Personal information sharing platform service provision system based on the right to transfer personal information
The platform service system addresses privacy and profit distribution issues by obtaining user consent, using sunset-type security numbers and a zero-trust model to securely share personal information while ensuring fair profit sharing.
Patent Information
- Application Number
- JP2024547727
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2023-01-16
- Filing Date
- 2023-10-06
- Publication Date
- 2026-01-07
- Estimated Expiration
- 2043-10-06
AI Technical Summary
Existing personal information sharing systems fail to effectively protect sensitive data while allowing data portability, leading to privacy violations, monopolies, and unfair profit distribution, particularly for small and medium-sized enterprises.
A platform service system that obtains user consent, constructs a database, limits information use periods with sunset-type security numbers, and ensures transparent profit sharing, using a zero-trust model for secure data handling.
Ensures secure and transparent sharing of personal information with sunset-type security measures, protecting user privacy and promoting fair profit distribution among data providers.
Smart Images

Figure 0007795236000004 
Figure 0007795236000005 
Figure 0007795236000006
Abstract
Description
[Technical Field]
[0001] The present invention relates to a personal information sharing platform service providing system based on the right to transfer personal information, and provides a platform that obtains consent to the provision of personal information for the use of personal information, shares personal information and distributes profits, and sets a limit on the period of information use with a secure number sunset type, while eliminating exposure to sensitive information. [Background technology]
[0002] The right to data portability is the right of data subjects to request the transfer or transmission of their information and to allow personal information controllers to use the information they are processing. The right to data portability strengthens data subjects' control over their personal information, guarantees their right to select services, and grants data subjects the right to use the information they have collected and managed by personal information controllers. It expands and strengthens the traditional right to request access to and copies of personal information. In Korea, the right to data portability is widely recognized as a means to promote the distribution and utilization of personal information, and legislative discussion has focused primarily on the utilization of personal information rather than the strengthening of data subjects' rights. In particular, since the right to data portability has come to be confused with the term "my data," it has been used as a basis for the distribution and sharing of personal information.
[0003] At this time, methods have been researched and developed for distributing profits to individuals when generating profits by sharing personal information. In this regard, prior art Korean Patent Publication No. 2022-0073899 (published on June 3, 2022) and Korean Patent Publication No. 2017-0045786 (published on April 28, 2017) disclose a configuration in which medical data is collected with the consent of the user of the user's device, then generated as personal data in the medical field through text mining and encryption, and metadata is separated from the personal data, which is then managed in a bifurcated manner and medical information is utilized using the metadata; and a configuration in which personal information data is separated into metadata and personal data, and when shared, personal data is converted into shared data and sold, providing an intermediary platform.
[0004] However, in the former and latter cases, personal information classified as Grade 1 information under the Personal Information Protection Act is simply removed and shared as big data or personal data, rather than providing the Grade 1 personal information most needed by actual information users. The right to information portability requires careful design due to the high risk of violating the privacy of data subjects and the potential for infringement of personal information property rights of personal information processors. Therefore, data mining businesses provide personal information after it has been completely deleted, de-identified, or anonymized. However, this would significantly reduce the value of the personal information. The right to information portability could further exacerbate the serious problem of the concentration and monopoly of personal information, lead to the indiscriminate transfer of public information overseas, and require data subjects to bear the transfer costs, resulting in the profits of large platform companies. Meanwhile, it could further exacerbate the personal information starvation problem for small and medium-sized enterprises. Therefore, research and development of a personal information sharing platform that can share personal information while protecting it is essential. Summary of the Invention [Problem to be solved by the invention]
[0005] In one embodiment of the present invention, a system for providing a personal information sharing platform service based on the right to transfer personal information may be provided, which may include obtaining consent for the provision of personal information from a user's device to use the user's personal information, constructing a database, enabling necessary items to be referenced on the requester's device, and displaying information such as the purpose of collecting and using the personal information, the items of personal information to be collected, and the retention and use period of the personal information when uploading a request post on the requester's device, limiting the information use period for telephone numbers among the personal information using a sunset type and providing a security number to the requester's device, thereby limiting the period without specifying the telephone number by providing a sunset type security number, and allowing the user's device to check the remainder of the generated profits, excluding taxes and fees, in a history log on the user's device when the requester's device wins an auction. However, the technical problems to be solved by this embodiment are not limited to those described above, and other technical problems may exist. [Means for solving the problem]
[0006] As a technical means for achieving the above-mentioned technical object, one embodiment of the present invention includes a platform service providing server including: a user terminal that agrees to provide personal information for personal information use, inputs at least one type of personal information for personal information use, and sets a price for the at least one type of personal information; a requester terminal that requests personal information for the user terminal and views personal information of preset items included in the personal information within a preset information use period; and a consent storage unit that obtains consent to providing personal information for personal information use from the user terminal; a database unit that receives and stores at least one piece of personal information input from the user terminal; an auction unit that sets a price for using at least one piece of personal information when at least one piece of personal information is requested from the requester terminal; and a period limiting unit that specifies an information use period, which is a viewing limit, for personal information of preset items among the at least one piece of personal information when the requester terminal wins the bid. [Effects of the Invention]
[0007] According to any one of the above-mentioned means for solving the problems of the present invention, a database is constructed by obtaining consent for the provision of personal information from the user's terminal for the use of the user's personal information, and the required items can be referenced on the requester's terminal. After that, when uploading a request post on the requester's terminal, information such as the purpose of collecting and using the personal information, the items of personal information to be collected, and the period of retention and use of the personal information is displayed and made clear. For the telephone number among the personal information, a sunset type information use period is limited on the requester's terminal, and a secure number is provided. By providing a sunset type secure number, a period can be limited without specifying the telephone number. If revenue is generated as a result of a successful bid on the requester's terminal, the remainder of the generated revenue, excluding taxes and fees, can be checked in the history log on the user's terminal. [Brief explanation of the drawings]
[0008] [Figure 1] 1 is a diagram illustrating a system for providing a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention. [Figure 2] 2 is a block diagram illustrating a platform service providing server included in the system of FIG. 1. FIG. [Figure 3] 1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 4] 1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 5] 1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 6] 1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 7]1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 8] 1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 9] 1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 10] 1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 11] 1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 12] 1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 13] 1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 14] 1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 15] 1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 16] 1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 17] 1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 18]1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 19] 1 is a diagram illustrating an embodiment of a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention; [Figure 20] 1 is an operational flowchart illustrating a method for providing a personal information sharing platform service based on a personal information transfer right according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0009] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings so that those skilled in the art can easily carry out the present invention. However, the present invention may be embodied in various different forms and is not limited to the embodiments described herein. In order to clearly explain the present invention in the drawings, parts that are not relevant to the description are omitted, and similar parts are designated by similar reference numerals throughout the specification. Throughout the specification, when a part is referred to as being "connected" to another part, this includes not only "directly connected" but also "electrically connected" with another element interposed therebetween. Furthermore, when a part is referred to as "comprising" a certain component, this does not mean excluding other components, but may further include other components, unless otherwise specified, and is understood not to preclude the possibility of the presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof. The terms "about," "substantially," and the like used throughout the specification are used to mean a numerical value or a close approximation of a numerical value when manufacturing and material tolerances inherent in the stated meaning are given, and are used to prevent unscrupulous infringers from unfairly exploiting the disclosure in which precise or absolute numerical values are recited to aid in the understanding of the present invention. The terms "steps of" or "steps of" used throughout the specification of the present invention do not mean "steps for."
[0010] As used herein, the term "module" includes hardware-implemented units, software-implemented units, and units implemented using both hardware and software. Also, one unit may be implemented using two or more pieces of hardware, or two or more units may be implemented by a single piece of hardware. Meanwhile, the term "module" is not limited to software or hardware; it may be configured to reside on an addressable storage medium or to execute one or more processors. Thus, by way of example, "module" includes components such as software components, object-oriented software components, class components, and task components, as well as processes, functions, attributes, procedures, subroutines, program code segments, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functionality provided within a component and a module may be combined into fewer components and modules or further separated into additional components and modules. Furthermore, a component and a module may be embodied to execute one or more CPUs within a device or security multimedia card. Some of the operations and functions described herein as being performed by a terminal, apparatus, or device may instead be performed by a server connected to the terminal, apparatus, or device. Similarly, some of the operations and functions described herein as being performed by a server may instead be performed by a terminal, apparatus, or device connected to the server.
[0011] In this specification, some of the operations or functions described as mapping or matching with a terminal may be interpreted as mapping or matching a terminal's unique number or personal identification information, which is identifying data of the terminal.
[0012] The present invention will now be described in detail with reference to the accompanying drawings.
[0013] Figure 1 is a diagram illustrating a system for providing a platform service for sharing personal information based on the right to transfer personal information according to one embodiment of the present invention. Referring to Figure 1, the system 1 for providing a platform service for sharing personal information based on the right to transfer personal information may include at least one user terminal 100, a platform service providing server 300, and at least one requester terminal 400. However, the system 1 for providing a platform service for sharing personal information based on the right to transfer personal information shown in Figure 1 is merely one embodiment of the present invention, and the present invention should not be construed as being limited by Figure 1.
[0014] 1 are generally connected via a network 200. For example, as shown in FIG. 1, at least one user terminal 100 may be connected to a platform service providing server 300 via the network 200. The platform service providing server 300 may be connected to at least one user terminal 100 and at least one requester terminal 400 via the network 200. The at least one requester terminal 400 may be connected to the platform service providing server 300 via the network 200.
[0015] Here, a network refers to a connected structure that allows information exchange between multiple nodes such as terminals and servers. Examples of such networks include local area networks (LANs), wide area networks (WANs), the Internet (WWW), wired / wireless data communication networks, telephone networks, and wired / wireless television communication networks. Examples of wireless data communication networks include, but are not limited to, 3G, 4G, 5G, 3GPP (registered trademark) (3rd Generation Partnership Project), 5GPP (5th Generation Partnership Project), LTE (Long Term Evolution), WIMAX (World Interoperability for Microwave Access), Wi-Fi, the Internet, LAN (Local Area Network), Wireless LAN (Wireless Local Area Network), WAN (Wide Area Network), PAN (Personal Area Network), RF (Radio Frequency), Bluetooth (registered trademark) network, NFC (Near-Field Communication) network, satellite broadcasting network, analog broadcasting network, DMB (Digital Multimedia Broadcasting) network, etc.
[0016] In the following, the term "at least one" is defined as a term including both singular and plural, and it is clear that even if the term "at least one" is not present, each component can exist in singular or plural and can mean singular or plural. Furthermore, it can be said that whether each component is provided in singular or plural can be changed depending on the embodiment.
[0017] At least one user terminal 100 may be a terminal of a user who agrees to provide personal information and uploads personal information for use by using a web page, app page, program, or application related to the personal information sharing platform service based on the right to transfer personal information. The user terminal 100 may also be a terminal that receives a share of profits obtained by utilizing personal information from the platform service providing server 300.
[0018] Here, at least one user terminal 100 may be implemented as a computer that can connect to a remote server or terminal through a network. Here, the computer may include, for example, a notebook computer, desktop computer, laptop computer, etc. that is equipped with a navigation system or a web browser. At this time, at least one user terminal 100 may be implemented as a terminal that can connect to a remote server or terminal through a network. At least one user terminal 100 may be, for example, a wireless communication device that ensures portability and mobility, and may include all kinds of handheld-based wireless communication devices such as navigation, PCS (Personal Communication System), GSM (Global System for Mobile communications), PDC (Personal Digital Cellular), PHS (Personal Handyphone System), PDA (Personal Digital Assistant), IMT (International Mobile Telecommunication)-2000, CDMA (Code Division Multiple Access)-2000, W-CDMA (W-Code Division Multiple Access), Wibro (Wireless Broadband Internet) terminals, smartphones, smartpads, tablet PCs, etc.
[0019] The platform service providing server 300 may be a server that provides a web page, app page, program, or application for a personal information sharing platform service based on the right to transfer personal information. The platform service providing server 300 may be a server that obtains consent to the provision of personal information for the use of personal information from at least one user terminal 100 and constructs a database by receiving input of at least one type of personal information for the use of personal information. The platform service providing server 300 may be a server that enables the requester terminal 400 to search for personal information meeting desired conditions, allows the requester terminal 400 to upload a request post specifying the purpose, scope, use, and period of use for the personal information, and sets a price for the use of the personal information. In this case, the platform service providing server 300 may be a server that provides personal information to the requester terminal 400 if a bid is won. The platform service providing server 300 may be a server that settles the remainder of the profits generated in the auction, minus taxes and fees, to the user terminal 100. In addition, the platform service providing server 300 may be a server that applies a secure number to the phone number among personal information and provides the information in a sunset type to limit the period of use of the information, and may be a server that provides rewards such as points only after entering proof that advertisements etc. of the requester terminal 400 have been opened when they are sent by email or mail to prevent abusing of the user terminal 100.
[0020] Here, the platform service providing server 300 may be implemented as a computer that can connect to a remote server or terminal through a network. Here, the computer may include, for example, a notebook computer, desktop computer, laptop computer, etc. equipped with a navigation system and a web browser.
[0021] At least one requester terminal 400 may be a terminal of an individual or a company who wishes to use personal information by using a web page, app page, program, or application related to the personal information sharing platform service based on the right to transfer personal information. The requester terminal 400 may be a terminal that searches whether the desired target information exists, and if successful, pays the winning bid and uses the personal information.
[0022] Here, at least one requester terminal 400 may be implemented as a computer that can connect to a remote server or terminal through a network. Here, the computer may include, for example, a notebook computer, desktop computer, laptop computer, etc. that is equipped with a navigation system or a web browser. At this time, at least one requester terminal 400 may be implemented as a terminal that can connect to a remote server or terminal through a network. At least one requester terminal 400 may be, for example, a wireless communication device that ensures portability and mobility, and may include all kinds of handheld-based wireless communication devices such as navigation, PCS (Personal Communication System), GSM (Global System for Mobile communications), PDC (Personal Digital Cellular), PHS (Personal Handyphone System), PDA (Personal Digital Assistant), IMT (International Mobile Telecommunication)-2000, CDMA (Code Division Multiple Access)-2000, W-CDMA (W-Code Division Multiple Access), Wibro (Wireless Broadband Internet) terminals, smartphones, smartpads, tablet PCs, etc.
[0023] Figure 2 is a block diagram illustrating a platform service providing server included in the system of Figure 1, and Figures 3 to 19 are diagrams illustrating an embodiment of a personal information sharing platform service based on personal information transfer rights in accordance with one embodiment of the present invention.
[0024] Referring to FIG. 2, the platform service providing server 300 may include a consent storage unit 310, a database creation unit 320, an auction unit 330, a time limit unit 340, a sunset number provision unit 350, an abuse prevention unit 360, a request posting management unit 370, an information provision unit 380, a receiving / sending indication unit 390, and a revenue status unit 391.
[0025] When the platform service providing server 300 according to an embodiment of the present invention or another server (not shown) operating in conjunction therewith transmits a personal information sharing platform service application, program, application page, web page, etc. based on the right to transfer personal information to at least one user terminal 100, at least one requester terminal 400, and at least one information providing server 500, at least one user terminal 100 and at least one requester terminal 400 may install or open the personal information sharing platform service application, program, application page, web page, etc. based on the right to transfer personal information. Furthermore, the service program may be driven in at least one user terminal 100 and at least one requester terminal 400 using a script executed in a web browser. Here, the web browser refers to a program that enables the use of web (WWW) services and receives and displays hypertext written in HyperText Mark-up Language (HTML), and includes, for example, Netscape, Explorer, Chrome, etc. Furthermore, the application refers to an application on a terminal, and includes, for example, an app executed on a mobile terminal (smartphone).
[0026] Referring to FIG. 2, the consent storage unit 310 can obtain consent from the user terminal 100 to provide personal information for the use of the personal information. The user terminal 100 can consent to the provision of personal information for the use of the personal information, enter at least one type of personal information for the use of the personal information, and set a price. In one embodiment of the present invention, when a requester (information user) uses the personal information of a user (information provider), i.e., if the user's information provider is sorted as a condition of the requester, the methods by which the requester can contact the information provider are mainly a telephone number, email address, and address. In this case, a telephone number, especially a mobile phone number, is highly sensitive personal information, but it is also the most important and essential contact point from the perspective of an information user purchasing information. However, when the information provider's mobile phone information is transmitted to the information user, it may be exposed to the information user's misuse, various illegal distributions, and criminal use.
[0027] In such cases, a temporary number known as a secure number is often used. In one embodiment of the present invention, a secure number with a limited expiration date is provided to the information user instead of the information provider's telephone number, but a sunsetting secure number with a limited expiration date can be provided. Conventional secure numbers are generated by randomly combining numbers and then forwarded through matching with a specific number, which is primarily issued and used by users. In contrast, the platform of the present invention allows the platform operator to generate a number for the information provider's telephone number, set it to be provided and linked to the information user through matching only for a specific period, and automatically delete it when the preset information expiration date expires. In other words, the sunsetting secure number can be said to be a sunsetting temporary number that is temporarily provided to the information user without revealing the information provider. In addition to the Sunset Secure Number, there are also Sunset Secure Email and Sunset Secure Address. The Sunset Secure Email and Sunset Secure Address are similar to a DNS server that connects a domain and an IP address to a server. After the platform provides the Sunset Secure Email and Sunset Secure Address to the requester terminal 400, the email sent to the Sunset Secure Email is sent to the actual user's email address, and in the case of the Sunset Secure Address, it can be accepted by the post office after a bulk conversion process.
[0028] The database unit 320 may receive and store at least one piece of personal information input from the user terminal 100. In this case, a zero-trust model, i.e., a zero-trust model that does not trust anything, may be established for protecting personal information in the database, for administrators or staff who manage the platform according to an embodiment of the present invention.
[0029] <Zero Trust Model>
[0030] The zero trust model, which refers to perimeter-less security, aims to achieve information security in all situations by assuming that attackers exist not only on external networks but also on identified internal networks. Existing perimeter-based security models implement powerful firewalls and gateway detection, effectively blocking external attackers from accessing internal networks. However, external remote workers such as telecommuters and cloud-based services are relatively vulnerable and therefore insecure. The zero trust model trusts nothing and considers even users on the internal network to be potential intruders. It is a new security architecture that focuses on protecting data rather than protecting boundaries. When accessing data, it does not absolutely trust any user. Instead, it continuously verifies who the user is, what purpose they are using, and what data they are accessing. It grants users only the minimum necessary privileges, restricting unnecessary access to other data.
[0031] <Definition of Zero Trust Architecture>
[0032] NIST introduces zero trust as "Never Trust, Always Verify." This means that you should never trust anything and always verify. Based on this principle, zero trust is a new cybersecurity paradigm that prioritizes protecting organizational resources. Zero trust breaks away from the traditional security model, which focuses on monitoring the network perimeter, and instead focuses on the individual interactions between individuals (users, data, computing equipment, etc.), such as who is using a service and what data is being accessed. Therefore, the objects of protection in the zero trust model include remote users outside the organization's network perimeter and personally owned PCs and mobile devices that are not owned by the organization and are used to connect to the network.
[0033] The zero trust model does not absolutely trust any user. Each user is given only the minimum privileges necessary for their work, and those privileges are continuously checked to restrict access to unauthorized data. When a user attempts to access data, their identity is verified, and they are granted the minimum privileges necessary for the work, with access privileges periodically checked. To implement the zero trust model, its structure must be designed like building a building. From the network structure, such as the location of information protection equipment and servers, to specific security policies, such as authentication methods and procedures for equipment and users, and access control methods, the detailed configuration of the entire organization's network and the operation and interaction of security-related elements must all be designed. This type of security structure design is called security architecture.
[0034] Zero-Trust Architecture (ZTA) defines seven principles for implementing a zero-trust model. An organization's infrastructure and business processes must be designed and implemented in accordance with these seven principles. The seven principles of ZTA are as follows: (1) Treat all data resources and computing services as assets that must be protected. This principle means treating all elements on an organization's network as assets. An organization's network is made up of various types of equipment. Data, services, data collection and storage devices, and SaaS (Software as a Service) are all considered assets that must be protected. Even devices such as personal laptops and tablets owned by remote workers should be considered assets that must be protected if they can be connected to the organization's network.
[0035] (2) All communications are protected regardless of their location on the network. This principle means that the trustworthiness of assets is not assessed based on their location on the network. The same procedures must be followed to meet security requirements whether accessing the network from within or outside the network. All communications must be conducted in the most secure manner, must meet confidentiality and integrity requirements, and the source of the connection, such as equipment or users, must be authenticated. (3) Access authority to organizational assets is granted on a per-session basis. When a user accesses an asset, the authority required for each task must be determined in advance, and only the minimum authority required for the requested task must be granted for that session. When the session expires or another task is requested, authentication procedures must be repeated and the corresponding minimum authority must be granted. To implement this principle, the classification of existing tasks and the required authority must be precisely defined at the initial design stage.
[0036] (4) Access to assets must be determined by a dynamic policy that takes into account various information, such as user identity, applications, services, and the status of the requested asset, as well as other operational and environmental requirements. To achieve zero trust, the assets owned by the organization, organizational members, and the access rights to the assets required by each member must be defined, and a dynamic policy that compiles and considers various information and grants the necessary rights must be applied. The information that can be collected at this time includes user identity, asset information, operational information, and environmental information, which can be organized as shown in Table 1.
[0037] [Table 1]
[0038] (5) The organization must not trust any assets and must monitor and measure the integrity and security status of the assets. When the organization evaluates the requirements for assets, it must also evaluate the security status of the assets. It must establish a system for continuously diagnosing the status of assets and mitigating risks (Continuous Diagnostics and Mitigation, CDM). If some assets have known vulnerabilities that have already been attacked, they can receive different permissions from other secure assets. For example, a personal device evaluated as having malicious code installed may be denied access to the network. (6) Before allowing access to assets, it is necessary to dynamically and strictly confirm the authentication of users and equipment and the possession of access rights. (7) The organization must collect as much information as possible, such as the security status of assets, network traffic and access request information, and communication status, and use it to improve security. In a zero-trust architecture, this principle is not limited to specific technologies. It is only necessary to design and implement it with various elements according to the organization's situation to meet the seven principles. <Core Logical Components of ZTA>
[0039] One of the most well-known zero trust models shows the components of zero trust and their interrelationships. In the control model, policies are determined and applied at the policy decision point (PDP) and policy enforcement point (PEP). Here, the policy decision point (PDP) is further divided into the policy engine (PE) and policy administrator (PA). The policy engine makes decisions regarding access requests to assets. It also dynamically approves or denies received requests based on organizational policies and collected information. The PA implements the PE's decisions. If the PE approves, it opens a session between the requester and the asset to connect communications. If it denies, it closes the session, blocking communications and managing the application of policies such as the user's session, authentication status, and granted privileges. In other words, the PDP determines policy and manages its application. The PEP can be seen as a gatekeeper that receives instructions from the policy-managing PA and opens and closes communications, and as a logger that records access and exit.
[0040] The ZTA implemented in the example model uses these three components to enable authentication, authorization management, and recording. While there are various ways for organizations to implement ZTA for their workflows, ZTA is typically implemented to fulfill the seven principles of ZTA. However, ZTA can be implemented in a variety of ways depending on the characteristics of each organization. For example, an actor's ID can be used as a core component in policy generation. In this case, access to the organization's data can be monitored and approved / denied based on the ID and the attributes attached to the ID. Personal data can also be placed on special network devices such as intelligent switches / routers, next-generation firewalls, and special-purpose gateways, and these can be logically and physically separated to protect each piece of personal data. If the PE determines how the network is configured using the SDP method, the PA can reconfigure it, and clients can request and approve access to the PEP configured by the PA. In conclusion, there is no need to be limited to a specific method; ZTA can be implemented to fulfill the seven principles in a way that suits each organization's characteristics.
[0041] <Reliability Algorithm>
[0042] In ZTA, the Policy Engine (PE) is responsible for deciding whether or not to apply a policy. When making a decision, the PE must evaluate the trustworthiness of the asset or the user accessing the asset. The policy applied by the PE depends on the assessed trustworthiness. The trustworthiness evaluation algorithm evaluates the factors in Table 2 below.
[0043] [Table 2]
[0044] PE evaluates the trustworthiness of an accessing entity based on the five factors and determines whether the accessing entity can access the asset. This trustworthiness algorithm can be implemented in various ways. Typical methods include the criteria-centered method, score-centered method, single-trust algorithm method, and multi-factor trust algorithm method. The criteria-centered method evaluates trustworthiness based on whether the accessing entity meets a specific criterion, while the score-centered method evaluates the trustworthiness of the accessing entity using a score system. The single-trust algorithm method evaluates the trustworthiness of each request individually, while the multi-factor trust algorithm method evaluates trustworthiness by considering the requesting entity's communication record and evaluation record. There is no correct answer when determining the trustworthiness algorithm. Since every organization's environment is different, the most appropriate method for the environment can be selected and implemented, just as the logical core components of ZTA are designed. In summary, zero trust protects all of an organization's data resources and computer services by not trusting any components on the network. Here, "components" refers to all elements on the network, including users and devices connected to the network, servers located on the internal network, network equipment, information protection equipment, and programs running on each device. In other words, even the components inside the network are not trusted. Zero trust architecture does not determine trust based on the point of network connection. Instead, it verifies the identity and authority of the accessing party when access to data and assets occurs, granting only the minimum privileges necessary for the requested task and managing access on a per-session basis for each task. The session is then terminated when the task is completed, and if another task is required, re-authentication is required before granting privileges. To realize this concept of zero trust, all assets must be periodically monitored and measured for integrity checks, infection status, etc., and as much information as possible, such as user identity, service request information, asset status, and network traffic and communication status, can be collected and used to improve security.
[0045] <Personal information encryption>
[0046] Encryption algorithms that can be used for database encryption can be classified into symmetric key (secret key) algorithms, public key algorithms, and hash algorithms depending on the key characteristics. In database encryption, a fast algorithm is appropriate for items that require continuous encryption and decryption each time a query is processed, such as names and resident ID numbers. A hash algorithm is appropriate for items that do not require decryption, such as passwords. In one embodiment of the present invention, a user's personal information can be encrypted and decrypted using symmetric key algorithms such as AES and DES. Of course, this does not preclude the use of public key or hash algorithms, or hybrid encryption that combines these.
[0047] When the requester terminal 400 requests at least one piece of personal information, the auction unit 330 may set a budget for using at least one piece of personal information. For example, assume that the requester targets women in their 20s and 30s residing in Seoul and needs personal information on these women. In this case, the auction unit 330 sorts the personal information that meets the conditions requested by the requester terminal 400 and then inputs a budget on the requester terminal 400. The auction unit 330 may sort the personal information for sale in ascending order of the price set on the user terminal 100, and may determine the number of pieces of personal information that can be purchased within the budget on the requester terminal 400. If the budget is 100,000 won and the price ranges from 100 won to 500 won, it may calculate how many pieces of personal information can be purchased for 100,000 won. The requester terminal 400 may increase the budget if there are insufficient information providers related to the item it requires, or may decrease the budget if there are too many information providers for the item. There can be various types of personal information items, but the AND and OR operators can be provided in the search filter so that the requester can specify when the requested personal information items are met simultaneously or when one personal information item meets only one condition, etc. Accordingly, the requester can set an AND condition or an OR condition. Of course, the NOT operator can also be added if it is a condition that the requester wants to match.
[0048] In this case, the user terminal 100 can set a price for each personal information item as shown in FIGS. 5 and 6. For example, a user can enter a name, gender, date of birth, place of birth, etc., and then perform authentication to verify whether the information is fake or real as shown in FIG. 7. There are limitations to setting a price (bidding) for information that has not been verified. This is because information that is confirmed to be real is more valuable than uncertain information whose authenticity is unknown. In addition to information that can identify a user, preference information such as favorite foods and preferred travel styles is also a blessing for advertisers, as shown in FIGS. 8 and 9. Therefore, a function for collecting and setting a price for such information can be provided. Providing such personal information as shown in FIGS. 10 and 11 can provide information such as the number of days an advertiser can contact the user. The points (revenue) earned by an advertiser purchasing their own information can be used in a points shop as shown in FIG. 12, can be exchanged for cash as shown in FIG. 13, and can be managed on a personal page as shown in FIG. 14. You can list your current information sales status as shown in Figure 15, and set prices as shown in Figure 16. When identity authentication is verified using application documents as shown in Figure 17, verification is performed by comparing various application documents with personal information after they are issued, and as shown in Figure 18, items that cannot be issued using application documents, such as preferences, can be verified through an acquaintance authentication process by selecting an acquaintance and having the acquaintance verify them. Functions such as those shown in Figure 19 can be provided, but are not limited to these.
[0049] The auction unit 330 can construct an auction model using an agent-based model (ABM) to simulate a competitive bidding market. In this case, the actors are businesses, i.e., bidders. The winning bidder can be awarded based on quantitative evaluation and bid amount. ABM is a system modeling approach consisting of autonomous and interacting actors. The actors are configured as constituent entities with key attributes and behavioral rules in the system and are simulated to interact in a given environment. Within the auction system, economic entities make choices to maximize profits by taking into account the behavior of competitors and their own attributes, and the results of these choices again affect each entity's profits. Since direct interaction between actors in an auction system is a form of collusion, the system is limited to situations where the results of other actors indirectly affect the winning bid.
[0050] <Bidders and bid price rating>
[0051] The price determination method for competitive bidding is a differential pricing method, which allows a bidder to set their bid price so that it becomes the winning bid price. Therefore, it is reasonable for a bidder to add a margin to their bid price. However, adding an excessive margin reduces the probability of winning, so an appropriate bid price must be considered.
[0052]
number
[0053] Equation 1 is a formula for calculating a winning bidder's expected profit, and an optimization algorithm is used to determine the bid price that maximizes the expected profit. The winning bidder's expected profit, π, is calculated by multiplying the probability of winning by the profit if the bid is successful. The probability of winning is calculated using order statistics. Assuming there are n-1 competitors in the auction, excluding the bidder, and ns successful bidders, the ns-lowest bid among the n-1 competitors must be higher than the bidder's own bid price, b. The cumulative distribution function F is a bidder's assumed distribution of competitors' bids and indicates the probability that a competitor's bid price, bj, is lower than the bidder's own bid price, b. Therefore, 1-F(b) indicates the probability that the bidder's own bid price is lower than the competitor's bid price. The profit if the bid is successful is calculated by subtracting the bidder's business cost, c, from the bid price, b. Using this, businesses can set their own bid prices and receive guidelines for bidding prices.
[0054] The period limiting unit 340 may specify and provide an information use period, which is a viewing limit, for personal information of preset items among at least one of the personal information when the bid is made by the requester terminal 400. The requester terminal 400 may request personal information of the user terminal 100 and view personal information of preset items included in the personal information within the preset information use period.
[0055] The sunset number providing unit 350 may provide a sunset type secure number as a substitute for a telephone number among personal information during the information usage period. The term sunset type means, like sunset clauses, that the secure number will expire after a specific period unless additional action is taken to extend the validity period. The term sunset clause may be used in conjunction with various concepts such as sunset law, sunset system, sunset legislation, sunset provision, and sunset regulation, and although they may differ slightly, they all imply that a specific period is set and the secure number will be abolished unless special measures are taken. In other words, the secure number can be used for a predetermined period, and after that, the secure number is deleted, meaning that messages and calls cannot be made from the user terminal 100 anymore.
[0056] This preset period is the information usage period, and the Personal Information Protection Act requires that the purpose, use, and period be clearly stated when using personal information. Therefore, setting this period serves to eliminate any intermediaries that may connect the requester terminal 400 to the user terminal 100, i.e., to eliminate any intermediate media. At this time, the security number is a randomly selected number and is mapped to [user phone number - security number], so if the requester terminal 400 makes a call or sends a message to the security number, it is forwarded to the user's phone number. Just like the phone number, a security email address and a security address (home address) can also be set in the same way along with the security number. As a result, the requester can only contact the user within the preset information usage period, and once the information usage period expires, there is no way to contact them any more.
[0057] When an email address or address is provided as personal information, the abuse prevention unit 360 may input a unique identification code output when the email address is opened or a unique identification code printed or inserted in the mail envelope sent to the address in order to provide points to the user device 100 for providing the personal information. Abusing refers to an act that has some kind of fraudulent purpose, such as causing harm to others or for the benefit of children. While a user's receipt of a share of revenue is premised on providing their personal information, receiving a share of revenue without viewing an advertisement or opening mail despite preventing acts using personal information is an act that goes against the requester's interests. Accordingly, after identifying the user device 100 through device fingerprinting, the unit may monitor and detect cases where a user repeatedly creates a fake account to obtain rewards on the user device 100 or repeatedly performs acts required to obtain rewards using a macrobot, and treat the user account as an abuser. If a user uses a large number of different devices rather than the same device, they can be monitored and identified as malicious users by determining whether they are connected to the same or similar GPS or Wi-Fi.
[0058] <Conditions for Device Fingerprinting>
[0059] Among device information, browser attributes appear relatively consistently, and core components can be selected to classify meaningful values for device identification, and such selection criteria can be determined based on factors such as applicability to the domestic Internet environment, ease of implementation, selection of common identification values for each device, avoidance of anti-fingerprinting, and minimization of privacy violations. The criteria for selecting identification values and the conditions for device detection methods are as follows:
[0060] First, it must be applicable to the domestic Internet environment. To more accurately determine device information for domestic users, it is necessary to assign weightings appropriate for the domestic Internet environment. For devices used domestically, information such as language and time zone is almost always consistent, so the weighting of corresponding attribute values in the device identification method should be lowered. Furthermore, for mobile devices, flexible condition value changes may be necessary, such as lowering the weighting of the connecting IP. This can be adjusted depending on the characteristics of each web service. Second, it must be easy to implement. For web services to collect device information such as JavaScript, Flash, and canvas fingerprinting, it is necessary to use minimal code to minimize user accessibility and slowdowns when accessing websites. In fact, implementing a large amount of JavaScript can result in the collection of unnecessary information and inevitably slow down website page landing speeds due to the implementation of scripts, so an implementation method to minimize this is needed.
[0061] Third, a common identification value must be selected across device browsers. User device browsers have both identifiable and indistinguishable values. Because the items that can be collected vary depending on the browser used, a value that allows for accurate results and identification must be selected, while technology that can be applied across all mobile devices is necessary. Fourth, anti-fingerprinting technology must be evaded. Browsers that hide header values and various tools that can hide tracking are available to prevent privacy violations. With the recent trend of increasing use of the Tor network and Tor browser, it is necessary to be able to detect attack patterns in which device attribute values are continually modified through the use of anti-tracking tools and proxies, and to implement additional security procedures. Anti-fingerprinting must be evaded by adding new tracking methods for information that cannot be collected on the user's device, or by applying technology to verify this.
[0062] Fifth, privacy violations must be minimized. Only the minimum amount of information necessary to identify a device must be collected, so that it cannot be used for any purpose other than identifying the user or the device itself. Because the collected information itself may be construed as a violation of personal information, legal notices of the collected information must be provided, and basic privacy protection measures must be in place, such as storing the collected information in a hash format.
[0063] <Optimal information gathering model>
[0064] To implement an actual web service based on the optimal information collection model, a browser collection script for device fingerprinting is run on the web server, and a fingerprinting server is used to combine characteristic values to generate a device fingerprinting ID. After that, behavior is tracked based on the device fingerprinting ID, and suspicious devices can be tagged or blocked, or managed by requiring additional authentication such as ARS authentication or domestic identity authentication depending on the type of service.
[0065] Device scoring for online fraud prevention
[0066] While attacks against corporate web services, such as online fraud, vary by industry, most web services that use accounts are exposed to the same risks. While traditional defenses are necessary to address these attacks, identifying devices connected to a network is considered an important technology for identifying potential risks to web services and preventing attacks. Device-based attack prevention can play a major role in effectively preventing attacks in online environments and providing secure services to trusted users. An attacker's device is generally not configured for only one web service. The more accurate device data is available, the easier it is to assess risks and stop attacks. Device identification is the first line of defense against online attacks and can be a powerful tool for identifying high-risk behaviors.
[0067] <Device scoring model>
[0068] The method of identifying device fingerprinting IDs (hereinafter referred to as device IDs) and tracking their behavior can be achieved by creating a unique ID using currently used technical cookies and combining it with the device fingerprinting ID. Depending on the site, combining it with a unique value held by the web service company, such as a unique serial number or user account ID, can be an even more valuable detection method. This method uses two unique keys.
[0069] The first key used is a cookie-based PUID (Product Unique Identifier). This is a value generated based on a cookie when a user's web browser first connects to a web service, and is the same concept as a UUID. This key can be used to check whether the user's browser connected to a particular website. The second key used is a DFID (Device Fingerprint Unique Identifier), generated using a unique value for the browser. This key can be generated by hashing each value of the optimal information collection model. For example, if hashing is done with SHA256, a 64-digit unique key will be created. These keys are stored in available storage spaces on the user's device, such as browser cookies, local storage, and HTML5 Web SQL, and are compared when accessing a website. Different standards can be applied depending on the detection level and policies of each site.
[0070] When the user terminal 100 first accesses a website, the device fingerprinting process begins, generating a PUID based on the user's browser cookie value. Separate from the PUID, the system generates a DFID through the process of acquiring the user's device information. These two keys are stored in the user's device and device fingerprinting system or web service databases and are used for subsequent comparisons. If the user's PUID exists but the DFID does not exist or does not match, a new one is generated and the change is recorded. Strengthened monitoring of the device is performed through tagging or blocking. Depending on the type of service, it may be effective to further identify the user using additional authentication methods such as ARS authentication or domestic identity authentication. The two keys, the PUID and DFID, can be used appropriately in conjunction with the management of access IP addresses of devices already in use and the management of logged-in account history for security management purposes.
[0071] <Device and account linking>
[0072] Linking device and account information for application to in-house web services and tracking this connection can be a useful tool for detecting cyber attackers working together. Organized and sophisticated hacking groups often use different types of devices located in multiple locations, but if they log in to the same account, tracking and managing this connection information allows for much more sophisticated detection than current defense methods that rely on IP addresses. For example, if the same mobile gateway IP is used, it is impossible to detect or block the activity, but it is possible to detect if one device creates multiple accounts in sequence or if multiple devices all use the same account, and such devices and user accounts can be managed for risk through separate scoring management.
[0073] The request post management unit 370 may upload request posts from requesters requesting the provision of personal information, arrange the request posts by pre-defined categories, and sort and list the request posts in descending order of accumulated rewards by pre-defined category.
[0074] The information providing unit 380 can provide the user terminal 100 with a database for personal information use and statistical data including bid amounts, and can provide maximum, average, and minimum bid amounts. The bid here can be a price setting per item of personal information that the user can set. In other words, it is a setting of how much they are willing to sell their information for. The platform of the applicant of the present invention (Korea Integrated Petition Center Co., Ltd.) issues various petition documents for each individual through its agent issuing service. If the information is verified through this, that is, if it is verified, a higher price can be set, but if it is not, a limit can be set on the amount that can be raised. In addition, by providing guidelines for the maximum and minimum prices of verified personal information, users can set the value of their personal information themselves.
[0075] When a requester uploads a request post requesting the provision of personal information on the requester terminal 400, the sender / receiver indicating unit 390 may specify the name of the requesting business of the requester and the purpose of use as required fields, select at least one of the phone number, email address, and address in the personal information, and input the sender's name to indicate the sender's name. A personal information controller who processes personal information must process the personal information to the extent necessary for the purpose of processing the personal information and must not use it for purposes other than those purposes, so the purpose of use may be indicated, and if a phone number is used to prevent indiscriminate spam from being delivered to the user, the calling number, if it is an email address, the calling email address, if it is a postal address, the calling address, etc. may be indicated.
[0076] When the earnings status unit 391 provides the earnings obtained by providing personal information in the user terminal 100 to the history log, it can provide the requester, purchase item, and bid price by date, provide earnings statistics by day, month, year, requester, and item, and provide the total earnings amount, withdrawal and balance history.
[0077] Hereinafter, the operation process of the platform service providing server according to the configuration of Fig. 2 will be described in detail with reference to Figs. 3 to 19. However, it is obvious that the embodiment is merely one of various embodiments of the present invention, and the present invention is not limited thereto.
[0078] Referring to FIG. 3, (a) the platform service providing server 300 constructs a personal information database by storing personal information uploaded through the user terminal 100 after consenting to the provision of personal information. Then, as shown in (b), the platform service providing server 300 allows the requester terminal 400 to search for the required personal information in the database. However, the platform service providing server 300 blurs, anonymizes, or pseudonyms the personal information, or displays only matching numbers, thereby preventing the personal information from being provided immediately. As shown in (c), the platform service providing server 300 allows the user terminal 100 to set a price (bidding). The requester terminal 400 can purchase the item after specifying the number of personal information according to the target conditions and budget. (d) If the requester terminal 400 wins the bid, the platform service providing server 300 provides personal information to the requester terminal 400. However, if personal information such as a phone number, email address, or home address is requested, an intermediate intermediary with a preset period, i.e., a limited period of information usage, such as a secure phone number, secure email address, or secure home address, can be provided to prevent the user's information from directly coming into the requester's hands.
[0079] As shown in (a) of Figure 4, the platform service providing server 300 can check whether the user has entered an irregular phone number, email address, or home address by checking the authentication number for the phone number, the email confirmation for the email, or the mail sent to the home address in order to prevent abuse of the user terminal 100. In addition, the platform service providing server 300 can perform a receipt confirmation for messages received via the phone number, an email open confirmation for emails, or a mail confirmation for mail in order to provide rewards to the user terminal 100. The email open confirmation can be performed by scanning a unique identification code, such as a QR code, that appears only when the email is opened, or by scanning a printed unique identification code that appears only when the mail is opened.
[0080] In addition, when uploading a request post as in (b), the platform service providing server 300 can list the highest accumulated rewards by dividing them into categories, and as in (c), the business name (requester's name), purpose of use, receiving method (select one of phone number / email / postal mail), and sender's name can be specified in advance, for example, 050 number for phone number, sender's name and email address for email, sender's address for postal mail, etc. In addition, the requester terminal 400 can provide desired purchase items individually or collectively, and provide the user terminal 100 with expected profits per sales item, etc. As shown in (d), the platform service providing server 300 can provide a revenue history to each user terminal 100, including information on the user (requester), purchase item, and bid price by date, and can provide overall revenue or non-revenue statistics by day, month, year, requester, and item, as well as the total revenue amount. It can also provide a withdrawal and balance history in a bankbook format with date, summary, deposit, withdrawal, balance, and notes, and can indicate revenue after deduction of income tax and fees. When settling, the user terminal 100 undergoes identity verification procedures to confirm the settlement date and time, limit, number of times, exception clauses, etc., and can indicate the deposit after deduction of tax.
[0081] <Touch point management policy>
[0082] In the case of a telephone number among contact points, the aforementioned sunset type security number is used to manage the information usage period and to map a random security number to the telephone number of the user terminal 100. In the case of emails, subject delimiters separated by [ ] must be provided to obtain consent and increase the open rate, and the requester terminal 400 can also check in advance whether the requested email content, design, and attachments can be transmitted. In addition, to prevent users from abandoning the email and increase the read rate, a preset feedback number or text can be entered after opening the email. In the case of addresses, a method can be used in which a photograph taken after receiving mail is uploaded or a printed number is entered when the mail is opened.
[0083] <Front page>
[0084] The statistics screen can provide the total number of participants, total cumulative sales amount, average sales amount per user, number of sales per user, average sales amount per database, etc. It can also provide the number of databases wishing to sell per user, average total selling bid amount per user, total number of databases for sale (EA), total bid amount per database for sale (Won), average bid amount per database, number of resales per database, etc.
[0085] Matters not explained in the method for providing a platform service for sharing personal information based on the right to transfer personal information in Figures 2 to 19 are the same as or can be easily inferred from the content explained previously in Figure 1 for the method for providing a platform service for sharing personal information based on the right to transfer personal information, so they will be omitted below.
[0086] Figure 20 is a diagram showing a process of transmitting and receiving data between components included in the system for providing a platform service for sharing personal information based on the right to transfer personal information according to one embodiment of the present invention shown in Figure 1. Hereinafter, an example of a process of transmitting and receiving data between components will be described with reference to Figure 20, but the present application is not limited to this embodiment, and it is obvious to those skilled in the art that the process of transmitting and receiving data shown in Figure 20 can be changed according to the various embodiments described above.
[0087] Referring to FIG. 20, the platform service providing server obtains consent from the user terminal to provide personal information for use of the personal information (S5100).
[0088] The platform service providing server receives and stores at least one piece of personal information from the user terminal (S5200), and when at least one piece of personal information is requested from the requester terminal, sets a budget for using at least one piece of personal information (S5300).
[0089] In addition, if the bid is won by the requester terminal, the platform service providing server specifies an information use period, which is a viewing restriction, for the personal information of a preset item among at least one of the personal information and provides it (S5400).
[0090] The order of the above steps (S5100 to S5400) is merely an example and is not limited thereto, that is, the order of the above steps (S5100 to S5400) may be changed, and some steps may be performed simultaneously or deleted.
[0091] Matters not described in the method for providing a platform service for sharing personal information based on the right to transfer personal information in Figure 20 are the same as or can be easily inferred from the content previously described in Figures 1 to 4 for the method for providing a platform service for sharing personal information based on the right to transfer personal information, so they will not be described below.
[0092] The method for providing a personal information sharing platform service based on the right to transfer personal information according to an embodiment described in FIG. 20 may also be embodied in the form of a recording medium containing computer-executable instructions, such as an application or program module executed by a computer. A computer-readable medium may be any available medium that can be accessed by a computer, and includes both volatile and non-volatile media, and separable and non-separable media. Furthermore, a computer-readable medium may include all computer storage media. A computer storage medium includes all volatile and non-volatile, separable and non-separable media embodied in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data.
[0093] The method for providing a personal information sharing platform service based on the right to transfer personal information according to an embodiment of the present invention may be executed by an application that is basically installed in the terminal (which may include a program included in a platform or operating system that is basically installed in the terminal), or may be executed by an application (i.e., a program) that a user directly installs in the master terminal through an application providing server such as an application store server, an application, or a web server related to the service. In this sense, the method for providing a personal information sharing platform service based on the right to transfer personal information according to an embodiment of the present invention may be embodied as an application (i.e., a program) that is basically installed in the terminal or that is directly installed by the user, and may be recorded on a computer-readable recording medium such as a terminal.
[0094] The above description of the present invention is for illustrative purposes only, and those skilled in the art will understand that the present invention can be easily modified into other specific forms without changing the technical spirit or essential features of the present invention. Therefore, the above-described embodiments should be understood to be illustrative in all respects and not limiting. For example, each component described as a single component may be implemented in a distributed form, and similarly, each component described as a distributed component may be implemented in a combined form.
[0095] The scope of the present invention is indicated by the claims that follow rather than by the above detailed description, and all modifications and variations that fall within the meaning and scope of the claims and their equivalents should be construed as being included within the scope of the present invention.
Claims
[Claim 1] A personal information sharing platform service providing system based on the right to transfer personal information, comprising a user terminal, a requester terminal, and a platform service providing server that are capable of transmitting and receiving information via a network, wherein the user terminal and the requester terminal are plural, and personal information provided from the user terminal is accessed by the requester terminal via the platform service providing server, The user terminal transmits consent to the provision of personal information for the use of the user's personal information to the platform service providing server, The platform service providing server stores the consent received from the user terminal in a consent storage unit, At least one type of personal information and each desired selling price of the personal information are transmitted to the platform service providing server by the user terminal; The platform service providing server stores the personal information and the desired selling price received from the user terminal in a database unit, A request to view the personal information stored in the database unit is sent to the platform service providing server by the requester terminal; The platform service providing server sorts the personal information corresponding to the personal information conditions included in the request received from the requester terminal in ascending order of the desired selling price through an auction unit, and transmits the number of personal information that can be purchased within the budget included in the request to the requester terminal; When the purchase of personal information is sent to the platform service provider server by the requester terminal, The platform service providing server specifies a viewing period by a period limiting unit, makes the purchased personal information viewable to the requester terminal, and transmits a settlement according to the purchase price included in the purchase to the user terminal that purchased the personal information. A personal information sharing platform service providing system based on the right to transfer personal information.
Citation Information
Patent Citations
Calculation device, calculation method, and calculation program
JP2015179473A
Personal data intermediary system
JP2023529716A
System and method for controlling client information distribution
KR1020140079645A
System for correlating anonymized unique identifers
US20220245644A1
Personal data mediation system
WO2021251697A1