Data management device, data management system, data management method, and program
The data management system addresses the challenge of changing data protection levels in data marts by using provider identification and disclosure condition storage units to ensure that only compliant data is presented, effectively managing data disclosure in response to changing conditions.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-11-17
- Publication Date
- 2026-03-13
AI Technical Summary
Existing data management technologies, such as those described in Patent Document 1, fail to manage the correspondence between data before and after conversion, making it difficult to change the protection level of data in a data mart appropriately in response to changes in data disclosure conditions.
A data management system that includes a first storage unit for storing provider identification information and disclosure conditions for data in a data warehouse, and a second storage unit for data in a data mart, allowing the system to identify and present data that matches specified disclosure conditions based on provider information.
Enables appropriate reflection of changes in data disclosure conditions in the data mart, ensuring that only data meeting the specified criteria is presented to users, thereby enhancing data protection and compliance with provider preferences.
Smart Images

Figure 0007829305000001 
Figure 0007829305000002 
Figure 0007829305000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a data management device, a data management system, a data management method, and a program.
Background Art
[0002] Currently, due to the spread of the Internet of Things (IoT), various technologies using big data collected from a large number of sensors are known. For example, a technology for extracting and processing data according to user needs from a data warehouse storing big data to generate a data mart and analyzing the data stored in the data mart is known.
[0003] By the way, currently, awareness of protecting personal information, trade secrets, etc. is increasing, and data providers may specify data disclosure conditions and restrict data disclosure. Patent Document 1 describes a technique for managing the protection level of data in a device that manages data collected from a data provider in order to prevent the outflow of data to be protected. Here, the data provider may desire to change the data disclosure conditions.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, the technology described in Patent Document 1 does not manage the correspondence between data before and after conversion when data is converted and managed. Therefore, while the technology described in Patent Document 1 can change the protection level of data before conversion, it is difficult to change the protection level of data after conversion. For example, in the technology described in Patent Document 1, when generating a data mart from a data warehouse, while it is possible to change the protection level of the data stored in the data warehouse, it is difficult to appropriately change the protection level of the data stored in the data mart. For this reason, there is a need for a technology that can appropriately reflect changes in data disclosure conditions in the disclosure of the data mart.
[0006] This disclosure is made in view of the above issues and aims to provide a data management device, data management system, data management method, and program that appropriately reflect changes in data disclosure conditions in the disclosure of data marts. [Means for solving the problem]
[0007] To achieve the above objectives, the data management device relating to this disclosure is A first storage means that stores first provider identification information for identifying each provider of data stored in a data warehouse that stores data searchable by a search expression, and disclosure condition information indicating data disclosure conditions specified by the provider indicated by the first provider identification information, Each provider of data stored in the data mart generated based on the aforementioned data warehouse and the data provider used to generate the data stored in the data mart from the data stored in the data warehouse. A second storage means for storing second provider identification information to identify a second provider, Based on the aforementioned disclosure conditions information and the second provider identification information, For each piece of data stored in the aforementioned data mart, identify the data disclosure conditions specified by the data provider used to generate the data. The system includes a presentation means for presenting to users of the data mart data that matches the data disclosure conditions among the data stored in the data mart. [Effects of the Invention]
[0008] In this disclosure, data that matches the data disclosure conditions is presented to users of the data mart based on disclosure condition information indicating the data disclosure conditions and provider information to identify the respective providers of the data stored in the data mart. Therefore, according to this disclosure, changes to the data disclosure conditions can be appropriately reflected in the disclosure of the data mart. [Brief explanation of the drawing]
[0009] [Figure 1] Configuration diagram of the data management system according to Embodiment 1 [Figure 2] Configuration diagram of the data management device according to Embodiment 1 [Figure 3] Functional configuration diagram of the data management device according to Embodiment 1 [Figure 4] First explanatory diagram of the screen presented to the data provider [Figure 5] Second explanatory diagram of the screen presented to the data provider. [Figure 6] This diagram shows the information stored in the first storage unit in Embodiment 1, where (A) is a diagram showing the provider table, (B) is a diagram showing the operation data storage table, and (C) is a diagram showing the disclosure conditions table. [Figure 7] First explanatory diagram of the screen presented to the data mart creator. [Figure 8] Second explanatory diagram of the screen presented to the data mart creator. [Figure 9] Diagram showing the calculation specification screen. [Figure 10] Diagram showing the data display screen. [Figure 11] This diagram shows the information stored in the second storage unit in Embodiment 1, where (A) is a diagram showing the creator account table, (B) is a diagram showing the data storage table, and (C) is a diagram showing the provider tracking table. [Figure 12] Figure showing the data catalog [Figure 13]It is a diagram showing disclosure data disclosed to users in Embodiment 1. (A) is a diagram showing disclosure data disclosed to users of group companies, and (B) is a diagram showing disclosure data disclosed to general users [Figure 14] Flowchart showing the data mart generation process executed by the data management device according to Embodiment 1 [Figure 15] Flowchart showing the data mart presentation process executed by the data management device according to Embodiment 1 [Figure 16] Flowchart showing the data management process executed by the data management device according to Embodiment 1 [Figure 17] Flowchart showing the data mart generation process executed by the data management device according to Embodiment 2 [Figure 18] It is a diagram showing information stored in the second storage unit in Embodiment 3. (A) is a diagram showing a data storage table, and (B) is a diagram showing a provider tracking table [Figure 19] It is a diagram showing disclosure data disclosed to users in Embodiment 3. (A) is a diagram showing disclosure data disclosed to users of group companies, and (B) is a diagram showing disclosure data disclosed to general users [Figure 20] Configuration diagram of the data management system according to Embodiment 4
Modes for Carrying Out the Invention
[0010] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals
[0011] (Embodiment 1) Figure 1 shows the configuration of the data management system 1000 according to Embodiment 1. The data management system 1000 is a system for managing data, and mainly a system for managing data marts. A data mart is a database that extracts and processes necessary data from data stored in a data warehouse, other data marts, etc., according to its purpose and use, and stores the extracted and processed data in an easy-to-use format. In this embodiment, the data mart is generated from a data warehouse or other data mart.
[0012] A data warehouse is a database that stores vast amounts of data so that it can be used according to a specific purpose. A data warehouse is a database that centrally stores and manages data in a format that can be searched using, for example, SQL (Structured Query Language) search expressions. In this embodiment, the data warehouse is the database that serves as the starting point for generating data marts. The data management system 1000 performs tasks such as generating data marts, disclosing data marts, and providing data marts. The data management system 1000 has a function to manage the scope of data disclosure. The data management system 1000 includes a data management device 100.
[0013] The data management device 100 is a device that manages data, primarily a device that manages data marts. The data management device 100 collects data from each property 300 to generate a data warehouse. Property 300 is a unit that represents a data collection source. The data management device 100 accepts data disclosure conditions from data providers. Data disclosure conditions are the conditions under which data will be disclosed.
[0014] The data disclosure conditions include conditions regarding data mart users, data types, and data search conditions. "Data mart users" is a concept that includes both "data mart creators" and "data mart viewers." Hereinafter, "data providers" will be simply referred to as "providers," "data mart users" as simply "users," "data mart creators" as simply "creators," and "data mart viewers" as simply "viewers."
[0015] The data management device 100 generates a data mart from a data warehouse or other data mart in accordance with the creator's instructions. The data management device 100 generates the data mart taking into account the data disclosure conditions. The data management device 100 also discloses the data mart in accordance with the viewer's instructions. The data management device 100 discloses the data mart taking into account the data disclosure conditions.
[0016] The data management device 100 is connected to the gateway 310, terminal device 330, and terminal device 400 via the communication network 500. The data management device 100 collects operational data from the equipment 320 via the gateway 310. The data management device 100 receives data disclosure conditions from providers via terminal device 330. The data management device 100 discloses the data mart to users via terminal device 400.
[0017] The data management device 100 is, for example, a cloud server that provides an environment for analyzing data collected from equipment 320. A cloud server is a server that provides resources in cloud computing. The data management device 100 has the functions of an ETL (Extract Transform Load) device, a data mart generation device, and a data viewing device.
[0018] The ETL device is a device that converts data collected from the device 320 into a data warehouse that can be read by the data mart generation device. The ETL device performs character code standardization, unit standardization, and completion of missing data, and converts the data into a searchable data format. The data mart generation device is a device that generates a data mart from the data warehouse according to the instructions of the creator. The data viewing device is a device that visualizes the data in the data mart. The data viewing device is also called a BI (Business Intelligence) tool. As shown in Figure 2, the data management device 100 comprises a control unit 11, a first storage unit 12, a second storage unit 13, a third storage unit 14, and a communication unit 15.
[0019] The control unit 11 includes a CPU (Central Processing Unit), ROM (Read Only Memory), RAM (Random Access Memory), RTC (Real Time Clock), etc. The CPU is also called a central processing unit, central computing unit, processor, microprocessor, microcomputer, DSP (Digital Signal Processor), etc., and functions as a central computing unit that executes processing and calculations related to the control of the data management device 100. In the control unit 11, the CPU reads programs and data stored in ROM and uses RAM as a work area to comprehensively control the data management device 100. The RTC is, for example, an integrated circuit with a timing function. The CPU can determine the current date and time from the time information read from the RTC.
[0020] The first storage unit 12 is a device for storing a vast amount of data. A data warehouse is constructed in the first storage unit 12, and various information related to the data warehouse is stored in the first storage unit 12. The first storage unit 12 includes, for example, a hard disk drive. The second storage unit 13 is a device for storing a vast amount of data. A data mart is constructed in the second storage unit 13, and various information related to the data mart is stored in the second storage unit 13. The second storage unit 13 includes, for example, a hard disk drive.
[0021] The third storage unit 14 is equipped with non-volatile semiconductor memory such as flash memory, EPROM (Erasable Programmable ROM), and EEPROM (Electrically Erasable Programmable ROM), and plays the role of a so-called auxiliary storage device. The third storage unit 14 stores programs and data used by the control unit 11 to execute various processes. The third storage unit 14 also stores data generated or acquired by the control unit 11 as a result of executing various processes.
[0022] The communication unit 15 communicates with the gateway 310, terminal device 330, terminal device 400, etc., via the communication network 500, in accordance with the control of the control unit 11. The communication unit 15 is equipped with a communication interface for connecting the data management device 100 to the communication network 500.
[0023] Property 300A and Property 300B are properties from which operational data is collected, such as residential properties. Property 300 is a collective term for Property 300A and Property 300B. Property 300 is equipped with a gateway 310 and multiple devices 320. The gateway 310 is a communication device for connecting the devices 320 to the communication network 500.
[0024] Device 320 is a device that provides operating data to the data management device 100. Device 320 is, for example, an air conditioner, water heater, refrigerator, rice cooker, etc. The operating data is data related to the operation of device 320, and is, for example, detection data detected by sensors installed in device 320, setting data which is data set in device 320, etc. In this embodiment, an example will be described in which device 320 is an air conditioner and the operating data is the operating data of the air conditioner.
[0025] The terminal device 330 is, for example, a device used by a user of property 300 and a data provider. The terminal device 330 transmits provider information, data disclosure conditions, etc., received from the provider to the data management device 100. The terminal device 330 is a smartphone, tablet terminal, notebook computer, etc. The terminal device 330 comprises a control unit (not shown) that controls the operation of the entire terminal device 330, a storage unit (not shown) that stores various information, a display unit (not shown) that displays various information, an operation reception unit (not shown) that accepts various operations, and a communication unit (not shown) that has the function of connecting to the communication network 500.
[0026] The terminal device 400 is, for example, a device used by data users. The terminal device 400 is a terminal operated by the creator of a data mart when generating a data mart, or a terminal operated by a viewer of a data mart when viewing a data mart. The terminal device 400 is a smartphone, tablet, notebook computer, etc. The terminal device 400 comprises a control unit (not shown) that controls the operation of the entire terminal device 400, a storage unit (not shown) that stores various types of information, a display unit (not shown) that displays various types of information, an operation reception unit (not shown) that accepts various operations, and a communication unit (not shown) that has the function of connecting to a communication network 500.
[0027] Next, the functions of the data management device 100 will be described with reference to Figure 3. Functionally, the data management device 100 comprises an instruction acquisition unit 101, an authentication unit 102, a presentation unit 103, a generation unit 104, and an update unit 105. Each of these functions is realized by software, firmware, or a combination of software and firmware. The software and firmware are written as programs and stored in the ROM or the third storage unit 14. The CPU then realizes each of these functions by executing the programs stored in the ROM or the third storage unit 14.
[0028] First, a data warehouse is constructed in the first storage unit 12, and first provider identification information and disclosure condition information are stored therein. The first provider identification information is information for identifying each provider of data stored in the data warehouse that stores data searchable by search formulas. The first provider identification information indicates which data stored in the data warehouse was provided by which provider. The disclosure condition information indicates the data disclosure conditions specified by the provider indicated by the first provider identification information. The disclosure condition information indicates the data disclosure conditions for each provider. The first storage unit 12 is an example of a first storage means.
[0029] The second storage unit 13 stores a data mart and second provider identification information. The second provider identification information is information used to identify the provider of each piece of data stored in the data mart generated based on the data warehouse. The second provider identification information indicates which data stored in the data mart is based on data provided by which provider. Note that the term "data provider" is a concept that includes not only "the provider of the data itself" but also "the provider of the data from which the data originates."
[0030] For example, if the provider of the first data stored in the data warehouse is the first provider, and the second data stored in the data mart is data generated based on the first data, then the first provider is the provider of the second data. The second provider identification information is information for tracking the origin of the data stored in the data mart. The second storage unit 13 is an example of the second storage means. The second provider identification information is also an example of provider identification information.
[0031] The instruction acquisition unit 101 acquires various instructions. For example, the instruction acquisition unit 101 acquires instructions from the provider to update data disclosure conditions via the terminal device 330. The instruction acquisition unit 101 also acquires instructions from the creator to generate a data mart via the terminal device 400. The instruction acquisition unit 101 also acquires instructions from the viewer to disclose a data mart via the terminal device 400.
[0032] The authentication unit 102 authenticates providers, creators, viewers, etc. For example, the authentication unit 102 authenticates providers, creators, viewers, etc. by comparing account information received from providers, creators, viewers, etc. with information stored in the third storage unit 14. Account information includes, for example, a login name and password.
[0033] The presentation unit 103 presents to the user data that matches the data disclosure conditions from among the data stored in the data mart, based on the disclosure conditions information and the second provider identification information. For example, the presentation unit 103 identifies the provider for each piece of data stored in the data mart and identifies the data disclosure conditions of the identified provider. The presentation unit 103 presents to the user data that matches the data disclosure conditions and does not present to the user data that does not match the data disclosure conditions.
[0034] The method by which the presentation unit 103 presents data to the user can be adjusted as appropriate. For example, the presentation unit 103 may generate an image containing the data to be presented and transmit the generated image to the terminal device 400 via the communication unit 15. In this case, the terminal device 400 displays the received image on its screen. Alternatively, for example, the presentation unit 103 may transmit presentation instruction information, including the data to be presented and presentation instructions, to the terminal device 400 via the communication unit 15. In this case, the terminal device 400 generates an image containing the data to be presented based on the received presentation instruction information and displays the generated image on its screen. The presentation unit 103 is an example of a presentation means.
[0035] The generation unit 104 generates a data mart from data stored in the data warehouse according to instructions from the data mart creator. For example, the generation unit 104 extracts data from the data warehouse that matches the search criteria specified by the creator. The generation unit 104 generates a data mart that stores the extracted data, processed data from the extracted data, etc. Processed data from the extracted data includes data obtained by applying predetermined calculations to the extracted data, data obtained by aggregating the extracted data, and data extracted from the extracted data according to predetermined search criteria.
[0036] When generating a data mart, the generation unit 104 generates second provider identification information based on first provider identification information and stores the second provider identification information in the second storage unit 13 in association with the data mart. The data warehouse is associated with first provider identification information for identifying the providers that provided the data stored in the data warehouse. Therefore, when the generation unit 104 creates a data mart from the data warehouse, it can identify the providers of the data to be stored in the data mart based on the first provider identification information. By storing the second provider identification information for identifying the identified providers in the second storage unit 13 in association with the data mart, the generation unit 104 makes it possible to trace the source of the data stored in the data mart. The generation unit 104 is an example of a generation means.
[0037] The second storage unit 13 stores catalog information that shows the contents of each of the multiple data marts. When the generation unit 104 generates a data mart, it adds information that shows the contents of the data mart to the catalog information. The presentation unit 103 presents the contents of the data mart to the user based on the catalog information. For example, when the presentation unit 103 detects a request from a viewer to view a data mart, it presents the contents of each of the multiple data marts to the viewer based on the catalog information. The viewer refers to the presented contents and selects one data mart from among the multiple data marts to view.
[0038] Furthermore, when the presentation unit 103 detects a data mart generation request from the creator, it presents the contents of multiple data marts to the creator based on the catalog information. The creator refers to the presented catalog information and selects one data mart from among the multiple data marts to be used as the source for generating a new data mart.
[0039] The generation unit 104 generates a new data mart from the data stored in the data mart, in accordance with instructions from the creator of the new data mart. In this way, the generation unit 104 can not only generate a data mart from a data warehouse, but also generate a new data mart from an existing data mart. When generating a new data mart, the generation unit 104 generates new second provider identification information to identify the provider of each piece of data stored in the new data mart, based on the second provider identification information. The generation unit 104 stores the new second provider identification information in the second storage unit 13, associating it with the new data mart.
[0040] Existing data marts are associated with second-party provider identification information used to identify the providers who provided the data stored in the data mart. Therefore, when the generation unit 104 creates a new data mart from an existing data mart, it can identify the providers of the data to be stored in the new data mart based on the existing second-party provider identification information associated with the existing data mart. The generation unit 104 stores the new second-party provider identification information, which indicates the identified provider, in the second storage unit 13 in association with the new data mart, thereby making it possible to track the origin of the data stored in the new data mart.
[0041] In this embodiment, the new data mart generated by the generation unit 104 does not contain any data that does not meet the data disclosure conditions. In other words, the generation unit 104 generates a new data mart containing only data that can be disclosed to the creator of the new data mart. The presentation unit 103 then presents the data stored in the new data mart to the creator of the new data mart when the generation unit 104 generates the new data mart.
[0042] Furthermore, the presentation unit 103 presents data stored in the data mart that matches the data disclosure conditions to the data mart viewer, in accordance with instructions from the data mart viewer. For example, if the data disclosure conditions grant the data mart viewer the same authority as the data mart creator, all data stored in the data mart is presented to the viewer. On the other hand, if the data disclosure conditions grant the data mart viewer weaker authority than the data mart creator, only some of the data stored in the data mart is presented to the viewer.
[0043] Here, the data disclosure conditions specified by a particular provider may include a condition that restricts the disclosure of data based on data provided by that particular provider to users who have certain attributes. In this case, if a user has certain attributes, the presentation unit 103 restricts the disclosure of data based on data provided by that particular provider from the data stored in the data mart.
[0044] The attributes of a user are, for example, attributes corresponding to the user's affiliation. For example, a user's attributes may be "internal," "group company," or "general." For example, if a user is an employee of the management company of data management device 100, the user's attribute is "internal." Also, for example, if a user is an employee of a group company of the management company, the user's attribute is "group company." Also, for example, if a user is a general user who is neither an employee of the management company nor a group company, the user's attribute is "general." In this case, for example, the data disclosure conditions specified by a specific provider may include a condition that restricts the disclosure of data based on data provided by that specific provider to general users.
[0045] Furthermore, data disclosure conditions specified by a particular provider may include conditions that restrict the disclosure of data based on a specific type of data to users who have certain attributes. In this case, if a user has certain attributes, the presentation unit 103 restricts the disclosure of data based on a specific type of data provided by a particular provider from the data stored in the data mart. How the data types are defined can be adjusted as appropriate. For example, the data types may be classified by operating mode, set temperature, room temperature, etc.
[0046] In this case, the data disclosure conditions specified by a particular provider may include a condition that restricts the disclosure of data based on operating data indicating the set temperature to general users. If the user is a general user, the presentation unit 103 restricts the disclosure of data based on the set temperature provided by the particular provider from the data stored in the data mart. On the other hand, if the user is an employee of the management company or a group company, the presentation unit 103 does not restrict the disclosure of data based on operating data provided by the particular provider from the data stored in the data mart.
[0047] A data mart is generated based on data retrieved from a data warehouse or other data marts according to search criteria specified by the creator of the data mart. Data disclosure conditions specified by a particular provider may include conditions that restrict the disclosure of data based on data retrieved using specific search criteria to users who have certain attributes. In this case, if a user has certain attributes and the data mart is generated according to specific search criteria, the presentation unit 103 restricts the disclosure of data stored in the data mart that is based on data provided by the particular provider.
[0048] In this case, the data disclosure conditions specified by a particular provider may include a condition that restricts the disclosure of data based on data searched using search criteria that specify a prefecture as the data source, for general users. In this case, if the user is a general user and the data mart was generated according to search criteria that specify Tokyo as the data source, the presentation unit 103 restricts the disclosure of data based on data provided by a particular provider from among the data stored in the data mart.
[0049] The update unit 105 updates information about the data provider in accordance with instructions from the data provider. For example, if the provider specifies new data disclosure conditions, the update unit 105 replaces the data disclosure conditions associated with this provider in the disclosure conditions information stored in the first storage unit 12 with the new data disclosure conditions. The update unit 105 also deletes information about the provider in accordance with instructions from the provider. For example, in accordance with a withdrawal request from the provider, the update unit 105 deletes information about this provider from the provider information described later.
[0050] A withdrawal request may or may not include a request for data deletion. If the withdrawal request includes a request for data deletion, the update unit 105 deletes the data provided by this provider from the data warehouse, deletes the information indicating this provider from the first provider identification information, and deletes the information indicating this provider's disclosure conditions from the disclosure conditions information. In this case, the update unit 105 also deletes the data based on the data provided by this provider from the data mart and deletes the information indicating this provider from the second provider identification information.
[0051] Next, referring to Figures 4 and 5, we will explain the screens that are presented to the data provider when they register various types of information using the terminal device 330.
[0052] First, the provider is presented with the login screen shown in Figure 4. The login screen accepts the input of a username and password. Next, the provider is presented with the process selection screen shown in Figure 4. The process selection screen accepts the provider's selection of the process to be performed. On the process selection screen, the provider selects one of the following: "Register or change settings," "Withdraw," or "Delete data and withdraw." If "Register or change settings" is selected, the process of registering or updating the provider information and data disclosure conditions, as described later, will be executed. If "Withdraw" is selected, the data provided will continue to be used even after withdrawal. If "Delete data and withdraw" is selected, the data will be deleted at the same time as withdrawal.
[0053] When "Register or Change Settings" is selected on the processing selection screen, the provider information input screen shown in Figure 4 is presented. The provider information input screen is a screen that accepts provider information, which is various information about the provider. Provider information includes, for example, date of birth, gender, and address. Next, the provider is presented with the provider information usage restriction specification screen shown in Figure 4. The provider information usage restriction specification screen is a screen that accepts the specification of usage restrictions for provider information. On this screen, it is specified whether or not to restrict the use of each item: date of birth, age, age group, gender, prefecture, and address. Note that age and age group are determined from the date of birth. The prefecture is determined from the address.
[0054] Next, the provider is presented with the usage restriction specification screen for the operating data shown in Figure 5. This screen accepts the specification of usage restrictions for the operating data. On this screen, individual specification is used when specifying each type of operating data individually, and group specification is used when specifying a group that includes multiple types of operating data. For example, setting information is a group that combines the operating mode, set temperature, etc., and occupancy information is a group that combines the room image, number of detected people, etc.
[0055] Next, the provider is presented with the usage scope specification screen shown in Figure 5. The usage scope specification screen is where the provider can specify the scope of use. The usage scope specification screen is where the provider can specify the scope of use for the items set on the usage restriction screen. The usage scope is the scope of the user and can be one of the following: "within the company," "within group companies," or "no restrictions."
[0056] Next, with reference to Figure 6, the information stored in the first storage unit 12 will be described. The first storage unit 12 stores a provider table, an operation data storage table, and a disclosure conditions table. Figure 6(A) is a diagram of the provider table. Figure 6(B) is a diagram of the operation data storage table. Figure 6(C) is a diagram of the disclosure conditions table.
[0057] The provider table is a table that stores provider information about providers who provide data to the data warehouse. The provider table stores provider information registered on the provider information input screen. The provider table displays provider information for each provider.
[0058] The operation data storage table is a table that stores operation data for equipment 320 provided by the provider in chronological order. The operation data storage table stores multiple records in chronological order, each containing a customer ID (Identifier) indicating the provider, a date and time, and operation data. The customer ID is information that makes it possible to identify the provider of the operation data stored in the data warehouse. Therefore, the customer ID included in the operation data storage table is an example of first provider identification information. The data stored in the data warehouse is basically the same as the data stored in the operation data storage table.
[0059] The disclosure conditions table is a table that records the data disclosure conditions specified by the provider. The disclosure conditions table shows the data disclosure conditions for each provider. The data disclosure conditions correspond to the information registered on the screen for specifying usage restrictions regarding provider information, the screen for specifying usage restrictions regarding driving data, and the screen for specifying usage scope. The disclosure conditions table is an example of disclosure conditions information.
[0060] Next, with reference to Figures 7, 8, 9, and 10, we will describe the screens presented to the data mart creator when they create a data mart using the terminal device 400.
[0061] First, the creator is presented with the login screen shown in Figure 7. The login screen accepts the input of a username and password. The data management device 100 authenticates the creator using the username and password. The creator's account is managed by the creator account table shown in Figure 11(A). The creator account table is a table that stores multiple records including the creator's name, affiliation, and password. The data management device 100 uses the creator account table to determine the creator's attributes from the username and discloses data to the extent corresponding to the attributes. In this embodiment, the creator's attributes correspond to the creator's affiliation and are one of "internal," "group company," or "general." Hereafter, the creator's affiliation will be assumed to be "internal."
[0062] Next, the creator is presented with the target data selection screen shown in Figure 7. The target data selection screen accepts the selection of target data. The target data is either a data warehouse or a single data mart. In the case of creating a data mart, the target data is the data warehouse or a single data mart that will serve as the base for generating the new data mart. In the case of viewing a data mart, the target data is the single data mart that is being requested to be viewed.
[0063] The target data selection screen displays a string indicating the data warehouse and a list of titles for each data mart. When the creator selects a data mart using the radio buttons and presses the "Catalog Reference" button, the contents of the data catalog for the selected data mart are displayed. Figure 12 shows an example of a data catalog. The catalog information includes the data catalog for each data mart. When the creator creates a new data mart from an existing data mart, they refer to the data catalog and select the data mart to be used to generate the new data mart. The following explanation assumes that the creator has selected the data warehouse.
[0064] When the creator selects a data warehouse, the condition specification screen shown in Figure 7 is presented. The condition specification screen is used to specify the conditions, calculations, etc., for generating the desired data mart. On the condition specification screen, the creator can specify, for example, the period, equipment, filtering conditions, operating data items, calculations, etc. When the "Select Equipment" button is pressed on the condition specification screen, the equipment selection screen shown in Figure 8 is presented. The equipment selection screen is used to select the type of equipment. The following explanation assumes that an air conditioner has been selected as the type of equipment.
[0065] When the "Select Filter Conditions" button is pressed on the conditions selection screen, the filter conditions selection screen shown in Figure 8 is displayed. The filter conditions selection screen is for selecting filtering conditions. The following explanation assumes that a prefecture has been selected. When a prefecture is selected on the filter conditions selection screen, the prefecture selection screen shown in Figure 8 is displayed. The prefecture selection screen is for selecting a prefecture. The following explanation assumes that Tokyo has been selected.
[0066] When the "Select Driving Data Item" button is pressed on the condition specification screen, the driving data item selection screen shown in Figure 8 is displayed. The driving data item selection screen is for selecting items of driving data. The following explanation assumes that "Set Temperature," "Indoor Temperature," "Outdoor Temperature," and "Number of Detected Persons" have been selected. When the "Specify Calculation" button is pressed on the condition specification screen, the calculation specification screen shown in Figure 9 is displayed. The calculation specification screen is for specifying calculations based on driving data. Calculations are performed for each record stored in the driving data storage table. The following explanation assumes that "Indoor Temperature" is selected as arg1, "Set Temperature" is selected as arg2, and the value obtained by subtracting arg2 from arg1 is defined as "Indoor Temperature Difference."
[0067] When the "Display" button is pressed on the condition specification screen, the data display screen shown in Figure 10 is presented. The data display screen displays data for the conditions specified by the creator, within the scope of the data disclosure conditions specified by the provider. The data display screen shown in Figure 10 displays a table containing records of the operating data of an air conditioner from a provider whose prefecture attribute is "Tokyo," including the data items "set temperature," "indoor temperature," "outdoor temperature," and "number of people detected," as well as "indoor temperature difference" based on "indoor temperature" and "set temperature," from the operating data storage table shown in Figure 6(B). Note that if the creator's attribute is "internal," there are no restrictions on data disclosure.
[0068] On the data display screen, when "Air Conditioner Usage in Tokyo" is entered as the data mart name and the "Confirm" button is pressed, the content displayed on the screen is converted to CSV (Comma Separated Values) format and a data mart is generated. Figure 11(B) shows the data storage table corresponding to the generated data mart.
[0069] When a data mart is generated, a provider tracking table, as shown in Figure 11(C), is created. The provider tracking table is used to track which provider provided each piece of data in the data mart. Providers are identified by customer IDs. The provider tracking table is generated based on the operational data storage table, which includes first-party provider identification information. The provider tracking table is an example of second-party provider identification information. Additionally, when a data mart is generated, a data catalog, as shown in Figure 12, is created according to the creator's edits. The data catalog is a table that shows the contents of the corresponding data mart.
[0070] Next, referring to Figure 13, we will explain the disclosed data that is made available to users from the data stored in the data mart.
[0071] Figure 13(A) shows the disclosed data disclosed to users whose attribute is "Group Company". In the disclosure conditions table shown in Figure 6(C), the provider with customer ID "0004" has set a restriction on the scope of disclosure for "Set Temperature". Therefore, records containing "Set Temperature" are not disclosed to users whose attribute is "Group Company" or "General". Also, in the disclosure conditions table shown in Figure 6(C), the provider with customer ID "0005" has set a restriction on prefectures. Therefore, records found using Tokyo as the search condition are not disclosed to users whose attribute is "Group Company" or "General". Accordingly, if the user's attribute is "Group Company", the disclosed data is obtained by deleting the records corresponding to records containing "0004" or "0005" in the provider tracking table shown in Figure 11(C) from the data storage table shown in Figure 11(B).
[0072] Figure 13(B) shows the disclosed data disclosed to users whose attribute is "General". In the disclosure conditions table shown in Figure 6(C), the provider with customer ID "0001" has a disclosure limit on "Number of Detected," so records containing "Number of Detected" are not disclosed to users whose attribute is "General". Therefore, if the user's attribute is "General," the disclosed data is obtained by deleting the records corresponding to records containing "0001," "0004," or "0005" in the provider tracking table shown in Figure 11(C) from the data storage table shown in Figure 11(B).
[0073] Next, the data mart generation process performed by the data management device 100 will be described with reference to the flowchart in Figure 14. The data mart generation process is performed with the data warehouse, first provider identification information, and disclosure condition information stored in the first storage unit 12. In other words, prior to the data mart generation process, the following processes are performed: generating a data warehouse from data collected from the device 320, generating first provider identification information from data collected from the device 320 and provider information, and generating disclosure condition information from data disclosure conditions specified by the provider.
[0074] First, the control unit 11 of the data management device 100 authenticates the creator of the data mart (step S101). For example, the control unit 11 displays the login screen shown in Figure 7 on the terminal device 400 and obtains the username and password from the terminal device 400. The control unit 11 compares the username and password with the information contained in the creator account table shown in Figure 11(A) to identify the creator's attributes.
[0075] After completing the processing in step S101, the control unit 11 presents a list of data source candidates (step S102). For example, based on the catalog information stored in the second storage unit 13, the control unit 11 displays the target data selection screen shown in Figure 7 on the terminal device 400. After completing the processing in step S102, the control unit 11 accepts the specification of a data source (step S103). The data source is a data warehouse or a data mart.
[0076] After completing the processing in step S103, the control unit 11 accepts the specification of data generation conditions (step S104). For example, the control unit 11 displays the condition specification screen shown in Figure 7, the equipment selection screen shown in Figure 8, the filtering condition selection screen, the operation data item selection screen, the prefecture selection screen, the calculation specification screen shown in Figure 9, etc., on the terminal device 400, and accepts the specification of data generation conditions from the creator via the terminal device 400.
[0077] Once the control unit 11 completes the processing in step S104, it presents the data within the disclosure scope (step S105). For example, the control unit 11 extracts and processes data from a data warehouse or an existing data mart according to the specified data generation conditions. Then, the control unit 11 selects data from the extracted and processed data according to the creator's attributes and displays the selected data on the terminal device 400.
[0078] For example, if the creator's attribute is "internal," the data display screen shown in Figure 10 is displayed on the terminal device 400. For example, if the creator's attribute is "group company," the terminal device 400 displays a screen in which the upper part of the data display screen shown in Figure 10 is replaced with the disclosed data shown in Figure 13(A). For example, if the creator's attribute is "general," the terminal device 400 displays a screen in which the upper part of the data display screen shown in Figure 10 is replaced with the disclosed data shown in Figure 13(B).
[0079] After completing the processing in step S105, the control unit 11 generates a data mart from the data within the disclosure scope (step S106). In other words, the control unit 11 generates a data mart within the disclosure scope according to the creator's attributes. After completing the processing in step S106, the control unit 11 saves the data mart (step S107). For example, the control unit 11 stores the generated data mart in the second storage unit 13.
[0080] When the control unit 11 completes the processing in step S107, it generates a data catalog and a provider tracking table (step S108). In other words, the control unit 11 generates a data catalog that shows the contents of the generated data mart. The control unit 11 also generates a provider tracking table to track the providers of each piece of data stored in the generated data mart.
[0081] When the control unit 11 completes the processing in step S108, it saves the data catalog and the provider tracking table (step S109). For example, the control unit 11 updates the catalog information stored in the second storage unit 13 to include the generated data catalog. The control unit 11 also stores the generated provider tracking table in the second storage unit 13 in association with the generated data mart. When the control unit 11 completes the processing in step S109, it completes the data mart generation process.
[0082] Next, the data mart presentation process performed by the data management device 100 will be explained with reference to the flowchart in Figure 15. The data mart presentation process is performed with the data warehouse, first provider identification information, and disclosure condition information stored in the first storage unit 12, and the data mart, second provider identification information, and catalog information stored in the second storage unit 13. In other words, the data mart generation process is performed prior to the data mart viewing process.
[0083] First, the control unit 11 authenticates the viewer of the data mart (step S201). The authentication of the viewer is basically the same process as the authentication of the creator. After completing the process in step S201, the control unit 11 presents each data mart (step S202). For example, based on the catalog information stored in the second storage unit 13, the control unit 11 displays a screen on the terminal device 400 that excludes the string "data warehouse" from the target data selection screen shown in Figure 7. After completing the process in step S202, the control unit 11 accepts the specification of the data mart to be viewed (step S203).
[0084] When the control unit 11 completes the processing in step S203, it presents data from the specified data mart that falls within the scope of disclosure (step S204). For example, the control unit 11 selects data from the specified data mart that corresponds to the viewer's attributes and displays the selected data on the terminal device 400. For example, if the viewer's attribute is "internal," the terminal device 400 displays a screen showing the upper part of the data display screen shown in Figure 10. For example, if the viewer's attribute is "group company," the terminal device 400 displays a screen showing the disclosure data shown in Figure 13(A). For example, if the creator's attribute is "general," the terminal device 400 displays a screen showing the disclosure data shown in Figure 13(B). When the control unit 11 completes the processing in step S204, it completes the data mart presentation process.
[0085] Next, the data management processes performed by the data management device 100 will be explained with reference to the flowchart in Figure 16.
[0086] First, the control unit 11 determines whether there is an instruction to register disclosure conditions or an instruction to change disclosure conditions (step S301). For example, when the terminal device 330 is displaying the processing selection screen shown in Figure 4, the control unit 11 determines whether the "Register or Change Settings" radio button is selected and whether the "OK" button is pressed.
[0087] When the control unit 11 determines that there is an instruction to register disclosure conditions or an instruction to change disclosure conditions (step S301: YES), it updates the disclosure condition information (step S302). For example, the control unit 11 displays the provider information input screen shown in Figure 4, the provider information usage restriction specification screen, the driving data usage restriction specification screen shown in Figure 5, the usage range specification screen, etc., on the terminal device 330 and accepts registration or change of data disclosure conditions from the provider. Then, the control unit 11 updates the disclosure condition information stored in the first storage unit 12 according to the data disclosure conditions received from the provider.
[0088] If the control unit 11 determines that there is no instruction to register disclosure conditions or to change disclosure conditions (step S301: NO), or if the processing in step S302 is completed, it determines whether there is an instruction to delete data (step S303). For example, when the terminal device 330 is displaying the processing selection screen shown in Figure 4, the control unit 11 determines whether the radio button for "Delete data and withdraw" is selected and whether the "OK" button is pressed.
[0089] When the control unit 11 determines that there is a data deletion instruction (step S303: YES), it reads the provider tracking table and the data mart (step S304). For example, the control unit 11 identifies the customer ID of the person to be deleted, who is the provider that requested the data deletion, and reads the provider tracking table containing the identified customer ID from the second storage unit 13. The control unit 11 also reads the data mart associated with this provider tracking table from the second storage unit 13.
[0090] When the control unit 11 completes the processing in step S304, it deletes the record containing the customer ID of the person to be deleted from the provider tracking table (step S305). When the control unit 11 completes the processing in step S305, it deletes the record corresponding to the deleted record from the data mart (step S306).
[0091] When the control unit 11 completes the processing in step S306, it saves the provider tracking table and the data mart (step S307). For example, the control unit 11 saves the provider tracking table, in which the record containing the customer ID of the person to be deleted has been deleted, and the data mart, in which the record corresponding to this record has been deleted, to the second storage unit 13. When the control unit 11 completes the processing in step S307, it deletes the record containing the customer ID of the person to be deleted from the data warehouse (step S308). When the control unit 11 determines that there is no instruction to delete data (step S303: NO), or when it has completed the processing in step S308, it completes the data management processing.
[0092] In this embodiment, the provider of data stored in the data mart can be traced using second provider identification information. Therefore, according to this embodiment, changes in data disclosure conditions can be appropriately reflected in the disclosure of the data mart. Furthermore, in this embodiment, when the data mart is generated, the second provider identification information is generated based on the first provider identification information. Therefore, according to this embodiment, the second provider information can be easily generated.
[0093] In this embodiment, the contents of the data mart are presented to the user based on the catalog information generated when the data mart is created. Therefore, according to this embodiment, the user can easily understand the contents of the data mart. Furthermore, in this embodiment, when a new data mart is generated from an existing data mart, new second-party provider identification information associated with the new data mart is generated from the existing second-party provider identification information associated with the existing data mart. Therefore, according to this embodiment, when a new data mart is generated from an existing data mart, new second-party provider identification information for tracking the source of the data stored in the new data mart can be easily created.
[0094] In this embodiment, the new data mart does not store data that does not meet the data disclosure conditions, and the data stored in the new data mart is presented to the creator of the new data mart. Therefore, according to this embodiment, when a new data mart is generated, the generated data mart can be presented to the creator as is. In addition, in this embodiment, according to the viewer's instructions, the data stored in the data mart that meets the data disclosure conditions is presented to the viewer. Therefore, according to this embodiment, the data mart can be presented with an appropriate scope of disclosure according to the viewer.
[0095] In this embodiment, if a user has certain attributes, the disclosure of data stored in the data mart that is based on data provided by a specific provider is restricted. Therefore, according to this embodiment, the data mart can be presented with an appropriate scope of disclosure according to the user's attributes. In this embodiment, if a user has certain attributes, the disclosure of data stored in the data mart that is based on a specific type of data provided by a specific provider is restricted. Therefore, according to this embodiment, the data mart can be presented with an appropriate scope of disclosure according to the user's attributes and the type of data.
[0096] In this embodiment, if a user has specific attributes and a data mart is generated according to specific search conditions, the disclosure of data based on data provided by specific providers within the data mart is restricted. Therefore, according to this embodiment, the data mart can be presented with an appropriate scope of disclosure according to the user's attributes and search conditions.
[0097] (Embodiment 2) Embodiment 1 described an example of generating a data mart within the scope of disclosure to the data mart creator. This embodiment describes an example of generating a data mart that includes data outside the scope of disclosure to the data mart creator, while presenting the data within the data mart to the creator within the scope of disclosure to the creator. Note that the same configurations and functions as in Embodiment 1 will be omitted or simplified as appropriate.
[0098] In this embodiment, the new data mart generated by the generation unit 104 contains data that does not conform to the data disclosure conditions. In other words, the generation unit 104 generates a new data mart that includes data outside the scope of disclosure to the creator of the data mart. On the other hand, when the generation unit 104 generates the new data mart, the presentation unit 103 presents the data that conforms to the data disclosure conditions from the data stored in the new data mart to the creator of the new data mart. Thus, in this embodiment, the data mart is not generated according to the creator's authority, but rather the data mart is generated without considering the creator's authority, and the data mart is disclosed to the creator to the extent corresponding to the creator's authority.
[0099] For example, in Embodiment 1, if the creator's attribute is "internal," all data matching the search criteria are displayed on the data display screen, as shown in Figure 10. A data mart containing all the data displayed on the data display screen is then generated, which corresponds to the data storage table shown in Figure 11(B). However, in Embodiment 1, if the creator's attribute is "group company," only the data corresponding to the creator's attribute among the data matching the search criteria is displayed on the data display screen, which corresponds to the data included in the disclosed data shown in Figure 13(A). A data mart containing all the data displayed on the data display screen is then generated, which corresponds to the data included in the disclosed data shown in Figure 13(A).
[0100] In Embodiment 1, the data mart is generated with a disclosure scope limited to the creator of the data mart. Therefore, users of this data mart cannot access data beyond this disclosure scope. For example, in Embodiment 1, if the attribute of the data mart creator is "group company," even if the attribute of the data mart viewer is "internal," only the same data as a viewer with the attribute "group company" can be viewed. Also, in Embodiment 1, if the attribute of the data mart creator is "group company," even if the attribute of the creator of a new data mart is "internal," only the same data mart as a creator of a new data mart with the attribute "group company" can be generated. Thus, in Embodiment 1, the data disclosure scope is narrowed and not expanded. Therefore, in this embodiment, the data mart is generated in such a way that the data disclosure scope can be expanded.
[0101] In other words, in this embodiment, if the creator's attribute is "group company," only the data corresponding to the creator's attribute among the data that matches the search criteria, i.e., the data included in the disclosed data shown in Figure 13(A), will be displayed. However, a data mart containing all the data that matches the search criteria, i.e., a data mart corresponding to the data storage table shown in Figure 11(B), is generated.
[0102] In this embodiment, a data mart is generated that exceeds the disclosure scope to the creator of the data mart. Therefore, users of this data mart can access data beyond this disclosure scope. For example, in this embodiment, even if the attribute of the data mart creator is "group company," if the attribute of the data mart viewer is "internal," the viewer can access data with a wider disclosure scope than a viewer with the attribute of "group company." Also, in this embodiment, even if the attribute of the data mart creator is "group company," if the attribute of the creator of a new data mart is "internal," a data mart can be generated with a wider scope than a new data mart creator with the attribute of "group company." Thus, in this embodiment, a data mart is generated in such a way that the scope of data disclosure can be expanded.
[0103] Next, the data mart generation process performed by the data management device 100 will be explained with reference to the flowchart in Figure 17.
[0104] First, the control unit 11 authenticates the creator of the data mart (step S401). After completing the process in step S401, the control unit 11 presents candidates for the data source (step S402). After completing the process in step S402, the control unit 11 accepts the specification of the data source (step S403). After completing the process in step S403, the control unit 11 accepts the specification of the data generation conditions (step S404).
[0105] After completing the processing in step S404, the control unit 11 presents data within the disclosure scope (step S405). For example, the control unit 11 extracts and processes data from the data warehouse or an existing data mart according to the specified data generation conditions. Then, the control unit 11 selects data from the extracted and processed data according to the creator's attributes and displays the selected data on the terminal device 400. After completing the processing in step S405, the control unit 11 generates a data mart that includes data outside the disclosure scope (step S406). For example, the control unit 11 generates a data mart that stores all the data extracted and processed from the data warehouse or an existing data mart according to the specified data generation conditions.
[0106] When the control unit 11 completes the processing in step S406, it saves the data mart (step S407). When the control unit 11 completes the processing in step S407, it generates a data catalog and a provider tracking table (step S408). When the control unit 11 completes the processing in step S408, it saves the data catalog and the provider tracking table (step S409). When the control unit 11 completes the processing in step S409, it completes the data mart generation process.
[0107] In this embodiment, a data mart is generated that contains data exceeding the disclosure scope for the creator of the data mart. Therefore, according to this embodiment, it is possible to expand the scope of data disclosure. For example, it is possible to make the disclosure scope for viewers of the data mart wider than the disclosure scope for the creator of the data mart.
[0108] (Embodiment 3) Embodiment 1 described an example in which the data mart does not store data from multiple providers. This embodiment describes an example in which the data mart stores data from multiple providers. Note that the same configurations and functions as in Embodiments 1 and 2 will be omitted or simplified as appropriate.
[0109] In this embodiment, the data warehouse stores first data provided by the first provider and second data provided by the second provider. The data mart stores third data based on the first and second data. The second provider identification information indicates the first provider and the second provider as providers of the third data.
[0110] The presentation unit 103 does not present the third data to the user if the disclosure of the first data is restricted by data disclosure conditions specified by the first provider, or if the disclosure of the second data is restricted by data disclosure conditions specified by the second provider. Thus, in this embodiment, if the source of one piece of data stored in the data mart is multiple providers, this piece of data will not be disclosed unless it conforms to all the data disclosure conditions specified by these multiple providers.
[0111] The information stored in the second storage unit 13 will be described below with reference to Figure 18. Figure 18(A) is a diagram showing the data storage table corresponding to the data mart generated in this embodiment. Figure 18(B) is a diagram showing the provider tracking table generated in this embodiment.
[0112] As shown in Figure 18(A), the data storage table stores multiple records including the date and time, average set temperature, and average room temperature. The average set temperature is the average value of the set temperatures collected at the same time. The average room temperature is the average value of the room temperatures collected at the same time. Here, it is assumed that when the data mart was generated, the set temperatures and room temperatures provided by the provider with customer ID "0001", the provider with customer ID "0003", the provider with customer ID "0004", and the provider with customer ID "0005" were retrieved according to the search conditions specified by the creator.
[0113] In this case, as shown in Figure 18(B), the provider tracking table indicates that the providers of the average set temperature and average room temperature are four individuals: provider with customer ID "0001", provider with customer ID "0003", provider with customer ID "0004", and provider with customer ID "0005". The average set temperature and average room temperature will not be presented to the user unless they meet all the data disclosure conditions specified by these four providers.
[0114] In this embodiment, if a single piece of data stored in a data mart originates from multiple providers, that piece of data will not be disclosed unless it conforms to all the data disclosure conditions specified by those multiple providers. According to this embodiment, data based on multiple pieces of data provided by multiple providers can be appropriately disclosed in accordance with the data disclosure conditions specified by those multiple providers.
[0115] (Embodiment 4) Embodiment 1 described an example in which the disclosure of data is determined on a record-by-record basis. This embodiment describes an example in which the disclosure of data is determined on a data-by-data basis. Note that the same configurations and functions as in Embodiments 1-3 will be omitted or simplified as appropriate.
[0116] In Embodiment 1, the decision to disclose data was made on a record-by-record basis, that is, on a data set basis for data provided by the same provider at the same time. For example, if the user attribute of the data mart is "group company," the data disclosure conditions specified by the provider with customer ID "0004" include the set temperature in the restricted data. Therefore, as shown in Figure 13(A), the disclosure of records containing data provided by the provider with customer ID "0004" is restricted. In other words, not only the set temperature provided by the provider with customer ID "0004" and the indoor temperature difference based on this set temperature are restricted, but also the indoor temperature, outdoor temperature, and number of detected people provided by the provider with customer ID "0004" at the same time as the set temperature are restricted.
[0117] In contrast, in this embodiment, the disclosure of data is determined on a data-by-data basis. For example, if the user attribute of the data mart is "group company," the data disclosure conditions specified by the provider with customer ID "0004" include the set temperature as restricted data. In this case, as shown in Figure 19(A), the disclosure of the set temperature provided by the provider with customer ID "0004" and the indoor temperature difference based on this set temperature is restricted. On the other hand, the disclosure of indoor temperature, outdoor temperature, and number of detected people, provided by the provider with customer ID 0004 at the same time as the set temperature, is not restricted.
[0118] Furthermore, for example, if the user attribute of the data mart is "general," the number of detected individuals is included in the restricted disclosure operating data under the data disclosure conditions specified by the provider with customer ID "0001." In this case, as shown in Figure 19(B), the disclosure of the number of detected individuals provided by the provider with customer ID "0001" is restricted, but the disclosure of other data provided by the provider with customer ID "0001" is not restricted. Also, the disclosure of the set temperature and the indoor temperature difference based on this set temperature provided by the provider with customer ID "0004" is restricted, but the disclosure of the indoor temperature, outdoor temperature, and number of detected individuals provided by the provider with customer ID "0004" at the same time as the set temperature is not restricted.
[0119] In this embodiment, the decision on whether or not to disclose data is made on a data-by-data basis, rather than on a record-by-record basis. Therefore, according to this embodiment, data disclosure can be restricted at a smaller level.
[0120] (Embodiment 5) Embodiment 1 described an example in which the data management system 1000 includes a single device. This embodiment describes an example in which the data management system 1100 includes multiple devices. Note that the same configurations and functions as in Embodiments 1-4 will be omitted or simplified as appropriate.
[0121] As shown in Figure 20, in this embodiment, the data management system 1100 comprises a data management device 110, a first storage device 610, and a second storage device 620. The data management device 110, the first storage device 610, and the second storage device 620 are each connected to a communication network 500.
[0122] The data management device 110 has basically the same configuration and functions as the data management device 110, except that it does not have the first storage unit 12 and the second storage unit 13. The first storage device 610 basically has the same functions as the first storage unit 12. The second storage device 620 basically has the same functions as the second storage unit 13. The first storage device 610 and the second storage device 620 include, for example, hard disk drives. The first storage device 610 is an example of the first storage means. The second storage device 620 is an example of the second storage means.
[0123] The data management device 110 accesses the data warehouse, first provider identification information, disclosure conditions information, etc., stored in the first storage device 610 via the communication network 500. The data management device 110 generates a data mart from the data warehouse stored in the first storage device 610. The data management device 110 saves the generated data mart to the second storage device 620 via the communication network 500. When generating the data mart, the data management device 110 generates second provider identification information based on the first provider identification information stored in the first storage device 610.
[0124] The data management device 110 generates catalog information when generating a data mart. The data management device 110 stores the second provider identification information and catalog information in the second storage device 620 via the communication network 500. The data management device 110 presents the viewer with a data catalog based on the catalog information stored in the second storage device 620, according to the viewer's instructions. The data management device 110 presents the viewer with the data mart stored in the second storage device 620 within the scope of disclosure based on the disclosure condition information stored in the first storage device 610 and the second provider identification information stored in the second storage device 620.
[0125] In this embodiment, the data warehouse and data mart are stored on devices different from the data management device 110. Therefore, according to this embodiment, the storage capacity of the data management device 110 can be reduced.
[0126] (modified version) Although embodiments have been described above, various modifications and applications are possible. It is arbitrary which parts of the configuration, function, and operation described in the above embodiments are adopted. Furthermore, additional configurations, functions, and operations may be adopted in addition to those described above. Also, the configurations, functions, and operations described in the above embodiments can be freely combined.
[0127] Embodiment 1 describes an example in which the data management device 100 has the functions of an ETL device, a data mart generation device, and a data viewing device. If there is another device that functions as an ETL device, the data management device 100 does not need to have the functions of an ETL device. Also, if there is another device that functions as a data viewing device, the data management device 100 does not need to have the functions of a data viewing device.
[0128] Embodiment 1 described an example in which the data stored in the data warehouse and data mart is operational data collected from the device 320. The data stored in the data warehouse and data mart may be other types of data.
[0129] Embodiment 1 describes an example in which the data warehouse, first provider identification information, and disclosure conditions information are stored in the first storage unit 12, and the data mart, second provider identification information, and catalog information are stored in the second storage unit 13. The storage devices in which this information is stored are not limited. For example, the data warehouse, first provider identification information, and disclosure conditions information may be stored in separate storage devices. Also, the data mart, second provider identification information, and catalog information may be stored in separate storage devices. Furthermore, the data warehouse may include the first provider identification information and disclosure conditions information. Also, the data mart may include the second provider identification information and catalog information. Also, the catalog information may include the second provider identification information.
[0130] In the above embodiment, the control unit 11 functioned as the respective components shown in Figure 3 by the CPU executing a program stored in the ROM or third storage unit 14. However, in this disclosure, the control unit 11 may be dedicated hardware. Dedicated hardware includes, for example, a single circuit, a composite circuit, a programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a combination thereof. If the control unit 11 is dedicated hardware, each function of each component may be realized by separate hardware, or the functions of each component may be realized together by a single piece of hardware. Furthermore, some of the functions of each component may be realized by dedicated hardware, and other parts by software or firmware. In this way, the control unit 11 can realize the above-mentioned functions by hardware, software, firmware, or a combination thereof.
[0131] It is also possible to make an existing personal computer or information terminal or other computer function as the data management devices 100 and 110 of this disclosure by applying an operating program that defines the operation of the data management devices 100 and 110 of this disclosure to that computer. Furthermore, the distribution method of such a program is arbitrary; for example, it may be distributed by storing it on a computer-readable recording medium such as a CD-ROM (Compact Disk ROM), DVD (Digital Versatile Disk), MO (Magneto Optical Disk), or memory card, or it may be distributed via a communication network such as the Internet.
[0132] This disclosure allows for various embodiments and modifications without departing from the broad spirit and scope of this disclosure. Furthermore, the embodiments described above are for illustrative purposes only and do not limit the scope of this disclosure. In other words, the scope of this disclosure is indicated by the claims, not by the embodiments. Various modifications made within the scope of the claims and the equivalent significance of the disclosure are considered to be within the scope of this disclosure. [Industrial applicability]
[0133] This disclosure is applicable to data management systems. [Explanation of symbols]
[0134] 11 Control Unit, 12 First Storage Unit, 13 Second Storage Unit, 14 Third Storage Unit, 15 Communication Unit, 100, 110 Data Management Device, 101 Instruction Acquisition Unit, 102 Authentication Unit, 103 Presentation Unit, 104 Generation Unit, 105 Update Unit, 300, 300A, 300B Items, 310 Gateway, 320 Equipment, 330, 400 Terminal Devices, 500 Communication Network, 610 First Storage Device, 620 Second Storage Device, 1000, 1100 Data Management System
Claims
1. A first storage means that stores first provider identification information for identifying the provider of each piece of data stored in a data warehouse that stores data searchable by a search expression, and disclosure condition information indicating the data disclosure conditions specified by the provider indicated by the first provider identification information, A second storage means for storing second provider identification information for identifying the provider of each of the data stored in the data mart generated based on the data warehouse, which is the data provider used to generate the data stored in the data mart from the data stored in the data warehouse, The presenting means includes, based on the disclosure conditions information and the second provider identification information, a means for identifying data disclosure conditions specified by the data provider used to generate the data for each piece of data stored in the data mart, and presenting to the users of the data mart the data that matches the data disclosure conditions from among the data stored in the data mart. Data management device.
2. The system further comprises generation means for generating the data mart from data stored in the data warehouse in accordance with instructions from the creator of the data mart, The generation means generates the second provider identification information based on the first provider identification information when generating the data mart, and stores the second provider identification information in the second storage means in association with the data mart. The data management device according to claim 1.
3. The second storage means stores catalog information indicating the contents of each of the multiple data marts, The generation means, when generating the data mart, adds information indicating the contents of the data mart to the catalog information, The presentation means presents the contents of the data mart to the user based on the catalog information. The data management device according to claim 2.
4. The generation means generates the new data mart from the data stored in the data mart in accordance with the instructions of the creator of the new data mart, When generating the new data mart, the generation means generates new second provider identification information indicating the provider of each data stored in the new data mart based on the second provider identification information, and stores the new second provider identification information in the second storage means in association with the new data mart. The data management device according to claim 2 or 3.
5. The new data mart generated by the generation means does not contain any data that does not conform to the data disclosure conditions. The presentation means presents the data stored in the new data mart to the creator of the new data mart when the generation means generates a new data mart. The data management device according to claim 4.
6. The new data mart generated by the generation means contains data that does not conform to the data disclosure conditions. The presentation means, when the generation means generates a new data mart, presents to the creator of the new data mart the data stored in the new data mart that matches the data disclosure conditions. The data management device according to claim 4.
7. The presentation means presents to the viewer of the data mart, in accordance with instructions from the viewer of the data mart, data stored in the data mart that meet the data disclosure conditions. A data management device according to any one of claims 1 to 6.
8. The data disclosure conditions specified by a particular provider include conditions that restrict the disclosure of data based on data provided by the particular provider to users who have certain attributes, The presentation means, if the user has the specific attribute, restricts the disclosure of data based on data provided by the specific provider from the data stored in the data mart. A data management device according to any one of claims 1 to 7.
9. The data disclosure conditions specified by the aforementioned specific provider include conditions that restrict the disclosure of data based on certain types of data to users having the aforementioned specific attributes, The presentation means, if the user has the specific attribute, restricts the disclosure of data based on the specific type of data provided by the specific provider from the data stored in the data mart. The data management device according to claim 8.
10. The aforementioned data mart is generated based on data retrieved from the data warehouse or other data marts according to search criteria specified by the creator of the aforementioned data mart. The data disclosure conditions specified by the aforementioned specific provider include a condition that restricts the disclosure of data based on data retrieved using specific search criteria to users having the aforementioned specific attributes, The presentation means, when the user has the specific attribute and the data mart is generated according to the specific search conditions, restricts the disclosure of data based on data provided by the specific provider from the data stored in the data mart. The data management device according to claim 8 or 9.
11. The aforementioned data warehouse stores the first data provided by the first provider and the second data provided by the second provider. The data mart stores a third data based on the first data and the second data. The second provider identification information indicates the first provider and the second provider as providers of the third data, The presentation means shall not present the third data to the user if the disclosure of the first data is restricted by the data disclosure conditions specified by the first provider, or if the disclosure of the second data is restricted by the data disclosure conditions specified by the second provider. A data management device according to any one of claims 1 to 10.
12. A first storage means that stores first provider identification information for identifying the provider of each piece of data stored in a data warehouse that stores data searchable by a search expression, and disclosure condition information indicating the data disclosure conditions specified by the provider indicated by the first provider identification information, A generation means that generates the data mart from the data stored in the data warehouse in accordance with the instructions of the data mart creator, A second storage means for storing second provider identification information for identifying the provider of each of the data stored in the data mart, which is the data used to generate the data stored in the data mart from the data stored in the data warehouse, The presenting means includes, based on the disclosure conditions information and the second provider identification information, a means for identifying data disclosure conditions specified by the data provider used to generate the data for each piece of data stored in the data mart, and presenting to the user the data among the data stored in the data mart that matches the data disclosure conditions. Data management system.
13. A data management method performed by a data management system comprising a first storage means, a second storage means, a control means, and a presentation means, The control means stores in the first storage means disclosure condition information that indicates data disclosure conditions specified by each provider of data stored in the data warehouse that stores data searchable by search formula, The control means stores provider identification information in the second storage means for identifying the provider of each of the data stored in the data mart generated based on the data warehouse, and which of the data stored in the data warehouse was used to generate the data stored in the data mart. The presentation means identifies data disclosure conditions specified by the data provider used to generate each piece of data stored in the data mart, based on the disclosure conditions information and the provider identification information, and presents to the user of the data mart the data that matches the data disclosure conditions among the data stored in the data mart. Data management methods.
14. Computers, Based on disclosure condition information indicating data disclosure conditions specified by each provider of data stored in a data warehouse that stores data searchable by a search expression, and provider identification information for identifying each provider of data stored in a data mart generated based on the data warehouse, which is the provider of the data used to generate the data stored in the data mart, the system identifies the data disclosure conditions specified by the data provider used to generate the data stored in the data mart for each piece of data stored in the data mart, and functions as a presentation means for presenting data stored in the data mart that matches the data disclosure conditions to the user of the data mart. program.
Citation Information
Patent Citations
Information management dictionary, server for data retrieval, data base retrieving method, data copying method and data retrieving program
JP2003022270A
Data mart providing system and program
JP2004302767A
Data management level determination program and data management level determination method
JP2020046920A
System and method for automatically synchronizing security-relevant information between a relational database and a multidimensional database
US20060026180A1