Data service providing method and data service providing system

The data service system addresses the challenge of handling personal data securely and compliantly by acquiring user consent policies and generating data services aligned with these policies, ensuring robust data handling.

JP7768496B2Active Publication Date: 2025-11-12TOSHIBA DIGITAL SOLUTIONS CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2021181140
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-11-05
Publication Date
2025-11-12
Estimated Expiration
2041-11-05

AI Technical Summary

Technical Problem

Existing data service systems fail to adequately handle personal data with the necessary strictness and compliance to user consent terms.

Method used

A data service providing method and system that includes steps for acquiring user consent policies, setting service collaboration policies, and generating and providing data services based on these policies, ensuring strict handling of personal data.

Benefits of technology

Ensures secure and compliant handling of personal data by integrating user consent and service collaboration policies, providing a robust framework for data service provision.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007768496000001
    Figure 0007768496000001
  • Figure 0007768496000002
    Figure 0007768496000002
  • Figure 0007768496000003
    Figure 0007768496000003
Patent Text Reader

Abstract

To provide a data service providing method and a data service providing system that handle data more strictly based upon use rules, etc.SOLUTION: In a data service providing system, an access policy control part 2 acquires an access policy P1 including information related to an agreement of an individual user U about use of data providing business. Data acquisition parts 1A, 1B and 1C acquire first data including data on the individual user U from data providing business DB1, DB2 and DB3 based upon the access policy P1. A cooperation control part 3 acquires an access policy including an agreement of a second individual user about use of service business, and sets a service cooperation policy P2 cooperating with the access policy P1. A provided data generation part 4 generates second data used for data service provided to service business based upon the service cooperation policy P2.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] FIELD Embodiments of the present invention relate to a data service providing method and a data service providing system. [Background technology]

[0002] Services that link different services via servers or clouds are being offered. For example, systems have been proposed that link different services by linking member information (user IDs, etc.) of different services to provide services. In such service provision methods and service provision systems, it is desirable to handle data, including personal data of users, more strictly in accordance with terms of use, etc. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-128966 [Patent Document 2] Japanese Patent Application Publication No. 2018-156405 Summary of the Invention [Problem to be solved by the invention]

[0004] The problem to be solved by the present invention is to provide a data service providing method and a data service providing system that can handle data including personal data more strictly. [Means for solving the problem]

[0005] A data service providing method according to an embodiment includes a first policy acquisition step, a data acquisition step, a second policy acquisition step, a policy setting step, a data generation step, and a data providing step. The first policy acquisition step acquires a first policy including information regarding a first individual user's consent to use of a data providing business. The data acquisition step acquires first data including data of the first individual user from the data providing business based on the first policy. The second policy acquisition step acquires a second policy including information regarding a second individual user's consent to use of a service business. The policy setting step sets a service collaboration policy that links the first policy and the second policy. The data generation step generates second data to be used in a data service to be provided to the service business from the first data based on the service collaboration policy. The data providing step provides a data service to the service business based on the second data. [Brief explanation of the drawings]

[0006] [Figure 1] FIG. 1 is a configuration diagram of a data service providing system according to a first embodiment. [Figure 2] FIG. 2 is a diagram showing a specific example of the data service providing system. [Figure 3] FIG. 2 is a functional block diagram of the data service providing system. [Figure 4] FIG. 2 is a functional block diagram of a data acquisition unit of the data service providing system. [Figure 5] FIG. 2 is a functional block diagram of an access policy control unit of the data service providing system. [Figure 6] FIG. 10 is a diagram showing an example of a data item newly created based on a combination policy. [Figure 7] FIG. 2 is a functional block diagram of a linkage information recording unit of the data service providing system. [Figure 8] FIG. 10 is a diagram showing an example of data providing business collaboration information. [Figure 9] FIG. 10 is a diagram showing an example of service business collaboration information. [Figure 10] FIG. 10 is a diagram showing an example of a service collaboration policy. [Figure 11] A diagram showing the terms of use for the first service business. [Figure 12] A diagram showing terms of use for the second service business. [Figure 13] A diagram showing terms of use for a third service business. [Figure 14] FIG. 10 is a diagram showing an example of a generated virtual table. [Figure 15] FIG. 2 is a functional block diagram of a data access control unit of the data service providing system. [Figure 16] FIG. 10 is a diagram showing a policy violation monitoring history. [Figure 17] A sequence diagram of the data service providing system that operates in conjunction with a linked application provided to individual users by the first data providing business. [Figure 18] This is a sequence diagram of the data service providing system that operates in conjunction with a linked application provided to individual users by the first service business. [Figure 19] Service integration confirmation screen for the same integrated application. [Figure 20] Service integration confirmation screen for the same integrated application. [Figure 21] The service integration completion screen of the same integrated application. [Figure 22] FIG. 10 is a sequence diagram of the data access control unit that manages policy violations. [Figure 23] FIG. 10 is a diagram showing HTML descriptions for a data service provided to the data service monitoring unit by the second service business. DETAILED DESCRIPTION OF THE INVENTION

[0007] Hereinafter, a data service providing method and a data service providing system according to an embodiment will be described with reference to the drawings.

[0008] (First embodiment) [Data service providing system 100] FIG. 1 is a configuration diagram of a data service providing system 100 according to the first embodiment. The data service providing system 100 is a system that provides data services to registered users (individual users U and service providers SP). "Providing data services" includes not only providing the data itself, but also providing data analysis results and various services based on the data.

[0009] The data service providing system 100 is composed of one or more servers. The basic infrastructure of the data service providing system 100 is constructed using a known data distributed processing system. The functions of the data service providing system 100 are realized by programs executed on the processors of the servers.

[0010] FIG. 2 is a diagram showing a specific example of the data service providing system 100. As shown in FIG. 2 includes servers SV1, SV2, SV3, and SV4. The servers SV1, SV2, SV3, and SV4 include hardware such as a processor such as a CPU, a memory, a recording medium such as a hard disk or a flash memory, and a communication device.

[0011] The servers SV1, SV2, SV3, and SV4 may be servers with different types of OS, software, etc. Furthermore, the servers SV1, SV2, SV3, and SV4 may be operated by different operating entities. The servers SV1, SV2, SV3, and SV4 may be installed in different countries or different regions.

[0012] All of the hardware and software resources of servers SV1 and SV2 are dedicated to the data service providing system 100. On the other hand, only some of the hardware and software resources of servers SV3 and SV4 are provided to the data service providing system 100. In other words, the data service providing system 100 may be a system that combines on-site servers such as servers SV1 and SV2 with cloud servers such as servers SV3 and SV4 that provide IaaS (Infrastructure as a Service), PaaS (Platform as a Service), or SaaS (Software as a Service). In the following description, "server" includes any of the above servers.

[0013] The functional blocks of the data service providing system 100 (such as a data acquisition unit 1, an access policy control unit 2, a cooperation control unit 3, a provided data generation unit 4, and a data access control unit 5) described below are realized by the operation of servers (for example, servers SV1, SV2, SV3, and SV4 shown in FIG. 2) that are distributed and arranged via a network NW. Note that the functional blocks of the data service providing system 100 may also be realized by the operation of a single server.

[0014] 1, a data service providing system 100 is connected via a network NW to a data device 200 managed by a data provider (DP), a terminal 300 (hereinafter referred to as a personal terminal 300) such as a smartphone, tablet terminal, or personal computer owned by an individual user U, a management device 400 owned by an administrator A of the data service providing system 100, and a service providing device 500 owned by a service provider SP. The data device 200, the management device 400, and the service providing device 500 may be a system configured by one or more servers.

[0015] The network NW may be a wide area network (WAN) such as the Internet, a private network (LAN) within the building where the data service providing system 100 is installed, or a combination thereof. The network NW may be either a wired or wireless network. Communication between devices may involve other devices such as an access point.

[0016] FIG. 3 is a functional block diagram of the data service providing system 100. As shown in FIG. The data service providing system 100 includes a data acquiring unit 1, an access policy control unit 2, a cooperation control unit 3, a provided data generating unit 4, and a data access control unit 5.

[0017] The data acquisition unit 1 acquires data including personal data of an individual user U from a data device 200 of a data provider DP and records it as acquired data (first data) D. The data access control unit 5 controls the system to respond to data service requests from service providers SP and the like. The provided data generation unit 4 generates provided data (second data) from the acquired data (first data) D in response to a data access request via the data access control unit 5. The access policy control unit 2 controls an access policy P1 for the acquired data (first data) D when generating the provided data (second data). The collaboration control unit 3 controls a service collaboration policy P2 that collaborates between the individual user U, a service business SB, and a data provision business DB.

[0018] [Data Acquisition Section 1] FIG. 4 is a functional block diagram of the data acquisition unit 1. The data acquisition unit 1 acquires data including personal data of an individual user U from the data device 200 of the data provider DP and records it as acquired data (first data) D (data acquisition step). The data acquisition unit 1 also provides the acquired data D to the provided data generation unit 4. The data acquisition unit 1 has a data import interface 11 and an acquired data recording unit 12.

[0019] The data import interface 11 is an interface for acquiring data from the data device 200 of the data provider DP. The data device 200 of the data provider DP provides data, including personal data of an individual user U, acquired with the consent of the individual user U to the data service providing system 100 via the data import interface 11.

[0020] Based on a contract with the data provider DP, the data import interface 11 acquires data from the data device 200 as the data providing business DB of the data provider DP and records the data in the acquired data recording unit 12. For example, the data import interface 11 periodically acquires data in bulk from the data device 200 of the data provider DP and updates the acquired data D recorded in the acquired data recording unit 12 (bulk type). The data import interface 11 may also acquire data in real time from a device connected via an API (Application Programming Interface) (streaming type).

[0021] The acquired data recording unit 12 is a data storage that records acquired data (first data) D acquired from the data provider DP. The acquired data (first data) D may be the raw data itself acquired from the data provider DP, or may be processed data that has been processed into a standard data format or the like by a data processing unit (not shown). The processed data is, for example, statistical data, aggregated data, anonymized data, pseudonymized data, etc.

[0022] In this embodiment, the data service providing system 100 has three data acquisition units 1. In the following description, when distinguishing between the three data acquisition units 1, they will be referred to as a first data acquisition unit 1A, a second data acquisition unit 1B, and a third data acquisition unit 1C, respectively.

[0023] The data acquisition unit 1 (first data acquisition unit 1A, second data acquisition unit 1B, and third data acquisition unit 1C) acquires and records acquired data D including multiple data types with different handling policies. Data including multiple data types with different handling policies is also called a "data group."

[0024] The first data acquisition unit 1A acquires and records purchasing data D1 provided by the first data providing business DB1, for example, from a data device 200 (hereinafter also referred to as "data device 200A") managed by the data provider DP1. The purchasing data D1 is, for example, purchasing detail data on a receipt or payment data. The data import interface 11 (hereinafter also referred to as "data import interface 11A") of the first data acquisition unit 1A is an interface that can acquire the purchasing data D1 from the data provider DP1.

[0025] The second data acquisition unit 1B acquires and records HR (Human Resources) data D2 provided by the second data providing business DB2, for example, from a data device 200 (hereinafter also referred to as "data device 200B") managed by the data provider DP2. The HR data D2 includes, for example, personnel announcement data, attendance data, salary data, and training data. The data import interface 11 (hereinafter also referred to as "data import interface 11B") of the second data acquisition unit 1B is an interface that can acquire the HR data D2 from the data provider DP2.

[0026] The third data acquisition unit 1C acquires and records health data D3 provided by the third data provider DB3, for example, from a data device 200 (hereinafter also referred to as "data device 200C") managed by the data provider DP3. The health data D3 may be, for example, health checkup data or daily vital health data. The data import interface 11 (hereinafter also referred to as "data import interface 11C") of the third data acquisition unit 1C is an interface that can acquire the health data D3 from the data provider DP3.

[0027] The data import interfaces 11 (data import interface 11A, data import interface 11B, and data import interface 11C) differ depending on the type of data to be handled and the data provider. Note that the data import interface 11 may be a general-purpose interface that can be used regardless of the type of data to be handled or the data provider.

[0028] The data acquisition unit 1 (first data acquisition unit 1A, second data acquisition unit 1B, and third data acquisition unit 1C) is a distributed storage distributed across different servers, and can store acquired data D including multiple data types with different handling policies in a distributed manner. Note that the data acquisition unit 1 (first data acquisition unit 1A, second data acquisition unit 1B, and third data acquisition unit 1C) may be provided on the same server. The acquired data D may include personal data such as intellectual education data, physical education data, moral education data, educational attendance data, qualification acquisition data, medical checkup data, power consumption data, gas usage data, water usage data, communication statement data, schedule data, music and video viewing data, etc.

[0029] In this embodiment, "purchase data," "HR data," and "health data" are used as examples of multiple data types with different handling policies, but the multiple data types with different handling policies are not limited to this. For example, when purchasing data is acquired from multiple different data providers, it may be handled as acquired data including a single data type with different handling policies.

[0030] [Access policy control section 2] FIG. 5 is a functional block diagram of the access policy control unit 2. As shown in FIG. The access policy control unit 2 controls an access policy P1 for the acquired data D recorded in the acquired data recording unit 12. The access policy P1 includes whether or not access to the acquired data D is permitted and the access conditions. The access policy P1 may include information regarding the deletion deadline for the acquired data D, the expiration date for data usage after conversion, such as anonymization or pseudonymization, from the raw data at the time of acquisition, and the life cycle. The access policy P1 may also include information regarding whether or not combined use with different types of data is permitted. The access policy control unit 2 has an access policy interface 21 and an access policy recording unit 24.

[0031] The access policy interface 21 is an interface connected to the personal terminal 300 and the management device 400 owned by the administrator A of the data service providing system 100. Specifically, the access policy interface 21 includes an API that connects the personal terminal 300 and the management device 400 with the access policy recording unit 24. The access policy interface 21 has an interface 22 for personal users and an interface 23 for administrators.

[0032] The personal user interface 22 includes an API that connects the personal terminal 300 and the access policy recording unit 24. The personal user interface 22 also connects the personal terminal 300 and the data access control unit 5, as shown in FIG.

[0033] The administrator interface 23 includes an API that connects the management device 400 owned by the administrator A and the access policy recording unit 24 .

[0034] The access policy recording unit 24 records an access policy P1 for the acquired data D. The access policy P1 recorded in the access policy recording unit 24 is managed by an individual user U and an administrator A via an access policy interface 21. The access policy recording unit 24 has a first access policy recording unit 25 and a second access policy recording unit 26.

[0035] The first access policy recording unit 25 records the access policy set by the individual user U via the individual user interface 22. The access policies recorded by the first access policy recording unit 25 include an individual user access policy 251 and a comprehensive access policy 252.

[0036] The individual user access policy 251 is an access policy set for each individual user U, which determines whether or not the service business SB can access the acquired data D including the personal data of the individual user U. The individual user access policy 251 is an access policy set for the personal data of the individual user U for various conditions, such as for each service business DB that provided the acquired data D, for each service business SB that uses the acquired data D, for each data type or purpose of use of the acquired data D, for each data provision mode, for each consent policy, for each region of use, and for each life cycle of the acquired data D. The individual user U can set the individual user access policy 251 for all combinations of these conditions.

[0037] The access policy that can be set for each data providing business DB in the individual user access policy 251 is, for example, whether data access is permitted when the data providing business DB that provided the acquired data D is the "first data providing business DB1" or the "second data providing business DB2."

[0038] The access policy that can be set for each service business SB in the individual user access policy 251 is, for example, whether data access is permitted when the service business SB is the "first service business SB1" or the "second service business SB2."

[0039] The access policy that can be set for each service business SB in the individual user access policy 251 is, for example, whether data access is permitted based on attribute information such as business category, industry, or business type, such as when the service business SB is a "public utility" or a "profit-making business."

[0040] The access policy that can be set for each data type in the individual user access policy 251 is, for example, whether or not data access is permitted when the data type is "purchase data D1" or "health data D3."

[0041] The access policy that can be set for each purpose of use in the individual user access policy 251 is, for example, whether data access is permitted when the purpose of use is "statistical use without identifying an individual" or "non-statistical use with identifying an individual."

[0042] The comprehensive access policy 252 is an access policy that comprehensively specifies the individual user access policies 251. The comprehensive access policy 252 roughly indicates whether or not access is permitted to the personal data of an individual user U, for example, using a tiered index ranging from level 1 to level 5. By setting the comprehensive access policy 252, the individual user U can roughly set the individual user access policy 251 for each individual user U, without having to set all of the individual user access policies 251.

[0043] In the following description, the “individual user access policy 251 ” includes the individual user access policy 251 that is broadly set by the comprehensive access policy 252 .

[0044] The personal user U can access the personal user access policy 251 using an application implemented using the API of the personal user interface 22. The application may be a native application running on the personal terminal 300, or a Web application running on the data service providing system 100. In the following description, the applications implemented using the API of the personal user interface 22 will also be referred to as "cooperative application AP1" and "cooperative application AP2."

[0045] The second access policy recording unit 26 records the access policy set by the administrator A via the administrator interface 23. The access policy recorded by the second access policy recording unit 26 includes virtual table definition information 261, a data type handling policy 262, a data type combination policy 263, and a service business access policy 264.

[0046] The virtual table definition information 261 is definition information used to set an access policy, and defines the specifications of the virtual table T generated by the provided data generation unit 4. The specifications defined in the virtual table definition information 261 are, for example, a schema indicating the structure and data items (columns) of the virtual table T. The "data items" are the types of data (contents, data types, etc.) handled by the virtual table T.

[0047] Data items that are not defined in the virtual table definition information 261 cannot be accessed from the data access control unit 5. The data items to be defined may be data items that are included in the acquired data D in advance, or may be data items that are newly created by combining data items from different acquired data D.

[0048] The data type handling policy 262 is an access policy that sets the handling of acquired data D for each data type. The data type handling policy 262 is, for example, a handling policy for purchasing data D1, a handling policy for HR data D2, or a handling policy for health data D3. The data type handling policy 262 may include data required when handling the acquired data D, such as metadata that indicates details of the acquired data D, such as an item code. By setting a handling policy for each data type, the data service providing system 100 can handle a wide variety of acquired data D.

[0049] The data type combination policy 263 is an access policy that sets a combination of different data types of acquired data D. The data type combination policy 263 is, for example, a rule for using the purchase data D1 and health data D3 in combination.

[0050] FIG. 6 is a diagram showing an example of a data item newly created based on the data type combination policy 263. Data items of acquired data D of different data types are combined based on the data type combination policy 263 and used as a new data item. For example, as shown in FIG. 6, the data items "food purchase date and time" and "purchased food name" of purchasing data D1 and the data item "exercise date and time" of health data D3 are combined and used as a new data item "name of food purchased before and after exercise." By setting the data type combination policy 263, it is possible to easily create a new data item that seamlessly associates data items of data types with different handling policies.

[0051] The service business access policy 264 is an access policy set for each service business SB based on a contract with the service provider SP, etc., which determines whether the service business SB can access the acquired data D. The service business access policy 264 is set for each "data item" defined in the virtual table definition information 261. The service business access policy 264 can be set comprehensively, for example, so as not to permit the first service business SB1 to access all data items related to the HR data D2.

[0052] The administrator A can access the first access policy recording unit 25 and the second access policy recording unit 26 using an application implemented using the API of the administrator interface 23. The application may be a native application that runs on the management device 400 owned by the administrator A, or a web application that runs on the data service providing system 100.

[0053] [Coordination Control Unit 3] FIG. 7 is a functional block diagram of the cooperation control unit 3. The linkage control unit 3 sets a service linkage policy P2 that links the individual user U, the service business SB, and the data providing business DB. The service linkage policy P2 is information that links the service business SB and the data providing business DB to the individual user U in order to provide a data service to the individual user U, and includes member ID data linkage information C1, information regarding the terms of use of the service business SB and the data providing business DB, and information regarding the individual user U's agreement to the terms of use. The linkage control unit 3 has a linkage interface 30 and a linkage information recording unit 34.

[0054] The collaboration interface 30 is an interface connected to the data device 200 owned by the data provider DP, the service providing device 500 owned by the service provider SP, and the management device 400 owned by the administrator A of the data service providing system 100. Specifically, the collaboration interface 30 includes an API that connects the service providing device 500 and the management device 400 with the collaboration information recording unit 34. The collaboration interface 30 has a data providing business collaboration interface 31, a service business collaboration interface 32, and an administrator collaboration interface 33.

[0055] The data provision business collaboration interface 31 is an interface connected to the data device 200 owned by the data provider DP. For example, the data provision business collaboration interface 31 is an interface connected to the data device 200A owned by the data provider DP1. The data provision business collaboration interface 31 includes an API that connects the data device 200 owned by the data provider DP and the collaboration information recording unit 34.

[0056] The service business collaboration interface 32 is an interface connected to a service providing device 500 owned by a service provider SP. For example, the service business collaboration interface 32 is an interface connected to a service providing device 500 owned by a service provider SP1 (hereinafter also referred to as "service providing device 500A") and a service providing device 500 owned by a service provider SP2 (hereinafter also referred to as "service providing device 500B"). The service business collaboration interface 32 includes an API that connects the service providing device 500 owned by the service provider SP and the collaboration information recording unit 34.

[0057] The administrator collaboration interface 33 is an interface connected to the management device 400 owned by the administrator A of the data service providing system 100. The administrator collaboration interface 33 includes an API that connects the management device 400 owned by the administrator A and the collaboration information recording unit 34.

[0058] The association information recording unit 34 records association information of users of the data service providing system 100. The association information recording unit 34 has a business operator association information recording unit 35 and an individual user association information recording unit 36. The business operator association information recording unit 35 records data providing business association information 351 and service business association information 354.

[0059] FIG. 8 is a diagram showing an example of the data providing business collaboration information 351. As shown in FIG. The data providing business collaboration information 351 has first linked member ID data 352 and a data providing business service collaboration policy 353. The data providing business collaboration information 351 is information that associates the first linked member ID data 352 with the data providing business service collaboration policy 353.

[0060] The first linked member ID data 352 is member ID data managed by the data provider DP and is member ID data that identifies individual user U in the data provided by the data provider DP. The first linked member ID data 352 includes a member ID managed by the data provider DP and member information associated with the member ID (name, address, date of birth, age, gender, email address, etc.). The data provision business linkage information 351 illustrated in FIG. 8 is information managed by the data provider DP1 and includes member ID data managed by the data provider DP1.

[0061] The member ID of the first linked member ID data 352 may not be the member ID itself managed by the data provider DP, but may be linked member ID data generated to indicate link information.

[0062] The service collaboration policy for data provision business (first policy) 353 is a service collaboration policy for the data provision business DB that includes the terms of use (first terms of use) specified for each data provision business DB of the data provider DP and the consent data of the individual user U to the terms of use.

[0063] The terms of use in the data provider business service collaboration policy 353 indicate the type of terms of use specified for each data provider business DB. The data provider business collaboration information 351 illustrated in FIG. 8 includes terms of use TD1 for the first data provider business DB1 provided by the data provider DP1 and terms of use TD2 for the first data provider business DB1. As shown in FIG. 8, terms of use for the same data provider business DB but with different content are managed as separate records. For example, if an individual user U agrees to terms of use TD2 for the first data provider business DB1, which specifies "statistical use that does not identify individuals (including provision to third parties)," and then agrees to terms of use TD1, which specifies "non-statistical use that identifies individuals (including provision to third parties)," then the agreements to these terms of use are managed as separate records. Furthermore, "terms of use with different content" include terms of use with different versions. For example, if an individual user U agrees to terms of use TD1 for the first data provider business DB1 and then agrees to terms of use TD1', which is a revised version of terms of use TD1, then the agreements to these terms of use are managed as separate records.

[0064] The consent data (also referred to as "information regarding consent") in the data provision business service collaboration policy 353 is data indicating the individual user U's consent to the corresponding terms of use (whether consent was granted, the date of consent, etc.). The consent data included in the data provision business collaboration information 351 illustrated in FIG. 8 indicates the date on which the corresponding terms of use were agreed to. "NULL" entered instead of the date in the consent data indicates that the individual user U has not agreed to the corresponding terms of use.

[0065] FIG. 9 is a diagram showing an example of the service business collaboration information 354. As shown in FIG. The service business collaboration information 354 has second linked member ID data 355 and a service collaboration policy for service business 356. The service business collaboration information 354 is information that associates the second linked member ID data 355 with the service collaboration policy for service business 356.

[0066] The second linked member ID data 355 is member ID data managed by the service provider SP and is member ID data that identifies the individual user U and is used by the service provider SB when reading data via the data access control unit 5. The second linked member ID data 355 includes a member ID managed by the service provider SP and member information associated with the member ID (such as name, address, date of birth, age, gender, and email address). The service business linkage information 354 illustrated in FIG. 9 is information managed by the service provider SP1 and includes member ID data managed by the service provider SP1.

[0067] The member ID of the second linked member ID data 355 may not be the member ID data itself managed by the service provider SP, but may be linked member ID data generated to indicate link information.

[0068] The service collaboration policy for service business (second policy) 356 is a service collaboration policy for service business SB that includes terms of use (second terms of use) specified for each service business SB of the service provider SP and consent data of individual user U to the terms of use.

[0069] The terms of use in the service collaboration policy 356 for service businesses indicate the type of terms of use specified for each service business SB. The service business collaboration information 354 illustrated in FIG. 9 includes terms of use TS1 for the first service business SB1 provided by the service provider SP1, terms of use TS2 for the second service business SB2, terms of use TS3 for the third service business SB3, and terms of use TS4 for the first service business SB1. As illustrated in FIG. 9, terms of use for the same service business SB but with different content are managed as separate records. For example, if an individual user U agrees to terms of use TS1 that specify the basic usage of the first service business SB1 and then agrees to terms of use TS4 that specify additional optional usage, the agreements to these terms of use are managed as separate records. Furthermore, "terms of use with different content" include terms of use with different versions. For example, if an individual user U agrees to terms of use TS1 for the first service business SB1 and then agrees to terms of use TS1', a revised version of terms of use TS1, the agreements to these terms of use are managed as separate records.

[0070] The consent data (also referred to as "consent information") in the service business service collaboration policy 356 is data indicating the individual user U's consent to the corresponding terms of use (such as whether consent was granted, the date of consent, etc.). The consent data included in the service business collaboration information 354 illustrated in FIG. 9 indicates the date on which the individual user U agreed to the corresponding terms of use. "NULL" entered instead of a date in the consent data indicates that the individual user U has not agreed to the corresponding terms of use. For example, if the terms of use of the service business SB are updated during a period in which the individual user U is not using the service business SB, it is unclear whether the individual user U has agreed to the new terms of use, and therefore the consent data for the individual user U is set to "NULL." Furthermore, if it is unclear for other reasons whether the individual user U has agreed to the terms of use, the consent data for the individual user U is set to "NULL."

[0071] The individual user association information recording unit 36 ​​records member ID data 361 and the like of registered individual users U who use the data service providing system 100. The administrator A can update the data recorded in the individual user association information recording unit 36 ​​via the administrator association interface 33.

[0072] FIG. 10 is a diagram showing an example of the service collaboration policy P2. The linkage control unit 3 generates member ID data linkage information C1 that associates first linked member ID data 352 and second linked member ID data 355 with member ID data 361. The linkage control unit 3 also generates a "service linkage policy P2" that associates service linkage policy for data providing business 353 and service linkage policy for service business 356 with member ID data linkage information C1. This allows individual user U, service business SB, and data providing business DB to link with each other in the data service provided by data service providing system 100.

[0073] The service collaboration policy P2 illustrated in FIG. 10 is generated when data provided by the data provider business DB1, the use of which is regulated by the terms of use TD1 of the data provider business DB1, is linked to the service businesses SB (first service business SB1, second service business SB2, and third service business SB3) provided by the service provider SP1. The service collaboration policy P2 is generated or updated, for example, when at least a portion of the data constituting the service collaboration policy P2 (member ID data 361, first linked member ID data 352, data provider business service collaboration policy 353, second linked member ID data 355, and service business service collaboration policy 356) is updated. For example, when an individual user U who has agreed to the terms of use TD1 of the data provider business DB1 agrees to the terms of use TS1 of the first service business SB1 and the service business service collaboration policy 356 is updated, the service collaboration policy P2 is updated. Note that in the service collaboration policy illustrated in FIG. 10, member information other than the name (address, date of birth, age, gender, email address, etc.) is omitted from the illustration.

[0074] [Provided Data Generation Unit 4] The provided data generation unit 4 generates provided data (second data) from acquired data (first data) D in response to a data access request from a registered user (individual user U and service provider SP) via the data access control unit 5. The data that the registered user (individual user U and service provider SP) can read via the data access control unit 5 is not the acquired data D recorded in the acquired data recording unit 12, but the provided data (second data).

[0075] The provided data generation unit 4 generates a virtual table T corresponding to the data access request as provided data (second data). The virtual table T is a table that is generated for each data access request and is not recorded in its entirety in a non-volatile storage unit. The provided data generation unit 4 responds to the data access request from the data access control unit 5 based on the generated virtual table T. As shown in FIG. 3, the provided data generation unit 4 has an access control integration unit 41 and a virtual table generation unit 42.

[0076] In response to a data access request from the data access control unit 5, the access control integration unit 41 integrates the "access policy P1" recorded in the access policy recording unit 24 with the "service collaboration policy P2" generated in the collaboration information recording unit 34 to generate "access control information P3." The access control information P3 is generated or updated, for example, when at least a part of the data constituting the access control information P3 (access policy P1 and service collaboration policy P2) is updated.

[0077] The virtual table generation unit 42 generates a virtual table (second data) T from the acquired acquired data (first data) D based on the access control information P3 generated by the access control integration unit 41.

[0078] The virtual table generation unit 42 acquires from the data acquisition unit 1 the acquisition data D required to respond to the data access request from the data access control unit 5, based on the access policy P1 and the service cooperation policy P2 included in the access control information P3.

[0079] Specifically, the virtual table generation unit 42 generates a virtual table (second data) T from the acquired data (first data) D based on the individual user access policy 251 included in the access policy P1. For example, if an individual user U restricts the use of personal data for the service business SB that made the data access request or for the purpose of use, the virtual table generation unit 42 generates a virtual table T from which the relevant personal data has been deleted.

[0080] Specifically, the virtual table generation unit 42 generates a virtual table (second data) T from the acquired data (first data) D based on the individual user access policy 251 included in the access policy P1. For example, if an individual user U restricts the use of a specific data item for the service business SB that has made the data access request, the virtual table generation unit 42 generates a virtual table T from which the relevant data item has been deleted.

[0081] Specifically, the virtual table generation unit 42 generates a virtual table (second data) T from the acquired data (first data) D based on the data provision business service collaboration policy 353 (see FIG. 10) included in the service collaboration policy P2. When the acquired data (first data) D used by the service business SB includes data provided by an individual user U, the virtual table generation unit 42 generates a virtual table T using data items permitted for use based on the terms of use of the data provision business DB to which the individual user U agreed.

[0082] For example, suppose that an individual user U who provided data to a first data providing business DB1, which is an electronic receipt business, has agreed to terms of use TD1 that stipulate "non-statistical use (including provision to a third party) that identifies individuals." In this case, when the acquired data (first data) D used by the service business SB includes data provided by the individual user U, the virtual table generation unit 42 can generate a virtual table T that includes data items related to the purchasing data D1 of the individual user U (such as the name of the food purchased and the date and time of food purchase) and data items that identify the individual user U (such as name).

[0083] For example, suppose that an individual user U who provided data to a first data providing business DB1, which is an electronic receipt business, agrees to terms of use TD2 that stipulate "statistical use without identifying individuals (including provision to a third party)." In this case, when the acquired data (first data) D used by the service business SB includes data provided by the individual user U, the virtual table generation unit 42 can generate a virtual table T that includes data items related to the purchasing data D1 of the individual user U (such as the name of the food purchased and the date and time of food purchase) but does not include data items that identify the individual user U (such as name). Furthermore, the data access control unit 5 is permitted to use the generated virtual table T only when the data access request from the data access control unit 5 is for statistical use.

[0084] Specifically, the virtual table generation unit 42 generates a virtual table (second data) T from the acquired data (first data) D based on the service collaboration policy 356 for the service business included in the service collaboration policy P2 (see FIG. 10). When a data access request is made from the service business SB in response to a request from an individual user U, the virtual table generation unit 42 generates the virtual table T using data items permitted for use based on the terms of use of the service business SB to which the individual user U has agreed.

[0085] FIG. 11 is a diagram showing terms of use TS1 for the first service business SB1. For example, suppose that an individual user U who uses the first service business SB1 agrees to the terms of use TS1 shown in Fig. 11. In this case, when a data access request is made from the first service business SB1 in response to a request from the individual user U, the virtual table generation unit 42 generates a virtual table T using data items that are permitted to be used based on the terms of use TS1 of the first service business SB1 to which the individual user U has agreed.

[0086] FIG. 12 is a diagram showing terms of use TS2 for the second service business SB2. For example, suppose that an individual user U who uses the second service business SB2 agrees to the terms of use TS2 shown in Fig. 12. In this case, when a data access request occurs from the second service business SB2 in response to a request from the individual user U, the virtual table generation unit 42 generates a virtual table T using data items that are permitted to be used based on the terms of use TS2 of the second service business SB2 to which the individual user U has agreed.

[0087] FIG. 13 is a diagram showing terms of use TS3 for the third service business SB3. For example, suppose that an individual user U who uses a third service business SB3 agrees to the terms of use TS3 shown in Fig. 13. In this case, when a data access request is made from the third service business SB3 in response to a request from the individual user U, the virtual table generation unit 42 generates a virtual table T using data items that are permitted to be used based on the terms of use TS3 of the third service business SB3 to which the individual user U has agreed.

[0088] FIG. 14 is a diagram showing an example of the virtual table T that is generated. The virtual table generation unit 42 generates a virtual table T for each service business SB that has received a data access request. For example, as shown in FIG. 14, the virtual table generation unit 42 creates a first virtual table T1 for a data access request from a first service business SB1. The virtual table generation unit 42 also creates a second virtual table T2 for a data access request from a second service business SB2. The virtual table generation unit 42 also creates a third virtual table T3 for a data access request from a third service business SB3. However, if the access control information P3 for multiple data access requests is the same, the virtual table generation unit 42 may generate only one virtual table T to respond to multiple data access requests with the same access control information P3.

[0089] [Data Access Control Unit 5] FIG. 15 is a functional block diagram of the data access control unit 5. The data access control unit 5 responds to data service requests from registered users (individual users U and service providers SP). After receiving a data service request, the data access control unit 5 issues a data access request to the provided data generation unit 4 to access the provided data (second data) required to provide the requested data service. The data access control unit 5 provides a data service to the data service requester based on the provided data (second data) acquired from the provided data generation unit 4. Providing a data service includes not only providing the data itself, but also providing data analysis results and various services based on the data. Methods of providing a data service include allowing the user to access the provided data generated in the data service providing system 100, and sending the generated provided data to the user via a predetermined network.

[0090] The data access control unit 5 also monitors whether or not there is a violation of the service collaboration policy P2 (hereinafter also referred to as "policy violation") in the provided data (second data) and the data service. Note that the data access control unit 5 may monitor whether or not there is a violation of the access policy P1 in addition to the violation of the service collaboration policy P2.

[0091] The data access control unit 5 has a service business data access interface 52, a personal user data access interface 53, a provided data monitoring unit 54, a data service monitoring unit 55, and a policy violation recording unit 56.

[0092] The service business data access interface 52 includes an API that connects the service providing device 500 owned by the service business SP with the provided data generation unit 4. The service business SB can receive data services from the data service providing system 100 via the service business data access interface 52.

[0093] The service business data access interface 52 includes, for example, an API for data search, an API for data analysis, and an API for visualizing the results of data analysis.

[0094] The personal user data access interface 53 connects the personal user interface 22 and the provided data generation unit 4. Via the personal user interface 22 and the personal user data access interface 53, the personal user U can confirm how his or her own personal data is being accessed by the service business SB.

[0095] The provided data monitoring unit 54 monitors whether or not there is a policy violation in the provided data (second data) acquired from the provided data generation unit 4. Specifically, when a data access request is issued from the service business SB in response to a request from an individual user U, the provided data monitoring unit 54 monitors whether or not the provided data acquired from the provided data generation unit 4 has been generated using only data items whose use is permitted based on the terms of use of the service business SB to which the individual user U has agreed.

[0096] For example, suppose that individual user U agrees to the terms of use TS2 (see FIG. 12) of the second service business SB2. The terms of use TS2 (see FIG. 12) do not permit the use of data items such as date of birth and age. When a data access request is issued from the second service business SB2 in response to a request from the individual user U, if the data items such as date of birth and age are used in the provided data acquired from the provided data generation unit 4, the provided data monitoring unit 54 detects a policy violation in the provided data.

[0097] The data service monitoring unit 55 monitors whether or not there is a policy violation in the data service provided to the service business SB by the service business data access interface 52. Specifically, the data service monitoring unit 55, acting as a virtual individual user U, issues a data service request to the service business data access interface 52 and monitors whether or not there is a policy violation in the data service provided.

[0098] Here, it is assumed that the data service monitoring unit 55, acting as a virtual individual user U of the service business SB, receives data services from the service business SB with the consent of the service provider SP that provides the service business SB.

[0099] For example, the data service monitoring unit 55 registers a virtual individual user VU, who is a virtual individual user U, as a user of the third service business SB3. Assume that the virtual individual user VU agrees to the terms of use TS3 (see FIG. 13) of the third service business SB3. The terms of use TS3 (see FIG. 13) do not permit the use of the data item of name. Next, the data service monitoring unit 55, acting as a data crawler, generates a data service request in response to a request from the virtual individual user VU to the service business data access interface 52. If the data item of name is used in the data service provided, the data service monitoring unit 55 detects a policy violation in the data service.

[0100] For example, the data service monitoring unit 55 detects a policy violation in a data service when an item related to a data item that is not permitted to be used is described in the HTML description of a web page or an API argument provided in the data service.

[0101] The data service monitoring unit 55 monitors policy violations in data services periodically at a preset cycle, such as once a week. Note that the data service monitoring unit 55 may also monitor policy violations in data services at random cycles.

[0102] FIG. 16 is a diagram showing the policy violation monitoring history PR. The policy violation recording unit 56 records policy violations detected by the provided data monitoring unit 54 or the data service monitoring unit 55 as a policy violation monitoring history PR. The policy violation monitoring history PR records details of the provided data or data service in which a policy violation was detected. The policy violation monitoring history PR includes the data providing business DB that is the data provider, the provided data ID that identifies the provided data that was used, the service provider SP and service business SB that are the recipients of the data, the terms of use that violated the policy, and the date and time of the violation.

[0103] [Operation of the data service providing system 100] Next, the operation of the data service providing system 100 when the first individual user U1 and the second individual user U2, who are individual users U, use the data service providing system 100 will be described.

[0104] <Collaboration with DB1, the first data provider> FIG. 17 is a sequence diagram of the data service providing system 100 that operates in conjunction with the cooperative application AP1 that the first data providing business DB1 provides to the individual user U.

[0105] A first personal user U1 is a user of the first data providing business DB1, and sends an application to the data service providing system 100 via an associated application AP1 installed on a personal terminal 300 to use the services of the first data providing business DB1, which is an electronic receipt business, via the data service providing system 100.

[0106] If the first individual user U1 who has applied for use is not a member of the data service providing system 100, the data service providing system 100 requests the first individual user U1 to register as a member of the data service providing system 100 via the data provision business collaboration interface 31. The first individual user U1 who has been requested to register as a member applies for registration as a member of the data service providing system 100 via the collaboration application AP1. The data provision business collaboration interface 31 updates the member ID data 361 in the individual user collaboration information recording unit 36.

[0107] The data service providing system 100 transmits at least one set of terms of use (such as the above-mentioned terms of use TD1 and terms of use TD2) to the first individual user U1 via the data providing business cooperation interface 31.

[0108] The first individual user U1 selects the terms of use to which he or she agrees via the cooperative application AP1 and transmits the selected terms of use to the data service providing system 100.

[0109] The data providing business collaboration interface 31 updates the data providing business service collaboration policy 353 in the business collaboration information recording unit 35 using information related to the terms of use agreed to by the first individual user U1.

[0110] Thereafter, the data import interface 11A of the first data acquisition unit 1A acquires purchasing data D1 related to the first individual user U1 from the data provider DP1 based on the terms of use agreed to by the first individual user U1, and records the data in the acquired data recording unit 12. The data import interface 11A may periodically acquire data in bulk (bulk type), or may acquire data in real time from a device connected via an API, for example (streaming type).

[0111] <Collaboration with First Service Business SB1> FIG. 18 is a sequence diagram of the data service providing system 100 that operates in conjunction with the cooperative application AP2 that the first service business SB1 provides to the individual user U.

[0112] A first personal user U1 and a second personal user U2 are users of the first service business SB1, and send a usage application to the data service providing system 100 via the collaboration application AP2 installed on the personal terminal 300 to use the services of the first data providing business DB1, which is a recipe suggestion business, via the data service providing system 100.

[0113] If the first personal user U1 or second personal user U2 who has applied for use is not a member of the data service providing system 100, the data service providing system 100 requests membership registration with the data service providing system 100 via the service business collaboration interface 32. The first personal user U1 or second personal user U2 who has been requested to register as a member applies for membership registration with the data service providing system 100 via the collaboration application AP2. The service business collaboration interface 32 updates the member ID data 361 in the personal user collaboration information recording unit 36.

[0114] The data service providing system 100 transmits at least one use of service (such as the use of service TS1 described above) to the first individual user U1 and the second individual user U2 via the service business cooperation interface 32.

[0115] The first individual user U1 and the second individual user U2 transmit the terms of use to which they agree to the data service providing system 100 via the cooperative application AP2.

[0116] The service business collaboration interface 32 updates the service business service collaboration policy 356 in the business collaboration information recording unit 35 using information regarding the terms of use agreed to by the first individual user U1 and the second individual user U2.

[0117] <Data service for second individual user U2> The second individual user U2 is not a user of the first data provider business DB1, but is a user of the first service business SB1. In this case, the second individual user U2 can use data services using data provided by other individual users U in the services provided by the first service business SB1, within the scope of the terms of use agreed to by the other individual users U who provided data to the first data provider business DB1 (for example, "statistical use without identifying individuals (including provision to third parties)"). However, the data services available to the second individual user U2 are limited to data items that are permitted for use based on the terms of use of the first service business SB1 agreed to by the second individual user U2.

[0118] For example, the collaborative application AP2 provided by the first service business SB1 (recipe suggestion business) can suggest popular recipes to a second individual user U2 from statistical information generated based on purchasing data D1 of an unspecified number of individual users U obtained from the first data provision business DB1 (electronic receipt business).

[0119] <Data service for first individual user U1> On the other hand, first individual user U1 is a user of first data provider business DB1 and first service business SB1. In this case, first individual user U1 can also use data services using data that he / she provided to first data provider business DB1 (electronic receipt business) within the scope of the terms of use to which he / she agreed in the services provided by first service business SB1 (recipe suggestion business). However, the data services that first individual user U1 can use are limited to data items that are permitted for use based on the terms of use of first service business SB1 to which first individual user U1 agreed.

[0120] For example, the collaborative application AP2 provided by the first service business SB1 (recipe suggestion business) can suggest optimal recipes to the first individual user U1 based on the purchasing data D1 of the first individual user U1 obtained from the first data provision business DB1 (electronic receipt business).

[0121] <Service collaboration> In order to receive the above data service, the first individual user U1 transmits a service link between the first data providing business DB1 and the first service business SB1 to the data service providing system 100 via the link application AP2 (a service link request). If necessary, the first individual user U1 transmits information (such as a member ID) indicating that he or she is a member who uses the first data providing business DB1 to the data service providing system 100.

[0122] The service business collaboration interface 32 updates the data collaboration policy P2 (see FIG. 10) in the business collaboration information recording unit 35 based on a service collaboration request from the first individual user U1. Specifically, the member ID data collaboration information C1 is updated, and the data providing business service collaboration policy 353 and the service business service collaboration policy 356 related to the first individual user U1 are associated with the updated member ID data collaboration information C1. As a result, the first individual user U1 can use the data service of the first service business SB1 that uses the data that the first individual user U1 has provided to the first data providing business DB1.

[0123] 19 and 20 show the service collaboration confirmation screen WA of the collaboration application AP2. The collaboration application AP2 may be a native application running on the personal terminal 300, or a web application running on the data service providing system 100. When the collaboration application AP2 is a native application, the service collaboration confirmation screen WA is generated and controlled by the personal terminal 300 based on communication with the collaboration control unit 3 via the service business collaboration interface 32. When the collaboration application AP2 is a web application, the service collaboration confirmation screen WA is generated and controlled by the collaboration control unit 3 based on communication with the personal terminal 300 via the service business collaboration interface 32.

[0124] The service collaboration confirmation screen WA is a screen for confirming the individual user U's consent to the service collaboration between the first data providing business DB1 and the first service business SB1. From the top to the bottom of the screen, the service collaboration confirmation screen WA has a collaborative service confirmation area W1, a message area W2, a consent confirmation area W3, a collaborative data confirmation area W4, and a data handling confirmation area W5.

[0125] The linked service confirmation area W1 clearly displays the two linked services using icons W11 and W12. The linked service confirmation area W1 also displays a data provision direction W13 that clearly indicates the direction in which data is provided in the two linked services. The icon W11 is an icon representing the first data providing business DB1, such as an icon of an application provided by the first data providing business DB1 or a brand logo related to the first data providing business DB1. The icon W12 is an icon representing the first service business SB1, such as an icon of an application provided by the first service business SB1 or a brand logo related to the first service business SB1.

[0126] The message area W2 displays a message or the like that prompts the individual user U for consent. The message area W2 may also display information specific to each individual user U.

[0127] The consent confirmation area W3 presents the terms of use for service collaboration to the individual user U, and confirms their agreement to the terms of use and their intention to start service collaboration. The consent confirmation area W3 has a message W31 displaying the terms of use, an agreement check button W32, and a start collaboration button W33. The agreement check button W32 is a radio button indicating that the individual user U agrees to the terms of use displayed in the message W31. The start collaboration button W33 is a button for confirming that the individual user U will start service collaboration.

[0128] The linked data confirmation area W4 clearly displays the data that will actually be linked. The linked data confirmation area W4 may also display, for example, an example of the data that will actually be linked.

[0129] The data handling confirmation area W5 displays how the linked data will be handled. The data handling confirmation area W5 has a message W51 explaining how data will be handled, a data provision business terms of use confirmation button W52, and a service business terms of use confirmation button W53. The data provision business terms of use confirmation button W52 is a button that opens a screen where the terms of use for the first data provision business DB1 (e.g., terms of use TD1) can be confirmed. The service business terms of use confirmation button W53 is a button that opens a screen where the terms of use for the first service business SB1 (e.g., terms of use TS1) can be confirmed. The individual user U can easily access the terms of use for the two linked services.

[0130] The data handling confirmation area W5 may have a button that opens a screen where the user can check each provider's privacy policy instead of (or in addition to) the terms of use. The privacy policy clearly defines each provider's policy regarding the collection, use, management, and protection of personal information (which may be limited to user information of a specific data service, etc.). For example, the data handling confirmation area W5 may have a button that opens a screen where the user can check the privacy policy of the data provider DP1 and a button that opens a screen where the user can check the privacy policy of the service provider SP1. Furthermore, the data handling confirmation area W5 may have a button that opens a screen where the user can check the privacy policy of the business company that provides the data service providing system 100. The individual user U can easily access the terms of use and / or the privacy policy of each business / service and, after reviewing them, decide whether to agree to the terms of use and begin service collaboration.

[0131] When the individual user U indicates consent to the terms of use by clicking the agreement check button W32 and then clicking the start collaboration button W33, the collaboration application AP2 requests the service business collaboration interface 32 to start service collaboration. When collaboration is completed in the collaboration control unit 3, the collaboration application AP2 displays the service collaboration completion screen WB.

[0132] FIG. 21 shows the service cooperation completion screen WB of the cooperative application AP2. The service linkage completion screen WB has, from the top to the bottom of the screen, a linked service confirmation area W1 and a message area W6 indicating the completion of linkage.

[0133] An individual user U who wishes to implement service collaboration can easily understand the two services to be linked in the linked service confirmation area W1 on the service collaboration confirmation screen WA, can easily check the data that will actually be linked in the linked data confirmation area W4, and can easily access the handling of the linked data in the data handling confirmation area W5. An individual user U who wishes to implement service collaboration can easily understand that service collaboration has been completed on the service collaboration completion screen WB.

[0134] <Operation of the provided data generation unit 4> Thereafter, the cooperative application AP2 transmits a data service request to the data service providing system 100. The data service providing system 100 receives the data service request via the service business data access interface 52 and checks the data service content. The service business data access interface 52 issues a data access request to the provided data generation unit 4 to access the provided data (second data) required to provide the requested data service.

[0135] Next, the provided data generation unit 4 generates a virtual table T as provided data (second data) from the acquired data (first data) D in response to the data access request (data generation step). The provided data generation unit 4 creates a virtual table T each time in response to a data access request, thereby generating a virtual table T that always reflects the access policy P1 and data linkage policy P2, which change from moment to moment. The data access control unit 5 can provide data services using provided data that reflects the latest access policy P1 and data linkage policy P2.

[0136] The provided data generation unit 4 may cache the created virtual table T as temporary storage. When the next data access request occurs, the provided data generation unit 4 may reuse all or part of the cached virtual table T if the related access policy P1 and data linkage policy P2 have not been updated. By using the cached data (cache data) as temporary storage, the provided data generation unit 4 can reduce the processing load of generating the virtual table T.

[0137] Next, the service business data access interface 52 provides a data service based on the virtual table T (data providing step).

[0138] <Policy violation management> FIG. 22 is a sequence diagram of the data access control unit 5 that manages policy violations. The data service monitoring unit 55 registers the virtual individual user VU as a user of the first service business SB1. It is assumed that the virtual individual user VU agrees to the terms of use TS1 (see FIG. 11) of the first service business SB1.

[0139] Furthermore, the data service monitoring unit 55 registers the virtual individual user VU as a user of the second service business SB2. It is assumed that the virtual individual user VU agrees to the terms of use TS2 (see FIG. 12) of the second service business SB2.

[0140] Next, the data service monitoring unit 55 generates a data service request from the first service business SB1 as the virtual individual user VU to the service business data access interface 52, as shown in Figure 22. The service business data access interface 52 issues a data access request to the provided data generation unit 4.

[0141] The provided data generation unit 4 generates provided data (second data) based on the data access request and outputs it to the data access interface 52 for service business.

[0142] The provided data monitoring unit 54 monitors whether or not the provided data (second data) acquired from the provided data generating unit 4 violates the policy regarding the terms of use TS1.

[0143] The service business data access interface 52 provides a data service to the first service business SB1 based on the acquired provision data (second data) virtual table T.

[0144] The first service business SB1 provides a data service to the virtual individual user VU based on the provided data service.

[0145] The data service monitoring unit 55 monitors whether or not there is any violation of the policy regarding the terms of use TS1 in the data service provided to the virtual individual user VU.

[0146] The policy violation recording unit 56 records, as a policy violation monitoring history PR, any policy violation detected by the provided data monitoring unit 54 or the data service monitoring unit 55. If a policy violation occurs, the data access control unit 5 takes action such as discontinuing data services to the first service business SB1.

[0147] Similarly, the data service monitoring unit 55 requests a data service from the second service business SB2 as a virtual individual user VU, and monitors whether there is any violation of the policy regarding the terms of use TS2 in the data service provided by the second service business SB2.

[0148] Here, it is assumed that the data service monitoring unit 55, acting as a virtual individual user U of the first service business SB1 and the second service business SB2, receives data services from these service businesses SB with the consent of the service provider SP1 that provides these service businesses SB.

[0149] FIG. 23 is a diagram showing an HTML description of a data service provided to the data service monitoring unit 55 by the second service business SB2. The terms of use TS2 (see FIG. 12) of the second service business SB2 do not permit the use of the data items of date of birth and age. However, the HTML description shown in FIG. 23 contains a keyword "40s" related to the data item of age, and it is presumed that the second service business SB2 is providing a data service using the data item of age. In this case, the data service monitoring unit 55 detects a policy violation in the data service.

[0150] For example, the data service monitoring unit 55 has keywords for each data item as dictionary data. For example, for the data item "age," the data service monitoring unit 55 prepares keywords that encompass variations in expression, such as "40 years old," "forties," and "forties," as dictionary data in advance. The data service monitoring unit 55 matches keywords related to data items that are not permitted to be used with HTML descriptions of web pages and API arguments in the data service provided by the second service business SB2, and detects a policy violation in the data service if a match is found.

[0151] For example, the data service monitoring unit 55 may use keywords for each data item generated in advance by machine learning as dictionary data. By using the dictionary data generated by machine learning, the data service monitoring unit 55 detects policy violations that cannot be identified at first glance, for example.

[0152] A service provider SP1 provides a first service business SB1 and a second service business SB2. Even if the service business data access interface 52 provides data services to the first service business SB1 and the second service business SB2 based on a data linkage policy P2 (see FIG. 10), the service provider SP1 may treat the received data services without distinction, which may result in a policy violation in the data services provided to individual user U. The data service monitoring unit 55 monitors whether or not there is a policy violation regarding the terms of use in the data services that were requested as virtual individual user VU and actually received, and therefore can detect a policy violation caused by the service provider SP1 treating the received data services without distinction.

[0153] According to the embodiment described above, the data service providing system 100 can more seamlessly manage a wide variety of acquired data D with different information management methods and handling methods by setting an access policy P1 for each data type and registered user (individual user U and service provider SP) for acquired data D including multiple data types with different handling policies. Furthermore, the data service providing system 100 can easily provide a data service in which the access policy P1 is strictly applied to acquired data D including personal data of individual user U.

[0154] Furthermore, according to the embodiment described above, the data service providing system 100 not only seamlessly provides data services to the service business SB using data acquired from the data providing business DP, but also collectively manages the terms of use of both the data providing business SB and the service business SB and the individual user U's consent to the terms of use as a service collaboration policy P2, and can easily provide data services that strictly apply the terms of use and consent to the terms of use.

[0155] (Variation) In each of the above embodiments, the provided data generation unit 4 generates a virtual table T as the provided data (second data). However, the provided data generation unit 4 may also generate a real table as the provided data (second data). The real table is a table that is pre-recorded in a non-volatile recording unit before a data access request is made. The provided data generation unit 4 periodically generates or updates a real table as provided data based on specific specifications (for example, provided data used for "statistical use without identifying individuals (including provision to a third party)"). By using such a real table, the provided data generation unit 4 can reduce the processing load for generating the provided data.

[0156] Furthermore, according to the embodiment described above, the data service providing system 100 monitors whether or not there is a violation ("policy violation") of the service collaboration policy P2 in the provided data (second data) and data service, and can provide a data service to which the service collaboration policy P2 is applied more strictly.

[0157] The programs in the above-described embodiments may be recorded on a computer-readable recording medium, and then loaded and executed by a computer system. The term "computer system" as used herein includes hardware such as an OS and peripheral devices. The term "computer-readable recording medium" refers to portable media such as flexible disks, optical magnetic disks, ROMs, and CD-ROMs, as well as storage devices such as hard disks built into a computer system. The term "computer-readable recording medium" may also include media that dynamically store programs for a short period of time, such as communication lines used when transmitting programs via networks such as the Internet or telephone lines, or media that store programs for a fixed period of time, such as volatile memory within a computer system serving as a server or client. The program may also be designed to implement some of the functions described above, or may be capable of implementing the functions described above in combination with a program already stored in the computer system.

[0158] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These embodiments can be implemented in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, as well as within the scope of the invention described in the claims and their equivalents. [Explanation of symbols]

[0159] 100...data service providing system, 1...data acquisition unit, 2...access policy control unit, 3...linkage control unit, 4...provided data generation unit, 5...data access control unit, 251...individual user access policy, 262...data type handling policy, 263...data type combination policy, 264...service business access policy, 361...member ID data, 352...first linked member ID data, 353...service linkage policy for data providing business, 355...second linked member ID data, 356...service linkage policy for service business, DP...data provider, DB...data providing business, SP...service provider, SB...service business

Claims

1. A server, a first policy acquisition step of acquiring a first policy including consent data indicating consent of the first individual user to use the data providing business; a data acquisition step of acquiring first data including data of the first individual user from the data providing business based on the first policy; a second policy acquisition step of acquiring a second policy including consent data indicating consent of the second individual user to use the service business; a policy setting step of setting a service collaboration policy that links the first policy and the second policy; a data generation step of generating second data to be used in a data service to be provided to the service business from the first data based on the first policy and the second policy linked in the service linkage policy; a data providing step of providing a data service to the service business based on the second data; Equipped with Data service delivery method.

2. the second policy includes consent data indicating the first individual user's consent to use of the service business; the data generating step generates the second data to be used for a data service provided to the service business from the first data based on the service collaboration policy when the first individual user uses the service business; The data service providing method according to claim 1 .

3. the service collaboration policy includes member data collaboration information that associates member data of the data providing business with member data of the service business; 3. The data service providing method according to claim 1.

4. The service linkage policy is generated or updated when at least a part of the first policy, the second policy, and the member data linkage information is updated. The data service providing method according to claim 3 .

5. the data generating step generates the second data using data items that are permitted to be used based on the content of the second individual user's consent to use of the service business; The data service providing method according to any one of claims 1 to 4.

6. the data generating step generates the second data using data items that are permitted to be used based on the content of the first individual user's consent to use of the service business; The data service providing method according to claim 2 .

7. the data generation step, when the first data includes data provided by the first individual user, generates the second data using data items whose use is permitted based on the content of the first individual user's consent to use of the data provision business; The data service providing method according to any one of claims 1 to 5.

8. The consent data for the use of the data providing business includes the date of consent; The consent data for the use of the service business includes the date of consent; The data service providing method according to any one of claims 1 to 7.

9. a service linking step of permitting the first individual user to link the data providing business for the first individual user with the service business for the first individual user; the service linking step includes presenting the linked data and how to handle the linked data to the first individual user; The data service providing method according to any one of claims 1 to 8.

10. the service collaboration step includes, after obtaining consent for the collaboration from the first individual user, notifying the first individual user that the collaboration has been completed; The data service providing method according to claim 9.

11. a policy monitoring step of monitoring whether or not the second data violates the service collaboration policy; The data service providing method according to any one of claims 1 to 10.

12. a policy monitoring step of monitoring whether or not there is a violation of the service collaboration policy in the data service provided by the service business to the second individual user; The data service providing method according to any one of claims 1 to 10.

13. a policy monitoring step of monitoring whether or not there is a violation of the service collaboration policy in the data service provided by the service business to the first individual user; The data service providing method according to any one of claims 1 to 10.

14. the policy monitoring step receives a data service from the service business as a virtual individual user, and monitors whether or not the received data service violates the service collaboration policy; 14. The data service providing method according to claim 12 or 13.

15. The first individual user and the second individual user are the same user. The data service providing method according to any one of claims 1 to 14.

16. a collaboration control unit that acquires a first policy including consent data indicating consent from a first individual user to the use of a data provision business, acquires a second policy including consent data indicating consent from a second individual user to the use of a service business, and sets a service collaboration policy that collaborates the first policy and the second policy; a data acquisition unit that acquires first data including data of the first individual user from the data providing business based on the first policy; a provision data generation unit that generates second data to be used in a data service to be provided to the service business from the first data based on the first policy and the second policy linked in the service linkage policy; a data access control unit that controls the service business to provide a data service based on the second data; Equipped with Data service provision system.

17. the second policy includes consent data indicating the first individual user's consent to use of the service business; the provision data generation unit generates the second data to be used for a data service to be provided to the service business from the first data based on the service linkage policy when the first individual user uses the service business; 17. The data service providing system according to claim 16.

18. the service collaboration policy includes member data collaboration information that associates member data of the data providing business with member data of the service business; 18. A data service providing system according to claim 16 or 17.

19. the collaboration control unit generates or updates the service collaboration policy when at least a part of the first policy, the second policy, and the member data collaboration information is updated; 19. The data service providing system according to claim 18.

20. the collaboration control unit presents the data to be collaborated and how to handle the data to be collaborated to the first individual user, and permits the first individual user to collaborate the data providing business for the first individual user with the service business for the first individual user; 20. A data service providing system according to any one of claims 16 to 19.

21. the data access control unit monitors whether or not there is a violation of the service collaboration policy in the data service provided by the service business to the first individual user; 21. The data service providing system according to any one of claims 16 to 20.

22. The method according to claim 21, wherein the first individual user and the second individual user are the same user.

22. A data service providing system according to any one of claims 16 to 21.

Citation Information

Patent Citations

  • System for gathering use result of life facility equipment using communication network

    JP2002056160A

  • Information mediation method and device

    JP2005346248A

  • Information providing method, information management system and control method for terminal equipment

    JP2016006553A

  • Service cooperation system, service cooperation device, terminal device, service cooperation method, and service cooperation program

    JP2016128966A

  • Service cooperation system, service cooperation method, and server

    JP2018156405A