0121] In response to receiving the account registration request, the terminal 50 accesses a web page for system account registration. At that time, the terminal 50 provides the notified user ID to the distribution control server 10. The former agent creates a system account in the same way as a normal user. Specifically, the former agent operates the terminal 50 to input login information (login ID, password), biometric information (e.g., facial image), identification documents with a photograph (driver's license, passport), etc. into the distribution control server 10.

[0122] If the identity verification using the identity verification document is successful, the distribution control server 10 cancels the "identity verification required" setting for the former agent. The former agent whose identity verification requirement has been canceled is treated in the same way as a normal user. In other words, the former agent (a child who has reached a certain age) whose identity verification requirement has been canceled can consent to data sharing and provision at their own discretion.

[0123] In addition, when a request for data sharing or data provision for the user data of a former agent whose agent setting has been cancelled is received, if the status of the former agent is "identity verification required", the distribution control server 10 will reject the request.

[0124] In addition, the ID linking and consent made by the former agent regarding the former representative will be saved, and data from before the representative became a regular user will continue to be subject to data distribution.

[0125] Next, each device included in the information distribution system according to the first embodiment will be described in detail.

[0126] [Distribution control server] 13 is a diagram showing an example of a processing configuration (processing module) of the distribution control server 10 according to the first embodiment. Referring to FIG. 13, the distribution control server 10 includes a communication control unit 201, a user management unit 202, an ID linking unit 203, a location information management unit 204, a data distribution control unit 205, a catalog information management unit 206, and a storage unit 207.

[0127] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the service server 20. The communication control unit 201 also transmits data to the service server 20. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0128] The user management unit 202 is a means for managing the accounts of multiple users who use the data distribution service for data stored in the service server 20 of the service provider. Specifically, the user management unit 202 realizes the above-mentioned user registration (user system registration). When the terminal 50 accesses the distribution control server 10, the user management unit 202 displays a GUI (Graphical User Interface) such as that shown in FIG. 14 on the terminal 50.

[0129] When a user wishes to register with the system (when the system registration button shown in FIG. 14 is pressed), the user management unit 202 acquires login information, biometric information (for example, a facial image), identification documents, and personal information (such as name, date of birth, contact information, and account information) from the user's terminal 50. For example, the user management unit 202 displays a GUI on the terminal 50 for acquiring login information, etc. (see FIG. 15).

[0130] In FIG. 15, the user presses the button corresponding to each item and inputs the information required to create a system account.

[0131] When the user management unit 202 acquires login information etc. from a user, it verifies the identity of the user. The user management unit 202 performs identity verification using the acquired biometric information (facial image) and the biometric information included in the identification document. The user management unit 202 performs identity verification by determining whether the two pieces of biometric information substantially match.

[0132] The user management unit 202 generates feature amounts from the acquired face image and the face image included in the personal identification document.

[0133] Since existing technology can be used for the process of generating feature amounts, detailed description thereof will be omitted. For example, the user management unit 202 extracts the eyes, nose, mouth, etc. from the face image as feature points. Then, the user management unit 202 calculates the positions of each feature point and the distances between each feature point as feature amounts (generating a feature vector consisting of multiple feature amounts).

[0134] Next, the user management unit 202 executes a matching process (one-to-one matching) using the two generated feature amounts. Specifically, the user management unit 202 calculates the similarity between corresponding face images using the two feature amounts. Based on the result of threshold processing on the calculated similarity, the user management unit 202 determines whether the two images are face images of the same person. Note that the similarity can be calculated using a chi-squared distance, Euclidean distance, or the like. The greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.

[0135] If the similarity is greater than a predetermined value (if the distance is shorter than a predetermined value), the user management unit 202 determines that the identity verification is successful. If the similarity is equal to or less than the predetermined value, the user management unit 202 determines that the identity verification is unsuccessful.

[0136] If the identity verification fails, the user management unit 202 notifies the user that the creation of the system account (user registration) has failed.

[0137] If the identity verification is successful, the user management unit 202 generates a user ID for identifying the user. For example, the user management unit 202 assigns a unique number each time a user registers in the system, and uses the assigned number as the user ID.

[0138] The user management unit 202 stores the user ID, login information, personal information, etc. in a user information database (see FIG. 16). As shown in FIG. 16, the user information database stores the user ID, personal information, and a personal identification ID for each service provider in association with each other. The user information database shown in FIG. 16 is an example and is not intended to limit the items to be stored. For example, the date and time of user registration may also be registered in the user information database.

[0139] The user management unit 202 transmits the generated user ID to the terminal 50.

[0140] The user management unit 202 controls user registration of a representative by a proxy. When a user logs in to a system account using login information, the user management unit 202 displays a GUI such as that shown in FIG. 17 on the terminal 50.

[0141] When the user wishes to set up a person to be represented (when the "Set up person to be represented" button shown in FIG. 17 is pressed), the user management unit 202 acquires information for registering the person to be represented in the system. Specifically, the user management unit 202 displays a GUI on the terminal 50 for acquiring a proxy authority certificate (e.g., maternal and child health handbook), personal information of the person to be represented (e.g., name, date of birth, etc.) and the like (see FIG. 18).

[0142] The user management unit 202 allows the setting of a representative if there is no contradiction between the information on the agent and the representative stated in the proxy authority certificate, the information on the logged-in user, and the information on the representative entered by the user. For example, if the name of the guardian in the maternal and child health handbook matches the name of the logged-in user, and the name of the child stated in the maternal and child health handbook matches the name of the representative entered by the logged-in user, the user management unit 202 grants the user the authority of attorney (recognizes the agency relationship).

[0143] When the proxy relationship is recognized, the user management unit 202 generates a user ID for the proxy. The user management unit 202 registers the generated user ID and personal information (the proxy's name, date of birth, etc.) in the user information database. Furthermore, the user management unit 202 registers in the user information database that a proxy has been set for the proxy, the user ID of the set proxy, and the relationship between the proxy and the proxy.

[0144] In the example of Figure 16, a proxy is set for the user with user ID "uID02", the user ID of the proxy is "uID01", and the relationship between the two is registered in the user information database as parent and child.

[0145] In this way, the user management unit 202 stores in a user information database an agency relationship in which a first user among multiple users registered in the system is the agent and a second user is the agent. More specifically, the user management unit 202 obtains from the first user an agency authority certificate to prove the relationship between the first and second users. The user management unit 202 determines whether the first user has agency authority based on the agency authority certificate. If the first user has agency authority, the user management unit 202 creates an account for the second user.

[0146] The user management unit 202 transmits the generated user ID of the person to be represented to the terminal 50 held by the representative.

[0147] The user management unit 202 controls the user registration of a person who is a representative (former person who is a representative). Fig. 19 is a flowchart showing an example of the operation of the user management unit 202 according to the first embodiment. The operation of the user management unit 202 regarding the user registration of a person who is a representative (former person who is a representative) will be described with reference to Fig. 19.

[0148] The user management unit 202 accesses the user information database periodically or at a predetermined timing, and determines whether or not the agency relationship for each agent can be terminated (step S101). Specifically, the user management unit 202 determines whether or not the agent can be terminated (termination of the agency relationship) depending on whether or not the agent has reached a predetermined age (for example, 18 years old, which is considered to be an adult).

[0149] If the proxy relationship cannot be released (step S101, No branch), the user management unit 202 does not perform any special processing.

[0150] If the proxy relationship can be terminated (step S101, Yes branch), the user management unit 202 requests the proxy (parent) to consider terminating the proxy relationship. Specifically, the user management unit 202 transmits a "proxy termination consideration request notification" to the terminal 50 of the proxy (step S102).

[0151] The user management unit 202 receives the review result (continuation of the proxy relationship, or cancellation of the proxy relationship) from the terminal 50 of the proxy.

[0152] If the agent wishes to continue the proxy relationship (step S103, No branch), the user management unit 202 does not perform any special processing.

[0153] If the agent wishes to terminate the agent relationship (step S103, Yes branch), the user management unit 202 terminates the agent relationship between the agent and the agent (step S104). Specifically, the user management unit 202 accesses the user information database and deletes the agent (user ID of the agent) set for the agent who has become an adult. At that time, the user management unit 202 sets the status of the former agent whose agent relationship has been terminated to "identity verification required."

[0154] Thereafter, the user management unit 202 requests the former agent whose agency relationship has been terminated to register a system account. Specifically, the distribution control server 10 sends an "account registration request" including the user ID of the former agent to the contact information notified by the former agent (the terminal 50 possessed by the former agent) (step S105).

[0155] When the terminal 50 of the former agent accesses the distribution control server 10 in response to receiving the account registration request, the user management unit 202 performs the same process as for system registration for a normal user. Specifically, the user management unit 202 acquires the login information, biometric information, etc. of the former agent (former agent who has become an adult) whose agency relationship has been terminated, using a GUI such as those shown in Figures 14 and 15.

[0156] The user management unit 202 executes identity verification using the biometric information (facial image) acquired from the former agent whose proxy relationship has been terminated and the biometric information recorded on the identity verification document (step S106).

[0157] If the identity verification fails (step S107, branch No), the user management unit 202 notifies the former agent that system registration has failed (step S108).

[0158] If the identity verification is successful (step S107, branch Yes), the user management unit 202 cancels the "identity verification required" setting for the former agent (step S109).

[0159] In this way, the user management unit 202 determines whether the agency relationship between the agent and the agent can be terminated, and if it is determined that the agency relationship can be terminated, it requests the first user (agent; for example, parent) to consider terminating the agency relationship. If the first user wishes to terminate the agency relationship, the user management unit 202 terminates the agency relationship with the second user (agent; for example, child). When the agency relationship is terminated, the user management unit 202 sets the status of the second user whose agency relationship has been terminated to "identity verification required." The user management unit 202 requests the second user, for whom identity verification is set required, to register an account that requires identity verification.

[0160] The ID federation unit 203 is a means for realizing the above-mentioned ID federation. The ID federation unit 203 receives an "ID federation request" from a terminal of a service provider (for example, a hospital terminal 60) or the service server 20. The ID federation request includes personal identification information, a personal identification ID, and a business code of a user who desires ID federation (registration with a service provider).

[0161] The ID linking unit 203 searches the user information database using personal identification information (such as the user's name or a combination of the name and date of birth) as a key to identify the corresponding user. The ID linking unit 203 sets the personal identification ID included in the ID linking request in a field corresponding to the business code among the personal identification ID fields of the identified user. That is, the ID linking unit 203 identifies the user registered in the system account from the personal identification information, and associates the service provider with the personal identification ID in the account of the identified user.

[0162] The location information management unit 204 is a means for managing location information acquired from service providers. The location information management unit 204 controls data accumulation for registering user data generated by the service provider when the service provider provides the service to the user in the information distribution system as data that can be provided to third parties.

[0163] The location information management unit 204 stores the location information acquired from each service server 20 in a location information database (see FIG. 20). As shown in FIG. 20, the location information database stores a personal identification ID, a business code, a data ID, a data type, a data accumulation date, and the like in association with each other.

[0164] Note that the location information database shown in Fig. 20 is an example and is not intended to limit the items to be stored, etc. Also, in the drawings including Fig. 20, for ease of understanding, the business code is expressed using the name of the service business.

[0165] The data distribution control unit 205 is a means for controlling data distribution by data sharing or data provision, with the data stored in the service server 20 as the object.

[0166] First, data distribution related to "sharing" will be explained.

[0167] The data distribution control unit 205 receives a sharing request from the service server 20. The sharing request includes the personal identification ID of the user who is the target of data acquisition, the business code of the sender of the sharing request, and the type of data desired to be acquired. In the example of Fig. 7, the sharing request includes the personal identification ID generated for the user by EC business B (service server 20-2), the business code of EC business B, and the data type "disease name."

[0168] The data distribution control unit 205 identifies the target person of data distribution based on the personal identification ID and business code included in the sharing request. Specifically, the data distribution control unit 205 identifies the target person by referring to the user information database shown in Fig. 16. In the above example, when a sharing request including the personal identification ID "EC01" is received from EC business B, the data distribution control unit 205 determines that the user is the target person of data distribution from the entry in the first row shown in Fig. 16.

[0169] The data distribution control unit 205 then identifies a service provider that stores the required data using the identified user's personal identification ID and the data type included in the sharing request. Specifically, the data distribution control unit 205 refers to the location information database shown in Fig. 20 and identifies a service provider that stores data corresponding to the data type included in the sharing request. In the above example, Hospital A is identified based on the user's personal identification ID "HL01" and the data type "disease name" included in the sharing request.

[0170] If the combination of the user's personal identification ID and the data type included in the sharing request is not stored in the location information database, the data distribution control unit 205 sends a negative response to the sender of the sharing request, indicating that the data cannot be shared. In the above example, if the combination of the user's personal identification ID "HL01" and the data type "disease name" is not registered in the location information database, a negative response is sent to the EC business operator B (service server 20-2).

[0171] When the target of data distribution and the accumulator of the data to be distributed are identified, the data distribution control unit 205 inquires about data sharing from the target of data distribution.

[0172] At this time, the data distribution control unit 205 refers to the user information database and determines the type of the identified data distribution target (normal user, user with a set proxy). For example, the data distribution control unit 205 determines the type of data distribution target depending on whether or not an ID is set in the proxy ID field in the entry of the data distribution target.

[0173] If the data distribution target is a normal user (if no proxy ID is set), the data distribution control unit 205 sends an inquiry about data sharing to the contact information of the data distribution target. In the above example, the inquiry is sent to the terminal 50 owned by the user.

[0174] When an agent is set for the data distribution target (when an agent ID is set), the data distribution control unit 205 transmits an inquiry about data sharing to the terminal 50 possessed by the agent of the agent. In the example of Fig. 16, when the data distribution target is the agent "uID02", the inquiry about data sharing is transmitted to the terminal 50 possessed by the agent "uID01".

[0175] The data sharing inquiry includes information such as the requester of the data sharing, the data accumulator, the type of data to be shared, etc. In the above example, the requester of the data sharing is set to E-commerce business operator B, the data accumulator is set to Hospital A, and the type of data to be shared is set to "disease name."

[0176] The data distribution control unit 205 receives a response to the data sharing inquiry from the terminal 50 .

[0177] If the user refuses to share the data, the data distribution control unit 205 notifies the data sharing request source that the data cannot be shared. In the above example, the data distribution control unit 205 transmits a negative response to the sharing request to the service server 20-2 of the EC business operator B.

[0178] If the user agrees to data sharing, the data distribution control unit 205 transmits a sharing instruction to the data accumulator. In the above example, the sharing instruction is transmitted to the service server 20-1 of Hospital A, which is the data accumulator.

[0179] The sharing instruction includes the personal identification ID generated by the data accumulator, information about the data sharing destination, and the data type to be shared. In the above example, the sharing instruction including the user's personal identification ID "HL01", the address of the service server 20-2 of the EC business operator B, and the data type "disease name" is sent to the service server 20-1 of the hospital A.

[0180] In this way, the data distribution control unit 205 transmits a sharing instruction including the personal identification ID of the user (target person) who has agreed to data sharing, which is generated by the data accumulator.

[0181] Next, data distribution related to "provision" will be explained.

[0182] The data distribution control unit 205 receives the request for provision and the list of account holders from the transaction server 40.

[0183] The data distribution control unit 205 identifies the catalog information requested to be provided from the data set name included in the request for provision.

[0184] The data distribution control unit 205 refers to the location information database and identifies the business code (data accumulator) and personal identification ID that accumulates the user data corresponding to the data type included in the identified catalog information.

[0185] The data distribution control unit 205 identifies a user who corresponds to the identified personal identification ID and is listed on the account holder list. The data distribution control unit 205 refers to the user information database and identifies a user who corresponds to the identified personal identification ID and is listed on the account holder list as a data distribution target.

[0186] When the target of data distribution and the accumulator of the data to be distributed are identified, the data distribution control unit 205 inquires of the target of data distribution about the provision of data.

[0187] At this time, the data distribution control unit 205 refers to the user information database and determines the type of the identified data distribution target (normal user, user with a designated proxy).

[0188] If the data distribution target is a normal user, the data distribution control unit 205 sends an inquiry about data provision to the terminal 50 possessed by the data distribution target.

[0189] If a proxy is set for the data distribution target, the data distribution control unit 205 transmits an inquiry regarding the provision of data to the terminal 50 possessed by the proxy.

[0190] The inquiry for data provision includes information about the source of the request for data provision, information about the data accumulator, and the type of data requested to be provided. In the above example, an inquiry is sent to each terminal 50, including the data utilization business as the source of the request for data provision, medical institution A as the data accumulator, and "disease name" as the type of data requested to be provided.

[0191] The data distribution control unit 205 transmits a provision instruction to the data accumulator for the user who has given consent. The provision instruction includes the personal identification ID of the user who has consented to the data provision, information on the data provision destination (the address of the business operator terminal 30), and the data type of the data to be provided.

[0192] In this way, when the data distribution control unit 205 acquires a request for data distribution regarding the user data of a second user (represented), it makes an inquiry to the first user (representative) regarding the distribution of the user data of the second user. Also, when the data distribution control unit 205 acquires a request for data distribution regarding the user data of a second user and the status of the second user is set to "identity verification required," it does not make an inquiry regarding data distribution to either the first or second user. When the data distribution control unit 205 acquires a request for data distribution regarding the user data of the second user after determining that identity verification of the second user who is set to identity verification required is successful, it makes an inquiry about data distribution to the second user (former representative) whose identity verification was successful.

[0193] The catalog information management unit 206 is a means for managing catalog information, and stores the catalog information created by the system administrator in the storage unit 207.

[0194] The catalog information management unit 206 receives a "catalog information transmission request" from the transaction server 40. In response to the reception of the request, the catalog information management unit 206 transmits the catalog information stored in the storage unit 207 to the transaction server 40.

[0195] The storage unit 207 stores information necessary for the operation of the distribution control server 10. In the storage unit 207, a user information database and the like are constructed.

[0196] [Service Server] 21 is a diagram showing an example of a processing configuration (processing modules) of the service server 20 according to the first embodiment. Referring to FIG. 21, the service server 20 includes a communication control unit 301, an ID linkage control unit 302, a data distribution request unit 303, a data storage control unit 304, a data distribution unit 305, and a storage unit 306.

[0197] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the distribution control server 10. The communication control unit 301 also transmits data to the distribution control server 10. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0198] The ID federation control unit 302 is a means for controlling ID federation of users. The ID federation control unit 302 acquires a request for ID federation from a user who is logged in to an account using a GUI (Graphical User Interface) or the like. In response to the request from the user, the ID federation control unit 302 transmits an "ID federation request" including personal identification information (such as the name of the logged-in user), a personal identification ID (such as the user's membership number), and a business code to the distribution control server 10.

[0199] The user's personal identification ID, personal specification information, user data, etc. are managed using a customer information database (see FIG. 22). As shown in FIG. 22, the customer information database holds information (flag) indicating whether or not ID federation for the user has been completed. Upon completing ID federation, the ID federation control unit 302 sets a flag in the ID federation status field for the corresponding user (a circle is set in FIG. 22).

[0200] The data distribution request unit 303 is a means for requesting data distribution (data sharing) of user data to an information distribution business operator. The data distribution request unit 303 transmits a sharing request to the distribution control server 10 in response to an operation by a service provider employee or the like. Specifically, the data distribution request unit 303 transmits a sharing request to the distribution control server 10, which includes the personal identification ID of the user who is the target of data acquisition, the business code of the user's own device, and the type of data desired to be acquired.

[0201] The data storage control unit 304 is a means for controlling the storage of user data generated as a result of providing a service to a user. The data storage control unit 304 associates the user's personal identification ID with the user's user data (data generated as a result of providing a service to the user or data necessary for the service to be provided to the user) and stores them in a customer information database.

[0202] As shown in Fig. 22, the data storage control unit 304 stores user data in a field corresponding to the type of data generated (stores specific data content). At that time, the data storage control unit 304 generates a data ID for identifying the user data and stores it in association with the user data and the data storage date. Note that Fig. 22 shows an example of a customer information database constructed in the service server 20-1 of Hospital A.

[0203] Here, for users for whom ID federation has been completed, the data storage control unit 304 transmits location information to the distribution control server 10 each time user data is stored in the customer information database. For example, consider a case where a service is provided to a user with a personal identification ID "HL01" and data on a disease name is generated as a result of a medical examination. In this case, location information including the personal identification ID "HL01", the business code "Hospital A", the data ID "HLD01", and the data type "Disease Name" is transmitted to the distribution control server 10.

[0204] The data distribution unit 305 is a means for realizing data distribution by “sharing” or “provision.” The data distribution unit 305 processes a “sharing instruction” or a “provision instruction” received from the distribution control server 10.

[0205] When a sharing instruction is received, the data distribution unit 305 refers to the customer information database and identifies an entry corresponding to the personal identification ID and data type included in the sharing instruction. For example, when a sharing instruction including the personal identification ID "HL01" and the data type "disease name" is received, the data distribution unit 305 identifies the entry shown in the top row of Fig. 22.

[0206] The data distribution unit 305 transmits the user data described in the corresponding data type field of the identified entry to the data sharing destination specified in the sharing instruction. In the examples of Figures 7 and 22, "stomach cancer" is transmitted to the service server 20-2 of the EC business operator B.

[0207] The data distribution unit 305 processes the provision instruction in the same way as the sharing instruction. The data distribution unit 305 transmits the user data determined by the personal identification ID and data type included in the provision instruction to the data destination specified by the provision instruction.

[0208] The storage unit 306 stores information necessary for the operation of the service server 20 .

[0209] [Operator terminal] A detailed description of the processing configuration of the business operator terminal 30 will be omitted. The business operator terminal 30 simply presents information to a user (such as an employee of a data utilization business operator) and accepts operations from the user. Specifically, the business operator terminal 30 simply displays a list of catalog information acquired from the transaction server 40, and transmits a request for provision to the transaction server 40, including the data set name and search conditions of the catalog information selected by the user.

[0210] [Trade Server] 23 is a diagram showing an example of a processing configuration (processing module) of the trading server 40 according to the first embodiment. Referring to FIG. 23, the trading server 40 includes a communication control unit 401, an account opening unit 402, a catalog information request unit 403, a provision request processing unit 404, and a storage unit 405.

[0211] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the distribution control server 10. The communication control unit 401 also transmits data to the distribution control server 10. The communication control unit 401 hands over data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 401. The communication control unit 401 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0212] The account opening unit 402 is a means for opening an account for a user who wishes to distribute data through provision. The account opening unit 402 acquires a user ID from the user's terminal 50. The account opening unit 402 adds the acquired user ID to a list of account holders (see FIG. 24).

[0213] The catalog information request unit 403 is a means for transmitting a “catalog information transmission request” to the distribution control server 10 .

[0214] When the catalog information request unit 403 receives a “catalog information presentation request” from the business operator terminal 30 , it transmits a “catalog information transmission request” to the distribution control server 10 .

[0215] In response to sending the request, the catalog information requesting unit 403 acquires catalog information stored in the distribution control server 10. The catalog information requesting unit 403 selects catalog information related to the service provider with which the device is affiliated, and transmits it to the data utilizing business (business terminal 30). The catalog information requesting unit 403 selects catalog information related to the affiliated service provider based on the business code of the affiliated service provider and the business code included in the catalog information.

[0216] The provision request processing unit 404 is a means for processing provision requests received from the business operator terminal 30. The provision request processing unit 404 examines the search conditions included in the provision request. Specifically, the provision request processing unit 404 examines the consistency between the data utilization purpose of the data utilizing business operator and the utilization purpose of the target data type. For example, if the content is "utilization purpose: development of new drugs, data type: disease name", the examination will be passed. In other words, the data utilizing business operator (business operator terminal 30) inputs the above-mentioned utilization purpose and data type into the transaction server 40 when requesting data provision.

[0217] If the examination is passed, the provision request processing unit 404 transmits the provision request acquired from the business operator terminal 30 together with the list of account holders to the distribution control server 10 .

[0218] The storage unit 405 stores information necessary for the operation of the transaction server 40. The storage unit 405 stores the business code of the partner service business.

[0219] [Device] 25 is a diagram showing an example of a processing configuration (processing module) of the terminal 50 according to the first embodiment. Referring to FIG. 25, the terminal 50 includes a communication control unit 501, a user registration control unit 502, an inquiry processing unit 503, a consideration request notification processing unit 504, and a storage unit 505.

[0220] The communication control unit 501 is a means for controlling communication with other devices. For example, the communication control unit 501 receives data (packets) from the distribution control server 10. The communication control unit 501 also transmits data to the distribution control server 10. The communication control unit 501 passes data received from other devices to other processing modules. The communication control unit 501 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 501. The communication control unit 501 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0221] The user registration control unit 502 is a means for controlling user registration. The user registration control unit 502 acquires login information and the like required for system registration in response to user operations, and transmits the acquired information to the distribution control server 10. The user registration control unit 502 also controls login to system accounts and the setting of agents.

[0222] The user registration control unit 502 stores the user ID issued by the distribution control server 10 in the storage unit 505. When a representative is set, the user registration control unit 502 stores the user ID issued by the distribution control server 10 in the storage unit 505. In response to an operation by the user, the user registration control unit 502 displays the user IDs (user ID of the agent, user ID of the representative) stored in the storage unit 505.

[0223] The inquiry processing unit 503 is a means for processing an inquiry about data sharing or data provision. The inquiry processing unit 503 acquires the user's intention (agreement or disagreement) using a GUI that matches the content of the inquiry (data sharing, data provision). The inquiry processing unit 503 transmits a response including the user's intention to the distribution control server 10.

[0224] The consideration request notification processing unit 504 is a means for processing the proxy cancellation consideration request notification. When the proxy cancellation consideration request notification is received from the distribution control server 10, the consideration request notification processing unit 504 acquires the user's desire (intention) regarding the termination of the agency relationship using a GUI or the like. Specifically, the consideration request notification processing unit 504 acquires whether the user wishes to continue the agency relationship or to terminate the agency relationship.

[0225] The consideration request notification processing unit 504 transmits the user's consideration result (continue the agency relationship or terminate the agency relationship) to the distribution control server 10. If the user wishes to terminate the agency relationship, the consideration request notification processing unit 504 transmits the contact information of the former agent (child) who was in the agency relationship to the distribution control server 10. For example, the consideration request notification processing unit 504 displays a GUI for inputting the contact information of the former agent, and transmits the obtained contact information to the distribution control server 10.

[0226] The storage unit 505 stores information necessary for the operation of the terminal 50.

[0227] [Hospital terminal] Examples of the hospital terminal 60 include mobile terminal devices such as smartphones and tablets, and computers (personal computers, laptop computers). The hospital terminal 60 can be any equipment or device that can accept operations from hospital staff and communicate with the distribution control server 10, etc. Furthermore, the configuration of the hospital terminal 60 is clear to those skilled in the art, so a detailed description will be omitted.

[0228] The hospital terminal 60 may transmit an ID federation request to the distribution control server 10 in response to an operation by a hospital staff member. The hospital terminal 60 also transmits the ID federation request to its own service server 20. The service server 20 (ID federation control unit 302) sets a flag in the ID federation status field of the entry (entry in the customer information database) of the user corresponding to the personal identification ID included in the ID federation request.

[0229] [System Operation] Next, a description will be given of the operation of the information distribution system according to the first embodiment. Fig. 26 is a sequence diagram showing an example of the operation of the information distribution system according to the first embodiment.

[0230] The distribution control server 10 receives a request for data distribution (step S31).

[0231] The distribution control server 10 identifies the data distribution target person (step S32).

[0232] The distribution control server 10 sends an inquiry regarding data distribution to the data distribution target (step S33). If the data distribution target is a regular user, the distribution control server 10 sends the inquiry to the terminal 50 held by the regular user. If the data distribution target is a user for whom an agent has been set, the distribution control server 10 sends the inquiry to the terminal 50 held by the agent.

[0233] The distribution control server 10 receives a response to the inquiry about data distribution (step S34).

[0234] When the user (a normal user or a proxy) agrees to the data distribution, the distribution control server 10 instructs the service server 20 to distribute the data (step S35).

[0235] The service server 20 transmits the user data to the specified destination (step S36).

[0236] As described above, in the information distribution system according to the first embodiment, when the replied person (child) reaches adulthood, the distribution control server 10 proposes to the agent (parent) that the agency relationship regarding the replied person be terminated. When the agent requests termination of the agency relationship, the distribution control server 10 enables the replied person to manage data by himself / herself after completing identity verification of the replied person. The distribution control server 10 proposes termination of the agency relationship to the agent when the replied person acquires capacity to assume responsibility. In other words, even if the agent has forgotten about the existence of an agency relationship that was previously established, the distribution control server 10 proposes termination of the agency relationship at an appropriate time. As a result, the agency relationship regarding the replied person's personal data is terminated, and the management entity of the personal data is smoothly changed.

[0237] Next, the hardware of each device constituting the information distribution system will be described. Fig. 27 is a diagram showing an example of the hardware configuration of the distribution control server 10.

[0238] The distribution control server 10 can be configured by an information processing device (so-called computer), and has the configuration exemplified in Fig. 27. For example, the distribution control server 10 includes a processor 311, a memory 312, an input / output interface 313, and a communication interface 314. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.

[0239] However, the configuration shown in Fig. 27 is not intended to limit the hardware configuration of the distribution control server 10. The distribution control server 10 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the distribution control server 10 is not intended to be limited to the example shown in Fig. 27, and for example, the distribution control server 10 may include multiple processors 311.

[0240] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).

[0241] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.

[0242] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display, etc. The input device is, for example, a device that accepts user operations such as a keyboard or a mouse.

[0243] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).

[0244] The functions of the distribution control server 10 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. Furthermore, the processing modules can be realized by semiconductor chips.

[0245] The service server 20, the transaction server 40, etc. can also be configured using information processing devices in the same way as the distribution control server 10, and their basic hardware configurations are no different from that of the distribution control server 10, so a description thereof will be omitted.

[0246] The distribution control server 10, which is an information processing device, is equipped with a computer, and the functions of the distribution control server 10 can be realized by causing the computer to execute a program. Furthermore, the distribution control server 10 executes the control method of the distribution control server 10 by the program.

[0247] [Variations] The configuration, operation, etc. of the information distribution system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.

[0248] In the above embodiment, the explanation has been given on the assumption that the information distribution business and the trading business are different businesses. However, one business may also carry out both the information distribution business and the trading business. In this case, one server device may have the functions of the distribution control server 10 and the trading server 40.

[0249] In the above embodiment, the server device 10 (user management unit 202) acquires the date of birth of the surrogate registered in the user information database and detects that the surrogate has reached adulthood based on the surrogate's age. However, the method for detecting that the surrogate has reached adulthood is not limited to this method, and any other method may be used. For example, the server device 10 may detect that the surrogate has reached adulthood using a proxy authority certificate (e.g., a maternal and child health handbook) acquired in advance, or by notification (collaboration) from an external organization that manages births.

[0250] The server device 10 may propose to terminate the proxy relationship to the proxy (parent) when the rep (child) registers with the system. For example, a child who has reached adulthood, unaware that his or her parent is (has been) managing his or her data on his or her behalf, may voluntarily apply to create a system account in the information distribution system. In this case, the server device 10 determines whether a proxy has been set for the user (child) based on personal information (such as name and date of birth) entered by the user (child) requesting the creation of a system account. If a proxy has been set for the applicant and the applicant is an adult, the server device 10 notifies the applicant that a proxy has been set. The server device 10 also notifies the proxy (parent) that the rep (child) has applied to create a system account and proposes to terminate the proxy relationship. Alternatively, if the applicant is already an adult, the server device 10 may terminate the proxy set for the applicant and subsequently notify the proxy (parent) that the proxy relationship has been terminated.

[0251] In the above embodiment, a case has been described in which the user information database is configured inside the distribution control server 10, but the database may also be constructed in an external database server or the like. That is, some of the functions of the distribution control server 10 may be implemented in another server. More specifically, it is sufficient that the above-described "data distribution control unit (data distribution control means)" and the like are implemented in any of the devices included in the system.

[0252] The form of data transmission and reception between each device (distribution control server 10, service server 20, etc.) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Personal information of users and the like is transmitted and received between these devices, and in order to appropriately protect this information, it is desirable to transmit and receive encrypted data.

[0253] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the execution order of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the illustrated steps can be changed to the extent that the content is not affected, such as by executing each process in parallel.

[0254] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.

[0255] From the above explanation, it is clear that the present invention has industrial applicability, and the present invention can be suitably applied to an information distribution system that distributes stored data relating to services provided to users.

[0256] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes. [Appendix 1] a management means for managing accounts of a plurality of users who use a data distribution service that targets data stored in a service server of a service provider; a storage means for storing an agency relationship in which a first user among the plurality of users is an agent and a second user is an agent; Equipped with The management means determines whether the proxy relationship can be terminated, and if it is determined that the proxy relationship can be terminated, requests the first user to consider terminating the proxy relationship. [Appendix 2] 2. The server device according to claim 1, wherein the management means terminates the proxy relationship between the first and second users when the first user wishes to terminate the proxy relationship. [Appendix 3] The server device according to claim 2, wherein the management means sets the status of the second user whose proxy relationship has been terminated to "identity verification required." [Appendix 4] The server device according to claim 3, wherein the management means requests the second user, for whom personal identification is required, to register an account that requires personal identification. [Appendix 5] The server device according to claim 4, further comprising a data distribution control means for controlling data distribution through data sharing or data provision, the data being stored in the service server. [Appendix 6] The server device described in Appendix 5, wherein the data distribution control means, when receiving a request for data distribution regarding the user data of the second user, makes an inquiry to the first user regarding the distribution of the user data of the second user. [Appendix 7] The server device described in Appendix 6, wherein the data distribution control means acquires a request for data distribution regarding the user data of the second user, and if the status of the second user is set to require personal identification, does not make an inquiry to either the first or second user regarding the distribution of the user data of the second user. [Appendix 8] The server device described in Appendix 7, wherein, when the data distribution control means receives a request for data distribution regarding the user data of the second user after it is determined that the identity verification of the second user for whom identity verification is required is successful, it makes an inquiry to the second user whose identity verification was successful regarding the distribution of the user data of the second user. [Appendix 9] 9. The server device according to claim 8, wherein the identity verification is performed using an identity verification document including a facial image. [Appendix 10] 10. The server device according to any one of claims 1 to 9, wherein the management means determines that the agency relationship can be terminated when the rep reaches a predetermined age. [Appendix 11] The management means obtaining from the first user an authorization certificate to certify the relationship between the first and second users; determining the proxy authority of the first user based on the proxy authority certificate; 10. The server device according to any one of claims 1 to 9, wherein an account for the second user is created when the first user has proxy authority. [Appendix 12] The server device according to claim 11, wherein the proxy authority certificate is a maternal and child health handbook or a copy of a family register. [Appendix 13] Manage the accounts of multiple users who use a data distribution service that targets data stored in the service server of the service provider; storing an agency relationship in which a first user among the plurality of users is an agent and a second user is an agent; A control method for a server device, which determines whether or not the proxy relationship can be terminated, and if it is determined that the proxy relationship can be terminated, requests the first user to consider terminating the proxy relationship. [Appendix 14] The computer installed in the server device A process for managing accounts of multiple users who use a data distribution service that targets data stored in a service server of a service provider; a process of storing an agency relationship in which a first user among the plurality of users is an agent and a second user is an agent; a process of determining whether or not the proxy relationship can be terminated, and if it is determined that the proxy relationship can be terminated, requesting the first user to consider terminating the proxy relationship; A computer-readable storage medium that stores a program for executing the above.

[0257] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof. [Explanation of symbols]

[0258] 10 Distribution Control Server 20 Service Server 20-1 Service Server 20-2 Service Server 30 Operator terminal 40 trading servers 50 devices 60 Hospital terminals 100 Server device 101 Management measures 102 Memory means 201 Communication control unit 202 User Management Department 203 ID Linkage Department 204 Location Information Management Department 205 Data Distribution Control Unit 206 Catalog Information Management Department 207 Memory section 301 Communication Control Unit 302 ID linkage control unit 303 Data Distribution Request Department 304 Data storage control unit 305 Data Distribution Department 306 Storage section 311 processor 312 memory 313 Input / Output Interface 314 Communication Interface 401 Communication control unit 402 Account Opening Department 403 Catalog Information Request 404 Provision Request Processing Unit 405 Storage section 501 Communication control unit 502 User registration control unit 503 Query processing unit 504 Review request notification processing unit 505 Storage section

Claims

1. a management means for managing accounts of a plurality of users who use a data distribution service that targets data stored in a service server of a service provider; a storage means for storing an agency relationship in which a first user among the plurality of users is an agent and a second user is an agent; Equipped with The management means determines whether the agency relationship can be terminated depending on whether the second user has acquired the capacity to be held responsible, and if it is determined that the agency relationship can be terminated because the second user has acquired the capacity to be held responsible, the server device requests the first user to consider terminating the agency relationship.

2. 2. The server device according to claim 1, wherein said management means cancels the proxy relationship between said first and second users when said first user wishes to cancel said proxy relationship.

3. 3. The server device according to claim 2, wherein the management means sets a status of the second user whose proxy relationship has been terminated to a status requiring personal identification.

4. The server device according to claim 3 , wherein the management unit requests the second user, for whom personal identification is required, to register an account that requires personal identification.

5. 5. The server device according to claim 4, further comprising a data distribution control means for controlling data distribution by data sharing or data provision, with the data stored in said service server as the object.

6. The server device according to claim 5, wherein the data distribution control means, when receiving a request for data distribution regarding the user data of the second user, makes an inquiry to the first user regarding the distribution of the user data of the second user.

7. The server device of claim 6, wherein the data distribution control means acquires a request for data distribution regarding the user data of the second user, and when the status of the second user is set to require personal identification, does not make an inquiry to either the first or second user regarding the distribution of the user data of the second user.

8. The server device of claim 7, wherein the data distribution control means, when it receives a request for data distribution regarding the user data of a second user for which personal identification is set as required after it is determined that the personal identification of the second user is successful, makes an inquiry to the second user whose personal identification has been successful regarding the distribution of the user data of the second user.

9. A computer installed in a server device, Manage the accounts of multiple users who use a data distribution service that targets data stored in the service server of the service provider; storing an agency relationship in which a first user among the plurality of users is an agent and a second user is an agent; A control method for a server device, which determines whether the agency relationship can be terminated depending on whether the second user has acquired criminal responsibility, and if it is determined that the agency relationship can be terminated because the second user has acquired criminal responsibility, requests the first user to consider terminating the agency relationship.

10. The computer installed in the server device A process for managing accounts of multiple users who use a data distribution service that targets data stored in a service server of a service provider; a process of storing an agency relationship in which a first user among the plurality of users is an agent and a second user is an agent; A process of determining whether or not the agency relationship can be terminated depending on whether or not the second user has acquired the capacity to be held responsible, and if it is determined that the agency relationship can be terminated because the second user has acquired the capacity to be held responsible, requesting the first user to consider terminating the agency relationship; A program to execute.

Citation Information

Patent Citations

  • Personal authentication system and method, and program

    JP2002222168A

  • Information processor, program, and information processing method

    JP2018163526A

  • Data distribution control device, data distribution control method, and data distribution control program

    JP2020129311A

  • Silver data trust system

    JP2020160843A

  • Method and apparatus to get consent using wireless internet protocol

    KR1020090041810A