system

The system allows users to view and consent to data distribution by presenting data to be shared, addressing the challenge of users being unable to check the content of distributed personal data.

JP7782677B2Active Publication Date: 2025-12-09NEC CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024510909
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-30
Publication Date
2025-12-09
Estimated Expiration
2042-03-30

AI Technical Summary

Technical Problem

Existing information distribution systems fail to enable users to check the content of personal data being distributed, making it difficult for them to decide whether to consent to its distribution.

Method used

A system comprising a service server and a distribution control server that presents data to be distributed to users before sharing it with other servers, allowing users to confirm the content and provide consent.

Benefits of technology

Enables users to check the contents of their data, facilitating informed consent for data distribution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007782677000001
    Figure 0007782677000001
  • Figure 0007782677000002
    Figure 0007782677000002
  • Figure 0007782677000003
    Figure 0007782677000003
Patent Text Reader

Abstract

Provided is a system which enables a user to confirm the content of data to be distributed. The system comprises a service server and a distribution control server that controls the data distribution. The service server is operated by a service provider and accumulates a plurality of pieces of data generated by providing the service to the user. When data to be distributed among the plurality of pieces of accumulated data is distributed from the service server to a server of a provider that is different from the service provider, the distribution control server presents, to the user, the data to be distributed.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a system, a distribution control server, a control method for a distribution control server, and a storage medium. [Background technology]

[0002] 2. Description of the Related Art There is an information distribution system that provides personal information held by a hospital or the like to a destination device such as a business operator with the consent of the individual.

[0003] For example, the information trading device in Patent Document 1 stores catalog information including detailed information on one or more data sets including personal information that can be provided from an information source device to an information destination device. The information trading device receives a request for providing a data set from the information destination device. The information trading device outputs a request for transmitting the data set indicated by the provision request to the information source device.

[0004] Patent Document 2 describes providing information on a user's health condition. The information provision system in Patent Document 2 includes a vital data acquisition means, an urgency determination means, a usefulness determination means, a consent determination means, and an information transmission means. The vital data acquisition means acquires the user's vital data. The urgency determination means determines whether the user has experienced an emergency symptom based on the vital data acquired by the vital data acquisition means. The usefulness determination means determines, for each destination, whether it is useful to transmit information on the user's health condition to the destination, taking into account the determination result by the urgency determination means. The consent determination means determines whether the user has consented to transmitting information on the user's health condition to the destination determined by the usefulness determination means to be useful. The information transmission means transmits information on the user's health condition to the destination determined by the consent determination means to be consented to. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] International Publication No. 2021 / 085061 [Patent Document 2] Japanese Patent Application Publication No. 2018-124853 Summary of the Invention [Problem to be solved by the invention]

[0006] As disclosed in Patent Documents 1 and 2, when personal data is provided to a third party, the consent of the user is required. In many information distribution systems, personal data is passed from the information provider to the information recipient using an API (Application Programming Interface) prepared by the information provider. In other words, personal data is distributed using a pre-prepared API.

[0007] However, due to limitations in the APIs used to distribute personal data, it is difficult for users to check the data individually. In other words, it is difficult for users to check the content of each individual data entity. If users cannot know the specific content (contents) of the data that is the subject of data distribution, they cannot decide whether or not to consent to the distribution of that data.

[0008] A primary object of the present invention is to provide a system, a distribution control server, a control method for the distribution control server, and a storage medium that contribute to enabling users to check the contents of data to be distributed. [Means for solving the problem]

[0009] According to a first aspect of the present invention, there is provided a system including a service server operated by a service provider that stores multiple pieces of data generated by providing a service to users, and a distribution control server that controls data distribution, wherein the distribution control server presents at least one piece of data that is the subject of data distribution to the user when the data distribution control server distributes at least one piece of data that is the subject of data distribution from the service server to a server of a provider other than the service provider.

[0010] According to a second aspect of the present invention, there is provided a distribution control server, which is operated by a service provider, stores a plurality of data generated by providing a service to a user, and comprises a communication control unit that communicates with a service server, and a data distribution control unit that, when at least one or more data items that are the subject of data distribution from the plurality of stored data items are distributed from the service server to a server of a provider other than the service provider, presents the at least one or more data items that are the subject of data distribution to the user.

[0011] According to a third aspect of the present invention, there is provided a method for controlling a distribution control server, in which the distribution control server communicates with a service server operated by a service provider and stores multiple data generated by providing services to users, and when at least one or more data items that are the subject of data distribution from the multiple stored data items are distributed from the service server to a server of a provider other than the service provider, the method presents the at least one or more data items that are the subject of data distribution to the user.

[0012] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium that stores a program for causing a computer installed in a distribution control server to execute the following processes: a process of communicating with a service server operated by a service provider and storing multiple data generated by providing services to users; and a process of presenting at least one or more data items that are the subject of data distribution to the user when at least one or more data items that are the subject of data distribution from the service server to a server of a provider other than the service provider are distributed from the service server to the user. [Effects of the Invention]

[0013] According to each aspect of the present invention, a system, a distribution control server, a control method for a distribution control server, and a storage medium are provided that contribute to enabling users to check the contents of data to be distributed. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above. [Brief explanation of the drawings]

[0014] [Figure 1] FIG. 1 is a diagram for explaining an outline of an embodiment. [Figure 2] FIG. 2 is a flowchart showing an example of the operation of one embodiment. [Figure 3] FIG. 3 is a diagram illustrating an example of a schematic configuration of an information distribution system according to the first embodiment. [Figure 4] FIG. 4 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 5] FIG. 5 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 6] FIG. 6 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 7] FIG. 7 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 8]FIG. 8 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 9] FIG. 9 is a diagram showing an example of a display on the terminal according to the first embodiment. [Figure 10] FIG. 10 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 11] FIG. 11 is a diagram illustrating an example of catalog information according to the first embodiment. [Figure 12] FIG. 12 is a diagram for explaining the operation of the information distribution system according to the first embodiment. [Figure 13] FIG. 13 is a diagram illustrating an example of a display on the terminal according to the first embodiment. [Figure 14] FIG. 14 is a diagram illustrating an example of a processing configuration of the distribution control server according to the first embodiment. [Figure 15] FIG. 15 is a diagram illustrating an example of a part of the user information database according to the first embodiment. [Figure 16] FIG. 16 is a diagram illustrating an example of a location information database according to the first embodiment. [Figure 17] FIG. 17 is a diagram illustrating an example of a processing configuration of the service server according to the first embodiment. [Figure 18] FIG. 18 is a diagram illustrating an example of a customer information database according to the first embodiment. [Figure 19] FIG. 19 is a diagram illustrating an example of a processing configuration of the trading server according to the first embodiment. [Figure 20] FIG. 20 is a diagram showing an example of the account holder list according to the first embodiment. [Figure 21] FIG. 21 is a diagram illustrating an example of a processing configuration of a terminal according to the first embodiment. [Figure 22] FIG. 22 is a sequence diagram showing an example of the operation of the information distribution system according to the first embodiment. [Figure 23] FIG. 23 is a sequence diagram showing an example of the operation of the information distribution system according to the first embodiment. [Figure 24]FIG. 24 is a diagram illustrating an example of a display on a terminal according to the second modification of the first embodiment. [Figure 25] FIG. 25 is a diagram illustrating an example of a display on a terminal according to the third modification of the first embodiment. [Figure 26] FIG. 26 is a diagram showing an example of a display on a terminal according to the fourth modification of the first embodiment. [Figure 27] FIG. 27 is a diagram illustrating an example of a hardware configuration of a distribution control server according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0015] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of main signals (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.

[0016] A system according to one embodiment includes a service server 101 and a distribution control server 102 that controls data distribution (see FIG. 1). The service server 101 is operated by a service provider and stores multiple pieces of data generated by providing services to users (step S1 in FIG. 2). When distributing data to be distributed from the multiple stored pieces of data from the service server 101 to a server of a provider other than the service provider, the distribution control server 102 presents the data to be distributed to the user (step S2).

[0017] When distributing data stored by the service server 101 to other businesses, the distribution control server 102 acquires the data to be distributed from the service server 101. The distribution control server 102 presents the acquired data (the data to be distributed) to the user and acquires the user's consent to the distribution of the data. In this way, the distribution control server 102 enables the user to confirm the content of the data to be distributed.

[0018] Specific embodiments will be described in more detail below with reference to the drawings.

[0019] [First embodiment] The first embodiment will be described in more detail with reference to the drawings.

[0020] [System Configuration] Fig. 3 is a diagram showing an example of a schematic configuration of an information distribution system according to the first embodiment. As shown in Fig. 3, participating members (actors) of the information distribution system include information distribution companies, service companies, data utilization companies, and trading companies.

[0021] An information distribution business is a business that provides a platform for a data distribution service (information distribution service) for personal data accumulated in a service business. The information distribution business controls data distribution between businesses (service businesses, data utilization businesses). The information distribution business is equipped with a distribution control server 10.

[0022] The distribution control server 10 is a device that controls data distribution. The distribution control server 10 is a server device that controls (realizes) data distribution between service providers and controls data distribution between service providers and data utilization businesses. The distribution control server 10 realizes an information distribution service for data held by service providers.

[0023] A service provider is an entity that provides services to individuals. A service provider may be a private business or a public institution. Examples of service providers include medical institutions (hospitals, pharmacies, etc.) that provide medical services to users, insurance companies that sell insurance products, retailers, and educational institutions that teach customers languages, sports, arts, etc.

[0024] Each service provider has a service server 20 for providing services to customers. The service server 20 is managed and operated by the service provider. The service server 20 holds (stores) data generated by the service provider when the service provider provides services to users, data necessary to provide services to users, etc.

[0025] The service provider holds user data related to the services it provides to users. The service server 20 is operated by the service provider and stores a variety of data generated in providing the services to users.

[0026] Data utilization businesses are entities that do not provide services directly to individuals. Examples of data utilization businesses include pharmaceutical companies. For example, pharmaceutical companies use data obtained from service providers to develop new drugs.

[0027] In this disclosure, entities that do not provide services to individuals will be referred to as "data utilization businesses" for explanation, but it goes without saying that data utilization businesses will act as "service businesses" when providing services to users. In other words, depending on the business form of a data utilization business, the data utilization business may also be a service business.

[0028] The data utilization business has a data utilization server 30 for acquiring and utilizing data from the service business.

[0029] A trading business is an entity that realizes transactions between service providers and data users. A trading business realizes data distribution between data generators (service providers) and data consumers (data users).

[0030] The trading company is provided with a trading server 40 for realizing the data distribution.

[0031] A user of the information distribution system uses a terminal 50 .

[0032] The devices shown in Fig. 3 are connected to each other via a network. For example, the distribution control server 10 and the service server 20 are connected by wired or wireless communication means and are configured to be able to communicate with each other.

[0033] 3 is an example and is not intended to limit the configuration of the information distribution system disclosed in the present application. For example, an information distribution business may include two or more distribution control servers 10. Furthermore, with regard to trading businesses and data utilizing businesses, the information distribution system includes data utilization servers 30 and trading servers 40 according to the number of businesses participating in the system.

[0034] [System Overview] Next, the general operation of the information distribution system according to the first embodiment will be described.

[0035] A user enters into an individual contract with a service provider from which the user wishes to receive a service. For example, the user provides the service provider with their name and other information and requests to enter into a new contract (a contract to receive the service) with the service provider.

[0036] For example, a user who wants to visit a hospital submits a health insurance card or the like with their name and other information written on it to the hospital. Alternatively, a user who wants to purchase an insurance product accesses the service server 20 operated by the insurance company and registers as a member. Alternatively, in the case of an EC (Electronic Commerce) business that provides services related to online shopping, the user accesses the service server 20 operated by the EC business and creates an account.

[0037] A service provider generates a "personal identification ID" to identify a new customer (user). For example, a hospital assigns a patient card number to manage users (patients) and generates the patient card number as the personal identification ID. An insurance company or an e-commerce business generates a membership number or the like to manage customers as the personal identification ID. The service server 20 stores the generated personal identification ID (for example, a patient card number or membership number) in a database or the like.

[0038] Once the personal identification ID is generated, the user can receive services from the service provider. For example, the user can receive medical services (health checkups, medical examinations, etc.) from a hospital, or purchase insurance products from an insurance company.

[0039] In order for user data generated by a service provider when providing a service to a user to be subject to data distribution, the data must be "stored." Data storage occurs when a service provider (a provider of user data) registers the user data in an information distribution system as data that can be provided to third parties. The distribution control server 10 controls data storage to enable data related to services provided to users by data accumulators (service providers) to be subject to data distribution.

[0040] The accumulated data will be subject to data distribution. In addition, the accumulation of user data requires the consent (agreement to data accumulation) of the user (the user who generated the user data).

[0041] "Storage" refers to the distribution of user data held by a service provider as information (data distribution), and users who agree to the storage are paid a fee.

[0042] "Sharing" and "provision" are methods of data distribution in information distribution systems.

[0043] "Sharing" is a means by which a service provider obtains data accumulated by another service provider. The distribution control server 10 controls data sharing, which allows a first service provider to obtain data accumulated by a second service provider. For example, data distribution through "sharing" is used when an e-commerce business obtains data generated by a hospital providing services to users. An insurance company uses data obtained from a hospital through data sharing to provide better services to users.

[0044] "Sharing" is used to improve the convenience of the service users themselves, so users are not paid compensation for data distribution (compensation for users). "Sharing" is used to utilize data accumulated by other service providers so that users can receive better services from the service providers.

[0045] "Provision" is a means by which data utilization businesses acquire data accumulated by other service businesses. The distribution control server 10 controls data provision so that data utilization businesses can acquire data accumulated by service businesses. For example, data distribution by "provision" is used when a pharmaceutical company acquires the results of a health check or examination from a hospital. The pharmaceutical company uses the data acquired from the hospital through data provision to help develop new drugs.

[0046] "Provision" is a method used by data utilization businesses that do not provide services directly to users, so compensation for data distribution (compensation to users) is incurred. In other words, when "provision" is performed, compensation is paid to the user.

[0047] The distribution control server 10 controls data sharing so that a data sharing destination (a service provider receiving data) can acquire data stored in a data sharing source. The distribution control server 10 controls data provision so that a data providing destination (a data utilizing business receiving data) can acquire data stored in a data providing source.

[0048] <Create a system account> Users of the information distribution system must register in advance (user registration, system registration). More specifically, the user accesses the distribution control server 10 and performs procedures for creating an account. In the following explanation, an account created in the information distribution system will be referred to as a "system account."

[0049] To create a system account, the user operates the terminal 50 that the user owns to access the distribution control server 10. In response to the access from the terminal 50, the distribution control server 10 displays a WEB page for creating a system account.

[0050] The user performs an operation for generating a system account (for example, pressing a predetermined button) to generate a system account. At that time, the distribution control server 10 acquires information necessary for generating the user's system account. Specifically, the distribution control server 10 acquires the user's login information (login ID, password) and personal information (name, date of birth, contact information, account information, etc.).

[0051] When the login information, personal information, etc. are acquired, the distribution control server 10 generates a user ID (Identifier) ​​for uniquely identifying the user in the information distribution system.

[0052] The distribution control server 10 stores the generated user ID, login information, and personal information (e.g., name, date of birth, contact information) of the user in association with each other. The distribution control server 10 stores this information in a "user information database." The user information database will be described in detail later.

[0053] The circulation control server 10 issues the generated user ID to the user (terminal 50). The terminal 50 stores the issued user ID.

[0054] <ID Linkage> As described above, in order to make the user data held by the service provider the target of data circulation, "data accumulation" is required. In order to achieve data accumulation, it is necessary to link the ID of the system account (user ID) and the ID (personal identification ID) generated by the service provider.

[0055] For example, as shown in FIG. 4, at the hospital counter, the user tells the hospital staff that they hope to utilize the user data held by the hospital (submit an application for data utilization). The hospital staff inputs the user's personal identification information, the user's personal identification ID (for example, the examination ticket number), and the business operator code into the hospital terminal 60.

[0056] Note that the personal identification information is information for identifying the user. Examples of the personal identification information include the user's name, or a combination of the name and date of birth.

[0057] Also, the business operator code is identification information (ID) for identifying the service providers participating in the information circulation system. For example, different codes are assigned to hospitals and insurance companies. The business operator code is shared among system participants (information circulation business operators, service providers, data utilization business operators) by any means. For example, when a service provider participates in the information circulation system, the information circulation business operator generates a business operator code assigned to the service provider. The information circulation business operator notifies the generated business operator code to the service provider, etc.

[0058] The hospital terminal 60 transmits an "ID linkage request" including the acquired personal identification information, personal identification ID, and business operator code to the circulation control server 10.

[0059] Alternatively, a user who wishes to utilize the user data of an EC business operates a terminal 50 to access the service server 20 of the EC business (see FIG. 5). The user logs in to an account of the EC business and submits an application for data utilization through the account. In response to the application, the service server 20 transmits an "ID federation request" including the user's personal identification information, personal identification ID, and business code to the distribution control server 10.

[0060] The distribution control server 10 acquires from the hospital terminal 60 and the service server 20 the personal identification information of the person desiring ID federation, the personal identification ID, and the business code of the service business (for example, hospital, e-commerce business) that is the target of ID federation.

[0061] The distribution control server 10 identifies the service provider that is the target of ID federation from the provider code. In addition, the distribution control server 10 identifies the user registered in the system account from the personal identification information, and associates the service provider with the personal identification ID in the account of the identified user.

[0062] Once a personal identification ID is registered in a system account (when ID linking is completed), the service provider that is the subject of ID linking will be able to "store" the user data of users who wish to utilize the data.

[0063] In addition, a user's "application for data utilization" to a service provider can be considered as consent (agreement) to the service provider storing user data.

[0064] <Data accumulation> When the service provider provides a service to a user, the service provider stores the user's personal identification ID and user data (personal data) in association with each other.

[0065] The service provider sends "location information" to the distribution control server 10 each time it stores user data (data resulting from the provision of the service, data necessary for the provision of the service) for a user for whom ID integration has been completed (a user who has applied for data utilization).

[0066] For example, as shown in Fig. 6, when a hospital provides medical services to each of users U1 to U3, the hospital holds the results for each user. For example, the hospital holds the examination results (disease name; for example, data such as stomach cancer, lung cancer, etc.) for each user.

[0067] The service provider (service server 20) stores the personal identification ID of each user in association with the user data obtained as a result of the provision of the service. For example, in the example of Fig. 6, the service server 20 uses a "customer information database" to store the personal identification ID of each of users U1 to U3 in association with the examination results. The customer information database will be described in detail later.

[0068] Every time a service provider stores user data relating to a user who has agreed to data storage, the service provider transmits "location information" to the distribution control server 10. The location information is information relating to the storage location of the user data (the entity storing the data; the service provider), etc. The location information includes a personal identification ID, a business code, the ID and type of the data being held, etc.

[0069] The distribution control server 10 stores the acquired location information in a "location information database." Details of the location information database will be described later. The location information database stores a personal identification ID, a business code, a data ID, a data type, and the like in association with each other.

[0070] <Viewing stored data> A user can request the information distribution system to view data stored in each service provider. Specifically, the user logs in to a portal site provided by the distribution control server 10.

[0071] The user operates the terminal 50 to request the distribution control server 10 to view the stored data (see FIG. 7). At that time, the distribution control server 10 may acquire requirements (data requirements) that define the stored data that the user wishes to view.

[0072] For example, a user may request to view data by specifying the type of data to be viewed and the requirements for the data to be provided. For example, a user may specify the type of data and the data search period as requirements for the data to be provided by the data accumulator (data requirements).

[0073] The "data type" included in the data requirements is set to a disease name, etc. The data search period specifies the period during which at least one piece of data to be distributed is searched for from among multiple accumulated data. In this way, the data requirements include the data type and the data search period. For example, the distribution control server 10 acquires data requirements from a user (requirements for data supplied from the service server 20; supplied data requirements) such as "disease names accumulated between January 1, 2021 and December 31, 2021."

[0074] The distribution control server 10 uses the user's user ID and data type (disease name in the above example) to identify the data accumulator that has accumulated the data that the user wishes to view. The distribution control server 10 transmits to the service server 20 an "accumulated data transmission request" that includes the personal identification ID corresponding to the identified data accumulator and data requirements (data type and data search period specified by the user).

[0075] The service server 20 identifies the user from the personal identification ID included in the request to send stored data, and identifies stored data from the stored data of the identified user that matches the data requirements (data type, data search period) specified in the request to send stored data.

[0076] The service server 20 transmits the identified stored data to the distribution control server 10. The distribution control server 10 displays the acquired stored data on the terminal 50 of the user.

[0077] In this way, the distribution control server 10 transmits an accumulated data transmission request including data requirements that specify the data that the user wishes to view to the service server 20. The distribution control server 10 presents the accumulated data obtained from the service server 20 (for example, a specific disease name such as stomach cancer) to the user.

[0078] As described above, the distribution control server 10 has a function that enables users to check their own data ownership status. That is, the distribution control server 10 has a "data management function" that enables users to check the contents of their own data as needed.

[0079] <Data sharing> A service provider that wishes to acquire data accumulated by another service provider (user data resulting from the provision of services to users by another service provider) can acquire that data through "sharing."

[0080] Here, with reference to Fig. 8, we will explain the case where insurance company C acquires data of user U1 stored in hospitals A and B through "sharing." Hospital A is equipped with service server 20-1, and hospital B is equipped with service server 20-2. Insurance company C is also equipped with service server 20-3.

[0081] First, user U1 operates terminal 50 to access the web page of insurance company C and purchase an insurance product. The insurance products sold by insurance company C come with "special offers." Specifically, the special offers include "a discount on insurance premiums if you submit all test results" and "a discount on initial fees if you submit the name of the disease from the previous year."

[0082] When user U1 purchases an insurance product with the above-mentioned benefit, insurance company C requests the distribution control server 10 to "share" the data (test results, disease name) set as a condition for granting the above-mentioned benefit. Specifically, insurance company C (service server 20-3) sends a "sharing request" to the distribution control server 10 (step S11).

[0083] The sharing request includes the personal identification ID of user U1 who is the subject of data distribution, the business code of the data sharing destination, the data requirements for the data requested to be shared (data type, data search period), and accompanying information explaining the purpose of the data sharing, etc.

[0084] In the above example of "Submit all test results to receive a discount on insurance premiums," the sharing request includes the personal identification ID (e.g., membership number) managed by insurance company C for user U1, the data type "test results," the data search period "not specified," and the associated information "premium discount." Also, in the example of "Submit a disease name from the previous year to receive a discount on the initial fee," the sharing request includes user U1's personal identification ID, data type "disease name," the data search period "January 1, 2021 to December 31, 2021," and the associated information "Submit a disease name from the previous year to receive a discount on the initial fee." The date on which the user purchased the insurance product is assumed to be some day in 2022.

[0085] In the following explanation, we will use the example of "receiving a discount on the initial fee by submitting the name of the disease from the previous year."

[0086] Based on the information included in the sharing request, the distribution control server 10 identifies the user U1 who is the target of the data distribution and the data accumulators (hospital A, hospital B) of the data to be distributed.

[0087] The distribution control server 10 acquires specific details (user data) of the data type for which data sharing is requested from the data accumulators (Hospital A, Hospital B). Specifically, the distribution control server 10 transmits a "stored data transmission request" to the service servers 20-1 and 20-2 of Hospital A and Hospital B, respectively (step S12).

[0088] The distribution control server 10 acquires the names of diseases of the user U1 stored in each of the hospitals A and B (the names of diseases stored within the data search period) in response to the request to transmit stored data (step S13).

[0089] The distribution control server 10 transmits an inquiry regarding data sharing to the terminal 50 possessed by the user U1 (step S14).

[0090] The terminal 50 that has received the inquiry about data sharing acquires the intention of the user U1 regarding data sharing. For example, the terminal 50 acquires the intention of the user U1 using a GUI (Graphical User Interface).

[0091] In the above example, the terminal 50 displays the specific disease name of the user U1 (the name of the disease diagnosed in the previous year) and also displays a GUI for acquiring the user's intention (see FIG. 9).

[0092] The user U1 checks the specific data content presented and decides whether or not to agree to the data sharing. The terminal 50 acquires the user U1's intention (agreement or disagreement to the data sharing) via the GUI.

[0093] The terminal 50 transmits a response to the inquiry about data sharing (agreement to data sharing or denial of data sharing) to the distribution control server 10 (step S15).

[0094] If consent is obtained from the user U1, the distribution control server 10 transmits a sharing instruction to the data accumulators (hospital A, hospital B) (step S16).

[0095] Upon receiving the sharing instruction, the service server 20-1 of Hospital A and the service server 20-2 of Hospital B refer to the customer information database and transmit the name of the disease of the target user U1 to the service server 20-3, which is the designated data sharing destination (step S17).

[0096] Next, data distribution through "provision" will be explained.

[0097] <Opening an account> Users who wish to receive compensation for providing data must open an account with a trading company. Opening an account for data provision will be explained with reference to Figure 10.

[0098] A trading business partner will partner with at least one of the multiple service businesses participating in the information distribution system. For example, a trading business that handles medical data will partner with a medical institution (hospital, pharmacy, etc.). Or, a trading business that handles educational data will partner with an education provider. The trading business will store the business code of the service business partner.

[0099] In addition, trading businesses store the business code of the data-utilizing business. For example, trading businesses generate the business code of the data-utilizing business when starting a transaction with the data-utilizing business. The business code of the data-utilizing business is shared among the information distribution business, trading businesses, and data-utilizing business by any method.

[0100] Trading businesses sell user data (accumulated data) held by partner service businesses to data utilization businesses. For example, if the partner service business shown in Figure 10 is a medical institution, the trading business will sell the data held by the partner medical institution to pharmaceutical companies, etc. All or part of the compensation obtained from the sale of the data will be paid to the users involved in the provided data.

[0101] As mentioned above, users who wish to receive compensation for providing data via a trading company must open an account with the trading company (trading server 40). Users participating in the information distribution system who wish to earn revenue by providing data open an "information account" with the trading server 40.

[0102] The user presents the user ID issued by the distribution control server 10 to the trading server 40 to open an information account. The trading server 40 stores the acquired user ID. The trading server 40 manages the user IDs of users who have opened accounts in an account holder list.

[0103] <Catalogue information> To realize data distribution through "provision," information distribution businesses prepare catalog information. The person in charge (system administrator) at the information distribution business defines the catalog information that lists the data that can be sold (see Figure 11). The catalog information is information that shows details of the data that the information distribution system can sell to data utilization businesses.

[0104] The dataset name included in the catalog information shown in Fig. 11 is information for identifying the catalog information. For example, a dataset related to a health checkup is given the name "Examination Results 1," and a dataset related to examination results is given the name "Examination Results 1."

[0105] The catalog information includes the business code of the service provider that handles the data set. The data type indicates the type of data held by the service provider (accumulated data that can be provided to third parties). For example, information such as "height," "weight," and "blood pressure" in medical examination results, and "disease name," "medication," and "test results" in examination results correspond to data types. The data format specifies the format in which the data will be provided.

[0106] The data utilization business acquires the catalog information via the trading business. More specifically, the data utilization server 30 transmits a “catalog information presentation request” to the trading server 40.

[0107] Upon receiving the catalog information presentation request, the transaction server 40 transmits a “catalog information transmission request” to the distribution control server 10 .

[0108] In response to receiving the catalog information transmission request, the distribution control server 10 transmits the catalog information defined by the information distributor to the transaction server 40 .

[0109] The transaction server 40 selects catalog information related to the partner service provider and transmits it to the data utilization server 30. For example, in the above example, the transaction server 40 selects catalog information related to the business of a pharmaceutical company and transmits it to the data utilization business. The data utilization business views the received catalog information and identifies the catalog information necessary for its own business.

[0110] <Data distribution through provision> Data utilization businesses that wish to obtain data accumulated by service providers can obtain that data by "provision."

[0111] Here, with reference to FIG. 12, a case will be described in which pharmaceutical company D acquires accumulated data (disease names) of hospitals A and B related to users U1 to U3 by "provision."

[0112] First, a person in charge at pharmaceutical company D refers to the catalog information provided by the trading business and identifies the necessary catalog information. Then, in accordance with the person in charge's instructions, the data utilization server 30 sends a request for provision to the trading server 40, which includes information about the data-utilizing business, the name of at least one or more data sets of the identified catalog information, and data requirements for the data to be provided (step S21).

[0113] The information on the data utilization business includes the name of the data utilization business, the business code, the data recipient (the address to which the data will be sent), etc. The data requirements include the type of data, the data search period, the required amount of data, etc., such as "more than 100 cases of disease name data accumulated in 2021."

[0114] The transaction server 40 examines the acquired provision request. If no problems are found during the examination, the transaction server 40 transmits the acquired provision request and the list of account holders to the distribution control server 10 (step S22).

[0115] The distribution control server 10 identifies the personal identification ID of the user who is listed on the account holder list and who is related to the requested catalog information. In the example of Fig. 12, the distribution control server 10 identifies the personal identification ID for each of users U1 to U3.

[0116] Thereafter, the distribution control server 10 acquires specific user data that matches the data for which provision is requested from the data accumulators (Hospital A, Hospital B). Specifically, the distribution control server 10 transmits an "accumulated data transmission request" including a personal identification ID and data requirements (data type, data search period) to the service servers 20-1 and 20-2 of Hospital A and Hospital B, respectively (step S23).

[0117] The distribution control server 10 acquires the names of diseases of the users U1 to U3 stored in each of the hospitals A and B in response to the stored data transmission request (step S24).

[0118] The distribution control server 10 sends an inquiry about the provision of data to the contact points (email addresses that can be received by the terminal 50) of the users U1 to U3 (step S25).

[0119] The inquiry for data provision includes information about the requester of the data provision (pharmaceutical company D), information about the data accumulators (hospital A, hospital B), and the specific content of the data requested to be provided.

[0120] The terminal 50 that has received the inquiry about data provision displays a GUI for acquiring the intention of each user regarding the data provision. For example, the terminal 50 displays a GUI as shown in Fig. 13. The terminal 50 uses the GUI to acquire the intention of the user (agreement or disagreement to the data provision).

[0121] The terminal 50 transmits a response to the inquiry about the data provision (agreement to the data provision or refusal to provide the data) to the distribution control server 10 (step S26).

[0122] The distribution control server 10 transmits a provision instruction to the data accumulators (Hospital A, Hospital B) for the users who have given their consent (step S27). For example, as described above, if the provision of 100 or more disease name data is requested, the distribution control server 10 transmits a provision instruction to the service servers 20-1 and 20-2 for the disease name data of the 100 or more users who have given their consent to the data provision.

[0123] The service servers 20 of Hospital A and Hospital B that have received the provision instruction refer to the customer information database and transmit the user data of the users who have agreed to the provision of data to the specified data destination (step S28). In the above example, if each of users U1 to U3 has agreed to the data provision, the disease name data of users including users U1 to U3 is transmitted to the data utilization server 30.

[0124] In this way, when distributing at least one or more pieces of data that are the subject of data distribution from among the plurality of pieces of data stored in the service server 20, the distribution control server 10 presents the at least one or more pieces of data that are the subject of data distribution to the user. More specifically, the distribution control server 10 transmits to the service server 20 a request to transmit stored data, which includes data requirements that specify at least one or more pieces of data that are the subject of data distribution from among the plurality of pieces of stored data. In response to receiving the request to transmit stored data, the service server 20 identifies data that matches the data requirements from among the plurality of pieces of stored data, and transmits the identified data to the distribution control server 10. The distribution control server 10 presents the acquired data to the user and obtains the user's intention regarding the distribution of the data (agreement or refusal to data distribution).

[0125] Next, each device included in the information distribution system according to the first embodiment will be described in detail.

[0126] [Distribution control server] 14 is a diagram showing an example of a processing configuration (processing module) of the distribution control server 10 according to the first embodiment. Referring to FIG. 14, the distribution control server 10 includes a communication control unit 201, a user registration unit 202, an ID linking unit 203, a location information management unit 204, an accumulated data acquisition unit 205, a data distribution control unit 206, a catalog information management unit 207, and a storage unit 208.

[0127] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the service server 20. The communication control unit 201 also transmits data to the service server 20. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0128] The user registration unit 202 is a means for realizing the above-mentioned user registration (system registration of a user). The user registration unit 202 acquires personal information (such as name, date of birth, contact information, and account information) from the user's terminal 50.

[0129] When the user registration unit 202 acquires the personal information, it generates a user ID for identifying the user. For example, the user registration unit 202 assigns a unique number each time a user registers in the system, and uses the assigned number as the user ID.

[0130] The user registration unit 202 stores the user ID and personal information in a user information database (see FIG. 15). As shown in FIG. 15, the user information database stores the user ID, personal information, and a personal identification ID for each service provider in association with each other. The user information database shown in FIG. 15 is an example and is not intended to limit the items to be stored. For example, the date and time of user registration may also be registered in the user information database.

[0131] The user registration unit 202 transmits the generated user ID to the terminal 50.

[0132] The ID federation unit 203 is a means for realizing the above-mentioned ID federation. The ID federation unit 203 receives an "ID federation request" from a terminal of a service provider (for example, a hospital terminal 60) or the service server 20. The ID federation request includes personal identification information, a personal identification ID, and a business code of a user who desires ID federation (registration with a service provider).

[0133] The ID linking unit 203 searches the user information database using personal identification information (such as the user's name or a combination of the name and date of birth) as a key to identify the corresponding user. The ID linking unit 203 sets the personal identification ID included in the ID linking request in a field corresponding to the business code among the personal identification ID fields of the identified user. That is, the ID linking unit 203 identifies the user registered in the system account from the personal identification information, and associates the service provider with the personal identification ID in the account of the identified user.

[0134] The location information management unit 204 is a means for managing location information acquired from service providers. The location information management unit 204 stores the location information acquired from each service server 20 in a location information database (see FIG. 16). As shown in FIG. 16, the location information database stores a personal identification ID, a business code, a data ID, a data type, and a data accumulation date (location information processing date) in association with each other.

[0135] Note that the location information database shown in Fig. 16 is an example and is not intended to limit the items to be stored, etc. In the drawings including Fig. 16, for ease of understanding, the business code is expressed using the name of the service business.

[0136] The stored data acquisition unit 205 is a means for controlling the viewing of stored data. When a user logs in to a portal site and performs a predetermined operation on the portal site, the stored data acquisition unit 205 controls the viewing of the stored data by the user.

[0137] The accumulated data acquisition unit 205 acquires the type of data the user wishes to view (e.g., disease name, test results, etc.), the period for searching the viewed data (viewed data requirements; e.g., data search period), etc., in accordance with the user's operations on the portal site.

[0138] The stored data acquisition unit 205 searches the user information database using the user ID of the user (the user ID of the logged-in user) as a key to identify the corresponding entry. The stored data acquisition unit 205 acquires the personal identification ID of each service provider from the personal identification ID field of the identified entry.

[0139] The stored data acquisition unit 205 searches the location information database using the acquired personal identification ID and the type of data the user wishes to view as keys, and identifies the corresponding entry. The stored data acquisition unit 205 acquires the business code of the service provider that holds the user data that the user wishes to view from the business code field of the identified entry.

[0140] In Figures 15 and 16, when a user with user ID "uID01" wishes to view user data of the data type "disease name," the business codes of Hospital A and Hospital B are identified based on personal identification IDs "HL01" and "HL11."

[0141] The stored data acquisition unit 205 transmits a "stored data transmission request" to the service server 20 corresponding to the identified business code. The stored data transmission request includes the user's personal identification ID (a personal identification ID used by the identified service business to manage the user; such as a patient card number), data requirements for the stored data that the user wishes to view (for example, data type, data search period), etc.

[0142] The stored data acquisition unit 205 receives the stored data (user data) from the service server 20 that has transmitted the stored data transmission request. The stored data acquisition unit 205 displays the acquired stored data on the user's terminal 50 (displays it on the portal site).

[0143] The data distribution control unit 206 is a means for controlling data distribution by "sharing" or "provision."

[0144] First, data distribution related to "sharing" will be explained.

[0145] The data distribution control unit 206 receives a sharing request from the service server 20. The sharing request includes the personal identification ID of the user who is the target of data acquisition, the business code of the sender of the sharing request, data requirements for the data desired to be acquired (data type, data search period), accompanying information describing the purpose of data sharing, etc.

[0146] In the example of Figure 8, the sharing request includes the personal identification ID generated by insurance company C (service server 20-3) for user U1, insurance company C's business code, the data type "disease name," the data search period (the year 2021), and associated information.

[0147] The data distribution control unit 206 identifies the target of data distribution based on the personal identification ID and business code included in the sharing request. Specifically, the data distribution control unit 206 identifies the target by referring to the user information database shown in Fig. 15. In the above example, when a sharing request including the personal identification ID "EC01" is received from insurance company C, the data distribution control unit 206 determines from the entry in the first row shown in Fig. 15 that user U1 is the target of data distribution.

[0148] The data distribution control unit 206 then identifies the service provider that stores the data for which data sharing is requested, using the identified user's personal identification ID and the data type included in the sharing request. Specifically, the data distribution control unit 206 refers to the location information database shown in Fig. 16 and identifies the service provider that stores data corresponding to the data type included in the sharing request. In the above example, Hospital A and Hospital B are identified based on User U1's personal identification IDs "HL01" and "HL11" and the data type "disease name" included in the sharing request.

[0149] If the combination of the user's personal identification ID and the data type included in the sharing request is not stored in the location information database, the data distribution control unit 206 sends a negative response to the sender of the sharing request, indicating that the data cannot be shared. In the above example, if the combination of user U1's personal identification ID "HL01" or "HL11" and the data type "disease name" is not registered in the location information database, a negative response is sent to insurance company C (service server 20-3).

[0150] When the target of data distribution and the accumulator of the data to be distributed are specified, the data distribution control unit 206 acquires the specific contents (user data) of the accumulated data for which data sharing is requested from the data accumulator.

[0151] In the above example, the data distribution control unit 206 acquires stored data from the service servers 20-1 and 20-2 of Hospital A and Hospital B. Specifically, the data distribution control unit 206 transmits an "stored data transmission request" to the service servers 20-1 and 20-2 of Hospital A and Hospital B, respectively.

[0152] In this case, the data distribution control unit 206, like the stored data acquisition unit 205, sends an stored data transmission request to the service server 200, which includes the user's personal identification ID, the data requirements included in the sharing request (data type, data search period), etc.

[0153] The data distribution control unit 206 acquires the stored data stored by the service provider in response to the request to transmit the stored data. In the above example, the data distribution control unit 206 acquires the specific disease names (e.g., urticaria, sinusitis, depression) of user U1 diagnosed within the data search period from the service servers 20-1 and 20-2 of Hospital A and Hospital B.

[0154] Thereafter, the data distribution control unit 206 inquires about data sharing from the data distribution target. Specifically, the data distribution control unit 206 sends an inquiry about data sharing to the contact information of the data distribution target. In the above example, the inquiry is sent to the terminal 50 owned by user U1.

[0155] The data sharing inquiry includes the requester of the data sharing (data sharing destination), the data accumulator, the specific content of the data to be shared (the accumulated data itself), any accompanying information included in the sharing request, etc. In the above example, the data sharing inquiry includes Insurance Company C as the requester of the data sharing, Hospitals A and B as the data accumulators, and the specific disease name of User U1 (urticaria, etc.).

[0156] The data distribution control unit 206 receives a response to the data sharing inquiry from the terminal 50 .

[0157] If the user refuses data sharing, the data distribution control unit 206 notifies the data sharing request source that data sharing is not possible. In the above example, the data distribution control unit 206 transmits a negative response to the sharing request to the service server 20-3 of the insurance company C.

[0158] If the user agrees to data sharing, the data distribution control unit 206 sends a sharing instruction to the data accumulator. In the above example, the sharing instruction is sent to the service servers 20-1 and 20-2 of Hospital A and Hospital B, which are the data accumulators.

[0159] The sharing instruction includes a personal identification ID generated by the data accumulator, information about the data sharing destination, data requirements for the data to be shared (data type, data search period), etc. In the above example, a sharing instruction including user U1's personal identification ID "HL01", the address of insurance company C's service server 20-3, the data type "disease name", and the data search period "for the year 2021" is sent to hospital A's service server 20-1. A sharing instruction with similar content is sent to hospital B's service server 20-2.

[0160] In this way, the data distribution control unit 206 transmits a sharing instruction including the personal identification ID of the user (target person) who has agreed to data sharing, which is generated by the data accumulator.

[0161] Next, data distribution related to "provision" will be explained.

[0162] The data distribution control unit 206 receives the request for provision and the list of account holders from the transaction server 40 .

[0163] The data distribution control unit 206 identifies the catalog information requested to be provided from the data set name included in the provision request.

[0164] The data distribution control unit 206 refers to the location information database and identifies the personal identification ID corresponding to the data type and business code included in the identified catalog information. In the example of Fig. 12, the personal identification ID corresponding to each of users U1 to U3 is identified.

[0165] The data distribution control unit 206 identifies the users corresponding to the specified personal identification ID and who are listed on the account holder list. The data distribution control unit 206 refers to the user information database and identifies each user (at least one or more data distribution targets) corresponding to the specified personal identification ID and who are listed on the account holder list.

[0166] When the data distribution target is identified, similarly to the case of data sharing, the data distribution control unit 206 transmits a stored data transmission request to the service server 20. The data distribution control unit 206 acquires the specific contents (user data) of the stored data for which provision is requested from the data accumulator.

[0167] Thereafter, the data distribution control unit 206 inquires of the data distribution target about the provision of data. Specifically, the data distribution control unit 206 sends an inquiry about the provision of data to the contact information of the data distribution target. In the above example, if each of users U1 to U3 has opened an information account with the trading company, an inquiry about the provision of data is sent to the terminal 50 possessed by each user.

[0168] A data request will include information about the source of the data request, information about the data repository, and the specific details of the data requested.

[0169] The data distribution control unit 206 transmits a provision instruction to the data accumulator for the user who has given consent. The provision instruction includes the personal identification ID of the user who has consented to the data provision, information on the data recipient (for example, the name of the business, the business code, and the address of the data utilization server 30), and data requirements for the data to be provided (data type, data search period), etc.

[0170] In this way, the data distribution control unit 206 transmits at least one or more pieces of data to be distributed, which are acquired in response to transmitting the stored data transmission request to the service server 20, to the terminal 50 possessed by the user. The data distribution control unit 206 acquires from the terminal 50 whether or not the user has agreed to the at least one or more pieces of data to be distributed being the subject of data distribution. When the user has agreed to the data to be distributed being the subject of data distribution, the data distribution control unit 206 instructs the service server 20 to transmit the data to be distributed to the sharing destination and the providing destination.

[0171] The catalog information management unit 207 is a means for managing catalog information, and stores the catalog information created by the system administrator in the storage unit 208.

[0172] The catalog information management unit 207 receives a "catalog information transmission request" from the transaction server 40. In response to the reception of the request, the catalog information management unit 207 transmits the catalog information stored in the storage unit 208 to the transaction server 40.

[0173] The storage unit 208 stores information necessary for the operation of the distribution control server 10. A user information database is constructed in the storage unit 208. Furthermore, a database that stores names of service providers in association with provider codes is also constructed in the storage unit 208.

[0174] [Service Server] 17 is a diagram showing an example of a processing configuration (processing modules) of the service server 20 according to the first embodiment. Referring to FIG. 17, the service server 20 includes a communication control unit 301, an ID linkage control unit 302, a data distribution request unit 303, a data storage control unit 304, a transmission request processing unit 305, a data distribution unit 306, and a storage unit 307.

[0175] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the distribution control server 10. The communication control unit 301 also transmits data to the distribution control server 10. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0176] The ID federation control unit 302 is a means for controlling ID federation of users. The ID federation control unit 302 acquires a request for ID federation from a user who is logged in to an account using a GUI (Graphical User Interface) or the like. In response to the request from the user, the ID federation control unit 302 transmits an "ID federation request" including personal identification information (such as the name of the logged-in user), a personal identification ID (such as the user's membership number), and a business code to the distribution control server 10.

[0177] The user's personal identification ID, personal specification information, user data, etc. are managed using a customer information database (see FIG. 18). As shown in FIG. 18, the customer information database holds information (flag) indicating whether or not ID federation for the user has been completed. Upon completing ID federation, the ID federation control unit 302 sets a flag in the ID federation status field for the corresponding user (a circle is set in FIG. 18).

[0178] The data distribution request unit 303 is a means for requesting data distribution (data sharing) of user data to an information distribution business operator. The data distribution request unit 303 transmits a sharing request to the distribution control server 10 in response to an operation by a service provider employee or the like. Specifically, the data distribution request unit 303 transmits a sharing request to the distribution control server 10, including the personal identification ID of the user who is the target of data acquisition, the business code of the user's own device, and data requirements (data type, data search period) for the data desired to be acquired.

[0179] The data storage control unit 304 is a means for controlling the storage of user data generated as a result of providing a service to a user. The data storage control unit 304 associates the user's personal identification ID with the user's user data (data generated as a result of providing a service to the user or data necessary for the service to be provided to the user) and stores them in a customer information database.

[0180] As shown in Fig. 18, the data storage control unit 304 stores user data in a field corresponding to the type of data generated (stores specific data content). At that time, the data storage control unit 304 generates a data ID for identifying the user data and stores it in association with the user data and the data storage date. Note that Fig. 18 shows an example of a customer information database constructed in the service server 20-1 of Hospital A.

[0181] Here, for users for whom ID federation has been completed, the data storage control unit 304 transmits location information to the distribution control server 10 each time user data is stored in the customer information database. For example, consider a case where a service is provided to a user with a personal identification ID "HL01" and data on a disease name is generated as a result of a medical examination. In this case, location information including the personal identification ID "HL01", the business code "Hospital A", the data ID "HLD01", and the data type "Disease Name" is transmitted to the distribution control server 10.

[0182] The transmission request processing unit 305 is a means for processing a request to transmit stored data received from the distribution control server 10 .

[0183] The transmission request processing unit 305 searches the customer information database using the personal identification ID included in the stored data transmission request as a key to identify a corresponding entry. Furthermore, the transmission request processing unit 305 reads out the data ID and user data corresponding to the data requirements (data type, data search period) included in the stored data transmission request from the identified entry.

[0184] If the transmission request processing unit 305 is successful in reading the user data, it transmits an affirmative response including the read user data and a data ID to the distribution control server 10. If the transmission request processing unit 305 fails to read the user data, it transmits a negative response to the distribution control server 10 indicating that the stored data transmission request cannot be processed normally.

[0185] The data distribution unit 306 is a means for realizing data distribution by “sharing” or “provision.” The data distribution unit 306 processes a “sharing instruction” or a “provision instruction” received from the distribution control server 10.

[0186] When a sharing instruction is received, the data distribution unit 306 refers to the customer information database and identifies an entry corresponding to the personal identification ID, data type, and data search period included in the sharing instruction. For example, when a sharing instruction including the personal identification ID "HL01", the data type "disease name", and the data search period "January 1, 2021 to December 31, 2021" is received, the data distribution unit 306 identifies the entries shown in the top and second rows of Figure 18.

[0187] The data distribution unit 306 transmits the user data described in the corresponding data type field of the identified entry to the data sharing destination specified in the sharing instruction. In the example of Figure 8, "urticaria" and "sinusitis" are transmitted to the service server 20-3 of Insurance Company C.

[0188] The data distribution unit 306 processes the provision instruction in the same way as the sharing instruction. The data distribution unit 306 transmits the user data determined by the personal identification ID, data type, and data search period included in the provision instruction to the data destination specified by the provision instruction.

[0189] The data distribution unit 306 may assign an ID to the data to be supplied so that the business operator receiving the data can associate the acquired data. For example, the data distribution unit 306 may calculate a hash value of the user's personal identification information (for example, name or a combination of name and date of birth) and transmit the hash value to the data distribution destination as the user's ID.

[0190] The storage unit 307 stores information necessary for the operation of the service server 20. For example, the storage unit 307 stores account information of each actor (service provider, user, information distributor), a business code, a personal identification ID, etc. in association with each other.

[0191] [Data Utilization Server] The processing configuration of the data utilization server 30 can be the same as that of the service server 20. The data distribution request unit 303 of the data utilization server 30 presents information to a user (such as an employee of a data utilization business operator) and accepts operations from the user. Specifically, the data distribution request unit 303 displays a list of catalog information acquired from the trading server 40, and transmits a provision request to the trading server 40, including the data set name and data requirements of the catalog information selected by the user.

[0192] [Trade Server] 19 is a diagram showing an example of a processing configuration (processing module) of the trading server 40 according to the first embodiment. Referring to FIG. 19, the trading server 40 includes a communication control unit 401, an account opening unit 402, a catalog information request unit 403, a provision request processing unit 404, and a storage unit 405.

[0193] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the distribution control server 10. The communication control unit 401 also transmits data to the distribution control server 10. The communication control unit 401 hands over data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 401. The communication control unit 401 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0194] The account opening unit 402 is a means for opening an account for a user who wishes to distribute data through provision. The account opening unit 402 acquires a user ID from the user's terminal 50. The account opening unit 402 adds the acquired user ID to a list of account holders (see FIG. 20).

[0195] The catalog information request unit 403 is a means for transmitting a “catalog information transmission request” to the distribution control server 10 .

[0196] When the catalog information request unit 403 receives a “catalog information presentation request” from the data utilization server 30 , it transmits a “catalog information transmission request” to the distribution control server 10 .

[0197] In response to sending the request, the catalog information requesting unit 403 acquires catalog information stored in the distribution control server 10. The catalog information requesting unit 403 selects catalog information related to the service provider with which the device is affiliated, and transmits it to the data utilization business (data utilization server 30). The catalog information requesting unit 403 selects catalog information related to the affiliated service business based on the business code of the affiliated service business and the business code included in the catalog information.

[0198] The provision request processing unit 404 is a means for processing provision requests received from the data utilization server 30. The provision request processing unit 404 examines the data requirements included in the provision request. Specifically, the provision request processing unit 404 examines the consistency between the data utilization purpose of the data utilization business operator and the utilization purpose of the target data type. For example, if the content is "purpose of utilization: development of new drugs, data type: disease name", the examination will pass. In other words, the data utilization business operator (data utilization server 30) inputs the above-mentioned utilization purpose and data type into the transaction server 40 when requesting data provision.

[0199] If the examination is passed, the provision request processing unit 404 transmits the provision request acquired from the data utilization server 30 together with the list of account holders to the distribution control server 10.

[0200] The storage unit 405 stores information necessary for the operation of the transaction server 40. The storage unit 405 stores the business code of the partner service business.

[0201] [Device] 21 is a diagram showing an example of a processing configuration (processing module) of the terminal 50 according to the first embodiment. Referring to FIG. 21, the terminal 50 includes a communication control unit 501, a personal information input unit 502, an inquiry processing unit 503, an account information input unit 504, and a storage unit 505.

[0202] The communication control unit 501 is a means for controlling communication with other devices. For example, the communication control unit 501 receives data (packets) from the distribution control server 10. The communication control unit 501 also transmits data to the distribution control server 10. The communication control unit 501 passes data received from other devices to other processing modules. The communication control unit 501 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 501. The communication control unit 501 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0203] The personal information input unit 502 is a means for inputting personal information to the distribution control server 10 when a user registers. The personal information input unit 502 uses any means to input personal information (such as name, date of birth, contact information, and account information) to the distribution control server 10. For example, the personal information input unit 502 acquires the above personal information from the user using a GUI and transmits the acquired personal information to the distribution control server 10.

[0204] The personal information input unit 502 stores the user ID issued by the distribution control server 10 in the storage unit 505 .

[0205] The query processing unit 503 is a means for processing queries received from the distribution control server 10 when data is distributed by sharing or when data is distributed by provision. The query processing unit 503 displays a GUI according to the content of the query (data sharing, data provision). For example, the query processing unit 503 displays the GUI shown in FIG. 9 or FIG. 13 to obtain the user's intention (agreement or disagreement to data distribution). The query processing unit 503 transmits a response including the user's intention to the distribution control server 10.

[0206] The account information input unit 504 is a means for inputting information for opening an information account, which is required when distributing data through provision, to the trading server 40. The account information input unit 504 transmits the user's user ID to the trading server 40.

[0207] The storage unit 505 stores information necessary for the operation of the terminal 50.

[0208] [Hospital terminal] Examples of the hospital terminal 60 include mobile terminal devices such as smartphones and tablets, and computers (personal computers, laptop computers). The hospital terminal 60 can be any equipment or device that can accept operations from hospital staff and communicate with the distribution control server 10, etc. Furthermore, the configuration of the hospital terminal 60 is clear to those skilled in the art, so a detailed description will be omitted.

[0209] The hospital terminal 60 may transmit an ID federation request to the distribution control server 10 in response to an operation by a hospital staff member. The hospital terminal 60 also transmits the ID federation request to its own service server 20. The service server 20 (ID federation control unit 302) sets a flag in the ID federation status field of the entry (entry in the customer information database) of the user corresponding to the personal identification ID included in the ID federation request.

[0210] [System Operation] Next, an explanation will be given of the operation of the information distribution system according to the first embodiment. Fig. 22 is a sequence diagram showing an example of the operation of the information distribution system according to the first embodiment. With reference to Fig. 22, an explanation will be given of the operation of the system when data is shared.

[0211] The service server 20 with which data is to be shared transmits a sharing request to the distribution control server 10 (step S31).

[0212] The distribution control server 10 acquires the accumulated data (user data; for example, specific disease names) of the data distribution target person (step S32).

[0213] The distribution control server 10 sends an inquiry about data sharing including the acquired stored data to the data distribution target (step S33).

[0214] When consent to data sharing is obtained from the data distribution target, the distribution control server 10 transmits a sharing instruction to the service server 20 that is the data sharing source (step S34).

[0215] In response to receiving the sharing instruction, the service server 20 transmits the accumulated data of the data distribution target person to the service server 20 of the data sharing destination (step S35).

[0216] 23 is a sequence diagram showing an example of the operation of the information distribution system according to the first embodiment. The operation of the system when sharing data will be described with reference to FIG.

[0217] The transaction server 40 transmits a request for provision to the distribution control server 10 (step S41).

[0218] The distribution control server 10 acquires the accumulated data of the data distribution target person (step S42).

[0219] The distribution control server 10 makes an inquiry to the data distribution target about the provision of data including the acquired stored data (step S43).

[0220] When consent to data provision is obtained from the data distribution target, the distribution control server 10 transmits a provision instruction to the service server 20 that is the data provider (step S44).

[0221] In response to receiving the provision instruction, the service server 20 transmits the accumulated data of the data distribution target person to the data provision destination (step S45).

[0222] <Modification 1 of the First Embodiment> In the above embodiment, an example has been described in which the data requirements include a data search period. However, the data requirements may include other information instead of or in addition to the data search period. For example, the number of data items to be acquired from the data accumulator may be included in the data requirements. For example, information such as "three accumulated data items" may be included in the data requirements.

[0223] Alternatively, the data requirements may include a data search period and the number of data items. For example, the data requirements may include information such as "three disease names obtained in the year 2021."

[0224] <Modification 2 of the First Embodiment> In the above embodiment, the distribution control server 10 transmits the stored data transmission request to the service server 20 before making an inquiry about data distribution to the user. However, the distribution control server 10 may transmit the stored data transmission request to the service server 20 when the user desires to know details of the stored data. In other words, the distribution control server 10 may transmit the stored data transmission request to the service server 20 after making an inquiry about data distribution.

[0225] Specifically, the user terminal 50 does not display details of the data to be supplied to the outside (shared data, provided data) on the consent acquisition screen shown in Fig. 9 or 13, but displays the type of data in question (for example, disease name). At that time, the terminal 50 displays a button (for example, a detailed display button) for obtaining details of the supplied data (see Fig. 24).

[0226] When the detail display button is pressed, the terminal 50 notifies the distribution control server 10 of this. Specifically, the terminal 50 transmits a “supply data transmission request” to the distribution control server 10.

[0227] In response to receiving the supply data transmission request, the distribution control server 10 transmits an accumulated data transmission request to the service server 20. The distribution control server 10 transmits the accumulated data acquired from the service server 20 to the terminal 50 as a response to the supply data transmission request.

[0228] The terminal 50 displays the acquired stored data (details of the supplied data). Specifically, the terminal 50 displays a GUI as shown in Fig. 9 using the acquired details of the stored data.

[0229] In this way, the information distribution system may present the type of data that is the subject of data distribution to the user, and if the user desires to know the specific content (details) of the data that is the subject of data distribution, may present the specific content (specific disease name, such as urticaria). In other words, if the user cannot decide whether or not to agree to data sharing, etc., just by understanding the type of data for which data sharing, etc. is requested, the user may input this to the distribution control server 10. Based on a request from a user, the distribution control server 10 may present the user with detailed information regarding the data held by the user.

[0230] That is, when a user requests to view at least one or more pieces of data that are the subject of data distribution, the distribution control server 10 presents the data that are the subject of data distribution to the user. Specifically, when a user requests to view data that are the subject of data distribution, the distribution control server 10 transmits an accumulated data transmission request, including data requirements such as the data type and data search period, to the service server 20. In response to receiving the accumulated data transmission request, the service server 20 identifies data that matches the data requirements from among the multiple pieces of accumulated data and transmits the identified data to the distribution control server 10. The distribution control server 10 presents the transmitted data to the user who requests to view the data.

[0231] <Modification 3 of the First Embodiment> In the above-described variant example 2 of the first embodiment, it was explained that the terminal 50 displays the data type ("disease name" in the example of Figure 24) regarding the data (shared data, provided data) that is to be supplied to the outside on the consent acquisition screen.

[0232] The terminal 50 may display, on the consent acquisition screen, the data type of the data to be supplied to the outside, and may also display information about the data accumulator of the data to be supplied to the outside. For example, the terminal 50 may display as shown in Fig. 25. When the detailed display button shown in Fig. 25 is pressed, the terminal 50 transmits a "supply data transmission request" to the distribution control server 10.

[0233] 25, the distribution control server 10 refers to the location information database to acquire the service provider and data accumulation date corresponding to the personal identification ID and data type. The distribution control server 10 then transmits an inquiry (inquiry about data sharing, inquiry about data provision) including the acquired information about the service provider and the data accumulation date to the terminal 50.

[0234] In this way, the distribution control server 10 may present to the user, before transmitting the stored data transmission request, information on the service provider that stores at least one or more data items that are the subject of data distribution (in the example of FIG. 25, the name of the hospital).

[0235] <Fourth Modification of the First Embodiment> In the above embodiment, the case where the user only knows the specific contents of the data provided to the outside has been described, but the data provided to the outside may be selectable by the user.

[0236] In this case, the data sharing or providing party will set data requirements such as "two disease names diagnosed in 2021."

[0237] When the distribution control server 10 receives a sharing request or a provision request including the above-mentioned data requirements, it sets the data search period to "January 1, 2021 to December 31, 2021" and sends a request to send stored data to the service server 20.

[0238] The distribution control server 10 transmits to the terminal 50 a data distribution inquiry including the data ID of the stored data received by transmitting the stored data transmission request, the stored data, and the like.

[0239] In response to receiving the inquiry, the terminal 50 displays a GUI as shown in Fig. 26. When the user selects two of the three disease names and presses the consent button, the terminal 50 transmits to the distribution control server 10 the information that the user has consented to data sharing, as well as the data ID of the accumulated data that the user has consented to sharing.

[0240] The distribution control server 10 instructs the service server 20, which stores the data corresponding to the acquired data ID, to distribute data (share data, provide data). In the example of FIG. 26, the distribution control server 10 notifies Hospital A of the data ID corresponding to "urticaria" and instructs it to share the disease name (urticaria). Similarly, the distribution control server 10 notifies Hospital B of the data ID corresponding to "depression" and instructs it to share the disease name (depression).

[0241] As described above, the information distribution system according to the first embodiment includes a "data management function" that enables users to manage their stored data. Users use the data management function to check the details of their stored data. Specifically, as shown in the location information database in FIG. 16, the database only lists the data type, not the specific details (e.g., the name of a specific disease, such as urticaria). The data management function allows users to check the specific data content. Furthermore, when obtaining a user's consent for data distribution (data sharing and data provision), the distribution control server 102 obtains the specific details for each data item from the service server 101. The distribution control server 102 presents the obtained data (the stored data itself; data to be distributed to other businesses) to the user. The user can confirm the presented specific data and consent to the distribution of the data (acquisition of the data by a business other than the data accumulator). In other words, since users can make a decision after confirming the content of the data to be distributed, data unintended by the user can be prevented from being passed on to a business other than the data accumulator.

[0242] Existing data distribution systems are scope-based systems, and often provide data to third parties only in units of data type, such as "disease name." In contrast, the data distribution system disclosed in this application is entity-based, enabling data to be provided to third parties in units of data entities, such as "depression." The data distribution system disclosed in this application also employs distributed data management. In a typical PDS (Personal Data Store), the PDS operator holds the data and issues authorization based on the individual's consent. In contrast, in the data distribution system disclosed in this application, the provider holds the data, while the data distribution operator holds data location information and issues authorization for third-party provision based on the individual's consent. As a result, information leaks from data distribution operators are difficult to anticipate, providing a more secure system.

[0243] Next, the hardware of each device constituting the information distribution system will be described. Fig. 27 is a diagram showing an example of the hardware configuration of the distribution control server 10.

[0244] The distribution control server 10 can be configured by an information processing device (so-called computer), and has the configuration exemplified in Fig. 27. For example, the distribution control server 10 includes a processor 311, a memory 312, an input / output interface 313, and a communication interface 314. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.

[0245] However, the configuration shown in Fig. 27 is not intended to limit the hardware configuration of the distribution control server 10. The distribution control server 10 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the distribution control server 10 is not intended to be limited to the example shown in Fig. 27, and for example, the distribution control server 10 may include multiple processors 311.

[0246] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).

[0247] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.

[0248] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a device that accepts user operations such as a keyboard or a mouse.

[0249] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).

[0250] The functions of the distribution control server 10 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. Furthermore, the processing modules can be realized by semiconductor chips.

[0251] The service server 20, the transaction server 40, etc. can also be configured using information processing devices in the same way as the distribution control server 10, and their basic hardware configurations are no different from that of the distribution control server 10, so a description thereof will be omitted.

[0252] The distribution control server 10, which is an information processing device, is equipped with a computer, and the functions of the distribution control server 10 can be realized by causing the computer to execute a program. Furthermore, the distribution control server 10 executes the control method of the distribution control server 10 by the program.

[0253] [Variations] The configuration, operation, etc. of the information distribution system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.

[0254] In the above embodiment, a case has been described in which the user information database is configured inside the distribution control server 10, but the database may also be constructed in an external database server or the like. That is, some of the functions of the distribution control server 10 may be implemented in another server. More specifically, it is sufficient that the above-described "data distribution control unit (data distribution control means)" and the like are implemented in any of the devices included in the system.

[0255] The form of data transmission and reception between each device (distribution control server 10, service server 20, etc.) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Personal information of users and the like is transmitted and received between these devices, and in order to appropriately protect this information, it is desirable to transmit and receive encrypted data.

[0256] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the execution order of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the illustrated steps can be changed to the extent that the content is not affected, such as by executing each process in parallel.

[0257] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.

[0258] From the above explanation, it is clear that the present invention has industrial applicability, and the present invention can be suitably applied to an information distribution system that distributes stored data relating to services provided to users.

[0259] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes. [Appendix 1] a service server operated by a service provider and accumulating a plurality of data generated in providing services to users; a distribution control server that controls data distribution; Including, The distribution control server presents at least one or more pieces of data that are the subject of the data distribution to the user when the data distribution is distributed from the service server to a server of a provider other than the service provider from among the plurality of stored data. [Appendix 2] the distribution control server transmits to the service server a stored data transmission request including data requirements that specify at least one or more data items to be subject to the data distribution among the plurality of stored data items; The system described in Appendix 1, wherein, in response to receiving the request to transmit stored data, the service server identifies data that meets the data requirements from among the plurality of stored data, and transmits the identified data to the distribution control server. [Appendix 3] The system described in Appendix 2, wherein the data requirements include at least one data type of the data to be distributed. [Appendix 4] The system described in Appendix 3, wherein the data requirements include a data search period that specifies a period for searching for at least one data item that is the subject of the data distribution from among the plurality of accumulated data items. [Appendix 5] The distribution control server transmitting at least one or more pieces of data to be subject to data distribution, acquired in response to transmitting the stored data transmission request to the service server, to a terminal possessed by the user; A system described in any one of Appendices 2 to 4, which obtains from the terminal whether or not the user has agreed to at least one or more pieces of data being the subject of the data distribution. [Appendix 6] The system described in Appendix 5, wherein, when the user agrees to have at least one or more pieces of data that are the subject of the data distribution be the subject of the data distribution, the distribution control server instructs the service server to transmit at least one or more pieces of data that are the subject of the data distribution to a server of a provider other than the service provider. [Appendix 7] The system according to any one of appendixes 1 to 6, wherein the distribution control server controls data sharing for a first service provider to obtain data stored in a second service provider. [Appendix 8] The system described in Appendix 7, wherein the distribution control server controls data provision so that a data utilization business can obtain data accumulated by the second service business. [Appendix 9] The system described in any one of appendices 2 to 4, wherein the distribution control server sends the stored data transmission request to the service server, including the data requirements that specify the data that the user wishes to view, and presents the data obtained from the service server to the user. [Appendix 10] The system described in Appendix 1, wherein the distribution control server presents at least one or more pieces of data that are the subject of the data distribution to the user when the user wishes to view at least one or more pieces of data that are the subject of the data distribution. [Appendix 11] when the user desires to view at least one or more pieces of data that are the subject of the data distribution, the distribution control server transmits to the service server a stored data transmission request that includes data requirements that specify at least one or more pieces of data that are the subject of the data distribution among the plurality of stored pieces of data; In response to receiving the stored data transmission request, the service server identifies data that matches the data requirements from among the plurality of stored data, and transmits the identified data to the distribution control server; The system described in Appendix 10, wherein the distribution control server presents the transmitted data to the user who wishes to view the data. [Appendix 12] The system described in Appendix 11, wherein the distribution control server presents to the user information about the service provider that stores at least one or more data items that are the subject of the data distribution before sending the stored data transmission request. [Appendix 13] a communication control unit that communicates with a service server operated by a service provider and that accumulates a plurality of data generated by providing services to users; a data distribution control unit that, when at least one piece of data to be distributed from the plurality of stored data is distributed from the service server to a server of a business operator different from the service business operator, presents the at least one piece of data to be distributed to the user; A distribution control server comprising: [Appendix 14] In the distribution control server, Communicate with a service server operated by a service provider, which stores multiple data generated by providing services to users, A control method for a distribution control server, which presents at least one or more pieces of data that are the subject of data distribution to the user when at least one or more pieces of data that are the subject of data distribution are distributed from the service server to a server of a provider other than the service provider from the plurality of stored data. [Appendix 15] The computer installed on the distribution control server A process of communicating with a service server operated by a service provider and accumulating multiple pieces of data generated by providing services to users; a process of presenting to the user at least one piece of data to be distributed from the plurality of stored data when the at least one piece of data to be distributed is distributed from the service server to a server of a business operator different from the service business operator; A computer-readable storage medium that stores a program for executing the above.

[0260] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof. [Explanation of symbols]

[0261] 10 Distribution Control Server 20 Service Server 20-1 Service Server 20-2 Service Server 20-3 Service Server 30 Data Utilization Server 40 trading servers 50 devices 60 Hospital terminals 101 Service Server 102 Distribution Control Server 201 Communication control unit 202 User Registration Department 203 ID Linkage Department 204 Location Information Management Department 205 Accumulated Data Acquisition Unit 206 Data Distribution Control Unit 207 Catalog Information Management Department 208 Storage section 301 Communication Control Unit 302 ID linkage control unit 303 Data Distribution Request Department 304 Data storage control unit 305 Transmission request processing unit 306 Data Distribution Department 307 Storage section 311 processor 312 memory 313 Input / Output Interface 314 Communication Interface 401 Communication control unit 402 Account Opening Department 403 Catalog Information Request 404 Provision Request Processing Unit 405 Storage section 501 Communication control unit 502 Personal information input section 503 Query processing unit 504 Account information input section 505 Storage section

Claims

1. a service server operated by a service provider and accumulating a plurality of data generated in providing services to users; a distribution control server that controls data distribution; Including, when distributing at least one or more pieces of data to be distributed from the plurality of stored pieces of data from the service server to a server of a business operator different from the service business operator, the distribution control server presents information about the at least one or more pieces of data to be distributed to the user; when the user desires to view at least one or more pieces of data that are the subject of the data distribution, the distribution control server transmits to the service server a stored data transmission request that includes data requirements that specify at least one or more pieces of data that are the subject of the data distribution among the plurality of stored pieces of data; In response to receiving the stored data transmission request, the service server identifies data that matches the data requirements from among the plurality of stored data, and transmits the identified data to the distribution control server; The distribution control server presents the transmitted data to the user, The data requirements include: At least one data type of data to be distributed; a data search period that specifies a period during which at least one data item to be the subject of the data distribution is searched for from among the plurality of stored data items; the number of pieces of data that are accumulated during the data search period and correspond to the data type, and that are requested to be transmitted by the service server; and Included, the system.

2. The distribution control server transmitting at least one or more pieces of data to be subject to data distribution, acquired in response to transmitting the stored data transmission request to the service server, to a terminal possessed by the user; The system according to claim 1 , further comprising: acquiring from said terminal whether or not said user has agreed to at least one or more pieces of data to be the subject of said data distribution.

3. The system described in claim 2, wherein, when the user agrees to have at least one or more pieces of data that are the subject of the data distribution be the subject of the data distribution, the distribution control server instructs the service server to transmit at least one or more pieces of data that are the subject of the data distribution to a server of a provider other than the service provider.

4. The system according to claim 1 , wherein the distribution control server controls data sharing for a first service provider to obtain data stored in a second service provider.

Citation Information

Patent Citations

  • Consent information aggregation management method, consent information aggregation management device, and program

    JP2014228961A

  • Information providing system

    JP2018124853A

  • Information providing device, information providing method and information providing program

    JP2020024511A

  • Data distribution control device, data distribution control method, and data distribution control program

    JP2020129311A

  • Information transaction system, information transaction device, information transaction method, and program

    WO2021085061A1