Medical information certification system and medical information certification method

The medical information certification system addresses unauthorized access by generating and verifying one-time codes linked to user medical information, ensuring secure and authentic verification, thereby preventing fraudulent use.

JP7784660B2Active Publication Date: 2025-12-12BLUE BOOKS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2021180523
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-11-04
Publication Date
2025-12-12
Estimated Expiration
2041-11-04

AI Technical Summary

Technical Problem

Conventional medical information certification systems are vulnerable to unauthorized acquisition and use of personal medical information due to image-processable data being easily duplicated, forged, or tampered with, leading to illegal activities.

Method used

A medical information certification system and method utilizing a management server that generates a one-time code linked to user medical information, transmitted via a user terminal to a verifier terminal, with a judgment process to verify the authenticity of the medical information, preventing unauthorized access and use.

Benefits of technology

Prevents unauthorized acquisition and use of personal medical information by ensuring secure and authentic verification through a one-time code system, reducing fraudulent activities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007784660000001
    Figure 0007784660000001
  • Figure 0007784660000002
    Figure 0007784660000002
  • Figure 0007784660000003
    Figure 0007784660000003
Patent Text Reader

Abstract

To enable preventing an unauthorized acquisition and unauthorized use of personal medical information.SOLUTION: A medical information certifying system 1 comprises: a management server 2 that stores medical information on a user; a user terminal 3; and a verifying person terminal 4. The management server 2 is configured to: receive a request from the user terminal 3; generate a one-time code which is associated with the medical information on the user being a certification object, and which is set with a valid time; and transmit the one-time code to the user terminal 3. The verifying person terminal 4 is configured to: acquire the one-time code; and transmit the acquired one-time code to the management server 2. The management server 2 is configured to: determine whether the medical information on the user of the certification object associated with the transmitted one-time code satisfies a prescribed condition; and transmit a determination result to the verifying person terminal 4. The verifying person terminal 4 is configured to display the determination result.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a medical information certification system and a medical information certification method that can certify, for example, an individual's medical information. [Background technology]

[0002] A vaccination support system has been proposed as an example of a system for certifying personal medical information (see Patent Document 1). In conventional vaccination support systems, vaccination reservations and vaccination records are stored on a system server, allowing recipients to view their registered reservation information and vaccination records on a mobile device.

[0003] Furthermore, in recent years, in order to prevent the spread of infectious diseases, there has been a demand for societal and international responses that require prior infection control measures and confirmation of the current health status of users, such as allowing people to enter stores, facilities, schools, medical institutions, or travel abroad on the condition that they present proof of vaccination or proof of a negative infectious disease test, or allowing them to receive reduced quarantine measures such as quarantine at the destination country.

[0004] However, when proof of vaccination completion or negative results of infectious disease tests are displayed on the display of a user's mobile phone or provided on paper, if the data is image-processable, there is a problem that personal medical information can be illegally obtained and used by duplicating, forging, or tampering with the display screen or certificate, which could enable illegal entry and exit, use of facilities or stores, travel, attendance at school, consultation at medical institutions, etc., in violation of national or local laws, regulations, or requests. For this reason, it is desirable to prevent the illegal acquisition and use of personal medical information when it is presented or referenced. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Utility Model Registration No. 3212784 Summary of the Invention [Problem to be solved by the invention]

[0006] In view of the above-mentioned problems, an object of the present invention is to provide a medical information certification system and a medical information certification method that can prevent the unauthorized acquisition and unauthorized use of personal medical information. [Means for solving the problem]

[0007] This invention is a medical information certification system and a medical information certification method comprising a management server that stores a user's medical information, a user terminal used by the user, and a verifier terminal, wherein the management server comprises a code generation unit that receives a request from the user terminal and generates a one-time code that is linked to the medical information of the user to be certified who operates the user terminal and has a set expiration time, and a first code transmission unit that transmits the one-time code generated by the code generation unit to the user terminal, the verifier terminal comprises a code acquisition unit that acquires the one-time code from the user terminal and a second code transmission unit that transmits the one-time code acquired by the code acquisition unit to the management server, the management server further comprises a judgment unit that judges whether the medical information of the user to be certified linked to the one-time code sent from the second code transmission unit satisfies predetermined conditions, and a judgment result transmission unit that transmits the judgment result judged by the judgment unit to the verifier terminal, and the verifier terminal further comprises a judgment result display unit that displays the judgment result sent from the judgment result transmission unit. [Effects of the Invention]

[0008] This invention makes it possible to prevent the unauthorized acquisition and use of personal medical information. [Brief explanation of the drawings]

[0009] [Figure 1] 1 is an explanatory diagram showing an example of the configuration of a medical information certification system according to the present invention; [Figure 2] FIG. 3 is an explanatory diagram showing an example of management data stored in an auxiliary storage unit of a management server. [Figure 3] FIG. 2 is an explanatory diagram showing an example of the data structure of a user data DB. [Figure 4] FIG. 4 is an explanatory diagram of the screen configuration of a login screen. [Figure 5] FIG. 4 is an explanatory diagram of the screen configuration of a home screen. [Figure 6] FIG. 1 is an explanatory diagram showing an example of the operation of a medical information certification system. [Figure 7] FIG. 10 is an explanatory diagram of the screen configuration of a code display screen. [Figure 8] FIG. 10 is an explanatory diagram of the screen configuration of a first result display screen. [Figure 9] FIG. 10 is an explanatory diagram of the screen configuration of a second result display screen. [Figure 10] FIG. 10 is an explanatory diagram of the screen configuration of the third result display screen. [Figure 11] FIG. 10 is an explanatory diagram of a screen configuration of a code display screen according to a modified example. DETAILED DESCRIPTION OF THE INVENTION

[0010] An embodiment of the present invention will now be described with reference to the drawings. <System configuration>

[0011] Figure 1 is a block diagram showing an example of the system configuration of a medical information certification system 1. The medical information certification system 1 is a system for storing personal medical information and providing a medical information certification service that certifies the medical information in order to confirm each individual's current health condition.

[0012] 1, the medical information certification system 1 includes a management server 2, a plurality of user terminals 3, and a plurality of verifying terminals 4. The management server 2, each of the plurality of user terminals 3, and each of the plurality of verifying terminals 4 are connected to each other so as to be able to communicate with each other via a public line (public network) 5 such as the Internet.

[0013] The user terminal 3 is a terminal used by the user to certify (present) his or her own medical information, and the verifier terminal 4 is a terminal used by a verifier to verify the user's medical information. For example, the verifier may be an employee of a store, facility, or venue for various events (hereinafter referred to as "store, etc."). In this case, the user certifies medical information such as proof of vaccination against infectious diseases or negative results from an infectious disease test, and the verifier can verify the user's medical information and determine whether to accept the user into the store, etc. In other words, the system can determine whether to accept the user into the store, etc. after confirming that infection prevention measures have been taken in advance and their current health status, thereby achieving both infection prevention and socioeconomic activity. The verifier may also be a medical professional such as a doctor or pharmacist, a school nurse, or a paramedic. In this case, the verifier can verify the user's medical data (such as health checkup data and medical record data). In the following, the present embodiment will be described using an example in which the verifier is an employee of a store, etc.

[0014] The management server 2 is configured as a general-purpose server computer, and the user terminal 3 and the verifying terminal 4 are configured as portable computers (mobile terminals) such as tablet PCs, smartphones, feature phones, and portable game consoles. The management server 2 may be configured as a single server computer or multiple server computers. Also, part or all of the management server 2 may be a cloud server. Furthermore, the verifying terminal 4 may be a POS terminal, an automatic ticket vending machine, an automatic check-in machine, etc.

[0015] The management server 2 includes a control unit 21, a communication unit 22, and an auxiliary storage unit 23, and functions as a web server. The communication unit 22 and the auxiliary storage unit 23 are each connected to the control unit 21 via a communication line (bus) or the like.

[0016] The user terminal 3 includes a control unit 31, an input unit 32, a display unit 33, an imaging unit 34, a communication unit 35, and an auxiliary storage unit 36. The input unit 32, the display unit 33, the imaging unit 34, the communication unit 35, and the auxiliary storage unit 36 ​​are each connected to the control unit 31 via a communication line or the like.

[0017] The verifying terminal 4 includes a control unit 41, an input unit 42, a display unit 43, a code obtaining unit 44, a communication unit 45, and an auxiliary storage unit 46. The input unit 42, the display unit 43, the code obtaining unit 44, the communication unit 45, and the auxiliary storage unit 46 are each connected to the control unit 41 via a communication line or the like.

[0018] The control unit 21 includes a calculation unit 24 and a main memory unit 25, and executes various calculations and control operations in the management server 2. The control unit 31 includes a calculation unit 37 and a main memory unit 38, and executes various calculations and control operations in the user terminal 3. The control unit 41 includes a calculation unit 47 and a main memory unit 48, and executes various calculations and control operations in the verifying terminal 4.

[0019] The calculation unit (24, 37, 47) is a calculation processing unit including a CPU or MPU. The main memory unit (25, 38, 48) has a RAM (DRAM) and a ROM. The RAM is used as a work area and buffer area for the calculation unit (24, 37, 47). The ROM stores the startup programs of the management server 2, the user terminal 3, or the verifying terminal 4, default values ​​for various information, etc.

[0020] The input unit (32, 42) has input components that accept operational inputs from the user or the verifying person, and an input detection circuit that is interposed between the input components and the calculation unit (37, 47). The input components are, for example, a touch panel and / or hardware operation buttons or keys. The touch panel can be of any type, such as a capacitive type, an electromagnetic induction type, a resistive film type, or an infrared type. The input detection circuit outputs an operation signal or operation data corresponding to the operation of each input component to the calculation unit (37, 47).

[0021] The display unit (33, 43) has a display and a display control circuit interposed between the display and the calculation unit (37, 47). The display may be, for example, an LCD (liquid crystal display) or an organic EL display. The display control circuit has a GPU, a VRAM, and the like. Under the direction of the calculation unit (37, 47), the GPU uses image generation data stored in the RAM to generate display image data in the VRAM for displaying various screens on the display, and outputs the generated display image data to the display.

[0022] The imaging unit 34 has an imaging element (image sensor), a focus lens, etc., and captures an image by converting imaging light (visible light) captured by the imaging element into an electrical signal. Examples of the imaging element include solid-state imaging elements such as a CCD (Charge Coupled Device) image sensor or a CMOS (Complementary Metal Oxide Semiconductor) image sensor. The captured image data output from the imaging unit 34 is stored in the main memory unit 38 or the auxiliary memory unit 36.

[0023] The communication units (35, 45) have a communication circuit for connecting to the public line 5. The communication circuit is a wired communication circuit or a wireless communication circuit, and communicates with an external computer via the public line 5 according to instructions from the calculation units (37, 47). The communication units (35, 45) can also directly communicate with each other via short-range wireless (for example, infrared, Wi-Fi (registered trademark), or Bluetooth (registered trademark)) without using the public line 5. In other words, the user terminal 3 and the verifying terminal 4 can directly communicate with each other via short-range wireless.

[0024] The code acquisition unit 44 acquires code information (one-time code) with a set expiration date from the user terminal 3. The one-time code is information generated (issued) by the management server 2 in response to a request from a user using the user terminal 3, and is expressed as data such as an appropriate character string or image. When this one-time code is generated, an expiration date (for example, 1 hour to 36 hours) is automatically set, and it is linked to the medical information of the requesting user. With regard to this linking, the one-time code itself may not contain the user's medical information, but the user ID included in the user's medical information may be stored as a set with the one-time code. Therefore, it is preferable to store the one-time code, user ID, expiration time, and authentication time as a set in the one-time code data DB 51. The one-time code generated by the management server 2 is sent to the requesting user terminal 3, and is then transmitted from the user terminal 3 to the verifying terminal 4 in a predetermined manner.

[0025] The method for acquiring the one-time code by the code acquisition unit 44 is not particularly limited. For example, an image of a code (code image) with an embedded one-time code may be displayed on the display unit 33 of the user terminal 3 and read by the verifier terminal 4. In this case, the verifier terminal 4 has an imaging unit (the imaging unit on the verifier terminal side) configured similarly to the imaging unit 34 described above, and the code acquisition unit 44 captures the code image with the imaging unit on the verifier terminal side, decodes the captured image, and acquires the one-time code embedded in the code. The code is a rectangular code such as a one-dimensional code (barcode) or a two-dimensional code. The two-dimensional code may be a matrix-type two-dimensional code such as QR Code (registered trademark), Micro QR Code, Aztec, DataMATRIX, MaxiCODE, or VeriCODE, or a stack-type two-dimensional code such as PDF417 or CODE49.

[0026] Alternatively, one-time code data (one-time code data) may be transmitted by short-range wireless communication from the user terminal 3 to the verifying terminal 4 (acquired via short-range wireless communication). In this case, the code acquiring unit 44 acquires the one-time code using the communication unit 45 or an externally connected dedicated reader (code reader).

[0027] The auxiliary memory unit (23, 36, 46) is composed of other non-volatile memory such as an HDD, SSD, flash memory, EEPROM, etc., and stores programs and various data used by the calculation unit (24, 37, 47) to control the operation of the management server 2, user terminal 3, or verifying terminal 4.

[0028] The auxiliary storage unit 23 of the management server 2 stores a management program 23a for executing various operations of the management server 2 in this system, and management data 23b required for using this system. The management program 23a includes a communication program for accessing (establishing communication with) an external device (user terminal 3 or verifier terminal 4), a code generation program for generating a one-time code, a first code transmission program for transmitting the one-time code to the user terminal, a code reception program for receiving the one-time code transmitted from the verifier terminal, a determination program for determining whether the medical information of the user to be certified, which is linked to the received one-time code, satisfies predetermined conditions, a determination result transmission program for transmitting the determination result to the verifier terminal 4, an invalidation program for invalidating the one-time code used for the determination so that it cannot be used for future determinations, and programs for selecting and executing various functions provided in the management server 2.

[0029] The management program 23a and the management data 23b are read out from the auxiliary storage unit 23 as needed and stored (deployed) in the main storage unit 25 (RAM). The operation of the management server 2 is realized by the calculation unit 24 executing the management program 23a deployed in the main storage unit 25 (RAM).

[0030] The auxiliary memory unit 36 ​​of the user terminal 3 stores a user program 36a for executing various operations of the user terminal 3 in this system in accordance with user input, and user data 36b required for using this system.

[0031] The user program 36a and user data 36b are read out from the auxiliary storage unit 36 ​​as needed and stored (expanded) in the main storage unit 38 (RAM). The operation of the user terminal 3 is realized by the calculation unit 37 executing the user program 36a expanded in the main storage unit 38 (RAM).

[0032] The user program 36a includes at least a communication program for accessing (establishing communication with) an external device (the management server 2 or the verifying terminal 4), a code request program for requesting the management server 2 to issue a one-time code, a code transmission program for transmitting the one-time code to the verifying terminal 4, a registration program for registering medical information in the management server 2, and a program for selecting and executing various functions provided in the user terminal 3. The user data 36b includes at least the user data required in this system.

[0033] The auxiliary memory unit 46 of the verifier terminal 4 stores a verifier program 46a for executing various operations of the verifier terminal 4 in this system in response to operational inputs by the verifier, and verifier data 46b required for using this system.

[0034] The verifier program 46a and the verifier data 46b are read out from the auxiliary storage unit 46 as needed and stored (expanded) in the main storage unit 48 (RAM). The operation of the verifier terminal 4 is realized by the calculation unit 47 executing the verifier program 46a expanded in the main storage unit 48 (RAM).

[0035] The verifyer program 46a includes at least a code acquisition program for controlling the code acquisition unit 44 to acquire a one-time code (one-time code data), a communication program for accessing (establishing communication with) an external device (the management server 2 or the user terminal 3), a second code transmission program for transmitting a one-time code to the management server 2, a determination result reception program for receiving a determination result transmitted from the management server 2, a determination result display program for displaying the determination result on the display unit 43, and a program for selecting and executing various functions of the verifyer terminal 4. When one-time code data is acquired using a code image, the code acquisition program includes an imaging program for controlling the imaging unit on the verifyer terminal to acquire a captured image, and a decoding program for extracting an image (code image) of a code (code) included in the captured image, decodes the extracted code image, and acquires information embedded in the code (executes a code reading function). The verifyer data 46b includes at least data of verifyer information required in this system.

[0036] The configurations of the management server 2, the user terminal 3, and the verifier terminal 4 shown in FIG. 1 are merely examples and are not limited thereto. For example, the management server 2 can be connected to computers at medical institutions and public institutions such as public health centers, ward offices, city halls, and town / village offices. The user terminal 3 and the verifier terminal 4 have a communication function and may be equipped with components related to this communication function (such as a speaker and a microphone). The user terminal 3 and the verifier terminal 4 also have a current location acquisition function that acquires their current location using radio waves from GPS satellites and may be equipped with components related to this current location acquisition function (such as an antenna that receives radio waves from GPS satellites). In this case, the location information of the user terminal 3 obtained when the medical information certification service is used can be used as location information for identifying the location of the store or other location where the verifier terminal 4 is installed (the location where this system is used). <Data structure>

[0037] Fig. 2 is an explanatory diagram showing an example of management data 23b stored in the auxiliary storage unit 23 of the management server 2. Fig. 3 is an explanatory diagram showing an example of the data structure of the user data DB 50. Various data used in the medical information certification system 1 is stored (registered) in the auxiliary storage unit 23 of the management server 2.

[0038] Specifically, as shown in Figure 2, the auxiliary memory unit 23 of the management server 2 registers a user data DB (database) 50, a one-time code data DB (database) 51, etc. as part of the management data 23b necessary for the operation of the medical information certification system 1.

[0039] 3, the user data DB 50 contains user authentication information data (authentication data) 61, vaccination record information data (vaccination record data) 62, test result information data (test result data) 63, medical certificate data (certificate data) 64, and medical information data (medical data) 65. Note that the vaccination record information, test result information, certificate information, and medical information may be collectively referred to as the user's medical information, and the vaccination record data 62, infectious disease test data 63, certificate data 64, and medical data 65 may be collectively referred to as the user's medical data 66.

[0040] The authentication data 61 is data for performing personal authentication of a user. For example, the authentication data 61 includes data such as unique identification information (user ID) assigned to each user and information on a password (key information) linked to the user ID. The user ID and password are expressed using numbers, letters, symbols, or a combination of these. For example, the user ID can be the user's name, telephone number, email address, address, health insurance card number, My Number, or any other character string. The user ID and password are set when the user is registered in the medical information certification system 1 and are registered in the user data DB 50. In personal authentication by the medical information certification system 1, if the combination of the user ID and password is correct, the personal authentication is successful (the user is identified), but if the combination of the user ID and password is incorrect, the personal authentication fails.

[0041] Note that instead of or in addition to the combination of the user ID and password, data (biometric data) of the user's biometric information (such as a face image, fingerprint information, or iris information) may be registered as the authentication data 61. In this case, personal authentication (biometric authentication) may be performed using the biometric data.

[0042] The vaccination record data 62 includes information on whether or not a vaccine applicable to each of various infectious diseases has been administered (vaccination information), information on when the vaccine was administered (vaccination timing information), etc. Furthermore, the vaccination record data 62 for vaccines that require multiple administrations to be effective also includes data on the number of vaccinations.

[0043] The infectious disease test data 63 is data on the test results when checking whether or not a person is infected with various infectious diseases (viruses). For example, it is data such as information on the results (positive / negative) of PCR tests, antibody tests, and antigen tests for various viruses. In other words, the infectious disease test data 63 is data indicating whether or not a person is infected with a specific infectious disease. Note that the infectious disease test data 63 may be deleted after a predetermined period has passed since the infectious disease test was conducted (after the period when the test results are considered to lose their validity has passed).

[0044] The certificate data 64 is data (electronic data of various certificates, etc.) about a certificate (vaccine passport) that a specific vaccine has been administered, a certificate (negative certificate) that a person is not infected with a specific infectious disease (negative test result), or a certificate (recovery certificate) that a person has recovered from a specific infectious disease. Note that certificates related to certificate information include certificates issued by public institutions such as the national government and local governments, as well as certificates issued by medical institutions.

[0045] The medical data 65 is data on the user's medical history at medical institutions, examination results, and various test results (health checkups, medical examinations, etc.) The medical data 65 is created when the user is registered in the medical information certification system 1 or when the user visits a medical institution for the first time after registration, and is updated each time the user visits a medical institution.

[0046] The medical data 66 (vaccination record data 62, infectious disease test data 63, certificate data 64, and medical treatment data 65) may be automatically acquired from computers of private testing institutions, medical institutions, or public institutions such as public health centers, ward offices, city halls, and town / village offices. The medical data registered in the medical institution's or public institution's computers is linked to personal data (personal information) such as a user's name, health insurance card number, or Individual Number. The management server 2 compares the personal data linked to the medical data registered in the medical institution's or public institution's computers with the authentication data 61 registered in the user data DB 50, and registers the acquired medical data linked to the matching user's authentication data 61 as medical data 66. If there is no user matching the medical data acquired from the medical institution's or public institution's computer, the medical data is not registered.

[0047] The medical data 66 may also be uploaded by the user himself / herself from the user terminal 3. In this case, the user uploads the medical data while logged in to the medical information certification service application, and therefore the uploaded medical data is linked to the authentication data 61 of the logged-in user.

[0048] 2, one-time code data is registered in the one-time code data DB 51. As described above, the one-time code data is generated with an expiration date in response to a request from a user who uses the user terminal 3, and is invalidated or deleted after the expiration date so that it cannot be used for future determinations. <System operation example>

[0049] An example of the operation of the medical information certification system 1 will be described below with reference to Figures 4 to 10. When the application for the medical information certification service is executed on the user terminal 3, various operation screens are displayed on the display unit 33 (display) of the user terminal 3.

[0050] As the first operation screen, a login screen 100 as shown in Fig. 4 is displayed on the display unit 33. The login screen 100 is a screen for performing personal authentication (logging in) to receive the medical information certification service, and has an ID input section 101 for inputting an ID (user ID), a password input section 102 for inputting a password, a login button 103 for executing the login, and a method change button 104 for executing another authentication method (changing the authentication method). The login button 103 and the method change button 104 function as software keys (operation buttons). Hereinafter, the software keys will be simply referred to as "buttons."

[0051] The ID input unit 101 and the password input unit 102 each have a text box (input field) that accepts text input. When the login button 103 is operated (selected) with correct data (a registered user ID and a password associated with the registered user ID) entered into the ID input unit 101 and the password input unit 102, respectively, login (personal authentication) is successful. If login fails, the login screen 100 returns to its initial state. Furthermore, when the method change button 104 is selected, the image capture unit 34 is activated, allowing the user to log in using another authentication method, such as biometric authentication. This login (personal authentication) is performed by transmitting the entered user ID and password to the management server 2, which then verifies whether the user ID and password match the data in the authentication data 61. After login is successful, the management server 2 and the user terminal 3 are connected, and subsequent communications between them are recognized as communications from the same user terminal 3 and processed accordingly.

[0052] If the login is successful, a home screen (my page) 110 as shown in Fig. 5 is displayed on the display unit 33. The home screen 110 has a code acquisition button 111 for acquiring (requesting) a one-time code, and a logout button 112. When the logout button 112 is selected, the user is logged out of the medical information certification service application, and the provision of the medical information certification service ends.

[0053] When the code acquisition button 111 is selected, a request is made to the management server 2 to issue (generate) a one-time code (S1 in FIG. 6), and the one-time code is generated by the management server 2 and sent to the user terminal 3 (S2 in FIG. 6). At this time, the one-time code is linked to the authentication data 61 of the user who requested the issuance of the one-time code (the logged-in user). An individual authentication number is also assigned to the one-time code. In this embodiment, an image of the code (code image) with the one-time code embedded is sent to the user terminal 3, and a code display screen 120 such as that shown in FIG. 7 is displayed on the display unit 33.

[0054] The code display screen 120 has a code display section (code image display section) 121 that displays a code image in which a one-time code is embedded, and a validity time display section 122 that shows the remaining validity time (validity period) of the one-time code. The validity time display section 122 may display the date and time as the expiration date instead of displaying the remaining validity time.

[0055] Furthermore, on the code display screen 120, it is possible to change the color of the background image (background image) according to the state of the medical data 66, and it is also possible to display watermark text on the background image. For example, on the code display screen 120, it is possible to change the color of the background image according to the time (elapsed period) that has passed since the infectious disease test was conducted, and it is also possible to display the number of vaccinations as watermark text on the background image.

[0056] Although not shown in the figure, when an application (code acquisition application) for the medical information certification service is executed in the verifier terminal 4, the code acquisition unit 44 becomes ready to acquire a one-time code. For example, if the code acquisition unit 44 has an imaging unit on the verifier terminal side, the imaging unit on the verifier terminal side is activated, and the code image displayed on the code display unit 121 can be captured by the imaging unit on the verifier terminal side. Then, the verifier terminal 4 extracts the code image from the captured image (captured image), decodes the extracted code image, and acquires the one-time code (S3 in FIG. 6).

[0057] When the verifier terminal 4 acquires the one-time code, it accesses the management server 2 and inquires about the medical data 66 of the user (the user to be certified) associated with the one-time code (S4 in FIG. 6). Specifically, the verifier terminal 4 transmits the one-time code data and information about the inquiry to the management server 2. For example, when inquiring about the medical data 66 as part of measures against a specific infectious disease, the verifier terminal 4 inquires about the management server 2 as to whether the user to be certified has received a predetermined number of vaccinations effective against the infectious disease, or about the results of an infectious disease test.

[0058] When inquiring about whether a vaccine has been administered, if multiple vaccinations are required, the management server 2 is also inquired about whether the required number of vaccinations have been administered. Also, when inquiring about an infectious disease test, the management server 2 is inquired about whether the time elapsed since the infectious disease test was conducted has exceeded the period that can guarantee its validity.

[0059] The management server 2 determines whether the medical data 66 of the user to be certified satisfies predetermined conditions (performs a determination process) in response to the inquiry, and transmits the determination result to the verifying terminal 4 (S5 in FIG. 6). For example, the predetermined conditions are conditions (acceptance conditions) for determining whether the user is in a health state that allows them to be accepted into a store or the like, and in this embodiment, the acceptance conditions are that the user has received a valid vaccination or that the result of an infectious disease test is negative.

[0060] In this embodiment, the management server 2 refers to the medical data 66 of the user to be certified, and transmits to the verifyer terminal 4 the determination result (whether or not the user to be certified can be accepted into a store, etc.) in response to inquiries such as whether the user to be certified has been vaccinated or whether the infectious disease test result of the user to be certified is negative. For example, if the user has been vaccinated or the infectious disease test result is negative, the management server 2 transmits to the verifyer terminal 4 a result indicating that the user can be accepted into a store, etc. (OK). On the other hand, if the user has not been vaccinated and the infectious disease test result cannot be confirmed as negative, the management server 2 transmits to the verifyer terminal 4 a result indicating that the user cannot be accepted into a store, etc. or is inappropriate (NG).

[0061] The judgment process (S5) using the same one-time code is performed only once, and when the judgment result is obtained or the one-time code is received, the one-time code is invalidated or data indicating that the judgment has been completed is linked to it. Therefore, even if the validity period is still in effect, subsequent inquiries about the same one-time code are not permitted. For this reason, if a subsequent inquiry about the same one-time code is made, the management server 2 sends a warning (requesting the verification terminal 4 to update or obtain a new one-time code) to the verification terminal 4.

[0062] When the checker terminal 4 receives the determination result, a result display screen 130 showing the determination result is displayed on the display unit 43. Figures 8 to 10 show examples of the result display screen 130. Figure 8 is an explanatory diagram of a first result display screen 130a showing a result that is OK, Figure 9 is an explanatory diagram of a second result display screen 130b showing a result that is NG, and Figure 10 is an explanatory diagram of a third result display screen 130c showing a result that is a warning.

[0063] As shown in Figures 8 to 10, the result display screen 130 has a result display section 131, an authentication number display section 132, a response result input section 133, a facial image display section 134, a code information display section 135, a vaccination record information display section 136, and a test result information display section 137.

[0064] The result display unit 131 is provided to simply display the judgment result, and an image, a message, or the like indicating the judgment result is displayed on the result display unit 131. For example, on the first result display screen 130a indicating an OK result, an image consisting of a circle and the letters "OK" and a message stating "Passport (medical information) has been successfully read" is displayed on the result display unit 131 (FIG. 8). On the second result display screen 130b indicating an NG result, an image consisting of a cross and the letters "NG" and a message stating "Failed to read passport" is displayed on the result display unit 131 (FIG. 9). On the third result display screen 130c indicating a warning result, an image consisting of a triangle and an exclamation mark (!") and a message stating "Please update your passport and authenticate again" is displayed on the result display unit 131 (FIG. 10).

[0065] The authentication number assigned to the one-time code is displayed in the authentication number display section 132. However, on the second result display screen 130b showing a result of NG, the authentication number is not displayed because the medical information verification has failed.

[0066] The response result input unit 133 is provided for inputting the response result of the checker (the user's behavior result) of whether or not the user was actually admitted to the store or the like, and has an entry refusal button 133a and an entry permission button 133b. The checker (such as an employee of the store or the like) operating the checker terminal 4 selects the entry refusal button 133a when the checker refuses entry to the store or does not enter the store, and selects the entry permission button 133b when the checker permits entry to the store (the user enters the store). When the entry refusal button 133a is selected, the checker terminal 4 transmits to the management server 2 information that the entry refusal button 133a was selected (information that the user did not enter the store). On the other hand, when the entry permission button 133b is selected, the checker terminal 4 transmits to the management server 2 information that the entry permission button 133b was selected (information that the user entered the store). Therefore, the management server 2 ultimately stores information (entry information) on whether the user entered the store or not. In addition, the store entry information is linked to the judgment result of the inquiry. For example, even if the judgment result is "OK," there is a possibility that the customer will not enter the store, or even if the judgment result is "NG," there is a possibility that the customer will be allowed to enter if infection control measures such as ensuring sufficient seat spacing are in place. In this way, the judgment result and the store entry information can be associated and stored. Therefore, statistics on the behavior of customers who were judged "OK" and those who were judged "NG" can be collected and used to develop more effective infection control measures. In addition, the store can grasp the number of customers who entered the store with "OK" and the number who entered with "NG." This can be used to design the store interior, such as widening the seating distance or increasing the number of partitions, depending on the ratio of customers who entered with "NG." In addition, by accumulating data on judgment results and behavior results, customers can be tracked anonymously, which can be used to develop more effective infection control measures.

[0067] The facial image display unit 134 displays the facial image of the user when the facial image of the user is registered (stored) in the user data DB 50. Therefore, the user's identity can be confirmed using the facial image. Note that the user may be allowed to select whether or not to display the facial image on the facial image display unit 134.

[0068] The code information display unit 135 displays information about the one-time code used for the judgment. For example, information about the date and time when the one-time code used for the judgment was generated and the date and time when the one-time code used for the judgment was displayed on the display unit 33 of the user terminal 3 is displayed. Therefore, if too much time has passed since the date and time displayed on the code information display unit 135, it can be determined that there is a possibility of fraudulent acquisition or fraudulent use through duplication, forgery, tampering, etc., and fraudulent acquisition or fraudulent use of the one-time code can be prevented. However, information about the one-time code is not displayed on the second result display screen 130b, which shows a result of NG.

[0069] The vaccination record information of the user to be certified is displayed in the vaccination record information display unit 136. For example, the vaccination record information of the user to be certified, such as the type of vaccine, the number of vaccinations, and the vaccination date and time (date and time of the last vaccination), is displayed in the vaccination record information display unit 136.

[0070] The most recent test result information of the user to be certified is displayed in the test result information display unit 137. For example, the test result information display unit 137 displays the test date and time and the time elapsed since the test date and time as the most recent test result information of the user to be certified.

[0071] However, the second result display screen 130b, which shows a result of NG, does not display the vaccination record information of the user to be certified and the test result information of the user to be certified (Fig. 9).In addition, the result display screen 130 can also display information such as the gender, age (generation), and phone number of the user to be certified.

[0072] Furthermore, gender is displayed on the result display screen 130, which further prevents authentication by fraudulent methods. Furthermore, a telephone number is displayed on the result display screen 130, so if the user terminal 3 is a smartphone, for example, the user can call the telephone number to check whether the call goes through to the user terminal 3 and confirm whether authentication has been performed correctly.

[0073] The above configuration and operation make it impossible to prove the user's correct medical information by duplicating, forging, or tampering with the display screen or paper certificate, thereby preventing inappropriate store entry due to the fraudulent acquisition and fraudulent use of personal medical information. In other words, since the verifier terminal 4 obtains the authentication result from information from the management server 2, it does not perform authentication based on false authentication results using fraudulently created images or apps on the user terminal 3, thereby preventing fraud.

[0074] Furthermore, since there is no direct exchange of medical information data between the user terminal 3 and the verifier terminal 4, and the verifier terminal 4 only acquires the judgment result data from the management server 2, leakage of personal information can be prevented.

[0075] In addition, in this embodiment, the one-time code is transmitted using a code image, so the user can easily present the one-time code, and the verifier can also easily obtain the one-time code.

[0076] Furthermore, since the one-time code does not contain any information about the user or their medical information, it is possible to prevent the one-time code from being read by other devices or applications, resulting in information leakage.

[0077] Furthermore, the medical information certification system 1 of the present invention can be used to certify vaccination records and infectious disease test results when accepting customers at stores, etc., thereby contributing to the prevention of infection spread while also promoting socioeconomic activities.

[0078] Furthermore, in this embodiment, once a one-time code is used for a judgment, the one-time code is invalidated and cannot be used for future judgments, thereby preventing the reuse of one-time codes and preventing the fraudulent acquisition and fraudulent use of personal medical information.

[0079] The code generation unit of this invention corresponds to the code generation program and control unit 21 operating in accordance with the program in the above embodiment, the first code transmission unit corresponds to the first code transmission program and control unit 21 operating in accordance with the program, the code acquisition unit corresponds to code acquisition unit 44, the second code transmission unit corresponds to the second code transmission program and control unit 41 operating in accordance with the program, the judgment unit corresponds to the judgment program and control unit 21 operating in accordance with the program, the judgment result transmission unit corresponds to the judgment result transmission program and control unit 21 operating in accordance with the program, the judgment result display unit corresponds to the judgment result display program and control unit 41 operating in accordance with the program, and the code image display unit corresponds to the code transmission program and control unit 31 operating in accordance with the program, but this invention is not limited to this embodiment and can be embodied in various other ways. Furthermore, the screens and specific configurations described in the above embodiment are merely examples and can be modified as appropriate depending on the actual product.

[0080] In the above-described embodiment, as part of measures against specific infectious diseases, the management server 2 is queried to determine whether a person has been vaccinated or whether the result of an infectious disease test is negative. However, the medical information certification system 1 of the present invention can also be applied when a person wishes to disclose his or her own medical information to medical professionals, school nurses, emergency personnel, etc. In this case, medical professionals, etc. can obtain (view) the user's medical information only when the user presents a valid one-time code. Therefore, medical information will not be viewed without the user's intention, and unauthorized acquisition and use of personal medical information can be prevented.

[0081] In addition to the above-described embodiment, the user may be able to select the type of medical information to be disclosed. For example, as shown in FIG. 11, the code display screen 120 may be provided with a switch button 123 for selecting (switching) which of vaccination record information, test result information, certificate information, and medical information to disclose to the verifying party. In this case, the code display screen 120 may be provided with a disclosure information display section 124 that displays the type of medical information to be disclosed, allowing the user to recognize the type of medical information to be disclosed. In this way, the minimum amount of medical information necessary can be disclosed to the verifying party, thereby ensuring the protection of personal information. [Industrial Applicability]

[0082] The invention can be used in industries such as verifying personal medical information. [Explanation of symbols]

[0083] 1. Medical Information Certification System 2...Administrative server 21...Control unit 22…Communications Department 23…Auxiliary storage unit 3...User terminal 31...Control unit 32...Input section 33...Display section 4...Verifier terminal 41...Control unit 42...Input section 43…Display section 44...Code acquisition section

Claims

1. A medical information certification system comprising a management server that stores user authentication information and user medical information linked to the user authentication information, a user terminal used by the user, and a verifier terminal, The management server a code generation unit that acquires authentication information of a user who operates the user terminal from the user terminal with which communication has been established, and that receives a request from the user terminal and generates a one-time code that is linked to the authentication information of the user who operates the user terminal and is to be certified, and that has a set validity period; a first code sending unit that sends the one-time code generated by the code generating unit to the user terminal; The verifying terminal a code acquisition unit that acquires the one-time code from the user terminal; a second code transmission unit that transmits the one-time code acquired by the code acquisition unit to the management server; The management server a determination unit that acquires authentication information of the user to be certified that is linked to the one-time code transmitted from the second code transmission unit, and determines whether medical information of the user to be certified that is linked to the authentication information satisfies a predetermined condition; a determination result transmission unit that transmits the determination result determined by the determination unit to the verifying terminal; The verifying terminal The apparatus further includes a judgment result display unit that displays the judgment result transmitted from the judgment result transmission unit. Medical information certification system.

2. the user terminal includes a code image display unit that displays a code image in which the one-time code is embedded, The code acquisition unit has an imaging unit that captures the code image, and decodes the code image captured by the imaging unit to acquire the one-time code. The medical information certification system according to claim 1.

3. the medical information includes vaccination record information relating to vaccination; The determination unit determines whether the user to be certified has been vaccinated with a vaccine effective against a specific infectious disease based on the vaccination record information of the user to be certified.

3. The medical information certification system according to claim 1 or 2.

4. the medical information includes test result information of an infectious disease test, The determination unit determines whether the user to be certified is suffering from a specific infectious disease based on the test result information of the user to be certified.

4. The medical information certification system according to claim 1, 2 or 3.

5. The verifying person terminal is a terminal used by a verifying person who determines whether or not to accept the user at a store or facility, The determination unit determines whether the medical information of the user to be certified satisfies the acceptance conditions of the store or facility.

5. The medical information certification system according to claim 1.

6. The management server further includes an invalidation unit that invalidates the one-time code when the one-time code is used for a determination by the determination unit, thereby making the one-time code unusable for future determinations.

6. The medical information certification system according to claim 1.

7. A medical information certification method in a medical information certification system comprising a management server that stores user authentication information and user medical information linked to the user authentication information, a user terminal used by the user, and a verifier terminal having a display unit, The management server acquires authentication information of a user who operates the user terminal from the user terminal with which communication has been established, and receives a request from the user terminal, generates a one-time code that is linked to the medical information of the user to be certified who operates the user terminal and has a set validity period; Transmitting the generated one-time code to the user terminal; The verifying terminal, Obtaining the one-time code from the user terminal; Transmitting the acquired one-time code to the management server; The management server acquiring authentication information of the user to be certified that is linked to the one-time code transmitted from the verifying terminal, and determining whether medical information of the user to be certified that is linked to the authentication information satisfies predetermined conditions; The result of the determination is transmitted to the verifying terminal; The verifying terminal The determination result transmitted from the management server is displayed on the display unit. Medical information certification method.

Citation Information

Patent Citations

  • Immunization support system

    JP3212784U

  • JPP6933317B