Information processing device, information processing method, and information processing program
By managing personal data on user terminals and using data capsules for secure transmission, the system addresses security and transparency issues in data handling, reducing leakage risks and enhancing user control.
Patent Information
- Application Number
- JP2023042156
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-03-16
- Publication Date
- 2025-12-25
- Estimated Expiration
- 2043-03-16
AI Technical Summary
Existing technologies do not adequately address the security and transparency issues in the provision and storage of personal privacy information, particularly in scenarios where data is managed on a server side, making it vulnerable to leaks and unclear usage to users.
A system where personal data is managed on a user's terminal device, with meta-information stored as data capsules on a server, allowing secure transmission and usage upon user authentication and authorization, ensuring data is not stored on the server side.
Enhances security and transparency in personal data handling by reducing the risk of data leakage and enabling users to control how their data is used, promoting peace of mind and visibility.
Smart Images

Figure 0007792364000001 
Figure 0007792364000002 
Figure 0007792364000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device, an information processing method, and an information processing program. [Background technology]
[0002] A technology is disclosed in which, based on a data provision log indicating that a user's personal privacy information has been provided to a data recipient, evidence of the receipt of the personal privacy information is requested from the previous data recipient, and the evidence received from the data recipient is associated with the data provision log and stored in a data storage device (DB). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2020-112993 Summary of the Invention [Problem to be solved by the invention]
[0004] However, the above-mentioned conventional techniques merely aim to improve the evidential strength of the data recipient's proof that he or she has received personal privacy information. There is still room for improvement in the provision and storage of personal privacy information.
[0005] The present application has been made in view of the above, and aims to further improve the security of providing and storing personal privacy information. [Means for solving the problem]
[0006] The information processing device of the present application is characterized by comprising: a creation unit that creates a data capsule for data securely stored on a user's terminal device by linking meta information of the data with the user's ID; a management unit that stores the data capsule; a reception unit that receives an information usage request from the user; a request unit that transmits the data capsule to the user's terminal device in response to the information usage request; and an acquisition unit that acquires the data from the user's terminal device in response to the transmission of the data capsule. [Effects of the Invention]
[0007] According to one aspect of the embodiment, the security of providing and storing personal privacy information can be further improved. [Brief explanation of the drawings]
[0008] [Figure 1] FIG. 1 is an explanatory diagram illustrating an example of the configuration of an information processing system according to an embodiment. [Figure 2] FIG. 2 is an explanatory diagram showing an overview of information registration according to the embodiment. [Figure 3] FIG. 3 is an explanatory diagram showing an overview of information use according to the embodiment. [Figure 4] FIG. 4 is a conceptual diagram illustrating an example of the configuration of an information processing system according to the embodiment. [Figure 5] FIG. 5 is a diagram illustrating an example of the configuration of a terminal device according to the embodiment. [Figure 6] FIG. 6 is a diagram illustrating an example of the configuration of a server device according to the embodiment. [Figure 7] FIG. 7 is a diagram illustrating an example of the meta-information database. [Figure 8] FIG. 8 is a diagram illustrating an example of the history information database. [Figure 9] FIG. 9 is a flowchart showing a processing procedure according to the embodiment. [Figure 10] FIG. 10 is a diagram illustrating an example of a hardware configuration. DETAILED DESCRIPTION OF THE INVENTION
[0009] Hereinafter, an information processing device, an information processing method, and an information processing program according to the present application (hereinafter referred to as "embodiments") will be described in detail with reference to the drawings. Note that the information processing device, the information processing method, and the information processing program according to the present application are not limited to these embodiments. Furthermore, the same components in the following embodiments will be denoted by the same reference numerals, and duplicated descriptions will be omitted.
[0010] [1. Overview of information processing method] First, an example of the configuration of an information processing system according to an embodiment will be described with reference to Fig. 1. Fig. 1 is an explanatory diagram showing an example of the configuration of an information processing system.
[0011] 1, the information processing system 1 includes a terminal device 10 and a server device 100. The terminal device 10 and the server device 100 are connected to each other via a network N (see FIG. 4) in a wired or wireless manner so as to be able to communicate with each other. In this embodiment, the terminal device 10 cooperates with the server device 100.
[0012] The terminal device 10 is a smart device such as a smartphone or tablet terminal used by a user U, and is a portable terminal device capable of communicating with any server device via a wireless communication network such as 5G (5th Generation) or LTE (Long Term Evolution). The terminal device 10 has a screen such as a liquid crystal display with a touch panel function, and accepts various operations on displayed data such as content, such as tapping, sliding, and scrolling, performed by the user U with a finger or a stylus. An operation performed on an area of the screen where content is displayed may be considered an operation on the content. The terminal device 10 may be not only a smart device, but also an information processing device such as a desktop PC (Personal Computer) or a notebook PC.
[0013] The terminal device 10 also has a data management function. The terminal device 10 stores information (data) related to individual users in a secure location. The secure location may be a secure area (secure element) inside the terminal device 10, or an external storage device. If the secure location is an external storage device, the terminal device 10 may have an appropriate access control function for securely accessing the external storage device. The data stored inside the terminal device 10 may itself be link information to an external device. The external storage device may be a USB key, a My Number card, or a storage server. The link information to the external device may be ledger information in blockchain technology (distributed ledger technology).
[0014] For example, the terminal device 10 may store various information about the user U. Specifically, the terminal device 10 may store information about attributes such as the user U's demographic attributes, psychographic attributes, geographic attributes, and behavioral attributes. For example, the terminal device 10 may store information such as the user's name, age, gender, address (home), place of work, family structure, hometown (local area), occupation, job title, income, qualifications, type of residence (detached house, apartment, etc.), whether or not the user has a car, commuting time to school or work, commuting route to school or work, commuter pass section (station, line, etc.), frequently used stations (other than the station nearest to the user's home or workplace), extracurricular activities (location, time zone, etc.), hobbies, interests, lifestyle, etc.
[0015] The server device 100 is an information processing device that works in conjunction with the terminal device 10 of each user U and provides API (Application Programming Interface) services for various applications (hereinafter referred to as apps) and various data to the terminal device 10 of each user U, and is realized by a computer, a cloud system, etc.
[0016] The server device 100 also has a user authentication function and a user information management function. The server device 100 uses the user information management function to manage, as a data capsule, meta information of data managed by the data management function of the terminal device 10 of the user U. The server device 100 then uses the meta information managed as a data capsule to authenticate the user U.
[0017] The server device 100 may also be an information processing device that provides some kind of online web service to the terminal device 10 of each user U. For example, the server device 100 may provide the following web services: internet connection, search service, social networking service (SNS), electronic commerce (EC), electronic payment, online games, online banking, online trading, hotel and ticket reservations, video and music distribution, news, maps, route search, route guidance, line information, operation information, and weather forecast. In practice, the server device 100 may cooperate with various servers that provide the above-mentioned web services and act as an intermediary for the web services or may be responsible for processing the web services.
[0018] The server device 100 also acquires various types of history information (log data) indicating the behavior of the user U from the terminal device 10 of the user U or from various servers based on the user ID, etc. For example, the server device 100 acquires a location history, which is a history of the user U's location and date and time, from the terminal device 10. The server device 100 also acquires a search history, which is a history of search queries entered by the user U, from a search server (search engine). The server device 100 also acquires a browsing history, which is a history of content viewed by the user U, from a content server. The server device 100 also acquires a purchase history (payment history), which is a history of the user U's product purchases and payment processes, from an e-commerce server or a payment processing server. The server device 100 may also acquire a listing history and a sales history, which are a history of the user U's listings on the marketplace, from the e-commerce server or the payment processing server. The server device 100 also acquires a posting history, which is a history of the user U's posts, from a posting server or SNS server that provides a word-of-mouth posting service. The various servers and the like described above may be the server device 100 itself. That is, the server device 100 may function as the various servers and the like described above.
[0019] [1-1. Personal information management device] In the information processing system 1 according to this embodiment, the terminal device 10, which is a user device, manages information (data) relating to individual users and provides the information to the server side (server device 100) when necessary in response to authentication and confirmation by the user U. In other words, the server device 100 does not store data, but requests data from the terminal device 10 only when necessary, and receives the data from the terminal device 10 that has received approval from the user U (approval for data use).
[0020] In conventional information management, personal information is managed on the server side. However, when personal information is managed on the server side, there is a possibility that it may be leaked from the server side. For example, if the server is hacked or subject to unauthorized access, user information may be leaked. Furthermore, it is unclear to users how their personal information is being used on the server side. Users are not sure how the server is using their information.
[0021] Therefore, in this embodiment, information about individual users is not stored on the server side (server device 100). The server device 100 manages only link information (data capsule) to information about individual users that is managed by the terminal device 10, which is the user's personal device.
[0022] [1-2. Information Registration] In this embodiment, the user U registers meta-information of information (data) relating to the user as a data capsule in the server device 100. Fig. 2 is an explanatory diagram showing an overview of information registration according to this embodiment.
[0023] For example, as shown in FIG. 2, as a preprocessing step, if a dedicated app is not installed in the terminal device 10, the user U installs the dedicated app in the terminal device 10 (step S0). For example, the terminal device 10 downloads and installs the dedicated app from an app store or the like via the network N (see FIG. 4). The dedicated app may be provided by the server device 100 via the app store, or may be provided directly by the server device 100. Note that if the dedicated app is already installed, this process is not necessary. The terminal device 10 realizes the data management function by activating the dedicated app.
[0024] Next, the user U uses the terminal device 10 to set authentication information required depending on the authentication means (a password in the case of password authentication) and then performs authentication with the server device 100 (step S1). That is, the user U registers and authenticates authentication information when installing (first launch) a dedicated app. For example, the user U uses the terminal device 10 to access the server device 100, which requires authentication for logging in. At this time, the server device 100 may register and authenticate a password (PW) for the user U, or may register and authenticate using FIDO (Fast Identity Online). Furthermore, the user U may be configured to perform authentication the next time the server device 100 is launched after logging out or when the dedicated app is restarted after an update.
[0025] Next, the user U uses the terminal device 10 to make an information registration request to the server device 100 and transmits the ID (user ID) and the type of data (data type) (step S2). For example, the data type is specified as "address" and transmitted. If there are multiple types of data, each type of data may be transmitted separately. Furthermore, if the server device 100 already stores a data capsule corresponding to the data type, the data capsule ID indicating the data capsule may be transmitted instead of the data type.
[0026] Next, the server device 100 creates and stores a data capsule by linking the ID sent from the terminal device 10 of the user U with the type of data (step S3). For example, the data capsule contains meta-information such as "data type: address," "management location: terminal device (user device)," "management software: application," and "access method: authentication." At this time, the server device 100 may link the data capsule with a data capsule ID and store it.
[0027] The data capsules may be stored inside or outside the server device 100. For example, the server device 100 may store the data capsules using cloud computing or blockchain technology (distributed ledger technology).
[0028] Next, after creating and storing the data capsule, the server device 100 transmits an information registration response (OK) to the terminal device 10 (step S4). At this time, the server device 100 may transmit a data capsule ID indicating the created data capsule together with the information registration response (OK) to the terminal device 10. Furthermore, the terminal device 10 may present information indicating the information registration response (OK) to the user U. Note that the information indicating the information registration response (OK) may be a message, a dialogue, a push notification, or the like.
[0029] [1-3. Information use] In this embodiment, user authentication is performed using meta-information (data capsule) relating to the individual user registered in the server device 100. Fig. 3 is an explanatory diagram showing an overview of information usage according to this embodiment.
[0030] For example, as shown in Fig. 3, when a user U attempts to use information (data) related to the user in a web service or the like provided by the server device 100 (or a destination), the terminal device 10 makes an information use request to the server device 100 and transmits an ID (user ID) and a type of data (step S11). For example, if the user U specifies "address" as the type of data, the terminal device 10 transmits the ID and "address." Note that, if the terminal device 10 knows the data capsule ID indicating the data capsule corresponding to the type of data, it may transmit the data capsule ID indicating the data capsule instead of the type of data.
[0031] In practice, the user U may consider and decide (select) whether to encrypt data when passing a data capsule ID (reference) to the server device 100 using the terminal device 10. For example, if the user U initially decides (selects) to encrypt data, the server device 100 creates a key pair consisting of a private key and a public key and passes the public key to the terminal device 10. As a result, when the user U decides (selects) to encrypt data, the terminal device 10 can encrypt the data using the public key and transmit it to the server device 100 (public key cryptography). A public key may be prepared for each user or each data capsule, or one public key (one pair) per server shared by all users. In this case, only the server device 100 that has the private key can decrypt the data. As for the method of passing the public key, the public key may be sent together with the ID, the server device 100 may separately publish the public key, or the public key may be pre-installed in a dedicated app.
[0032] Next, server device 100 transmits a data capsule together with (or as) an authentication and authorization request to terminal device 10 (step S12).
[0033] Next, the terminal device 10 presents an authentication and authorization request to the user U (step S13). For example, the terminal device 10 requests authentication from the user U and also requests authorization for the use of information (data) related to the individual user (data use authorization).
[0034] Next, the user U performs authentication and authorization in response to the authentication and authorization request (step S14). For example, the user U performs user verification using the terminal device 10 (authentication device) to locally verify the identity of the user. Here, an example will be described in which the authenticator is a built-in authenticator. Note that, in reality, the authenticator may be an external authenticator that is physically independent from the terminal device 10 and can be linked to the terminal device 10. For example, the terminal device 10 (authentication device) performs biometric authentication based on biometric information acquired from the user U. In addition, it is not limited to biometric authentication, but may also be one-time password or multi-factor authentication. In addition, the user U approves the use of information (data) related to the user. Note that, in reality, the user U may perform user verification using the terminal device 10 (authentication device) when approving the use of information (data) related to the user.
[0035] Next, the user U sends an authentication and authorization response (OK) as a result of the authentication and authorization (step S15). For example, the user U presents that the terminal device 10 (authentication device) has successfully verified the user and that the user has authorized the use of information (data) related to the user. In practice, the terminal device 10 may determine that the user U has authorized the use of information (data) related to the user based on the successful user verification.
[0036] Next, in response to the authentication and approval response (OK), the terminal device 10 acquires information (data) relating to the individual user stored by the data management function (step S16).
[0037] Next, the terminal device 10 transmits information (data) relating to the individual user to the server device 100 via the network N (see FIG. 4) (step S17). At this time, it is preferable that the terminal device 10 encrypts the information (data) relating to the individual user and transmits it to the server device 100. For example, the terminal device 10 may encrypt the information (data) relating to the individual user with the above-mentioned public key and transmit it to the server device 100. In this case, the server device 100 may obtain the information (data) relating to the individual user by decrypting it with the encryption key (public key encryption method).
[0038] Next, the server device 100 uses the information (data) relating to the individual user transmitted from the terminal device 10 (step S18). For example, the server device 100 uses the information (data) relating to the individual user in its own or a subsequent web service, etc. When the server device 100 uses the information (data) relating to the individual user in a web service, etc. other than its own, the server device 100 presents the data in a format that allows the server device 100 to delete it.
[0039] Next, the server device 100 stores a usage history (log) of the information (data) related to the individual user (step S19). In this embodiment, the server device 100 does not store the information (data) related to the individual user itself. After using the information (data) related to the individual user, the server device 100 discards it. Each time the server device 100 uses the information (data) related to the individual user, it obtains it from the terminal device 10, which is the storage location, according to the above procedure.
[0040] However, in reality, the user U can decide how to handle information (data) relating to the user himself / herself. The basis of this embodiment is a form in which data is not stored in the server device 100, but it may be possible to control (decide) it according to the preference of the user U or a data storage policy (where and how the user U wants to manage his / her data). For example, after acquiring the data, if the user U wants to store the data in the server device 100 (after confirming with the user U), the data may be stored in the server device 100.
[0041] Furthermore, when storing data in the server device 100, an example can be considered in which the information (data) stored in the terminal device 10 is treated as primary data, and the data capsule framework according to this embodiment is used to store the data as secondary data in the server device 100 (based on the policy described above), thereby achieving "synchronization." For example, one example can be considered in which, when the "address" of the primary data in the terminal device 10 is updated, the "address" of the secondary data in the server device 100 is immediately updated.
[0042] Furthermore, when data is stored in the server device 100, it may be possible to control (determine) it according to a data deletion (erasure) policy. For example, when data is left on the server side, it may be automatically deleted (erased) after a certain period of time has passed, or it may be possible to delete (erasure) it immediately when specified by the user U.
[0043] [1-4. Requests to use other users' data] Although this embodiment describes a case where user U attempts to use information (data) related to the user U himself / herself, technically, this can also be used when user U attempts to use information (data) related to another user. For example, in step S11, when user U attempts to use information (data) related to another user in server device 100, terminal device 10 makes an information use request to server device 100 and transmits the ID of the other user and the type of desired data. Then, when the other user responds to the authentication and authorization request received from server device 100 regarding the information use request (when the other user's authorization is received), server device 100 may allow user U to use the information (data) related to the other user.
[0044] [1-5. Other] In this embodiment, meta information of the data is stored in the server device 100. User information, which is the main body of the data, is registered in the terminal device 10, which is a user device. When using the user information, the terminal device 10 notifies the server device 100 of the items of information required. The server device 100 requests and obtains information from the meta information related to the items of information required from the terminal device 10. When a request is received from the server device 100, the terminal device 10 performs user authentication for the user U.
[0045] Furthermore, when a data capsule ID is sent from terminal device 10, server device 100 finds detailed information about the data corresponding to the data capsule ID and contacts terminal device 10. Based on the detailed information about the data, terminal device 10 reads out registered user information and presents it to user U. Note that an application flag may be set when the data capsule is registered.
[0046] The server device 100 may also add a credibility level as meta information of the data. If there is no data capsule ID at the time of initial registration, the terminal device 10 can understand the credibility level of the meta information, and in that case, the meta information registration flow is immediately executed.
[0047] The user U may select the contents of the data capsule (meta information to be registered). For example, the user U may be able to select thinned-out location information, detailed location information, etc. The server device 100 may indicate minimum requirements for the granularity of the information. For example, various granularities may be set, such as prefectures and municipalities (e.g., "Shinagawa-ku, Tokyo"), or the number of digits of a GPS (Global Positioning System). Furthermore, a dedicated app may store the user U's preferences in advance, and if information can be provided at a granularity that matches the preferences, an agreement is obtained each time, but before that, it may be confirmed whether information within the agreed-upon range can be acquired (the acquisition possibility multiplied by the preference).
[0048] Furthermore, it is not limited to information such as "Shinagawa Ward, Tokyo," but can also be used for any data that has a tree structure, such as data where the granularity can be set in a similar manner if the meaning of linguistic information is organized into a tree-like hierarchy.When using tree-structured data, it is possible to not only use a tree structure determined by rules, but also to automate the use of only those that match in terms of reliability and granularity by learning the information tree using machine learning, etc.
[0049] The registration server that registers the meta-information and the request server (processing execution server) that uses the meta-information may be separate. That is, there does not need to be one server device 100. For example, the capsule ID may be transmitted from the terminal device 10 to the processing execution server, and the processing execution server may inquire of the registration server, and the registration server may make a request to the terminal device.
[0050] Furthermore, the data capsule ID itself may be a combination of information types. For example, when a first user wants to perform processing based on information from a second user, the first user requests the server device 100 to use the information from the second user. The server device 100 inquires of the second user, and if the second user approves (OK), the server device 100 performs processing based on the information from the second user and transmits the processing results to the first user.
[0051] In this embodiment, there is no need to store data on the server side, which reduces the risk of data leakage on the server side. Also, because users are authenticated and authorized for each use of data on the server side, the transparency of data usage is improved. As a result, data usage by users and its visualization can be promoted. This also leads to peace of mind for users.
[0052] The data may be used in any manner. Regarding how the data is handled after use, it may be determined whether or not to leave the data on the server side. Authentication may also be FIDO authentication. The data capsule may also be stored on the user's device (app) and managed by linking it to a FIDO key. The authenticity of the data may also be checked.
[0053] [2. Example of information processing system configuration] Next, the configuration of an information processing system 1 including a server device 100 according to an embodiment will be described with reference to Fig. 4. Fig. 4 is a conceptual diagram showing an example of the configuration of the information processing system according to the embodiment. As shown in Fig. 4, the information processing system 1 according to the embodiment includes a terminal device 10 and a server device 100. These various devices are connected to each other via a network N so as to be able to communicate with each other via wired or wireless communication. The network N is, for example, a LAN (Local Area Network) or a WAN (Wide Area Network) such as the Internet.
[0054] Furthermore, the number of devices included in the information processing system 1 shown in Fig. 4 is not limited to that shown in the figure. For example, in Fig. 4, for the sake of simplicity, only one terminal device 10 is shown, but this is merely an example and is not limiting, and two or more devices may be included.
[0055] The terminal device 10 is an information processing device used by a user U. For example, the terminal device 10 may be a smart device such as a smartphone or tablet terminal, a mobile phone such as a feature phone (Gala-ke or Gala-ho), a PC (Personal Computer), a PDA (Personal Digital Assistant), a game console or AV device with communication functions, an information appliance or digital appliance, a car navigation system, a wearable device such as a smart watch or a head-mounted display, smart glasses, etc. The terminal device 10 may also be a house or building, a car, a home appliance, an electronic device, etc. that is compatible with the Internet of Things (IOT).
[0056] In addition, the terminal device 10 can connect to the network N via a wireless communication network such as LTE (Long Term Evolution), 4G (4th Generation), or 5G (5th Generation: 5th generation mobile communication system), or via short-range wireless communication such as Bluetooth (registered trademark) or wireless LAN (Local Area Network), and communicate with the server device 100.
[0057] The server device 100 is, for example, a computer such as a PC or a blade server, or a mainframe or a workstation, etc. The server device 100 may be realized by cloud computing.
[0058] [3. Example of terminal device configuration] Next, the configuration of the terminal device 10 will be described with reference to Fig. 5. Fig. 5 is a diagram showing an example of the configuration of the terminal device 10. As shown in Fig. 5, the terminal device 10 includes a communication unit 11, a display unit 12, an input unit 13, a positioning unit 14, a sensor unit 20, a control unit 30 (controller), and a storage unit 40.
[0059] (Communications Department 11) The communication unit 11 is connected to a network N (see FIG. 4) by wire or wirelessly, and transmits and receives information to and from the server device 100 via the network N. For example, the communication unit 11 is realized by a NIC (Network Interface Card), an antenna, etc.
[0060] (Display section 12) Display unit 12 is a display device that displays various information such as position information. For example, display unit 12 is a liquid crystal display (LCD) or an organic electro-luminescent display (OLED). Display unit 12 is also a touch panel display, but is not limited to this.
[0061] (Input section 13) The input unit 13 is an input device that accepts various operations from the user U. For example, the input unit 13 has buttons for inputting characters, numbers, etc. The input unit 13 may be an input / output port (I / O port), a USB (Universal Serial Bus) port, etc. If the display unit 12 is a touch panel display, a part of the display unit 12 functions as the input unit 13. The input unit 13 may be a microphone that accepts voice input from the user U. The microphone may be wireless.
[0062] (Positioning unit 14) The positioning unit 14 receives signals (radio waves) transmitted from satellites of a GPS (Global Positioning System), and acquires position information (e.g., latitude and longitude) indicating the current position of the terminal device 10, which is the device itself, based on the received signals. That is, the positioning unit 14 positions the position of the terminal device 10. Note that GPS is merely an example of a GNSS (Global Navigation Satellite System).
[0063] The positioning unit 14 can also measure the position using various methods other than GPS. For example, the positioning unit 14 may measure the position by using various communication functions of the terminal device 10 as an auxiliary positioning means for position correction, etc., as described below.
[0064] (Wi-Fi positioning) For example, the positioning unit 14 uses a Wi-Fi (registered trademark) communication function of the terminal device 10 or a communication network provided by each communication company to measure the position of the terminal device 10. Specifically, the positioning unit 14 performs Wi-Fi communication or the like and measures the distance to a nearby base station or access point, thereby measuring the position of the terminal device 10.
[0065] (Beacon positioning) The positioning unit 14 may also measure the position by using a Bluetooth (registered trademark) function of the terminal device 10. For example, the positioning unit 14 measures the position of the terminal device 10 by connecting to a beacon transmitter connected by the Bluetooth (registered trademark) function.
[0066] (geomagnetic positioning) The positioning unit 14 also measures the position of the terminal device 10 based on a geomagnetic pattern of a structure that has been measured in advance and a geomagnetic sensor that the terminal device 10 has.
[0067] (RFID positioning) Furthermore, for example, if the terminal device 10 has a function of an RFID (Radio Frequency Identification) tag equivalent to a contactless IC card used at station ticket gates, in stores, etc., or has a function of reading an RFID tag, the location where the terminal device 10 was used is recorded together with information on the payment or the like made by the terminal device 10. The positioning unit 14 may obtain such information to determine the location of the terminal device 10. Alternatively, the location may be determined by an optical sensor, an infrared sensor, or the like provided in the terminal device 10.
[0068] The positioning unit 14 may measure the position of the terminal device 10 using one or a combination of the above-mentioned positioning means, as needed.
[0069] (Sensor unit 20) The sensor unit 20 includes various sensors mounted on or connected to the terminal device 10. The connection may be wired or wireless. For example, the sensors may be detection devices other than the terminal device 10, such as wearable devices or wireless devices. In the example shown in FIG. 5, the sensor unit 20 includes an acceleration sensor 21, a gyro sensor 22, a barometric pressure sensor 23, a temperature sensor 24, a sound sensor 25, a light sensor 26, a magnetic sensor 27, and an image sensor (camera) 28.
[0070] The above-described sensors 21 to 28 are merely examples and are not intended to be limiting. That is, the sensor unit 20 may be configured to include some of the sensors 21 to 28, or may include other sensors such as a humidity sensor in addition to or instead of the sensors 21 to 28.
[0071] The acceleration sensor 21 is, for example, a three-axis acceleration sensor, and detects physical movements of the terminal device 10, such as the direction of movement, speed, and acceleration of the terminal device 10. The gyro sensor 22 detects physical movements of the terminal device 10, such as tilt in three axial directions, based on the angular velocity of the terminal device 10. The air pressure sensor 23 detects, for example, the air pressure around the terminal device 10.
[0072] Since the terminal device 10 includes the acceleration sensor 21, the gyro sensor 22, the atmospheric pressure sensor 23, etc., it is possible to measure the position of the terminal device 10 using a technique such as Pedestrian Dead-Reckoning (PDR) that uses these sensors 21 to 23. This makes it possible to obtain indoor position information that is difficult to obtain using a positioning system such as GPS.
[0073] For example, the number of steps, walking speed, and distance walked can be calculated using a pedometer that uses the acceleration sensor 21. In addition, the direction of travel, line of sight, and body tilt of the user U can be determined using the gyro sensor 22. In addition, the altitude and floor on which the terminal device 10 of the user U is located can be determined from the air pressure detected by the air pressure sensor 23.
[0074] The temperature sensor 24 detects, for example, the temperature around the terminal device 10. The sound sensor 25 detects, for example, the sound around the terminal device 10. The light sensor 26 detects the illuminance around the terminal device 10. The magnetic sensor 27 detects, for example, the geomagnetism around the terminal device 10. The image sensor 28 captures an image around the terminal device 10.
[0075] The above-mentioned air pressure sensor 23, temperature sensor 24, sound sensor 25, light sensor 26, and image sensor 28 can detect the air pressure, temperature, sound, and illuminance, respectively, and capture images of the surroundings, thereby detecting the environment and situation around the terminal device 10. Furthermore, the accuracy of the location information of the terminal device 10 can be improved based on the environment and situation around the terminal device 10.
[0076] (control unit 30) The control unit 30 includes, for example, a microcomputer having a CPU (Central Processing Unit), ROM (Read Only Memory), RAM, input / output ports, etc., and various other circuits. The control unit 30 may also be configured with hardware such as an integrated circuit, for example, an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array). The control unit 30 includes a transmitting unit 31, a receiving unit 32, and a processing unit 33.
[0077] (Transmitter 31) The transmission unit 31 can transmit, for example, various information input by the user U using the input unit 13, various information detected by each sensor 21 to 28 mounted on or connected to the terminal device 10, and location information of the terminal device 10 measured by the positioning unit 14 to the server device 100 via the communication unit 11.
[0078] (Receiving unit 32) The receiving unit 32 can receive various types of information provided by the server device 100 and requests for various types of information from the server device 100 via the communication unit 11.
[0079] (Processing unit 33) The processing unit 33 controls the entire terminal device 10, including the display unit 12. For example, the processing unit 33 can output various information transmitted by the transmitting unit 31 and various information received from the server device 100 by the receiving unit 32 to the display unit 12 for display.
[0080] (Storage unit 40) The storage unit 40 is realized by, for example, a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as an HDD (Hard Disk Drive), an SSD (Solid State Drive), an optical disk, etc. The storage unit 40 stores various programs, various data, etc.
[0081] Furthermore, information (data) relating to individual users or link information to external devices is stored in the secure area (secure element) of the storage unit 40. For example, the link information to external devices may indicate a storage location of the information (data) relating to individual users stored in the external device. Furthermore, the link information to external devices may be ledger information in blockchain technology (distributed ledger technology). Note that if the link information to external devices is unrelated to the information (data) relating to individual users, the link information to external devices may be stored in the normal area of the storage unit 40. Furthermore, even if the information (data) relating to individual users is stored after encryption or the like using a dedicated app, it may be stored in the normal area.
[0082] [4. Server device configuration example] Next, the configuration of the server device 100 according to the embodiment will be described with reference to Fig. 6. Fig. 6 is a diagram showing an example of the configuration of the server device 100 according to the embodiment. As shown in Fig. 6, the server device 100 includes a communication unit 110, a storage unit 120, and a control unit 130.
[0083] (Communication unit 110) The communication unit 110 is realized by, for example, a network interface card (NIC), etc. The communication unit 110 is also connected to a network N (see FIG. 4) by wire or wirelessly.
[0084] (Storage unit 120) The storage unit 120 is realized by, for example, a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as an HDD, an SSD, an optical disk, etc. As shown in FIG. 6 , the storage unit 120 has a meta information database 121 and a history information database 122.
[0085] (Metadata Database 121) The meta information database 121 stores user information about the user U. For example, the meta information database 121 stores various information such as the attributes of the user U. FIG. 7 is a diagram showing an example of the meta information database 121. In the example shown in FIG. 7, the meta information database 121 has items such as "user ID (identifier)," "data capsule ID," "data type," "storage location," "management software," and "access method."
[0086] The "user ID" indicates identification information for identifying the user U. The "user ID" may be the contact information of the user U (telephone number, email address, etc.), or may be identification information for identifying the terminal device 10 of the user U.
[0087] Furthermore, "data capsule ID" indicates identification information for identifying a data capsule containing meta-information about information (data) related to the individual user. Furthermore, "data type" indicates the type (category) of information related to the individual user. Furthermore, "storage location" indicates the storage location of information related to the individual user. Furthermore, "management software" indicates management software for information related to the individual user. For example, management software indicates a dedicated application for managing information related to the individual user. Furthermore, "access method" indicates the method for accessing information related to the individual user.
[0088] For example, in the example shown in Figure 7, a data capsule containing meta information (data) related to personal information of user U, identified by user ID "U1", is identified by data capsule ID "DC#1" and includes the data type "address", storage location "terminal device" (user device), management software "app", and access method "authentication".
[0089] 7, abstract values such as "U1" and "DC#1" are used for illustration, but "U1" and "DC#1" are assumed to store information such as specific character strings and numerical values. Below, abstract values may also be illustrated in diagrams relating to other information.
[0090] The meta-information database 121 may store various types of information depending on the purpose, without being limited to the above. For example, the meta-information database 121 may store a public key for performing signature verification on information signed with a private key. The meta-information database 121 may also store information on groups that share information with the user U and other users U. For example, the meta-information database 121 may store a user ID in association with identification information for identifying a group or identification information for identifying other users U.
[0091] (History Information Database 122) The history information database 122 stores various information related to history information (log data) that indicates the behavior of the user U. Fig. 8 is a diagram showing an example of the history information database 122. In the example shown in Fig. 8, the history information database 122 has items such as "user ID," "location history," "search history," "browsing history," "purchase history," and "posting history."
[0092] "User ID" indicates identification information for identifying user U. "Location history" indicates the location history, which is the history of user U's location and movements. "Search history" indicates the search history, which is the history of search queries entered by user U. "Browsing history" indicates the browsing history, which is the history of content viewed by user U. "Purchase history" indicates the purchase history, which is the history of purchases made by user U. "Posting history" indicates the posting history, which is the history of posts made by user U. "Posting history" may also include questions about user U's possessions.
[0093] For example, in the example shown in Figure 8, user U, identified by user ID "U1," moved as shown in "Location History #1," searched as shown in "Search History #1," viewed content as shown in "Viewing History #1," purchased specific products at specific stores as shown in "Purchase History #1," and posted as shown in "Posting History #1."
[0094] Here, in the example shown in Figure 8, abstract values such as "U1", "Location History #1", "Search History #1", "Browsing History #1", "Purchase History #1", and "Post History #1" are used for the illustration, but "U1", "Location History #1", "Search History #1", "Browsing History #1", "Purchase History #1", and "Post History #1" are assumed to store specific information such as character strings and numbers.
[0095] The history information database 122 may store various types of information depending on the purpose, without being limited to the above. For example, the history information database 122 may store a usage history of information (data) about individual users. In this case, the history information database 122 may store the usage history of information (data) about individual users in addition to the history information indicating the behavior of the user U. The history information database 122 may also store a usage history of a predetermined service by the user U. The history information database 122 may also store history information indicating in which service the information (data) about individual users was used. The history information database 122 may also store a store visit history or facility visit history of the user U. The history information database 122 may also store a payment history of payments (electronic payments) made using the terminal device 10 of the user U.
[0096] (control unit 130) 6, the explanation will be continued. The control unit 130 is a controller, and is realized by, for example, a CPU (Central Processing Unit), an MPU (Micro Processing Unit), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or the like, executing various programs (corresponding to an example of an information processing program) stored in a storage device inside the server device 100 using a storage area such as a RAM as a working area. In the example shown in FIG. 6, the control unit 130 has a receiving unit 131, a creating unit 132, a managing unit 133, a requesting unit 134, an acquiring unit 135, and a data processing unit 136.
[0097] (Reception Department 131) The reception unit 131 receives an information registration request from the user U. At this time, the reception unit 131 receives the ID of the user U and the type of data when the information registration request is made from the user U. The reception unit 131 also receives a data usage request from the user U. At this time, the reception unit 131 may receive a data capsule ID indicating the data capsule when the data usage request is made from the user U.
[0098] (Creation Department 132) The creation unit 132 creates a data capsule for data securely stored in the terminal device 10 of the user U by linking meta information of the data with the ID of the user U. For example, the creation unit 132 creates a data capsule by linking meta information including the type of data with the ID of the user U. For example, the data capsule includes the type of data, the storage location, and the access method. After creating the data capsule, the creation unit 132 may return a response to the registration request (indicating that registration is complete) to the user U.
[0099] (Management Department 133) The management unit 133 stores the data capsule. After the data has been used, the management unit 133 does not store the data, but stores the usage history of the data. However, the management unit 133 may also store the data if the user U permits or allows the storage of the data.
[0100] (Request part 134) In response to a data usage request, the request unit 134 transmits a data capsule to the terminal device 10 of the user U. For example, the request unit 134 transmits the data capsule to the terminal device 10 of the user U and requests authentication of the user U and approval to use the data. At this time, when the request unit 134 receives a data capsule ID indicating the data capsule, the request unit 134 may transmit the data capsule corresponding to the data capsule ID to the terminal device 10 of the user U.
[0101] (Acquisition part 135) The acquisition unit 135 acquires data securely stored in the terminal device 10 of the user U from the terminal device 10 of the user U. For example, the acquisition unit 135 acquires data from the terminal device 10 of the user U after the terminal device 10 of the user U has successfully authenticated the user U and approved the use of the data. For example, the data includes information about the user U personally or link information to an external device.
[0102] At this time, the acquisition unit 135 acquires the data from the terminal device 10 of the user U in response to transmission of a data capsule including meta-information of the data.
[0103] (Data processing unit 136) The data processing unit 136 uses the data acquired from the terminal device 10 of the user U. After using the data, the data processing unit 136 discards the data without storing it. However, if the user U permits or allows the data to be stored, the data processing unit 136 does not have to discard the data.
[0104] The data processing unit 136 can also use data that is securely stored in the terminal device 10 of another user U. For example, the reception unit 131 receives a request from the user U to use data that is securely stored in the terminal device 10 of the other user U. In response to the request to use the data from the user U, the request unit 134 transmits a data capsule corresponding to the data to the terminal device 10 of the other user U. In response to the transmission of the data capsule, the acquisition unit 135 acquires the data from the terminal device 10 of the other user U.
[0105] [5. Processing Procedure] Next, a processing procedure by the server device 100 according to the embodiment will be described with reference to Fig. 9. Fig. 9 is a flowchart showing the processing procedure according to the embodiment. Note that the processing procedure shown below is repeatedly executed by the control unit 130 of the server device 100.
[0106] 9, the reception unit 131 of the server device 100 receives an information registration request from a user U (step S101). At this time, the reception unit 131 receives the ID of the user U and the type of data when the information registration request is received from the user U.
[0107] Next, the creation unit 132 of the server device 100 creates a data capsule for the data securely stored in the terminal device 10 of the user U by linking the meta information of the data with the ID of the user U (step S102). For example, the creation unit 132 creates a data capsule by linking meta information including the type of data with the ID of the user U. For example, the data capsule includes the type of data, the storage location, and the access method.
[0108] Next, the management unit 133 of the server device 100 stores the data capsule (step S103).
[0109] Next, the receiving unit 131 of the server device 100 receives a data usage request from the user U (step S104). At this time, the receiving unit 131 may receive a data capsule ID indicating the data capsule when the data usage request is received from the user U.
[0110] Next, the request unit 134 of the server device 100 transmits the data capsule to the terminal device 10 of the user U in response to the data usage request (step S105). For example, the request unit 134 transmits the data capsule to the terminal device 10 of the user U and requests authentication of the user U and approval to use the data. At this time, when the request unit 134 receives a data capsule ID indicating the data capsule, it may extract and transmit the data capsule corresponding to the data capsule ID.
[0111] Next, the acquisition unit 135 of the server device 100 acquires the data securely stored in the terminal device 10 of the user U in response to transmission of the data capsule including the meta-information of the data from the terminal device 10 of the user U (step S106). For example, the acquisition unit 135 acquires the data from the terminal device 10 of the user U after the terminal device 10 of the user U has successfully authenticated the user U and approved the use of the data. For example, the data includes information about the individual user U or link information to an external device.
[0112] Next, the data processing unit 136 of the server device 100 uses the data acquired from the terminal device 10 of the user U (step S107).
[0113] Next, the data processing unit 136 of the server device 100 discards the data after using it without storing it (step S108). However, if the user U has permitted or allowed the data to be stored, the data processing unit 136 does not have to discard the data. In other words, if the user U has permitted or allowed the data to be stored, the processing of step S108 does not have to be performed.
[0114] Next, the management unit 133 of the server device 100 does not store the data after the data has been used, but stores the usage history of the data (step S109). However, the management unit 133 may also store the data if the user U permits or allows the storage of the data.
[0115] [6. Modifications] The terminal device 10 and the server device 100 described above may be implemented in various different forms other than the above embodiment. Therefore, modifications of the embodiment will be described below.
[0116] In the above embodiment, some or all of the processing executed by the server device 100 may actually be executed by the terminal device 10. For example, the processing may be completed in a stand-alone manner (by the terminal device 10 alone). In this case, the terminal device 10 is assumed to have the functions of the server device 100 in the above embodiment. Furthermore, in the above embodiment, the terminal device 10 is linked to the server device 100, and therefore, from the perspective of the user U, it appears that the processing of the server device 100 is also being executed by the terminal device 10. In other words, from another perspective, the terminal device 10 can also be said to be equipped with the server device 100.
[0117] In the above embodiment, the information registration shown in Fig. 2 may be performed during the FIDO registration process. For example, the user U may use the terminal device 10 to register an ID (user ID) and a data type (data classification) to the server device 100 together with (or immediately after) registering public key information in the FIDO registration process.
[0118] Furthermore, in the above embodiment, when using information as shown in FIG. 3, FIDO authentication may be combined. For example, in step S12 of FIG. 3, the server device 100 may transmit a challenge to the terminal device 10 along with the data capsule. The challenge is a random character string that is valid only once and is a data string that is different each time based on random numbers. The user performs user verification using the terminal device 10 (authenticator) to locally verify the identity of the user. Then, the terminal device 10 (authenticator) signs information (data) related to the individual user as a verification result together with the challenge using a private key, and transmits the signed data to the server device 100. Upon receiving the signed data, the server device 100 verifies the signature using a public key.
[0119] [7. Effects] As described above, the information processing device of the present application includes a creation unit 132 that creates a data capsule by linking meta information of data securely stored in user U's terminal device 10 with user U's ID, a management unit 133 that stores the data capsule, a reception unit 131 that receives a data usage request from user U, a request unit 134 that transmits the data capsule to user U's terminal device 10 in response to the data usage request, and an acquisition unit 135 that acquires data from user U's terminal device 10 in response to the transmission of the data capsule.
[0120] The request unit 134 transmits the data capsule to the terminal device 10 of the user U and requests authentication and data use approval of the user U. The acquisition unit 135 acquires the data from the terminal device 10 of the user U after the terminal device 10 of the user U has successfully authenticated the user U and approved the data use.
[0121] The information processing device according to the present application further includes a data processing unit 136 that uses data acquired from the terminal device 10 of the user U. The management unit 133 does not store data, but stores the usage history of the data.
[0122] After using the data, the data processing unit 136 discards it without storing it.
[0123] The receiving unit 131 receives a data capsule ID indicating a data capsule when a data usage request is made by the user U. The request unit 134 extracts and transmits the data capsule corresponding to the data capsule ID.
[0124] The receiving unit 131 receives the ID of the user U and the type of data when an information registration request is made from the user U. The creating unit 132 creates a data capsule by linking meta information including the type of data with the ID of the user U.
[0125] The data capsule includes the type of data, the storage location, and the access method.
[0126] The data includes information about the individual user U or link information to an external device.
[0127] The reception unit 131 receives a request from a user U to use data that is securely stored in the terminal device 10 of another user U. In response to the request to use the data from the user U, the request unit 134 transmits a data capsule corresponding to the data to the terminal device 10 of the other user U. In response to the transmission of the data capsule, the acquisition unit 135 acquires the data from the terminal device 10 of the other user U.
[0128] By performing any one or a combination of the above-described processes, the information processing device according to the present application can further improve the security of providing and storing personal privacy information.
[0129] [8. Hardware Configuration] The terminal device 10 and the server device 100 according to the above-described embodiments are realized by a computer 1000 having a configuration as shown in Fig. 10, for example. The following description will be given taking the server device 100 as an example. Fig. 10 is a diagram showing an example of a hardware configuration. The computer 1000 is connected to an output device 1010 and an input device 1020, and has a configuration in which a calculation device 1030, a primary storage device 1040, a secondary storage device 1050, an output I / F (Interface) 1060, an input I / F 1070, and a network I / F 1080 are connected via a bus 1090.
[0130] The arithmetic device 1030 operates based on programs stored in the primary storage device 1040 and the secondary storage device 1050, programs read from the input device 1020, and the like, and executes various processes. The arithmetic device 1030 is realized by, for example, a CPU (Central Processing Unit), an MPU (Micro Processing Unit), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or the like.
[0131] The primary storage device 1040 is a memory device such as a RAM (Random Access Memory) that temporarily stores data used by the arithmetic device 1030 for various calculations. The secondary storage device 1050 is a storage device in which data used by the arithmetic device 1030 for various calculations and various databases are registered, and is realized by a ROM (Read Only Memory), an HDD (Hard Disk Drive), an SSD (Solid State Drive), a flash memory, or the like. The secondary storage device 1050 may be an internal storage device or an external storage device. The secondary storage device 1050 may also be a removable storage medium such as a USB (Universal Serial Bus) memory or an SD (Secure Digital) memory card. The secondary storage device 1050 may also be cloud storage (online storage), a NAS (Network Attached Storage), a file server, or the like.
[0132] The output I / F 1060 is an interface for transmitting information to be output to an output device 1010 that outputs various types of information, such as a display, a projector, a printer, etc., and is realized by a connector conforming to a standard such as USB (Universal Serial Bus), DVI (Digital Visual Interface), or HDMI (High Definition Multimedia Interface), etc. The input I / F 1070 is an interface for receiving information from various input devices 1020, such as a mouse, a keyboard, a keypad, a button, a scanner, etc., and is realized by a USB, etc.
[0133] Furthermore, the output I / F 1060 and the input I / F 1070 may be wirelessly connected to the output device 1010 and the input device 1020, respectively. That is, the output device 1010 and the input device 1020 may be wireless devices.
[0134] The output device 1010 and the input device 1020 may be integrated into one device, such as a touch panel. In this case, the output I / F 1060 and the input I / F 1070 may also be integrated into one device as an input / output I / F.
[0135] The input device 1020 may be a device that reads information from, for example, an optical recording medium such as a CD (Compact Disc), a DVD (Digital Versatile Disc), or a PD (Phase Change Rewritable Disk), a magneto-optical recording medium such as an MO (Magneto-Optical disk), a tape medium, a magnetic recording medium, or a semiconductor memory.
[0136] The network I / F 1080 receives data from other devices via the network N and sends it to the arithmetic device 1030, and also transmits data generated by the arithmetic device 1030 to other devices via the network N.
[0137] The arithmetic unit 1030 controls the output device 1010 and the input device 1020 via the output I / F 1060 and the input I / F 1070. For example, the arithmetic unit 1030 loads a program from the input device 1020 or the secondary storage device 1050 onto the primary storage device 1040 and executes the loaded program.
[0138] For example, when the computer 1000 functions as the server device 100, the arithmetic unit 1030 of the computer 1000 executes a program loaded onto the primary storage device 1040 to realize the functions of the control unit 130. The arithmetic unit 1030 of the computer 1000 may also load a program acquired from another device via the network I / F 1080 onto the primary storage device 1040 and execute the loaded program. The arithmetic unit 1030 of the computer 1000 may also cooperate with the other device via the network I / F 1080 to call and use the functions and data of a program from another program of the other device.
[0139] [9. Other] Although the embodiments of the present application have been described above, the present invention is not limited to the contents of these embodiments. Furthermore, the above-described components include those that can be easily imagined by a person skilled in the art, those that are substantially the same, and those that are within the scope of so-called equivalents. Furthermore, the above-described components can be combined as appropriate. Furthermore, various omissions, substitutions, or modifications of the components can be made without departing from the spirit of the above-described embodiments.
[0140] Furthermore, among the processes described in the above embodiments, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically using a known method. In addition, the information including the processing procedures, specific names, various data, and parameters shown in the above documents and drawings can be changed as desired unless otherwise specified. For example, the various information shown in each drawing is not limited to the information shown in the drawings.
[0141] Furthermore, the components of each device shown in the figure are conceptual functional components and do not necessarily have to be physically configured as shown in the figure. In other words, the specific form of distribution and integration of each device is not limited to that shown in the figure, and all or part of them can be functionally or physically distributed and integrated in any unit depending on various loads, usage conditions, etc.
[0142] For example, the above-mentioned server device 100 may be realized by multiple server computers, and depending on the function, the configuration can be flexibly changed, such as by calling an external platform using an API (Application Programming Interface) or network computing.
[0143] Furthermore, the above-described embodiments and modifications can be combined as appropriate within the scope of not causing any contradiction in the processing content.
[0144] Furthermore, the above-mentioned "section, module, unit" can be read as "means" or "circuit," etc. For example, an acquisition unit can be read as an acquisition means or an acquisition circuit. [Explanation of symbols]
[0145] 1. Information Processing Systems 10 Terminal Equipment 100 Server device 110 Communications Department 120 Storage section 121 Metadata Database 122 Historical Information Database 130 Control Unit 131 Reception 132 Creation Department 133 Management Department 134 Request part 135 Acquisition Department 136 Data Processing Unit
Claims
1. a creation unit that creates a data capsule by linking meta information of data securely stored in a user's terminal device with the user's ID; a management unit that stores the data capsule; a reception unit that receives an information use request from the user; a request unit that transmits the data capsule to the user's terminal device in response to an information utilization request; an acquisition unit that acquires the data from the user's terminal device in response to transmission of the data capsule; An information processing device comprising:
2. the request unit transmits the data capsule to the user's terminal device and requests authentication of the user and approval for data use; The acquisition unit acquires the data from the terminal device of the user after the user has been successfully authenticated and approved for use of the data in the terminal device of the user.
2. The information processing apparatus according to claim 1, wherein:
3. a data processing unit that uses the data acquired from the user's terminal device, The management unit does not store the data, but stores the usage history of the data.
2. The information processing apparatus according to claim 1, wherein:
4. The data processing unit discards the data after using it without storing it.
4. The information processing apparatus according to claim 3,
5. the receiving unit receives a data capsule ID indicating the data capsule when the user makes an information use request; The request unit extracts and transmits the data capsule corresponding to the data capsule ID.
2. The information processing apparatus according to claim 1, wherein:
6. the receiving unit receives an ID of the user and a type of the data when an information registration request is made from the user, The creation unit creates a data capsule by linking meta information including the type of data with the user ID.
2. The information processing apparatus according to claim 1, wherein:
7. The data capsule includes the type of data, a storage location, and an access method.
2. The information processing apparatus according to claim 1, wherein:
8. The data includes information about the user or a link to an external device.
2. The information processing apparatus according to claim 1, wherein:
9. the receiving unit receives, from the user, a request to use data securely stored in a terminal device of another user; the request unit transmits a data capsule corresponding to the data to the terminal device of the other user in response to a request for use of the data from the other user; The acquisition unit acquires the data from the terminal device of the other user in response to transmission of the data capsule.
2. The information processing apparatus according to claim 1, wherein:
10. An information processing method executed by an information processing device, a creation step of creating a data capsule by linking meta information of data securely stored in a user's terminal device with the user's ID; a management step of storing the data capsule; a receiving step of receiving an information use request from the user; a request step of transmitting the data capsule to the user's terminal device in response to an information utilization request; an acquisition step of acquiring the data from the user's terminal device in response to transmission of the data capsule; An information processing method comprising:
11. a creation procedure for creating a data capsule by linking meta information of data securely stored in a user's terminal device with the user's ID; a management procedure for storing the data capsule; a receiving procedure for receiving an information use request from the user; a request procedure for transmitting the data capsule to the user's terminal device in response to an information utilization request; an acquisition step of acquiring the data from the user's terminal device in response to transmission of the data capsule; An information processing program characterized by causing a computer to execute the above.
Citation Information
Patent Citations
Data sharing system
JP2003085022A
Electronic device, method for indexing resources on an electronic device using an indexing agent residing on the device, system for indexing resources available on a network, available on a number of network connectable electronic devices Method of indexing resources, method of indexing resources on an electronic device having a resident indexing agent
JP2006502461A
Matching system and personal information management device
JP2009238067A
Personal information providing device and personal information providing method
JP2013020643A
Management device, data providing device, computer program, management method and data providing method
JP2020112993A